サイバーリスク情報提供 Dアラート 特許取得済み

不正URLへのアクセス、不正メールの受信

メール受信した
弊社お客様
0 URLアクセスした
弊社お客様
23
2025/03/03
※2025/03/03 更新
マルウェア感染させると考えられるURLを検知(2025/03/03)
■IoC(※1)
Type: IOC: Signature:
URL hxxp://193[.]200[.]78[.]49/tftp
hxxp://52[.]66[.]212[.]238/yakuza[.]ppc
hxxp://52[.]66[.]212[.]238/yakuza[.]i586
hxxp://52[.]66[.]212[.]238/yakuza[.]mips
hxxp://52[.]66[.]212[.]238/yakuza[.]arm6
hxxp://52[.]62[.]119[.]131/hidakibest[.]arm4
hxxp://52[.]66[.]212[.]238/yakuza[.]m68k
hxxp://52[.]62[.]119[.]131/hidakibest[.]mips
hxxp://52[.]66[.]212[.]238/yakuza[.]x86
hxxp://52[.]66[.]212[.]238/yakuza[.]arm4
hxxp://104[.]194[.]9[.]127/vv/armv4eb
hxxp://104[.]194[.]9[.]127/vv/mipsel
hxxp://104[.]194[.]9[.]127/tt/mipsel64
hxxp://104[.]194[.]9[.]127/vv/armv4l
hxxp://193[.]143[.]1[.]63/e
hxxp://193[.]143[.]1[.]63/vv/armv5l
hxxp://104[.]194[.]9[.]127/v
hxxp://104[.]194[.]9[.]127/vv/armv7l
hxxp://104[.]194[.]9[.]127/vv/armv6l
hxxp://104[.]194[.]9[.]127/tt/mips
hxxp://193[.]143[.]1[.]63/vv/i686
hxxp://193[.]143[.]1[.]63/r
hxxp://104[.]194[.]9[.]127/tt/sparc
hxxp://104[.]194[.]9[.]127/tt/riscv32
hxxp://104[.]194[.]9[.]127/k
hxxp://104[.]194[.]9[.]127/ee/armv4eb
hxxp://104[.]194[.]9[.]127/vv/sparc
hxxp://193[.]143[.]1[.]63/tt/sh4
hxxp://104[.]194[.]9[.]127/tt/i686
hxxp://193[.]143[.]1[.]63/vv/sh4
hxxp://104[.]194[.]9[.]127/vv/sh4
hxxp://193[.]143[.]1[.]63/n
hxxp://104[.]194[.]9[.]127/n
hxxp://193[.]143[.]1[.]63/vv/riscv32
hxxp://104[.]194[.]9[.]127/u
hxxp://104[.]194[.]9[.]127/vv/riscv32
hxxp://104[.]194[.]9[.]127/vv/mips
hxxp://104[.]194[.]9[.]127/tt/mips64
hxxp://104[.]194[.]9[.]127/ee/armv4l
hxxp://104[.]194[.]9[.]127/tt/sh4
hxxp://104[.]194[.]9[.]127/ee/armv5l
hxxp://104[.]194[.]9[.]127/vv/mips64
hxxp://193[.]143[.]1[.]63/vv/armv6l
hxxp://104[.]194[.]9[.]127/tt/mipsel
hxxp://104[.]194[.]9[.]127/vv/armv5l
hxxp://104[.]194[.]9[.]127/ee/armv6l
hxxp://193[.]143[.]1[.]63/vv/powerpc
hxxp://104[.]194[.]9[.]127/tt/armv6l
hxxp://104[.]194[.]9[.]127/tt/armv7l
hxxp://104[.]194[.]9[.]127/vv/powerpc
hxxp://104[.]194[.]9[.]127/vv/arc
hxxp://104[.]194[.]9[.]127/tt/arc
hxxp://104[.]194[.]9[.]127/tt/armv4eb
hxxp://104[.]194[.]9[.]127/tt/armv5l
hxxp://104[.]194[.]9[.]127/ee/armv7l
hxxp://193[.]143[.]1[.]63/tt/i686
hxxp://104[.]194[.]9[.]127/tt/powerpc
hxxp://104[.]194[.]9[.]127/vv/i686
hxxp://193[.]143[.]1[.]63/vv/armv4l
hxxp://193[.]143[.]1[.]63/k
hxxp://193[.]143[.]1[.]63/v
hxxp://104[.]194[.]9[.]127/tt/armv4l
hxxp://104[.]194[.]9[.]127/l
hxxp://104[.]194[.]9[.]127/s
hxxp://104[.]194[.]9[.]127/t
hxxp://104[.]194[.]9[.]127/e
hxxp://104[.]194[.]9[.]127/f
hxxp://193[.]143[.]1[.]63/c
hxxp://104[.]194[.]9[.]127/r
hxxp://193[.]143[.]1[.]63/l
hxxp://193[.]143[.]1[.]63/s
hxxp://193[.]143[.]1[.]63/t
hxxp://104[.]194[.]9[.]127/c
hxxp://193[.]143[.]1[.]63/f
hxxp://193[.]143[.]1[.]63/u
hxxp://193[.]143[.]1[.]63/tt/mipsel64
hxxp://193[.]143[.]1[.]63/tt/arc
hxxp://193[.]143[.]1[.]63/vv/mips
hxxp://193[.]143[.]1[.]63/tt/powerpc
hxxp://193[.]143[.]1[.]63/vv/armv7l
hxxp://193[.]143[.]1[.]63/tt/mips
