不正URLへのアクセス、不正メールの受信
-
メール受信した
弊社お客様0社 URLアクセスした
弊社お客様2社 -
2025/07/22
※2025/07/22 更新
マルウェア感染させると考えられるURLを検知(2025/07/22)
■IoC(※1)
Type: | IOC: | Signature: |
---|---|---|
URL | hxxp://176[.]46[.]157[.]32/files/5373596444/E56Hmst[.]exe | PureLogs Stealer |
URL | hxxp://176[.]46[.]157[.]60/inc/Fold[.]exe hxxp://176[.]46[.]157[.]32/files/6345767864/0m410bx[.]exe hxxps://famigh[.]shop/xpal hxxps://shopmeyxc[.]pro/5[.]exe hxxp://176[.]46[.]157[.]32/files/8072533983/7ZDjVO6[.]exe hxxps://cooawbi[.]top/dpla hxxps://ourkbpw[.]top/aoti hxxps://saviutf[.]pics/tiwq hxxps://swalocf[.]lat/atxi hxxps://aczpy[.]pics/daog hxxps://cawbn[.]pics/zjdu hxxps://exveaxa[.]lat/atjx hxxps://thoqp[.]lat/zidw hxxps://cichau[.]lat/agbn hxxps://bluepxd[.]shop/xait hxxp://176[.]46[.]157[.]60/inc/cron2[.]exe hxxp://176[.]46[.]157[.]60/inc/cron1[.]exe hxxps://fedrodj[.]top/xkdw hxxps://castdyt[.]pics/zajg hxxp://176[.]46[.]157[.]60/inc/alex12312[.]exe hxxps://banati[.]sasha-solzhenicyn[.]ru/login hxxps://www[.]ucoxqdemo[.]fedor-turin[.]ru/login hxxps://www[.]b[.]sasha-solzhenicyn[.]ru/login hxxps://cometopa[.]top/xlda hxxps://posteqz[.]top/aoot hxxps://karapvc[.]pics/gkld hxxps://rubeuiq[.]pics/tkka hxxps://wrfygsi[.]lat/xxaz hxxps://srlemnhg[.]top/adxd hxxps://rootino[.]top/tqoi hxxps://rhiuit[.]shop/agpr hxxps://strujqwn[.]xyz/xkkd hxxps://siniavzv[.]life/xajz hxxps://seruneqy[.]live/akiz hxxps://recopcwr[.]top/atki hxxps://permwgp[.]xyz/xlak hxxps://bornim[.]top/xoak hxxp://176[.]46[.]157[.]32/files/1013240947/OT5TCkJ[.]exe hxxps://tunenrnc[.]top/xodz hxxps://ultracpj[.]xyz/apgk hxxps://vegemuoe[.]top/xauy hxxps://leftmxfg[.]lol/atmn/api hxxps://sworwdcp[.]top/aote hxxp://176[.]46[.]157[.]32/files/5356600191/3ZfDlBR[.]exe hxxps://pavansmr[.]pics/akjt hxxps://accepkw[.]shop/xlor hxxps://cuwewki[.]shop/wqiz hxxps://nowqx[.]xyz/taos hxxps://jaclwdc[.]top/ziur hxxps://pandhnyk[.]top/zids hxxps://wlldberries[.]pro/3[.]exe hxxp://176[.]46[.]157[.]32/files/1013240947/LXBYr17[.]exe hxxps://github[.]com/echenn1/1lmar/raw/refs/heads/main/stub4[.]exe hxxps://github[.]com/strenn1h/Monotone-HWID-Spoofer/raw/refs/heads/main/Monotone[.]exe hxxps://github[.]com/l1WAyn3/FiveM-Spoofer/raw/refs/heads/main/CFXBypass[.]exe hxxps://calioons[.]top/xiwu hxxps://jalonla[.]top/atuy hxxps://worlejrc[.]xyz/xaiw hxxps://corronxu[.]xyz/xowq hxxps://neocskfj[.]lol/atiw/api hxxps://inveimzd[.]lol/zldk/api hxxps://loxinxg[.]pics/atnd hxxps://iosivtoah[.]lat/twqx hxxps://irreesarw[.]top/zlad hxxps://sitemap[.]fedor-turin[.]ru/login hxxps://167[.]160[.]161[.]11/login |
Lumma Stealer |
URL | hxxp://176[.]46[.]157[.]32/files/1013240947/wJc43xr[.]exe hxxp://176[.]46[.]157[.]32/files/1013240947/IJTK85d[.]exe hxxp://176[.]46[.]157[.]32/files/1013240947/hRKvkgT[.]exe |
