不正URLへのアクセス、不正メールの受信
-
メール受信した
弊社お客様0社 URLアクセスした
弊社お客様1社 -
2024/05/15
※2024/05/15 更新
マルウェア感染させると考えられるURLを検知(2024/05/15)
■IoC(※1)
Type: | IOC: | Signature: |
---|---|---|
URL | hxxp://38[.]15[.]131[.]216/xDiAqOwvPZdOa69[.]bin hxxp://185[.]29[.]9[.]120/ysmJZrSvph82[.]bin hxxp://178[.]215[.]236[.]229/xFcYFZKQRkETQdPiA198[.]bin hxxp://64[.]188[.]27[.]210/yBmSw127[.]bin hxxp://178[.]215[.]236[.]229/Anodiserings[.]fla hxxp://64[.]188[.]21[.]131/NZMqCEqKkx48[.]bin hxxp://194[.]59[.]31[.]206/CDIJGWfZ253[.]bin hxxp://86[.]38[.]225[.]41/ImunPfh144[.]bin hxxp://86[.]38[.]225[.]41/PkVhOCfbTkJ41[.]bin hxxp://162[.]245[.]190[.]151/AcRyaKHTvRvr120[.]bin hxxps://veloutinebydelite[.]ro/statikeres[.]hhp hxxps://ibllt[.]com/wp-admin/Pseudonoble[.]lzh |
CloudEyE |
URL | hxxp://23[.]226[.]57[.]18/%E5%AD%A6%E6%9C%89%E4%BC%98%E6%95%99[.]apk hxxp://23[.]226[.]57[.]2/%E5%AD%A6%E6%9C%89%E4%BC%98%E6%95%99[.]apk hxxp://23[.]226[.]57[.]43/%E5%AD%A6%E6%9C%89%E4%BC%98%E6%95%99[.]apk |
SpyMax |
URL | hxxp://13[.]60[.]65[.]219:8080/mimikats[.]ps1 hxxp://13[.]60[.]65[.]219:8080/test[.]ps1 |
MimiKatz |
URL | hxxp://13[.]60[.]65[.]219:8080/cmd[.]ps1 hxxp://1[.]14[.]192[.]93:443/Rpc hxxps://13[.]232[.]63[.]18/cx hxxp://103[.]148[.]151[.]179:8080/api/v1/async/info hxxps://www[.]jumpsrever[.]top/__utm[.]gif hxxp://47[.]117[.]174[.]198/_/scs/mail-static/_/js/ hxxps://89[.]187[.]28[.]116/j[.]ad hxxp://36[.]111[.]191[.]33:8888/pixel hxxp://13[.]232[.]63[.]18:8080/visit[.]js hxxps://121[.]40[.]127[.]134:4443/ptj hxxps://103[.]17[.]119[.]73/push hxxp://45[.]136[.]14[.]91:9090/updates[.]rss hxxp://service-kj4ef32e-1252578700[.]gz[.]tencentapigw[.]com[.]cn/api/x hxxp://141[.]98[.]7[.]79/cm hxxps://gov[.]vsj888[.]shop:8443/index[.]js hxxp://192[.]3[.]24[.]157:801/ptj hxxp://47[.]243[.]26[.]247:5000/activity hxxp://47[.]92[.]96[.]144/push hxxp://43[.]138[.]168[.]21:8098/dot[.]gif hxxp://81[.]71[.]127[.]160:8888/visit[.]js hxxps://43[.]143[.]110[.]110/en_US/all[.]js hxxp://111[.]231[.]21[.]83/load hxxp://43[.]138[.]222[.]123/dpixel hxxp://23[.]95[.]65[.]198:2222/ptj hxxp://110[.]41[.]21[.]173/ptj hxxp://47[.]115[.]215[.]30:6666/visit[.]js hxxp://123[.]57[.]85[.]206:50000/fwlink hxxps://update[.]360safety[.]xyz:8443/IE9CompatViewList[.]xml hxxps://vsj888[.]shop:2083/index[.]js hxxps://47[.]243[.]26[.]247:5001/activity hxxps://www[.]checktimes[.]top/promote/static/XV4SPLMOG |
Cobalt Strike |
URL | hxxp://13[.]60[.]65[.]219:8080/meter2[.]exe | Meterpreter |
URL | hxxps://tpu[.]schedule[.]golfballnutz[.]com/editContent hxxps://jmd[.]members[.]openarmscv[.]com/editContent |
FAKEUPDATES |
URL | hxxps://github[.]com/Synapsesys/Synapse/releases/download/ah/Discord[.]exe hxxp://94[.]156[.]68[.]134/start[.]exe hxxp://94[.]156[.]68[.]134/costs[.]zip hxxp://94[.]156[.]68[.]134/regasms[.]exe hxxp://94[.]156[.]68[.]134/costs[.]vbs hxxp://94[.]156[.]68[.]134/MartDrum[.]exe hxxp://5[.]42[.]96[.]7/lend/taskmgr[.]exe |
