不正URLへのアクセス、不正メールの受信
-
メール受信した
弊社お客様0社 URLアクセスした
弊社お客様1社 -
2025/07/17
※2025/07/17 更新
マルウェア感染させると考えられるURLを検知(2025/07/17)
■IoC(※1)
Type: | IOC: | Signature: |
---|---|---|
URL | hxxps://codeveinsurance[.]info/lkki8494hd/8kkhdswrta/100/panel/uploads/Rkwhiakkhl[.]wav hxxp://198[.]46[.]173[.]60/34/bethebestpeoplesentiretimeforbestkeepingskillwithbetter[.]vbe hxxp://198[.]46[.]173[.]60/34/cvn/bethebestpeoplesentiretimeforbestkeepingskillwithbetter_________bethebestpeoplesentiretimeforbestkeepingskillwithbetter__________bethebestpeoplesentiretimeforbestkeepingskillwithbetter[.]doc |
Remcos |
URL | hxxps://sontungcoffee[.]com/wr[.]txt hxxps://b2breservas[.]shop/Upcrypter/02/MeusArquivos03[.]txt hxxps://b2breservas[.]shop/Upcrypter/02/MeusArquivos01[.]txt hxxps://b2breservas[.]shop/Upcrypter/02/MeusArquivos02[.]txt |
Warzone RAT |
URL | hxxp://162[.]248[.]53[.]119:8000/run[.]sh[.]bkp hxxp://162[.]248[.]53[.]119:8000/run-CN[.]sh hxxp://162[.]248[.]53[.]119:8000/run[.]sh hxxps://www[.]wgetfiles[.]com/f/cj[.]exe hxxp://162[.]248[.]53[.]119:8000/tnn[.]ps1 hxxps://raw[.]githubusercontent[.]com/fussin54654/batcher/refs/heads/main/xmrig[.]exe hxxps://raw[.]githubusercontent[.]com/fussin54654/batcher/refs/heads/main/ethminer[.]exe |
Coinminer |
URL | hxxp://176[.]46[.]157[.]32/files/5254702106/uNk9nyt[.]exe hxxp://176[.]46[.]157[.]60/inc/stub[.]exe |
SalatStealer |
URL | hxxp://176[.]46[.]157[.]60/inc/cron20252[.]exe hxxp://176[.]46[.]157[.]60/inc/alex2025[.]exe hxxp://167[.]160[.]161[.]247/l8890f[.]exe hxxp://176[.]46[.]157[.]60/inc/cron20251[.]exe hxxps://kilcvv[.]top/xdod hxxps://collb[.]shop/tiwq hxxps://elilzy[.]shop/aggs hxxps://inbeso[.]lat/pdgs hxxps://germon[.]pics/taiw hxxps://gigohe[.]top/diau hxxps://blihlo[.]shop/atkg hxxps://creewuh[.]shop/qazx hxxps://gunrightsp[.]run/bksaHyg hxxps://blockhubr[.]live/jhgf hxxps://clammyblushi[.]biz/api hxxps://offbeat-moans[.]cyou/api hxxps://thehealthylifesstop[.]top/api hxxps://kbracketba[.]shop/Bdwo hxxps://fearleszsjourney[.]tech/api hxxps://creativeoutlookstop[.]top/api hxxps://thrivintgcommunity[.]top/api hxxps://balfts[.]lat/zanb hxxps://unicorntop[.]top/api hxxps://digitalmarketing101[.]click/api hxxps://plugboth[.]digital/AOijsau hxxps://hopezx[.]run/opsgz hxxps://resonantpasot[.]icu/api hxxps://investiigato[.]website/api hxxps://vwibrantwonders[.]rest/api hxxps://genhqq[.]xyz/gair hxxps://crowdwarek[.]shop/C hxxps://minndfulpath[.]top/api hxxps://gecoea[.]lat/daiw hxxps://scieseandbeyond[.]world/api hxxps://theadventureclubstop[.]top/api hxxps://boldcyanvas[.]top/api hxxps://nuttyshopr[.]biz/j hxxps://guerp[.]xyz/faif hxxps://uncombsguq[.]xyz/aziq hxxps://adventurestoptop[.]top/api hxxps://fluffycqomfort[.]world/QweD hxxps://tawdrydadysz[.]icu/api hxxps://shfsz[.]xyz/xjda hxxps://sizefixeds[.]icu/api hxxps://lossekniyyt[.]click/api hxxps://hypothesizys[.]click/api hxxps://advertised[.]life/api hxxps://crimod[.]xyz/gsew hxxps://snras[.]run/lxad hxxps://cheapptaxysu[.]click/api hxxps://thebeautylovelytop[.]top/api hxxps://joyfulhezart[.]tech/api hxxps://azurgewhisper[.]hair/api hxxps://fieldhitty[.]click/api hxxps://digitmopdg[.]live/fhyy hxxps://gratcf[.]digital/apd hxxps://nebdulaq[.]digital/aQwdw hxxps://spifd[.]top/aiuw hxxp://176[.]46[.]157[.]32/files/6691015685/EkddUAg[.]exe |
