不正URLへのアクセス、不正メールの受信
-
メール受信した
弊社お客様0社 URLアクセスした
弊社お客様0社 -
2025/10/22
※2025/10/22 更新
マルウェア感染させると考えられるURLを検知(2025/10/22)
■IoC(※1)
| Type: | IOC: | Signature: |
|---|---|---|
| URL | hxxps://q8z1[.]7i091[.]online/sinkers hxxps://drunk[.]5-forez-515-o[.]ru/yarcwox9 hxxps://v2[.]7i091[.]online/sinkers hxxps://buyer[.]xiqek-40-ye-8[.]ru/2uz54ki3 hxxps://yh3a[.]7i091[.]online/sinkers hxxps://coast[.]2-fyzog-201-e[.]ru/docrz15u hxxps://vj3c[.]9z2503[.]ru/zxoiwbz0jk[.]sh hxxps://issue[.]2-fyzog-201-e[.]ru/fyk[.]check?t=d283i1lk hxxps://flour[.]1-mafus-044-e[.]ru/xw[.]google?t=ev0ejbk4 hxxps://vj3c[.]9z2503[.]ru/pklztt5e6a[.]sh hxxps://t5y0[.]9z2503[.]ru/ti2ooxyux6[.]sh hxxps://bring05[.]5-milod-931-o[.]ru/sjq3[.]google?t=g891khh3 hxxps://t5y0[.]9z2503[.]ru/vilhr2yvvd[.]sh hxxps://forty[.]4-pytim-30-ua[.]ru/jf4e[.]check?t=9hainbmw hxxps://forty[.]4-pytim-30-ua[.]ru/o0b5b3k4 hxxps://r4h8[.]9z2503[.]ru/z85mll0z3u[.]sh hxxps://keeniy8[.]5-milod-931-o[.]ru/ccfs[.]check?t=6bryrvkz hxxps://lover[.]0-we-fid-707-i[.]ru/p4w[.]google?t=bdxcp0jh hxxps://1gzu[.]9z2503[.]ru/obfz8plrzw[.]sh hxxps://fa1se4[.]5-milod-931-o[.]ru/l6[.]google?t=ypiex10z hxxps://g7k[.]7i091[.]online/sinkers hxxps://issue[.]2-fyzog-201-e[.]ru/9gr91gck hxxps://yk8q[.]6362o9[.]ru/u4gso20adp[.]sh hxxps://fiber[.]5-juzeb-0-io[.]ru/tqzu[.]check?t=vwg7vc7f hxxps://greet4[.]0-we-fid-707-i[.]ru/f6bp[.]check?t=wpwrfn4z hxxps://c2d1[.]6362o9[.]ru/je9mbsur1n[.]sh hxxps://brlef33[.]1-byhih-05-ey[.]ru/ub3c6[.]google?t=ac8835fh hxxps://c2d1[.]6362o9[.]ru/nte9nko72k[.]sh hxxps://me9x[.]9z2503[.]ru/mns1v0ys4c[.]sh hxxps://death[.]7-doxok-46-eu[.]ru/tpaq[.]check?t=h5tb2y2f hxxps://f9m0[.]7i091[.]online/sinkers hxxps://me9x[.]9z2503[.]ru/domhtnicrh[.]sh hxxps://fresh[.]5-milod-931-o[.]ru/seti83yx hxxps://fresh[.]5-milod-931-o[.]ru/cxxfq[.]google?t=6law9e50 hxxps://fla5h[.]2-fyzog-201-e[.]ru/vi[.]google?t=pgcb1uea hxxps://r4h8[.]9z2503[.]ru/axelxfys5u[.]sh hxxps://w9r2[.]6362o9[.]ru/3s1px12h9t[.]sh hxxps://deb1t[.]1-byhih-05-ey[.]ru/vrckb[.]google?t=antccrwg hxxps://3mta[.]6362o9[.]ru/cltdehzlex[.]sh hxxps://above55[.]7-nenop-38-oy[.]ru/5r[.]check?t=v8utud2o hxxps://al1ve[.]1-mafus-044-e[.]ru/u6[.]google?t=det04ytv hxxps://3mta[.]6362o9[.]ru/yxkwpdius1[.]sh hxxps://b7lx[.]6362o9[.]ru/77ncr5zinw[.]sh hxxps://482[.]r46eu[.]ru/k7[.]google?t=hj89jfko hxxps://w9r2[.]6362o9[.]ru/xopom0x53s[.]sh hxxps://drift[.]1-byhih-05-ey[.]ru/lbh5[.]check?t=r2llbg5g hxxps://740[.]c70ye[.]ru/r1[.]google?t=e1962mla