AsyncRAT |
URL | hxxps://github[.]com/SetThreadExecutionState/ModifiedDiscordClient/raw/main/yar[.]exe | XWorm |
URL | hxxp://bigcheeserodents[.]com/mcmaster-collective-agreement-faculty hxxps://boisebrides[.]keydesigndevelopment[.]com/manual[.]php hxxp://ikwilvanmijnpoloaf[.]nl/2023/06/08/secret-agreement-between-germany hxxps://booking[.]chaletsphilippe[.]com/manual[.]php hxxps://booking[.]intersport[.]it/manual[.]php hxxps://bvp[.]ch/manual[.]php hxxp://signcitysa[.]com/general-manager-role-key-responsibilities-and-legal-implications hxxps://brastal[.]pl/manual[.]php hxxps://bramafhu[.]pl/manual[.]php hxxps://businesstraveller[.]pl/manual[.]php |
GootLoader |
URL | hxxps://karakaplandalgada[.]shop/ZDQyN2NmOGEZOTIK/ hxxps://karakaplandalgada124[.]shop/ZDQyN2NmOGEZOTIK/ hxxps://kapankralda[.]top/ZDQyN2NmOGEZOTIK/ hxxps://karakaplandalgadadas[.]com/ZDQyN2NmOGEZOTIK/ hxxps://neredekalgelsn3[.]shop/ZDQyN2NmOGEZOTIK/ hxxps://kamarkadals53[.]shop/ZDQyN2NmOGEZOTIK/ hxxps://manavkaradas[.]shop/ZDQyN2NmOGEZOTIK/ hxxps://karacellalder[.]shop/ZDQyN2NmOGEZOTIK/ hxxps://kamaradas412[.]top/ZDQyN2NmOGEZOTIK/ hxxps://karadalganagerekta2[.]com/ZDQyN2NmOGEZOTIK/ |
Coper |
URL | hxxp://taketa[.]top/imageTocpuupdateApiTemporary[.]php | DCRat |
URL | hxxps://covid19help[.]top/fpeace[.]scr hxxps://bruta[.]pl/Monkeynut[.]emz hxxps://bruta[.]pl/WSfBhsycdugbAkKJGNw168[.]bin hxxp://23[.]94[.]36[.]162/xampp/lop/lo/everythinggoingfineandgreatwithbeautiuflthingstounderstandhowmuchsheisbeautiufleverytimeiwanthatgirltobeonline___reallyamazingbeautiuflgirl[.]doc hxxp://23[.]94[.]36[.]162/4506/vnc[.]exe hxxp://178[.]215[.]236[.]229/TRBLCsIxmPWcv159[.]bin hxxp://178[.]215[.]236[.]229/Wordstars[.]csv hxxp://198[.]12[.]81[.]162/xampp/hur/beautifuldaystartedwithbeautiufllifeandrosetogetmeverynicethingsonmylifeialwaysloveandcarethethingstobegreatfulandbeautiulffo___revertoeverybody[.]doc hxxp://198[.]12[.]81[.]162/60590/spoolsv[.]exe hxxp://192[.]3[.]64[.]142/70900/vncx[.]exe |
Formbook |
URL | hxxp://94[.]156[.]8[.]210/akurg[.]exe hxxp://192[.]227[.]173[.]67/Ifeanyi[.]exe hxxp://192[.]227[.]173[.]67/xampp/bgu/beautifulthingstohappenedeverypointofviewtounderstandsheisgreatandbeautifultounderstandsheisgreatgirl___ireallyloveflowers[.]doc hxxps://api[.]telegram[.]org/bot7033508944:AAH7L9s0SGF-SvntnXPT9jk41drQhGs3fYU/ hxxps://api[.]telegram[.]org/bot7060813422:AAFqFKdMJlLvutqPAnHO4f8vnk2X1rQvsl0/ |
Agent Tesla |