Lumma Stealer |
URL | hxxp://176[.]46[.]157[.]32/files/7896190691/7fVfch6[.]exe hxxp://176[.]46[.]157[.]32/files/6335391544/CK5X8md[.]exe |
Rhadamanthys |
URL | hxxp://141[.]98[.]6[.]181/4c8837c73f7c4af9[.]php hxxp://87[.]120[.]93[.]21/78b887e60b7f4fed[.]php hxxp://147[.]45[.]47[.]68/a8f961c72f0d877c[.]php |
Stealc |
URL | hxxp://213[.]209[.]150[.]18/1nklk1vPbjjueqLnywd[.]exe hxxp://213[.]209[.]150[.]18/23bjnklk1vjuaLnylppp[.]exe hxxps://api[.]telegram[.]org/bot7628702957:AAE--AGhaDpshWOvl1V7RgIJq4LxUxuphC8/sendMessage?chat_id=7786667883 |
MASS Logger |
URL | hxxp://176[.]46[.]157[.]32/files/7912714940/cavng54[.]exe | DarkComet |
URL | hxxps://1182[.]jp/wp-content/Milinch[.]csv hxxps://1182[.]jp/wp-content/dNWoIAthDruRKG57[.]bin |
CloudEyE |
URL | hxxp://46[.]105[.]34[.]222/svc[.]lnk hxxp://15[.]235[.]176[.]226/svr[.]scr |
Quasar RAT |
URL | hxxp://89[.]23[.]103[.]161/Downloads/Report[.]lnk hxxps://tripplefury[.]com/pword/partygirlfun2017 |
Emmenhtal |
URL | hxxp://172[.]94[.]96[.]95/panel/gate[.]php | Athena |
URL | hxxp://213[.]209[.]150[.]18/53Pbjnklk1vuMaLnyll[.]exe | XWorm |
URL | hxxps://api[.]telegram[.]org/bot7146044656:AAHIAaiM_rAN9e7GBvEIRqFXjFy_1UyoQpc/sendMessage?chat_id=7660849299 | Snake Keylogger |
URL | hxxp://8[.]138[.]187[.]231/02[.]08[.]2022[.]exe hxxp://47[.]245[.]90[.]197/02[.]08[.]2022[.]exe hxxp://155[.]94[.]175[.]189/02[.]08[.]2022[.]exe hxxp://8[.]130[.]191[.]106/02[.]08[.]2022[.]exe hxxp://223[.]4[.]33[.]190/02[.]08[.]2022[.]exe hxxp://8[.]130[.]191[.]106:18080/02[.]08[.]2022[.]exe hxxp://47[.]237[.]173[.]81/02[.]08[.]2022[.]exe hxxp://124[.]223[.]54[.]248/02[.]08[.]2022[.]exe hxxp://106[.]12[.]215[.]229:8080/02[.]08[.]2022[.]exe hxxp://189[.]1[.]243[.]105:4443/02[.]08[.]2022[.]exe hxxp://120[.]24[.]241[.]109:6001/02[.]08[.]2022[.]exe hxxp://47[.]120[.]48[.]100/02[.]08[.]2022[.]exe hxxp://1[.]94[.]98[.]11:8082/02[.]08[.]2022[.]exe hxxp://91[.]245[.]254[.]86/02[.]08[.]2022[.]exe hxxp://118[.]31[.]18[.]77:1000/02[.]08[.]2022[.]exe hxxp://123[.]57[.]245[.]136:1332/02[.]08[.]2022[.]exe hxxp://39[.]101[.]64[.]124:9999/02[.]08[.]2022[.]exe hxxp://47[.]121[.]136[.]179:443/02[.]08[.]2022[.]exe hxxp://217[.]154[.]212[.]25:8080/02[.]08[.]2022[.]exe hxxp://146[.]70[.]79[.]53/02[.]08[.]2022[.]exe hxxp://42[.]193[.]4[.]115:6666/02[.]08[.]2022[.]exe hxxp://49[.]235[.]64[.]155:4444/02[.]08[.]2022[.]exe hxxp://42[.]193[.]231[.]41:443/02[.]08[.]2022[.]exe hxxp://43[.]138[.]22[.]149:8080/02[.]08[.]2022[.]exe |
Cobalt Strike |
URL | hxxp://185[.]216[.]68[.]35/win/checking[.]ps1 hxxps://github[.]com/fussin54654/batcher/releases/download/python/xmrig[.]exe hxxps://github[.]com/fussin54654/batcher/releases/download/python/ethminer[.]exe |
XMRig |
