金眼狗团伙曾多次利用水坑网站托管恶意软件安装包,向受害者设备植入木马,使用过 .NET、C++、Go、Delphi 等语言开发恶意软件,攻击样本的整体免杀水平较高
主要软件:
- Telegram中文版安装包
- 快连VPN
- Potato社交软件
- WPS办公软件
- 搜狗输入法
- Opera浏览器
- Chrome浏览器
- Tor
- 爱思助手
- Team Viewer
- ToDesk
- 穿梭VPN
- 快帆VPN
- 飞连VPN
- v2rayN
- 爱加速
- TradingView投资软件
- 旋风转换器
有问题的网址(水坑域名和恶意下载服务器):
- www.telegramkx[.]com
- i4.com[.]vn
- aisizhushou.com
- cn-wps.com
- fl-vpn.com
- cs-vpn.com
- transocks-vpn.com
- gategw.com
- zh-aijiasu.com
- ajsvpn.com
- zh-potato.com
- potato-zh.com
- opuaera.com
- sogou-shurufa.com
- todiskcn.com
- todisk-zh.com
- v2raynos[.]com
- zh-csvpn.com
- zh-mexc.com
- chinese-whatsapp.com
- apps-whatsapp.com
- zhcn-whatsapp.org
- downloads-whatsapp.com
- windows-whatsapp.com
- china-whatsapp.com
- telegramca.com
- china-telegram.im
- www-telegram.org
- telegrampw.com
- telegramlo.com
- telegramqo.com
- telegramkx.com
- telegramox.com
- telegram-apk.com
- telegram-desktop.org
- qobddze.cn
- oeokx.cn
- okx-client.cn
- zh-okex.cn
- zh-gateio.cn
- aicoinzh.com
- tradingview-en.com
- ayicoin.com
- aicoims.com
- nbxieheng.cn
- line-zhcn.com
- www-wps.org
恶意下载服务器:
- www.heimao-136.com
- www.heimao-134.com
- www.heimao-132.com
- www.heimao-131.com
- zhcn.down-cdn.com
- zh.seacdndown.com
- cdn-down.cdndown.shop
- tlelga929.oss-cn-hongkong.aliyuncs.com
- mmm3.oss-cn-hongkong.aliyuncs.com
- tgurl.cc
- dshjfdf.oss-cn-hongkong.aliyuncs.com
- trdgh.oss-cn-hongkong.aliyuncs.com
- tgram1025.oss-cn-hongkong.aliyuncs.com
- uifdt6.oss-cn-hongkong.aliyuncs.com
- oss-kuaisu.oss-cn-hongkong.aliyuncs.com
- teleram914.oss-cn-hongkong.aliyuncs.com
- assau.oss-ap-southeast-7.aliyuncs.com
- downs-hao123.top
- 38.12.22.84
- 38.12.20.98
- paopaoliaotian.s3.ap-east-1.amazonaws.com
- softs-downloads.oss-ap-southeast-1.aliyuncs.com