不正URLへのアクセス、不正メールの受信
-
メール受信した
弊社お客様0社 URLアクセスした
弊社お客様5社 -
2026/03/25
※2026/03/25 更新
マルウェア感染させると考えられるURLを検知(2026/03/25)
■IoC(※1)
| Type: | IOC: | Signature: |
|---|---|---|
| URL | hxxp://87[.]120[.]219[.]222:41292/1/flintcloak210[.]ljy hxxp://87[.]120[.]219[.]222:41292/1/kaemsjlikeme244[.]ldv hxxp://87[.]120[.]219[.]222:41292/1/trucecloak188[.]dsx hxxp://87[.]120[.]219[.]222:41292/1/yashegmakguezk495[.]nxa hxxp://87[.]120[.]219[.]222:41292/1/widen676flora[.]kid hxxp://87[.]120[.]219[.]222:41292/1/truce596jolly[.]ips hxxp://87[.]120[.]219[.]222:41292/1/ridge44ridge[.]ybe hxxp://87[.]120[.]219[.]222:41292/1/diemsgqhazoem54[.]wxq hxxp://87[.]120[.]219[.]222:41292/1/wristacorn717[.]hjf hxxp://87[.]120[.]219[.]222:41292/1/ysahgemaskgezx825[.]ice hxxp://87[.]120[.]219[.]222:41292/1/maiejtyraomrf872[.]tzo hxxp://87[.]120[.]219[.]222:41292/1/maiejtkameneu178[.]bcq hxxp://87[.]120[.]219[.]222:41292/1/oceanlance429[.]ihp hxxp://87[.]120[.]219[.]222:41292/1/diemsgqcaopelkf329[.]emb hxxp://87[.]120[.]219[.]222:41292/1/terra523peach[.]uyv hxxp://87[.]120[.]219[.]222:41292/1/blazecloak699[.]jpu hxxp://87[.]120[.]219[.]222:41292/1/charmwrist97[.]qsa hxxp://87[.]120[.]219[.]222:41292/1/ayesjqomgesazyt925[.]xrk hxxp://87[.]120[.]219[.]222:41292/1/aiasgpe422aiasgpe[.]fsv hxxp://87[.]120[.]219[.]222:41292/1/terravinyl495[.]sgu hxxp://87[.]120[.]219[.]222:41292/1/mbeirdajryshg135[.]mjy hxxp://87[.]120[.]219[.]222:41292/1/ajryshgajryshg251[.]hfm hxxp://87[.]120[.]219[.]222:41292/1/florawaltz640[.]bwg hxxp://87[.]120[.]219[.]222:41292/1/ayesaherefytasgmki392[.]qux hxxp://87[.]120[.]219[.]222:41292/1/gleamgleam377[.]rgb hxxp://87[.]120[.]219[.]222:41292/1/zmgrajgtemasg379[.]itt hxxp://87[.]120[.]219[.]222:41292/1/esygmheayesjqom157[.]mcm hxxp://87[.]120[.]219[.]222:41292/1/wuemasgqkewofm962[.]pzs hxxp://87[.]120[.]219[.]222:41292/1/wuemasgqeyrmasjq793[.]mli hxxp://45[.]225[.]135[.]61/GdaWJLSiOjz162[.]bin hxxps://mobshah[.]com/dd/pp[.]sam hxxp://198[.]23[.]177[.]216/vbwgjPfywCM166[.]bin hxxp://198[.]23[.]177[.]216/fLfOXQlvlFlyi168[.]bin hxxp://198[.]23[.]177[.]216/Contru154[.]jpb hxxp://198[.]23[.]177[.]216/Lumin59[.]mix hxxp://198[.]23[.]177[.]216/zbLErzBTDQQB188[.]bin |
CloudEyE |
| URL | hxxp://87[.]120[.]219[.]222:41292/9839572789384/Documents/Shared/Reports/wishlist87231[.]bat hxxp://87[.]120[.]219[.]222:41292/2/docs[.]bat hxxps://www[.]nxtprocure[.]net/ilpevmyx[.]zip hxxp://192[.]3[.]122[.]231/img/hoo/img_180511[.]png hxxp://104[.]168[.]5[.]54/133/givemebestthingsbrother[.]vbs hxxp://107[.]172[.]135[.]4/60/godwithuskobogreat[.]hta |
Remcos |
