不正URLへのアクセス、不正メールの受信
-
メール受信した
弊社お客様0社 URLアクセスした
弊社お客様1社 -
2024/03/27
※2024/03/27 更新
マルウェア感染させると考えられるURLを検知(2024/03/27)
■IoC(※1)
Type: | IOC: | Signature: |
---|---|---|
URL | hxxp://193[.]233[.]132[.]167/lend/RDX[.]exe hxxp://193[.]233[.]132[.]167/lend/afile[.]exe |
RedLine Stealer |
URL | hxxp://209[.]90[.]233[.]33/wmCpfYlQj52[.]bin hxxp://209[.]90[.]233[.]33/OMsxaOrxylMsOEbAtS117[.]bin hxxp://209[.]90[.]233[.]33/SGyvrPxu208[.]bin hxxp://147[.]78[.]103[.]250/mrpTlINpLbl210[.]bin hxxp://147[.]78[.]103[.]250/Cravenhearted[.]mix hxxps://drive[.]google[.]com/uc?export=download&id=1z_cDnpzVpKxFwEKB2sCHJacVruFL6m3d |
CloudEyE |
URL | hxxp://193[.]163[.]7[.]20/a76cb438a7769bbb/msvcp140[.]dll hxxp://193[.]163[.]7[.]20/a76cb438a7769bbb/nss3[.]dll hxxp://193[.]163[.]7[.]20/a76cb438a7769bbb/sqlite3[.]dll hxxp://193[.]163[.]7[.]20/a76cb438a7769bbb/softokn3[.]dll hxxp://193[.]163[.]7[.]20/a76cb438a7769bbb/freebl3[.]dll hxxp://193[.]163[.]7[.]20/a76cb438a7769bbb/mozglue[.]dll hxxp://193[.]163[.]7[.]20/a76cb438a7769bbb/vcruntime140[.]dll hxxp://185[.]172[.]128[.]26/f993692117a3fda2[.]php |
Stealc |
URL | hxxp://107[.]175[.]113[.]216/xampp/krm/KRMC[.]txt hxxps://paste[.]ee/d/oB1NO hxxp://107[.]175[.]113[.]216/xampp/krm/PixelImagesview[.]jpg hxxp://107[.]175[.]113[.]216/xampp/krm/kr/heisagirlwholovedmealotwithoutanyexptationssheisreallyagoodgirlshemybabydear_____itrulylovedherfromthehearbecauseverycutebayb[.]doc hxxps://covid19help[.]top/admzx[.]scr hxxp://154[.]38[.]188[.]98/90900/SDDE[.]txt hxxps://paste[.]ee/d/bWBGI hxxp://154[.]38[.]188[.]98/90900/createdloverkissed[.]vbs hxxp://154[.]38[.]188[.]98/90900/ohoj/createdloverstogetbackgreatthingstoknowthekissingthingstohappenedtounderstandthetwothingstounderstand_____youaremysweetheartlover[.]doc |
Remcos |
URL | hxxp://193[.]233[.]132[.]167/lend/amadycry[.]exe | Amadey |
URL | hxxps://www[.]8design[.]se/xmlrpc[.]php hxxps://prokeypc[.]com/xmlrpc[.]php hxxps://madalynsklar[.]com/xmlrpc[.]php hxxps://hortonhighschool[.]ca/xmlrpc[.]php hxxps://richardvanhooijdonk[.]com/xmlrpc[.]php hxxps://www[.]adventurewallcoverings[.]co[.]za/xmlrpc[.]php hxxps://g8education[.]edu[.]au/xmlrpc[.]php hxxps://abtenau-info[.]at/xmlrpc[.]php hxxps://voluntariosenelmundo[.]com/xmlrpc[.]php hxxps://greveclimaticaestudantil[.]pt/xmlrpc[.]php hxxps://beginagaininstitute[.]com/xmlrpc[.]php hxxps://leadershipmanagement[.]com[.]au/xmlrpc[.]php hxxps://academieairespace[.]com/xmlrpc[.]php hxxps://bollywoodtadka[.]xyz/xmlrpc[.]php hxxps://ccspaintingllc[.]com/xmlrpc[.]php hxxps://www[.]carlhansensolv[.]dk/xmlrpc[.]php hxxps://sitesrip[.]org/xmlrpc[.]php hxxps://ambitiouswithcards[.]com/xmlrpc[.]php hxxps://zarmes[.]ir/xmlrpc[.]php hxxps://blackdiamondbjj[.]com/xmlrpc[.]php hxxps://bearnutscomic[.]com/xmlrpc[.]php hxxps://psychosfera[.]kz/xmlrpc[.]php hxxps://www[.]assenmacher-koeln[.]de/xmlrpc[.]php hxxps://sim-unlock[.]blog/xmlrpc[.]php hxxps://dailyshepursues[.]com/xmlrpc[.]php