不正URLへのアクセス、不正メールの受信
-
メール受信した
弊社お客様0社 URLアクセスした
弊社お客様4社 -
2025/03/24
※2025/03/24 更新
マルウェア感染させると考えられるURLを検知(2025/03/24)
■IoC(※1)
Type: | IOC: | Signature: |
---|---|---|
URL | hxxps://u1[.]anticsblooper[.]shop/v19d3frguk[.]mp3 hxxps://u1[.]anticsblooper[.]shop/2i7pv1xg7h[.]mp3 hxxps://u1[.]anticsblooper[.]shop/7npfk4jooo[.]mp3 hxxps://u1[.]anticsblooper[.]shop/pzznj8yb09[.]mp3 hxxps://u1[.]anticsblooper[.]shop/6bgykx5brj[.]mp3 hxxps://check[.]aytuna[.]icu/gkcxv[.]google hxxps://u1[.]anticsblooper[.]shop/q3q194mc8y[.]mp3 hxxps://u1[.]anticsblooper[.]shop/3lxylsz3xr[.]mp3 hxxps://check[.]oibupi[.]icu/gkcxv[.]google hxxps://u1[.]anticsblooper[.]shop/h0075m6rhk[.]mp3 hxxps://u1[.]anticsblooper[.]shop/dburnrtq7t[.]mp3 hxxps://u1[.]anticsblooper[.]shop/il6le0br1h[.]mp3 hxxps://u1[.]anticsblooper[.]shop/53m7iv6vm7[.]mp3 hxxps://check[.]yonuga[.]icu/gkcxv[.]google hxxps://check[.]eezedu[.]icu/gkcxv[.]google hxxps://check[.]eucudo[.]icu/gkcxv[.]google hxxps://u1[.]anticsblooper[.]shop/4adhwtvgml[.]mp3 hxxps://check[.]eozusa[.]icu/gkcxv[.]google hxxps://u1[.]anticsblooper[.]shop/t8ef8zvalf[.]mp3 hxxps://u1[.]anticsblooper[.]shop/sn0ivc0pms[.]mp3 hxxps://check[.]ioqoda[.]icu/gkcxv[.]google hxxps://check[.]oegebo[.]icu/gkcxv[.]google hxxps://u1[.]anticsblooper[.]shop/9g7blb3ipa[.]mp3 hxxps://u1[.]anticsblooper[.]shop/9nn5y6ij9e[.]mp3 hxxps://u1[.]anticsblooper[.]shop/staleakjkl[.]mp3 hxxps://u1[.]anticsblooper[.]shop/vh85odktui[.]mp3 hxxps://u1[.]anticsblooper[.]shop/bbnxgw0kl6[.]mp3 hxxps://u1[.]anticsblooper[.]shop/kth3ais7sb[.]mp3 hxxps://u1[.]anticsblooper[.]shop/mi2yz2a6gx[.]mp3 hxxps://u1[.]anticsblooper[.]shop/0j0bjodybf[.]mp3 hxxps://u1[.]anticsblooper[.]shop/7mlr9nhp62[.]mp3 hxxps://u1[.]dormitoryzoom[.]shop/kbt9pbq2qr[.]mp3 hxxps://u1[.]dormitoryzoom[.]shop/2zdz888kme[.]mp3 hxxps://u1[.]dormitoryzoom[.]shop/dm3oriol9j[.]mp3 hxxps://u1[.]dormitoryzoom[.]shop/8twojl66ch[.]mp3 hxxps://u1[.]dormitoryzoom[.]shop/c8c0yzr2ng[.]mp3 hxxps://check[.]ysozim[.]icu/gkcxv[.]google hxxps://check[.]ozotuk[.]icu/gkcxv[.]google hxxps://u1[.]dormitoryzoom[.]shop/9jhgm4gao6[.]mp3 hxxps://u1[.]dormitoryzoom[.]shop/smppqcrzun[.]mp3 hxxps://u1[.]dormitoryzoom[.]shop/fnclocgo1s[.]mp3 hxxps://u1[.]dormitoryzoom[.]shop/3pxblqlrcc[.]mp3 hxxps://u1[.]dormitoryzoom[.]shop/iz4ps4liac[.]mp3 hxxps://u1[.]dormitoryzoom[.]shop/udftkvy0qi[.]mp3 hxxps://u1[.]dormitoryzoom[.]shop/0e2yez3naj[.]mp3 hxxps://u1[.]dormitoryzoom[.]shop/7dmej2tbdz[.]mp3 hxxps://u1[.]dormitoryzoom[.]shop/o634qa4nta[.]mp3 hxxps://u1[.]dormitoryzoom[.]shop/pn4pjp1h20[.]mp3 hxxps://u1[.]dormitoryzoom[.]shop/fqcj89uxe1[.]mp3 hxxps://u1[.]dormitoryzoom[.]shop/iueghfjfxc[.]mp3 hxxps://u1[.]dormitoryzoom[.]shop/45q4hywmi7[.]mp3 hxxps://u1[.]dormitoryzoom[.]shop/d39abmy9wy[.]mp3 hxxps://u1[.]dormitoryzoom[.]shop/zywmy14kiq[.]mp3 hxxps://u1[.]dormitoryzoom[.]shop/tam21vjt3g[.]mp3 hxxps://u1[.]dormitoryzoom[.]shop/4vetwd26w0[.]mp3 hxxps://spacefyu[.]today/Gkeio hxxps://u1[.]dormitoryzoom[.]shop/0pjqp722r8[.]mp3 hxxps://u1[.]dormitoryzoom[.]shop/hofhu533ek[.]mp3 hxxps://u1[.]dormitoryzoom[.]shop/71qrf5eoak[.]mp3 hxxps://u1[.]dormitoryzoom[.]shop/f503mlg6cf[.]mp3 hxxps://u1[.]dormitoryzoom[.]shop/87tn6hc3hc[.]mp3 hxxps://u1[.]dormitoryzoom[.]shop/ew73q9rvx3[.]mp3 hxxps://u1[.]dormitoryzoom[.]shop/osaqogmxob[.]mp3 hxxps://u1[.]dormitoryzoom[.]shop/iqdwjvguww[.]mp3 hxxps://u1[.]dormitoryzoom[.]shop/gbaxvthz7e[.]mp3 hxxps://u1[.]dormitoryzoom[.]shop/w9ldo6spgy[.]mp3 hxxps://check[.]ohuxah[.]icu/gkcxv[.]google hxxps://check[.]ugarob[.]icu/gkcxv[.]google hxxps://u1[.]dormitoryzoom[.]shop/p6nkjo2eyg[.]mp3 hxxps://check[.]alosym[.]icu/gkcxv[.]google hxxps://check[.]equcym[.]icu/gkcxv[.]google hxxps://u1[.]issuingdingbat[.]shop/rvj600pbx9[.]mp3 hxxps://check[.]uzuqed[.]icu/gkcxv[.]google hxxps://u1[.]issuingdingbat[.]shop/d9fg2f0dr8[.]mp3 