hxxps://dream5[.]tuful32io3[.]online/743s2b4xs2[.]sh hxxps://06342[.]r46eu[.]ru/w904[.]google?t=wvtne5em hxxps://sti11[.]tuful32io3[.]online/azl5k4z9nu[.]sh hxxps://sk1es[.]tuful32io3[.]online/2wofb7i1u0[.]sh hxxps://719[.]r46eu[.]ru/bt[.]check?t=8i6e4b0e hxxps://flame4[.]tuful32io3[.]online/kg7jopsmza[.]sh hxxps://3499013[.]r46eu[.]ru/mx4[.]google?t=8tzp88bd hxxps://60012[.]c70ye[.]ru/ixbip3ig hxxps://1[.]1397u6[.]ru/0arl0h9tyb[.]js hxxps://60012[.]c70ye[.]ru/0n[.]google?t=xosgiyu0 hxxps://mo0n[.]sys7yn0iy5[.]online/rk4s7pd7es[.]sh hxxps://rose2[.]tuful32io3[.]online/sdy0l9kcwr[.]sh hxxps://2215[.]c70ye[.]ru/qd7[.]check?t=qq8sgci8 hxxps://uk[.]1397u6[.]ru/m5d79nfmgq[.]js hxxps://gr0w[.]sys7yn0iy5[.]online/7hbldobqxr[.]sh hxxps://a9[.]c70ye[.]ru/vp[.]check?t=v1c9jrl0 hxxps://r1se[.]sys7yn0iy5[.]online/5og9zf6cz5[.]sh hxxps://30[.]c70ye[.]ru/xa2[.]google?t=bzpegshu hxxps://30[.]c70ye[.]ru/rgsjr7rb hxxps://us[.]1397u6[.]ru/0mr4p0i6xb[.]js hxxps://r1se[.]sys7yn0iy5[.]online/nqrv51oxp4[.]sh hxxps://27[.]c70ye[.]ru/h39[.]check?t=9rhe9i86 hxxps://12[.]c70ye[.]ru/n3poljlj hxxps://s0lar[.]sys7yn0iy5[.]online/mwu7wmpakn[.]sh hxxps://12[.]c70ye[.]ru/0n[.]google?t=r7ir8kdm hxxps://12[.]c70ye[.]ru/r9p3fip7 hxxps://z[.]1397u6[.]ru/5zix8gpb9j[.]js hxxps://76[.]k59ee[.]ru/qrxed14u hxxps://xdv[.]qcet8[.]ru/hp3i9v1kzm[.]js hxxps://10[.]k59ee[.]ru/2m[.]google?t=qallr85p hxxps://shineo[.]sys7yn0iy5[.]online/tcv7xn8c3h[.]sh hxxps://93[.]k59ee[.]ru/4ta[.]check?t=62gy2f46 hxxps://shineo[.]sys7yn0iy5[.]online/u4sxwxighb[.]sh hxxps://41[.]k59ee[.]ru/yn[.]google?t=unxmmiot hxxps://softs[.]sys7yn0iy5[.]online/5zbkzn2fb9[.]sh hxxps://89[.]c70ye[.]ru/6eg0c7jp hxxps://uk[.]1397u6[.]ru/t027ywh7wy[.]js hxxps://softs[.]sys7yn0iy5[.]online/kja2u5xjq1[.]sh hxxps://89[.]c70ye[.]ru/2wm[.]google?t=lvg4w1aw hxxps://a9[.]c70ye[.]ru/6o24d08b hxxps://p6v3[.]1397u6[.]ru/p5n77lnq2o[.]sh hxxps://01[.]d55u5[.]ru/z4[.]google?t=533zvkal hxxps://h4n0[.]1397u6[.]ru/faj6j6x0cc[.]sh hxxps://77[.]d55u5[.]ru/ep[.]google?t=zfm4kymu hxxps://04[.]k59ee[.]ru/qm3[.]google?t=3ls520at hxxps://h4n0[.]1397u6[.]ru/aor11iopdy[.]sh hxxps://32[.]k59ee[.]ru/u8npi81h hxxps://d5r[.]qcet8[.]ru/62ysmevad7[.]js hxxps://5t[.]s61y5[.]ru/d31qi8qw hxxps://zdj[.]qcet8[.]ru/wgcol4hvbv[.]js hxxps://84[.]d55u5[.]ru/apypb6wx hxxps://uf8[.]qcet8[.]ru/r33lj3b0ev[.]js hxxps://71[.]r46eu[.]ru/ksihsotj hxxps://9s[.]qcet8[.]ru/4dnwpo0rxl[.]js hxxps://4[.]r46eu[.]ru/05jcb5ss hxxps://9s[.]qcet8[.]ru/xh796dbkw5[.]js hxxps://1w[.]s61y5[.]ru/0a4[.]google?t=r76nqdqp