サイバーリスク情報提供 Dアラート 特許取得済み

不正URLへのアクセス、不正メールの受信

メール受信した
弊社お客様
0 URLアクセスした
弊社お客様
1
2025/03/12
※2025/03/12 更新
マルウェア感染させると考えられるURLを検知(2025/03/12)
■IoC(※1)
Type: IOC: Signature:
URL hxxp://154[.]127[.]56[.]114/SnOoPy[.]sh
hxxp://154[.]127[.]56[.]114/a-r[.]m-6[.]SNOOPY
hxxp://185[.]142[.]53[.]43/bee
hxxp://185[.]142[.]53[.]43/massload
hxxp://185[.]142[.]53[.]43/buf
hxxp://185[.]142[.]53[.]43/zxc[.]sh
hxxp://185[.]142[.]53[.]43/phi[.]sh
hxxp://196[.]251[.]81[.]246/demon[.]mpsl
hxxp://196[.]251[.]81[.]246/demon[.]mips
hxxp://196[.]251[.]81[.]246/nezukobins/demon[.]mips
hxxp://196[.]251[.]81[.]246/nezukobins/demon[.]mpsl
Bashlite
URL hxxps://dashboard[.]nzlifecoaching[.]com/profileLayout
hxxps://rasin[.]shop/files/original[.]js
hxxps://rasin[.]shop/files/index[.]php
hxxps://rasin[.]shop/files/fis[.]php
hxxps://reliefmdlabs[.]com/KBDTAM99[.]zip
hxxps://catalog[.]sjsailboats[.]com/profileLayout
hxxps://srpkoa[.]com/4e6t[.]js
hxxps://srpkoa[.]com/js[.]php
FAKEUPDATES
URL hxxp://176449cm[.]nyashk[.]ru/imagepacket[.]php
hxxp://89[.]107[.]10[.]189/videolowauthProtectTrack[.]php
hxxp://5[.]252[.]155[.]127/9LocalProcess/8Provider/dumpTemp/Request/pollprotect3/65/4Pipeeternal/TestPython/javascript/HttpUploadsApiVideo/auth/WindowssqlJavascript/ExternalPythoncpugameSqlPubliccdnDownloads[.]php
hxxp://697624cm[.]nyanyash[.]ru/providerPipepythonjavascriptprocessprotectDatalifeLocalcentral[.]php
hxxp://91[.]132[.]59[.]41/sqlLocal/authUniversalLongpollJavascript/CpuDefault/requestSecureLinux/Php7/VideoprotonDump/videoLinepipePollLowProtecttrafficTesttemp[.]php
DCRat
URL hxxp://185[.]29[.]11[.]34/1/pocgseS28[.]bin
hxxp://185[.]29[.]11[.]34/1/mMUAIEnR254[.]bin
CloudEyE
URL hxxp://62[.]60[.]226[.]53/89b86fda49329a90/sqlite3[.]dll
hxxp://62[.]60[.]226[.]53/89b86fda49329a90/softokn3[.]dll
hxxp://62[.]60[.]226[.]53/89b86fda49329a90/msvcp140[.]dll
hxxp://62[.]60[.]226[.]53/89b86fda49329a90/mozglue[.]dll
hxxp://62[.]60[.]226[.]53/89b86fda49329a90/vcruntime140[.]dll
hxxp://62[.]60[.]226[.]53/89b86fda49329a90/nss3[.]dll
hxxp://62[.]60[.]226[.]53/89b86fda49329a90/freebl3[.]dll
Stealc
URL hxxps://check[.]laqyk[.]icu/gkcxv[.]google
hxxps://check[.]podyz[.]icu/gkcxv[.]google
hxxps://u1[.]optdropper[.]shop/Siarhei_Korbut_-_Aging[.]mp3
hxxps://u1[.]optdropper[.]shop/Siarhei_Korbut_-_Pavement[.]mp3
hxxps://u1[.]optdropper[.]shop/Siarhei_Korbut_-_Failing[.]mp3
hxxps://u1[.]superheroomen[.]shop/Siarhei_Korbut_-_Tinfoil[.]mp3
hxxps://check[.]rygog[.]icu/gkcxv[.]google
hxxps://u1[.]superheroomen[.]shop/Siarhei_Korbut_-_Thirstily[.]mp3
hxxps://u1[.]superheroomen[.]shop/Siarhei_Korbut_-_Proclaim[.]mp3
hxxps://u1[.]superheroomen[.]shop/Siarhei_Korbut_-_Pavement[.]mp3
hxxps://u1[.]optdropper[.]shop/Siarhei_Korbut_-_Proclaim[.]mp3
hxxps://check[.]gytas[.]icu/gkcxv[.]google
hxxps://u1[.]superheroomen[.]shop/Siarhei_Korbut_-_Removing[.]mp3
hxxps://check[.]myquk[.]icu/gkcxv[.]google
hxxps://u1[.]superheroomen[.]shop/Siarhei_Korbut_-_Prison[.]mp3
