Author:Mir-lin@126.com (chulin)
Information provision:Small G(Greysign)
Trojan page:Http://download.it168.com/08/0801/86013/86013_3.shtml
Trojan:Http://www4.it168.com/bottom/newfoot.jsEmbedded framework code.
The analysis report is as follows:
Log is generated by FreShow.
[Wide] http://download.it168.com/08/0801/86013/86013_3.shtml
[Script] http://download.it168.com/2007include/ntes.js
[Script] http://publish.it168.com/2006newhead/search.js
[Script] http://head.it168.com/22/count26.js
[Script] http://software.it168.com/include/searchall.js
[Script] http://download.it168.com/txt/default_menu_softtype.js
[Script] http://download.it168.com/js/download_dcs_tag.js
[Script] http://software.it168.com/txt/0801_new_top10.js
[Script] http://download.it168.com/include/lookpace.js
[Frame] http://download.it168.com/vote.asp? Id = 86013
[Frame] http://download.it168.com/iframe.asp? Id = 86013
[Is hanging here] http://www4.it168.com/bottom/newfoot.js
[HTML in newfoot. js] http://software.it168.com/downloadbottom/downloadbottom3.htm
Embedding framework with balance.htm] http://www.cnsw.org/blank.htm
[Balnk.htm implant] http://k.j8j8.biz/103/
[Balnk.htm implant] http://k.j8j8.biz/103/
This is hung like downloadbootom3.htm] http://software.it168.com/downloadbottom/downloadbottom4.htm
[Script] http://adshow.it168.com/AdFile/Js/advs_home_v1.js? Rnd= 1230
[Script] http://adshow.it168.com/adfile/js/advtmp_v1.js
[Script] http://download.it168.com/08/0801/86013/ "+ actionurl +"
[Frame] http://adshow.it168.com/count/files/js8.asp
Http://k.j8j8.biz/103/Inside
MS06-014 vulnerability, downloadHttp://vvv.123sky.biz/103/103.exe
Download Real vulnerabilities,Http://vvv.123sky.biz/103/103.exe
There is also an lz.htm for the r.htmand 14.htmto be transferred to another region.
Lz.htm is a public vulnerability, and the download is alsoHttp://vvv.123sky.biz/103/103.exe
However, the HOSTS of the main domain names have been blocked, so the use of the HOSTS anti-Black files on this site will not be threatened.
The missing www.cnsw.org is immediately blocked! Please pay attention to the update of the HOSTS anti-Black file...