サイバーリスク情報提供 Dアラート 特許取得済み

不正URLへのアクセス、不正メールの受信

メール受信した
弊社お客様
0 URLアクセスした
弊社お客様
1
2025/04/24
※2025/04/24 更新
マルウェア感染させると考えられるURLを検知(2025/04/24)
■IoC(※1)
Type: IOC: Signature:
URL hxxps://u1[.]electivewielder[.]digital/3hj0u7zdm9[.]xi
hxxps://u1[.]electivewielder[.]digital/ayr4a6jcu1[.]xi
hxxps://u1[.]electivewielder[.]digital/qmqn50fetk[.]xi
hxxps://u1[.]electivewielder[.]digital/hcijgmmwub[.]xi
hxxps://u1[.]electivewielder[.]digital/9snen6tn3k[.]xi
hxxps://u1[.]electivewielder[.]digital/psjgs4ne14[.]xi
hxxps://u1[.]electivewielder[.]digital/eeg97l4220[.]xi
hxxps://u1[.]electivewielder[.]digital/ymqdpwjrwl[.]xi
hxxps://u1[.]electivewielder[.]digital/hwq42jh6mb[.]xi
hxxps://u1[.]electivewielder[.]digital/8k2907259r[.]xi
hxxps://u1[.]electivewielder[.]digital/gj8mq44oxk[.]xi
hxxps://u1[.]electivewielder[.]digital/im43a14zzg[.]xi
hxxps://u1[.]electivewielder[.]digital/7s5gig4r75[.]xi
hxxps://u1[.]electivewielder[.]digital/3g44a5fe7g[.]xi
hxxps://u1[.]electivewielder[.]digital/w8q7aoj8vv[.]xi
hxxps://u1[.]electivewielder[.]digital/2ct8aql7w0[.]xi
hxxps://u1[.]electivewielder[.]digital/vxjyfqz1z2[.]xi
hxxps://u1[.]electivewielder[.]digital/yf0mj29lyl[.]xi
hxxps://u1[.]electivewielder[.]digital/a3cnr4qiq3[.]xi
hxxps://u1[.]electivewielder[.]digital/nmhjld12f6[.]xi
hxxps://u1[.]putdownpopcorn[.]digital/yh11n0009q[.]xi
hxxps://u1[.]putdownpopcorn[.]digital/n0cb27mell[.]xi
hxxps://u1[.]putdownpopcorn[.]digital/aye3fqeerk[.]xi
ClearFake
URL hxxps://ilongitudde[.]digital/wizu
hxxps://wn[.]sg/file[.]exe
hxxps://wn[.]sg/script[.]ps1
hxxp://193[.]233[.]113[.]11:6565/rcMoI_random[.]exe
hxxps://1zlatitudert[.]live/teui
hxxps://ecoexpanpd[.]live/tnbz
hxxps://gstarofliught[.]top/wozd
Lumma Stealer
URL hxxp://193[.]233[.]113[.]11:6565/eYUPc_random[.]exe
hxxp://193[.]233[.]113[.]11:6565/JqdXK_random[.]exe
hxxp://193[.]233[.]113[.]11:6565/nsQDE_random[.]exe
Orcus RAT
URL hxxp://193[.]233[.]113[.]11:6565/UOgZm_random[.]exe Phemedrone Stealer
URL hxxp://193[.]233[.]113[.]11:6565/Ccwwm_random_signed[.]exe
hxxp://193[.]233[.]113[.]11:6565/Ccwwm_random[.]exe
hxxp://193[.]233[.]113[.]11:6565/PzLXC_random[.]exe
XenoRAT
URL hxxp://193[.]233[.]113[.]11:6565/XOrTn_random[.]exe
hxxp://193[.]233[.]113[.]11:6565/cdzbd_random[.]exe
hxxps://picklethaikr[.]com/Amphierotism[.]dsp
hxxps://picklethaikr[.]com/moonpenny[.]java
hxxps://smcshippingdlhl[.]com/Plight164[.]mso
Remcos
URL hxxp://185[.]215[.]113[.]44/mine/random[.]exe
hxxp://185[.]215[.]113[.]41/mine/random[.]exe
hxxp://185[.]39[.]17[.]239/mine/random[.]exe
hxxp://185[.]39[.]17[.]162/mine/random[.]exe
Amadey
URL hxxps://api[.]telegram[.]org/bot7715357161:AAE9IdlR1Hn1uMv31jwBvM9c_eM9vJ8rw90/sendMessage?chat_id= Stealerium
URL hxxps://heirataninitalien[.]com/Aluminiumprofile/Aluminiumprofile[.]txt DBatLoader
URL hxxps://api[.]telegram[.]org/bot7867316967:AAFUOdQqoEfMJbbXRk-2OfZ2bD6fI60N5qs/sendMessage?chat_id=5892742353
hxxps://api[.]telegram[.]org/bot7701894069:AAFAvlQMDQyGiAQsfF8wATl6f48L5Ztr534/sendMessage?chat_id=7565412517
Snake Keylogger
