サイバーリスク情報提供 Dアラート 特許取得済み

不正URLへのアクセス、不正メールの受信

メール受信した
弊社お客様
0 URLアクセスした
弊社お客様
1
2024/05/15
※2024/05/15 更新
マルウェア感染させると考えられるURLを検知(2024/05/15)
■IoC(※1)
Type: IOC: Signature:
URL hxxp://38[.]15[.]131[.]216/xDiAqOwvPZdOa69[.]bin
hxxp://185[.]29[.]9[.]120/ysmJZrSvph82[.]bin
hxxp://178[.]215[.]236[.]229/xFcYFZKQRkETQdPiA198[.]bin
hxxp://64[.]188[.]27[.]210/yBmSw127[.]bin
hxxp://178[.]215[.]236[.]229/Anodiserings[.]fla
hxxp://64[.]188[.]21[.]131/NZMqCEqKkx48[.]bin
hxxp://194[.]59[.]31[.]206/CDIJGWfZ253[.]bin
hxxp://86[.]38[.]225[.]41/ImunPfh144[.]bin
hxxp://86[.]38[.]225[.]41/PkVhOCfbTkJ41[.]bin
hxxp://162[.]245[.]190[.]151/AcRyaKHTvRvr120[.]bin
hxxps://veloutinebydelite[.]ro/statikeres[.]hhp
hxxps://ibllt[.]com/wp-admin/Pseudonoble[.]lzh
CloudEyE
URL hxxp://23[.]226[.]57[.]18/%E5%AD%A6%E6%9C%89%E4%BC%98%E6%95%99[.]apk
hxxp://23[.]226[.]57[.]2/%E5%AD%A6%E6%9C%89%E4%BC%98%E6%95%99[.]apk
hxxp://23[.]226[.]57[.]43/%E5%AD%A6%E6%9C%89%E4%BC%98%E6%95%99[.]apk
SpyMax
URL hxxp://13[.]60[.]65[.]219:8080/mimikats[.]ps1
hxxp://13[.]60[.]65[.]219:8080/test[.]ps1
MimiKatz
URL hxxp://13[.]60[.]65[.]219:8080/cmd[.]ps1
hxxp://1[.]14[.]192[.]93:443/Rpc
hxxps://13[.]232[.]63[.]18/cx
hxxp://103[.]148[.]151[.]179:8080/api/v1/async/info
hxxps://www[.]jumpsrever[.]top/__utm[.]gif
hxxp://47[.]117[.]174[.]198/_/scs/mail-static/_/js/
hxxps://89[.]187[.]28[.]116/j[.]ad
hxxp://36[.]111[.]191[.]33:8888/pixel
hxxp://13[.]232[.]63[.]18:8080/visit[.]js
hxxps://121[.]40[.]127[.]134:4443/ptj
hxxps://103[.]17[.]119[.]73/push
hxxp://45[.]136[.]14[.]91:9090/updates[.]rss
hxxp://service-kj4ef32e-1252578700[.]gz[.]tencentapigw[.]com[.]cn/api/x
hxxp://141[.]98[.]7[.]79/cm
hxxps://gov[.]vsj888[.]shop:8443/index[.]js
hxxp://192[.]3[.]24[.]157:801/ptj
hxxp://47[.]243[.]26[.]247:5000/activity
hxxp://47[.]92[.]96[.]144/push
hxxp://43[.]138[.]168[.]21:8098/dot[.]gif
hxxp://81[.]71[.]127[.]160:8888/visit[.]js
hxxps://43[.]143[.]110[.]110/en_US/all[.]js
hxxp://111[.]231[.]21[.]83/load
hxxp://43[.]138[.]222[.]123/dpixel
hxxp://23[.]95[.]65[.]198:2222/ptj
hxxp://110[.]41[.]21[.]173/ptj
hxxp://47[.]115[.]215[.]30:6666/visit[.]js
hxxp://123[.]57[.]85[.]206:50000/fwlink
hxxps://update[.]360safety[.]xyz:8443/IE9CompatViewList[.]xml
hxxps://vsj888[.]shop:2083/index[.]js
hxxps://47[.]243[.]26[.]247:5001/activity
hxxps://www[.]checktimes[.]top/promote/static/XV4SPLMOG
Cobalt Strike