hxxp://193[.]143[.]1[.]63/ee/armv6l
hxxp://193[.]143[.]1[.]63/tt/mipsel
hxxp://193[.]143[.]1[.]63/vv/mipsel
hxxp://193[.]143[.]1[.]63/vv/arc
hxxp://193[.]143[.]1[.]63/tt/mips64
hxxp://193[.]143[.]1[.]63/tt/sparc
hxxp://193[.]143[.]1[.]63/vv/armv4eb
hxxp://193[.]143[.]1[.]63/ee/armv4l
hxxp://193[.]143[.]1[.]63/vv/mips64
hxxp://193[.]143[.]1[.]63/tt/armv5l
hxxp://193[.]143[.]1[.]63/tt/armv7l
hxxp://193[.]143[.]1[.]63/tt/riscv32
hxxp://193[.]143[.]1[.]63/ee/armv4eb
hxxp://193[.]143[.]1[.]63/ee/armv7l
hxxp://193[.]143[.]1[.]63/tt/armv6l
hxxp://193[.]143[.]1[.]63/vv/sparc
hxxp://193[.]143[.]1[.]63/tt/armv4eb
hxxp://193[.]143[.]1[.]63/ee/armv5l
hxxp://193[.]143[.]1[.]63/tt/armv4l
hxxp://87[.]121[.]84[.]116/iloveviki/viki[.]x64
hxxp://87[.]121[.]84[.]116/iloveviki/viki[.]x86
hxxp://87[.]121[.]84[.]116/iloveviki/viki[.]x86-64
hxxp://87[.]121[.]84[.]116/iloveviki/viki[.]arm64
hxxp://87[.]121[.]84[.]116/iloveviki/viki[.]386
hxxp://87[.]121[.]84[.]116/iloveviki/viki[.]i386
hxxp://87[.]121[.]84[.]116/iloveviki/viki[.]amd64
hxxp://87[.]121[.]84[.]116/iloveviki/all[.]sh
hxxp://185[.]157[.]247[.]126/tsh4
hxxp://194[.]85[.]251[.]73/iloveviki/viki[.]arm64
hxxp://23[.]157[.]176[.]170/load[.]sh
hxxp://185[.]232[.]205[.]129/x86
hxxp://185[.]232[.]205[.]129/mips
hxxp://185[.]232[.]205[.]129/weed
hxxp://185[.]232[.]205[.]129/wget[.]sh
hxxp://102[.]219[.]181[.]231/c2/load[.]sh
hxxp://dianzanla[.]com/jackmyi586
hxxp://dianzanla[.]com/jackmyarmv6
hxxp://dianzanla[.]com/jackmym86k
hxxp://dianzanla[.]com/jackmyi686
hxxp://dianzanla[.]com/jackmysparc
hxxp://dianzanla[.]com/jackmymips
hxxp://dianzanla[.]com/jackmyarmv4
hxxp://dianzanla[.]com/jackmypowerpc
hxxp://dianzanla[.]com/jackmyx86
hxxp://dianzanla[.]com/jackmyarmv5
hxxp://dianzanla[.]com/jackmysh4
hxxp://dianzanla[.]com/jackmymipsel
hxxp://dianzanla[.]com/bins[.]sh
hxxp://165[.]154[.]224[.]116/jackmyi686
hxxp://165[.]154[.]224[.]116/jackmyi586
hxxp://165[.]154[.]224[.]116/jackmymipsel
hxxp://165[.]154[.]224[.]116/jackmym86k
hxxp://165[.]154[.]224[.]116/jackmysparc
hxxp://165[.]154[.]224[.]116/jackmymips
hxxp://165[.]154[.]224[.]116/jackmyarmv4
hxxp://165[.]154[.]224[.]116/jackmypowerpc
hxxp://165[.]154[.]224[.]116/jackmysh4
hxxp://165[.]154[.]224[.]116/jackmyx86
hxxp://165[.]154[.]224[.]116/jackmyarmv6
hxxp://165[.]154[.]224[.]116/jackmyarmv5
Bashlite
URL hxxps://aiqinsights[.]icu/api
hxxps://pukisound[.]icu/api
hxxps://chlenvaginakz[.]icu/api
hxxp://176[.]113[.]115[.]7/files/7481626938/MCxU5Fj[.]exe
hxxps://dawtastream[.]bet/api
hxxp://176[.]113[.]115[.]7/files/6416878235/FydOzyQ[.]exe
hxxps://reservation-confirms[.]com/in[.]php?action=1
hxxps://ggepllay[.]com/in[.]php?action=2
hxxps://procedeed-verific[.]com/in[.]php?action=2
hxxps://important-confirmation[.]com/in[.]php?action=2
hxxps://ggepiay[.]com/in[.]php?action=2
hxxps://fxepiay[.]com/in[.]php?action=2
hxxps://important-confiirm[.]com/in[.]php?action=2
hxxps://reservation-confirms[.]com/in[.]php?action=2
hxxps://fxepiay[.]com/in[.]php?action=1
