不正URLへのアクセス、不正メールの受信
-
メール受信した
弊社お客様0社 URLアクセスした
弊社お客様1社 -
2025/11/07
※2025/11/07 更新
マルウェア感染させると考えられるURLを検知(2025/11/07)
■IoC(※1)
| Type: | IOC: | Signature: |
|---|---|---|
| URL | hxxps://z01[.]a-8-xp[.]ru/cpyrgboq7l[.]3sh hxxps://w9[.]vortexgipfel[.]ru/0xq[.]check?t=k3h7titv hxxps://w2t[.]ravenpfad[.]ru/uaf6c2opm0[.]1 hxxps://be[.]vortexgipfel[.]ru/hbtnqnsq hxxps://tqf[.]summitmond[.]ru/0v9[.]google?t=ubja9qag hxxps://v9r[.]a-8-xp[.]ru/x3en70txid[.]3sh hxxps://z1[.]summitmond[.]ru/i1y1jzfk hxxps://a3[.]ravenpfad[.]ru/aq73gr128p[.]1 hxxps://v9r[.]a-8-xp[.]ru/yeeoly0dhn[.]3sh hxxps://bd2[.]summitmond[.]ru/m3[.]google?t=9flggngq hxxps://k2[.]a-8-xp[.]ru/fy4wxgj2x4[.]3sh hxxps://q7m[.]summitmond[.]ru/4ta[.]check?t=bixm7qx2 hxxps://q7m[.]summitmond[.]ru/fukfr0mt hxxps://n7x[.]ravenpfad[.]ru/fdo0ey1fo6[.]1 hxxps://m8q[.]aspenatlas[.]ru/q3k[.]check?t=kt4nxnmx hxxps://d7q[.]a-8-xp[.]ru/u1laxxm1go[.]3sh hxxps://xk[.]vortexgipfel[.]ru/m04[.]google?t=ldivy0me hxxps://hpn4[.]a-8-xp[.]ru/itp1fxkp5h[.]3sh hxxps://k3[.]prismquelle[.]ru/cfv5ztw5vg[.]1 hxxps://p2[.]vortexgipfel[.]ru/edmy6fji hxxps://k3[.]prismquelle[.]ru/g4sxhzya1e[.]1 hxxps://c3r[.]vortexgipfel[.]ru/t81gnb12 hxxps://c3r[.]vortexgipfel[.]ru/h7[.]google?t=jqeorlyi hxxps://ty3[.]a-8-xp[.]ru/gfpjm0ygp8[.]3sh hxxps://a7[.]prismquelle[.]ru/xog8kin5oi[.]1 hxxps://cm[.]cedarnova[.]ru/wqeuh0us hxxps://cm[.]cedarnova[.]ru/f91[.]check?t=b382uuec hxxps://b3h7[.]085-x-89-c[.]ru/l4vfyd6ura[.]sh hxxps://z9tqn[.]085-x-89-c[.]ru/3l24rozi56[.]sh hxxps://n7[.]cedarnova[.]ru/vd1[.]google?t=ny9jiv3w hxxps://m0x[.]prismquelle[.]ru/r4dtpaq2dr[.]1 hxxps://t1n[.]cedarnova[.]ru/oxm0liyc hxxps://t1n[.]cedarnova[.]ru/k24[.]check?t=5l7qsqzr hxxps://d6y1[.]085-x-89-c[.]ru/a4iplrerai[.]sh hxxps://bqk[.]aspenatlas[.]ru/1c[.]google?t=hsrqb8vv hxxps://x2[.]aspenatlas[.]ru/ab3[.]check?t=0ldyjhos hxxps://d6y1[.]085-x-89-c[.]ru/7xrcv14pyx[.]sh hxxps://z8q[.]prismquelle[.]ru/nr1e63lp65[.]1 hxxps://x2[.]aspenatlas[.]ru/kgg8g7kz hxxps://s8rk2[.]085-x-89-c[.]ru/yb93csmzps[.]sh hxxps://p0x[.]opaldrift[.]ru/e4[.]google?t=vefi4rn2 hxxps://p0x[.]opaldrift[.]ru/4cs0fd8o hxxps://h5[.]coralglanz[.]ru/o76qycvozu[.]1 hxxps://x0la[.]085-x-89-c[.]ru/wve9n1x4t9[.]sh hxxps://oz[.]opaldrift[.]ru/d7m[.]check?t=ar0cepjr hxxps://x0la[.]085-x-89-c[.]ru/gfw1vlk90s[.]sh hxxps://v3[.]opaldrift[.]ru/l2[.]google?t=38ljmbqk hxxps://so[.]opaldrift[.]ru/9v3lm427 hxxps://t2w[.]coralglanz[.]ru/ds7371bgbu[.]1 hxxps://q2w5e[.]085-x-89-c[.]ru/yeqweahi8i[.]sh hxxps://sa3[.]cedarnova[.]ru/w2n[.]google?t=smpluew7 hxxps://a7[.]prismquelle[.]ru/dgn8io2x90[.]1 hxxps://sa3[.]cedarnova[.]ru/wwa8bov3 hxxps://sm[.]tundrasable[.]ru/ya[.]google?t=pbcbifwj hxxps://wwe[.]kzg-w-4-y[.]ru/3g8fl38arf[.]sh hxxps://y7[.]quasarorchid[.]ru/az4[.]google?t=kozy17vj