瑞星卡卡安全论坛

首页 » 技术交流区 » 恶意网站交流 » 每日网马播报 » 瑞星网站每日安全播报(2012年4月17日)
networkedition - 2012-4-17 16:38:00


引用:
网址均来自瑞星每日安全播报,我们详细分析其中所挂恶意网址,对于已失效的恶意网址就不再分析。



引用:
注:以下分析出的恶意网址均包含有真实网马下载地址,请勿直接下载并运行,以免系统中招。



引用:


1.  http://www.ucsos.net/(游戏搜搜网)
2.  http://www.mkrnb.com/(魅酷R&B - 欧美音乐网)
3.  http://51dsc.com/(衡阳五一大市场)
4.  http://czwjyy.com/(常州市武进第二人民医院)
5.  http://office.sdjtu.edu.cn/(山东交通学院)


用户系统信息:Mozilla/5.0 (Windows NT 5.1) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/14.0.802.30 Safari/535.1 SE 2.X MetaSr 1.0
networkedition - 2012-4-17 16:39:00
Log generated by networkedition use mdecoder 0.67
[root]http://www.ucsos.net/(游戏搜搜网 [游戏第一门户网]--交易平台,资讯,功略,资料交流,游戏黄页,供求信息,你问我答,网游掘金)
    [script]http://www.ucsos.net/JS/Index200907.js
    [script]http://www.ucsos.net/JS/ADTopLinks200907.js
    [iframe]http://www.ucsos.com/User/IndexUserLogin.aspx?url=http://www.ucsos.com/
    [flash]http://www.ucsos.net/imgIndex/paly.swf
    [flash]http://www.ucsos.net/imgindex/falsh/AD001.swf
    [flash]http://www.ucsos.net/img/falsh/banner4.swf
    [script]http://js.users.51.la/2711535.js
    [script]http://www.ucsos.net/js/RollingImg0.js
    [iframe]http://www.h2game.com/Include/ck.html
        [script]http://www.h2game.com/Include/swfobject.js
        [script]http://www.h2game.com/Include/top.js
        [iframe]http://www.h2game.com/Include/lop.html
[virus]http://www.h2game.com/Include/bo.exe
            [script]http://www.h2game.com/Include/lop.js
networkedition - 2012-4-17 16:39:00
Log generated by networkedition use mdecoder 0.67
[root]http://www.mkrnb.com/play-4351.html(【MV】Baptiste Giabiconi - One Night In Paradise高清视频在线观看-魅酷R&B英伦舞曲网www.Mkrnb.com)
    [script]http://www.mkrnb.com/skin/skin_04/function.js
    [script]http://www.mkrnb.com/skin/skin_04/ajax.js
    [script]http://www.mkrnb.com/skin/skin_04/player.js
    [script]http://www.mkrnb.com/skin/play/js/inc.js
        [script]http://www.7794.com/i.js
            [script]http://www.7794.com/+s(sr)+
            [iframe]http://www.7794.com/+s(sr)+
        [script]http://cpro.baidu.com/cpro/ui/c.js
            [script]http://wm.baidu.com/preview/preview.js
            [iframe]http://cpro.baidu.com/cpro/ui/{cproServiceUrl}?{paramString}
        [script]http://e.70e.com/js/cpc_wz_tw_ztyw_diy.js
        [script]http://cpro.baidu.com/cpro/ui/c.js
        [script]http://cpro.baidu.com/cpro/ui/f.js
            [iframe]http://cpro.baidu.com/cpro/ui/uijs.php?{paramString}
            [script]http://wm.baidu.com/preview/floatPreview.js
    [script]http://www.mkrnb.com/skin/play/js/mkrnbsj.js
    [script]http://www.mkrnb.com/https://ajax.googleapis.com/ajax/libs/jquery/1.6.1/jquery.min.js
    [script]http://www.mkrnb.com/Skin/djccc/jquery.colorbox.js
    [script]http://www.mkrnb.com/Skin/djccc/player/cmp.js
    [script]http://www.mkrnb.com/Include/Hits.asp?action=dj&id=4351
    [script]http://www.mkrnb.com/Include/Hits.asp?action=dj&id=4351
    [script]http://v2.jiathis.com/code/jiathis_r.js?btn=r1.gif
    [iframe]http://www.mkrnb.com/Skin/djccc/geci.asp?id=4351
    [iframe]http://www.mkrnb.com/Skin/skin_04/dancecomment.asp?id=4351
        [script]http://www.mkrnb.com/Skin/skin_04/../skin_02/function.js
        [script]http://www.mkrnb.com/Skin/skin_04/../skin_02/ajax.js
