不正URLへのアクセス、不正メールの受信
-
メール受信した
弊社お客様0社 URLアクセスした
弊社お客様0社 -
2026/02/16
※2026/02/16 更新
マルウェア感染させると考えられるURLを検知(2026/02/16)
■IoC(※1)
| Type: | IOC: | Signature: |
|---|---|---|
| URL | hxxp://150[.]241[.]83[.]74/8574ba9c14cf4c8b[.]php hxxp://77[.]221[.]154[.]40/7e1669c87b2a4f93[.]php hxxps://159[.]69[.]114[.]128/b5caa8f188054fc8[.]php hxxps://185[.]196[.]10[.]147/f6c05fe452e5af24[.]php hxxps://45[.]88[.]76[.]205/30f6901d21ae0dd7[.]php hxxp://66[.]63[.]187[.]223/d7d759eb06ee4a63[.]php hxxp://93[.]152[.]230[.]54/47fec8f722884ace[.]php hxxp://196[.]251[.]107[.]130/buildx_x64[.]exe hxxp://176[.]65[.]144[.]88/3dc541941cdc4a25[.]php |
Stealc |
| URL | hxxps://voyage[.]klon2par6si[.]ru/cloudflare hxxps://donner[.]plar9ten2zo[.]ru/cloudflare hxxps://espoir[.]plar9ten2zo[.]ru/cloudflare hxxps://nebula[.]blen7kor2za[.]ru/cloudflare hxxps://zukunft[.]blen7kor2za[.]ru/cloudflare hxxps://stille[.]fron4tek7ly[.]ru/cloudflare hxxps://mirage[.]glor5ven2ta[.]ru/cloudflare hxxps://infinity[.]glor5ven2ta[.]ru/cloudflare hxxps://bravery[.]fron4tek7ly[.]ru/cloudflare hxxps://horizon[.]plon6var1ty[.]ru/cloudflare hxxps://koenig[.]tron6val4ky[.]ru/cloudflare hxxps://wunder[.]griv8ton5za[.]ru/cloudflare hxxps://finesse[.]plon6var1ty[.]ru/cloudflare hxxps://x7p9a[.]brisk4tango[.]coupons/msdn hxxps://legend[.]griv8ton5za[.]ru/cloudflare hxxps://harbor[.]plint7marco[.]coupons/msdn hxxps://k4m8q[.]plint7marco[.]coupons/msdn hxxps://n0va-rn[.]brisk4tango[.]coupons/msdn hxxps://echo3[.]brisk4tango[.]coupons/msdn hxxps://m3q7v[.]clint9vargo[.]coupons/msdn hxxps://rnove5[.]drift2cargo[.]coupons/msdn hxxps://67ocfzzz[.]hangesulka[.]digital/?=check&&actmn=IHnzCWdLetMZQtri hxxps://vector[.]drift2cargo[.]coupons/msdn hxxps://z9t2d[.]drift2cargo[.]coupons/msdn hxxps://c1ear-v[.]clint9vargo[.]coupons/msdn hxxps://signal[.]clint9vargo[.]coupons/msdn hxxps://breeze[.]whirl189wind[.]coupons/msdn hxxps://a6t9q[.]whirl189wind[.]coupons/msdn hxxps://st0ne-rn[.]mile163stone[.]coupons/msdn hxxps://marker[.]mile163stone[.]coupons/msdn hxxps://p8x4n[.]mile163stone[.]coupons/msdn hxxps://c9n4p[.]connect8mathem[.]coupons/msdn hxxps://pr0ph3t[.]fortune23tv[.]coupons/msdn hxxps://oracle[.]fortune23tv[.]coupons/msdn hxxps://r5m2x[.]fortune23tv[.]coupons/msdn hxxps://w1nd-ll[.]whirl189wind[.]coupons/msdn hxxps://calc-rn1[.]connect8mathem[.]coupons/msdn hxxps://formula[.]connect8mathem[.]coupons/msdn hxxps://stonework[.]ja8u2rudila[.]ru/msdn hxxps://douceurpure[.]dy5trops7uffy[.]ru/msdn hxxps://softcloud[.]dy5trops7uffy[.]ru/msdn hxxps://nx402bji[.]digimatrix[.]digital/?