不正URLへのアクセス、不正メールの受信
-
メール受信した
弊社お客様0社 URLアクセスした
弊社お客様1社 -
2025/05/12
※2025/05/12 更新
マルウェア感染させると考えられるURLを検知(2025/05/12)
■IoC(※1)
Type: | IOC: | Signature: |
---|---|---|
URL | hxxp://213[.]226[.]113[.]234/nhf7/phbf[.]exe hxxp://212194cm[.]nyashware[.]ru/PhppacketmultiBaseuniversalTrackUploadsdownloads[.]php |
DCRat |
URL | hxxps://lclatteqrpq[.]digital/kljz hxxps://kaeneasq[.]live/nmgj hxxps://4homewappzb[.]top/tqba hxxps://vinsidegrah[.]run/ieop hxxps://rhomewappzb[.]top/tqba hxxps://kgrizzlqzuk[.]live/qhbu hxxps://taleweaiver[.]run/toibnh hxxps://sjawdedmirror[.]run/ewqd hxxps://fowlflright[.]digital/qopy hxxps://bulgecont[.]run/gaoh hxxps://searchilyo[.]run/gsna hxxps://qhdatawavej[.]digital/bafy hxxps://pnoxajb[.]top/bnbd hxxps://lvclatteqrpq[.]digital/kljz hxxps://insulaey[.]live/gantb hxxps://dclatteqrpq[.]digital/kljz hxxps://6civitasu[.]run/werrp hxxps://0ninepicchf[.]bet/lznd hxxps://wskninepicchf[.]bet/lznd hxxps://i3ninepicchf[.]bet/lznd hxxps://hinsidegrah[.]run/ieop hxxps://-sninepicchf[.]bet/lznd hxxps://blackljjwc[.]run/banj hxxps://5grizzlqzuk[.]live/qhbu hxxps://nightloqv[.]run/ihfd hxxps://slinsidegrah[.]run/ieop hxxps://interpwthc[.]digital/juab hxxps://xninepicchf[.]bet/lznd hxxps://kinsidegrah[.]run/ieop hxxps://cblackljjwc[.]run/banj hxxps://blackswmxc[.]top/bgry hxxps://8ninepicchf[.]bet/lznd hxxps://rninepicchf[.]bet/lznd hxxps://zmedtipp[.]live/mnvzx hxxps://overcovtcg[.]top/juhd hxxps://meteorplyp[.]live/lekp hxxps://hunterinrx[.]run/mnbt hxxp://185[.]156[.]72[.]121/files/5494432675/wqhx1rv[.]exe hxxp://185[.]156[.]72[.]121/files/fate/random[.]exe hxxp://185[.]156[.]72[.]121/files/5964778733/fV8FBMo[.]exe hxxp://80[.]64[.]18[.]161/files/8000373688/mdjiEXg[.]exe hxxps://sinterpwthc[.]digital/juab hxxps://3clatteqrpq[.]digital/kljz hxxps://xovercovtcg[.]top/juhd hxxp://80[.]64[.]18[.]161/files/5494432675/wqhx1rv[.]exe hxxps://animatcxju[.]live/gwqz hxxps://5voznessxyy[.]life/bnaz hxxps://yodescenrugb[.]bet/woap hxxps://unlimirxam[.]digital/qop hxxps://posseswsnc[.]top/akds hxxps://featurlyin[.]top/pdal hxxps://flowerexju[.]bet/lanz hxxps://easterxeen[.]run/zavc hxxps://araucahkbm[.]live/baneb hxxps://6emeteorplyp[.]live/lekp hxxps://winsidegrah[.]run/ieop hxxps://4clatteqrpq[.]digital/kljz hxxp://185[.]156[.]72[.]121/files/6520688851/4UJDiQw[.]exe hxxp://89[.]208[.]104[.]175:5002/kiprona[.]exe hxxp://185[.]156[.]72[.]121/luma/random[.]exe hxxps://github[.]com/legendary99999/sdvdafvsdfbvdfsb/releases/download/dfbdsgfbfadbadf/dais[.]exe hxxps://github[.]com/legendary99999/vdfsvgdfsavsdfvs/releases/download/dafbadfbwdfba/LatitudeVsnet[.]exe |
