不正URLへのアクセス、不正メールの受信
-
メール受信した
弊社お客様0社 URLアクセスした
弊社お客様1社 -
2024/08/08
※2024/08/08 更新
マルウェア感染させると考えられるURLを検知(2024/08/08)
■IoC(※1)
Type: | IOC: | Signature: |
---|---|---|
URL | hxxps://xza[.]donors[.]eucharisticjesus[.]net/orderReview hxxps://alphawatchrmf[.]com/cdn-vs/original[.]js hxxps://alphawatchrmf[.]com/cdn-vs/main[.]php hxxps://alphawatchrmf[.]com/cdn-vs/download[.]php hxxps://veb[.]donors[.]eucharisticjesus[.]net/orderReview hxxps://cqp[.]donors[.]eucharisticjesus[.]net/orderReview hxxps://zead[.]donors[.]eucharisticjesus[.]net/orderReview hxxps://gdhnc[.]donors[.]eucharisticjesus[.]net/orderReview hxxps://myanswerpronto[.]com/cdn-vs/22per[.]php hxxps://velellablue[.]com/cdn-vs/22per[.]php |
FAKEUPDATES |
URL | hxxp://23[.]94[.]247[.]40:7890/OBjb hxxp://210[.]71[.]231[.]3/like[.]exe |
Cobalt Strike |
URL | hxxp://147[.]45[.]44[.]104/prog/66af31c75d213_123p[.]exe hxxp://193[.]32[.]162[.]25/pages/Update[.]exe |
Coinminer |
URL | hxxp://147[.]45[.]44[.]104/prog/66b1c36969eae_main[.]exe hxxp://147[.]45[.]44[.]104/yuop/66b1f63c9578f_doz[.]exe |
Vidar |
URL | hxxp://91[.]92[.]242[.]99/ZqXZaKPIFpdXHH159[.]bin hxxps://www[.]synergyinnovationsgroup[.]com/YuzCf148[.]bin hxxps://mail[.]synergyinnovationsgroup[.]com/YuzCf148[.]bin hxxp://mail[.]synergyinnovationsgroup[.]com/YuzCf148[.]bin hxxp://synergyinnovationsgroup[.]com/YuzCf148[.]bin hxxp://www[.]synergyinnovationsgroup[.]com/YuzCf148[.]bin hxxps://synergyinnovationsgroup[.]com/YuzCf148[.]bin hxxps://www[.]ranchoboscardin[.]com[.]br/dc/Skylightets[.]chm hxxps://www[.]ranchoboscardin[.]com[.]br/dc/Coffer[.]dsp hxxps://ranchoboscardin[.]com[.]br/dc/Asynartete[.]csv hxxps://www[.]ranchoboscardin[.]com[.]br/dc/Antibureaukratiske[.]thn hxxps://ranchoboscardin[.]com[.]br/dc/Elendil[.]sea hxxps://www[.]ranchoboscardin[.]com[.]br/dc/Maalmndene[.]aca hxxps://ranchoboscardin[.]com[.]br/dc/Coffer[.]dsp hxxps://www[.]ranchoboscardin[.]com[.]br/dc/bravurariers[.]jpb hxxps://ranchoboscardin[.]com[.]br/dc/Antibureaukratiske[.]thn hxxps://www[.]ranchoboscardin[.]com[.]br/dc/Dividedness[.]prx hxxps://www[.]ranchoboscardin[.]com[.]br/dc/Asynartete[.]csv hxxps://ranchoboscardin[.]com[.]br/dc/Dividedness[.]prx hxxps://ranchoboscardin[.]com[.]br/dc/bravurariers[.]jpb hxxps://www[.]ranchoboscardin[.]com[.]br/dc/Elendil[.]sea hxxps://ranchoboscardin[.]com[.]br/dc/Maalmndene[.]aca hxxps://www[.]ranchoboscardin[.]com[.]br/dc/Neobotany[.]ttf hxxps://ranchoboscardin[.]com[.]br/dc/Skylightets[.]chm hxxps://www[.]ranchoboscardin[.]com[.]br/dc/Greensand[.]ocx hxxps://ranchoboscardin[.]com[.]br/dc/Neobotany[.]ttf