不正URLへのアクセス、不正メールの受信
-
メール受信した
弊社お客様0社 URLアクセスした
弊社お客様5社 -
2023/10/06
※2023/10/06 更新
マルウェア感染させると考えられるURLを検知(2023/10/06)
■IoC(※1)
Type: | IOC: | Signature: |
---|---|---|
URL | hxxp://171[.]22[.]28[.]213/222[.]exe hxxp://77[.]91[.]68[.]52/fuza/rus[.]exe hxxp://45[.]129[.]14[.]83/r[.]exe hxxp://queens-hvac-service[.]com/start/vlc[.]exe |
RedLine Stealer |
URL | hxxp://192[.]3[.]95[.]205/500/audiogse[.]exe hxxp://192[.]3[.]95[.]205/550/audiogse[.]exe |
Formbook |
URL | hxxps://surplz[.]com/adre/ hxxps://aipccoaching[.]com/nide/ hxxps://madekingrealties[.]com/ut/ hxxps://idsaperu[.]com/ist/ hxxps://ibig[.]co[.]il/uo/?79497121 hxxps://yellowstone[.]com[.]mm/rahu/?35697121 hxxps://nasa2000[.]com[.]mx/uaa/?48597121 hxxps://normacsales[.]com/eal/?70397121 hxxp://23[.]184[.]48[.]119/tvnc/?57697121%2F/ hxxps://aquatickidsglobalschool[.]com/ie/ hxxps://patrialand[.]com/ii/ hxxps://founders[.]net[.]au/uu/ hxxp://23[.]184[.]48[.]119/tvnc/ hxxps://idsaperu[.]com/ist/?70497121 hxxps://yellowstone[.]com[.]mm/rahu/?37497121 hxxp://23[.]184[.]48[.]119/tvnc/?86597121 hxxp://23[.]184[.]48[.]119/tvnc/?11697121 hxxps://aquatickidsglobalschool[.]com/ie/?81297121 hxxps://mtosmarketingagency[.]com/iu/?19197121 hxxps://idsaperu[.]com/ist/?23297121 hxxps://ifcconstructions[.]com/eose/?63297121 hxxps://mtosmarketingagency[.]com/iu/?88497121 hxxps://hudaibiahcollege[.]com/eaup/?1 hxxps://teachenglishonline[.]org/eaom/?1 hxxps://mobilefixer[.]in/rat/?1 hxxps://norcantec[.]com[.]ar/umn/?1 hxxps://wolsale[.]com/ea/?1 hxxps://medicionacustica[.]cl/eio/?1 hxxps://handygifts[.]in/oiuo/?1 hxxps://angelesescobar[.]cl/uure/?1 hxxps://allazeez[.]in/ue/?1 hxxps://dbtowing[.]ca/ir/?1 hxxps://hyperwall[.]ir/tedi/?1 hxxps://shreekalastudioz[.]com/est/?1 hxxps://englishnet[.]com[.]mx/qe/?1 hxxps://thecatalyzersevents[.]ae/aq/?1 hxxps://myprojectssydney[.]com[.]au/iest/?1 hxxps://technopark[.]com[.]pk/ma/?1 hxxps://motherteresacharitablesociety[.]com/sati/?1 hxxps://olympicscientific[.]ca/ee/?1 hxxps://homeimprovementskills[.]us/ttli/?1 hxxps://learnstuffs[.]com/eoun/?1 hxxps://rshm[.]co[.]in/eaii/?1 hxxps://factorycounter[.]com/nuur/?1 hxxps://fa[.]sah[.]com[.]pk/sa/?1 hxxps://loganwritersfestival[.]com[.]au/umco/?1 hxxps://healthads[.]shop/qtec/?1 hxxps://trysupplements[.]online/rr/?1 hxxps://urhobodaily[.]com/oue/?1 hxxps://websfy[.]com/sa/?1 hxxps://zpsc[.]edu[.]bd/ieto/?1 hxxps://hermanaluzangelica[.]com/qe/?1 hxxps://laboratorygulfinchemicalsolutions[.]com/ets/?1 hxxps://vertical-gardener[.]com/cqlu/?1 hxxps://ezeuba[.]me/tvai/?1 hxxps://realsportscast24[.]co[.]uk/rsis/?1 hxxps://jobvortex[.]com/si/?1 hxxps://packline[.]org/eoor/?1 