不正URLへのアクセス、不正メールの受信
-
メール受信した
弊社お客様0社 URLアクセスした
弊社お客様23社 -
2025/03/03
※2025/03/03 更新
マルウェア感染させると考えられるURLを検知(2025/03/03)
■IoC(※1)
Type: | IOC: | Signature: |
---|---|---|
URL | hxxp://193[.]200[.]78[.]49/tftp hxxp://52[.]66[.]212[.]238/yakuza[.]ppc hxxp://52[.]66[.]212[.]238/yakuza[.]i586 hxxp://52[.]66[.]212[.]238/yakuza[.]mips hxxp://52[.]66[.]212[.]238/yakuza[.]arm6 hxxp://52[.]62[.]119[.]131/hidakibest[.]arm4 hxxp://52[.]66[.]212[.]238/yakuza[.]m68k hxxp://52[.]62[.]119[.]131/hidakibest[.]mips hxxp://52[.]66[.]212[.]238/yakuza[.]x86 hxxp://52[.]66[.]212[.]238/yakuza[.]arm4 hxxp://104[.]194[.]9[.]127/vv/armv4eb hxxp://104[.]194[.]9[.]127/vv/mipsel hxxp://104[.]194[.]9[.]127/tt/mipsel64 hxxp://104[.]194[.]9[.]127/vv/armv4l hxxp://193[.]143[.]1[.]63/e hxxp://193[.]143[.]1[.]63/vv/armv5l hxxp://104[.]194[.]9[.]127/v hxxp://104[.]194[.]9[.]127/vv/armv7l hxxp://104[.]194[.]9[.]127/vv/armv6l hxxp://104[.]194[.]9[.]127/tt/mips hxxp://193[.]143[.]1[.]63/vv/i686 hxxp://193[.]143[.]1[.]63/r hxxp://104[.]194[.]9[.]127/tt/sparc hxxp://104[.]194[.]9[.]127/tt/riscv32 hxxp://104[.]194[.]9[.]127/k hxxp://104[.]194[.]9[.]127/ee/armv4eb hxxp://104[.]194[.]9[.]127/vv/sparc hxxp://193[.]143[.]1[.]63/tt/sh4 hxxp://104[.]194[.]9[.]127/tt/i686 hxxp://193[.]143[.]1[.]63/vv/sh4 hxxp://104[.]194[.]9[.]127/vv/sh4 hxxp://193[.]143[.]1[.]63/n hxxp://104[.]194[.]9[.]127/n hxxp://193[.]143[.]1[.]63/vv/riscv32 hxxp://104[.]194[.]9[.]127/u hxxp://104[.]194[.]9[.]127/vv/riscv32 hxxp://104[.]194[.]9[.]127/vv/mips hxxp://104[.]194[.]9[.]127/tt/mips64 hxxp://104[.]194[.]9[.]127/ee/armv4l hxxp://104[.]194[.]9[.]127/tt/sh4 hxxp://104[.]194[.]9[.]127/ee/armv5l hxxp://104[.]194[.]9[.]127/vv/mips64 hxxp://193[.]143[.]1[.]63/vv/armv6l hxxp://104[.]194[.]9[.]127/tt/mipsel hxxp://104[.]194[.]9[.]127/vv/armv5l hxxp://104[.]194[.]9[.]127/ee/armv6l hxxp://193[.]143[.]1[.]63/vv/powerpc hxxp://104[.]194[.]9[.]127/tt/armv6l hxxp://104[.]194[.]9[.]127/tt/armv7l hxxp://104[.]194[.]9[.]127/vv/powerpc hxxp://104[.]194[.]9[.]127/vv/arc hxxp://104[.]194[.]9[.]127/tt/arc hxxp://104[.]194[.]9[.]127/tt/armv4eb hxxp://104[.]194[.]9[.]127/tt/armv5l hxxp://104[.]194[.]9[.]127/ee/armv7l hxxp://193[.]143[.]1[.]63/tt/i686 hxxp://104[.]194[.]9[.]127/tt/powerpc hxxp://104[.]194[.]9[.]127/vv/i686 hxxp://193[.]143[.]1[.]63/vv/armv4l hxxp://193[.]143[.]1[.]63/k hxxp://193[.]143[.]1[.]63/v hxxp://104[.]194[.]9[.]127/tt/armv4l hxxp://104[.]194[.]9[.]127/l hxxp://104[.]194[.]9[.]127/s hxxp://104[.]194[.]9[.]127/t hxxp://104[.]194[.]9[.]127/e hxxp://104[.]194[.]9[.]127/f hxxp://193[.]143[.]1[.]63/c hxxp://104[.]194[.]9[.]127/r hxxp://193[.]143[.]1[.]63/l hxxp://193[.]143[.]1[.]63/s hxxp://193[.]143[.]1[.]63/t hxxp://104[.]194[.]9[.]127/c hxxp://193[.]143[.]1[.]63/f hxxp://193[.]143[.]1[.]63/u hxxp://193[.]143[.]1[.]63/tt/mipsel64 hxxp://193[.]143[.]1[.]63/tt/arc hxxp://193[.]143[.]1[.]63/vv/mips hxxp://193[.]143[.]1[.]63/tt/powerpc hxxp://193[.]143[.]1[.]63/vv/armv7l hxxp://193[.]143[.]1[.]63/tt/mips