hxxps://ranchoboscardin[.]com[.]br/dc/Frysetjet[.]afm hxxps://ranchoboscardin[.]com[.]br/dc/Greensand[.]ocx hxxps://www[.]ranchoboscardin[.]com[.]br/dc/Frysetjet[.]afm hxxps://www[.]ranchoboscardin[.]com[.]br/dc/Sabellarian[.]xtp hxxps://ranchoboscardin[.]com[.]br/dc/hYIMYakzawECsYBwW56[.]bin hxxps://ranchoboscardin[.]com[.]br/dc/TVLdv58[.]bin hxxps://www[.]ranchoboscardin[.]com[.]br/dc/TVLdv58[.]bin hxxps://ranchoboscardin[.]com[.]br/dc/AMqoYbIPYLOcGMZVU24[.]bin hxxps://www[.]ranchoboscardin[.]com[.]br/dc/hYIMYakzawECsYBwW56[.]bin hxxps://ranchoboscardin[.]com[.]br/dc/yJjosxRDWJDyinhY170[.]bin hxxps://www[.]ranchoboscardin[.]com[.]br/dc/AMqoYbIPYLOcGMZVU24[.]bin hxxps://www[.]ranchoboscardin[.]com[.]br/dc/yJjosxRDWJDyinhY170[.]bin hxxps://www[.]ranchoboscardin[.]com[.]br/dc/uUKNOfmYcaMfWIety113[.]bin hxxps://ranchoboscardin[.]com[.]br/dc/uUKNOfmYcaMfWIety113[.]bin hxxps://ranchoboscardin[.]com[.]br/dc/JdaAc179[.]bin hxxps://www[.]ranchoboscardin[.]com[.]br/dc/JdaAc179[.]bin hxxps://www[.]ranchoboscardin[.]com[.]br/dc/PsPyggxVUPQVS252[.]bin hxxps://ranchoboscardin[.]com[.]br/cs/Smalmed[.]jpb hxxps://www[.]ranchoboscardin[.]com[.]br/cs/Smalmed[.]jpb hxxps://www[.]ranchoboscardin[.]com[.]br/cs/Rrknoglerne[.]asd hxxps://ranchoboscardin[.]com[.]br/cs/Rrknoglerne[.]asd hxxps://www[.]ranchoboscardin[.]com[.]br/cs/yGxZBUGU144[.]bin hxxps://ranchoboscardin[.]com[.]br/cs/yGxZBUGU144[.]bin |
CloudEyE |
URL | hxxp://192[.]3[.]109[.]147/18/sweethoneygirlkisseronlipstosweet[.]gIF hxxp://192[.]3[.]193[.]155/xampp/uhj/picturegreatforeveryonetokissherlips[.]gIF hxxp://192[.]3[.]193[.]155/xampp/uhj/mlm/sincesheiseverbuildnewthingentirelifewithouthavinganythingbczshelovedherwithentiretimetogetmebackwithnewsupportof________girlsheretokissurlip[.]doc hxxp://192[.]3[.]109[.]147/88/mssc/mygirlistotalchangeswithentirethingstobeunderstandeverythingwillbegreatalwaysgreatireallybelievethingsareback________greatthingstotal[.]doc hxxp://192[.]3[.]109[.]147/88/greatbiscutforbabieshealthgreatthings[.]gIF hxxps://sudocumentodepago[.]click/descargas/JULIO2024R[.]txt hxxps://sudocumentodepago[.]click/upload/aa[.]exe hxxps://sudocumentodepago[.]click/upload/dmw[.]exe hxxp://192[.]3[.]193[.]155/xampp/uhj/GDFG[.]txt |
Remcos |
URL | hxxp://80[.]66[.]75[.]214/g8djmsaxA/Plugins/clip64[.]dll hxxp://80[.]66[.]75[.]214/g8djmsaxA/Plugins/cred64[.]dll |
Amadey |
URL | hxxp://45[.]151[.]62[.]96/setup[.]exe | DarkGate |
URL | hxxp://antivirusaway[.]top/pipePhpSecureGeolongpollDbBasedatalifedle[.]php hxxp://241622cm[.]n9shteam1[.]top/PipejavascriptrequestGeoCpulongpollBigloaddefaultbasePublic[.]php |
