不正URLへのアクセス、不正メールの受信
-
メール受信した
弊社お客様0社 URLアクセスした
弊社お客様1社 -
2024/10/16
※2024/10/16 更新
マルウェア感染させると考えられるURLを検知(2024/10/16)
■IoC(※1)
Type: | IOC: | Signature: |
---|---|---|
URL | hxxp://89[.]110[.]93[.]210/eternalUpdate/vmUpdateauthUniversalwordpressDle[.]php | DCRat |
URL | hxxp://h2zq[.]shop/sRNbiUpn/UOLneWlcZGknmye7[.]bin hxxp://h2zq[.]shop/vkkfxjzd/Arrantly[.]dsp hxxps://promenter[.]rs/XWpZCkLt231[.]bin hxxps://promenter[.]rs/Dipodid[.]pfm hxxp://e4b1[.]shop/NcxnhVyB/Bugthvlenes[.]xtp hxxp://e4b1[.]shop/IopbjShW/OkxrjPAYllWRxqB113[.]bin hxxps://apslline[.]com/Motocrossbanerne37[.]pif hxxps://apslline[.]com/LfGiMdRCMSvlQHkIpf170[.]bin |
CloudEyE |
URL | hxxp://assets[.]gziraq[.]com/css/54f0fa329a53[.]exe hxxp://178[.]63[.]148[.]7/09f5d6b1c37d35fd/nss3[.]dll hxxp://178[.]63[.]148[.]7/09f5d6b1c37d35fd/msvcp140[.]dll hxxp://178[.]63[.]148[.]7/09f5d6b1c37d35fd/freebl3[.]dll hxxp://178[.]63[.]148[.]7/09f5d6b1c37d35fd/sqlite3[.]dll hxxp://178[.]63[.]148[.]7/09f5d6b1c37d35fd/vcruntime140[.]dll hxxp://178[.]63[.]148[.]7/09f5d6b1c37d35fd/mozglue[.]dll hxxp://178[.]63[.]148[.]7/09f5d6b1c37d35fd/softokn3[.]dll hxxp://178[.]22[.]31[.]96/b65e93b2e3fe9102/softokn3[.]dll hxxp://178[.]22[.]31[.]96/b65e93b2e3fe9102/mozglue[.]dll hxxp://178[.]22[.]31[.]96/b65e93b2e3fe9102/freebl3[.]dll hxxp://178[.]22[.]31[.]96/b65e93b2e3fe9102/sqlite3[.]dll hxxp://185[.]244[.]219[.]195/ac45f2162b48380d/nss3[.]dll hxxp://178[.]22[.]31[.]96/b65e93b2e3fe9102/vcruntime140[.]dll hxxp://185[.]244[.]219[.]195/ac45f2162b48380d/msvcp140[.]dll hxxp://185[.]244[.]219[.]195/ac45f2162b48380d/freebl3[.]dll hxxp://178[.]22[.]31[.]96/b65e93b2e3fe9102/msvcp140[.]dll hxxp://185[.]244[.]219[.]195/ac45f2162b48380d/softokn3[.]dll hxxp://178[.]22[.]31[.]96/b65e93b2e3fe9102/nss3[.]dll hxxp://185[.]244[.]219[.]195/ac45f2162b48380d/vcruntime140[.]dll hxxp://185[.]244[.]219[.]195/ac45f2162b48380d/sqlite3[.]dll hxxp://185[.]244[.]219[.]195/ac45f2162b48380d/mozglue[.]dll hxxp://45[.]66[.]248[.]237/9e6547173a597645[.]php hxxp://91[.]211[.]248[.]13/316ea06a752c4625[.]php |
Stealc |
URL | hxxp://152[.]201[.]184[.]91/segura[.]vbs hxxp://152[.]201[.]184[.]91/asegurar[.]vbs hxxp://149[.]28[.]242[.]23/445/cb/nicelooknicegirlffriend[.]hta hxxp://185[.]29[.]11[.]111/455/eb/seethebestthingswithmegreatdays[.]hta hxxp://103[.]131[.]130[.]248/355/nm/nicesweetgirlsareeverydayonme[.]hta hxxp://149[.]28[.]90[.]82/575/uh/ienetworkonherewithgreatthingsonhere[.]hta hxxp://185[.]29[.]11[.]111/455/RGFFTG[.]txt hxxp://172[.]245[.]123[.]25/xampp/eq/evnetworkneedgoodthings[.]hta hxxp://hunter[.]freshworx[.]com/et8_webservice/mail/attach/61EB0719-3A26-D60D-7630-B0A2084EEB02/770864_inquiry&order[.]doc hxxp://154[.]216[.]19[.]160/txt/mnobinm[.]doc hxxp://107[.]172[.]31[.]14/xampp/ess/superstartwanttobeomeerynicepersonaroundtheworldwholoveagoodgirlwhocanwanttogetthegirlbeackwithentirethingstobegodownwithme_______sheisverynicegirlforme[.]doc hxxp://87[.]120[.]84[.]38/txt/9qP0xWlHdvhkbFG[.]doc hxxp://103[.]131[.]130[.]248/355/WSRRED[.]txt hxxp://104[.]168[.]7[.]23/457/EDVVCG[.]txt hxxp://sbelegi[.]com[.]br/wp-content/plugins/cognac/smsinc[.]txt |
