不正URLへのアクセス、不正メールの受信
-
メール受信した
弊社お客様0社 URLアクセスした
弊社お客様1社 -
2025/03/10
※2025/03/10 更新
マルウェア感染させると考えられるURLを検知(2025/03/10)
■IoC(※1)
Type: | IOC: | Signature: |
---|---|---|
URL | hxxp://839805cm[.]nyashk[.]ru/vmjavascriptSecuregeneratorDatalifeCdn[.]php hxxp://396608cm[.]nyashk[.]ru/pipePythonAuthDefaultlinuxwindowsgeneratorwordpress[.]php hxxp://207405cm[.]nyashk[.]ru/secureflower[.]php hxxp://070687cm[.]nyashk[.]ru/eternalPhppolldbGeneratorTestuploadsdownloads[.]php hxxp://95[.]182[.]122[.]208/Vmtemporary/Uploads/publicBaseVm/AsyncUpdatePipe/Temp/asynctrackProtonprocess/python/ProtectLow/JavascriptRequestLongpoll[.]php hxxp://383281cm[.]nyashk[.]ru/eternalVideo[.]php hxxp://95[.]163[.]86[.]252/48longpollpacket/4TemporaryLow/imagelow/wordpressMultiuploadsUniversal/5processor/Downloads/tracktestVmAuth/ImagePublicLineUploads/Pipetemporary/DownloadsbaseAsync/ToSql/PublicJavascript/Line6low8/eternalvideoJavascriptapilinuxgeneratorDlePubliccentral[.]php |
DCRat |
URL | hxxp://185[.]7[.]214[.]108/a[.]mp4 hxxp://185[.]7[.]214[.]108/b[.]mp4 hxxp://92[.]255[.]85[.]66/rt[.]exe hxxp://176[.]113[.]115[.]7/files/7212159662/HmngBpR[.]exe hxxps://20[.]229[.]103[.]183/nioxclient[.]exe hxxp://20[.]229[.]103[.]183/nioxclient[.]exe hxxps://20[.]229[.]103[.]183/nioxxy[.]exe |
AsyncRAT |
URL | hxxps://check[.]nyrar[.]icu/gkcxv[.]google hxxps://check[.]dalut[.]icu/gkcxv[.]google hxxps://check[.]vavoj[.]icu/gkcxv[.]google hxxps://check[.]papeb[.]icu/gkcxv[.]google hxxps://check[.]xylor[.]icu/gkcxv[.]google hxxps://check[.]jemyq[.]icu/gkcxv[.]google hxxps://check[.]jipaf[.]icu/gkcxv[.]google hxxps://u1[.]wildnessreflected[.]shop/bdc2be5bddda548dec3c2d88464a698627ac9447aae621d8[.]wks hxxps://check[.]vadom[.]icu/gkcxv[.]google hxxps://check[.]mepum[.]icu/gkcxv[.]google hxxps://u1[.]puckerlinguist[.]shop/Siarhei_Korbut_-_Salary[.]mp3 hxxps://u1[.]drizzleraving[.]shop/Siarhei_Korbut_-_Dime[.]mp3 hxxps://u1[.]puckerlinguist[.]shop/Siarhei_Korbut_-_Disown[.]mp3 hxxps://u1[.]puckerlinguist[.]shop/Siarhei_Korbut_-_Garden[.]mp3 hxxps://u1[.]puckerlinguist[.]shop/Siarhei_Korbut_-_Ice[.]mp3 hxxps://u1[.]drizzleraving[.]shop/Siarhei_Korbut_-_Diligent[.]mp3 hxxps://check[.]juxoi[.]icu/gkcxv[.]google hxxps://u1[.]drizzleraving[.]shop/Siarhei_Korbut_-_Overpay[.]mp3 hxxps://u1[.]drizzleraving[.]shop/Siarhei_Korbut_-_Grant[.]mp3 hxxps://u1[.]drizzleraving[.]shop/Siarhei_Korbut_-_Vascular[.]mp3 hxxps://u1[.]puckerlinguist[.]shop/Siarhei_Korbut_-_Humongous[.]mp3 hxxps://u1[.]puckerlinguist[.]shop/Siarhei_Korbut_-_Remedial[.]mp3 hxxps://u1[.]puckerlinguist[.]shop/Siarhei_Korbut_-_Devotion[.]mp3 hxxps://check[.]henuo[.]icu/gkcxv[.]google hxxps://u1[.]puckerlinguist[.]shop/Siarhei_Korbut_-_Laborious[.]mp3 hxxps://u1[.]puckerlinguist[.]shop/Siarhei_Korbut_-_Mockup[.]mp3 hxxps://u1[.]puckerlinguist[.]shop/Siarhei_Korbut_-_Flaxseed[.]mp3 hxxps://check[.]jilex[.]icu/gkcxv[.]google hxxps://check[.]qinah[.]icu/gkcxv[.]google hxxps://u1[.]drizzleraving[.]shop/Siarhei_Korbut_-_Estrogen[.]mp3 hxxps://check[.]jiceo[.]icu/gkcxv[.]google hxxps://check[.]somyq[.]icu/gkcxv[.]google hxxps://check[.]jipuh[.]icu/gkcxv[.]google hxxps://check[.]kynoc[.]icu/gkcxv[.]google hxxps://u1[.]drizzleraving[.]shop/Siarhei_Korbut_-_Bulginess[.]mp3 hxxps://u1[.]drizzleraving[.]shop/Siarhei_Korbut_-_Trespass[.]mp3 