威胁分析:Turla APT所用的多个IP隶属多家卫星服务运营商

  193.220.55.6

  83.229.62.212

  169.255.100.152

  113.208.81.33

  82.146.174.40

  82.146.175.52

  113.208.81.48

  83.229.75.141

  77.246.76.19

  209.239.79.121

  209.239.79.125

  217.194.150.31

  82.146.166.58

  217.194.149.111

  169.255.100.122

  169.255.101.65

  113.208.81.55

  217.8.36.239

  83.229.62.210

  82.146.175.48

  82.146.175.69

  41.203.79.74

  77.73.187.223

  217.194.150.22

  域名:

  trytowin[.]ignorelist[.]com treesofter[.]mooo[.]com sportinfo[.]yourtrap[.]com profound[.]zzux[.]com badget[.]ignorelist[.]com norwaynews[.]mooo[.]com dellservice[.]publicvm[.]com priceline[.]publicvm[.]com forumgeek[.]zzux[.]com mouses[.]strangled[.]net

  SHA-1:

 

  f415844680ed9118ea74e0c7712b35044f0cc20d