I found this existing python script in the library that would really assist me with centralizing and executing bat file scripts to our end points.
The script downloads a .bat file off our our google drive public shared file link, downloads it to the specified folder and the executes it.
The link for the original article is below:
https://scripts.itarian.com/frontend/web/topic/script-to-download-and-execute-the-bat-file
However i have configured the procedure and run it, it does the following: Downloads the bat file to the specified folder but then modifies the bat file and infects a bunch of garbage into the bat file and thats it…
I am looking for it to download the batch file to the specified folder and then execute the bat file. My target end point is a windows server 2019 OS. The log file of the procedure shows the following:
C:\ProgramData\CSAutoMaintenance\CSTestBat\TestBat.bat C:\ProgramData\CSAutoMaintenance\CSTestBat\TestBat.bat Excuting Bat File --------------------------- C:\Program Files (x86)\COMODO\Comodo ITSM><!DOCTYPE html><html><head><meta name=“google” content=“notranslate”><meta http-equiv=“X-UA-Compatible” content=“IE=edge;”><style>@font-face{font-family:‘Roboto’;font-style:italic;font-weight:400;src:local(‘Roboto Italic’),local(‘Roboto-Italic’),url(//fonts.gstatic.com/s/roboto/v18/KFOkCnqEu92Fr1Mu51xIIzc.ttf)format(‘truetype’);}@font-face{font-family:‘Roboto’;font-style:normal;font-weight:300;src:local(‘Roboto Light’),local(‘Roboto-Light’),url(//fonts.gstatic.com/s/roboto/v18/KFOlCnqEu92Fr1MmSU5fBBc9.ttf)format(‘truetype’);}@font-face{font-family:‘Roboto’;font-style:normal;font-weight:400;src:local(‘Roboto Regular’),local(‘Roboto-Regular’),url(//fonts.gstatic.com/s/roboto/v18/KFOmCnqEu92Fr1Mu4mxP.ttf)format(‘truetype’);}@font-face{font-family:‘Roboto’;font-style:normal;font-weight:700;src:local(‘Roboto Bold’),local(‘Roboto-Bold’),url(//fonts.gstatic.com/s/roboto/v18/KFOlCnqEu92Fr1MmWUlfBBc9.ttf)format(‘truetype’);}</style><meta name=“referrer” content=“origin”><title>Infinitt_PACS_VR_SVR_Log_File_Recycling.bat - Google Drive</title><meta property=“og:title” content=“Infinitt_PACS_VR_SVR_Log_File_Recycling.bat”><meta property=“og:type” content=“article”><meta property=“og:site_name” content=“Google Docs”><meta property=“og:url” content=“https://drive.google.com/file/d/1PGtcEiilwobJ0elwCb0B1t_RK3PiaREQ/view?usp=drive_open&usp=embed_facebook”><link rel=“shortcut icon” href=“https://ssl.gstatic.com/docs/doclist/images/icon_14_generic_favicon.ico”><link rel=“stylesheet” href=“https://fonts.googleapis.com/css?family=Google+Sans:300,400,500,700”><link