APT_CyberCriminal_Campagin_.../2016/2016.01.07.rigging-compromise/Cisco Talos Blog_ Rigging compromise - RIG Exploit Kit_files/1Zp01FoOIAZe5GLUcKPqwYF6eHlcVg-fQqL1mfGLki8.js
CyberMonitor 7cd6ba7319 go
2017-02-11 15:00:00 +08:00

1 line
10 KiB
JavaScript

/* Anti-spam. Want to say hello? Contact (base64) Ym90Z3VhcmQtY29udGFjdEBnb29nbGUuY29t */(function(){eval('var c=function(D,W,p){return 2>=arguments.length?Array.prototype.slice.call(D,W):Array.prototype.slice.call(D,W,p)},I=function(D,W,p){if(W=typeof D,"object"==W)if(D){if(D instanceof Array)return"array";if(D instanceof Object)return W;if(p=Object.prototype.toString.call(D),"[object Window]"==p)return"object";if("[object Array]"==p||"number"==typeof D.length&&"undefined"!=typeof D.splice&&"undefined"!=typeof D.propertyIsEnumerable&&!D.propertyIsEnumerable("splice"))return"array";if("[object Function]"==p||"undefined"!=typeof D.call&&"undefined"!=typeof D.propertyIsEnumerable&&!D.propertyIsEnumerable("call"))return"function"}else return"null";else if("function"==W&&"undefined"==typeof D.call)return"object";return W},l=this,u=function(D,W,p,m,C){p=D.split("."),m=l,p[0]in m||!m.execScript||m.execScript("var "+p[0]);for(;p.length&&(C=p.shift());)p.length||void 0===W?m=m[C]?m[C]:m[C]={}:m[C]=W},g,b=(new function(){},function(D){try{d(this,D)}catch(W){h(this,W)}}),V=function(D,W,p,m,C){for(W=[],m=p=0;m<D.length;m++)C=D.charCodeAt(m),128>C?W[p++]=C:(2048>C?W[p++]=C>>6|192:(55296==(C&64512)&&m+1<D.length&&56320==(D.charCodeAt(m+1)&64512)?(C=65536+((C&1023)<<10)+(D.charCodeAt(++m)&1023),W[p++]=C>>18|240,W[p++]=C>>12&63|128):W[p++]=C>>12|224,W[p++]=C>>6&63|128),W[p++]=C&63|128);return W},z=(b.prototype.Ye=function(D,W,p,m){if(3==D.length){for(p=0;3>p;p++)W[p]+=D[p];for(p=0,m=[13,8,13,12,16,5,3,10,15];9>p;p++)W[3](W,p%3,m[p])}},g=b.prototype,function(D,W,p,m){return function(){if(!m||D.j)return P(D,D.Q2,arguments),P(D,D.L,p),N(D,W)}}),E=function(D,W,p,m,C,F,L,e,S){return m=function(){return p()},e=b,C=b.prototype,L=C.O,F=C.s,S=C.Z,p=function(D,Z,R){for(D=m[C.B],R=0,Z=D===W,D=D&&D[C.B];D&&D!=F&&D!=L&&D!=e&&D!=S&&20>R;)R++,D=D[C.B];return p[C.nm+Z+!(!D+(R+3>>3))]},m[C.C]=function(D){p[C.W]=D},m[C.C](D),D=m},O=(g.J=156,function(D,W,p,m){for(m=W-1,p=[];0<=m;m--)p[W-1-m]=D>>8*m&255;return p}),k=(b.prototype.b=function(D,W){if(W=this.o[D],void 0===W)throw this.Z(this.M,0,D),this.A;return W()},b.prototype.dn=function(D,W){W.push(D[0]<<24|D[1]<<16|D[2]<<8|D[3]),W.push(D[4]<<24|D[5]<<16|D[6]<<8|D[7]),W.push(D[8]<<24|D[9]<<16|D[10]<<8|D[11])},function(D,W,p,m,C,F){for(W={},p=n(D),W.g=n(D),W.U=[],m=n(D)-1,C=n(D),F=0;F<m;F++)W.U.push(n(D));for(W.h=D.b(p),W.u=D.b(C);m--;)W.U[m]=D.b(W.U[m]);return W}),d=function(D,W){D.o=[],P(D,D.a,0),P(D,D.R,0),D.j=true,P(D,D.Y,2048),P(D,D.X,"object"==typeof window?window:l),P(D,D.f,0),P(D,D.b8,D),P(D,D.I,0),P(D,D.T,D.T),P(D,D.i,0),P(D,D.K,[]),P(D,D.L,{}),P(D,D.v,[]),P(D,D.m,[]),P(D,D.H,r(4)),P(D,98,function(p,D,C){D=n(p),C=n(p),0!