不正URLへのアクセス、不正メールの受信
-
メール受信した
弊社お客様0社 URLアクセスした
弊社お客様0社 -
2026/02/17
※2026/02/17 更新
マルウェア感染させると考えられるURLを検知(2026/02/17)
■IoC(※1)
| Type: | IOC: | Signature: |
|---|---|---|
| URL | hxxps://secure-access-point[.]nifty4locker[.]coupons/webclient hxxps://ws[.]nifty4locker[.]coupons/webclient hxxps://api[.]orbit6crate[.]coupons/webclient hxxps://cdn-b12[.]nifty4locker[.]coupons/webclient hxxps://gate-07[.]orbit6crate[.]coupons/webclient hxxps://global-sync-srv[.]orbit6crate[.]coupons/webclient hxxps://internal-web-proxy[.]plum5parcel[.]coupons/webclient hxxps://dl[.]plum5parcel[.]coupons/webclient hxxps://cloud-m3[.]plum5parcel[.]coupons/webclient hxxps://q4m8v[.]believein41fant[.]coupons/webclient hxxps://m0d-rnflux[.]blu45modern[.]coupons/webclient hxxps://atelier[.]blu45modern[.]coupons/webclient hxxps://x7p9a[.]blu45modern[.]coupons/webclient hxxps://workshop[.]khlopotun6turn[.]coupons/webclient hxxps://t6k2n[.]khlopotun6turn[.]coupons/webclient hxxps://be1ieve-vvave[.]believein41fant[.]coupons/webclient hxxps://horizon[.]believein41fant[.]coupons/webclient hxxps://m9r3p[.]pitman123wid[.]coupons/webclient hxxps://3aofxgg5[.]orbit44kind[.]digital/?=check&&actmn=CeCWFzKXkbzLvPTd hxxps://kh10p0-rnate[.]khlopotun6turn[.]coupons/webclient hxxps://dispatch[.]reporter9speck[.]coupons/webclient hxxps://z3n7a[.]reporter9speck[.]coupons/webclient hxxps://p1trnan-vvex[.]pitman123wid[.]coupons/webclient hxxps://ledger[.]pitman123wid[.]coupons/webclient hxxps://contour[.]paw85silhouette[.]coupons/webclient hxxps://c9t5q[.]paw85silhouette[.]coupons/webclient hxxps://rep0rt-rnix[.]reporter9speck[.]coupons/webclient hxxps://monolith[.]stone48tyranny[.]coupons/webclient hxxps://p8x1m[.]stone48tyranny[.]coupons/webclient hxxps://si1h0uette-llnk[.]paw85silhouette[.]coupons/webclient hxxps://v1[.]bleuforet[.]coupons/sync hxxps://hyp0-vvrite[.]capitul98hypo[.]coupons/webclient hxxps://treatise[.]capitul98hypo[.]coupons/webclient hxxps://a5v9n[.]capitul98hypo[.]coupons/webclient hxxps://f0ur-rnark[.]four486stop[.]coupons/webclient hxxps://waypoint[.]four486stop[.]coupons/webclient hxxps://r2k6d[.]four486stop[.]coupons/webclient hxxps://st0ne-vvyrd[.]stone48tyranny[.]coupons/webclient hxxps://uri2df93[.]blue128cinder[.]digital/?=check&&actmn=iOMWxfPWFjgToGHe hxxps://auth-global-zone[.]schnellauf[.]coupons/sync hxxps://dl[.]schnellauf[.]coupons/sync hxxps://gate-v7[.]nuitetoile[.]coupons/sync hxxps://external-web-node[.]nuitetoile[.]coupons/sync hxxps://api[.]nuitetoile[.]coupons/sync hxxps://node44[.]starkwind[.]coupons/sync hxxps://data-transfer-srv[.]starkwind[.]coupons/sync hxxps://ws[.]starkwind[.]coupons/sync hxxps://cdn-b9[.]bleuforet[.]coupons/sync hxxps://secure-cloud-link[.]bleuforet[.]coupons/sync hxxps://bnt11[.]mainsage[.]coupons/09fa47a71346a hxxps://customer-ref-91[.]goldberg[.]coupons/09fa47a71346a hxxps://xqz-p[.]goldberg[.]coupons/09fa47a71346a hxxps://u842[.]goldberg[.]coupons/09fa47a71346a hxxps://edge-99[.]vertjardin[.]coupons/sync hxxps://direct-access-point[.]vertjardin[.]coupons/sync hxxps://jyx7jwja[.]blue128cinder[.]digital/?