不正URLへのアクセス、不正メールの受信
-
メール受信した
弊社お客様0社 URLアクセスした
弊社お客様5社 -
2023/11/24
※2023/11/24 更新
マルウェア感染させると考えられるURLを検知(2023/11/24)
■IoC(※1)
Type: | IOC: | Signature: |
---|---|---|
URL | hxxp://sl[.]himanfast[.]com/order/tuc3[.]exe | Socks5 Systemz |
URL | hxxps://ahoram-appphp[.]tech/strong/ hxxps://ahoram-appphp[.]tech/strong/phone[.]txt hxxps://ahoram-appphp[.]tech/strong/web[.]txt hxxps://ahoram-appphp[.]tech/mori/ hxxps://ahoram-appphp[.]tech/mori/log[.]php hxxps://ahoram-appphp[.]tech/mori/phone[.]txt hxxps://thebestgn[.]xyz/etanol/log[.]php hxxps://thebestgn[.]xyz/etanol/web[.]txt hxxps://jkishere[.]site/api/-1002134250337 hxxps://jkishere[.]site/config/-1002134250337 hxxps://jkishere[.]site/api/-1002134250337?encrypted=true hxxps://jkishere[.]site/config/-1002006205199 hxxps://jkishere[.]site/api/-1002006205199 hxxps://jkishere[.]site/api/-1002006205199?encrypted=true hxxps://iranme[.]nitrocp[.]xyz/Remote |
IRATA |
URL | hxxps://fuelrescue[.]ie/eco/ hxxps://www[.]robertoscaia[.]com/eco/ hxxps://www[.]patrickforeilly[.]com/eco/ hxxps://dein-waschbaer[.]de/wp-admin/network/Voice/VoiceAi_Setup[.]exe hxxp://defrosscrappeo[.]pw/api hxxp://hollconsole[.]pw/api hxxp://suppliepackas[.]pw/api hxxp://staircompletemil[.]pw/api hxxp://helpfulsteepyi[.]pw/api hxxp://codeofconducrasa[.]pw/api |
Lumma Stealer |
URL | hxxp://homoeo4u[.]com/john/Panel/fre[.]php hxxp://prime[.]topendpower[.]top/_errorpages/prime/five/fre[.]php |
LokiBot |
URL | hxxp://5[.]42[.]86[.]60/Protectdownloads/track0Local/basevoiddb/dle/TrafficLow/pollProcessor/temporary/6central/PolllowProcessorapisqlLinuxWppublicuploads[.]php hxxp://188[.]120[.]235[.]51/asyncuniversalLow/serverTraffic1Datalife/ServerLow/UniversaltrackBigload/temppacket1/Datalifeupdate62/ProviderDump/php_HttpmultiUploads[.]php hxxp://193[.]37[.]71[.]22/_7/GeoAuthEternal/ExternalphpWpServer/Temporary/VmProcess/multiDbRequest/PhpsecureProcessorProtectdefaultFlower[.]php hxxp://82[.]146[.]33[.]89/TrackAsyncbase7/defaultVm/PublicprotonProvider/VoiddbsqlpollBetter/03temporaryEternal/server/9Wp1Wordpress/updateDatalife2/Private/Javascript/publicgeo2/ExternallinesecureprocessLongpollLinuxWppublicDownloads[.]php |
DCRat |
URL | hxxps://discord[.]com/api/webhooks/1176618094270087188/ska8K-IVLXPC4XPgrIiupFjKjBIz3HGdgungFafUV_84d3Tfn341sZlAGngmmh9aBBpS hxxps://cpcalendars[.]rakishevkenes[.]com/bin/jjj[.]exe hxxps://discord[.]com/api/webhooks/1176151058632937522/y3_ZQ9r_IRjvTwuuG-qOGBsgjULALJ5GOiLifCNfXyDDpjQXVdGAXe9Pwh2OfkhBFusI hxxps://api[.]telegram[.]org/bot6615716687:AAEfiXJl8ANTEvl5ZklXyRPpJ-gX15NtCds/ hxxps://api[.]telegram[.]org/bot6856354887:AAEhYr_CwB2t7a7ltil8dFSh6IIrdJt5tjM/ hxxps://api[.]telegram[.]org/bot6855166222:AAEObSa5lE7Tuvkvs9nlbOEfO6lqJbHLXVo/ hxxps://discord[.]com/api/webhooks/1176163719265390654/oQps-r_etbrQYsg3NN3Of1uDN1MB94JV8NRyJ3sJ3y5YB7g9lgWhBCf-TC1Z3FruApd8 hxxp://zang3[.]conyersdill[.]top/_errorpages/obizx[.]doc |
