全部
最新采集的全量资讯流
-
银狐IOC情报 批次#20260604065012
银狐恶意软件IOC情报新增: 1个路径。数据时间: 2026-06-03 21:03 UTC
银狐恶意软件IOC情报新增: 1个路径。数据时间: 2026-06-03 21:03 UTC银狐恶意软件IOC情报新增: 1个路径。数据时间: 2026-06-03 21:03 UTC扩展字段
{ "batch_id": "20260604065012", "domains": [], "file_paths": [ { "file_name": "icsvcext.dll", "path": "C:\\Users\\Administrator\\AppData\\Local\\Microsoft\\Windows\\UPPS\\icsvcext.dll" } ], "hashes": [], "ips": [], "stats": { "new_domains": 0, "new_file_paths": 1, "new_hashes": 0, "new_ips": 0, "total_new": 1 }, "update_time": "2026-06-03T21:03:27.441000+00:00", "update_time_ms": 1780520607441 } -
银狐IOC情报 批次#20260604055025
银狐恶意软件IOC情报新增: 5个IP, 3个域名, 30个样本, 47个路径。数据时间: 2026-06-03 21:03 UTC
银狐恶意软件IOC情报新增: 5个IP, 3个域名, 30个样本, 47个路径。数据时间: 2026-06-03 21:03 UTC银狐恶意软件IOC情报新增: 5个IP, 3个域名, 30个样本, 47个路径。数据时间: 2026-06-03 21:03 UTC扩展字段
{ "batch_id": "20260604055025", "domains": [ { "value": "qweaap.icu" }, { "value": "yvhphtmdwvmt.net" }, { "value": "recdataoneveter.cc" } ], "file_paths": [ { "file_name": "Paint.exe", "path": "C:\\Users\\Administrator\\AppData\\Roaming\\Paint.exe" }, { "file_name": "winieehi.exe", "path": "C:\\Users\\Administrator\\AppData\\Local\\Temp\\winieehi.exe" }, { "file_name": "tmp2AAE.tmp", "path": "C:\\Users\\Administrator\\AppData\\Local\\Temp\\tmp2AAE.tmp" }, { "file_name": "owxyw.exe", "path": "C:\\Users\\Administrator\\AppData\\Local\\Temp\\owxyw.exe" }, { "file_name": "winuhadvh.exe", "path": "C:\\Users\\Administrator\\AppData\\Local\\Temp\\winuhadvh.exe" }, { "file_name": "wecutil.exe", "path": "C:\\Users\\Administrator\\AppData\\Roaming\\Microsoft\\Windows\\dllcache\\wecutil.exe" }, { "file_name": "oloxym.exe", "path": "C:\\Users\\Administrator\\AppData\\Local\\Temp\\oloxym.exe" }, { "file_name": "tmp1E1B.tmp", "path": "C:\\Users\\Administrator\\AppData\\Local\\Temp\\tmp1E1B.tmp" }, { "file_name": "winlawm.exe", "path": "C:\\Users\\Administrator\\AppData\\Local\\Temp\\winlawm.exe" }, { "file_name": "winsoel.exe", "path": "C:\\Users\\Administrator\\AppData\\Local\\Temp\\winsoel.exe" }, { "file_name": "winqtnoo.exe", "path": "C:\\Users\\Administrator\\AppData\\Local\\Temp\\winqtnoo.exe" }, { "file_name": "xtbmpv.exe", "path": "C:\\Users\\Administrator\\AppData\\Local\\Temp\\xtbmpv.exe" }, { "file_name": "wintdls.exe", "path": "C:\\Users\\Administrator\\AppData\\Local\\Temp\\wintdls.exe" }, { "file_name": "winsgxrp.exe", "path": "C:\\Users\\Administrator\\AppData\\Local\\Temp\\winsgxrp.exe" }, { "file_name": "tmp66D.tmp", "path": "C:\\Users\\Administrator\\AppData\\Local\\Temp\\tmp66D.tmp" }, { "file_name": "winlejtp.exe", "path": "C:\\Users\\Administrator\\AppData\\Local\\Temp\\winlejtp.exe" }, { "file_name": "net.exe", "path": "C:\\Users\\Administrator\\AppData\\Roaming\\Microsoft\\Windows\\dllcache\\net.exe" }, { "file_name": "tmp4B94.tmp", "path": "C:\\Users\\Administrator\\AppData\\Local\\Temp\\tmp4B94.tmp" }, { "file_name": "rnckrn.exe", "path": "C:\\Users\\Administrator\\AppData\\Local\\Temp\\rnckrn.exe" }, { "file_name": "rinv.exe", "path": "C:\\Users\\Administrator\\AppData\\Local\\Temp\\rinv.exe" }, { "file_name": "icsvcext.dll", "path": "C:\\Users\\Admin\\AppData\\Local\\Microsoft\\Windows\\UPPS\\icsvcext.dll" }, { "file_name": "tmp7340.tmp", "path": "C:\\Users\\Administrator\\AppData\\Local\\Temp\\tmp7340.tmp" }, { "file_name": "winwulid.exe", "path": "C:\\Users\\Administrator\\AppData\\Local\\Temp\\winwulid.exe" }, { "file_name": "tmp58E2.tmp", "path": "C:\\Users\\Administrator\\AppData\\Local\\Temp\\tmp58E2.tmp" }, { "file_name": "oulg.exe", "path": "C:\\Users\\Administrator\\AppData\\Local\\Temp\\oulg.exe" }, { "file_name": "bqtwdr.exe", "path": "C:\\Users\\Administrator\\AppData\\Local\\Temp\\bqtwdr.exe" }, { "file_name": "winknlh.exe", "path": "C:\\Users\\Administrator\\AppData\\Local\\Temp\\winknlh.exe" }, { "file_name": "typeperf.exe", "path": "C:\\Users\\Administrator\\AppData\\Roaming\\Microsoft\\Windows\\dllcache\\typeperf.exe" }, { "file_name": "tmp74F5.tmp", "path": "C:\\Users\\Administrator\\AppData\\Local\\Temp\\tmp74F5.tmp" }, { "file_name": "verclsid.exe", "path": "C:\\Users\\Administrator\\AppData\\Roaming\\Microsoft\\Windows\\dllcache\\verclsid.exe" }, { "file_name": "tmpE24B.tmp", "path": "C:\\Users\\Administrator\\AppData\\Local\\Temp\\tmpE24B.tmp" }, { "file_name": "winaqcg.exe", "path": "C:\\Users\\Administrator\\AppData\\Local\\Temp\\winaqcg.exe" }, { "file_name": "winswqa.exe", "path": "C:\\Users\\Administrator\\AppData\\Local\\Temp\\winswqa.exe" }, { "file_name": "winnqmpnh.exe", "path": "C:\\Users\\Administrator\\AppData\\Local\\Temp\\winnqmpnh.exe" }, { "file_name": "InputSwitchToastHandler.exe", "path": "C:\\Users\\Administrator\\AppData\\Roaming\\Microsoft\\Windows\\dllcache\\InputSwitchToastHandler.exe" }, { "file_name": "winsrlyxi.exe", "path": "C:\\Users\\Administrator\\AppData\\Local\\Temp\\winsrlyxi.exe" }, { "file_name": "3kkeqsn1j18w.tmp", "path": "C:\\Users\\Administrator\\AppData\\Local\\Temp\\XYZABCDE\\3kkeqsn1j18w.tmp" }, { "file_name": "winrcuhc.exe", "path": "C:\\Users\\Administrator\\AppData\\Local\\Temp\\winrcuhc.exe" }, { "file_name": "winxqtdbj.exe", "path": "C:\\Users\\Administrator\\AppData\\Local\\Temp\\winxqtdbj.exe" }, { "file_name": "winnbmly.exe", "path": "C:\\Users\\Administrator\\AppData\\Local\\Temp\\winnbmly.exe" }, { "file_name": "netsh.exe", "path": "C:\\Users\\Administrator\\AppData\\Roaming\\Microsoft\\Windows\\dllcache\\netsh.exe" }, { "file_name": "aspb.exe", "path": "C:\\Users\\Administrator\\AppData\\Local\\Temp\\aspb.exe" }, { "file_name": "winvskqc.exe", "path": "C:\\Users\\Administrator\\AppData\\Local\\Temp\\winvskqc.exe" }, { "file_name": "DesktopLayer.exe", "path": "C:\\Program Files (x86)\\Microsoft\\DesktopLayer.exe" }, { "file_name": "tmp4BE2.tmp", "path": "C:\\Users\\Administrator\\AppData\\Local\\Temp\\tmp4BE2.tmp" }, { "file_name": "Combo_52729650.exe", "path": "C:\\ProgramData\\Manten\\Combo_52729650.exe" }, { "file_name": "winwosv.exe", "path": "C:\\Users\\Administrator\\AppData\\Local\\Temp\\winwosv.exe" } ], "hashes": [ { "md5": null, "sha1": null, "sha256": "40937a89dfdee3ebe55917a801d399833cd1943904962ee56be7f823d94732f4" }, { "md5": null, "sha1": null, "sha256": "3ae3e15b8b55f83d702e686a0bbd7c13c1684830cde4eeb90a36669f920ed98a" }, { "md5": null, "sha1": null, "sha256": "01e3eae81b157722840ce4616c6978cc3e6ba94642498032e36712c5e53982b4" }, { "md5": null, "sha1": null, "sha256": "6ba9494d37a814e08fe1b102dbdf1fa7797e38b92810f7bcdbe176b8b0cac417" }, { "md5": null, "sha1": null, "sha256": "79613f5ea0dc406c7f8f72d4943860b1c69b31287e98e23547f098a400a6cf5e" }, { "md5": null, "sha1": null, "sha256": "be57b064edeb18b2ddd66097e89ee61e563107482769dcdcf5cc220b3d83214a" }, { "md5": null, "sha1": null, "sha256": "8e9434ed8e0f08ad94d49fe0f482c34e3ba2183556bb66c5dcc94dcee9e6cd21" }, { "md5": null, "sha1": null, "sha256": "d56990f71a46b4de6a83151d425c9684f5d51dabffb494cb4fabd64a6323c130" }, { "md5": null, "sha1": null, "sha256": "36e089d04f566b866925af2e120d48c9fd5ecaa5245204bfb96914966af073fc" }, { "md5": null, "sha1": null, "sha256": "fcd848e99670cef7a51bf0386be83b58c00d7a6586acfabe334bbf03f6b08dda" }, { "md5": null, "sha1": null, "sha256": "3da5d2be709886e9471ad0d383f0e11ecab27b4cad64b5d66295e35f679143b9" }, { "md5": null, "sha1": null, "sha256