hxxps://easy1pay[.]org[.]in/sqaa/?1 hxxps://krishnajwellery[.]com/reti/?1 hxxps://beautyforwellness[.]com/ti/?1 hxxps://queenbbridals[.]ng/rt/?1 hxxps://essams[.]com/au/?1 hxxps://dealsfordell[.]com/leou/?1 hxxps://salaammaharashtra[.]in/mqu/?1 hxxps://realtynoida[.]com/un/?1 hxxps://4am[.]health/ate/?1 hxxps://pakistanroof[.]com/ps/?1 hxxps://knockknock[.]com[.]mt/lo/?1 hxxps://homeblossomdecor[.]com/iu/?1 hxxps://pseventer[.]com/di/?1 hxxps://creativekiwi[.]lk/iiat/?1 hxxps://abhijayaspices[.]com/eadp/?1 hxxps://outdooremarati[.]com/roe/?1 hxxps://futurefoodfarms[.]com[.]ng/gmss/?1 hxxps://matrix-egy[.]net/uior/?1 hxxps://brindiz[.]com/eu/?1 hxxps://servicecustomercare[.]com/seip/?1 hxxps://aquatickidsglobalschool[.]com/et/?1 hxxps://nexspace[.]co[.]th/uii/?1 hxxps://kimandclak-ltd[.]com/lam/?1 hxxps://garimaenterprises[.]co[.]in/se/?1 hxxps://easyfitautoglass[.]co[.]za/iqat/?1 hxxps://masterschoolkandana[.]site/sort/?1 hxxps://lionaiassistant[.]com/vde/?1 hxxps://rhpsupplychain[.]com/sl/?1 hxxps://buyproductnow[.]online/dol/?1 hxxps://wedoit[.]global/arp/?1 hxxps://cheaptravelservice[.]us/is/?1 hxxps://rawdah-mlhm[.]com/iin/?1 hxxps://modivaluxury[.]com/et/?1 hxxps://jankiinternational[.]in/deit/?1 hxxps://hooverrepairservicecenterauthorized[.]com/mrrs/?1 hxxps://stjohnsdamoh[.]co[.]in/er/?1 hxxps://portleon[.]com/uh/?1 hxxps://getinnerwears[.]com/un/?1 hxxps://scholarshiplug[.]com/uun/?1 hxxps://flatfeecorp[.]co/or/?1 hxxps://application-form[.]ca/ts/?1 hxxps://quicknet[.]co[.]in/nsm/?1 hxxps://copainbar[.]com/ted/?1 hxxps://norvik[.]ug/gteu/?1 hxxps://ventanillaunicapalermo[.]com[.]co/co/?1 hxxps://rodeate[.]com/uee/?1 hxxps://ibda3-code[.]me/lrpa/?1 hxxps://fundaciongrillos[.]org/utm/?1 hxxps://cinecreativofilmschool[.]com/issn/?1 hxxps://mcbsistemas[.]com[.]br/al/?1 hxxps://healosure[.]com/nii/?1 hxxps://taxicentral[.]ir/qll/?1 hxxps://portalmar[.]com[.]br/na/?1 hxxps://qastoman[.]com/du/?1 hxxps://plugpicks[.]com/acum/?1 hxxps://webdesigninhull[.]co[.]uk/tei/?1 hxxps://levarrise[.]com/rl/?1 hxxps://icg-egy[.]net/det/?1 hxxps://harrisairaviation[.]com/si/?1 hxxps://kimcamacademy[.]net/doo/?1 hxxps://wizzardz-solutions[.]com/ar/?1 hxxps://aviorify[.]com/ie/?1 hxxps://buyshyhub[.]com/tu/?1 hxxps://teravonsolar[.]com/is/?1 hxxps://digicry[.]com/ul/?1 hxxps://tennislifemag[.]com/dim/?1 hxxps://hostyfly[.]com/qtie/?1 hxxps://lovereignshf[.]com/ua/?1 hxxps://sallybdran[.]co[.]il/uem/?1 hxxps://amshesp[.]com/rooe/?1 hxxps://lavaliosa[.]com[.]mx/di/?1 hxxps://funsaef[.]org/ips/?1 hxxps://freguesiadabeleza[.]com[.]br/auf/?1 hxxps://vbnexcod[.]co[.]in/ri/?1 hxxps://brilliant-solutions[.]ae/it/?1 