不正URLへのアクセス、不正メールの受信
-
メール受信した
弊社お客様0社 URLアクセスした
弊社お客様2社 -
2024/12/13
※2024/12/13 更新
マルウェア感染させると考えられるURLを検知(2024/12/13)
■IoC(※1)
Type: | IOC: | Signature: |
---|---|---|
URL | hxxp://www[.]speak-a-message[.]com/downloads/prereqs/vcredist_x86[.]exe hxxp://download[.]emailorganizer[.]com/download/NEOProSetup[.]exe hxxp://31[.]41[.]244[.]11/files/8199790517/u1w30Wt[.]exe hxxp://185[.]81[.]68[.]147/cx[.]exe hxxp://185[.]81[.]68[.]147/ssg[.]exe hxxp://185[.]81[.]68[.]147/dropper[.]exe |
RedLine Stealer |
URL | hxxp://45[.]132[.]107[.]229/1acc7899d5577c57/nss3[.]dll hxxp://185[.]215[.]113[.]206/68b591d6548ec281/sqlite3[.]dll?E hxxp://45[.]132[.]107[.]229/1acc7899d5577c57/sqlite3[.]dll hxxp://45[.]132[.]107[.]229/1acc7899d5577c57/mozglue[.]dll hxxp://45[.]132[.]107[.]229/1acc7899d5577c57/vcruntime140[.]dll hxxp://45[.]132[.]107[.]229/1acc7899d5577c57/freebl3[.]dll hxxp://45[.]132[.]107[.]229/1acc7899d5577c57/msvcp140[.]dll |
Stealc |
URL | hxxp://f1059329[.]xsph[.]ru/Built[.]exe | BlankGrabber |
URL | hxxp://182[.]92[.]99[.]95/kaijiorder/cert/41a1111[.]hta | Ghost RAT |
URL | hxxp://20[.]83[.]148[.]22:8080/test30[.]exe hxxp://31[.]220[.]56[.]140:8888/avast/updates/security/patch1[.]1[.]3[.]exe hxxps://onnetmais[.]org/onnetmais/tcl_sync[.]js hxxp://status[.]mycompliancereports[.]com/AzureConnect[.]exe |
Cobalt Strike |
URL | hxxp://a1057700[.]xsph[.]ru/Azure[.]exe hxxp://31[.]41[.]244[.]12/files/unique1/random[.]exe hxxp://a1051707[.]xsph[.]ru/qwex[.]exe hxxp://31[.]41[.]244[.]12/files/6386900832/9feskIx[.]exe hxxp://31[.]41[.]244[.]10/files/6386900832/9feskIx[.]exe hxxp://31[.]41[.]244[.]9/files/6386900832/9feskIx[.]exe hxxp://31[.]41[.]244[.]11/files/6386900832/9feskIx[.]exe hxxp://a1059592[.]xsph[.]ru/XW[.]exe hxxp://185[.]81[.]68[.]147/AsyncClient[.]exe |
AsyncRAT |
URL | hxxp://drdavidfishbein[.]com/file/129[.]txt | Agent Tesla |
URL | hxxps://fileshare[.]seite[.]me/uploads/Client[.]exe hxxp://upload[.]vina-host[.]com/get/rtSyBOyqu8/aa[.]exe hxxp://upload[.]vina-host[.]com/get/TvIsNLdnvi/ardara[.]exe hxxp://upload[.]vina-host[.]com/get/rCsDtGEso7/jesus[.]exe hxxp://185[.]81[.]68[.]147/xx[.]exe |
Quasar RAT |
URL | hxxp://sporcketngearforu[.]com/dune64[.]bin | Havoc |
URL | hxxps://pla[.]material[.]amstillroofing[.]com/merchantServices hxxps://prajapatisamaj[.]info/work/original[.]js hxxps://djnito[.]com/haye728[.]js hxxps://djnito[.]com/js[.]php hxxps://prajapatisamaj[.]info/work/index[.]php hxxps://prajapatisamaj[.]info/work/download[.]php hxxps://prajapatisamaj[.]info/work/yyy[.]zip hxxps://uadew[.]riders[.]50kfor50years[.]com/merchantServices |
FAKEUPDATES |
