不正URLへのアクセス、不正メールの受信
-
メール受信した
弊社お客様0社 URLアクセスした
弊社お客様5社 -
2026/02/24
※2026/02/24 更新
マルウェア感染させると考えられるURLを検知(2026/02/24)
■IoC(※1)
| Type: | IOC: | Signature: |
|---|---|---|
| URL | hxxp://62[.]60[.]226[.]159/NuclearBomb[.]exe | RedLine Stealer |
| URL | hxxps://l[.]revio[.]live/LunX[.]zip hxxps://c[.]revio[.]live/Cyrex[.]zip hxxps://lunt[.]revio[.]live/LunX[.]zip hxxps://lunq[.]revio[.]live/LunX[.]zip hxxps://lunc[.]revio[.]live/LunX[.]zip hxxps://lunp[.]revio[.]live/LunX[.]zip hxxps://lun[.]onters[.]sbs/LunX[.]zip hxxps://lunme[.]onters[.]sbs/LunX[.]zip hxxps://lunhx[.]onters[.]sbs/LunX[.]zip |
PureCrypter |
| URL | hxxps://deusxeno[.]ws/%D0%92%D0%BE%D0%BEts%D9%8Bta%D1%80%D1%80%D0%B5%D0%B3%D1%83%D0%BEs[.]zip hxxps://qploits[.]online/D%D0%B5uscit%D1%83%20v1[.]zip hxxps://lunnat[.]technick[.]sbs/LunX[.]zip hxxps://lnet[.]technick[.]sbs/LunX[.]zip hxxps://cnet[.]technick[.]sbs/Cyrex[.]zip hxxps://cyrnat[.]technick[.]sbs/Cyrex[.]zip hxxps://qploits[.]online/%D0%9Did%D0%B5%D1%81it%D1%83%20v2[.]zip hxxps://getryos[.]com/%D0%92%D0%BE%D0%BEtsta%D1%80%D1%80%D0%B5rUI2[.]zip hxxp://130[.]12[.]180[.]43/files/5698774781/q6Hwfb6[.]exe hxxp://130[.]12[.]180[.]43/files/5698774781/vzZaZ32[.]exe hxxps://deusxeno[.]ws/Bootstap%D1%80%D0%B5r%D1%83%D0%BEsUI[.]zip hxxps://gudiop[.]lol/downloads hxxps://deusxeno[.]ws/Bootstap%D1%80%D0%B5%D0%B3%D1%83ossUl[.]zip hxxps://eploits[.]info/J%D0%BE%D1%83%D1%81it%D1%83%20v2[.]zip hxxp://130[.]12[.]180[.]43/files/gop/random[.]exe hxxp://130[.]12[.]180[.]43/files/5698774781/dzeFptZ[.]exe hxxps://deusxeno[.]ws/Bootsta%D1%80%D1%80erUl[.]zip hxxps://deusxeno[.]ws/Bootstappe%D0%B3UI[.]zip hxxps://glo[.]alpinematters[.]com/hxxps://155[.]117[.]232[.]231/ |
Vidar |
| URL | hxxps://ainttby[.]com/6f54[.]js hxxps://ainttby[.]com/js[.]php hxxps://ts4style[.]com/5fa3[.]js hxxps://ts4style[.]com/js[.]php |
KongTuke |
| URL | hxxp://abscete[.]info/zetus/five/fre[.]php hxxp://electrico[.]co[.]zw/wp-templates/five/five/fre[.]php hxxps://electrico[.]co[.]zw/wp-templates/five/five/PvqDq929BSx_A_D_M1n_a[.]php hxxp://electrico[.]co[.]zw/wp-templates/five/five/PvqDq929BSx_A_D_M1n_a[.]php |
LokiBot |
| URL | hxxps://jd4ftwmb[.]stoneweir[.]digital/?=check&&actmn=CfqzlBPFkRjzUZub hxxps://u281os5q[.]wintermere[.]digital/?=check&&actmn=mMAAuswnBirHqBba hxxps://zekjryh8[.]misthollow[.]digital/?=check&&actmn=peVrnhENZnlcJquF hxxps://0l833z7h[.]ironbark[.]digital/?=check&&actmn=zKEysasVYiENjuYe hxxps://stqol819[.]thornwick[.]digital/?=check&&actmn=PoVcDVKSaXACdEqZ hxxps://yzac4fqt[.]duskvale[.]digital/?=check&&actmn=MgQLMWlMGgUfHsgb hxxps://26s1p5ue[.]frostholm[.]digital/?=check&&actmn=igyevHRFOhxwmulg hxxps://1m82015w[.]embercore[.]digital/?=check&&actmn=xPSiwhFqseBEHlsC hxxps://qfm9nqbc[.]windford[.]digital/?=check&&actmn=tgJLvUpPlMgIjOLQ hxxps://m67fvuhb[.]darkpine[.]digital/?