07-14-攻防演练之请防守方重点关注威胁情报样本信息
原文链接: https://mp.weixin.qq.com/s?__biz=MzIyNDg2MDQ4Ng==&mid=2247487384&idx=1&sn=4372d34f1a4cb28c23e95755af7d8b94
07-14-攻防演练之请防守方重点关注威胁情报样本信息
原创 微步在线 攻防SRC 2025-07-14 09:57
【今日情报】微步情报局确认以下IP有攻击行为,建议加强关注或采取封禁措施🚫
|
|
---|---|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
请防守方重点关注 微步情报局已捕获下列样本:
❗❗❗样本主题:失窃证明.zip
🔴SHA256: e94ecfd09e776a298ea2aac91d3166f5244b726c707bb521ca049e58e085743b
🔴MD5: 1e3f4f148f2236b51af16f2f35dddd2b
🔴C2:1317148038-42nowyv1ug.ap-beijing.tencentscf.com
🔴分析结论:CobaltStrike木马
❗❗❗样本主题:应聘材料.zip
🔴SHA256: eb6c288c731d50989263fdc5d8631b07a36bfa7c016dd98bffde11500314ae1d
🔴MD5: 8e5037d2521b2bc764a3de47c07a2283
🔴C2:120.24.241.109:443
🔴分析结论:CobaltStrike木马
❗❗❗样本主题:应聘人员登记表+个人简历+个人身份证正反面+获奖证书+刘安国.zip
🔴SHA256: fdbc6adc4336eb9e6f650ae8ec9036df7a6d53327c7ab542bf0259ee74992209
🔴MD5: ae3e39f5c5bea3c8cc191e1c0be49b81
🔴C2:39.99.144.188:443
🔴分析结论:CobaltStrike木马