URL | hxxp://www[.]tbi5r[.]top/um09/ hxxp://www[.]uckice[.]shop/um09/ hxxp://www[.]uestrasenda[.]cloud/um09/ hxxp://www[.]uperstar360[.]net/um09/ hxxp://www[.]uxe[.]rent/um09/ hxxp://www[.]uziweilai[.]top/um09/ hxxp://www[.]vhlkau0[.]xyz/um09/ hxxp://www[.]viary[.]lol/um09/ hxxp://www[.]wxyn3[.]top/um09/ hxxp://www[.]oma[.]club/um09/ hxxp://www[.]ook[.]photo/um09/ hxxp://www[.]oungandassociatesmusic[.]net/um09/ hxxp://www[.]ov-imhg[.]live/um09/ hxxp://www[.]ov-pukr[.]cfd/um09/ hxxp://www[.]pcigieikmfhw[.]website/um09/ hxxp://www[.]pujosa[.]top/um09/ hxxp://www[.]rand-bewin[.]pro/um09/ hxxp://www[.]rbetano[.]app/um09/ hxxp://www[.]mphmu[.]top/um09/ hxxp://www[.]mstj[.]xyz/um09/ hxxp://www[.]ndke[.]top/um09/ hxxp://www[.]ndovsjepangkemarin7[.]buzz/um09/ hxxp://www[.]nerrj[.]vip/um09/ hxxp://www[.]nr1fp[.]top/um09/ hxxp://www[.]nugglebuds[.]net/um09/ hxxp://www[.]okerdom0398[.]buzz/um09/ hxxp://www[.]olarisfinance[.]pro/um09/ hxxp://www[.]oldchain-br037[.]sbs/um09/ hxxp://www[.]iberacaaodigital[.]shop/um09/ hxxp://www[.]ingerie-22584[.]bond/um09/ hxxp://www[.]ireoverseasgroup[.]shop/um09/ hxxp://www[.]itrinkizi20[.]xyz/um09/ hxxp://www[.]ittledeath[.]art/um09/ hxxp://www[.]j5[.]top/um09/ hxxp://www[.]levatedynamics[.]net/um09/ hxxp://www[.]lmj8zx[.]pro/um09/ hxxp://www[.]mersdty[.]xyz/um09/ hxxp://www[.]awangmburiabang[.]sbs/um09/ hxxp://www[.]c3471[.]top/um09/ hxxp://www[.]cto[.]design/um09/ hxxp://www[.]diryacare[.]xyz/um09/ hxxp://www[.]edresans[.]cfd/um09/ hxxp://www[.]emoreplay[.]shop/um09/ hxxp://www[.]evxxw[.]top/um09/ hxxp://www[.]h44x[.]top/um09/ hxxp://www[.]ancyglobal[.]capital/um09/ hxxp://www[.]anopyops[.]net/um09/ hxxp://www[.]ansenlan[.]net/um09/ hxxp://www[.]apitronis[.]xyz/um09/ hxxp://www[.]apply[.]xyz/um09/ hxxp://www[.]aptrailhunterzone[.]click/um09/ hxxp://www[.]aroon[.]media/um09/ hxxp://www[.]ataract-surgery-85805[.]bond/um09/ hxxp://www[.]atchehub[.]xyz/um09/ hxxp://www[.]avinnorris[.]shop/um09/ hxxp://www[.]46[.]top/um09/ hxxp://www[.]66ny5[.]top/um09/ hxxp://www[.]89clubb[.]art/um09/ hxxp://www[.]8vip135[.]net/um09/ hxxp://www[.]ailseent[.]cfd/um09/ hxxp://www[.]alank[.]ltd/um09/ hxxp://www[.]amtech[.]dev/um09/ hxxp://www[.]0qpd5[.]click/um09/ hxxp://www[.]1f8zn[.]click/um09/ hxxp://www[.]3-155-18-241[.]lol/um09/ |
Formbook |
URL | hxxps://sos-atlanta[.]com/mohs[.]zip hxxps://sizzlingcareer[.]com/beqw[.]zip hxxps://sos-atlanta[.]com/besm[.]zip hxxps://ashesplayer[.]top/jjj/include[.]js hxxps://ashesplayer[.]top/jjj/buffer[.]js hxxp://sizzlingcareer[.]com/lal[.]ps1 hxxps://sizzlingcareer[.]com/lal[.]ps1 hxxps://bedoueroom[.]top/kll/buf[.]js |
NetSupportManager RAT |
URL | hxxp://185[.]100[.]157[.]217:85/Captcha[.]exe hxxps://api[.]telegram[.]org/bot7968139020:AAGRChL7dWuVKo0vXIeFvLSyn6oA3yW3Hk8/sendMessage hxxps://api[.]telegram[.]org/bot7625290642:AAEC_TIsp8mXV-r4b_JsskPORSmz8QErTI0/sendMessage hxxps://api[.]telegram[.]org/bot6699976426:AAH3LwiM2DsMRmtymDdBYW-cxNazRC7Tx3E/sendMessage hxxps://api[.]telegram[.]org/bot7242353426:AAE0UMuUCXqSmPT1HXOO869O-44QR09kZwU/sendMessage hxxp://176[.]46[.]157[.]32/files/8111443583/YT1For2[.]exe |
AsyncRAT |
URL | hxxps://raw[.]githubusercontent[.]com/pcman223/discord-Rat-Maker/refs/heads/main/Built[.]exe | BlankGrabber |
URL | hxxp://162[.]248[.]53[.]119:8000/kwthread | Merlin |
URL | hxxps://m[.]awareinsurance[.]com/viewDashboard | FAKEUPDATES |
URL | hxxp://77[.]83[.]245[.]64/UPZDKGAF[.]bin | Ghost RAT |