hxxps://uniquemanufacture[.]co[.]in/eo/?1 hxxps://onlineearnway[.]com/oa/?1 hxxps://chiroqueabogados[.]pe/nd/?1 hxxps://hypothequeswestisland[.]ca/aim/?1 hxxps://aakashfertilitycentre[.]in/qsp/?1 hxxps://skillerszone[.]com/eexe/?1 hxxps://newspaperman[.]in/arp/?1 hxxps://pipedrive-experts[.]ca/lnro/?1 hxxps://twingalleria[.]com/ec/?1 hxxps://hypnotherapytrainingcollege[.]com[.]au/en/?1 hxxps://bellepreviews[.]com/tute/?1 hxxps://gfs-ae[.]com/sd/?1 hxxps://campfuckyeah[.]com/us/?1 hxxps://promediol[.]com/it/?1 hxxps://conceptloop[.]net/rdm/?1 hxxps://insanmadanijambi[.]org/ispe/?1 hxxps://olimartesser[.]com[.]br/iuts/?1 hxxps://chetanaenterprises-nx[.]com/tide/?1 hxxps://med-care[.]co/qoiu/?1 hxxps://hypotheques438[.]ca/mue/?1 hxxps://expressioncomp[.]com/tete/?1 hxxps://i-techsolutions[.]co[.]ke/amr/?1 hxxps://needzsolutions[.]com/oeiu/?1 hxxps://fouredgefm[.]com/iemt/?1 hxxps://jobhunt88[.]com/ad/?1 hxxps://bamboom[.]com[.]co/eq/?1 hxxps://moucecore[.]org/unsn/?1 hxxps://adz[.]biz[.]id/rt/?1 hxxps://supremeelevator[.]com/msti/?1 hxxps://medrexmedicaltrding[.]tw/taub/?1 hxxps://saurcool[.]com/nt/?1 hxxps://demandehypothecaire[.]ca/uq/?1 hxxps://eloagro[.]agr[.]br/aeep/?1 hxxps://gazisupershop[.]com/ae/?1 hxxps://perfect-itsolutions[.]com/pm/?1 hxxps://samittechnorubber[.]in/ax/?1 hxxps://metalfiber[.]com[.]pe/put/?1 hxxps://kabirulaqib[.]com/nam/?1 hxxps://igmvs[.]com/duqo/?1 hxxps://facturial[.]es/equ/?1 hxxps://jekinformatica[.]com[.]br/pi/?1 hxxps://pittsburghbizpage[.]com/ut/?1 hxxps://dollar2023[.]com/esd/?1 hxxps://nbsdevelopments[.]com/na/?1 hxxps://organicfoodslahore[.]com/tsa/?1 hxxps://benaamedia[.]com/siui/?1 hxxps://disneyworldvacationhouse[.]com/omr/?1 hxxps://surplz[.]com/ue/?1 hxxps://lembang[.]net/eia/?1 hxxps://metastockinv[.]com/afg/?1 hxxps://my-lynk[.]com/niu/?1 hxxps://excelliaschool[.]edu[.]in/ior/?1 hxxps://pythoncodesnippets[.]com/uee/?1 hxxps://qbhhospitality[.]com/deu/?1 hxxps://desarrollosprogramas[.]com/ttsa/?1 hxxps://nipoafricaeng[.]co[.]tz/oii/?1 hxxps://tsmedia[.]id/atso/?1 hxxps://cuneiformtest[.]com/eit/?1 hxxps://kevinpharmachem[.]com/su/?1 hxxps://pehspl[.]co[.]in/td/?1 hxxps://connectww[.]net/eiut/?1 hxxps://creatixacademy[.]com/ueot/?1 hxxps://desertandbloom[.]com/uq/?1 hxxps://priceclub[.]online/ln/?1 hxxps://shankarmaharaj[.]com/num/?1 hxxps://kejriwalyojana[.]com/qoua/?1 hxxps://digitalsafecertificadora[.]com[.]br/eeta/?1 hxxps://drmurtazashomoeopathy[.]in/bman/?1 hxxps://kipor[.]ae/osrq/?1 hxxps://sppflash[.]com[.]ar/utsv/?1 hxxps://rkindustriesguj[.]com/doo/?1 hxxps://olajideabiola[.]com/au/?1 hxxps://tyresonlinestore[.]com/em/?1 hxxps://hotshortlet[.]com/iosm/?1 