Lumma Stealer |
URL | hxxps://u1[.]lax0[.]ru/2k5jjj73x9[.]1 hxxps://u1[.]lax0[.]ru/ozhli4m4jz[.]1 hxxps://u1[.]lax0[.]ru/ivso4qye2f[.]1 hxxps://u1[.]lax0[.]ru/w0dia672ny[.]1 hxxps://u1[.]lax0[.]ru/yq44fo8lza[.]1 hxxps://u1[.]lax0[.]ru/8psg6bwhzm[.]1 hxxps://u1[.]lax0[.]ru/706kwkyzi6[.]1 hxxps://u1[.]lax0[.]ru/r10cc1ffp1[.]1 hxxps://u1[.]lax0[.]ru/lu6n3xcw50[.]1 hxxps://u1[.]lax0[.]ru/t6e3h62y8o[.]1 hxxps://u1[.]lax0[.]ru/gnvh7765gf[.]1 hxxps://u1[.]wyja[.]ru/shs79aqmv0[.]1 hxxps://u1[.]wyja[.]ru/1mpd3e319b[.]1 hxxps://u1[.]wyja[.]ru/yomr97w711[.]1 hxxps://u1[.]wyja[.]ru/xv8015nw28[.]1 hxxps://u1[.]wyja[.]ru/rdjt52u94g[.]1 hxxps://u1[.]wyja[.]ru/ludztndejk[.]1 hxxps://u1[.]wyja[.]ru/x27yftbapp[.]1 hxxps://u1[.]wyja[.]ru/tj86rfxfpa[.]1 hxxps://u1[.]wyja[.]ru/h4oku349ne[.]1 hxxps://u1[.]wyja[.]ru/b0juvwfjah[.]1 hxxps://u1[.]wyja[.]ru/hbp0f89nxb[.]1 hxxps://u1[.]wyja[.]ru/wplmf0md8p[.]1 hxxps://u1[.]wyja[.]ru/pn2x0c58ku[.]1 hxxps://u1[.]wyja[.]ru/3w1ayk59ru[.]1 hxxps://u1[.]wyja[.]ru/qy5d63z2rb[.]1 hxxps://u1[.]wyja[.]ru/3ueo8g75as[.]1 hxxps://u1[.]wyja[.]ru/a6561byo90[.]1 hxxps://u1[.]wyja[.]ru/3c3ecesqxa[.]1 hxxps://u1[.]wyja[.]ru/nuufk6h0g4[.]1 hxxps://u1[.]wyja[.]ru/f9c1m7y7xb[.]1 hxxps://u1[.]wyja[.]ru/bgvpn3c93c[.]1 hxxps://u1[.]wyja[.]ru/d9l8q5kbpj[.]1 hxxps://u1[.]wyja[.]ru/63mjv32nrv[.]1 hxxps://u1[.]wyja[.]ru/whur0a5nx5[.]1 hxxps://u1[.]wyja[.]ru/ulpdyaf3wr[.]1 hxxps://u1[.]wyja[.]ru/nqrp5osrny[.]1 hxxps://u1[.]wyja[.]ru/w5sl1aj1kv[.]1 hxxps://u1[.]wyja[.]ru/ra12f91gut[.]1 hxxps://u1[.]wyja[.]ru/6lvb148aki[.]1 hxxps://u1[.]wyja[.]ru/0ynbxsh2a4[.]1 hxxps://u1[.]wyja[.]ru/msabm9l27s[.]1 |
ClearFake |
URL | hxxp://185[.]142[.]53[.]233/l hxxp://103[.]149[.]29[.]68/garm7 hxxp://92[.]60[.]77[.]69/EkSgbins[.]sh hxxp://176[.]65[.]148[.]16:8080/mpsl hxxp://176[.]65[.]148[.]16:8080/mips hxxp://176[.]65[.]148[.]16/mips hxxp://176[.]65[.]148[.]16/mpsl |
Bashlite |
URL | hxxp://146[.]158[.]127[.]185:41312/Mozi[.]m hxxp://102[.]97[.]107[.]14:50547/Mozi[.]m hxxp://61[.]3[.]26[.]117:55159/Mozi[.]m |
