不正URLへのアクセス、不正メールの受信
-
メール受信した
弊社お客様0社 URLアクセスした
弊社お客様5社 -
2025/09/01
※2025/09/01 更新
マルウェア感染させると考えられるURLを検知(2025/09/01)
■IoC(※1)
Type: | IOC: | Signature: |
---|---|---|
URL | hxxp://178[.]16[.]55[.]189/files/5254702106/4sDv8Er[.]exe hxxps://195[.]140[.]146[.]115/processorprivate[.]php hxxp://trainisshit[.]shop/19b574f278f94a33[.]php hxxp://87[.]120[.]126[.]205/1bbf46c2e1b942e5[.]php |
Stealc |
URL | hxxp://45[.]142[.]195[.]242/auth/login/ hxxp://91[.]236[.]116[.]22/auth/login/ hxxp://91[.]236[.]116[.]151/auth/login/ |
Matanbuchus |
URL | hxxps://files[.]taxibleapp[.]com/pixel[.]png hxxps://app[.]montreallimousineservice[.]com/pixel[.]png |
FAKEUPDATES |
URL | hxxps://linomu[.]com/ajax/pixi[.]min[.]js hxxps://spider-wamp[.]com/share[.]pdb hxxps://spider-wamp[.]com/res/relaxzone hxxps://spider-wamp[.]com/assets/img/fe99357658356062[.]txt hxxps://couturellin[.]com/ajax/pixi[.]min[.]js hxxps://humble-photo[.]com/res/rotateweb hxxps://humble-photo[.]com/coil[.]snupkg hxxps://humble-photo[.]com/assets/img/fe99357658356062[.]txt |
NetSupportManager RAT |
URL | hxxps://washerv[.]ru/qygd hxxps://noggs[.]ru/yopd hxxps://georgej[.]ru/plnb hxxps://iosif-brodskiy[.]su/login hxxps://showcet[.]top/qpoe hxxps://oneflof[.]ru/tids hxxps://epitherd[.]ru/zadw hxxps://backab[.]ru/lkdo hxxps://eigwos[.]ru/wqex hxxps://genuumc[.]top/adlr hxxps://kimmenkiz[.]ru/zldw hxxps://grodpgy[.]top/xkde hxxps://rapsmmv[.]top/weii hxxps://limcuz[.]ru/wotr hxxp://178[.]16[.]55[.]189/files/8052963817/8tMKDbN[.]exe hxxp://213[.]111[.]153[.]40/lf7n/ihbs[.]odd hxxp://178[.]16[.]55[.]189/files/1538454832/3FR2qFu[.]exe hxxps://attaocc[.]top/zqde hxxps://blooaeo[.]top/alpe hxxps://solacdf[.]top/xiot |
Lumma Stealer |
URL | hxxps://api[.]telegram[.]org/bot8263492357:AAHxJjfaJ5mL5Aw3iR_2Q7vObM0sqEu--ng/sendMessage?chat_id=7564846096 | Snake Keylogger |
URL | hxxps://213[.]202[.]208[.]237/panel/login[.]php | Mars Stealer |
URL | hxxps://webrat[.]in/login/ hxxps://62[.]109[.]0[.]189/login/ |
SalatStealer |
URL | hxxp://5[.]133[.]102[.]214/Client-built[.]exe | Quasar RAT |
URL | hxxps://raw[.]githubusercontent[.]com/peterson643eu/projecttop/refs/heads/main/ZJQPPAJN[.]exe | HijackLoader |
URL | hxxps://g100jvcf[.]com[.]br/arquivo_20250828213230[.]txt hxxp://178[.]16[.]55[.]189/files/1041884934/KYHBs8w[.]exe |
XWorm |
