data:image/s3,"s3://crabby-images/72d1d/72d1da790cbf3f66406eaa897ca7cec12f513574" alt="Osk exe source code"
data:image/s3,"s3://crabby-images/132d6/132d692f7edec8da83739afc26ccbcc59484e8f0" alt="osk exe source code osk exe source code"
Sigma detected: MSHTA Spawning Windows ShellĪuthor: Michael Haag: Data: Comm and: 'C:\W indows\Sys tem32\cmd. exe' /c bc dedit /set recoverye nabled No, ProcessId : 1984
data:image/s3,"s3://crabby-images/543c2/543c2c9b8b20d13070d96090e3f1190fce92b24b" alt="osk exe source code osk exe source code"
(collection): Data: Comm and: 'C:\W indows\Sys tem32\cmd.
OSK EXE SOURCE CODE PRO
Shell').Re gRead('HKC U\\Softwar e\\AMMOA\\ DZNUG')) c lose() ', ParentImag e: C:\Wind ows\SysWOW 64\mshta.e xe, Parent ProcessId: 4524, Pro cessComman dLine: 'C: \Windows\S ystem32\cm d.exe' /c wmic SHADO WCOPY DELE TE, Proces sId: 4972Īuthor: Florian Roth (rule), Tom U. exe, NewPr ocessName: C:\Window s\SysWOW64 \cmd.exe, OriginalFi leName: C: \Windows\S ysWOW64\cm d.exe, Par entCommand Line: msht a.exe 'jav ascript:ev al(new Act iveXObject ('WScript. exe' /c wm ic SHADOWC OPY DELETE, CommandL ine|base64 offset|con tains:, I mage: C:\W indows\Sys WOW64\cmd.
data:image/s3,"s3://crabby-images/40c79/40c79d868f90fb3d1295743278d5fa2b7f4aad9e" alt="osk exe source code osk exe source code"
exe' /c wm ic SHADOWC OPY DELETE, CommandL ine: 'C:\W indows\Sys tem32\cmd. Sigma detected: Delete shadow copy via WMICĪuthor: Joe Security: Data: Comm and: 'C:\W indows\Sys tem32\cmd. ( ЭТО НЕ РАБОТАЕТ ) Public Declare Function FindWindow Lib "user32" Alias "FindWindowA" _ (ByVal lpClassName As String, ByVal lpWindowName As String) As Long Public Declare Function SetWindowPos Lib "user32" _ (ByVal hwnd As Long, ByVal hWndInsertAfter As Long, ByVal x As Long, _ ByVal y As Long, ByVal cx As Long, ByVal cy As Long, ByVal wFlags As Long) As Long Public Const SWP_NOSIZE = &H1 Public Const HWND_TOPMOST = -1 Sub Sample() Dim Ret As Long, retval As Long Dim Shex As Object Set Shex = CreateObject("Shell.Application") Shex.Open ("C:\Windows\System32\osk.exe") Wait 1 Ret = FindWindow("OSKMainClass", "On-Screen Keyboard") If Ret 0 Then 'Msgbox "On-Screen Keyboard Window Found" retval = SetWindowPos(Ret, HWND_TOPMOST, 0, 0, 0, 0, SWP_NOSIZE) DoEvents If retval = False Then MsgBox "Unable to move Window" End If End Sub Private Sub Wait(ByVal nSec As Long) nSec = nSec + Timer While nSec > Timer DoEvents Wend End Sub
data:image/s3,"s3://crabby-images/72d1d/72d1da790cbf3f66406eaa897ca7cec12f513574" alt="Osk exe source code"