不正URLへのアクセス、不正メールの受信
-
メール受信した
弊社お客様0社 URLアクセスした
弊社お客様0社 -
2023/06/02
※2023/06/02 更新
マルウェア感染させると考えられるURLを検知(2023/06/02)
■IoC(※1)
Type: | IOC: | Signature: |
---|---|---|
URL | hxxp://107[.]175[.]113[.]199/350/hkcmd[.]exe hxxp://195[.]178[.]120[.]24/kxvxvzczxncloki[.]txt hxxp://103[.]133[.]104[.]112/98/hkcmd[.]exe hxxp://194[.]180[.]48[.]59/jokerzx[.]exe hxxp://103[.]133[.]104[.]112/rf/iotiotiotiotiot%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23iotiotiotiotiotiot[.]doc hxxp://171[.]22[.]30[.]164/joker/five/fre[.]php hxxp://103[.]14[.]224[.]41/48/hkcmd[.]exe hxxp://107[.]175[.]113[.]199/iii/iiiiiiiiiiiiiii%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23iiiiii[.]doc |
LokiBot |
URL | hxxps://stablewin32[.]app/download/AdobePhotoshop_pass1234[.]rar hxxps://stablewin32[.]app/download/BandicamScreenRecorder_pass1234[.]rar hxxp://77[.]91[.]68[.]62/DSC01491/fotocr06[.]exe hxxp://antispam-screen[.]com/fjgD555c3/index[.]php hxxp://213[.]226[.]123[.]14/jd93d22Cb1/index[.]php hxxp://179[.]43[.]154[.]148/fjgD555c3/index[.]php hxxp://soul-kissed[.]org/fjgD555c3/index[.]php hxxp://80[.]94[.]92[.]35/g9TTnd3bS/index[.]php hxxp://5[.]42[.]65[.]1/gj3C2sN30/Login[.]php hxxp://78[.]47[.]9[.]120/so57Nst/Login[.]php hxxp://77[.]91[.]68[.]62/wings/game/Login[.]php |
Amadey |
URL | hxxp://195[.]178[.]120[.]24/U2th5k1keGkDeMw[.]exe hxxp://192[.]227[.]183[.]138/130/hkcmd[.]exe hxxp://107[.]172[.]130[.]135/chu[.]exe hxxp://192[.]227[.]183[.]138/125/hkcmd[.]exe hxxp://185[.]246[.]222[.]101/ccs/vc[.]txt hxxp://195[.]178[.]120[.]24/ugxjgvxbbvxzjjj[.]txt hxxp://103[.]171[.]1[.]87/ede/ventascry[.]exe hxxp://87[.]121[.]221[.]18/10783____/smss[.]exe hxxp://194[.]180[.]48[.]59/agodzx[.]doc hxxp://45[.]88[.]66[.]43/bbvabbva[.]txt hxxp://194[.]180[.]48[.]59/agodzx[.]exe hxxp://185[.]246[.]222[.]101/ccs/pcz[.]txt hxxp://84[.]54[.]50[.]31/D/VLC[.]txt hxxp://84[.]54[.]50[.]31/D/fara[.]txt hxxp://195[.]178[.]120[.]24/jsdvZHVXnbzczvbZVC[.]txt hxxp://195[.]178[.]120[.]24/nxzjcbxzmvbxmbcvz[.]txt hxxp://194[.]180[.]48[.]59/obizx[.]doc |
Agent Tesla |
URL | hxxp://fdioshjfuiosdfhjsdio[.]tw-team[.]com/Fecurity[.]exe hxxp://fdioshjfuiosdfhjsdio[.]tw-team[.]com/javaw[.]exe |
RedLine Stealer |
URL | hxxp://198[.]46[.]132[.]184/vg/KcwLtdBjfYStiX253[.]bin hxxp://198[.]46[.]132[.]184/80/hkcmd[.]exe |
SmokeLoader |
URL | hxxp://103[.]171[.]1[.]87/ede/dd[.]exe hxxp://103[.]171[.]1[.]87/ede/wasx[.]exe |
Warzone RAT |
URL | hxxp://pcwizard[.]net/yz/mann/index[.]php hxxp://thenaturalflavorproject[.]com/cg/seema[.]exe |
Azorult |
