绿盟科技威胁周报(2024.09.09-2024.09.15) – 绿盟科技技术博客
Tags
attack-pattern: Whois - T1596.002
Common Information
Type Value
UUID b9659104-f7d9-4a2a-a1b8-55638b55dca3
Fingerprint db6f1effbfbeeeb4
Analysis status DONE
Considered CTI value 0
Text language
Published Sept. 20, 2024, 10:35 a.m.
Added to db Sept. 20, 2024, 4:59 a.m.
Last updated Nov. 12, 2024, 4 a.m.
Headline 绿盟科技威胁周报(2024.09.09-2024.09.15)
Title 绿盟科技威胁周报(2024.09.09-2024.09.15) – 绿盟科技技术博客
Detected Hints/Tags/Attributes 8/1/15
RSS Feed
Details Id Enabled Feed title Url Added to db
Details 5 绿盟科技技术博客 http://blog.nsfocus.net/feed/ 2024-08-30 22:08
Attributes
Details Type #Events CTI Value
Details Domain 35
ti.nsfocus.com
Details File 2
调用bandizip.exe
Details File 2
解压缩code.7z
Details File 2
通过python调用恶意python脚本code.jpg
Details File 2
同时删除code.jpg
Details File 1
8.ai
Details Url 1
https://ti.nsfocus.com/security-news/iloqs
Details Url 1
https://ti.nsfocus.com/security-news/iloq6
Details Url 2
https://ti.nsfocus.com/security-news/iloqh
Details Url 1
https://ti.nsfocus.com/security-news/ilopi
Details Url 2
https://ti.nsfocus.com/security-news/iloqp
Details Url 1
https://ti.nsfocus.com/security-news/iloqk
Details Url 1
https://ti.nsfocus.com/security-news/iloqe
Details Url 2
https://ti.nsfocus.com/security-news/ilopy
Details Url 2
https://ti.nsfocus.com/security-news/ilopa