rel=“stylesheet” href=“https://www.gstatic.com//apps-fileview//ss/k=apps-fileview.v.8uYZcMJXS1k.L.X.O/d=0/ct=zgms/rs=AO0039vzgTbwksC4aREKTz3EpkiflBsJ1w”><script>_docs_flag_initialData={“docs-ails”:“docs_cold”,“docs-fwds”:“docs_sdf”,“docs-crs”:“docs_crs_nfd”,“docs-shdn”:0,“docs-tfh”:"",“info_params”:{},“docos-eddmh”:false,“docs-edcsp”:true,“docs-eohmo”:false,“uls”:"",“docs-enpf”:false,“docs-ce”:false,“docs-api-keys”:{},“buildLabel”:“texmex_2020.18-Thu_RC01”,“docs-show_debug_info”:false,“ondlburl”:“https://docs.google.com”,“drive_url”:“https://drive.google.com”,“app_url”:“https://drive.google.com/file/",“docs-mid”:2048,“docs-eicd”:false,“docs-icdmt”:[],“docs-sup”:"/file",“docs-seu”:“https://drive.google.com/file/d/1PGtcEiilwobJ0elwCb0B1t_RK3PiaREQ/edit”,“docs-crp”:"/file/d/1PGtcEiilwobJ0elwCb0B1t_RK3PiaREQ/view",“docs-crq”:“usp\u003ddrive_open”,“docs-ecvca”:true,“docs-uptc”:[“lsrp”,“ca”,“sh”,“noreplica”,“ouid”,“dl”,“hi”,“popr”,“sdsid”,“usp”,“urp”,“utm_source”,“utm_medium”,“utm_campaign”,“utm_term”,“utm_content”,“aaac”,“sle”],“docs-doddn”:"Continuum Systems”,“docs-dodn”:“continuum.za.com”,“docs-uddn”:"",“docs-udn”:"",“docs-cwsd”:"",“docs-gsmd”:"",“docs-epil”:false,“docs-esmp”:false,“docs-al”:[0,0,0,1,0],“docs-deculmu”:“https://support.google.com/drive?p\u003dsaving_errors",“docs-deuoflmu”:"",“docs-debulmu”:"",“docs-deodlmu”:"",“docs-ndt”:"Untitled Texmex”,“docs-prn”:"",“docs-emtbi”:false,“docs-as”:"",“docs-etdimo”:false,“docs-mdck”:"",“docs-etiff”:false,“docs-mriim”:1800000,“docs-eccbs”:false,“docos-sosj”:false,“docs-rlmp”:false,“docs-mmpt”:15000,“docs-erd”:false,“docs-erfar”:false,“docs-ensb”:false,“docs-ddts”:false,“docs-uootuns”:false,“docs-amawso”:false,“docs-mdso”:false,“docs-ofmpp”:false,“docs-anlpfdo”:false,“docs-phe”:"",“docs-pid”:"",“docs-ebbouf”:false,“docs-efs”:false,“docs-ricocpb”:false,“docs-eali”:false,“docs-etauihm”:false,“docs-eiap”:false,“docs-egs”:false,“docs-eeott”:false,“docs-eics”:false,“docos-plss”:false,“docs-hft”:"",“docs-edsi”:false,“docs-ececs”:false,“docs-eslars”:false,“docs-edp”:false,“docs-edlo”:false,“docs-eem”:false,“docs-offline-enccpd”:false,“docs-edsl”:false,“docs-efsii”:false,“docs-elcfd”:false,“docs-ejtlr”:false,“docs-edmitm”:false,“docs-enjec”:false,“docs-ehdr”:false,“docs-egmid”:false,“docs-efmsh”:false,“docs-elri”:true,“ecid”:true,“docs-eir”:false,“docs-edll”:false,“server_time_ms”:1589756305833,“gaia_session_id”:"",“app-bc”:"#d1d1d1",“enable_iframed_embed_api”:true,“docs-fut”:“https://drive.google.com#folders/{folderId}",“docs-isb”:false,“docs-enct”:false,“docs-agdc”:false,“docs-anddc”:false,“docs-adndldc”:false,“docs-efts”:false,“docs-cn”:"",“docs-dpftr”:false,“docs-dwc”:false,“docs-depquafr”:false,“docs-elsr”:false,“docs-elmc”:false,“docs-frbanmc”:false,“docs-rldce”:false,“docs-sasic”:false,“docs-dom”:false,“docs-ebidu”:false,“docs-edamc”:false,“docs-edomic”:false,“docs-eddm”:false,“docs-edpme”:"",“docs-fwd”:false,“docs-elds”:false,“docs-mcssa”:false,“docs-eph”:false,“docs-epat”:false,“docs-eppd”:false,“docs-essph”:false,“docs-tdd”:false,“docs-mib”:5242880,“docs-mip”:6250000,“docs-rsc”:"",“docs-ssi”:false,“docs-uoci”:"",“docs-gth”:"",“docs-po”:“https://drive.google.com”,“docs-to”:“https://drive.google.com”,“projector_view_url”:“https://drive.google.com/file/d/1PGtcEiilwobJ0elwCb0B1t_RK3PiaREQ/view?usp\u003ddocs_web”,“docs-seso”:false,“docs-eastdfm”:false,“docs-eastd”:false,“docs-eoes”:false,“docs-eoespr”:false,“docs-dpiuf”:false,“opendv”:false,“onePickImportDocumentUrl”:"",“opmbs”:5242880,“opmpd”:2500,“opbu”:“https://docs.google.com/picker”,“opru”:“https://drive.google.com/relay.html”,“opdu”:false,“opccp”:false,“ophi”:“texmex”,“opst”:“000770F2032503033543787FBFC5DC56B0F1F0E8E44B1F69F5::1589756305836”,“opuci”:"",“docs-eopiiv2”:true,“docs-dm”:“application/x-msdos-program”,“docs-ndsom”:[],“docs-sdsom”:[],“docs-lfui”:false,“jobset”:“prod”,“docs-etbws”:false,“docs-ebpi”:false,“docs-eebvt”:false,“docs-eebvf”:false,“docs-emsib”:false,“docs-eiib”:false,“docs-se”:false,“docs-egf”:false,“docs-surfb”:false,“docs-uptuf”:true,“docs-eodp”:false,“docs-odolh”:false,“docs-odpu”:[null,null,null,"//drive.google.com/odp/embed?authuser\u003d"],“docs-spdy”:false,“xdbcfAllowHostNamePrefix”:true,“xdbcfAllowXpc”:true,“docs-iror”:true,“promo_url”:"",“promo_second_url”:"",“promo_title”:"",“promo_title_prefix”:"",“promo_content_html”:"",“promo_more_element_text”:"",“promo_second_more_element_text”:"",“promo_element_id”:"",“promo_orientation”:1,“promo_arrow_alignment”:0,“promo_show_on_click”:false,“promo_hide_arrow”:false,“promo_show_on_load”:false,“promo_mark_dismissed_on_show”:false,“promo_use_global_preference”:false,“promo_use_material_styling”:false,“promo_close_button_text”:"",“promo_icon_url”:"",“promo_action_id”:"",“promo_impression_id”:0,“promo_is_contextual”:false,“docs-ccwt”:0,“docs-eccw”:false,“docs-epcc”:false,“docs_abuse_link”:“https://drive.google.com/abuse?id\u003d1PGtcEiilwobJ0elwCb0B1t_RK3PiaREQ”,“docs-msoil”:“docs_spanner”,“docs-gsoil”:“docs_gsabs”,"docs-fsd”:false}; _docs_flag_cek= null ;</script><script>window.viewerData = {config: {‘id’: ‘1PGtcEiilwobJ0elwCb0B1t_RK3PiaREQ’, ‘title’: ‘Infinitt_PACS_VR_SVR_Log_File_Recycling.bat’, ‘isItemTrashed’: false ,‘enableEmbedDialog’: true,‘projectorFeedbackId’: ‘99950’, ‘projectorFeedbackBucket’: ‘viewer-web’,}, configJson: ["",null,null,null,null,1,null,"",null,1,1,[1,null,null,“AIzaSyDVQw45DwoYh632gvsP5vPDqEKvb-Ywnb8”,0,null,1,null,null,“AIzaSyC1eQ1xj69IdTMeii5r7brs3R90eck-m7k”,0,"/drive/v2beta",0,0,1,[0,0,0]
After executing the Bat file it looks like something goes wrong in Comodo…and this output is then injected into my bat file that lands on my end point.
Please can you advise if there is a patch that is needed?
Thanks,
Herbert