Remcos |
URL | hxxp://46[.]41[.]138[.]23/Spotify[.]exe hxxps://api[.]telegram[.]org/bot5834796283:AAGrwY-Kkn2VgcNc7OCI3d_ssicyDA9JZcg/ hxxp://198[.]46[.]178[.]134/DHLLLFILEMPDW-constraints[.]vbs |
Agent Tesla |
URL | hxxp://154[.]216[.]19[.]160/txt/MKAVLA[.]exe hxxps://garanticonstruct[.]ro/wp/lzXwrPn219[.]bin hxxps://garanticonstruct[.]ro/1/Ajonjoli115[.]rar hxxp://104[.]168[.]7[.]23/457/nc/nicewithgreatpcitureofgreatthingstobe[.]hta hxxp://4[.]154[.]172[.]127/iobj/testingProtected[.]exe hxxp://94[.]154[.]172[.]127/iobj/testingProtected[.]exe hxxp://193[.]233[.]203[.]31/mine/pressureprocesspro[.]zip |
Formbook |
URL | hxxps://remainyadjw[.]biz/api hxxps://revirepart[.]biz/api hxxps://counbuyytwy[.]biz/api hxxps://osberverynsb[.]biz/api hxxps://soupedburhsh[.]biz/api hxxps://divewanntwj[.]biz/api hxxps://lemnnywu[.]buzz/api hxxps://dividefik[.]buzz/api hxxps://wittyhurteh[.]buzz/api hxxps://magneticcosi[.]buzz/api hxxps://explositonuy[.]buzz/api hxxps://endureferrar[.]buzz/api hxxps://discouragedkw[.]buzz/api hxxps://blesstextrei[.]buzz/api hxxps://folkfloreks[.]buzz/api hxxps://gaspytanykw[.]buzz/api hxxps://homedarenwj[.]buzz/api hxxps://innovatioy[.]buzz/api hxxps://proclaimykn[.]buzz/api hxxps://punchudump[.]buzz/api hxxps://chinnyvoushw[.]shop/api hxxps://herberyloduso[.]shop/api hxxps://fevertalkkywkwm[.]shop/api hxxp://assets[.]gziraq[.]com/css/63e909b3647d[.]exe hxxp://94[.]103[.]125[.]119/l[.]exe hxxp://assets[.]gziraq[.]com/css/d74f5005fa82[.]exe hxxp://193[.]233[.]203[.]37/moon/LummaC2[.]exe |
Lumma Stealer |
URL | hxxps://hepsinezipla4dime522[.]com/YzM1YThkNDFkNmQ0/ hxxps://hepsinidoe01malltim21[.]com/YzM1YThkNDFkNmQ0/ hxxps://hersenbo67saaldia548[.]com/YzM1YThkNDFkNmQ0/ hxxps://alayinag45idserr5454[.]com/YzM1YThkNDFkNmQ0/ hxxps://neadamsin45mda1yq[.]com/YzM1YThkNDFkNmQ0/ hxxps://hepsinezipl4dim522[.]com/YzM1YThkNDFkNmQ0/ hxxps://hersenbo67saldi548[.]com/YzM1YThkNDFkNmQ0/ hxxps://alayinag45ider5454[.]com/YzM1YThkNDFkNmQ0/ hxxps://neadamsin45mayq[.]com/YzM1YThkNDFkNmQ0/ hxxps://guvenilirislemlershop[.]com[.]tr/ZGFiNTEyMzU5Njlj/ hxxps://hizliveguvenilirshop[.]com[.]tr/ZGFiNTEyMzU5Njlj/ hxxps://guvenilirshopislemler[.]com[.]tr/ZGFiNTEyMzU5Njlj/ hxxps://guvenilirislemler[.]com[.]tr/ZGFiNTEyMzU5Njlj/ hxxps://2guvenilirislemler[.]com[.]tr/ZGFiNTEyMzU5Njlj/ hxxps://3guvenilirislemler[.]com[.]tr/ZGFiNTEyMzU5Njlj/ hxxps://4guvenilirislemler[.]com[.]tr/ZGFiNTEyMzU5Njlj/ hxxps://5guvenilirislemler[.]com[.]tr/ZGFiNTEyMzU5Njlj/ hxxps://alkentbartkert1231[.]com/MzQ1Yzk1ZGQ4ODY3/ hxxps://gargasgarmamaraz22[.]com/MzQ1Yzk1ZGQ4ODY3/ hxxps://mutelengen322[.]com/MzQ1Yzk1ZGQ4ODY3/ hxxps://romelarkenzam443[.]com/MzQ1Yzk1ZGQ4ODY3/ hxxps://marankanzanmamakar131[.]com/MzQ1Yzk1ZGQ4ODY3/ hxxps://94[.]141[.]120[.]53/ZGZmNzZhNzQ1M2Iz/ |
