不正URLへのアクセス、不正メールの受信
-
メール受信した
弊社お客様0社 URLアクセスした
弊社お客様2社 -
2026/03/09
※2026/03/09 更新
マルウェア感染させると考えられるURLを検知(2026/03/09)
■IoC(※1)
| Type: | IOC: | Signature: |
|---|---|---|
| URL | hxxps://f7ozu1t9[.]flogginquisit[.]digital/?=check&&actmn=YVIBwWnnTOgWtApP hxxps://ygzulpfl[.]floatmurta[.]digital/?=check&&actmn=vtRMqiYITFEuxxIu hxxps://lsvvpb8t[.]drinktide[.]digital/?=check&&actmn=ELXlcEnNyuHDptpw hxxps://kvid5obz[.]awakepathog[.]digital/?=check&&actmn=PMmxemMLVOJZPEko hxxps://sqddakti[.]awakepathog[.]digital/?=check&&actmn=FhKBGAbPdxMGLMmf hxxps://g70aw0re[.]bucketeuthan[.]digital/?=check&&actmn=rsVbayURMrZwROJO hxxps://0a6nq1j0[.]budenowcvolt[.]digital/?=check&&actmn=qMoLVibgciSorqTF hxxps://pgubdbmp[.]austeritymorg[.]digital/?=check&&actmn=YjFdVRNSzYRhjBug hxxps://1pqv53qc[.]dumbbellshower[.]digital/?=check&&actmn=fqKKoXttkOgYYrsq hxxps://tquq11g4[.]colitishatred[.]digital/?=check&&actmn=IGIRAdjVetwzjGzH hxxps://f4gyiajw[.]impeachlizob[.]digital/?=check&&actmn=dTBgPoTLTlgAbTnO |
ClearFake |
| URL | hxxps://fulusus[.]com/api/install-failure | Glupteba |
| URL | hxxps://electrico[.]co[.]zw/wp-admin/five/five/PvqDq929BSx_A_D_M1n_a[.]php | LokiBot |
| URL | hxxps://oriana84[.]com/5a7h[.]js hxxps://oriana84[.]com/js[.]php hxxps://heavens-gate[.]top/o hxxps://ewar4pres[.]com/5j2s[.]js hxxps://ewar4pres[.]com/js[.]php hxxps://road-to-hell[.]top/o |
KongTuke |
| URL | hxxp://158[.]94[.]211[.]222/vidar/random[.]exe | Amadey |
| URL | hxxp://158[.]94[.]211[.]222/files/gop/random[.]exe hxxp://158[.]94[.]211[.]222/files/6608710704/1r6sQRc[.]exe hxxp://158[.]94[.]211[.]222/files/5900855435/eNLe4nm[.]exe hxxp://158[.]94[.]211[.]222/files/7453936223/5GFpJxh[.]exe hxxp://158[.]94[.]211[.]222/files/7290860719/OTcX1Qs[.]exe hxxp://158[.]94[.]211[.]222/files/7411337060/ZCGm9Ky[.]exe hxxps://103[.]27[.]157[.]144/api/download hxxps://keitarocheats[.]com/api/download hxxp://158[.]94[.]211[.]222/files/6961337700/4p8oGAO[.]exe hxxp://158[.]94[.]211[.]222/files/mr/random[.]exe hxxp://158[.]94[.]211[.]222/files/rdx/random[.]exe hxxp://app[.]enekora[.]com/app/download[.]php |
Vidar |
| URL | hxxp://158[.]94[.]211[.]222/files/7782139129/PKenO2z[.]exe hxxp://158[.]94[.]211[.]222/files/7044575709/ABbqsJz[.]exe hxxp://158[.]94[.]211[.]222/files/8437455245/ByDG8Kl[.]exe |
SalatStealer |
| URL | hxxp://tirechinecarpett[.]pw/api hxxp://musclefarelongea[.]pw/api hxxp://fanlumpactiras[.]pw/api hxxps://baraltransportes[.]com/20khgc26oiwefoibfuww[.]php hxxps://retiriu[.]cyou/api hxxp://curtainjors[.]fun/api hxxp://superyupp[.]fun/api hxxp://158[.]94[.]211[.]222/files/8261736065/6QBuVkN[.]exe |
