小天管理 发表于 2024年6月23日 发表于 2024年6月23日 原由:昨天晚上的时候,发现微软的 Authenticator 弹出了个莫名其妙的认证请求,一开始疑惑是谁在登录,并且开始回想起本人平常有没有泄露账户,经排查,没泄露过该账户出去,该账户只用于微软家族的产品登录,没用于其他地方,疑似是通过 csrf /数据泄露获取到邮箱号 通过 https://account.live.com/Activity 进行排查,发现两个 IP 登录操作,如下 114.100.82.7 ,尝试登录时间为:6.22 00:08 分操作 111.127.50.125 ,尝试登录时间为:6.23 17:35 分操作 whois 信息如下 114.100.82.7 % [whois.apnic.net] % Whois data copyright terms http://www.apnic.net/db/dbcopyright.html % Information related to '114.96.0.0 - 114.103.255.255' % Abuse contact for '114.96.0.0 - 114.103.255.255' is 'anti-spam@chinatelecom.cn' inetnum: 114.96.0.0 - 114.103.255.255 netname: CHINANET-AH descr: CHINANET Anhui PROVINCE NETWORK descr: China Telecom descr: No.31,jingrong street descr: Beijing 100032 country: CN admin-c: JW89-AP tech-c: JW89-AP abuse-c: AC1573-AP status: ALLOCATED PORTABLE remarks: service provider remarks: -------------------------------------------------------- remarks: To report network abuse, please contact mnt-irt remarks: For troubleshooting, please contact tech-c and admin-c remarks: Report invalid contact via www.apnic.net/invalidcontact remarks: -------------------------------------------------------- mnt-by: APNIC-HM mnt-lower: MAINT-CHINANET-AH mnt-routes: MAINT-CHINANET-AH mnt-irt: IRT-CHINANET-CN last-modified: 2021-06-15T08:06:13Z source: APNIC irt: IRT-CHINANET-CN address: No.31 ,jingrong street,beijing address: 100032 e-mail: anti-spam@chinatelecom.cn abuse-mailbox: anti-spam@chinatelecom.cn admin-c: CH93-AP tech-c: CH93-AP auth: # Filtered remarks: anti-spam@chinatelecom.cn was validated on 2024-04-15 mnt-by: MAINT-CHINANET last-modified: 2024-04-15T01:54:23Z source: APNIC role: ABUSE CHINANETCN address: No.31 ,jingrong street,beijing address: 100032 country: ZZ phone: +000000000 e-mail: anti-spam@chinatelecom.cn admin-c: CH93-AP tech-c: CH93-AP nic-hdl: AC1573-AP remarks: Generated from irt object IRT-CHINANET-CN remarks: anti-spam@chinatelecom.cn was validated on 2024-04-15 abuse-mailbox: anti-spam@chinatelecom.cn mnt-by: APNIC-ABUSE last-modified: 2024-04-15T01:55:05Z source: APNIC person: Jinneng Wang address: 17/F, Postal Building No.120 Changjiang address: Middle Road, Hefei, Anhui, China country: CN phone: +86-551-2659073 fax-no: +86-551-2659287 e-mail: ahdata@189.cn nic-hdl: JW89-AP mnt-by: MAINT-CHINANET-AH last-modified: 2014-02-21T01:19:43Z source: APNIC % This query was served by the APNIC Whois Service version 1.88.25 (WHOIS-JP3) 111.127.50.125 % [whois.apnic.net] % Whois data copyright terms http://www.apnic.net/db/dbcopyright.html % Information related to '111.126.0.0 - 111.127.255.255' % Abuse contact for '111.126.0.0 - 111.127.255.255' is 'anti-spam@chinatelecom.cn' inetnum: 111.126.0.0 - 111.127.255.255 netname: CHINANET-NM descr: CHINANET NeiMengGu province