サイバーリスク情報提供 Dアラート 特許取得済み

不正URLへのアクセス、不正メールの受信

メール受信した
弊社お客様
0 URLアクセスした
弊社お客様
0
2024/03/15
※2024/03/15 更新
マルウェア感染させると考えられるURLを検知(2024/03/15)
■IoC(※1)
Type: IOC: Signature:
URL hxxp://147[.]45[.]47[.]93:30487/zidan/frukt[.]exe Amadey
URL hxxps://hadogarden[.]com/wp-content/uploads/tag_one[.]exe
hxxps://bitbucket[.]org/testing-pen/test_repo/raw/7154c0cfab0b1ff7e7baf5e934f5089a5b1086c3/zec[.]exe
hxxps://nessotechbd[.]com/TEMPradius[.]exe
Stealc
URL hxxp://pervchat[.]cam:30000/afgi7dmg/excludedownload[.]exe Coinminer
URL hxxp://198[.]12[.]81[.]158/jxx/jx/tourserettulovercomeandkissmehardandsheneverknowthatiwillkissherbodytokiss___iamgreatlovertounderstandtheprcess[.]doc
hxxp://198[.]12[.]81[.]158/5506/NSS[.]exe
hxxp://91[.]92[.]246[.]241/xampp/bgo/messagelovertobegoodbecauseheisloveisgreatbeforeyoumessagetobegoodlover_____joingtloveridebecauseloetobegoodtoher[.]doc
Agent Tesla
URL hxxp://mollabhaban[.]com/assets/plugins/themepicker/current[.]exe
hxxp://193[.]233[.]132[.]197/crypted[.]exe
Lumma Stealer
URL hxxps://mauricioclopatofsky[.]tel/user/five/fre[.]php
hxxp://mauricioclopatofsky[.]tel/user/five/fre[.]php
LokiBot
URL hxxps://36[.]131[.]222[.]214/static/js/jquery-3[.]3[.]1[.]min[.]js
hxxps://59[.]80[.]47[.]124/static/js/jquery-3[.]3[.]1[.]min[.]js
hxxps://106[.]225[.]221[.]115/static/js/jquery-3[.]3[.]1[.]min[.]js
hxxps://43[.]141[.]11[.]229/static/js/jquery-3[.]3[.]1[.]min[.]js
hxxps://47[.]97[.]222[.]10:60443/dot[.]gif
hxxp://119[.]91[.]26[.]244/activity
hxxp://8[.]219[.]54[.]123/cm
hxxp://103[.]146[.]140[.]99/__utm[.]gif
hxxp://162[.]14[.]107[.]218/en_US/all[.]js
hxxps://119[.]91[.]26[.]244/ca
hxxp://1[.]94[.]52[.]236:88/ca
hxxps://xunleicloud[.]com:8443/j[.]ad
hxxp://120[.]46[.]207[.]190/visit[.]js
hxxps://docloudstorage[.]com/content/hot/y/liveupdate/
hxxp://112[.]124[.]65[.]163:8089/jquery-3[.]3[.]1[.]min[.]js
hxxps://kumbaraan[.]com/jquery-3[.]3[.]1[.]min[.]js
hxxps://154[.]92[.]19[.]29:4774/updates
hxxps://cdn-1488[.]winstate[.]cc:7443/visit[.]js
hxxps://37[.]1[.]197[.]252/cx
hxxp://172[.]210[.]42[.]227/ocsp/
hxxp://35[.]153[.]33[.]243:8000/ga[.]js
hxxp://42[.]186[.]17[.]183:8080/j[.]ad
hxxp://86[.]106[.]20[.]179:3389/kj[.]html
hxxps://107[.]174[.]228[.]79/g[.]pixel
Cobalt Strike
URL hxxp://bhkghki[.]com/search/?q=67e28dd86a5ef62a130aa5197c27d78406abdd88be4b12ebb517aa5c96bd86ed82df14d714bca5817673aa4ce8889b5e4fa9281ae978a771ea771795af8e05c645db22f31df92d8b38e316a667d307eca743ec4c2b07b52966923a678afe13c5e897
hxxp://bhkghki[.]com/search/?q=67e28dd86a5ef62a130aa5197c27d78406abdd88be4b12eab517aa5c96bd86ee928e48805a8bbc896c58e713bc90c91936b5281fc235a925ed3e04d6bd974a95129070b616e96cc92be20ea778c255bbe258b90d3b4eed3233d1626a8ff810c0eb94983eca6d
hxxp://bufjqcb[.]com/search/?q=67e28dd8655ba479120da84d7c27d78406abdd88be4b12ebb517aa5c96bd86ed82df14d714bca5817673aa4fe8889b5e4fa9281ae978a071ea771795af8e05c645db22f31df92d8838ed12a666d307eca743ec4c2b07b52966923a678afe13c5e895
