不正URLへのアクセス、不正メールの受信
-
メール受信した
弊社お客様0社 URLアクセスした
弊社お客様0社 -
2026/02/09
※2026/02/09 更新
マルウェア感染させると考えられるURLを検知(2026/02/09)
■IoC(※1)
| Type: | IOC: | Signature: |
|---|---|---|
| URL | hxxp://23[.]160[.]56[.]192/p[.]txt | XOR DDoS |
| URL | hxxp://130[.]12[.]180[.]43/files/8468434805/fKDnWbX[.]exe hxxp://130[.]12[.]180[.]43/files/6719008056/LR0D6Rm[.]bat hxxp://130[.]12[.]180[.]43/files/7538357236/XxpGuvc[.]bat |
Quasar RAT |
| URL | hxxp://691239cm[.]nyash[.]es/TowindowsDownloads[.]php hxxp://161bet[.]com[.]br/faq[.]html:8888/ hxxp://161bet[.]com[.]br/faq[.]html:2087/ hxxp://161bet[.]com[.]br/faq[.]html:2096/ hxxp://161bet[.]com[.]br/faq[.]html:443/ hxxp://161bet[.]com[.]br/faq[.]html:4782/ hxxp://161bet[.]com[.]br/faq[.]html:80/ hxxp://161bet[.]com[.]br/faq[.]html:8080/ hxxp://161bet[.]com[.]br/faq[.]html:8848/ hxxp://161bet[.]com[.]br/faq[.]html:2053/ hxxp://161bet[.]com[.]br/faq[.]html:2083/ |
DCRat |
| URL | hxxp://retrodayaengineering[.]icu/LUK[.]hta hxxp://45[.]153[.]34[.]90/WEB/EAZYYYYY[.]ps1 hxxp://retrodayaengineering[.]icu/HAR[.]hta hxxp://130[.]12[.]180[.]43/files/8408827406/3nc8x41[.]exe hxxp://130[.]12[.]180[.]43/files/8408827406/l2yrUyb[.]exe |
XWorm |
| URL | hxxps://powercat[.]dog/28954 | AdWind |
| URL | hxxps://emierich[.]com/2p2o[.]js hxxps://weibast[.]com/5m1d[.]js hxxps://weibast[.]com/js[.]php hxxps://rpgpals[.]com/9n4d[.]js hxxps://rpgpals[.]com/js[.]php |
KongTuke |
| URL | hxxps://api[.]telegram[.]org/bot8469606505:AAEsZTHohQDV5U0GSQLk171vIQQBVrodQT8/sendMessage?chat_id=8178506397 hxxps://api[.]telegram[.]org/bot8462087005:AAEXzjR7NvdtxxNL2ihYxpi0tpCxnUs8h0A/sendMessage?chat_id=8591926998 hxxp://45[.]153[.]34[.]90/WEB/YALLOWSISI[.]ps1 hxxp://45[.]153[.]34[.]90/WEB/arryaaaaaaaaa[.]ps1 hxxp://45[.]153[.]34[.]90/WEB/park[.]ps1 hxxp://45[.]153[.]34[.]90/WEB/FAN[.]ps1 hxxp://45[.]153[.]34[.]90/WEB/aryaphan[.]ps1 hxxps://api[.]telegram[.]org/bot7991374459:AAGqLt4_FwfvWftSxNRxCJUe9JJnuwk3hag/sendMessage?chat_id=7362332542 hxxps://api[.]telegram[.]org/bot7798195026:AAH8zcgq8bQQS41esEQNvsXxdHgX3MIQfds/sendMessage?chat_id=6159490685 hxxps://api[.]telegram[.]org/bot8517178613:AAF9-ZfEPoNbgFEjDbCTJwlxO_jbjYbWz1I/sendMessage?chat_id=7362332542 hxxps://api[.]telegram[.]org/bot8230350418:AAFQRigObWln5SAjYOSvlqGPoLSbTRmcID0/sendMessage?chat_id=8411670109 hxxps://api[.]telegram[.]org/bot8444575742:AAHLLbPz4cdYw0mujxWTVIVzIvYajRAvIVc/sendMessage?chat_id=1585465694 hxxps://api[.]telegram[.]org/bot8229288098:AAG4-JW4dR3DuW8kIXv7IoBIaiO-2L_Pzlc/sendMessage?chat_id=7934899287 |