hxxps://check[.]ugodat[.]icu/gkcxv[.]google hxxps://u1[.]issuingdingbat[.]shop/u1p9tuuhnx[.]mp3 hxxps://u1[.]issuingdingbat[.]shop/tmptwiuuyk[.]mp3 hxxps://u1[.]issuingdingbat[.]shop/e37hfvea1z[.]mp3 hxxps://u1[.]issuingdingbat[.]shop/ke60e7lqtv[.]mp3 hxxps://u1[.]issuingdingbat[.]shop/rcknx2ojcz[.]mp3 hxxps://check[.]azaler[.]icu/gkcxv[.]google hxxps://check[.]fepub[.]icu/gkcxv[.]google hxxps://u1[.]issuingdingbat[.]shop/5rilgbxrly[.]mp3 hxxps://check[.]fidec[.]icu/gkcxv[.]google hxxps://u1[.]issuingdingbat[.]shop/99eog8zcwl[.]mp3 hxxps://u1[.]issuingdingbat[.]shop/ucrzx3wjj3[.]mp3 hxxps://u1[.]issuingdingbat[.]shop/h5porr3813[.]mp3 hxxps://u1[.]issuingdingbat[.]shop/v1xbn84agt[.]mp3 hxxps://u1[.]issuingdingbat[.]shop/zry1gvcat8[.]mp3 hxxps://u1[.]issuingdingbat[.]shop/apbckpnrf9[.]mp3 hxxps://u1[.]issuingdingbat[.]shop/ylbx7j5ek0[.]mp3 hxxps://u1[.]issuingdingbat[.]shop/57dwxjl9g3[.]mp3 |
ClearFake |
URL | hxxp://mostere[.]com:9002/9002[.]conf hxxp://huanyu3333[.]com:9001/9001[.]conf hxxps://dopeonsolana[.]info/MarchJuicyOrange[.]txt hxxps://github[.]com/Uelenka/supreme-spork/raw/refs/heads/main/RuntimeBroker[.]exe hxxps://raw[.]githubusercontent[.]com/Uelenka/supreme-spork/refs/heads/main/RuntimeBroker[.]exe |
Quasar RAT |
URL | hxxps://loycos[.]com/6a9k[.]js hxxps://loycos[.]com/js[.]php hxxps://computertecs[.]com/3h7k[.]js hxxps://loycos[.]com/1q2w[.]js hxxps://computertecs[.]com/js[.]php hxxps://kkmic[.]com/1q2w[.]js hxxps://kkmic[.]com/js[.]php hxxps://kkmic[.]com/4e6t[.]js hxxps://cryptohardware[.]shop/files/libeasier[.]js hxxps://cryptohardware[.]shop/files/index[.]php hxxps://cryptohardware[.]shop/files/fixxx[.]php hxxps://consumer-compare[.]com/comcat[.]zip |
FAKEUPDATES |
URL | hxxps://bv[.]yuoei[.]shop/7fbe5fb3ba958a77f17d1d400555809e71d86fe8999830c1[.]wpd hxxps://176[.]65[.]141[.]165:8587/0721217eab03d184996db/uihhm5or[.]adx0l hxxps://api[.]strawberry-fruit[.]shop/78fc5131525a9e8d335b1/192xrm94[.]kf4 hxxp://45[.]93[.]20[.]224/Reader/Build104[.]exe |
Rhadamanthys |
URL | hxxps://tripzlux[.]digital/login hxxps://marksmaner[.]live/api hxxps://yarmamenti[.]world/api hxxps://uarmoryarch[.]shop/api hxxps://7targett[.]top/api hxxps://trdipwise[.]bet/api hxxps://twripnest[.]bet/api hxxps://wilidern[.]life/api hxxps://touurista[.]life/api hxxps://knobnhook[.]icu/api hxxps://jetsetgo[.]life/api hxxps://getogfone[.]bet/api hxxps://gojeourney[.]life/api hxxps://gestaway[.]bet/api hxxps://pawgsitiv[.]icu/api hxxps://tourjoty[.]bet/api hxxps://flighbtgo[.]bet/api hxxps://jetnroad[.]bet/api hxxps://wandesrl[.]life/api hxxps://jellydpubli[.]icu/api hxxps://globekpey[.]bet/api hxxps://voyagenj[.]bet/api hxxps://leggbasind[.]icu/api hxxps://supjportsho[.]icu/api hxxps://crafottcage[.]icu/api hxxps://pepedeepz[.]icu/api hxxps://oemoutxlet[.]icu/api hxxps://stylefstore[.]icu/api hxxps://qattachmenta[.]icu/api hxxps://czovercabin[.]icu/api hxxps://gogetxto[.]life/api hxxps://touvrlane[.]bet/api hxxps://7weaponwo[.]life/api hxxps://esccapewz[.]run/ANSbwqy hxxps://travewlio[.]shop/ZNxbHi hxxps://touvrlane[.]bet/ASKwjq hxxps://sighbtseeing[.]shop/ASJnzh hxxps://advennture[.]top/GKsiio hxxps://targett[.]top/dsANGt hxxps://holidamyup[.]today/AOzkns hxxps://triplooqp[.]world/APowk hxxps://orbitrxh[.]shop/GIwuioe hxxps://h1[.]yyoiy[.]shop/750413b4e6897a671bc759e04597952a0be747830189873b[.]xlsm hxxps://kiserman[.]shop/mysteriousplay[.]mp3 hxxps://boomingdeals[.]shop/file3[.]bin hxxp://176[.]113[.]115[.]7/files/5780230317/KX7TDcm[.]exe hxxps://github[.]com/wer812/vbvgghjjio999000/raw/refs/heads/main/bnoaprihjatuasss[.]exe hxxps://l4weaponwo[.]life/api hxxps://h3[.]yyoiy[.]shop/087296f1dee69c2624b2eddca0f347c520eb5afc96080203[.]vstm hxxps://h2[.]yyoiy[.]shop/7fbe5fb3ba958a77f17d1d400555809e71d86fe8999830c1[.]wpd hxxps://hxptlqrz[.]store/forgot[.]mp3 hxxps://-targett[.]top/api hxxps://trekaolot[.]run/api hxxp://62[.]60[.]226[.]112/public_files/kkiFdAd[.]txt hxxp://62[.]60[.]226[.]112/public_files/dmgrgcp[.]txt hxxp://62[.]60[.]226[.]112/public_files/njcemid[.]txt hxxp://176[.]113[.]115[.]7/files/7001656225/OkH8IPF[.]exe hxxp://176[.]113[.]115[.]7/files/5780230317/tK0oYx3[.]exe |
