不正URLへのアクセス、不正メールの受信
-
メール受信した
弊社お客様0社 URLアクセスした
弊社お客様3社 -
2025/05/26
※2025/05/26 更新
マルウェア感染させると考えられるURLを検知(2025/05/26)
■IoC(※1)
Type: | IOC: | Signature: |
---|---|---|
URL | hxxps://theipgenerators[.]com/uploads/onedriverservs[.]jpg hxxps://raw[.]githubusercontent[.]com/ducanh82919/ducanh/refs/heads/main/remcos_a[.]exe hxxp://185[.]29[.]9[.]60/400/kmn/bestintervaltimeforbestsuccestobe[.]hta hxxp://185[.]29[.]9[.]60/500/wevb/greathappinessentiretimeformegetback[.]hta hxxp://185[.]29[.]9[.]60/500/greathappinessentiretimeformegetback[.]txt hxxp://185[.]29[.]9[.]60/400/bestintervaltimeforbestsuccestobe[.]txt hxxp://107[.]172[.]132[.]32/xampp/kobf/kbf/goodgreatadvantagewithnnicepeoples[.]hta hxxp://91[.]219[.]151[.]227/xampp/kgnn/invitingforabestrestartcomegood[.]vbe hxxp://91[.]219[.]151[.]227/xampp/kgnn/kgn/invitingforabestrestartcomegood[.]hta hxxps://bayidestek[.]org/vm/gcwhhegwz[.]txt hxxp://91[.]219[.]151[.]227/xampp/kgnn/invitingforabestrestartcomegood[.]txt hxxp://107[.]172[.]132[.]32/xampp/kobf/goodgreatadvantagewithnnicepeoples[.]txt |
Remcos |
URL | hxxp://94[.]131[.]97[.]94:8000/exodo/loader[.]bin | donut_injector |
URL | hxxp://78[.]40[.]219[.]126:8000/shell[.]exe | Metasploit |
URL | hxxp://185[.]156[.]72[.]196/ycl | GCleaner |
URL | hxxp://62[.]60[.]226[.]191/svcldr[.]exe | RedLine Stealer |
URL | hxxp://193[.]42[.]36[.]21/02[.]08[.]2022[.]exe hxxp://89[.]23[.]116[.]202:50001/02[.]08[.]2022[.]exe hxxp://194[.]102[.]104[.]25:8443/02[.]08[.]2022[.]exe hxxp://154[.]221[.]16[.]38/02[.]08[.]2022[.]exe hxxp://47[.]93[.]4[.]110:8081/02[.]08[.]2022[.]exe hxxp://43[.]198[.]129[.]60:8080/02[.]08[.]2022[.]exe hxxp://68[.]64[.]176[.]72/02[.]08[.]2022[.]exe hxxp://167[.]172[.]71[.]139:7443/02[.]08[.]2022[.]exe hxxp://47[.]92[.]209[.]232:9090/02[.]08[.]2022[.]exe hxxp://154[.]198[.]50[.]83:4444/02[.]08[.]2022[.]exe hxxp://223[.]254[.]131[.]213/02[.]08[.]2022[.]exe hxxp://5[.]58[.]172[.]98:8080/02[.]08[.]2022[.]exe hxxp://5[.]58[.]172[.]98/02[.]08[.]2022[.]exe hxxp://49[.]51[.]135[.]62/02[.]08[.]2022[.]exe hxxp://www[.]tomo[.]ink:8888/airdrop-tool[.]exe hxxp://34[.]93[.]12[.]185/artifact_x64[.]exe hxxp://158[.]160[.]140[.]95:10500/a[.]exe hxxp://78[.]40[.]219[.]126:8000/test(1)[.]exe hxxp://124[.]71[.]137[.]28:28077/1220[.]exe hxxp://124[.]71[.]110[.]163:7450/02[.]08[.]2022[.]exe hxxp://146[.]190[.]90[.]236/02[.]08[.]2022[.]exe hxxp://121[.]40[.]229[.]202:2222/02[.]08[.]2022[.]exe hxxp://206[.]189[.]37[.]185:6699/02[.]08[.]2022[.]exe hxxp://118[.]24[.]22[.]168:8080/02[.]08[.]2022[.]exe hxxp://47[.]128[.]251[.]8:8080/02[.]08[.]2022[.]exe hxxp://149[.]104[.]31[.]203/02[.]08[.]2022[.]exe hxxp://152[.]136[.]17[.]91:6666/02[.]08[.]2022[.]exe hxxp://111[.]229[.]217[.]32:6666/02[.]08[.]2022[.]exe hxxp://178[.]128[.]20[.]233:6699/02[.]08[.]2022[.]exe hxxp://60[.]205[.]253[.]112:9955/MHRv hxxp://47[.]128[.]251[.]8:8089/02[.]08[.]2022[.]exe hxxp://47[.]117[.]125[.]219/02[.]08[.]2022[.]exe hxxp://60[.]205[.]253[.]112:9955/02[.]08[.]2022[.]exe hxxp://43[.]252[.]229[.]158:9898/02[.]08[.]2022[.]exe hxxp://121[.]61[.]98[.]177:444/02[.]08[.]2022[.]exe hxxp://139[.]159[.]157[.]238:55555/02[.]08[.]2022[.]exe |