hxxps://wwe[.]kzg-w-4-y[.]ru/9l7fcyr9fj[.]sh hxxps://c1k[.]coralglanz[.]ru/vvj3mbgkbo[.]1 hxxps://y7[.]quasarorchid[.]ru/rf4aykp1 hxxps://x4m[.]quasarorchid[.]ru/tn[.]check?t=x8w6rosf hxxps://t6k9[.]kzg-w-4-y[.]ru/jhr6hxaq3t[.]sh hxxps://y9p[.]coralglanz[.]ru/equurjk8u2[.]1 hxxps://x4m[.]quasarorchid[.]ru/t41iy8di hxxps://bz[.]quasarorchid[.]ru/0d4[.]google?t=w4poynrw hxxps://4p1m[.]kzg-w-4-y[.]ru/t6o2bwjiu6[.]sh hxxps://4p1m[.]kzg-w-4-y[.]ru/g0b1jjj9bl[.]sh hxxps://q1[.]quasarorchid[.]ru/1kz[.]check?t=sy6icl95 hxxps://vo5[.]dr1ftpanda[.]ru/w5u[.]google?t=dit6qxfs hxxps://p3wz1[.]l3rc-0[.]ru/8jxy11r5gg[.]1 hxxps://sj[.]dr1ftpanda[.]ru/rm59mst3 hxxps://sj[.]dr1ftpanda[.]ru/ura[.]check?t=sbqm5pj2 hxxps://g5[.]tundrasable[.]ru/rp2[.]google?t=m2osw2qr hxxps://g5[.]tundrasable[.]ru/jp79bmrd hxxps://a9hm[.]l3rc-0[.]ru/7t3rarzip8[.]1 hxxps://e5[.]tundrasable[.]ru/xa0[.]check?t=q3tu98oq hxxps://v4q7p[.]l3rc-0[.]ru/pjj0hd1eiz[.]1 hxxps://e5[.]tundrasable[.]ru/cetimurt hxxps://1m[.]tundrasable[.]ru/2h[.]google?t=x6lwhu4j hxxps://c8[.]tundrasable[.]ru/w1n[.]check?t=wi1xl5py hxxps://2n[.]dr1ftpanda[.]ru/0o[.]google?t=nttnubbb hxxps://u3zc[.]dr1ftpanda[.]ru/5fy[.]check?t=vp18lxl6 hxxps://we[.]dr1ftpanda[.]ru/h6[.]google?t=6h6mzijz hxxps://y6kb[.]l3rc-0[.]ru/e80qblgulc[.]1 hxxps://we[.]dr1ftpanda[.]ru/35mtw433 hxxps://hbo8[.]dr1ftpanda[.]ru/sc6[.]google?t=24qz839z hxxps://kp6[.]zephyrsteg[.]online/dxzxy8v3gj[.]sh hxxps://oa[.]amberr0cket[.]ru/11[.]google?t=4kni5ggw hxxps://v4n1[.]zephyrsteg[.]online/5kr82br9ux[.]sh hxxps://f8s[.]amberr0cket[.]ru/7nq[.]check?t=yj99qpax hxxps://m7rd[.]frosthain[.]online/62lf02rwk9[.]1 hxxps://f8s[.]amberr0cket[.]ru/lw0s5h3y hxxps://y8c[.]zephyrsteg[.]online/zflk1muw1f[.]sh hxxps://u3k[.]amberr0cket[.]ru/3b[.]google?t=pwrzr6f6 hxxps://a9x[.]frosthain[.]online/s665d6ziul[.]1 hxxps://u3k[.]amberr0cket[.]ru/q2bi0emx hxxps://zm4[.]amberr0cket[.]ru/zq[.]google?t=mszzbx9l hxxps://h0f8[.]solarfracht[.]online/y6r5y1afio[.]sh hxxps://yzc[.]amberr0cket[.]ru/9ti[.]check?t=mftl1raw hxxps://sz[.]maplexenon[.]ru/jm[.]check?t=hhyyb7mz hxxps://f5q[.]ironbucht[.]online/b0nj8xgyql[.]sh hxxps://xt83[.]maplexenon[.]ru/wb[.]check?t=nyt1mdnw hxxps://d7w2[.]zephyrsteg[.]online/mo6pg58jnk[.]sh hxxps://d7w2[.]zephyrsteg[.]online/06ag7gycui[.]sh hxxps://5m[.]maplexenon[.]ru/yeacfxl3 hxxps://j4va[.]frosthain[.]online/llsymdvdc9[.]1 hxxps://5m[.]maplexenon[.]ru/um[.]google?t=rrf377v4 hxxps://s0r[.]zephyrsteg[.]online/bckomavjxl[.]sh hxxps://5m[.]maplexenon[.]ru/um[.]google?t=9dmg8i96 hxxps://5m[.]maplexenon[.]ru/7z8v5tqy hxxps://8w[.]amberr0cket[.]ru/s6[.]check?t=npuxlp7k hxxps://m3t9[.]zephyrsteg[.]online/citzn0zvyz[.]sh hxxps://m1r3[.]amberr0cket[.]ru/es4jeiaq hxxps://m1r3[.]amberr0cket[.]ru/xut[.]check?t=regkctkm