URL hxxp://13[.]60[.]65[.]219:8080/meter2[.]exe Meterpreter
URL hxxps://tpu[.]schedule[.]golfballnutz[.]com/editContent
hxxps://jmd[.]members[.]openarmscv[.]com/editContent
FAKEUPDATES
URL hxxps://github[.]com/Synapsesys/Synapse/releases/download/ah/Discord[.]exe
hxxp://94[.]156[.]68[.]134/start[.]exe
hxxp://94[.]156[.]68[.]134/costs[.]zip
hxxp://94[.]156[.]68[.]134/regasms[.]exe
hxxp://94[.]156[.]68[.]134/costs[.]vbs
hxxp://94[.]156[.]68[.]134/MartDrum[.]exe
hxxp://5[.]42[.]96[.]7/lend/taskmgr[.]exe
AsyncRAT
URL hxxps://github[.]com/SetThreadExecutionState/ModifiedDiscordClient/raw/main/yar[.]exe XWorm
URL hxxp://bigcheeserodents[.]com/mcmaster-collective-agreement-faculty
hxxps://boisebrides[.]keydesigndevelopment[.]com/manual[.]php
hxxp://ikwilvanmijnpoloaf[.]nl/2023/06/08/secret-agreement-between-germany
hxxps://booking[.]chaletsphilippe[.]com/manual[.]php
hxxps://booking[.]intersport[.]it/manual[.]php
hxxps://bvp[.]ch/manual[.]php
hxxp://signcitysa[.]com/general-manager-role-key-responsibilities-and-legal-implications
hxxps://brastal[.]pl/manual[.]php
hxxps://bramafhu[.]pl/manual[.]php
hxxps://businesstraveller[.]pl/manual[.]php
GootLoader
URL hxxps://karakaplandalgada[.]shop/ZDQyN2NmOGEZOTIK/
hxxps://karakaplandalgada124[.]shop/ZDQyN2NmOGEZOTIK/
hxxps://kapankralda[.]top/ZDQyN2NmOGEZOTIK/
hxxps://karakaplandalgadadas[.]com/ZDQyN2NmOGEZOTIK/
hxxps://neredekalgelsn3[.]shop/ZDQyN2NmOGEZOTIK/
hxxps://kamarkadals53[.]shop/ZDQyN2NmOGEZOTIK/
hxxps://manavkaradas[.]shop/ZDQyN2NmOGEZOTIK/
hxxps://karacellalder[.]shop/ZDQyN2NmOGEZOTIK/
hxxps://kamaradas412[.]top/ZDQyN2NmOGEZOTIK/
hxxps://karadalganagerekta2[.]com/ZDQyN2NmOGEZOTIK/
Coper
URL hxxp://taketa[.]top/imageTocpuupdateApiTemporary[.]php DCRat
URL hxxps://covid19help[.]top/fpeace[.]scr
hxxps://bruta[.]pl/Monkeynut[.]emz
hxxps://bruta[.]pl/WSfBhsycdugbAkKJGNw168[.]bin
hxxp://23[.]94[.]36[.]162/xampp/lop/lo/everythinggoingfineandgreatwithbeautiuflthingstounderstandhowmuchsheisbeautiufleverytimeiwanthatgirltobeonline___reallyamazingbeautiuflgirl[.]doc
hxxp://23[.]94[.]36[.]162/4506/vnc[.]exe
hxxp://178[.]215[.]236[.]229/TRBLCsIxmPWcv159[.]bin
hxxp://178[.]215[.]236[.]229/Wordstars[.]csv
hxxp://198[.]12[.]81[.]162/xampp/hur/beautifuldaystartedwithbeautiufllifeandrosetogetmeverynicethingsonmylifeialwaysloveandcarethethingstobegreatfulandbeautiulffo___revertoeverybody[.]doc
