不正URLへのアクセス、不正メールの受信
-
メール受信した
弊社お客様0社 URLアクセスした
弊社お客様0社 -
2024/03/15
※2024/03/15 更新
マルウェア感染させると考えられるURLを検知(2024/03/15)
■IoC(※1)
| Type: | IOC: | Signature: |
|---|---|---|
| URL | hxxp://147[.]45[.]47[.]93:30487/zidan/frukt[.]exe | Amadey |
| URL | hxxps://hadogarden[.]com/wp-content/uploads/tag_one[.]exe hxxps://bitbucket[.]org/testing-pen/test_repo/raw/7154c0cfab0b1ff7e7baf5e934f5089a5b1086c3/zec[.]exe hxxps://nessotechbd[.]com/TEMPradius[.]exe |
Stealc |
| URL | hxxp://pervchat[.]cam:30000/afgi7dmg/excludedownload[.]exe | Coinminer |
| URL | hxxp://198[.]12[.]81[.]158/jxx/jx/tourserettulovercomeandkissmehardandsheneverknowthatiwillkissherbodytokiss___iamgreatlovertounderstandtheprcess[.]doc hxxp://198[.]12[.]81[.]158/5506/NSS[.]exe hxxp://91[.]92[.]246[.]241/xampp/bgo/messagelovertobegoodbecauseheisloveisgreatbeforeyoumessagetobegoodlover_____joingtloveridebecauseloetobegoodtoher[.]doc |
Agent Tesla |
| URL | hxxp://mollabhaban[.]com/assets/plugins/themepicker/current[.]exe hxxp://193[.]233[.]132[.]197/crypted[.]exe |
Lumma Stealer |
| URL | hxxps://mauricioclopatofsky[.]tel/user/five/fre[.]php hxxp://mauricioclopatofsky[.]tel/user/five/fre[.]php |
LokiBot |
| URL | hxxps://36[.]131[.]222[.]214/static/js/jquery-3[.]3[.]1[.]min[.]js hxxps://59[.]80[.]47[.]124/static/js/jquery-3[.]3[.]1[.]min[.]js hxxps://106[.]225[.]221[.]115/static/js/jquery-3[.]3[.]1[.]min[.]js hxxps://43[.]141[.]11[.]229/static/js/jquery-3[.]3[.]1[.]min[.]js hxxps://47[.]97[.]222[.]10:60443/dot[.]gif hxxp://119[.]91[.]26[.]244/activity hxxp://8[.]219[.]54[.]123/cm hxxp://103[.]146[.]140[.]99/__utm[.]gif hxxp://162[.]14[.]107[.]218/en_US/all[.]js hxxps://119[.]91[.]26[.]244/ca hxxp://1[.]94[.]52[.]236:88/ca hxxps://xunleicloud[.]com:8443/j[.]ad hxxp://120[.]46[.]207[.]190/visit[.]js hxxps://docloudstorage[.]com/content/hot/y/liveupdate/ hxxp://112[.]124[.]65[.]163:8089/jquery-3[.]3[.]1[.]min[.]js hxxps://kumbaraan[.]com/jquery-3[.]3[.]1[.]min[.]js hxxps://154[.]92[.]19[.]29:4774/updates hxxps://cdn-1488[.]winstate[.]cc:7443/visit[.]js hxxps://37[.]1[.]197[.]252/cx hxxp://172[.]210[.]42[.]227/ocsp/ hxxp://35[.]153[.]33[.]243:8000/ga[.]js hxxp://42[.]186[.]17[.]183:8080/j[.]ad hxxp://86[.]106[.]20[.]179:3389/kj[.]html hxxps://107[.]174[.]228[.]79/g[.]pixel |
Cobalt Strike |
| URL | hxxp://bhkghki[.]com/search/?q=67e28dd86a5ef62a130aa5197c27d78406abdd88be4b12ebb517aa5c96bd86ed82df14d714bca5817673aa4ce8889b5e4fa9281ae978a771ea771795af8e05c645db22f31df92d8b38e316a667d307eca743ec4c2b07b52966923a678afe13c5e897 hxxp://bhkghki[.]com/search/?q=67e28dd86a5ef62a130aa5197c27d78406abdd88be4b12eab517aa5c96bd86ee928e48805a8bbc896c58e713bc90c91936b5281fc235a925ed3e04d6bd974a95129070b616e96cc92be20ea778c255bbe258b90d3b4eed3233d1626a8ff810c0eb94983eca6d hxxp://bufjqcb[.]com/search/?q=67e28dd8655ba479120da84d7c27d78406abdd88be4b12ebb517aa5c96bd86ed82df14d714bca5817673aa4fe8889b5e4fa9281ae978a071ea771795af8e05c645db22f31df92d8838ed12a666d307eca743ec4c2b07b52966923a678afe13c5e895 