=check&&actmn=HfDHKxaPiVgihVTA hxxps://topking[.]be5t2lancrown[.]ru/msdn hxxps://argentvif[.]8etmon1sto[.]ru/msdn hxxps://goldcoin[.]8etmon1sto[.]ru/msdn hxxps://altstadt[.]ja8u2rudila[.]ru/msdn hxxps://mainrepair[.]du5tmanrepai7[.]ru/msdn hxxps://quickfix[.]du5tmanrepai7[.]ru/msdn hxxps://edlerkranz[.]be5t2lancrown[.]ru/msdn hxxps://globalwork[.]f2ctoryp1anet[.]ru/msdn hxxps://geheimcode[.]cav1ng5cript[.]ru/msdn hxxps://deepdark[.]cav1ng5cript[.]ru/msdn hxxps://toutsavoir[.]f2bricat9sar[.]ru/msdn hxxps://ironsteel[.]f2bricat9sar[.]ru/msdn hxxps://edlerkranz[.]be5t2lancrown[.]ru/check hxxps://topking[.]be5t2lancrown[.]ru/check hxxps://grandmonde[.]f2ctoryp1anet[.]ru/msdn hxxps://extra-bonus[.]pommerouge[.]coupons/check hxxps://geheimcode[.]cav1ng5cript[.]ru/check hxxps://deepdark[.]cav1ng5cript[.]ru/check hxxps://toutsavoir[.]f2bricat9sar[.]ru/check hxxps://ironsteel[.]f2bricat9sar[.]ru/check hxxps://mainrepair[.]du5tmanrepai7[.]ru/check hxxps://quickfix[.]du5tmanrepai7[.]ru/check hxxps://top-angebot[.]blaukraft[.]coupons/check hxxps://super-prix[.]pommerouge[.]coupons/check hxxps://vent-frais[.]ventdoux[.]coupons/check hxxps://blitz-deal[.]blaukraft[.]coupons/check hxxps://promo-libre[.]ventdoux[.]coupons/check hxxps://stern-fahrt[.]stolzmond[.]coupons/check hxxps://mond-schein[.]stolzmond[.]coupons/check hxxps://grand-reve[.]revesage[.]coupons/check hxxps://kalt-start[.]winterzug[.]coupons/check hxxps://eis-bahn[.]winterzug[.]coupons/check hxxps://eco-nature[.]clairforet[.]coupons/check hxxps://bois-vert[.]clairforet[.]coupons/check hxxps://nuit-douce[.]revesage[.]coupons/check hxxps://coffre-fort[.]noitresor[.]coupons/check hxxps://mon-tresor[.]noitresor[.]coupons/check hxxps://wald-lauf[.]herbstlauf[.]coupons/check hxxps://gold-zeit[.]herbstlauf[.]coupons/check hxxps://q7m9v[.]crint3valko[.]coupons/string hxxps://b1int-rnix[.]blint8darvo[.]coupons/string hxxps://harvest[.]blint8darvo[.]coupons/string hxxps://x8p3a[.]blint8darvo[.]coupons/string hxxps://cascade[.]flint1zarco[.]coupons/string hxxps://t4k2n[.]flint1zarco[.]coupons/string hxxps://cr1nt-vvay[.]crint3valko[.]coupons/string hxxps://pr1sk-rnate[.]prisk7tarvo[.]coupons/string hxxps://outpost[.]prisk7tarvo[.]coupons/string hxxps://m6r8p[.]prisk7tarvo[.]coupons/string hxxps://f1int-0rb[.]flint1zarco[.]coupons/string hxxps://bju1b4zl[.]websphere[.]digital/?