hxxps://important-confiirm[.]com/in[.]php?action=1
hxxps://procedeed-verific[.]com/in[.]php?action=1
hxxps://ggepllay[.]com/in[.]php?action=1
hxxps://important-confirmation[.]com/in[.]php?action=1
hxxps://ggepiay[.]com/in[.]php?action=1
hxxps://payment[.]verification-proceess[.]com/in[.]php?action=1
hxxps://payment[.]verification-proceess[.]com/in[.]php?action=2
hxxps://verification-proceess[.]com/in[.]php?action=2
hxxps://leafvypathways[.]top/api
hxxps://www[.]benshamcentre[.]co[.]uk/continue/45[.]ps1
hxxps://electronicpgioneers[.]live/login
hxxp://176[.]113[.]115[.]7/files/6142491850/FvbuInU[.]exe
hxxps://bizmir[.]shop/powergem[.]mp3
hxxp://62[.]60[.]226[.]112/public_files/omrnimg[.]txt
hxxp://62[.]60[.]226[.]112/public_files/ajgoFab[.]txt
hxxp://62[.]60[.]226[.]112/public_files/rjamfkg[.]txt
hxxps://oak-smash[.]cyou/api
hxxps://printerdiallog[.]fun/api
hxxps://cybgerlaunch[.]digital/api
hxxps://blissfttulmoments[.]top/api
hxxps://tampermonkey06[.]top/api
hxxps://bloodyeleftor[.]world/api
hxxps://creativehjub[.]tech/api
hxxps://brjightfuture[.]tech/api
hxxps://pastedeputten[.]life/api
hxxps://tampermonkey03[.]top/api
hxxps://subawhipnator[.]life/api
hxxps://tampermonkey08[.]top/api
hxxps://tampermonkey02[.]top/api
hxxps://smart-living365[.]top/api
hxxps://disobilittyhell[.]live/api
hxxp://62[.]60[.]226[.]112/public_files/hkkcrng[.]txt
hxxp://176[.]113[.]115[.]7/files/qqdoup/random[.]exe
hxxps://jowyfulbloom[.]shop/api
hxxps://innojvatech[.]shop/api
hxxps://tqechtrends[.]shop/api
hxxps://earthsymphzony[.]today/api
hxxps://gadgsetflow[.]shop/api
hxxps://exarthynature[.]run/api
hxxps://digitalcrdjafters[.]top/api
hxxps://datadynnamics[.]today/api
hxxps://towerymodest[.]top/api
hxxps://reliefintorud[.]life/api
hxxps://pipesofmugge[.]fun/api
hxxps://naturerbhythm[.]world/api
hxxps://naturjalharmony[.]top/api
hxxps://markerjurys[.]cyou/api
hxxps://moduledbillke[.]world/api
hxxps://natureexpflorer[.]run/api
hxxps://nateurescanvas[.]world/api
hxxps://netgineero[.]life/api
hxxps://goldensounew[.]world/api
hxxps://grainybande[.]life/api
hxxps://hideousown[.]top/api
hxxps://gesturedseedz[.]fun/api
hxxps://forfardunifor[.]world/api
hxxps://foortyturhud[.]run/api
hxxps://exposedbuid[.]life/api
hxxps://fortunedtrivial[.]top/api
hxxps://digitalfxorge[.]world/api
hxxps://elegantlawwen[.]run/api
hxxps://difgitalnexus[.]run/api
hxxps://desribessquwd[.]today/api
hxxps://entereddeacr[.]run/api
hxxps://crystahlclearwaters[.]bet/api
hxxps://earwaxeduek[.]run/api
hxxps://alcohopreden[.]top/api
hxxps://bloomingzgardens[.]today/api
hxxp://176[.]113[.]115[.]7/files/fate/random[.]exe
hxxps://uploadhaven[.]store/ewest[.]m4a
hxxps://wildxflowerdream[.]life/api
hxxps://163[.]5[.]32[.]73/GlobalDesk[.]exe
hxxp://163[.]5[.]32[.]73/GlobalDesk[.]exe
hxxps://banappeals[.]net/GlobalDesk[.]exe
hxxps://pevemtnchil[.]live/api
hxxps://tracnquilforest[.]life/api
hxxps://starrynsightsky[.]icu/api
hxxps://circujitstorm[.]bet/api
hxxps://techpxioneers[.]run/api
hxxps://foresctwhispers[.]top/api