Cobalt Strike |
URL | hxxps://github[.]com/legendary99999/cron22222/releases/download/vdfavbadfvadvav/cron2222222[.]exe hxxp://185[.]156[.]72[.]2/files/5876083921/LgEEypr[.]exe hxxps://github[.]com/legendary99999/corn1111111/releases/download/cron111111111/cron111111[.]exe hxxps://github[.]com/legendary99999/dfbvsfdbadb/releases/download/bafdbdfbsgdbd/alex21321321[.]exe hxxps://github[.]com/legendary99999/dsvdfvafd/releases/download/fdvsdfvavf/jokerererrer[.]exe hxxps://github[.]com/legendary99999/vdfvsfdvfs/releases/download/vdfsvsfds/htvp[.]exe hxxps://gofzm[.]digital/apx/api hxxp://185[.]156[.]72[.]2/files/6092752623/qc8MT4h[.]exe hxxp://185[.]156[.]72[.]2/files/5494432675/cawzlaZ[.]exe hxxp://185[.]156[.]72[.]2/files/1966372229/Ii9EI01[.]exe hxxps://writintrvh[.]top/login hxxps://www[.]sasha-solzhenicyn[.]ru/login hxxp://185[.]156[.]72[.]2/files/5494432675/1GJEEz3[.]exe hxxps://incqtq[.]run/jfsu/api hxxps://phoucc[.]digital/pxa/api hxxps://github[.]com/legendary99999/kjnjknjknkj/releases/download/kjnkjnmnkm/alex123121[.]exe hxxps://rustore[.]sasha-solzhenicyn[.]ru/login hxxp://185[.]156[.]72[.]2/files/944277523/cpaA9mT[.]exe hxxp://185[.]156[.]72[.]2/files/7395145367/PILIDWi[.]exe hxxp://185[.]156[.]72[.]2/files/7517730577/lDwQbjO[.]exe hxxp://www[.]sasha-solzhenicyn[.]ru/login hxxp://185[.]156[.]72[.]2/files/1241621040/bIoOQu3[.]exe hxxp://185[.]156[.]72[.]2/files/5494432675/47QcwMT[.]exe hxxps://cvzco[.]run/qiwo/api |
Lumma Stealer |
URL | hxxp://121[.]40[.]202[.]70/666[.]exe | Babar |
URL | hxxp://123[.]129[.]219[.]217:888/office[.]exe | Ghost RAT |
URL | hxxps://ace-project[.]org/d[.]js hxxps://sdnews[.]top/lv/select[.]js hxxps://sdnews[.]top/lv/ddas[.]php hxxps://windomstatetheater[.]com/rars[.]zip hxxp://185[.]207[.]133[.]123/fakeurl[.]htm hxxps://losartan[.]top/lv/xfa[.]js hxxps://losartan[.]top/lv/select[.]js hxxps://medthermography[.]com/ddas[.]php hxxps://medthermography[.]com/lebu[.]zip |
NetSupportManager RAT |
URL | hxxps://dnsgowindows-ds[.]org/Z9JThRRIL hxxps://windowsmsn-cn[.]live/pdsKPOzlxM hxxps://dnsgowindows-ds[.]org/gRMOgPz |
KongTuke |
URL | hxxp://45[.]93[.]20[.]28/c66c0eade263c9a8/nss3[.]dll? hxxp://176[.]65[.]142[.]161/9fbba3fc8079e5bb/nss3[.]dll hxxp://147[.]45[.]178[.]55/263ff79562167f22/sqlite3[.]dll hxxp://94[.]142[.]138[.]153/42fd16945056b8c5/nss3[.]dll hxxp://176[.]65[.]142[.]161/9fbba3fc8079e5bb/sqlite3[.]dll hxxps://github[.]com/legend1234561111/Ksjdjdjsnsns/releases/download/Isjsjsjss/8272722[.]exe hxxp://62[.]60[.]226[.]188/e9591576f6114884[.]php hxxp://185[.]156[.]72[.]2/files/1025416692/TIX1nL9[.]exe hxxp://185[.]156[.]72[.]2/files/1059862722/B4977Fk[.]exe |
