不正URLへのアクセス、不正メールの受信
-
メール受信した
弊社お客様0社 URLアクセスした
弊社お客様1社 -
2024/12/02
※2024/12/02 更新
マルウェア感染させると考えられるURLを検知(2024/12/02)
■IoC(※1)
Type: | IOC: | Signature: |
---|---|---|
URL | hxxps://qihdv[.]lessons[.]southsidechurchofchristla[.]org/merchantServices hxxps://alx[.]studio[.]lacrenshawcrossing[.]com/merchantServices hxxps://bfd78[.]biz/work/original[.]js hxxps://bfd78[.]biz/work/das[.]php hxxps://bfd78[.]biz/work/index[.]php hxxps://bfd78[.]biz/work/yyy[.]zip hxxps://serbubet[.]store/work/original[.]js hxxps://serbubet[.]store/work/das[.]php hxxps://serbubet[.]store/work/yyy[.]zip hxxps://serbubet[.]store/work/index[.]php hxxps://www[.]teleproservice[.]com/work/original[.]js hxxps://www[.]teleproservice[.]com/work/yyy[.]zip hxxps://www[.]teleproservice[.]com/work/das[.]php hxxps://www[.]teleproservice[.]com/work/index[.]php hxxps://fushishandm[.]info/work/yyy[.]zip hxxps://fushishandm[.]info/work/original[.]js hxxps://fushishandm[.]info/work/download[.]php hxxps://fushishandm[.]info/work/index[.]php hxxps://breminantores[.]shop/work/original[.]js hxxps://breminantores[.]shop/work/yyy[.]zip hxxps://breminantores[.]shop/work/index[.]php hxxps://breminantores[.]shop/work/download[.]php hxxps://bigtasty[.]shop/work/original[.]js hxxps://bigtasty[.]shop/work/download[.]php hxxps://bigtasty[.]shop/work/yyy[.]zip hxxps://bigtasty[.]shop/work/index[.]php hxxps://foodiepharm[.]com/work/original[.]js hxxps://foodiepharm[.]com/work/yyy[.]zip hxxps://foodiepharm[.]com/work/downloader[.]php hxxps://foodiepharm[.]com/work/index[.]php hxxps://best-net[.]biz/work/original[.]js hxxps://best-net[.]biz/work/yyy[.]zip hxxps://best-net[.]biz/work/index[.]php hxxps://best-net[.]biz/work/downloader[.]php hxxps://homjh[.]studio[.]lacrenshawcrossing[.]com/merchantServices |
FAKEUPDATES |
URL | hxxp://94[.]156[.]177[.]41/davinci/five/fre[.]php hxxp://94[.]156[.]177[.]41/davinci/five/PvqDq929BSx_A_D_M1n_a[.]php |
LokiBot |
URL | hxxp://103[.]195[.]103[.]63:222/g5bbapVsvPgnwnVhFgSf[.]jpg hxxp://103[.]195[.]103[.]63:222/tt001010100100101000100010111010010101000101[.]txt hxxp://31[.]41[.]244[.]11/files/1824233174/cAvEmnl[.]exe hxxp://31[.]41[.]244[.]11/files/1824233174/EJQ2xs8[.]exe |
AsyncRAT |
URL | hxxp://31[.]41[.]244[.]11/files/6553216548/rWmzULI[.]exe | Azorult |
URL | hxxp://31[.]41[.]244[.]11/files/1212999483/t6kzDd6[.]exe hxxps://encrypthub[.]net/Main/antivm[.]ps1 |
Amadey |
URL | hxxps://pidlirmidlir23[.]com/ZTZkODUzMTBjYTA3/ hxxps://roskingming3333[.]site/MWQxMmUxNmEyYmU4/ hxxps://pigav233[.]com/ZTZkODUzMTBjYTA3/ |
Coper |
URL | hxxp://80[.]78[.]21[.]233/DarkGate_Loader[.]exe | DarkGate |
URL | hxxps://powermasteryonline[.]com/xmlrpc[.]php | GootLoader |