hxxp://198[.]12[.]81[.]162/60590/spoolsv[.]exe
hxxp://192[.]3[.]64[.]142/70900/vncx[.]exe
Formbook
URL hxxp://94[.]156[.]8[.]210/akurg[.]exe
hxxp://192[.]227[.]173[.]67/Ifeanyi[.]exe
hxxp://192[.]227[.]173[.]67/xampp/bgu/beautifulthingstohappenedeverypointofviewtounderstandsheisgreatandbeautifultounderstandsheisgreatgirl___ireallyloveflowers[.]doc
hxxps://api[.]telegram[.]org/bot7033508944:AAH7L9s0SGF-SvntnXPT9jk41drQhGs3fYU/
hxxps://api[.]telegram[.]org/bot7060813422:AAFqFKdMJlLvutqPAnHO4f8vnk2X1rQvsl0/
Agent Tesla
URL hxxps://pasteio[.]com/download/xyWOunnBqFsE
hxxp://172[.]93[.]222[.]102/7090/vnb[.]exe
hxxp://172[.]93[.]222[.]102/xampp/hgb/hg/beautifulroseflowerwanttogetinhandbecauseitsgreatthingshandbeautiuflthingshappenedtogetback___beautiuflflowers[.]doc
hxxp://45[.]33[.]50[.]155/2202/hmk[.]txt
hxxps://paste[.]ee/d/54WjO
hxxp://45[.]33[.]50[.]155/2202/emo/beautifulimagesgetmebacktotheupdationtogetitbackagainfortheupdatessheisbeautiuflgirliknowverywell__iwanttogivekisstoherloverlips[.]doc
hxxp://45[.]33[.]50[.]155/2202/sampleimagepixelupdated[.]jpg
hxxp://94[.]156[.]68[.]134/rem[.]exe
hxxps://pasteio[.]com/raw/xHsXld2c2eeu
hxxp://dokdo[.]in/qET
hxxps://dokdo[.]in/qET
hxxp://104[.]168[.]32[.]29/xampp/vbg/beautifulthingshappeningwithbecautiuflwordssheisverynicegirlwhoilovedalotfromtheheartbeautifulgirlfrined__sheverynice[.]doc
hxxp://104[.]168[.]32[.]29/80300/vncc[.]exe
hxxps://polatfamilyengine[.]com/wp_doors/img-files/Gapsly[.]accdb
hxxps://polatfamilyengine[.]com/wp_doors/img-files/1f9058b0-f4fd-4617-a4e9-21f640e729ed[.]accdb
Remcos
URL hxxps://dukeenergyltd[.]top/loudzx[.]scr
hxxps://franccoisfreres[.]com/PWS/fre[.]php
hxxp://franccoisfreres[.]com/PWS/fre[.]php
hxxp://sempersim[.]su/d2/fre[.]php
LokiBot
URL hxxp://192[.]3[.]111[.]153/nmo/NMO[.]txt
hxxps://paste[.]ee/d/w7yvh
hxxp://192[.]3[.]111[.]153/nmo/nm/beautifulthingstobegreatwithgreatthingshappeningaroundthewordlsheisverybeautiuflgirlifoundsheisgood___girlineveryminutestoundrstand[.]doc
hxxp://192[.]3[.]111[.]153/nmo/imagesoftherosearebeautiful[.]jpg
Warzone RAT
URL hxxp://13[.]60[.]65[.]219:8080/lync[.]exe
hxxp://16[.]170[.]254[.]73:8080/_ep2FFKAzWVHCEYJItoVwAYzPWkkCICO0k3guIeD
hxxp://13[.]53[.]131[.]190:8080/T7pAcJijO5W3e7Z60qiKkgIbQQoP6rbMsig_dPfHn1F6kzv1p2_hbOVGIM1iSbt1qtn6ErvFdXNrJE-Nn
Metasploit
URL hxxp://clean-master[.]tech/img/logo[.]jpg
