不正URLへのアクセス、不正メールの受信
-
メール受信した
弊社お客様0社 URLアクセスした
弊社お客様5社 -
2026/05/25
※2026/05/25 更新
マルウェア感染させると考えられるURLを検知(2026/05/25)
■IoC(※1)
| Type: | IOC: | Signature: |
|---|---|---|
| URL | hxxp://91[.]92[.]242[.]236/files-129312398/files/file_cf4c0966dc8263ae[.]exe hxxp://91[.]92[.]242[.]236/files-129312398/files/file_06ad553c86ec86c7[.]exe hxxp://91[.]92[.]242[.]236/files-129312398/files/file_66b7f7ac55ab3943[.]exe hxxp://165[.]231[.]215[.]21/install[.]exe hxxp://91[.]92[.]242[.]236/files-129312398/files/file_7d9b4f2278093dda[.]exe |
Coinminer |
| URL | hxxps://lasagna-bakingpro[.]christmas/bc876c95-8245-4fbf-86d2-5ca047cf41d0/g[.]ch hxxps://stack-control-plane[.]christmas/eb055f0d-3036-411c-96cd-c7c7d05eb8e2/g[.]ch hxxps://cyber-defensepro[.]christmas/61fd8544-b2a4-4acd-b26f-e33cd488d250/g[.]ch hxxps://quantumvelocitylabs[.]christmas/78875570-5e84-486b-a61d-0005477244e6/g[.]ch hxxps://ancientparchmentarchive[.]christmas/46954175-4239-46b9-94c1-2ed084e7cf2f/g[.]ch hxxps://orbital-mechanics[.]christmas/1588c80a-dd8b-4a75-8d35-4b18c1801193/g[.]ch hxxps://subterranean-mineral[.]christmas/212fbe40-570d-403b-81b9-e895913bb568/g[.]ch hxxps://smartworkflowmanagement[.]christmas/3333cb84-ffcf-4715-8afe-a87a919bf5a3/g[.]ch hxxps://neon-cyberpunk[.]christmas/d0d852ed-9946-4317-8b96-e1740da525d7/g[.]ch hxxps://linguisticpuzzlesolver[.]christmas/d2cfd9d2-c83c-49b2-a54b-ae75333809dd/g[.]ch hxxps://linguisticpuzzlesolver[.]christmas/237e77e4-e9dd-4832-ac74-7c08e36f8b19/g[.]ch hxxps://vintagevinylrestoration[.]christmas/f6b92bf0-7e99-48e6-8b94-178717dfab11/g[.]ch hxxps://trading-academyexpert[.]christmas/614bf1e9-4498-4c92-8a38-0bc6b48678c9/g[.]ch hxxps://logicbufferskills[.]christmas/6bfc3d4d-4b96-418d-9580-ba33fc9fee48/g[.]ch hxxps://pixelart-canvas[.]christmas/92c054f2-ff2b-41bb-abe2-04b838ace443/g[.]ch hxxps://chickencutlet-hacks[.]christmas/96a44b1a-a1ce-4725-92a8-c3de38e825ee/ton[.]ch hxxps://chickencutlet-hacks[.]christmas/28601180-c97e-4631-91ff-c70af4e7e173/g[.]ch hxxps://chroniclearchivekeeper[.]christmas/a69046cd-ffaa-4b2e-95d3-c3c082cfe1b6/g[.]ch hxxps://formkey[.]asia/d01af252-520e-49c5-bb8f-dedf96636d23/ton[.]ch hxxps://spamgym[.]asia/7a28b2c1-d858-4730-a6c5-efb8b85d586d/ton[.]ch hxxps://spamgym[.]asia/8bb4f999-2220-484b-ae1d-4c8921d2bbaa/ton[.]ch hxxps://reposboy[.]asia/4b1907aa-05c5-465b-9f6b-836a0b125eb3/ton[.]ch hxxps://cache-orbit[.]christmas/24570d7a-161a-490a-8818-be3190f8a653/ton[.]ch