hxxps://u1[.]superheroomen[.]shop/Siarhei_Korbut_-_Rind[.]mp3
hxxps://check[.]fajez[.]icu/gkcxv[.]google
hxxps://u1[.]wannabeclobber[.]shop/Siarhei_Korbut_-_Cork[.]mp3
hxxps://u1[.]wannabeclobber[.]shop/Siarhei_Korbut_-_Division[.]mp3
hxxps://u1[.]wannabeclobber[.]shop/Siarhei_Korbut_-_Defiance[.]mp3
hxxps://u1[.]wannabeclobber[.]shop/Siarhei_Korbut_-_Endurance[.]mp3
hxxps://check[.]dovoo[.]icu/gkcxv[.]google
hxxps://u1[.]wannabeclobber[.]shop/Siarhei_Korbut_-_Motto[.]mp3
hxxps://u1[.]wannabeclobber[.]shop/Siarhei_Korbut_-_Radiance[.]mp3
hxxps://u1[.]wannabeclobber[.]shop/Siarhei_Korbut_-_Recoil[.]mp3
hxxps://check[.]vevou[.]icu/gkcxv[.]google
ClearFake
URL hxxps://nextgenideas2023[.]top/api
hxxps://-earthsymphzony[.]today/api
hxxp://176[.]113[.]115[.]7/files/5153162918/P2SXMuh[.]exe
hxxps://narisechairedd[.]shop/api
hxxps://flegenassedk[.]top/api
hxxps://2[.]sterpickced[.]digital/api
hxxp://176[.]113[.]115[.]7/files/6691015685/DVaKyq7[.]exe
hxxp://176[.]113[.]115[.]7/files/6691015685/6NPpGdC[.]exe
hxxps://-htardwarehu[.]icu/api
hxxps://eeexplorebieology[.]run/api
hxxps://organicfxecrets[.]today/api
hxxps://0garagedrootz[.]top/api
hxxps://univerxes[.]shop/api
hxxps://felegenassedk[.]top/api
hxxps://7bugildbett[.]top/api
hxxps://4modelshiverd[.]icu/api
hxxps://backyardbounty[.]live/api
hxxps://paweshom[.]digital/api
hxxps://relaxingxpillow[.]digital/api
hxxps://expergalscience[.]live/api
hxxps://localfxement[.]live/api
hxxps://quantuqearch[.]live/api
hxxps://geyntlepillows[.]live/api
hxxps://riversftonejourney[.]digital/api
hxxps://kulihase[.]digital/api
hxxps://incidenlikedop[.]digital/api
hxxps://exoprlanet[.]digital/api
hxxps://blissfulspillow[.]digital/api
hxxps://scikevision[.]today/api
hxxps://peacefzulpillow[.]today/api
hxxps://cocjkoonpillow[.]today/api
hxxps://oxceansounds[.]digital/api
hxxps://passievedhbu[.]icu/api
hxxps://cratevexxerj[.]icu/api
hxxps://sprinbgstre[.]icu/api
hxxps://zfostinjec[.]today/api
hxxps://deepspac[.]digital/api
hxxps://outofthisw[.]shop/api
hxxps://wildlnifeecho[.]world/api
hxxps://futuwrebyte[.]world/api
hxxps://bhgyuncovered[.]world/api
hxxps://pillowhagven[.]world/api
hxxps://limitlxesshorizons[.]tech/api
hxxps://wandererx[.]tech/api
hxxps://jojyfulmoments[.]tech/api
hxxps://zenrichyourlife[.]tech/api
hxxps://dreambigideaxs[.]tech/api
hxxps://soulfuxlconnections[.]tech/api
hxxps://bxettertogether[.]tech/api
hxxps://fruitfuvljourney[.]tech/api
hxxps://inspiredlivxing[.]tech/api
hxxps://sharingknowlezdge[.]tech/api
hxxps://changemakezrs[.]tech/api
hxxps://inspirzedthoughts[.]tech/api
hxxps://fearlessdreazmers[.]tech/api
hxxps://harmoniousrelapzs[.]tech/api
hxxps://genvtlewhispers[.]tech/api
hxxps://wildpadventures[.]tech/api
hxxps://creativxecorner[.]tech/api
hxxps://balancpedlife[.]tech/api
hxxps://sunpnyvibes[.]tech/api
hxxps://grxeenplanet[.]tech/api
hxxps://daixlyinspiration[.]tech/api
