A forum for reverse engineering, OS internals and malware analysis 

Forum for analysis and discussion about malware.
 #29427  by EP_X0FF
 Sun Oct 16, 2016 10:46 am
ikolor wrote:next..
https://www.virustotal.com/en/file/0c4e ... 464378997/
This is VBS worm Dunihi.

2nd obfuscation stage and actual VBS worm script in attach as txt files. Posts moved.

https://www.virustotal.com/en/file/2959 ... 476614487/
Attachments
vbs script
(12.13 KiB) Downloaded 44 times
stage 2
(105.48 KiB) Downloaded 42 times