hxxps://labdjang[.]asia/ca6dcb4d-a7bd-4116-80f4-992b542c3567/ton[.]ch hxxps://reposboy[.]asia/37fd9404-b366-49b3-8b03-b1b77f3fac39/ton[.]ch hxxps://phase-shiftbridge[.]christmas/verif hxxps://nodefabric[.]christmas/361d2a9d-9c75-4043-bfd8-bbca0794e89e/api[.]js hxxps://nodefabric[.]christmas/64f2d2a2-efba-49bf-b079-1ba81e02a777/ton[.]ch hxxps://virtual-packet-grid[.]christmas/5405d3e1-2a9c-468d-8d44-c66d47f51cea/ton[.]ch hxxps://holisticdetective[.]christmas/verif hxxps://sopranos-familytree[.]christmas/chk hxxps://snow-harbor[.]christmas/chk hxxps://xenomorphhiveintel[.]christmas/chk hxxps://mfwhezll[.]gift-lattice[.]christmas/8ee92af5-0bfd-4f2d-9008-878f5978ff55 hxxps://winter-pulse[.]christmas/chk hxxps://gift-lattice[.]christmas/chk hxxps://mvltyody[.]frost-engine[.]christmas/02b9cfc1-2c23-4ca6-b36e-fbec31299c31 hxxps://ftjilgqw[.]winter-pulse[.]christmas/dabbd14d-3c14-425b-85e7-e2550832fc63 hxxps://hoycbijv[.]holiday-matrix[.]christmas/bc3341b1-731e-4187-93fc-7f86b7753cf5 hxxp://ilhvyrij[.]ipv4has-lampnew[.]cyou/786762b0-4825-4286-99b2-577a9bc95013 hxxp://mkszunli[.]flopstin-gymcargo[.]cyou/ab9efe8d-0c62-405b-bb4f-1e0e6c3a048e hxxp://mfbrkbuv[.]betnoise-unionour[.]cyou/49a68922-608d-42f2-aefe-fc929839d14a hxxps://paqcfwvt[.]winter-pulse[.]christmas/a754bad3-7e7b-479d-b307-bcbfcb2a933f hxxps://hzlqlpfw[.]frost-engine[.]christmas/30570070-8dda-4769-8eef-c0c5a6867cb6 hxxps://ihtfqktk[.]holiday-matrix[.]christmas/96b7aba8-3295-4cfa-ba52-95f2dcc75e6a hxxps://ukkqtbst[.]snow-harbor[.]christmas/e3d9565f-68aa-44b0-aa7d-b64a3e9d24dd hxxps://mokmgdal[.]gift-lattice[.]christmas/3e376a3d-065b-463f-93dd-8721c73c2e12 hxxps://lzascdxk[.]xenomorphhiveintel[.]christmas/ed43f705-077c-4a27-afdb-6d2678de06be hxxps://badxqjge[.]gift-lattice[.]christmas/505ac99f-02c9-42a2-9d0d-c95052c9ebea hxxp://badxqjge[.]gift-lattice[.]christmas/505ac99f-02c9-42a2-9d0d-c95052c9ebea hxxp://euftrhnx[.]computationalgrid[.]com/ba1019ee-a048-4bd5-a90d-1fc5da2b8696 hxxps://9v42ch67[.]proxy-frontier[.]digital/?ublib=0bd596cf-3da7-4c07-a54b-75fc88461ef7 hxxps://y4gf3n18[.]network-foundry[.]digital/?ublib=aa690aff-01d7-4af1-bcb4-29bfade3d6b3 hxxps://n4burrgj[.]runtime-cascade[.]digital/?ublib=659ee75f-49e9-4100-8588-f9666da8f00c hxxp://wer[.]cache-processing-node[.]com/etc hxxps://uudiolsq[.]packet-frontier[.]digital/?ublib=94a04734-43ed-4fea-a748-248f926b72ef hxxps://gq0e2dm9[.]kernel-beacon[.]digital/?ublib=67272593-a627-4ddf-bb7e-474c50f5a448 hxxps://fkmrx4nm[.]signal-meridian[.]digital/?ublib=72a75cdb-387d-4b1c-ac11-92ad91b9e7f7 