shadowbrokers-exploits/windows/Resources/Ep/Scripts/malfind/getsig6.eps
2017-04-14 11:45:07 +02:00

18 lines
No EOL
467 B
PostScript

string $syspath = GetEnv("SYSPATH");
string $ipmontr = "$syspath\\ipmontr.exe";
string $ipconfhlp = "$syspath\\ipconfhlp.dll";
@record on;
`dir $ipmontr`;
int $size_ipcontr = GetCmdData("size");
`dir $ipconfhlp`;
int $size_ipconfhlp = GetCmdData("size");
@record off;
if (prompt "SIG6 was detected. Do you want to grab the exe and dll? ($ipmontr, size: $size_ipcontr, $ipconfhlp, size: $size_ipconfhlp)") {
`get $ipmontr`;
`get $ipconfhlp`;
}