hxxp://193[.]143[.]1[.]63/ee/armv6l hxxp://193[.]143[.]1[.]63/tt/mipsel hxxp://193[.]143[.]1[.]63/vv/mipsel hxxp://193[.]143[.]1[.]63/vv/arc hxxp://193[.]143[.]1[.]63/tt/mips64 hxxp://193[.]143[.]1[.]63/tt/sparc hxxp://193[.]143[.]1[.]63/vv/armv4eb hxxp://193[.]143[.]1[.]63/ee/armv4l hxxp://193[.]143[.]1[.]63/vv/mips64 hxxp://193[.]143[.]1[.]63/tt/armv5l hxxp://193[.]143[.]1[.]63/tt/armv7l hxxp://193[.]143[.]1[.]63/tt/riscv32 hxxp://193[.]143[.]1[.]63/ee/armv4eb hxxp://193[.]143[.]1[.]63/ee/armv7l hxxp://193[.]143[.]1[.]63/tt/armv6l hxxp://193[.]143[.]1[.]63/vv/sparc hxxp://193[.]143[.]1[.]63/tt/armv4eb hxxp://193[.]143[.]1[.]63/ee/armv5l hxxp://193[.]143[.]1[.]63/tt/armv4l hxxp://87[.]121[.]84[.]116/iloveviki/viki[.]x64 hxxp://87[.]121[.]84[.]116/iloveviki/viki[.]x86 hxxp://87[.]121[.]84[.]116/iloveviki/viki[.]x86-64 hxxp://87[.]121[.]84[.]116/iloveviki/viki[.]arm64 hxxp://87[.]121[.]84[.]116/iloveviki/viki[.]386 hxxp://87[.]121[.]84[.]116/iloveviki/viki[.]i386 hxxp://87[.]121[.]84[.]116/iloveviki/viki[.]amd64 hxxp://87[.]121[.]84[.]116/iloveviki/all[.]sh hxxp://185[.]157[.]247[.]126/tsh4 hxxp://194[.]85[.]251[.]73/iloveviki/viki[.]arm64 hxxp://23[.]157[.]176[.]170/load[.]sh hxxp://185[.]232[.]205[.]129/x86 hxxp://185[.]232[.]205[.]129/mips hxxp://185[.]232[.]205[.]129/weed hxxp://185[.]232[.]205[.]129/wget[.]sh hxxp://102[.]219[.]181[.]231/c2/load[.]sh hxxp://dianzanla[.]com/jackmyi586 hxxp://dianzanla[.]com/jackmyarmv6 hxxp://dianzanla[.]com/jackmym86k hxxp://dianzanla[.]com/jackmyi686 hxxp://dianzanla[.]com/jackmysparc hxxp://dianzanla[.]com/jackmymips hxxp://dianzanla[.]com/jackmyarmv4 hxxp://dianzanla[.]com/jackmypowerpc hxxp://dianzanla[.]com/jackmyx86 hxxp://dianzanla[.]com/jackmyarmv5 hxxp://dianzanla[.]com/jackmysh4 hxxp://dianzanla[.]com/jackmymipsel hxxp://dianzanla[.]com/bins[.]sh hxxp://165[.]154[.]224[.]116/jackmyi686 hxxp://165[.]154[.]224[.]116/jackmyi586 hxxp://165[.]154[.]224[.]116/jackmymipsel hxxp://165[.]154[.]224[.]116/jackmym86k hxxp://165[.]154[.]224[.]116/jackmysparc hxxp://165[.]154[.]224[.]116/jackmymips hxxp://165[.]154[.]224[.]116/jackmyarmv4 hxxp://165[.]154[.]224[.]116/jackmypowerpc hxxp://165[.]154[.]224[.]116/jackmysh4 hxxp://165[.]154[.]224[.]116/jackmyx86 hxxp://165[.]154[.]224[.]116/jackmyarmv6 hxxp://165[.]154[.]224[.]116/jackmyarmv5 |
Bashlite |
URL | hxxps://aiqinsights[.]icu/api hxxps://pukisound[.]icu/api hxxps://chlenvaginakz[.]icu/api hxxp://176[.]113[.]115[.]7/files/7481626938/MCxU5Fj[.]exe hxxps://dawtastream[.]bet/api hxxp://176[.]113[.]115[.]7/files/6416878235/FydOzyQ[.]exe hxxps://reservation-confirms[.]com/in[.]php?action=1 hxxps://ggepllay[.]com/in[.]php?action=2 hxxps://procedeed-verific[.]com/in[.]php?action=2 hxxps://important-confirmation[.]com/in[.]php?action=2 hxxps://ggepiay[.]com/in[.]php?action=2 hxxps://fxepiay[.]com/in[.]php?action=2 hxxps://important-confiirm[.]com/in[.]php?action=2 hxxps://reservation-confirms[.]com/in[.]php?action=2 hxxps://fxepiay[.]com/in[.]php?action=1 