hxxps://radziantenergy[.]tech/api
hxxps://excitinzgtrends[.]tech/api
hxxps://artfupldesign[.]tech/api
hxxps://cuddlypifllow[.]life/api
hxxps://techixnnovation[.]tech/api
hxxps://harvestseasonblog[.]life/api
hxxps://0sterpickced[.]digital/api
hxxps://qmrodularmall[.]top/api
hxxps://rgaragedrootz[.]top/api
hxxps://efostinjec[.]today/api
hxxps://cfeatureccus[.]shop/api
hxxps://acjlaspcorne[.]icu/api
hxxps://classironedd[.]top/api
hxxps://agedsoucid[.]top/api
hxxps://fixfturefin[.]top/api
hxxps://operateoxasi[.]top/api
hxxps://desigvndeta[.]top/api
hxxps://bolbtbo[.]top/api
hxxps://accefsorysp[.]top/api
hxxps://joingeryjunc[.]top/api
hxxps://fittinvgfie[.]top/api
hxxps://compgonentco[.]top/api
hxxps://moluntmarke[.]top/api
hxxps://vbegindecafer[.]world/api
hxxps://vfostinjec[.]today/api
hxxps://ymodelshiverd[.]icu/api
hxxps://corangemyther[.]live/api
hxxps://barisechairedd[.]shop/api
Lumma Stealer
URL hxxp://www[.]usk360[.]xyz/my18/
hxxp://www[.]utuelleretraite[.]bond/my18/
hxxp://www[.]uyurbanaraava[.]shop/my18/
hxxp://www[.]xclusivedealsspots[.]sbs/my18/
hxxp://www[.]xpertisechat[.]xyz/my18/
hxxp://www[.]ypercog[.]xyz/my18/
hxxp://www[.]yset[.]info/my18/
hxxp://www[.]zgtl[.]click/my18/
hxxp://www[.]reshdirectivesolutions[.]info/my18/
hxxp://www[.]rnamiara[.]online/my18/
hxxp://www[.]ruck-driver-jobs-41162[.]bond/my18/
hxxp://www[.]rustless888[.]xyz/my18/
hxxp://www[.]ryptoosvita[.]website/my18/
hxxp://www[.]shim[.]shop/my18/
hxxp://www[.]strology-options-12038[.]bond/my18/
hxxp://www[.]tmsolcoinews[.]uno/my18/
hxxp://www[.]ummitpointconsulting[.]net/my18/
hxxp://www[.]odesfactory[.]xyz/my18/
hxxp://www[.]offee-machine-19139[.]bond/my18/
hxxp://www[.]oiyter[.]xyz/my18/
hxxp://www[.]omelyrooms[.]online/my18/
hxxp://www[.]oneyiq[.]xyz/my18/
hxxp://www[.]ousecure[.]online/my18/
hxxp://www[.]ovedirectiveteam[.]info/my18/
hxxp://www[.]partamento-sao-paulo-610[.]click/my18/
hxxp://www[.]reatyarmouth-cruisetours[.]today/my18/
hxxp://www[.]ivor[.]online/my18/
hxxp://www[.]knowido[.]net/my18/
hxxp://www[.]kosor-ossorilmma[.]online/my18/
hxxp://www[.]ladproductreviews[.]shop/my18/
hxxp://www[.]lizz[.]finance/my18/
hxxp://www[.]lotheroes[.]casino/my18/
hxxp://www[.]luebunkers[.]online/my18/
hxxp://www[.]nnotechg[.]net/my18/
hxxp://www[.]obilityscooterscooters[.]today/my18/
hxxp://www[.]gendamos[.]online/my18/
hxxp://www[.]hartplus[.]autos/my18/
hxxp://www[.]hiefworthextendfirmbridge[.]xyz/my18/
hxxp://www[.]hoenixlearningnetwork[.]net/my18/
hxxp://www[.]iartetuexperiencia[.]live/my18/
hxxp://www[.]infix[.]today/my18/
hxxp://www[.]itblog[.]tech/my18/
hxxp://www[.]itness-center-ph-8859635[.]zone/my18/
hxxp://www[.]eatintell[.]net/my18/
hxxp://www[.]ebpazarim[.]net/my18/
hxxp://www[.]elonyyoung[.]net/my18/
hxxp://www[.]emotepilottraining[.]online/my18/
hxxp://www[.]ermanosu[.]online/my18/
hxxp://www[.]esconseils[.]net/my18/
hxxp://www[.]exas88me[.]pro/my18/
hxxp://www[.]excopilot[.]xyz/my18/