hxxps://peacerivervet[.]com/xmlrpc[.]php hxxps://kitchenofdebjani[.]com/xmlrpc[.]php hxxps://xn--80ajgpcpbhkds4a4g[.]xn--p1ai/xmlrpc[.]php hxxps://toptorials[.]com/xmlrpc[.]php hxxps://xn--ngbeab6ar43f[.]com/xmlrpc[.]php hxxps://www[.]bienenzucht-villachland[.]at/xmlrpc[.]php hxxps://openloadmovies[.]live/xmlrpc[.]php hxxps://businessforfilipinos[.]com/xmlrpc[.]php hxxps://www[.]doctorsacademy[.]org/list/xmlrpc[.]php hxxps://tiodonghua[.]com/xmlrpc[.]php hxxps://tobano[.]pl/xmlrpc[.]php hxxps://eastnaija[.]com/xmlrpc[.]php hxxps://travelperi[.]com/xmlrpc[.]php hxxps://gribnik[.]info/xmlrpc[.]php hxxps://paydo[.]com/xmlrpc[.]php hxxps://1poclimaty[.]ru/xmlrpc[.]php hxxps://mindfulsearching[.]com/xmlrpc[.]php hxxps://psdkits[.]com/xmlrpc[.]php hxxps://porusski[.]me/xmlrpc[.]php hxxps://cultureroadtravel[.]com/xmlrpc[.]php hxxps://nzdcr[.]co[.]nz/xmlrpc[.]php |
GootLoader |
URL | hxxp://www[.]dobiamfollollc[.]online:3777/vogxhf/Panel/five/fre[.]php hxxps://sempersim[.]su/c16/fre[.]php hxxp://sempersim[.]su/c16/fre[.]php |
LokiBot |
URL | hxxp://176[.]32[.]35[.]104:82/dpixel hxxp://176[.]32[.]35[.]104/cm hxxps://103[.]150[.]10[.]45:8443/load hxxp://120[.]78[.]155[.]42/dot[.]gif hxxp://124[.]71[.]5[.]199:6666/dot[.]gif hxxps://36[.]25[.]254[.]124/en-us/silentauth hxxps://42[.]194[.]199[.]231:7443/ga[.]js hxxp://39[.]107[.]89[.]22:4443/ca hxxp://service-cedqvyh7-1322145958[.]sh[.]tencentapigw[.]com/ptj hxxp://123[.]207[.]45[.]112/dot[.]gif hxxps://43[.]156[.]21[.]230/dpixel hxxp://154[.]221[.]17[.]44:2999/cx hxxp://129[.]204[.]201[.]114/ptj hxxps://121[.]36[.]255[.]43/www/handle/doc hxxp://47[.]99[.]162[.]137/updates[.]rss hxxp://g[.]fyss888[.]com:808/ca |
Cobalt Strike |
URL | hxxp://metis-black[.]com/skid[.]ppc hxxp://metis-black[.]com/skid[.]arm7 hxxp://metis-black[.]com/skid[.]spc hxxp://metis-black[.]com/skid[.]arm6 hxxp://metis-black[.]com/skid[.]mpsl hxxp://metis-black[.]com/skid[.]arm5 hxxp://metis-black[.]com/skid[.]mips hxxp://metis-black[.]com/skid[.]sh4 hxxp://metis-black[.]com/skid[.]m68k hxxp://metis-black[.]com/skid[.]x86_64 hxxp://metis-black[.]com/skid[.]arm hxxp://91[.]92[.]251[.]65/skid[.]x86_64 hxxp://91[.]92[.]251[.]65/skid[.]arm7 hxxp://91[.]92[.]251[.]65/skid[.]mips hxxp://91[.]92[.]251[.]65/skid[.]arm5 hxxp://91[.]92[.]251[.]65/skid[.]arm6 hxxp://91[.]92[.]251[.]65/skid[.]arm hxxp://91[.]92[.]251[.]65/skid[.]sh4 hxxp://91[.]92[.]251[.]65/skid[.]mpsl hxxp://91[.]92[.]251[.]65/skid[.]m68k hxxp://91[.]92[.]251[.]65/skid[.]ppc hxxp://91[.]92[.]251[.]65/skid[.]spc hxxp://91[.]92[.]253[.]201/mips hxxp://91[.]92[.]253[.]201/i586 hxxp://91[.]92[.]253[.]201/arm hxxp://91[.]92[.]253[.]201/i686 hxxp://91[.]92[.]253[.]201/arm6 hxxp://91[.]92[.]253[.]201/arm7 hxxp://91[.]92[.]253[.]201/sh4 hxxp://91[.]92[.]253[.]201/mipsel hxxp://91[.]92[.]253[.]201/arc hxxp://91[.]92[.]253[.]201/x86_64 hxxp://139[.]99[.]36[.]201/most-sh4 hxxp://139[.]99[.]36[.]201/most-arm7 hxxp://139[.]99[.]36[.]201/most-mips hxxp://139[.]99[.]36[.]201/most-ppc hxxp://139[.]99[.]36[.]201/most-mpsl hxxp://139[.]99[.]36[.]201/most-arm6 hxxp://139[.]99[.]36[.]201/most-arm hxxp://139[.]99[.]36[.]201/a hxxp://139[.]99[.]36[.]201/debug[.]dbg hxxp://139[.]99[.]36[.]201/most-arm5 hxxp://139[.]99[.]36[.]201/most-x86 hxxp://139[.]99[.]36[.]201/most-m68k hxxp://139[.]99[.]36[.]201/and |