URL | hxxps://www[.]dld[.]ae/zp/zp[.]txt hxxps://www[.]dld[.]ae/zp/eua[.]txt hxxps://www[.]dld[.]ae/zp/euk[.]txt hxxps://www[.]dld[.]ae/zp/euaa[.]txt hxxps://www[.]dld[.]ae/zp/as[.]txt hxxps://www[.]dld[.]ae/zp/mx[.]txt hxxps://www[.]dld[.]ae/zp/zk[.]txt hxxps://www[.]dld[.]ae/zp/zpeu[.]txt hxxps://www[.]dld[.]ae/zp/zp[.]exe hxxps://www[.]dld[.]ae/zp/zpeu[.]exe hxxp://103[.]167[.]90[.]55/99/hkcmd[.]exe hxxp://103[.]167[.]90[.]55/ui/uiuiuiuiuiuiuiuiuiuiuiu%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23uiuiuiuiuiuiuiu[.]doc hxxp://213[.]227[.]155[.]225/88/hkcmd[.]exe |
CloudEyE |
URL | hxxp://162[.]55[.]212[.]236/dbupdater[.]exe | SectopRAT |
URL | hxxp://5[.]252[.]21[.]12/bf7893cc2d43c936[.]php hxxp://88[.]119[.]168[.]142/Ouasas[.]exe hxxp://80[.]85[.]241[.]225/ef05b005854373ec[.]php hxxp://80[.]85[.]241[.]225/ef05b005854%0073ec[.]php |
Stealc |
URL | hxxps://eliteadsclocker[.]com/eroa/ hxxps://eliteadsclocker[.]com/em/ hxxps://altinvadi[.]net/ut/ hxxps://eliteadsclocker[.]com/eeti/ hxxps://nladfk[.]com/isue/ hxxps://sercitec[.]com/rmua/ hxxps://sercitec[.]com/dnue/ hxxps://zmqnbags[.]com/psao/ hxxps://dozajans[.]com/eio/ hxxps://afauto[.]it/ooi/ hxxps://afauto[.]it/etut/ hxxps://nladfk[.]com/teos/ hxxps://torahs2cents[.]com/ro/ hxxps://almoez[.]com/ia/ hxxps://kardeslerboncukhediyelik[.]com/nasd/ hxxps://kardeslerboncukhediyelik[.]com/esem/ hxxps://altinvadi[.]net/dero/ hxxps://kardeslerboncukhediyelik[.]com/au/ hxxps://kardeslerboncukhediyelik[.]com/daa/ hxxps://torahs2cents[.]com/vo/ hxxps://jayalakshmitravels[.]com/ites/ hxxps://247xtrade[.]com/um/ hxxps://aamalapp[.]com/ist/ hxxps://securesoftwaredesing[.]com/aa/ hxxps://torahs2cents[.]com/rr/ hxxps://tejuoshoshoppingcomplex[.]com/uodn/ hxxps://infigroupsindia[.]com/im/ hxxps://almoez[.]com/in/ hxxps://angelakelleyphotography[.]com/erur/ hxxps://exoticoo[.]com/csum/ hxxps://droyals[.]com/ct/ hxxps://securesoftwaredesing[.]com/ca/ hxxps://studio24mw[.]com/adie/ hxxps://modernurogyn[.]com/aif/ hxxps://treadlefish[.]net/eo/ hxxps://ufagold[.]com/li/ hxxps://angelakelleyphotography[.]com/etni/ hxxps://ufagold[.]com/usi/ hxxps://studio24mw[.]com/ml/ hxxps://almoez[.]com/qu/ hxxps://droyals[.]com/ume/ hxxps://modernurogyn[.]com/ads/ hxxps://expaceos[.]com/uao/ hxxps://nladfk[.]com/iu/ hxxps://next-vapors[.]com/stei/ hxxps://vitalsync[.]org/utr/ hxxps://torahs2cents[.]com/eai/ hxxps://247xtrade[.]com/et/ hxxps://infigroupsindia[.]com/rp/ hxxps://angelakelleyphotography[.]com/itma/ hxxps://securesoftwaredesing[.]com/uadq/ hxxps://binbakar[.]com/uv/ hxxps://vitalsync[.]org/nscf/ hxxps://angelakelleyphotography[.]com/aiua/ hxxps://shayksatay[.]com/uau/ hxxps://toplitoral[.]com/atsu/ hxxps://almoez[.]com/dme/ hxxps://almoez[.]com/nmcc/ hxxps://jayalakshmitravels[.]com/oeni/ hxxps://nladfk[.]com/sus/ hxxps://nladfk[.]com/ba/ hxxps://logistic-pro[.]net/mi/ hxxps://logistic-pro[.]net/tioi/ hxxps://nooranbeauty[.]com/se/ hxxps://tammisnaps[.]com/ede/ hxxps://shayksatay[.]com/moi/ hxxps://next-vapors[.]com/ad/ hxxps://treadlefish[.]net/losb/ hxxps://tiblej[.]com/mo/ hxxps://binbakar[.]com/tte/ hxxps://hm-international[.]com/li/ hxxps://linkajobs[.]com/na/ hxxps://nananobengkouakou[.]net/oo/ hxxps://agrominingtecnologia[.]net[.]br/uie/ hxxps://vitalsync[.]org/uci/ hxxps://vitalsync[.]org/sa/ hxxps://treadlefish[.]net/tu/ hxxps://eastindiaagro[.]com/ntu/ hxxps://jayalakshmitravels[.]com/iiiq/ hxxps://bajosombra[.]com/xt/ hxxps://nananobengkouakou[.]net/umt/ hxxps://eastindiaagro[.]com/pec/ hxxps://toplitoral[.]com/ti/ hxxps://tpksecuritygroup[.]com/niq/ hxxps://bajosombra[.]com/at/ hxxps://tammisnaps[.]com/ecuu/ hxxps://exoticoo[.]com/ela/ hxxps://exoticoo[.]com/riu/ hxxps://toplitoral[.]com/eten/ hxxps://toplitoral[.]com/as/ hxxps://exoticoo[.]com/cios/ hxxps://eastindiaagro[.]com/ol/ hxxps://modernurogyn[.]com/uiuq/ hxxp://162[.]252[.]175[.]130/p6F/B510 hxxp://162[.]252[.]175[.]227/w7wn/B510 hxxp://151[.]236[.]9[.]153/aHGTlct/B510 hxxps://leepebitz[.]com/eeb/ hxxps://vitalsync[.]org/usar/ hxxps://edumontonline[.]com/qt/ hxxps://sherwoodsproperty[.]com/sl/ hxxps://afiadv[.]org/xmeyuqpuid/xmeyuqpuid[.]zip hxxps://afiadv[.]org/xmeyuqpuid/rentfree1[.]zip hxxps://garokelka[.]com/r8jtup[.]msi hxxps://koriska[.]com/fy5jsi[.]msi hxxps://tofinka[.]com/m9bbkl[.]msi hxxps://lakirasa[.]com/7ygrkx[.]msi hxxps://retrenia[.]com/9oar6p[.]msi hxxps://gurakis[.]com/cw3mfy[.]msi hxxp://151[.]236[.]9[.]194/jaDPXzl/D715 hxxp://151[.]236[.]9[.]212/etSDN/D715 hxxp://151[.]236[.]14[.]91/05iEi/D715 hxxps://kemenpppa[.]go[.]id/ppdeqzaqjw/rentfree[.]zip hxxps://monicacruz[.]com[.]co/jhdnpqwzxr/rentfree[.]zip hxxps://solucionarimoveis[.]com[.]br/twqvsmjjms/rentfree[.]zip hxxps://desireautoservice[.]ae/jjpevrsmet/rentfree[.]zip hxxp://assurancebtp[.]net/jgjbaamvgg/rentfree[.]zip hxxps://yallanzakeronline[.]com/nthnhildnh/rentfree[.]zip hxxps://ritus[.]com[.]br/ltmunshgsp/rentfree[.]zip hxxps://artejoy[.]com/gdelawvxwq/rentfree[.]zip hxxps://royalbeirutkw[.]com/jnrjghovih/rentfree[.]zip hxxps://payondego[.]com/oalzmwupcx/rentfree[.]zip hxxps://ossuniao[.]com[.]br/awolznfmdr/rentfree[.]zip hxxps://wpbatch9[.]site/fyvhagbath/rentfree[.]zip hxxps://especialistadamente[.]com[.]br/nhvihlwtjd/rentfree[.]zip hxxps://homtex[.]in/ojrajwqxwc/rentfree[.]zip hxxps://agraartandcraft[.]com/wayqirsetv/rentfree[.]zip hxxps://shemis[.]co/jhgtfwtewo/rentfree[.]zip hxxps://tessacharpentier[.]com/cxczputnzi/rentfree[.]zip hxxps://al-munawara[.]com/ed/ hxxps://leepebitz[.]com/eao/ hxxps://peasx[.]com/bup/ hxxps://itacr[.]com/accn/ hxxps://sumeetgroup[.]com/liee/ hxxps://testsieger-online[.]com/os/ hxxps://newbeginningsshc[.]com/le/ hxxps://velstenapparel[.]com/ifoe/ hxxps://hecfexpo[.]com/tnne/ hxxps://ilnadir[.]com/ve/ hxxps://melaniegowen[.]com/ti/ hxxps://frey2[.]com/elvq/ hxxps://noor786110[.]com/ts/ hxxps://chinformatique-dz[.]com/lvle/ hxxps://tenants[.]com/aqbl/ hxxps://batsamco[.]com/lvot/ hxxps://gawahweekly[.]com/sese/ hxxps://cgscoaching[.]com/vedu/ hxxps://patmypets[.]com/qlsi/ hxxps://acutweb[.]com/nne/ hxxps://launchfxm[.]com/euit/ hxxps://quranforkids[.]com/cti/ hxxps://cutacut[.]com/iqaq/ hxxps://goromgorom[.]com/pt/ hxxps://vdtlte[.]com/pot/ hxxps://shilhaandara[.]com/cue/ hxxps://recrealtor[.]com/srnl/ hxxps://eagleuhd[.]com/ied/ hxxps://mszjapan[.]com/assu/ hxxps://exoticoo[.]com/urro/ hxxps://guillesa[.]com/tete/ hxxps://kandnsrecipecenter[.]com/dit/ hxxps://safrat-alriyadh[.]com/amm/ hxxps://tyrehouse[.]com/to/ hxxps://alnashe-trucks[.]com/rt/ hxxps://irembo[.]com/dlio/ hxxps://osttbrokeragellc[.]com/pmos/ hxxps://jbsacademy[.]com/et/ hxxps://nafeescables[.]com/uca/ hxxps://jacksonkatz[.]com/erso/ hxxps://ecotasar[.]com/amuo/ hxxps://wkkengineering[.]com/as/ hxxps://basenaija[.]com/ut/ hxxps://portmapp[.]com/uamn/ hxxps://fdviral[.]com/viie/ hxxps://ihubtalent[.]com/at/ hxxps://curemedicals[.]com/et/ hxxps://wiztecbd[.]com/po/ hxxps://allpinless[.]com/ihiu/ hxxps://sudaksha[.]com/uc/ hxxps://centralvalleylaw[.]com/dne/ hxxps://hurghadamuseum[.]com/iua/ hxxps://fahmy-group[.]com/iuu/ hxxps://modernprecast[.]com/ino/ hxxps://fatonmustafi[.]com/leul/ hxxps://reposebay[.]com/set/ hxxps://nidanhospital[.]com/olup/ hxxps://massive-electronics[.]com/emse/ hxxps://ejbreneman[.]com/nl/ hxxps://indianrobostore[.]com/no/ hxxps://daralhemaya[.]com/equ/ hxxps://bibianos[.]com/oes/ hxxps://samaafm[.]com/ises/ hxxps://vainavitechnologies[.]com/ae/ hxxps://ecceworldconference[.]in/izryjrhasj/rentfree[.]zip hxxps://desireautoservices[.]com/rthfshoblq/rentfree[.]zip hxxps://abrechadacasa[.]com[.]br/mxctojjoxa/rentfree[.]zip hxxps://biocretebags[.]com/swnmjiyylk/rentfree[.]zip hxxps://promoverte[.]net/mumkwxadec/rentfree[.]zip hxxps://trustmeemily[.]com/xedvpqhvdr/rentfree[.]zip hxxps://afiadv[.]org/xmeyuqpuid/rentfree[.]zip hxxps://bmkoin[.]ch/rsdadvvsvy/rentfree[.]zip hxxps://rosneft-armenia[.]am/kqmnijnipa/rentfree[.]zip hxxps://alhoja[.]info/jlvprqoyyh/rentfree[.]zip hxxp://realizemyproject[.]com/fzpxlhizxp/rentfree[.]zip hxxps://weboceantech[.]com/jbtadmrmko/rentfree[.]zip hxxps://sonictax[.]com[.]au/nhpybtfjnz/rentfree[.]zip hxxps://spandhana[.]co[.]in/drhxrpuicl/rentfree[.]zip hxxps://bmkoin[.]io/iuvgtrlpyv/rentfree[.]zip hxxps://skyline-solutions[.]net/nmxvncowyb/rentfree[.]zip hxxps://promolaser[.]com[.]mx/ptstwupoul/rentfree[.]zip hxxp://assurancetp[.]com/iebcqyhjfa/rentfree[.]zip hxxp://espacoflora[.]com[.]br/nvwnotxwhi/rentfree[.]zip hxxps://masol[.]fr/kqqhgrymhg/rentfree[.]zip |
