不正URLへのアクセス、不正メールの受信
-
メール受信した
弊社お客様0社 URLアクセスした
弊社お客様1社 -
2025/04/23
※2025/04/23 更新
マルウェア感染させると考えられるURLを検知(2025/04/23)
■IoC(※1)
Type: | IOC: | Signature: |
---|---|---|
URL | hxxps://u1[.]electivewielder[.]digital/wo9c5skfmr[.]xi hxxps://u1[.]electivewielder[.]digital/mbyi5l7mt4[.]xi hxxps://u1[.]electivewielder[.]digital/h2nb73cb3v[.]xi hxxps://u1[.]electivewielder[.]digital/a0qydj9kd0[.]xi hxxps://vynen[.]icu/114a29f9f7a842b5b84186e3c2292ae7[.]txt hxxps://vynen[.]icu/fde187bff75e4f638331d5a31ef7d02f[.]txt hxxps://vynen[.]icu/236037287d3c4d26ba96c673d218ed3a[.]txt hxxps://vynen[.]icu/b2e2a6b1a50a4c4b8edbdea994bd6272[.]txt hxxps://u1[.]electivewielder[.]digital/1nle718udo[.]xi hxxps://vynen[.]icu/40b9327d1599486cb928d9d8654f8667[.]txt hxxps://vynen[.]icu/3e4ab3f83f4a4f09a53d0f2b390d3470[.]txt hxxps://vynen[.]icu/4ffd207ce7414259a524196d97b98a19[.]txt hxxps://vynen[.]icu/0fc5b62906f748f3a77bea8ea9dcce84[.]txt hxxps://vynen[.]icu/7a4daf6c42d1463a89c4ec229d60e4b9[.]txt hxxps://vynen[.]icu/734df85822ff45d298da792e0e81679c[.]txt hxxps://vynen[.]icu/96959f79e4554398a0db8557013718c7[.]txt hxxps://vynen[.]icu/17ce925df66e43eeb2e2a87dca9544a1[.]txt hxxps://vynen[.]icu/36b1618d7b2a42b7ae8c7626346c4ddd[.]txt hxxps://vynen[.]icu/5b6c776550c848edb0f934ca721ce538[.]txt hxxps://vynen[.]icu/d97d565e94b14ca09d6a59746c65928b[.]txt hxxps://vynen[.]icu/a42d276ab20042639e8951b1917280a8[.]txt hxxps://vynen[.]icu/299e72298c8e462fb30339042e77cee4[.]txt hxxps://u1[.]electivewielder[.]digital/19k9nhreu4[.]xi hxxps://vynen[.]icu/4e638bd1245d4b5b96c5d644e1a3b2a2[.]txt hxxps://vynen[.]icu/005b6c6101214922b60b00e869851a42[.]txt hxxps://vynen[.]icu/3dbb8bf4bb5b4d6888ddb4a84335c47e[.]txt hxxps://vynen[.]icu/ce2439d3ee754261965b6a459e764863[.]txt hxxps://vynen[.]icu/27d708b9508043b992c2ecc7ef631a23[.]txt hxxps://vynen[.]icu/12890681ac7a49bc82eea16c1b7d9a00[.]txt hxxps://vynen[.]icu/6ff960b5d433495ca4f2b16c8319b9bc[.]txt hxxps://vynen[.]icu/e1bfd37ba0034a7698c7945cdcee6526[.]txt hxxps://vynen[.]icu/f019cf207d1247b3919e65f3356ea08b[.]txt hxxps://vynen[.]icu/e856b4b4b4044aeb83803ce2d5fef481[.]txt hxxps://vynen[.]icu/74d1cba994be414ab1d6354090080548[.]txt hxxps://vynen[.]icu/1b00e3a5220343508ad9ebeaf3fafdcb[.]txt hxxps://vynen[.]icu/1e74e21dfb3a4be98c9a29bb61704e3e[.]txt hxxps://vynen[.]icu/d0e2c80cab674b598ede922b325a0116[.]txt hxxps://vynen[.]icu/f2de24fb2ab14436985a3ed06143b708[.]txt hxxps://vynen[.]icu/daf7006c651741a8a81da2c1d0d7c4da[.]txt hxxps://vynen[.]icu/1fe84587d3ac42749c799890bcd42874[.]txt