Lumma Stealer |
URL | hxxp://192[.]3[.]95[.]138/215/easytogivebestthingswhichveryastmovingentire[.]hta hxxps://courtyardhealthcare[.]com/March/Edgeviewwebs[.]exe hxxp://104[.]168[.]7[.]32/xampp/swety/sheisverybeautifulgirlwithnicelipsandallgreat[.]png hxxp://144[.]91[.]127[.]5/xampp/milkmist/veryniceandgoodsweetmilkymistwhichtastty[.]png hxxp://144[.]91[.]127[.]5/xampp/nc/new_image[.]jpg hxxp://104[.]168[.]7[.]32/xampp/swety/sheisverybeautifulgirlwithnicelipsandallgreat[.]txt hxxp://109[.]172[.]87[.]111/115/mygirlbeautifuleveriseenmycutegirlsheismydear[.]txt hxxp://109[.]172[.]87[.]111/112/bestbeautifulthingsentiretimebetterresultsgive[.]hta hxxp://198[.]23[.]212[.]233/578/vfc[.]exe hxxp://217[.]154[.]16[.]81/233/sino/aminthebestdutyservicewithgreatnessgiveniaminthebestduty_______iaminthebestdutyservicewithgreatnessgiven______iaminthebestdutyservicewithgreatnessgiveniaminthe[.]doc hxxp://213[.]165[.]70[.]23/312/cros/nicepeoplesgoodpeoplesgreatskillforthepeoplesnice____________nicepeoplesgoodpeoplesgreatskillforthepeoplesnice_____________nicepeoplesgoodpeoplesgreatskillforthepeoplesnice[.]doc hxxp://69[.]48[.]201[.]40/255/ssen/oybestgirlformybestkissesevermybestgirl________mybestgirlformybestkissesever______mybestgirlformybestkissesevermybestgirlformybest[.]doc hxxp://192[.]3[.]95[.]138/xampp/amb/sweetbabaygirlwithmybestthinkingsevermademe[.]hta hxxp://176[.]65[.]144[.]3/FILE/KENNNTTT[.]ps1 hxxp://176[.]65[.]144[.]3/file/kenttt[.]ps1 hxxp://196[.]251[.]91[.]42/up/uploads/rcpro[.]exe hxxp://196[.]251[.]91[.]42/up/uploads/rclight[.]exe |
Remcos |
URL | hxxp://38[.]49[.]40[.]130/SB360[.]exe | MimiKatz |
URL | hxxps://api[.]telegram[.]org/bot8031163681:AAFH2N6BlT_hbhu2xWrmOscGz8sn0r9CGYs/ hxxps://api[.]telegram[.]org/bot7828202228:AAHkdf9t5lpLwaCERqNSg_8EuuR0ho-xJ5M/ hxxps://baijika[.]com/wp/sasw[.]exe hxxp://192[.]3[.]216[.]141/kumulallalaconstraints[.]vbs hxxp://176[.]65[.]144[.]3/file/MULK[.]ps1 |
Agent Tesla |
URL | hxxp://www[.]y-marketing-chef[.]online/u021 hxxp://www[.]yperfakeverse[.]xyz/m13o hxxp://www[.]ypham-japan[.]shop/m13o hxxp://www[.]yroisland[.]net/m13o hxxp://www[.]yvalikdigital[.]online/bs03 hxxp://www[.]zit[.]world/m13o hxxp://www[.]ziugsyw[.]xyz/m13o hxxp://www[.]zkcontents[.]xyz/h3wr hxxp://www[.]verythingchat[.]xyz/m13o hxxp://www[.]viddeos[.]red/m13o hxxp://www[.]video-games-39348[.]bond/h3wr hxxp://www[.]vitance[.]digital/bn02 hxxp://www[.]w88link[.]vip/h3wr hxxp://www[.]warehouse-inventory-39425[.]bond/h3wr hxxp://www[.]welding-jobs-27111[.]bond/h3wr hxxp://www[.]wiftloom[.]pics/bn02 hxxp://www[.]wlf[.]dev/bs03 hxxp://www[.]xpat-health-insurance-ng[.]online/bn02 hxxp://www[.]urkish-hair-268864660[.]click/bs03 hxxp://www[.]ursing-home-43203[.]bond/bn02 hxxp://www[.]urumsbicard[.]net/bs03 hxxp://www[.]ushgroup[.]info/m13o hxxp://www[.]usinesposte[.]cyou/u021 hxxp://www[.]uskomaras-gyor[.]net/u021 hxxp://www[.]uslim-dating-iocc5xdbns61[.]today/m13o hxxp://www[.]usshelter[.]net/bs03 hxxp://www[.]v-finance[.]info/bn02 hxxp://www[.]ugmentedmap[.]xyz/u021 hxxp://www[.]ulsedream[.]online/u021 hxxp://www[.]umidifier-74367[.]bond/bs03 hxxp://www[.]un20250227-23[.]fun/m13o hxxp://www[.]uperstash[.]xyz/bn02 hxxp://www[.]upiterassistant[.]xyz/bn02 hxxp://www[.]ureformula[.]shop/m13o hxxp://www[.]ubstrate360[.]xyz/bs03 hxxp://www[.]ucien[.]world/bs03 hxxp://www[.]ucky-win-spin[.]xyz/u021 hxxp://www[.]udes-kitchen[.]net/bs03 hxxp://www[.]uefana[.]biz/bn02 hxxp://www[.]uenstigesofas[.]today/bn02 hxxp://www[.]trongmindcheck[.]today/bn02 hxxp://www[.]trsfaa[.]shop/h3wr