URL | hxxps://pasteio[.]com/download/xyWOunnBqFsE hxxp://172[.]93[.]222[.]102/7090/vnb[.]exe hxxp://172[.]93[.]222[.]102/xampp/hgb/hg/beautifulroseflowerwanttogetinhandbecauseitsgreatthingshandbeautiuflthingshappenedtogetback___beautiuflflowers[.]doc hxxp://45[.]33[.]50[.]155/2202/hmk[.]txt hxxps://paste[.]ee/d/54WjO hxxp://45[.]33[.]50[.]155/2202/emo/beautifulimagesgetmebacktotheupdationtogetitbackagainfortheupdatessheisbeautiuflgirliknowverywell__iwanttogivekisstoherloverlips[.]doc hxxp://45[.]33[.]50[.]155/2202/sampleimagepixelupdated[.]jpg hxxp://94[.]156[.]68[.]134/rem[.]exe hxxps://pasteio[.]com/raw/xHsXld2c2eeu hxxp://dokdo[.]in/qET hxxps://dokdo[.]in/qET hxxp://104[.]168[.]32[.]29/xampp/vbg/beautifulthingshappeningwithbecautiuflwordssheisverynicegirlwhoilovedalotfromtheheartbeautifulgirlfrined__sheverynice[.]doc hxxp://104[.]168[.]32[.]29/80300/vncc[.]exe hxxps://polatfamilyengine[.]com/wp_doors/img-files/Gapsly[.]accdb hxxps://polatfamilyengine[.]com/wp_doors/img-files/1f9058b0-f4fd-4617-a4e9-21f640e729ed[.]accdb |
Remcos |
URL | hxxps://dukeenergyltd[.]top/loudzx[.]scr hxxps://franccoisfreres[.]com/PWS/fre[.]php hxxp://franccoisfreres[.]com/PWS/fre[.]php hxxp://sempersim[.]su/d2/fre[.]php |
LokiBot |
URL | hxxp://192[.]3[.]111[.]153/nmo/NMO[.]txt hxxps://paste[.]ee/d/w7yvh hxxp://192[.]3[.]111[.]153/nmo/nm/beautifulthingstobegreatwithgreatthingshappeningaroundthewordlsheisverybeautiuflgirlifoundsheisgood___girlineveryminutestoundrstand[.]doc hxxp://192[.]3[.]111[.]153/nmo/imagesoftherosearebeautiful[.]jpg |
Warzone RAT |
URL | hxxp://13[.]60[.]65[.]219:8080/lync[.]exe hxxp://16[.]170[.]254[.]73:8080/_ep2FFKAzWVHCEYJItoVwAYzPWkkCICO0k3guIeD hxxp://13[.]53[.]131[.]190:8080/T7pAcJijO5W3e7Z60qiKkgIbQQoP6rbMsig_dPfHn1F6kzv1p2_hbOVGIM1iSbt1qtn6ErvFdXNrJE-Nn |
Metasploit |
URL | hxxp://clean-master[.]tech/img/logo[.]jpg hxxp://clean-master[.]tech/img/logo2[.]jpg hxxp://5[.]42[.]96[.]64/server/ww12/AppGate2103v01[.]exe |
Lumma Stealer |
URL | hxxp://77[.]221[.]151[.]47/install[.]exe hxxp://195[.]15[.]201[.]129/xm[.]zip |
Coinminer |
URL | hxxp://bvewnuh[.]com/search/?q=67e28dd8395dfb2f495fac1e7c27d78406abdd88be4b12ebb517aa5c96bd86ed82df14d714bca5817673aa4ce8889b5e4fa9281ae978a771ea771795af8e05c645db22f31df92d8b38e316a667d307eca743ec4c2b07b52966923a6289ff10c0ed9d hxxp://bvewnuh[.]com/search/?q=67e28dd8395dfb2f495fac1e7c27d78406abdd88be4b12eab517aa5c96bd86e992854d845a8bbc896c58e713bc90c91936b5281fc235a925ed3e04d6bd974a95129070b616e96cc92be20ea778c255bbe258b90d3b4eed3233d1626a8ff810c5e8959b3bcf67 hxxp://beglbim[.]com/search/?q=67e28dd86b5bf57b435daf497c27d78406abdd88be4b12ebb517aa5c96bd86ed82df14d714bca5817673aa49e8889b5e4fa9281ae978f271ea771795af8e05c645db22f31dfe339426fa11af66c152adb719a9577e55b8603e983a608ffa16c0ee95983c hxxp://beglbim[.]com/search/?q=67e28dd86b5bf57b435daf497c27d78406abdd88be4b12eab517aa5c96bd86ee94834a885a8bbc896c58e713bc90c91c36b5281fc235a925ed3e51d6bd974a95129070b616e96cc92be510b866db52b2e34aec4c2b14a82966836f23d7f210c7ee909d3bcc6f9411 hxxp://erxjkgw[.]ua/search/?q=67e28dd83859fa2b145ba44a7c27d78406abdd88be4b12ebb517aa5c96bd86ed82df14d714bca5817673aa4de8889b5e4fa9281ae978a771ea771795af8e05c645db22f31df92d8b38e316a667d307eca743ec4c2b07b52966923a6289ff15c0ec97 