URL | hxxps://92[.]255[.]57[.]88/7bbacc20a3bd2eb5[.]php hxxp://46[.]8[.]237[.]122/0d6db6b62b0bcd23[.]php hxxp://95[.]215[.]207[.]32/410e29c26c8bd0b2[.]php hxxp://154[.]216[.]17[.]90/a48146f6763ef3af[.]php hxxp://154[.]216[.]17[.]90/5fafb04068123149/nss3[.]dll hxxp://154[.]216[.]17[.]90/5fafb04068123149/freebl3[.]dll hxxp://154[.]216[.]17[.]90/5fafb04068123149/mozglue[.]dll hxxp://95[.]215[.]207[.]32/a4984344fcf41cc7/sqlite3[.]dll hxxp://95[.]215[.]207[.]32/a4984344fcf41cc7/nss3[.]dll hxxp://154[.]216[.]17[.]90/5fafb04068123149/msvcp140[.]dll hxxp://95[.]215[.]207[.]32/a4984344fcf41cc7/msvcp140[.]dll hxxp://154[.]216[.]17[.]90/5fafb04068123149/sqlite3[.]dll hxxp://95[.]215[.]207[.]32/a4984344fcf41cc7/freebl3[.]dll hxxp://154[.]216[.]17[.]90/5fafb04068123149/softokn3[.]dll hxxp://95[.]215[.]207[.]32/a4984344fcf41cc7/vcruntime140[.]dll hxxp://95[.]215[.]207[.]32/a4984344fcf41cc7/mozglue[.]dll hxxp://95[.]215[.]207[.]32/a4984344fcf41cc7/softokn3[.]dll hxxp://154[.]216[.]17[.]90/5fafb04068123149/vcruntime140[.]dll |
Stealc |
URL | hxxp://122[.]208[.]222[.]247/x//mips hxxp://122[.]208[.]222[.]247/x//mipsel hxxp://122[.]208[.]222[.]247/x/ppc64el hxxp://122[.]208[.]222[.]247/x/aarch64 hxxp://122[.]208[.]222[.]247/x/arc hxxp://122[.]208[.]222[.]247/x/mips64 hxxp://122[.]208[.]222[.]247/x/armv6l hxxp://122[.]208[.]222[.]247/x/armv7l hxxp://122[.]208[.]222[.]247/x/powerpc hxxp://122[.]208[.]222[.]247/x/m68k hxxp://122[.]208[.]222[.]247/x/mips64abi hxxp://122[.]208[.]222[.]247/x/s390x hxxp://122[.]208[.]222[.]247/x/mips64elgnuabi hxxp://122[.]208[.]222[.]247/x/i686 hxxp://122[.]208[.]222[.]247/x/ppc64 hxxp://122[.]208[.]222[.]247/x/mips64el hxxp://122[.]208[.]222[.]247/x/ppc hxxp://122[.]208[.]222[.]247/x/x86_64 hxxp://122[.]208[.]222[.]247/x/sh4 hxxp://122[.]208[.]222[.]247/x/sparc64 hxxp://122[.]208[.]222[.]247/x/sh[.]sh hxxp://122[.]208[.]222[.]247/x/mips hxxp://122[.]208[.]222[.]247/x/mipsel hxxp://122[.]208[.]222[.]247/x/sh hxxp://122[.]208[.]222[.]247/x/kai hxxp://122[.]208[.]222[.]247/x/armv5tejl |
Tsunami |
URL | hxxp://31[.]41[.]244[.]11/files/6859095220/XsFuJt6[.]exe hxxps://balloon-sneak[.]cyou/api hxxps://effect-shake[.]cyou/api hxxps://lumdexibuy[.]shop/api hxxp://31[.]41[.]244[.]11/files/151334531/lnwtLq4[.]exe hxxps://water-acidict[.]cyou/api hxxps://bet-cook-fixer[.]cyou/api hxxps://infect-crackle[.]cyou/api hxxps://teach-shave[.]cyou/api hxxps://voter-screnn[.]cyou/api hxxps://impend-differ[.]biz/api hxxps://print-vexer[.]biz/api hxxps://dare-curbys[.]biz/api hxxps://covery-mover[.]biz/api hxxps://formy-spill[.]biz/api hxxps://dwell-exclaim[.]biz/api hxxps://zinc-sneark[.]biz/api hxxps://se-blurry[.]biz/api hxxp://31[.]41[.]244[.]11/files/889557051/WqtakkK[.]exe hxxp://31[.]41[.]244[.]11/files/889557051/6nBCzLk[.]exe hxxp://31[.]41[.]244[.]11/files/151334531/N67fLgN[.]exe |