hxxp://www[.]twuytr[.]online/m13o hxxp://www[.]tyxtpzv[.]info/u021 hxxp://www[.]uaizhan[.]xyz/m13o hxxp://www[.]uantumnovamind[.]pro/u021 hxxp://www[.]swift[.]xyz/bs03 hxxp://www[.]taolishuxia[.]vip/h3wr hxxp://www[.]tarbeat-league[.]pro/bn02 hxxp://www[.]td0t[.]info/bn02 hxxp://www[.]technectar[.]top/h3wr hxxp://www[.]thaum[.]africa/h3wr hxxp://www[.]tp-jos178-a2[.]online/u021 hxxp://www[.]s2ega[.]live/u021 hxxp://www[.]sa-store[.]online/bs03 hxxp://www[.]sararossos[.]realtor/h3wr hxxp://www[.]sharedbtc[.]xyz/h3wr hxxp://www[.]sneakershopnowsportsale[.]shop/h3wr hxxp://www[.]spearsplatssplint[.]cloud/h3wr hxxp://www[.]ssetexcelstrongmanageroot[.]xyz/bs03 hxxp://www[.]sunday[.]cafe/h3wr hxxp://www[.]rice-artificial-886827482[.]click/m13o hxxp://www[.]riferrari[.]shop/m13o hxxp://www[.]riminal-mischief[.]cfd/bs03 hxxp://www[.]rodigy[.]world/u021 hxxp://www[.]rodigytools[.]xyz/u021 hxxp://www[.]rodirectiveconsultinghq[.]info/bn02 hxxp://www[.]romptsdesigns[.]xyz/bs03 hxxp://www[.]rooutfits[.]net/bs03 hxxp://www[.]rusthousestyle[.]sbs/u021 hxxp://www[.]ravelconverter[.]net/bn02 hxxp://www[.]raveline[.]tech/bs03 hxxp://www[.]ravelopedia[.]info/u021 hxxp://www[.]reamcloudbright[.]sbs/u021 hxxp://www[.]reameast[.]live/bn02 hxxp://www[.]reeseotool[.]pro/u021 hxxp://www[.]rendvault[.]fashion/m13o hxxp://www[.]rettvollmar[.]shop/m13o hxxp://www[.]rg-txtagstorefrontfze[.]world/bs03 hxxp://www[.]piccomms[.]net/bs03 hxxp://www[.]pidersandsparrowsgroup[.]info/u021 hxxp://www[.]pscaleluxury[.]net/u021 hxxp://www[.]pt-45[.]online/u021 hxxp://www[.]qsvuss[.]pics/h3wr hxxp://www[.]r33bz[.]online/m13o hxxp://www[.]radient777[.]xyz/u021 hxxp://www[.]radioplaylist[.]xyz/h3wr hxxp://www[.]railers[.]info/m13o hxxp://www[.]ovesmaps[.]online/bn02 hxxp://www[.]owbest[.]click/m13o hxxp://www[.]oworking-space-1[.]live/bs03 hxxp://www[.]p8uatwdpyjgafakp[.]cyou/h3wr hxxp://www[.]partmentflatart[.]xyz/m13o hxxp://www[.]pecoincopilot[.]xyz/bn02 hxxp://www[.]peekr[.]app/m13o hxxp://www[.]personal-loans-51463[.]bond/h3wr hxxp://www[.]opcorninc[.]lol/u021 hxxp://www[.]opculturebuzz[.]info/u021 hxxp://www[.]ork-from-home-vn3[.]click/u021 hxxp://www[.]osmetic-packaging-jobs[.]click/m13o hxxp://www[.]osss[.]shop/u021 hxxp://www[.]otdrones[.]shop/m13o hxxp://www[.]oughstorememorial[.]lifestyle/bs03 hxxp://www[.]ouseofisra-el[.]net/bs03 hxxp://www[.]ovepeace-jp[.]net/bn02 hxxp://www[.]onductlogicpioneergroupfirm[.]xyz/u021 hxxp://www[.]online-advertising-56759[.]bond/h3wr hxxp://www[.]online-advertising-61202[.]bond/h3wr hxxp://www[.]onlynaturalpetes[.]shop/h3wr hxxp://www[.]onstruction-jobs-92972[.]bond/m13o hxxp://www[.]oodwin-law[.]cfd/bs03 hxxp://www[.]ool-tools[.]xyz/u021 hxxp://www[.]ootball-coaching-40064[.]bond/bn02 hxxp://www[.]olar-systems-panels-18238[.]bond/m13o hxxp://www[.]ollectors[.]legal/bn02 hxxp://www[.]olominer[.]net/bn02 hxxp://www[.]olorityx[.]info/u021 hxxp://www[.]olourg[.]irish/bs03 hxxp://www[.]omaine-videlot[.]net/u021 hxxp://www[.]ombadillian[.]net/u021 hxxp://www[.]ompresormx1[.]today/m13o hxxp://www[.]on66my[.]xyz/bs03 hxxp://www[.]nvhotworx[.]net/h3wr hxxp://www[.]oans-credits-73480[.]bond/bs03 hxxp://www[.]odkacasino-333[.]buzz/bs03 hxxp://www[.]odltown[.]xyz/h3wr hxxp://www[.]ofas-district[.]world/bn02 hxxp://www[.]ohnmcafee[.]xyz/bs03 hxxp://www[.]ohnnywilly[.]tech/bn02 hxxp://www[.]olar-panel-jobs-13264[.]bond/h3wr hxxp://www[.]ngin[.]live/m13o hxxp://www[.]nifiedway[.]sbs/m13o hxxp://www[.]nipsvuesandbox[.]studio/bs03 hxxp://www[.]nnovativeworld[.]cyou/u021 hxxp://www[.]nomy[.]app/m13o hxxp://www[.]nopickayo[.]biz/bn02 hxxp://www[.]nuocjpg[.]info/h3wr hxxp://www[.]nventory-software-45680[.]bond/bn02 hxxp://www[.]nventory-software-91161[.]bond/bn02 hxxp://www[.]mybucketwish[.]net/h3wr hxxp://www[.]nagapa[.]irish/bs03 hxxp://www[.]namensk[.]info/bn02 hxxp://www[.]ndo777login[.]pro/u021 