hxxp://clean-master[.]tech/img/logo2[.]jpg
hxxp://5[.]42[.]96[.]64/server/ww12/AppGate2103v01[.]exe
Lumma Stealer
URL hxxp://77[.]221[.]151[.]47/install[.]exe
hxxp://195[.]15[.]201[.]129/xm[.]zip
Coinminer
URL hxxp://bvewnuh[.]com/search/?q=67e28dd8395dfb2f495fac1e7c27d78406abdd88be4b12ebb517aa5c96bd86ed82df14d714bca5817673aa4ce8889b5e4fa9281ae978a771ea771795af8e05c645db22f31df92d8b38e316a667d307eca743ec4c2b07b52966923a6289ff10c0ed9d
hxxp://bvewnuh[.]com/search/?q=67e28dd8395dfb2f495fac1e7c27d78406abdd88be4b12eab517aa5c96bd86e992854d845a8bbc896c58e713bc90c91936b5281fc235a925ed3e04d6bd974a95129070b616e96cc92be20ea778c255bbe258b90d3b4eed3233d1626a8ff810c5e8959b3bcf67
hxxp://beglbim[.]com/search/?q=67e28dd86b5bf57b435daf497c27d78406abdd88be4b12ebb517aa5c96bd86ed82df14d714bca5817673aa49e8889b5e4fa9281ae978f271ea771795af8e05c645db22f31dfe339426fa11af66c152adb719a9577e55b8603e983a608ffa16c0ee95983c
hxxp://beglbim[.]com/search/?q=67e28dd86b5bf57b435daf497c27d78406abdd88be4b12eab517aa5c96bd86ee94834a885a8bbc896c58e713bc90c91c36b5281fc235a925ed3e51d6bd974a95129070b616e96cc92be510b866db52b2e34aec4c2b14a82966836f23d7f210c7ee909d3bcc6f9411
hxxp://erxjkgw[.]ua/search/?q=67e28dd83859fa2b145ba44a7c27d78406abdd88be4b12ebb517aa5c96bd86ed82df14d714bca5817673aa4de8889b5e4fa9281ae978a771ea771795af8e05c645db22f31df92d8b38e316a667d307eca743ec4c2b07b52966923a6289ff15c0ec97
hxxp://erxjkgw[.]ua/search/?q=67e28dd83859fa2b145ba44a7c27d78406abdd88be4b12eab517aa5c96bd86ec96874e885a8bbc896c58e713bc90c91836b5281fc235a925ed3e04d6bd974a95129070b616e96cc92be20ea778c255bbe258b90d3b4eed3233d1626a8ff810c5e8959e3bce6d
hxxp://bdkpepl[.]com/search/?q=67e28dd83a5da32a155afd1b7c27d78406abdd88be4b12ebb517aa5c96bd86ed82df14d714bca5817673aa4ce8889b5e4fa9281ae978a271ea771795af8e05c645db22f31dfe339426fa11af66c152adb719a9577e55b8603e983a608ffa16c0eb959e3f
hxxp://ckbsiqb[.]net/search/?q=67e28dd86a5ef62a130aa5197c27d78406abdd88be4b12ebb517aa5c96bd86ed82df14d714bca5817673aa4ce8889b5e4fa9281ae978a771ea771795af8e05c645db22f31df92d8b38e316a667d307eca743ec4c2b07b52966923a6289ff13c2ec96
hxxp://ckbsiqb[.]net/search/?q=67e28dd86a5ef62a130aa5197c27d78406abdd88be4b12eab517aa5c96bd86e891844a875a8bbc896c58e713bc90c91936b5281fc235a925ed3e04d6bd974a95129070b616e96cc92be20ea778c255bbe258b90d3b4eed3233d1626a8ff810c5e8959839ce6c