| URL | hxxps://api[.]telegram[.]org/bot8308741389:AAGU2vnidFSlDKqGP1ijGyWte13nYPXP9_A/sendMessage?chat_id=7932467022 hxxps://api[.]telegram[.]org/bot8700382988:AAH5nQO-ZqbH2Eq7r7XmFahaRjT6Q5M6phA/sendMessage?chat_id=5061956073 |
Snake Keylogger |
| URL | hxxp://158[.]94[.]208[.]7/files/7782139129/ZSZfFtn[.]exe hxxp://158[.]94[.]208[.]7/files/8074464496/Fu4sGxz[.]exe hxxp://5[.]252[.]21[.]239/files/7782139129/ZSZfFtn[.]exe hxxp://185[.]222[.]160[.]157/files/7782139129/ZSZfFtn[.]exe hxxp://158[.]94[.]208[.]168/files/7782139129/ZSZfFtn[.]exe hxxp://130[.]12[.]180[.]43/files/8079848160/emlOLoh[.]exe |
SalatStealer |
| URL | hxxps://bunesaria[.]com/kiska hxxps://housing4talent[.]com/wp-blog-footer[.]php?page= hxxps://biaolfkfkakajsfj[.]com/asdggg[.]js hxxps://maxintora[.]com/lampas hxxps://shopattotalwrap[.]com/wp-blog-footer[.]php?page= hxxps://fsdfsodfofofosdof[.]com/daskdak[.]js |
IClickFix |
| URL | hxxps://5zfv7hdg[.]ironapp[.]digital/?=check&&actmn=QrFaivtdUFUcHXAC hxxps://jdx5tnr0[.]sunbit[.]digital/?=check&&actmn=vhTbAesCsIGTHUZP hxxps://uwor76f8[.]oaknet[.]digital/?=check&&actmn=drvTptepxZwxHxGJ hxxps://dgp13ezr[.]winddev[.]digital/?=check&&actmn=juwRQGoaJFQJrxaD hxxps://677jb7co[.]goldsys[.]digital/?=check&&actmn=KhQyOtBACJsezVQW hxxps://8o8xcdx1[.]rockapp[.]digital/?=check&&actmn=KcwvMoWxvrfXnZaI hxxps://c02az6tr[.]lakeweb[.]digital/?=check&&actmn=IBYzVKUyCMfWNVuB hxxps://avk93cqg[.]ironhub[.]digital/?=check&&actmn=kQmNUYzNmHznuFCK |
ClearFake |
| URL | hxxp://43[.]228[.]157[.]123/oqqqqoa[.]mp3 hxxps://repost[.]optico-voda[.]info/denyexorcist hxxps://enotbanknoti[.]co/stabber |
ACR Stealer |
| URL | hxxp://80[.]89[.]237[.]130/1[.]exe hxxps://myverifhouse[.]sbs/api/index[.]php?a= hxxp://80[.]89[.]237[.]112/1[.]exe hxxp://158[.]94[.]208[.]7/files/8531638373/QWFfVk7[.]exe hxxp://5[.]252[.]21[.]239/files/rdx/random[.]exe hxxp://5[.]252[.]21[.]239/files/7453936223/KAQ8PQ5[.]exe hxxp://5[.]252[.]21[.]239/files/8531638373/QWFfVk7[.]exe hxxp://5[.]252[.]21[.]239/files/7782139129/S6xWuZ1[.]exe hxxp://5[.]252[.]21[.]239/files/5900855435/eNLe4nm[.]exe hxxp://5[.]252[.]21[.]239/files/8574065846/HPlEReH[.]exe hxxp://5[.]252[.]21[.]239/files/gop/random[.]exe hxxp://5[.]252[.]21[.]239/files/unique5/random[.]exe hxxp://5[.]252[.]21[.]239/vidar/random[.]exe hxxp://185[.]222[.]160[.]157/files/7453936223/KAQ8PQ5[.]exe hxxp://185[.]222[.]160[.]157/files/5900855435/eNLe4nm[.]exe hxxp://185[.]222[.]160[.]157/files/7782139129/S6xWuZ1[.]exe hxxp://185[.]222[.]160[.]157/files/8574065846/HPlEReH[.]exe hxxp://185[.]222[.]160[.]157/files/8531638373/QWFfVk7[.]exe hxxp://185[.]222[.]160[.]157/files/unique5/random[.]exe hxxp://185[.]222[.]160[.]157/files/rdx/random[.]exe