hxxps://calmingtefxtures[.]run/api
hxxps://experimentalideas[.]today/api
hxxps://gadgethgfub[.]icu/api
hxxps://hardrwarehaven[.]run/api
hxxps://techmindzs[.]live/api
hxxps://codxefusion[.]top/api
hxxps://quietswtreams[.]life/api
hxxps://techspherxe[.]top/api
hxxps://hardswarehub[.]today/api
Lumma Stealer
URL hxxp://62[.]60[.]226[.]112/file/3601_2042[.]exe
hxxps://github[.]com/Oscarito20222/diciembre/raw/refs/heads/main/sena[.]exe
hxxps://marubeni[.]cc/mpclient[.]dll
hxxps://marubeni[.]cc/Acuerdo_de_Orden_de_Compra[.]exe
hxxps://45[.]11[.]59[.]49/mpclient[.]dll
hxxp://45[.]11[.]59[.]49/mpclient[.]dll
hxxp://23[.]95[.]60[.]80/677/krna/nicepersonforsweetkissinggirlformygirl[.]hta
hxxp://192[.]3[.]95[.]138/213/seethebestthingswecandothatwithgreatness[.]gIF
hxxp://23[.]95[.]235[.]9/550/mis/seethebestjourneygivenmebestthingswithbettercasaes[.]hta
hxxp://192[.]3[.]95[.]138/213/seetha/seethebestthingswecandothatwithgreatness[.]hta
hxxp://45[.]11[.]59[.]49/Acuerdo_de_Orden_de_Compra[.]exe
hxxps://45[.]11[.]59[.]49/Acuerdo_de_Orden_de_Compra[.]exe
Remcos
URL hxxps://apxservices[.]esrv[.]me/app/svchost[.]exe Venom RAT
URL hxxps://www[.]mediafire[.]com/file_premium/8q094mjevfshw6g/glass[.]mp3/file
hxxps://check[.]vehom[.]icu/gkcxv[.]google
hxxps://check[.]luboz[.]icu/gkcxv[.]google
hxxps://check[.]xapus[.]icu/gkcxv[.]google
hxxps://check[.]fafyd[.]icu/gkcxv[.]google
hxxps://check[.]nuwab[.]icu/gkcxv[.]google
hxxps://check[.]mijuf[.]icu/gkcxv[.]google
hxxps://check[.]mosat[.]icu/gkcxv[.]google
hxxps://check[.]cined[.]icu/gkcxv[.]google
hxxps://check[.]remag[.]icu/gkcxv[.]google
hxxps://check[.]myfet[.]icu/gkcxv[.]google
hxxps://check[.]jixal[.]icu/gkcxv[.]google
hxxps://check[.]hysuz[.]icu/gkcxv[.]google
hxxps://check[.]qogur[.]icu/gkcxv[.]google
hxxps://check[.]qozil[.]icu/gkcxv[.]google
hxxps://check[.]woqym[.]icu/gkcxv[.]google
hxxps://check[.]bipyl[.]icu/gkcxv[.]google
hxxps://check[.]qitub[.]icu/gkcxv[.]google
hxxps://check[.]pojon[.]icu/gkcxv[.]google
hxxps://check[.]vudih[.]icu/gkcxv[.]google
hxxps://check[.]cuzon[.]icu/gkcxv[.]google
hxxps://check[.]zixeq[.]icu/gkcxv[.]google
hxxps://check[.]danob[.]icu/gkcxv[.]google
hxxps://check[.]pidal[.]icu/gkcxv[.]google
hxxps://check[.]gytec[.]icu/gkcxv[.]google
hxxps://check[.]gejop[.]icu/gkcxv[.]google
hxxps://check[.]wowuk[.]icu/gkcxv[.]google
hxxps://check[.]vykud[.]icu/gkcxv[.]google
hxxps://check[.]bifuh[.]icu/gkcxv[.]google
hxxps://check[.]kupav[.]icu/gkcxv[.]google
hxxps://check[.]kekid[.]icu/gkcxv[.]google
hxxps://check[.]suqev[.]icu/gkcxv[.]google
hxxps://check[.]ninif[.]icu/gkcxv[.]google
hxxps://check[.]tyheb[.]icu/gkcxv[.]google
hxxps://check[.]zagyw[.]icu/gkcxv[.]google
hxxps://check[.]somiv[.]icu/gkcxv[.]google
hxxps://check[.]neweb[.]icu/gkcxv[.]google
hxxps://check[.]wezop[.]icu/gkcxv[.]google
hxxps://check[.]jaxim[.]icu/gkcxv[.]google
hxxps://check[.]gykem[.]icu/gkcxv[.]google
hxxps://vaultcord[.]net/assets/captcha[.]exe
hxxps://check[.]wygoq[.]icu/gkcxv[.]google