Lumma Stealer |
| URL | hxxp://94[.]156[.]102[.]255/files/coolfile[.]exe hxxp://94[.]156[.]102[.]255/files/mswincryptographdata[.]exe hxxp://94[.]156[.]102[.]255/files/totallynotavirus[.]exe hxxp://216[.]126[.]239[.]100/bt/svchost[.]exe |
NjRAT |
| URL | hxxp://45[.]207[.]157[.]11/linux_arm7 hxxp://45[.]207[.]157[.]11/linux_arm64 hxxp://45[.]207[.]157[.]11/linux_amd64 |
Kaiji |
| URL | hxxp://45[.]66[.]228[.]176/linux_arm7 hxxp://45[.]66[.]228[.]176/linux_arm64 hxxp://80[.]97[.]124[.]196/arm4 hxxp://142[.]248[.]80[.]139/huhu/debug/debug[.]sh4 hxxp://152[.]89[.]170[.]85/bins/violetsh4 |
Bashlite |
| URL | hxxp://107[.]175[.]89[.]136/nuts/poop hxxp://80[.]97[.]124[.]196/run[.]sh hxxp://80[.]97[.]124[.]196/milan[.]sh hxxp://158[.]94[.]211[.]222/files/8546791173/H8eEFNo[.]exe hxxp://178[.]16[.]54[.]109/xmrget[.]exe |
Coinminer |
| URL | hxxps://api[.]telegram[.]org/bot8564778242:AAEwHvnRSHl3x0XbIisxAsWOVApKmbsncUI/sendMessage?chat_id=7584924098 hxxps://api[.]telegram[.]org/bot7961408037:AAFndSTOC6gJ9CfuvAhdbImFJU3tkAO-Whg/sendMessage?chat_id=8252112577 hxxps://api[.]telegram[.]org/bot8058628990:AAElUbK5-uf1fYsi1phs3WLENYoRKTGZmGc/sendMessage?chat_id=6885960134 hxxps://api[.]telegram[.]org/bot8281394643:AAE_hH7gywruYpu-1wjifzbqZ3dxXbMOCMQ/sendMessage?chat_id=6070021912 hxxps://api[.]telegram[.]org/bot8066502598:AAEBP18n47EyabMfCLnFinPAOucBrs7dTwc/sendMessage?chat_id=5761766565 hxxps://api[.]telegram[.]org/bot8537927662:AAFD5S2DCyfvufcRgzfr8OrWLVzG98ExYUA/sendMessage?chat_id=8579883216 hxxps://api[.]telegram[.]org/bot8584581191:AAGcTfRY8MafgD6JaaQV8UFtoyKzCeG0c1Y/sendMessage?chat_id=8579883216 hxxps://api[.]telegram[.]org/bot8576116522:AAE-0gcoyBXrDvPNXGfL6eRkmTOCqC7lsBw/sendMessage?chat_id=5766507567 hxxps://api[.]telegram[.]org/bot8270022972:AAFtLCac3cfNK6o9girbnQqLg9azHUMtf0s/sendMessage?chat_id=7584924098 hxxps://api[.]telegram[.]org/bot7977178969:AAFwjdCS6KcFH4t5FTJ9aBX6wlrUL1mZ3TQ/sendMessage?chat_id=7584924098 hxxps://api[.]telegram[.]org/bot7936760211:AAHxklowogJmfcK2Usq9Gnkw1YodcOblQlQ/sendMessage?chat_id=6341109890 hxxps://cocinanikkei[.]com[.]pe/img_085256[.]png hxxps://api[.]telegram[.]org/bot8507629023:AAGgX1jgQlRnvYObWU5CyhAZerx8rM6JacQ/sendMessage?chat_id=7790028979 hxxps://api[.]telegram[.]org/bot8786909228:AAExLiYSXnXtuiJE_y0Fj8Esekxs8l0EOUE/sendMessage?chat_id=5138702702 |
Snake Keylogger |
