不正URLへのアクセス、不正メールの受信
-
メール受信した
弊社お客様0社 URLアクセスした
弊社お客様0社 -
2023/05/12
※2023/05/12 更新
マルウェア感染させると考えられるURLを検知(2023/05/12)
■IoC(※1)
Type: | IOC: | Signature: |
---|---|---|
URL | hxxp://194[.]38[.]20[.]225/lf[.]sh hxxp://194[.]38[.]20[.]225/pg2[.]sh hxxp://194[.]38[.]20[.]225/ws[.]sh hxxp://194[.]38[.]20[.]225/ap[.]sh hxxp://194[.]38[.]20[.]225/ph[.]sh hxxp://194[.]38[.]20[.]225/gi[.]sh hxxp://194[.]38[.]20[.]225/ae[.]sh hxxp://94[.]142[.]138[.]111/software/tst2[.]exe hxxp://194[.]38[.]20[.]225/d[.]sh hxxp://194[.]38[.]20[.]225/f[.]sh hxxp://194[.]38[.]20[.]225/ex[.]sh hxxp://194[.]38[.]20[.]225/pg[.]sh hxxp://194[.]38[.]20[.]225/wb[.]sh hxxp://194[.]38[.]20[.]225/ge[.]sh hxxp://ink-scape[.]online/GoogleHealthChecker[.]exe |
Coinminer |
URL | hxxp://79[.]137[.]203[.]59/3nbslScQ/Login[.]php hxxp://176[.]113[.]115[.]253/b8dmsSo/Login[.]php hxxp://31337[.]hk/b8dmsSo/Login[.]php hxxp://77[.]91[.]124[.]20/store/games/Login[.]php |
Amadey |
URL | hxxp://62[.]109[.]22[.]191/Test/WindowsJsprivate/processorBaseGeneratorTemporary[.]php hxxp://ink-scape[.]online/MRD[.]exe |
DCRat |
URL | hxxp://94[.]142[.]138[.]111/software/Build-1S[.]exe hxxp://94[.]142[.]138[.]111/software/Build1[.]exe |
BlackGuard |
URL | hxxp://45[.]201[.]189[.]9:52645/i hxxp://43[.]200[.]122[.]248:57814/a-r[.]m-5[.]AXIS hxxp://3[.]39[.]9[.]144:50654/x-3[.]2-[.]AXIS hxxp://3[.]39[.]9[.]144:50654/p-p[.]c-[.]AXIS hxxp://3[.]39[.]9[.]144:50654/a-r[.]m-5[.]AXIS hxxp://3[.]39[.]9[.]144:50654/a-r[.]m-4[.]AXIS hxxp://3[.]39[.]9[.]144:50654/m-6[.]8-k[.]AXIS hxxp://3[.]39[.]9[.]144:50654/i-5[.]8-6[.]AXIS hxxp://3[.]39[.]9[.]144:50654/x-8[.]6-[.]AXIS |
Bashlite |
URL | hxxps://openaijobs[.]ru/frank[.]jpg hxxps://77[.]91[.]124[.]130/gallery/photo_570[.]exe |
RedLine Stealer |
URL | hxxp://154[.]12[.]230[.]59/234/vbc[.]exe hxxps://masherofmasters[.]cyou/chin/coco1[.]hta hxxps://masherofmasters[.]cyou/chin/coco1[.]exe |
Agent Tesla |
URL | hxxp://23[.]94[.]206[.]76/240/vbc[.]exe hxxp://23[.]94[.]206[.]76/d/QQQQ%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23qqq[.]doc |
CloudEyE |
URL | hxxps://spec[.]ir/moow/five/fre[.]php hxxp://171[.]22[.]30[.]147/305/five/fre[.]php hxxp://spec[.]ir/moow/five/fre[.]php |
LokiBot |
URL | hxxp://117[.]219[.]125[.]195:52518/Mozi[.]m | Mozi |
URL | hxxp://downlodanydesk[.]com/app/AnyDesk[.]exe | Warzone RAT |