hxxps://vynen[.]icu/0585f6adace248cf983b8493cc36a338[.]txt hxxps://vynen[.]icu/31ced4e58b71429ab4d3c1181864f1c5[.]txt hxxps://vynen[.]icu/f3b883326ef749c7885d943ba66d402e[.]txt hxxps://vynen[.]icu/2c574d8834a940e68d80c1f90c49b771[.]txt hxxps://vynen[.]icu/2ea948f911814b1789a53771b58ccdf2[.]txt hxxps://vynen[.]icu/4556fc4773dd4fd0a10f760c6a9aaef8[.]txt hxxps://vynen[.]icu/48fd807e82dd4c00a6c33e6d16eb9bbd[.]txt hxxps://vynen[.]icu/956277b46c064eb1a99f0925abe39a37[.]txt hxxps://vynen[.]icu/d142b7972f2843b9b0cec543700b1840[.]txt hxxps://vynen[.]icu/98efc091e634490daf75a4c0049f543c[.]txt hxxps://vynen[.]icu/ce692edcf41e4df3809d9cfacfaf0435[.]txt hxxps://vynen[.]icu/8438f56f582243ecbb532a9c3806fea1[.]txt hxxps://vynen[.]icu/e3062b5ab1b04356bb41c820da494319[.]txt hxxps://vynen[.]icu/5354d68f5a0f4fa7ad94719c6d72f194[.]txt hxxps://vynen[.]icu/c46fd66ef54a4e54a5d0da4b5ab9a232[.]txt hxxps://vynen[.]icu/55722610692d46acbc7ae1c81e7d1031[.]txt hxxps://vynen[.]icu/96e608bb89554b7197bb9fb1f251a089[.]txt hxxps://vynen[.]icu/a24f78e480d84e7584960d64886c8ad8[.]txt hxxps://vynen[.]icu/6d2fee3cd59d42ebaf505c573670c2b5[.]txt hxxps://vynen[.]icu/cedb0e0c2673480d87e29efb15dbb2cf[.]txt hxxps://vynen[.]icu/e898d6103c0b41e6a47941258fc62373[.]txt hxxps://vynen[.]icu/7d483528f46d4738ac015d8453ad2672[.]txt hxxps://vynen[.]icu/d47387388f264fc18f0c40dbbd6f9a18[.]txt hxxps://vynen[.]icu/51a9ef4b196643cb9cd44e317c863484[.]txt hxxps://vynen[.]icu/72fb5c01e45943dda2501c01bb900f4c[.]txt hxxps://vynen[.]icu/5e8e4e76ec9c4cae90e160369f0af0a6[.]txt hxxps://u1[.]electivewielder[.]digital/91pcby5i3e[.]xi hxxps://u1[.]electivewielder[.]digital/h5q0ygg5oi[.]xi hxxps://u1[.]electivewielder[.]digital/ahthcngexm[.]xi hxxps://u1[.]electivewielder[.]digital/qsxmwbgg53[.]xi hxxps://u1[.]electivewielder[.]digital/jnlawcfh0c[.]xi hxxps://u1[.]electivewielder[.]digital/d0umvzo7s5[.]xi hxxps://u1[.]electivewielder[.]digital/gt6mkl1lit[.]xi hxxps://u1[.]electivewielder[.]digital/niyqwvyfs3[.]xi hxxps://u1[.]electivewielder[.]digital/j32pqeaus0[.]xi |
ClearFake |
URL | hxxp://62[.]106[.]66[.]149/Sakura[.]sh hxxp://103[.]51[.]147[.]183/ntp hxxp://103[.]51[.]147[.]183/Sakura[.]sh hxxp://31[.]58[.]58[.]113/mrscythe[.]sh hxxp://82[.]24[.]200[.]71/r hxxp://82[.]24[.]200[.]71/k hxxp://82[.]24[.]200[.]71/n hxxp://82[.]24[.]200[.]71/f hxxp://82[.]24[.]200[.]71/g hxxp://82[.]24[.]200[.]71/e hxxp://82[.]24[.]200[.]71/t hxxp://82[.]24[.]200[.]71/v hxxp://82[.]24[.]200[.]71/m hxxp://82[.]24[.]200[.]71/s hxxp://82[.]24[.]200[.]71/c hxxp://82[.]24[.]200[.]71/l hxxp://82[.]24[.]200[.]71/u