瑞星卡卡安全论坛

首页 » 技术交流区 » 恶意网站交流 » http://www.syjn.gov.cn/(沈阳市节能信息网)
networkedition - 2010-3-16 14:30:00
Log generated by networkedition use mdecoder 0.50
[root]http://www.syjn.gov.cn/html/wow/2078.html
    [script]http://js.users.51.la/3329381.js
    [script]http://club.9istyle.com/wap/include/main/wow.jpg?IZWNGB
        [iframe]http://club.9istyle.com/wap/include/wov1/ie.html?爱aaa123
            [exe]http://club.9istyle.com/wap/include/2828.exe
    [exe]http://club.9istyle.com/wap/include/common.css
    [exe]http://club.9istyle.com/wap/include/wow.exe
    [exe]http://club.9istyle.com/wap/include/wow.exe
    [exe]http://club.9istyle.com/wap/include/wow.exe
    [exe]http://club.9istyle.com/wap/include/wow.exe

用户系统信息:Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1) ; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729; InfoPath.2)
小傻大呆 - 2010-3-16 18:13:00
Log is generated by FreShow.
[wide]http://www.syjn.gov.cn/html/wow/2078.html
    [script]http://js.users.51.la/3329381.js
    [script]http://club.9istyle.com/wap/include/main/wow.jpg?IZWNGB
        [frame]http://club.9istyle.com/wap/include/main/http:\/\/club.9istyle.com\/wap\/include\/wov1\/ie.html?爱aaa123
            [object]http://club.9istyle.com/wap/include/2828.exe
念初 - 2010-3-16 19:14:00
关于:hxxp://www.wyx.xcvtc.edu.cn/解密的日志(全体输出 -  3):

Level  1>http://club.9istyle.com/wap/include/main/wow.jpg?IZWNGB
Level  2>http://club.9istyle.com/wap/include/wov1/ie.html?爱aaa123
Level  4>http://club.9istyle.com/wap/include/2828.exe

日志由 Redoce2.0第88次修正版于 2010-3-16 19:13:49 生成。

C2密钥
njuptzc - 2010-3-17 21:49:00
Log is generated by FreShow.
[wide]http://www.syjn.gov.cn/html/wow/2078.html
    [script]http://js.users.51.la/3329381.js
    [script]http://club.9istyle.com/wap/include/main/wow.jpg?IZWNGB
        [frame]http://club.9istyle.com/wap/include/wovv/ie.html?爱aaa123
            [object]http://club.9istyle.com/wap/include/2828.exe
1
查看完整版本: http://www.syjn.gov.cn/(沈阳市节能信息网)