不正URLへのアクセス、不正メールの受信
-
メール受信した
弊社お客様0社 URLアクセスした
弊社お客様1社 -
2025/03/05
※2025/03/05 更新
マルウェア感染させると考えられるURLを検知(2025/03/05)
■IoC(※1)
Type: | IOC: | Signature: |
---|---|---|
URL | hxxp://87[.]120[.]84[.]108/videoToWindowsTesttrackDownloads[.]php hxxp://138[.]68[.]80[.]167/packetDefaultasyncTrafficwordpresspublicTempcdn[.]php hxxp://047506cm[.]nyanyash[.]ru/externalvideopythonpollTracktemp[.]php |
DCRat |
URL | hxxps://api[.]telegram[.]org/bot1422952298:AAEUK5QmhKaWUtETf1GIcyg7deR8JXsbh2c/sendMessage?chat_id=1189853645 | ToxicEye |
URL | hxxps://gocoloflarecrest[.]xyz/MzVlMGQ1ZjgxZTc5/ hxxps://cobokostarfall[.]xyz/MTlhODdkOTM2NDBk/ hxxps://bobofosolsticepeak[.]xyz/ODE4YTdiYmY1YTdl/ hxxps://twilightkokocodream[.]xyz/MzExMzM0YTQ2ZGRk/ |
Coper |
URL | hxxps://check[.]mevif[.]icu/gkcxv[.]google hxxps://check[.]celir[.]icu/gkcxv[.]google hxxps://check[.]qukex[.]icu/gkcxv[.]google hxxps://miz2[.]dorklifedubbed[.]shop/bdc2be5bddda548dec3c2d88464a698627ac9447aae621d8[.]wks hxxps://check[.]pedaz[.]icu/gkcxv[.]google hxxps://check[.]vijaw[.]icu/gkcxv[.]google hxxps://check[.]jojyq[.]icu/gkcxv[.]google hxxps://check[.]lybuk[.]icu/gkcxv[.]google hxxps://check[.]nafeh[.]icu/gkcxv[.]google hxxps://check[.]darax[.]icu/gkcxv[.]google hxxps://check[.]lijam[.]icu/gkcxv[.]google hxxps://check[.]bajys[.]icu/gkcxv[.]google hxxps://check[.]qozab[.]icu/gkcxv[.]google hxxps://check[.]zitit[.]icu/gkcxv[.]google |
ClearFake |
URL | hxxp://103[.]195[.]236[.]247/muVvVNVv2[.]bin hxxp://185[.]29[.]10[.]46/eCIYDU35[.]bin hxxp://64[.]227[.]9[.]228/NEWiFYoUpvFlLum94[.]bin hxxps://scheller-technik[.]ch/rdzCQqRApiRiIsBxSLOTpEWxHy124[.]bin hxxps://scheller-technik[.]ch/devil[.]ps1 hxxps://caffechian[.]com/men/Designovervejelse166[.]afm hxxps://caffechian[.]com/odi/Unclinch[.]sea hxxps://caffechian[.]com/man/tBZbbsobFeVRtxeSUqt130[.]bin hxxps://caffechian[.]com/od/LJPGgswapeLcUAcB131[.]bin hxxps://caffechian[.]com/bbl/qlmorpVOtKtAgVEEan27[.]bin hxxps://caffechian[.]com/bbn/Sinecureposter[.]hhk hxxps://ooriginalused[.]com/sup/anhBwc119[.]bin hxxps://ooriginalused[.]com/supps/Sulfathiazole[.]pcz hxxps://jbstrckng[.]com/Milo1[.]png hxxps://jbstrckng[.]com/Milo2[.]png |
CloudEyE |
URL | hxxp://103[.]205[.]252[.]29:5566/server[.]exe | YoungLotus |
URL | hxxp://k1d5[.]icu/TP341/index[.]php | Azorult |
URL | hxxps://api[.]telegram[.]org/bot7583159374:AAGmUpm1cvufdu_K5LQElvjNL05QwuNiJT8/sendMessage?chat_id=6659038027 hxxps://api[.]telegram[.]org/bot7688397122:AAEYj2Kah8TZtfQXLu0PLMPgrPHyc1YyYuw/sendMessage?chat_id=986310232 hxxps://api[.]telegram[.]org/bot7200174383:AAGiuIXRkOAbU2n4B0G-2otS20RqwZrRApI/sendMessage?chat_id=7365979371 hxxps://api[.]telegram[.]org/bot7811478868:AAFz8G54tjfmoXGXiHlkaDDwEoEtiu2Dae8/sendMessage?chat_id=5692813672 |
Snake Keylogger |