=check&&actmn=GWqsHfuFmSnepveo hxxps://nab0k0v-llnk[.]nabokov30slam[.]coupons/string hxxps://verbatim[.]nabokov30slam[.]coupons/string hxxps://z3n7a[.]nabokov30slam[.]coupons/string hxxps://c9t5q[.]kozhevnik6lan[.]coupons/string hxxps://k0zhev-rnix[.]kozhevnik6lan[.]coupons/string hxxps://glacier[.]kozhevnik6lan[.]coupons/string hxxps://h0m0-vvex[.]homo483geneous[.]coupons/string hxxps://artifact[.]homo483geneous[.]coupons/string hxxps://p8x1m[.]homo483geneous[.]coupons/string hxxps://r2k6d[.]plea36slavneck[.]coupons/string hxxps://lantern[.]plea36slavneck[.]coupons/string hxxps://p1ea-rnask[.]plea36slavneck[.]coupons/string hxxps://7wgxbccc[.]cyberlane[.]digital/?=check&&actmn=PrQoKzpocOwEtfcG hxxps://secure-login-area[.]cielsombre[.]coupons/amdkmdag hxxps://v3[.]cielsombre[.]coupons/amdkmdag hxxps://app[.]terrepure[.]coupons/amdkmdag hxxps://de-partner-node[.]mondlicht[.]coupons/amdkmdag hxxps://cdn7[.]mondlicht[.]coupons/amdkmdag hxxps://quick-verify[.]terrepure[.]coupons/amdkmdag hxxps://static-assets-srv[.]stillesee[.]coupons/amdkmdag hxxps://go[.]stillesee[.]coupons/amdkmdag hxxps://direct-gateway-77[.]vifespoir[.]coupons/amdkmdag hxxps://tracking[.]vifespoir[.]coupons/amdkmdag hxxps://x7p9a[.]nebula4tango[.]coupons/x64 hxxps://internal-promo-link[.]federleicht[.]coupons/amdkmdag hxxps://b3-alpha[.]federleicht[.]coupons/amdkmdag hxxps://q4m8v[.]rocket7flora[.]coupons/x64 hxxps://nebula-vv1ng[.]nebula4tango[.]coupons/x64 hxxps://harvest[.]nebula4tango[.]coupons/x64 hxxps://lantern[.]rocket7flora[.]coupons/x64 hxxps://cascade[.]amber2vivid[.]coupons/x64 hxxps://t6k2n[.]amber2vivid[.]coupons/x64 hxxps://r0cket-rnix[.]rocket7flora[.]coupons/x64 hxxps://jung1e-rnate[.]jungle9orbit[.]coupons/x64 hxxps://outpost[.]jungle9orbit[.]coupons/x64 hxxps://m9r3p[.]jungle9orbit[.]coupons/x64 hxxps://arnb3r-0rb[.]amber2vivid[.]coupons/x64 hxxps://signal[.]matrix8piano[.]coupons/x64 hxxps://z3n7a[.]matrix8piano[.]coupons/x64 hxxps://c9t5q[.]breeze1falcon[.]coupons/x64 hxxps://k15kqv93[.]fluxdrive[.]digital/?=check&&actmn=lrTHndEmrsnOSzKh hxxps://rnatr1x-vvay[.]matrix8piano[.]coupons/x64 hxxps://qa7sawuw[.]wildframe41[.]digital/?