URL hxxps://skynetx[.]com[.]br/booking[.]htm
hxxps://detail-booking[.]com[.]br/127[.]0[.]0[.]1[.]htm
hxxps://hotellatitud33sur[.]cl/tarefab[.]html
hxxps://casalomaminca[.]com/wp-content/uploads/2025/02/Public[.]gif
hxxps://casalomaminca[.]com/wp-content/uploads/2025/02/segredo[.]pdf
hxxps://casalomaminca[.]com/wp-content/uploads/2025/02/segredov[.]pdf
hxxps://casalomaminca[.]com/wp-content/uploads/2025/02/segredob[.]pdf
hxxps://penawarhippotherapy[.]com/sys32careservicedrive[.]zip
hxxps://penawarhippotherapy[.]com/rayidverifications[.]txt
hxxps://505farmandseed[.]com/LTjip68ZQWO646ildh8t87WZB5GJQ69WGAK
AsyncRAT
URL hxxps://api[.]telegram[.]org/bot7351016463:AAGaSCwogyvMwOBi9oZwl130UkJbideHblY/sendMessage?chat_id=7274578413
hxxps://api[.]telegram[.]org/bot7205916078:AAFQ6NpbHhPGiPH1d9s_8AK4GHKKE8__Or4/sendMessage?chat_id=6316946670
hxxps://api[.]telegram[.]org/bot7662100427:AAEoYTSTVmFCTZkOAuJcUfcN0P7ri2N9eAQ/sendMessage?chat_id=1258525953
hxxps://api[.]telegram[.]org/bot7924086586:AAHk0WMui1_sXZg6ChLoISZLMgByDL-pk5Q/sendMessage?chat_id=5557063310
hxxps://api[.]telegram[.]org/bot7563203487:AAHhSgz1iFnK1H20SCy9LplVO72JVDjbi_Y/sendMessage?chat_id=6726002655
MASS Logger
URL hxxps://apelmerah[.]top/desk/Trust[.]zip
hxxps://mtowner[.]com/5t4r[.]js
hxxps://mtowner[.]com/4e3r[.]js
hxxps://mtowner[.]com/js[.]php
hxxps://soficave[.]com/nlm/sss[.]php
hxxps://soficave[.]com/nlm/loop[.]js
hxxps://ayzyw[.]top/nlm/loop[.]js
hxxps://ayzyw[.]top/nlm/sss[.]php
hxxps://ayzyw[.]top/nlm/index[.]php
hxxps://www[.]ishimotors[.]com/profileLayout
hxxps://yiug[.]outfit[.]dianamercer[.]com/orderReview
hxxps://www[.]valleypreptutoring[.]us/profileLayout
FAKEUPDATES
URL hxxps://arkofgreatness[.]org/Bespecked[.]psm
hxxps://arkofgreatness[.]org/Koreanerne[.]toc
hxxps://arkofgreatness[.]org/Carcerist[.]deploy
hxxps://goals4pets[.]com/Mindstegrnsers[.]prm
CloudEyE
URL hxxp://www[.]yuklemeislemi[.]online/s1l/
hxxp://www[.]wamohssurgery[.]com/s1/
hxxp://www[.]wwwvn602[.]com/s1/
hxxp://www[.]wx-newtork[.]net/s1/
hxxp://www[.]xn--950bn7a776apfal10cnib[.]com/s1/
hxxp://www[.]xn--bescheidprfung-psb[.]com/s1/
hxxp://www[.]yemail[.]email/s1/
hxxp://www[.]youngminds[.]place/s1/
hxxp://www[.]surfbumapparel[.]com/s1/
hxxp://www[.]taylormthomas[.]net/s1/
hxxp://www[.]testvmsept07yyyyy[.]site/s1/
hxxp://www[.]themodaempire[.]com/s1/
hxxp://www[.]time4beauty-blog[.]info/s1/
hxxp://www[.]tuthofilly[.]info/s1/
hxxp://www[.]uniqueeyez[.]com/s1/
hxxp://www[.]petal[.]parts/s1/
hxxp://www[.]plombierslivrygargan[.]com/s1/
hxxp://www[.]rencornachine[.]com/s1/
hxxp://www[.]sanmarinoseries[.]com/s1/
hxxp://www[.]seadragonfob[.]com/s1/
hxxp://www[.]moneyprime[.]net/s1/
hxxp://www[.]myaeh[.]info/s1/
hxxp://www[.]mycarefamily[.]net/s1/
hxxp://www[.]nostalgicexpress[.]com/s1/
hxxp://www[.]nowgopaint[.]com/s1/
hxxp://www[.]nulunauniversity[.]com/s1/
hxxp://www[.]la-forme-matrice[.]com/s1/
hxxp://www[.]lifemindmed[.]com/s1/
hxxp://www[.]lineagro[.]com/s1/
hxxp://www[.]liveoverseasconference[.]com/s1/
hxxp://www[.]mad[.]foundation/s1/