Stealerium |
| URL | hxxps://api[.]telegram[.]org/bot8512555116:AAG0X6w-tKKSElrCDhHIaPtXgy2wIRma4pg/ hxxp://45[.]153[.]34[.]90/WEB/STEINSECOND[.]ps1 hxxp://45[.]153[.]34[.]90/WEB/STEINSECONDD[.]ps1 hxxp://45[.]153[.]34[.]90/WEB/STEINN[.]ps1 |
Agent Tesla |
| URL | hxxps://api[.]telegram[.]org/bot8195252587:AAHqMfddO9ZD9x5zTvbK-UmzyFi_aIf37C8/sendMessage?chat_id=6311012313 hxxps://api[.]telegram[.]org/bot8440824913:AAEKra-VNyC-HzKnLTGW77TGFjZtKwoIhUk/sendMessage?chat_id=7362332542 hxxps://api[.]telegram[.]org/bot8227408033:AAFNFLTD0IANa531sNjnYtJzPT9wN87Mbfo/sendMessage?chat_id=7362332542 |
DarkCloud |
| URL | hxxp://45[.]153[.]34[.]90/WEB/grain[.]ps1 hxxp://45[.]153[.]34[.]90/WEB/arya[.]ps1 |
BluStealer |
| URL | hxxp://45[.]153[.]34[.]90/WEB/MODE[.]ps1 hxxp://91[.]92[.]243[.]254:7777/91[.]92[.]243[.]254/khadifaz/ENCRYPTED[.]ps1 hxxp://91[.]92[.]243[.]254:7777/91[.]92[.]243[.]254/khadifaz/khadifa/jfk3ghGZt7pDHG2E5g9g[.]js hxxp://91[.]92[.]243[.]254:7777/91[.]92[.]243[.]254/vvbv/ENCRYPTED[.]ps1 hxxp://91[.]92[.]243[.]254:7777/91[.]92[.]243[.]254/vvbvone/vvbv/1ghGE1jfkgF29gt7pDHG[.]js |
Formbook |
| URL | hxxp://45[.]153[.]34[.]90/WEB/eazybim[.]ps1 hxxp://130[.]12[.]180[.]43/files/7044575709/ZFEg4Ra[.]exe hxxps://api[.]telegram[.]org/bot7113911764:AAE-8KT0w4_ZHeCpXBwG_Qtxw3uv_AvSwR8/sendMessage hxxps://api[.]telegram[.]org/bot8329962954:AAEH8WftBu_pwZpcobpV6jJROneK2mCHrWo/sendMessage hxxps://api[.]telegram[.]org/bot7316577574:AAGlFAgovip0WdyC2Qj_nBxKU0wNzI7OON8/sendMessage hxxps://api[.]telegram[.]org/bot7113911764:AAGEc9fxtpJXWVIaO_1wvyHaRsuT2EFhVUU/sendMessage hxxps://api[.]telegram[.]org/bot8498071055:AAHpkLnFSqcqoBJ5BRLXLoNzGKZN-fcRM_E/sendMessage |
AsyncRAT |
| URL | hxxps://a6u344gi[.]galloverpower[.]digital/?=check&&actmn=BQhUvRNucJQlpbzJ hxxps://uljt1y53[.]inspirpatience[.]digital/?=check&&actmn=ZUqluZwGngHogjfO hxxps://2wjmdomc[.]breathforgiv[.]digital/?=check&&actmn=GdDTxbxDMAYbyRXo |
ClearFake |
| URL | hxxp://103[.]101[.]85[.]39/e57fc20ec405486a[.]php hxxp://178[.]17[.]62[.]64/749c1d9b3f7647ce[.]php hxxp://80[.]97[.]160[.]144/05f640dd85154ef9[.]php hxxps://95[.]216[.]187[.]218/cf2bf91a3641f615[.]php hxxps://172[.]86[.]70[.]117/94ed4bf54583a4fa[.]php hxxps://77[.]83[.]175[.]105/18a9a962225b1ffb[.]php hxxp://130[.]12[.]180[.]43/files/7598745812/ACWEBaQ[.]exe hxxp://151[.]240[.]151[.]64/073a8dc27abd4402[.]php hxxp://185[.]174[.]133[.]12/98926703060a4fbf[.]php |
Stealc |