=check&&actmn=sQCUUaHHKnfndNqC hxxps://shad0vv-rnix[.]shadow6nectar[.]coupons/x64 hxxps://oracle[.]shadow6nectar[.]coupons/x64 hxxps://p8x1m[.]shadow6nectar[.]coupons/x64 hxxps://br33ze-llnk[.]breeze1falcon[.]coupons/x64 hxxps://glacier[.]breeze1falcon[.]coupons/x64 hxxps://fus10n-vvex[.]fusion2harbor[.]coupons/x64 hxxps://formula[.]fusion2harbor[.]coupons/x64 hxxps://r2k6d[.]fusion2harbor[.]coupons/x64 hxxps://cdn[.]mintvoucher[.]coupons/webclient hxxps://auth88[.]snapbargain[.]coupons/webclient hxxps://static-data-srv[.]snapbargain[.]coupons/webclient hxxps://fast-track-delivery[.]dealharbor[.]coupons/webclient hxxps://api[.]dealharbor[.]coupons/webclient hxxps://user-node4[.]mintvoucher[.]coupons/webclient hxxps://secure-gateway-app[.]mintvoucher[.]coupons/webclient hxxps://edge-cache2[.]perkparcel[.]coupons/webclient hxxps://internal-promo-zone[.]perkparcel[.]coupons/webclient hxxps://go[.]perkparcel[.]coupons/webclient hxxps://srv-90[.]dealharbor[.]coupons/webclient hxxps://beta-node[.]deal4harbor[.]coupons/webclient hxxps://remote-access-v1[.]deal4harbor[.]coupons/webclient hxxps://ws[.]deal4harbor[.]coupons/webclient hxxps://cloud-st1[.]perk9parcel[.]coupons/webclient hxxps://direct-web-client[.]perk9parcel[.]coupons/webclient hxxps://app[.]perk9parcel[.]coupons/webclient hxxps://m-link[.]bonus3basket[.]coupons/webclient hxxps://global-site-check[.]bonus3basket[.]coupons/webclient hxxps://e3ys4ixz[.]mint2layer[.]digital/?=check&&actmn=pZDYRwwOFaRsvnEM hxxps://ns1[.]bonus3basket[.]coupons/webclient hxxps://cdn-303-web[.]flash5saver[.]coupons/webclient hxxps://update-system-srv[.]flash5saver[.]coupons/webclient hxxps://dev[.]flash5saver[.]coupons/webclient hxxps://s3[.]amber9stash[.]coupons/webclient hxxps://data-flow-central[.]amber9stash[.]coupons/webclient hxxps://node-v99[.]amber9stash[.]coupons/webclient |
ClearFake |
| URL | hxxps://lenx[.]tukitravel[.]com/LunX[.]zip hxxps://gupixlot[.]lol/downloads hxxps://xenos[.]love/%D0%92%D0%BE%D0%BEtsta%D1%80%D1%80%D0%B5%D0%B3%D1%83%D0%BEs[.]zip hxxps://cyx[.]tukitravel[.]com/Cyrex[.]zip hxxps://hideplo[.]com/Velost%D0%B0%D1%80%D1%80%D0%B5%D0%B3%20v1[.]0[.]1[.]zip hxxps://reb[.]greenenergygroup[.]org/LunX[.]zip hxxps://gre[.]greenenergygroup[.]org/LunX[.]zip hxxps://cxr[.]tukitravel[.]com/Cyrex[.]zip hxxps://orion[.]onl/%D0%92%D0%BE%D0%BEtsta%D1%80%D1%80%D0%B5%D0%B3%D1%83%D0%BEs[.]zip hxxps://gohpit[.]lol/downloads hxxps://drp[.]greenenergygroup[.]org/LunX[.]zip hxxps://cyr[.]crossfitmissionbay[.]com/Cyrex[.]zip hxxps://orion[.]onl/%D0%92%D0%BE%D0%BEtsta%D1%80%D1%80%D0%B5%D0%B3%D1%83%D0%BEss[.]zip hxxps://hop[.]greenenergygroup[.]org/LunX[.]zip hxxps://rfk[.]crossfitmissionbay[.]com/Cyrex[.]zip hxxps://krp[.]greenenergygroup[.]org/LunX[.]zip