MooBot |
URL | hxxp://192[.]210[.]215[.]35/nesdij[.]exe hxxps://covid19help[.]top/microzx[.]scr |
Agent Tesla |
URL | hxxp://103[.]211[.]56[.]154:8745/ms[.]exe | Ghost RAT |
URL | hxxps://sessionannoucemenwj[.]shop/api hxxps://cleartotalfisherwo[.]shop/api hxxps://worryfillvolcawoi[.]shop/api hxxps://enthusiasimtitleow[.]shop/api hxxps://dismissalcylinderhostw[.]shop/api hxxps://affordcharmcropwo[.]shop/api hxxps://diskretainvigorousiw[.]shop/api hxxps://communicationgenerwo[.]shop/api hxxps://pillowbrocccolipe[.]shop/api |
Lumma Stealer |
URL | hxxps://pastebin[.]com/raw/BnA87rAD hxxps://pastebin[.]com/raw/C4xdJ0HD hxxps://pastebin[.]com/raw/zqLD5KmN |
Metasploit |
URL | hxxp://93[.]123[.]39[.]145/8484[.]txt | PXRECVOWEIWOEI |
URL | hxxps://svf[.]catching[.]fishingrealinvestments[.]com/editContent hxxps://rbmi[.]catching[.]fishingrealinvestments[.]com/editContent hxxps://rnnp[.]catching[.]fishingrealinvestments[.]com/editContent hxxps://amv[.]places[.]creeksidehuntingpreserve[.]com/editContent hxxps://sxo[.]catching[.]fishingrealinvestments[.]com/editContent |
FAKEUPDATES |
URL | hxxp://91[.]92[.]254[.]140/w[.]sh hxxp://91[.]92[.]254[.]140/loli[.]lol[.]arm |
Bashlite |
URL | hxxps://94[.]242[.]61[.]211/martinvnc[.]exe | Quasar RAT |
URL | hxxps://94[.]242[.]61[.]211/XClient[.]exe hxxp://185[.]196[.]10[.]233/dggfsff[.]exe |
AsyncRAT |
URL | hxxps://94[.]242[.]61[.]211/stub[.]exe | BitRAT |
URL | hxxps://94[.]242[.]61[.]211/sleep[.]exe | DarkComet |
URL | hxxps://textbin[.]net/raw/aofsqfmb7s | NjRAT |
URL | hxxps://ingatecsus[.]com[.]br/assumendaipsam/Point[.]exe | Pikabot |
URL | hxxps://cdn[.]discordapp[.]com/attachments/1063894486901587979/1221860531594596433/2_npp[.]8[.]6[.]4[.]portable[.]x64[.]zip?ex=66141d4b&is=6601a84b&hm=d2e98cf94633ac960476f283cc188da331ccb5b10b7ef53a17c7b07c9154a955& hxxps://apllicam[.]com/operational-resources hxxps://apllicam[.]com/Corporate-financial |
WikiLoader |
URL | hxxp://ddddpib[.]info/search/?q=67e28dd83955a42b4006aa1b7c27d78406abdd88be4b12ebb517aa5c96bd86ed82df14d714bca5817673aa4ee8889b5e4fa9281ae978f671ea771795af8e05c642db22f31df92d8b38e316a667d307eca743ec4c2b07b52966923a668af613c3ec95 hxxp://dliqxri[.]info/search/?q=67e28dd83a5da32a155afd1b7c27d78406abdd88be4b12ebb517aa5c96bd86ed82df14d714bca5817673aa4ce8889b5e4fa9281ae978a271ea771795af8e05c642db22f31dfe339426fa11af66c152adb719a9577e55b8603e983a608ffe15c9ed969f3c |
Socks5 Systemz |
URL | hxxp://withupdate[.]com/oudowibspr hxxp://backupitfirst[.]com/wgfqneerod |
DarkGate |
URL | hxxps://skinnyjeanso[.]com/live/ | Unidentified 111 (Latrodectus) |