hxxp://erxjkgw[.]ua/search/?q=67e28dd83859fa2b145ba44a7c27d78406abdd88be4b12eab517aa5c96bd86ec96874e885a8bbc896c58e713bc90c91836b5281fc235a925ed3e04d6bd974a95129070b616e96cc92be20ea778c255bbe258b90d3b4eed3233d1626a8ff810c5e8959e3bce6d hxxp://bdkpepl[.]com/search/?q=67e28dd83a5da32a155afd1b7c27d78406abdd88be4b12ebb517aa5c96bd86ed82df14d714bca5817673aa4ce8889b5e4fa9281ae978a271ea771795af8e05c645db22f31dfe339426fa11af66c152adb719a9577e55b8603e983a608ffa16c0eb959e3f hxxp://ckbsiqb[.]net/search/?q=67e28dd86a5ef62a130aa5197c27d78406abdd88be4b12ebb517aa5c96bd86ed82df14d714bca5817673aa4ce8889b5e4fa9281ae978a771ea771795af8e05c645db22f31df92d8b38e316a667d307eca743ec4c2b07b52966923a6289ff13c2ec96 hxxp://ckbsiqb[.]net/search/?q=67e28dd86a5ef62a130aa5197c27d78406abdd88be4b12eab517aa5c96bd86e891844a875a8bbc896c58e713bc90c91936b5281fc235a925ed3e04d6bd974a95129070b616e96cc92be20ea778c255bbe258b90d3b4eed3233d1626a8ff810c5e8959839ce6c hxxp://bphuaot[.]com/search/?q=67e28dd83e5cfa2f440afa1d7c27d78406abdd88be4b12ebb517aa5c96bd86ed82df14d714bca5817673aa4ce8889b5e4fa9281ae978a471ea771795af8e05c645db22f31dfe339426fa11af66c152adb719a9577e55b8603e983a608ffa16c0ed97993f hxxp://bphuaot[.]com/search/?q=67e28dd83e5cfa2f440afa1d7c27d78406abdd88be4b12eab517aa5c96bd86ec9d8445835a8bbc896c58e713bc90c91936b5281fc235a925ed3e07d6bd974a95129070b616e96cc92be510b866db52b2e34aec4c2b14a82966836f23d7f210c7ee909d3bcf6d9512 hxxp://bgveonv[.]com/search/?q=67e28dd83d5fa62d1358fa4d7c27d78406abdd88be4b12ebb517aa5c96bd86ed82df14d714bca5817673aa4de8889b5e4fa9281ae978ff71ea771795af8e05c645db22f31df92d8b38e316a667d307eca743ec4c2b07b52966923a6289ff16c6ec9c hxxp://bglskej[.]com/search/?q=67e28dd86d0ca420440ef91f7c27d78406abdd88be4b12ebb517aa5c96bd86ed82df14d714bca5817673aa49e8889b5e4fa9281ae978f671ea771795af8e05c645db22f31dfe339426fa11af66c152adb719a9577e55b8603e983a608ffa16c0e8939833 hxxp://bglskej[.]com/search/?q=67e28dd86d0ca420440ef91f7c27d78406abdd88be4b12eab517aa5c96bd86ec97824f885a8bbc896c58e713bc90c91c36b5281fc235a925ed3e55d6bd974a95129070b616e96cc92be510b866db52b2e34aec4c2b14a82966836f23d7f210c7ee909d3bca69941e hxxp://ddcjcux[.]info/search/?q=67e28dd86554fa2a495aa4197c27d78406abdd88be4b12ebb517aa5c96bd86ed82df14d714bca5817673aa4de8889b5e4fa9281ae978a071ea771795af8e05c645db22f31df92d8b38e316a667d307eca743ec4c2b07b52966923a6289ff17c4ec90 hxxp://aqerofp[.]ru/search/?q=67e28dd86c5cf27a4508ad177c27d78406abdd88be4b12ebb517aa5c96bd86ed82df14d714bca5817673aa4de8889b5e4fa9281ae978f771ea771795af8e05c645db22f31dfe339426fa11af66c152adb719a9577e55b8603e983a608ffa16c0e991993a hxxp://aqerofp[.]ru/search/?q=67e28dd86c5cf27a4508ad177c27d78406abdd88be4b12eab517aa5c96bd86ec97844c835a8bbc896c58e713bc90c91836b5281fc235a925ed3e54d6bd974a95129070b616e96cc92be510b866db52b2e34aec4c2b14a82966836f23d7f210c7ee909d3bcb6b9517 