Coper |
URL | hxxp://154[.]216[.]17[.]30/sh | RedTail |
URL | hxxps://oldwetcat[.]com/trade/fix[.]php hxxps://oldwetcat[.]com/trade/di[.]php hxxps://oldwetcat[.]com/trade/index[.]php hxxps://oldwetcat[.]com/trade/original[.]js hxxps://pemalite[.]com/web-analyzer[.]js hxxps://piedsmontlaw[.]com/web-analyzer[.]js hxxps://howmanychairs[.]com/web-analyzer[.]js hxxps://nqs[.]rooms[.]fierceatfifty[.]com/orderReview hxxps://www[.]loopbackanalytics[.]com/wp-includes/gdsayy[.]php hxxps://agu[.]rooms[.]fierceatfifty[.]com/orderReview hxxps://ugq[.]rooms[.]fierceatfifty[.]com/orderReview hxxps://vbjne[.]rooms[.]fierceatfifty[.]com/orderReview |
FAKEUPDATES |
URL | hxxp://172[.]245[.]123[.]25/xampp/cs/niceworkingprojectforeveryone[.]hta hxxp://172[.]245[.]123[.]25/270/taskhostw[.]exe hxxps://api[.]telegram[.]org/bot7718195303:AAH0NmZU1fTlGiQsVioB6NIIeKKsLF_-cmM/sendMessage?chat_id=6624630813 hxxps://api[.]telegram[.]org/bot7733918918:AAEtGoUvhJXT-4wtbogjQ__0KDlSf2pw6MQ/sendMessage?chat_id=7969902771 |
Snake Keylogger |
URL | hxxp://147[.]124[.]214[.]129:1244/j/keys hxxp://147[.]124[.]214[.]129:1244/j/s0HhMg2 |
InvisibleFerret |
URL | hxxp://assets[.]gziraq[.]com/css/7f3c2473d1e6[.]exe | Vidar |
URL | hxxp://zoomcallers[.]com/en-gb/insider/Intel-Driver-and-SupportInstaller_SBNJHK78837fwef783SHJshbjhbj[.]exe hxxp://zoomcallers[.]com/en-gb/insider/Intel-DriverSupport_SBNJHK788372hJHSBh2323[.]exe |
Rhadamanthys |
URL | hxxps://api[.]telegram[.]org/bot8171626722:AAGIo9PvRpFrmWwamfv0SMURLy1PCYFG9a8/sendMessage?chat_id=6542615755 | DarkCloud |
URL | hxxp://185[.]244[.]219[.]87/Doc[.]pdf[.]lnk | QakBot |
URL | hxxp://94[.]154[.]172[.]127/iobj/xwormProtected[.]exe | AsyncRAT |
URL | hxxp://ns1[.]smlms[.]mr/Doc[.]exe | Sliver |
URL | hxxp://209[.]141[.]51[.]21/xmrig[.]exe hxxp://119[.]192[.]128[.]163:28080/docs/x[.]rar hxxp://20[.]210[.]245[.]1/actives[.]exe |
Coinminer |
URL | hxxp://87[.]120[.]84[.]38/txt/iA8CGls28DqWbrP[.]exe | MASS Logger |
URL | hxxp://31[.]172[.]80[.]237/qkdjdjj22[.]x86 hxxp://31[.]172[.]80[.]237/qkdjdjj22[.]arm6 hxxp://31[.]172[.]80[.]237/qkdjdjj22[.]m68k hxxp://31[.]172[.]80[.]237/qkdjdjj22[.]mpsl |
Bashlite |
URL | hxxp://87[.]120[.]127[.]223/CheckX-Cracked-VIP[.]exe hxxp://91[.]208[.]206[.]5/mime/partdevelopment[.]zip |
RedLine Stealer |
URL | hxxp://all-access-media[.]com/media/templates/site/localer-en[.]hta | NetSupportManager RAT |
URL | hxxp://37[.]221[.]67[.]152/sparta/timeintegrate[.]exe | PureLogs Stealer |
URL | hxxp://91[.]208[.]206[.]5/env/yearprogrampro[.]zip hxxp://85[.]239[.]33[.]132/mod03/bluemaintenance%60[.]zip hxxp://91[.]208[.]206[.]5/env/alsodiscussionpro[.]zip |
DarkTortilla |
URL | hxxp://85[.]17[.]9[.]164/9BsnvS2hf/index[.]php | Amadey |
URL | hxxp://37[.]221[.]67[.]152/agenda/thoughtdeal[.]zip | NjRAT |