Reversing the 'yunyun.vbs' virus
Hello I have been bored tired and coding :) as usual. I got a pen drive some time last
year and I realized there was too many 'Thumb.db' files so I
and guess what I saw
Yes that is the yunyun alright coded in Microsoft VBS then I got interested
in the encrypted part of the code, I want to see whats in there.
Te Encryption and decryption routine is using XOR which means its the same
algorithm in and out. Here is the en/decryption routine
As you can see this is very simple so I wrote a little perl script to decrypt
I have made it simpler so anyone can learn from it.
Any ways so with that the mystery was unveiled and then mystery 2
There's a part the needs formatting and this virus/worm is really cool at handling
newlines. Anyway you need to format it then translate it here's the code to format
Ok so uhm that's that, I have more virii/worms but take this for starters
Oh and if anyone has the 'stuxnet' vorm please let me have a binary copy
in tar.gz format.
Next time.
