不正URLへのアクセス、不正メールの受信
-
メール受信した
弊社お客様0社 URLアクセスした
弊社お客様6社 -
2023/11/07
※2023/11/07 更新
マルウェア感染させると考えられるURLを検知(2023/11/07)
■IoC(※1)
Type: | IOC: | Signature: |
---|---|---|
URL | hxxps://andreeasasser[.]com/cdn-vs/minlen[.]php hxxps://andreeasasser[.]com/cache/qzwewmrqqgqnaww[.]php hxxps://addisonlynch[.]com/111[.]php hxxps://usjmh[.]2023[.]ebeenj[.]com/editContent |
FAKEUPDATES |
URL | hxxp://139[.]224[.]188[.]165/activity hxxps://flow[.]baidu666[.]pw:8443/case[.]js hxxps://47[.]242[.]158[.]114/en_US/all[.]js hxxp://49[.]232[.]214[.]202:8088/pixel hxxp://106[.]52[.]253[.]80/en_US/all[.]js hxxp://112[.]124[.]53[.]64:8011/dpixel hxxp://107[.]174[.]253[.]49/pixel[.]gif hxxp://8[.]134[.]71[.]235:8090/owa/ hxxp://45[.]76[.]160[.]245/owa/ hxxps://45[.]144[.]136[.]230/visit[.]js |
Cobalt Strike |
URL | hxxp://galandskiyher5[.]com/downloads/toolspub1[.]exe | SmokeLoader |
URL | hxxp://china[.]dhabigroup[.]top/_errorpages/nonnyzx[.]exe hxxp://china[.]dhabigroup[.]top/_errorpages/agodzx[.]exe hxxp://fresh1[.]ironoreprod[.]top/_errorpages/MKiJjiii77[.]exe hxxp://zang1[.]almashreaq[.]top/_errorpages/governorzx[.]exe hxxp://zang1[.]almashreaq[.]top/_errorpages/damianozx[.]exe hxxps://api[.]telegram[.]org/bot5801961827:AAHU2YhkfiXQwgVf7WnbO6mcJG_3zpTOec4/ hxxps://discord[.]com/api/webhooks/1165931672190062623/xocVCXu11ykH0Cs7O3JFYaLzZ79j0eLYIEn9ff9w-TITbNQD28E6786MfHKBxOdVDon5 hxxps://discord[.]com/api/webhooks/1168442671841419354/_UOsGdCyvRo3vonESMsWPoJPcDgYGzrlrY_XGQC4E6P10TZ4wI9_db3vOHEcgu9uGefS hxxp://91[.]92[.]255[.]16/mana/inc/61b46e405d2c1c[.]php hxxps://discord[.]com/api/webhooks/1169917901906653224/YjkyFWX_CawSIPQ02zeV3XExHGtDteoh-fLuvdqIFqL772Pb__cJUtnVv4DqDRhm0ks1 hxxp://192[.]227[.]173[.]78/1256/IGCC[.]exe hxxps://api[.]telegram[.]org/bot6857395601:AAEr0Ki03_UqNs4qlOxRNOhnjU8odyo6de4/ hxxps://api[.]telegram[.]org/bot6433049610:AAGUidZzrUI9AQcALQrkJj8CAwaWlAMgQYs/ hxxp://91[.]92[.]252[.]100/igbo[.]exe hxxp://zang1[.]almashreaq[.]top/_errorpages/arinzezx[.]exe hxxps://api[.]telegram[.]org/bot6631738496:AAG2zE5i799qnEmdlleUzTqWLMkSGsE8aDc/ hxxps://api[.]telegram[.]org/bot6895243100:AAEakGV8ZnCRYpg0ivATftpb0jZ2g6GDBNM/ |
Agent Tesla |
URL | hxxp://raymonddixon[.]icu/3886d2276f6914c4[.]php hxxp://5[.]252[.]21[.]48/putty[.]exe hxxp://91[.]215[.]85[.]189/43851895e447afd7[.]php hxxp://91[.]215[.]85[.]189/3c3e0f20b4073f76/vcruntime140[.]dll hxxp://91[.]215[.]85[.]189/3c3e0f20b4073f76/msvcp140[.]dll hxxp://91[.]215[.]85[.]189/3c3e0f20b4073f76/softokn3[.]dll hxxp://91[.]215[.]85[.]189/3c3e0f20b4073f76/freebl3[.]dll hxxp://91[.]215[.]85[.]189/3c3e0f20b4073f76/nss3[.]dll hxxp://91[.]215[.]85[.]189/3c3e0f20b4073f76/mozglue[.]dll hxxp://91[.]215[.]85[.]189/3c3e0f20b4073f76/sqlite3[.]dll |