hxxp://www[.]ndosbobet888[.]net/u021 hxxp://www[.]nequaled-fang[.]shop/bn02 hxxp://www[.]nesuns[.]asia/h3wr hxxp://www[.]nfmod[.]net/bs03 hxxp://www[.]lp[.]cash/u021 hxxp://www[.]lwinabar[.]online/u021 hxxp://www[.]m128[.]xyz/bn02 hxxp://www[.]magicfurries[.]shop/h3wr hxxp://www[.]mallelectricarsgb[.]bond/m13o hxxp://www[.]martdrivecare[.]sbs/bn02 hxxp://www[.]mbeddedcopilot[.]xyz/u021 hxxp://www[.]men-health-64737[.]bond/h3wr hxxp://www[.]motrim[.]click/bs03 hxxp://www[.]lectro-hub[.]online/m13o hxxp://www[.]lectronics-engineering[.]cfd/bn02 hxxp://www[.]leganttreasuresboutique[.]info/bs03 hxxp://www[.]lifemeasures[.]net/h3wr hxxp://www[.]lil[.]lat/h3wr hxxp://www[.]lip-injections-74025[.]bond/h3wr hxxp://www[.]lomail[.]sbs/bs03 hxxp://www[.]lowavenue[.]info/bs03 hxxp://www[.]italbitez[.]info/m13o hxxp://www[.]itchen-remodeling-up[.]world/bs03 hxxp://www[.]ituttotienda[.]online/bs03 hxxp://www[.]ivepeace[.]asia/u021 hxxp://www[.]iverlakes[.]online/m13o hxxp://www[.]jolve[.]shop/h3wr hxxp://www[.]klopcy[.]xyz/bs03 hxxp://www[.]lberche[.]info/m13o hxxp://www[.]leartec[.]health/bs03 hxxp://www[.]inegameyz[.]digital/bn02 hxxp://www[.]influencer-marketing-81492[.]bond/h3wr hxxp://www[.]ingchunboxermagazine[.]net/u021 hxxp://www[.]intercall[.]tech/h3wr hxxp://www[.]ipsexshop[.]shop/m13o hxxp://www[.]irinevlerbombaci[.]xyz/bn02 hxxp://www[.]ishwasher-jobs-678341[.]today/m13o hxxp://www[.]istapro[.]shop/bn02 hxxp://www[.]itadelot[.]tech/u021 hxxp://www[.]idscomefirst[.]online/bs03 hxxp://www[.]ielosanantonio[.]online/bs03 hxxp://www[.]ifestylebonus[.]pro/bn02 hxxp://www[.]ijn-websupport[.]sbs/bs03 hxxp://www[.]illionblocks[.]xyz/u021 hxxp://www[.]ilybookstone[.]shop/bn02 hxxp://www[.]imilarityapi[.]xyz/m13o hxxp://www[.]imorraes[.]shop/m13o hxxp://www[.]impleq[.]xyz/u021 hxxp://www[.]hatgptstrategies[.]net/u021 hxxp://www[.]heap-flights-1466962[.]fyi/u021 hxxp://www[.]heneapolis[.]city/bn02 hxxp://www[.]hoangntran[.]net/h3wr hxxp://www[.]htravel[.]net/bn02 hxxp://www[.]hufi[.]pink/m13o hxxp://www[.]iberdata[.]xyz/bn02 hxxp://www[.]ictionworks[.]xyz/u021 hxxp://www[.]figment[.]company/h3wr hxxp://www[.]fine-to-fine[.]top/h3wr hxxp://www[.]fluorforesetgambes[.]cloud/h3wr hxxp://www[.]fusowostore[.]buzz/h3wr hxxp://www[.]fve88[.]win/bn02 hxxp://www[.]g100[.]beauty/bs03 hxxp://www[.]gcitgvop[.]online/bn02 hxxp://www[.]gents4b[.]online/bn02 hxxp://www[.]getthelook[.]app/h3wr hxxp://www[.]etnonna[.]app/u021 hxxp://www[.]evala[.]online/m13o hxxp://www[.]evmedia[.]info/bn02 hxxp://www[.]ewaraja[.]xyz/m13o hxxp://www[.]ex-in-wien[.]net/bs03 hxxp://www[.]exiqkfylkx[.]sbs/h3wr hxxp://www[.]eyond360[.]xyz/bn02 hxxp://www[.]f[.]delivery/u021 hxxp://www[.]ferrotypes[.]yachts/h3wr hxxp://www[.]epemog[.]online/bs03 hxxp://www[.]erforbedsets[.]shop/u021 hxxp://www[.]erfrootdarting[.]shop/u021 hxxp://www[.]ersonaai[.]shop/bn02 hxxp://www[.]ersondigital[.]shop/u021 hxxp://www[.]erspirexbrasil[.]online/bs03 hxxp://www[.]ertifiedfasting[.]info/m13o hxxp://www[.]estaking888[.]xyz/u021 hxxp://www[.]etafusion[.]tech/m13o hxxp://www[.]elegilgh[.]run/bs03 hxxp://www[.]eliverynacional[.]online/m13o hxxp://www[.]emvmaasbn[.]pro/m13o hxxp://www[.]enseitool[.]xyz/bs03 hxxp://www[.]ental-care-2762127[.]fyi/bs03 hxxp://www[.]ental-implants-58831[.]bond/m13o hxxp://www[.]entista-de-urgencia-us[.]online/u021 hxxp://www[.]enyore[.]community/bn02 hxxp://www[.]epeiroterbesestrepe[.]cloud/h3wr hxxp://www[.]ecnipack[.]click/u021 hxxp://www[.]edopen[.]net/bn02 hxxp://www[.]eet-new-people-88653[.]bond/bn02 hxxp://www[.]egalregistration[.]net/m13o hxxp://www[.]egreen[.]green/m13o hxxp://www[.]eishininternationalava[.]shop/bn02 hxxp://www[.]elegelhg[.]qpon/bs03 hxxp://www[.]elegelhg[.]watch/m13o hxxp://www[.]eleghegl[.]xyz/bs03 hxxp://www[.]driel[.]info/h3wr hxxp://www[.]eachassistant[.]xyz/bn02 