kingToolbox / kingToolbox/WindTerm

安全告警-WindTerm访问的域名被标识为恶意IOC

Open
#3,641 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
C
Stars
32.3k
Forks
2.5k
PR merge metrics
No merged PRs in 30d

Description

Image

Image
程序访问的域名被微步情报标识为恶意IOC

Contributor guide

No contributing guide indexed for this repository

Research direction

The issue provides screenshots and reports that a domain accessed by WindTerm was identified as a malicious IOC by 微步情报. No source file, test, or entry point is named, so first locate the code responsible for outbound domain access and determine which domain is involved. Done means identifying whether the access is expected and documenting or addressing the confirmed cause.

Written by the indexing model from the issue text.

Assessment

Tech stack
c
Domain
security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Quiet
Clarity
Needs clarification
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.