hxxps://bolixtiol[.]lol/downloads hxxps://orion[.]onl/%D0%92%D0%BE%D0%BEtst%D0%B0%D1%80%D1%80e%D0%B3ui[.]zip hxxps://tak[.]crossfitmissionbay[.]com/Cyrex[.]zip hxxps://qwt[.]greenenergygroup[.]org/LunX[.]zip hxxps://hideplo[.]com/Velost%D0%B0%D1%80%D1%80%D0%B5%D0%B3%20v1[.]0[.]2[.]zip hxxps://devc[.]ws/%D0%92%D0%BE%D0%BEtstapp%D0%B5%D0%B3%D1%8564[.]zip hxxps://gypisiondev[.]lol/downloads |
Vidar |
| URL | hxxp://bins[.]herios[.]st/herios[.]mips hxxps://216[.]10[.]244[.]155/yakuza[.]x86 hxxps://216[.]10[.]244[.]155/yakuza[.]arm4 hxxps://216[.]10[.]244[.]155/yakuza[.]mips hxxps://216[.]10[.]244[.]155/yakuza[.]ppc hxxps://216[.]10[.]244[.]155/yakuza[.]m68k hxxps://216[.]10[.]244[.]155/yakuza[.]mpsl hxxps://216[.]10[.]244[.]155/yakuza[.]x32 hxxps://216[.]10[.]244[.]155/yakuza[.]sh4 hxxps://216[.]10[.]244[.]155/yakuza[.]i586 hxxps://216[.]10[.]244[.]155/bins[.]sh hxxps://216[.]10[.]244[.]155/yakuza[.]arm6 |
Bashlite |
| URL | hxxp://130[.]12[.]180[.]43/files/6318146369/45l8jJQ[.]exe | SantaStealer |
| URL | hxxp://192[.]3[.]47[.]183/178/ce/cs[.]doC hxxp://96[.]44[.]154[.]205/35/cw/cee[.]doC hxxp://192[.]210[.]186[.]236/09/cc/00000[.]doc |
Remcos |
| URL | hxxps://pastebin[.]com/raw/s9dq5qMX hxxp://130[.]12[.]180[.]43/files/7044575709/54WMpxF[.]exe hxxp://130[.]12[.]180[.]43/files/7992210799/YiWxtWG[.]exe |
XWorm |
| URL | hxxp://www[.]ttghk[.]com/malyka/panel/shit[.]exe | Pony |
| URL | hxxp://aofkamu[.]com/wp-admin/css/css/tasks[.]php | Neutrino |
| URL | hxxp://freeschoolbox[.]info/tailor/fre[.]php hxxps://91[.]92[.]243[.]254/password/five/PvqDq929BSx_A_D_M1n_a[.]php |
LokiBot |
| URL | hxxp://www[.]tradeswindservices[.]com/ds28/ hxxp://www[.]tusarun[.]net/ds28/ hxxp://www[.]v47hmab703[.]forum/ds28/ hxxp://www[.]vendoremporiumrc[.]com/ds28/ hxxp://www[.]vrindavan[.]online/ds28/ hxxp://www[.]wecht2025[.]com/ds28/ hxxp://www[.]xn--o39a4rfls25drvhv3h[.]com/ds28/ hxxp://www[.]zf12521[.]info/ds28/ hxxp://www[.]s11c3j[.]vip/ds28/ hxxp://www[.]shegotthehookup[.]com/ds28/ hxxp://www[.]shu9[.]top/ds28/ hxxp://www[.]shuelab[.]kr/ds28/ hxxp://www[.]shzlpjum[.]top/ds28/ hxxp://www[.]skyvibes[.]info/ds28/ hxxp://www[.]smartguardinnovations[.]site/ds28/ hxxp://www[.]streetwisecinema[.]com/ds28/ hxxp://www[.]supuda[.]com/ds28/ hxxp://www[.]theassamvibe[.]com/ds28/ hxxp://www[.]mylittlechart[.]com/ds28/ hxxp://www[.]ocalrank[.]com/ds28/ hxxp://www[.]p6uy[.]top/ds28/ hxxp://www[.]parientchain[.]com/ds28/ hxxp://www[.]pawmfy[.]store/ds28/ hxxp://www[.]petbelles[.]com/ds28/ hxxp://www[.]portuguese[.]guru/ds28/ hxxp://www[.]prithvihairexports[.]com/ds28/ hxxp://www[.]reyaan[.]tech/ds28/ hxxp://www[.]isvqnfgq[.]click/ds28/ hxxp://www[.]iyi73[.]cfd/ds28/ hxxp://www[.]jhpifr[.]info/ds28/ hxxp://www[.]lawyerconnectindia[.]com/ds28/ hxxp://www[.]loquieroya[.]website/ds28/ hxxp://www[.]m3fgct[.]top/ds28/ hxxp://www[.]m41mg[.]top/ds28/ hxxp://www[.]malayshophk[.]site/ds28/ hxxp://www[.]mrplindia[.]com/ds28/ hxxp://www[.]mugguru[.]com/ds28/ hxxp://www[.]fermonhomerepairs[.]com/ds28/ hxxp://www[.]filesxyz[.]online/ds28/ hxxp://www[.]freshero[.]my/ds28/ hxxp://www[.]g7fdnl[.]bond/ds28/ hxxp://www[.]gmotionvfx[.]com/ds28/ hxxp://www[.]gurmesra[.]com/ds28/ hxxp://www[.]i36eg963gd[.]forum/ds28/ hxxp://www[.]ikkvzr[.]com/ds28/ hxxp://www[.]infomere[.]ru/ds28/ hxxp://www[.]boukharicharicapllc[.]com/ds28/ hxxp://www[.]caupons[.]com/ds28/ hxxp://www[.]couar[.]xyz/ds28/ hxxp://www[.]cuy9qk[.]sbs/ds28/ hxxp://www[.]dbst1o[.]bond/ds28/ hxxp://www[.]ellejeantaylorglow[.]com/ds28/ hxxp://www[.]estaon[.]store/ds28/ hxxp://www[.]fashioningcommunuty[.]com/ds28/ hxxp://www[.]fashionistareign[.]shop/ds28/ hxxp://www[.]feo7om[.]bond/ds28/ hxxp://www[.]1f9863be829c59ca[.]com/ds28/ hxxp://www[.]7mfmgsh[.]sbs/ds28/ hxxp://www[.]aa8668[.]xyz/ds28/ hxxp://www[.]allthetastings[.]com/ds28/ hxxp://www[.]ardinsys[.]com/ds28/ hxxp://www[.]ashenfrostblissful[.]shop/ds28/ hxxp://www[.]b17825924[.]com/ds28/ hxxp://www[.]bankweek[.]ru/ds28/ hxxp://www[.]bigsbetcasino-ubv[.]ru/ds28/ hxxp://www[.]xcggg[.]top/gn29/ hxxp://www[.]xfqxaa[.]com/gn29/ hxxp://www[.]yuristkon[.]ru/gn29/ hxxp://www[.]ziga555slot[.]com/gn29/ hxxp://www[.]serverkamboja[.]online/gn29/ hxxp://www[.]slomelly[.]com/gn29/ hxxp://www[.]ss8a30gt[.]bond/gn29/ hxxp://www[.]theaiprondirectory[.]com/gn29/ hxxp://www[.]tisvxh[.]sbs/gn29/ hxxp://www[.]vaycasino1864[.]com/gn29/ hxxp://www[.]violinsforsale[.]store/gn29/ hxxp://www[.]visual-dna[.]ai/gn29/ hxxp://www[.]watcher[.]gifts/gn29/ hxxp://www[.]webweavers[.]kr/gn29/ hxxp://www[.]wsminshop8[.]com/gn29/ hxxp://www[.]nup5un[.]shop/gn29/ hxxp://www[.]odysseymarketingcrew[.]com/gn29/ hxxp://www[.]opbpxqjk[.]bond/gn29/ hxxp://www[.]pzqwz[.]icu/gn29/ hxxp://www[.]r4u6wi[.]shop/gn29/ hxxp://www[.]reumatologonorte[.]com/gn29/ hxxp://www[.]rockfest-game[.]com/gn29/ hxxp://www[.]selinavordest[.]asia/gn29/ hxxp://www[.]serenitycopperpeptides[.]com/gn29/ hxxp://www[.]jellyfishsaigon[.]cloud/gn29/ hxxp://www[.]kler8a[.]info/gn29/ hxxp://www[.]lezmansion[.]com/gn29/ hxxp://www[.]liftu[.]shop/gn29/ hxxp://www[.]livinglearninglaughing[.]com/gn29/ hxxp://www[.]mainhu[.]id[.]vn/gn29/ hxxp://www[.]movaprivate[.]com/gn29/ hxxp://www[.]mvcty[.]xyz/gn29/ hxxp://www[.]nika-casino-es[.]com/gn29/ hxxp://www[.]emrcustoms[.]com/gn29/ hxxp://www[.]evermarkmercantile[.]com/gn29/ hxxp://www[.]fareqr[.]com/gn29/ hxxp://www[.]feyzc8[.]vip/gn29/ hxxp://www[.]fw81e5z7r3b-ghe9[.]top/gn29/ hxxp://www[.]genomic[.]site/gn29/ hxxp://www[.]inaurainsurance[.]com/gn29/ hxxp://www[.]indigo-moose[.]com/gn29/ hxxp://www[.]ippyaaj[.]sbs/gn29/ hxxp://www[.]irisbankid[.]com/gn29/ hxxp://www[.]jackpotindex[.]top/gn29/ hxxp://www[.]cuzziecaresystems[.]com/gn29/ hxxp://www[.]cy2xr302[.]vip/gn29/ hxxp://www[.]davebmale[.]com/gn29/ hxxp://www[.]dosalpick[.]com/gn29/ hxxp://www[.]dr-karimaccountant[.]com/gn29/ hxxp://www[.]dreamyhub[.]com[.]br/gn29/ hxxp://www[.]drenithej[.]com/gn29/ hxxp://www[.]dyizzhj[.]info/gn29/ hxxp://www[.]ekdalsperspektiv[.]se/gn29/ hxxp://www[.]9wcxao[.]bond/gn29/ hxxp://www[.]agentedger[.]com/gn29/ hxxp://www[.]aiconsultancy[.]ch/gn29/ hxxp://www[.]appdasmagras[.]com[.]br/gn29/ hxxp://www[.]bannedbookstore[.]com/gn29/ hxxp://www[.]brainbloom[.]ai/gn29/ hxxp://www[.]buyozz[.]com/gn29/ hxxp://www[.]canadausatimeshare[.]us/gn29/ hxxp://www[.]cranered[.]com/gn29/ hxxp://www[.]crazyalaskandrivers[.]com/gn29/ hxxp://www[.]1orei[.]cyou/gn29/ hxxp://www[.]53974[.]com/gn29/ |
Formbook |
| URL | hxxp://193[.]143[.]1[.]16/g8hrS4f4vh/Login[.]php | Amadey |
| URL | hxxps://api[.]telegram[.]org/bot7528951370:AAFhLhVBzQF3v1A-7Wjkf8XOAicyYI6p2nM/sendMessage?chat_id=6623091671 | MASS Logger |
| URL | hxxps://api[.]telegram[.]org/bot7724523460:AAHngsin_-PJwm0YyvNGNJmdFr6kneFLhBU/sendMessage?chat_id=7571756559 hxxps://api[.]telegram[.]org/bot8201863571:AAE4X8C0xHcO77QA3Z77oznq79cUzRWlhMA/sendMessage?chat_id=7917918427 |
Stealerium |
| URL | hxxps://downloads[.]beaconvistamedical[.]com/windows-test[.]exe hxxps://downloads[.]beaconvistamedical[.]com/windows-test-beacon[.]exe |
Sliver |
| URL | hxxps://downloads[.]beaconvistamedical[.]com/notepad[.]exe | Metasploit |
