技术摘要
数据描述了一份ThreatFox信息源更新,其中包含与2025年12月14日恶意软件活动相关的入侵指标(IOCs)。该威胁被归类为开源情报(OSINT)、载荷投递和网络活动,这表明其主要侧重于收集和共享有关恶意软件相关网络行为和载荷的情报。然而,未列出具体受影响的产品、版本或漏洞,也没有与此条目相关的补丁或已知漏洞利用信息。威胁级别被评为中等,威胁等级指标为2,传播指标为3,表明其传播范围中等,但直接影响有限。缺乏具体的技术细节、通用缺陷枚举(CWE)或指标,限制了评估威胁确切性质或攻击向量的能力。此条目似乎是来自ThreatFox MISP(恶意软件信息共享平台)信息源的信息更新,该平台是一个用于共享威胁情报的开源情报平台,而非关于新漏洞或活跃漏洞利用的报告。因此,它更像是一种态势感知工具,而非即时安全警报。
潜在影响
鉴于缺乏具体受影响的系统、漏洞利用或漏洞,对欧洲组织的直接影响可能微乎其微。这些信息可能有助于安全团队通过更新IOC数据库和改进恶意软件相关网络活动的检测能力,来增强其威胁情报能力。然而,由于缺乏可操作的指标或已知的漏洞利用,该威胁目前对系统的机密性、完整性和可用性不构成重大风险。依赖ThreatFox等开源情报源的欧洲组织可以利用这些数据来保持态势感知,但不应期望立即产生运营影响。中等严重性评级表明需要保持警惕,但无需立即采取补救措施。
缓解建议
组织应将ThreatFox的IOC集成到其现有的威胁情报平台和安全信息与事件管理(SIEM)系统中,以增强检测能力。定期更新IOC源并将其与内部日志相关联,可以提高对潜在恶意软件活动的早期预警。网络监控应侧重于与所述类别一致的异常载荷投递模式和可疑网络活动。由于未识别出具体补丁或漏洞,应重点保持强大的终端保护、网络分段和异常检测。安全团队还应持续进行开源情报收集和分析,以便在更广泛的威胁背景中理解这些IOC。与国家和欧洲网络安全中心的合作可以提供额外的见解和验证。
入侵指标(IOCs)
以下是经过整理的IOC列表,包含URL、哈希值、IP地址和域名。
URL
https://exoduwallet.io/exodus.exehttps://sotavpn.shop/http://towerbingobongoboom.com:8080/updater?for=72cfa65519c25a05c2556fcc010387fchttps://smtp.xn--80adx0bza.xn--80aphgvco4b.xn--p1ai/https://theinvestworthy.com/https://romeroaktorpalimpsest.com/16836-near-war-veteran-memorial-parkhttps://steamcommunity.com/profiles/76561199877608270/http://w2li.xyz/healthhttp://w2li.xyz/connhttp://w2li.xyz/8f42fdde60222ec1.nodehttp://w2li.xyz/uploads/09aeb1c5c233f36f.dllhttp://nightlume.xyz/eternalpythonjavascript_linuxdownloads.phphttp://mail.revitpourtous.com:53/filestreamingservice/files/6ea77424-b4f6-4a77http://webmail.revitpourtous.com:53/filestreamingservice/files/6ea77424-b4f6-4a77http://transmagistralcountysystem.info:8080/updater?for=0aa6b9f07a5b27b2069c137c69ec91ebhttp://10.2.10.224:80/jzsf
哈希值 (SHA256示例及端口号)
- 哈希:
01dc573ef5281f437fc225ccb0b47e2b5a54802b6f43798137be90ca5ef3ca52(未知RAT载荷) - 端口/IOC:
2404,9000,465,3790,443,3778,8712,20443,8888,9918,7443,1604,1488,60010,5676,18129,9772,8001,8081,80,20300,2405,31337,3333,62143,4782,8000,4444,34712,62104,8080,11155,808,9200,18100,60000,7000,4483,1337,8990,33311,3652,9812,6597(对应多种恶意软件C2,如Remcos、Cobalt Strike、Meterpreter、XWorm等)
IP地址与端口 (文件类型IOC)