| URL | hxxp://130[.]12[.]180[.]43/files/918797661/MT51cLB[.]exe hxxp://45[.]137[.]201[.]200:8082/download hxxp://clawbuzz[.]xyz/bunc hxxps://i[.]404[.]pm/2025/09/27/1758984967-5707[.]jpeg |
SalatStealer |
| URL | hxxps://23[.]254[.]229[.]88/attivita/index[.]php | Amadey |
| URL | hxxp://130[.]12[.]180[.]43/files/6951863039/XcnPbsV[.]exe hxxp://130[.]12[.]180[.]43/files/8068616748/4L2OGu0[.]exe hxxp://39[.]106[.]81[.]175:5002/download/xQ4gNK9auvFo4[.]exe hxxp://39[.]106[.]81[.]175:5002/download/Setup[.]exe hxxp://39[.]106[.]81[.]175:5002/download/Y3593UGC11D2[.]exe hxxp://39[.]106[.]81[.]175:5002/download/xa29d6ca899a2a2c1497b192dc8aeb1cb6290109c347ffe3bc66d950dc0b0f1a6[.]exe hxxp://39[.]106[.]81[.]175:5002/download/x554650562de7ff4b0a266857cdd8bad5c3445dbe23816c7898eb679d34652391[.]exe hxxp://39[.]106[.]81[.]175:5002/download/KeyGeneratorPro[.]exe hxxp://39[.]106[.]81[.]175:5002/download/37KKS9R5AOV0[.]exe |
SantaStealer |
| URL | hxxp://scorpcasinos[.]com/7/Output[.]js | Loda |
| URL | hxxp://htcgroups[.]ga/flop/beez/fre[.]php | LokiBot |
| URL | hxxp://192[.]140[.]176[.]79:12124/02[.]08[.]2022[.]exe hxxp://102[.]134[.]48[.]37:8888/5Kzc hxxp://www[.]emezonhe[.]me:443/jquery-3[.]3[.]1[.]min[.]js hxxp://47[.]105[.]41[.]59:10080/9zQY hxxps://13[.]41[.]96[.]167/02[.]08[.]2022[.]exe hxxps://117[.]72[.]181[.]104/02[.]08[.]2022[.]exe hxxps://115[.]190[.]140[.]220:1443/02[.]08[.]2022[.]exe hxxps://123[.]58[.]64[.]57:34567/02[.]08[.]2022[.]exe hxxps://117[.]72[.]79[.]68:30001/02[.]08[.]2022[.]exe hxxps://115[.]120[.]245[.]134/02[.]08[.]2022[.]exe hxxps://138[.]124[.]15[.]54:63798/02[.]08[.]2022[.]exe hxxps://3[.]66[.]49[.]194/02[.]08[.]2022[.]exe hxxps://8[.]152[.]99[.]85/02[.]08[.]2022[.]exe hxxp://www[.]feft234321[.]xyz/02[.]08[.]2022[.]exe hxxps://179[.]43[.]186[.]214:7889/02[.]08[.]2022[.]exe hxxps://107[.]149[.]192[.]54:8080/02[.]08[.]2022[.]exe hxxps://212[.]14[.]244[.]222:808/02[.]08[.]2022[.]exe hxxp://tr0ff3[.]cn/02[.]08[.]2022[.]exe hxxps://39[.]98[.]51[.]2:18444/02[.]08[.]2022[.]exe hxxps://172[.]190[.]244[.]213/02[.]08[.]2022[.]exe hxxps://8[.]138[.]222[.]215/02[.]08[.]2022[.]exe hxxps://47[.]92[.]82[.]162/02[.]08[.]2022[.]exe hxxps://103[.]69[.]194[.]63/02[.]08[.]2022[.]exe hxxps://38[.]38[.]250[.]99:5800/02[.]08[.]2022[.]exe hxxp://92[.]118[.]124[.]53/02[.]08[.]2022[.]exe hxxps://115[.]190[.]233[.]79/02[.]08[.]2022[.]exe hxxps://8[.]152[.]99[.]85:8443/02[.]08[.]2022[.]exe hxxps://113[.]45[.]155[.]146:4433/02[.]08[.]2022[.]exe