hxxps://check[.]tubyf[.]icu/gkcxv[.]google
ClearFake
URL hxxp://expertuslugi[.]top/Documents/file[.]lnk
hxxp://01[.]pogoda86[.]online/Documents/file[.]lnk
hxxp://62[.]133[.]61[.]101/Documents/file[.]lnk
QakBot
URL hxxps://94[.]156[.]177[.]41/scc4/five/PvqDq929BSx_A_D_M1n_a[.]php
hxxps://centrehotel[.]vn/wp1/Panel/fre[.]php
hxxps://centrehotel[.]vn/wp/Panel/fre[.]php
hxxp://centrehotel[.]vn/wp1/Panel/fre[.]php
hxxp://centrehotel[.]vn/wp/Panel/fre[.]php
LokiBot
URL hxxps://193[.]124[.]185[.]114/LjJDHIMSFH/index[.]php
hxxp://176[.]113[.]115[.]7/mine/random[.]exe
hxxp://176[.]113[.]115[.]6/Ni9kiput/index[.]php
hxxp://185[.]215[.]113[.]209/di0her478/index[.]php
hxxp://62[.]60[.]226[.]15/8fj482jd9/index[.]php
hxxp://176[.]113[.]115[.]6/Ni9kiput/Login[.]php
hxxp://176[.]113[.]115[.]7/files/748049926/bwuGbC2[.]exe
hxxp://cobolrationumelawrtewarms[.]com/3ofn3jf3e2ljk/Plugins/cred[.]dll
hxxp://cobolrationumelawrtewarms[.]com/3ofn3jf3e2ljk/Plugins/cred64[.]dll
hxxp://cobolrationumelawrtewarms[.]com/3ofn3jf3e2ljk/Plugins/clip64[.]dll
hxxp://cobolrationumelawrtewarms[.]com/3ofn3jf3e2ljk/Plugins/clip[.]dll
hxxp://176[.]113[.]115[.]7/test/exe/random[.]exe
hxxp://176[.]113[.]115[.]7/test/am_no[.]bat
hxxp://185[.]215[.]113[.]16/test/am_no[.]bat
Amadey
URL hxxps://79[.]137[.]206[.]248/d210652e231a5729/vcruntime140[.]dll
hxxps://45[.]88[.]76[.]205/3a8d14c36ef0a8cc/sqlite3[.]dll
hxxps://45[.]88[.]76[.]205/3a8d14c36ef0a8cc/vcruntime140[.]dll
hxxps://45[.]88[.]76[.]205/3a8d14c36ef0a8cc/mozglue[.]dll
hxxp://185[.]28[.]119[.]223/55145c8889ec57f2/mozglue[.]dll
hxxps://104[.]252[.]127[.]64/12f8d7cc8b7f3b56/sqlite3[.]dll
hxxp://185[.]28[.]119[.]223/55145c8889ec57f2/sqlite3[.]dll
hxxp://193[.]233[.]48[.]86/849027f16851d4a2/vcruntime140[.]dll
hxxp://193[.]233[.]48[.]86/849027f16851d4a2/sqlite3[.]dll
hxxps://104[.]252[.]127[.]64/12f8d7cc8b7f3b56/mozglue[.]dll
hxxp://185[.]28[.]119[.]223/55145c8889ec57f2/vcruntime140[.]dll
hxxp://193[.]233[.]48[.]86/849027f16851d4a2/mozglue[.]dll
hxxp://193[.]233[.]254[.]53/c824d1e0a60278fe/nss3[.]dll
hxxp://193[.]233[.]254[.]53/c824d1e0a60278fe/softokn3[.]dll
hxxp://193[.]233[.]254[.]53/c824d1e0a60278fe/freebl3[.]dll
hxxp://193[.]233[.]254[.]53/c824d1e0a60278fe/mozglue[.]dll
hxxp://193[.]233[.]254[.]53/c824d1e0a60278fe/msvcp140[.]dll
hxxp://193[.]233[.]254[.]53/c824d1e0a60278fe/vcruntime140[.]dll
hxxp://193[.]233[.]254[.]53/c824d1e0a60278fe/sqlite3[.]dll
hxxp://193[.]233[.]254[.]53/278c2fb3d8583f0e[.]php
Stealc
URL hxxp://103[.]195[.]236[.]247/MLWRNwPzit136[.]bin
hxxp://103[.]195[.]236[.]247/ZHvnZYHgRkSdFwQ20[.]bin
hxxp://103[.]195[.]236[.]247/XYkCELhlmXhCy143[.]bin
hxxp://103[.]195[.]236[.]247/qRSnfbRRc45[.]bin
hxxp://91[.]223[.]3[.]167/kyc/egmLCjewSctm228[.]bin
hxxp://91[.]223[.]3[.]167/kyc/ctKilGSwEs245[.]bin
hxxp://91[.]223[.]3[.]167/kyc/WuhNRAISNqPdCP171[.]bin
hxxp://91[.]223[.]3[.]167/kyc/eeGFmpkwtraydbUpxCDPKWpkQ185[.]bin
hxxp://91[.]223[.]3[.]167/kyc/WVCikggYnE71[.]bin
hxxp://91[.]223[.]3[.]167/kyc/GTOEnVZfzZJyiTCCnXD153[.]bin