hxxps://check[.]cicyb[.]icu/gkcxv[.]google hxxps://u1[.]drizzleraving[.]shop/Siarhei_Korbut_-_Carwash[.]mp3 hxxps://check[.]xuceb[.]icu/gkcxv[.]google hxxps://check[.]kacoz[.]icu/gkcxv[.]google hxxps://check[.]wohur[.]icu/gkcxv[.]google hxxps://check[.]tunep[.]icu/gkcxv[.]google hxxps://u1[.]drizzleraving[.]shop/Siarhei_Korbut_-_Cosmos[.]mp3 hxxps://u1[.]drizzleraving[.]shop/Siarhei_Korbut_-_Elves[.]mp3 hxxps://check[.]givus[.]icu/gkcxv[.]google hxxps://u1[.]drizzleraving[.]shop/Siarhei_Korbut_-_proton[.]mp3 hxxps://u1[.]overuseunderuse[.]shop/Siarhei_Korbut_-_Judicial[.]mp3 hxxps://check[.]jorah[.]icu/gkcxv[.]google hxxps://u1[.]overuseunderuse[.]shop/Siarhei_Korbut_-_Large[.]mp3 hxxps://u1[.]overuseunderuse[.]shop/Siarhei_Korbut_-_Nanny[.]mp3 hxxps://check[.]gefeq[.]icu/gkcxv[.]google hxxps://u1[.]overuseunderuse[.]shop/Siarhei_Korbut_-_Recent[.]mp3 hxxps://u1[.]overuseunderuse[.]shop/Siarhei_Korbut_-_Shrug[.]mp3 hxxps://u1[.]overuseunderuse[.]shop/Siarhei_Korbut_-_Trespass[.]mp3 hxxps://u1[.]overuseunderuse[.]shop/Siarhei_Korbut_-_Unwed[.]mp3 |
ClearFake |
URL | hxxps://twilightbobofoglade[.]xyz/ODE4YTdiYmY1YTdl/ hxxps://shadowgocolospire[.]xyz/MzVlMGQ1ZjgxZTc5/ hxxps://radiantkokocopeak[.]xyz/MzExMzM0YTQ2ZGRk/ |
Coper |
URL | hxxp://15[.]204[.]95[.]223/mk6nn70wu6hrji89[.]php hxxps://185[.]219[.]81[.]135/4175180d6b714647/mozglue[.]dll hxxps://185[.]219[.]81[.]135/4175180d6b714647/vcruntime140[.]dll hxxps://185[.]219[.]81[.]135/4175180d6b714647/sqlite3[.]dll |
Stealc |
URL | hxxps://api[.]telegram[.]org/bot7922909971:AAESR5mvezMqr8iz6psLIehHVuWpWpAUuaI/sendMessage?chat_id=7518399906 hxxps://api[.]telegram[.]org/bot8052153515:AAEy1R0ssCqYRtfr5MLZ5lbcuC9K_RdIieY/sendMessage?chat_id=5022382431 hxxps://api[.]telegram[.]org/bot7818500050:AAEF0oLynYLWs5GcxHwzYD3bt4ZSEit-TrI/sendMessage?chat_id=5780514555 |
DarkCloud |
URL | hxxp://www[.]zhexifniu[.]top/v32e/ hxxp://www[.]ressconversation[.]run/v32e/ hxxp://www[.]rview[.]net/v32e/ hxxp://www[.]sgazaproject[.]net/v32e/ hxxp://www[.]tgr[.]pro/v32e/ hxxp://www[.]tudy-in-spain-58534[.]bond/v32e/ hxxp://www[.]umpsiconi[.]shop/v32e/ hxxp://www[.]urseryinfo[.]net/v32e/ hxxp://www[.]vwhay[.]info/v32e/ hxxp://www[.]wmzotvekqsnbaxvf[.]shop/v32e/ hxxp://www[.]yperpigmentation-45231[.]bond/v32e/ hxxp://www[.]oorso[.]live/v32e/ hxxp://www[.]ootox[.]xyz/v32e/ hxxp://www[.]orussiansthub987q[.]shop/v32e/ hxxp://www[.]oyalthaiherb[.]net/v32e/ hxxp://www[.]parkautotransport[.]website/v32e/ hxxp://www[.]pdld[.]net/v32e/ hxxp://www[.]phconline[.]info/v32e/ hxxp://www[.]pvoqftnckomcx[.]shop/v32e/ hxxp://www[.]redit-cards-46185[.]bond/v32e/ hxxp://www[.]nolises[.]shop/v32e/ hxxp://www[.]ntesa[.]group/v32e/ hxxp://www[.]obahrainiioyiq[.]shop/v32e/ hxxp://www[.]oho[.]uno/v32e/ hxxp://www[.]olawanliao33[.]click/v32e/ hxxp://www[.]ollipop[.]group/v32e/ hxxp://www[.]oloactive[.]college/v32e/ hxxp://www[.]ome-loans-72725[.]bond/v32e/ hxxp://www[.]onda1[.]cloud/v32e/ hxxp://www[.]ontacttracingwristband[.]net/v32e/ hxxp://www[.]hiseledvisions[.]art/v32e/ hxxp://www[.]ihdwt[.]info/v32e/ hxxp://www[.]itchens-31[.]bond/v32e/ hxxp://www[.]ixel49[.]shop/v32e/ hxxp://www[.]kin-rejuvenation-60489[.]bond/v32e/ hxxp://www[.]kin-rejuvenation-67012[.]bond/v32e/ hxxp://www[.]log987resultbest[.]shop/v32e/ hxxp://www[.]mcb[.]info/v32e/ hxxp://www[.]nmali[.]top/v32e/ hxxp://www[.]emglobal[.]net/v32e/ hxxp://www[.]enesiscorporation[.]tech/v32e/ hxxp://www[.]estdrivencompliance[.]net/v32e/ hxxp://www[.]etoxsecrets[.]today/v32e/ hxxp://www[.]exbjfpbxhjcgzsdgumh[.]shop/v32e/ hxxp://www[.]fqbjnaw[.]xyz/v32e/ hxxp://www[.]g-poc[.]net/v32e/ hxxp://www[.]hestarterkit[.]xyz/v32e/ hxxp://www[.]arehouse-jobs-43584[.]bond/v32e/ hxxp://www[.]aybankz[.]click/v32e/ hxxp://www[.]aycrk[.]net/v32e/ hxxp://www[.]b777[.]top/v32e/ hxxp://www[.]bgripl[.]xyz/v32e/ hxxp://www[.]ddanything[.]win/v32e/ hxxp://www[.]dtech[.]team/v32e/ hxxp://www[.]ecurity-jobs-61871[.]bond/v32e/ hxxp://www[.]ell-property-32572[.]bond/v32e/ hxxp://www[.]1gv52[.]top/v32e/ hxxp://www[.]4109a37a693[.]xyz/v32e/ hxxp://www[.]51je936qi[.]sbs/v32e/ hxxp://www[.]6m86[.]xyz/v32e/ hxxp://www[.]abysitter-service-32322[.]bond/v32e/ hxxp://www[.]ags-under-999516409[.]click/v32e/ hxxp://www[.]andoes[.]tech/v32e/ hxxp://www[.]anglore-flats-gov01[.]today/v32e/ hxxp://www[.]archattinfobreach2024[.]net/v32e/ hxxps://github[.]com/legendary99999/dfsfdsfdsfds/releases/download/dfsfsdfds/begin[.]exe hxxp://147[.]124[.]213[.]50/crypt/dressman[.]exe hxxp://141[.]98[.]10[.]154/35/hkcmd[.]exe hxxp://172[.]245[.]123[.]17/xampp/nv/niceworkingskillwthichbetterperformancefromme[.]hta hxxp://172[.]245[.]123[.]17/487/ossio[.]exe |
Formbook |
URL | hxxp://81[.]161[.]229[.]110/htdocs/cipqxjgngwskxjn[.]exe hxxp://109[.]206[.]241[.]81/htdocs/xrkxbdndgkmasms[.]exe hxxp://37[.]139[.]129[.]142/htdocs/cmdtmbhfqptykgk[.]exe hxxp://37[.]139[.]129[.]142/htdocs/ccagzmdbfxyxjyp[.]exe hxxp://37[.]139[.]129[.]142/htdocs/xkqesjpetwmqwor[.]exe hxxp://81[.]161[.]229[.]110/htdocs/gtfyhanmmstrewk[.]exe hxxp://81[.]161[.]229[.]110/htdocs/raqneqpjbnogszg[.]exe hxxp://81[.]161[.]229[.]110/htdocs/tehrftmzkjbpxpp[.]exe hxxp://81[.]161[.]229[.]110/htdocs/hnykjfzszbpprhg[.]exe hxxp://109[.]206[.]241[.]81/htdocs/wdwqzmbhjqntanr[.]exe hxxp://37[.]139[.]129[.]142/htdocs/csfbnaszlbkdkhr[.]exe hxxp://37[.]139[.]129[.]142/htdocs/nnmbedlzoxrdjqb[.]exe hxxp://37[.]139[.]129[.]142/htdocs/dwrtzrdgckiwasl[.]exe hxxp://81[.]161[.]229[.]110/htdocs/clwsnxmbrkekqee[.]exe hxxp://37[.]139[.]129[.]142/htdocs/jtjpsfbrgehowsw[.]exe hxxp://81[.]161[.]229[.]110/htdocs/oyaddrsqprepzdn[.]exe hxxp://109[.]206[.]241[.]81/htdocs/ncdcbrmywczgfzh[.]exe hxxp://37[.]139[.]129[.]142/htdocs/wagzfgztkrwncmg[.]exe hxxp://37[.]139[.]129[.]142/htdocs/jhhcspkiyfanfly[.]exe hxxp://37[.]139[.]129[.]142/htdocs/asmrqdskmfapfgl[.]exe |
MASS Logger |
URL | hxxps://api[.]telegram[.]org/bot7785850878:AAH2Lyzq3W9zvu9XTH0GM1FQwRjG4iLaHuM/sendMessage?chat_id=6989593343 hxxps://api[.]telegram[.]org/bot8147359814:AAFqq1spFpNySus2Q92Z7HxFe84oTTR0k6o/sendMessage?chat_id=1166322455 hxxps://api[.]telegram[.]org/bot7895118317:AAGrVh3BGkPztPIw30H4HXBbPxYmBtMiKV0/sendMessage?chat_id=5649235024 hxxps://api[.]telegram[.]org/bot7234500135:AAFVeYtIHal1O-v2C3mf_pSCdsnW9Uj_VPg/sendMessage?chat_id=1413074050 hxxps://api[.]telegram[.]org/bot7921923009:AAEv3LWDM47jA_y8EzZ01dRTZHuO6oQD-6Q/sendMessage?chat_id=6204380879 hxxps://api[.]telegram[.]org/bot7979985497:AAFvroWg86Vs6An0zC4VfIajVlOKCPlaswc/sendMessage?chat_id=7365979371 |
Snake Keylogger |