hxxp://82[.]24[.]200[.]71/tt/sh4 hxxp://82[.]24[.]200[.]71/vv/sh4 hxxp://82[.]24[.]200[.]71/tt/mips hxxp://82[.]24[.]200[.]71/vv/riscv32 hxxp://82[.]24[.]200[.]71/tt/mips64 hxxp://82[.]24[.]200[.]71/tt/armv5l hxxp://82[.]24[.]200[.]71/tt/mipsel64 hxxp://82[.]24[.]200[.]71/vv/armv4eb hxxp://82[.]24[.]200[.]71/vv/arc hxxp://82[.]24[.]200[.]71/vv/mips64 hxxp://82[.]24[.]200[.]71/vv/mips hxxp://82[.]24[.]200[.]71/tt/armv4eb hxxp://82[.]24[.]200[.]71/tt/armv6l hxxp://217[.]18[.]210[.]168/Demon[.]arm6 hxxp://217[.]18[.]210[.]168/Demon[.]ppc hxxp://217[.]18[.]210[.]168/Demon[.]i586 hxxp://217[.]18[.]210[.]168/Demon[.]arm4 hxxp://217[.]18[.]210[.]168/Demon[.]mips hxxp://217[.]18[.]210[.]168/Demon[.]sh4 hxxp://217[.]18[.]210[.]168/Demon[.]mpsl hxxp://217[.]18[.]210[.]168/bins[.]sh hxxp://217[.]18[.]210[.]168/Demon[.]sparc hxxp://217[.]18[.]210[.]168/Demon[.]x86 hxxp://217[.]18[.]210[.]168/Demon[.]arm5 hxxp://217[.]18[.]210[.]168/Demon[.]i686 hxxp://217[.]18[.]210[.]168/Demon[.]m68k |
Bashlite |
URL | hxxps://api[.]telegram[.]org/bot7708941755:AAESo20CaDDAOjLLtHQBUxBHzsPN6t2HmCk/sendMessage?chat_id=8161167655 hxxps://api[.]telegram[.]org/bot7902039985:AAH7eJ6DbkfepygByCwW_SS_mCd3wICFw9o/sendMessage?chat_id=671054766 hxxps://api[.]telegram[.]org/bot7563833743:AAGqp8ZlKOECgMPhdAq5I6-k3SMLKGbXjjY/sendMessage?chat_id=6403200178 hxxps://api[.]telegram[.]org/bot8089454501:AAEUAwGJnwKnjnWzV-_V3aqpvU28E05RJz4/sendMessage?chat_id=7886581547 |
MASS Logger |
URL | hxxps://api[.]telegram[.]org/bot7888839198:AAH6TMA_SV36t7oAaUnUAt3VGroqCWPydzg/sendMessage?chat_id=7426887626 | Snake Keylogger |
URL | hxxp://185[.]39[.]17[.]70/zgrnf/pik[.]ps1 | DCRat |
URL | hxxp://185[.]215[.]113[.]41/files/1401316133/zPXcqIt[.]exe | Vidar |
URL | hxxp://185[.]215[.]113[.]41/files/6957769607/iiybdCt[.]exe hxxps://docs2025[.]com[.]br/1xx[.]pdf hxxps://docs2025[.]com[.]br/1type[.]pdf hxxps://docs2025[.]com[.]br/1tronvbs[.]pdf hxxps://docs2025[.]com[.]br/1Execute[.]pdf hxxps://docs2025[.]com[.]br/1Framework[.]pdf hxxps://docs2025[.]com[.]br/1invoke[.]pdf hxxps://docs2025[.]com[.]br/1load[.]pdf hxxps://docs2025[.]com[.]br/1method[.]pdf hxxps://docs2025[.]com[.]br/1msg[.]pdf hxxps://docs2025[.]com[.]br/1runpe[.]pdf hxxps://docs2025[.]com[.]br/1tronbat[.]pdf hxxps://docs2025[.]com[.]br/1tronps1[.]pdf |
AsyncRAT |