URL | hxxps://185[.]227[.]154[.]123/async/newtab_promos hxxps://43[.]140[.]252[.]193:9090/j[.]ad hxxp://103[.]39[.]78[.]129:8080/cm hxxp://39[.]107[.]242[.]125/match hxxp://14[.]128[.]37[.]157:50001/fd/ls/ hxxp://5[.]44[.]42[.]26/ga[.]js hxxp://194[.]87[.]45[.]20/load hxxps://5[.]44[.]42[.]26/dot[.]gif hxxps://cyberwf[.]cf/cx hxxp://39[.]107[.]242[.]125:2345/j[.]ad hxxp://39[.]106[.]45[.]206:8088/visit[.]js hxxp://5[.]189[.]231[.]218:7070/j[.]ad hxxps://8[.]217[.]144[.]113/ptj hxxps://34[.]125[.]210[.]221/owa/ hxxp://1[.]117[.]71[.]245:8888/xiaodi8/ hxxp://47[.]113[.]227[.]71:7777/updates[.]rss hxxps://42[.]193[.]20[.]173/ptj hxxp://47[.]115[.]220[.]239:8011/ga[.]js hxxp://epicenergyservicestexas[.]com:8080/case[.]css hxxp://43[.]143[.]15[.]179:809/home/static/js/jquery-3[.]5[.]2[.]min[.]js hxxp://101[.]201[.]65[.]35:9999/dot[.]gif hxxps://34[.]125[.]210[.]221:4433/owa/ hxxp://91[.]213[.]50[.]110/dot[.]gif hxxp://223[.]104[.]103[.]116:8000/fwlink hxxps://45[.]81[.]243[.]125/image/ hxxp://101[.]42[.]16[.]56:8082/ptj |
Cobalt Strike |
URL | hxxps://segurostrejoya[.]com/rr/ hxxp://77[.]91[.]87[.]158/uVwm0A/iEGEXjIXZDYY hxxp://77[.]91[.]87[.]198/qfbfu/3N15hkw hxxp://91[.]193[.]43[.]98/AGvZh8C/0v2kU hxxps://unimarkme[.]com/vtne/ hxxps://detergent-jo[.]com/uaqi/ hxxps://tmhabogados[.]com/ee/ hxxps://dsquareelectronics[.]com/au/ hxxps://jasarah-business[.]com/reu/ hxxps://media360me[.]com/uait/ hxxps://thephoolmala[.]com/iqis/ hxxps://ada-soft[.]com/grl/ hxxps://foodtrucknearby[.]com/atci/ hxxps://fffoundationltd[.]com/qdai/ hxxps://astrodurgaji[.]com/attv/ hxxps://htmlcodeplay[.]com/lppu/ hxxps://tophatrealtygroup[.]com/etid/ hxxps://marylouretton[.]com/un/ hxxps://expertstheory[.]com/mm/ hxxps://digitagric[.]com/iene/ hxxps://allpropavement[.]com/aod/ hxxps://ceroerrorenmedicacion[.]com/de/ hxxps://classipie[.]com/acq/ hxxps://pilottr[.]com/ect/ hxxps://gr3publicidade[.]com/ins/ hxxps://theuaemart[.]com/aar/ hxxps://octanehardwear[.]com/evie/ hxxps://hiconnecteg[.]com/un/ hxxps://helptimize[.]com/tt/ hxxps://nhisblr[.]com/ti/ hxxps://kwarim[.]com/oai/ hxxps://whatnextweb[.]com/nm/ hxxps://freebiezz[.]com/cne/ hxxps://lonagroup[.]com/ta/ hxxps://thaiiron[.]com/ebe/ hxxps://developersakibur[.]com/saie/ hxxps://partnerlearningsolutions[.]com/tii/ hxxps://motivera360[.]com/ioe/ hxxps://gomezcompany[.]com/teri/ hxxps://garagedoorrepairspringfieldma[.]com/qs/ hxxps://asfsteelco[.]com/tsie/ hxxps://arnavarena[.]com/to/ hxxps://vladimirmesic[.]com/ivs/ hxxps://elitedasvendasonline[.]com/eul/ hxxps://nokshikuthir[.]com/ei/ hxxps://bvmpp[.]com/umq/ hxxps://taluja[.]com/ta/ hxxps://microslush[.]com/ires/ hxxps://bodybuildingsupplementzone[.]com/faei/ hxxps://henselengineeringcompany[.]com/mlcd/ hxxps://lotusmont[.]com/uts/ hxxps://holypsychic[.]com/ur/ hxxps://theharvestworldwide[.]com/rutv/ hxxps://capriphotographer[.]com/elt/ hxxps://klimabilgisi[.]com/mnrm/ hxxps://winpeforum[.]com/iqo/ hxxps://developersakibur[.]com/isqe/ hxxps://despachosotomayor[.]com/ut/ hxxps://komincapital[.]com/ds/ hxxps://ihopkcportugues[.]com/ee/ hxxps://criandoliberdade[.]com/beir/ hxxps://bugscrum[.]com/irp/ hxxps://jnssolucoes[.]com/lot/ hxxps://hkcheema[.]com/mtq/ hxxps://algarcost[.]com/au/ hxxps://sundaoriginal[.]com/btea/ hxxps://qualitycaster[.]com/sr/ hxxps://facturadigitalcr[.]com/aueu/ hxxps://eyjautomotors[.]com/ta/ hxxps://boemicoffee[.]com/ci/ hxxps://thenewepisode[.]com/tpm/ hxxps://webduratech[.]com/cn/ hxxps://dmiss[.]com/cpai/ hxxps://sahityaclasses[.]com/tmm/ hxxps://elsrtornillo[.]com/utet/ hxxps://leveconsorcios[.]com/rura/ hxxps://auditprop[.]com/lu/ hxxps://chrisbernardproperties[.]com/ic/ hxxps://talpitrucking[.]com/tq/ hxxps://techtiesibrahim[.]com/rol/ hxxps://grandsakurahotel[.]com/oauo/ hxxps://jojoexports[.]com/mi/ hxxps://ammanoperafestival[.]com/mioo/ hxxps://zacuta[.]com/es/ hxxps://transalias[.]com/ia/ hxxps://opencartar[.]com/nno/ hxxps://tacadeconsultingltd[.]com/is/ hxxps://advantagemsolutions[.]com/ns/ hxxps://theheadsoccerunblocked[.]com/lnst/ hxxps://allnewsfx[.]com/aean/ hxxps://vedrishi[.]com/ou/ hxxps://wiseflys[.]com/ront/ hxxps://instantfunnellab[.]com/sb/ hxxps://allsimpackages[.]com/noa/ hxxps://greenreset[.]com/tqui/ hxxps://pegasussourcing[.]com/ds/ hxxps://corrocoategypt[.]com/dr/ hxxps://grandsakurahotel[.]com/eo/ hxxps://kindercan[.]com/eifi/ hxxps://rubensplima[.]com/ut/ hxxps://delwanqatar[.]com/ii/ hxxps://iobaghiniexpress[.]com/aou/ hxxps://reliamedtransport[.]com/qoue/ hxxps://malpanipipes[.]com/nima/ hxxps://sna-india[.]com/naep/ hxxps://bitsvalleyilabs[.]com/tp/ hxxps://neethikathir[.]com/oemt/ hxxps://manzuryasociados[.]com/rmoi/ hxxps://origoapp[.]com/teu/ hxxps://safes-endocrine[.]com/eda/ hxxps://mangageto[.]com/upa/ hxxps://mariachiplata[.]com/peta/ hxxps://bharatmehra[.]com/sibi/ hxxps://warnmat[.]com/qiui/ hxxps://milleniuninformatica[.]com/eert/ hxxps://pricelala[.]com/coi/ hxxps://rapidroofingrepairs[.]com/qiui/ hxxps://frbodystyling[.]com/ro/ hxxps://poblanosmexicanoh[.]com/lbna/ hxxps://pgepakistan[.]com/ttmn/ hxxps://hentaipussypics[.]com/trmu/ hxxps://dentalbraces4me[.]com/susn/ hxxps://askemiratilawyers[.]com/am/ hxxps://voiceoftraders[.]com/sois/ hxxps://bsinesssoft[.]com/sirc/ hxxps://travirex[.]com/lt/ hxxps://edicionesalba[.]com/iqd/ hxxps://wevdevpro[.]com/ndeo/ hxxps://bienesraicesaldama[.]com/at/ hxxps://edsinetechnologiesltd[.]com/mq/ hxxps://sahwalaws[.]com/nno/ hxxps://medigapinsurancetraining[.]com/io/ hxxps://2oddspro[.]com/aiii/ hxxps://optimalsolutionsonline[.]com/vee/ hxxps://lesdeuxpalmiers[.]com/tum/ hxxps://agrokarti[.]com/tmeu/ hxxps://sglinternational[.]com/tape/ hxxps://udghoshdaily[.]com/oe/ hxxps://djgruas[.]com/errm/ hxxps://narlaxsolutions[.]com/tavp/ hxxps://visualimprentadigital[.]com/aeit/ hxxps://asopoker[.]com/dro/ hxxps://andes-organics[.]com/mot/ hxxps://designexpertsinc[.]com/el/ hxxps://sumeetgroup[.]com/eip/ hxxps://nnabuikeofordileandassociate[.]com/nqnu/ hxxps://amgcontable[.]com/uq/ hxxps://lipsumtechnologies[.]com/ao/ hxxps://marketsbestrading[.]com/ua/ hxxps://thebankly[.]com/aus/ hxxps://fb505[.]com/od/ hxxps://shilhaandara[.]com/mme/ hxxps://prasinosimports[.]com/at/ hxxps://fluksrv[.]com/mo/ hxxps://itstoreindia[.]com/aits/ hxxps://frey2[.]com/dmo/ hxxps://leafsols[.]com/renu/ hxxps://cupclickphoto[.]com/nem/ hxxps://algarcost[.]com/oi/ hxxps://barakatpharmacy[.]com/iopu/ hxxps://mylofn[.]com/tu/ hxxps://kda-ltd[.]com/tipp/ hxxps://saharascientific[.]com/se/ hxxps://cigarx[.]com/iqom/ hxxps://inclusiveartseducation[.]com/nt/ hxxps://lyhourgroup[.]com/oa/ hxxps://crownstarperfumes[.]com/uet/ hxxps://supportsul[.]com/ieur/ hxxps://ivorochadesigner[.]com/cfso/ hxxps://rapidwealthcreation[.]com/ua/ hxxps://gpspga[.]com/tq/ hxxps://ujwalaacademy[.]com/mtca/ hxxps://vikastyagiindore[.]com/uma/ hxxps://highness-sa[.]com/cl/ hxxps://drpetertio[.]com/ite/ hxxps://hmtdtechvn[.]com/eur/ hxxps://picc-penang[.]com/ee/ hxxps://mrityunjaytrust[.]com/lo/ hxxps://alfosoolonline[.]com/isa/ hxxps://boletisa[.]com/uia/ hxxps://noor786110[.]com/au/ hxxps://restapiproject[.]com/eirv/ hxxps://abuylike[.]com/tn/ hxxps://20mng[.]com/iapo/ hxxps://themagazinebar[.]com/uri/ hxxps://rossandmorrison[.]com/dr/ hxxps://myvision4india[.]com/uqb/ hxxps://buyoriginaldocumentonline[.]com/aenm/ hxxps://promoativas[.]com/atlo/ hxxps://gastrors[.]com/rttu/ hxxps://ecommerceoutset[.]com/phii/ hxxps://vreasolutions[.]com/tt/ hxxps://kadisse[.]com/re/ hxxps://grupoecoil[.]com/pi/ hxxps://atecwireless[.]com/qi/ hxxps://studio23salonandspa[.]com/mns/ hxxps://valampurihotel[.]com/at/ hxxps://medigapinsurancetraining[.]com/io/?non hxxps://pegasussourcing[.]com/ds/?mueansdsa hxxps://3dtimelab[.]com/lm/ hxxps://navigatetocanada[.]com/mr/ hxxps://guangzhou-arts[.]com/etc/ hxxps://radissonbluresidence[.]com/iau/ hxxps://highness-sa[.]com/is/ hxxps://ashapurarealtors[.]com/ucsa/ hxxps://slotrenchless[.]com/tr/ hxxps://workxon[.]com/sqeu/ hxxps://jv-one[.]com/ocrp/ hxxps://gpshelpline[.]com/pe/ hxxps://sudaksha[.]com/lrl/ hxxps://navigatetocanada[.]com/uqut/ hxxps://the-propsplace[.]com/rep/ hxxps://comunidadluchaymovimiento[.]com/aiu/ hxxps://arabiansandenergy[.]com/mrtu/ hxxps://mycpacord[.]com/oq/ hxxps://saltnsalt360[.]com/tuin/ hxxps://clickndpick[.]com/dau/ hxxps://andes-organics[.]com/ace/ hxxps://nidanhospital[.]com/um/ hxxps://shipwaysindonesia[.]com/at/ hxxps://ninetofab[.]com/arn/ hxxps://kda-ltd[.]com/nlti/ hxxps://ewebplace[.]com/sdu/ hxxps://wisefemy[.]com/ns/ hxxps://grandsakurahotel[.]com/iiun/ hxxps://printigano[.]com/ei/ hxxps://palmyrallc[.]com/mnit/ hxxps://wisefemy[.]com/maec/ hxxps://thecenturionhotel[.]com/suts/ hxxps://ewebplace[.]com/aq/ hxxps://jv-one[.]com/afac/ hxxps://divinehustlemedia[.]com/am/ hxxps://boemicoffee[.]com/aauc/ hxxps://lesdeuxpalmiers[.]com/eu/ hxxps://gwinatelier[.]com/sq/ hxxps://ventolinhl[.]com/odeo/ hxxps://bajarly[.]com/nos/ hxxps://trdacademy[.]com/incm/ hxxps://celdasrafael[.]com/adui/ hxxps://fingertipsacc[.]com/ampt/ hxxps://govinacademy[.]com/at/ hxxps://prasinosimports[.]com/itim/ hxxps://cema-technology[.]com/ps/ hxxps://nursingpen[.]com/rrt/ hxxps://economizeconsorcios[.]com/sas/ hxxps://bienesraicesaldama[.]com/tu/ hxxps://allnewsfx[.]com/ofsf/ hxxps://lnbmx[.]com/ti/ hxxps://chezyiammecatering[.]com/tisb/ hxxps://bespokecj[.]com/oru/ hxxps://rasa-system[.]com/lis/ hxxps://chezyiammecatering[.]com/uaqo/ hxxps://djgruas[.]com/re/ hxxps://shipwaysindonesia[.]com/uers/ hxxps://reliamedtransport[.]com/aear/ hxxps://grandsakurahotel[.]com/re/ hxxps://gprproperty[.]com/ttau/ hxxps://myretailbusiness[.]com/nu/ hxxps://graficadorevendedor[.]com/tute/ hxxps://bawabatalbadeia[.]com/eon/ hxxps://bajarly[.]com/cer/ hxxps://hackatoninmobiliario[.]com/as/ hxxps://gymlop[.]com/imn/ hxxps://rosecollectionofficial[.]com/gs/ hxxps://cupclickphoto[.]com/roco/ hxxps://delwanqatar[.]com/an/ hxxps://dcimenterprises[.]com/se/ hxxps://facturadigitalcr[.]com/lv/ hxxps://algarcost[.]com/ime/ hxxps://nortechng[.]com/ero/ hxxps://juarezpools[.]com/is/ hxxps://noormakina[.]com/vsr/ hxxps://tudinseu[.]com/onet/ hxxps://dtdkargo[.]com/qus/ hxxps://medicaretrainingonline[.]com/muuf/ hxxps://infoinsect[.]com/aeit/ hxxps://lesdeuxpalmiers[.]com/cest/ hxxps://eagleuhd[.]com/udt/ hxxps://arabiansandenergy[.]com/lit/ hxxps://libriafrica[.]com/roai/ hxxps://allpinless[.]com/rmpe/ hxxps://facturadigitalcr[.]com/oo/ hxxps://algarcost[.]com/spuv/ hxxps://careersreach[.]com/tafi/ hxxps://jnssolucoes[.]com/utgm/ hxxps://glass2grass[.]com/iif/ hxxp://79[.]137[.]248[.]163/XnQd2bL/ZV5TY1fKtTpw hxxp://91[.]193[.]43[.]101/h71/nODJLqb hxxps://workxon[.]com/uu/ hxxps://ventatravel[.]com/og/ hxxps://jv-one[.]com/lrr/ hxxps://wisefemy[.]com/disu/ hxxps://usalamatechnology[.]com/ammq/ hxxps://jeetomoney247[.]com/el/ hxxps://sociopoolindia[.]com/ce/ hxxps://skyparktravel[.]com/ia/ hxxps://libriafrica[.]com/roii/ hxxps://shipwaysindonesia[.]com/esep/ hxxps://divinehustlemedia[.]com/tseu/ hxxps://clickndpick[.]com/ml/ hxxps://bisndt[.]com/er/ hxxps://divinehustlemedia[.]com/etui/ hxxps://clickndpick[.]com/eune/ hxxps://belachennai[.]com/aol/ hxxps://balgocburada[.]com/oidr/ hxxps://bajarly[.]com/mes/ hxxps://amiriauto[.]com/tur/ |
QakBot |
URL | hxxps://xbsky[.]score[.]symposiumhaiti[.]com/gotoCheckout hxxps://klqj[.]score[.]symposiumhaiti[.]com/gotoCheckout |
FAKEUPDATES |
URL | hxxp://www[.]sdtp[.]lt/wp-admin/Aqedjsldjbw | Remcos |
URL | hxxp://load2up[.]top/setup[.]exe hxxp://ink-scape[.]online/GoogleHeaIIthChecker[.]exe hxxp://origa2up[.]top/newbuild[.]exe |
Arkei Stealer |
URL | hxxp://91[.]193[.]43[.]96/main[.]php hxxp://91[.]193[.]43[.]96/upl[.]ps1 |
NetSupportManager RAT |
URL | hxxp://77[.]73[.]131[.]239/s[.]exe | SmokeLoader |
URL | hxxps://masherofmasters[.]cyou/chin/ob1[.]exe hxxps://masherofmasters[.]cyou/chin/se1[.]exe hxxps://masherofmasters[.]cyou/chin/ka1[.]exe hxxps://masherofmasters[.]cyou/chin/no[.]exe |
MASS Logger |
URL | hxxp://144[.]126[.]194[.]85/C2H7M7P9W6G3S3N8/96692826357471468817[.]bin hxxp://138[.]197[.]175[.]219/E5B1L2R4W6K1A1F/19458864137650990516[.]bin |
RecordBreaker |
URL | hxxps://masherofmasters[.]cyou/chin/eng1[.]exe | Snake Keylogger |