瑞星卡卡安全论坛

首页 » 技术交流区 » 恶意网站交流 » http://www.bd365.net/(保定频道_保定综合门户网站 )
networkedition - 2010-9-2 14:56:00
Log generated by networkedition use mdecoder 0.54
[root]http://www.bd365.net/nul.show.asp?dy=217769560(魔兽3.22安装出现问题 - 已解决 )
    [script]http://www.hangzhou-anmo.com/baidu3.js
    [script]http://www.hangzhou-anmo.com/baidu2.js
    [script]http://www.hangzhou-anmo.com/baidu.js
        [exp]http://www.jjeffyfc19.info/wm/wow/index.htm(Exploit.Ie0dayCVE0806.a)
[virus]http://www.hangzhou-anmo.com/zai/2.exe
            [script]http://www.jjeffyfc19.info/wm/wow/yt.jpg
            [script]http://js.users.51.la/4037154.js
    [script]http://www.hangzhou-anmo.com/baidu4.js
    [script]http://www.hangzhou-anmo.com/baidu2.js

用户系统信息:Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1) ; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729; InfoPath.2)
jks_风 - 2010-9-2 22:55:00
MS这三个网马都为同一人所为
Log is generated by FreShow.
[wide]http://www.bd365.net/nul.show.asp?dy=217769560
    [script]http://www.hangzhou-anmo.com/baidu3.js
    [script]http://www.hangzhou-anmo.com/baidu2.js
        [object]http://www.hangzhou-anmo.com\\xiazai\\2.exe
    [script]http://www.hangzhou-anmo.com/baidu.js
        [frame]http://www.jjeffyfc19.info/wm/wow/index.htm
            [script]http://www.jjeffyfc19.info/wm/wow/yt.jpg
            [script]http://js.users.51.la/4037154.js
    [script]http://www.hangzhou-anmo.com/baidu4.js
    [script]http://www.hangzhou-anmo.com/baidu2.js
1
查看完整版本: http://www.bd365.net/(保定频道_保定综合门户网站 )