hxxps://important-confiirm[.]com/in[.]php?action=1 hxxps://procedeed-verific[.]com/in[.]php?action=1 hxxps://ggepllay[.]com/in[.]php?action=1 hxxps://important-confirmation[.]com/in[.]php?action=1 hxxps://ggepiay[.]com/in[.]php?action=1 hxxps://payment[.]verification-proceess[.]com/in[.]php?action=1 hxxps://payment[.]verification-proceess[.]com/in[.]php?action=2 hxxps://verification-proceess[.]com/in[.]php?action=2 hxxps://leafvypathways[.]top/api hxxps://www[.]benshamcentre[.]co[.]uk/continue/45[.]ps1 hxxps://electronicpgioneers[.]live/login hxxp://176[.]113[.]115[.]7/files/6142491850/FvbuInU[.]exe hxxps://bizmir[.]shop/powergem[.]mp3 hxxp://62[.]60[.]226[.]112/public_files/omrnimg[.]txt hxxp://62[.]60[.]226[.]112/public_files/ajgoFab[.]txt hxxp://62[.]60[.]226[.]112/public_files/rjamfkg[.]txt hxxps://oak-smash[.]cyou/api hxxps://printerdiallog[.]fun/api hxxps://cybgerlaunch[.]digital/api hxxps://blissfttulmoments[.]top/api hxxps://tampermonkey06[.]top/api hxxps://bloodyeleftor[.]world/api hxxps://creativehjub[.]tech/api hxxps://brjightfuture[.]tech/api hxxps://pastedeputten[.]life/api hxxps://tampermonkey03[.]top/api hxxps://subawhipnator[.]life/api hxxps://tampermonkey08[.]top/api hxxps://tampermonkey02[.]top/api hxxps://smart-living365[.]top/api hxxps://disobilittyhell[.]live/api hxxp://62[.]60[.]226[.]112/public_files/hkkcrng[.]txt hxxp://176[.]113[.]115[.]7/files/qqdoup/random[.]exe hxxps://jowyfulbloom[.]shop/api hxxps://innojvatech[.]shop/api hxxps://tqechtrends[.]shop/api hxxps://earthsymphzony[.]today/api hxxps://gadgsetflow[.]shop/api hxxps://exarthynature[.]run/api hxxps://digitalcrdjafters[.]top/api hxxps://datadynnamics[.]today/api hxxps://towerymodest[.]top/api hxxps://reliefintorud[.]life/api hxxps://pipesofmugge[.]fun/api hxxps://naturerbhythm[.]world/api hxxps://naturjalharmony[.]top/api hxxps://markerjurys[.]cyou/api hxxps://moduledbillke[.]world/api hxxps://natureexpflorer[.]run/api hxxps://nateurescanvas[.]world/api hxxps://netgineero[.]life/api hxxps://goldensounew[.]world/api hxxps://grainybande[.]life/api hxxps://hideousown[.]top/api hxxps://gesturedseedz[.]fun/api hxxps://forfardunifor[.]world/api hxxps://foortyturhud[.]run/api hxxps://exposedbuid[.]life/api hxxps://fortunedtrivial[.]top/api hxxps://digitalfxorge[.]world/api hxxps://elegantlawwen[.]run/api hxxps://difgitalnexus[.]run/api hxxps://desribessquwd[.]today/api hxxps://entereddeacr[.]run/api hxxps://crystahlclearwaters[.]bet/api hxxps://earwaxeduek[.]run/api hxxps://alcohopreden[.]top/api hxxps://bloomingzgardens[.]today/api hxxp://176[.]113[.]115[.]7/files/fate/random[.]exe hxxps://uploadhaven[.]store/ewest[.]m4a hxxps://wildxflowerdream[.]life/api hxxps://163[.]5[.]32[.]73/GlobalDesk[.]exe hxxp://163[.]5[.]32[.]73/GlobalDesk[.]exe hxxps://banappeals[.]net/GlobalDesk[.]exe hxxps://pevemtnchil[.]live/api hxxps://tracnquilforest[.]life/api hxxps://starrynsightsky[.]icu/api hxxps://circujitstorm[.]bet/api hxxps://techpxioneers[.]run/api hxxps://foresctwhispers[.]top/api hxxps://calmingtefxtures[.]run/api hxxps://experimentalideas[.]today/api hxxps://gadgethgfub[.]icu/api hxxps://hardrwarehaven[.]run/api hxxps://techmindzs[.]live/api hxxps://codxefusion[.]top/api hxxps://quietswtreams[.]life/api hxxps://techspherxe[.]top/api hxxps://hardswarehub[.]today/api |