": "487b05cf51dbb11cee298ea02b6340dd88c95aab4d8829669b2efd00744a8115" }, { "md5": null, "sha1": null, "sha256": "750c76d801281c8129556c188bc83180d97369b446f29b1677dc6539f642f117" }, { "md5": null, "sha1": null, "sha256": "e5c5873347fc6bcd3f73c9908e0d71211e7f889ca118217482cc0b5d64626651" }, { "md5": null, "sha1": null, "sha256": "660a5494cc6232d4fec9b5e2a592cedc4d9cf5007feb5d209cc996a0f392c130" }, { "md5": null, "sha1": null, "sha256": "b6c470dfefa5b2a790fd93533be78d226846db31ab8c51a04610e6d553e9d316" }, { "md5": null, "sha1": null, "sha256": "490f027c658e0609b266360ba1e8bae2191da93e05bf11c04e0b2311cf3dfd27" }, { "md5": null, "sha1": null, "sha256": "dbcfdf7a243f0f33f8ca50927738bd380607fafef248879360c0fbf52a0d9209" }, { "md5": null, "sha1": null, "sha256": "0541980d6dce0bc093a95497348ec206efab98f248e8508ae4361e1af982f61f" }, { "md5": null, "sha1": null, "sha256": "f8e250362ada375fbaeb0970ae8f8106816130611d90ea3eb707f5f31bdfb90a" }, { "md5": null, "sha1": null, "sha256": "e3cb70f83edd290419cd5db20322f6dc3305e364c47e8f2fdb1a12daac662a3a" }, { "md5": null, "sha1": null, "sha256": "565c8d1496ecf75c79736bcf86725f455b4c3498ff2b360bc39afa941a956266" }, { "md5": null, "sha1": null, "sha256": "ba46f420a51c21ced4a9d3088426888e9266f8a16ca087405d6f6c7801b24050" }, { "md5": null, "sha1": null, "sha256": "833d78df4af2c9c058219f7ec03df614ef2cbf1d1f54ae76f1e6737c79b2ac02" }, { "md5": null, "sha1": null, "sha256": "b2970a91be73b144ccb6b1d298b02693e69fc0198a0f52fac37d0bc5bbd7fc97" }, { "md5": null, "sha1": null, "sha256": "75626543dcce6a384e79373081a48e2a0375810a7d676b97fb16b238114035c6" }, { "md5": null, "sha1": null, "sha256": "3606c7f375a4fe6721aeb2f90241510383bc8d09e7667b7760812bc2a53a7a85" }, { "md5": null, "sha1": null, "sha256": "b112d6d2fa2f3330bfe15a5692eb01f3038e5b96571c9a32626e8f2a67c4734f" }, { "md5": null, "sha1": null, "sha256": "3abc086320a3a0f7b9121024aa64330ce4530a5e57a8fb3efb2bdca4e70b760d" }, { "md5": null, "sha1": null, "sha256": "cab58605080deda1ee16b980a2894300afb3fb0ffa25852700d7f5153b7b2b6d" } ], "ips": [ { "value": "185.203.39.134" }, { "value": "43.99.56.192" }, { "value": "31.57.65.118" }, { "value": "8.218.252.45" }, { "value": "27.124.44.140" } ], "stats": { "new_domains": 3, "new_file_paths": 47, "new_hashes": 30, "new_ips": 5, "total_new": 85 }, "update_time": "2026-06-03T21:03:27.441000+00:00", "update_time_ms": 1780520607441 } -
SeeWriteHear by cmdorganization
SeeWriteHear specializes in providing print and digital accessibility solutions, including Braille, large print, and web accessibility services. Their offerings cater to various industries such as education, government, and publishing, ensuring compliance with usability standards. The company focuses on innovative technology to enhance accessibility for indi…
SeeWriteHear specializes in providing print and digital accessibility solutions, including Braille, large print, and web accessibility services. Their offerings cater to various industries such as education, government, and publishing, ensuring compliance with usability standards. The company focuses on innovative technology to enhance accessibility for indiSeeWriteHear specializes in providing print and digital accessibility solutions, including Braille, large print, and web accessibility services. Their offerings cater to various industries such as education, government, and publishing, ensuring compliance with usability standards. The company focuses on innovative technology to enhance accessibility for individuals with disabilities. With a commitment to information equality, SeeWriteHear serves clients by creating accessible content and providing consulting and training services.扩展字段