=check&&actmn=qJMOBKMGGWKwyDER hxxps://qa6l1lsk[.]moonpath[.]digital/?=check&&actmn=jQBpmJrReJgrDbUk hxxps://ojqxtq3l[.]ironrock[.]digital/?=check&&actmn=fzBbeQNmDlLbJgiw hxxps://odbsasjd[.]upgrade4file[.]digital/?=check&&actmn=aIjlDJUshdaUlwoM hxxps://0uwsxbye[.]forward3cross[.]digital/?=check&&actmn=FRzyCUUYRXAJjqPn hxxps://366kf0hf[.]up12file[.]digital/?=check&&actmn=SeKeSbevZsJAERVj hxxps://r8ada0zp[.]novacode[.]digital/?=check&&actmn=cvnwONogSTzZaomy hxxps://joieshk7[.]hexalink[.]digital/?=check&&actmn=vrrNPRVDNZBWMwJL hxxps://lg1kpu12[.]microzen[.]digital/?=check&&actmn=pJUtqigIrxBgGPdv hxxps://water-network-node[.]rapidbrook[.]ru/service/verification[.]google hxxps://vo230hqh[.]cybervox[.]digital/?=check&&actmn=odRcSBHAUChvXJVg hxxps://fast-flow-point[.]rapidbrook[.]ru/service/verification[.]google hxxps://hydrological-collector[.]rapidbrook[.]ru/service/verification[.]google hxxps://region-sync-base[.]brightvale[.]ru/service/verification[.]google hxxps://light-valley-hub[.]brightvale[.]ru/service/verification[.]google hxxps://solar-energy-control[.]brightvale[.]ru/service/verification[.]google hxxps://rapid-stream-data[.]rapidbrook[.]ru/service/verification[.]google hxxps://nature-logic-base[.]wildfern[.]ru/service/verification[.]google hxxps://forest-deep-sync-node[.]wildfern[.]ru/service/verification[.]google hxxps://botanical-research-archive[.]wildfern[.]ru/service/verification[.]google hxxps://quiet-air-monitor[.]quietwind[.]ru/service/verification[.]google hxxps://weather-station-data[.]quietwind[.]ru/service/verification[.]google hxxps://silent-flow-node[.]quietwind[.]ru/service/verification[.]google hxxps://atmospheric-sensor-unit[.]quietwind[.]ru/service/verification[.]google hxxps://bright-field-stat[.]brightvale[.]ru/service/verification[.]google hxxps://central-pine-node[.]smartpine[.]ru/service/verification[.]google hxxps://smart-timber-track[.]smartpine[.]ru/service/verification[.]google hxxps://wood-processing-unit[.]smartpine[.]ru/service/verification[.]google hxxps://wild-leaf-trace[.]wildfern[.]ru/service/verification[.]google hxxps://it-pine-management[.]smartpine[.]ru/service/verification[.]google hxxp://aidiyet[.]esb[.]org[.]tr/landpage?ms=hxxp://bloomshift[.]takeoverspring[.]in[.]net/service/verification[.]google hxxps://ship-dock-control[.]coolharbor[.]ru/service/check[.]google hxxps://cool-port-storage[.]coolharbor[.]ru/service/check[.]google hxxps://ocean-harbor-gate[.]coolharbor[.]ru/service/check[.]google hxxps://main-crest-auth[.]clearcrest[.]ru/service/check[.]google hxxps://high-altitude-sensor[.]clearcrest[.]ru/service/check[.]google hxxps://crest-logic-point[.]clearcrest[.]ru/service/check[.]google hxxps://t0ijoagy[.]crystalbit[.]digital/?