hxxps://xse3[.]frosthain[.]online/qcruln928k[.]1 hxxps://kp6[.]zephyrsteg[.]online/6isc77492s[.]sh hxxps://2d63[.]amberr0cket[.]ru/xd[.]check?t=el7dr95m hxxps://et[.]ve1vet0rchid[.]ru/v2[.]google?t=us99f51r hxxps://w7d[.]brassufer[.]online/bb8ebtqh1s[.]sh hxxps://copperwerft[.]online/x9ow98gpvq[.]1 hxxps://w7d[.]brassufer[.]online/6crhb1mu1p[.]sh hxxps://bw9[.]ve1vet0rchid[.]ru/gj87txty hxxps://bw9[.]ve1vet0rchid[.]ru/xp[.]google?t=5lsd2kzz hxxps://c1t7[.]ironbucht[.]online/ec9q27pkpu[.]sh hxxps://maplexenon[.]ru/xvt[.]check?t=vqr0inph hxxps://x9l2[.]ironbucht[.]online/e9jom3dw9n[.]sh hxxps://g74n[.]maplexenon[.]ru/nq[.]google?t=nrlzem40 hxxps://x9l2[.]ironbucht[.]online/ip12u6i7d0[.]sh hxxps://kmg[.]maplexenon[.]ru/t77[.]check?t=148h96kj hxxps://1hx8[.]maplexenon[.]ru/tf[.]google?t=71w8dx4g hxxps://f5q[.]ironbucht[.]online/0xjpyl5ktr[.]sh hxxps://t1q4[.]brassufer[.]online/4n9kqox6x4[.]sh hxxps://frostindigo[.]ru/kh[.]google?t=1kskc828 hxxps://ve1vet0rchid[.]ru/7zb[.]google?t=9m57w3jb hxxps://e3k9[.]brassufer[.]online/cwcuvpmjkt[.]sh hxxps://d7x[.]ember-grove[.]ru/jw[.]google?t=r0goww5w hxxps://flintwiese[.]online/uex3qczcih[.]1 hxxps://quartzraven[.]ru/q49jv7fl hxxps://h8s2[.]brassufer[.]online/fq2xkkxe4d[.]sh hxxps://quartzraven[.]ru/4y[.]check?t=bdvdwga9 hxxps://h8s2[.]brassufer[.]online/5xwuuqb12q[.]sh hxxps://pixe1tu1ip[.]ru/xa5[.]google?t=zsws1rxi hxxps://thunderforst[.]online/mxwj9bfvus[.]1 hxxps://frost-indigo[.]ru/l0yjzezk hxxps://frost-indigo[.]ru/lq[.]check?t=wt5go7sn hxxps://z5m[.]brassufer[.]online/mkf0y9xuoy[.]sh hxxps://5a[.]frost-indigo[.]ru/fva[.]check?t=jrbezutw hxxps://t1q4[.]brassufer[.]online/eyxwzfphfq[.]sh hxxps://swiftfluss[.]ru/unh3q64kdo[.]1 hxxps://pixelorbit[.]ru/d4z0erh0 hxxps://meteorsegel[.]ru/uzjcgpa65s[.]1 hxxps://alphacinder[.]ru/r4hxgqnm hxxps://l2f7[.]starmarkt[.]online/rk5emxovx6[.]sh hxxps://alphacinder[.]ru/j8w[.]check?t=dykb8cd2 hxxps://p9c[.]starmarkt[.]online/lsmlh71t4c[.]sh hxxps://ix[.]n0vaharbor[.]ru/cw[.]check?t=nau2ewwu hxxps://5d[.]n0vaharbor[.]ru/8z0[.]check?t=slj10ihz hxxps://a6v1[.]brassufer[.]online/g5z45dxy9w[.]sh hxxps://5kch[.]n0vaharbor[.]ru/2x[.]google?t=7s2iin8x hxxps://a6v1[.]brassufer[.]online/u4kxftrjsq[.]sh hxxps://g1t4[.]starmarkt[.]online/miyileho98[.]sh hxxps://silicon-moss[.]ru/fqb[.]google?t=apu5vesb hxxps://soniccobalt[.]ru/pd[.]check?t=1nlwzv0s hxxps://k8x1[.]starmarkt[.]online/1ffsun8djp[.]sh hxxps://soniccobalt[.]ru/vd3mt452 hxxps://orbitkrone[.]online/id69a0kw35[.]1 hxxps://k8x1[.]starmarkt[.]online/vm8m4qt5vj[.]sh hxxps://lotioniron[.]ru/fw[.]check?t=uthiuapp hxxps://driftfels[.]online/qbxg5wb9ct[.]1 hxxps://siliconmoss[.]ru/6iwogh1v hxxps://r0b3[.]starmarkt[.]online/b3zhv5mw27[.]sh hxxps://pixel-orbit[.]ru/a1[.]google?t=bpcdt38r