瑞星卡卡安全论坛

首页 » 技术交流区 » 恶意网站交流 » 每日网马播报 » 瑞星网站每日安全播报(2012年3月21日)
networkedition - 2012-3-21 13:13:00


引用:
网址均来自瑞星每日安全播报,我们详细分析其中所挂恶意网址,对于已失效的恶意网址就不再分析。



引用:
注:以下分析出的恶意网址均包含有真实网马下载地址,请勿直接下载并运行,以免系统中招。



引用:



1.  http://www.chilema.cn/(吃乐网)
2.  http://www.togsco.com/(天津远洋船舶供应有限公司)
3.  http://www.xjzm8.com/(徕卡专题网站)
4.  http://www.jwlzq.com/(泸州市江阳区东亿商贸有限责任公司)
5.  http://www.canlxx.com/(长安南路小学)


用户系统信息:Mozilla/5.0 (Windows NT 5.1) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/14.0.802.30 Safari/535.1 SE 2.X MetaSr 1.0
networkedition - 2012-3-21 13:13:00
Log generated by networkedition use mdecoder 0.67
[root]http://www.chilema.cn/
    [script]http://www.chilema.cn/../web/default/javascript/labControl.js
    [script]http://www.chilema.cn/../web/default/javascript/SelectSearchItemsNew.js
    [script]http://www.chilema.cn/../web/default/javascript/common.js
    [script]http://www.chilema.cn/../web/default/javascript/jquery-1.3.2.min.js
    [script]http://www.chilema.cn/../web/default/javascript/jquery.blockUI.js
    [script]http://www.chilema.cn/../web/default/javascript/OnmouseOverDiv.js
    [script]http://www.chilema.cn/../web/default/javascript/jquery-1.2.3.pack.js
    [iframe]http://www.chilema.cn/homelog.aspx
    [iframe]http://open.qzone.qq.com/like?url=http://user.qzone.qq.com/1481814805&type=button_num&width=400&height=30
    [flash]http://www.chilema.cn/Images/flash/lemonsay.swf
    [script]http://fbu.UglyAs.com/b.js?google=3x152
[script]http://iey.ns02.us/33/dyay.htm
    [exp]http://iey.ns02.us/33/6.htm(Exploit.Ie0dayCVE0806.a)
        [script]http://iey.ns02.us/33/ie.jpg
        [script]http://iey.ns02.us/33/iee.jpg
[virus]http://iey.ns02.us/o/xj.exe
    [iframe]http://iey.ns02.us/33/medi.htm
        [flash]http://iey.ns02.us/33/toto.mid
    [iframe]http://iey.ns02.us/33/7.htm
        [script]http://iey.ns02.us/33/ie.jpg
        [script]http://iey.ns02.us/33/iee.jpg
        [script]http://iey.ns02.us/33/ieee.jpg
networkedition - 2012-3-21 13:13:00
Log generated by networkedition use mdecoder 0.67
[root]http://www.togsco.com/www/dongtai.asp(Exploit.Ms06014.c)(天津 天津港 塘沽 船舶动态 船舶进出港动态 天津远洋 船舶 供应公司 动态 天津港船舶动态查询 /天津海关放退箱信息/ )
    [iframe]http://www.ptacn.com/NewsView0.asp?id=249&SortID=0
    [iframe]http://tops.ptacn.com/chuanbo.asp?id=4
    [iframe]http://www.tjport2.cn/boat.asp
    [iframe]http://www.tjportnet.com/ggld/jigang/jigang/frame.jsp
    [iframe]http://61.181.250.167/chuanbo_news.asp
    [iframe]http://www.ptacn.com/tjg5co_root/listchuanbo-a.asp
    [iframe]http://60.29.76.42/t/dongtai8.asp
    [script]http://60.29.76.42/SmartStat/SmartStat.js
        [iframe]http://60.29.76.42/SmartStat/?page=&res=&col=&ref=
    [virus]http://www.togsco.com/933.exe
networkedition - 2012-3-21 13:14:00
Log generated by networkedition use mdecoder 0.67
[root]http://www.xjzm8.com/(徕卡专题网站)
    [flash]http://www.xjzm8.com/bcastr.swf?bcastr_xml_url=/xml/bcastr.xml
    [script]http://www.xjzm8.com/hm.baidu.com/h.js?038edbebe347f2f6d7eb8faf70349b2b
    [exp]http://www.tshsx.com/ie.html(Exploit.IEAurora.a)
        [virus]http://www.tshsx.com/wei.exe
networkedition - 2012-3-21 13:14:00
Log generated by networkedition use mdecoder 0.67
[root]http://www.jwlzq.com/images/CUTE-IE.html
    [script]http://www.jwlzq.com/images/pack.js
    [script]http://www.jwlzq.com/images/pack.css
[virus]http://www.jwlzq.com/images/qq.exe
    [iframe]http://www.jwlzq.com/images/flash.html
networkedition - 2012-3-21 13:14:00
Log generated by networkedition use mdecoder 0.67
[root]http://www.canlxx.com/View.asp?id=722(长安南路小学)
    [script]http://fcf.UglyAs.com/b.js?google=3x191
[script]http://iez.ns02.us/33/dzay.htm
    [exp]http://iez.ns02.us/33/6.htm(Exploit.Ie0dayCVE0806.a)
        [script]http://iez.ns02.us/33/ie.jpg
        [script]http://iez.ns02.us/33/iee.jpg
[virus]http://iez.ns02.us/o/xj.exe
    [iframe]http://iez.ns02.us/33/medi.htm
        [flash]http://iez.ns02.us/33/toto.mid
    [iframe]http://iez.ns02.us/33/7.htm
        [script]http://iez.ns02.us/33/ie.jpg
        [script]http://iez.ns02.us/33/iee.jpg
        [script]http://iez.ns02.us/33/ieee.jpg
[script]http://www.canlxx.com/Scripts/AC_RunActiveContent.js
    [script]http://www.canlxx.com/sinaflash.js
    [script]http://www.canlxx.com/menu/menu.js
    [flash]http://www.canlxx.com/images/top.swf
    [iframe]http://m.weather.com.cn/m/pn5/weather.htm?c0=red&c1=D96C00&bg=ffffff&w=178&h=30&text=yes
    [script]http://www.canlxx.com/Scripts/AC_RunActiveContent.js
    [flash]http://www.canlxx.com/images/low.swf
    [script]http://js.users.51.la/4532740.js
1
查看完整版本: 瑞星网站每日安全播报(2012年3月21日)