QakBot |
URL | hxxp://45[.]143[.]223[.]208/x86_64 hxxp://45[.]143[.]223[.]208/m68k hxxp://45[.]143[.]223[.]208/i686 hxxp://45[.]143[.]223[.]208/arm6 hxxp://45[.]143[.]223[.]208/mips hxxp://45[.]143[.]223[.]208/sh4 hxxp://45[.]143[.]223[.]208/mips64 hxxp://45[.]143[.]223[.]208/arm7 hxxp://45[.]143[.]223[.]208/ppc hxxp://45[.]143[.]223[.]208/i486 hxxp://45[.]143[.]223[.]208/arm5 hxxp://45[.]143[.]223[.]208/arm |
Bashlite |
URL | hxxp://31[.]44[.]184[.]82/pixel[.]gif hxxp://112[.]124[.]64[.]37/match hxxps://aleagroupdevelopment[.]com/html[.]js hxxp://101[.]43[.]109[.]197:8090/jquery-3[.]3[.]1[.]min[.]js hxxps://103[.]44[.]246[.]104/pixel[.]gif hxxps://47[.]100[.]210[.]39/news/details hxxp://aleagroupdevelopment[.]com/ku[.]js hxxps://207[.]246[.]102[.]129/Forums[.]html hxxp://207[.]246[.]102[.]129/ee[.]html hxxps://67[.]198[.]232[.]217/pixel[.]gif hxxp://118[.]89[.]134[.]97/IE9CompatViewList[.]xml hxxps://111[.]230[.]98[.]119/api/getit hxxps://cf[.]wsxqaz[.]top:8443/jquery-3[.]3[.]1[.]min[.]js hxxp://31[.]44[.]184[.]82/visit[.]js hxxp://85[.]117[.]234[.]181:8096/load hxxp://195[.]211[.]98[.]91/change/money/Start hxxp://124[.]223[.]91[.]53/ca hxxps://www[.]ba1duu[.]icu:8000/en_US/all[.]js hxxps://app[.]dlmix[.]ourdvs[.]com/dist/css/bootstrap[.]min[.]css hxxp://47[.]100[.]210[.]39:8080/clemente/details hxxp://121[.]5[.]56[.]160:44444/dpixel hxxp://107[.]173[.]122[.]167:8008/ga[.]js hxxps://47[.]100[.]180[.]123:3004/IE9CompatViewList[.]xml hxxp://49[.]233[.]107[.]150:7524/dpixel hxxp://149[.]129[.]72[.]37:12580/__utm[.]gif hxxp://107[.]172[.]201[.]137:8086/ptj hxxp://114[.]55[.]59[.]125:8081/IE9CompatViewList[.]xml hxxps://149[.]129[.]72[.]37:18444/push hxxp://194[.]55[.]224[.]169/match hxxp://119[.]45[.]197[.]68:8089/ptj hxxp://121[.]41[.]101[.]90:12280/visit[.]js hxxps://js[.]msedgeupdate[.]com/__utm[.]gif hxxp://152[.]32[.]129[.]157:85/__utm[.]gif hxxp://43[.]143[.]203[.]110/fwlink hxxps://43[.]138[.]30[.]109:7777/ga[.]js hxxp://124[.]221[.]127[.]90/updates[.]rss hxxps://116[.]204[.]114[.]153/activity hxxps://121[.]41[.]101[.]90/visit[.]js hxxp://39[.]98[.]184[.]70:8080/pixel hxxp://111[.]230[.]52[.]21:8000/ptj hxxp://59[.]110[.]221[.]242/ca hxxp://150[.]158[.]13[.]117:9000/wp08/wp-includes/dtcla[.]php hxxp://80[.]143[.]33[.]5:2222/ga[.]js hxxps://209[.]141[.]39[.]46:1443/fwlink hxxp://54[.]204[.]197[.]16/ca hxxps://43[.]140[.]247[.]133/aaaaaaaaa