hxxp://www[.]gac[.]online/my18/
hxxp://www[.]91033[.]pro/my18/
hxxp://www[.]adawol[.]click/my18/
hxxp://www[.]aiaearthworks[.]net/my18/
hxxp://www[.]alleoncoin[.]net/my18/
hxxp://www[.]anufixo[.]xyz/my18/
hxxp://www[.]bplus[.]motorcycles/my18/
hxxp://www[.]bzxnbzy[.]xyz/my18/
hxxp://www[.]eagleinsurancepros[.]website/my18/
hxxp://www[.]earntok[.]shop/my18/
hxxp://www[.]120qa[.]xyz/my18/
hxxp://www[.]16bet[.]website/my18/
hxxp://www[.]27652[.]locker/my18/
hxxp://www[.]5432pxnshot[.]pics/my18/
Formbook
URL hxxps://185[.]215[.]113[.]209/di0her478/index[.]php Amadey
URL hxxps://senelcicekcilik08[.]com/ZjQ2Njg0MWJjNGE0/
hxxps://kledgarentokat3535[.]com/ZjQ2Njg0MWJjNGE0/
hxxps://turhoslemar[.]com/ZjQ2Njg0MWJjNGE0/
hxxps://amasyaperdecilik[.]com/ZjQ2Njg0MWJjNGE0/
hxxps://ordneskrmvr5252[.]com/ZjQ2Njg0MWJjNGE0/
hxxps://aliatabakastakirkharamilers[.]com/MzUyMGI3MTIxOWF/
hxxps://alibabacankirkharamiler[.]net/MzUyMGI3MTIxOWFk/
hxxps://alibabacankirkharamiler[.]com/MzUyMGI3MTIxOWFk/
hxxps://kirkharamilervealibabacans[.]net/MzUyMGI3MTIxOWFk/
hxxps://kirkharamilersavastayinebea[.]com/MzUyMGI3MTIxOWFk/
Coper
URL hxxp://107[.]167[.]35[.]61/miner
hxxp://107[.]167[.]35[.]61/c
hxxp://107[.]167[.]35[.]61/b
hxxp://107[.]167[.]35[.]61/f
hxxp://185[.]125[.]50[.]8/mVsXkjvb3/Plugins/firefox[.]exe
hxxp://w[.]softprojectcode[.]com/miner
Coinminer
URL hxxp://23[.]95[.]235[.]28/xampp/vn/v/kissingwithbestexperiencedgirlfriendonhereformenice[.]hta
hxxp://198[.]12[.]89[.]24/123/casse[.]exe
hxxp://198[.]12[.]89[.]24/xampp/ncv/niceworkingskillwithbestideasevermade[.]hta
hxxp://23[.]95[.]235[.]28/550/vcc[.]exe
MASS Logger
URL hxxp://192[.]227[.]228[.]22/840/vcc[.]exe DBatLoader
URL hxxps://api[.]telegram[.]org/bot6820629737:AAGJ8tOkoD9jFHkd_L1kG1ntQ1J6zLhFsMc/sendMessage?chat_id=6783205225 Snake Keylogger
URL hxxps://fopiese[.]com/web/data
hxxps://dinctov[.]com/web/data
hxxps://ennaser[.]com/web/data
hxxps://hyatart[.]com/web/data
hxxps://bladilk[.]com/web/data
hxxps://giridly[.]com/web/data
hxxps://pleclep[.]com/web/data
hxxps://phanleb[.]com/web/data
Zloader
URL hxxp://gd53[.]cfd/TL341/index[.]php Azorult
URL hxxps://www[.]mediafire[.]com/file_premium/tgt65hk2h8vsbrn/skeletal[.]bin/file HijackLoader
URL hxxps://github[.]com/deripascod/coderoom/raw/refs/heads/main/thawdtyh[.]exe
hxxps://github[.]com/deripascod/coderoom/raw/refs/heads/main/nyoilsafkjawd[.]exe
hxxps://github[.]com/deripascod/coderoom/raw/refs/heads/main/crossings[.]exe
hxxps://github[.]com/deripascod/coderoom/raw/refs/heads/main/boilfdsefSQ[.]exe
Remcos
URL hxxp://89[.]23[.]107[.]240:7777/confirm2[.]com/AdvancedVovMusicPlayerCommunitySetup[.]msi DanaBot
URL hxxp://89[.]23[.]107[.]240:7777/confirm2[.]com/Capcha Emmenhtal
※1「i-FILTER」アクセスログを検索し端末を特定してください 不要なアクセスを避けるため、一部変更しております。 ■製品対応状況(※2) ▽i-FILTER(※3) ・[脅威情報サイト]カテゴリでブロック可能 ※2 ブロックの可否は各製品の設定によるため、実際の結果はアクセスログを参照してください。 ※3 暗号化された通信の場合は、SSL Adapterの設定を「利用」にする必要があります。
イベント・セミナー情報