不正URLへのアクセス、不正メールの受信
-
メール受信した
弊社お客様0社 URLアクセスした
弊社お客様3社 -
2025/04/09
※2025/04/09 更新
マルウェア感染させると考えられるURLを検知(2025/04/09)
■IoC(※1)
Type: | IOC: | Signature: |
---|---|---|
URL | hxxps://u1[.]strongboxjarring[.]shop/9oq0lch9ad[.]aac hxxps://u1[.]strongboxjarring[.]shop/x8loggcyfh[.]aac hxxps://u1[.]strongboxjarring[.]shop/g5huzo67dt[.]aac hxxps://u1[.]strongboxjarring[.]shop/1zjl663lv3[.]aac hxxps://u1[.]strongboxjarring[.]shop/8aeize7t6y[.]aac hxxps://check[.]riced[.]icu/gkcxv[.]google hxxps://u1[.]strongboxjarring[.]shop/16ke4t1sxe[.]aac hxxps://u1[.]ruptureduckling[.]shop/5cd1slsviv[.]aac hxxps://u1[.]ruptureduckling[.]shop/vgptmmodkd[.]aac hxxps://u1[.]ruptureduckling[.]shop/qi7msujd0r[.]aac hxxps://u1[.]ruptureduckling[.]shop/fwxnia9xnp[.]aac hxxps://u1[.]ruptureduckling[.]shop/4w5oflzy8q[.]aac hxxps://check[.]zatij[.]icu/gkcxv[.]google hxxps://u1[.]ruptureduckling[.]shop/74jtj3jxhs[.]aac hxxps://u1[.]ruptureduckling[.]shop/ckgxytq0u3[.]aac hxxps://check[.]wejyj[.]icu/gkcxv[.]google hxxps://u1[.]ruptureduckling[.]shop/sggwuta8z2[.]aac hxxps://u1[.]ruptureduckling[.]shop/b0pmvngac4[.]aac hxxps://u1[.]ruptureduckling[.]shop/ixb7iq320i[.]aac hxxps://check[.]nikys[.]icu/gkcxv[.]google |
ClearFake |
URL | hxxp://185[.]29[.]10[.]66/2/hFJWVnXF66[.]bin hxxp://185[.]29[.]10[.]66/2/ChBPXZb133[.]bin hxxps://www[.]transparenciaquillota[.]cl/gzWguOVQIi86[.]bin hxxps://www[.]transparenciaquillota[.]cl/Rithe[.]msi hxxps://pfatrivandrum[.]org/fonts/HjDAVIyk236[.]bin hxxps://pfatrivandrum[.]org/fonts/Tuberculinizing[.]fla hxxp://kwonganhoney[.]com[.]au/5t/Fjerkrsakses[.]snp hxxps://pfatrivandrum[.]org/images/aCfKgtyuWBBPfeXCdOqxK171[.]bin hxxps://pfatrivandrum[.]org/images/Midafternoon[.]snp hxxp://upnet[.]bg/d0/Stokkedslagene[.]pcx hxxps://bintiwaafrika[.]co[.]tz/wp-content/upgrade/users/ddTAdXUInDF55[.]bin hxxps://bintiwaafrika[.]co[.]tz/wp-content/upgrade/users/Lydisolerede[.]psm |
CloudEyE |
URL | hxxp://213[.]209[.]150[.]18/tfqHNUJxJdFp8T0[.]exe | LokiBot |
URL | hxxp://176[.]113[.]115[.]7/files/6586442134/Nehh6wZ[.]exe hxxp://176[.]113[.]115[.]7/files/6679473704/NlmvJyQ[.]exe hxxps://-touvrlane[.]bet/ASKwjq hxxps://vwxayfarer[.]live/ALosnz hxxps://lholidamyup[.]today/AOzkns hxxps://cometasr[.]shop/KASKizo hxxps://itouvrlane[.]bet/ASKwjq hxxps://ezdoll[.]shop/onematchfun[.]ogg hxxps://leasyfwdr[.]digital/azxs hxxps://soursopsf[.]run/gsoiao hxxps://salaccgfa[.]top/gsooz hxxps://zestmedo[.]top/login |
Lumma Stealer |
URL | hxxps://erdalbesikc123iler[.]com/ZGZlZTNiYThiMjcx/ hxxps://effyleydi2020[.]com/ZGZlZTNiYThiMjcx/ hxxps://karamelpeteksepet1[.]com/ZGZlZTNiYThiMjcx/ hxxps://mutfakcinecolar[.]com/ZGZlZTNiYThiMjcx/ hxxps://ciceksepetilove[.]com/ZGZlZTNiYThiMjcx/ |
Coper |
URL | hxxps://lawofcjdj[.]com/js[.]php hxxps://lawofcjdj[.]com/4r6t[.]js hxxps://myvrhost[.]viottoholdings[.]com/profileLayout hxxps://customer[.]adroitbookkeepingsolutions[.]com/profileLayout hxxps://gsejewelers[.]com/5r3e[.]js hxxps://gsejewelers[.]com/js[.]php hxxps://nelsonsys[.]com/5y7y[.]js hxxps://nelsonsys[.]com/js[.]php hxxps://gsejewelers[.]com/4e2w[.]js |