hxxps://nowapsiindia[.]com/eoas/?1 hxxps://6shoequarterhorses[.]com/tu/?1 hxxps://antarperu[.]com[.]pe/uqe/?1 hxxps://culturadireitoesociedade[.]com[.]br/ts/?1 hxxps://ora-dental[.]com/eni/?1 hxxps://arosalmasayif[.]com/rc/?1 hxxps://topdailystory[.]com/ste/?1 hxxps://inefa[.]cl/aq/?1 hxxps://radhagobindrefrigeration[.]com/is/?1 hxxps://agriformexico[.]com/fc/?1 hxxps://europe-garage-automobile[.]com/atu/?1 hxxps://pusadurbanbank[.]com/id/?1 hxxps://constitutionalsanctuarycity[.]org/eit/?1 hxxps://themarijuanashow[.]com/iu/?1 hxxps://airtaceuropa[.]com/trqa/?1 hxxps://ko2labs[.]com/isa/?1 hxxps://demande-hypothecaire[.]ca/lei/?1 hxxps://rxmedicos[.]in/thc/?1 hxxps://ircuniversity[.]org/ele/?1 hxxps://tingolazodeportes[.]com/re/?1 hxxps://want2beme[.]com/acm/?1 hxxps://mortgage-application-form[.]com/bem/?1 hxxps://rapidskinandhairclinic[.]com/iaol/?1 hxxps://ashwithaatech[.]com/io/?1 hxxps://khalimoff[.]com/std/?1 hxxps://astroheenasharma[.]in/efmr/?1 hxxps://mweimall[.]co[.]ke/cu/?1 hxxps://pineheightsystems[.]com[.]ng/ei/?1 hxxps://rup-tot[.]com/da/?1 hxxps://generalplans[.]us/uqm/?1 hxxps://grupotrespro[.]com/uv/?1 hxxps://casadebill[.]org/it/?1 hxxps://assuredservice[.]co[.]in/ln/?1 hxxps://misryoum[.]com/eere/?1 hxxps://tedsbrain[.]com/oila/?1 hxxps://mdmonirul[.]com/uuqn/?1 hxxps://geetabeautyhub[.]in/pt/?1 hxxps://celebtribune[.]com/odm/?1 hxxps://shalife[.]in/luoi/?1 hxxps://mushiwushi[.]com/tlu/?1 hxxps://megatrustinc[.]com/mau/?1 hxxps://lashesbylittlesecret[.]com/uac/?1 hxxps://standartbud[.]net/turo/?1 hxxps://mostlynonsensical[.]com/rb/?1 hxxps://kernel-ec[.]com/oore/?1 hxxps://glasslineoriental[.]com/oan/?1 hxxps://maxcelulares[.]com[.]br/ie/?1 hxxps://torkleader[.]com/nmll/?1 hxxps://akpoazaagroup[.]com/qnr/?1 hxxps://lynearwealth[.]com/to/?1 hxxps://liegefelicio[.]com[.]br/qgl/?1 hxxps://spertual[.]site/umd/?1 hxxps://plantscares[.]in/tua/?1 hxxps://besttoptenpro[.]com/uspt/?1 hxxps://casagilapizaco[.]mx/it/?1 hxxps://taxitransferskeri[.]com/rit/?1 hxxps://clinicametropolitana[.]com[.]co/tnno/?1 hxxps://southwestairtrip[.]com/tnsi/ hxxps://mtosmarketingagency[.]com/iu/ hxxps://founders[.]net[.]au/uu/?70597121 hxxps://yellowstone[.]com[.]mm/rahu/?37197121 |
DarkGate |
URL | hxxp://172[.]86[.]76[.]208/zh2/sm/OIUIII0IUII0Ioioioi0ioi0iouuuiii0i0oiooioi0oioIOOI0I0IOO0OIO000%23%23%23%23%23%23%23%23%23%23%23%23%23%23000000000000000000%23%23%23%23%23%23%23%23%23%23%23%23%23%23000000[.]doc hxxps://cdn[.]discordapp[.]com/attachments/1151682677464903743/1158912269288218704/testtw[.]exe hxxp://94[.]156[.]253[.]128/2144/HTMLcontent[.]vbs hxxp://103[.]182[.]16[.]23/900/UGFH[.]txt