URL | hxxps://snuegglypillow[.]top/api hxxps://spikyscaldeo[.]cyou/api hxxps://citxresearchers[.]icu/api hxxps://fuurxchnologies[.]top/api hxxps://farfinable[.]top/api hxxps://moderzysics[.]top/api hxxps://reseagetwork[.]top/api hxxps://agriculthub[.]run/api hxxps://agriework[.]life/api hxxps://arisechairedd[.]shop/api hxxps://analgcslab[.]run/api hxxps://comrfyclouds[.]run/api hxxps://cozsmicjo[.]top/api hxxps://cjuddlepillows[.]icu/api hxxps://farmercommunity[.]life/api hxxps://absoulpushx[.]life/api hxxps://dataexzorers[.]icu/api hxxps://croprojegies[.]run/api hxxps://discxeryspace[.]icu/api hxxps://fahentures[.]today/api hxxps://explqngscience[.]life/api hxxps://cropmqttools[.]today/api hxxps://envirbntalstudies[.]shop/api hxxps://fieldies[.]bet/api hxxps://gengfocus[.]today/api hxxps://modelshiverd[.]icu/api hxxps://gestryfocus[.]run/api hxxps://greenfieldsnetwork[.]bet/api hxxps://heritagebreeds[.]run/api hxxps://garagedrootz[.]top/api hxxps://labdizeries[.]run/api hxxps://gardeninggains[.]bet/api hxxps://mathinsighjts[.]shop/api hxxps://puillowjourney[.]icu/api hxxps://scienssights[.]today/api hxxps://orchardinspiration[.]top/api hxxps://paradoxxedin[.]world/api hxxps://permaculturepath[.]run/api hxxps://scienxonnect[.]run/api hxxps://organicgrowershub[.]shop/api hxxps://ossifiedreduio[.]shop/api hxxps://scizencehub[.]life/api hxxps://spitestrippe[.]top/api hxxps://soilandseed[.]icu/api hxxps://scientififange[.]top/api hxxps://techworld2025[.]top/api hxxps://explorebieology[.]run/api hxxps://hphygcsforum[.]life/api hxxps://ktechspherxe[.]top/api hxxps://eearthsymphzony[.]today/api hxxps://j8arisechairedd[.]shop/api hxxps://begindecafer[.]world/api hxxps://gmodelshiverd[.]icu/api hxxps://catterjur[.]run/api hxxps://orangemyther[.]live/api hxxps://fostinjec[.]today/api hxxps://sterpickced[.]digital/api hxxps://9garagedrootz[.]top/api hxxps://ksterpickced[.]digital/api hxxps://phygcsforum[.]life/api hxxps://6catterjur[.]run/api hxxps://agroecologyguide[.]digital/api hxxps://kmoderzysics[.]top/api hxxps://seedsxouts[.]shop/api hxxps://rcodxefusion[.]top/api hxxps://cropcircleforum[.]today/api hxxps://pgadgethgfub[.]icu/api hxxps://bz2ncodxefusion[.]top/api hxxps://bexarthynature[.]run/api hxxps://bquietswtreams[.]life/api hxxps://bcodxefusion[.]top/api hxxps://xexarthynature[.]run/api hxxps://shardrwarehaven[.]run/api hxxps://xcollapimga[.]fun/api hxxps://jquietswtreams[.]life/api hxxps://defaulemot[.]run/api hxxps://utechspherxe[.]top/api hxxps://nebdulaq[.]digital/api hxxps://acatterjur[.]run/api hxxps://followfauc[.]cyou/api hxxps://zimportenptoc[.]com/api hxxps://voicesharped[.]com/api hxxps://inputrreparnt[.]com/api hxxps://torpdidebar[.]com/api hxxps://rebeldettern[.]com/api hxxps://actiothreaz[.]com/api hxxps://bgarulouscuto[.]com/api hxxps://sbreedertremnd[.]com/api hxxps://yshiningrstars[.]help/api hxxps://oblastikcn[.]com/api hxxps://fxreshideas[.]tech/api hxxps://pstormlegue[.]com/api hxxps://unaturewsounds[.]help/api hxxps://qblastikcn[.]com/api hxxps://6naturewsounds[.]help/api hxxps://lestagames[.]world/api hxxps://iblastikcn[.]com/api hxxps://nbdsfljsdfjewf[.]info/api hxxps://fcatterjur[.]run/api hxxps://6sterpickced[.]digital/api hxxps://vyafostinjec[.]today/api hxxps://8sterpickced[.]digital/api