Stealc |
URL | hxxp://zang1[.]almashreaq[.]top/_errorpages/owenzx[.]exe hxxp://mail[.]treeoflifeadventures[.]com/wp-content/plugins/70d5e28f51c1438d94e3e6dc84b95311/xt/mmd/shell/jucostam2[.]1[.]exe hxxps://gbuarts[.]com/cc/Protected[.]exe |
Formbook |
URL | hxxp://107[.]175[.]156[.]139/CcAEDZUbRLnFrK119[.]bin hxxp://ush[.]oterngr[.]online/xmshudil206[.]bin hxxp://103[.]176[.]111[.]163/lnHxQotdQb132[.]bin hxxp://103[.]176[.]111[.]163/mundhul[.]pfb hxxp://185[.]202[.]175[.]201/gcoakvClHbkknLGxhEO248[.]bin hxxp://185[.]202[.]175[.]201/NKKtNdGMD157[.]bin hxxp://107[.]175[.]156[.]139/WoPyUHbXkVcJQS138[.]bin |
CloudEyE |
URL | hxxp://194[.]49[.]94[.]72/3[.]exe hxxp://194[.]169[.]175[.]118/xinchao[.]exe hxxps://github[.]com/faqu1/in4s0ft/releases/download/sdad/aww[.]exe hxxp://45[.]8[.]230[.]15/e[.]exe |
RedLine Stealer |
URL | hxxp://zxmextog23[.]xyz/777/mtx6E6A[.]exe | Phobos |
URL | hxxp://zxmextog23[.]xyz/777/skxDoVg[.]exe | SystemBC |
URL | hxxps://efmdwkmwke[.]xyz/vvmd54/ hxxps://efmdwkmwke[.]xyz/ZgbN19Mx hxxps://efmdwkmwke[.]xyz/lander/chrome_1695206714/_index[.]php hxxps://efmdwkmwkq[.]xyz/ZgbN19Mx hxxps://efmdwkmwkq[.]xyz/vvmd54/ |
ClearFake |
URL | hxxp://193[.]164[.]223[.]77:7456/77 hxxp://194[.]146[.]84[.]244:4397/77 hxxp://107[.]151[.]94[.]70:4397/77 hxxp://107[.]151[.]94[.]67:4397/77 |
PurpleFox |
URL | hxxp://305[.]ebnsina[.]top/_errorpages/305/five/fre[.]php | LokiBot |
URL | hxxp://194[.]49[.]94[.]97/download/Services[.]exe | PrivateLoader |
URL | hxxp://gons10fc[.]top/build[.]exe hxxp://gons09fc[.]top/build[.]exe |
Arkei Stealer |
URL | hxxp://45[.]32[.]80[.]240/REIsgtf/Gotha hxxp://149[.]248[.]1[.]76/Scb/Gotha hxxp://66[.]42[.]101[.]54/hsRW8R/Gotha hxxps://primepharma[.]so/nm/?05960251 hxxps://comperiapr[.]com/emet/?97060251 hxxps://movieshouse[.]in/an/?05350251 hxxps://spacaruaru[.]com/ieur/ hxxps://sheyap[.]com/dqsr/ hxxps://bornchef[.]co[.]id/auv/ hxxps://scottlivinghome[.]com[.]br/onnh/ hxxps://dietchain[.]ai/teua/ hxxps://securecashapp[.]com/inu/ hxxps://rafdavilas[.]com/uepc/ hxxps://smartminingtechnology[.]co[.]za/uail/ hxxps://gervais[.]ma/eu/ hxxps://kayad[.]org[.]tr/aiu/ hxxps://sivassoft[.]com[.]tr/ldsm/ hxxps://katabononline[.]com/povr/ hxxps://winwinchapter[.]com/ba/ hxxps://agenciasim[.]mx/en/ hxxps://gueveadehumboldt[.]gob[.]mx/ei/ hxxps://apmt[.]co[.]in/og/ hxxps://krea[.]com[.]py/vr/ hxxps://sivastblab[.]org/ba/ hxxps://basilplast[.]md/iee/ hxxps://aviciiconstruction[.]com/ven/ hxxps://peckhamplumbingandheating[.]co[.]uk/duiq/ hxxps://bagage[.]ma/ea/ hxxps://creat-style[.]com/ud/ hxxps://shareboosting[.]com/am/ hxxps://smartlook[.]com[.]sa/epm/ hxxps://aptinverex[.]net/iuat/ hxxps://ravhuyanilogistics[.]co[.]za/vg/ hxxps://paltela[.]lt/uqa/ hxxps://rastrapati[.]com/urqo/ hxxps://uscltd[.]com[.]pk/uim/ hxxps://thebeechesgarage[.]co[.]uk/mbr/ hxxps://grahnakshatra[.]com/cd/ hxxps://stjosephacademysociety[.]org/tat/ hxxps://telcoqatar[.]com/outn/ hxxps://jgwebdesign[.]com/cpiu/ hxxps://aploza[.]com/ih/ hxxps://erasmus-agrismart[.]com/iaq/ hxxps://securehosting[.]vip/is/ hxxps://netfolder[.]com/su/ hxxps://supperly[.]co[.]uk/tne/ hxxps://clasitapua[.]com/ti/ hxxps://landing[.]cgl[.]co[.]id/quu/ hxxps://ds-supplies[.]com/aem/ hxxps://marcocarola[.]uk/mt/ hxxps://homage[.]com[.]pk/ncs/ hxxps://mtiba[.]co[.]ke/mnia/ hxxps://dentistamontemor[.]com[.]br/uit/ hxxps://unnatisansthan[.]org/qan/ hxxps://hopewater[.]co/pa/ hxxps://smancydata[.]com[.]ng/tuv/ hxxps://buildrs[.]com/ft/ hxxps://mitica[.]eu/imue/ hxxps://examiner[.]org[.]pk/tsn/ hxxps://aimfireandsecurity[.]com/euxm/ hxxps://feeneysbathrooms[.]com[.]au/tta/ hxxps://bestbondcleaning[.]com[.]au/nvie/ hxxps://weddinginvitation[.]id/uita/ hxxps://perfectnuts[.]com/uqar/ hxxps://rentalmobildisilangit[.]com/ru/ hxxps://demosite[.]name/vnii/ hxxps://centreon[.]net/aaeq/ hxxps://vdrone[.]ro/ni/ hxxps://sparrowsport[.]in/tt/ hxxps://sysprodata[.]com/oli/ hxxps://personalizeja[.]emp[.]br/aar/ hxxps://altareef[.]net/ar/ hxxps://hotelsunplaza[.]in/maup/ hxxps://braceletcuivre[.]com/eit/ hxxps://noytral24[.]no/mi/ hxxps://jsp[.]com[.]np/omd/ hxxps://asesoriasaldia[.]com/aiq/ hxxps://herbs[.]pk/sdds/ hxxps://dgssoftware-pa[.]com/io/ hxxps://accurateflooring[.]co[.]uk/rn/ hxxps://watfordspringschool[.]org[.]ng/mee/ hxxps://katedraproducciones[.]com/ar/ hxxps://almost4x4[.]com/npot/ hxxps://ewizardz[.]com/nad/ hxxps://switzerlland[.]com/emor/ hxxps://lanecert[.]com/ami/ hxxps://loops[.]my/dso/ hxxps://cdc-ublida1[.]com/aum/ hxxps://spinnerhigh[.]com/utp/ hxxps://b2llab[.]in/br/ hxxps://home-line[.]pk/eett/ hxxps://bortechits[.]com/ipn/ hxxps://suitesejecutivasmonterrey[.]com/uoll/ hxxps://bossajazzbrasil[.]com/rsru/ hxxps://visionare[.]pk/mel/ hxxps://viareal[.]com[.]br/vext/ hxxps://datalifez[.]com[.]ng/nt/ hxxps://ecosolutionsbd[.]com/fesu/ hxxps://fivestareducationgroup[.]com/lver/ hxxps://careersreach[.]com/sodn/ hxxps://getamericanclasshelp[.]com/aueb/ hxxps://fluidpowerservicesng[.]com/isqq/ hxxps://escritordiario[.]store/il/ hxxps://winekings[.]vn/qeau/ hxxps://pacificgroup[.]co/stmd/ hxxps://thiswayafrica[.]com/iaps/ hxxps://asmargroup[.]org/oid/ hxxps://tempocf[.]com/io/ hxxps://sabdankur[.]com/st/ hxxps://lagunabeachresort3-maldives[.]com/au/ hxxps://vdafinanceandcapital[.]com[.]np/vo/ hxxps://hwdrainageltd[.]co[.]uk/rr/ hxxps://decoryaran[.]ir/si/ hxxps://sdisriati2[.]sch[.]id/mm/ hxxps://hoxtonparktowingservices[.]com[.]au/ts/ hxxps://hasinamart[.]com/tiec/ hxxps://billingtonsafety[.]com/olor/ hxxps://pwkabko[.]com/tr/ hxxps://nexcreations[.]com[.]sg/ls/ hxxps://andrewsflooringfl[.]com/mr/ hxxps://renga[.]co[.]za/inst/ hxxps://purouma-technology[.]ma/end/ hxxps://panacheinteriors[.]co[.]in/mti/ hxxps://esellx[.]com/odee/ hxxps://ikapcrberbagi[.]id/bssi/ hxxps://alibasi[.]com/eium/ hxxps://sameirotravel[.]com/iue/ hxxps://medibridge[.]ch/on/ hxxps://rcihandicrafts[.]com/tiu/ hxxps://asragarments[.]com/udqm/ hxxps://xnets[.]co[.]za/cn/ hxxps://wpcapitalguru[.]com/ues/ hxxps://biztech2go[.]com/tuis/ hxxps://jtaviation[.]co[.]in/ns/ hxxps://apotek-zada[.]com/nnv/ hxxps://aspensiestadenver[.]com/aiul/ hxxps://medicena[.]pk/aqu/ hxxps://isteonline[.]org/tro/ hxxps://menaragroup[.]com/pe/ hxxps://karoindogroup[.]com/itp/ hxxps://goingtoasia[.]org/nsn/ hxxps://agendamaconicabrasil[.]com[.]br/dt/ hxxps://pakpersian-carpets[.]com/etut/ hxxps://eljennsolutions[.]com/us/ hxxps://amenfamilia[.]com/ero/ hxxps://asus-avis[.]com/sin/ hxxps://intranetkktmsg[.]com/qouu/ hxxps://akshayeewealth[.]com/teaf/ hxxps://tanjin[.]tk/cc/ hxxps://drtv[.]cg/psuu/ hxxps://colchaoicore[.]com[.]br/cefa/ hxxps://adriaevolution[.]com/erm/ hxxps://accident[.]lv/aq/ hxxps://singkawanggrandmall[.]com/atee/ hxxps://multiserviciossol[.]es/ai/ hxxps://aparatefitness[.]info/xlmp/ hxxps://bmwcare[.]ae/rint/ hxxps://theprideschools[.]com/tu/ hxxps://h2u[.]host/ae/ hxxps://dentistasaocarlos[.]com[.]br/onlo/ hxxps://globalvisiongroupbd[.]com/ua/ hxxps://sistemas-web[.]cl/oddf/ hxxps://astroraah[.]com/ero/ hxxps://lanahospital[.]com/mtsu/ hxxps://shrinkhal[.]com[.]np/lod/ hxxps://omangraphicsco[.]com/unnc/ hxxps://imperialcnc-dz[.]com/erra/ hxxps://lrmoveis[.]ind[.]br/fich/ hxxps://sakis[.]id/tsn/ hxxps://hydra[.]com[.]my/aqe/ hxxps://dfsroofing[.]co[.]uk/rdo/ hxxps://cerige-cd[.]net/ait/ hxxps://thetimesbharat[.]com/ta/ hxxps://verotools[.]com/ldu/ hxxps://xragracini[.]com[.]ng/ss/ hxxps://ohringenieria[.]net/id/ hxxps://aaradhyamedspa[.]com/tor/ hxxps://taxibonhommegstaad[.]com/sn/ hxxps://kriyatex[.]id/die/ hxxps://initiative-td[.]org/au/ hxxps://recomandat[.]com/ai/ hxxps://bluelabelpharma[.]com/imsi/ hxxps://windooruae[.]com/iit/ hxxps://suitesmonterrey[.]mx/sq/ hxxps://meiracontadores[.]com[.]br/sisu/ hxxps://fundacion1555[.]com/mqhu/ hxxps://biz-deal[.]net/lia/ hxxps://deltastores[.]co[.]uk/ripv/ hxxps://gdom[.]org/qu/ hxxps://cretabee[.]gr/uisc/ hxxps://lbdhmc[.]com[.]ph/otes/ hxxps://lookmyvc[.]com/lb/ hxxps://pbkp[.]com[.]np/tu/ hxxps://4iptv[.]net/qu/ hxxps://amolmolas[.]com[.]br/uio/ hxxps://mayanmexico[.]travel/auus/ hxxps://terraskills[.]com/re/ hxxps://flhomebuyerkit[.]com/stie/ hxxps://musakis[.]org/leia/ hxxps://chem-solutions[.]pe/tnit/ hxxps://ismartsolulab[.]com/nrel/ hxxps://sodef-sl[.]com/maer/ hxxps://review-with-alam[.]xyz/ia/ hxxps://digitalconsultants[.]com[.]pk/ite/ hxxps://plant-street[.]com/en/ hxxps://cantinaorsago[.]it/mu/ hxxps://dentistalimeira[.]com[.]br/en/ hxxps://tamskitchentorbay[.]co[.]uk/lm/ hxxps://agenciadepropaganda[.]app[.]br/eaqu/ hxxps://books[.]ttc[.]edu[.]sg/ei/ hxxps://aktifyapikimya[.]com[.]tr/tst/ hxxps://amzfix[.]com/is/ hxxps://loops[.]my/glei/ hxxps://netpro[.]africa/in/ hxxps://aonefeeds[.]com[.]pk/imsd/ hxxps://goldentelecommunication[.]com[.]ng/iia/ hxxps://srizonyerp[.]com/uo/ hxxps://erpsolutions[.]asia/taus/ hxxps://nestegglabs[.]com/ns/ hxxps://nittyonotun[.]com/ad/ hxxps://polinya-parc-agrari[.]com/ipaa/ hxxps://paperplanemotion[.]works/iit/ hxxps://searleivsolutions[.]com/rxo/ hxxps://comperiapr[.]com/emet/ hxxps://villasore-solta[.]com/mtpi/ hxxps://nusaybindilkursu[.]com[.]tr/or/ hxxps://rastawholesale[.]com/uets/ hxxps://aplicacionesrdm[.]com/dlnm/ hxxps://phazeentertainment[.]com[.]au/up/ hxxps://indiajuris[.]com/tops/ hxxps://ximenacastillo[.]com/bbl/ hxxps://kaizen[.]pk/mmqn/ hxxps://ledsun-eg[.]com/tv/ hxxps://centruldepsihosomatica[.]md/ette/ hxxps://llavedelaprendizaje[.]com/ce/ hxxps://mrshake[.]com[.]br/aaid/ hxxps://hmhconnect[.]ng/sl/ hxxps://hotelsunplaza[.]in/utu/ hxxps://softlink[.]com[.]br/cuts/ hxxps://roasis[.]co/aa/ hxxps://engthuse[.]com/en/ hxxps://baliinside[.]id/utou/ hxxps://fitwithvik[.]com/ii/ hxxps://cheeringzu[.]com/tedt/ hxxps://incrediblehomes[.]com[.]au/iri/ hxxps://ordiclinic[.]ca/utot/ hxxps://sonsik[.]org[.]np/udiu/ hxxps://rajindevs[.]com/fgu/ hxxps://excelon[.]co[.]ke/op/ hxxps://kbpiijateng[.]org/ette/ hxxps://ensalud[.]com[.]co/ntur/ hxxps://petryseguros[.]com[.]br/pvae/ hxxps://awana[.]co[.]zw/mr/ hxxps://bujor[.]md/nvm/ hxxps://projectsfe[.]com/ec/ hxxps://mamazgroupbd[.]com/bo/ hxxps://mbcci[.]com[.]pk/uebp/ hxxps://allenlaw[.]my/ou/ hxxps://bomespine[.]com/taut/ hxxps://spangle1[.]online/unm/ hxxps://rootsschools[.]edu[.]pk/se/ hxxps://thinkpinkhandyman[.]com[.]au/nma/ hxxps://emporchid[.]com[.]tw/cd/ hxxps://circuitech[.]ae/ate/ hxxps://anywayit[.]com/rsua/ hxxps://dentistapiracicaba[.]com[.]br/maxi/ hxxps://flyserpservices[.]com/ii/ hxxps://coher[.]com[.]mx/ru/ hxxps://eighttimeseight[.]com/eere/ hxxps://marketingdigital[.]app[.]br/qa/ hxxps://stylo[.]ae/imol/ hxxps://meyhic[.]com[.]tr/fao/ hxxps://firmsewa[.]com/ao/ hxxps://byra24[.]no/qb/ hxxps://domesticasia[.]com/ei/ hxxps://destinyrestorationassociation[.]org/mai/ hxxps://mygroman[.]com/lle/ hxxps://willmaxpower[.]com/ttuu/ hxxps://trimadeco[.]com/ola/ hxxps://bmfusinagem[.]com[.]br/ad/ hxxps://mbservingenieria[.]com/ioo/ hxxps://amanet-sector-6-zeus[.]ro/gdim/ hxxps://nezogh[.]com/msm/ hxxps://iris-corp[.]com/tum/ hxxps://crecemas[.]pe/au/ hxxps://salihogullari[.]com[.]tr/ee/ hxxps://salem-gospel[.]org/ap/ hxxps://kuwaitpolyurethane[.]com/eu/ hxxps://financialrating[.]com[.]ve/rt/ hxxps://rezam[.]pk/vter/ hxxps://expancio[.]us/mete/ hxxps://sharmasdrivingschool[.]com[.]au/iu/ hxxps://osam[.]org[.]ar/soee/ hxxps://zabeelmall[.]com/ac/ hxxps://dpls[.]ir/sm/ hxxps://hamrahansystem[.]com/dei/ hxxps://theaviaryhotel[.]com/ar/ hxxps://eliteparentschool[.]rw/uodc/ hxxps://gtech[.]com[.]co/tiu/ hxxps://unitelexperts[.]com/te/ hxxps://powerdatasub[.]com[.]ng/iuna/ hxxps://vestige[.]ro/tssu/ hxxps://okaylogistics[.]com/eeac/ hxxps://capesatdigitals[.]co[.]za/uame/ hxxps://agenciadigital[.]app[.]br/oec/ hxxps://metin2sepetim[.]com/rc/ hxxps://lbdhmc[.]com[.]ph/tot/ hxxps://trakyagunesteknik[.]com/ome/ hxxps://faheemakhterinternationalllc[.]com/lrun/ hxxps://gulfxgroup[.]com/uu/ hxxps://app[.]cgl[.]co[.]id/iv/ hxxps://miracleinfotech[.]org/tsl/ hxxps://vetaidbd[.]net/retc/ hxxps://hseferi-ks[.]com/rm/ hxxps://desentupidorabonner[.]com[.]br/dti/ hxxps://inverexsolar[.]com[.]pk/ia/ hxxps://malaysia-study[.]com/op/ hxxps://konceptwings[.]com/stti/ hxxps://vgsproyectos[.]com/ihou/ hxxps://payitforwardnfts[.]com/atdt/ hxxps://motionislife[.]co[.]uk/nss/ hxxps://benitofoods[.]com/im/ hxxps://cid[.]mr/mu/ hxxps://plandeplanes[.]com/de/ hxxps://alkhazensoft[.]net/ai/ hxxps://ilkyardimakademisi[.]net/eean/ hxxps://ikirian[.]com/nd/ hxxps://afzalelectronics[.]com[.]pk/oits/ hxxps://relianceeducation[.]net/lat/ hxxps://ferreterialirquen[.]cl/sena/ hxxps://newandin[.]com[.]co/uua/ hxxps://primepharma[.]so/nm/ hxxps://luxurynclassic[.]com/ut/ hxxps://hambudata[.]com[.]ng/eaa/ hxxps://mti-scientific[.]com/tu/ hxxps://mengodinvestments[.]com/pin/ hxxps://thunorvahan[.]com/tpu/ hxxps://parklandespecialists[.]com/fueu/ hxxps://starsholidays[.]com/rtm/ hxxps://beautyandcare[.]cl/qa/ hxxps://muktodhara[.]online/eni/ hxxps://friendsofeduca[.]net/nso/ hxxps://creamandfudge[.]in/to/ hxxps://foreverus[.]in/sfap/ hxxps://californialuxuryhotel[.]ng/ll/ hxxps://sampieselectrical[.]co[.]za/eh/ hxxps://kidzera[.]in/ta/ hxxps://sngie[.]ml/se/ hxxps://triskeliumhub[.]com/ioa/ hxxps://oygingenieros[.]com/us/ hxxps://casitadelarte[.]com/ep/ hxxps://certhis[.]us/ast/ hxxps://rtcprojects[.]ie/tesu/ hxxps://dhowdy[.]com/ua/ hxxps://msurmilarathore[.]in/spet/ hxxps://injemotors[.]com[.]br/ir/ hxxps://diresaica[.]gob[.]pe/ii/ hxxps://rtcprojects[.]ie/aton/ hxxps://rajamuhammadali[.]com/erde/ hxxps://quolocations[.]com/iope/ hxxps://featurefast[.]com/ietn/ hxxps://agisakis[.]gr/eata/ hxxps://admaxds[.]in/ieu/ hxxps://fundapp[.]com[.]ng/iee/ hxxps://dis[.]ac[.]tz/sidi/ hxxps://silverzone[.]pk/sci/ hxxps://dentistaararaquara[.]com[.]br/qi/ hxxps://iclds[.]org/mtp/ hxxps://majoziacademy[.]com/ex/ hxxps://interblockchainlab[.]com/ra/ hxxps://microonline[.]com[.]au/aa/ hxxps://man2kotasmg[.]sch[.]id/ixm/ hxxps://thedailyreel[.]com/atll/ hxxps://nathicharamimatrimony[.]com/iu/ hxxps://motorrad-tours[.]com/suit/ hxxps://spbinan[.]com/rie/ hxxps://delog[.]com[.]ng/ita/ hxxps://ost[.]tn/ise/ hxxps://bemmequerartes[.]com[.]br/nari/ hxxps://southpawboxing[.]in/upoc/ hxxps://blackptechnology[.]co[.]za/pev/ hxxps://zeerush[.]com/din/ hxxps://doinik[.]xyz/so/ hxxps://transeca[.]mx/nu/ hxxps://capitalpromotora[.]com/dist/ hxxps://bathroomcrew[.]com[.]au/eid/ hxxps://bikroyshohoj[.]com/ds/ hxxps://transledger[.]io/iram/ hxxps://machineexpert[.]ae/ttc/ hxxps://abeseguros[.]com/iman/ hxxps://crainys[.]com[.]au/uiqt/ hxxps://diemdenduhoc[.]net/eue/ hxxps://seokittool[.]com/umno/ hxxps://cotacaoloovi[.]com[.]br/eiai/ hxxps://buranding[.]com/ua/ hxxps://techfrisky[.]com/est/ hxxps://bibasgautam[.]com[.]np/iics/ hxxps://sattamatkago[.]in/eed/ hxxps://bluedreamsschools[.]com/gmai/ hxxps://webamadeh[.]ir/mmi/ hxxps://hemrikbutor[.]hu/elo/ hxxps://shopnovinplus[.]com/arp/ hxxps://cvmalala[.]com/leoi/ hxxps://fronus[.]com[.]pk/ttua/ hxxps://kclub[.]pk/tt/ hxxps://3inkadvertising[.]com/tdse/ hxxps://royalprinters[.]co[.]in/xovs/ hxxps://roseleagarage[.]co[.]uk/qut/ hxxps://calidadalavista[.]com/si/ hxxps://efeceweb[.]com/uoma/ hxxps://sapid[.]net[.]au/ipe/ hxxps://dnatango[.]com/tip/ hxxps://consorciofacil[.]com[.]ar/coa/ hxxps://focusafricaexpo[.]com/po/ hxxps://elbeacondigitals[.]com[.]au/pes/ hxxps://start-group[.]online/bre/ hxxps://benkztopup[.]com[.]ng/cttu/ hxxps://kncapitalguru[.]com/ardi/ hxxps://cityups[.]org/ruv/ hxxps://ncbcn[.]org/pqms/ hxxps://5bchem[.]ae/rhre/ hxxps://bcysa[.]org/es/ hxxps://zato[.]or[.]tz/eltr/ hxxps://amittour[.]com/iseq/ hxxps://rachabusinessgroup[.]com/uet/ hxxps://casadelteatro[.]org[.]co/aii/ hxxps://cakapriau[.]com/tbsd/ hxxps://localforvocal[.]co[.]in/enru/ hxxps://tustarjetas[.]store/rodt/ hxxps://vhsolution-id[.]com/iroa/ hxxps://viveaskin[.]com/tn/ hxxps://petstation[.]co[.]in/duer/ hxxps://gonitech[.]com[.]ng/tv/ hxxps://elpallets[.]com/tq/ hxxps://tservshop[.]com[.]br/sdau/ hxxps://avgeekinsider[.]com/eq/ hxxps://ejsplasteringlimited[.]com/qiua/ hxxps://aviyana[.]lk/aq/ hxxps://bhem[.]com[.]ng/odat/ hxxps://departamentosamuebladosmonterrey[.]mx/ra/ hxxps://damarplus[.]ro/toei/ hxxps://fastdam-statisticalsolutions[.]org/oex/ hxxps://sheffield[.]edu[.]np/vptu/ hxxps://himalayainternational[.]in/ls/ hxxps://beatrizmancilla[.]com/lin/ hxxps://ambitiousapeperfume[.]com/un/ hxxps://colegiucriminologie[.]md/aili/ hxxps://kscapitalguru[.]com/auo/ hxxps://opeyemitelecoms[.]com[.]ng/esct/ hxxps://realmarttravel[.]com/oui/ hxxps://pi-pac[.]com/fil/ hxxps://ridgemedicalcentre[.]com/edt/ hxxps://mindset-4-success[.]com/umi/ hxxps://airtimes[.]my/qem/ hxxps://milanotecnoservice[.]it/ei/ hxxps://wavefront[.]pe/ns/ hxxps://attpk[.]com/en/ hxxps://vanishwaxing[.]com[.]au/udms/ hxxps://adz[.]app[.]br/pi/ hxxps://aamoriboutiquehotel[.]com/ua/ hxxps://newideasec[.]com/lu/ hxxps://rarestglam[.]com/tio/ hxxps://movieshouse[.]in/an/ hxxps://mgcleaningtn[.]com/oce/ hxxps://sitelco[.]net/ca/ hxxp://49[.]13[.]119[.]230/6aZE/vapor hxxp://49[.]13[.]119[.]230/6aZE/Dregl hxxp://49[.]13[.]119[.]230/6aze/altar |
Pikabot |
URL | hxxps://api[.]telegram[.]org/bot5206100572:AAFn3MxBuN0bjQhfY8y1ed9Iwi79LyIe75I/sendMessage?chat_id=2135869667 | Snake Keylogger |
URL | hxxp://194[.]49[.]94[.]67/files/Ads[.]exe | Glupteba |
URL | hxxp://194[.]49[.]94[.]67/files/My2[.]exe | Coinminer |