URL | hxxps://pdfonestart[.]com/onestart/download/0?cid=DhPzN6ia3KYC0lty hxxps://tansmittunnel[.]com/?cid=f64XjQBxxANVBLO&id=0 hxxps://download01[.]anxiousai[.]com/?cid=otAiq13xrOhgRyf40&id=0 hxxps://pdf-working[.]net/?cid=Z0g1CA0UfQnqSfmnk&id=0 hxxps://webdwnload[.]biz/?cid=FJPuajgHskgpdo5bp&id=0 hxxps://download01[.]sharkeagle[.]com/?cid=ZfY7mMB4zDVP1O0j&id=0 hxxps://download03[.]pdfgj[.]com/?cid=jRqF9vY4XflfhFyM&id=0 hxxps://pdffilehub[.]net/?cid=XhXtzvUZrWzmEkp&id=0 hxxps://transmitcdnzion[.]com/?cid=xYBQX5e7cPR8X8vD&id=0 hxxps://download05[.]pdfgj[.]com/?cid=jUjrACiDrPL9BZrZb&id=0 hxxps://dynamicmemchannel[.]com/?cid=KVMwlwtB2ZhX0e2h&id=0 hxxps://download04[.]pdfgj[.]com/?cid=zYg5fchPkvRadrVn&id=0 hxxps://nodesteamlink[.]net/?cid=UKKd0LrtUN87W307CT&id=0 hxxps://advancedtransmitart[.]net/?cid=sVM2l7BlwBRrNKcM3&id=0 hxxps://micromacrotechbase[.]com/?cid=S2wh9DfWvpDS1pin&id=0 hxxps://essentialsignaltunnel[.]com/?cid=H7QLD4EHx8md2Ofww&id=0 hxxps://generativezmedium[.]com/?cid=2ks1AT35b0kqZxHa&id=0 hxxps://onestartbrowser[.]com/onestart/download/0?cid=aSm2pHmRpqtqfBFEg |
TamperedChef |
URL | hxxp://463957cm[.]nyash[.]es/EternalJavascript_RequestpollhttpLongpollLinux[.]php hxxp://185[.]246[.]65[.]153/packet/Auth5Generatorgenerator/8Traffic/UniversalGamephp8/Voiddbtemporary/CdnpollProtect/Api/VmPacket/Db1/7/Temporary47/javascript/6external/phpVoiddbpipe/DatalifeWordpress/PolljavascriptCentralDump/BaseRequestJsProcess/Basepublic/DownloadsCentralMariadbTest/PacketLinuxTemp[.]php |
DCRat |
URL | hxxps://murphkirk[.]com/4s1a[.]js hxxps://murphkirk[.]com/js[.]php |
KongTuke |
URL | hxxp://117[.]72[.]34[.]208:6667/02[.]08[.]2022[.]exe hxxp://45[.]143[.]233[.]205:888/02[.]08[.]2022[.]exe hxxp://81[.]71[.]159[.]99:81/02[.]08[.]2022[.]exe hxxp://8[.]148[.]189[.]187:8081/02[.]08[.]2022[.]exe hxxp://103[.]172[.]26[.]89/02[.]08[.]2022[.]exe hxxp://42[.]51[.]45[.]33:83/02[.]08[.]2022[.]exe hxxp://196[.]251[.]70[.]130/02[.]08[.]2022[.]exe hxxp://43[.]132[.]170[.]194:2095/02[.]08[.]2022[.]exe hxxp://103[.]214[.]22[.]224:56/02[.]08[.]2022[.]exe hxxp://196[.]251[.]70[.]131/02[.]08[.]2022[.]exe hxxp://196[.]251[.]70[.]112/02[.]08[.]2022[.]exe hxxp://43[.]156[.]59[.]110:802/02[.]08[.]2022[.]exe hxxp://193[.]226[.]78[.]58:8001/02[.]08[.]2022[.]exe hxxp://179[.]43[.]186[.]243/02[.]08[.]2022[.]exe hxxp://13[.]67[.]132[.]99/02[.]08[.]2022[.]exe hxxp://152[.]136[.]139[.]105:6666/02[.]08[.]2022[.]exe hxxp://60[.]251[.]198[.]157:9999/02[.]08[.]2022[.]exe hxxp://43[.]255[.]158[.]60/02[.]08[.]2022[.]exe hxxp://129[.]204[.]146[.]115:8085/02[.]08[.]2022[.]exe hxxp://185[.]242[.]233[.]128/02[.]08[.]2022[.]exe hxxp://103[.]38[.]81[.]221:8888/02[.]08[.]2022[.]exe hxxp://193[.]112[.]206[.]250:24635/JqUM |
Cobalt Strike |
