公众号新规只对常读和星标的公众号才能展示大图推送,建议大家把公众号“night安全”设为星标,否则可能就看不到啦!
免责声明
night安全致力于分享技术学习和工具掌握。然而请注意不得将此用于任何未经授权的非法行为,请您严格遵守国家信息安全法律法规。任何违反法律、法规的行为,均与本人无关。如有侵权烦请告知,我们会立即删除并致歉。谢谢!
##2024你懂得##
内容部分信息已脱敏,复制文章内的关键词回复公众号获取今日情报详情。
情报详情获取方式:
回复:20240729-001
风险情报
SQL
浪潮GS企业管理软件xtdysrv.asmx
泛微HrmService存在
Netgear WN604无线路由器siteSurvey.php
Linux kemef
WWBN AVideo存在
Solar-Log存在
餐厅数字化综合管理平台
样本情报
样本主题:建议虚拟机中运行本程序.exe
SHA256: 524fbb6bbc86885ed0ec0ba3194302df0a1e356dded509e55725362cd2662b00
MD5: 33650f678ffc4857aaaa9a6513d6becb
相关域名:doc.run、sched.tdnsv8.com、www.shangxueba.com、oweeqjtrqesn.kuaizhan.com、www.cdn.dnsv1.com、www.dsa.sp.spcdntip.com
攻击手法:域前置
分析结论:CobaltStrike木马
样本主题:****-https.exe
SHA256: 85302308d8bf8d807ab179e5c4bdeb88379ddbcd4a342c07a29d1ca8dab8258a
MD5: 4a3456392d3b19f74bcd77d192b62774
C2:27.211.158.244:43904
分析结论:CobaltStrike木马
样本主题:***-新媒体矩阵微信稿.iso
SHA256: 22f85b30529877305948b2942d3f3347b62b61ed61572f30cd26ccca553cf6b5
MD5: 1c273925cfb2a43b8a915934721f0f32
恶意软件:private-javascript.oss-cn-hangzhou.aliyuncs.com.s2-web.dogedns.com
分析结论:CobaltStrike木马
样本主题:西安****有限公司资料信息.zip
SHA256: 667cf48fec5c42592382cbe28e077ce7cefb68f93496c160b74580b1ffae5e18
MD5: d91bf15ad5e67bc051fcc4b30d2e2cfe
恶意软件:yuntechmirror.oss-cn-hangzhou.aliyuncs.com、chinabucketos.oss-cn-hangzhou.aliyuncs.com、ailiyunbrowser.oss-cn-hangzhou.aliyuncs.com、alizbhn.oss-cn-shenzhen.aliyuncs.com
相关域名:123youke.com、rjf56.com、turingmaker.com
攻击手法:域前置
分析结论:CobaltStrike木马
域名情报
2024.nizarsaadjabal.com
www.0xqtt57e.sched.vip-dk.tdnsvod1.cn
123youke.com
rjf56.com
turingmaker.com
doc.run
sched.tdnsv8.com
www.shangxueba.com
oweeqjtrqesn.kuaizhan.com
www.cdn.dnsv1.com
www.dsa.sp.spcdntip.com
ip情报
5.75.142.149
52.227.248.137
213.138.97.228
112.124.54.173
193.176.10.151
193.178.170.60
188.165.180.10
83.149.93.148
152.32.249.41
152.32.251.32
152.32.210.197
146.190.74.215
146.190.168.188
146.190.120.181
101.37.81.72
83.149.128.151
148.113.173.193
185.54.147.165
185.53.207.27
23.97.147.64
121.41.169.217
152.32.169.48
182.92.232.85
47.94.222.178
152.42.156.97
121.196.232.45
213.140.128.244
116.62.236.119
142.93.172.2
100.1.226.158
23.101.206.185
23.96.110.38
112.124.41.218
112.124.19.38
112.124.71.123
159.65.28.100
159.65.41.205
159.65.201.83
159.65.40.119
159.69.197.20
159.69.199.205
118.195.183.184
39.106.59.150
159.65.254.198
159.65.23.71
159.75.96.211
194.177.53.5
180.150.65.157
85.105.39.57
94.124.124.18
221.228.67.19
202.22.224.9
78.189.148.231
41.72.131.58
50.188.104.152
18.153.90.3
150.243.160.243
211.102.192.24
34.120.243.209
34.122.3.35
34.122.230.145
34.121.16.143
34.123.183.150
34.124.197.180
119.45.22.216
34.126.175.29
34.131.16.86
34.131.198.92
34.133.148.51
34.135.206.153
34.135.86.210
34.134.82.31
189.151.208.19
39.68.73.160
116.62.197.15
167.86.115.93
86.57.135.24
4.206.159.130
124.70.103.151
106.55.202.118
123.6.81.16
61.160.224.9
121.32.243.7
61.160.224.8
223.111.128.11
106.55.202.118
117.72.75.193
77.90.22.16 德国 黑森州 美因河畔法兰克福
223.104.73.133 中国 广东省 珠海市
......
推荐站内搜索:最好用的开发软件、免费开源系统、渗透测试工具云盘下载、最新渗透测试资料、最新黑客工具下载……
还没有评论,来说两句吧...