=check&&actmn=CpJeGMHYfoTeGaXJ hxxps://app[.]vertjardin[.]coupons/sync hxxps://fast-path-x[.]clairsol[.]coupons/09fa47a71346a hxxps://v-n-v[.]zeitgeist[.]coupons/09fa47a71346a hxxps://unique-set-02[.]zeitgeist[.]coupons/09fa47a71346a hxxps://trck[.]zeitgeist[.]coupons/09fa47a71346a hxxps://k-7[.]mainsage[.]coupons/09fa47a71346a hxxps://session-id-a9[.]mainsage[.]coupons/09fa47a71346a hxxps://p-link[.]eisenherz[.]coupons/09fa47a71346a hxxps://z99[.]clairsol[.]coupons/09fa47a71346a hxxps://x8[.]browser-crash-report[.]coupons/09fa47a71346a hxxps://proc-9-auth[.]browser-crash-report[.]coupons/09fa47a71346a hxxps://unique-trace-id[.]stackdump-collector[.]coupons/09fa47a71346a hxxps://m-91[.]stackdump-collector[.]coupons/09fa47a71346a hxxps://z-node[.]telemetry-api-v1[.]coupons/09fa47a71346a hxxps://session-8201[.]telemetry-api-v1[.]coupons/09fa47a71346a hxxps://v-ref[.]telemetry-api-v1[.]coupons/09fa47a71346a hxxps://sync-v-8[.]extension-health-sync[.]coupons/09fa47a71346a hxxps://q-set[.]extension-health-sync[.]coupons/09fa47a71346a hxxps://p77[.]debug-edge-cases[.]coupons/09fa47a71346a hxxps://gateway-node-x[.]debug-edge-cases[.]coupons/09fa47a71346a hxxps://user29[.]debug-edge-cases[.]coupons/09fa47a71346a hxxps://b-3[.]stackdump-collector[.]coupons/09fa47a71346a hxxps://report-stream-55[.]dev-trace-analyzer[.]coupons/handler hxxps://t-9[.]dev-trace-analyzer[.]coupons/09fa47a71346a hxxps://w-4[.]syslog-remote-buffer[.]coupons/09fa47a71346a hxxps://buffer-temp-a[.]syslog-remote-buffer[.]coupons/09fa47a71346a hxxps://log33[.]syslog-remote-buffer[.]coupons/09fa47a71346a hxxps://r12[.]extension-health-sync[.]coupons/09fa47a71346a hxxps://brightstar[.]endpoint-metrics-internal[.]coupons/handler hxxps://silverleaf[.]endpoint-metrics-internal[.]coupons/handler hxxps://0bz6vz64[.]blue128cinder[.]digital/?=check&&actmn=vMUywRSJneoRukxU hxxps://blueocean[.]endpoint-metrics-internal[.]coupons/handler hxxps://freshbreeze[.]sandbox-proxy-diagnostic[.]coupons/handler hxxps://redstone[.]sandbox-proxy-diagnostic[.]coupons/handler hxxps://smartcloud[.]sandbox-proxy-diagnostic[.]coupons/handler hxxps://wildriver[.]runtime-error-handler[.]coupons/handler hxxps://goldenapple[.]runtime-error-handler[.]coupons/handler hxxps://greenforest[.]runtime-error-handler[.]coupons/handler hxxps://citylight[.]urbanharvest[.]coupons/chromesetup_x64 hxxps://openfield[.]swiftmotion[.]coupons/chromesetup_x64 hxxps://fastsky[.]swiftmotion[.]coupons/chromesetup_x64 hxxps://darkriver[.]swiftmotion[.]coupons/chromesetup_x64 hxxps://greenpark[.]urbanharvest[.]coupons/chromesetup_x64 |