hxxp://94[.]156[.]253[.]128/2144/io0Ioi0IOIOOIOi0i00ioioii0ioi0oiOII0OIO0OIOI0I0000%23%23%23%23%23%23%23%23%23%23%23%23%23%230000000%23%23%23%23%23%23%23%23%23%23%23%23%23%2300000000[.]doc hxxp://94[.]156[.]253[.]128/2144/UHO[.]txt hxxp://103[.]182[.]16[.]23/900/i0ioi0iooioo0IOI0OIOIOiooioi00IOIoioioio0ioi0iOIOioiiOIoiOIOIOioIO0IOIO0[.]doc hxxp://103[.]182[.]16[.]23/900/HTMLcode[.]vbs hxxps://discordapp[.]com/api/webhooks/1150611970358255616/TcoC3JrTki0Xd-EXOGznvPK0OsuJm9IeeUEQvrN7JXow_2oGDOWPWLU8gGbdLwevrDns hxxp://192[.]3[.]95[.]131/250/HTML[.]exe hxxp://185[.]225[.]74[.]45/goynimba[.]vbs hxxp://79[.]110[.]48[.]52/okl[.]vbs hxxp://85[.]31[.]45[.]8/legend[.]exe hxxps://api[.]telegram[.]org/bot6547287693:AAGGgrnDvtLiSnFJxDycaluud9osnQGIN1E/ hxxp://193[.]42[.]33[.]63/castororiginbase64[.]txt hxxp://193[.]42[.]33[.]63/castrrrrrrrrrrrrrrrFile[.]vbs hxxp://192[.]3[.]101[.]8/270/audiodg[.]exe hxxp://192[.]3[.]101[.]8/WSS/i0iioi0IOIOi0ioiioi0ioI0IOI0I9OII0IOIOI0IOIOI0IOIOIOI000%23%23%23%23%23%23%23%23%23%23%23%23%23%23000000000000000000%23%23%23%23%23%23%23%23%23%23%23%23%23%230000000000[.]doc |
Agent Tesla |
URL | hxxps://amazonascash[.]com/cdn-js/minlen[.]php hxxps://amazonascash[.]com/cdn/qzwewmrqqgqnaww[.]php hxxp://profille-cex-io[.]com/111[.]php hxxps://boiibzqmk12j[.]com/ZgbN19Mx hxxps://boiibzqmk12j[.]com/lander/chrome_1695206714/_index[.]php hxxps://boiibzqmk12j[.]com/vvmd54/ |
FAKEUPDATES |
URL | hxxp://171[.]22[.]28[.]220:8081/login hxxps://mediaskollsoft[.]com/login |
RisePro |
URL | hxxp://116[.]202[.]7[.]149:27015/archieve[.]zip hxxp://78[.]47[.]27[.]247/archieve[.]zip |
Vidar |
URL | hxxp://81[.]161[.]229[.]10/uiGnZWV151[.]bin hxxp://74[.]84[.]150[.]168/tnkOsz198[.]bin hxxp://74[.]84[.]150[.]168/oMruCoV111[.]bin hxxp://74[.]84[.]150[.]168/ZBIixROS197[.]bin |
CloudEyE |
URL | hxxps://cdn1[.]frocdn[.]ch/5gyoVmvWF1aEZTZ[.]exe | Coinminer |
URL | hxxps://www[.]transportesevaristomadero[.]com/cfpcontent/fdbsndbgrjsdfnldnsgbsldfbjbsvhtbbwljbglwtgwrjrytdhsr/server1[.]exe hxxps://github[.]com/TwistyMeat/ee/raw/main/EpPDrE[.]exe |
AsyncRAT |
URL | hxxps://sempersim[.]su/a12/fre[.]php hxxp://185[.]216[.]71[.]207/_errorpages/china/five/fre[.]php hxxp://66[.]228[.]35[.]206/perfect/dorime[.]exe hxxp://103[.]30[.]10[.]177/330/audiodg[.]exe hxxp://103[.]30[.]10[.]177/320/audiodg[.]exe hxxp://45[.]77[.]76[.]224/~clinics/?check hxxps://sempersim[.]su/a16/fre[.]php hxxp://185[.]216[.]71[.]207/_errorpages/official/five/fre[.]php |
LokiBot |
URL | hxxp://172[.]86[.]76[.]208/11223/i0i0ii0i0I0OII0OI0OI00I0Iioi0io0oi0ioi000000%23%23%23%23%23%23%23%23%23%23%23%23%23%230000000000%23%23%23%23%23%23%23%23%23%23%23%23%23%2300000000[.]doc | Remcos |