hxxps://165[.]245[.]141[.]24/02[.]08[.]2022[.]exe hxxps://111[.]228[.]55[.]96/02[.]08[.]2022[.]exe hxxps://38[.]147[.]172[.]92:8443/02[.]08[.]2022[.]exe hxxps://39[.]98[.]51[.]2:18443/02[.]08[.]2022[.]exe hxxps://8[.]219[.]76[.]168/02[.]08[.]2022[.]exe hxxps://36[.]140[.]162[.]173:4433/02[.]08[.]2022[.]exe hxxps://47[.]105[.]36[.]109/02[.]08[.]2022[.]exe hxxps://47[.]120[.]46[.]230/02[.]08[.]2022[.]exe hxxp://zyhservers[.]top/02[.]08[.]2022[.]exe hxxps://54[.]170[.]125[.]202/02[.]08[.]2022[.]exe hxxps://170[.]64[.]234[.]187/02[.]08[.]2022[.]exe hxxps://170[.]64[.]221[.]190/02[.]08[.]2022[.]exe hxxps://107[.]149[.]192[.]54:7443/02[.]08[.]2022[.]exe hxxps://202[.]146[.]218[.]74:2024/02[.]08[.]2022[.]exe hxxps://150[.]109[.]244[.]222:8888/02[.]08[.]2022[.]exe hxxp://176[.]65[.]151[.]201:8080/02[.]08[.]2022[.]exe hxxps://223[.]26[.]63[.]57/02[.]08[.]2022[.]exe hxxps://51[.]79[.]251[.]70/02[.]08[.]2022[.]exe hxxps://35[.]199[.]157[.]76/02[.]08[.]2022[.]exe hxxp://45[.]150[.]108[.]229/02[.]08[.]2022[.]exe hxxp://vitoboy[.]com/02[.]08[.]2022[.]exe hxxp://www[.]zyhservers[.]top/02[.]08[.]2022[.]exe hxxps://52[.]248[.]41[.]253:8443/02[.]08[.]2022[.]exe hxxps://banner[.]patch-support[.]com/02[.]08[.]2022[.]exe hxxps://39[.]104[.]78[.]25:8443/02[.]08[.]2022[.]exe hxxps://124[.]222[.]218[.]20:2345/02[.]08[.]2022[.]exe hxxps://120[.]27[.]211[.]70:18443/02[.]08[.]2022[.]exe hxxps://18[.]119[.]116[.]151/02[.]08[.]2022[.]exe hxxp://115[.]190[.]160[.]206/02[.]08[.]2022[.]exe hxxp://192[.]3[.]233[.]166:59850/02[.]08[.]2022[.]exe hxxps://101[.]200[.]193[.]211:8088/02[.]08[.]2022[.]exe hxxps://120[.]27[.]211[.]70:18444/02[.]08[.]2022[.]exe hxxps://47[.]109[.]48[.]57/02[.]08[.]2022[.]exe hxxps://188[.]166[.]178[.]198/02[.]08[.]2022[.]exe hxxps://172[.]208[.]108[.]15/02[.]08[.]2022[.]exe hxxps://54[.]85[.]23[.]82:8443/02[.]08[.]2022[.]exe hxxps://176[.]65[.]151[.]201:4443/02[.]08[.]2022[.]exe hxxps://38[.]147[.]172[.]92:18443/02[.]08[.]2022[.]exe hxxps://43[.]134[.]61[.]180/02[.]08[.]2022[.]exe hxxp://51[.]79[.]251[.]70/02[.]08[.]2022[.]exe hxxp://180[.]76[.]141[.]175/02[.]08[.]2022[.]exe hxxp://59[.]110[.]28[.]230/02[.]08[.]2022[.]exe hxxp://38[.]147[.]172[.]92:8081/02[.]08[.]2022[.]exe |
Cobalt Strike |