hxxp://www[.]ealdirectiveteam[.]info/m13o hxxp://www[.]ealmsec[.]info/bs03 hxxp://www[.]ealthywayzone[.]online/m13o hxxp://www[.]ebatmalam[.]info/bn02 hxxp://www[.]ecafecito[.]net/bn02 hxxp://www[.]echstat[.]xyz/bn02 hxxp://www[.]cp[.]fun/bn02 hxxp://www[.]cremation-services-13702[.]bond/h3wr hxxp://www[.]crypt[.]xyz/m13o hxxp://www[.]cyma98[.]sbs/bs03 hxxp://www[.]d-agent[.]xyz/u021 hxxp://www[.]dalang[.]click/bs03 hxxp://www[.]digi-well[.]cloud/h3wr hxxp://www[.]digiprem[.]tech/h3wr hxxp://www[.]ccessibleeyecare[.]info/u021 hxxp://www[.]cenicroutes[.]net/u021 hxxp://www[.]circling[.]sbs/h3wr hxxp://www[.]cjams[.]autos/h3wr hxxp://www[.]co-vision[.]net/h3wr hxxp://www[.]cosflare[.]online/h3wr hxxp://www[.]ayundevtest[.]xyz/h3wr hxxp://www[.]b9s2e[.]buzz/h3wr hxxp://www[.]bjcwedding[.]xyz/m13o hxxp://www[.]botakempire-8[.]xyz/h3wr hxxp://www[.]brflix[.]online/h3wr hxxp://www[.]bytxop[.]online/u021 hxxp://www[.]camtech[.]online/bs03 hxxp://www[.]cas32[.]top/h3wr hxxp://www[.]assaumergerfunds[.]info/bs03 hxxp://www[.]atinafyava[.]shop/bs03 hxxp://www[.]atoto[.]online/bn02 hxxp://www[.]ava[.]design/bn02 hxxp://www[.]avadacasino21[.]buzz/bs03 hxxp://www[.]avenspar[.]xyz/bs03 hxxp://www[.]avillabandlebattus[.]cloud/h3wr hxxp://www[.]awspro4d[.]net/m13o hxxp://www[.]ay-id2299[.]info/u021 hxxp://www[.]anjau2[.]cfd/m13o hxxp://www[.]antoorschoonmaak-1628796[.]world/bs03 hxxp://www[.]appyhere[.]net/bn02 hxxp://www[.]aptops-for-sale[.]cfd/u021 hxxp://www[.]ar-loans-35530[.]bond/bn02 hxxp://www[.]arkettschleifen-dielen[.]online/bn02 hxxp://www[.]arlist[.]app/m13o hxxp://www[.]arlsjrmenu[.]net/m13o hxxp://www[.]artinspiration[.]net/h3wr hxxp://www[.]aifriendship[.]store/h3wr hxxp://www[.]aigeofsage[.]shop/bn02 hxxp://www[.]ailyhotdealstoday[.]world/m13o hxxp://www[.]aindirectiveteam[.]info/bs03 hxxp://www[.]ainiceria[.]pro/m13o hxxp://www[.]akaz-1882[.]shop/bn02 hxxp://www[.]aludmia[.]info/u021 hxxp://www[.]anashekwrites[.]net/u021 hxxp://www[.]99game[.]xyz/m13o hxxp://www[.]a911[.]xyz/h3wr hxxp://www[.]abianice-warszawska[.]online/bs03 hxxp://www[.]acacovip[.]bet/bn02 hxxp://www[.]acercoffeecompanyava[.]shop/bn02 hxxp://www[.]aceseek[.]online/m13o hxxp://www[.]ad-schandau-cruise1[.]today/u021 hxxp://www[.]adenauno1240[.]online/m13o hxxp://www[.]affiliate-marketing-16056[.]bond/h3wr hxxp://www[.]58bet[.]website/bs03 hxxp://www[.]5m4kj[.]net/u021 hxxp://www[.]5psjco[.]top/h3wr hxxp://www[.]68092[.]legal/h3wr hxxp://www[.]777-dental-implants-au-204[.]cfd/bn02 hxxp://www[.]777-dental-implants-au-204[.]cfd/u021 hxxp://www[.]77hashrate[.]xyz/bs03 hxxp://www[.]88p2p[.]xyz/m13o hxxp://www[.]89g[.]lol/bn02 hxxp://www[.]0ns[.]pro/bs03 hxxp://www[.]2345zxrtvc[.]homes/u021 hxxp://www[.]23t[.]xyz/bs03 hxxp://www[.]3-nine[.]net/m13o hxxp://www[.]355[.]loan/u021 hxxp://www[.]536386[.]xyz/h3wr hxxp://www[.]07391[.]mobi/u021 hxxp://172[.]245[.]123[.]24/170/ebc[.]exe hxxp://172[.]245[.]123[.]28/xampp/mtgf/170[.]hta hxxp://176[.]65[.]144[.]3/FILE/STEPH[.]ps1 hxxp://172[.]245[.]123[.]24/133/vfc[.]exe hxxp://176[.]65[.]144[.]3/file/YG[.]ps1 hxxp://176[.]65[.]144[.]3/file/GUYBIN[.]ps1 |
Formbook |
URL | hxxp://204[.]10[.]160[.]145/PzqnFOyZhsFpli222[.]bin hxxp://176[.]65[.]144[.]55/pZIkO233[.]bin |
CloudEyE |
URL | hxxps://meet-join[.]us/xbe/xz[.]vue hxxps://meet-join[.]us/xbe/xbe[.]vue hxxps://meet-join[.]us/xbe/x7[.]vue |
NetSupportManager RAT |
URL | hxxp://134[.]199[.]209[.]199/ht-jupit hxxp://142[.]93[.]224[.]147/ulinux-logs |
FindPOS |
URL | hxxp://192[.]3[.]101[.]146/75/nices[.]exe hxxp://192[.]3[.]101[.]146/xampp/ekmo/ekm/meguebestkingofinternationalkingscomingback[.]hta |
MASS Logger |