URL | hxxp://77[.]91[.]68[.]52/fuza/foto3553[.]exe | Amadey |
URL | hxxps://cdn[.]discordapp[.]com/attachments/1151682677464903743/1159251797123272806/Checkes[.]exe | Warzone RAT |
URL | hxxp://specnaznachenie[.]ru/download/mstsc[.]exe hxxp://sakentoshi[.]ru/download/mstsc[.]exe |
SmokeLoader |
URL | hxxps://34[.]124[.]197[.]156:8443/activity hxxp://92[.]63[.]196[.]46:8092/dot[.]gif hxxp://45[.]207[.]27[.]79:8080/pixel[.]gif hxxp://120[.]26[.]74[.]112/dpixel hxxp://118[.]24[.]128[.]43/load |
Cobalt Strike |
URL | hxxps://gazisupershop[.]com/autquia/i[.]exe hxxp://sentrex219[.]xyz/777/skxeYqr[.]exe |
SystemBC |
URL | hxxps://superrrdental[.]com/H6F/dshjdsjkkd hxxps://oloplentex[.]com/3uqck/UEdedsd3 hxxps://orthodentrics[.]com/8GE/44dsdsf32342 hxxps://provfin[.]com[.]au/ea/?1 hxxps://yourponno[.]com/iev/?1 hxxps://kaprat[.]com/nte/?1 hxxps://komarna[.]biz/ud/?1 hxxps://alalifperfume[.]com/ui/?1 hxxps://ctisupplies[.]co[.]ke/ov/?1 hxxps://texasnewusa[.]com/lta/?1 hxxps://maullinspa[.]cl/ut/?1 hxxps://alfa-omega-pty[.]com/as/?1 hxxps://updatetechbd[.]com/lsc/?1 hxxps://dol[.]sah[.]com[.]pk/tue/?1 hxxps://acitcollege[.]com/ihle/?1 hxxps://theconsulting[.]io/iidt/?1 hxxps://walkinmyshoes[.]org[.]au/btnt/?1 hxxps://kcims[.]org/ua/?1 hxxps://petholickw[.]com/lm/?1 hxxps://nahitahukuk[.]com/qaq/?1 hxxps://alikhan[.]com[.]pk/puia/?1 hxxps://celestialthaispa[.]com/pt/?1 hxxps://kundagal[.]af/iosc/?1 hxxps://touchenexus[.]com/se/?1 hxxps://akla[.]com[.]pk/oua/?1 hxxps://yrspc-app[.]net/esxe/?1 hxxps://sunagbsc[.]org/at/?1 hxxps://stonedigitalcenter[.]co[.]tz/otis/?1 hxxps://aonenetwork[.]com[.]np/siqe/?1 hxxps://homeproservices[.]org/oe/?1 hxxps://rareflock[.]com/toea/?1 hxxps://portonesautomaticosbolivia[.]com/am/?1 hxxps://rodriyt[.]com/qi/?1 hxxps://nata2023[.]in/mmq/?1 hxxps://brandpacker[.]net/oel/?1 hxxps://vsjinfotech[.]com/dcis/?1 hxxps://advipickles[.]com/ate/?1 hxxps://mafuliyadevimm[.]in/neis/?1 hxxps://shopnovinplus[.]com/uon/?1 hxxps://techeverywhere[.]space/us/?1 hxxps://forextradings[.]net/vt/?1 hxxps://pktrakia[.]com/imu/?1 hxxps://battlegroundmobileindia[.]link/er/?1 hxxps://mukundmotors[.]com/dlr/?1 hxxps://adast-alfn[.]com/suai/?1 hxxps://electroblitz[.]ro/uql/?1 hxxps://aryanmediasolutions[.]com/rl/?1 hxxps://alphamgt[.]com[.]ng/solr/?1 hxxps://gallinairan[.]com/snlu/?1 hxxps://crudeoilinvestment[.]online/outt/?1 hxxps://smartjayasolution[.]com/tl/?1 hxxps://simplyvisit[.]co[.]uk/tpae/?1 hxxps://ezejiamatufoundation[.]com/etr/?1 hxxps://metasailor[.]co/pas/?1 hxxps://thestandpoint[.]ca/catm/?1 hxxps://teakwd[.]com/euta/?1 hxxps://wyseden[.]com/squu/?1 hxxps://percastillo[.]pe/tge/?1 