| URL | hxxps://api[.]telegram[.]org/bot8122638065:AAFSTRbyzlny-FWPEdoDR-kQc_IT2i98laI/sendMessage?chat_id=7587806587 hxxps://api[.]telegram[.]org/bot8168044731:AAE_SSHJF0SFdqhvFL9hpuz1oO2odQ-QitI/sendMessage?chat_id=1634902688 hxxps://api[.]telegram[.]org/bot8150439900:AAFmuL3cQy9m1WmWfvlTQMrtfNuEItrzWuQ/sendMessage?chat_id=6903984581 hxxps://api[.]telegram[.]org/bot8238630484:AAFeWQ4Uhn3WFdxhgu9JfYDameFumvKUlM4/sendMessage?chat_id=6939220311 hxxps://api[.]telegram[.]org/bot8326495629:AAEMK0NQNEBKqEUI19BZiQDBK3id8oEGwac/sendMessage?chat_id=8486884224 |
Snake Keylogger |
| URL | hxxp://124[.]167[.]238[.]38:8020/linux hxxp://47[.]83[.]202[.]230:60106/linux hxxp://47[.]242[.]47[.]14:60127/linux hxxp://47[.]237[.]77[.]26:60126/linux hxxp://47[.]242[.]142[.]111:60100/linux hxxp://112[.]124[.]33[.]87:60147/linux hxxp://114[.]215[.]193[.]12:60124/linux hxxp://23[.]249[.]28[.]118:60132/linux hxxp://47[.]237[.]140[.]12:60145/linux hxxp://164[.]68[.]97[.]90:60149/linux hxxp://8[.]152[.]7[.]218:60136/linux hxxp://8[.]222[.]207[.]98:60149/linux hxxp://178[.]62[.]63[.]125:60147/linux |
P2Pinfect |
| URL | hxxp://46[.]101[.]112[.]70/m-6[.]8-k[.]Sakura hxxp://46[.]101[.]112[.]70/i-5[.]8-6[.]Sakura hxxp://46[.]101[.]112[.]70/a-r[.]m-7[.]Sakura hxxp://46[.]101[.]112[.]70/a-r[.]m-5[.]Sakura hxxp://46[.]101[.]112[.]70/m-p[.]s-l[.]Sakura hxxp://46[.]101[.]112[.]70/x-3[.]2-[.]Sakura hxxp://46[.]101[.]112[.]70/p-p[.]c-[.]Sakura hxxp://46[.]101[.]112[.]70/x-8[.]6-[.]Sakura hxxp://46[.]101[.]112[.]70/s-h[.]4-[.]Sakura hxxp://46[.]101[.]112[.]70/m-i[.]p-s[.]Sakura hxxp://46[.]101[.]112[.]70/a-r[.]m-4[.]Sakura hxxp://87[.]121[.]79[.]127/x86_64 hxxp://46[.]101[.]112[.]70/Sakura[.]sh hxxp://185[.]165[.]169[.]101/bins/bot[.]superh hxxp://158[.]94[.]210[.]187/yakuza[.]mips hxxp://158[.]94[.]210[.]187/yakuza[.]sh4 hxxp://216[.]239[.]104[.]59/skid[.]mpsl hxxp://158[.]94[.]210[.]187/yakuza[.]mpsl hxxp://158[.]94[.]210[.]187/yakuza[.]i586 hxxp://216[.]239[.]104[.]59/skid[.]sparc hxxp://216[.]239[.]104[.]59/skid[.]arm5 hxxp://158[.]94[.]210[.]187/yakuza[.]arm4 hxxp://216[.]239[.]104[.]59/skid[.]ppc hxxp://158[.]94[.]210[.]187/yakuza[.]m68k hxxp://158[.]94[.]210[.]187/yakuza[.]x32 hxxp://216[.]239[.]104[.]59/skid[.]arm4 hxxp://158[.]94[.]210[.]187/yakuza[.]ppc hxxp://87[.]121[.]79[.]127/mipsel hxxp://216[.]239[.]104[.]59/skid[.]sh hxxp://158[.]94[.]210[.]187/bins[.]sh hxxp://103[.]45[.]245[.]174/sex[.]sh hxxp://103[.]45[.]245[.]174/586 hxxp://158[.]94[.]210[.]187/yakuza[.]x86 hxxp://103[.]45[.]245[.]174/m68k hxxp://103[.]45[.]245[.]174/dss hxxp://103[.]45[.]245[.]174/ppc hxxp://103[.]45[.]245[.]174/co hxxp://103[.]45[.]245[.]174/x86 hxxp://103[.]45[.]245[.]174/dc hxxp://103[.]45[.]245[.]174/sh4 