サイバーリスク情報提供 Dアラート 特許取得済み

不正URLへのアクセス、不正メールの受信

メール受信した
弊社お客様
0 URLアクセスした
弊社お客様
3
2025/01/28
※2025/01/30 更新
マルウェア感染させると考えられるURLを検知(2025/01/28)
■IoC(※1)
Type: IOC: Signature:
URL hxxp://82[.]146[.]42[.]97/Image/ProtonBetterprotectLine/poll/VmGeo/AuthgeoPrivateWp/DefaultcdnSqlPublic/http27http/Secure/pythonRequest18/Http/Datalife/60uploadsGenerator/3Db/8Protect7/asyncPrivate/serverProviderDump/CpuProtect/protectpublicVoiddb/httpTo/Javascript_RequestAuthServerprotectpublicdownloads[.]php
hxxp://438286cm[.]nyashnyash[.]ru/videopipeHttpPacketserverWordpressDleuploads[.]php
DCRat
URL hxxps://volcanoyev[.]click/api
hxxp://176[.]113[.]115[.]225/c[.]jpg
hxxp://176[.]113[.]115[.]225/a[.]jpg
hxxp://176[.]113[.]115[.]225/b[.]jpg
hxxps://pwedereihge[.]shop/api
hxxps://dinopsych[.]com/?t=4
hxxps://xorok[.]shop/Racoona[.]eml
hxxp://promoforge360[.]com/677332d0f24fde066b58b260
hxxp://tremista[.]com/676c76a6a464ed59c1298843
Lumma Stealer
URL hxxp://45[.]61[.]137[.]151/1a90bc2aa73eeb41/sqlite3[.]dll
hxxps://23[.]88[.]122[.]134/579d5c7e95a610c1/vcruntime140[.]dll
hxxps://162[.]55[.]215[.]42/c8d1769211d0cfb0[.]php
hxxp://91[.]239[.]53[.]29/d925e943a21dd486/freebl3[.]dll
hxxp://91[.]239[.]53[.]29/d925e943a21dd486/nss3[.]dll
hxxp://91[.]239[.]53[.]29/d925e943a21dd486/softokn3[.]dll?
hxxp://91[.]239[.]53[.]29/d925e943a21dd486/mozglue[.]dll
hxxp://91[.]239[.]53[.]29/d925e943a21dd486/msvcp140[.]dll
hxxp://91[.]239[.]53[.]29/d925e943a21dd486/vcruntime140[.]dll
hxxp://91[.]239[.]53[.]29/d925e943a21dd486/sqlite3[.]dll
Stealc
URL hxxps://solve[.]lqwt[.]org/awjsx[.]captcha
hxxps://solve[.]dpqx[.]org/awjsx[.]captcha
ClearFake
URL hxxps://goldenbirdhub[.]xyz/Y2VmOGI0NTIwZTE5/
hxxps://rabbitkeske8[.]xyz/ZDBhYWRlZWY0ZjU3/
Coper
URL hxxp://84[.]200[.]154[.]119/sh4
hxxp://160[.]191[.]245[.]20/main_arm7
Bashlite
URL hxxp://gadgco[.]com/tmp/index[.]php
hxxp://niksplus[.]ru/tmp/index[.]php
hxxp://officsolo[.]biz/tmp/index[.]php
hxxp://pkodev[.]net/tmp/index[.]php
SmokeLoader
URL hxxp://85[.]31[.]47[.]84/adsafref/Panel/five/fre[.]php
hxxp://85[.]31[.]47[.]84:5336/adsafref/Panel/five/fre[.]php
hxxp://85[.]31[.]47[.]84:5336/adsafref/Panel/five/PvqDq929BSx_A_D_M1n_a[.]php
LokiBot
URL hxxp://45[.]138[.]183[.]226/upload/T[.]exe XWorm
URL hxxps://energigroup[.]hu/WRlalDGsST0[.]bin
hxxps://energigroup[.]hu/nNifdlrg32[.]bin
hxxp://energigroup[.]hu/WRlalDGsST0[.]bin
hxxp://energigroup[.]hu/nNifdlrg32[.]bin
Agent Tesla
URL hxxp://www[.]irofprague[.]net/b02a/
hxxp://www[.]nitedstatesofart[.]net/b02a/
hxxp://www[.]atellite-internet-74549[.]bond/b02a/
hxxp://www[.]zmi[.]info/b02a/
hxxp://www[.]vgtdvchvmdsvmdhbvgv[.]pro/b02a/
hxxp://www[.]ubbs[.]xyz/b02a/
hxxp://www[.]u5kt[.]net/b02a/
hxxp://www[.]airbypatrickmcguire[.]net/b02a/
hxxp://www[.]mpteamtoto88[.]today/b02a/
hxxp://www[.]vlisazouasiul[.]store/b02a/
hxxp://www[.]9kct[.]xyz/b02a/
hxxp://www[.]arjohbs[.]shop/b02a/
hxxp://www[.]argloscaremedia[.]info/b02a/
