Host | ISP | City | CountryCode | CountryName | Latitude | Longitude | Talos | ThreatVault |
130.61.36.89 | Oracle Cloud | Frankfurt am Main | DE | Germany | 50.1188 | 8.6843 | Suspicious IP Address | Unknown, Medium Risk |
158.101.166.68 | Oracle Cloud | Frankfurt am Main | DE | Germany | 50.1049 | 8.6295 | Suspicious IP Address | Unknown, Medium Risk |
198.50.143.157 | OVH SAS | CA | Canada | 43.6319 | -79.3716 | Suspicious IP Address | Unknown, Medium Risk | |
129.213.161.202 | Oracle Cloud | US | United States | 38.6583 | -77.2481 | Suspicious IP Address | Unknown, Medium Risk |
whaust
2020年4月29日 星期三
Suspicious IP Address / Unknown, Medium Risk
2020年4月28日 星期二
SSDLC Meetup Highlights
We exchange opinions each other, and come into the highlights as following :
1. Input Validation (輸入驗證):
- 檔案上傳檢查 (病毒, 檔案大小, 沙箱檢查)
- 輸入值檢查 (SQL/I , Cross-Site Scripting)
2. Zero Trust Model (零信任模式) :
2. Zero Trust Model (零信任模式) :
解決合法帳號濫用情境
- 借帳號使用 :會影響不可否認性 (non-repudiation)
- 大量使用超過合理範圍
- 最小權限授權
- 特權帳號管理
3. Variable Range Check (變數範圍檢查) :
3. Variable Range Check (變數範圍檢查) :
- 案例【原油期首現負數 平不了倉?金管會要追】: 系統分析時,你會想到有一天油價會到達 負值嗎 ? 原油期貨出現史上首見的負價值,期貨商下單系統卻沒有「負值」可供投資人平倉,證期局副局長蔡麗玲23日表示,已主動要求期貨商公會調查各期貨商交易系統,了解本月21日有多少投資人是因為下單系統無負值,不能下單平倉,若是期貨商系統問題,金管會將要求期貨商「也要負點責任」。https://udn.com/news/story/7238/4507155
4. 威脅種類與所需措施
威脅種類 所需措施 Spoofing Authenticity Tampering Integrity Repudiation Non-repudiability Information disclosure Confidentiality Denial of Service Availability Elevation of Privilege Authorization
2020年4月27日 星期一
Malware : ShadowBroker , md5sum : Generate MD5 value
date > date.txt
md5sum date.txt
1e53389b6fef60fbb7663b2b890111b0 date.txt
命令 : md5sum
Let's do it !
ShadowBroker.malware
get all the file in C:\Windows\NetworkDistribution\
ShadowBroker.malware
get all the file in C:\Windows\NetworkDistribution\
md5sum * > readme.txt
c31d696f93ec84e635c4560034340e171 adfw-2.dll 770d0caa24d964ea7c04ff5daf290f08 adfw.dll ee2d6e1d976a3a92fb1c2524278922ae cnli-0.dll a539d27f33ef16e52430d3d2e92e9d5c cnli-1.dll 3c2fe2dbdf09cfa869344fdb53307cb2 coli-0.dll f82fa69bfe0522163eb0cf8365497da2 crli-0.dll 1ca9e6eb86036daea4dfa3297f70d542 dmgd-1.dll a05c7011ab464e6c353a057973f5a06e dmgd-4.dll d9b5b26f0423230e99768092f17919a3 esco-0.dll 3e5d06dc6e7890e1800cf24c9f599856 etch-0.dll 4ff94c163565a38a27cf997ad07b3d69 etchCore-0.x64.dll 1f0669f13dc0545917e8397063f806db