URL | hxxps://172[.]245[.]142[.]60/551/wcb/nicegirlforyou[.]hta hxxp://172[.]245[.]142[.]60/551/wcb/nicegirlforyou[.]hta hxxp://185[.]215[.]113[.]209/inc/RMX[.]exe hxxp://138[.]68[.]185[.]118/60/wce/nookieniceverysweetthingsgoingonherewithnicelooking_______nookiemuchbetterthananythingusayingwhichnicefor______verynicelookingnookiechocolcatefalour[.]doc hxxps://bitbucket[.]org/facturacioncol/fact/downloads/Out2[.]exe hxxps://bitbucket[.]org/facturacioncol/fact/downloads/null[.]exe hxxps://bitbucket[.]org/facturacioncol/fact/downloads/neptuno[.]exe |
Remcos |
URL | hxxps://tacitglibbr[.]biz/api hxxps://immureprech[.]biz/api hxxp://45[.]131[.]135[.]227/Captcha[.]hta hxxps://sordid-snaked[.]cyou/api hxxps://awake-weaves[.]cyou/api hxxps://wrathful-jammy[.]cyou/api hxxps://debonairnukk[.]xyz/api hxxps://diffuculttan[.]xyz/api hxxps://effecterectz[.]xyz/api hxxps://deafeninggeh[.]biz/api hxxp://176[.]113[.]115[.]19/ScreenUpdateSync[.]exe hxxps://spellshagey[.]biz/api hxxps://profusetawdy[.]click/api hxxps://bellflamre[.]click/api hxxp://31[.]41[.]244[.]9/files/hell911/random[.]exe hxxp://31[.]41[.]244[.]12/files/hell911/random[.]exe hxxp://31[.]41[.]244[.]12/files/6904700471/Z9Pp9pM[.]exe hxxp://31[.]41[.]244[.]10/files/kardanvalov88/random[.]exe hxxp://31[.]41[.]244[.]11/files/kardanvalov88/random[.]exe hxxp://31[.]41[.]244[.]9/files/6904700471/Z9Pp9pM[.]exe hxxp://31[.]41[.]244[.]9/files/kardanvalov88/random[.]exe hxxp://31[.]41[.]244[.]10/files/6904700471/Z9Pp9pM[.]exe hxxp://31[.]41[.]244[.]10/files/hell911/random[.]exe hxxp://185[.]215[.]113[.]16/inc/alexshlu[.]exe hxxp://31[.]41[.]244[.]12/files/kardanvalov88/random[.]exe hxxp://185[.]215[.]113[.]209/inc/alexshlu[.]exe hxxp://31[.]41[.]244[.]11/files/hell911/random[.]exe hxxp://31[.]41[.]244[.]11/files/burpin1/random[.]exe hxxp://31[.]41[.]244[.]9/files/fate/random[.]exe hxxp://31[.]41[.]244[.]12/files/fate/random[.]exe hxxp://31[.]41[.]244[.]11/files/fate/random[.]exe hxxp://31[.]41[.]244[.]10/files/fate/random[.]exe hxxp://31[.]41[.]244[.]10/files/8049824649/yiklfON[.]exe hxxp://31[.]41[.]244[.]11/files/8049824649/yiklfON[.]exe hxxp://31[.]41[.]244[.]12/files/8049824649/yiklfON[.]exe hxxp://31[.]41[.]244[.]9/files/8049824649/yiklfON[.]exe hxxp://212[.]113[.]107[.]84/trololo/tester[.]exe hxxp://31[.]41[.]244[.]11/files/6904700471/9JTVo50[.]exe |
Lumma Stealer |
URL | hxxp://193[.]3[.]19[.]151/auth/login | Meduza Stealer |
URL | hxxps://seabreezehf[.]top/YTZhZjliODdlYTI4/ | Coper |
URL | hxxp://owa[.]rootkit-ninja[.]com/costra/Panel/login[.]php | Lucifer |
URL | hxxps://kolobrownsalesye-fong[.]com/v/HUM[.]ps1 | MASS Logger |