hxxp://185[.]222[.]160[.]157/files/gop/random[.]exe hxxp://185[.]222[.]160[.]157/vidar/random[.]exe hxxp://158[.]94[.]208[.]168/files/gop/random[.]exe hxxp://158[.]94[.]208[.]168/files/unique5/random[.]exe hxxp://158[.]94[.]208[.]168/files/7453936223/KAQ8PQ5[.]exe hxxp://158[.]94[.]208[.]168/files/5900855435/eNLe4nm[.]exe hxxp://158[.]94[.]208[.]168/files/8531638373/QWFfVk7[.]exe hxxp://158[.]94[.]208[.]168/files/7782139129/S6xWuZ1[.]exe hxxp://158[.]94[.]208[.]168/files/8574065846/HPlEReH[.]exe hxxp://158[.]94[.]208[.]168/files/8434554557/X8cqVrA[.]exe hxxp://185[.]222[.]160[.]157/files/8434554557/X8cqVrA[.]exe hxxp://188[.]137[.]182[.]115/1[.]exe hxxp://158[.]94[.]208[.]168/vidar/random[.]exe |
Vidar |
| URL | hxxps://aawbi[.]com/5232f[.]js hxxps://aawbi[.]com/js[.]php hxxps://artsselection[.]com/bookmarks hxxps://zeftasarim[.]com/quick hxxps://zeftasarim[.]com/lefter |
KongTuke |
| URL | hxxp://158[.]94[.]208[.]7/files/7850695435/gpaMBVQ[.]msi hxxp://5[.]252[.]21[.]239/files/7850695435/gpaMBVQ[.]msi hxxp://185[.]222[.]160[.]157/files/7850695435/gpaMBVQ[.]msi hxxp://158[.]94[.]208[.]168/files/7850695435/gpaMBVQ[.]msi |
EternalRocks |
| URL | hxxp://158[.]94[.]208[.]7/files/7776573655/5xOR1kH[.]exe hxxp://158[.]94[.]208[.]7/files/7776573655/uVFeyUy[.]exe hxxp://158[.]94[.]208[.]7/files/7776573655/8RPb9TK[.]exe hxxp://158[.]94[.]208[.]7/files/7776573655/sTOae3E[.]exe hxxp://5[.]252[.]21[.]239/files/7776573655/KSsORhg[.]exe |
GCleaner |
| URL | hxxp://217[.]119[.]129[.]76/api/NTE3YjdjNWU1NjYzNjU2YTA1N2Y= hxxp://213[.]176[.]73[.]130/api/NTE3YjdjNWU1NjYzNjU2YTA1N2Y= |
SmartLoader |
| URL | hxxp://91[.]92[.]242[.]3:7777/noesisllc[.]online/wealt1818/wealtt/nerdfwiqtwqhdgfrwt6fntdwrgonht[.]js hxxp://45[.]156[.]87[.]230/img_095026[.]png |
MASS Logger |
| URL | hxxps://api[.]telegram[.]org/bot8728000947:AAHZ0h9_GfrQ-qpBVmHLcI7ZRyQQl7eA6G4/sendMessage?chat_id=5590894570 hxxps://api[.]telegram[.]org/bot8622471160:AAGNcswY1AVYADWLd-SuKYNprQhFuY9qvQg/sendMessage?chat_id=7426057666 |
Stealerium |
| URL | hxxp://77[.]91[.]96[.]222:7777/gate/ed3b194a53b1d17525ba6396ee hxxp://77[.]91[.]96[.]222:7777/gate/ef25005b57a0c2382bec63 hxxp://158[.]94[.]208[.]7/files/7341834371/BgAtGH0[.]exe hxxp://158[.]94[.]208[.]7/files/8531638373/9Hbhrms[.]exe hxxp://158[.]94[.]208[.]7/files/8531638373/ELPdXJY[.]exe hxxp://5[.]252[.]21[.]239/files/7341834371/BgAtGH0[.]exe hxxp://185[.]222[.]160[.]157/files/7341834371/BgAtGH0[.]exe hxxp://158[.]94[.]208[.]168/files/7341834371/BgAtGH0[.]exe |
Stealc |