hxxps://kriasoftux[.]com/le/?1 hxxps://itscnf[.]com/rs/?1 hxxps://carcodebd[.]com/quc/?1 hxxps://wagonsskillfoundation[.]com/ameu/?1 hxxps://clickdelcaribe[.]com[.]mx/oat/?1 hxxps://sigmaproducts[.]co[.]in/cae/?1 hxxps://izipay[.]sale/seua/?1 hxxps://sparespace[.]in/lli/?1 hxxps://novpara[.]capital/se/?1 hxxps://clinicsmilekraft[.]com/uees/?1 hxxps://doumvn[.]com/eai/?1 hxxps://muralis[.]ro/aq/?1 hxxps://ptferubbers[.]com/uua/?1 hxxps://calenaglobaltrade[.]com/eu/?1 hxxps://buzzbt[.]io/blio/?1 hxxps://midlightsoft[.]com/peum/?1 hxxps://xirconhomes[.]com[.]au/oelu/?1 hxxps://ebaeuropacontrol[.]com/asu/?1 hxxps://broadwayevents[.]co[.]za/oeii/?1 hxxps://healthylivingdiet[.]us/aitr/?1 hxxps://raghavagency[.]com/doae/?1 hxxps://rayhanacademy[.]com/unim/?1 hxxps://elevon[.]co/ot/?1 hxxps://care4sneaker[.]com/esid/?1 hxxps://adonisaviation[.]in/pmi/?1 hxxp://www[.]attsuppliers[.]com/TC/?1337 hxxps://naun[.]com[.]br/ur/?1 hxxps://strategy180[.]com[.]au/amsn/?1 hxxps://oximedbolivia[.]com/turn/?1 hxxps://medigest[.]in/uaeq/?1 hxxps://asianrealty[.]co/scar/?1 hxxps://miliaonline[.]com/uas/?1 hxxps://wheelieschoolchile[.]cl/csus/?1 hxxps://arigopay[.]com/pamr/?1 hxxps://wiselyworksdemo[.]com[.]au/nhl/?1 hxxps://infogrotech[.]com/cnl/?1 hxxps://yeni-dad[.]az/aos/?1 hxxps://gamintcorporateltd[.]com/mrue/?1 hxxps://kkdghssalumni[.]com/dme/?1 hxxps://realestateimpact[.]us/laoo/?1 hxxps://drawbox[.]pt/etue/?1 hxxps://outworktech[.]com/ld/?1 hxxps://pelicanmarket[.]net/upui/?1 hxxps://vivafitnessgym[.]com/as/?1 hxxps://crisfaria[.]com[.]br/est/?1 hxxps://saiffastners[.]com/mqdo/?1 hxxps://conecthosting[.]top/nsmi/?1 hxxps://myrescue[.]ke/labr/?1 hxxps://mohasanteck[.]com/am/?1 hxxps://shamsuddeensparepartsenterprise[.]com[.]ng/auue/?1 hxxps://snowhillvythiri[.]com/uho/?1 hxxps://kiswepatil[.]in/tm/?1 hxxps://neurodivergentna[.]com/bp/?1 hxxps://malc[.]sa/it/?1 hxxps://onlinegratuitycalculator[.]com/eta/?1 hxxps://miammiam[.]sg/rina/?1 hxxps://usdo[.]in/oon/?1 hxxps://mamobiles[.]pk/iins/?1 hxxps://transmilez[.]com/isup/?1 hxxps://fit-decor[.]com/fas/?1 hxxps://brasigncertificacao[.]com[.]br/ates/?1 hxxps://thehumanitarianfund[.]org/stc/?1 hxxps://wagonslearning[.]in/uiqq/?1 hxxps://shivanisolar[.]com/esrs/?1 hxxps://brokrbindr[.]ca/ab/?1 hxxps://sapansahu[.]com/paiu/?1 hxxps://engenhariaiguacu[.]com[.]br/ede/?1 hxxps://keyvigilant[.]com[.]mx/otpr/?1 hxxps://yagneek[.]com/sm/?1 hxxps://jlsangola[.]com/quc/?1 hxxps://mallasprogalv[.]com/ia/?1 hxxps://bandafourhead[.]com[.]br/oiai/?1 hxxps://psyperceive[.]com/tau/?1 hxxps://gestionfuturaauditores[.]com/io/?1 hxxps://ndbl[.]com[.]bd/cctn/?1 