URL | hxxp://213[.]165[.]60[.]112/Documents/KeyScramblerIE[.]dll hxxp://172[.]245[.]152[.]142/110/jpg=png/IMAG[.]JPG=DocPDFclouds_shp0774566000922343455[.]PDF@[.]doc?&squeegee=rabid&pear=astonishing&mastication |
Remcos |
URL | hxxp://156[.]226[.]174[.]33/bot[.]mpsl hxxp://156[.]226[.]174[.]33/bot[.]mips hxxp://156[.]226[.]174[.]33/bot[.]mipsel hxxp://45[.]153[.]34[.]194/sh4 hxxp://91[.]224[.]92[.]22:58485/observatory/sh4 hxxp://91[.]224[.]92[.]22:58485/observatory/mpsl hxxp://158[.]51[.]126[.]131/n/armv7l hxxp://158[.]51[.]126[.]131/n/armv5l hxxp://45[.]170[.]245[.]23/a-r[.]m-7[.]Sakura hxxp://45[.]170[.]245[.]23/m-6[.]8-k[.]Sakura hxxp://45[.]170[.]245[.]23/p-p[.]c-[.]Sakura hxxp://45[.]170[.]245[.]23/x-3[.]2-[.]Sakura hxxp://45[.]170[.]245[.]23/x-8[.]6-[.]Sakura hxxp://2[.]58[.]113[.]219/bot[.]mipsel hxxp://2[.]58[.]113[.]219/bot[.]mips |
Bashlite |
URL | hxxp://178[.]16[.]55[.]224/i686 hxxp://178[.]16[.]55[.]224/x86_64 hxxp://178[.]16[.]55[.]224/aarch64 hxxp://178[.]16[.]55[.]224/sh hxxp://178[.]16[.]55[.]224/arm7 hxxp://178[.]16[.]55[.]224/clean hxxp://178[.]16[.]55[.]189/files/5298241443/DbKGUdI[.]exe hxxp://129[.]152[.]20[.]82:8000/Windows[.]x64[.]silent[.]CPU[.]exe |
Coinminer |
URL | hxxp://156[.]226[.]183[.]237:2222/Library-solid-lzma[.]exe | ValleyRAT |
URL | hxxps://103[.]245[.]231[.]209/gateway/xhko7xq5[.]hlhhc | Rhadamanthys |
URL | hxxps://raw[.]githubusercontent[.]com/visage23wr/qwe/refs/heads/main/explorer[.]exe hxxps://github[.]com/visage23wr/qwe/raw/refs/heads/main/explorer[.]exe hxxps://raw[.]githubusercontent[.]com/visage23wr/parserweb/refs/heads/main/wwwwwww[.]exe |
AsyncRAT |
URL | hxxps://raw[.]githubusercontent[.]com/visage23wr/parserweb/refs/heads/main/parser[.]exe | Agent Tesla |
URL | hxxp://178[.]16[.]55[.]189/files/7383249982/tv9IK83[.]ps1 hxxp://178[.]16[.]55[.]189/files/8434554557/G9Qkcq0[.]exe |
PureLogs Stealer |
URL | hxxp://178[.]16[.]53[.]7/icoxn/login[.]php | TinyLoader |
URL | hxxp://178[.]16[.]53[.]7/cvdfnaFJBmC1/Login[.]php hxxp://77[.]90[.]153[.]62/cvdfnaFJBmC0/Login[.]php hxxp://178[.]16[.]53[.]7/cvdfnaFJBmC1/Plugins/clip64[.]dll hxxp://178[.]16[.]53[.]7/cvdfnaFJBmC1/Plugins/clip[.]dll hxxp://178[.]16[.]53[.]7/cvdfnaFJBmC1/Plugins/cred64[.]dll hxxp://178[.]16[.]53[.]7/cvdfnaFJBmC1/Plugins/cred[.]dll hxxp://176[.]46[.]152[.]47/cvdfnaFJBmC2/index[.]php hxxp://178[.]16[.]53[.]7/cvdfnaFJBmC1/index[.]php hxxp://77[.]90[.]153[.]62/cvdfnaFJBmC0/index[.]php |
Amadey |
