不正URLへのアクセス、不正メールの受信
-
メール受信した
弊社お客様0社 URLアクセスした
弊社お客様0社 -
2024/04/19
※2024/04/19 更新
マルウェア感染させると考えられるURLを検知(2024/04/19)
■IoC(※1)
Type: | IOC: | Signature: |
---|---|---|
URL | hxxps://124[.]222[.]173[.]133/jquery-3[.]3[.]1[.]min[.]js hxxp://209[.]141[.]57[.]75/test hxxps://43[.]138[.]222[.]123/fwlink hxxp://195[.]181[.]245[.]38:7966/QTUc hxxp://195[.]181[.]245[.]38:7966/pixel[.]gif hxxps://121[.]41[.]50[.]152/en_US/all[.]js hxxp://121[.]41[.]50[.]152/pixel hxxp://43[.]143[.]168[.]206:81/jquerys-6[.]3[.]5[.]max[.]js |
Cobalt Strike |
URL | hxxp://topgamecheats[.]dev/amadey[.]exe hxxp://topgamecheats[.]dev/fud_new[.]exe hxxp://163[.]5[.]215[.]125/Amzey[.]exe hxxp://147[.]45[.]47[.]102:57893/hera/amadka[.]exe |
Amadey |
URL | hxxps://tecklardagasda2[.]shop/ZDQyN2NmOGEZOTIK/ hxxps://maraksatandas13[.]shop/ZDQyN2NmOGEZOTIK/ hxxps://teckmarakbads2[.]shop/ZDQyN2NmOGEZOTIK/ |
Coper |
URL | hxxp://94[.]156[.]8[.]161/skid[.]arm6 hxxp://94[.]156[.]8[.]161/skid[.]sparc hxxp://94[.]156[.]8[.]161/skid[.]arm4 hxxp://94[.]156[.]8[.]161/skid[.]arm5 hxxp://94[.]156[.]8[.]161/skid[.]mpsl hxxp://94[.]156[.]8[.]161/skid[.]mips hxxp://92[.]249[.]48[.]38/rebirth[.]arm4 hxxp://92[.]249[.]48[.]38/rebirth[.]i686 |
Bashlite |
URL | hxxps://covid19help[.]top/JBNvj66BwYU3yCv[.]scr hxxps://dukeenergyltd[.]top/H8w3nxJQ4Gya5ED[.]scr hxxp://trailers24[.]eu/GH[.]bin hxxps://covid19help[.]top/MmxW3NwsZw7f1zs[.]scr hxxp://192[.]3[.]216[.]151/xlamlikeiamverymuchwithentirethingslovertokissthegreatlogswhichcomingotmewithenitrelove__okmyconmennytokiss[.]doc hxxps://api[.]telegram[.]org/bot6369080394:AAFEItWVNdHHyWWLHTZ_gGRSeWMYewCCU2w/ hxxps://drive[.]google[.]com/uc?export=download&id=1NvbKMbrPZMDLSvMx1GFj0nyLRJLEqW hxxps://mhsonsco[.]com/wp-content/eclat[.]txt hxxps://paste[.]ee/d/5ASfs |
Agent Tesla |
URL | hxxps://universalmovies[.]top/o9RbXKF6ZJDK949[.]scr hxxps://paste[.]ee/d/W8owz hxxps://fanconom[.]shop/grace/mac[.]txt hxxps://fanconom[.]shop/grace/gf[.]txt hxxps://onedrive[.]live[.]com/download?resid=4E6F63F4C3C86180%21112&authkey=!AJi85Fsyq6pgUBw hxxps://covid19help[.]top/0pORecqxeDazSCU[.]scr |
Formbook |
URL | hxxp://23[.]95[.]60[.]75/80/HMF[.]txt hxxp://23[.]95[.]60[.]75/80/hnm/ireallywantakissfrommywifesheisverybeautifulgirlwhoilovealotsheisreallybeautifulgirleveriseenshe___ismybabygirlmylove[.]doc hxxp://23[.]95[.]60[.]75/xampp/hnv/EXAMPLEOFIMAGE[.]JPEG hxxp://103[.]198[.]26[.]25/2020/HJC[.]exe |
Remcos |
