Created
May 7, 2019 19:23
-
-
Save GeoffMahugu/b49644ecd3f26f48d42747da6ee1f0ee to your computer and use it in GitHub Desktop.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
<html> | |
<head> | |
<meta http-equiv=pragma content=nocache> | |
<META HTTP-EQUIV=Expires CONTENT=-1> | |
<script language=”Javascript”> | |
function autoSubmit() { | |
//alert(“Auto submit from redirection.jsp”); | |
document.forms[0].submit(); | |
} | |
</script> | |
</head> | |
<?xml version=”1.0" encoding=”UTF-8"?> | |
<WISPAccessGatewayParam xmlns:xsi=”http://www.w3.org/2001/XMLSchema-instance" | |
xsi:noNamespaceSchemaLocation=”http://www.acmewisp.com/WISPAccessGatewayParam.xsd"> <Redirect> | |
<AccessProcedure>1.0</AccessProcedure> | |
<AccessLocation>Ahmedabad</AccessLocation> | |
<LocationName>Ahmedabad</LocationName> | |
<LoginURL>https://testipass.com/24online/servlet/smartclient?mode=1</LoginURL> | |
<MessageType>100</MessageType> | |
<ResponseCode>0</ResponseCode> | |
</Redirect> | |
</WISPAccessGatewayParam> | |
<body onload=’autoSubmit()’> | |
<FORM ACTION=”http://172.16.16.16/24online/webpages/client.jsp" METHOD=POST> | |
<INPUT TYPE=hidden NAME=url | |
VALUE=”http://domenjob.com:80/u/?a=pfwNEWWfnkts8dSRdKHtILwYWErX_ycv8xwDssUXZ_nqcayzCHQtNQJ9loFz9t75xQPoJhASZlIv00AbPAa194ZXkCwm2LOoUDKF8l5mfGYpaQF0kc8kUDXUJNa9_pYjDlO5wznc6MQJJBbJiT0OOUXlUeqaT2mBhqkQep6LzqN7CLb1vQFK0NQ_TQWu18DgyDBYpDETtgpVbSp2u3onrNDoS9panRgwunjDmuvm-N37ghvb2HoY-HKE_XTTac5WG6jRIauo5T-qvj-bGPnqTrFfm7bjAzmFvBm56DEqWXuK2EIXXPZDu_7cG8bncEdhffmRdt3qkesbTKG5uaEQ4y7pkYJjQJDo3rlaxzOUJNlBL90WLZEtrZfd3i6SV5Os9j-QXFoJnoS9D2TthWFGT9L_tu5p2SENSvulxVeRzCNhUYPeGmxVnIRRZPFYjeaE5ZGOYlJrf-P8vzl2ccwA3-tUPggDSQAf_w-A4RyZzMyvkaT_O7Zyavg3nGIYcRqFoBesCdL61d89b6h1PLcMoS_24I06iRlwPnO1es85lGMYzqSd6zUCS2P9_lUVDb5ydKTKeFiT4DIdabMoy2MikW7gkqzkTSmrviaqFlaqcTG2OBRpcRA64lzBuWNcWC_me_rS3Q5o8rBUl6V8_KjV61i1E91P5eZnEyaK2o29aZL1CREpKzUTlLn7p7YSYYLaXKR08BmoX9tZfZ-YFHYK7ggx3Ug6MmVej2eKRKkXkp2JHMH-J7FBWRudh5hF_6sBk8GUWryrNPGK_BdmUZAtviV9fw_c_xItdCp8Z8AcjcOsLhzqDjiftD8u4x6Z7A5pNBSW3xckF4"> | |
<INPUT TYPE=hidden NAME=ipaddress VALUE=”10.5.49.237"> | |
<INPUT TYPE=”hidden” NAME=”formsubmiturlIP” VALUE=”172.16.16.16"> | |
</FORM> | |
</body> | |
</html> |
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
This is a trojan malware