hxxps://99[.]r46eu[.]ru/mkk2rod9 hxxps://b0t[.]4y328[.]online/nx6zynpm0a[.]js hxxps://3a[.]r46eu[.]ru/20fz42e1 hxxps://qm4z[.]4y328[.]online/jsc1c2hbzh[.]js hxxps://08[.]r46eu[.]ru/w28e71v9 hxxps://w7[.]4y328[.]online/ub7s62v7wv[.]js hxxps://k2[.]5h4553[.]online/1d8pkdb1do[.]js hxxps://b[.]c70ye[.]ru/5dgw9wqb hxxps://h2k[.]4y328[.]online/yx1b5rt2od[.]js hxxps://k9[.]c70ye[.]ru/s9lh7fb5 hxxps://p9y3[.]4y328[.]online/o1kt65nqay[.]js hxxps://22[.]c70ye[.]ru/p73qi69u hxxps://x[.]4y328[.]online/x81b6avq24[.]js hxxps://7[.]c70ye[.]ru/obt9glil hxxps://x[.]4y328[.]online/84omyglvkn[.]js hxxps://inomp[.]ci6ef[.]ru/sinkers hxxps://d5[.]5h4553[.]online/1b5zdfydvq[.]js hxxps://90[.]k59ee[.]ru/a890uecb hxxps://qz1a[.]5h4553[.]online/so630ggmd6[.]js hxxps://05[.]c70ye[.]ru/donffyxc hxxps://g9[.]d55u5[.]ru/fbfvdhx8 hxxps://j[.]5h4553[.]online/83j7wfkst4[.]js hxxps://x7[.]d55u5[.]ru/m0q[.]check?t=l5vcm22s hxxps://x7[.]d55u5[.]ru/l2smvqi6 hxxps://xb0n[.]5h4553[.]online/af0tfp4voq[.]js hxxps://0a[.]k59ee[.]ru/ndguos7k hxxps://a4[.]s61y5[.]ru/9j8lusbc hxxps://c7p[.]5m9081[.]online/o7hz8zgdck[.]js hxxps://83[.]s61y5[.]ru/jul8udp3 hxxps://c7p[.]5m9081[.]online/56amp92j2l[.]js hxxps://2[.]s61y5[.]ru/8aexh7tz hxxps://n9[.]5m9081[.]online/59db28rqfj[.]js hxxps://44[.]d55u5[.]ru/d5z4t0j3 hxxps://j[.]5h4553[.]online/t6is12mefi[.]js hxxps://44[.]d55u5[.]ru/4stsbbnw hxxps://j[.]5h4553[.]online/iisw89e53f[.]js hxxps://z1[.]9wb-k[.]ru/j2mwpy16 hxxps://w4[.]5m9081[.]online/9mtp2su0qs[.]js hxxps://4[.]9wb-k[.]ru/5lm9h90e hxxps://w4[.]5m9081[.]online/wl319rpnip[.]js hxxps://x1[.]s61y5[.]ru/p6e5z21p hxxps://t1va[.]5m9081[.]online/ffc9naiecd[.]js hxxps://s[.]0vs-r[.]ru/engme3yd hxxps://rz3[.]5m9081[.]online/v20t9tmefd[.]js hxxps://w1[.]9wb-k[.]ru/kyynh9mc hxxps://rz3[.]5m9081[.]online/s0es1i4zei[.]js hxxps://pt[.]9wb-k[.]ru/dibgtlmh hxxps://g0x8[.]5m9081[.]online/9ms5h20rj7[.]js hxxps://p[.]8d9691[.]online/h9nnx62mbm[.]js hxxps://q1[.]0vs-r[.]ru/hisb9ub7 hxxps://a3zq[.]8d9691[.]online/6xg0makcbx[.]js hxxps://r7[.]0vs-r[.]ru/uspisa1k hxxps://f6[.]8d9691[.]online/b0bojjg5ko[.]js hxxps://p9[.]1vd-z[.]ru/c8yec7qz hxxps://u0b[.]8d9691[.]online/iy6lkg7rp1[.]js hxxps://x[.]1vd-z[.]ru/eclidu3s hxxps://m7y1[.]8d9691[.]online/w7084bhhkl[.]js hxxps://n3[.]1vd-z[.]ru/grg592jy hxxps://p[.]8d9691[.]online/zoc16g3tcz[.]js hxxps://a[.]1vd-z[.]ru/9xne638g |
ClearFake |
| URL | hxxp://178[.]16[.]55[.]189/files/5917492177/UuAJSEE[.]exe | Stealc |
