networkedition - 2012-9-14 13:51:00
网址均来自瑞星每日安全播报,我们详细分析其中所挂恶意网址,对于已失效的恶意网址就不再分析。
注:以下分析出的恶意网址均包含有真实网马下载地址,请勿直接下载并运行,以免系统中招。
1. http://dpc.zhangpu.gov.cn/(漳浦县发展和改革局)
2. http://youth.dlmu.edu.cn/(大连海事大学)
3. http://www.zjmjzz.com/(马剑镇中校园网)
用户系统信息:Mozilla/5.0 (Windows NT 5.1) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/14.0.802.30 Safari/535.1 SE 2.X MetaSr 1.0
networkedition - 2012-9-14 13:52:00
Log generated by networkedition use mdecoder 0.67
[root]http://dpc.zhangpu.gov.cn/news/look_news.asp?id=1524(Exploit.Ms06014.c)(Oh,my god!)
[script]http://dpc.zhangpu.gov.cn/news/../images/view.js
[flash]http://dpc.zhangpu.gov.cn/news/../images/flashtop.swf
[virus]http://183.60.157.72/down_group285/M00/00/62/tzydSE8_ju8AAAAAAAueAG-SPr40121347/Dlaupass.exe?k=BM26Ja5-1TCzk3DhAOOiOA&t=1329579897&u=125.108.40.87@2643602@dpffrtvb&file=Dlaupass.exe
networkedition - 2012-9-14 13:52:00
Log generated by networkedition use mdecoder 0.67
[root]http://youth.dlmu.edu.cn/v6/f/1/1/new_lzg.htm
[virus]http://youth.dlmu.edu.cn/v6/f/1/1/lzg.exe
networkedition - 2012-9-14 13:53:00
Log generated by anonymous use mdecoder 0.67
[root]http://www.zjmjzz.com/html/zyxz/jyjx/914963.html(多媒体教学网络系统LanStar 7.0旗舰版 -教育教学)
[iframe]http://www.zjmjzz.com/user/userlogin.asp?action=Top
[script]http://fld.AtHerSite.com/b.js?google=5x232
[script]http://fmf.AtHerSite.com/b.js?google=6x013
[script]http://vmr.Jkub.com:66/3/mray.htm
[iframe]http://vmr.Jkub.com:66/3/360yb.htm
[virus]http://vmr.Jkub.com:66/o/dt.exe
[script]http://js.tongji.linezing.com/2800225/tongji.js
[script]http://tongji.linezing.com/clickmap/load_clickmap.html?r=+token+
[script]http://js.tongji.linezing.com/2800225//clickcollect.js
[script]http://fvc.AtHerSite.com/b.js?google=8x171
[script]http://fwm.FindHere.org/b.js?google=8x281
[script]http://fyk.FindHere.org/b.js?google=9x133
[script]http://www.zjmjzz.com/KS_Inc/language.js
[flash]http://www.zjmjzz.com/UpFiles/logo.swf
[script]http://www.zjmjzz.com/Html/JS/S_DownLoad.js
[script]http://www.zjmjzz.com/KS_Inc/time/3.js
[script]http://www.zjmjzz.com/ks_inc/ajax.js
© 2000 - 2024 Rising Corp. Ltd.