{ "activity": "Technology", "attack_date": "2026-06-03T20:50:11.638231+00:00", "country": "GB", "discovered_at": "2026-06-03T20:50:13.391240+00:00", "duplicate_count": 0, "group": "cmdorganization", "permalink": "https://www.ransomware.live/id/U2VlV3JpdGVIZWFyQGNtZG9yZ2FuaXphdGlvbg==", "post_url": null, "press": null, "screenshot": null, "website": "www.seewritehear.com" } -
CVE-2026-37700 | MaxSite CMS 109.2 admin_page cross site scripting
A vulnerability classified as <a href="https://vuldb.com/kb/risk">problematic</a> was found in <a href="https://vuldb.com/product/maxsite:cms">MaxSite CMS 109.2</a>. This vulnerability affects the function <code>admin_page</code>. Such manipulation leads to cross site scripting. This vulnerability is listed as <a href="https://vuldb.com/cve/CVE-2026-37700">…
A vulnerability classified as <a href="https://vuldb.com/kb/risk">problematic</a> was found in <a href="https://vuldb.com/product/maxsite:cms">MaxSite CMS 109.2</a>. This vulnerability affects the function <code>admin_page</code>. Such manipulation leads to cross site scripting. This vulnerability is listed as <a href="https://vuldb.com/cve/CVE-2026-37700">A vulnerability classified as <a href="https://vuldb.com/kb/risk">problematic</a> was found in <a href="https://vuldb.com/product/maxsite:cms">MaxSite CMS 109.2</a>. This vulnerability affects the function <code>admin_page</code>. Such manipulation leads to cross site scripting. This vulnerability is listed as <a href="https://vuldb.com/cve/CVE-2026-37700">CVE-2026-37700</a>. The attack may be performed from remote. There is no available exploit.扩展字段
{ "raw_pub_date": "Wed, 03 Jun 2026 22:45:31 +0200" } -
CVE-2026-50033 | Acronis DeviceLock DLP prior 9.0.15051.93227 uncontrolled search path
A vulnerability classified as <a href="https://vuldb.com/kb/risk">critical</a> has been found in <a href="https://vuldb.com/product/acronis:devicelock_dlp">Acronis DeviceLock DLP</a>. This affects an unknown part. This manipulation causes uncontrolled search path. This vulnerability is tracked as <a href="https://vuldb.com/cve/CVE-2026-50033">CVE-2026-50033…
A vulnerability classified as <a href="https://vuldb.com/kb/risk">critical</a> has been found in <a href="https://vuldb.com/product/acronis:devicelock_dlp">Acronis DeviceLock DLP</a>. This affects an unknown part. This manipulation causes uncontrolled search path. This vulnerability is tracked as <a href="https://vuldb.com/cve/CVE-2026-50033">CVE-2026-50033A vulnerability classified as <a href="https://vuldb.com/kb/risk">critical</a> has been found in <a href="https://vuldb.com/product/acronis:devicelock_dlp">Acronis DeviceLock DLP</a>. This affects an unknown part. This manipulation causes uncontrolled search path. This vulnerability is tracked as <a href="https://vuldb.com/cve/CVE-2026-50033">CVE-2026-50033</a>. The attack is restricted to local execution. No exploit exists. It is recommended to upgrade the affected component.扩展字段
{ "raw_pub_date": "Wed, 03 Jun 2026 22:44:48 +0200" } -
CVE-2026-44682 | Acronis DeviceLock DLP prior 9.0.15051.93227 uncontrolled search path
A vulnerability described as <a href="https://vuldb.com/kb/risk">critical</a> has been identified in <a href="https://vuldb.com/product/acronis:devicelock_dlp">Acronis DeviceLock DLP</a>. Affected by this issue is some unknown functionality. The manipulation results in uncontrolled search path. This vulnerability is identified as <a href="https://vuldb.com/…
