不正URLへのアクセス、不正メールの受信
-
メール受信した
弊社お客様0社 URLアクセスした
弊社お客様22社 -
2024/10/23
※2024/10/23 更新
マルウェア感染させると考えられるURLを検知(2024/10/23)
■IoC(※1)
Type: | IOC: | Signature: |
---|---|---|
URL | hxxps://cheappyholk[.]store/api hxxps://clammygrumnj[.]store/api hxxps://buildinggyw[.]cfd/api hxxps://unrestyherf[.]cfd/api hxxps://sellyoffri[.]cfd/api hxxps://lucnhyasi[.]cfd/api hxxps://pierrycomm[.]cfd/api hxxps://calfyrelifak[.]cfd/api hxxps://floodypocu[.]cfd/api hxxps://iniativeit[.]cfd/api hxxps://scrambledmy[.]cfd/api hxxps://arenabaeny[.]cfd/api hxxps://chaseinfrrc[.]cfd/api hxxps://balancedwei[.]cfd/api hxxps://lecturstrid[.]cfd/api hxxps://paitheadki[.]cfd/api hxxps://teenagrski[.]cfd/api hxxps://talantedoi[.]cfd/api hxxps://tollyabledbyi[.]cfd/api hxxps://harmonydhyr[.]cfd/api hxxps://chiefdisocu[.]cfd/api hxxps://hesitateiox[.]cfd/api hxxps://reffpicks[.]cfd/api hxxps://agendasinky[.]cfd/api hxxps://pleaddymoenu[.]cfd/api hxxps://assumedsimmy[.]cfd/api hxxps://sufferiny[.]cfd/api hxxps://resoluitdrawz[.]cfd/api hxxps://noucenemtny[.]cfd/api hxxps://endyreversez[.]cfd/api hxxps://coupledxry[.]cfd/api hxxps://cooperatedmw[.]cfd/api hxxps://bodyridegw[.]cfd/api hxxps://newsystuff[.]cfd/api hxxps://valuednoty[.]cfd/api |
Lumma Stealer |
URL | hxxp://94[.]156[.]177[.]220/skipo/five/fre[.]php hxxp://94[.]156[.]177[.]220/skipo/five/PvqDq929BSx_A_D_M1n_a[.]php |
LokiBot |
URL | hxxps://dareka4te[.]shop/endpoint hxxps://lakadmakatdg[.]shop/home[.]tar |
ClearFake |
URL | hxxps://94[.]156[.]253[.]20/NzNlMDMzYWExMzk1/ hxxps://staris7542352r23[.]net/NzNlMDMzYWExMzk1/ hxxps://staris6442352r23[.]net/NzNlMDMzYWExMzk1/ hxxps://staris5342352r23[.]net/NzNlMDMzYWExMzk1/ hxxps://staris4242352r23[.]net/NzNlMDMzYWExMzk1/ hxxps://staris3142352r23[.]net/NzNlMDMzYWExMzk1/ hxxps://2pethsop332[.]com/MzQ1Yzk1ZGQ4ODY3/ hxxps://3pethsop332[.]com/MzQ1Yzk1ZGQ4ODY3/ hxxps://4pethsop332[.]com/MzQ1Yzk1ZGQ4ODY3/ hxxps://5pethsop332[.]com/MzQ1Yzk1ZGQ4ODY3/ hxxps://6pethsop332[.]com/MzQ1Yzk1ZGQ4ODY3/ hxxps://22pethsop332[.]com/MzQ1Yzk1ZGQ4ODY3/ hxxps://32pethsop332[.]com/MzQ1Yzk1ZGQ4ODY3/ hxxps://52pethsop332[.]com/MzQ1Yzk1ZGQ4ODY3/ |
Coper |
URL | hxxps://api[.]telegram[.]org/bot6086388911:AAGHpITQe4oLJhzRR86O2JB3Tmd1xG2gIqM/sendMessage?chat_id=1932526247 hxxps://api[.]telegram[.]org/bot7733074716:AAHPqUDZNcrQPzH_G03x5ppIOnkxZuz-Nyk/sendMessage?chat_id=7337843299 |
Snake Keylogger |
URL | hxxp://119[.]123[.]170[.]28:41182/Mozi[.]m hxxp://175[.]107[.]0[.]60:36453/Mozi[.]m |
Mozi |
URL | hxxp://204[.]10[.]160[.]169/lftLvIEO72[.]bin | CloudEyE |
URL | hxxps://zumkoshapsret[.]com/live/ hxxps://worlpquano[.]com/live/ hxxps://trymeakafr[.]com/live/ hxxps://stripplasst[.]com/live/ hxxps://jertacco[.]com/live/ hxxps://finjuiceer[.]com/live/ hxxps://coolarition[.]com/live/ hxxps://carflotyup[.]com/live/ hxxps://aytobusesre[.]com/live/ |
Latrodectus |
URL | hxxps://lbko[.]rooms[.]fierceatfifty[.]com/orderReview hxxps://tcy[.]rooms[.]fierceatfifty[.]com/orderReview |
FAKEUPDATES |
URL | hxxp://198[.]46[.]178[.]134/madamwebbbbbbbbbbase6444[.]txt | OriginLogger |