etchCore-0.x86.dll 47106682e18b0c53881252061ffcaa2d eteb-2.dll 24aa99837d14bee5da2e2339b07f9d4c etebCore-2.x64.dll 89b7dac7d9ce5b75b08f5d037edd3869 etebCore-2.x86.dll 756b6353239874d64291e399584ac9e5 Eternalblue-2.2.0.fb 5b18e38e2b99ebd24937751e936b2161 Eternalchampion-2.0.0.fb ba629216db6cf7c0c720054b0c9a13f3 exma-1.dll 649b368c52de83e52474a20ce4f83425 exma.dll 4803a7863da607333378b773b6a17f4c iconv.dll 43aac72a9602ef53c5769f04e1be7386 libcurl.dll f01f09fe90d0f810c44dce4e94785227 libeay32.dll 5adcbe8bbba0f6e733550ce8a9762fa0 libiconv-2.dll 9a5cec05e9c158cbc51cdc972693363d libxml2.dll 1e9e29a4e8b29d074827c1bc9f1f6d27 out.dll 6fe4544d00b77e0295e779e82d8f0fe5 pcla-0.dll 00dd6b018c3c2d347df43f779715bca5 pcre-0.dll 09836461312a3781af6e1298c6b2c249 pcrecpp-0.dll 30017e300c6d92e126bf92017c195c37 pcreposix-0.dll 2f0a52ce4f445c6e656ecebbcaceade5 posh-0.dll b777086fd83d0bc1dccdc7c126b207d0 posh.dll d41d8cd98f00b204e9800998ecf8427e process1.txt 7beb08b9b4fc27c883f593f6abc53eee pytrch.py aac9bc7fd2ed52d277199ccf373a996f pytrch.pyc 2c2ef3b01ffa0ab28b3bd7c88f2ac22f _pytrch.pyd 8969668746ae64ca002cc7289cd1c5da riar-2.dll e53f9e6f1916103aab8703160ad130c0 riar.dll c24315b0585b852110977dacafe6c8c1 spoolsv.exe 8b0da6527cfbbd3897c7f206861d5951 spoolsv.xml 5e8ecdc3e70e2ecb0893cbda2c18906f ssleay32.dll eccf12c44c88e76671a427420b08d4c2 svchost.xml 0647dcd31c77d1ee6f8fac285104771a tibe-1.dll f0881d5a7f75389deba3eff3f4df09ac tibe-2.dll f61e81eaf4a9ac9cd52010da3954c2a9 tibe.dll 8b0a4ce79f5ecdb17ad168e35db0d0f9 trch-0.dll 838ceb02081ac27de43da56bec20fc76 trch-1.dll 01d5adbfee39c5807ee46f7990f5fda7 trch.dll 46f7b320b13a4b618946042360215179 trfo-0.dll 3e89c56056e5525bf4d9e52b28fbbca7 trfo-2.dll d1aae806243cc0bedb83a22919a3a660 trfo.dll 83076104ae977d850d1e015704e5730a tucl-1.dll 1fa609bc0d252ca0915d6aed2df7ccc2 tucl.dll 6b7276e4aa7a1e50735d2f6923b40de4 ucl.dll 6dc722c9844e61427a47a2759a8fbec0 x64.dll 95786b6c28bf8dba7bbfeeba9e1ec27a x86.dll 5b72ccfa122e403919a613785779af49 xdvl-0.dll 9744f0000284c2807de0651c7e0d980a zibe.dll e4ad4df4e41240587b4fe8bbcb32db15 zlib1.dll
2020年4月24日 星期五
Attack SHA-1 (TC-0424)
SHA1
ed2febf310ae90739002b9ddb07a29d0b2c8e92462ae4a0a6dcc19cc537ddef3 |
3f06740b150e1fa64c501210e83e75adecd074e99fe90160912bbd2368a33be5 |
aa8adf96fc5a7e249a6a487faaf0ed3e00c40259fdae11d4caf47a24a9d3aaed |