network descr: Data Communication Division descr: China Telecom descr: No.31,jingrong street descr: Beijing 100032 country: CN admin-c: CH93-AP tech-c: CH93-AP abuse-c: AC1573-AP status: ALLOCATED PORTABLE remarks: service provider remarks: -------------------------------------------------------- remarks: To report network abuse, please contact mnt-irt remarks: For troubleshooting, please contact tech-c and admin-c remarks: Report invalid contact via www.apnic.net/invalidcontact remarks: -------------------------------------------------------- notify: cyg@nmgtele.com mnt-by: APNIC-HM mnt-lower: MAINT-CHINANET-NM mnt-routes: MAINT-CHINANET-NM mnt-irt: IRT-CHINANET-CN last-modified: 2021-06-15T08:05:56Z source: APNIC irt: IRT-CHINANET-CN address: No.31 ,jingrong street,beijing address: 100032 e-mail: anti-spam@chinatelecom.cn abuse-mailbox: anti-spam@chinatelecom.cn admin-c: CH93-AP tech-c: CH93-AP auth: # Filtered remarks: anti-spam@chinatelecom.cn was validated on 2024-04-15 mnt-by: MAINT-CHINANET last-modified: 2024-04-15T01:54:23Z source: APNIC role: ABUSE CHINANETCN address: No.31 ,jingrong street,beijing address: 100032 country: ZZ phone: +000000000 e-mail: anti-spam@chinatelecom.cn admin-c: CH93-AP tech-c: CH93-AP nic-hdl: AC1573-AP remarks: Generated from irt object IRT-CHINANET-CN remarks: anti-spam@chinatelecom.cn was validated on 2024-04-15 abuse-mailbox: anti-spam@chinatelecom.cn mnt-by: APNIC-ABUSE last-modified: 2024-04-15T01:55:05Z source: APNIC person: Chinanet Hostmaster nic-hdl: CH93-AP e-mail: anti-spam@chinatelecom.cn address: No.31 ,jingrong street,beijing address: 100032 phone: +86-10-58501724 fax-no: +86-10-58501724 country: CN mnt-by: MAINT-CHINANET last-modified: 2022-02-28T06:53:44Z source: APNIC % This query was served by the APNIC Whois Service version 1.88.25 (WHOIS-JP3) 使用 https://ip.sy/查询的地理位置如下 114.100.82.7: 中国安徽省合肥市瑶海区北二环路,瑶海区香江国际佳元(北二环路南) // 安徽省合肥市瑶海区方庙街道北二环路 144 号香江国际佳元 111.127.50.125: 中国内蒙古自治区呼和浩特市赛罕区蒙中医院巷,赛罕区民望家园 1 区(蒙中医院巷北) // 内蒙古自治区呼和浩特市赛罕区昭乌达路街道民望巷民望家园一区 ASN 均为: AS4134 微步: https://x.threatbook.com/v5/ip/114.100.82.7 https://x.threatbook.com/v5/ip/111.127.50.125 腾讯威胁平台: https://tix.qq.com/search/single?keyword=114.100.82.7& https://tix.qq.com/search/single?keyword=111.127.50.125& 查询总结: 114.100.82.7 ,有恶意样本,没有绑定域名 111.127.50.125 ,有恶意样本,绑定域名(均为 2023-2022 年):hypercachenet.com(微步),supercachenet.com(微步),qc.dolfincdnx.net(腾讯威胁中心反查),jdcloudstatus.net(腾讯威胁中心反查),cachenode.cn(腾讯威胁中心反查),szbdyd.com(腾讯威胁中心反查) (疑似 CDN ?) 111.127.50.125 对应 ICP: hypercachenet.com:北京抖音信息服务有限公司 supercachenet.com:北京微播视界科技有限公司 dolfincdnx.net:贵州白山云科技股份有限公司 jdcloudstatus.net:北京京东叁佰陆拾度电子商务有限公司 cachenode.cn:长沙市摩根网络科技有限公司 szbdyd.com:江西节点技术服务有限公司 两者 IP 只开了 53 TCP + 1041 TCP 疑似是一伙人,不知各位 V 友怎么看待,疑似是国内某个扫号团伙拿到了微软泄露的数据库进行批量登录验证爆破
已推荐帖子