hxxps://github[.]com/legendary99999/dsfsdffds/releases/download/fdsfsfdfdsdfs/alex12312[.]exe hxxps://github[.]com/legendary99999/ewfksdlfmv/releases/download/dsfdsfds/gold[.]rim[.]exe hxxps://github[.]com/legendary99999/fdfsdfdssfd/releases/download/dfsdfsdfsdsf/fher[.]exe hxxps://github[.]com/legendary99999/sdfsdffdsdfs/releases/download/dsffdsdfsdfs/alex122121[.]exe hxxps://github[.]com/legendary99999/dfsfsdfsd/releases/download/dsfsdfdfsfsd/cronikxqqq[.]exe hxxps://github[.]com/legendary99999/fedsfdsfds/releases/download/dsfdsfdfsdfs/alex1213321[.]exe hxxps://github[.]com/legendary99999/fsddfsdfsdfsdfsfds/releases/download/sdfdfsdsfdsf/fuck122112[.]exe hxxps://github[.]com/legendary99999/fsdfdsfds/releases/download/sdffdsfsddfs/alex12112[.]exe hxxps://github[.]com/legendary99999/sdffdsfdssd/releases/download/sdffdfdsfd/alex[.]exe hxxps://github[.]com/legendary99999/fdsfsdfdsfds/releases/download/dfsfdsfdsdsf/con12312211221[.]exe hxxps://github[.]com/legendary99999/edffsdfds/releases/download/fsdfdsdfs/alex111111[.]exe hxxp://176[.]113[.]115[.]7/files/5153162918/pwHxMTy[.]exe hxxp://176[.]113[.]115[.]7/files/5526411762/CgmaT61[.]exe hxxp://176[.]113[.]115[.]7/download[.]php hxxp://185[.]81[.]68[.]7/download[.]php hxxp://45[.]93[.]20[.]28/download[.]php hxxps://0modelshiverd[.]icu/api hxxps://arisechairedd[.]shop/JnsHY hxxps://garisechairedd[.]shop/api hxxps://begindecafer[.]world/QwdZdf hxxp://176[.]113[.]115[.]7/files/5526411762/yUI6F6C[.]exe hxxp://176[.]113[.]115[.]7/files/6491397189/T0QdO0l[.]exe hxxp://176[.]113[.]115[.]7/files/6691015685/V0Bt74c[.]exe hxxp://176[.]113[.]115[.]7/files/6416878235/AvKILpK[.]exe hxxps://rseedsxouts[.]shop/api hxxps://jcropcircleforum[.]today/api hxxps://agriwellness[.]world/api hxxps://astralconnec[.]icu/api hxxps://zfurrycomp[.]top/api hxxps://other-rans[.]cyou/api hxxps://childishbagge[.]fun/api hxxps://livlivprolivasdvaa[.]shop/api hxxps://interfensuffer[.]fun/api hxxp://91[.]202[.]233[.]151/1337Traget/1337X-1[.]exe hxxp://91[.]202[.]233[.]151/1337/TORRENTOLD-1[.]exe hxxps://resrtfulnights[.]live/api hxxps://chemistrycworner[.]today/api hxxps://sdfwfsdf[.]icu/api hxxps://sngugglepillow[.]live/api hxxps://matkldwide[.]digital/api hxxps://oearthsymphzony[.]today/api hxxps://7garagedrootz[.]top/api hxxps://7modelshiverd[.]icu/api hxxps://3orangemyther[.]live/api hxxps://vtechspherxe[.]top/api hxxps://livestveblog[.]live/api hxxps://arch1[.]usa1news[.]buzz/s/mirror/mNuFgfJgBDBr9i7DSdfRjuBx/file[.]zip hxxps://q8explorebieology[.]run/api hxxps://5ktechmindzs[.]live/api hxxps://6codxefusion[.]top/api hxxps://7phygcsforum[.]life/api hxxps://ycatterjur[.]run/api hxxps://xsterpickced[.]digital/api hxxps://larisechairedd[.]shop/api hxxps://9sterpickced[.]digital/api hxxps://coderspabradise[.]life/api hxxps://chimneysickend[.]icu/api hxxps://jucnglecrea[.]bet/login hxxps://astronav[.]world/bvvW hxxps://confessnibmle[.]top/api hxxps://dsimensio[.]bet/api hxxps://smartsolutions24[.]top/api hxxps://ddeaddereaste[.]today/api hxxps://0defaulemot[.]run/api hxxps://morangemyther[.]live/api hxxps://5arisechairedd[.]shop/api hxxps://qfostinjec[.]today/api hxxps://ibegindecafer[.]world/api hxxps://hgaragedrootz[.]top/api hxxp://176[.]113[.]115[.]7/files/6860984455/HHPgDSI[.]exe