Agent Tesla |
URL | hxxps://midatlanticlabel[.]com/lander/chrome_1695206714/_cf[.]php hxxps://midatlanticlabel[.]com/fEOV2v/ hxxps://midatlanticlabel[.]com/a3A7qLVn hxxps://thebestthings1337[.]online/fEOV2v/ hxxps://thebestthings1337[.]online/a3A7qLVn hxxps://theoptimistfirst[.]site/fEOV2v/ hxxps://theoptimistfirst[.]site/a3A7qLVn hxxps://howmuchtimeuneed[.]online/fEOV2v/ hxxps://howmuchtimeuneed[.]online/a3A7qLVn |
ClearFake |
URL | hxxp://185[.]172[.]128[.]154/ama[.]exe hxxp://185[.]196[.]8[.]238/amarer[.]exe |
Amadey |
URL | hxxp://101[.]43[.]165[.]220/push hxxps://124[.]221[.]209[.]99/image/ hxxps://13[.]52[.]77[.]84/search/ hxxps://104[.]143[.]46[.]178/jquery-3[.]3[.]1[.]min[.]js hxxp://101[.]43[.]45[.]243:88/Microsoft/owa/ hxxp://43[.]138[.]118[.]67/push hxxp://175[.]178[.]174[.]131:7878/en_US/all[.]js hxxp://101[.]43[.]165[.]220:8080/g[.]pixel hxxp://47[.]113[.]204[.]90:8080/pixel hxxp://175[.]178[.]174[.]131:6666/ca hxxp://8[.]134[.]109[.]120:2323/cm hxxp://139[.]224[.]188[.]165/match hxxp://60[.]204[.]139[.]246/cx hxxp://124[.]223[.]83[.]171:8055/visit[.]js hxxp://38[.]147[.]172[.]207:6666/dpixel hxxp://121[.]43[.]55[.]16/en_US/all[.]js hxxp://47[.]115[.]201[.]46:60001/cx hxxp://39[.]107[.]107[.]245:8091/visit[.]js hxxp://167[.]71[.]53[.]89/ptj hxxp://44[.]225[.]229[.]165:8888/match hxxp://119[.]45[.]181[.]134/dpixel hxxp://111[.]230[.]198[.]166:8333/dpixel hxxp://121[.]41[.]2[.]26:50050/push hxxp://8[.]140[.]135[.]23:8080/__utm[.]gif hxxp://47[.]113[.]204[.]90:8080/ga[.]js hxxps://95[.]85[.]73[.]13/push hxxp://117[.]72[.]35[.]30/__utm[.]gif hxxps://45[.]137[.]148[.]114/ga[.]js hxxps://47[.]232[.]145[.]107/ca hxxps://175[.]178[.]3[.]16/dot[.]gif hxxps://188[.]166[.]148[.]25/updates[.]rss hxxp://104[.]245[.]213[.]48/pixel[.]gif hxxp://121[.]41[.]2[.]26:50050/g[.]pixel hxxp://95[.]214[.]25[.]121/ptj hxxp://110[.]42[.]249[.]222/__utm[.]gif hxxp://43[.]138[.]118[.]67/IE9CompatViewList[.]xml hxxp://106[.]75[.]162[.]243/load hxxp://47[.]96[.]229[.]84/ca hxxp://101[.]201[.]50[.]90/push hxxp://45[.]32[.]8[.]42:6543/pixel[.]gif hxxps://39[.]98[.]157[.]4/IE9CompatViewList[.]xml hxxp://121[.]5[.]195[.]89:8848/en_US/all[.]js hxxp://121[.]5[.]195[.]89:8080/dot[.]gif hxxp://124[.]221[.]178[.]17/dpixel hxxp://60[.]204[.]223[.]119/load hxxps://49[.]232[.]34[.]39/fwlink hxxp://106[.]14[.]143[.]151:55555/j[.]ad hxxp://118[.]89[.]124[.]242:2121/pixel[.]gif hxxp://8[.]137[.]48[.]121/load hxxp://39[.]101[.]77[.]24/cm hxxp://114[.]132[.]238[.]70:7777/__utm[.]gif