NjRAT |
URL | hxxp://139[.]99[.]115[.]205/ba[.]scr hxxp://176[.]46[.]157[.]32/files/5676046372/hGT8gAm[.]exe |
Quasar RAT |
URL | hxxp://sleaqwad[.]shop/45cc90de006049c9[.]php | Stealc |
URL | hxxp://soyasticks[.]club/user/joe/five/fre[.]php hxxp://quantumegypt[.]com/images/navigation/enclosures/xvc/admin2/fre[.]php hxxp://bapican[.]com/bin/javascript/Panel/five/fre[.]php hxxps://94[.]156[.]177[.]41/mrt/five/PvqDq929BSx_A_D_M1n_a[.]php hxxp://closaparent[.]com/broker/five/fre[.]php hxxp://kings[.]jesseworld[.]eu/five/five/fre[.]php hxxp://papgon10[.]ru/rozay/fred[.]php hxxp://mulyadi[.]co[.]id/wp-includes/look/Panel/five1/fre[.]php |
LokiBot |
URL | hxxps://yorja[.]org/?u=osxxx | StrelaStealer |
URL | hxxp://176[.]46[.]157[.]32/files/7256252040/H43M3PI[.]exe | XenoRAT |
URL | hxxp://176[.]46[.]157[.]32/files/7716073527/b72PpfJ[.]exe | Vidar |
URL | hxxps://cdn[.]tagbox[.]io/assets/6842fd214eab980011f42899/4a50f66b-8dbf-46b6-b09d-c1fc220ff15a---msi_mpg[.]jpg hxxp://176[.]46[.]157[.]32/files/938772541/nSm55B1[.]exe |
Remcos |
URL | hxxps://bond007[.]xyz/publishertag/apstag[.]js hxxps://bond007[.]xyz/publishertag/buffer[.]js hxxp://getcredentialingdone[.]com/lal[.]ps1 hxxps://www[.]getcredentialingdone[.]com/hsqw[.]zip hxxps://buildingjobs[.]xyz/tag/buffer[.]js hxxp://ignifugacionsarguix[.]com/lal[.]ps1 hxxps://ignifugacionsarguix[.]com/momo[.]zip hxxps://streaming-films[.]xyz/tag/tag[.]js hxxps://streaming-films[.]xyz/tag/buffer[.]js hxxp://www[.]austinroofs[.]net/hs[.]ps1 hxxp://www[.]austinroofs[.]net/hsmo[.]zip |
NetSupportManager RAT |
URL | hxxps://dl[.]newtoyourgame[.]com/viewDashboard hxxps://manwithedhelp[.]top/files/loop[.]js hxxps://manwithedhelp[.]top/files/index[.]php hxxps://jiezishijie[.]top/files/index[.]php hxxps://jiezishijie[.]top/files/vi[.]php hxxps://jiezishijie[.]top/files/loop[.]js hxxps://abtsi[.]com/4r2e[.]js hxxps://app[.]novationseo[.]com/viewDashboard |
FAKEUPDATES |
URL | hxxp://176[.]46[.]157[.]32/files/6335391544/9mL4zC7[.]exe hxxp://176[.]46[.]157[.]32/files/6335391544/C0op6ik[.]exe hxxp://176[.]46[.]157[.]32/files/7571974446/mPXNFkZ[.]exe hxxp://176[.]46[.]157[.]32/files/6335391544/MD8FdPH[.]exe hxxp://176[.]46[.]157[.]32/files/7929079921/FypNDh8[.]exe |
Coinminer |
URL | hxxp://176[.]46[.]157[.]32/files/7395374685/7Un6LSu[.]exe hxxps://13[.]124[.]220[.]164/phpmyadmin/index[.]php hxxp://logrecovery[.]com/hmfd8ejdS/Login[.]php hxxp://176[.]46[.]157[.]60/d8tr4u9k/index[.]php hxxp://66[.]63[.]187[.]111/Waaagh/index[.]php hxxp://176[.]46[.]157[.]60/d8tr4u9k/Login[.]php hxxp://66[.]63[.]187[.]111/Waaagh/Login[.]php hxxp://176[.]46[.]157[.]32/files/8085140108/2L8HOn5[.]exe |
Amadey |