Stealc |
URL | hxxps://raw[.]githubusercontent[.]com/EraHost/njjjnjnjn/main/Installer[.]exe hxxps://raw[.]githubusercontent[.]com/nahilagirl/s64projetc/refs/heads/main/AntiSpyware[.]exe hxxps://github[.]com/Hof6/R/raw/refs/heads/main/WindowsSecurity[.]exe hxxps://github[.]com/Hof6/R/raw/refs/heads/main/Windows[.]exe |
NjRAT |
URL | hxxps://raw[.]githubusercontent[.]com/servergame2024/yrdy/main/quasarat[.]exe hxxps://raw[.]githubusercontent[.]com/tienda4/musical/refs/heads/main/winstart[.]exe hxxps://raw[.]githubusercontent[.]com/Herodiw/julus/refs/heads/main/Discord[.]exe hxxps://raw[.]githubusercontent[.]com/Noxytheguy/imcrazy/refs/heads/main/System[.]exe hxxps://raw[.]githubusercontent[.]com/Waynesson/[.]Ps1-importer/refs/heads/main/Client-built[.]exe hxxps://raw[.]githubusercontent[.]com/biqbiqwibeqiebwiq/urban-couscous/refs/heads/main/king[.]exe hxxp://185[.]156[.]72[.]2/files/1781548144/ppcCcpS[.]exe |
Quasar RAT |
URL | hxxps://raw[.]githubusercontent[.]com/payoffz/tha-bronx-2-script-by-payoffz/refs/heads/main/bootstrapper[.]exe hxxps://raw[.]githubusercontent[.]com/SAMET10R/ProxyListforchecker/main/a[.]exe hxxps://raw[.]githubusercontent[.]com/SAMET10R/ProxyListforchecker/main/AsyncClient[.]exe hxxps://raw[.]githubusercontent[.]com/coderx666/i_miss_u/main/AsyncClient[.]exe hxxp://151[.]242[.]41[.]114/CvWizard/CvWizardV2[.]exe hxxp://bkngrvff[.]com/bgj3/ckjg[.]exe hxxp://185[.]156[.]72[.]2/files/5165347769/Z9zS9ZJ[.]exe hxxps://gykteam[.]org/chrome[.]exe hxxps://raw[.]githubusercontent[.]com/Fileupload123-sys/files/main/EpicGames[.]exe |
AsyncRAT |
URL | hxxp://nexuss[.]international/a[.]exe | XenoRAT |
URL | hxxp://196[.]251[.]72[.]33/m68k hxxp://196[.]251[.]72[.]33/mips64 hxxp://196[.]251[.]72[.]33/ppc |
MooBot |
URL | hxxp://107[.]172[.]132[.]57/GHGYQGmIoLLoFBmaNuW252[.]bin hxxp://107[.]172[.]132[.]57/NMjSlKwWQJ215[.]bin hxxp://107[.]172[.]132[.]31/pIsOkqyziBUlibd253[.]bin |
CloudEyE |
URL | hxxp://38[.]60[.]249[.]97/skid[.]mips hxxp://193[.]32[.]162[.]74/lol[.]mips hxxp://38[.]60[.]249[.]97/lol[.]mips hxxp://89[.]187[.]25[.]251/586 hxxp://89[.]187[.]25[.]251/dss hxxp://89[.]187[.]25[.]251/ppc hxxp://89[.]187[.]25[.]251/sh4 hxxp://89[.]187[.]25[.]251/i686 hxxp://89[.]187[.]25[.]251/co hxxp://89[.]187[.]25[.]251/x86 hxxp://89[.]187[.]25[.]251/mipsel hxxp://89[.]187[.]25[.]251/sex[.]sh hxxp://89[.]187[.]25[.]251/arm61 hxxp://89[.]187[.]25[.]251/mips hxxp://89[.]187[.]25[.]251/m68k hxxp://46[.]23[.]108[.]133/armv6l hxxp://46[.]23[.]108[.]133/armv4l hxxp://46[.]23[.]108[.]133/armv5l hxxp://46[.]23[.]108[.]133/sh4 hxxp://46[.]23[.]108[.]133/i686 hxxp://46[.]23[.]108[.]133/m68k hxxp://46[.]23[.]108[.]133/mipsel hxxp://46[.]23[.]108[.]133/i586 hxxp://207[.]244[.]244[.]252/sex[.]sh hxxp://207[.]244[.]244[.]252/arm61 |
Bashlite |