hxxp://bufjqcb[.]com/search/?q=67e28dd8655ba479120da84d7c27d78406abdd88be4b12eab517aa5c96bd86e890874f885a8bbc896c58e713bc90c91a36b5281fc235a925ed3e03d6bd974a95129070b616e96cc92be20ea478cc51bbe358b90d3b4eed3233d1626a8ff810c0eb94983eca6f hxxp://nemo[.]dofuly[.]info/data/pdf/june[.]exe hxxp://slim[.]dofuly[.]info/data/pdf/may[.]exe hxxp://borxiqr[.]com/search/?q=67e28dd83d5fa62d1358fa4d7c27d78406abdd88be4b12ebb517aa5c96bd86ed82df14d714bca5817673aa4de8889b5e4fa9281ae978ff71ea771795af8e05c645db22f31df92d8b38e316a667d307eca743ec4c2b07b52966923a678afb17c4e797 hxxp://dtuoyom[.]info/search/?q=67e28dd83a5da32a155afd1b7c27d78406abdd88be4b12ebb517aa5c96bd86ed82df14d714bca5817673aa4ce8889b5e4fa9281ae978a271ea771795af8e05c645db22f31df92d8838ed12a666d307eca743ec4c2b07b52966923a678afb17c4e79d hxxp://aizwfdi[.]ru/search/?q=67e28dd86554fa2a495aa4197c27d78406abdd88be4b12ebb517aa5c96bd86ed82df14d714bca5817673aa4de8889b5e4fa9281ae978a071ea771795af8e05c646db22f31df92d8b38e316a667d307eca743ec4c2b07b52966923a678afb17c4e896 hxxp://aizwfdi[.]ru/search/?q=67e28dd86554fa2a495aa4197c27d78406abdd88be4b12eab517aa5c96bd86ee9c864b855a8bbc896c58e713bc90c91836b5281fc235a925ed3e03d6bd974a95129070b615e96cc92be20ea778c255bbe258b90d3b4eed3233d1626a8ff810c0eb919c3fca6c hxxp://bfbkncr[.]com/search/?q=67e28dd86b5ea42a430af91a7c27d78406abdd88be4b12ebb517aa5c96bd86ed82df14d714bca5817673aa4ce8889b5e4fa9281ae978a771ea771795af8e05c646db22f31df92d8838ed12a666d307eca743ec4c2b07b52966923a678afb17c4e897 hxxp://bfbkncr[.]com/search/?q=67e28dd86b5ea42a430af91a7c27d78406abdd88be4b12eab517aa5c96bd86ef91854e815a8bbc896c58e713bc90c91936b5281fc235a925ed3e04d6bd974a95129070b615e96cc92be20ea478cc51bbe358b90d3b4eed3233d1626a8ff810c0eb919c3fca6d hxxp://ezpooyv[.]ua/search/?q=67e28dd83d5fa62d1358fa4d7c27d78406abdd88be4b12ebb517aa5c96bd86ed82df14d714bca5817673aa4de8889b5e4fa9281ae978ff71ea771795af8e05c645db22f31df92d8b38e316a667d307eca743ec4c2b07b52966923a678afb14c2ed95 hxxp://csajzls[.]net/search/?q=67e28dd86c0ea7794406f94d7c27d78406abdd88be4b12ebb517aa5c96bd86ed82df14d714bca5817673aa44e8889b5e4fa9281ae978f671ea771795af8e05c645db22f31df92d8838ed12a666d307eca743ec4c2b07b52966923a678afb14c2ee94 hxxp://csajzls[.]net/search/?q=67e28dd86c0ea7794406f94d7c27d78406abdd88be4b12eab517aa5c96bd86e99d8245815a8bbc896c58e713bc90c91136b5281fc235a925ed3e55d6bd974a95129070b616e96cc92be20ea478cc51bbe358b90d3b4eed3233d1626a8ff810c0eb919f39cc6e hxxp://bnjkrnv[.]com/search/?q=67e28dd83d5fa62d1358fa4d7c27d78406abdd88be4b12ebb517aa5c96bd86ed82df14d714bca5817673aa4de8889b5e4fa9281ae978ff71ea771795af8e05c645db22f31df92d8b38e316a667d307eca743ec4c2b07b52966923a678afb15c0ed96 hxxp://bnjkrnv[.]com/search/?q=67e28dd83d5fa62d1358fa4d7c27d78406abdd88be4b12eab517aa5c96bd86ee95874c815a8bbc896c58e713bc90c91836b5281fc235a925ed3e5cd6bd974a95129070b616e96cc92be20ea778c255bbe258b90d3b4eed3233d1626a8ff810c0eb919e3bcf6c