=p.b(D)&&P(p,p.a,p.b(C))}),P(D,84,function(p){U(p,1)}),P(D,3,function(p){H(p,0)}),P(D,113,function(p,D,C){D=n(p),C=n(p),P(p,C,p.b(C)%p.b(D))}),P(D,47,function(p){H(p,4)}),P(D,77,function(p,D,C,W){D=n(p),C=n(p),W=n(p),P(p,W,(p.b(D)in p.b(C))+0)}),P(D,62,function(p,D,C,W,L){D=n(p),C=n(p),W=n(p),D=p.b(D),L=p.b(n(p)),C=p.b(C),W=p.b(W),0!==D&&D.addEventListener(C,z(p,W,L,true),false)}),P(D,20,function(D,m){m=D.b(n(D)),y(D,m)}),P(D,54,function(D,m,C){m=n(D),C=n(D),m=D.b(m),P(D,C,I(m))}),P(D,19,function(D){t(D,4)}),P(D,94,function(D,m){m=k(D),P(D,m.g,m.h.apply(m.u,m.U))}),P(D,88,function(D){U(D,2)}),P(D,79,function(D,m,C){m=n(D),C=n(D),m=D.b(m),P(D,C,m)}),P(D,40,function(D,m,C,W,L,e,S,T,Z,R){if(m=n(D),C=n(D)<<8|n(D),W="",void 0!=D.o[D.P])for(L=D.b(D.P);C--;)e=L[n(D)<<8|n(D)],W+=e;else{for(W=Array(C),L=0;L<C;L++)W[L]=n(D);for(C=[],e=L=0;L<W.length;)S=W[L++],128>S?C[e++]=String.fromCharCode(S):191<S&&224>S?(T=W[L++],C[e++]=String.fromCharCode((S&31)<<6|T&63)):239<S&&365>S?(T=W[L++],Z=W[L++],R=W[L++],S=((S&7)<<18|(T&63)<<12|(Z&63)<<6|R&63)-65536,C[e++]=String.fromCharCode(55296+(S>>10)),C[e++]=String.fromCharCode(56320+(S&1023))):(T=W[L++],Z=W[L++],C[e++]=String.fromCharCode((S&15)<<12|(T&63)<<6|Z&63));W=C.join("")}P(D,m,W)}),P(D,125,function(D,m,W){m=n(D),W=n(D),P(D,W,D.b(W)+D.b(m))}),P(D,74,function(D,m,W,F){m=n(D),W=n(D),F=n(D),P(D,F,D.b(m)<<W)}),P(D,44,function(D,m,W,F){m=n(D),W=n(D),F=n(D),P(D,F,D.b(m)|D.b(W))}),P(D,61,function(D,W,C,F){W=n(D),C=n(D),F=n(D),P(D,F,D.b(W)>>C)}),P(D,23,function(D){H(D,3)}),P(D,49,function(D,W,C,F){W=n(D),C=n(D),F=n(D),D.b(W)>D.b(C)&&P(D,F,D.b(F)+1)}),P(D,2,function(D,W,C,F){W=n(D),C=n(D),F=n(D),D.b(W)==D.b(C)&&P(D,F,D.b(F)+1)}),P(D,122,function(D){t(D,2)}),P(D,108,function(D,W,C,F){if(W=D.c.pop()){for(C=n(D);0<C;C--)F=n(D),W[F]=D.o[F];W[D.K]=D.o[D.K],D.o=W}else P(D,D.a,D.V.length)}),P(D,105,function(D){H(D,7)}),P(D,53,function(D){t(D,1)}),P(D,51,function(D,W,C,F){W=n(D),C=n(D),F=n(D),P(D,F,D.b(W)||D.b(C))}),P(D,36,function(D,W,C,F,L){for(W=n(D),C=n(D)<<8|n(D),F=Array(C),L=0;L<C;L++)F[L]=n(D);P(D,W,F)}),P(D,82,function(D,W,C){W=n(D),C=n(D),P(D,C,function(D){return eval(D)}(D.b(W)))}),P(D,50,function(){}),P(D,60,function(D,W,C){W=n(D),C=n(D),P(D,C,D.b(C)-D.b(W))}),P(D,119,function(D,W,C){W=n(D),C=n(D),P(D,C,D.b(C)*D.b(W))}),P(D,28,function(D,W,C,F,L,e,S){W=k(D),F=W.u,L=W.h,C=W.U,S=C.length,0==S?e=new F[L]:1==S?e=new