不正URLへのアクセス、不正メールの受信
-
メール受信した
弊社お客様0社 URLアクセスした
弊社お客様1社 -
2025/04/24
※2025/04/24 更新
マルウェア感染させると考えられるURLを検知(2025/04/24)
■IoC(※1)
Type: | IOC: | Signature: |
---|---|---|
URL | hxxps://u1[.]electivewielder[.]digital/3hj0u7zdm9[.]xi hxxps://u1[.]electivewielder[.]digital/ayr4a6jcu1[.]xi hxxps://u1[.]electivewielder[.]digital/qmqn50fetk[.]xi hxxps://u1[.]electivewielder[.]digital/hcijgmmwub[.]xi hxxps://u1[.]electivewielder[.]digital/9snen6tn3k[.]xi hxxps://u1[.]electivewielder[.]digital/psjgs4ne14[.]xi hxxps://u1[.]electivewielder[.]digital/eeg97l4220[.]xi hxxps://u1[.]electivewielder[.]digital/ymqdpwjrwl[.]xi hxxps://u1[.]electivewielder[.]digital/hwq42jh6mb[.]xi hxxps://u1[.]electivewielder[.]digital/8k2907259r[.]xi hxxps://u1[.]electivewielder[.]digital/gj8mq44oxk[.]xi hxxps://u1[.]electivewielder[.]digital/im43a14zzg[.]xi hxxps://u1[.]electivewielder[.]digital/7s5gig4r75[.]xi hxxps://u1[.]electivewielder[.]digital/3g44a5fe7g[.]xi hxxps://u1[.]electivewielder[.]digital/w8q7aoj8vv[.]xi hxxps://u1[.]electivewielder[.]digital/2ct8aql7w0[.]xi hxxps://u1[.]electivewielder[.]digital/vxjyfqz1z2[.]xi hxxps://u1[.]electivewielder[.]digital/yf0mj29lyl[.]xi hxxps://u1[.]electivewielder[.]digital/a3cnr4qiq3[.]xi hxxps://u1[.]electivewielder[.]digital/nmhjld12f6[.]xi hxxps://u1[.]putdownpopcorn[.]digital/yh11n0009q[.]xi hxxps://u1[.]putdownpopcorn[.]digital/n0cb27mell[.]xi hxxps://u1[.]putdownpopcorn[.]digital/aye3fqeerk[.]xi |
ClearFake |
URL | hxxps://ilongitudde[.]digital/wizu hxxps://wn[.]sg/file[.]exe hxxps://wn[.]sg/script[.]ps1 hxxp://193[.]233[.]113[.]11:6565/rcMoI_random[.]exe hxxps://1zlatitudert[.]live/teui hxxps://ecoexpanpd[.]live/tnbz hxxps://gstarofliught[.]top/wozd |
Lumma Stealer |
URL | hxxp://193[.]233[.]113[.]11:6565/eYUPc_random[.]exe hxxp://193[.]233[.]113[.]11:6565/JqdXK_random[.]exe hxxp://193[.]233[.]113[.]11:6565/nsQDE_random[.]exe |
Orcus RAT |
URL | hxxp://193[.]233[.]113[.]11:6565/UOgZm_random[.]exe | Phemedrone Stealer |
URL | hxxp://193[.]233[.]113[.]11:6565/Ccwwm_random_signed[.]exe hxxp://193[.]233[.]113[.]11:6565/Ccwwm_random[.]exe hxxp://193[.]233[.]113[.]11:6565/PzLXC_random[.]exe |
XenoRAT |
URL | hxxp://193[.]233[.]113[.]11:6565/XOrTn_random[.]exe hxxp://193[.]233[.]113[.]11:6565/cdzbd_random[.]exe hxxps://picklethaikr[.]com/Amphierotism[.]dsp hxxps://picklethaikr[.]com/moonpenny[.]java hxxps://smcshippingdlhl[.]com/Plight164[.]mso |
Remcos |
URL | hxxp://185[.]215[.]113[.]44/mine/random[.]exe hxxp://185[.]215[.]113[.]41/mine/random[.]exe hxxp://185[.]39[.]17[.]239/mine/random[.]exe hxxp://185[.]39[.]17[.]162/mine/random[.]exe |
Amadey |
URL | hxxps://api[.]telegram[.]org/bot7715357161:AAE9IdlR1Hn1uMv31jwBvM9c_eM9vJ8rw90/sendMessage?chat_id= | Stealerium |
URL | hxxps://heirataninitalien[.]com/Aluminiumprofile/Aluminiumprofile[.]txt | DBatLoader |
URL | hxxps://api[.]telegram[.]org/bot7867316967:AAFUOdQqoEfMJbbXRk-2OfZ2bD6fI60N5qs/sendMessage?chat_id=5892742353 hxxps://api[.]telegram[.]org/bot7701894069:AAFAvlQMDQyGiAQsfF8wATl6f48L5Ztr534/sendMessage?chat_id=7565412517 |