| URL | hxxp://124[.]44[.]3[.]74:88/beacon[.]exe hxxp://51[.]77[.]77[.]161:443/sitemap[.]xml hxxp://13[.]232[.]97[.]61/02[.]08[.]2022[.]exe hxxp://118[.]89[.]73[.]78/02[.]08[.]2022[.]exe hxxp://47[.]239[.]230[.]84:20000/02[.]08[.]2022[.]exe hxxp://120[.]76[.]143[.]184:443/02[.]08[.]2022[.]exe hxxp://142[.]171[.]223[.]34:19873/02[.]08[.]2022[.]exe hxxp://156[.]238[.]242[.]231/02[.]08[.]2022[.]exe hxxp://128[.]241[.]229[.]70:6001/02[.]08[.]2022[.]exe hxxp://8[.]141[.]93[.]66:8081/02[.]08[.]2022[.]exe hxxp://70[.]169[.]51[.]111/02[.]08[.]2022[.]exe hxxp://47[.]109[.]45[.]70:12345/02[.]08[.]2022[.]exe hxxp://120[.]26[.]18[.]220/02[.]08[.]2022[.]exe hxxp://45[.]192[.]110[.]197:8088/02[.]08[.]2022[.]exe hxxp://118[.]107[.]0[.]254:2002/02[.]08[.]2022[.]exe hxxp://213[.]64[.]72[.]46/02[.]08[.]2022[.]exe hxxp://186[.]123[.]85[.]29/02[.]08[.]2022[.]exe hxxp://8[.]148[.]251[.]204:801/02[.]08[.]2022[.]exe hxxp://8[.]148[.]251[.]204:2095/02[.]08[.]2022[.]exe hxxp://18[.]142[.]177[.]189/02[.]08[.]2022[.]exe hxxp://117[.]72[.]191[.]140:8028/02[.]08[.]2022[.]exe hxxp://101[.]132[.]167[.]9/02[.]08[.]2022[.]exe hxxp://18[.]142[.]177[.]189:8443/02[.]08[.]2022[.]exe hxxp://119[.]91[.]54[.]176:50001/02[.]08[.]2022[.]exe |
Cobalt Strike |
| URL | hxxp://130[.]12[.]180[.]43/files/7461970488/l6Ujlzq[.]exe hxxp://130[.]12[.]180[.]43/files/8408827406/fjbtTXM[.]exe hxxp://130[.]12[.]180[.]43/files/7461970488/njzn0tA[.]exe hxxps://api[.]telegram[.]org/bot8507720456:AAEpnoVGcyydXM2D0JemO6am4qPyH0fi2x0/sendMessage hxxps://api[.]telegram[.]org/bot8232514058:AAECWvT9fIzCZ81IKw8kYZnobvGJujJBlG0/sendMessage hxxp://130[.]12[.]180[.]43/files/8546428528/IyVls5r[.]exe |
AsyncRAT |
| URL | hxxp://130[.]12[.]180[.]43/files/748049926/JoykGgp[.]exe hxxp://130[.]12[.]180[.]43/files/748049926/qMKWsxs[.]exe |
SystemBC |
| URL | hxxps://audioza[.]cyou/api hxxps://portuge[.]cyou/api hxxps://drawnbe[.]cyou/api hxxps://ziziphe[.]cyou/api hxxps://benefitsonlineportal[.]com/api hxxps://editorr[.]cyou/api hxxps://backsan[.]cyou/api |
Lumma Stealer |
| URL | hxxp://84[.]21[.]189[.]5:5506/qww[.]txt hxxps://widexenmexico[.]com[.]mx/plugins/Cloudflare/challenge/IsHuman/ID53728/ |
HijackLoader |
| URL | hxxp://130[.]12[.]180[.]43/files/5023688490/auz7wwz[.]exe hxxp://130[.]12[.]180[.]43/files/5347973496/lNNDJUc[.]exe |
NjRAT |
| URL | hxxp://130[.]12[.]180[.]43/files/8408827406/6jrtKpb[.]exe hxxp://192[.]3[.]118[.]16/nuts/poop hxxp://130[.]12[.]180[.]43/files/6723359323/ZNY48if[.]exe |
Coinminer |
| URL | hxxp://quicrob[.]com/7z[.]dll hxxp://quicrob[.]com/lnk[.]7z hxxp://quicrob[.]com/at[.]7z hxxp://quicrob[.]com/7z[.]exe |
NetSupportManager RAT |
| URL | hxxp://130[.]12[.]180[.]43/files/8294657075/w4PZ9hn[.]exe | SalatStealer |