hxxp://91[.]223[.]3[.]167/kyc/hjChLKG248[.]bin
hxxp://91[.]223[.]3[.]167/kyc/egqdqHveDtdUf140[.]bin
hxxp://91[.]223[.]3[.]167/kyc/nsDefBo180[.]bin
hxxp://91[.]223[.]3[.]167/kyc/BRJYieLQWdfXViZXosPEti245[.]bin
hxxp://185[.]29[.]10[.]46/WWrru4[.]bin
hxxp://185[.]29[.]10[.]46/BDSDHYKdlnZZt28[.]bin
CloudEyE
URL hxxp://176[.]113[.]115[.]7/files/748049926/27JinXS[.]exe
hxxp://45[.]59[.]120[.]8/files/driver/netdriver[.]exe
hxxp://45[.]59[.]120[.]8/files/release/winnet[.]exe
hxxp://45[.]59[.]120[.]8/files/catlogs/rundrive[.]exe
SystemBC
URL hxxp://185[.]7[.]214[.]211/a[.]mp4
hxxp://185[.]7[.]214[.]211/we[.]exe
XWorm
URL hxxp://176[.]113[.]115[.]7/files/7098980627/mAtJWNv[.]exe
hxxps://vx-events[.]com/build[.]exe
Vidar
URL hxxp://196[.]251[.]88[.]141/x86_64
hxxp://196[.]251[.]88[.]141/i686
hxxp://196[.]251[.]88[.]141/aarch64
hxxp://196[.]251[.]90[.]104/x[.]tgz
hxxp://196[.]251[.]90[.]104/bro/x86_64
hxxp://83[.]147[.]13[.]230/AV[.]scr
hxxp://83[.]147[.]13[.]230/Photo[.]scr
hxxp://83[.]147[.]13[.]230/Video[.]scr
hxxp://83[.]147[.]13[.]230/x0ox0ox0oxDefault/AV[.]scr
hxxp://83[.]147[.]13[.]230/x0ox0ox0oxDefault/Video[.]scr
hxxp://83[.]147[.]13[.]230/x0ox0ox0oxDefault/Photo[.]scr
Coinminer
URL hxxp://196[.]251[.]88[.]141/clean
hxxp://196[.]251[.]88[.]141/sh
RedTail
URL hxxp://196[.]251[.]85[.]6/sms/cart[.]zip PerlBot
URL hxxps://kusal[.]com/msidntld[.]zip
hxxps://highway-loads[.]com/xbe/xbe[.]vue
hxxps://highway-loads[.]com/update[.]php
NetSupportManager RAT
URL hxxp://172[.]245[.]123[.]17/550/casse[.]exe
hxxp://172[.]245[.]123[.]17/xampp/nina/nicegirlfriendonherewithkissinglips[.]hta
hxxp://www[.]sport-news-73209[.]bond/rupi/
hxxp://www[.]suatcelikelgk[.]fun/rupi/
hxxp://www[.]swissdigitalhotelspass[.]cloud/rupi/
hxxp://www[.]tirangaa11[.]xyz/rupi/
hxxp://www[.]treatments-dental-find01[.]today/rupi/
hxxp://www[.]walkethereum[.]xyz/rupi/
hxxp://www[.]watershipdown[.]net/rupi/
hxxp://www[.]wzdry[.]autos/rupi/
hxxp://www[.]xbvfbdgdzgxcxfgdgbjlk[.]website/rupi/
hxxp://www[.]yent[.]biz/rupi/
hxxp://www[.]personalbunker[.]info/rupi/
hxxp://www[.]power-banks-44377[.]bond/rupi/
hxxp://www[.]primemotors[.]store/rupi/
hxxp://www[.]pulgadas[.]net/rupi/
hxxp://www[.]pureay[.]life/rupi/
hxxp://www[.]qicoxfxv[.]cyou/rupi/
hxxp://www[.]rehat[.]xyz/rupi/
hxxp://www[.]rinarabu[.]info/rupi/
hxxp://www[.]satoshigamefi[.]xyz/rupi/
hxxp://www[.]security-service-50960[.]bond/rupi/
hxxp://www[.]softwaresignal[.]cloud/rupi/
hxxp://www[.]sport-news-66076[.]bond/rupi/
hxxp://www[.]ighthold[.]pro/rupi/
hxxp://www[.]ilostmydogbarter[.]shop/rupi/
hxxp://www[.]investment-management-kff[.]today/rupi/
hxxp://www[.]jngck[.]autos/rupi/
hxxp://www[.]job-offer-72029[.]bond/rupi/
hxxp://www[.]kingmojok[.]sbs/rupi/
hxxp://www[.]kinneykoorhmnkranach[.]cloud/rupi/
hxxp://www[.]nodcolnplay[.]today/rupi/
hxxp://www[.]nursetoy[.]net/rupi/
hxxp://www[.]online-advertising-17957[.]bond/rupi/
hxxp://www[.]optime-otech[.]xyz/rupi/
hxxp://www[.]ezapp[.]net/rupi/
hxxp://www[.]fbvfgb[.]lol/rupi/