F[L](C[0]):2==S?e=new F[L](C[0],C[1]):3==S?e=new F[L](C[0],C[1],C[2]):4==S?e=new F[L](C[0],C[1],C[2],C[3]):D.Z(D.N),P(D,W.g,e)}),P(D,76,function(){}),P(D,18,function(D,W,C,F){W=n(D),C=n(D),F=n(D),C=D.b(C),W=D.b(W),P(D,F,W[C])}),P(D,37,function(D,W,C,F){W=n(D),C=n(D),F=n(D),D.b(W)[D.b(C)]=D.b(F)}),P(D,56,function(D,W,C){W=n(D),C=n(D),P(D,C,""+D.b(W))}),P(D,33,function(D,W,C,F){W=n(D),C=n(D),F=D.b(n(D)),C=D.b(C),P(D,W,z(D,C,F))}),P(D,65,function(D,W,C,F,L,e){if(W=n(D),C=n(D),F=n(D),L=n(D),W=D.b(W),C=D.b(C),F=D.b(F),D=D.b(L),"object"==I(W)){for(e in L=[],W)L.push(e);W=L}for(L=0,e=W.length;L<e;L+=F)C(W.slice(L,L+F),D)}),P(D,66,function(){}),P(D,14,function(D){U(D,4)}),f(),W&&"!"==W.charAt(0)?D.D=W:(D.V=window.atob?B(window.atob(W)):null,D.V&&D.V.length?(D.c=[],D.s()):D.Z(D.l))},N=(g.f=213,g.P=172,g.Y=132,function(D,W,p,m){return p=D.b(D.a),D.V&&p<D.V.length?(P(D,D.a,D.V.length),y(D,W)):P(D,D.a,W),m=D.s(),P(D,D.a,p),m}),f=(g.L=150,function(D){for(D=0;64>D;++D);}),v=function(D,W,p,m){return m=function(){return W},p=function(){return m()},p[D.C]=function(D){W=D},p},x=(g.a=220,g.v2=42,b.prototype.Cm=function(D,W,p,m){try{m=D[(W+2)%3],D[W]=D[W]-D[(W+1)%3]-m^(1==W?m<<p:m>>>p)}catch(C){throw C;}},function(D,W,p,m,C,F){for(C=D.b(W),W=W==D.H?function(W,p,m,F){if(p=C.length,m=p-4>>3,C.Km!=m){C.Km=m,m=(m<<3)-4,F=[0,0,0,D.b(D.i)];try{C.Zx=M(q(C,m),q(C,m+4),F)}catch(Z){throw Z;}}C.push(C.Zx[p&7]^W)}:function(D){C.push(D)},m&&W(m&255),F=0,m=p.length;F<m;F++)W(p[F])}),P=function(D,W,p){if(W==D.a||W==D.R)if(D.o[W])D.o[W][D.C](p);else D.o[W]=v(D,p);else if(W!=D.v&&W!=D.H&&W!=D.K||!D.o[W])D.o[W]=E(p,D.b);W==D.f&&(D.F=void 0,P(D,D.a,D.b(D.a)+4))},q=function(D,W){return D[W]<<24|D[W+1]<<16|D[W+2]<<8|D[W+3]},h=(g.l=17,g.v=166,g.C="toString",g.w=33,g.V2=10,g.Q2=197,function(D,W){D.D=("E:"+W.message+":"+W.stack).slice(0,2048)}),r=function(D,W){for(W=Array(D);D--;)W[D]=255*Math.random()|0;return W},y=function(D,W){D.c.push(D.o.slice()),D.o[D.a]=void 0,P(D,D.a,W)},Y=(b.prototype.Z=function(D,W,p,m){m=this.b(this.R),D=[D,m>>8&255,m&255],void 0!=p&&D.push(p),0==this.b(this.K).length&&(this.o[this.K]=void 0,P(this,this.K,D)),p="",W&&(W.message&&(p+=W.message),W.stack&&(p+=":"+W.stack)),W=this.b(this.Y),3<W&&(p=p.slice(0,W-3),W-=p.length+3,p=V(p.replace(/\\r\\n/g,"\\n")),x(this,this.H,O(p.length,2).concat(p),this.oL)),P(this,this.Y,W)},g.R=188,g.I=179,g.X=241,g.N=22,g.oL=12,g.A={},g.W=36,g.H=135,g.K=207,g.nm=34,g.aL=15,function(D,W,p,m){if(8192>=D.length)return String.fromCharCode.apply(null,D);for(p=0,W="";p<D.length;p+=8192)m=c(D,p,p+8192),W+=String.fromCharCode.apply(null,m);return W}),n=(g.M=30,g.T=251,g.b8=209,g.i=160,function(D,W,p){if(W=D.b(D.a),!