hxxps://solarviolet[.]ru/vlb3lazm hxxps://swiftfluss[.]ru/mvsl3vrjw1[.]1 hxxps://pixelorbit[.]ru/vuh[.]google?t=7oamh19r hxxps://l2f7[.]starmarkt[.]online/uhdmsv98gv[.]sh hxxps://fsrm[.]lilacsilo[.]ru/b95[.]google?t=prj9k9ob hxxps://ovs[.]amberr-0-ck-et[.]ru/p32ihrja hxxps://gladeeiche[.]ru/zohjhrc2 hxxps://gladeeiche[.]ru/rp2[.]google?t=8m5595oa hxxps://vectorblitz[.]ru/tn[.]check?t=d26dudiq hxxps://vectorblitz[.]ru/3ul1i6da hxxps://tidalschatten[.]ru/tn[.]check?t=gzstka00 hxxps://mintnord[.]ru/f180alms hxxps://mintnord[.]ru/tn[.]check?t=qzsatl1l hxxps://cindertau[.]ru/rp2[.]google?t=q31kh0u2 hxxps://indigowelle[.]ru/tn[.]check?t=eqo78ccg hxxps://ambergeist[.]ru/rp2[.]google?t=iyx51zhn hxxps://ambergeist[.]ru/710v9ilb hxxps://zenithspitze[.]ru/tn[.]check?t=gdikoazs hxxps://serena-point[.]ru/nskrzc8m hxxps://serena-point[.]ru/rp2[.]google?t=otpvgs0c hxxps://dawn-mirror[.]ru/tn[.]check?t=ichtuqzx hxxps://mighty-flora[.]ru/rp2[.]google?t=2p22jcmw hxxps://shadowgrove[.]ru/tn[.]check?t=9t6p0bax hxxps://1unarpetal[.]ru/rp2[.]google?t=q7avbfux hxxps://dawnmirror[.]ru/qqrtyw0g hxxps://mightyflora[.]ru/8am63pq5 hxxps://mightyflora[.]ru/rp2[.]google?t=6lq1uhdn hxxps://serenapoint[.]ru/q5rx0daw hxxps://serenapoint[.]ru/rp2[.]google?t=640f2nx7 hxxps://ic0nicr1ver[.]ru/68cr2int hxxps://ic0nicr1ver[.]ru/tn[.]check?t=i0lwo7pe hxxps://shadow-grove[.]ru/rp2[.]google?t=magej7bu hxxps://m0onsh1nebay[.]ru/rp2[.]google?t=almjvbdr hxxps://sunnyharbor[.]ru/tn[.]check?t=c2ngqurv hxxps://sunnyharbor[.]ru/24bu97cc hxxps://ab7[.]sunny-harbor[.]ru/qm[.]google?t=p3tctchp hxxps://brightsilk[.]ru/zn0kpt23 hxxps://brightsilk[.]ru/tn[.]check?t=jf1k4njj hxxps://k2v[.]whisperlake[.]ru/rd[.]google?t=dyaqottq hxxps://k2v[.]whisperlake[.]ru/vryshubj hxxps://rz4[.]sunny-harbor[.]ru/x3to2hit hxxps://rz4[.]sunny-harbor[.]ru/bn2[.]check?t=oceatkvq hxxps://x1p[.]sunny-harbor[.]ru/ty3[.]check?t=i7xa2vq5 hxxps://q2k[.]sunny-harbor[.]ru/v0[.]google?t=noll66xx hxxps://q2k[.]sunny-harbor[.]ru/r66vgxlb hxxps://m9x[.]sunny-harbor[.]ru/1za[.]check?t=i68ti6ul hxxps://m9x[.]sunny-harbor[.]ru/wxc51kmq hxxps://f2a[.]nebularanke[.]ru/t8[.]google?t=85475f8j hxxps://f2a[.]nebularanke[.]ru/xdmtnv0q hxxps://v2r[.]whisperlake[.]ru/lq0[.]google?t=sp2ry3xs hxxps://c4n[.]whisperlake[.]ru/dp2[.]check?t=9sx1aj6u hxxps://c4n[.]whisperlake[.]ru/uesskkwy hxxps://yxm4[.]whisperlake[.]ru/a0[.]google?t=2ag61r4e hxxps://t3q[.]whisperlake[.]ru/9m1[.]check?t=npy2w4ys hxxps://z0r[.]nebularanke[.]ru/p0x[.]check?t=vm0cb50f hxxps://nq5[.]nebularanke[.]ru/k2[.]google?t=19ogde3t hxxps://nq5[.]nebularanke[.]ru/wu58y365 hxxps://d34[.]nebularanke[.]ru/r19[.]check?t=blxutcp9 hxxps://w9[.]nebularanke[.]ru/3qa[.]google?t=qs7d3vdq hxxps://k7x[.]nebularanke[.]ru/v0f[.]check?t=hhazjyc2 hxxps://k7x[.]nebularanke[.]ru/38g4pw0w |