b7d8fcc3fb533e5e0069e00bc5a68551479e54a990bb1b658e1bd092c0507d68 |
2af73c8603e1d51661b0fffc09be306797558204bcbd4f95dd2dfe8363901606 |
cf25bdc6711a72713d80a4a860df724a79042be210930dcbfc522da72b39bb12 |
f0df80978b3a563077def7ba919e2f49e5883d24176e6b3371a8eef1efe2b06a |
70dbb0b5562cd034c6b70a4a86a346b0f0039acf1b09f5814c42895963e12ea0 |
96edea8d08ab10eee86776cfb9e32b4701096d21c39dbffeb49bd638f09d726a |
36107f74be98f15a45ff716e37dad70f1ff9515bc72a0a1ec583b803c220aa92 |
06c031f0d905cdeb0d9c172c27ae0c2d25bbf0d08db27a4aa98ec540a15306e7 |
b2a3172a1d676f00a62df376d8da805714553bb3221a8426f9823a8a5887daaa |
a4c460b27d03daf7828f6b6db87e0ff3ee851fdb1b8654b0a778b4c34953a3dc |
6775d627d99733f3f02494db7e13935b505132f43c56e7f8850c54e6627691de |
a418edc5f1fb14fbf9398051225f649810fa75514ca473610be44264bf3c663c |
0259d41720f7084716a3b2bbe34ac6d3021224420f81a4e839b0b3401e5ef29f |
85b936960fbe5100c170b777e1647ce9f0f01e3ab9742dfc23f37cb0825b30b5 |
52e88433f2106cc9a3a961cd8c3d0a8939d8de28f2ef3ee8ea648534a8b036a4 |
ca63dbb99d9da431bf23aca80dc787df67bb01104fb9358a7813ed2fce479362 |
d104c3f46f8722b561da4682a596e664cebad49185eea85bd0533547cbb92760 |
be8eb97d8171b8c91c6bc420346f7a6d2d2f76809a667ade03c990feffadaad5 |
15ffbb8d382cd2ff7b0bd4c87a7c0bffd1541c2fe86865af445123bc0b770d13 |
55039ab48c0916a38f1ceee08ba9f9cf5f292064cf3ee6631f22becde5e74b2d |
f8ee4c00a3a53206d8d37abe5ed9f4bfc210a188cd5b819d3e1f77b34504061e |
d8ed4f58f8e83865be9a38a6c443e42c83554290709f29664ddf4f6e00cdd266 |
47e16f7db53d9adf24d193ff4d523b1bc7ae59ff8520cfa012365bdb947c96f9 |
1c8100aca288483d5c29dcf33df887e72513f9b1cb6d0c96045401981351307c |
17d6dde8a6715b9311734cb557b76160a22e340785b3950eae23aae67b0af6a8 |
93f0a1fe486ad222b742e451f25f4c9219b1e0f5b4273a15ce08dd714827745a |
cde45f7ff05f52b7215e4b0ea1f2f42ad9b42031e16a3be9772aa09e014bacdb |
aceb27720115a63b9d47e737fd878a61c52435ea4ec86ba8e58ee744bc85c4f3 |
1743e1bd4176ffb62a1a0503a0d76033752f8bd34f6f09db85c2979c04bbdd29 |
df9200ba0d967487b9eb9627078d7faa88072c493b6d9e2b68211c14b06e9f4e |
5f30aa2fe338191b972705412b8043b0a134cdb287d754771fc225f2309e82ee |
36b0fa6c0da7434707e7e330f40316458c0c1edc39b80e2fe58745cd77955eb3 |
d3c6985d965cad5bff6075677ed8c2cafee4c3a048fb5af81b442665c76dff7b |
c977ac10aa3d2250a1af39630f532184a5185f505bcd5f03ea7083a3a701a969 |
c00ded23530a99ce053dc63b71d99462d358b2a07ee34065b5aff489357420de |
b1d48e8185d9d366dce8c723ba765d6c593b7873cb43d77335084b58bbc7cb4d |