FAKEUPDATES |
URL | hxxp://172[.]245[.]208[.]13/wex/wpx22[.]js | WSHRAT |
URL | hxxps://www[.]flybirdexpbd[.]com/jbfdbfasync[.]txt hxxps://www[.]flybirdexpbd[.]com/new_image[.]jpg hxxp://191[.]93[.]113[.]197/Winlogon[.]vbs |
AsyncRAT |
URL | hxxp://176[.]65[.]142[.]190/BLACKYY/BAG[.]ps1 hxxps://api[.]telegram[.]org/bot7082905567:AAFthQUn2UsOR5WT8ZCtytgzcEfoNXulR-A/ hxxps://api[.]telegram[.]org/bot7843184775:AAHOBE0-FzN1xU2pDbHBOhnzF23tEv9NLAk/ |
Agent Tesla |
URL | hxxp://d3f5[.]online/TL341/index[.]php | Azorult |
URL | hxxps://api[.]telegram[.]org/bot7697507440:AAFuQezSw7DI3zQgq4l4VVgAyKJBog75g3Q/sendMessage?chat_id=1452764935 hxxps://api[.]telegram[.]org/bot7797524813:AAEaIK0RkTGJOWsh2vOvumW_54vTNVKkYBQ/sendMessage?chat_id=7228047221 hxxps://api[.]telegram[.]org/bot7654373771:AAGOFFM0m4GFmu47nbE2ge7QEBzcxUn5PmM/sendMessage?chat_id=5007084465 hxxps://api[.]telegram[.]org/bot7158350058:AAF2snVpEK38ac2bAfeKv7kzzgdhOxx17G4/sendMessage?chat_id=1018401531 hxxps://api[.]telegram[.]org/bot7985484998:AAFsmCUbj-RbndicWEKPuhEvaDYH47OZGAg/sendMessage?chat_id=5798480986 hxxps://api[.]telegram[.]org/bot8106879360:AAHaYBYQGYSWJjihGiri4Qp-e1wgGh-cf5o/sendMessage?chat_id=7722316791 hxxps://api[.]telegram[.]org/bot7522799860:AAGndtHCenriyfec1ugcxSZv_j1V3rll_-8/sendMessage?chat_id=6322838897 hxxps://api[.]telegram[.]org/bot7191250169:AAFkvmV4xhcZoEl641qiQbJXLazzcaj6fVA/sendMessage?chat_id=5828071914 hxxps://api[.]telegram[.]org/bot8044953014:AAE_YVs1tIse1kiBBKSg8c0YFIvzAjDJHyM/sendMessage?chat_id=6341109890 hxxps://api[.]telegram[.]org/bot5614430001:AAEbIWTdXfu3s5s1KKnyCPgJuVgY1hvdWTw/sendMessage?chat_id=5628150055 hxxps://api[.]telegram[.]org/bot7932780903:AAFl5mC199bkUJR8Ea8e1Xhisx0Js_-PmDk/sendMessage?chat_id=1695799026 hxxps://api[.]telegram[.]org/bot7290518653:AAE8ef37d8xOmKETJqD9tnJR6y_FaNfYcSg/sendMessage?chat_id=7153546848 hxxps://api[.]telegram[.]org/bot7783674897:AAFbHdASwB5CHE3mIl0fvi0NySBTY4csAwk/sendMessage?chat_id=8040488185 hxxps://api[.]telegram[.]org/bot7298225341:AAFmefIUDDnELjBK83TpZcoeeW_Q2irGSDY/sendMessage?chat_id=7162961553 hxxps://api[.]telegram[.]org/bot7802155527:AAH6KLqLwjkSPCYSovZkPLf0RwZD2Qk6ULY/sendMessage?chat_id=6468285478 hxxps://api[.]telegram[.]org/bot7082832297:AAEda5vRZm5Ms2gikHJfOqy4zN_V1zydQI0/sendMessage?chat_id=5262847201 hxxps://api[.]telegram[.]org/bot7331223637:AAEEj9-hok9qv06GfzNOXwOBvIphLxLoQFY/sendMessage?chat_id=5749111949 hxxps://api[.]telegram[.]org/bot7851180322:AAElCRrJUChM2Vl3xRuSuIoNVOcq2KJ7_ZQ/sendMessage?chat_id=6443108993 |
Snake Keylogger |
URL | hxxp://103[.]15[.]28[.]149/ppc hxxp://103[.]15[.]28[.]149/sh4 |
Bashlite |
URL | hxxp://maxdarrah[.]com/ServidorIntimacoes/mytesta1e[.]pdf[.]lnk hxxp://www[.]gateway[.]funnelconsultants[.]com/ServidorIntimacoes/mytesta1e[.]pdf[.]lnk hxxp://bezpecnost-csob[.]cz[.]kjfdraws[.]com/ServidorIntimacoes/mytesta1e[.]pdf[.]lnk hxxp://www[.]superxsuper[.]com/ServidorIntimacoes/mytesta1e[.]pdf[.]lnk hxxp://www[.]mobileautosalon[.]com/ServidorIntimacoes/mytesta1e[.]pdf[.]lnk hxxp://sabrasmith[.]com/ServidorIntimacoes/mytesta1e[.]pdf[.]lnk hxxp://superxsuper[.]com/ServidorIntimacoes/mytesta1e[.]pdf[.]lnk |