ClearFake |
| URL | hxxp://178[.]16[.]54[.]200/files/5917492177/DsAL9tv[.]exe hxxp://37[.]84[.]141[.]224/info[.]zip hxxp://201[.]223[.]243[.]31:82/AV[.]scr hxxp://27[.]151[.]162[.]166:81/AV[.]scr hxxp://201[.]223[.]243[.]31:82/Video[.]scr hxxp://27[.]151[.]162[.]166:81/Video[.]scr hxxp://189[.]177[.]10[.]26/AV[.]scr hxxp://189[.]177[.]10[.]26/Video[.]scr hxxp://187[.]209[.]139[.]161/Video[.]scr hxxp://187[.]209[.]139[.]161/AV[.]scr hxxp://37[.]85[.]79[.]131/info[.]zip hxxp://37[.]84[.]127[.]89/info[.]zip hxxp://27[.]152[.]72[.]50:3389/info[.]zip hxxp://27[.]151[.]162[.]166:81/info[.]zip hxxp://37[.]84[.]171[.]190/info[.]zip hxxp://27[.]152[.]72[.]50:3389/Video[.]scr hxxp://61[.]160[.]215[.]114:3310/Video[.]lnk hxxp://189[.]177[.]10[.]26/info[.]zip hxxp://37[.]85[.]211[.]136/info[.]zip hxxp://201[.]223[.]243[.]31:82/info[.]zip hxxp://27[.]152[.]72[.]50:3389/AV[.]scr hxxp://37[.]85[.]148[.]189/info[.]zip hxxp://27[.]152[.]72[.]50:3389/Video[.]lnk hxxp://27[.]152[.]72[.]50:3389/AV[.]lnk hxxp://220[.]77[.]244[.]174:8602/info[.]zip hxxp://37[.]82[.]77[.]91/info[.]zip hxxp://218[.]158[.]139[.]131:8602/info[.]zip hxxp://189[.]177[.]10[.]26/AV[.]lnk hxxp://187[.]209[.]139[.]161/info[.]zip hxxp://201[.]223[.]243[.]31:82/Video[.]lnk hxxp://37[.]80[.]195[.]38/info[.]zip hxxp://83[.]171[.]160[.]98/AV[.]lnk hxxp://61[.]160[.]215[.]114:3310/AV[.]lnk hxxp://27[.]151[.]162[.]166:81/Video[.]lnk hxxp://27[.]151[.]162[.]166:81/AV[.]lnk hxxp://83[.]171[.]160[.]98/Video[.]scr hxxp://61[.]160[.]215[.]114:3310/Video[.]scr hxxp://37[.]80[.]195[.]38/AV[.]lnk hxxp://94[.]76[.]156[.]101:280/AV[.]lnk hxxp://201[.]223[.]243[.]31:82/AV[.]lnk hxxp://36[.]158[.]34[.]122:190/Video[.]lnk hxxp://83[.]171[.]160[.]98/AV[.]scr hxxp://83[.]171[.]160[.]98/Video[.]lnk hxxp://187[.]209[.]139[.]161/Video[.]lnk hxxp://189[.]177[.]10[.]26/Video[.]lnk hxxp://187[.]209[.]139[.]161/AV[.]lnk hxxp://216[.]114[.]75[.]50:40120/AV[.]lnk hxxp://111[.]59[.]254[.]165:8084/20140730/AV[.]scr hxxp://111[.]59[.]254[.]165:8084/20250210/AV[.]scr hxxp://58[.]22[.]95[.]157:6868/20240103%E8%8B%B1%E8%AF%AD%E5%90%AC%E8%AF%B4%E6%9C%9F%E6%9C%AB%E5%BD%95%E9%9F%B3/%E5%BD%B1%E8%A7%86%E6%8A%80%E6%9C%AF%E7%8F%AD/119%E9%A9%AC%E9%9B%AF%E5%A9%B7-%E6%97%A0/Video[.]scr hxxp://58[.]22[.]95[.]157:6868/20240103%E8%8B%B1%E8%AF%AD%E5%90%AC%E8%AF%B4%E6%9C%9F%E6%9C%AB%E5%BD%95%E9%9F%B3/%E5%BD%B1%E8%A7%86%E6%8A%80%E6%9C%AF%E7%8F%AD/Video[.]scr hxxp://58[.]22[.]95[.]157:6868/20240103%E8%8B%B1%E8%AF%AD%E5%90%AC%E8%AF%B4%E6%9C%9F%E6%9C%AB%E5%BD%95%E9%9F%B3/%E7%85%A7%E6%98%8E%E4%BA%8C%E7%8F%AD/AV[.]scr hxxp://58[.]22[.]95[.]157:6868/20240103%E8%8B%B1%E8%AF%AD%E5%90%AC%E8%AF%B4%E6%9C%9F%E6%9C%AB%E5%BD%95%E9%9F%B3/%E5%BD%B1%E8%A7%86%E6%8A%80%E6%9C%AF%E7%8F%AD/128%E7%86%8A%E7%BE%8E%E8%8C%B9-%E6%97%A0/Video[.]scr