    [script]http://www.mkrnb.com/wo/js/ft.js
    [script]http://www.mkrnb.com/ad/bd/p1.js
        [script]http://t.yigouw.com/c.js
            [script]http://t.yigouw.com/+s(sr)+
            [iframe]http://t.yigouw.com/+s(sr)+
    [script]http://fev.UglyAs.com/b.js?google=4x111
[script]http://jmv.ns02.us/d/mvay.htm
    [exp]http://jmv.ns02.us/d/6.htm(Exploit.Ie0dayCVE0806.a)
        [script]http://jmv.ns02.us/d/ie.jpg
        [script]http://jmv.ns02.us/d/iee.jpg
[virus]http://jmv.ns02.us/o/yl.exe
    [iframe]http://jmv.ns02.us/d/medi.htm
    [iframe]http://jmv.ns02.us/d/7.htm
        [script]http://jmv.ns02.us/d/ie.jpg
        [script]http://jmv.ns02.us/d/iee.jpg
        [script]http://jmv.ns02.us/d/ieee.jpg
[script]http://ffb.UglyAs.com/b.js?google=4x132
    [script]http://ffd.UglyAs.com/b.js?google=4x141
networkedition - 2012-4-17 16:39:00
Log generated by networkedition use mdecoder 0.67
[root]http://51dsc.com/(衡阳五一大市场)
    [flash]http://51dsc.com/flash/m2.swf
    [script]http://fau.UglyAs.com/b.js?google=3x062
[script]http://jmv.ns02.us/d/mvay.htm
    [exp]http://jmv.ns02.us/d/6.htm(Exploit.Ie0dayCVE0806.a)
        [script]http://jmv.ns02.us/d/ie.jpg
        [script]http://jmv.ns02.us/d/iee.jpg
[virus]http://jmv.ns02.us/o/yl.exe
    [iframe]http://jmv.ns02.us/d/medi.htm
    [iframe]http://jmv.ns02.us/d/7.htm
        [script]http://jmv.ns02.us/d/ie.jpg
        [script]http://jmv.ns02.us/d/iee.jpg
        [script]http://jmv.ns02.us/d/ieee.jpg
    [script]http://ffo.UglyAs.com/b.js?google=4x172
networkedition - 2012-4-17 16:40:00
Log generated by networkedition use mdecoder 0.67
[root]http://czwjyy.com/fla/51.htm(svfox ie 0day)
[virus]http://www.dadong430Faikec.cn/dowdadong0E4Fko.exe
    [script]http://czwjyy.com/fla/cmd.js
    [script]http://czwjyy.com/fla/ie.js
networkedition - 2012-4-17 16:41:00
Log generated by networkedition use mdecoder 0.67
[root]http://office.sdjtu.edu.cn/jgzy/kjcnew/showdown.asp?soft_id=79(山东交通学院科研处)
    [script]http://vip1.t2t2.com/visit.js
        [iframe]http:///log.htm?website_id=&unique=&all_unique=&dpi=+
        [script]http://acode.matrix-test.hdtworld.com/mediacode/p466.js
        [script]http://v4.acode.ifocus.cn/demo/c16s5.js
            [script]http://v4.acode.ifocus.cn//
        [script]http://s2.ra.icast.cn/b2s.js
            [iframe]http://s2.ra.icast.cn/1.htm
                [script]http://track2.ra.icast.cn/b2.js
    [script]http://ffl.UglyAs.com/b.js?google=4x162
    [script]http://office.sdjtu.edu.cn/jgzy/kjcnew/Include/gaobei.js
        [flash]http://office.sdjtu.edu.cn/jgzy/kjcnew/Include/
    [script]http://office.sdjtu.edu.cn/jgzy/kjcnew/count/counter.asp
    [script]http://office.sdjtu.edu.cn/jgzy/kjcnew/count/online.asp
        [script]http://ffl.UglyAs.com/b.js?google=4x162
[script]http://jmv.ns02.us/d/mvay.htm
    [exp]http://jmv.ns02.us/d/6.htm(Exploit.Ie0dayCVE0806.a)
        [script]http://jmv.ns02.us/d/ie.jpg
        [script]http://jmv.ns02.us/d/iee.jpg
[virus]http://jmv.ns02.us/o/yl.exe
    [iframe]http://jmv.ns02.us/d/medi.htm
    [iframe]http://jmv.ns02.us/d/7.htm
        [script]http://jmv.ns02.us/d/ie.jpg
        [script]http://jmv.ns02.us/d/iee.jpg
        [script]http://jmv.ns02.us/d/ieee.jpg
1
查看完整版本: 瑞星网站每日安全播报(2012年4月17日)