hxxp://bphuaot[.]com/search/?q=67e28dd83e5cfa2f440afa1d7c27d78406abdd88be4b12ebb517aa5c96bd86ed82df14d714bca5817673aa4ce8889b5e4fa9281ae978a471ea771795af8e05c645db22f31dfe339426fa11af66c152adb719a9577e55b8603e983a608ffa16c0ed97993f
hxxp://bphuaot[.]com/search/?q=67e28dd83e5cfa2f440afa1d7c27d78406abdd88be4b12eab517aa5c96bd86ec9d8445835a8bbc896c58e713bc90c91936b5281fc235a925ed3e07d6bd974a95129070b616e96cc92be510b866db52b2e34aec4c2b14a82966836f23d7f210c7ee909d3bcf6d9512
hxxp://bgveonv[.]com/search/?q=67e28dd83d5fa62d1358fa4d7c27d78406abdd88be4b12ebb517aa5c96bd86ed82df14d714bca5817673aa4de8889b5e4fa9281ae978ff71ea771795af8e05c645db22f31df92d8b38e316a667d307eca743ec4c2b07b52966923a6289ff16c6ec9c
hxxp://bglskej[.]com/search/?q=67e28dd86d0ca420440ef91f7c27d78406abdd88be4b12ebb517aa5c96bd86ed82df14d714bca5817673aa49e8889b5e4fa9281ae978f671ea771795af8e05c645db22f31dfe339426fa11af66c152adb719a9577e55b8603e983a608ffa16c0e8939833
hxxp://bglskej[.]com/search/?q=67e28dd86d0ca420440ef91f7c27d78406abdd88be4b12eab517aa5c96bd86ec97824f885a8bbc896c58e713bc90c91c36b5281fc235a925ed3e55d6bd974a95129070b616e96cc92be510b866db52b2e34aec4c2b14a82966836f23d7f210c7ee909d3bca69941e
hxxp://ddcjcux[.]info/search/?q=67e28dd86554fa2a495aa4197c27d78406abdd88be4b12ebb517aa5c96bd86ed82df14d714bca5817673aa4de8889b5e4fa9281ae978a071ea771795af8e05c645db22f31df92d8b38e316a667d307eca743ec4c2b07b52966923a6289ff17c4ec90
hxxp://aqerofp[.]ru/search/?q=67e28dd86c5cf27a4508ad177c27d78406abdd88be4b12ebb517aa5c96bd86ed82df14d714bca5817673aa4de8889b5e4fa9281ae978f771ea771795af8e05c645db22f31dfe339426fa11af66c152adb719a9577e55b8603e983a608ffa16c0e991993a
hxxp://aqerofp[.]ru/search/?q=67e28dd86c5cf27a4508ad177c27d78406abdd88be4b12eab517aa5c96bd86ec97844c835a8bbc896c58e713bc90c91836b5281fc235a925ed3e54d6bd974a95129070b616e96cc92be510b866db52b2e34aec4c2b14a82966836f23d7f210c7ee909d3bcb6b9517
hxxp://dtyatfn[.]info/search/?q=67e28dd86554fa2a495aa4197c27d78406abdd88be4b12ebb517aa5c96bd86ed82df14d714bca5817673aa4de8889b5e4fa9281ae978a071ea771795af8e05c645db22f31df92d8b38e316a667d307eca743ec4c2b07b52966923a6289ff18c7ec95
hxxp://dtyatfn[.]info/search/?q=67e28dd86554fa2a495aa4197c27d78406abdd88be4b12eab517aa5c96bd86eb948248875a8bbc896c58e713bc90c91836b5281fc235a925ed3e03d6bd974a95129070b616e96cc92be20ea778c255bbe258b90d3b4eed3233d1626a8ff810c5e895933cce6f