Lumma Stealer |
URL | hxxp://45[.]131[.]108[.]84/hidakibest[.]mpsl hxxp://45[.]131[.]108[.]84/hidakibest[.]arm4 hxxp://45[.]131[.]108[.]84/hidakibest[.]arm6 hxxp://45[.]131[.]108[.]84/hidakibest[.]sparc hxxp://45[.]131[.]108[.]84/hidakibest[.]mips hxxp://45[.]131[.]108[.]84/hidakibest[.]arm5 hxxp://45[.]131[.]108[.]84/hidakibest[.]ppc hxxp://45[.]131[.]108[.]84/hidakibest[.]arm7 hxxp://45[.]131[.]108[.]84/hidakibest[.]x86 hxxp://85[.]209[.]17[.]110/snype[.]sh hxxp://85[.]209[.]17[.]110/snype[.]arm5 hxxp://85[.]209[.]17[.]110/snype[.]arm6 hxxp://85[.]209[.]17[.]110/snype[.]arm4 hxxp://85[.]209[.]17[.]110/snype[.]sparc hxxp://85[.]209[.]17[.]110/snype[.]x86 hxxp://85[.]209[.]17[.]110/snype[.]mpsl hxxp://85[.]209[.]17[.]110/snype[.]ppc hxxp://85[.]209[.]17[.]110/snype[.]mips |
Bashlite |
URL | hxxp://79[.]124[.]78[.]109/wp-includes/phyllopodan7V7GD[.]php hxxp://79[.]124[.]78[.]109/wp-includes/barasinghaby[.]ps1 hxxp://79[.]124[.]78[.]109/flocking[.]php |
Koi Loader |
URL | hxxp://93[.]123[.]85[.]15/Update/update3/Protect0Secure/ExternalRequestDefaultsql/VideoVideo/4Pipe/EternaljavascriptrequesthttpGeneratortrackDlepublicPrivateuploads[.]php hxxp://390412cm[.]n9shteam[.]in/ProviderImagepipeTopacketbaseuniversaldle[.]php hxxp://213[.]108[.]22[.]118/protectlinuxuniversaltrackcdn[.]php hxxp://147[.]45[.]47[.]156/CentralLocal1/Eternal_sqlGeneratorWordpressdatalifeUploads[.]php |
DCRat |
URL | hxxp://58[.]47[.]122[.]191:60532/Mozi[.]m hxxp://112[.]229[.]186[.]195:46487/Mozi[.]m |
Mozi |
URL | hxxp://125[.]33[.]224[.]103:8085/Video[.]scr hxxp://125[.]33[.]228[.]48:8085/Photo[.]scr hxxp://125[.]33[.]224[.]103:8085/Photo[.]scr hxxp://125[.]33[.]228[.]48:8085/AV[.]scr hxxp://125[.]33[.]224[.]103:8085/AV[.]scr hxxp://125[.]33[.]228[.]48:8085/Video[.]scr hxxp://183[.]30[.]202[.]24:82/AV[.]scr hxxp://183[.]30[.]202[.]24:82/Photo[.]scr hxxp://183[.]30[.]202[.]24:82/Video[.]scr hxxp://118[.]119[.]34[.]44:81/images/AV[.]scr hxxp://79[.]184[.]130[.]68:2137/Video[.]scr hxxp://118[.]119[.]34[.]44:81/images/Photo[.]scr hxxp://123[.]130[.]204[.]103:8888/Photo[.]scr hxxp://81[.]42[.]249[.]132:1080/Video[.]scr hxxp://123[.]130[.]204[.]103:8888/Video[.]scr hxxp://118[.]119[.]34[.]44:81/Video[.]scr hxxp://183[.]30[.]204[.]83:81/AV[.]scr hxxp://183[.]30[.]204[.]83:81/Photo[.]lnk hxxp://118[.]119[.]34[.]44:81/AV[.]scr hxxp://183[.]30[.]204[.]83:81/Video[.]scr hxxp://79[.]184[.]130[.]68:2137/AV[.]scr hxxp://81[.]42[.]249[.]132:1080/Photo[.]scr hxxp://118[.]119[.]34[.]44:81/Photo[.]scr hxxp://183[.]30[.]204[.]83:81/Photo[.]scr hxxp://183[.]30[.]204[.]105:81/Video[.]scr