hxxp://www[.]michaellobato[.]com/s1/
hxxp://www[.]harmonyviolin[.]win/s1/
hxxp://www[.]hemalipaterl[.]com/s1/
hxxp://www[.]jennashrivercoaching[.]com/s1/
hxxp://www[.]jinchenjin[.]com/s1/
hxxp://www[.]kimbhoh[.]info/s1/
hxxp://www[.]freedom100plan[.]info/s1/
hxxp://www[.]ghyxm[.]info/s1/
hxxp://www[.]gmecpn[.]men/s1/
hxxp://www[.]goodkindtrue[.]com/s1/
hxxp://www[.]gzsanj[.]com/s1/
hxxp://www[.]hami[.]link/s1/
hxxp://www[.]cuchilleria[.]net/s1/
hxxp://www[.]d55105[.]com/s1/
hxxp://www[.]dondavidaltopalermo[.]com/s1/
hxxp://www[.]doomcrowoffical[.]com/s1/
hxxp://www[.]faraon-beth6[.]com/s1/
hxxp://www[.]bufdv[.]com/s1/
hxxp://www[.]cagschools[.]com/s1/
hxxp://www[.]cex[.]party/s1/
hxxp://www[.]cirquedumarina[.]com/s1/
hxxp://www[.]counsellingsupervisor[.]com/s1/
hxxp://www[.]amcmadmen[.]com/s1/
hxxp://www[.]amonlineb[.]com/s1/
hxxp://www[.]animalnooz[.]info/s1/
hxxp://www[.]appin[.]tech/s1/
hxxp://www[.]bbbav93931[.]com/s1/
hxxp://www[.]bojny[.]net/s1/
hxxp://www[.]7needsofpatients[.]com/s1/
hxxp://www[.]9cri[.]accountant/s1/
hxxp://www[.]aandswholesale[.]com/s1/
hxxp://www[.]adithyavm[.]com/s1/
hxxp://www[.]ads-line[.]com/s1/
hxxp://www[.]airmediabda[.]com/s1/
Formbook
URL hxxp://87[.]121[.]84[.]209/xmrig[.]exe
hxxp://87[.]121[.]84[.]209/xmrig
Coinminer
URL hxxp://45[.]135[.]194[.]45/s
hxxp://45[.]135[.]194[.]45/tt/mipsel64
hxxp://45[.]135[.]194[.]45/tt/mips
hxxp://45[.]135[.]194[.]45/m
hxxp://45[.]135[.]194[.]45/c
hxxp://45[.]135[.]194[.]45/t
hxxp://45[.]135[.]194[.]45/vv/sh4
hxxp://45[.]135[.]194[.]45/vv/armv4eb
hxxp://45[.]135[.]194[.]45/tt/mips64
hxxp://45[.]135[.]194[.]45/vv/arc
hxxp://45[.]135[.]194[.]45/tt/armv6l
hxxp://45[.]135[.]194[.]45/r
hxxp://45[.]135[.]194[.]45/tt/armv5l
hxxp://45[.]135[.]194[.]45/vv/riscv32
hxxp://45[.]135[.]194[.]45/e
hxxp://45[.]135[.]194[.]45/v
hxxp://45[.]135[.]194[.]45/tt/armv4eb
hxxp://45[.]135[.]194[.]45/k
hxxp://45[.]135[.]194[.]45/u
hxxp://45[.]135[.]194[.]45/l
hxxp://45[.]135[.]194[.]45/tt/sh4
hxxp://45[.]135[.]194[.]45/vv/mips64
hxxp://45[.]135[.]194[.]45/g
hxxp://45[.]135[.]194[.]45/f
hxxp://45[.]135[.]194[.]45/vv/mips
hxxp://45[.]135[.]194[.]45/n
Bashlite
URL hxxps://api[.]telegram[.]org/bot7309095694:AAEXFDt7C83fFTVGyimcrdZyYXx9OkR4Q6g/ Agent Tesla
URL hxxps://www[.]cracsiu[.]com/Downloads/test
hxxps://mail[.]inanditer[.]com/Downloads/test
hxxps://cpanel[.]tiortans[.]com/Downloads/test
hxxp://zqq[.]qualityglobal[.]wiki/Downloads/test
hxxp://r3xl[.]legacyplatformfile[.]info/Downloads/test
hxxp://mail[.]solardetech[.]info/Downloads/test
hxxps://webdisk[.]loginmicrosoftonlinedocument[.]com/Downloads/test
Emmenhtal
URL hxxp://185[.]39[.]17[.]162/files/489132901/cVEHCL4[.]exe RedLine Stealer
URL hxxp://185[.]39[.]17[.]162/files/1781548144/x5l4kAD[.]exe Quasar RAT
URL hxxp://185[.]39[.]17[.]162/files/5561582465/WwrZHbF[.]exe DarkVision RAT
※1「i-FILTER」アクセスログを検索し端末を特定してください 不要なアクセスを避けるため、一部変更しております。 ■製品対応状況(※2) ▽i-FILTER(※3) ・[脅威情報サイト]カテゴリでブロック可能 ※2 ブロックの可否は各製品の設定によるため、実際の結果はアクセスログを参照してください。 ※3 暗号化された通信の場合は、SSL Adapterの設定を「利用」にする必要があります。
イベント・セミナー情報