hxxp://216[.]239[.]104[.]59/skid[.]x86 hxxp://103[.]45[.]245[.]174/mips hxxp://216[.]239[.]104[.]59/skid[.]arm6 hxxp://41[.]216[.]189[.]183:8080/payload/nekmrfwc5o?token=0ClkpLLcj8n0JMA176t7u0Sv4FByP4vJ hxxp://41[.]216[.]189[.]183:8080/payload/oawy5x7ofd?token=0ClkpLLcj8n0JMA176t7u0Sv4FByP4vJ hxxp://41[.]216[.]189[.]183:8080/payload/aiqar0oflu?token=0ClkpLLcj8n0JMA176t7u0Sv4FByP4vJ hxxp://178[.]215[.]236[.]28/linux_arm5 hxxp://178[.]215[.]236[.]28/linux_arm7 hxxp://158[.]94[.]208[.]2/libraries/s7n[.]armv5l hxxp://158[.]94[.]208[.]2/libraries/s7n[.]armv4l hxxp://158[.]94[.]208[.]2/libraries/s7n[.]sh4 hxxp://158[.]94[.]208[.]2/libraries/s7n[.]mipsel hxxp://158[.]94[.]208[.]2/libraries/s7n[.]mips hxxp://158[.]94[.]208[.]2/libraries/s7n[.]armv6l |
Bashlite |
| URL | hxxps://currentsystems[.]com/api hxxp://130[.]12[.]180[.]43/files/8428202012/2ES6RO8[.]exe hxxps://dinglev[.]cyou/api hxxps://coverxyzer[.]su/vvvfdv hxxps://enjoyag[.]cyou/api hxxps://tragedj[.]cyou/api hxxps://braxttp[.]cyou/api hxxps://exchank[.]cyou/api hxxps://canonjo[.]asia/api hxxps://vetchir[.]cyou/api hxxp://9958850[.]com/api hxxps://hanggxx[.]cyou/api hxxps://mecholuq[.]cyou/api hxxps://cyberplg[.]cyou/api hxxps://makeravh[.]cyou/api |
Lumma Stealer |
| URL | hxxp://45[.]137[.]99[.]184/bins/build[.]32 hxxp://45[.]137[.]99[.]184/bins/build[.]arm64 hxxp://45[.]137[.]99[.]184/bins/build[.]arm hxxp://45[.]137[.]99[.]184/bins/build[.]64 hxxp://77[.]90[.]185[.]76/xsr hxxp://130[.]12[.]180[.]43/files/1110512891/f0IJaJf[.]exe hxxp://176[.]65[.]148[.]108/xmrig hxxp://130[.]12[.]180[.]43/files/7302144605/SYuwNKs[.]exe hxxp://xghost[.]xyz/nuts/poop hxxp://15[.]204[.]132[.]49/nuts/poop hxxp://46[.]8[.]78[.]175/systemd |
Coinminer |
| URL | hxxp://130[.]12[.]180[.]43/files/8428202012/eWQB8iX[.]exe | SmokeLoader |
| URL | hxxp://130[.]12[.]180[.]43/files/1731904112/TXpyp1Y[.]exe hxxp://130[.]12[.]180[.]43/files/1731904112/h5ZT3Io[.]exe hxxp://130[.]12[.]180[.]43/files/6608710704/z6HdLiH[.]exe |
Vidar |
| URL | hxxp://62[.]60[.]226[.]159/LB3[.]exe | BlackMatter |
| URL | hxxp://130[.]12[.]180[.]43/files/7538357236/XxpGuvc[.]exe hxxp://130[.]12[.]180[.]43/files/7538357236/nvWRiFP[.]exe |
NjRAT |
| URL | hxxp://130[.]12[.]180[.]43/files/6919303532/s95MQBL[.]exe | MaskGramStealer |
| URL | hxxp://tatoo-france[.]info/vouk53tt hxxp://quantum-conect[.]digital/243uwuyki hxxp://buttergoods[.]info/rhn610pdg |
TrickMo |
| URL | hxxp://dnlgu[.]ru/8492015736[.]php | Azorult |