hxxp://58[.]22[.]95[.]157:6868/20240103%E8%8B%B1%E8%AF%AD%E5%90%AC%E8%AF%B4%E6%9C%9F%E6%9C%AB%E5%BD%95%E9%9F%B3/%E5%BD%B1%E8%A7%86%E6%8A%80%E6%9C%AF%E7%8F%AD/AV[.]scr hxxp://58[.]22[.]95[.]157:6868/20240103%E8%8B%B1%E8%AF%AD%E5%90%AC%E8%AF%B4%E6%9C%9F%E6%9C%AB%E5%BD%95%E9%9F%B3/%E7%85%A7%E6%98%8E%E4%BA%8C%E7%8F%AD/Video[.]scr hxxp://58[.]22[.]95[.]157:6868/20240103%E8%8B%B1%E8%AF%AD%E5%90%AC%E8%AF%B4%E6%9C%9F%E6%9C%AB%E5%BD%95%E9%9F%B3/%E5%BD%B1%E8%A7%86%E6%8A%80%E6%9C%AF%E7%8F%AD/119%E9%A9%AC%E9%9B%AF%E5%A9%B7-%E6%97%A0/AV[.]scr hxxp://58[.]22[.]95[.]157:6868/20240103%E8%8B%B1%E8%AF%AD%E5%90%AC%E8%AF%B4%E6%9C%9F%E6%9C%AB%E5%BD%95%E9%9F%B3/%E5%BD%B1%E8%A7%86%E6%8A%80%E6%9C%AF%E7%8F%AD/128%E7%86%8A%E7%BE%8E%E8%8C%B9-%E6%97%A0/AV[.]scr hxxp://31[.]28[.]44[.]39/USB-%D0%BD%D0%B0%D0%BA%D0%BE%D0%BF%D0%B8%D1%82%D0%B5%D0%BB%D1%8C/Photo[.]lnk hxxp://31[.]28[.]44[.]39/%D0%9F%D0%B8%D0%BB%D0%BE%D1%82/Video[.]scr hxxp://31[.]28[.]44[.]39/%D0%9F%D0%B8%D0%BB%D0%BE%D1%82/Photo[.]scr hxxp://31[.]28[.]44[.]39/USB-%D0%BD%D0%B0%D0%BA%D0%BE%D0%BF%D0%B8%D1%82%D0%B5%D0%BB%D1%8C/Photo[.]scr hxxp://31[.]28[.]44[.]39/%D0%9F%D0%B8%D0%BB%D0%BE%D1%82/AV[.]scr hxxp://31[.]28[.]44[.]39/USB-%D0%BD%D0%B0%D0%BA%D0%BE%D0%BF%D0%B8%D1%82%D0%B5%D0%BB%D1%8C/AV[.]scr hxxp://31[.]28[.]44[.]39/USB-%D0%BD%D0%B0%D0%BA%D0%BE%D0%BF%D0%B8%D1%82%D0%B5%D0%BB%D1%8C/Video[.]scr hxxp://31[.]28[.]44[.]39/%D0%9F%D0%B8%D0%BB%D0%BE%D1%82/AV[.]lnk hxxp://31[.]28[.]44[.]39/USB-%D0%BD%D0%B0%D0%BA%D0%BE%D0%BF%D0%B8%D1%82%D0%B5%D0%BB%D1%8C/AV[.]lnk hxxp://31[.]28[.]44[.]39/USB-%D0%BD%D0%B0%D0%BA%D0%BE%D0%BF%D0%B8%D1%82%D0%B5%D0%BB%D1%8C/Video[.]lnk hxxp://31[.]28[.]44[.]39/%D0%9F%D0%B8%D0%BB%D0%BE%D1%82/Photo[.]lnk hxxp://31[.]28[.]44[.]39/%D0%9F%D0%B8%D0%BB%D0%BE%D1%82/Video[.]lnk hxxp://83[.]171[.]160[.]98/Photo[.]scr hxxp://178[.]16[.]54[.]200/files/8455735771/2tvA1kd[.]exe |
Coinminer |
| URL | hxxp://178[.]16[.]55[.]189/files/7948739500/5cwJjT0[.]exe | Lu0Bot |
| URL | hxxps://g4v[.]solarfracht[.]online/tk61jrv31g[.]sh hxxps://7[.]kzg-w-4-y[.]ru/t6zimgt461[.]sh hxxps://c2[.]kzg-w-4-y[.]ru/zue6w6a18g[.]sh hxxps://c2[.]kzg-w-4-y[.]ru/s3bavcir0a[.]sh hxxps://la[.]kzg-w-4-y[.]ru/mk7z9jhkgu[.]sh hxxps://la[.]kzg-w-4-y[.]ru/4q2gfnsumt[.]sh hxxps://b1x3[.]solarfracht[.]online/3wt6ak75jh[.]sh hxxps://qk7[.]solarfracht[.]online/ox6zcomtyx[.]sh hxxps://qk7[.]solarfracht[.]online/f128pz6jbw[.]sh hxxps://t9m2[.]solarfracht[.]online/sxo5cjxuro[.]sh hxxps://r2l[.]solarfracht[.]online/dvzbccietd[.]sh |
AMOS |
| URL | hxxp://194[.]180[.]49[.]148:8900/rabert[.]exe hxxp://wafflemafia[.]top/d/server[.]exe hxxp://185[.]208[.]159[.]182/d/server[.]exe hxxp://31[.]57[.]219[.]205/doc[.]exe hxxp://178[.]16[.]54[.]200/files/1781548144/PEC68GW[.]exe |
Quasar RAT |