=check&&actmn=WSvNePvrQpYFSZHK hxxps://central-monitoring-hub[.]clearcrest[.]ru/service/check[.]google hxxps://weather-warning-system[.]stormbay[.]ru/service/verification[.]google hxxps://storm-bay-watch[.]stormbay[.]ru/service/verification[.]google hxxps://main-cool-harbor-sys[.]coolharbor[.]ru/service/check[.]google hxxps://swog3mgt[.]openmatrix[.]digital/?=check&&actmn=QvVvjcqNDWiPekAZ hxxps://silver-zone-sync[.]silverfield[.]ru/service/verification[.]google hxxps://swift-flow-node[.]swiftcanyon[.]ru/service/verification[.]google hxxps://geo-rock-sync-base[.]swiftcanyon[.]ru/service/verification[.]google hxxps://depth-canyon-monitor[.]swiftcanyon[.]ru/service/verification[.]google hxxps://swift-canyon-pass[.]swiftcanyon[.]ru/service/verification[.]google hxxps://dune-logic-base[.]rapiddune[.]ru/service/verification[.]google hxxps://heat-sync-node[.]rapiddune[.]ru/service/verification[.]google hxxps://desert-storm-monitor[.]rapiddune[.]ru/service/verification[.]google hxxps://rapid-dune-sand[.]rapiddune[.]ru/service/verification[.]google hxxps://urban-data-point[.]urbanridge[.]ru/service/verification[.]google hxxps://city-ridge-sync[.]urbanridge[.]ru/service/verification[.]google hxxps://high-rise-monitor[.]urbanridge[.]ru/service/verification[.]google hxxps://urban-ridge-city[.]urbanridge[.]ru/service/verification[.]google hxxps://f2i32y9f[.]silvernode[.]digital/?=check&&actmn=mBntqeCswGETrRAO hxxps://bright-grove-park[.]brightgrove[.]ru/service/verification[.]google |
ClearFake |
| URL | hxxp://173[.]211[.]70[.]196:443/02[.]08[.]2022[.]exe hxxp://81[.]68[.]89[.]216:8088/02[.]08[.]2022[.]exe hxxps://aaronart[.]com/H64[.]exe hxxps://creativevoltage[.]com/M64[.]exe hxxp://115[.]190[.]53[.]184:666/02[.]08[.]2022[.]exe hxxp://1[.]94[.]40[.]59:65534/02[.]08[.]2022[.]exe hxxp://8[.]131[.]77[.]227:817/02[.]08[.]2022[.]exe |
Cobalt Strike |
| URL | hxxp://166[.]88[.]142[.]172/fuckjewishpeople[.]x86 hxxp://192[.]109[.]200[.]42/bins/beacon[.]x86_64_musl hxxp://192[.]109[.]200[.]42/bins/beacon[.]x86 hxxp://192[.]109[.]200[.]42/bins/beacon[.]arm7 hxxp://192[.]109[.]200[.]42/bins/beacon[.]arm64 hxxp://192[.]109[.]200[.]42/bins/beacon[.]x86_64 hxxp://156[.]246[.]95[.]51/bot[.]x86_64 hxxp://185[.]132[.]53[.]180/a-r[.]m-5[.]Sakura hxxp://185[.]132[.]53[.]180/m-i[.]p-s[.]Sakura hxxp://185[.]132[.]53[.]180/x-8[.]6-[.]Sakura hxxp://185[.]132[.]53[.]180/m-6[.]8-k[.]Sakura hxxp://185[.]132[.]53[.]180/a-r[.]m-7[.]Sakura hxxp://185[.]132[.]53[.]180/p-p[.]c-[.]Sakura hxxp://185[.]132[.]53[.]180/m-p[.]s-l[.]Sakura hxxp://185[.]132[.]53[.]180/a-r[.]m-4[.]Sakura hxxp://185[.]132[.]53[.]180/i-5[.]8-6[.]Sakura hxxp://185[.]132[.]53[.]180/s-h[.]4-[.]Sakura hxxp://185[.]132[.]53[.]180/x-3[.]2-[.]Sakura hxxp://185[.]132[.]53[.]180/a-r[.]m-6[.]Sakura hxxp://45[.]91[.]133[.]229/download/UpdaterServices3[.]exe