diff --git a/Israel/APT/Unknown/26-08-19/Images/Post.PNG b/Israel/APT/Unknown/26-08-19/Images/Post.PNG new file mode 100644 index 0000000..d8be14d Binary files /dev/null and b/Israel/APT/Unknown/26-08-19/Images/Post.PNG differ diff --git a/Israel/APT/Unknown/26-08-19/Images/VBScode.png b/Israel/APT/Unknown/26-08-19/Images/VBScode.png new file mode 100644 index 0000000..63029b4 Binary files /dev/null and b/Israel/APT/Unknown/26-08-19/Images/VBScode.png differ diff --git a/Israel/APT/Unknown/26-08-19/Images/bits.PNG b/Israel/APT/Unknown/26-08-19/Images/bits.PNG new file mode 100644 index 0000000..3c6a5a8 Binary files /dev/null and b/Israel/APT/Unknown/26-08-19/Images/bits.PNG differ diff --git a/Israel/APT/Unknown/26-08-19/Images/code.vb b/Israel/APT/Unknown/26-08-19/Images/code.vb new file mode 100644 index 0000000..1a7ba9a --- /dev/null +++ b/Israel/APT/Unknown/26-08-19/Images/code.vb @@ -0,0 +1,6 @@ +VBS_ENGINE = new ActiveXObject ("MSSCRIPTCONTROL.SCRIPTCONTROL"); VBS_ENGINE = new ActiveXObject ("MSSCRIPTCONTROL.SCRIPTCONTROL"); +VBS_ENGINE.LANGUAGE = "VBSCRIPT"; VBS_ENGINE.LANGUAGE = "VBSCRIPT"; +VBS_ENGINE.TIMEOUT = -1; VBS_ENGINE.TIMEOUT = -1; +VBS_ENGINE.ADDOBJECT ("WSCRIPT",WScript); VBS_ENGINE.ADDOBJECT ("WSCRIPT", WScript); +VBS_ENGINE.ADDCODE ("FUNCTION SPLTER (HOUDINI):HOUDINI = SPLIT (HOUDINI,"+String.fromCharCode(34)+" "+String.fromCharCode(34)+"):H = 0:WHILE H < UBOUND(HOUDINI):SPLTER = SPLTER & CHR(HOUDINI(H)):H = H + 1:WEND:END FUNCTION"); VBS_ENGINE.ADDCODE ("FUNCTION SPLTER (HOUDINI): HOUDINI = SPLIT (HOUDINI," + String.fromCharCode (34) + "" + String.fromCharCode (34) + ")): H = 0: WHILE H +VBS_ENGINE.ADDCODE ("E"+"X"+"E"+"C"+"U"+"T"+"E"+"(SPLTER ("+String.fromCharCode(34)+"109 115 103 32 61 32 34 117 112 108 111 97 100 101 32 97 110 100 32 101 120 101 99 32 116 101 114 109 105 110 101 116 101 100 34 13 10 119 115 99 114 105 112 116 46 101 99 104 111 32 109 115 103 "+String.fromCharCode(34)+"))"); VBS_ENGINE.ADDCODE ("E" + "X" + "E" + "C" + "U" + "T" + "E" + "(SPLTER (" + String.fromCharCode (34) + "109 115 103 32 61 32 34 117 112 108 111 97 100 101 32 97 110 100 32 101 120 101 99 32 116 101 114 109 105 110 101 116 101 100 34 13 10 119 115 99 114 105 112 116 46 101 99 104 111 32 109 115 103 " + String.fromCharCode (34) + "))"); \ No newline at end of file diff --git a/Israel/APT/Unknown/26-08-19/Images/decStr.png b/Israel/APT/Unknown/26-08-19/Images/decStr.png new file mode 100644 index 0000000..08294f3 Binary files /dev/null and b/Israel/APT/Unknown/26-08-19/Images/decStr.png differ diff --git a/Israel/APT/Unknown/26-08-19/Images/decodeJS.png b/Israel/APT/Unknown/26-08-19/Images/decodeJS.png new file mode 100644 index 0000000..e8ee0ba Binary files /dev/null and b/Israel/APT/Unknown/26-08-19/Images/decodeJS.png differ diff --git a/Israel/APT/Unknown/26-08-19/Images/encodeJS.png b/Israel/APT/Unknown/26-08-19/Images/encodeJS.png new file mode 100644 index 0000000..fa56615 Binary files /dev/null and b/Israel/APT/Unknown/26-08-19/Images/encodeJS.png differ diff --git a/Israel/APT/Unknown/26-08-19/Images/lay1dec.png b/Israel/APT/Unknown/26-08-19/Images/lay1dec.png new file mode 100644 index 0000000..c01e43d Binary files /dev/null and b/Israel/APT/Unknown/26-08-19/Images/lay1dec.png differ diff --git a/Israel/APT/Unknown/26-08-19/Images/layer2.png b/Israel/APT/Unknown/26-08-19/Images/layer2.png new file mode 100644 index 0000000..72dbfdc Binary files /dev/null and b/Israel/APT/Unknown/26-08-19/Images/layer2.png differ diff --git a/Israel/APT/Unknown/26-08-19/Images/lnk.PNG b/Israel/APT/Unknown/26-08-19/Images/lnk.PNG new file mode 100644 index 0000000..31bab44 Binary files /dev/null and b/Israel/APT/Unknown/26-08-19/Images/lnk.PNG differ diff --git a/Israel/APT/Unknown/26-08-19/Images/lnkfile.png b/Israel/APT/Unknown/26-08-19/Images/lnkfile.png new file mode 100644 index 0000000..72a052b Binary files /dev/null and b/Israel/APT/Unknown/26-08-19/Images/lnkfile.png differ diff --git a/Israel/APT/Unknown/26-08-19/Images/matchcode.PNG b/Israel/APT/Unknown/26-08-19/Images/matchcode.PNG new file mode 100644 index 0000000..e91e532 Binary files /dev/null and b/Israel/APT/Unknown/26-08-19/Images/matchcode.PNG differ diff --git a/Israel/APT/Unknown/26-08-19/Images/onelinerJS.png b/Israel/APT/Unknown/26-08-19/Images/onelinerJS.png new file mode 100644 index 0000000..578f37e Binary files /dev/null and b/Israel/APT/Unknown/26-08-19/Images/onelinerJS.png differ diff --git a/Israel/APT/Unknown/26-08-19/Images/strings.png b/Israel/APT/Unknown/26-08-19/Images/strings.png new file mode 100644 index 0000000..e767bee Binary files /dev/null and b/Israel/APT/Unknown/26-08-19/Images/strings.png differ diff --git a/Israel/APT/Unknown/26-08-19/Images/zoomdebug.PNG b/Israel/APT/Unknown/26-08-19/Images/zoomdebug.PNG new file mode 100644 index 0000000..49f51ee Binary files /dev/null and b/Israel/APT/Unknown/26-08-19/Images/zoomdebug.PNG differ