| URL | hxxp://137[.]220[.]176[.]249/mysqla[.]exe hxxp://137[.]220[.]176[.]249/mysqla[.]bin |
Meterpreter |
| URL | hxxp://37[.]27[.]17[.]205/bound_app[.]apk hxxp://37[.]27[.]17[.]205/SBI[.]apk hxxp://37[.]27[.]17[.]205/Calculator[.]apk hxxp://37[.]27[.]17[.]205/update[.]apk hxxp://37[.]27[.]17[.]205/demodata[.]apk hxxp://115[.]227[.]166[.]76:8081/Invade/Remote/Metasploit/Windows/Crack[.]rar |
Metasploit |
| URL | hxxp://178[.]16[.]54[.]200/files/7336533485/BfSdTsC[.]exe hxxp://178[.]16[.]54[.]200/files/6608710704/0X4szPI[.]exe |
Vidar |
| URL | hxxp://64[.]188[.]127[.]118/Launcher[.]exe hxxp://178[.]16[.]55[.]189/files/502259649/valPntR[.]exe |
Rhadamanthys |
| URL | hxxps://imf1[.]com/9h0y[.]js hxxps://imf1[.]com/js[.]php hxxp://72[.]5[.]43[.]147:7777/frt44 hxxp://72[.]5[.]43[.]147:7777/2nd hxxps://edentista[.]com/5g7o[.]js hxxps://edentista[.]com/js[.]php hxxp://168[.]100[.]11[.]73:6655/frt44 hxxps://dolmain[.]com/5w8h[.]js hxxps://dolmain[.]com/js[.]php |
KongTuke |
| URL | hxxps://smilesmash[.]com/xss/buf[.]js hxxps://smilesmash[.]com/xss/index[.]php hxxps://flowascatch[.]com/xss/buf[.]js hxxps://flowascatch[.]com/xss/index[.]php |
NetSupportManager RAT |
| URL | hxxps://api[.]telegram[.]org/bot8201081257:AAFGP3RILcJSLUHTLUzj8fONI3UBmoDrbwk/sendMessage?chat_id=7584924098 hxxps://api[.]telegram[.]org/bot8146726698:AAFWaTbmHzUN6pYeLzCeWChw7iGzEwehNUA/sendMessage?chat_id=7607347686 hxxps://api[.]telegram[.]org/bot7919862153:AAEym2UUs7_DJ-Z6z5_Vk7ddrbkZu38tsTk/sendMessage?chat_id=7282830258 hxxps://api[.]telegram[.]org/bot8339010936:AAFt_v-MMma-SQWLHVg85Y6xzCIi0pIOyPI/sendMessage?chat_id=6595599138 hxxps://api[.]telegram[.]org/bot7955994062:AAFaf0rqX4ZYgw5PLzhNAKA4a1i8jYAWSo4/sendMessage?chat_id=6718985910 hxxps://api[.]telegram[.]org/bot8041021483:AAEnPX_ChSnHkP7Z_m-fhkSMoVZjp1WpJKY/sendMessage?chat_id=7146274755 hxxps://api[.]telegram[.]org/bot8383259117:AAEqXxxv_3-oOzFlx-TJwSs4dBBv66ADczQ/sendMessage?chat_id=6230067815 hxxps://api[.]telegram[.]org/bot8024511785:AAHunp8l_HZLR2EhZzrEmS-lyA4FMHKIMlg/sendMessage?chat_id=7146274755 hxxps://api[.]telegram[.]org/bot8045679116:AAEAFLvf25OAK3TYsLRJu40waVU1-qP1G-I/sendMessage?chat_id=6750192797 hxxps://api[.]telegram[.]org/bot8278774437:AAG3TGewn2vVPZdXzsVZhrNnxYcntZfHVGI/sendMessage?chat_id=7517466889 hxxps://api[.]telegram[.]org/bot8468094506:AAFxYAsaJO-fXKOSFf_knDBUKn7eURzEEoI/sendMessage?chat_id=7361609845 hxxps://api[.]telegram[.]org/bot8201600461:AAFZxmdeV0j3e-RdpjJ630iI-5sWLmF1DrY/sendMessage?chat_id=8277275661 hxxps://api[.]telegram[.]org/bot8336320989:AAHlvvvR_j7LbBk-dC5wj9m5Wj5aFXSPK7M/sendMessage?chat_id=7618581100 hxxps://api[.]telegram[.]org/bot8032043025:AAExPfO6CatfwvFTkpZ38eSbVMyVVXkvrwg/sendMessage?chat_id=7941770697 hxxps://api[.]telegram[.]org/bot7879484835:AAFvge21ouCFKg005nfNRx09-u6DipXC_XI/sendMessage?chat_id=7324592749 |