hxxp://45[.]91[.]133[.]229/download/UpdaterServices4[.]exe hxxp://45[.]91[.]133[.]229/download/botseo[.]exe hxxp://45[.]91[.]133[.]229/download/UpdaterServices1[.]exe hxxp://45[.]91[.]133[.]229/download/upbot[.]exe hxxp://45[.]91[.]133[.]229/download/UpdaterServices2[.]exe hxxp://45[.]91[.]133[.]229/download/UpdaterServices[.]exe hxxp://45[.]66[.]228[.]200/linux_arm7 hxxp://144[.]31[.]207[.]40/linux_arm7 hxxp://45[.]66[.]228[.]200/linux_arm64 hxxp://104[.]6[.]82[.]222:8081/bot[.]sh4 hxxp://104[.]6[.]82[.]222:8081/bot[.]x86_64 hxxp://130[.]12[.]180[.]124/rq0anbhkd976/assets/js/pmapqb9hcs |
Bashlite |
| URL | hxxp://130[.]12[.]180[.]43/files/5926060486/XFG15R6[.]exe hxxp://130[.]12[.]180[.]43/files/7615186854/gZNlw1R[.]exe hxxp://130[.]12[.]180[.]43/files/5926060486/p4oPI3H[.]exe |
SantaStealer |
| URL | hxxps://tamedgeesy[.]sbs/api hxxps://relalingj[.]sbs/api hxxps://rottieud[.]sbs/api hxxps://brownieyuz[.]sbs/api hxxps://explainvees[.]sbs/api hxxps://ducksringjk[.]sbs/api hxxps://thinkyyokej[.]sbs/api hxxps://repostebhu[.]sbs/api hxxps://pragapin[.]sbs/api hxxp://basilicros[.]su/asdasq hxxp://broguenko[.]su/asfase hxxp://familyriwo[.]su/fssdaw hxxp://hammernew[.]su/asdase hxxp://heavylussy[.]su/ccvfd hxxp://homuncloud[.]su/ascasef hxxp://izzardtow[.]su/cascasc hxxp://whitepepper[.]su/asds hxxps://unaideg[.]cyou/api hxxps://withsuj[.]cyou/api |
Lumma Stealer |
| URL | hxxp://130[.]12[.]180[.]43/files/7776573655/1VwHhQ5[.]exe | GCleaner |
| URL | hxxp://172[.]245[.]95[.]24/XBZkmNgBpJqpjJ9[.]bin hxxp://172[.]245[.]95[.]24/rfieCkbAGkCDNgcyfdFYrD6[.]bin hxxp://84[.]38[.]129[.]77/RDkmaVQECQNm94[.]bin hxxp://84[.]38[.]129[.]77/HXUGmKrAljTiKGkDGL55[.]bin |
CloudEyE |
| URL | hxxps://teamrising[.]ae/arquivo_20260219172505[.]txt hxxp://158[.]94[.]211[.]63/dealer/ebukaxworm[.]txt hxxp://158[.]94[.]211[.]63/dealer/oilandgasxwormugo[.]txt hxxp://158[.]94[.]211[.]63/dealer/yunewfile[.]txt |
XWorm |
| URL | hxxp://130[.]12[.]180[.]43/files/5411854720/JyOpiNX[.]exe hxxp://93[.]185[.]167[.]10/f/[.]b0s hxxp://104[.]194[.]152[.]180/download/install[.]exe hxxp://31[.]59[.]129[.]233/nuts/poop hxxp://130[.]12[.]180[.]43/files/1781548144/3BXsQpC[.]exe hxxp://61[.]160[.]213[.]179:86/Video[.]scr hxxp://61[.]160[.]213[.]179:86/Photo[.]scr hxxp://183[.]30[.]204[.]216:2213/Video[.]scr hxxp://113[.]116[.]149[.]250:9980/Video[.]scr hxxp://183[.]30[.]204[.]216:2213/Photo[.]scr hxxp://183[.]30[.]204[.]216:2213/AV[.]scr hxxp://114[.]252[.]224[.]245:5005/AV[.]scr hxxp://114[.]252[.]224[.]245:5005/Video[.]scr hxxp://113[.]116[.]149[.]250:9980/Photo[.]scr hxxp://114[.]252[.]224[.]245:5005/Photo[.]scr hxxp://130[.]12[.]180[.]43/files/8408827406/GbY0R7a[.]exe |
Coinminer |
| URL | hxxp://130[.]12[.]180[.]43/files/8532745682/eVLF2SR[.]exe hxxp://45[.]91[.]133[.]229/download/beedv1[.]rar |
