银狐再临——瞄准财税岗位定向钓鱼攻击
Tags
Common Information
Type Value
UUID ce25ce6e-4656-4cc3-b3b4-0057c85e2d19
Fingerprint 2228e6ab8a7786b2
Analysis status DONE
Considered CTI value 2
Text language
Published March 27, 2024, midnight
Added to db Aug. 31, 2024, 9:04 a.m.
Last updated Oct. 22, 2024, 8:56 a.m.
Headline 银狐再临——瞄准财税岗位定向钓鱼攻击
Title 银狐再临——瞄准财税岗位定向钓鱼攻击
Detected Hints/Tags/Attributes 0/0/37
Attributes
Details Type #Events CTI Value
Details CERT 360 CN 2
CERT-R-2024-768
Details Domain 2
www.yk668.work
Details Domain 2
www.30tsjju.com
Details Domain 2
lwefjf0kef.com
Details Domain 2
www.zhuang0.cn
Details Domain 2
bsnbfv.work
Details Domain 2
nechina.net
Details Domain 2
augenstern-1324625829.cos.ap-guangzhou.myqcloud.com
Details Domain 100
cert.360.cn
Details File 2
以.bz2
Details File 2
916.zip
Details File 2
916.chm
Details File 2
并加载其服务器上的load.xsl
Details File 2
而这个load.xsl
Details File 3
load.xml
Details File 35
config.txt
Details File 2
zfnxs.exe
Details File 2
进而加载ffmpg.dll
Details File 2
文件对foo.png
Details File 2
ffmpg.dll
Details md5 2
3ce0af1f871bbfb5be669b08e7557dd1
Details md5 2
1cc411fe36c369fab5dceb53f370a512
Details md5 2
848121e7e7c8e9d5ad4db0e0a9dd3976
Details md5 2
1419b2b1e0836acceab18e832b1eb750
Details md5 2
534bf8fd7e82d1e173126b6aafef0461
Details md5 2
e7b01d3b18d06a008dc27be4dd85f151
Details md5 2
1b5ef099cfeb52ef74edf99bf50af0ef
Details md5 2
79a88331aaef8e53ed33a9c344ea8769
Details Url 2
https://nechina.net/916.zip
Details Url 2
https://www.yk668.work/share/f2b623d7689aa124ae93
Details Url 2
http://www.30tsjju.com
Details Url 2
http://lwefjf0kef.com
Details Url 2
https://www.zhuang0.cn
Details Url 2
https://bsnbfv.work/vuepan/?id=7d45602ad7d83bafbe61
Details Url 2
https://nechina.net
Details Url 2
https://augenstern-1324625829.cos.ap-guangzhou.myqcloud.com/bwj/config/config.txt
Details Url 93
https://cert.360.cn