hxxps://dxsdji[.]felhangolo[.]com/7801266f-7be5-4f9d-9301-2154542f65fa hxxps://hqcmiiiu[.]cloud-orbit[.]digital/?ublib=b38ec3bf-301b-435a-a39c-37314ea5f352 hxxps://xdfbko[.]feszt360[.]hu/436049f6-40c3-4c50-b420-e1a81a1431ec hxxps://trejzg[.]femeso[.]hu/60fd6bbb-3774-46d1-afcc-9d6e31df4890 hxxps://nqvfew[.]flybuilt[.]eu/977d4603-4081-4280-8ea6-62ecfcc84f05 hxxps://58knxotz[.]proxy-compass[.]digital/?ublib=36534f41-dc9c-4236-b20e-843ee861e728 hxxps://vuvwlz[.]fluss[.]hu/6542db39-5779-4a96-8233-000e048dc99d hxxps://ieeljt[.]fittkor[.]hu/0ea4384d-3295-4e89-829c-803c6e58deff hxxps://npukpk[.]fodraszoktatas[.]eu/03ace386-a37f-41e7-a367-df0d30df34a5 hxxps://wwkgzd[.]flybuiltstudio[.]com/526ac08f-2188-419f-b2ad-e01b2bdb0df1 hxxps://qsxrao[.]flybuilt[.]hu/39b08f37-efbc-45ce-b98f-6ddaba53f04d hxxps://mcq9ktcv[.]telemetry-nexus[.]digital/?ublib=9e0e3bf9-684e-4e01-a7fd-2515bc86a6cf hxxps://kgztgu[.]fortunalamella[.]hu/7e778cbe-1bd4-47ce-a5a1-749ea5b2d8b2 hxxps://arrtom[.]followyourjoy[.]hu/1bf3899c-8774-4bfd-8c72-3cbf18fa43e0 hxxps://kimfeg[.]fusionizemanagement[.]com/7c384dc5-3f03-45ff-a6b3-33d9cdabffe2 hxxps://jgkvlq[.]fulop-vargafanni[.]hu/4afef2dd-f74b-4814-9cb1-a55b16831552 hxxps://dbvxnw[.]fullnrg[.]hu/b9fc31b1-4e34-4141-83f0-d0b44a3d678a hxxps://rapiny[.]gamesystem[.]hu/41f6b5f6-1409-4e72-bb56-b1e8b20004dd hxxps://m8fpbfz3[.]container-bridge[.]digital/?ublib=bc2b0bc7-3bae-4b2c-81d8-7502c54e6974 hxxps://bysjry[.]fusionize[.]org/38c76721-58d1-4d51-bf1a-4b72d51153fa hxxps://sneodo[.]gerecseglamping[.]com/5f2d7851-ece8-4664-a3fc-6bb9268a3f48 hxxps://qcjqcd[.]geokalk[.]hu/36af5d35-8a0a-4fa5-a468-e79d1758e6a3 hxxps://gcrexj[.]glfree[.]hu/6264891c-a891-416b-baed-d70b678223fe hxxps://bzngye4l[.]proxy-orbit[.]digital/?ublib=8eacdf4c-7761-4d63-8c76-5f3336392399 hxxps://uekdrl[.]gesol[.]hu/e4b6a640-32d1-4574-b94e-47564431cbb2 |
ClearFake |
| URL | hxxps://api[.]telegram[.]org/bot8819063414:AAEpYlsBXInWazZ2GFClFNkokB2RYsTTNic/ | Agent Tesla |
| URL | hxxps://lfwxgs[.]com/debug/loader[.]sh | AMOS |
| URL | hxxps://opaqueshellsoftsmoke[.]monster/indexactiverevenue[.]php hxxps://totebagsforwork[.]com/nfront[.]php hxxps://totebagsforwork[.]com/nback[.]php |
Satacom |
| URL | hxxp://91[.]92[.]242[.]236/files-129312398/files/file_61fdc9c6c9548f20[.]exe | Amadey |
| URL | hxxp://91[.]92[.]242[.]236/files-129312398/files/file_05115473da05b069[.]exe hxxps://abimj[.]edu[.]af/institute/10/cloudiya10[.]txt |