AsyncRAT |
| URL | hxxp://130[.]12[.]180[.]43/files/6964245325/RTMbrxA[.]exe | MaskGramStealer |
| URL | hxxp://www[.]wzsw5[.]shop/fz49/ hxxp://www[.]xeoc[.]shop/fz49/ hxxp://www[.]xfqjrms[.]bond/ns05/ hxxp://www[.]xn--essncesensorial-tnb[.]com[.]br/ns05/ hxxp://www[.]xtmmm[.]top/ns05/ hxxp://www[.]yakutianguide[.]ru/ns05/ hxxp://www[.]yinmen-luxeron[.]com/ns05/ hxxp://www[.]ucuuj829346[.]luxe/tu90/ hxxp://www[.]uexgdf[.]vip/tu90/ hxxp://www[.]uspcs[.]click/tu90/ hxxp://www[.]valencia-motogp[.]com/ns05/ hxxp://www[.]vaxfreemilk[.]com/fz49/ hxxp://www[.]ved-my-semya-smotret[.]online/ns05/ hxxp://www[.]w7z81v[.]info/fz49/ hxxp://www[.]wacareerplus[.]com/ns05/ hxxp://www[.]watakyu-kaimin[.]com/fz49/ hxxp://www[.]wguwbnq792[.]vip/ns05/ hxxp://www[.]winhubwin[.]com/tu90/ hxxp://www[.]wwwph143ph[.]com/ns05/ hxxp://www[.]t7qt8rj9xg[.]cc/fz49/ hxxp://www[.]taier-rooftile[.]com/fz49/ hxxp://www[.]teatiger[.]ru/fz49/ hxxp://www[.]techihub[.]store/ns05/ hxxp://www[.]thebinpvd[.]com/tu90/ hxxp://www[.]thkifry[.]bond/fz49/ hxxp://www[.]thx15213w3[.]cc/fz49/ hxxp://www[.]tk7[.]store/tu90/ hxxp://www[.]tnlfy5[.]info/tu90/ hxxp://www[.]triplehunter[.]com/tu90/ hxxp://www[.]tripscan21[.]top/fz49/ hxxp://www[.]ts6g19v[.]com/ns05/ hxxp://www[.]sakuramassages[.]com/fz49/ hxxp://www[.]serviceplus[.]pro/ns05/ hxxp://www[.]shadowluck[.]com/tu90/ hxxp://www[.]shop808culture[.]com/fz49/ hxxp://www[.]shopzone[.]life/tu90/ hxxp://www[.]southstconstruction[.]com/ns05/ hxxp://www[.]spjpantp[.]top/fz49/ hxxp://www[.]stidq2kmxg[.]cc/fz49/ hxxp://www[.]studyvibez[.]site/fz49/ hxxp://www[.]superspectiva[.]com/tu90/ hxxp://www[.]sushiswap-app[.]com/fz49/ hxxp://www[.]piaohua2[.]top/ns05/ hxxp://www[.]pin-up8k5[.]com/tu90/ hxxp://www[.]pinup-casino-zerkalo[.]buzz/fz49/ hxxp://www[.]pixelkonnstructor[.]store/fz49/ hxxp://www[.]qzsy74[.]sbs/fz49/ hxxp://www[.]racekapital[.]com/fz49/ hxxp://www[.]ratamento[.]gripe/tu90/ hxxp://www[.]remi62[.]com/tu90/ hxxp://www[.]revistadomomento[.]com/ns05/ hxxp://www[.]rfrcjpn[.]bond/fz49/ hxxp://www[.]rntpr8460f[.]cfd/tu90/ hxxp://www[.]rostabilon[.]com/ns05/ hxxp://www[.]rwd[.]exchange/tu90/ hxxp://www[.]ombhhy5[.]sbs/fz49/ hxxp://www[.]omprimmoonremetboo[.]ru/ns05/ hxxp://www[.]opnhqw[.]sbs/ns05/ hxxp://www[.]or6l8v1wb[.]pro/fz49/ hxxp://www[.]orakuxafolidv[.]info/fz49/ hxxp://www[.]outletbelle[.]com/tu90/ hxxp://www[.]oxelys-solution[.]fr/tu90/ hxxp://www[.]pabitechnology[.]us/ns05/ hxxp://www[.]paciscion[.]com/ns05/ hxxp://www[.]parcitogolf[.]com/tu90/ hxxp://www[.]pc-china-mile[.]com/ns05/ hxxp://www[.]pealenik[.]com/fz49/ hxxp://www[.]muokamasyfose[.]ru/ns05/ hxxp://www[.]myoakviewbenefits[.]com/fz49/ hxxp://www[.]n1ph1s[.]info/fz49/ hxxp://www[.]natravamed[.]com/ns05/ hxxp://www[.]newiberiacarwrecklawyer[.]com/tu90/ hxxp://www[.]nihao626260[.]top/tu90/ hxxp://www[.]nobunosuke[.]com/tu90/ hxxp://www[.]nolachronicle[.]com/fz49/ hxxp://www[.]notguilty[.]sk/tu90/ hxxp://www[.]ntbeinhd16[.]cfd/ns05/ hxxp://www[.]o4ev6y[.]top/tu90/ hxxp://www[.]oinsjet[.]com/tu90/ hxxp://www[.]limitlesssupplements[.]shop/tu90/ hxxp://www[.]lunrycas[.]com/tu90/ hxxp://www[.]lxwph[.]cfd/tu90/ hxxp://www[.]m-nabu[.]com/tu90/ hxxp://www[.]m0496kf[.]shop/tu90/ hxxp://www[.]macrovectoralliance[.]sbs/ns05/ hxxp://www[.]mafiyacoffee[.]com/tu90/ hxxp://www[.]maka69[.]net/fz49/ hxxp://www[.]manilaplayplay[.]com/fz49/ hxxp://www[.]marylandguild[.]com/fz49/ hxxp://www[.]mehmetarhan[.]com/tu90/ hxxp://www[.]miacheap[.]flights/ns05/ hxxp://www[.]molivarnet[.]asia/tu90/ hxxp://www[.]info-premierballers[.]com/tu90/ hxxp://www[.]isnevrc[.]bond/ns05/ hxxp://www[.]iwfp9o[.]vip/ns05/ hxxp://www[.]jennyfercoox[.]com/tu90/ hxxp://www[.]jess-sol[.]com/fz49/ hxxp://www[.]jexedyu7[.]pro/ns05/ hxxp://www[.]jnanadeepaexpert[.]com/ns05/ hxxp://www[.]jordnmusic[.]com/tu90/ hxxp://www[.]kevinolinger[.]com/ns05/ hxxp://www[.]kisahkasihsatwa[.]com/tu90/ hxxp://www[.]kodagen[.]com/tu90/ hxxp://www[.]krczibo[.]bond/ns05/ hxxp://www[.]learingcenter[.]com/fz49/ hxxp://www[.]h0j6lbe[.]icu/ns05/ hxxp://www[.]hardfeelingsblog[.]com/tu90/ hxxp://www[.]health-prader-willi-nyz6s7[.]live/ns05/ hxxp://www[.]heetmehtaofficial[.]com/fz49/ hxxp://www[.]help[.]ventures/tu90/ hxxp://www[.]hsck[.]pub/ns05/ hxxp://www[.]hubsmartproperties[.]com/ns05/ hxxp://www[.]hxcwyj[.]com/ns05/ hxxp://www[.]hyeokus[.]com/fz49/ hxxp://www[.]ierrepironet[.]com/ns05/ hxxp://www[.]igjewelry[.]com/tu90/ hxxp://www[.]impulsvendrell[.]com/fz49/ hxxp://www[.]faithbenefit[.]com/ns05/ hxxp://www[.]findsteqboutique[.]shop/ns05/ hxxp://www[.]fkbr50[.]com/fz49/ hxxp://www[.]front-ft[.]com/fz49/ hxxp://www[.]furrybeehive[.]com/ns05/ hxxp://www[.]garrisonfxc[.]com/ns05/ hxxp://www[.]gensetresmi[.]com/ns05/ hxxp://www[.]giftprints[.]cl/fz49/ hxxp://www[.]glamourexpert[.]live/tu90/ hxxp://www[.]goatover[.]com/tu90/ hxxp://www[.]guttercleaningburlingtonma[.]com/ns05/ hxxp://www[.]gvewm[.]xyz/ns05/ hxxp://www[.]decisintrepid[.]com/tu90/ hxxp://www[.]demingworld[.]com/ns05/ hxxp://www[.]dldaljq[.]bond/fz49/ hxxp://www[.]drwn[.]ch/fz49/ hxxp://www[.]dxmestudioacademia[.]com/fz49/ hxxp://www[.]ecovitalformulasbf[.]info/fz49/ hxxp://www[.]elytraonline[.]store/fz49/ hxxp://www[.]erralinfa[.]com/tu90/ hxxp://www[.]esenciacz[.]info/fz49/ hxxp://www[.]eu-r-pg[.]com/tu90/ hxxp://www[.]evolegy[.]com/ns05/ hxxp://www[.]f6el2g[.]top/fz49/ hxxp://www[.]bvcki[.]xyz/fz49/ hxxp://www[.]c800ah[.]info/ns05/ hxxp://www[.]centerwellstateave1[.]com/tu90/ hxxp://www[.]charmpulse[.]biz/ns05/ hxxp://www[.]chxmpion[.]com/ns05/ hxxp://www[.]clavebathhouse[.]info/fz49/ hxxp://www[.]clearflowlearing[.]com/ns05/ hxxp://www[.]conterahip[.]xyz/tu90/ hxxp://www[.]curation[.]today/tu90/ hxxp://www[.]d0re26amc[.]info/ns05/ hxxp://www[.]darkxpixel[.]store/tu90/ hxxp://www[.]dayaneejoaquim[.]com[.]br/ns05/ hxxp://www[.]ango[.]works/ns05/ hxxp://www[.]antest-iroepke-251105-2[.]com/tu90/ hxxp://www[.]ar3ebj[.]bond/fz49/ hxxp://www[.]argachali[.]com/fz49/ hxxp://www[.]arysportswear[.]us/tu90/ hxxp://www[.]awardevolution[.]com/fz49/ hxxp://www[.]berwiannicoslife7[.]com/ns05/ hxxp://www[.]bigfootwoodcare[.]shop/ns05/ hxxp://www[.]bobewigi[.]com/fz49/ hxxp://www[.]boostupbloggings[.]com/fz49/ hxxp://www[.]botan-essentials[.]store/ns05/ hxxp://www[.]brixaloneth[.]world/tu90/ hxxp://www[.]91mh042[.]vip/ns05/ hxxp://www[.]9thaqjxs[.]top/fz49/ hxxp://www[.]9x2si9q5[.]shop/ns05/ hxxp://www[.]adashucoaching[.]com/fz49/ hxxp://www[.]adgenmedia[.]info/fz49/ hxxp://www[.]agno[.]sk/fz49/ hxxp://www[.]airobotcatering[.]com/ns05/ hxxp://www[.]ajq979-q4mjso[.]com/ns05/ hxxp://www[.]akabetvip[.]email/ns05/ hxxp://www[.]akademia-lik[.]ru/tu90/ hxxp://www[.]akxugw[.]info/tu90/ hxxp://www[.]amazondale[.]com/tu90/ hxxp://www[.]170064a[.]com/tu90/ hxxp://www[.]2tenmarketingok[.]com/ns05/ hxxp://www[.]3fusyu[.]bond/fz49/ hxxp://www[.]44352896[.]com/tu90/ hxxp://www[.]4889763[.]cc/tu90/ hxxp://www[.]5736x[.]xyz/ns05/ hxxp://www[.]6n4pcj[.]cyou/tu90/ hxxp://www[.]6supv0[.]vip/fz49/ hxxp://www[.]712uu[.]top/tu90/ hxxp://www[.]7m20wvee[.]bond/tu90/ hxxp://www[.]8ei3mlle[.]bond/fz49/ hxxp://www[.]8uh6g[.]top/fz49/ hxxp://www[.]013832[.]com/tu90/ hxxp://www[.]030054405[.]xyz/fz49/ hxxp://www[.]08227903[.]com/tu90/ hxxp://www[.]0fb7fwr0[.]bond/fz49/ hxxp://www[.]130102y[.]com/fz49/ hxxps://kariyersokagi[.]com[.]tr/files/Enquiry[.]js hxxp://147[.]124[.]212[.]141/dd/bin[.]e |
Formbook |
| URL | hxxp://betsan01[.]top/download[.]php?file=lv[.]exe | CryptBot |
| URL | hxxps://89[.]23[.]103[.]42/hb9ivshs02/index[.]php | Amadey |
| URL | hxxp://193[.]38[.]248[.]139/8c91e91fdd93452c[.]php hxxps://85[.]28[.]47[.]30/920475a59bac849d[.]php hxxps://85[.]28[.]47[.]70/744f169d372be841[.]php hxxps://45[.]153[.]34[.]175/c4e3d825c1654e79[.]php hxxp://196[.]251[.]107[.]104/build1[.]exe |
Stealc |
| URL | hxxp://eyota[.]com[.]sg/group/panelnew/gate[.]php | Pony |
| URL | hxxp://130[.]12[.]182[.]211:25196/linux_386 hxxp://130[.]12[.]182[.]211:25196/linux_mips hxxp://130[.]12[.]182[.]211:25196/linux_aarch64 hxxp://130[.]12[.]182[.]211:25196/linux_arm6 hxxp://130[.]12[.]182[.]211:25196/linux_amd64 hxxp://130[.]12[.]182[.]211:25196/linux_arm5 hxxp://130[.]12[.]182[.]211:25196/linux_mips64 hxxp://130[.]12[.]182[.]211:25196/linux_arm7 hxxp://130[.]12[.]182[.]211:25196/linux_mipsel |
Kaiji |