hxxp://183[.]30[.]204[.]105:81/Photo[.]scr hxxp://183[.]30[.]204[.]105:81/AV[.]scr hxxp://123[.]130[.]204[.]103:8888/AV[.]lnk hxxp://118[.]119[.]34[.]44:81/images/Video[.]lnk hxxp://79[.]184[.]130[.]68:2137/Photo[.]lnk hxxp://79[.]184[.]130[.]68:2137/Video[.]lnk hxxp://123[.]130[.]204[.]103:8888/AV[.]scr hxxp://81[.]42[.]249[.]132:1080/Photo[.]lnk hxxp://118[.]119[.]34[.]44:81/images/Video[.]scr hxxp://183[.]30[.]202[.]24:82/AV[.]lnk hxxp://118[.]119[.]34[.]44:81/Photo[.]lnk hxxp://125[.]33[.]228[.]48:8085/Video[.]lnk hxxp://81[.]42[.]249[.]132:1080/AV[.]scr hxxp://79[.]184[.]130[.]68:2137/Photo[.]scr hxxp://123[.]130[.]204[.]103:8888/Photo[.]lnk hxxp://183[.]30[.]204[.]105:81/AV[.]lnk hxxp://183[.]30[.]204[.]105:81/Video[.]lnk hxxp://118[.]119[.]34[.]44:81/AV[.]lnk hxxp://123[.]130[.]204[.]103:8888/Video[.]lnk hxxp://125[.]33[.]224[.]103:8085/AV[.]lnk hxxp://125[.]33[.]228[.]48:8085/AV[.]lnk hxxp://79[.]184[.]130[.]68:2137/AV[.]lnk hxxp://118[.]119[.]34[.]44:81/images/AV[.]lnk hxxp://183[.]30[.]204[.]83:81/Video[.]lnk hxxp://81[.]42[.]249[.]132:1080/AV[.]lnk hxxp://81[.]42[.]249[.]132:1080/Video[.]lnk hxxp://183[.]30[.]204[.]83:81/AV[.]lnk hxxp://183[.]30[.]204[.]105:81/Photo[.]lnk hxxp://125[.]33[.]228[.]48:8085/Photo[.]lnk hxxp://183[.]30[.]202[.]24:82/Video[.]lnk hxxp://125[.]33[.]224[.]103:8085/Photo[.]lnk hxxp://118[.]119[.]34[.]44:81/Video[.]lnk hxxp://118[.]119[.]34[.]44:81/images/Photo[.]lnk hxxp://125[.]33[.]224[.]103:8085/Video[.]lnk hxxp://183[.]30[.]202[.]24:82/Photo[.]lnk hxxp://31[.]41[.]244[.]11/files/7403972632/gU8ND0g[.]exe hxxp://31[.]41[.]244[.]11/files/7488655239/XW5qFPl[.]exe hxxp://66[.]63[.]187[.]200/[.]puscarie/[.]main hxxp://154[.]216[.]17[.]44/mvt/xmrig[.]exe hxxp://154[.]216[.]17[.]44/dns/pwer |
Coinminer |
URL | hxxp://183[.]30[.]204[.]105:81/info[.]zip hxxp://183[.]30[.]204[.]83:81/info[.]zip hxxp://60[.]26[.]217[.]71:88/info[.]zip |
XMRig |
URL | hxxp://j-fores[.]com/order/244_Hranhyyrkhq hxxps://j-fores[.]com/order/244_Hranhyyrkhq |
CloudEyE |
URL | hxxps://csg-app[.]com/office365/build[.]exe | RedLine Stealer |
URL | hxxps://109[.]120[.]139[.]195/birdflower[.]exe hxxps://dvihz[.]com/birdflower[.]exe hxxps://dvihz[.]com/siveria[.]exe hxxps://dvihz[.]com/unique[.]exe |
Meduza Stealer |
URL | hxxps://j-fores[.]com/order/RFQ[.]zip hxxp://j-fores[.]com/order/RFQ[.]zip |
DBatLoader |
URL | hxxp://31[.]41[.]244[.]11/files/7783987494/EbjU3lW[.]exe hxxp://31[.]41[.]244[.]11/files/7783987494/3FEtgVY[.]exe |
Vidar |
URL | hxxp://31[.]41[.]244[.]11/files/6180536652/xZNk1YZ[.]exe | SystemBC |
URL | hxxp://92[.]42[.]96[.]203/api/OWUsODEsN2QsYTAsYTMsOGEsOGMsOTUsNmIsODIs/ | SmartLoader |
URL | hxxp://165[.]154[.]184[.]75/SearchUII[.]exe | NjRAT |