hxxps://tbegindecafer[.]world/api hxxps://mbfostinjec[.]today/api hxxps://3begindecafer[.]world/api hxxps://pfostinjec[.]today/api hxxps://kaiserdome[.]run/api hxxps://fyeredfamily[.]world/api hxxps://pevtparadise[.]world/api hxxps://theinterg[.]world/api hxxps://happyjh[.]world/api hxxps://pawfsandcl[.]world/api hxxps://tailsogfthewild[.]world/api hxxps://astrotg[.]world/api hxxps://inztergalact[.]world/api hxxps://celestigalp[.]icu/api hxxps://voyeugger[.]today/api hxxps://animnalha[.]icu/api hxxps://astronav[.]world/api hxxps://resignfallk[.]icu/api hxxps://kaittenkorner[.]today/api hxxps://spacetimech[.]today/api hxxps://piellowbliss[.]icu/api hxxps://furryjourlneys[.]icu/api hxxps://kingfdomo[.]today/api hxxps://sanugglebud[.]today/api hxxps://tonedanswered[.]today/api hxxps://stellafradv[.]world/api hxxps://wilodlifewhis[.]icu/api hxxps://happyyhowler[.]icu/api hxxps://cosmichori[.]today/api hxxps://crittercoorner[.]today/api hxxps://fusrryfables[.]today/api hxxps://wildwmorlds[.]life/api hxxps://astrophysical[.]today/api hxxps://constellationfe[.]run/api hxxps://mfeteorolog[.]life/api hxxps://regullanbalk[.]life/api hxxps://cosmopla[.]life/api hxxps://quantumuni[.]life/api hxxps://starfieldsin[.]life/api hxxps://animalujnity[.]run/api hxxps://pxawprintsafari[.]run/api hxxps://baerkandmeow[.]run/api hxxps://wildwonlders[.]run/api hxxps://playfulupaws[.]life/api hxxps://galxacticex[.]run/api hxxps://scalfeandtail[.]life/api hxxps://qcelestialo[.]run/api hxxps://cueddlycrea[.]run/api hxxps://animpalaffe[.]life/api hxxps://astrobib[.]life/api hxxps://winnevarid[.]run/api hxxps://virtualvxinsight[.]run/api hxxps://astrfcalinsights[.]run/api hxxps://codeevobvlution[.]run/api hxxps://astrogaze[.]run/api hxxps://huibokoras[.]run/api hxxps://creathurecove[.]bet/api hxxps://crebatureco[.]bet/api hxxps://feathteredf[.]bet/api hxxps://orbeitings[.]run/api hxxps://puawprintm[.]bet/api hxxps://scientihfichub[.]bet/api hxxps://ztechwave[.]bet/api hxxps://soilhewocacy[.]bet/api hxxps://pililowease[.]run/api hxxps://universeho[.]bet/api hxxps://lightyears[.]bet/api hxxps://quantyu[.]bet/api hxxps://areawannte[.]bet/api hxxps://farmtoonnection[.]bet/api hxxps://planestaryo[.]bet/api hxxps://sectioarran[.]bet/api |
Lumma Stealer |
URL | hxxp://mirok[.]click/UGkfLqRnkm95[.]bin hxxp://196[.]251[.]92[.]38/FTBjypzLOQQ40[.]bin hxxps://chneiu[.]icu/qZzaQfFD/epGfV132[.]bin hxxps://pendeliveryhl[.]com/ZpOXPI208[.]bin hxxp://204[.]10[.]160[.]132/UTgljylAMMNbXSs200[.]bin |
CloudEyE |
URL | hxxps://api[.]telegram[.]org/bot7351654760:AAFbpZoZSrKZKoCJV2by7hbyBL3xnGEoUrU/ hxxps://api[.]telegram[.]org/bot5902621720:AAG63saKfqN8L1Gxy5Zs-PFqX69DHY3i2Yg/ hxxp://147[.]124[.]213[.]50/crypt/hustle[.]exe |
Agent Tesla |
URL | hxxps://cf-prod-cap[.]cfd/georgefloyd[.]bat hxxps://cf-prod-cap[.]cfd/aliu1[.]ps1 hxxp://87[.]121[.]79[.]103/download/6b4cc14c9c6445989353e73e97374f17[.]txt hxxps://github[.]com/legendary99999/dsfdfsfdsfdsfdsfds/releases/download/dsfjdfjsdfjsdfs/ChromeUpdate[.]exe hxxps://github[.]com/legendary99999/dfsfdsfdsfds12/releases/download/dsfdsasasasa/done12312[.]exe hxxps://github[.]com/legendary99999/sdfdsfdsfdsfds/releases/download/sdffdsfdssfdfsdfddfs/valorant_ESP_aimbot[.]exe hxxp://185[.]7[.]214[.]211/b[.]jpg hxxps://growthinsightit[.]com/images/screentime[.]vbs hxxps://growthinsightit[.]com/images/streamfarms[.]bin hxxps://cf-prod-cap[.]cfd/cf_verif[.]ps1 |