| URL | hxxp://121[.]37[.]40[.]52/d hxxp://libss[.]0x504[.]com/linux_arm6 hxxp://libss[.]0x504[.]com/linux_arm5 hxxp://libss[.]0x504[.]com/linux_arm7 hxxp://91[.]92[.]241[.]94/massload hxxp://91[.]92[.]241[.]94/x86 hxxp://193[.]32[.]162[.]53/mipsel |
Bashlite |
| URL | hxxp://158[.]94[.]208[.]7/files/1781548144/nKZgdKm[.]exe hxxp://158[.]94[.]208[.]7/files/1781548144/JKon0XP[.]exe hxxp://158[.]94[.]208[.]168/files/1781548144/QlQgCVH[.]exe |
XWorm |
| URL | hxxp://178[.]16[.]52[.]201/9cca20c6df659f72/t_cpt_bld172638[.]bin hxxp://178[.]16[.]52[.]201/9cca20c6df659f72/m_cpt1903[.]bin hxxp://ns7[.]softline[.]top:443/s/ref=nb_sb_noss_1/167-3294888-0262949/field-keywords=books hxxp://ns8[.]softline[.]top:443/s/ref=nb_sb_noss_1/167-3294888-0262949/field-keywords=books hxxp://ns9[.]softline[.]top:443/s/ref=nb_sb_noss_1/167-3294888-0262949/field-keywords=books |
Cobalt Strike |
| URL | hxxps://sbstorage[.]club/012378DS[.]VDW hxxp://sbstorage[.]club/z/abandonedly[.]vmp[.]exe |
Loda |
| URL | hxxps://repost[.]punto-viva[.]info/firewall_policy[.]conf | NetSupportManager RAT |
| URL | hxxp://5[.]252[.]21[.]239/files/8434554557/X8cqVrA[.]exe hxxp://158[.]94[.]208[.]7/files/8434554557/X8cqVrA[.]exe hxxps://allsydevs[.]com/image0321[.]png |
PureRAT |
| URL | hxxp://185[.]222[.]160[.]157/files/5848981546/l119oBn[.]exe hxxp://158[.]94[.]208[.]168/files/5848981546/hRw1yLa[.]exe |
SmokeLoader |
| URL | hxxps://roomabolishsnifftwk[.]shop/api hxxps://civilianurinedtsraov[.]shop/api hxxps://stalfbaclcalorieeis[.]shop/api hxxps://employhabragaomlsp[.]shop/api hxxps://femininiespywageg[.]shop/api hxxps://averageaattractiionsl[.]shop/api hxxps://buttockdecarderwiso[.]shop/api hxxps://museumtespaceorsp[.]shop/api hxxps://bleedminejw[.]buzz/api hxxps://rapeflowwj[.]lat/api hxxps://crosshuaht[.]lat/api hxxps://sustainskelet[.]lat/api hxxps://aspecteirs[.]lat/api hxxps://energyaffai[.]lat/api hxxps://necklacebudi[.]lat/api hxxps://discokeyus[.]lat/api hxxps://grannyejh[.]lat/api hxxps://volcanoyev[.]click/api hxxps://reinfomarbke[.]site/api hxxps://monopuncdz[.]site/api hxxps://unityshootsz[.]site/api hxxps://moeventmynz[.]site/api hxxps://plaintifuf[.]site/api hxxps://honerstyzu[.]site/api hxxps://bringlanejk[.]site/api hxxps://uppermixturyz[.]site/api hxxps://moutheventushz[.]shop/api hxxps://respectabosiz[.]shop/api hxxps://bakedstusteeb[.]shop/api hxxps://conceszustyb[.]shop/api hxxps://nightybinybz[.]shop/api hxxps://standartedby[.]shop/api hxxps://mutterissuen[.]shop/api hxxps://worddosofrm[.]shop/api hxxps://knifedxejsu[.]cyou/api hxxps://demonstationfukewko[.]shop/api hxxps://liabilitynighstjsko[.]shop/api hxxps://alcojoldwograpciw[.]shop/api hxxps://incredibleextedwj[.]shop/api