hxxps://gpexpatservices[.]com/ain/?1 hxxps://zeytouni[.]net/dl/?1 hxxps://biolankaagrifoods[.]com/nas/?1 hxxps://refalalmadinah[.]com/bseu/?1 hxxps://organicsoul[.]in/iq/?1 hxxps://poonamcoatings[.]com/tio/?1 hxxps://nateweise[.]com/ltdo/?1 hxxps://fixdax[.]co[.]in/ltq/?1 hxxps://ikhsoyod[.]mn/ums/?1 hxxps://offerselecter[.]com/latu/?1 hxxps://smarttv[.]show/qmc/?1 hxxps://bakhshjobs[.]com/issa/?1 hxxps://himalayanoak[.]in/pnt/?1 hxxps://winsumfashion[.]com/timu/?1 hxxps://goh[.]org[.]au/tusf/?1 hxxps://cdatulua[.]com/uelv/?1 hxxps://technopus[.]com/ate/?1 hxxps://psservicesindia[.]com/doet/?1 hxxps://vulturetv[.]com/tau/?1 hxxps://khalifatravels[.]com[.]pk/auuq/?1 hxxps://chipnweb[.]com/tu/?1 hxxps://shriganapathisourses[.]com/cor/?1 hxxps://kapaass[.]com/mn/?1 hxxps://carisfly[.]com/toed/?1 hxxps://yushanmedia[.]com[.]np/taiq/?1 hxxps://beseen-bla[.]com/troi/?1 hxxps://arkeyo[.]com/ma/?1 hxxps://arterecreiovidros[.]com[.]br/sa/?1 hxxps://lpexpert[.]site/qtqu/?1 hxxps://gatesfencingyork[.]co[.]uk/smd/?1 hxxps://goyaclinics[.]com/nii/?1 hxxps://codecut[.]site/ual/?1 hxxps://ejlalacademy[.]com/al/?1 hxxps://raffaelamarescalco[.]it/uisc/?1 hxxps://actecksoft[.]com/do/?1 hxxps://abouthealthupdates[.]us/atic/?1 hxxp://www[.]attsuppliers[.]com/TC/?1 |
Pikabot |
URL | hxxp://bottlewattoh[.]fun/api hxxp://feathspacesaf[.]fun/api hxxp://rosaryconbo[.]fun/api hxxp://resistangroupee[.]fun/api hxxp://rollbeamone[.]fun/api |
Lumma Stealer |
URL | hxxps://ssd-vip[.]website/hasan/web[.]txt hxxps://ssd-vip[.]website/hasan/log[.]php hxxps://ssd-vip[.]website/hasan hxxps://ssd-vip[.]website/nva/web[.]txt hxxps://ssd-vip[.]website/nva/log[.]php hxxps://ssd-vip[.]website/nva hxxps://sahamedalat[.]seatech[.]ir/login/Apply[.]php hxxps://sahamedalat[.]seatech[.]ir/login/get[.]php hxxps://sahamedalat[.]seatech[.]ir/login/sh[.]php hxxps://sahamedalat[.]seatech[.]ir/login/kakero/ hxxps://sahamedalat[.]seatech[.]ir/login hxxps://tc[.]icnsh[.]pro/%F0%9D%90%9C%E2%80%8C%E2%80%8C/app[.]apk hxxps://remote[.]mynameisking[.]site/api/-1001691314064 hxxps://remote[.]mynameisking[.]site/api/ hxxps://ssd-vip[.]website/sez/web[.]txt hxxps://ssd-vip[.]website/sez/log[.]php hxxps://ssd-vip[.]website/sez hxxps://tc[.]icnsh[.]pro/%F0%9D%90%9C%E2%80%8C%E2%80%8C/app[.]php hxxps://remote[.]mynameismamad[.]site/api/-1001522258809 hxxps://remote[.]mynameismamad[.]site/api hxxps://remote[.]mynameissheykh[.]site/api/-1001691314064 hxxps://remote[.]mynameissheykh[.]site/api/ |
IRATA |
URL | hxxps://grapemundo[.]com/Apk/vc[.]js | WSHRAT |
URL | hxxp://44[.]203[.]122[.]41/def[.]ps1 | XWorm |
URL | hxxp://77[.]91[.]68[.]78/lend/2-3-0_2023-10-05_14-14[.]exe | Raccoon |