hxxp://8[.]141[.]81[.]51:6666/activity hxxp://154[.]211[.]15[.]205:8888/updates[.]rss hxxp://38[.]46[.]8[.]10:8080/jquery-3[.]3[.]1[.]min[.]js hxxp://1[.]92[.]76[.]153/ca hxxp://172[.]105[.]235[.]197:8008/j[.]ad hxxp://1[.]94[.]98[.]79/ca hxxp://132[.]232[.]113[.]242/j[.]ad hxxp://118[.]89[.]124[.]242:1234/pixel hxxp://8[.]141[.]81[.]51:7777/visit[.]js hxxp://178[.]128[.]123[.]154:1234/load hxxp://121[.]43[.]55[.]16/activity hxxp://1[.]92[.]76[.]153/en_US/all[.]js hxxp://101[.]35[.]141[.]80:10088/j[.]ad hxxps://166[.]1[.]18[.]197/add/contact-us/U0TEJ4UO hxxp://166[.]1[.]18[.]197/add/contact-us/U0TEJ4UO hxxp://193[.]201[.]9[.]82/pixel[.]gif |
Cobalt Strike |
URL | hxxp://194[.]49[.]94[.]97/ww/1[.]exe hxxp://178[.]250[.]186[.]15/task/OWYsN2YsN2YsYTAsOWUsODYsOGMsOTYsNjQsN2Ms hxxp://178[.]250[.]186[.]15/loader/screen/OWYsN2YsN2YsYTAsOWUsODYsOGMsOTYsNjQsN2Ms |
RedLine Stealer |
URL | hxxps://teleturismo[.]it/wp-includes/Tzvgdu[.]vdf | PureCrypter |
URL | hxxp://45[.]95[.]147[.]204/x86 | Bashlite |
URL | hxxps://pasteio[.]com/raw/xYXfaeD9JudR hxxps://pasteio[.]com/raw/xeef54NztA9k hxxps://techcusp[.]com/custom/Order_Information[.]zip hxxp://opencart[.]notebookparcalari[.]com/custom/Invoice[.]zip hxxp://51[.]68[.]124[.]231/headers/automaticamente/index[.]php |
Remcos |
URL | hxxp://194[.]38[.]22[.]53/ge[.]sh hxxp://194[.]38[.]22[.]53/cf[.]sh hxxp://194[.]38[.]22[.]53/spr[.]sh hxxp://194[.]38[.]22[.]53/wb[.]sh hxxp://194[.]38[.]22[.]53/pg[.]sh hxxp://194[.]38[.]22[.]53/scg[.]sh hxxp://download[.]asyncfox[.]xyz/download/multi[.]sh |
Coinminer |
URL | hxxp://175[.]107[.]0[.]220:53042/Mozi[.]m | Mozi |
URL | hxxp://185[.]172[.]128[.]69/allnewumm[.]exe | SmokeLoader |
URL | hxxp://st[.]qishia[.]com/softs/setup7[.]exe | CloudEyE |
URL | hxxp://zang1[.]almashreaq[.]top/_errorpages/plugmanzx[.]exe | Nanocore RAT |
URL | hxxps://wzswbw[.]dm[.]files[.]1drv[.]com/y4mk3WkgT4Bc_SY6PFxyiHJjlc9W6HVSKBeJr65iryU3PO7fh6xrzVKf8_3pNwZBqEZqmCgqYNY_i8GMFcSpuVinnefGPW0psWXnfrSkzdzn4XwyxlaK483rkm42SdRrk7MVb7dfnP_JQBPAKPMBEUWb_-8m5IijvDlu9lFsp5YlK_Q9FClL58yu3W445S82DDo9qugo7e5k-CaKEBuHF9ECw/Job%20Description%20Plan%20UNIQLO%202023[.]zip?download&psid=1 | DUCKTAIL |
URL | hxxps://pfwi[.]novelty[.]akibacreative[.]com/editContent hxxps://sbn[.]novelty[.]akibacreative[.]com/editContent hxxps://zolbr[.]novelty[.]akibacreative[.]com/editContent hxxps://lvumu[.]novelty[.]akibacreative[.]com/editContent hxxps://wnkhh[.]novelty[.]akibacreative[.]com/editContent hxxps://ujii[.]sync[.]oystergardens[.]club/editContent hxxps://hhgs[.]sync[.]oystergardens[.]club/editContent |
FAKEUPDATES |
URL | hxxp://blazh[.]shop/ZH341/index[.]php hxxp://d4gj[.]shop/GJ341/index[.]php |
Azorult |