URL | hxxp://87[.]121[.]105[.]163/Storvesirs43[.]psm hxxp://94[.]156[.]79[.]64/hiyIlO235[.]bin hxxp://94[.]156[.]79[.]64/Agterskibe[.]fla hxxp://94[.]156[.]79[.]64/Udemiljets[.]pfm hxxp://87[.]121[.]105[.]163/YSnpkrCwWalJFSpN146[.]bin hxxp://87[.]121[.]105[.]163/Flyvnings[.]u32 hxxps://drive[.]google[.]com/uc?export=download&id=1h1Hc1TR1ClhrKoTyhz4tNgmZew2GoSnw hxxp://87[.]121[.]105[.]184/Gleamer[.]mix hxxp://87[.]121[.]105[.]184/yheFuLEFhskyHXyKesmPV163[.]bin hxxp://nitio[.]com/x2/Tartare[.]chm hxxp://94[.]156[.]79[.]64/dcCkyPzTem152[.]bin hxxps://kraljevikonaci[.]rs/tjpemvtKauOPkJFzMDNQPAMHdEhX63[.]bin hxxps://ricohltd[.]top/PIoDroeALMbPB243[.]bin hxxp://192[.]3[.]216[.]151/Gorps112[.]pcx hxxp://192[.]3[.]216[.]151/nlwwHQDzv162[.]bin hxxp://94[.]156[.]79[.]64/cMkeRMn30[.]bin hxxp://94[.]156[.]79[.]64/Rkenstaten[.]dsp hxxp://87[.]121[.]105[.]184/GTFcpD82[.]bin hxxp://87[.]121[.]105[.]184/Fodgngerovergangs[.]prm hxxp://87[.]121[.]105[.]184/Afmagringer[.]xsn hxxp://87[.]121[.]105[.]163/vhhJQWfiJN142[.]bin hxxp://87[.]121[.]105[.]163/sssSAXCCU156[.]bin hxxp://87[.]121[.]105[.]163/Licences[.]ttf hxxp://87[.]121[.]105[.]163/Taktreguleringsaftaler[.]dwp hxxp://87[.]121[.]105[.]163/Pseudoisomer27[.]rar hxxp://192[.]3[.]216[.]151/Signposting13[.]sea hxxp://192[.]3[.]216[.]151/sJyXpDSUBeZH78[.]bin |
CloudEyE |
URL | hxxp://bishopberrian[.]com/1[.]exe hxxps://pasteio[.]com/raw/xOsL4tr8v5CV hxxps://pasteio[.]com/raw/xR2Q067LLE5e hxxps://pasteio[.]com/raw/xwV5XgmAPXkQ hxxps://pasteio[.]com/raw/x6uMfEQ0i3XB hxxps://bishopberrian[.]com/1[.]exe hxxps://pasteio[.]com/raw/xjvkPdr0BkzL hxxps://pasteio[.]com/raw/x7RZVIWaDKb5 |
NjRAT |
URL | hxxp://94[.]156[.]66[.]198/x | Coinminer |
URL | hxxp://103[.]42[.]31[.]29:808/linux_mips_softfloat hxxp://103[.]42[.]31[.]29:808/linux_386 hxxp://103[.]42[.]31[.]29:808/linux_mips hxxp://103[.]42[.]31[.]29:808/linux_amd64 hxxp://103[.]42[.]31[.]29:808/linux_arm6 hxxp://103[.]42[.]31[.]29:808/linux_mipsel hxxp://103[.]42[.]31[.]29:808/linux_mips64 hxxp://103[.]42[.]31[.]29:808/linux_mips64_softfloat hxxp://103[.]42[.]31[.]29:808/linux_mipsel_softfloat hxxp://103[.]42[.]31[.]29:808/linux_arm5 hxxp://103[.]42[.]31[.]29:808/linux_mips64el_softfloat hxxp://103[.]42[.]31[.]29:808/linux_mips64el hxxp://103[.]42[.]31[.]29:808/linux_arm64 hxxp://103[.]42[.]31[.]29:808/linux_ppc64 hxxp://103[.]42[.]31[.]29:808/linux_ppc64el hxxp://103[.]42[.]31[.]29:808/linux_arm7 |
Kaiji |
URL | hxxp://154[.]9[.]235[.]76/ccf[.]exe hxxp://bzwl888[.]sbs/ccf[.]exe |
Nitol |
URL | hxxps://upd5[.]pro/update/02[.]dll hxxps://45[.]77[.]68[.]166/update/02[.]dll hxxp://45[.]77[.]68[.]166/update/02[.]dll |
QakBot |
URL | hxxp://public-ftp[.]com/img/logo2[.]jpg hxxps://flowers4world[.]shop/current[.]exe hxxp://public-ftp[.]com/img/logo[.]jpg hxxps://github[.]com/pbhhdf/12/raw/main/keepvid-pro_full2578[.]exe |
Lumma Stealer |
