后台偷跑流量程序及IP列表(持续更新)

1640阅读 0评论2016-10-12 lsstarboy
分类:系统运维

1、微软GWX.exe:微软的升级到windows 10进程,对应KB3035583补丁,此补丁可以卸载,后台偷偷到184.50.87.74下载升级文件。

2、微软联网IP,每次检测到联网时,先解析,对应的IP为:131.107.255.255,如果该IP通,则外网可访问。

3、搜狗的IP:
    1)启动时,首先访问:security.sogou.com,对应IP为4个,在这4个中逐个试:123.125.125.*,61.135.189.*
 2)正常时使用时,连接cdn服务器,联通常用IP:23.126.51.0/24,123.126.113.0/24,111.202.102.0/24,222.132.5.0/24

96.7.54.0/24??
14:43:40.749546 IP 192.168.20.151.63324 > 223.6.6.6.53: 42203+ A? ping.pinyin.sogou.com. (39)
14:43:40.753818 IP 192.168.20.151.68 > 255.255.255.255.67: BOOTP/DHCP, Request from f4:4d:30:74:69:a4, length 300
14:43:40.762649 IP 223.6.6.6.53 > 192.168.20.151.63324: 42203 6/0/0 CNAME ping.sogou.com., CNAME cnc.ping.sogou.com., A 123.126.51.109, A 111.202.102.35, A 123.126.51.104, A 111.202.102.36 (140)
14:43:40.762657 IP 223.6.6.6.53 > 192.168.20.151.62032: 38377 6/0/0 CNAME proxy.sogou.com., CNAME cnc.proxy.sogou.com., A 111.202.102.39, A 111.202.102.38, A 123.126.51.32, A 123.126.51.33 (143)


4、FireFox

(1)启动:先连到 secure.informaction.com,也可能跟noscripts有关,IP主要为:
    69.195.158.194-197
(2)akamai.net,IP为IPv6
(3)证书网站: ,主要IP:
184.50.87.59  184.50.87.8
(4)service.mozilla.com,主要IP:
35.166.212.6  35.161.123.253,  35.162.62.96,  52.24.78.153  52.24,26.116 35.162.26.185  52.24.242.14 35.167.223.122




上一篇:FireFox禁用Flash Player升级和锁定
下一篇:失效的网络打印机会导致photoshop等程序打开变慢