hxxp://www[.]flatterfoetusfreezer[.]cloud/rupi/
hxxp://www[.]food-packing-job-11697[.]bond/rupi/
hxxp://www[.]foreveralive[.]store/rupi/
hxxp://www[.]frca02620[.]live/rupi/
hxxp://www[.]fterledger[.]xyz/rupi/
hxxp://www[.]gassitgawkygigues[.]cloud/rupi/
hxxp://www[.]georgeglutosegravers[.]cloud/rupi/
hxxp://www[.]gg01j7y[.]pro/rupi/
hxxp://www[.]hahcaa[.]bid/rupi/
hxxp://www[.]heyfriend[.]design/rupi/
hxxp://www[.]hh888[.]cfd/rupi/
hxxp://www[.]casinogoldis[.]xyz/rupi/
hxxp://www[.]christmas-decoration-80176[.]bond/rupi/
hxxp://www[.]cinematech[.]today/rupi/
hxxp://www[.]cnzdp[.]autos/rupi/
hxxp://www[.]dahqxo[.]info/rupi/
hxxp://www[.]dance-classes-65797[.]bond/rupi/
hxxp://www[.]danceglobal[.]store/rupi/
hxxp://www[.]disnestdustbineelboat[.]cloud/rupi/
hxxp://www[.]dreamverse[.]page/rupi/
hxxp://www[.]duoqia[.]xyz/rupi/
hxxp://www[.]enior-apartments-81739[.]bond/rupi/
hxxp://www[.]0u47m9[.]top/rupi/
hxxp://www[.]2711cuvisoe6[.]pro/rupi/
hxxp://www[.]75660[.]mobi/rupi/
hxxp://www[.]8788899[.]vip/rupi/
hxxp://www[.]ambyr[.]green/rupi/
hxxp://www[.]bedcapbegaudybegrim[.]cloud/rupi/
hxxp://www[.]belly-fat-removal-de-3215[.]today/rupi/
hxxp://www[.]brfiyzpa[.]tokyo/rupi/
Formbook
URL hxxps://blessedwirrow[.]org/qlZvFjfnSJFACbQAFa8YG
hxxps://couterfv[.]top/work/ups[.]php
hxxps://theneerbreak[.]com/comcat2[.]zip
hxxps://couterfv[.]top/work/original[.]js
hxxps://couterfv[.]top/work/index[.]php
hxxps://netsolut[.]com/6t3e[.]js
hxxps://netsolut[.]com/js[.]php
hxxps://windows[.]envisionfonddulac[.]net/profileLayout
hxxps://whcms[.]greendreamcannabis[.]com/profileLayout
hxxps://wqenpene[.]com/5r1r[.]js
hxxps://wqenpene[.]com/js[.]php
FAKEUPDATES
URL hxxps://api[.]telegram[.]org/bot8148405664:AAFb_cbqQTIFZ13tP3LwL5F33tl4VcY2Tx8/sendMessage?chat_id=6090860697
hxxps://api[.]telegram[.]org/bot7567849111:AAEKKNLjjrM12czbp-BVJH8URTHuasvZtSc/sendMessage?chat_id=7249492547
Snake Keylogger
URL hxxp://194[.]87[.]99[.]40/To0Http/EternalAuth6Db/Downloadswp/base/Public/2Cpu/pythonDatalife/dle4/VmUpdate/lowApi/EternalPhpJavascriptLowUpdateWindowsTestpublic[.]php
hxxp://075185cm[.]nyashk[.]ru/secureUpdateServerTrackLocalUploads[.]php
hxxp://821518cm[.]nyanyash[.]ru/externalpython_secureGeoFlowerTestdownloads[.]php
hxxp://692218cm[.]nyanyash[.]ru/PhpJavascriptUpdatemultiProtectsql[.]php
hxxp://140061cm[.]nyanyash[.]ru/_SecurehttpDbAsyncWordpressWptemp[.]php
hxxp://230852cm[.]nyashk[.]ru/ExternaltojsAuthGameserverlocal[.]php
hxxp://87[.]251[.]66[.]162/providerprotectdleCentral[.]php
hxxp://89[.]111[.]152[.]13/1temporarydownloadsgeo/longpollGeoBigload/Private/8traffic/asyncauthcentral/ProtectSecure1/pipe/testMultiBigloadMulti/Api/cdnProcess/_/Windows3/uploadsEternal/Php_Bigloadlinuxwindowstemp[.]php
hxxp://loveme123ru[.]ru/PipeAuthmultiwordpress[.]php
DCRat
URL hxxp://162[.]243[.]219[.]170/ppc
hxxp://162[.]243[.]219[.]170/m68k
MooBot
URL hxxps://bitbucket[.]org/Javaforweb/javascript/downloads/JavaScript-plugin[.]exe RedLine Stealer
URL hxxp://47[.]92[.]211[.]202:4321/lLWN