Lumma Stealer |
URL | hxxp://62[.]60[.]226[.]112/file/3601_2042[.]exe hxxps://github[.]com/Oscarito20222/diciembre/raw/refs/heads/main/sena[.]exe hxxps://marubeni[.]cc/mpclient[.]dll hxxps://marubeni[.]cc/Acuerdo_de_Orden_de_Compra[.]exe hxxps://45[.]11[.]59[.]49/mpclient[.]dll hxxp://45[.]11[.]59[.]49/mpclient[.]dll hxxp://23[.]95[.]60[.]80/677/krna/nicepersonforsweetkissinggirlformygirl[.]hta hxxp://192[.]3[.]95[.]138/213/seethebestthingswecandothatwithgreatness[.]gIF hxxp://23[.]95[.]235[.]9/550/mis/seethebestjourneygivenmebestthingswithbettercasaes[.]hta hxxp://192[.]3[.]95[.]138/213/seetha/seethebestthingswecandothatwithgreatness[.]hta hxxp://45[.]11[.]59[.]49/Acuerdo_de_Orden_de_Compra[.]exe hxxps://45[.]11[.]59[.]49/Acuerdo_de_Orden_de_Compra[.]exe |
Remcos |
URL | hxxps://apxservices[.]esrv[.]me/app/svchost[.]exe | Venom RAT |
URL | hxxps://www[.]mediafire[.]com/file_premium/8q094mjevfshw6g/glass[.]mp3/file hxxps://check[.]vehom[.]icu/gkcxv[.]google hxxps://check[.]luboz[.]icu/gkcxv[.]google hxxps://check[.]xapus[.]icu/gkcxv[.]google hxxps://check[.]fafyd[.]icu/gkcxv[.]google hxxps://check[.]nuwab[.]icu/gkcxv[.]google hxxps://check[.]mijuf[.]icu/gkcxv[.]google hxxps://check[.]mosat[.]icu/gkcxv[.]google hxxps://check[.]cined[.]icu/gkcxv[.]google hxxps://check[.]remag[.]icu/gkcxv[.]google hxxps://check[.]myfet[.]icu/gkcxv[.]google hxxps://check[.]jixal[.]icu/gkcxv[.]google hxxps://check[.]hysuz[.]icu/gkcxv[.]google hxxps://check[.]qogur[.]icu/gkcxv[.]google hxxps://check[.]qozil[.]icu/gkcxv[.]google hxxps://check[.]woqym[.]icu/gkcxv[.]google hxxps://check[.]bipyl[.]icu/gkcxv[.]google hxxps://check[.]qitub[.]icu/gkcxv[.]google hxxps://check[.]pojon[.]icu/gkcxv[.]google hxxps://check[.]vudih[.]icu/gkcxv[.]google hxxps://check[.]cuzon[.]icu/gkcxv[.]google hxxps://check[.]zixeq[.]icu/gkcxv[.]google hxxps://check[.]danob[.]icu/gkcxv[.]google hxxps://check[.]pidal[.]icu/gkcxv[.]google hxxps://check[.]gytec[.]icu/gkcxv[.]google hxxps://check[.]gejop[.]icu/gkcxv[.]google hxxps://check[.]wowuk[.]icu/gkcxv[.]google hxxps://check[.]vykud[.]icu/gkcxv[.]google hxxps://check[.]bifuh[.]icu/gkcxv[.]google hxxps://check[.]kupav[.]icu/gkcxv[.]google hxxps://check[.]kekid[.]icu/gkcxv[.]google hxxps://check[.]suqev[.]icu/gkcxv[.]google hxxps://check[.]ninif[.]icu/gkcxv[.]google hxxps://check[.]tyheb[.]icu/gkcxv[.]google hxxps://check[.]zagyw[.]icu/gkcxv[.]google hxxps://check[.]somiv[.]icu/gkcxv[.]google hxxps://check[.]neweb[.]icu/gkcxv[.]google hxxps://check[.]wezop[.]icu/gkcxv[.]google hxxps://check[.]jaxim[.]icu/gkcxv[.]google hxxps://check[.]gykem[.]icu/gkcxv[.]google hxxps://vaultcord[.]net/assets/captcha[.]exe hxxps://check[.]wygoq[.]icu/gkcxv[.]google hxxps://check[.]tubyf[.]icu/gkcxv[.]google |