URL | hxxps://api[.]telegram[.]org/bot7469710327:AAFd_SRb0l1kKsCUeV6os4r7ufpnbWf2zEk/sendMessage?chat_id=5722673103 hxxps://api[.]telegram[.]org/bot8029392247:AAGJ17Hi6c8K28Lp4EnflGtHZAmiDJMm9Ig/sendMessage?chat_id=7481206208 hxxps://api[.]telegram[.]org/bot7624982458:AAF_lSk1IxZpF5LbOLsMBtaySzHpr-2Roy0/sendMessage?chat_id=1294593001 hxxps://api[.]telegram[.]org/bot7668280137:AAFzc522qBc8Oo76R8B1lNylK2GNutE-msA/sendMessage?chat_id=2135869667 |
Snake Keylogger |
URL | hxxp://198[.]23[.]212[.]233/550/cvvs[.]exe | DBatLoader |
URL | hxxp://62[.]60[.]226[.]108:8000/login/?next=/ | Gorilla |
URL | hxxps://brightmind67[.]sbs/YzhjOGJlMmZkNzNi | Coper |
URL | hxxps://casettalecese[.]it/wp-content/uploads/2022/10/hemigastrectomySDur[.]php hxxps://elektrablasi[.]it/wp-content/uploads/2020/02/patrolwomen1gX[.]php hxxps://casettalecese[.]it/wp-content/uploads/2022/10/bivalviaGrr[.]php hxxps://www[.]centralelatterieti[.]com/wp-content/uploads/2020/commendedtz4[.]php hxxp://185[.]14[.]31[.]13/wp-content/includes/propugnaculum51[.]php hxxps://casettalecese[.]it/wp-content/uploads/2022/10 hxxp://94[.]247[.]42[.]253/pilot[.]php hxxp://185[.]14[.]31[.]13/drawtubes[.]php |
Koi Loader |
URL | hxxp://77[.]90[.]153[.]241/a07daa7aeaf96e14/sqlite3[.]dll hxxp://77[.]90[.]153[.]241/a07daa7aeaf96e14/softokn3[.]dll hxxp://77[.]90[.]153[.]241/a07daa7aeaf96e14/msvcp140[.]dll hxxp://77[.]90[.]153[.]241/a07daa7aeaf96e14/mozglue[.]dll hxxp://77[.]90[.]153[.]241/a07daa7aeaf96e14/nss3[.]dll hxxp://77[.]90[.]153[.]241/a07daa7aeaf96e14/vcruntime140[.]dll hxxp://77[.]90[.]153[.]241/a07daa7aeaf96e14/freebl3[.]dll |
Stealc |
URL | hxxp://104[.]245[.]240[.]20/[.]puscarie/[.]report_system hxxp://104[.]245[.]240[.]20/[.]puscarie/[.]main hxxps://bitbucket[.]org/dasdasdasd5h656/rthrthrth/raw/90b74e469487f7a993c3909b4654750040c22c2f/MinD[.]exe hxxp://185[.]215[.]113[.]66/x[.]exe |
Coinminer |
URL | hxxp://39[.]104[.]25[.]13:8111/02[.]08[.]2022[.]exe hxxp://8[.]155[.]44[.]213:7001/02[.]08[.]2022[.]exe hxxp://42[.]186[.]17[.]183:8080/02[.]08[.]2022[.]exe hxxp://148[.]66[.]2[.]198/02[.]08[.]2022[.]exe hxxp://192[.]241[.]195[.]81/02[.]08[.]2022[.]exe hxxp://148[.]66[.]2[.]197/02[.]08[.]2022[.]exe hxxp://148[.]66[.]2[.]196/02[.]08[.]2022[.]exe hxxp://113[.]44[.]194[.]13:6666/02[.]08[.]2022[.]exe hxxp://47[.]109[.]159[.]25:29524/02[.]08[.]2022[.]exe hxxp://101[.]43[.]166[.]60:6666/02[.]08[.]2022[.]exe hxxp://107[.]189[.]2[.]38:8089/02[.]08[.]2022[.]exe hxxp://101[.]126[.]87[.]67:8004/02[.]08[.]2022[.]exe hxxp://213[.]94[.]218[.]22/02[.]08[.]2022[.]exe hxxp://101[.]126[.]87[.]67:8001/02[.]08[.]2022[.]exe hxxp://112[.]53[.]96[.]114:9090/02[.]08[.]2022[.]exe hxxp://148[.]66[.]2[.]194/02[.]08[.]2022[.]exe hxxp://148[.]66[.]2[.]195/02[.]08[.]2022[.]exe hxxp://124[.]71[.]161[.]5:50000/02[.]08[.]2022[.]exe hxxp://1[.]95[.]212[.]120/02[.]08[.]2022[.]exe hxxp://1[.]94[.]185[.]235:9090/02[.]08[.]2022[.]exe hxxp://8[.]148[.]20[.]113:2222/02[.]08[.]2022[.]exe hxxp://103[.]27[.]109[.]184:8000/02[.]08[.]2022[.]exe hxxp://101[.]36[.]127[.]225:9666/02[.]08[.]2022[.]exe hxxp://101[.]42[.]18[.]6:9999/02[.]08[.]2022[.]exe hxxp://1[.]14[.]123[.]213:7777/02[.]08[.]2022[.]exe hxxp://142[.]171[.]116[.]94/02[.]08[.]2022[.]exe hxxp://120[.]26[.]226[.]30/02[.]08[.]2022[.]exe hxxp://43[.]138[.]54[.]95/02[.]08[.]2022[.]exe hxxp://20[.]83[.]148[.]22/02[.]08[.]2022[.]exe hxxp://47[.]92[.]211[.]202:4321/02[.]08[.]2022[.]exe hxxp://47[.]103[.]98[.]3:50051/02[.]08[.]2022[.]exe hxxp://101[.]35[.]228[.]105:20080/02[.]08[.]2022[.]exe hxxp://47[.]95[.]8[.]59:808/02[.]08[.]2022[.]exe hxxp://118[.]31[.]16[.]216:81/02[.]08[.]2022[.]exe hxxp://1[.]15[.]34[.]67:7777/02[.]08[.]2022[.]exe hxxp://47[.]112[.]118[.]101:1234/02[.]08[.]2022[.]exe hxxp://47[.]243[.]99[.]248/02[.]08[.]2022[.]exe hxxp://47[.]239[.]236[.]221:8087/02[.]08[.]2022[.]exe hxxp://39[.]107[.]242[.]125/02[.]08[.]2022[.]exe hxxp://124[.]221[.]47[.]70:19999/02[.]08[.]2022[.]exe hxxp://1[.]94[.]117[.]32/02[.]08[.]2022[.]exe hxxp://154[.]219[.]96[.]203/02[.]08[.]2022[.]exe hxxp://154[.]92[.]14[.]41:2999/02[.]08[.]2022[.]exe