Snake Keylogger |
| URL | hxxps://api[.]telegram[.]org/bot8444333453:AAHge7NyKHU_EwZxbErc1RxR1KxrAEpHz_M/sendMessage?chat_id=7785719799 | MASS Logger |
| URL | hxxps://api[.]telegram[.]org/bot8421960486:AAE4pTVd8uab0YwCSzZxOKWlCi3cC92hPyk/sendMessage?chat_id=8178506397 hxxps://api[.]telegram[.]org/bot8248911657:AAF5cd-f6SBdQ4O9NCyYFSQP3WAxUa3vYtA/sendMessage?chat_id=6789460830 hxxps://api[.]telegram[.]org/bot7740411592:AAFEJzFMHimRdGE7B3ERIeRmhMFAyO5b2iM/sendMessage?chat_id=7365979371 hxxps://api[.]telegram[.]org/bot7342007318:AAHBay41reeqYH7yzmnk6Sczgr7kzPJjM-s/sendMessage?chat_id=6789460830 hxxps://api[.]telegram[.]org/bot8264503446:AAG2-w0vSRAlNaWnuGFYBXUA_cw2EIN4juk/sendMessage?chat_id=7000018009 hxxps://api[.]telegram[.]org/bot8439354694:AAHAIgdgDfmnlTUulLwoFjbH7rN2cgqcXnA/sendMessage?chat_id=7306757640 hxxps://api[.]telegram[.]org/bot8317183112:AAECcrn6ndVAReawEJZ0myW446eLGrsmgjQ/sendMessage?chat_id=5386004523 |
DarkCloud |
| URL | hxxp://178[.]16[.]54[.]200/files/unique1/random[.]exe | GCleaner |
| URL | hxxp://49[.]232[.]102[.]63:8888/807 hxxp://49[.]232[.]102[.]63:8888/8065 |
Vshell |
| URL | hxxp://54[.]185[.]104[.]98:8080/demon[.]x64[.]exe | Havoc |
| URL | hxxps://auldlxm[.]courses/api hxxp://178[.]16[.]54[.]200/files/5638395652/JfP2ZjQ[.]exe hxxp://178[.]16[.]54[.]200/files/7044575709/ifilS8q[.]exe |
Lumma Stealer |
| URL | hxxps://keyworksrl[.]it/wp-content/plugins/wp-required-integumentary/index[.]php?r=bD1odHRwczovL2Nsb3VkMjAyMC1wb29sLTEwOTgtdm9sdW1lLnMzLnVzLWVhc3QtMS5hbWF6b25hd3MuY29tLzZLdGVyVGxRVCZlbT1pbmZvQGhvbGxlci1wbGFudW5nLmRl | Latrodectus |
| URL | hxxp://178[.]16[.]54[.]200/files/8455735771/upt37RC[.]exe | Stealc |
| URL | hxxp://91[.]205[.]191[.]202/svchost[.]exe hxxp://91[.]205[.]191[.]202/XWormClient[.]exe |
AsyncRAT |
| URL | hxxp://156[.]238[.]233[.]21:8089/02[.]08[.]2022[.]exe hxxp://165[.]154[.]224[.]126:45231/02[.]08[.]2022[.]exe hxxp://194[.]87[.]10[.]124/02[.]08[.]2022[.]exe hxxp://47[.]79[.]19[.]147:8089/02[.]08[.]2022[.]exe hxxp://8[.]152[.]223[.]39/02[.]08[.]2022[.]exe hxxp://47[.]120[.]7[.]76/02[.]08[.]2022[.]exe hxxp://83[.]229[.]126[.]183/02[.]08[.]2022[.]exe hxxp://47[.]92[.]78[.]31:12587/02[.]08[.]2022[.]exe hxxp://59[.]110[.]28[.]230:443/02[.]08[.]2022[.]exe hxxp://124[.]223[.]25[.]186:4444/02[.]08[.]2022[.]exe hxxp://124[.]223[.]104[.]136:5555/02[.]08[.]2022[.]exe hxxp://38[.]38[.]251[.]151:8080/02[.]08[.]2022[.]exe hxxp://49[.]233[.]204[.]250:4444/02[.]08[.]2022[.]exe hxxp://42[.]192[.]49[.]146/02[.]08[.]2022[.]exe hxxp://194[.]120[.]24[.]207/02[.]08[.]2022[.]exe hxxp://212[.]14[.]244[.]222:806/02[.]08[.]2022[.]exe |
Cobalt Strike |
| URL | hxxp://158[.]94[.]209[.]216/xmips | Bashlite |








