EndurerOriginal
1Version
A netizen said that no matter what website he opened on his computer, the displayed pages were hxxp: // 218.*1 *. 1*4.170 vip1.htm and vip2.htm.
Hxxp: // 218.*1 *. 1*4.170/vip1.htm content is US-ASCII encoded. Download http://purpleendurer.ys168.com encoding decoding to US-ASCIIProgramThe obtained content contains the Javascript script.CodeThe function is to download the file 611.exe, save it as C:/Microsoft.com, and run it.
File Description: D:/test/611.exe
Attribute: ---
An error occurred while obtaining the file version information!
Creation Time:
Modification time:
Access time:
Size: 25144 bytes, 24.568 KB
MD5: aae6832da-28c36a13713b9aebec6bfc
Kaspersky reportsVirus. win32.autorun. fThe rising report isWorm. win32.delf. B
Hxxp: // 218.*1 *. 1*4.170/vip2.htm content also uses US-ASCII encoding. The decoded content contains Javascript script code, which is more complex than vip1.htm. The downloaded file 611.exeis saved as temp/Microsoft.com and Microsoft. vbs is created for running.