ClearFake |
| URL | hxxp://130[.]12[.]180[.]151/data[.]powerpc hxxp://45[.]131[.]64[.]121/armv4l hxxp://172[.]86[.]114[.]147/pftp |
Bashlite |
| URL | hxxps://luq[.]technol[.]sbs/LunX[.]zip hxxps://cyx[.]technol[.]sbs/Cyrex[.]zip hxxps://devc[.]ws/%D0%92ootst%D0%B0%D1%80%D1%80%D0%B5%D0%B3%D1%83%D0%BEs%D1%8564[.]zip hxxps://cyx[.]technok[.]sbs/Cyrex[.]zip hxxps://lun[.]technok[.]sbs/LunX[.]zip hxxps://devc[.]ws/%D0%92%D0%BE%D0%BEtst%D0%B0%D1%80%D1%80%D0%B5%D0%B3yos%D1%8564[.]zip hxxps://humodin[.]lol/downloads |
Vidar |
| URL | hxxp://196[.]251[.]107[.]130/zx[.]exe | SVCStealer |
| URL | hxxp://196[.]251[.]107[.]130/nk[.]exe hxxps://45[.]11[.]92[.]124/982c183d8a9835c6[.]php |
Stealc |
| URL | hxxp://130[.]12[.]180[.]43/files/5926060486/gHcZQCz[.]exe hxxp://130[.]12[.]180[.]43/files/5926060486/fdkr9E3[.]exe hxxp://130[.]12[.]180[.]43/files/7103746036/aJqN6D8[.]exe hxxp://130[.]12[.]180[.]43/files/7665230745/PWhwmLT[.]exe hxxp://130[.]12[.]180[.]43/files/7103746036/qvfjiKH[.]exe hxxp://130[.]12[.]180[.]43/files/7103746036/5nFcTuB[.]exe hxxp://130[.]12[.]180[.]43/files/7103746036/K3qLlt0[.]exe hxxp://130[.]12[.]180[.]43/files/5926060486/JiBn9LM[.]exe hxxp://130[.]12[.]180[.]43/files/7103746036/ceFMAdH[.]exe hxxp://130[.]12[.]180[.]43/files/7103746036/ZI8wjWI[.]exe hxxp://130[.]12[.]180[.]43/files/5926060486/MKktCIh[.]exe |
SantaStealer |
| URL | hxxp://96[.]44[.]154[.]205/156/ecu/ece[.]doc hxxp://96[.]44[.]154[.]205/156/23dsf343464645dfg456546456232dsff43453453f[.]js hxxps://pastee[.]dev/d/w86oeGtn/0 hxxps://store-na-phx-4[.]gofile[.]io/download/direct/cbd8ed80-2067-4791-9d7e-8a3d4d41864f/Adobe_Acrobat_Reader[.]js |
Remcos |
| URL | hxxp://101[.]200[.]193[.]211:8086/02[.]08[.]2022[.]exe | Cobalt Strike |
| URL | hxxps://infinitaki[.]com/TikTok18[.]apk | TrickMo |
| URL | hxxp://192[.]109[.]200[.]5/webb/ENCRYPTED[.]ps1 | Agent Tesla |
| URL | hxxp://130[.]12[.]180[.]43/files/8546428528/EE7OeTn[.]exe | Quasar RAT |
| URL | hxxps://theipcommunity[.]com/optimized_MSI[.]png | XWorm |
| URL | hxxp://130[.]12[.]180[.]43/files/8227038158/PlgS3C9[.]exe | PureRAT |
| URL | hxxp://130[.]12[.]180[.]43/files/8349010648/HIYwJGW[.]exe hxxp://130[.]12[.]180[.]43/files/8366207456/jtauUdV[.]exe |
SalatStealer |
| URL | hxxps://eishin-kk-co[.]asia/dev/ENCRYPTEDP[.]ps1 hxxps://api[.]telegram[.]org/bot7246162905:AAH58N2KrbWrc8B6-sVjI0Dvfr_Afvqhk4I/sendMessage?chat_id=7941708421 |
Stealerium |
| URL | hxxps://cryaesa[.]cyou/api | Lumma Stealer |
| URL | hxxp://130[.]12[.]180[.]43/files/748049926/ka0OL2S[.]exe | SystemBC |
| URL | hxxp://62[.]60[.]226[.]159/qrjqtxdcxn[.]exe | Amadey |







