本帖最后由 I11usion 于 2024-3-1 10:13 编辑
钓鱼网页信息钓鱼官网
https://www.finalshell.org/ 样本下载链接
Windows端: https://www.finalshell.org/finalshell_install.msi macOS端: https://www.finalshell.org/downloads/finalshell_install.pkg Linux端: rm -f finalshell_install_linux.sh ;wget finalshell.org/downloads/finalshell_install_linux.sh;chmod +x finalshell_install_linux.sh;./finalshell_install_linux.sh;
搜索引擎结果
Google搜索,处于第二位(第一位为真实官网)
bing搜索国内版,处于第二位(第一位为真实官网)
bing搜索国际版,处于第三位(第一位为真实官网)
沙箱分析结果微步云沙箱 https://s.threatbook.com/report/file/f0c1a5632bb7609fad8b3248ca57cba2c623863dd1940f4de3e0f01f6860cf78 https://s.threatbook.com/report/url/ffad6a874799a4ad4d4f8098c037ace0
virustotal https://www.virustotal.com/gui/file/f0c1a5632bb7609fad8b3248ca57cba2c623863dd1940f4de3e0f01f6860cf78
相关IOC
恶意域名1683.org 恶意IP38.181.35.129 13.107.21.200 204.79.197.200 恶意下载链接http://1683.org/e7/107.148.48.35/lib_32 http://1683.org/e7/107.148.48.35/reg32 样本hashSHA256:f0c1a5632bb7609fad8b3248ca57cba2c623863dd1940f4de3e0f01f6860cf78 SHA1:cca502a6266daf73f850cec2ad09810c2be671ca MD5:3b3718ac42fe21cd46eef8e456fc6376
|