URL | hxxp://185[.]215[.]113[.]41/files/1058602646/HeDEMmf[.]exe hxxps://longitudde[.]digital/wizu hxxps://latitudert[.]live/teui hxxps://kpiratetwrath[.]run/ytus hxxps://equatorf[.]run/reiq hxxps://hemispherexz[.]top/xapp hxxps://dstarofliught[.]top/wozd hxxps://climatologfy[.]top/kbud hxxps://naturesartgistry[.]today/api hxxps://wawrhamer[.]live/oigbh hxxps://wquilltayle[.]live/gksi hxxps://polandecor[.]digital/dugg hxxps://dsalaccgfa[.]top/gsooz hxxp://185[.]215[.]113[.]41/files/1448402890/T2t1yIo[.]exe hxxps://xhemispherexz[.]top/xapp hxxps://5equatorf[.]run/reiq hxxps://xclimatologfy[.]top/kbud hxxp://185[.]215[.]113[.]41/files/qqdoup/random[.]exe hxxp://185[.]215[.]113[.]44/luma/random[.]exe hxxp://185[.]215[.]113[.]41/luma/random[.]exe hxxps://turkeytzq[.]live/powk hxxps://c6quilltayle[.]live/gksi hxxps://mequatorf[.]run/reiq hxxps://plongitudde[.]digital/wizu hxxps://3hemispherexz[.]top/xapp |
Lumma Stealer |
URL | hxxp://185[.]39[.]17[.]162/download[.]php hxxp://185[.]39[.]17[.]239/download[.]php hxxp://185[.]215[.]113[.]59/Dy5h4kus/index[.]php hxxp://185[.]215[.]113[.]59/Dy5h4kus/Login[.]php |
Amadey |
URL | hxxps://umpmfss[.]top/files/index[.]php hxxps://umpmfss[.]top/files/loop[.]js hxxps://umpmfss[.]top/files/vis[.]php hxxps://manwithedhelp[.]top/files/vi[.]php hxxps://nettixx[.]com/4w2e[.]js hxxps://nettixx[.]com/js[.]php hxxps://cpanel[.]freein-deed[.]com/profileLayout hxxps://apelmerah[.]top/desk/loop[.]js hxxps://apelmerah[.]top/desk/vis[.]php hxxps://apelmerah[.]top/desk/index[.]php hxxps://secure[.]gatecollegesystem[.]com/profileLayout hxxps://jjpalace[.]com/4r3e[.]js hxxps://jjpalace[.]com/js[.]php |
FAKEUPDATES |
URL | hxxps://fuckhdmov[.]top/desk/loop[.]js hxxps://fuckhdmov[.]top/desk/select[.]js hxxps://fuckhdmov[.]top/desk/vis[.]php hxxps://itradepay[.]com/Key[.]zip hxxp://itradepay[.]com/Key[.]zip |
NetSupportManager RAT |
URL | hxxp://home[.]fivell5th[.]top/FBTjVCNVSpaXwPVFxYNX17 hxxp://home[.]sixbb6mn[.]top/jTNyqiIkTqrjLPexvdad174 hxxp://home[.]onebb1mn[.]top/guDuUgLBfcehRYlFfBKg174 |
CryptBot |
URL | hxxps://cpcalendars[.]auiesce[.]ru/Downloads/test hxxp://cpcalendars[.]constructionproject[.]cc/Downloads/test hxxps://mail[.]laritchan[.]com/Downloads/test hxxps://webmail[.]cracsiu[.]com/Downloads/test hxxps://cpcalendars[.]diercusn[.]com/Downloads/test hxxps://u3nj[.]quixotic4[.]com/Downloads/test hxxps://cpcalendars[.]edistrami[.]com/Downloads/test hxxps://ki46-mailscanner[.]000-0x2autxx-8yhx[.]cc/Downloads/test hxxps://cpanel[.]diercusn[.]com/Downloads/test hxxps://cpcalendars[.]abandone[.]ru/Downloads/test hxxps://cpanel[.]ralvinetp[.]com/Downloads/test hxxps://cpcontacts[.]tyamile[.]ru/Downloads/test hxxps://cpcontacts[.]diercusn[.]com/Downloads/test hxxps://cpcontacts[.]brazrice[.]ru/Downloads/test