Mozi |
URL | hxxp://78[.]153[.]140[.]66/kinsing hxxp://78[.]153[.]140[.]66/ex[.]sh hxxp://78[.]153[.]140[.]66/curl-amd64 hxxp://78[.]153[.]140[.]66/kinsing2 hxxp://78[.]153[.]140[.]66/kinsing_aarch64 hxxp://78[.]153[.]140[.]66/libsystem[.]so hxxp://78[.]153[.]140[.]66/h2[.]sh hxxp://78[.]153[.]140[.]66/f[.]sh hxxp://78[.]153[.]140[.]66/o[.]sh hxxp://78[.]153[.]140[.]66/tf[.]sh hxxp://78[.]153[.]140[.]66/w[.]sh hxxp://78[.]153[.]140[.]66/k[.]sh hxxp://78[.]153[.]140[.]66/p[.]sh hxxp://78[.]153[.]140[.]66/kn[.]sh hxxp://78[.]153[.]140[.]66/pg[.]sh hxxp://78[.]153[.]140[.]66/vb[.]sh hxxp://78[.]153[.]140[.]66/hb[.]sh hxxp://78[.]153[.]140[.]66/scg[.]sh hxxp://78[.]153[.]140[.]66/unk[.]sh hxxp://78[.]153[.]140[.]66/wpf[.]sh hxxp://78[.]153[.]140[.]66/sc[.]sh hxxp://78[.]153[.]140[.]66/tr[.]sh hxxp://78[.]153[.]140[.]66/an[.]sh hxxp://78[.]153[.]140[.]66/s[.]sh hxxp://78[.]153[.]140[.]66/j[.]sh hxxp://78[.]153[.]140[.]66/mo[.]sh hxxp://78[.]153[.]140[.]66/bg[.]sh hxxp://78[.]153[.]140[.]66/ku[.]sh hxxp://78[.]153[.]140[.]66/h[.]sh hxxp://78[.]153[.]140[.]66/n[.]sh hxxp://78[.]153[.]140[.]66/lr[.]sh hxxp://78[.]153[.]140[.]66/ki[.]sh hxxp://78[.]153[.]140[.]66/sp[.]sh hxxp://78[.]153[.]140[.]66/lh[.]sh hxxp://78[.]153[.]140[.]66/sa[.]sh hxxp://78[.]153[.]140[.]66/ni[.]sh hxxp://78[.]153[.]140[.]66/t[.]sh hxxp://78[.]153[.]140[.]66/tm[.]sh hxxp://78[.]153[.]140[.]66/do[.]sh hxxp://78[.]153[.]140[.]66/cb[.]sh hxxp://78[.]153[.]140[.]66/tc[.]sh hxxp://78[.]153[.]140[.]66/sup[.]sh hxxp://78[.]153[.]140[.]66/r[.]sh hxxp://78[.]153[.]140[.]66/md[.]sh hxxp://78[.]153[.]140[.]66/spr[.]sh hxxp://78[.]153[.]140[.]66/st[.]sh hxxp://78[.]153[.]140[.]66/a[.]sh hxxp://78[.]153[.]140[.]66/pa[.]sh hxxp://78[.]153[.]140[.]66/m[.]sh hxxp://78[.]153[.]140[.]66/xx[.]sh hxxp://78[.]153[.]140[.]66/sm[.]sh hxxp://78[.]153[.]140[.]66/se[.]sh hxxp://78[.]153[.]140[.]66/ph[.]sh hxxp://78[.]153[.]140[.]66/cp[.]sh hxxp://78[.]153[.]140[.]66/vm[.]sh hxxp://78[.]153[.]140[.]66/vml[.]sh hxxp://78[.]153[.]140[.]66/ge[.]sh hxxp://78[.]153[.]140[.]66/pg2[.]sh hxxp://78[.]153[.]140[.]66/ae[.]sh hxxp://78[.]153[.]140[.]66/ap[.]sh hxxp://78[.]153[.]140[.]66/cf[.]sh hxxp://78[.]153[.]140[.]66/mi[.]sh hxxp://78[.]153[.]140[.]66/gi[.]sh hxxp://78[.]153[.]140[.]66/acb[.]sh hxxp://78[.]153[.]140[.]66/rm[.]sh hxxp://78[.]153[.]140[.]66/gl[.]sh hxxp://78[.]153[.]140[.]66/wb[.]sh hxxp://78[.]153[.]140[.]66/mt[.]sh hxxp://78[.]153[.]140[.]66/py[.]sh hxxp://78[.]153[.]140[.]66/d[.]sh |
