瑞星卡卡安全论坛

首页 » 技术交流区 » 恶意网站交流 » 每日网马播报 » 瑞星网站每日安全播报(2010年5月4日)
networkedition - 2010-5-4 15:22:00


引用:
网址均来自瑞星每日安全播报,我们详细分析其中所挂恶意网址,对于已失效的恶意网址就不再分析。



引用:
注:以下分析出的恶意网址均包含有真实网马下载地址,请勿直接下载并运行,以免系统中招。



引用:

1. http://www.ccn.com.cn/(中国消费网)
2. http://www.china-train.net/(中国培训网--中国培训第一交易服务平台)
3. http://www.dragontv.cn/(东方卫视)
4. http://www.amoi.com.cn/(Amoi夏新手机)
5. http://www.feloo.com/(飞龙培训网:资深教育培训网)


用户系统信息:Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1) ; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729; InfoPath.2)
networkedition - 2010-5-4 15:22:00
Log is generated by FreShow.
[wide]http://www.ccn.com.cn/plus/list/10559.html
    [script]http://www.games520.cn/swf.js
        [frame]http://wow.games520.cn/gana.html?统计
            [object]http://121.12.170.183:8081/user/inc/gj.exe
    [script]http://js.users.51.la/3624100.js
networkedition - 2010-5-4 15:22:00
Log is generated by FreShow.
[wide]http://www.china-train.net/downsystem/View.asp?SoftID=5953
    [script]http://12a.inc.0rg.fr/inc.js?tn=iacnnet_pg&cv=0&cid=1157572&csid=302
        [frame]http://gg4.tvb.c4.fr:99/03/03.htm?2
            [object]http://cbb.xsjsb.coyo.eu:88/xz/03.exe
        [frame]http://12a.inc.0rg.fr/
        [frame]http://count25.51yes.com/sa.aspx?id=259340713&refe='+window.parent.location+'&location=http%3A//'+paramsArr[0]+'&color=32x&resolution=1280x1024&returning=1&language=zh-cn&ua=Mozilla/4.0%20%28compatible%3B%20MSIE%206.0%3B%20Windows%20NT%205.1%3B%20SV1%3B%20.NET%20CLR%202.0.50727%3B%20.NET%20CLR%203.0.04506.30%29
    [script]http://12a.inc.0rg.fr/inc.js?tn=iacnnet_pg&cv=0&cid=1157572&csid=302
    [script]http://12a.inc.0rg.fr/inc.js?tn=iacnnet_pg&cv=0&cid=1157572&csid=302
networkedition - 2010-5-4 15:23:00
Log is generated by FreShow.
[wide]http://www.dragontv.cn/html/new/2009/0304/1757.html
    [script]http://121.12.170.183:8081/user/inc/yh/yh.png?永恒
        [frame]http://121.12.170.183:8081/user/inc/yh/ie.html?魔兽
            [object]http://121.12.170.183:8081/user/inc/yh.exe
    [script]http://js.users.51.la/3164776.js
networkedition - 2010-5-4 15:23:00
Log is generated by FreShow.
[wide]http://www.amoi.com.cn/
    [script]http://www.amoi.com.cn/open.js
    [script]http://count20.51yes.com/click.aspx?id=206331118&logo=9
    [script]http://www.amoi.com.cn/js/flow.js
    [script]http://www.amoi.com.cn/index_piao.js
    [script]http://www.amoi.com.cn/shopgg/open.js
    [script]http://c%2Ew%76%675.%63n
    [script]http://c%2Ew%76%675.%63n
    [script]http://%71%2E%6Eje%31%2E%63n
        [frame]http://wingx1.8800.org:97/xo/dk.html
            [script]http://js.tongji.linezing.com/1566155/tongji.js
            [frame]http://wingx1.8800.org:97/xo/0.htm
                [frame]http://wingx1.8800.org:97/xo/../0.htm
                    [object]http://tjdfsd.3322.org:12/.h
                [script]http://wingx1.8800.org:97/xo/\"http://js.tongji.linezing.com/1549551/tongji.js\"
                [script]http://wingx1.8800.org:97/xo/\"http://js.tongji.linezing.com/1549551/tongji.js\"
        [frame]http://so.nje0.cn/so.htm
    [script]http://q%2E%6Ej%652.%63n
networkedition - 2010-5-4 15:23:00
Log is generated by FreShow.
[wide]http://www.feloo.com/shop/show.php?id=3547
    [script]http://s4.cnzz.com/stat.php?id=2125167&web_id=2125167
    [script]http://s4.cnzz.com/stat.php?id=2125167&web_id=2125167
    [frame]http://fanli123.centriohosting.com//1/1.html
    [script]http://s4.cnzz.com/stat.php?id=2125167&web_id=2125167
    [script]http://s4.cnzz.com/stat.php?id=2125167&web_id=2125167
    [frame]http://fanli123.centriohosting.com//1/1.html
        [frame]http://fanli123.centriohosting.com//1/love.html
            [frame]http://fanli123.centriohosting.com//1/n73.htm
                [frame]http://fanli123.centriohosting.com//1/ahf.htm
                    [frame]http://fanli123.centriohosting.com//1/i1.htm