A vulnerability described as <a href="https://vuldb.com/kb/risk">critical</a> has been identified in <a href="https://vuldb.com/product/acronis:devicelock_dlp">Acronis DeviceLock DLP</a>. Affected by this issue is some unknown functionality. The manipulation results in uncontrolled search path. This vulnerability is identified as <a href="https://vuldb.com/A vulnerability described as <a href="https://vuldb.com/kb/risk">critical</a> has been identified in <a href="https://vuldb.com/product/acronis:devicelock_dlp">Acronis DeviceLock DLP</a>. Affected by this issue is some unknown functionality. The manipulation results in uncontrolled search path. This vulnerability is identified as <a href="https://vuldb.com/cve/CVE-2026-44682">CVE-2026-44682</a>. The attack is only possible with local access. There is not any exploit available. Upgrading the affected component is recommended.扩展字段
{ "raw_pub_date": "Wed, 03 Jun 2026 22:44:15 +0200" } -
CVE-2026-44609 | Acronis DeviceLock DLP prior 9.0.15051.93227 uncontrolled search path
A vulnerability marked as <a href="https://vuldb.com/kb/risk">critical</a> has been reported in <a href="https://vuldb.com/product/acronis:devicelock_dlp">Acronis DeviceLock DLP</a>. Affected by this vulnerability is an unknown functionality. The manipulation leads to uncontrolled search path. This vulnerability is referenced as <a href="https://vuldb.com/c…
A vulnerability marked as <a href="https://vuldb.com/kb/risk">critical</a> has been reported in <a href="https://vuldb.com/product/acronis:devicelock_dlp">Acronis DeviceLock DLP</a>. Affected by this vulnerability is an unknown functionality. The manipulation leads to uncontrolled search path. This vulnerability is referenced as <a href="https://vuldb.com/cA vulnerability marked as <a href="https://vuldb.com/kb/risk">critical</a> has been reported in <a href="https://vuldb.com/product/acronis:devicelock_dlp">Acronis DeviceLock DLP</a>. Affected by this vulnerability is an unknown functionality. The manipulation leads to uncontrolled search path. This vulnerability is referenced as <a href="https://vuldb.com/cve/CVE-2026-44609">CVE-2026-44609</a>. The attack can only be performed from a local environment. No exploit is available. It is suggested to upgrade the affected component.扩展字段
{ "raw_pub_date": "Wed, 03 Jun 2026 22:43:39 +0200" } -
CVE-2026-42061 | Acronis DeviceLock DLP 9.0.15051.93227 unnecessary privileges
A vulnerability labeled as <a href="https://vuldb.com/kb/risk">critical</a> has been found in <a href="https://vuldb.com/product/acronis:devicelock_dlp">Acronis DeviceLock DLP 9.0.15051.93227</a>. Affected is an unknown function. Executing a manipulation can lead to execution with unnecessary privileges. The identification of this vulnerability is <a href="…
A vulnerability labeled as <a href="https://vuldb.com/kb/risk">critical</a> has been found in <a href="https://vuldb.com/product/acronis:devicelock_dlp">Acronis DeviceLock DLP 9.0.15051.93227</a>. Affected is an unknown function. Executing a manipulation can lead to execution with unnecessary privileges. The identification of this vulnerability is <a href="A vulnerability labeled as <a href="https://vuldb.com/kb/risk">critical</a> has been found in <a href="https://vuldb.com/product/acronis:devicelock_dlp">Acronis DeviceLock DLP 9.0.15051.93227</a>. Affected is an unknown function. Executing a manipulation can lead to execution with unnecessary privileges. The identification of this vulnerability is <a href="https://vuldb.com/cve/CVE-2026-42061">CVE-2026-42061</a>. The attack can only be executed locally. There is no exploit available. The affected component should be upgraded.扩展字段
{ "raw_pub_date": "Wed, 03 Jun 2026 22:42:54 +0200" }