XWorm |
URL | hxxp://110[.]41[.]78[.]57:8443/signin | Cobalt Strike |
URL | hxxps://medicamentsbonmarche[.]top/files/fill[.]php hxxps://urethaneai[.]com/euler[.]zip hxxps://medicamentsbonmarche[.]top/files/index[.]php hxxps://mallternet[.]com/js[.]php hxxps://medicamentsbonmarche[.]top/files/original[.]js hxxps://mallternet[.]com/6t5t[.]js hxxps://my-tasjeel-ae[.]com/getid[.]js hxxps://spain-playmarket[.]com/Chrome/Update/ hxxps://billing[.]shrewsburysocialclub[.]org/profileLayout |
FAKEUPDATES |
URL | hxxp://bmw4i428[.]su/bmwxmrig/xmrig[.]exe hxxp://107[.]167[.]42[.]214/miner hxxp://107[.]167[.]42[.]212/miner hxxp://107[.]167[.]32[.]212/miner hxxp://y[.]shavsl[.]com/miner hxxp://107[.]167[.]34[.]78/gif hxxp://107[.]167[.]42[.]211/gif hxxp://107[.]167[.]42[.]211/miner hxxp://192[.]186[.]12[.]50/miner hxxp://192[.]186[.]12[.]54/miner hxxp://107[.]167[.]42[.]210/miner hxxp://107[.]167[.]34[.]78/miner hxxp://107[.]167[.]34[.]74/miner hxxp://107[.]167[.]34[.]74/gif hxxp://107[.]167[.]42[.]210/gif hxxp://192[.]186[.]12[.]50/gif hxxp://192[.]186[.]12[.]54/gif hxxp://107[.]167[.]34[.]75/miner hxxp://w[.]shavsl[.]com/miner hxxp://z[.]shavsl[.]com/miner hxxp://192[.]186[.]12[.]51/miner hxxp://107[.]167[.]34[.]76/miner hxxp://w[.]shavsl[.]com/gif hxxp://107[.]167[.]34[.]75/gif hxxp://z[.]shavsl[.]com/gif hxxp://107[.]167[.]34[.]76/gif hxxp://192[.]186[.]12[.]51/gif hxxp://107[.]167[.]42[.]212/gif hxxp://107[.]167[.]32[.]212/gif hxxp://107[.]167[.]42[.]214/gif hxxp://w[.]shavsl[.]com/f hxxp://w[.]shavsl[.]com/c hxxp://w[.]shavsl[.]com/b hxxp://107[.]167[.]34[.]75/b hxxp://z[.]shavsl[.]com/f hxxp://107[.]167[.]34[.]75/f hxxp://z[.]shavsl[.]com/c hxxp://107[.]167[.]34[.]75/c hxxp://107[.]167[.]34[.]76/c hxxp://192[.]186[.]12[.]51/c hxxp://107[.]167[.]34[.]76/b hxxp://107[.]167[.]34[.]76/f hxxp://192[.]186[.]12[.]51/b hxxp://192[.]186[.]12[.]51/f hxxp://107[.]167[.]42[.]214/c hxxp://107[.]167[.]32[.]212/c hxxp://107[.]167[.]32[.]212/b hxxp://107[.]167[.]42[.]212/c hxxp://107[.]167[.]42[.]212/b hxxp://107[.]167[.]42[.]214/b hxxp://107[.]167[.]42[.]214/f hxxp://107[.]167[.]42[.]212/f hxxp://107[.]167[.]32[.]212/f hxxp://y[.]shavsl[.]com/f hxxp://107[.]167[.]34[.]74/b hxxp://y[.]shavsl[.]com/b hxxp://y[.]shavsl[.]com/c hxxp://107[.]167[.]34[.]74/c hxxp://107[.]167[.]34[.]78/f hxxp://107[.]167[.]42[.]210/b hxxp://107[.]167[.]34[.]78/c hxxp://107[.]167[.]42[.]210/f hxxp://107[.]167[.]42[.]211/b hxxp://192[.]186[.]12[.]54/c hxxp://192[.]186[.]12[.]50/b hxxp://107[.]167[.]34[.]78/b hxxp://107[.]167[.]42[.]211/f hxxp://192[.]186[.]12[.]50/c hxxp://192[.]186[.]12[.]54/f hxxp://107[.]167[.]42[.]211/c hxxp://107[.]167[.]42[.]210/c hxxp://192[.]186[.]12[.]50/f hxxp://107[.]167[.]34[.]74/f hxxp://192[.]186[.]12[.]54/b hxxp://107[.]167[.]34[.]77/miner |
Coinminer |
URL | hxxp://45[.]59[.]120[.]8/files/dinnmamunms/cubrodriver[.]exe | SystemBC |
URL | hxxps://floatnightlife[.]com/rms[.]msi?sn=65 | RMS |
URL | hxxps://github[.]com/legendary99999/dsfksdfkds/releases/download/dsfdsfdsdf/XMZTSVYE_l10_wix4_dash[.]exe | Tofsee |
URL | hxxps://github[.]com/legendary99999/saffsfsd/releases/download/dsffdssff/12321321[.]exe hxxps://farmagrupodw[.]com/temp/Elated[.]exe |