hxxp://bufjqcb[.]com/search/?q=67e28dd8655ba479120da84d7c27d78406abdd88be4b12eab517aa5c96bd86e890874f885a8bbc896c58e713bc90c91a36b5281fc235a925ed3e03d6bd974a95129070b616e96cc92be20ea478cc51bbe358b90d3b4eed3233d1626a8ff810c0eb94983eca6f
hxxp://nemo[.]dofuly[.]info/data/pdf/june[.]exe
hxxp://slim[.]dofuly[.]info/data/pdf/may[.]exe
hxxp://borxiqr[.]com/search/?q=67e28dd83d5fa62d1358fa4d7c27d78406abdd88be4b12ebb517aa5c96bd86ed82df14d714bca5817673aa4de8889b5e4fa9281ae978ff71ea771795af8e05c645db22f31df92d8b38e316a667d307eca743ec4c2b07b52966923a678afb17c4e797
hxxp://dtuoyom[.]info/search/?q=67e28dd83a5da32a155afd1b7c27d78406abdd88be4b12ebb517aa5c96bd86ed82df14d714bca5817673aa4ce8889b5e4fa9281ae978a271ea771795af8e05c645db22f31df92d8838ed12a666d307eca743ec4c2b07b52966923a678afb17c4e79d
hxxp://aizwfdi[.]ru/search/?q=67e28dd86554fa2a495aa4197c27d78406abdd88be4b12ebb517aa5c96bd86ed82df14d714bca5817673aa4de8889b5e4fa9281ae978a071ea771795af8e05c646db22f31df92d8b38e316a667d307eca743ec4c2b07b52966923a678afb17c4e896
hxxp://aizwfdi[.]ru/search/?q=67e28dd86554fa2a495aa4197c27d78406abdd88be4b12eab517aa5c96bd86ee9c864b855a8bbc896c58e713bc90c91836b5281fc235a925ed3e03d6bd974a95129070b615e96cc92be20ea778c255bbe258b90d3b4eed3233d1626a8ff810c0eb919c3fca6c
hxxp://bfbkncr[.]com/search/?q=67e28dd86b5ea42a430af91a7c27d78406abdd88be4b12ebb517aa5c96bd86ed82df14d714bca5817673aa4ce8889b5e4fa9281ae978a771ea771795af8e05c646db22f31df92d8838ed12a666d307eca743ec4c2b07b52966923a678afb17c4e897
hxxp://bfbkncr[.]com/search/?q=67e28dd86b5ea42a430af91a7c27d78406abdd88be4b12eab517aa5c96bd86ef91854e815a8bbc896c58e713bc90c91936b5281fc235a925ed3e04d6bd974a95129070b615e96cc92be20ea478cc51bbe358b90d3b4eed3233d1626a8ff810c0eb919c3fca6d
hxxp://ezpooyv[.]ua/search/?q=67e28dd83d5fa62d1358fa4d7c27d78406abdd88be4b12ebb517aa5c96bd86ed82df14d714bca5817673aa4de8889b5e4fa9281ae978ff71ea771795af8e05c645db22f31df92d8b38e316a667d307eca743ec4c2b07b52966923a678afb14c2ed95
hxxp://csajzls[.]net/search/?q=67e28dd86c0ea7794406f94d7c27d78406abdd88be4b12ebb517aa5c96bd86ed82df14d714bca5817673aa44e8889b5e4fa9281ae978f671ea771795af8e05c645db22f31df92d8838ed12a666d307eca743ec4c2b07b52966923a678afb14c2ee94
hxxp://csajzls[.]net/search/?q=67e28dd86c0ea7794406f94d7c27d78406abdd88be4b12eab517aa5c96bd86e99d8245815a8bbc896c58e713bc90c91136b5281fc235a925ed3e55d6bd974a95129070b616e96cc92be20ea478cc51bbe358b90d3b4eed3233d1626a8ff810c0eb919f39cc6e
hxxp://bnjkrnv[.]com/search/?q=67e28dd83d5fa62d1358fa4d7c27d78406abdd88be4b12ebb517aa5c96bd86ed82df14d714bca5817673aa4de8889b5e4fa9281ae978ff71ea771795af8e05c645db22f31df92d8b38e316a667d307eca743ec4c2b07b52966923a678afb15c0ed96
hxxp://bnjkrnv[.]com/search/?q=67e28dd83d5fa62d1358fa4d7c27d78406abdd88be4b12eab517aa5c96bd86ee95874c815a8bbc896c58e713bc90c91836b5281fc235a925ed3e5cd6bd974a95129070b616e96cc92be20ea778c255bbe258b90d3b4eed3233d1626a8ff810c0eb919e3bcf6c
hxxp://bgefosx[.]com/search/?q=67e28dd83a5da32a155afd1b7c27d78406abdd88be4b12ebb517aa5c96bd86ed82df14d714bca5817673aa4ce8889b5e4fa9281ae978a271ea771795af8e05c645db22f31df92d8838ed12a666d307eca743ec4c2b07b52966923a678afb15c0ec9d