URL | hxxps://socialsscesforum[.]icu/api hxxps://aqppgenius[.]life/api hxxps://gloweceeralk[.]online/api hxxps://pddinghenarkijui[.]shop/api hxxps://wordingvenuo[.]fun/api |
Lumma Stealer |
URL | hxxp://g12se[.]com/pLJzBbZhhOnaPl85[.]bin hxxp://g12se[.]com/Tavsere[.]qxd hxxps://scheller-technik[.]ch/devils[.]ps1 hxxps://scheller-technik[.]ch/duWMrYyFyCaxT131[.]bin hxxp://esabol[.]com[.]bo/Betrkningernes11[.]fla hxxp://172[.]245[.]123[.]17/xampp/uh/fg[.]hta hxxp://172[.]245[.]123[.]17/420/cssess[.]exe hxxp://172[.]245[.]123[.]17/xampp/cnc/createbestthingswithgoodnewsgwithgreatnews[.]hta hxxp://www[.]xucg[.]sbs/hm26/ hxxp://www[.]yber-ninja[.]store/hm26/ hxxp://www[.]younoi100web[.]online/hm26/ hxxp://www[.]yperbox[.]fun/hm26/ hxxp://www[.]yvirginiegarnier[.]design/hm26/ hxxp://www[.]pps-61461[.]bond/hm26/ hxxp://www[.]prite[.]bio/hm26/ hxxp://www[.]ragrantgarjden[.]top/hm26/ hxxp://www[.]riceflashpulseflow[.]xyz/hm26/ hxxp://www[.]ruediscipleshipwear[.]shop/hm26/ hxxp://www[.]scortistanbulnoble[.]xyz/hm26/ hxxp://www[.]takeserviceclaim[.]online/hm26/ hxxp://www[.]tellieuse[.]site/hm26/ hxxp://www[.]tqy[.]store/hm26/ hxxp://www[.]ustclogs[.]shop/hm26/ hxxp://www[.]uxemboutique[.]store/hm26/ hxxp://www[.]wertb[.]xyz/hm26/ hxxp://www[.]xpressbasic[.]store/hm26/ hxxp://www[.]npersbrec[.]pro/hm26/ hxxp://www[.]ome-repair-003[.]today/hm26/ hxxp://www[.]onstruktor[.]fit/hm26/ hxxp://www[.]oodwaste[.]biz/hm26/ hxxp://www[.]oofing-jobs-au11-dp[.]click/hm26/ hxxp://www[.]orcalphone[.]net/hm26/ hxxp://www[.]orovistogoeur[.]shop/hm26/ hxxp://www[.]oseblissflower[.]net/hm26/ hxxp://www[.]ottomlinesa[.]net/hm26/ hxxp://www[.]oungerlonger[.]online/hm26/ hxxp://www[.]ovexyazilim[.]xyz/hm26/ hxxp://www[.]pplyforverifiedrateupdate[.]xyz/hm26/ hxxp://www[.]hoabforall[.]work/hm26/ hxxp://www[.]houzentei-soukan[.]work/hm26/ hxxp://www[.]iccana[.]store/hm26/ hxxp://www[.]inematography-course-95431[.]bond/hm26/ hxxp://www[.]ink21planetbola88[.]xyz/hm26/ hxxp://www[.]iquilfy[.]finance/hm26/ hxxp://www[.]iromimapearl[.]website/hm26/ hxxp://www[.]isefyxerlink[.]info/hm26/ hxxp://www[.]j091p63ng[.]vip/hm26/ hxxp://www[.]kmmm[.]fun/hm26/ hxxp://www[.]martev[.]world/hm26/ hxxp://www[.]ap[.]rent/hm26/ hxxp://www[.]aremmano-abruzzese[.]net/hm26/ hxxp://www[.]ascular[.]shop/hm26/ hxxp://www[.]cehaiou[.]net/hm26/ hxxp://www[.]ebbtw[.]shop/hm26/ hxxp://www[.]eki[.]tokyo/hm26/ hxxp://www[.]enjoy[.]store/hm26/ hxxp://www[.]ental-implants-trend[.]today/hm26/ hxxp://www[.]erafic[.]shop/hm26/ hxxp://www[.]erlincasinostars[.]net/hm26/ hxxp://www[.]ertsolana[.]site/hm26/ hxxp://www[.]evelupstudio[.]store/hm26/ hxxp://www[.]07health[.]net/hm26/ hxxp://www[.]3436800poknvdrt43wd[.]xyz/hm26/ hxxp://www[.]5172[.]net/hm26/ hxxp://www[.]8013[.]net/hm26/ hxxp://www[.]albello[.]xyz/hm26/ hxxp://www[.]ale-fertility-cyprus[.]today/hm26/ hxxp://www[.]alista21[.]site/hm26/ hxxp://www[.]allrepair-br14[.]bond/hm26/ hxxp://www[.]andar919-ok[.]lol/hm26/ hxxp://www[.]anzeal[.]xyz/hm26/ hxxp://www[.]anzxjao[.]shop/hm26/ hxxp://www[.]00ltsapp03[.]vip/hm26/ |