URL | hxxp://982361cm[.]nyash[.]es/imagelineLongpollDefaultdbuploads[.]php hxxp://195[.]62[.]49[.]187/providerpythonlowbigload[.]php hxxp://132961cm[.]nyash[.]es/Flowerdatalife[.]php |
DCRat |
URL | hxxp://172[.]245[.]95[.]38/xcIeLenvM223[.]bin hxxp://172[.]245[.]95[.]38/KTtiGNTyCEVcaZ148[.]bin hxxp://96[.]44[.]154[.]199/MMxWCNqQMQAmGYMMP123[.]bin hxxp://172[.]245[.]95[.]38/KbLCFnCOWvWtk84[.]bin |
CloudEyE |
URL | hxxp://207[.]167[.]64[.]24/sh4 hxxp://45[.]135[.]194[.]156/Gamma[.]mpsl hxxp://45[.]135[.]194[.]156/Gamma[.]x86_64 hxxp://45[.]135[.]194[.]156/Gamma[.]sh4 hxxp://45[.]135[.]194[.]156/Gamma[.]arm6 hxxp://45[.]135[.]194[.]156/Gamma[.]mips hxxp://45[.]135[.]194[.]156/Gamma[.]arm7 hxxp://45[.]135[.]194[.]156/Gamma[.]m68k hxxp://45[.]135[.]194[.]156/Gamma[.]x86 hxxp://45[.]135[.]194[.]156/Gamma[.]arm5 hxxp://196[.]251[.]66[.]32/HBTs/top1miku[.]mipsel hxxp://196[.]251[.]66[.]32/HBTs/top1miku[.]powerpc hxxp://45[.]135[.]194[.]156/Gamma[.]ppc hxxp://172[.]96[.]14[.]125/sh4 hxxp://45[.]135[.]194[.]156/c[.]sh hxxp://45[.]125[.]66[.]95/mpsl hxxp://45[.]125[.]66[.]95/mips hxxp://115[.]187[.]17[.]117/gmpsl hxxp://115[.]187[.]17[.]117/garm7 hxxp://115[.]187[.]17[.]117/lmips hxxp://115[.]187[.]17[.]117/lmpsl hxxp://115[.]187[.]17[.]117/xmips hxxp://115[.]187[.]17[.]117/gompsl hxxp://115[.]187[.]17[.]117/gmips hxxp://50[.]3[.]47[.]60/m-6[.]8-k[.]Sakura hxxp://50[.]3[.]47[.]60/a-r[.]m-7[.]Sakura hxxp://50[.]3[.]47[.]60/a-r[.]m-4[.]Sakura hxxp://50[.]3[.]47[.]60/x-3[.]2-[.]Sakura hxxp://50[.]3[.]47[.]60/i-5[.]8-6[.]Sakura hxxp://50[.]3[.]47[.]60/m-i[.]p-s[.]Sakura hxxp://50[.]3[.]47[.]60/x-8[.]6-[.]Sakura hxxp://50[.]3[.]47[.]60/p-p[.]c-[.]Sakura hxxp://50[.]3[.]47[.]60/s-h[.]4-[.]Sakura hxxp://50[.]3[.]47[.]60/a-r[.]m-6[.]Sakura hxxp://50[.]3[.]47[.]60/a-r[.]m-5[.]Sakura hxxp://50[.]3[.]47[.]60/m-p[.]s-l[.]Sakura hxxp://89[.]116[.]20[.]194:81/armv5l |
Bashlite |
URL | hxxp://176[.]46[.]157[.]32/files/1060542873/GPgb8s5[.]exe hxxp://176[.]46[.]157[.]32/files/7677226784/vRDhILL[.]exe |
XWorm |
URL | hxxps://www[.]technoproject[.]it/doc/Sammensvejsendes[.]fla hxxps://www[.]technoproject[.]it/doc/Apraxia[.]pcx hxxp://www[.]whqrsj[.]com/hx287/ hxxp://www[.]winchesuk[.]co[.]uk/hx287/ hxxp://www[.]xiaoxiaoqi[.]net/hx287/ hxxp://www[.]xn--0tr47cry2eihq[.]net/hx287/ hxxp://www[.]yget[.]ltd/hx287/ hxxp://www[.]yiyangguoji[.]com/hx287/ hxxp://www[.]yizhiting[.]kim/hx287/ hxxp://www[.]yourdiscountrealtor[.]com/hx287/ hxxp://www[.]zixuetiandi[.]com/hx287/ hxxp://www[.]qova[.]ltd/hx287/ hxxp://www[.]seedsoffashion[.]com/hx287/ hxxp://www[.]shop-kuyou[.]com/hx287/ hxxp://www[.]sntzag[.]info/hx287/ hxxp://www[.]solucionservihogar[.]com/hx287/ hxxp://www[.]souzan-haddad[.]com/hx287/ hxxp://www[.]styleswithrobin[.]com/hx287/ hxxp://www[.]sunsetserenadenc[.]com/hx287/ hxxp://www[.]talk2ipsos[.]com/hx287/ hxxp://www[.]thebucktowntaproom[.]com/hx287/ hxxp://www[.]tztauto[.]com/hx287/ hxxp://www[.]unitedfinancesavings[.]com/hx287/ hxxp://www[.]watchbracket[.]com/hx287/ hxxp://www[.]whdebang[.]com/hx287/ hxxp://www[.]jinkou-sh[.]com/hx287/ hxxp://www[.]karmes[.]net/hx287/ hxxp://www[.]keepcrueltyhistory[.]com/hx287/ hxxp://www[.]llong678[.]com/hx287/ hxxp://www[.]lumiereinvestments[.]net/hx287/ hxxp://www[.]m2glutenfree[.]com/hx287/ hxxp://www[.]missionssummit[.]com/hx287/ hxxp://www[.]mohecao[.]com/hx287/ hxxp://www[.]neteducation4you[.]com/hx287/ hxxp://www[.]news3039[.]gripe/hx287/ hxxp://www[.]nhacaiw88[.]info/hx287/ hxxp://www[.]novite-mebeli[.]info/hx287/ hxxp://www[.]panama123456[.]com/hx287/ hxxp://www[.]ponyblood[.]com/hx287/ hxxp://www[.]divasofdesignboutique[.]com/hx287/ hxxp://www[.]dtoo[.]ltd/hx287/ hxxp://www[.]dyzns[.]com/hx287/ hxxp://www[.]eiwqcorp[.]com/hx287/ hxxp://www[.]garanthemedical[.]com/hx287/ hxxp://www[.]globale-finance48[.]com/hx287/ hxxp://www[.]globe-fish-test[.]net/hx287/ hxxp://www[.]go2tips[.]com/hx287/ hxxp://www[.]hbcyzmdj[.]com/hx287/ hxxp://www[.]hibtp[.]com/hx287/ hxxp://www[.]imagic-inc[.]net/hx287/ hxxp://www[.]iphonex[.]city/hx287/ hxxp://www[.]itaucard-descontos[.]net/hx287/ hxxp://www[.]jbatherholt[.]net/hx287/ hxxp://www[.]085097[.]com/hx287/ hxxp://www[.]2067lindavista[.]info/hx287/ hxxp://www[.]artmaior[.]com/hx287/ hxxp://www[.]bitcoinwalletco[.]com/hx287/ hxxp://www[.]boardwnel[.]net/hx287/ hxxp://www[.]c27be5aon[.]online/hx287/ hxxp://www[.]cashusa-support[.]com/hx287/ hxxp://www[.]chiru-atelier[.]com/hx287/ hxxp://www[.]covpsychiz[.]com/hx287/ hxxp://www[.]cpab-marbeuf[.]com/hx287/ hxxp://www[.]creation--site--internet[.]com/hx287/ hxxp://www[.]creditreportdr[.]com/hx287/ hxxp://www[.]csmtasima[.]com/hx287/ hxxp://www[.]despacho360[.]com/hx287/ hxxp://213[.]209[.]150[.]18/bjnklkeqvjuMaLnym[.]exe hxxp://77[.]90[.]153[.]74/ch[.]exe |
Formbook |
URL | hxxps://api[.]telegram[.]org/bot8078802821:AAGwBPKGHHkp6Us6iMh_VHqHkgUkain56Fk/sendMessage?chat_id=8102497587 hxxps://api[.]telegram[.]org/bot8022335561:AAEn8c2C2M8LJjKwVqJo5PY1K1AqIIWI7jc/sendMessage?chat_id=7731003424 |
MASS Logger |
URL | hxxps://system6-mxe-ups3[.]com/goN9Z2In7mYQmN92dzX11CQL[.]php hxxps://system6-mxe-ups3[.]com/p5Pss34GvX21pxO0bz25vLqU[.]php |
StrongPity |
URL | hxxp://hurampronand[.]com/mlu/forum[.]php hxxp://probominku[.]ru/mlu/forum[.]php hxxp://theintrughe[.]ru/mlu/forum[.]php hxxp://defeat-autism[.]com/forum/viewtopic[.]php hxxp://defeat-autism[.]org/forum/viewtopic[.]php hxxp://jadecreditdesign[.]com/forum/viewtopic[.]php hxxp://glgkorea[.]com/forum/viewtopic[.]php hxxp://adrianjones[.]net/KoCH31yz[.]exe hxxp://chipconveyors[.]co[.]in/MTRUvt[.]exe hxxp://colemanandassociates[.]ca/BBppY[.]exe hxxp://joshihospitalpvtltd[.]com/NzKUU[.]exe hxxp://raylan[.]com/ejQ88c[.]exe hxxp://timconnorscoach[.]com/kZNzE7[.]exe hxxp://www[.]hvh-immo[.]de/YcA3S[.]exe hxxp://yashodaseeds[.]com/xFSEzRYR[.]exe |