hxxp://mail[.]legacyplatformfile[.]info/Downloads/test hxxps://webdisk[.]abandone[.]ru/Downloads/test hxxps://www[.]keystonestratgy[.]com/Downloads/test hxxps://asd[.]tyamile[.]ru/Downloads/test hxxps://www[.]gelepicon[.]com/Downloads/test hxxps://cpcontacts[.]cracsiu[.]com/Downloads/test hxxp://cpcontacts[.]newprojectz[.]co/Downloads/test hxxp://mail[.]wetllands[.]co/Downloads/test hxxp://cpcalendars[.]accessdnsl[.]com/Downloads/test hxxp://webdisk[.]borubon-online[.]com/Downloads/test hxxp://mail[.]constructionproject[.]cc/Downloads/test hxxp://cpanel[.]vega101[.]com/Downloads/test hxxp://cpcontacts[.]omnl-uk[.]com/Downloads/test hxxp://cpcalendars[.]omnl-uk[.]com/Downloads/test hxxp://www[.]esigndocu[.]ru/Downloads/test hxxp://www[.]prictec-ps[.]com/Downloads/test hxxp://webmail[.]taelimsystem[.]vip/Downloads/test hxxp://www[.]workspacedoc[.]com/Downloads/test hxxp://www[.]steinbeis-europa[.]com/Downloads/test hxxp://www[.]viewsharedonlinefiles[.]com/Downloads/test hxxp://mail[.]emriateslogistics[.]com/Downloads/test hxxp://mail[.]qualityglobal[.]wiki/Downloads/test hxxp://qenor[.]solardetech[.]info/Downloads/test hxxp://webmail[.]enfamxb[.]com/Downloads/test hxxp://mail[.]file42shp[.]com/Downloads/test hxxp://webdisk[.]constructionproject[.]cc/Downloads/test hxxp://cpanel[.]qualityglobal[.]wiki/Downloads/test hxxp://mail[.]firexaue[.]com/Downloads/test hxxp://mail[.]steinbeis-europa[.]com/Downloads/test hxxp://webdisk[.]ketnplc[.]com/Downloads/test hxxp://mx[.]accessdnsl[.]com/Downloads/test hxxp://prum[.]crsetchic[.]com/Downloads/test hxxp://www[.]securedgofile[.]info/Downloads/test hxxp://webmail[.]ketnplc[.]com/Downloads/test hxxp://cpanel[.]lamperll[.]com/Downloads/test hxxps://mail[.]ratrislio[.]com/Downloads/test hxxps://mail[.]auiesce[.]ru/Downloads/test hxxps://mail[.]webbrewentzel[.]com/Downloads/test hxxps://cpcontacts[.]abandone[.]ru/Downloads/test hxxps://cpanel[.]quixotic4[.]com/Downloads/test hxxps://mail[.]ealacrity[.]ru/Downloads/test hxxps://www[.]sialtysic[.]com/Downloads/test hxxps://webdisk[.]tyamile[.]ru/Downloads/test hxxps://35fas[.]cracsiu[.]com/Downloads/test hxxps://www[.]ormoncion[.]com/Downloads/test hxxps://bxozc[.]brazenf[.]ru/Downloads/test hxxps://cpcalendars[.]brazenf[.]ru/Downloads/test hxxps://www[.]vorynexa[.]com/Downloads/test hxxps://cpcontacts[.]nateleybo[.]com/Downloads/test hxxps://mail[.]eighlereg[.]com/Downloads/test hxxps://mail[.]trioneyev[.]com/Downloads/test hxxps://cpanel[.]tyamile[.]ru/Downloads/test