Vidar |
| URL | hxxp://85[.]204[.]125[.]76/a-r[.]m-7[.]Sakura hxxp://85[.]204[.]125[.]76/bot hxxp://85[.]204[.]125[.]76/p-p[.]c-[.]Sakura hxxp://85[.]204[.]125[.]76/a-r[.]m-6[.]Sakura hxxp://85[.]204[.]125[.]76/i-5[.]8-6[.]Sakura hxxp://85[.]204[.]125[.]76/a-r[.]m-5[.]Sakura hxxp://85[.]204[.]125[.]76/m-p[.]s-l[.]Sakura hxxp://85[.]204[.]125[.]76/a-r[.]m-4[.]Sakura hxxp://85[.]204[.]125[.]76/m-i[.]p-s[.]Sakura hxxp://85[.]204[.]125[.]76/s-h[.]4-[.]Sakura hxxp://85[.]204[.]125[.]76/x-3[.]2-[.]Sakura hxxp://85[.]204[.]125[.]76/m-6[.]8-k[.]Sakura hxxp://85[.]204[.]125[.]76/x-8[.]6-[.]Sakura hxxp://176[.]65[.]139[.]219/arm61 hxxp://176[.]65[.]139[.]61/wife[.]sh4 hxxp://176[.]65[.]139[.]61/wife[.]i686 hxxp://176[.]65[.]139[.]61/wife[.]arm4 |
Bashlite |
| URL | hxxp://130[.]12[.]180[.]190/15/ hxxp://130[.]12[.]180[.]190/12/ hxxp://178[.]16[.]54[.]109/15[.]exe |
Phorpiex |
| URL | hxxp://193[.]23[.]118[.]14:443/z9EcTAFSXSfJUMhRocXcPQVCYXseukwPaulkjvM-UN5wZNLi8iS4CiTTvRF-OKZ5X3gkr40dxnoxog7R4rhLHNpfja_ZCPNTP | Metasploit |
| URL | hxxp://45[.]148[.]10[.]210/hostmane hxxp://45[.]148[.]10[.]210/blackbih hxxp://45[.]148[.]10[.]210/blackboi hxxp://45[.]148[.]10[.]210/listener |
Mirai |
| URL | hxxp://151[.]242[.]125[.]187/dck hxxp://87[.]121[.]79[.]193/dck hxxp://87[.]121[.]79[.]73/dck |
Dofloo |
| URL | hxxp://107[.]189[.]3[.]150/b2f628/cronb[.]sh hxxp://209[.]141[.]58[.]166/b2f628/cronb[.]sh hxxp://140[.]99[.]32[.]48/b2f628/cronb[.]sh hxxp://205[.]185[.]118[.]246/b2f628/cronb[.]sh hxxp://b[.]9-9-8[.]com/brysj/cronb[.]sh |
RedTail |
| URL | hxxp://170[.]130[.]55[.]223/8a5722931e174543a98d[.]php hxxp://93[.]115[.]29[.]56/d3ffeca97818488f8fd2[.]php hxxp://158[.]94[.]208[.]102/bot_x64[.]exe hxxp://62[.]60[.]226[.]159/uploads/LzD94IdIfoeT[.]exe |
Stealc |
| URL | hxxp://138[.]197[.]117[.]175/oPvjr94jfe/Plugins/vnc[.]exe | TinyNuke |
| URL | hxxp://91[.]92[.]242[.]236/files-129312398/files/file_8648a3932ba8c3b6[.]exe hxxp://91[.]92[.]242[.]236/files-129312398/files/file_41b9b0ae817a81c5[.]exe hxxp://91[.]92[.]242[.]236/files-129312398/files/file_7ae1efec59cf42de[.]exe hxxp://91[.]92[.]242[.]236/files-129312398/files/file_85e88c7ae15946b2[.]exe |
MaskGramStealer |
| URL | hxxps://api[.]telegram[.]org/bot8915038126:AAHRBcjbPjmweVlfv3mVS9PT6E83PAgneiY/sendMessage?chat_id=8610932651 | AsyncRAT |
| URL | hxxp://91[.]92[.]242[.]236/files-129312398/files/file_2e4e1082336e95de[.]exe hxxp://185[.]102[.]115[.]99/client[.]exe |
RemoteX |







