不正URLへのアクセス、不正メールの受信
-
メール受信した
弊社お客様0社 URLアクセスした
弊社お客様3社 -
2025/01/28
※2025/01/30 更新
マルウェア感染させると考えられるURLを検知(2025/01/28)
■IoC(※1)
Type: | IOC: | Signature: |
---|---|---|
URL | hxxp://82[.]146[.]42[.]97/Image/ProtonBetterprotectLine/poll/VmGeo/AuthgeoPrivateWp/DefaultcdnSqlPublic/http27http/Secure/pythonRequest18/Http/Datalife/60uploadsGenerator/3Db/8Protect7/asyncPrivate/serverProviderDump/CpuProtect/protectpublicVoiddb/httpTo/Javascript_RequestAuthServerprotectpublicdownloads[.]php hxxp://438286cm[.]nyashnyash[.]ru/videopipeHttpPacketserverWordpressDleuploads[.]php |
DCRat |
URL | hxxps://volcanoyev[.]click/api hxxp://176[.]113[.]115[.]225/c[.]jpg hxxp://176[.]113[.]115[.]225/a[.]jpg hxxp://176[.]113[.]115[.]225/b[.]jpg hxxps://pwedereihge[.]shop/api hxxps://dinopsych[.]com/?t=4 hxxps://xorok[.]shop/Racoona[.]eml hxxp://promoforge360[.]com/677332d0f24fde066b58b260 hxxp://tremista[.]com/676c76a6a464ed59c1298843 |
Lumma Stealer |
URL | hxxp://45[.]61[.]137[.]151/1a90bc2aa73eeb41/sqlite3[.]dll hxxps://23[.]88[.]122[.]134/579d5c7e95a610c1/vcruntime140[.]dll hxxps://162[.]55[.]215[.]42/c8d1769211d0cfb0[.]php hxxp://91[.]239[.]53[.]29/d925e943a21dd486/freebl3[.]dll hxxp://91[.]239[.]53[.]29/d925e943a21dd486/nss3[.]dll hxxp://91[.]239[.]53[.]29/d925e943a21dd486/softokn3[.]dll? hxxp://91[.]239[.]53[.]29/d925e943a21dd486/mozglue[.]dll hxxp://91[.]239[.]53[.]29/d925e943a21dd486/msvcp140[.]dll hxxp://91[.]239[.]53[.]29/d925e943a21dd486/vcruntime140[.]dll hxxp://91[.]239[.]53[.]29/d925e943a21dd486/sqlite3[.]dll |
Stealc |
URL | hxxps://solve[.]lqwt[.]org/awjsx[.]captcha hxxps://solve[.]dpqx[.]org/awjsx[.]captcha |
ClearFake |
URL | hxxps://goldenbirdhub[.]xyz/Y2VmOGI0NTIwZTE5/ hxxps://rabbitkeske8[.]xyz/ZDBhYWRlZWY0ZjU3/ |
Coper |
URL | hxxp://84[.]200[.]154[.]119/sh4 hxxp://160[.]191[.]245[.]20/main_arm7 |
Bashlite |
URL | hxxp://gadgco[.]com/tmp/index[.]php hxxp://niksplus[.]ru/tmp/index[.]php hxxp://officsolo[.]biz/tmp/index[.]php hxxp://pkodev[.]net/tmp/index[.]php |
SmokeLoader |
URL | hxxp://85[.]31[.]47[.]84/adsafref/Panel/five/fre[.]php hxxp://85[.]31[.]47[.]84:5336/adsafref/Panel/five/fre[.]php hxxp://85[.]31[.]47[.]84:5336/adsafref/Panel/five/PvqDq929BSx_A_D_M1n_a[.]php |
LokiBot |
URL | hxxp://45[.]138[.]183[.]226/upload/T[.]exe | XWorm |
URL | hxxps://energigroup[.]hu/WRlalDGsST0[.]bin hxxps://energigroup[.]hu/nNifdlrg32[.]bin hxxp://energigroup[.]hu/WRlalDGsST0[.]bin hxxp://energigroup[.]hu/nNifdlrg32[.]bin |
Agent Tesla |