Kinsing |
URL | hxxp://192[.]210[.]214[.]133/XfBcMMKsEsSsyijkGSS214[.]bin hxxp://glamandglow[.]com[.]sg/slo[.]bin hxxp://192[.]210[.]214[.]133/ryYoBjjOUNK30[.]bin |
CloudEyE |
URL | hxxps://architrata[.]com/drive/ hxxps://carflotyup[.]com/drive/ hxxps://send[.]mycatisanalien[.]com/wp-content/plugins/alo-easymail/tr[.]php?v=MzAzMDB8ZWI4YWI2NjNkYThiODllZmM5YTViMTkx hxxps://ropoclosto[.]co/wp-content/plugins/background-image-cropper/khxxuq[.]php?dsya=vws6i hxxps://topguningit[.]com/test/ hxxps://lofiramegi[.]com/test/ |
Latrodectus |
URL | hxxp://185[.]235[.]128[.]114/fonts/eworvolt[.]rar hxxp://useof[.]org/my-files/3[.]PL_PIEC001-L20250227-GLOBAL_ATOP[.]pdf[.]zip hxxps://useof[.]org/my-files/3[.]PL_PIEC001-L20250227-GLOBAL_ATOP[.]pdf[.]zip |
Kimsuky |
URL | hxxps://verifyyourconnect[.]com/gHWilwqt[.]txt hxxps://mychecksecureconnect[.]cloud/Zfv2wKNh[.]txt hxxps://verifconncaptcha[.]com/t2NnbBsi[.]txt hxxps://lgsdesign[.]co[.]uk/rascos[.]zip hxxps://www[.]surethinks[.]com/xostes[.]zip hxxps://jaagnet[.]com/ksps[.]zip hxxps://lgsdesign[.]co[.]uk/kistes[.]zip hxxps://jaagnet[.]com/rara[.]zip hxxps://lgsdesign[.]co[.]uk/fosdos[.]zip hxxps://allstarstriping[.]com/wp-content/misles[.]zip hxxps://allstarstriping[.]com/wp-content/fosres[.]zip hxxps://lgsdesign[.]co[.]uk/coscos[.]zip hxxps://jaagnet[.]com/raks[.]zip hxxps://zqpdofuynuha[.]top/nlm/files/Commitments[.]zip hxxps://allstarstriping[.]com/wp-content/misres[.]zip hxxps://jaagnet[.]com/osos[.]zip hxxps://lgsdesign[.]co[.]uk/leskis[.]zip hxxps://scf[.]com/kste[.]zip hxxps://lgsdesign[.]co[.]uk/pisras[.]zip hxxps://surethinks[.]com/rasbus[.]zip hxxps://surethinks[.]com/zasras[.]zip hxxps://my-privatebanker[.]top/jse/minjs[.]js hxxps://my-privatebanker[.]top/jse/select[.]js hxxps://jaagnet[.]com/rsrs[.]zip hxxps://my-privatebanker[.]top/jse/xxx[.]php |
NetSupportManager RAT |
URL | hxxp://78[.]153[.]140[.]66/config[.]json hxxp://78[.]153[.]140[.]66/xmrig[.]exe hxxp://78[.]153[.]140[.]66/lf[.]sh hxxp://78[.]153[.]140[.]66/ws[.]sh hxxp://78[.]153[.]140[.]66/c[.]sh hxxp://78[.]153[.]140[.]66/1[.]ps1 hxxp://78[.]153[.]140[.]66/cpr[.]sh hxxp://78[.]153[.]140[.]66/ce[.]sh |