hxxp://www[.]luratu[.]xyz/b02a/
hxxp://www[.]kit[.]run/b02a/
hxxp://www[.]zliving[.]xyz/b02a/
hxxp://www[.]obistores[.]online/b02a/
hxxp://www[.]wdcb30[.]top/s7v2/
hxxp://www[.]everycreation[.]shop/nsev/
hxxp://www[.]limitlesssky[.]org/50p5/
hxxp://www[.]luismoreno[.]monster/06xo/
hxxp://www[.]dhkatp[.]vip/4qrw/
hxxp://www[.]hentaistgma[.]net/j6o1/
hxxp://www[.]promasterev[.]shop/zjp0/
hxxp://www[.]pethut[.]shop/wrhe/
hxxp://www[.]polarmuseum[.]info/m8hf/
hxxp://www[.]greekhause[.]org/tn42/
hxxp://www[.]allsolar[.]xyz/cph9/
hxxp://www[.]bismarckrecovery[.]com/kp5k/
hxxp://www[.]vegastinyhomes[.]net/f2tm/
hxxp://www[.]airbatchnow[.]online/ekgk/
hxxp://www[.]huemanstudio[.]today/0ob6/
hxxp://www[.]rtpngk[.]xyz/yd3l/
hxxp://www[.]mechecker[.]life/b6h1/
hxxp://www[.]lojashelp[.]video/ao78/
hxxp://www[.]tracy[.]club/rwcg/
hxxp://www[.]resumeyourway[.]info/vn92/
hxxp://www[.]kx507981[.]shop/q3r9/
hxxp://www[.]ohio-adr[.]net/j0y4/
hxxp://www[.]serverplay[.]live/6b8s/
hxxp://www[.]meg21c[.]top/3jg0/
hxxp://www[.]rockbull[.]pro/0tt2/
hxxp://www[.]trapkitten[.]website/y6hh/
hxxp://www[.]44ddw[.]top/3e3b/
hxxp://www[.]ngmr[.]xyz/4muf/
hxxp://www[.]sansensors[.]info/ip84/
hxxp://www[.]wdeb18[.]top/kv48/
hxxp://www[.]weatherbook[.]live/tfj4/
hxxp://www[.]pachuco[.]supply/7gdu/
hxxp://www[.]childlesscatlady[.]today/2kmz/
hxxp://www[.]kabaribukota[.]press/nr90/
hxxp://www[.]federall[.]store/afqz/
hxxp://www[.]inf30027group23[.]xyz/xzfm/
hxxp://www[.]allthingsjasmin[.]com/pbmf/
hxxp://www[.]ntn[.]solar/fcmy/
hxxp://www[.]torex33[.]online/pvct/
hxxp://www[.]platinumkitchens[.]info/dquo/
hxxp://www[.]eslameldaramlly[.]site/nlx0/
hxxp://www[.]theproselytizer[.]net/od1n/
hxxp://www[.]amitayush[.]digital/93j5/
hxxp://www[.]030002304[.]xyz/d7z8/
hxxp://www[.]aaavvejibej[.]bond/lh0g/
hxxp://www[.]useanecdotenow[.]tech/vera/
hxxp://www[.]bayarcepat19[.]click/q1x3/
hxxp://www[.]bluegirls[.]blog/g1ze/
hxxp://www[.]aromavida[.]net/4rlw/
hxxp://www[.]crochetpets[.]online/vand/
hxxp://www[.]queima[.]shop/mdoj/
hxxp://www[.]nojamaica[.]net/g7eq/
hxxp://www[.]komart[.]shop/b2t1/
hxxp://www[.]livemarkat[.]live/8h0p/
hxxp://www[.]d27dm[.]top/ptbb/
hxxp://www[.]rtpgaruda888resmi[.]xyz/u8o7/
hxxp://www[.]chalet-tofane[.]net/3bhs/
hxxp://www[.]xfgqbh[.]site/ir6g/
hxxp://www[.]mag-flex[.]com/ir6g/
hxxp://www[.]trisixnine[.]net/0057/
hxxp://www[.]softillery[.]info/cyhg/
hxxp://www[.]easestore[.]shop/qflp/
hxxp://www[.]yu35n[.]top/kejj/
hxxp://www[.]yourhomecopilot[.]online/gctn/
hxxp://www[.]fastr[.]live/gsjn/
hxxp://www[.]dto20[.]shop/efvy/
hxxp://www[.]uxzl[.]site/ir6g/
hxxp://www[.]carpmaxxbait[.]online/ir6g/
hxxp://www[.]dumpstedoctorca[.]com/ir6g/
hxxp://www[.]revelationfithub[.]com/ir6g/
hxxp://www[.]cuffbow[.]com/ir6g/
hxxp://www[.]hk9[.]xyz/ir6g/
hxxp://www[.]lollybowly[.]com/ir6g/
hxxp://www[.]aarunifoodcrafters[.]com/ir6g/
hxxp://www[.]jarvisandbrown[.]com/ir6g/
hxxp://www[.]gattosat[.]icu/ir6g/