hxxp://dtyatfn[.]info/search/?q=67e28dd86554fa2a495aa4197c27d78406abdd88be4b12ebb517aa5c96bd86ed82df14d714bca5817673aa4de8889b5e4fa9281ae978a071ea771795af8e05c645db22f31df92d8b38e316a667d307eca743ec4c2b07b52966923a6289ff18c7ec95 hxxp://dtyatfn[.]info/search/?q=67e28dd86554fa2a495aa4197c27d78406abdd88be4b12eab517aa5c96bd86eb948248875a8bbc896c58e713bc90c91836b5281fc235a925ed3e03d6bd974a95129070b616e96cc92be20ea778c255bbe258b90d3b4eed3233d1626a8ff810c5e895933cce6f hxxp://bwimhid[.]com/search/?q=67e28dd86b5cf27c420ff9177c27d78406abdd88be4b12ebb517aa5c96bd86ed82df14d714bca5817673aa4ce8889b5e4fa9281ae978a371ea771795af8e05c645db22f31dfe339426fa11af66c152adb719a9577e55b8603e983a608ffa16c0e692983c hxxp://bwimhid[.]com/search/?q=67e28dd86b5cf27c420ff9177c27d78406abdd88be4b12eab517aa5c96bd86ef90874e835a8bbc896c58e713bc90c91936b5281fc235a925ed3e00d6bd974a95129070b616e96cc92be510b866db52b2e34aec4c2b14a82966836f23d7f210c7ee909d3bc4689411 hxxps://sneg[.]fastbutters[.]com/style/060[.]exe hxxp://bfggqql[.]com/search/?q=67e28dd83955a42b4006aa1b7c27d78406abdd88be4b12ebb517aa5c96bd86ed82df14d714bca5817673aa4ee8889b5e4fa9281ae978f671ea771795af8e05c645db22f31df92d8b38e316a667d307eca743ec4c2b07b52966923a6289fe13c1ec96 hxxp://ccrqooz[.]net/search/?q=67e28dd86d5cf57b120caf497c27d78406abdd88be4b12ebb517aa5c96bd86ed82df14d714bca5817673aa4ce8889b5e4fa9281ae978a371ea771795af8e05c645db22f31dfe339426fa11af66c152adb719a9577e55b8603e983a608ffa16c1ed94993b hxxp://ccrqooz[.]net/search/?q=67e28dd86d5cf57b120caf497c27d78406abdd88be4b12eab517aa5c96bd86e891844f825a8bbc896c58e713bc90c91936b5281fc235a925ed3e00d6bd974a95129070b616e96cc92be510b866db52b2e34aec4c2b14a82966836f23d7f210c7ee909d3acf6e9516 |
Socks5 Systemz |
URL | hxxp://62[.]234[.]2[.]198/up[.]rar | DarkComet |
URL | hxxp://flexiblemaria[.]com/iinkqrwu hxxp://flexiblemaria[.]com/umkglnks hxxp://91[.]222[.]173[.]186/iinkqrwu hxxp://91[.]222[.]173[.]186/umkglnks hxxp://104[.]238[.]135[.]111/ChromeUpdate[.]msi hxxps://newsarena[.]sbs/ChromeUpdate[.]msi hxxps://104[.]238[.]135[.]111/ChromeUpdate[.]msi |
DarkGate |
URL | hxxp://45[.]137[.]207[.]137/cbrbinaries/cbr[.]arm hxxp://45[.]137[.]207[.]137/cbr[.]arm |
Bashlite |
URL | hxxp://168[.]100[.]11[.]226/21372AA119DAB62FF66C4E6CE179C8CE[.]exe | DanaBot |
URL | hxxp://94[.]156[.]68[.]141/h9fmdW5/index[.]php | Amadey |
URL | hxxp://5[.]42[.]67[.]23/batushka/univ[.]exe hxxp://5[.]42[.]67[.]23/batushka/nine[.]exe hxxp://5[.]42[.]67[.]23/oorigg/univ[.]exe hxxp://5[.]42[.]67[.]23/dl[.]php?pub=mixfive/ hxxp://miles-and-more-kreditkartes[.]com/batushka/univ[.]exe hxxp://doggie-services[.]com/batushka/nine[.]exe hxxp://jobs-servers[.]com/batushka/nine[.]exe hxxp://miles-and-more-kreditkartes[.]com/batushka/nine[.]exe |
GCleaner |