| URL | hxxps://api[.]telegram[.]org/bot8374256646:AAE1pqkgUv83UVO1lWGCCCWIzR9sVWmv4l4/sendMessage?chat_id=6805981916 hxxps://api[.]telegram[.]org/bot8713396250:AAF8dh398LQP54fPze51Pwt83ognY0SSM_o/sendMessage?chat_id=5639113726 hxxps://api[.]telegram[.]org/bot8424956530:AAEuHj0oNjsPhXKjTup7U3rrMTw56UsNOoE/sendMessage?chat_id=8107323670 hxxps://api[.]telegram[.]org/bot5095036073:AAEUdbdoQ_lgs7wZgrR-XxCyddDuY92GVFk/sendMessage?chat_id=1425503508 hxxps://api[.]telegram[.]org/bot8401696891:AAEYs7_Ah8jc_tbgn-dZ1WL-JuSZ8alyGb8/sendMessage?chat_id=2065242915 hxxps://api[.]telegram[.]org/bot8591798401:AAFCfu1v5L9pYXZieLzX1dnN3QxSElsRciE/sendMessage?chat_id=5530180817 hxxps://api[.]telegram[.]org/bot8327696630:AAE5WZWoMTFw_wD0LTOs7QxTzPg7WzzsIAs/sendMessage?chat_id=6283883842 hxxps://api[.]telegram[.]org/bot8252417845:AAEbHWp7gUk0_kNWITzr2N0ePoobqrn2AVY/sendMessage?chat_id=7536086895 |
Stealerium |
| URL | hxxps://api[.]telegram[.]org/bot8525394189:AAGn1t1KyQvgB24ZJALCdkPiRg-wFZgb9LA/ hxxps://api[.]telegram[.]org/bot8233248054:AAGU8Vsx9YauaDW1wDr-eip-4Mg_nrFtpiY/ hxxps://ameyiando[.]com/main/ENCRYPT[.]Ps1 hxxp://107[.]173[.]143[.]118/bgdol[.]png hxxps://casadoserralheirosaocarlos[.]com[.]br/ENCRYPTZ[.]Ps1 hxxp://107[.]173[.]143[.]118/actiok[.]png hxxp://107[.]173[.]143[.]118/mynnepeng[.]png hxxp://107[.]173[.]143[.]118/saxch[.]png hxxp://107[.]173[.]143[.]118/nderu[.]png hxxps://casadoserralheirosaocarlos[.]com[.]br/ENCRYPTS[.]Ps1 hxxp://39[.]106[.]81[.]175:5002/download/Syntex_Spoofer[.]exe hxxp://39[.]106[.]81[.]175:5002/download/Roblox_Executor[.]exe |
Agent Tesla |
| URL | hxxps://www[.]73bet[.]app/:4782 hxxps://www[.]73bet[.]app/:8848 hxxps://www[.]73bet[.]app/:443 hxxps://www[.]73bet[.]app/:7707 hxxps://www[.]73bet[.]app/:8808 hxxps://www[.]73bet[.]app/:8888 hxxps://www[.]73bet[.]app/:6606 hxxps://github[.]com/ademmartinez71-cmd/test/raw/refs/heads/main/XClient[.]exe hxxps://raw[.]githubusercontent[.]com/ademmartinez71-cmd/test/refs/heads/main/XClient[.]exe hxxps://fertas[.]com[.]tr/fish[.]txt hxxp://158[.]94[.]211[.]222/files/2070717540/IPvJTgG[.]bat hxxps://dl[.]dropboxusercontent[.]com/scl/fi/x97ra6bino9olbolx8ha8/optimized_MSI[.]png?rlkey=ek4gmta3ih6tg3kq3m9su1zsr&st=ao90xecu&dl=0?id=661120a4-f576-4e8f-bc6a-7b48650ac68c |
AsyncRAT |
| URL | hxxp://158[.]94[.]211[.]222/files/8733674968/jLZuxmu[.]exe | DarkVision RAT |
| URL | hxxp://158[.]94[.]211[.]222/files/8548282130/trP9KGI[.]exe hxxp://158[.]94[.]211[.]222/files/8548282130/trP9KGI[.]bat |
Quasar RAT |
| URL | hxxps://91[.]92[.]243[.]117/TaskSvc[.]vbs | CloudEyE |
| URL | hxxp://43[.]164[.]1[.]146:8082/login/index | Vshell |
| URL | hxxps://lvlenergy[.]pl/?u=ncilyoqjvutpmi5skblrf4a hxxps://lynx-new[.]mightrecoverymarketing[.]com/?u=etmbh5zutjelbfywikpqsvq hxxps://lxbrands[.]se/?u=2iklnysz37hzawp4khgr23y hxxps://lyssatee[.]com/?u=n3bdxmkppncau5brlqbigaa hxxps://morskirai[.]com/?u=dyprzu6hlmki5euacmy4qfq |
Emmenhtal |
| URL | hxxp://213[.]176[.]73[.]161/api/NTE3YjdjNWU1NjYzNjU2YTA1N2Y= hxxp://217[.]119[.]129[.]122/api/NTE3YjdjNWU1NjYzNjU2YTA1N2Y= |
SmartLoader |
| URL | hxxp://46[.]149[.]73[.]60/4SLEYpfAk57hGubo/wslservice[.]mp3 hxxp://46[.]149[.]73[.]60/4SLEYpfAk57hGubo/messagebus[.]pdf hxxp://46[.]149[.]73[.]60/4SLEYpfAk57hGubo/FNPLicensingService[.]php hxxps://acecareer[.]edu/wp-includes/certificates/acr-karimichikstrelyaet-639081475329349420[.]exe hxxp://185[.]242[.]3[.]239/kfhogts hxxp://185[.]242[.]3[.]239/oqqqqoa[.]mp3 hxxps://mgtms[.]cc/force/Win_Driver_SSL_support_v43[.]22[.]209[.]44[.]exe |
ACR Stealer |
| URL | hxxps://acecareer[.]edu/wp-includes/certificates/Qtum[.]exe hxxp://158[.]94[.]211[.]222/amka/random[.]exe hxxp://178[.]16[.]54[.]109/rem[.]exe |
SmokeLoader |
| URL | hxxp://96[.]44[.]159[.]145/25/c/img_221646[.]png hxxps://openlineseguros[.]com[.]br/onedrives/img_233123[.]png |
Remcos |
| URL | hxxp://158[.]94[.]211[.]222/files/7309295924/SpdWqa6[.]exe hxxp://158[.]94[.]211[.]222/files/1797567872/w6UBu3m[.]exe hxxps://openlineseguros[.]com[.]br/onedrives/img_131302[.]png hxxps://openlineseguros[.]com[.]br/onedrives/optimized_MSI[.]png hxxps://openlineseguros[.]com[.]br/onedrives/img_235532[.]png |
XWorm |
| URL | hxxp://178[.]16[.]54[.]109/twizt[.]exe | Phorpiex |
| URL | hxxps://github[.]com/adyvot/update/raw/refs/heads/main/0urkspr63xoryra2[.]exe hxxps://raw[.]githubusercontent[.]com/adyvot/update/refs/heads/main/0urkspr63xoryra2[.]exe |
NonEuclid RAT |
| URL | hxxp://158[.]94[.]211[.]222/files/8468794285/iBC1OE9[.]exe hxxp://158[.]94[.]211[.]222/files/8468794285/5vroDFE[.]exe hxxp://158[.]94[.]211[.]222/files/8468794285/sBC01fa[.]exe |
SantaStealer |
| URL | hxxps://216[.]126[.]236[.]17/Ezo0HJkTPWyaIZsj86znTAzDNBQB3JFjrh2qin0yZKkczcchQlrXoftNLL8Sw64H_NJ8Kmljo7qZ5PpDzK-QGxm4L7zmhr1DsEdR hxxp://35[.]231[.]116[.]180/payload[.]ps1 |
Metasploit |
| URL | hxxp://179[.]43[.]163[.]126/datalib/315y9t[.]cwbl hxxp://81[.]161[.]229[.]234/blob/eduw5y[.]24nr |
Rhadamanthys |
| URL | hxxps://github[.]com/Sof1st1s/Astralis-Client/releases/download/1[.]0[.]3/Astralis[.]exe hxxps://api[.]telegram[.]org/bot8663134019:AAHdrCn7SSoguECru3uvFdgSoU5nwvvga5Y/sendMessage?chat_id=7640752901 |
ToxicEye |
| URL | hxxps://fuckcartel[.]icu/download/gitlol | Epsilon Stealer |
| URL | hxxps://216[.]126[.]236[.]17/Ezo0HJkTPWyaIZsj86znTAzDNBQB3JFjrh2qin0yZKkczcchQlrXoftNLL8Sw64H_NJ8Kmljo7qZ5PpDzK-QGxm4L7zmhr1DsEdR/ | Meterpreter |
| URL | hxxp://78[.]153[.]140[.]16/kinsing hxxp://78[.]153[.]140[.]16/kinsing_aarch64 |
Kinsing |