ClearFake |
URL | hxxp://expertuslugi[.]top/Documents/file[.]lnk hxxp://01[.]pogoda86[.]online/Documents/file[.]lnk hxxp://62[.]133[.]61[.]101/Documents/file[.]lnk |
QakBot |
URL | hxxps://94[.]156[.]177[.]41/scc4/five/PvqDq929BSx_A_D_M1n_a[.]php hxxps://centrehotel[.]vn/wp1/Panel/fre[.]php hxxps://centrehotel[.]vn/wp/Panel/fre[.]php hxxp://centrehotel[.]vn/wp1/Panel/fre[.]php hxxp://centrehotel[.]vn/wp/Panel/fre[.]php |
LokiBot |
URL | hxxps://193[.]124[.]185[.]114/LjJDHIMSFH/index[.]php hxxp://176[.]113[.]115[.]7/mine/random[.]exe hxxp://176[.]113[.]115[.]6/Ni9kiput/index[.]php hxxp://185[.]215[.]113[.]209/di0her478/index[.]php hxxp://62[.]60[.]226[.]15/8fj482jd9/index[.]php hxxp://176[.]113[.]115[.]6/Ni9kiput/Login[.]php hxxp://176[.]113[.]115[.]7/files/748049926/bwuGbC2[.]exe hxxp://cobolrationumelawrtewarms[.]com/3ofn3jf3e2ljk/Plugins/cred[.]dll hxxp://cobolrationumelawrtewarms[.]com/3ofn3jf3e2ljk/Plugins/cred64[.]dll hxxp://cobolrationumelawrtewarms[.]com/3ofn3jf3e2ljk/Plugins/clip64[.]dll hxxp://cobolrationumelawrtewarms[.]com/3ofn3jf3e2ljk/Plugins/clip[.]dll hxxp://176[.]113[.]115[.]7/test/exe/random[.]exe hxxp://176[.]113[.]115[.]7/test/am_no[.]bat hxxp://185[.]215[.]113[.]16/test/am_no[.]bat |
Amadey |
URL | hxxps://79[.]137[.]206[.]248/d210652e231a5729/vcruntime140[.]dll hxxps://45[.]88[.]76[.]205/3a8d14c36ef0a8cc/sqlite3[.]dll hxxps://45[.]88[.]76[.]205/3a8d14c36ef0a8cc/vcruntime140[.]dll hxxps://45[.]88[.]76[.]205/3a8d14c36ef0a8cc/mozglue[.]dll hxxp://185[.]28[.]119[.]223/55145c8889ec57f2/mozglue[.]dll hxxps://104[.]252[.]127[.]64/12f8d7cc8b7f3b56/sqlite3[.]dll hxxp://185[.]28[.]119[.]223/55145c8889ec57f2/sqlite3[.]dll hxxp://193[.]233[.]48[.]86/849027f16851d4a2/vcruntime140[.]dll hxxp://193[.]233[.]48[.]86/849027f16851d4a2/sqlite3[.]dll hxxps://104[.]252[.]127[.]64/12f8d7cc8b7f3b56/mozglue[.]dll hxxp://185[.]28[.]119[.]223/55145c8889ec57f2/vcruntime140[.]dll hxxp://193[.]233[.]48[.]86/849027f16851d4a2/mozglue[.]dll hxxp://193[.]233[.]254[.]53/c824d1e0a60278fe/nss3[.]dll hxxp://193[.]233[.]254[.]53/c824d1e0a60278fe/softokn3[.]dll hxxp://193[.]233[.]254[.]53/c824d1e0a60278fe/freebl3[.]dll hxxp://193[.]233[.]254[.]53/c824d1e0a60278fe/mozglue[.]dll hxxp://193[.]233[.]254[.]53/c824d1e0a60278fe/msvcp140[.]dll hxxp://193[.]233[.]254[.]53/c824d1e0a60278fe/vcruntime140[.]dll hxxp://193[.]233[.]254[.]53/c824d1e0a60278fe/sqlite3[.]dll hxxp://193[.]233[.]254[.]53/278c2fb3d8583f0e[.]php |
Stealc |
URL | hxxp://103[.]195[.]236[.]247/MLWRNwPzit136[.]bin hxxp://103[.]195[.]236[.]247/ZHvnZYHgRkSdFwQ20[.]bin hxxp://103[.]195[.]236[.]247/XYkCELhlmXhCy143[.]bin hxxp://103[.]195[.]236[.]247/qRSnfbRRc45[.]bin hxxp://91[.]223[.]3[.]167/kyc/egmLCjewSctm228[.]bin hxxp://91[.]223[.]3[.]167/kyc/ctKilGSwEs245[.]bin hxxp://91[.]223[.]3[.]167/kyc/WuhNRAISNqPdCP171[.]bin hxxp://91[.]223[.]3[.]167/kyc/eeGFmpkwtraydbUpxCDPKWpkQ185[.]bin hxxp://91[.]223[.]3[.]167/kyc/WVCikggYnE71[.]bin hxxp://91[.]223[.]3[.]167/kyc/GTOEnVZfzZJyiTCCnXD153[.]bin hxxp://91[.]223[.]3[.]167/kyc/hjChLKG248[.]bin hxxp://91[.]223[.]3[.]167/kyc/egqdqHveDtdUf140[.]bin hxxp://91[.]223[.]3[.]167/kyc/nsDefBo180[.]bin hxxp://91[.]223[.]3[.]167/kyc/BRJYieLQWdfXViZXosPEti245[.]bin hxxp://185[.]29[.]10[.]46/WWrru4[.]bin hxxp://185[.]29[.]10[.]46/BDSDHYKdlnZZt28[.]bin |