hxxps://cpanel[.]keystonestratgy[.]com/Downloads/test hxxps://cpcontacts[.]ealacrity[.]ru/Downloads/test hxxps://cpanel[.]edistrami[.]com/Downloads/test hxxps://cpcalendars[.]ralvinetp[.]com/Downloads/test hxxp://webmail[.]aaoun[.]com/Downloads/test hxxp://cpcalendars[.]landoradebalthazar[.]com/Downloads/test hxxp://mail[.]gdocudrive[.]com/Downloads/test hxxp://webmail[.]mercuirusint[.]com/Downloads/test hxxp://cpcalendars[.]7ntneg[.]com/Downloads/test hxxp://webmail[.]mondial-ae[.]com/Downloads/test hxxp://webdisk[.]vega101[.]com/Downloads/test hxxp://cpcalendars[.]borubon-online[.]com/Downloads/test hxxp://cpcontacts[.]sinoceancn[.]com/Downloads/test hxxp://webdisk[.]matenom[.]com/Downloads/test hxxp://cpcalendars[.]nvdcsadmin[.]org/Downloads/test hxxp://webdisk[.]cutterenergysolutions[.]info/Downloads/test hxxp://mail[.]ewsaustraila[.]com/Downloads/test hxxp://www[.]danfsos[.]com/Downloads/test hxxp://www[.]wetllands[.]co/Downloads/test hxxp://cpanel[.]landoradebalthazar[.]com/Downloads/test hxxp://mail[.]asnako[.]com/Downloads/test hxxp://webmail[.]qualityglobal[.]wiki/Downloads/test hxxp://8vq[.]allaeima[.]com/Downloads/test hxxp://www[.]constructionproject[.]cc/Downloads/test hxxp://www[.]greenmountain-no[.]com/Downloads/test hxxp://www[.]legacyplatformfile[.]info/Downloads/test hxxp://www[.]alva-technology[.]com/Downloads/test hxxp://mail[.]novapnagaea[.]com/Downloads/test hxxp://www[.]vega101[.]com/Downloads/test hxxp://www[.]cutterenergysolutions[.]info/Downloads/test hxxp://cpcalendars[.]mondial-ae[.]com/Downloads/test hxxp://webdisk[.]enfamxb[.]com/Downloads/test hxxp://webmail[.]lamperll[.]com/Downloads/test |
Emmenhtal |
URL | hxxp://102[.]98[.]85[.]161:39940/Mozi[.]m hxxp://102[.]97[.]107[.]119:50631/Mozi[.]m hxxp://182[.]124[.]232[.]215:48236/Mozi[.]m |
Mozi |
URL | hxxp://alien-training[.]com/award[.]pdf[.]exe | Meterpreter |
URL | hxxp://88[.]214[.]48[.]93/ea2cb15d61cc476f[.]php | Stealc |
URL | hxxp://185[.]39[.]17[.]162/testmine/random[.]exe | XWorm |
URL | hxxp://94[.]103[.]91[.]246/addInfection | GhostLocker |
URL | hxxp://195[.]3[.]223[.]110/ccYHMMSqVX193[.]bin hxxp://195[.]3[.]223[.]110/bGjToCA87[.]bin hxxps://watitoto6login[.]com/Kberen[.]lpk |
CloudEyE |
URL | hxxps://spectrumwireless[.]net/statement[.]exe | PureCrypter |
URL | hxxp://185[.]215[.]113[.]41/files/5804781818/eZp5zCz[.]exe | LockBit |
URL | hxxp://larisantiara[.]com/content/kentttttt[.]ps1 | Remcos |
URL | hxxp://185[.]215[.]113[.]44/files/unique2/random[.]exe hxxp://185[.]215[.]113[.]41/files/unique2/random[.]exe |
GCleaner |