hxxp://www[.]devocionmusic[.]com/ir6g/
hxxp://www[.]markthing[.]site/ir6g/
hxxp://www[.]myhosting[.]co[.]in/ir6g/
hxxp://www[.]solar-windturbine[.]life/ir6g/
hxxp://www[.]flusznwrldwide[.]com/ir6g/
hxxp://www[.]lifedrawingbristol[.]co[.]uk/ir6g/
hxxp://www[.]weberze[.]com/ir6g/
hxxp://www[.]getmylinks[.]cc/ir6g/
hxxp://www[.]aspasskeoffice[.]homes/ir6g/
hxxp://www[.]sathyfe[.]com/ir6g/
hxxp://www[.]electronicraw[.]com/ir6g/
hxxp://www[.]earn50k[.]com/ir6g/
hxxp://www[.]arasymimbi[.]com/ir6g/
hxxp://www[.]lriz[.]site/ir6g/
hxxp://www[.]pinnaclebyte[.]info/ir6g/
hxxp://www[.]avolci[.]com/ir6g/
hxxp://www[.]am8pw[.]us/ir6g/
hxxp://www[.]projectimprov[.]com/ir6g/
hxxp://www[.]energeticfranchise[.]top/ir6g/
hxxp://www[.]jamesgadzikmd[.]com/ir6g/
hxxp://www[.]kavanzi[.]com/ir6g/
hxxp://www[.]tupinkeept[.]cfd/ir6g/
hxxp://www[.]portfutures[.]asia/ir6g/
hxxp://www[.]cgm-logistics[.]org/ir6g/
hxxp://www[.]dutch-wildlife[.]shop/ir6g/
hxxp://www[.]dsisarl[.]com/ir6g/
hxxp://www[.]haftplicht[.]com/ir6g/
hxxp://www[.]roundhaygardenscene[.]com/ir6g/
hxxp://www[.]alace5[.]com/ir6g/
hxxp://www[.]mscfoundation[.]info/ir6g/
hxxp://www[.]brighterhomesdecor[.]com/ir6g/
hxxp://www[.]efidence[.]com/ir6g/
hxxp://www[.]tk254kr6rwr7mjtru[.]com/ir6g/
hxxp://www[.]haycoches[.]com/ir6g/
hxxp://www[.]electra-airways[.]info/ir6g/
hxxp://www[.]happiluv[.]com/ir6g/
hxxp://www[.]goog1evip15[.]com/ir6g/
hxxp://www[.]womenscalshion[.]com/ir6g/
hxxp://www[.]lenaguillemette[.]com/ir6g/
hxxp://www[.]mc9uh8d70[.]site/ir6g/
hxxp://www[.]scwspark[.]com/ir6g/
hxxp://www[.]royalkredit[.]online/ir6g/
hxxp://www[.]bkexclusivecars[.]net/ir6g/
hxxp://www[.]moncoop[.]coop/ir6g/
hxxp://www[.]tehranrizcomputer[.]com/ir6g/
hxxp://www[.]sazekents[.]cfd/ir6g/
hxxp://www[.]xediedie[.]icu/ir6g/
hxxp://www[.]eeja[.]uk/ir6g/
hxxp://www[.]iwin[.]exposed/ir6g/
hxxp://www[.]ok2yu[.]us/ir6g/
hxxp://www[.]zwetststuren[.]cfd/ir6g/
hxxp://www[.]fraternize[.]org/ir6g/
Formbook
URL hxxp://1[.]12[.]235[.]247:4434/Ezf8 Cobalt Strike
URL hxxp://mtspsmjeli[.]sch[.]id/cl/XP_remcos%202021_HzUYr10[.]bin CloudEyE
URL hxxps://aquila[.]mt/prudatweak/updater[.]exe
hxxp://3[.]86[.]167[.]64/fag3[.]exe
hxxp://3[.]86[.]167[.]64/fag[.]exe
Quasar RAT
URL hxxps://tmpfiles[.]org/dl/19921232/build[.]exe
hxxp://185[.]215[.]113[.]39/files/5765828710/WP9kUB7[.]exe
RedLine Stealer
URL hxxp://lbnfbehmicmkceh[.]top/1[.]php
hxxps://opticna[.]com/4e1w[.]js
hxxps://terrenalia[.]com/Woot[.]zip
hxxps://pictureiol[.]top/work/upload[.]php
hxxps://pictureiol[.]top/work/index[.]php
hxxps://pictureiol[.]top/work/original[.]js
hxxps://opticna[.]com/js[.]php
FAKEUPDATES
URL hxxp://178[.]215[.]224[.]105:9076/LIDL-Documents[.]vbs
hxxps://mocdrol[.]com[.]br/calculator[.]txt
Remcos
※1「i-FILTER」アクセスログを検索し端末を特定してください 不要なアクセスを避けるため、一部変更しております。 ■製品対応状況(※2) ▽i-FILTER(※3) ・[脅威情報サイト]カテゴリでブロック可能 ※2 ブロックの可否は各製品の設定によるため、実際の結果はアクセスログを参照してください。 ※3 暗号化された通信の場合は、SSL Adapterの設定を「利用」にする必要があります。
イベント・セミナー情報