hxxp://110[.]42[.]111[.]128:62443/JsSM
hxxp://192[.]64[.]83[.]210/service[.]exe
Cobalt Strike
URL hxxp://612583[.]na8[.]me/crop/setup5357[.]msi
hxxp://612583[.]na8[.]me/update/Document-RZ120500678[.]lnk
hxxp://6348901[.]na7[.]me/upd/Document-NT2103045[.]lnk
hxxp://6348901[.]na7[.]me/cold/setup0038[.]msi
hxxp://185[.]146[.]232[.]62:8080/cold/setup0038[.]msi
hxxp://37[.]1[.]215[.]147:8080/update/Document-RZ120500678[.]lnk
hxxp://37[.]1[.]215[.]147:8080/crop/setup5357[.]msi
hxxp://185[.]146[.]232[.]62:8080/upd/Document-NT2103045[.]lnk
hxxp://89[.]185[.]80[.]111:8080/part/setup5168[.]msi
hxxp://firsteviewer[.]com/part/setup5168[.]msi
hxxp://89[.]185[.]80[.]111:8080/parts/form%20i-4283[.]pdf[.]lnk
hxxp://firsteviewer[.]com/parts/form%20i-4283[.]pdf[.]lnk
MetaStealer
URL hxxp://154[.]82[.]84[.]114:6635/38[.]91[.]115[.]206[.]dll
hxxp://154[.]82[.]84[.]114:6635/38[.]46[.]10[.]90[.]dll
hxxp://154[.]82[.]84[.]114:6635/27[.]124[.]47[.]29[.]dll
hxxp://154[.]82[.]84[.]114:6635/27[.]124[.]3[.]252[.]dll
Ghost RAT
URL hxxp://61[.]215[.]151[.]173/x/irq2
hxxp://61[.]215[.]151[.]173/x/irq0
hxxp://61[.]215[.]151[.]173/x/irq1
hxxp://61[.]215[.]151[.]173/x/pty
Tsunami
URL hxxps://www[.]suarakutim[.]com/temp/wspconfig[.]rpm
hxxps://www[.]suarakutim[.]com/temp/hosebird[.]rpm
hxxps://paulinatajda[.]com/1-8123718/839492384932-james[.]zip
hxxps://paulinatajda[.]com/sa[.]txt
HijackLoader
URL hxxps://ventureengine[.]lk/wp-content/plugins/z-downloads/?token=AlDlnt6H9wExRGZ9UpLt Latrodectus
URL hxxp://91[.]223[.]3[.]167/ITK/Bgfdbxoxrvc[.]dat
hxxp://91[.]223[.]3[.]167/ITK/Vowrddnb[.]wav
hxxp://91[.]223[.]3[.]167/ITK/Yfmhkoxf[.]wav
hxxp://91[.]223[.]3[.]167/ITK/Cdwzsyfc[.]vdf
hxxp://91[.]223[.]3[.]167/ITK/Znpbzu[.]vdf
hxxp://91[.]223[.]3[.]167/ITK/Uvslfeer[.]dat
hxxp://91[.]223[.]3[.]167/ITK/Xktezflm[.]mp4
hxxp://91[.]223[.]3[.]167/ITK/Wqelqjsju[.]pdf
hxxp://91[.]223[.]3[.]167/ITK/Pnxbfy[.]wav
PureCrypter
URL hxxps://api[.]telegram[.]org/bot7394412765:AAG5ArQcPcl2_QrLsNEyfLfmGRJAnsMA654/sendMessage
hxxp://62[.]60[.]226[.]112/public_files/FSadIdk[.]txt
hxxps://91[.]202[.]233[.]169/Tak/Reg/Marz/ENVS/DR1[.]txt
hxxps://91[.]202[.]233[.]169/Tak/Reg/Marz/ENVS/DZ[.]txt
hxxp://onlineauth2-client4765445b-32c6-49b0-83e6-1d93765276[.]com/admintemp[.]exe
hxxp://94[.]154[.]172[.]154/admintemp[.]exe
hxxp://inzbdex[.]xyz/admintemp[.]exe
AsyncRAT
URL hxxp://62[.]60[.]226[.]112/public_files/egehikm[.]txt neshta
URL hxxp://198[.]12[.]81[.]109/xampp/muh/givemebestgoodthingstobe[.]hta Agent Tesla
URL hxxp://192[.]227[.]215[.]147/panel/index[.]php
hxxp://192[.]236[.]146[.]95/leosa/index[.]php
Azorult
URL hxxp://regtoyou[.]com/amvgaghabjvlamkmms TrickMo
URL hxxp://59[.]97[.]176[.]67:57293/Mozi[.]m Mozi
URL hxxp://122[.]114[.]193[.]75/demon[.]x64[.]exe[.]dll Havoc
※1「i-FILTER」アクセスログを検索し端末を特定してください 不要なアクセスを避けるため、一部変更しております。 ■製品対応状況(※2) ▽i-FILTER(※3) ・[脅威情報サイト]カテゴリでブロック可能 ※2 ブロックの可否は各製品の設定によるため、実際の結果はアクセスログを参照してください。 ※3 暗号化された通信の場合は、SSL Adapterの設定を「利用」にする必要があります。
イベント・セミナー情報