URL | hxxps://pf[.]vozunaa0[.]ru/m0mhozydnp[.]flac hxxps://pf[.]vozunaa0[.]ru/tc2ap0gip6[.]flac hxxps://pf[.]vozunaa0[.]ru/o2msk4peed[.]flac hxxps://pf[.]vozunaa0[.]ru/ub98qlena6[.]flac hxxps://pf[.]vozunaa0[.]ru/hesn33k7ie[.]flac hxxps://pf[.]vozunaa0[.]ru/rm7l5sp35y[.]flac hxxps://pf[.]vozunaa0[.]ru/wmnclxn9gh[.]flac hxxps://pf[.]vozunaa0[.]ru/lutrutztut[.]flac hxxps://pf[.]vozunaa0[.]ru/ze7ipk8oco[.]flac hxxps://pf[.]vozunaa0[.]ru/626dc02em1[.]flac hxxps://pf[.]vozunaa0[.]ru/v7tkup1q3w[.]flac hxxps://pf[.]vozunaa0[.]ru/b5h3zlk84t[.]flac hxxps://pf[.]vozunaa0[.]ru/attl2sq1jg[.]flac hxxps://pf[.]vozunaa0[.]ru/bcsh64qlx5[.]flac hxxps://pf[.]vozunaa0[.]ru/coi92674r2[.]flac hxxps://pf[.]vozunaa0[.]ru/pw1vr5p6xf[.]flac hxxps://pf[.]vozunaa0[.]ru/3xl7zgerzz[.]flac hxxps://pf[.]vozunaa0[.]ru/c53y7vpcir[.]flac hxxps://pf[.]vozunaa0[.]ru/fo7bdwlqzh[.]flac hxxps://pf[.]vozunaa0[.]ru/m91x7ogmwp[.]flac hxxps://pf[.]vozunaa0[.]ru/c79pgouk1i[.]flac hxxps://pf[.]vozunaa0[.]ru/2ijsvrig6e[.]flac hxxps://pf[.]vozunaa0[.]ru/xcuux73txn[.]flac hxxps://pf[.]vozunaa0[.]ru/snzxthjf5l[.]flac hxxps://pf[.]vozunaa0[.]ru/rvumcz3449[.]flac hxxps://pf[.]vozunaa0[.]ru/lni1o2nuut[.]flac hxxps://pf[.]vozunaa0[.]ru/p8yp1drvvg[.]flac hxxps://pf[.]vozunaa0[.]ru/ysei4urzlr[.]flac hxxps://pf[.]vozunaa0[.]ru/bpzmuxtswq[.]flac hxxps://pf[.]vozunaa0[.]ru/o7nk3388vn[.]flac hxxps://pf[.]vozunaa0[.]ru/8ieq4o7buy[.]flac hxxps://pf[.]vozunaa0[.]ru/erdhzxa5hq[.]flac hxxps://pf[.]vozunaa0[.]ru/cbcjdbttil[.]flac hxxps://pf[.]vozunaa0[.]ru/n1qq2nw6o4[.]flac hxxps://pf[.]vozunaa0[.]ru/rolcmxxn17[.]flac hxxps://we[.]vupabya1[.]ru/y4ouz26plb[.]flac hxxps://we[.]vupabya1[.]ru/kmmewmamuh[.]flac hxxps://we[.]vupabya1[.]ru/jpb23rmnpg[.]flac hxxps://we[.]vupabya1[.]ru/p0nn0rfg0t[.]flac hxxps://we[.]vupabya1[.]ru/ujsfuloo00[.]flac hxxps://we[.]vupabya1[.]ru/q1r7zhsi41[.]flac hxxps://we[.]vupabya1[.]ru/xppu7bmk6v[.]flac hxxps://we[.]vupabya1[.]ru/964urx1kw5[.]flac hxxps://we[.]vupabya1[.]ru/5szjwydo8h[.]flac hxxps://we[.]vupabya1[.]ru/0e36i16qyl[.]flac hxxps://we[.]vupabya1[.]ru/ndvylhpuya[.]flac hxxps://we[.]vupabya1[.]ru/u04t63irft[.]flac hxxps://we[.]vupabya1[.]ru/b07oc082jl[.]flac hxxps://we[.]vupabya1[.]ru/1p7h0khkxa[.]flac hxxps://we[.]vupabya1[.]ru/p2m2dybaau[.]flac hxxps://we[.]vupabya1[.]ru/36r24qadb9[.]flac hxxps://we[.]vupabya1[.]ru/nmwecyjd2g[.]flac |
ClearFake |
URL | hxxp://gamestoredownload[.]download/autoconfig/level3sp/fre[.]php | LokiBot |
URL | hxxp://178[.]16[.]53[.]7/cvdfnaFJBmC1/Plugins/vnc[.]exe | TinyNuke |
URL | hxxps://store[.]cloudsdog[.]top/city/cn[.]exe hxxp://178[.]16[.]55[.]189/files/unique4/random[.]exe |
Socks5 Systemz |
URL | hxxp://178[.]16[.]54[.]225/f | Ngioweb |
URL | hxxp://fwcpafl[.]com/dam/ponnie/gate[.]php | Pony |