盜取QQ密碼的Trojan.PSW.QQPass.rky正通過QQ資訊中的網址傳播

來源:互聯網
上載者:User

endurer 原創

2007-01-29 第1

QQ收到如下資訊:
/-------
hxxp://www.a**hw**l**q*t.com/**1*23**.html 這裡有我的照片大家來看下順便給個評價謝謝了
-------/

開啟該網頁,沒有內容,但網頁中的VBScript代碼會利用 Microsoft.XMLHTTP 和 scrīpting.FileSystemObject 下載檔案 123.exe,儲存為 %temp%/svchost.exe,然後調用自訂函數tcsafe1exe(m5,X9)。

自訂函數tcsafe1exe()的功能是建立Shell.Application 對象Xe,利用 Xe 的 ShellExecute 方法 來運行 %temp%/svchost.exe。

這點與

劫持瀏覽器並彈廣告的Trojan.Clicker.VB.ajn正通過QQ資訊中的網址傳播
http://endurer.bokee.com/6074696.html
http://www.blogcn.com/user50/endurer/blog/51870395.html
http://blog.csdn.net/Purpleendurer/archive/2007/01/28/1496462.aspx

中的VBScript指令碼程式相似。

/-----
檔案說明符 : D:/test/123.exe
屬性 : A---
擷取檔案版本資訊大小失敗!
建立時間 : 2007-1-28 22:51:10
修改時間 : 2007-1-28 22:51:24
訪問時間 : 2007-1-28 0:0:0
大小 : 43490 位元組 42.482 KB
MD5 : 25c796d526b18a2e244b93bb6074f23a
-----/
Kaspersky報為:Trojan-PSW.Win32.QQPass.qg
瑞星報為:Trojan.PSW.QQPass.rky 

Scanned file:   123.exe - Infected

123.exe - infected by Trojan-PSW.Win32.QQPass.qg

Statistics:
Known viruses: 262925 Updated: 29-01-2007
File size (Kb): 43 Virus bodies: 1
Files: 1 Warnings: 0
Archives: 0 Suspicious: 0

昨晚這兩個殺軟都沒反應,想不到今天都報了~

聯繫我們

該頁面正文內容均來源於網絡整理,並不代表阿里雲官方的觀點,該頁面所提到的產品和服務也與阿里云無關,如果該頁面內容對您造成了困擾,歡迎寫郵件給我們,收到郵件我們將在5個工作日內處理。

如果您發現本社區中有涉嫌抄襲的內容,歡迎發送郵件至: info-contact@alibabacloud.com 進行舉報並提供相關證據,工作人員會在 5 個工作天內聯絡您,一經查實,本站將立刻刪除涉嫌侵權內容。

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.