URL | hxxp://78[.]40[.]219[.]126:8000/LaZagne[.]exe | LaZagne |
URL | hxxp://78[.]40[.]219[.]126:8000/demon[.]x64[.]exe | Havoc |
URL | hxxp://78[.]40[.]219[.]126:8000/JuicyPotato[.]exe | JuicyPotato |
URL | hxxp://112[.]252[.]174[.]190:8888/Video[.]scr hxxp://112[.]252[.]174[.]190:8888/AV[.]scr hxxp://112[.]252[.]174[.]190:8888/Photo[.]scr hxxp://121[.]206[.]55[.]31:8899/AV[.]scr hxxp://121[.]206[.]55[.]31:8899/Video[.]scr hxxp://118[.]119[.]35[.]174:81/Video[.]scr hxxp://121[.]206[.]55[.]31:8899/Photo[.]scr hxxp://118[.]119[.]35[.]174:81/AV[.]scr hxxp://118[.]119[.]35[.]174:81/Photo[.]scr hxxp://176[.]65[.]149[.]220/aarch64 hxxp://176[.]65[.]149[.]220/x86_64 hxxp://185[.]156[.]72[.]2/files/5309343745/cOAm8Oh[.]exe hxxp://183[.]30[.]204[.]106:81/Photo[.]scr hxxp://116[.]133[.]72[.]4:20000/Photo[.]scr hxxp://116[.]133[.]72[.]4:20000/AV[.]scr hxxp://116[.]133[.]72[.]4:20000/Video[.]scr hxxp://183[.]30[.]204[.]106:81/AV[.]scr hxxp://183[.]30[.]204[.]106:81/Video[.]scr hxxp://185[.]156[.]72[.]2/files/6994673644/iB8CQ9J[.]exe hxxps://raw[.]githubusercontent[.]com/USC10001/Di/main/DNSLookup[.]cpl |
Coinminer |
URL | hxxp://103[.]40[.]161[.]135/DhlServer[.]exe hxxps://github[.]com/legendary99999/ndffdgsdfbvsd/releases/download/vdfssdfvsdv/nico12321312[.]exe |
Redosdru |
URL | hxxp://111[.]229[.]78[.]104/output_64[.]exe hxxp://185[.]156[.]72[.]2/files/5925264250/HAGtYlC[.]exe |
ValleyRAT |
URL | hxxp://195[.]82[.]146[.]131/hthsdb74/index[.]php hxxp://185[.]156[.]72[.]2/mine/random[.]exe |
Amadey |
URL | hxxps://khavar[.]com/aecheck2[.]txt hxxp://209[.]54[.]101[.]190/xampp/emmo/bestchoiceofnetworkwithgreatness[.]hta hxxp://209[.]54[.]101[.]190/580/TiWorker[.]exe hxxp://209[.]54[.]101[.]190/xampp/pom/weseethebestkingswithbetterperofrmance[.]hta hxxp://209[.]54[.]101[.]190/xampp/pom/po/weseethebestkingswithbetterperofrmance[.]hta hxxp://209[.]54[.]101[.]190/610/TiWorker[.]exe |
DBatLoader |
URL | hxxps://api[.]telegram[.]org/bot8191032015:AAH_iCE8cb9GhHq2MIO4ztZgeMw8hJJzmqk/sendMessage?chat_id=5426700465 hxxps://api[.]telegram[.]org/bot8116679558:AAFdKwNPiMVbIW9Kg4INxF41oUxDIqgVK2w/sendMessage?chat_id=7660849299 hxxps://api[.]telegram[.]org/bot7972921620:AAFo_-jqrPW8d-enR4-3pIyoIyvWzup4VRQ/sendMessage?chat_id=7255914643 hxxps://api[.]telegram[.]org/bot8120805029:AAESN3zy2OV4H3VKH0loSkFCeohYJ3w3Hb0/sendMessage?chat_id=1497043324 hxxp://213[.]209[.]150[.]18/plugmanff2[.]exe hxxps://api[.]telegram[.]org/bot8008875220:AAFutd6i_vZgq2dV6i0f-kXuP6CfkLICCDo/sendMessage?chat_id=5559571239 hxxp://213[.]209[.]150[.]18/obihh3[.]exe hxxps://api[.]telegram[.]org/bot7619784587:AAEE7qJaqrDRjIBD68kgAC0IckIOp4b9TQk/sendMessage?chat_id=1526443499 |
Snake Keylogger |
URL | hxxp://160[.]187[.]199[.]6:10002/mimikatz[.]exe hxxps://github[.]com/USC10001/Di/raw/refs/heads/main/Mizedo64[.]exe hxxps://github[.]com/USC10001/Di/raw/refs/heads/main/Mizedo[.]exe |
MimiKatz |