URL | hxxp://vitantgroup[.]com/Plugins/cred64[.]dll hxxps://citactica[.]com/wp-content/wp-login[.]php hxxps://icw2016[.]coachfederation[.]cz/wp-includes/images/wp/ hxxps://hospitalvilleroy[.]com[.]br/wp-includes/fonts/icons/ hxxps://brauche-it[.]de/wp-includes/blocks/blocksu9ky0o hxxps://okesense[.]oketheme[.]com/wp-includes/sodium_compat/sodium_compatT4FF1a hxxps://coworkingdeamicis[.]com/wp-includes/Text/TextYpRm9l hxxps://plagnol-charpentier[.]fr/wp-includes/random_compat/random_compata0zW7Q hxxp://185[.]81[.]68[.]148/8Fvu5jh4DbS/index[.]php hxxp://185[.]81[.]68[.]147/7vhfjke3/index[.]php hxxp://185[.]81[.]68[.]147/gfx[.]exe |
Amadey |
URL | hxxps://api[.]telegram[.]org/bot7125297965:AAFl6eQAjxqGeAfWHpfHbGAtADDAZUyFidM/sendMessage?chat_id=6367688286 | Snake Keylogger |
URL | hxxp://192[.]113[.]101[.]66:42037/Mozi[.]m hxxp://117[.]235[.]101[.]167:47343/Mozi[.]m |
Mozi |
URL | hxxp://31[.]41[.]244[.]12/files/martin/random[.]exe hxxp://185[.]215[.]113[.]36/Javvvum[.]exe |
CryptBot |
URL | hxxp://31[.]41[.]244[.]12/files/7403972632/C1J7SVw[.]exe hxxp://31[.]41[.]244[.]9/files/7403972632/C1J7SVw[.]exe hxxp://31[.]41[.]244[.]10/files/7403972632/C1J7SVw[.]exe hxxp://31[.]41[.]244[.]12/files/7403972632/gU8ND0g[.]exe hxxp://f0706909[.]xsph[.]ru/img/50[.]exe hxxp://31[.]41[.]244[.]11/files/5131681669/7U5ylzK[.]exe hxxp://31[.]41[.]244[.]11/files/5131681669/CuKxXX0[.]exe |
Coinminer |
URL | hxxp://185[.]215[.]113[.]16/inc/jsawdtyjde[.]exe?b hxxp://91[.]240[.]118[.]204:8000/VmManagedSetup[.]exe |
SystemBC |
URL | hxxp://31[.]41[.]244[.]9/files/523681048/3EUEYgl[.]exe hxxp://31[.]41[.]244[.]10/files/523681048/3EUEYgl[.]exe hxxp://31[.]41[.]244[.]11/files/523681048/3EUEYgl[.]exe hxxp://31[.]41[.]244[.]12/files/523681048/3EUEYgl[.]exe hxxp://31[.]41[.]244[.]12/files/encoxx/random[.]exe hxxp://31[.]41[.]244[.]9/files/encoxx/random[.]exe hxxp://31[.]41[.]244[.]10/files/encoxx/random[.]exe hxxp://31[.]41[.]244[.]11/files/encoxx/random[.]exe |
Vidar |
URL | hxxp://31[.]41[.]244[.]12/files/unique2/random[.]exe | GCleaner |
URL | hxxp://docusign[.]servergate[.]org/cd/Document[.]lnk hxxps://servergate[.]org/rt/setup[.]msi |
MetaStealer |
URL | hxxp://64[.]69[.]34[.]217:8082/login/index | Vshell |
URL | hxxp://94[.]159[.]113[.]204/up[.]php | StrelaStealer |
URL | hxxps://www[.]stipamana[.]com/sdjfgsnzlkfoknzkfngasoeanpsDNbgsrggtehy/dyhdfyjdsftjsetawtwewayryghsdtysryatwewtrta/agasdrhstjhyfjghsrgaregafjyhdfhstsh/ydfctyxrgtsertrsez/asxhfzdhhz[.]exe | Warzone RAT |
URL | hxxp://185[.]81[.]68[.]147/vvv[.]exe | Sliver |
URL | hxxp://212[.]162[.]149[.]94/hapaASjpjADwmkbMzkaWEdnWGbt71[.]bin hxxp://212[.]162[.]149[.]94/QdhIlV89[.]bin |
CloudEyE |
URL | hxxp://172[.]105[.]88[.]18/ujq0oqpea94f4f8f/msedge[.]exe hxxp://furryporn[.]top/ujq0oqpea94f4f8f/msedge[.]exe |
NjRAT |
URL | hxxp://80[.]82[.]65[.]70/dl?name=mixthree[.]exe | Socks5 Systemz |