Pony |
URL | hxxp://160[.]250[.]129[.]6:8080/02[.]08[.]2022[.]exe hxxp://47[.]109[.]140[.]12:4432/02[.]08[.]2022[.]exe hxxp://118[.]178[.]89[.]112/02[.]08[.]2022[.]exe hxxp://47[.]245[.]61[.]75:6666/02[.]08[.]2022[.]exe hxxp://59[.]110[.]81[.]93:9999/02[.]08[.]2022[.]exe hxxp://117[.]72[.]223[.]157/02[.]08[.]2022[.]exe hxxp://42[.]51[.]34[.]56:8009/02[.]08[.]2022[.]exe hxxp://114[.]116[.]18[.]42:2087/02[.]08[.]2022[.]exe hxxp://47[.]96[.]224[.]76:9999/02[.]08[.]2022[.]exe hxxp://137[.]220[.]232[.]142:25364/02[.]08[.]2022[.]exe hxxp://106[.]14[.]118[.]159:7777/02[.]08[.]2022[.]exe hxxp://43[.]163[.]221[.]96:8080/02[.]08[.]2022[.]exe hxxp://124[.]221[.]116[.]169/02[.]08[.]2022[.]exe hxxp://172[.]235[.]29[.]53/02[.]08[.]2022[.]exe hxxp://1[.]94[.]137[.]198:9989/02[.]08[.]2022[.]exe hxxp://117[.]50[.]175[.]19/02[.]08[.]2022[.]exe hxxp://104[.]223[.]123[.]227:1234/02[.]08[.]2022[.]exe hxxp://101[.]42[.]187[.]157/02[.]08[.]2022[.]exe hxxp://154[.]216[.]157[.]235/02[.]08[.]2022[.]exe hxxp://47[.]96[.]224[.]76:9999/LLzK hxxp://42[.]114[.]195[.]153:4444/02[.]08[.]2022[.]exe hxxp://101[.]126[.]17[.]8:8888/02[.]08[.]2022[.]exe hxxp://106[.]12[.]215[.]229:8099/02[.]08[.]2022[.]exe hxxp://45[.]144[.]137[.]60:8457/02[.]08[.]2022[.]exe hxxp://47[.]117[.]179[.]86/02[.]08[.]2022[.]exe |
Cobalt Strike |
URL | hxxp://176[.]46[.]157[.]32/files/1920446977/QRKEwZm[.]exe | Rhadamanthys |
URL | hxxp://176[.]46[.]157[.]32/files/5765828710/gHHTrEi[.]exe hxxp://176[.]46[.]157[.]32/files/5765828710/y9Js1n2[.]exe |
RedLine Stealer |
URL | hxxp://198[.]23[.]133[.]163/PkPqOAw183[.]bin hxxp://176[.]46[.]157[.]32/files/6877286426/6HrCF36[.]exe hxxp://176[.]46[.]157[.]32/files/6877286426/KkLbDSA[.]exe hxxp://176[.]46[.]157[.]32/files/6877286426/incKOAf[.]exe |
Agent Tesla |
URL | hxxp://176[.]46[.]157[.]32/files/1752031887/n6Vhjyk[.]exe hxxp://176[.]46[.]157[.]32/files/1752031887/ESlxAtU[.]exe hxxp://176[.]46[.]157[.]32/files/975552894/opMXldg[.]exe hxxp://176[.]46[.]157[.]32/files/975552894/u4cj5MB[.]exe hxxp://176[.]46[.]157[.]32/files/331224038/sWwAThx[.]exe hxxp://176[.]46[.]157[.]32/files/975552894/o9TXyzQ[.]exe |
SalatStealer |
URL | hxxp://80[.]66[.]85[.]195/api/YTAsODYsODIsOWQsYTEsODgsOTAsOTUsNjUsN2Qs | SmartLoader |
URL | hxxps://corpcougar[.]in/waplord/32/index[.]php | Azorult |
URL | hxxps://api[.]telegram[.]org/bot6852270017:AAFOVJ2m_OJ-xvJdXcOoP2hDLMCTR_prUiU/sendMessage?chat_id=6683518699 | DarkCloud |