DCRat |
URL | hxxps://nisvsorupsssazusxehome[.]xyz/MTA2MzQzMjEyMzM3/ | Coper |
URL | hxxp://69[.]166[.]230[.]221/113/sahost[.]exe hxxp://69[.]166[.]230[.]221/xampp/ibnet/IEnetworks[.]hta hxxps://pastecode[.]dev/raw/baskrfz1/paste1[.]txt hxxp://192[.]210[.]150[.]33/88/sweetdresswearwithgirlstyle[.]gIF hxxp://192[.]210[.]150[.]33/88/mssc/wecreatednewentertainmenttounderstandhowperfectyourlovertogetmebackwithenitrethingstogbeworkwithentirenetwork_________sheismygirlwhoilovedtruly[.]doc |
Formbook |
URL | hxxp://147[.]45[.]44[.]104/yuop/66b274e0e1b95_shapr3D[.]exe | Lumma Stealer |
URL | hxxp://91[.]92[.]243[.]78:8080/TARGETS/Pedro_1/Reader_en_install[.]exe hxxp://91[.]92[.]243[.]78:8080/PureHvnc/Reader_en_install[.]exe hxxp://91[.]92[.]243[.]78:8080/hvnc[.]exe |
PureCrypter |
URL | hxxp://103[.]45[.]247[.]13/Aqua[.]arm4 hxxp://103[.]45[.]247[.]13/Aqua[.]arm5 |
Bashlite |
URL | hxxp://185[.]215[.]113[.]19/inc/Cbmefxrmnv[.]exe | SystemBC |
URL | hxxp://185[.]215[.]113[.]19/inc/clsid[.]exe hxxp://mail[.]synergyinnovationsgroup[.]com/IMjqggfGsjOkXDuwwaMHlATCTLUF214[.]bin hxxps://mail[.]synergyinnovationsgroup[.]com/IMjqggfGsjOkXDuwwaMHlATCTLUF214[.]bin hxxp://www[.]synergyinnovationsgroup[.]com/IMjqggfGsjOkXDuwwaMHlATCTLUF214[.]bin hxxps://www[.]synergyinnovationsgroup[.]com/IMjqggfGsjOkXDuwwaMHlATCTLUF214[.]bin hxxp://synergyinnovationsgroup[.]com/IMjqggfGsjOkXDuwwaMHlATCTLUF214[.]bin hxxps://synergyinnovationsgroup[.]com/IMjqggfGsjOkXDuwwaMHlATCTLUF214[.]bin hxxps://sudocumentodepago[.]click/upload/aa[.]vbs hxxps://sudocumentodepago[.]click/upload/dmw[.]vbs hxxps://107[.]172[.]31[.]19/88/sahost[.]exe hxxps://107[.]172[.]31[.]19/xampp/ku/88[.]hta hxxp://107[.]172[.]31[.]19/xampp/ku/88[.]hta hxxp://107[.]172[.]31[.]19/88/sahost[.]exe |
Agent Tesla |
URL | hxxp://185[.]215[.]113[.]19/inc/systems[.]exe | RedLine Stealer |
URL | hxxp://192[.]3[.]176[.]138/106/sahost[.]exe hxxp://192[.]3[.]176[.]138/105/sahost[.]exe hxxp://192[.]3[.]176[.]138/xampp/ozon/oz/106[.]hta hxxp://192[.]3[.]176[.]138/60/sahost[.]exe hxxp://198[.]46[.]174[.]139/95/wahost[.]exe hxxp://198[.]46[.]174[.]139/50/regasm[.]exe hxxp://192[.]3[.]176[.]138/55/sahost[.]exe hxxp://192[.]3[.]176[.]138/95/sahost[.]exe hxxp://192[.]3[.]176[.]138/70/sahost[.]exe hxxp://198[.]46[.]174[.]139/60/regasm[.]exe |
Snake Keylogger |
URL | hxxp://87[.]106[.]114[.]72/rat[.]exe | Quasar RAT |
URL | hxxps://ranchoboscardin[.]com[.]br/dc/xmay[.]txt hxxps://www[.]ranchoboscardin[.]com[.]br/dc/xmay[.]txt |
XWorm |
URL | hxxps://didsit[.]com/data[.]php | NetSupportManager RAT |