Formbook |
URL | hxxps://www[.]centralelatterieti[.]com/wp-content/uploads/2020/obviation3S0[.]php hxxps://www[.]centralelatterieti[.]com/wp-content/uploads/2020/dazementxdy7[.]php hxxps://www[.]centralelatterieti[.]com/wp-content/uploads/2020/subgularExtK[.]ps1 hxxp://178[.]17[.]170[.]209/overglass[.]php hxxps://www[.]centralelatterieti[.]com/wp-content/uploads/2020/sulphureousAm[.]exe |
Koi Loader |
URL | hxxp://104[.]168[.]7[.]26/350/greatdaycomingforyourwithbestthingsbetter[.]hta hxxp://74[.]208[.]123[.]191/566/sightkissgivenmebestfeelingentiretimesgivebeautifulkiss[.]hta hxxp://172[.]245[.]123[.]17/xampp/kmc/nseemybestgoodthingsonbestwaygivenme[.]hta hxxp://172[.]245[.]123[.]17/xampp/kmc/kn/encryption01[.]jpg hxxp://172[.]245[.]123[.]17/xampp/knice/beautifulmomentswithniceplacegive[.]txt hxxp://172[.]245[.]123[.]17/xampp/knice/beautifulmomentswithniceplacegive[.]hta hxxp://172[.]245[.]123[.]17/xampp/knice/zbeautifulmomentswithniceplacegive[.]hta |
Remcos |
URL | hxxp://192[.]3[.]220[.]17/morninghtaaaafilex[.]hta | Agent Tesla |
URL | hxxps://s02-welcome[.]cfd/vWJgBibsQc79I9DW[.]html hxxps://s02-welcome[.]cfd/ghBYPjsBHNqpKBY2[.]html hxxps://cheaccskguspartner[.]com/?__cf_chl_tk=[.]KXffmQpBw7ToBqZZchFEMrO4M_LmNRVMBVgiJ8yn6Q-1741089542-1[.]0[.]1[.]1-K9NRsUjxwSBYTEB7hbNrYuYhn5Rdh8FGclVpyXE[.]iX8 |
XWorm |
URL | hxxps://digitalflwr[.]com/captcha[.]php hxxps://intellisense[.]live/gerda[.]php hxxps://forefilarem[.]com/test/ |
Latrodectus |
URL | hxxps://91[.]240[.]118[.]2:9769/78fc5131525a9e8d335b1/asba3xl7[.]v343f | Rhadamanthys |
URL | hxxps://harmarpets[.]com/4w8u[.]js hxxps://harmarpets[.]com/js[.]php hxxps://filmlerzltyazilimsx[.]shop/work/original[.]js hxxps://filmlerzltyazilimsx[.]shop/work/index[.]php hxxps://filmlerzltyazilimsx[.]shop/work/fill[.]php hxxps://thetileboutique[.]in/wiatrace[.]zip |
FAKEUPDATES |
URL | hxxps://185[.]196[.]8[.]195/u6vhSc3PPq/index[.]php | Amadey |
URL | hxxp://37[.]139[.]129[.]142/htdocs/ephgsylqpfdwsqw[.]exe hxxp://81[.]161[.]229[.]110/htdocs/ingmdybaekrstrt[.]exe |
MASS Logger |
URL | hxxps://91[.]215[.]85[.]11/15f869479d73f92a/sqlite3[.]dll hxxp://45[.]155[.]250[.]218/92bfcbf4e12ebf6e/vcruntime140[.]dll hxxp://208[.]91[.]189[.]189/05b85f6a6b0e9444/vcruntime140[.]dll hxxp://45[.]15[.]157[.]211/6d44dd0da6f70e60/sqlite3[.]dll hxxp://109[.]107[.]181[.]33/742d3278227bff91/vcruntime140[.]dll hxxps://68[.]183[.]108[.]129/75959266227880b0/vcruntime140[.]dll hxxp://172[.]86[.]77[.]102/84ab9e91729b85a0/sqlite3[.]dll |
Stealc |