109.123.227.146:240431.56.27.19:90003.85.108.239:465199.101.111.88:379089.111.149.164:44313.213.128.58:44345.13.225.72:3778156.234.145.52:8712156.234.101.168:8712149.104.30.242:20443154.222.18.152:8888107.172.31.101:9918178.16.53.119:888854.169.194.248:7443199.101.109.57:3790139.59.116.230:44391.238.104.82:160487.242.106.13:148862.146.175.106:6001016.163.15.152:5676213.209.143.76:1812987.121.84.60:9772159.65.222.92:8001111.231.11.55:888839.104.81.39:8081115.190.238.185:80204.77.130.20:8888156.234.101.170:8712156.234.101.163:8712144.126.149.104:203003.114.19.102:80103.177.47.147:379054.83.104.76:240545.93.20.50:80195.20.17.33:8888156.234.216.177:8712181.214.100.68:313371.55.101.190:443156.67.26.237:80173.212.250.92:333334.136.172.215:3333188.119.123.91:3333193.161.193.99:6214366.49.168.90:4782194.59.30.9:8000185.11.61.69:900095.113.168.128:74435.255.103.171:8079.45.101.40:4444199.101.111.209:379043.160.202.246:443193.161.193.99:34712193.161.193.99:62104183.136.132.66:808044.252.85.168:443162.243.28.13:1115585.132.57.251:478254.205.202.152:80834.229.140.12:920034.229.140.12:1810034.229.140.12:6000034.229.140.12:700034.229.140.12:8000139.59.116.230:80184.190.169.22:4483209.74.71.43:1337147.45.198.121:8990181.214.100.68:888846.202.152.29:3331151.20.235.140:44375.2.19.211:443118.107.3.249:365291.92.34.48:478223.235.188.181:981223.235.163.219:9812103.48.135.195:981243.240.239.246:9812156.234.152.175:9812103.48.135.198:981223.235.174.10:981223.235.174.18:9812103.48.135.217:981243.240.239.252:981223.235.163.209:9812156.234.152.176:9812216.92.60.88:443132.145.75.68:6597
域名
crum.ripplecask.ruomega.ripplecask.rubmz0.ripplecask.ruvx7.snareplum.rupatch.snareplum.ruhth.snareplum.rurfz.snareplum.rupkxq.gl1tchloam.ruxc2i.gl1tchloam.rusp5.gl1tchloam.rufax.gl1tchloam.rutrace.snare-plum.rupaper.snare-plum.ruqfbmr.snare-plum.rutvlounge.awassociacaodejudosi.orgasos1.neth4o.snare-plum.runova.v0lticrum.ruv7rg.v0lticrum.ruvjsjr.v0lticrum.rumicrosoft.shopmzx.in.netverify.shopmzx.in.netorbit.v0lticrum.rud6gu.ripple-cask.ru75z.ripple-cask.ruglitch.ripple-cask.ruajpl.ripple-cask.rubeta.kettlewisp.rur2k.kettlewisp.ru89pdo.kettlewisp.ruejt0w.kettlewisp.rucask.kettle-wisp.ruodd.kettle-wisp.rufizz.kettle-wisp.rumix.kettle-wisp.ruch.stormf0x.rustorm.stormf0x.rumint.stormf0x.rucloud.stormf0x.rurepositorylinux.site84u.softmint.ru4tqikdkjp.localto.nethellober-62592.portmap.hostsoft.softmint.ruy4uhk.softmint.ruwkt.softmint.ruqtf.raincr5st.rumizh.raincr5st.ruwave.raincr5st.ruromeroaktorpalimpsest.comrelays.buziopoasbubu.topapp.buziopoasbubu.topclothcrib.xyzricestar.xyz9q.raincr5st.ruyminsgdb.cnmyrepis.gd5nr.deepcl0ud.ruwind.deepcl0ud.ruwqu5.deepcl0ud.ruw2li.xyzmcx.deepcl0ud.rucastlerocks.za.combeta.bluef1re.ruclear.bluef1re.rutrace.bluef1re.ruember.bluef1re.ruq5.wild5ky.ru63oi.wild5ky.ru13rv.wild5ky.rufield.wild5ky.rugc31.windst0ne.ru556.windst0ne.ruhfe.windst0ne.rupo1y8.windst0ne.rulj.clearl1ne.ruwt.clearl1ne.runexus.clearl1ne.ruab.clearl1ne.rudelta.rockstorm.ru5wnc.rockstorm.rumist.rockstorm.rucrest.rockstorm.ru4n.darkbreeze.ruhog.darkbreeze.rubyte.darkbreeze.rujq.darkbreeze.rurock.mistybyte.rus2eeka-62143.portmap.hostellu2222-37691.portmap.hostn7xbtfikx.localto.netapp.castlerocks.za.comekmeowprogram.ddns.nettq.mistybyte.ruwhx.mistybyte.ru6ifg.mistybyte.rucirrus.cloudv1be.runimbus5.cloudv1be.rualtos.cloudv1be.ruzen.cloudv1be.rudelta.datash1ft.rustream3.datash1ft.rucache.datash1ft.ruindex.datash1ft.rushard.datash1ft.rubyte.bytefl0w.ruflux2.bytefl0w.rutrace.bytefl0w.runexus.bytefl0w.ruherb.mintst0rm.rubreeze.mintst0rm.ruzeph1r.mintst0rm.rumesh.netw1ng.rulink3.netw1ng.ruhub.netw1ng.ruroute.netw1ng.rugust.windc0de.rucycl1e.windc0de.rudraft.windc0de.rusquall.storml1nk.rubolt.storml1nk.ruarc2.storml1nk.rucrest.storml1nk.rustrat.skytrac5.ruglide.skytrac5.ruapex4.skytrac5.rutrail.skytrac5.ruzeph.skytrac5.rusilk.softdr1ve.rusoulnxc-62104.portmap.hostgrenki2005-34712.portmap.hostcentre-instruction.gl.at.ply.ggfrancaeso-ctrik-51614.portmap.host1.tcp.jp.ngrok.ioplush2.softdr1ve.ruvelvet.softdr1ve.rusatin.softdr1ve.rurime.frostc0re.ruhoar.frostc0re.rufirn3.frostc0re.ruchill.frostc0re.rucobalt.bluest0ne.ruazure2.bluest0ne.ruslate.bluest0ne.runoir.darkp1xel.rugamma.darkp1xel.rudelta5.darkp1xel.rushade.darkp1xel.runoct.darkmint.ruherb2.darkmint.ruglade.darkmint.rufrost.darkmint.ruegqfg1ah2lbhoksjmxz30w==ledge.cliffbright.ruridge3.cliffbright.rubrink.cliffbright.rusun.cliffbright.ruember.f1restorm.ruflare1.f1restorm.rusquall.f1restorm.ruash.f1restorm.rudelta.r1verdusk.rugloam.r1verdusk.rubend.r1verdusk.ruhush2.r1verdusk.rumalware.motchilltv.hownazrej.sa.comshade.shadowm1nt.ruherb5.shadowm1nt.rubasil.shadowm1nt.runoir.shadowm1nt.ruarch.mistybr1dge.ruspan2.mistybr1dge.ru
来源: ThreatFox MISP 信息源
发布日期: 2025年12月14日,星期日
威胁ID: 693f5421b0f1e1d5302e7a41
威胁级别: 中等 (威胁等级: 2, 分布: 3)
类型: 恶意软件 / 开源情报(OSINT)