URL | hxxp://www[.]irofprague[.]net/b02a/ hxxp://www[.]nitedstatesofart[.]net/b02a/ hxxp://www[.]atellite-internet-74549[.]bond/b02a/ hxxp://www[.]zmi[.]info/b02a/ hxxp://www[.]vgtdvchvmdsvmdhbvgv[.]pro/b02a/ hxxp://www[.]ubbs[.]xyz/b02a/ hxxp://www[.]u5kt[.]net/b02a/ hxxp://www[.]airbypatrickmcguire[.]net/b02a/ hxxp://www[.]mpteamtoto88[.]today/b02a/ hxxp://www[.]vlisazouasiul[.]store/b02a/ hxxp://www[.]9kct[.]xyz/b02a/ hxxp://www[.]arjohbs[.]shop/b02a/ hxxp://www[.]argloscaremedia[.]info/b02a/ hxxp://www[.]luratu[.]xyz/b02a/ hxxp://www[.]kit[.]run/b02a/ hxxp://www[.]zliving[.]xyz/b02a/ hxxp://www[.]obistores[.]online/b02a/ hxxp://www[.]wdcb30[.]top/s7v2/ hxxp://www[.]everycreation[.]shop/nsev/ hxxp://www[.]limitlesssky[.]org/50p5/ hxxp://www[.]luismoreno[.]monster/06xo/ hxxp://www[.]dhkatp[.]vip/4qrw/ hxxp://www[.]hentaistgma[.]net/j6o1/ hxxp://www[.]promasterev[.]shop/zjp0/ hxxp://www[.]pethut[.]shop/wrhe/ hxxp://www[.]polarmuseum[.]info/m8hf/ hxxp://www[.]greekhause[.]org/tn42/ hxxp://www[.]allsolar[.]xyz/cph9/ hxxp://www[.]bismarckrecovery[.]com/kp5k/ hxxp://www[.]vegastinyhomes[.]net/f2tm/ hxxp://www[.]airbatchnow[.]online/ekgk/ hxxp://www[.]huemanstudio[.]today/0ob6/ hxxp://www[.]rtpngk[.]xyz/yd3l/ hxxp://www[.]mechecker[.]life/b6h1/ hxxp://www[.]lojashelp[.]video/ao78/ hxxp://www[.]tracy[.]club/rwcg/ hxxp://www[.]resumeyourway[.]info/vn92/ hxxp://www[.]kx507981[.]shop/q3r9/ hxxp://www[.]ohio-adr[.]net/j0y4/ hxxp://www[.]serverplay[.]live/6b8s/ hxxp://www[.]meg21c[.]top/3jg0/ hxxp://www[.]rockbull[.]pro/0tt2/ hxxp://www[.]trapkitten[.]website/y6hh/ hxxp://www[.]44ddw[.]top/3e3b/ hxxp://www[.]ngmr[.]xyz/4muf/ hxxp://www[.]sansensors[.]info/ip84/ hxxp://www[.]wdeb18[.]top/kv48/ hxxp://www[.]weatherbook[.]live/tfj4/ hxxp://www[.]pachuco[.]supply/7gdu/ hxxp://www[.]childlesscatlady[.]today/2kmz/ hxxp://www[.]kabaribukota[.]press/nr90/ hxxp://www[.]federall[.]store/afqz/ hxxp://www[.]inf30027group23[.]xyz/xzfm/ hxxp://www[.]allthingsjasmin[.]com/pbmf/ hxxp://www[.]ntn[.]solar/fcmy/ hxxp://www[.]torex33[.]online/pvct/ hxxp://www[.]platinumkitchens[.]info/dquo/ hxxp://www[.]eslameldaramlly[.]site/nlx0/ hxxp://www[.]theproselytizer[.]net/od1n/ hxxp://www[.]amitayush[.]digital/93j5/ hxxp://www[.]030002304[.]xyz/d7z8/ hxxp://www[.]aaavvejibej[.]bond/lh0g/ hxxp://www[.]useanecdotenow[.]tech/vera/ hxxp://www[.]bayarcepat19[.]click/q1x3/ hxxp://www[.]bluegirls[.]blog/g1ze/ hxxp://www[.]aromavida[.]net/4rlw/ hxxp://www[.]crochetpets[.]online/vand/ hxxp://www[.]queima[.]shop/mdoj/ hxxp://www[.]nojamaica[.]net/g7eq/ hxxp://www[.]komart[.]shop/b2t1/ hxxp://www[.]livemarkat[.]live/8h0p/ hxxp://www[.]d27dm[.]top/ptbb/ hxxp://www[.]rtpgaruda888resmi[.]xyz/u8o7/ hxxp://www[.]chalet-tofane[.]net/3bhs/ hxxp://www[.]xfgqbh[.]site/ir6g/ hxxp://www[.]mag-flex[.]com/ir6g/ hxxp://www[.]trisixnine[.]net/0057/ hxxp://www[.]softillery[.]info/cyhg/ hxxp://www[.]easestore[.]shop/qflp/ hxxp://www[.]yu35n[.]top/kejj/ hxxp://www[.]yourhomecopilot[.]online/gctn/ hxxp://www[.]fastr[.]live/gsjn/ hxxp://www[.]dto20[.]shop/efvy/ hxxp://www[.]uxzl[.]site/ir6g/ hxxp://www[.]carpmaxxbait[.]online/ir6g/ hxxp://www[.]dumpstedoctorca[.]com/ir6g/ hxxp://www[.]revelationfithub[.]com/ir6g/ hxxp://www[.]cuffbow[.]com/ir6g/ hxxp://www[.]hk9[.]xyz/ir6g/ hxxp://www[.]lollybowly[.]com/ir6g/ hxxp://www[.]aarunifoodcrafters[.]com/ir6g/ hxxp://www[.]jarvisandbrown[.]com/ir6g/ hxxp://www[.]gattosat[.]icu/ir6g/ hxxp://www[.]devocionmusic[.]com/ir6g/ hxxp://www[.]markthing[.]site/ir6g/ hxxp://www[.]myhosting[.]co[.]in/ir6g/ hxxp://www[.]solar-windturbine[.]life/ir6g/ hxxp://www[.]flusznwrldwide[.]com/ir6g/ hxxp://www[.]lifedrawingbristol[.]co[.]uk/ir6g/ hxxp://www[.]weberze[.]com/ir6g/ hxxp://www[.]getmylinks[.]cc/ir6g/ hxxp://www[.]aspasskeoffice[.]homes/ir6g/ hxxp://www[.]sathyfe[.]com/ir6g/ hxxp://www[.]electronicraw[.]com/ir6g/ hxxp://www[.]earn50k[.]com/ir6g/ hxxp://www[.]arasymimbi[.]com/ir6g/ hxxp://www[.]lriz[.]site/ir6g/ hxxp://www[.]pinnaclebyte[.]info/ir6g/ hxxp://www[.]avolci[.]com/ir6g/ hxxp://www[.]am8pw[.]us/ir6g/ hxxp://www[.]projectimprov[.]com/ir6g/ hxxp://www[.]energeticfranchise[.]top/ir6g/ hxxp://www[.]jamesgadzikmd[.]com/ir6g/ hxxp://www[.]kavanzi[.]com/ir6g/ hxxp://www[.]tupinkeept[.]cfd/ir6g/ hxxp://www[.]portfutures[.]asia/ir6g/ hxxp://www[.]cgm-logistics[.]org/ir6g/ hxxp://www[.]dutch-wildlife[.]shop/ir6g/ hxxp://www[.]dsisarl[.]com/ir6g/ hxxp://www[.]haftplicht[.]com/ir6g/ hxxp://www[.]roundhaygardenscene[.]com/ir6g/ hxxp://www[.]alace5[.]com/ir6g/ hxxp://www[.]mscfoundation[.]info/ir6g/ hxxp://www[.]brighterhomesdecor[.]com/ir6g/ hxxp://www[.]efidence[.]com/ir6g/ hxxp://www[.]tk254kr6rwr7mjtru[.]com/ir6g/ hxxp://www[.]haycoches[.]com/ir6g/ hxxp://www[.]electra-airways[.]info/ir6g/ hxxp://www[.]happiluv[.]com/ir6g/ hxxp://www[.]goog1evip15[.]com/ir6g/ hxxp://www[.]womenscalshion[.]com/ir6g/ hxxp://www[.]lenaguillemette[.]com/ir6g/ hxxp://www[.]mc9uh8d70[.]site/ir6g/ hxxp://www[.]scwspark[.]com/ir6g/ hxxp://www[.]royalkredit[.]online/ir6g/ hxxp://www[.]bkexclusivecars[.]net/ir6g/ hxxp://www[.]moncoop[.]coop/ir6g/ hxxp://www[.]tehranrizcomputer[.]com/ir6g/ hxxp://www[.]sazekents[.]cfd/ir6g/ hxxp://www[.]xediedie[.]icu/ir6g/ hxxp://www[.]eeja[.]uk/ir6g/ hxxp://www[.]iwin[.]exposed/ir6g/ hxxp://www[.]ok2yu[.]us/ir6g/ hxxp://www[.]zwetststuren[.]cfd/ir6g/ hxxp://www[.]fraternize[.]org/ir6g/ |
Formbook |
URL | hxxp://1[.]12[.]235[.]247:4434/Ezf8 | Cobalt Strike |
URL | hxxp://mtspsmjeli[.]sch[.]id/cl/XP_remcos%202021_HzUYr10[.]bin | CloudEyE |
URL | hxxps://aquila[.]mt/prudatweak/updater[.]exe hxxp://3[.]86[.]167[.]64/fag3[.]exe hxxp://3[.]86[.]167[.]64/fag[.]exe |
Quasar RAT |
URL | hxxps://tmpfiles[.]org/dl/19921232/build[.]exe hxxp://185[.]215[.]113[.]39/files/5765828710/WP9kUB7[.]exe |
RedLine Stealer |
URL | hxxp://lbnfbehmicmkceh[.]top/1[.]php hxxps://opticna[.]com/4e1w[.]js hxxps://terrenalia[.]com/Woot[.]zip hxxps://pictureiol[.]top/work/upload[.]php hxxps://pictureiol[.]top/work/index[.]php hxxps://pictureiol[.]top/work/original[.]js hxxps://opticna[.]com/js[.]php |
FAKEUPDATES |
URL | hxxp://178[.]215[.]224[.]105:9076/LIDL-Documents[.]vbs hxxps://mocdrol[.]com[.]br/calculator[.]txt |
Remcos |