Emmenhtal |
URL | hxxp://www[.]zd[.]online/u02r/ hxxp://www[.]rbitsgateway[.]xyz/u02r/ hxxp://www[.]reamcloudpoint[.]sbs/u02r/ hxxp://www[.]remlinclub[.]online/u02r/ hxxp://www[.]riplead[.]shop/u02r/ hxxp://www[.]rvoyager[.]xyz/u02r/ hxxp://www[.]ursing-home-51[.]bond/u02r/ hxxp://www[.]usshelter[.]net/u02r/ hxxp://www[.]vitream4[.]online/u02r/ hxxp://www[.]wanttoliveathelena57west[.]net/u02r/ hxxp://www[.]orcerush[.]xyz/u02r/ hxxp://www[.]orldofconsumption[.]shop/u02r/ hxxp://www[.]ouse-cleaning-us-6811[.]shop/u02r/ hxxp://www[.]pin-win-bonanza[.]xyz/u02r/ hxxp://www[.]pinrqube[.]shop/u02r/ hxxp://www[.]playcash[.]fun/u02r/ hxxp://www[.]portsterminal[.]xyz/u02r/ hxxp://www[.]rain-pipe-cleaning-4530[.]bond/u02r/ hxxp://www[.]nventory-software-74785[.]bond/u02r/ hxxp://www[.]oans-credits-97557[.]bond/u02r/ hxxp://www[.]obcases[.]online/u02r/ hxxp://www[.]ocy1f[.]shop/u02r/ hxxp://www[.]olehavenq[.]shop/u02r/ hxxp://www[.]omevisionpro[.]online/u02r/ hxxp://www[.]oolplusservis[.]online/u02r/ hxxp://www[.]or-yes[.]info/u02r/ hxxp://www[.]linkcopilots[.]xyz/u02r/ hxxp://www[.]llaadharservices[.]shop/u02r/ hxxp://www[.]mescorp[.]online/u02r/ hxxp://www[.]metrxip[.]online/u02r/ hxxp://www[.]mployment-lawyer-near-me[.]cfd/u02r/ hxxp://www[.]ngineering-near-me[.]cfd/u02r/ hxxp://www[.]nimesyentai[.]biz/u02r/ hxxp://www[.]nline-advertising-23082[.]bond/u02r/ hxxp://www[.]gvyv[.]cfd/u02r/ hxxp://www[.]hewagonbox[.]club/u02r/ hxxp://www[.]iabetgirisi[.]net/u02r/ hxxp://www[.]iamtemp2[.]online/u02r/ hxxp://www[.]igeast[.]xyz/u02r/ hxxp://www[.]isspoppydesignava[.]shop/u02r/ hxxp://www[.]itchellstreamhub[.]online/u02r/ hxxp://www[.]ivevr[.]online/u02r/ hxxp://www[.]lexavegaspgs22[.]club/u02r/ hxxp://www[.]bbabet[.]pro/u02r/ hxxp://www[.]cnba77[.]sbs/u02r/ hxxp://www[.]esignsmith[.]online/u02r/ hxxp://www[.]esturist[.]website/u02r/ hxxp://www[.]ewsinprague[.]click/u02r/ hxxp://www[.]eyn[.]ltd/u02r/ hxxp://www[.]givens[.]info/u02r/ hxxp://www[.]gresale[.]net/u02r/ hxxp://www[.]ainsdrop[.]fun/u02r/ hxxp://www[.]akeit[.]studio/u02r/ hxxp://www[.]ampmonkey[.]net/u02r/ hxxp://www[.]apitalentryplussteerhubweb[.]xyz/u02r/ hxxp://www[.]arbary[.]shop/u02r/ hxxp://www[.]atchband[.]info/u02r/ hxxp://www[.]atlx[.]net/u02r/ hxxp://www[.]azete[.]biz/u02r/ hxxp://www[.]0red[.]xyz/u02r/ hxxp://www[.]17pcuo430r[.]shop/u02r/ hxxp://www[.]1garagedoor[.]online/u02r/ hxxp://www[.]abysitter-service-97519[.]bond/u02r/ hxxp://www[.]admachin3[.]shop/u02r/ |
Formbook |
URL | hxxp://192[.]3[.]23[.]235/xampp/javn/mrm/greatnicegirlbackontheearthwithgoodnews[.]hta | Remcos |
URL | hxxps://servimantenimiento[.]com/msg[.]zip?&num=747 hxxps://servimantenimiento[.]com/msg[.]zip hxxps://medthermography[.]com/neth[.]zip?&num=691 hxxps://medthermography[.]com/neth[.]zip |
NetSupportManager RAT |