CloudEyE |
URL | hxxp://176[.]113[.]115[.]7/files/748049926/27JinXS[.]exe hxxp://45[.]59[.]120[.]8/files/driver/netdriver[.]exe hxxp://45[.]59[.]120[.]8/files/release/winnet[.]exe hxxp://45[.]59[.]120[.]8/files/catlogs/rundrive[.]exe |
SystemBC |
URL | hxxp://185[.]7[.]214[.]211/a[.]mp4 hxxp://185[.]7[.]214[.]211/we[.]exe |
XWorm |
URL | hxxp://176[.]113[.]115[.]7/files/7098980627/mAtJWNv[.]exe hxxps://vx-events[.]com/build[.]exe |
Vidar |
URL | hxxp://196[.]251[.]88[.]141/x86_64 hxxp://196[.]251[.]88[.]141/i686 hxxp://196[.]251[.]88[.]141/aarch64 hxxp://196[.]251[.]90[.]104/x[.]tgz hxxp://196[.]251[.]90[.]104/bro/x86_64 hxxp://83[.]147[.]13[.]230/AV[.]scr hxxp://83[.]147[.]13[.]230/Photo[.]scr hxxp://83[.]147[.]13[.]230/Video[.]scr hxxp://83[.]147[.]13[.]230/x0ox0ox0oxDefault/AV[.]scr hxxp://83[.]147[.]13[.]230/x0ox0ox0oxDefault/Video[.]scr hxxp://83[.]147[.]13[.]230/x0ox0ox0oxDefault/Photo[.]scr |
Coinminer |
URL | hxxp://196[.]251[.]88[.]141/clean hxxp://196[.]251[.]88[.]141/sh |
RedTail |
URL | hxxp://196[.]251[.]85[.]6/sms/cart[.]zip | PerlBot |
URL | hxxps://kusal[.]com/msidntld[.]zip hxxps://highway-loads[.]com/xbe/xbe[.]vue hxxps://highway-loads[.]com/update[.]php |
NetSupportManager RAT |
URL | hxxp://172[.]245[.]123[.]17/550/casse[.]exe hxxp://172[.]245[.]123[.]17/xampp/nina/nicegirlfriendonherewithkissinglips[.]hta hxxp://www[.]sport-news-73209[.]bond/rupi/ hxxp://www[.]suatcelikelgk[.]fun/rupi/ hxxp://www[.]swissdigitalhotelspass[.]cloud/rupi/ hxxp://www[.]tirangaa11[.]xyz/rupi/ hxxp://www[.]treatments-dental-find01[.]today/rupi/ hxxp://www[.]walkethereum[.]xyz/rupi/ hxxp://www[.]watershipdown[.]net/rupi/ hxxp://www[.]wzdry[.]autos/rupi/ hxxp://www[.]xbvfbdgdzgxcxfgdgbjlk[.]website/rupi/ hxxp://www[.]yent[.]biz/rupi/ hxxp://www[.]personalbunker[.]info/rupi/ hxxp://www[.]power-banks-44377[.]bond/rupi/ hxxp://www[.]primemotors[.]store/rupi/ hxxp://www[.]pulgadas[.]net/rupi/ hxxp://www[.]pureay[.]life/rupi/ hxxp://www[.]qicoxfxv[.]cyou/rupi/ hxxp://www[.]rehat[.]xyz/rupi/ hxxp://www[.]rinarabu[.]info/rupi/ hxxp://www[.]satoshigamefi[.]xyz/rupi/ hxxp://www[.]security-service-50960[.]bond/rupi/ hxxp://www[.]softwaresignal[.]cloud/rupi/ hxxp://www[.]sport-news-66076[.]bond/rupi/ hxxp://www[.]ighthold[.]pro/rupi/ hxxp://www[.]ilostmydogbarter[.]shop/rupi/ hxxp://www[.]investment-management-kff[.]today/rupi/ hxxp://www[.]jngck[.]autos/rupi/ hxxp://www[.]job-offer-72029[.]bond/rupi/ hxxp://www[.]kingmojok[.]sbs/rupi/ hxxp://www[.]kinneykoorhmnkranach[.]cloud/rupi/ hxxp://www[.]nodcolnplay[.]today/rupi/ hxxp://www[.]nursetoy[.]net/rupi/ hxxp://www[.]online-advertising-17957[.]bond/rupi/ hxxp://www[.]optime-otech[.]xyz/rupi/ hxxp://www[.]ezapp[.]net/rupi/ hxxp://www[.]fbvfgb[.]lol/rupi/ hxxp://www[.]flatterfoetusfreezer[.]cloud/rupi/ hxxp://www[.]food-packing-job-11697[.]bond/rupi/ hxxp://www[.]foreveralive[.]store/rupi/ hxxp://www[.]frca02620[.]live/rupi/ hxxp://www[.]fterledger[.]xyz/rupi/ hxxp://www[.]gassitgawkygigues[.]cloud/rupi/ hxxp://www[.]georgeglutosegravers[.]cloud/rupi/ hxxp://www[.]gg01j7y[.]pro/rupi/ hxxp://www[.]hahcaa[.]bid/rupi/ hxxp://www[.]heyfriend[.]design/rupi/ hxxp://www[.]hh888[.]cfd/rupi/ hxxp://www[.]casinogoldis[.]xyz/rupi/ hxxp://www[.]christmas-decoration-80176[.]bond/rupi/ hxxp://www[.]cinematech[.]today/rupi/ hxxp://www[.]cnzdp[.]autos/rupi/ hxxp://www[.]dahqxo[.]info/rupi/ hxxp://www[.]dance-classes-65797[.]bond/rupi/ hxxp://www[.]danceglobal[.]store/rupi/ hxxp://www[.]disnestdustbineelboat[.]cloud/rupi/ hxxp://www[.]dreamverse[.]page/rupi/ hxxp://www[.]duoqia[.]xyz/rupi/ hxxp://www[.]enior-apartments-81739[.]bond/rupi/ hxxp://www[.]0u47m9[.]top/rupi/ hxxp://www[.]2711cuvisoe6[.]pro/rupi/ hxxp://www[.]75660[.]mobi/rupi/ hxxp://www[.]8788899[.]vip/rupi/ hxxp://www[.]ambyr[.]green/rupi/ hxxp://www[.]bedcapbegaudybegrim[.]cloud/rupi/ hxxp://www[.]belly-fat-removal-de-3215[.]today/rupi/ hxxp://www[.]brfiyzpa[.]tokyo/rupi/ |
Formbook |
URL | hxxps://blessedwirrow[.]org/qlZvFjfnSJFACbQAFa8YG hxxps://couterfv[.]top/work/ups[.]php hxxps://theneerbreak[.]com/comcat2[.]zip hxxps://couterfv[.]top/work/original[.]js hxxps://couterfv[.]top/work/index[.]php hxxps://netsolut[.]com/6t3e[.]js hxxps://netsolut[.]com/js[.]php hxxps://windows[.]envisionfonddulac[.]net/profileLayout hxxps://whcms[.]greendreamcannabis[.]com/profileLayout hxxps://wqenpene[.]com/5r1r[.]js hxxps://wqenpene[.]com/js[.]php |
FAKEUPDATES |
URL | hxxps://api[.]telegram[.]org/bot8148405664:AAFb_cbqQTIFZ13tP3LwL5F33tl4VcY2Tx8/sendMessage?chat_id=6090860697 hxxps://api[.]telegram[.]org/bot7567849111:AAEKKNLjjrM12czbp-BVJH8URTHuasvZtSc/sendMessage?chat_id=7249492547 |
Snake Keylogger |
URL | hxxp://194[.]87[.]99[.]40/To0Http/EternalAuth6Db/Downloadswp/base/Public/2Cpu/pythonDatalife/dle4/VmUpdate/lowApi/EternalPhpJavascriptLowUpdateWindowsTestpublic[.]php hxxp://075185cm[.]nyashk[.]ru/secureUpdateServerTrackLocalUploads[.]php hxxp://821518cm[.]nyanyash[.]ru/externalpython_secureGeoFlowerTestdownloads[.]php hxxp://692218cm[.]nyanyash[.]ru/PhpJavascriptUpdatemultiProtectsql[.]php hxxp://140061cm[.]nyanyash[.]ru/_SecurehttpDbAsyncWordpressWptemp[.]php hxxp://230852cm[.]nyashk[.]ru/ExternaltojsAuthGameserverlocal[.]php hxxp://87[.]251[.]66[.]162/providerprotectdleCentral[.]php hxxp://89[.]111[.]152[.]13/1temporarydownloadsgeo/longpollGeoBigload/Private/8traffic/asyncauthcentral/ProtectSecure1/pipe/testMultiBigloadMulti/Api/cdnProcess/_/Windows3/uploadsEternal/Php_Bigloadlinuxwindowstemp[.]php hxxp://loveme123ru[.]ru/PipeAuthmultiwordpress[.]php |
DCRat |
URL | hxxp://162[.]243[.]219[.]170/ppc hxxp://162[.]243[.]219[.]170/m68k |
MooBot |
