Robot | Path | Permission |
GoogleBot | / | ✔ |
BingBot | / | ✔ |
BaiduSpider | / | ✔ |
YandexBot | / | ✔ |
User-agent: * Disallow: Sitemap: http://dfir.it/sitemap.xml |
Title | dfir |
Description | Recently I was playing with VirusTotal Intelligence and while testing some dynamic behavior queries I stumbled upon this strange PE binary (MD5: |
Keywords | N/A |
WebSite | dfir.it |
Host IP | 104.21.72.14 |
Location | United States |
Euro€354,257
Zuletzt aktualisiert: 2022-07-06 11:09:33
dfir.it ha il rango globale Semrush di 29,877,476. dfir.it ha un valore stimato di € 354,257, in base alle entrate pubblicitarie stimate. dfir.it riceve circa 40,876 visitatori unici ogni giorno. Il suo web server si trova in United States, con indirizzo IP 104.21.72.14. Secondo SiteAdvisor, dfir.it è sicuro da visitare |
Valore di acquisto/vendita | Euro€354,257 |
Entrate giornaliere degli annunci | Euro€328 |
Entrate mensili degli annunci | Euro€9,811 |
Entrate annuali degli annunci | Euro€117,723 |
Visitatori unici giornalieri | 2,726 |
Nota: tutti i valori di traffico e guadagni sono stime. |
Host | Type | TTL | Data |
dfir.it. | A | 300 | IP: 104.21.72.14 |
dfir.it. | A | 300 | IP: 172.67.173.189 |
dfir.it. | AAAA | 300 | IPV6: 2606:4700:3032::ac43:adbd |
dfir.it. | AAAA | 300 | IPV6: 2606:4700:3034::6815:480e |
dfir.it. | NS | 86400 | NS Record: fred.ns.cloudflare.com. |
dfir.it. | NS | 86400 | NS Record: lorna.ns.cloudflare.com. |
dfir.it. | MX | 300 | MX Record: 0 mx-caprica.zoneedit.com. |
dfir.it. | TXT | 300 | TXT Record: v=spf1 mx ip4:23.27.50.10/32 ip4:166.88.18.34/32 ~all |
dfir it! responding to incidents with candied bacon RSS Blog Archives The Supreme Backdoor Factory Feb 26 th , 2019 5:53 pm Recently I was playing with VirusTotal Intelligence and while testing some dynamic behavior queries I stumbled upon this strange PE binary (MD5: 7fce12d2cc785f7066f86314836c95ec ). The file claimed to be an installer for the JXplorer 3.3.1.2, a Java-based “cross platform LDAP browser and editor” as indicated on its official web page . Why was it strange? Mostly because I did not expect an installer for a quite popular LDAP browser to create a scheduled task in order to download and execute PowerShell code from a subdomain hosted by free dynamic DNS provider: I initially planned to keep this write-up short and focus on dissecting suspicious JXplorer binary. However, analyzing the JXplorer binary turned out to be only the first step into the world of backdoored software. Read on → Down the Rabbit Hole With Packaged PowerShell Scripts May 8 th , 2018 4:55 pm Several |
HTTP/1.1 301 Moved Permanently Date: Fri, 29 Oct 2021 11:56:57 GMT Connection: keep-alive Cache-Control: max-age=3600 Expires: Fri, 29 Oct 2021 12:56:57 GMT Location: https://dfir.it/ Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v3?s=eN9Sd9TQPl%2BU0uWd57ohr9w%2FJ2zdJzfHyDuTkjmkojPpRxoRvRIIqUudtzPa%2Ba6xFMKAqYCqc5BlH0GNo0rkJf6%2BdiIPK%2B9k5RzSX7n83yBCQgzXLEt4AhQw"}],"group":"cf-nel","max_age":604800} NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800} X-Content-Type-Options: nosniff Server: cloudflare CF-RAY: 6a5c393d5da02be7-ORD alt-svc: h3=":443"; ma=86400, h3-29=":443"; ma=86400, h3-28=":443"; ma=86400, h3-27=":443"; ma=86400 HTTP/2 200 date: Fri, 29 Oct 2021 11:56:57 GMT content-type: text/html accept-ranges: bytes last-modified: Tue, 26 Feb 2019 20:40:04 GMT cf-cache-status: DYNAMIC expect-ct: max-age=604800, report-uri="https://report-uri.cloudflare.com/cdn-cgi/beacon/expect-ct" report-to: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v3?s=lwTC4%2F2JRCZRb1TCPi6DcaRTFt4U3yqNwHOxN%2BccfIUnIeT7HEDFPPy0G7Y1sQsMyaDIXMrq8qgSh%2B4h9aqp5vCdsxM%2BIJt1roKKrVjlxz1BEIDGwKbgB853"}],"group":"cf-nel","max_age":604800} nel: {"success_fraction":0,"report_to":"cf-nel","max_age":604800} strict-transport-security: max-age=15552000; includeSubDomains x-content-type-options: nosniff server: cloudflare cf-ray: 6a5c393dcd292b1c-ORD alt-svc: h3=":443"; ma=86400, h3-29=":443"; ma=86400, h3-28=":443"; ma=86400, h3-27=":443"; ma=86400 |
Domain: dfir.it Status: clientDeleteProhibited Signed: no Created: 2014-10-08 02:35:18 Last Update: 2020-10-24 00:50:13 Expire Date: 2021-10-08 Registrant Organization: hidden Admin Contact Name: hidden Organization: hidden Technical Contacts Name: hidden Registrar Organization: OVH Name: OVH-REG Web: http://www.ovh.com/welcome DNSSEC: no Nameservers fred.ns.cloudflare.com lorna.ns.cloudflare.com |