                        [script]http://fanli123.centriohosting.com//1/swfobject.js
                        [frame]http://fanli123.centriohosting.com//1/f10.htm
                    [frame]http://fanli123.centriohosting.com//1/f2.htm
                    [frame]http://fanli123.centriohosting.com//1/i1.htm
            [frame]http://fanli123.centriohosting.com//1/18.htm
                [script]http://fanli123.centriohosting.com//1/party.css
                    [object]http://fanli123.centriohosting.com/2.exe
            [frame]http://fanli123.centriohosting.com//1/19.htm
                [object]http://fanli123.centriohosting.com/2.exe
            [frame]http://fanli123.centriohosting.com//1/n95.htm
                [frame]http://fanli123.centriohosting.com//1/of.htm
        [script]http://s4.cnzz.com/stat.php?id=2126941&web_id=2126941
    [script]http://js.users.51.la/1928680.js
njuptzc - 2010-5-4 21:51:00
Log is generated by FreShow.
[wide]http://www.ccn.com.cn/plus/list/10559.html
    [script]http://www.games520.cn/swf.js
        [frame]http://wow.games520.cn/gana.html?统计
            [object]http://121.12.170.183:8081/user/inc/gj.exe
    [script]http://js.users.51.la/3624100.js
密钥C2
njuptzc - 2010-5-4 21:54:00
Log is generated by FreShow.
[wide]http://www.china-train.net/downsystem/View.asp?SoftID=5953
    [script]http://12b.inc.0rg.fr/inc.js?tn=iacnnet_pg&cv=0&cid=1157572&csid=302
        [frame]http://gg5.tvb.c4.fr:99/03/03.htm?2
            [object]http://cbb.xsjsb.coyo.eu:88/xz/03.exe
        [frame]http://12b.inc.0rg.fr/
        [frame]http://count25.51yes.com/sa.aspx?id=259340713&refe='+window.parent.location+'&location=http%3A//'+paramsArr[0]+'&color=32x&resolution=1280x1024&returning=1&language=zh-cn&ua=Mozilla/4.0%20%28compatible%3B%20MSIE%206.0%3B%20Windows%20NT%205.1%3B%20SV1%3B%20.NET%20CLR%202.0.50727%3B%20.NET%20CLR%203.0.04506.30%29
    [script]http://12b.inc.0rg.fr/inc.js?tn=iacnnet_pg&cv=0&cid=1157572&csid=302
    [script]http://12b.inc.0rg.fr/inc.js?tn=iacnnet_pg&cv=0&cid=1157572&csid=302
密钥BD
njuptzc - 2010-5-4 22:03:00
Log is generated by FreShow.
[wide]http://www.feloo.com/shop/show.php?id=3547
    [script]http://s4.cnzz.com/stat.php?id=2125167&web_id=2125167
    [script]http://s4.cnzz.com/stat.php?id=2125167&web_id=2125167
    [frame]http://fanli123.centriohosting.com//1/1.html
    [script]http://s4.cnzz.com/stat.php?id=2125167&web_id=2125167
    [script]http://s4.cnzz.com/stat.php?id=2125167&web_id=2125167
    [frame]http://fanli123.centriohosting.com//1/1.html
        [frame]http://fanli123.centriohosting.com//1/love.html
            [frame]http://fanli123.centriohosting.com//1/n73.htm
                [frame]http://fanli123.centriohosting.com//1/ahf.htm
                    [frame]http://fanli123.centriohosting.com//1/i1.htm
                    [frame]http://fanli123.centriohosting.com//1/f2.htm
                    [frame]http://fanli123.centriohosting.com//1/i1.htm
            [frame]http://fanli123.centriohosting.com//1/18.htm
                [script]http://fanli123.centriohosting.com//1/party.css
                    [object]http://fanli123.centriohosting.com/2.exe
            [frame]http://fanli123.centriohosting.com//1/19.htm
                [object]http://fanli123.centriohosting.com/2.exe
            [frame]http://fanli123.centriohosting.com//1/n95.htm
            [frame]http://fanli123.centriohosting.com//1/n73.htm
            [frame]http://fanli123.centriohosting.com//1/18.htm
            [frame]http://fanli123.centriohosting.com//1/19.htm
            [frame]http://fanli123.centriohosting.com//1/n95.htm
        [script]http://s4.cnzz.com/stat.php?id=2126941&web_id=2126941
    [script]http://js.users.51.la/1928680.js
第一个解密时候要将AHWM换成%u,密钥是BD,第二个直接解密钥bd
念初 - 2010-5-4 23:46:00
中国消费网那个挂马似曾相识,去掉干扰YY,密钥C2,没记错的话一个多月前解过
1
查看完整版本: 瑞星网站每日安全播报(2010年5月4日)