关于:hxxp://zxcv11.3322.org:99/解密的日志(全体输出 - 23):
Level 0>http://zxcv11.3322.org:99/
Level 1>http://zxcv11.3322.org:99/me-.html?id=u2
Level 2>http://zxcv11.3322.org:99/Chic.cssLevel 3>http://zxcv11.3322.org:99/Style.CssLevel 1>http://zxcv11.3322.org:99/me-.html?id=u1
Level 2>http://zxcv11.3322.org:99/me-.html?id=u1/Chic.cssLevel 1>http://zxcv11.3322.org:99/check.php?id=id
Level 1>http://zxcv11.3322.org:99/safe.js
Level 1>http://js.tongji.linezing.com/1530557/tongji.js
Level 2>http://js.tongji.linezing.com/1530557/+url_id+/clickcollect.js
Level 2>http://tongji.linezing.com/clickmap/load_clickmap.html?r=+Math.random
Level 1>http://js.tongji.linezing.com/1530554/tongji.js
Level 2>http://js.tongji.linezing.com/1530554/+url_id+/clickcollect.js
Level 1>http://js.tongji.linezing.com/+tongji_num+/tongji.js
Level 2>http://js.tongji.linezing.com/1460303/tongji.js
Level 2>http://js.tongji.linezing.com/1339401/tongji.js
Level 2>http://js.tongji.linezing.com/1475272/tongji.js
Level 2>http://js.tongji.linezing.com/1358882/tongji.js
Level 2>http://js.tongji.linezing.com/1404518/tongji.js
Level 2>http://js.tongji.linezing.com/1419200/tongji.js
Level 2>http://js.tongji.linezing.com/1399654/tongji.js
Level 2>http://js.tongji.linezing.com/1237116/tongji.js
Level 2>http://js.tongji.linezing.com/615056/tongji.js
日志由 Redoce2.0第88次修正版于 2010/3/15 16:04:12 生成。
变态哈 U1 U2的代码加起来才能得出最后的隐藏网马的完整shellcode