Coinminer |
URL | hxxps://api[.]telegram[.]org/bot7651004190:AAE860hHGVHpx41mxFNWpq1v8oOiRe2jxS8/sendMessage?chat_id=7277519501 hxxps://api[.]telegram[.]org/bot7909313568:AAEPynogvu-iFVgRcoHJdqvMYuKJnd9qNQA/sendMessage?chat_id=7123661829 hxxps://api[.]telegram[.]org/bot7760383524:AAFFORwEj-JVG3I09wqo7_aZQvwyvLnd0Wg/sendMessage?chat_id=7641703900 hxxps://api[.]telegram[.]org/bot7659150395:AAHQ0QbjJcA4PLaOKaWsytTBYyGA_lLiU_Q/sendMessage?chat_id=7537757541 hxxps://api[.]telegram[.]org/bot7739919249:AAHKGHTy78jD_XCuFhjoHrf_l_sOV-bS69k/sendMessage?chat_id=5382791083 hxxps://api[.]telegram[.]org/bot7725890352:AAFCNwzY8Mo7L69FMtT4nFF7mVlo9woRsss/sendMessage?chat_id=5378655757 hxxps://api[.]telegram[.]org/bot7901443925:AAHl1FE1kJmt3xqeiuNXwBT00mU8-Ci3IeU/sendMessage?chat_id=1584484420 |
MASS Logger |
URL | hxxps://api[.]telegram[.]org/bot7925481137:AAFMfqe2EfNqHhsYicuiK2otgGb-OIloa1w/sendMessage?chat_id=7647464174 hxxps://api[.]telegram[.]org/bot7383727899:AAGWw1_bLG4qxggR_xF_xDSfeKNhkfwxNOk/sendMessage?chat_id=7174574119 hxxps://api[.]telegram[.]org/bot7268921698:AAFLMRz2Af53baS9DgXTkZqbgKcSDWUiFUg/sendMessage?chat_id=6370711846 hxxps://api[.]telegram[.]org/bot7781618197:AAFmKOgUgathTDiDgYRH5DdKhfUNVL3A1j0/sendMessage?chat_id=1426930973 hxxps://api[.]telegram[.]org/bot8098626755:AAGKuJKBDtG4eRbP6v2gWZBCNxZIQ1Ksjy4/sendMessage?chat_id=7205131036 hxxps://api[.]telegram[.]org/bot8065368007:AAHiK8UX-lL98_BRQfEkg_Tmm2itvEdaw_c/sendMessage?chat_id=5492983899 hxxps://api[.]telegram[.]org/bot7316163433:AAHNSG6_pW7bvb7uNB50s1rKcnoS6x2lwbE/sendMessage?chat_id=7361435574 hxxps://api[.]telegram[.]org/bot7906164947:AAEfe-HyjlG6wdpvqJlGxGzrjlbj5fcAI0o/sendMessage?chat_id=7153546848 hxxps://api[.]telegram[.]org/bot7937639112:AAHLK1GSl55SkxBp6NWnPerR6oa3W7nl5wM/sendMessage?chat_id=7828110568 hxxps://api[.]telegram[.]org/bot7991344770:AAHNadMUlWoTRm94PMWR6w2X66xpDLsLOVI/sendMessage?chat_id=7326273705 hxxps://api[.]telegram[.]org/bot7549034365:AAGYl3jcC64v4PWQMqwDTG2ZuFEYbXGCthk/sendMessage?chat_id=7828110568 hxxps://api[.]telegram[.]org/bot8063185889:AAHu9KyyzBBydK1jNP5TNLYYqq199VjbxGs/sendMessage?chat_id=7451270736 hxxps://api[.]telegram[.]org/bot8180480083:AAEocgqxwuEEgrgAP2vic1cjJBGEvSiPRe4/sendMessage?chat_id=7788933199 