hxxp://bwimhid[.]com/search/?q=67e28dd86b5cf27c420ff9177c27d78406abdd88be4b12ebb517aa5c96bd86ed82df14d714bca5817673aa4ce8889b5e4fa9281ae978a371ea771795af8e05c645db22f31dfe339426fa11af66c152adb719a9577e55b8603e983a608ffa16c0e692983c
hxxp://bwimhid[.]com/search/?q=67e28dd86b5cf27c420ff9177c27d78406abdd88be4b12eab517aa5c96bd86ef90874e835a8bbc896c58e713bc90c91936b5281fc235a925ed3e00d6bd974a95129070b616e96cc92be510b866db52b2e34aec4c2b14a82966836f23d7f210c7ee909d3bc4689411
hxxps://sneg[.]fastbutters[.]com/style/060[.]exe
hxxp://bfggqql[.]com/search/?q=67e28dd83955a42b4006aa1b7c27d78406abdd88be4b12ebb517aa5c96bd86ed82df14d714bca5817673aa4ee8889b5e4fa9281ae978f671ea771795af8e05c645db22f31df92d8b38e316a667d307eca743ec4c2b07b52966923a6289fe13c1ec96
hxxp://ccrqooz[.]net/search/?q=67e28dd86d5cf57b120caf497c27d78406abdd88be4b12ebb517aa5c96bd86ed82df14d714bca5817673aa4ce8889b5e4fa9281ae978a371ea771795af8e05c645db22f31dfe339426fa11af66c152adb719a9577e55b8603e983a608ffa16c1ed94993b
hxxp://ccrqooz[.]net/search/?q=67e28dd86d5cf57b120caf497c27d78406abdd88be4b12eab517aa5c96bd86e891844f825a8bbc896c58e713bc90c91936b5281fc235a925ed3e00d6bd974a95129070b616e96cc92be510b866db52b2e34aec4c2b14a82966836f23d7f210c7ee909d3acf6e9516
Socks5 Systemz
URL hxxp://62[.]234[.]2[.]198/up[.]rar DarkComet
URL hxxp://flexiblemaria[.]com/iinkqrwu
hxxp://flexiblemaria[.]com/umkglnks
hxxp://91[.]222[.]173[.]186/iinkqrwu
hxxp://91[.]222[.]173[.]186/umkglnks
hxxp://104[.]238[.]135[.]111/ChromeUpdate[.]msi
hxxps://newsarena[.]sbs/ChromeUpdate[.]msi
hxxps://104[.]238[.]135[.]111/ChromeUpdate[.]msi
DarkGate
URL hxxp://45[.]137[.]207[.]137/cbrbinaries/cbr[.]arm
hxxp://45[.]137[.]207[.]137/cbr[.]arm
Bashlite
URL hxxp://168[.]100[.]11[.]226/21372AA119DAB62FF66C4E6CE179C8CE[.]exe DanaBot
URL hxxp://94[.]156[.]68[.]141/h9fmdW5/index[.]php Amadey
URL hxxp://5[.]42[.]67[.]23/batushka/univ[.]exe
hxxp://5[.]42[.]67[.]23/batushka/nine[.]exe
hxxp://5[.]42[.]67[.]23/oorigg/univ[.]exe
hxxp://5[.]42[.]67[.]23/dl[.]php?pub=mixfive/
hxxp://miles-and-more-kreditkartes[.]com/batushka/univ[.]exe
hxxp://doggie-services[.]com/batushka/nine[.]exe
hxxp://jobs-servers[.]com/batushka/nine[.]exe
hxxp://miles-and-more-kreditkartes[.]com/batushka/nine[.]exe
GCleaner
※1「i-FILTER」アクセスログを検索し端末を特定してください 不要なアクセスを避けるため、一部変更しております。 ■製品対応状況(※2) ▽i-FILTER(※3) ・[脅威情報サイト]カテゴリでブロック可能 ※2 ブロックの可否は各製品の設定によるため、実際の結果はアクセスログを参照してください。 ※3 暗号化された通信の場合は、SSL Adapterの設定を「利用」にする必要があります。
イベント・セミナー情報