hxxp://dtlbdhd[.]info/search/?q=67e28dd86d0ef17b460ef9177c27d78406abdd88be4b12ebb517aa5c96bd86ed82df14d714bca5817673aa45e8889b5e4fa9281ae978f671ea771795af8e05c645db22f31df92d8b38e316a667d307eca743ec4c2b07b52966923a678afa13c1ee9d
hxxp://dtlbdhd[.]info/search/?q=67e28dd86d0ef17b460ef9177c27d78406abdd88be4b12eab517aa5c96bd86eb968449835a8bbc896c58e713bc90c91036b5281fc235a925ed3e55d6bd974a95129070b616e96cc92be20ea778c255bbe258b90d3b4eed3233d1626a8ff810c0eb90983acc67
hxxp://bodfuue[.]com/search/?q=67e28dd86f5af1211209a81b7c27d78406abdd88be4b12ebb517aa5c96bd86ed82df14d714bca5817673aa48e8889b5e4fa9281ae978f071ea771795af8e05c645db22f31df92d8838ed12a666d307eca743ec4c2b07b52966923a678afa13c1ed94
hxxp://bodfuue[.]com/search/?q=67e28dd86f5af1211209a81b7c27d78406abdd88be4b12eab517aa5c96bd86e8978245825a8bbc896c58e713bc90c91d36b5281fc235a925ed3e53d6bd974a95129070b616e96cc92be20ea478cc51bbe358b90d3b4eed3233d1626a8ff810c0eb90983acf6e
Socks5 Systemz
URL hxxp://122[.]114[.]10[.]11:8082/gup[.]xml
hxxp://122[.]114[.]10[.]11:8082/GUP[.]exe
hxxp://122[.]114[.]10[.]11:8082/update[.]png
hxxp://122[.]114[.]10[.]11:8082/GodPotato-NET4[.]exe
hxxp://122[.]114[.]10[.]11:8082/libcurl[.]dll
hxxp://122[.]114[.]225[.]100:8082/gup[.]xml
hxxp://122[.]114[.]225[.]100:8082/GUP[.]exe
hxxp://122[.]114[.]225[.]100:8082/update[.]png
hxxp://122[.]114[.]225[.]100:8082/GodPotato-NET4[.]exe
hxxp://122[.]114[.]225[.]100:8082/libcurl[.]dll
hxxp://124[.]106[.]197[.]167/browser[.]exe
hxxp://124[.]106[.]197[.]167/Valhalla-Keygen[.]exe
hxxp://124[.]106[.]197[.]167/installer[.]txt
hxxp://124[.]106[.]197[.]167/hg[.]pdf
hxxp://124[.]106[.]197[.]167/defeat[.]exe
hxxp://124[.]106[.]197[.]167/demon[.]exe
hxxp://124[.]106[.]197[.]167/reverse[.]exe
hxxp://124[.]106[.]197[.]167/defeat[.]rar
hxxp://124[.]106[.]197[.]167/svchost[.]txt
hxxp://122[.]114[.]192[.]234:8082/GUP[.]exe
hxxp://122[.]114[.]192[.]234:8082/gup[.]xml
hxxp://122[.]114[.]192[.]234:8082/GodPotato-NET4[.]exe
hxxp://122[.]114[.]192[.]234:8082/libcurl[.]dll
hxxp://122[.]114[.]192[.]234:8082/update[.]png
Havoc
URL hxxp://172[.]245[.]208[.]34/mylatestoriginromania[.]txt OriginLogger
URL hxxp://193[.]233[.]252[.]242/hidakibest[.]sparc
hxxp://193[.]233[.]252[.]242/hidakibest[.]ppc
hxxp://193[.]233[.]252[.]242/hidakibest[.]arm4
hxxp://193[.]233[.]252[.]242/hidakibest[.]mpsl
Bashlite
URL hxxps://mzv[.]round[.]fishingreelinvestment[.]com/editContent
hxxps://tiw[.]round[.]fishingreelinvestment[.]com/editContent
FAKEUPDATES
URL hxxp://1[.]92[.]90[.]232:8080/Xzserver[.]exe Ghost RAT
URL hxxp://91[.]220[.]109[.]66/eternalgeocentral[.]php DCRat
URL hxxps://yourunitedlaws[.]com/mrD/4462/ Pikabot
※1「i-FILTER」アクセスログを検索し端末を特定してください 不要なアクセスを避けるため、一部変更しております。 ■製品対応状況(※2) ▽i-FILTER(※3) ・[脅威情報サイト]カテゴリでブロック可能 ※2 ブロックの可否は各製品の設定によるため、実際の結果はアクセスログを参照してください。 ※3 暗号化された通信の場合は、SSL Adapterの設定を「利用」にする必要があります。
イベント・セミナー情報