人机验证诱骗用户运行危险的PowerShell脚本
Common Information
Type Value
UUID 987acf96-b3eb-40ee-b198-6a25b5ad5d2e
Fingerprint 1a27d12fa3807141
Analysis status DONE
Considered CTI value 0
Text language
Published June 20, 2024, midnight
Added to db Sept. 9, 2024, 2:20 p.m.
Last updated Nov. 18, 2024, 1:38 a.m.
Headline 人机验证诱骗用户运行危险的PowerShell脚本
Title 人机验证诱骗用户运行危险的PowerShell脚本
Detected Hints/Tags/Attributes 5/1/7
Source URLs
RSS Feed
Details Id Enabled Feed title Url Added to db
Details 483 CN-SEC 中文网 https://cn-sec.com/feed/ 2024-08-30 22:08
Attributes
Details Type #Events CTI Value
Details Domain 2
antibotx.b-cdn.net
Details Domain 3
clicktogo.click
Details File 2
captcha-verify.html
Details File 1
最终下载并运行一个名为trans08.exe
Details File 1209
powershell.exe
Details File 1
trans08.exe
Details Url 1
https://clicktogo.click/downloads/tra08