URL | hxxps://bitbucket[.]org/Javaforweb/javascript/downloads/JavaScript-plugin[.]exe | RedLine Stealer |
URL | hxxp://47[.]92[.]211[.]202:4321/lLWN hxxp://110[.]42[.]111[.]128:62443/JsSM hxxp://192[.]64[.]83[.]210/service[.]exe |
Cobalt Strike |
URL | hxxp://612583[.]na8[.]me/crop/setup5357[.]msi hxxp://612583[.]na8[.]me/update/Document-RZ120500678[.]lnk hxxp://6348901[.]na7[.]me/upd/Document-NT2103045[.]lnk hxxp://6348901[.]na7[.]me/cold/setup0038[.]msi hxxp://185[.]146[.]232[.]62:8080/cold/setup0038[.]msi hxxp://37[.]1[.]215[.]147:8080/update/Document-RZ120500678[.]lnk hxxp://37[.]1[.]215[.]147:8080/crop/setup5357[.]msi hxxp://185[.]146[.]232[.]62:8080/upd/Document-NT2103045[.]lnk hxxp://89[.]185[.]80[.]111:8080/part/setup5168[.]msi hxxp://firsteviewer[.]com/part/setup5168[.]msi hxxp://89[.]185[.]80[.]111:8080/parts/form%20i-4283[.]pdf[.]lnk hxxp://firsteviewer[.]com/parts/form%20i-4283[.]pdf[.]lnk |
MetaStealer |
URL | hxxp://154[.]82[.]84[.]114:6635/38[.]91[.]115[.]206[.]dll hxxp://154[.]82[.]84[.]114:6635/38[.]46[.]10[.]90[.]dll hxxp://154[.]82[.]84[.]114:6635/27[.]124[.]47[.]29[.]dll hxxp://154[.]82[.]84[.]114:6635/27[.]124[.]3[.]252[.]dll |
Ghost RAT |
URL | hxxp://61[.]215[.]151[.]173/x/irq2 hxxp://61[.]215[.]151[.]173/x/irq0 hxxp://61[.]215[.]151[.]173/x/irq1 hxxp://61[.]215[.]151[.]173/x/pty |
Tsunami |
URL | hxxps://www[.]suarakutim[.]com/temp/wspconfig[.]rpm hxxps://www[.]suarakutim[.]com/temp/hosebird[.]rpm hxxps://paulinatajda[.]com/1-8123718/839492384932-james[.]zip hxxps://paulinatajda[.]com/sa[.]txt |
HijackLoader |
URL | hxxps://ventureengine[.]lk/wp-content/plugins/z-downloads/?token=AlDlnt6H9wExRGZ9UpLt | Latrodectus |
URL | hxxp://91[.]223[.]3[.]167/ITK/Bgfdbxoxrvc[.]dat hxxp://91[.]223[.]3[.]167/ITK/Vowrddnb[.]wav hxxp://91[.]223[.]3[.]167/ITK/Yfmhkoxf[.]wav hxxp://91[.]223[.]3[.]167/ITK/Cdwzsyfc[.]vdf hxxp://91[.]223[.]3[.]167/ITK/Znpbzu[.]vdf hxxp://91[.]223[.]3[.]167/ITK/Uvslfeer[.]dat hxxp://91[.]223[.]3[.]167/ITK/Xktezflm[.]mp4 hxxp://91[.]223[.]3[.]167/ITK/Wqelqjsju[.]pdf hxxp://91[.]223[.]3[.]167/ITK/Pnxbfy[.]wav |
PureCrypter |
URL | hxxps://api[.]telegram[.]org/bot7394412765:AAG5ArQcPcl2_QrLsNEyfLfmGRJAnsMA654/sendMessage hxxp://62[.]60[.]226[.]112/public_files/FSadIdk[.]txt hxxps://91[.]202[.]233[.]169/Tak/Reg/Marz/ENVS/DR1[.]txt hxxps://91[.]202[.]233[.]169/Tak/Reg/Marz/ENVS/DZ[.]txt hxxp://onlineauth2-client4765445b-32c6-49b0-83e6-1d93765276[.]com/admintemp[.]exe hxxp://94[.]154[.]172[.]154/admintemp[.]exe hxxp://inzbdex[.]xyz/admintemp[.]exe |
AsyncRAT |
URL | hxxp://62[.]60[.]226[.]112/public_files/egehikm[.]txt | neshta |
URL | hxxp://198[.]12[.]81[.]109/xampp/muh/givemebestgoodthingstobe[.]hta | Agent Tesla |
URL | hxxp://192[.]227[.]215[.]147/panel/index[.]php hxxp://192[.]236[.]146[.]95/leosa/index[.]php |
Azorult |
URL | hxxp://regtoyou[.]com/amvgaghabjvlamkmms | TrickMo |
URL | hxxp://59[.]97[.]176[.]67:57293/Mozi[.]m | Mozi |
URL | hxxp://122[.]114[.]193[.]75/demon[.]x64[.]exe[.]dll | Havoc |