hxxps://shortsvelventysjo[.]shop/api hxxps://shatterbreathepsw[.]shop/api hxxps://tolerateilusidjukl[.]shop/api hxxps://productivelookewr[.]shop/api hxxps://sideindexfollowragelrew[.]pw/api hxxps://finickypwk[.]lat/api hxxps://shoefeatthe[.]lat/api hxxps://savorraiykj[.]lat/api hxxps://kickykiduz[.]lat/api hxxps://miniatureyu[.]lat/api hxxps://leggelatez[.]lat/api hxxps://washyceehsu[.]lat/api hxxps://bloodyswif[.]lat/api hxxps://curtainykeo[.]lat/api |
Lumma Stealer |
| URL | hxxps://vahanindia[.]sbs/apk/mParivahan[.]apk | SMSspy |
| URL | hxxps://zoomaccess[.]us/lightout/notepads[.]exe | RatonRAT |
| URL | hxxps://raw[.]githubusercontent[.]com/twitodaniel10-sudo/Security/refs/heads/main/runner[.]exe hxxps://raw[.]githubusercontent[.]com/twitodaniel10-sudo/Security/refs/heads/main/old[.]exe hxxps://raw[.]githubusercontent[.]com/twitodaniel10-sudo/Security/main/SysAuditHost[.]exe hxxps://raw[.]githubusercontent[.]com/twitodaniel10-sudo/Security/refs/heads/main/toogood[.]exe |
Havoc |
| URL | hxxp://179[.]43[.]142[.]248/update/libssl[.]dll hxxp://31[.]220[.]57[.]50/abctop/oy7xup[.]thms hxxp://179[.]43[.]154[.]216/img/favicon[.]ico hxxp://212[.]193[.]30[.]32/upload/libcurl[.]dll hxxps://91[.]92[.]249[.]180:3374/817865d7b77e30b00f/lgknd2s9[.]1nmdh |
Rhadamanthys |
| URL | hxxp://130[.]12[.]180[.]43/files/7044575709/yQcmXNb[.]exe | Quasar RAT |
| URL | hxxp://158[.]94[.]208[.]168/files/8012574236/ZMxUkZd[.]exe hxxp://158[.]94[.]208[.]168/files/8012574236/NPvu1Ol[.]exe |
NjRAT |
| URL | hxxp://185[.]93[.]89[.]18:6677/IRemotePanel | RedLine Stealer |
| URL | hxxp://198[.]23[.]177[.]216/Kugle[.]pcx | Agent Tesla |
| URL | hxxp://87[.]121[.]84[.]57/nuts/poop hxxp://31[.]56[.]229[.]221/nuts/poop |
Coinminer |
| URL | hxxp://158[.]94[.]208[.]168/files/6334661508/lzyfkOs[.]exe | AsyncRAT |
| URL | hxxps://www[.]clifton-interiors[.]com/Panel/five/fre[.]php | LokiBot |
| URL | hxxp://bwshvew[.]com/search/?q=67e28dd8695ba47e425bf84c7c27d78406abdd88be4b12ebb517aa5c96bd86ed82df14d714bca5817673aa4ae8889b5e4fa9281ae978fe71ea771795af8e05c645db22f31dfe339426fa11af66c152adb719a9577e55b8603e983a6089fb12c4ec909c3d hxxp://bbjjnfd[.]com/search/?q=67e28dd86c58f5294706ad177c27d78406abdd88be4b12ebb517aa5c96bd86ed82df14d714bca5817673aa4ce8889b5e4fa9281ae978a271ea771795af8e05c645db22f31dfe339426fa12a466c553adb719a9577e55b8603e983a6089fb12c4ec909c38 |
Socks5 Systemz |
| URL | hxxps://api[.]telegram[.]org/bot8784907729:AAH3wk7pqa231ZPGBNKipBenJmi2TScVA5I/sendMessage?chat_id=5732008790 | DarkCloud |
| URL | hxxp://89[.]45[.]6[.]18/oPvjr94jfe/index[.]php hxxp://89[.]45[.]6[.]18/oPvjr94jfe/Login[.]php |
Amadey |