hxxps://api[.]telegram[.]org/bot7191116407:AAGbcB26CBntmp54gysuFnUZ8ujteJqqV9A/sendMessage?chat_id=7289936961 hxxps://api[.]telegram[.]org/bot7639357452:AAETvqIZm6rwst2qAZEgLLpMn_RgCn4Xo8M/sendMessage?chat_id=7153546848 hxxps://api[.]telegram[.]org/bot7837424347:AAHX7LgH_7xufgBLTVSRHe_GIcRpYOVKLtE/sendMessage?chat_id=6859171055 hxxps://api[.]telegram[.]org/bot7801493167:AAEB4WXJGTJOHMz0AiJb2sT4xWzkAygrtn0/sendMessage?chat_id=6721908209 hxxps://api[.]telegram[.]org/bot7949318878:AAFeRt-MD2QVjbSjAuMJg9_fQT68p52KDXQ/sendMessage?chat_id=8071918969 hxxps://api[.]telegram[.]org/bot7992345449:AAHlJcKXsM7TFCggUz3JFyFnStaHVI-Kf_w/sendMessage?chat_id=6725996464 hxxps://api[.]telegram[.]org/bot8005797173:AAGGVmIM16i2vB5-MVzaLKJ4OaeFa2QH7Kc/sendMessage?chat_id=1909112828 |
Snake Keylogger |
URL | hxxps://cecdubai[.]me/yakwhitefile/161_Biwwrempmde hxxps://onfiltre[.]com[.]tr/wp-content/wex[.]gif hxxps://huadongrubbercable[.]com/JOHNSON31/klexovjni[.]txt |
Remcos |
URL | hxxps://api[.]telegram[.]org/bot7740014778:AAHvv4iO_JUp_5ZN94WZwkIb3odsDxvRSjM/sendMessage?chat_id=8066550143 hxxps://api[.]telegram[.]org/bot8177260835:AAEXCx28DtJ7-eKIv0s5TZm7zodxfQwk_8g/sendMessage?chat_id=7341396678 |
AsyncRAT |
URL | hxxps://packedbrick[.]com/IB4zUEmTzFv831zG2HSjRlSntuq8fJ6Q0-JaBCv4v6g hxxps://cpanel[.]santechplumbing[.]com/profileLayout hxxps://photoreport[.]roamdetail[.]com/profileLayout |
FAKEUPDATES |
URL | hxxp://diicotsec[.]ru:8080/v3/ hxxp://diicotsec[.]ru:8080/v3//receive[.]php hxxp://diicotsec[.]ru:8080/animeNET/login[.]php hxxp://diicotsec[.]ru:8080/v3/login[.]php |
BlackNET RAT |
URL | hxxp://167[.]250[.]49[.]155/bin/billi_e58d74e455634dc695ed8a7b8b320325[.]exe hxxps://98[.]177[.]107[.]142:60446/9tkuuCtbv_U_dz51V3a7EQp5MDcDpINqWhwotIngsQ1uAUwvw5SH/ hxxp://69[.]55[.]62[.]10:8080/vq6qtQjsS3-REJAS-Re9rwfH30bYpWOs6cnIRrJZlc36-yn0McKtf-dBnU4R5zvTAXPgcjVaaUeWFYSuwReprrKo4nsCylLGU/ |
Meterpreter |
URL | hxxp://panel[.]diicotsec[.]ru:8080/x/api/endpoint[.]php | XMRig |