609ed51631da2defa34d58f60dc2a0f38e1574d8cf07647b844fc8b95de4bd8c |
8a5cce25f1bf60e716709c724b96630b95e55cc0e488d74d60ea50ffba7d6946 |
15292172a83f2e7f07114693ab92753ed32311dfba7d54fe36cc7229136874d9 |
3596e8fa5e19e860a2029fa4ab7a4f95fadf073feb88e4f82b19a093e1e2737c |
7ddbade1f4fcb48f254e7defa1ab5ec568e8ff0403693860b76870e11816aee6 |
ad3c0b153d5b5ba4627daa89cd2adbb18ee5831cb67feeb7394c51ebc1660f41 |
19690e5b862042d9011dbdd92504f5012c08d51efca36828a5e9bdfe27d88842 |
3fcffe9eae90ec365efb361674613ac95de50b2ccfd634c24491923f85c309a5 |
fe4640fefa4bef02041a771a206f9184adb38de051f0d8726c4579736fe13bb6 |
50f329e034db96ba254328cd1e0f588af6126c341ed92ddf4aeb96bc76835937 |
b556b5c077e38dcb65d21a707c19618d02e0a65ff3f9887323728ec078660cc3 |
9b8ec5d0c10ccdd3933b7712ba40065d1b0dd3ffa7968fb28ad426cd5eee5001 |
db0831e19a4e3a736ea7498dadc2d6702342f75fd8f7fbae1894ee2e9738c2b4 |
0439628816cabe113315751e7113a9e9f720d7e499ffdd78acbac1ed8ba35887 |
8e03f05ecd08cb78f37ccd92c48cd9d357c438112b85bd154e8261c19e38a56e |
f06d02359666b763e189402b7fbf9dfa83ba6f4da2e7d037b3f9aebefd2d5a45 |
d3db1e56360b25e7f36abb822e03c18d23a19a9b5f198e16c16e06785fc8c5fa |
c51bce247bee4a6f4cd2d7d45483b5b1d9b53f8cc0e04fb4f4221283e356959d |
2020年4月23日 星期四
2020年4月22日 星期三
XMRig Miner Command and Control Traffic Detection(85299)
Mine Pool IP :
DPORT 45700
136.243.102.154
94.130.239.15
138.201.27.243
88.99.142.163
46.4.120.18
94.130.143.162
78.46.49.222
78.46.87.181
138.201.20.89
163.172.226.137
195.154.62.247
163.172.226.114
163.172.206.67
163.172.207.69
163.172.203.178
2020 年間のセキュリティ機能トレーニング(5/15オープン登録)
1.目的
ICT安全責任レベルのA、B、およびCのレベルを持つ公的機関(組織)を支援して、ICT安全管理法の要件(ICT安全責任レベルの段階への段階的アプローチ)に準拠するには、関連する情報セキュリティ機能評価証明書が必要です。公安機関(構造)のフルタイム(責任者)の専門家のセキュリティ知識とスキルを向上させるトレーニング。
2.参加者
公安機関(構造)の常勤(責任)要員。
3.頻度
登録は5月15日10時からです。
補助金クラス:職員の研修費用は行政院の50%が助成し、残りは研修機関が助成します。
自己資金によるクラス:職員のトレーニング費用は、トレーニング組織から完全に助成されます。
で
訂閱:
文章 (Atom)
Popular
-
При планировании проекта разработки программного обеспечения я часто сталкиваюсь с помощником, который задает мне вопрос: в чем разница межд...
-
Question 1 of 10 Which type of cyberattack sends extremely high volumes of network traffic such as packets, data, or transactions that rend...
-
今天你的老爸我將談論兩種技術,Cisco vPC: Virtual Port Channel (虛擬端口通道) 和 VSS:Virtual Switching system (虛擬交換系統)。 這兩種技術在各自領域的工作方式不同。 你們不用一直Google去查,我在這兒把它們之...