Snake Keylogger |
URL | hxxps://skynetx[.]com[.]br/booking[.]htm hxxps://detail-booking[.]com[.]br/127[.]0[.]0[.]1[.]htm hxxps://hotellatitud33sur[.]cl/tarefab[.]html hxxps://casalomaminca[.]com/wp-content/uploads/2025/02/Public[.]gif hxxps://casalomaminca[.]com/wp-content/uploads/2025/02/segredo[.]pdf hxxps://casalomaminca[.]com/wp-content/uploads/2025/02/segredov[.]pdf hxxps://casalomaminca[.]com/wp-content/uploads/2025/02/segredob[.]pdf hxxps://penawarhippotherapy[.]com/sys32careservicedrive[.]zip hxxps://penawarhippotherapy[.]com/rayidverifications[.]txt hxxps://505farmandseed[.]com/LTjip68ZQWO646ildh8t87WZB5GJQ69WGAK |
AsyncRAT |
URL | hxxps://api[.]telegram[.]org/bot7351016463:AAGaSCwogyvMwOBi9oZwl130UkJbideHblY/sendMessage?chat_id=7274578413 hxxps://api[.]telegram[.]org/bot7205916078:AAFQ6NpbHhPGiPH1d9s_8AK4GHKKE8__Or4/sendMessage?chat_id=6316946670 hxxps://api[.]telegram[.]org/bot7662100427:AAEoYTSTVmFCTZkOAuJcUfcN0P7ri2N9eAQ/sendMessage?chat_id=1258525953 hxxps://api[.]telegram[.]org/bot7924086586:AAHk0WMui1_sXZg6ChLoISZLMgByDL-pk5Q/sendMessage?chat_id=5557063310 hxxps://api[.]telegram[.]org/bot7563203487:AAHhSgz1iFnK1H20SCy9LplVO72JVDjbi_Y/sendMessage?chat_id=6726002655 |
MASS Logger |
URL | hxxps://apelmerah[.]top/desk/Trust[.]zip hxxps://mtowner[.]com/5t4r[.]js hxxps://mtowner[.]com/4e3r[.]js hxxps://mtowner[.]com/js[.]php hxxps://soficave[.]com/nlm/sss[.]php hxxps://soficave[.]com/nlm/loop[.]js hxxps://ayzyw[.]top/nlm/loop[.]js hxxps://ayzyw[.]top/nlm/sss[.]php hxxps://ayzyw[.]top/nlm/index[.]php hxxps://www[.]ishimotors[.]com/profileLayout hxxps://yiug[.]outfit[.]dianamercer[.]com/orderReview hxxps://www[.]valleypreptutoring[.]us/profileLayout |
FAKEUPDATES |
URL | hxxps://arkofgreatness[.]org/Bespecked[.]psm hxxps://arkofgreatness[.]org/Koreanerne[.]toc hxxps://arkofgreatness[.]org/Carcerist[.]deploy hxxps://goals4pets[.]com/Mindstegrnsers[.]prm |
CloudEyE |
URL | hxxp://www[.]yuklemeislemi[.]online/s1l/ hxxp://www[.]wamohssurgery[.]com/s1/ hxxp://www[.]wwwvn602[.]com/s1/ hxxp://www[.]wx-newtork[.]net/s1/ hxxp://www[.]xn--950bn7a776apfal10cnib[.]com/s1/ hxxp://www[.]xn--bescheidprfung-psb[.]com/s1/ hxxp://www[.]yemail[.]email/s1/ hxxp://www[.]youngminds[.]place/s1/ hxxp://www[.]surfbumapparel[.]com/s1/ hxxp://www[.]taylormthomas[.]net/s1/ hxxp://www[.]testvmsept07yyyyy[.]site/s1/ hxxp://www[.]themodaempire[.]com/s1/ hxxp://www[.]time4beauty-blog[.]info/s1/ hxxp://www[.]tuthofilly[.]info/s1/ hxxp://www[.]uniqueeyez[.]com/s1/ hxxp://www[.]petal[.]parts/s1/ hxxp://www[.]plombierslivrygargan[.]com/s1/ hxxp://www[.]rencornachine[.]com/s1/ hxxp://www[.]sanmarinoseries[.]com/s1/ hxxp://www[.]seadragonfob[.]com/s1/ hxxp://www[.]moneyprime[.]net/s1/ hxxp://www[.]myaeh[.]info/s1/ hxxp://www[.]mycarefamily[.]net/s1/ hxxp://www[.]nostalgicexpress[.]com/s1/ hxxp://www[.]nowgopaint[.]com/s1/ hxxp://www[.]nulunauniversity[.]com/s1/ hxxp://www[.]la-forme-matrice[.]com/s1/ hxxp://www[.]lifemindmed[.]com/s1/ hxxp://www[.]lineagro[.]com/s1/ hxxp://www[.]liveoverseasconference[.]com/s1/ hxxp://www[.]mad[.]foundation/s1/ hxxp://www[.]michaellobato[.]com/s1/ hxxp://www[.]harmonyviolin[.]win/s1/ hxxp://www[.]hemalipaterl[.]com/s1/ hxxp://www[.]jennashrivercoaching[.]com/s1/ hxxp://www[.]jinchenjin[.]com/s1/ hxxp://www[.]kimbhoh[.]info/s1/ hxxp://www[.]freedom100plan[.]info/s1/ hxxp://www[.]ghyxm[.]info/s1/ hxxp://www[.]gmecpn[.]men/s1/ hxxp://www[.]goodkindtrue[.]com/s1/ hxxp://www[.]gzsanj[.]com/s1/ hxxp://www[.]hami[.]link/s1/ hxxp://www[.]cuchilleria[.]net/s1/ hxxp://www[.]d55105[.]com/s1/ hxxp://www[.]dondavidaltopalermo[.]com/s1/ hxxp://www[.]doomcrowoffical[.]com/s1/ hxxp://www[.]faraon-beth6[.]com/s1/ hxxp://www[.]bufdv[.]com/s1/ hxxp://www[.]cagschools[.]com/s1/ hxxp://www[.]cex[.]party/s1/ hxxp://www[.]cirquedumarina[.]com/s1/ hxxp://www[.]counsellingsupervisor[.]com/s1/ hxxp://www[.]amcmadmen[.]com/s1/ hxxp://www[.]amonlineb[.]com/s1/ hxxp://www[.]animalnooz[.]info/s1/ hxxp://www[.]appin[.]tech/s1/ hxxp://www[.]bbbav93931[.]com/s1/ hxxp://www[.]bojny[.]net/s1/ hxxp://www[.]7needsofpatients[.]com/s1/ hxxp://www[.]9cri[.]accountant/s1/ hxxp://www[.]aandswholesale[.]com/s1/ hxxp://www[.]adithyavm[.]com/s1/ hxxp://www[.]ads-line[.]com/s1/ hxxp://www[.]airmediabda[.]com/s1/ |
Formbook |
URL | hxxp://87[.]121[.]84[.]209/xmrig[.]exe hxxp://87[.]121[.]84[.]209/xmrig |
Coinminer |
URL | hxxp://45[.]135[.]194[.]45/s hxxp://45[.]135[.]194[.]45/tt/mipsel64 hxxp://45[.]135[.]194[.]45/tt/mips hxxp://45[.]135[.]194[.]45/m hxxp://45[.]135[.]194[.]45/c hxxp://45[.]135[.]194[.]45/t hxxp://45[.]135[.]194[.]45/vv/sh4 hxxp://45[.]135[.]194[.]45/vv/armv4eb hxxp://45[.]135[.]194[.]45/tt/mips64 hxxp://45[.]135[.]194[.]45/vv/arc hxxp://45[.]135[.]194[.]45/tt/armv6l hxxp://45[.]135[.]194[.]45/r hxxp://45[.]135[.]194[.]45/tt/armv5l hxxp://45[.]135[.]194[.]45/vv/riscv32 hxxp://45[.]135[.]194[.]45/e hxxp://45[.]135[.]194[.]45/v hxxp://45[.]135[.]194[.]45/tt/armv4eb hxxp://45[.]135[.]194[.]45/k hxxp://45[.]135[.]194[.]45/u hxxp://45[.]135[.]194[.]45/l hxxp://45[.]135[.]194[.]45/tt/sh4 hxxp://45[.]135[.]194[.]45/vv/mips64 hxxp://45[.]135[.]194[.]45/g hxxp://45[.]135[.]194[.]45/f hxxp://45[.]135[.]194[.]45/vv/mips hxxp://45[.]135[.]194[.]45/n |
Bashlite |
URL | hxxps://api[.]telegram[.]org/bot7309095694:AAEXFDt7C83fFTVGyimcrdZyYXx9OkR4Q6g/ | Agent Tesla |
URL | hxxps://www[.]cracsiu[.]com/Downloads/test hxxps://mail[.]inanditer[.]com/Downloads/test hxxps://cpanel[.]tiortans[.]com/Downloads/test hxxp://zqq[.]qualityglobal[.]wiki/Downloads/test hxxp://r3xl[.]legacyplatformfile[.]info/Downloads/test hxxp://mail[.]solardetech[.]info/Downloads/test hxxps://webdisk[.]loginmicrosoftonlinedocument[.]com/Downloads/test |
Emmenhtal |
URL | hxxp://185[.]39[.]17[.]162/files/489132901/cVEHCL4[.]exe | RedLine Stealer |
URL | hxxp://185[.]39[.]17[.]162/files/1781548144/x5l4kAD[.]exe | Quasar RAT |
URL | hxxp://185[.]39[.]17[.]162/files/5561582465/WwrZHbF[.]exe | DarkVision RAT |