| URL | hxxps://chamjs[.]com/xss/buf[.]js hxxps://chamjs[.]com/xss/index[.]php hxxps://chamjs[.]com/xss/bof[.]js hxxps://www[.]siegelpigeons[.]com/barracoksx[.]zip |
NetSupportManager RAT |
| URL | hxxps://spaste[.]us/raw/rsayhbah hxxp://91[.]92[.]240[.]63/arquivo_20251015234503[.]txt hxxp://23[.]95[.]117[.]243/img/kmro/kkdi99ew0cv03jdjfsdhj400df04sdxcv0we03220dcxvjs9f930sxcvj322jjsdf0sdf0sfxc0f032jdkfs[.]hta hxxps://minel-lights[.]rs/finance/titus[.]txt hxxps://216[.]9[.]227[.]119/250/secv56fghgh56n67878700hhhkhjvdgfdfg90fgf6555f56656[.]vbe |
Remcos |
| URL | hxxp://85[.]239[.]246[.]89/snk/Drivespan[.]dll | Koadic |
| URL | hxxp://176[.]46[.]152[.]62:5858/71a590d6d4a144a4be1d58b9e919769b_build[.]exe hxxp://176[.]46[.]152[.]62:5858/154c65a53e794aecbd54dc513b4c6a33_crypted_build[.]exe hxxp://176[.]46[.]152[.]62:5858/51d15381c5e74b9a8706fa7fd3fea133_build[.]exe hxxp://176[.]46[.]152[.]62:5858/1405f383e97449d388aa69dcc45ab7c2_crypted_build[.]exe hxxp://176[.]46[.]152[.]62:5858/e52ccdbdb1bd4e31b80b7ec1f38f9b84_crypted_build[.]exe |
Rhadamanthys |
| URL | hxxp://176[.]46[.]152[.]62:5858/wilde[.]exe | SalatStealer |
| URL | hxxps://api[.]telegram[.]org/bot8494379124:AAEY3MdJGkCMgmZrdqmOQqDlNSX4PoijlCU/sendMessage?chat_id=7788030038 | Snake Keylogger |
| URL | hxxps://shkb-info[.]com/file/supp35[.]pdf | MetaStealer |
| URL | hxxps://tytbit[.]ru/download/838c6d81-d61b-4a27-8862-486af361f6a8[.]bat | XWorm |
| URL | hxxps://api[.]telegram[.]org/bot7579245280:AAGsgUtmmqAzd10cvda1hXEf34laRJqqLMw/ hxxp://213[.]209[.]157[.]234/host/cash[.]ps1 |
Agent Tesla |
| URL | hxxps://91[.]92[.]242[.]27/kaWt2QXfpPueNM/Login[.]php | Amadey |
| URL | hxxps://151[.]25[.]164[.]9:8443/sda1/Video[.]scr hxxps://151[.]25[.]164[.]9:8443/sda1/Photo[.]scr hxxps://151[.]25[.]164[.]9:8443/sda1/System%20Volume%20Information/Photo[.]scr hxxps://151[.]25[.]164[.]9:8443/sda1/System%20Volume%20Information/Video[.]scr hxxps://151[.]25[.]164[.]9:8443/sda1/AV[.]scr hxxps://151[.]25[.]164[.]9:8443/sda1/System%20Volume%20Information/AV[.]scr |
Coinminer |
| URL | hxxp://125[.]208[.]17[.]105:99/buding0/dbghelp[.]dll hxxp://43[.]249[.]192[.]196:89/1/Items[.]dll hxxp://103[.]120[.]89[.]25:99/buding/dbghelp[.]dll hxxp://119[.]163[.]233[.]82:81/buding1/dbghelp[.]dll |
KrBanker |
| URL | hxxp://103[.]96[.]75[.]2:17705/good[.]cc hxxp://103[.]96[.]75[.]2:17705/good[.]exe |
Emotet |
| URL | hxxp://337598cm[.]nyash[.]es/ImagesecurelongpollLocal[.]php | DCRat |
| URL | hxxp://23[.]160[.]56[.]26/p[.]txt | XOR DDoS |