(W in D.V))throw D.Z(D.S),D.A;return void 0==D.F&&(D.F=q(D.V,W-4),D.$=void 0),D.$!=W>>3&&(D.$=W>>3,p=[0,0,0,D.b(D.f)],D.ep=M(D.F,D.$,p)),P(D,D.a,W+1),D.V[W]^D.ep[W%8]}),M=(g.m=151,g.B="caller",function(D,W,p,m){try{for(m=0;84941944608!=m;)D+=(W<<4^W>>>5)+W^m+p[m&3],m+=2654435769,W+=(D<<4^D>>>5)+D^m+p[m>>>11&3];return[D>>>24,D>>16&255,D>>8&255,D&255,W>>>24,W>>16&255,W>>8&255,W&255]}catch(C){throw C;}}),B=(g.S=31,g.G=21,g=b.prototype,function(D,W,p,m,C){for(W=[],m=p=0;m<D.length;m++){for(C=D.charCodeAt(m);255<C;)W[p++]=C&255,C>>=8;W[p++]=C}return W}),U=(g.TT=function(D){return(D=window.performance)&&D.now?function(){return D.now()|0}:function(){return+new Date}}(),function(D,W,p,m){for(p=n(D),m=0;0<W;W--)m=m<<8|n(D);P(D,p,m)}),t=(g.O=function(D,W,p,m,C,F,L,e,S,T){if(this.D)return this.D;try{if(this.j=false,W=this.b(this.v).length,p=this.b(this.H).length,m=this.b(this.Y),this.o[this.J]&&N(this,this.b(this.J)),C=this.b(this.K),0<C.length&&x(this,this.v,O(C.length,2).concat(C),this.aL),F=this.b(this.I)&511,F-=this.b(this.v).length+5,L=this.b(this.H),4<L.length&&(F-=L.length+3),0<F&&x(this,this.v,O(F,2).concat(r(F)),this.V2),4<L.length&&x(this,this.v,O(L.length,2).concat(L),this.v2),e=r(2).concat(this.b(this.v)),e[1]=e[0]^3,S=window.btoa?window.btoa(Y(e)).replace(/\\+/g,"-").replace(/\\//g,"_").replace(/=/g,""):void 0,S)S="!"+S;else for(C=0,S="";C<e.length;C++)T=e[C][this.C](16),1==T.length&&(T="0"+T),S+=T;this.b(this.v).length=W,this.b(this.H).length=p,P(this,this.Y,m),D=S,this.j=true}catch(Z){h(this,Z),D=this.D}return D},function(D,W,p,m){p=n(D),m=n(D),x(D,m,O(D.b(p),W))}),H=(g.s=function(D,W,p,m,C,F){try{for(m=0,p=void 0,W=5001,D=this.V.length;--W&&(m=this.b(this.a))<D;)try{P(this,this.R,m),C=n(this),(p=this.b(C))&&p.call?p(this):this.Z(this.G,0,C)}catch(L){L!=this.A&&(F=this.b(this.T),F!=this.T?(P(this,F,L),P(this,this.T,this.T)):this.Z(this.N,L))}W||this.Z(this.w)}catch(L){try{this.Z(this.N,L)}catch(e){h(this,e)}}return this.b(this.L)},function(D,W,p,m,C,F){m=W&3,p=W&4,C=n(D),F=n(D),C=D.b(C),p&&(C=V((""+C).replace(/\\r\\n/g,"\\n"))),m&&x(D,F,O(C.length,2)),x(D,F,C)});g.H2=function(D,W,p){return W^=W<<13,W^=W>>17,(W=(W^W<<5)&p)||(W=1),D^W},g.tn=function(D,W){return W=this.O(),D&&D(W),W},g.RL=function(D,W,p,m,C,F){for(p=[],F=m=0;F<D.length;F++)for(C=C<<W|D[F],m+=W;7<m;)m-=8,p.push(C>>m&255);return p},g.UL=function(D,W,p,m,C){for(C=m=0;C<D.length;C++)m+=D.charCodeAt(C),m+=m<<10,m^=m>>6;return m+=m<<3,m^=m>>11,D=m+(m<<15)>>>0,m=new Number(D&(1<<W)-1),m[0]=(D>>>W)%p,m};try{window.addEventListener("unload",function(){},false)}catch(D){}u("botguard.bg",b),u("botguard.bg.prototype.invoke",b.prototype.tn);')})()