hxxp://124[.]222[.]81[.]106:8888/02[.]08[.]2022[.]exe hxxp://39[.]107[.]242[.]125:666/02[.]08[.]2022[.]exe hxxp://47[.]97[.]96[.]34/02[.]08[.]2022[.]exe hxxp://8[.]138[.]33[.]224/02[.]08[.]2022[.]exe hxxp://64[.]23[.]128[.]110/02[.]08[.]2022[.]exe hxxp://43[.]160[.]201[.]195:6666/02[.]08[.]2022[.]exe hxxp://47[.]117[.]147[.]55/02[.]08[.]2022[.]exe hxxp://113[.]44[.]194[.]13:4444/02[.]08[.]2022[.]exe hxxp://139[.]155[.]239[.]97/02[.]08[.]2022[.]exe hxxp://213[.]94[.]218[.]23/02[.]08[.]2022[.]exe hxxp://113[.]44[.]154[.]245:8099/02[.]08[.]2022[.]exe hxxp://40[.]81[.]23[.]3:23898/02[.]08[.]2022[.]exe hxxp://213[.]94[.]218[.]17/02[.]08[.]2022[.]exe hxxp://213[.]94[.]218[.]16/02[.]08[.]2022[.]exe hxxp://213[.]94[.]218[.]21/02[.]08[.]2022[.]exe hxxp://213[.]94[.]218[.]19/02[.]08[.]2022[.]exe hxxp://213[.]94[.]218[.]18/02[.]08[.]2022[.]exe hxxp://13[.]200[.]162[.]35:7777/02[.]08[.]2022[.]exe hxxp://47[.]99[.]169[.]201/02[.]08[.]2022[.]exe hxxp://124[.]221[.]41[.]140:5555/02[.]08[.]2022[.]exe hxxp://103[.]12[.]149[.]85/02[.]08[.]2022[.]exe hxxp://39[.]103[.]57[.]189/02[.]08[.]2022[.]exe hxxp://47[.]100[.]176[.]218:7777/02[.]08[.]2022[.]exe hxxp://1[.]94[.]249[.]10:81/02[.]08[.]2022[.]exe hxxp://1[.]94[.]249[.]10/02[.]08[.]2022[.]exe hxxp://1[.]94[.]249[.]10:2000/02[.]08[.]2022[.]exe hxxp://1[.]92[.]142[.]27/02[.]08[.]2022[.]exe |
Cobalt Strike |
URL | hxxps://github[.]com/AnonAm0369/am/raw/refs/heads/main/RuntimeBroker[.]exe | NjRAT |
URL | hxxps://texasdispatchers[.]com/PDF[.]exe hxxp://196[.]251[.]84[.]175/Documents/CLAIM3456709[.]lnk |
DanaBot |
URL | hxxp://45[.]151[.]62[.]199/Documents/plplo5[.]lnk hxxp://45[.]151[.]62[.]199/Documents/testo[.]lnk hxxp://45[.]151[.]62[.]199/Documents/testo2[.]lnk hxxp://voozaak[.]ru/Documents/testo2[.]lnk hxxp://voozaak[.]ru/Documents/testo[.]lnk hxxp://voozaak[.]ru/Documents/plplo5[.]lnk |
QakBot |
URL | hxxp://176[.]65[.]144[.]3/file/xenn[.]ps1 | RedLine Stealer |
URL | hxxp://45[.]125[.]66[.]136:18080/sb | Pink |
URL | hxxp://196[.]251[.]91[.]42/up/uploads/encryption02[.]jpg hxxp://196[.]251[.]91[.]42/up/uploads/File[.]bat |
XWorm |
URL | hxxps://telete[.]in/char0nsevenll | Raccoon |
URL | hxxps://bitbucket[.]org/mcafee-online/hodh009/downloads/XClient3[.]exe hxxps://bitbucket[.]org/mcafee-online/hodh009/downloads/ConsoleApp1[.]exe hxxps://bitbucket[.]org/mcafee-online/hodh009/downloads/XClient2[.]exe hxxp://196[.]251[.]91[.]42/up/uploads/SDR[.]exe hxxp://196[.]251[.]91[.]42/up/uploads/SKD[.]exe hxxp://196[.]251[.]91[.]42/up/uploads/LAP97[.]exe hxxp://196[.]251[.]91[.]42/up/uploads/SP/1908[.]exe hxxp://196[.]251[.]91[.]42/up/uploads/SP/1909[.]exe hxxp://196[.]251[.]91[.]42/up/uploads/dsl[.]exe hxxp://196[.]251[.]91[.]42/up/uploads/1909[.]exe hxxp://196[.]251[.]91[.]42/up/uploads/1908[.]exe |
AsyncRAT |
URL | hxxp://45[.]93[.]20[.]28/test/exe/random[.]exe hxxp://185[.]215[.]113[.]209/Di0Her478/Login[.]php hxxp://185[.]208[.]158[.]116/bVoZEtTa1/Login[.]php |
Amadey |
URL | hxxp://174[.]138[.]23[.]254/boom/LB3[.]exe | LockBit |
URL | hxxp://89[.]169[.]13[.]30/api/YTAsODYsODIsOWQsYTEsODgsOTAsOTUsNjUsN2Qs | SmartLoader |
URL | hxxp://194[.]180[.]158[.]53/bins[.]sh hxxp://194[.]180[.]158[.]53/yakuza[.]mips hxxp://194[.]180[.]158[.]53/yakuza[.]x32 hxxp://194[.]180[.]158[.]53/yakuza[.]i586 hxxp://194[.]180[.]158[.]53/yakuza[.]arm4 hxxp://194[.]180[.]158[.]53/yakuza[.]sh4 hxxp://194[.]180[.]158[.]53/yakuza[.]m68k hxxp://194[.]180[.]158[.]53/yakuza[.]ppc hxxp://194[.]180[.]158[.]53/yakuza[.]arm6 hxxp://194[.]180[.]158[.]53/yakuza[.]mpsl |
Bashlite |
URL | hxxp://107[.]174[.]192[.]179/app/laf6w_001[.]exe hxxp://107[.]174[.]192[.]179/app/d3jhg_003[.]exe |
DarkVision RAT |
URL | hxxps://befukiv[.]com/cortina hxxps://befukiv[.]com/muchaspuchas |
Anatsa |
URL | hxxp://176[.]113[.]115[.]7/files/wolfgangalive0/xmsn[.]exe | Tofsee |