| URL | hxxp://82[.]25[.]63[.]150/Q[.]GRE hxxp://64[.]95[.]12[.]162/captcha[.]php hxxps://defragglerupdate[.]com/software[.]zip |
NetSupportManager RAT |
| URL | hxxp://130[.]12[.]180[.]43/files/8307178715/VGAvfwd[.]exe | SalatStealer |
| URL | hxxps://eroticaforfree[.]com/nfront[.]php hxxps://eroticaforfree[.]com/nback[.]php |
Satacom |
| URL | hxxps://api[.]telegram[.]org/bot8528232795:AAEcxrshf3NCvH1DpgB1iUuJ-dP6S1-Hbe0/sendMessage?chat_id= hxxps://api[.]telegram[.]org/bot8445647069:AAFS-efLM_PeYZmpQhMfUXGFpaTNyXLJBF8/sendMessage?chat_id=6580547032 hxxp://147[.]124[.]212[.]141/dd/dd[.]sala hxxps://api[.]telegram[.]org/bot7537774095:AAG3NUNGelEzgGtbXmvz6_F6alj9VfSYk0M/sendMessage?chat_id=6406632357 |
Stealerium |
| URL | hxxp://195[.]16[.]44[.]75:8080/ps_payload[.]doc hxxp://195[.]16[.]44[.]75:8080/vpn_config[.]doc hxxp://195[.]16[.]44[.]75:8080/update5555[.]doc hxxp://195[.]16[.]44[.]75:8080/urgent_update[.]doc hxxp://195[.]16[.]44[.]75:8080/update[.]doc hxxp://195[.]16[.]44[.]75:8080/shell5555[.]doc hxxp://195[.]16[.]44[.]75:8080/revshell[.]doc hxxp://195[.]16[.]44[.]75:8080/go2[.]doc hxxp://195[.]16[.]44[.]75:8080/final[.]doc hxxp://195[.]16[.]44[.]75:8080/patch_update[.]doc hxxp://195[.]16[.]44[.]75:8080/cmd_patch[.]doc hxxp://195[.]16[.]44[.]75:8080/phish_final[.]doc hxxp://195[.]16[.]44[.]75:8080/go_update[.]doc hxxp://195[.]16[.]44[.]75:8080/x64_payload[.]doc hxxp://195[.]16[.]44[.]75:8080/follina_payload[.]doc hxxp://195[.]16[.]44[.]75:8080/follina[.]doc hxxp://195[.]16[.]44[.]75:8080/doc3[.]doc |
Metasploit |
| URL | hxxp://195[.]16[.]44[.]75:8080/Rubeus[.]exe hxxp://195[.]16[.]44[.]75:8080/KrbRelayUp[.]exe hxxp://195[.]16[.]44[.]75:8080/DavRelayUp2[.]exe |
Rubeus |
| URL | hxxp://195[.]16[.]44[.]75:8080/rev64[.]exe | Meterpreter |
| URL | hxxp://195[.]16[.]44[.]75:8080/chisel[.]exe | Hive |
| URL | hxxp://195[.]16[.]44[.]75:8080/LaZagne[.]exe | LaZagne |
| URL | hxxp://195[.]16[.]44[.]75:8080/DavRelayUp[.]exe | MimiKatz |
| URL | hxxps://gateway[.]lighthouse[.]storage/ipfs/bafkreigbl2q3x5x2bgljw7jzc6vpbsqxvkezpcdbxym7pdjqtt3hyb4hzu hxxps://gateway[.]lighthouse[.]storage/ipfs/bafybeiglav5n6cekzmy5szszt3gko62zw6aixefv3l2l7s6ozyttts6cka hxxp://144[.]172[.]100[.]220/img/optimized_MSI[.]png hxxps://bvaco[.]com/arquivo_20260223131604[.]txt hxxp://85[.]11[.]167[.]183/arquivo_20260222225726[.]txt hxxp://91[.]92[.]241[.]197:5124/1/pp1/mmnmy[.]png |
Remcos |
| URL | hxxps://bursaelektriktamir[.]com/Jesuchristi/SECURE[.]Ps1 hxxps://api[.]telegram[.]org/bot8210009990:AAGCiGEIqNsJJYLNYR7xangQyR_KyPaPED8/sendMessage?chat_id=1271362249 hxxps://bvaco[.]com/arquivo_20260223164236[.]txt hxxp://158[.]94[.]211[.]63/dealer/ugooilnewsnake[.]txt |
Snake Keylogger |
| URL | hxxps://twtaxgo[.]cn/uploads/20260129/taxIs_RX3001[.]7z | ValleyRAT |
| URL | hxxp://147[.]50[.]253[.]3/run[.]exe | Babadeda |