URL | hxxps://safekindkind[.]com/49282943[.]txt hxxps://safekindkind[.]com/Myreserv[.]pdf hxxp://195[.]82[.]146[.]131/HthsDb74/Plugins/v1[.]exe hxxp://195[.]82[.]146[.]131/HthsDb74/Plugins/v2[.]exe |
Vidar |
URL | hxxps://prepare[.]adroitbookkeeping[.]com/profileLayout | FAKEUPDATES |
URL | hxxp://213[.]209[.]150[.]18/agodhh3[.]exe hxxps://api[.]telegram[.]org/bot7652194569:AAFLWFEYaKfNfpFqGD7DCC1HKus8HDLSy8g/sendMessage?chat_id=6410945890 hxxps://api[.]telegram[.]org/bot8004081294:AAEeQb3kkdq-mgW3gSkEAnMJX0fU078688E/sendMessage?chat_id=6023628633 hxxp://209[.]54[.]101[.]190/600/TiWorker[.]exe |
MASS Logger |
URL | hxxp://213[.]209[.]150[.]210/css/VasuisUly[.]exe hxxps://dayzcheatcheck[.]online/nbpxworm[.]php hxxp://185[.]156[.]72[.]2/files/7276312541/KT3QQR7[.]bat |
XWorm |
URL | hxxp://94[.]154[.]35[.]115/user_profiles_photo/update[.]exe | PureLogs Stealer |
URL | hxxps://join[.]hjc[.]org[.]hk/wp-content/plugins/wp-either-forms/index[.]php?r=bD1odHRwczovL2RxcmRidi5jb20v | Latrodectus |
URL | hxxp://111[.]229[.]166[.]77:10086/CFHD[.]exe hxxp://111[.]229[.]166[.]77:10086/%E7%94%9F%E6%AD%BB%E7%8B%99%E5%87%BB2[.]exe hxxp://111[.]229[.]166[.]77:10086/%E6%B0%B8%E5%8A%AB[.]exe hxxp://111[.]229[.]166[.]77:10086/CS2[.]exe |
KrBanker |
URL | hxxp://89[.]23[.]99[.]246/43/DbWindowsBaseVoiddb/Multi6/image/Cdn/providertoJsServerdefaultTrafficUniversaltrack[.]php hxxp://188[.]120[.]225[.]17/Api/temporaryproton8traffic/Line2Game/_TempLocal/uploads7auth/3Flowertraffic/Geoauthlocal[.]php hxxp://185[.]156[.]72[.]2/files/7138747973/dFM0zy0[.]exe hxxp://terrychain[.]ru/linePythonWordpressdatalife[.]php hxxp://merilcraft[.]ru/vmtopollgameapiwindowsdownloads[.]php |
DCRat |
URL | hxxp://innovapan[.]cl/admin/panelnew/gate[.]php hxxp://topstitchshop[.]com/blog/wp-feed[.]php hxxp://luggagepoint[.]de/forum/viewtopic[.]php hxxp://193[.]32[.]68[.]21/p/gate[.]php |
Pony |
URL | hxxp://corklightlngtrade[.]com/part/setup3755[.]msi | MetaStealer |
URL | hxxp://209[.]54[.]101[.]190/590/TiWorker[.]exe hxxp://209[.]54[.]101[.]190/xampp/emmo/em/bestchoiceofnetworkwithgreatness[.]hta |
Formbook |
URL | hxxps://gknkargo[.]com/zxc/app[.]zip | AMOS |
URL | hxxps://h4[.]renewed-landline[.]top/shark[.]bin | Shark |
URL | hxxp://107[.]172[.]132[.]31/Paramelaconite[.]exe hxxp://107[.]175[.]246[.]32/xampp/rgb/nic/nicetoseeyoubesttingstodobetterwaysgivebetter________nicetoseeyoubesttingstodobetterwaysgivebetter_________nicetoseeyoubesttingstodobetterwaysgivebetter[.]doc |
Agent Tesla |
URL | hxxp://nkbada[.]online/cloud/API_Integration[.]pdf[.]lnk hxxp://integration[.]click/API_Integration[.]pdf[.]lnk hxxp://bmidrive[.]pro/API_Integration[.]pdf[.]lnk hxxp://140[.]82[.]16[.]230/cloud/API_Integration[.]pdf[.]lnk |
VenomLNK |
URL | hxxp://185[.]156[.]72[.]2/files/7279638629/BgB7nrb[.]exe | Rhadamanthys |
URL | hxxp://103[.]207[.]124[.]122:36267/Mozi[.]m | Mozi |