Trojan analysis-malicious code implanted in the IT168 download channel. It seems violent ..

Source: Internet
Author: User

Author:Mir-lin@126.com (chulin)

Information provision:Small G(Greysign)
Trojan page:Http://download.it168.com/08/0801/86013/86013_3.shtml
Trojan:Http://www4.it168.com/bottom/newfoot.jsEmbedded framework code.
The analysis report is as follows:


Log is generated by FreShow.
[Wide] http://download.it168.com/08/0801/86013/86013_3.shtml
[Script] http://download.it168.com/2007include/ntes.js
[Script] http://publish.it168.com/2006newhead/search.js
[Script] http://head.it168.com/22/count26.js
[Script] http://software.it168.com/include/searchall.js
[Script] http://download.it168.com/txt/default_menu_softtype.js
[Script] http://download.it168.com/js/download_dcs_tag.js
[Script] http://software.it168.com/txt/0801_new_top10.js
[Script] http://download.it168.com/include/lookpace.js
[Frame] http://download.it168.com/vote.asp? Id = 86013
[Frame] http://download.it168.com/iframe.asp? Id = 86013
[Is hanging here] http://www4.it168.com/bottom/newfoot.js
[HTML in newfoot. js] http://software.it168.com/downloadbottom/downloadbottom3.htm



Embedding framework with balance.htm] http://www.cnsw.org/blank.htm
[Balnk.htm implant] http://k.j8j8.biz/103/
[Balnk.htm implant] http://k.j8j8.biz/103/
This is hung like downloadbootom3.htm] http://software.it168.com/downloadbottom/downloadbottom4.htm
[Script] http://adshow.it168.com/AdFile/Js/advs_home_v1.js? Rnd= 1230
[Script] http://adshow.it168.com/adfile/js/advtmp_v1.js
[Script] http://download.it168.com/08/0801/86013/ "+ actionurl +"
[Frame] http://adshow.it168.com/count/files/js8.asp



Http://k.j8j8.biz/103/Inside


MS06-014 vulnerability, downloadHttp://vvv.123sky.biz/103/103.exe


Download Real vulnerabilities,Http://vvv.123sky.biz/103/103.exe


There is also an lz.htm for the r.htmand 14.htmto be transferred to another region.

Lz.htm is a public vulnerability, and the download is alsoHttp://vvv.123sky.biz/103/103.exe

However, the HOSTS of the main domain names have been blocked, so the use of the HOSTS anti-Black files on this site will not be threatened.

The missing www.cnsw.org is immediately blocked! Please pay attention to the update of the HOSTS anti-Black file...

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.