Socks5 Systemz |
URL | hxxps://github[.]com/legendary99999/llllll/releases/download/kkkkkk/MetaTrader[.]exe hxxps://bitbucket[.]org/microsoftingsoftwares/faw/downloads/Barfaser[.]exe |
Lumar |
URL | hxxp://176[.]113[.]115[.]7/files/748049926/nhDLtPT[.]exe hxxp://185[.]125[.]50[.]8/mVsXkjvb3/Plugins/clip64[.]dll hxxp://185[.]125[.]50[.]8/mVsXkjvb3/Plugins/cred64[.]dll |
Amadey |
URL | hxxp://42[.]233[.]146[.]156:41970/Mozi[.]m hxxp://192[.]10[.]136[.]219:34446/Mozi[.]m hxxp://117[.]235[.]42[.]77:46582/Mozi[.]m |
Mozi |
URL | hxxps://pendeliveryhl[.]com/Murker[.]lpk hxxp://23[.]95[.]235[.]9/452/nicegirlwanttokissingmylipswithnicely[.]hta |
Remcos |
URL | hxxp://176[.]113[.]115[.]7/files/1644719861/sqVWjvh[.]exe | Vidar |
URL | hxxp://176[.]113[.]115[.]7/files/5419477542/ADFoyxP[.]exe | StormKitty |
URL | hxxp://95[.]164[.]53[.]3/contact | AMOS |
URL | hxxps://20[.]229[.]103[.]183/niox[.]exe | BlankGrabber |
URL | hxxp://www[.]socialnetwork-toolbase[.]de/ucs/pny/gate[.]php | Pony |
URL | hxxp://196[.]251[.]80[.]231/Sakura[.]sh hxxp://196[.]251[.]80[.]231/a-r[.]m-4[.]s hxxp://196[.]251[.]80[.]231/a-r[.]m-6[.]s hxxp://196[.]251[.]80[.]231/x-8[.]6-[.]s hxxp://196[.]251[.]80[.]231/a-r[.]m-7[.]s hxxp://196[.]251[.]80[.]231/opticus[.]sh hxxp://196[.]251[.]80[.]231/s-h[.]4-[.]opticus hxxp://196[.]251[.]80[.]231/p-p[.]c-[.]opticus hxxp://196[.]251[.]80[.]231/m-i[.]p-s[.]opticus hxxp://196[.]251[.]80[.]231/x-3[.]2-[.]opticus hxxp://196[.]251[.]80[.]231/i-5[.]8-6[.]opticus hxxp://196[.]251[.]80[.]231/a-r[.]m-4[.]opticus hxxp://196[.]251[.]80[.]231/a-r[.]m-7[.]opticus hxxp://196[.]251[.]80[.]231/m-p[.]s-l[.]opticus hxxp://196[.]251[.]80[.]231/m-6[.]8-k[.]opticus hxxp://196[.]251[.]80[.]231/a-r[.]m-5[.]opticus hxxp://196[.]251[.]80[.]231/x-8[.]6-[.]opticus hxxp://196[.]251[.]80[.]231/a-r[.]m-6[.]opticus hxxp://45[.]135[.]194[.]28/Sakura[.]sh hxxp://45[.]135[.]194[.]28/a-r[.]m-5[.]Sakura hxxp://45[.]135[.]194[.]28/i-5[.]8-6[.]Sakura hxxp://45[.]135[.]194[.]28/m-i[.]p-s[.]Sakura hxxp://45[.]135[.]194[.]28/m-p[.]s-l[.]Sakura hxxp://45[.]135[.]194[.]28/m-6[.]8-k[.]Sakura hxxp://45[.]135[.]194[.]28/a-r[.]m-4[.]Sakura hxxp://45[.]135[.]194[.]28/a-r[.]m-6[.]Sakura hxxp://45[.]135[.]194[.]28/p-p[.]c-[.]Sakura hxxp://45[.]135[.]194[.]28/a-r[.]m-7[.]Sakura |
Bashlite |
URL | hxxp://176[.]113[.]115[.]7/files/7821444099/mIrI3a9[.]exe | StrelaStealer |
URL | hxxp://185[.]196[.]8[.]88:9190/test[.]woff | donut_injector |
URL | hxxps://x[.]0[.]feedback/uh_uh+uh | Sliver |
URL | hxxp://152[.]36[.]128[.]18/cgi-bin/p[.]cgi | Prometei |
URL | hxxp://h2slq[.]store/PL341/index[.]php | Azorult |
URL | hxxps://refereng[.]shop/tozemeniaclo[.]mp3 hxxps://cariz[.]shop/junkypool[.]mp3 |
Emmenhtal |
URL | hxxps://authenticatior[.]com/vrep[.]msi hxxps://authenticatior[.]com/NSM[.]lic hxxps://authenticatior[.]com/Client32[.]ini hxxp://176[.]113[.]115[.]7/files/6291786446/fCsM05d[.]bat |
NetSupportManager RAT |
URL | hxxp://58ff574[.]na3[.]to/cake/setup1549[.]msi hxxp://34[.]85[.]195[.]5:8080/cake/setup1549[.]msi hxxp://34[.]85[.]195[.]5:8080/doc/Document-BU110526045[.]lnk hxxp://58ff574[.]na3[.]to/doc/Document-BU110526045[.]lnk |
MetaStealer |
URL | hxxp://107[.]172[.]157[.]141/pty4 | Tsunami |