URL | hxxp://43[.]139[.]240[.]201:8389/02[.]08[.]2022[.]exe hxxp://156[.]245[.]28[.]75/02[.]08[.]2022[.]exe hxxp://124[.]220[.]205[.]147:81/02[.]08[.]2022[.]exe hxxp://43[.]139[.]240[.]201:8088/02[.]08[.]2022[.]exe hxxp://103[.]4[.]8[.]40/02[.]08[.]2022[.]exe hxxp://154[.]12[.]20[.]34/02[.]08[.]2022[.]exe hxxp://47[.]111[.]109[.]16/02[.]08[.]2022[.]exe hxxp://121[.]40[.]159[.]30:9000/02[.]08[.]2022[.]exe hxxp://123[.]56[.]187[.]48:8008/02[.]08[.]2022[.]exe hxxp://8[.]134[.]51[.]218:24444/02[.]08[.]2022[.]exe hxxp://62[.]234[.]92[.]164/02[.]08[.]2022[.]exe hxxp://103[.]45[.]68[.]135:8888/02[.]08[.]2022[.]exe hxxp://167[.]99[.]76[.]115/02[.]08[.]2022[.]exe hxxp://62[.]234[.]92[.]164:8085/02[.]08[.]2022[.]exe hxxp://43[.]156[.]57[.]179/02[.]08[.]2022[.]exe hxxp://45[.]192[.]104[.]206:6003/02[.]08[.]2022[.]exe hxxp://47[.]97[.]113[.]36:10010/02[.]08[.]2022[.]exe hxxp://129[.]211[.]28[.]15:7777/02[.]08[.]2022[.]exe hxxp://8[.]131[.]118[.]10:4444/02[.]08[.]2022[.]exe hxxp://62[.]113[.]107[.]81/02[.]08[.]2022[.]exe hxxp://47[.]120[.]37[.]142:443/02[.]08[.]2022[.]exe hxxp://106[.]53[.]191[.]52/02[.]08[.]2022[.]exe |
Cobalt Strike |
URL | hxxps://www[.]arcon[.]com[.]pe/chukii[.]ps1 | Agent Tesla |
URL | hxxp://mxblog77[.]cfd/777/ hxxp://demblog797[.]xyz/statweb255/index[.]php hxxp://admlogs457[.]cfd/statweb255/index[.]php hxxp://blogmstat599[.]xyz/statweb255/index[.]php hxxp://bloglogs757[.]cfd/statweb255/index[.]php hxxp://pzh1966[.]com/statweb255/index[.]php hxxp://serverlogs295[.]xyz/statweb255/index[.]php hxxp://servblog475[.]cfd/statweb255/index[.]php |
SmokeLoader |
URL | hxxp://43[.]249[.]172[.]195:888/21 | XOR DDoS |
URL | hxxps://cbsnaturalway[.]com/diagnostics[.]php | Satacom |
URL | hxxp://185[.]156[.]72[.]121/files/unique1/random[.]exe hxxp://80[.]64[.]18[.]161/files/unique1/random[.]exe |
Vidar |
URL | hxxp://185[.]156[.]72[.]121/testmine/random[.]exe hxxp://185[.]156[.]72[.]121/test/exe/random[.]exe |
Amadey |
URL | hxxp://185[.]156[.]72[.]121/files/unique2/random[.]exe | GCleaner |
URL | hxxps://download-server[.]online/Get?q=WinMTR | BumbleBee |
URL | hxxp://47[.]239[.]245[.]153:60103/linux hxxp://47[.]254[.]126[.]99:60100/linux hxxp://47[.]237[.]70[.]194:60130/linux hxxp://47[.]242[.]47[.]183:60101/linux |
P2Pinfect |
URL | hxxp://176[.]65[.]137[.]203/6677[.]elf hxxp://176[.]65[.]137[.]203/7767[.]elf hxxp://176[.]65[.]137[.]203/get[.]sh |
ConnectBack |
URL | hxxps://github[.]com/legendary99999/vdasvsdfvsdfv/releases/download/fdbafdbadba/Installer[.]exe | DarkComet |
URL | hxxps://github[.]com/legendary99999/bvsdfbsdgfbsfdgb/releases/download/vdafgbvadfvafdv/build[.]exe | XenoRAT |