hxxp://bgefosx[.]com/search/?q=67e28dd83a5da32a155afd1b7c27d78406abdd88be4b12ebb517aa5c96bd86ed82df14d714bca5817673aa4ce8889b5e4fa9281ae978a271ea771795af8e05c645db22f31df92d8838ed12a666d307eca743ec4c2b07b52966923a678afb15c0ec9d hxxp://dtlbdhd[.]info/search/?q=67e28dd86d0ef17b460ef9177c27d78406abdd88be4b12ebb517aa5c96bd86ed82df14d714bca5817673aa45e8889b5e4fa9281ae978f671ea771795af8e05c645db22f31df92d8b38e316a667d307eca743ec4c2b07b52966923a678afa13c1ee9d hxxp://dtlbdhd[.]info/search/?q=67e28dd86d0ef17b460ef9177c27d78406abdd88be4b12eab517aa5c96bd86eb968449835a8bbc896c58e713bc90c91036b5281fc235a925ed3e55d6bd974a95129070b616e96cc92be20ea778c255bbe258b90d3b4eed3233d1626a8ff810c0eb90983acc67 hxxp://bodfuue[.]com/search/?q=67e28dd86f5af1211209a81b7c27d78406abdd88be4b12ebb517aa5c96bd86ed82df14d714bca5817673aa48e8889b5e4fa9281ae978f071ea771795af8e05c645db22f31df92d8838ed12a666d307eca743ec4c2b07b52966923a678afa13c1ed94 hxxp://bodfuue[.]com/search/?q=67e28dd86f5af1211209a81b7c27d78406abdd88be4b12eab517aa5c96bd86e8978245825a8bbc896c58e713bc90c91d36b5281fc235a925ed3e53d6bd974a95129070b616e96cc92be20ea478cc51bbe358b90d3b4eed3233d1626a8ff810c0eb90983acf6e |
Socks5 Systemz |
| URL | hxxp://122[.]114[.]10[.]11:8082/gup[.]xml hxxp://122[.]114[.]10[.]11:8082/GUP[.]exe hxxp://122[.]114[.]10[.]11:8082/update[.]png hxxp://122[.]114[.]10[.]11:8082/GodPotato-NET4[.]exe hxxp://122[.]114[.]10[.]11:8082/libcurl[.]dll hxxp://122[.]114[.]225[.]100:8082/gup[.]xml hxxp://122[.]114[.]225[.]100:8082/GUP[.]exe hxxp://122[.]114[.]225[.]100:8082/update[.]png hxxp://122[.]114[.]225[.]100:8082/GodPotato-NET4[.]exe hxxp://122[.]114[.]225[.]100:8082/libcurl[.]dll hxxp://124[.]106[.]197[.]167/browser[.]exe hxxp://124[.]106[.]197[.]167/Valhalla-Keygen[.]exe hxxp://124[.]106[.]197[.]167/installer[.]txt hxxp://124[.]106[.]197[.]167/hg[.]pdf hxxp://124[.]106[.]197[.]167/defeat[.]exe hxxp://124[.]106[.]197[.]167/demon[.]exe hxxp://124[.]106[.]197[.]167/reverse[.]exe hxxp://124[.]106[.]197[.]167/defeat[.]rar hxxp://124[.]106[.]197[.]167/svchost[.]txt hxxp://122[.]114[.]192[.]234:8082/GUP[.]exe hxxp://122[.]114[.]192[.]234:8082/gup[.]xml hxxp://122[.]114[.]192[.]234:8082/GodPotato-NET4[.]exe hxxp://122[.]114[.]192[.]234:8082/libcurl[.]dll hxxp://122[.]114[.]192[.]234:8082/update[.]png |
Havoc |
| URL | hxxp://172[.]245[.]208[.]34/mylatestoriginromania[.]txt | OriginLogger |
| URL | hxxp://193[.]233[.]252[.]242/hidakibest[.]sparc hxxp://193[.]233[.]252[.]242/hidakibest[.]ppc hxxp://193[.]233[.]252[.]242/hidakibest[.]arm4 hxxp://193[.]233[.]252[.]242/hidakibest[.]mpsl |
Bashlite |
| URL | hxxps://mzv[.]round[.]fishingreelinvestment[.]com/editContent hxxps://tiw[.]round[.]fishingreelinvestment[.]com/editContent |
FAKEUPDATES |
| URL | hxxp://1[.]92[.]90[.]232:8080/Xzserver[.]exe | Ghost RAT |
| URL | hxxp://91[.]220[.]109[.]66/eternalgeocentral[.]php | DCRat |
| URL | hxxps://yourunitedlaws[.]com/mrD/4462/ | Pikabot |