hxxp://39[.]101[.]70[.]33/ga[.]js hxxp://114[.]132[.]67[.]32:8850/updates[.]rss hxxp://116[.]62[.]188[.]205:801/j[.]ad hxxp://tongwl[.]top:8080/pixel hxxps://78[.]128[.]112[.]201/visit[.]js hxxps://163[.]172[.]214[.]172/ga[.]js hxxp://116[.]62[.]188[.]205:6666/visit[.]js hxxps://110[.]40[.]156[.]244:444/updates[.]rss hxxp://43[.]143[.]243[.]15:1080/g[.]pixel hxxp://101[.]42[.]254[.]219:5656/api/x hxxp://43[.]142[.]74[.]120:9090/ptj hxxp://123[.]207[.]68[.]150/match hxxp://202[.]79[.]169[.]52:8000/Complete/Option/IJROHEEXEK hxxps://46[.]29[.]165[.]123/visit[.]js hxxp://1[.]116[.]144[.]253/updates[.]rss hxxp://175[.]178[.]41[.]181/ca hxxps://121[.]4[.]154[.]20/cx hxxps://47[.]115[.]215[.]203/en_US/all[.]js hxxp://45[.]63[.]53[.]9:4444/cm hxxp://yestcoin[.]com:4444/visit[.]js hxxp://121[.]4[.]154[.]20/IE9CompatViewList[.]xml hxxp://91[.]213[.]50[.]110/pixel[.]gif hxxp://67[.]198[.]232[.]217/pixel[.]gif hxxp://cs[.]server[.]bike/dot[.]gif hxxp://154[.]204[.]59[.]208/pixel[.]gif hxxps://121[.]40[.]127[.]134:8090/updates[.]rss hxxps://1[.]14[.]70[.]97:8899/cx |
Cobalt Strike |
URL | hxxp://195[.]211[.]98[.]91/map/v8[.]80/JavaScript | Metasploit |
URL | hxxp://84[.]54[.]50[.]31/D/NEV[.]exe hxxp://109[.]206[.]240[.]64/HKL[.]vbs hxxp://45[.]66[.]230[.]127/32/hkcmd[.]exe hxxp://45[.]66[.]230[.]127/iii/iiiiiiiiiiiiiiiiiiiiiiii%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23iiiiiiiiiiiiiiiiiiiiii[.]doc |
Remcos |
URL | hxxps://polushka[.]net/1/77[.]exe | Laplas |
URL | hxxps://mapla[.]com[.]mx/uploads/index[.]php | NetSupportManager RAT |
URL | hxxp://84[.]54[.]50[.]31/D/ga[.]exe hxxp://84[.]54[.]50[.]31/D/Nano[.]exe |
zgRAT |
URL | hxxp://91[.]107[.]229[.]39:8999/aN7jD0qO6kT5bK5bQ4eR8fE1xP7hL2vK/mozglue[.]dll hxxp://91[.]107[.]229[.]39:8999/aN7jD0qO6kT5bK5bQ4eR8fE1xP7hL2vK/nss3[.]dll hxxp://91[.]107[.]229[.]39:8999/aN7jD0qO6kT5bK5bQ4eR8fE1xP7hL2vK/softokn3[.]dll hxxp://91[.]107[.]229[.]39:8999/aN7jD0qO6kT5bK5bQ4eR8fE1xP7hL2vK/freebl3[.]dll hxxp://91[.]107[.]229[.]39:8999/aN7jD0qO6kT5bK5bQ4eR8fE1xP7hL2vK/vcruntime140[.]dll hxxp://91[.]107[.]229[.]39:8999/aN7jD0qO6kT5bK5bQ4eR8fE1xP7hL2vK/msvcp140[.]dll hxxp://91[.]107[.]229[.]39:8999/aN7jD0qO6kT5bK5bQ4eR8fE1xP7hL2vK/sqlite3[.]dll |
RecordBreaker |
URL | hxxp://91[.]107[.]210[.]207/b66ssc[.]dotm hxxp://91[.]107[.]210[.]207/tinytask[.]exe |
LockBit |
URL | hxxp://84[.]54[.]50[.]31/D/R[.]exe hxxp://84[.]54[.]50[.]31/D/D[.]exe |
Formbook |
URL | hxxp://84[.]54[.]50[.]31/D/ar[.]exe hxxp://84[.]54[.]50[.]31/D/ARR[.]exe |
Snake Keylogger |
URL | hxxp://208[.]67[.]107[.]146/Xvhwgnaxcaj[.]png | PureCrypter |
URL | hxxp://folkmusicstreams[.]com/TIME/mac[.]php | Bitter RAT |