URL | hxxp://bn[.]networkbn[.]click/telnet hxxp://bn[.]networkbn[.]click/w[.]sh hxxp://bn[.]networkbn[.]click/wget[.]sh hxxp://103[.]167[.]88[.]226/wget[.]sh hxxp://103[.]167[.]88[.]226/w[.]sh hxxp://103[.]167[.]88[.]226/telnet hxxp://103[.]167[.]88[.]226/and hxxp://103[.]167[.]88[.]226/bot[.]arm7 hxxp://103[.]167[.]88[.]226/bot[.]m68k hxxp://103[.]167[.]88[.]226/debug[.]dbg hxxp://103[.]167[.]88[.]226/bot[.]sh4 hxxp://103[.]167[.]88[.]226/bot[.]x86 hxxp://103[.]167[.]88[.]226/bot[.]mpsl hxxp://103[.]167[.]88[.]226/bot[.]arm hxxp://103[.]167[.]88[.]226/bot[.]ppc hxxp://103[.]167[.]88[.]226/bot[.]arm5 hxxp://103[.]167[.]88[.]226/bot[.]arm6 hxxp://103[.]167[.]88[.]226/a hxxp://103[.]167[.]88[.]226/c[.]sh hxxp://45[.]128[.]232[.]236/bot[.]x86_64 hxxp://45[.]128[.]232[.]236/bot[.]sh4 hxxp://45[.]128[.]232[.]236/bot[.]spc hxxp://45[.]128[.]232[.]236/bot[.]arm hxxp://45[.]128[.]232[.]236/bot[.]ppc hxxp://45[.]128[.]232[.]236/bot[.]arm7 hxxp://45[.]128[.]232[.]236/bot[.]arm6 hxxp://45[.]128[.]232[.]236/bot[.]mips hxxp://45[.]128[.]232[.]236/bot[.]m68k hxxp://45[.]128[.]232[.]236/bot[.]mpsl hxxp://45[.]128[.]232[.]236/bot[.]x86 hxxp://45[.]128[.]232[.]236/bot[.]arm5 |
MooBot |
URL | hxxps://pasteio[.]com/raw/xmrhZ7VhlJjD | VoidRAT |
URL | hxxps://bmp[.]register[.]arpsychotherapy[.]com/editContent hxxps://ypoh[.]register[.]arpsychotherapy[.]com/editContent hxxps://mucp[.]register[.]arpsychotherapy[.]com/editContent |
FAKEUPDATES |
URL | hxxp://0had[.]com/stage hxxp://93[.]190[.]140[.]76/factura hxxp://0had[.]com/DisabilityCharge[.]exe hxxp://91[.]92[.]253[.]126/Downloads/Factura_SA161[.]pdf[.]lnk hxxp://91[.]92[.]253[.]126/Downloads/SA161[.]pdf[.]lnk hxxp://93[.]190[.]140[.]76/DisabilityCharge[.]exe |
Rhadamanthys |
URL | hxxps://transfer[.]adttemp[.]com[.]br/get/dOl98/shortcut[.]exe hxxps://pasteio[.]com/raw/xrBUD0WWN4La hxxps://pasteio[.]com/raw/xXQ39a5f9EJP hxxp://esdjasd[.]maxkrnldc[.]online/L1nc0In[.]php |
DCRat |
URL | hxxps://taxdocview[.]com/download/Leon-1040Documents[.]zip | XWorm |
URL | hxxps://beautyservicenearme[.]com/data[.]php?8838 hxxps://onesmartiptv[.]com/help/per[.]php |
NetSupportManager RAT |
URL | hxxp://77[.]221[.]151[.]32/server/ww12/AppGate2103v01[.]exe | PrivateLoader |
URL | hxxps://power[.]crazyfigs[.]top/style/070[.]exe hxxp://bnqiocp[.]com/search/?q=67e28dd86554fa2a495aa4197c27d78406abdd88be4b12ebb517aa5c96bd86ed82df14d714bca5817673aa4de8889b5e4fa9281ae978a071ea771795af8e05c644db22f31df92d8b38e316a667d307eca743ec4c2b07b52966923a648af812c5e696 hxxp://bnqiocp[.]com/search/?q=67e28dd86554fa2a495aa4197c27d78406abdd88be4b12eab517aa5c96bd86e99d844c835a8bbc896c58e713bc90c91836b5281fc235a925ed3e03d6bd974a95129070b617e96cc92be20ea778c255bbe258b90d3b4eed3233d1626a8ff810c3eb92993ec46c |
Socks5 Systemz |
URL | hxxps://jonathantwo[.]com/d8d1e3a4bbaa51cc5062674f36cfd353/6779d89b7a368f4f3f340b50a9d18d71[.]exe hxxp://185[.]172[.]128[.]19/Uni400uni[.]exe |
Glupteba |
URL | hxxps://tequilacofradiamx[.]com/minyhug/fxgsfhsdtytdjfudyjfjewrwsejyt/Panel/five/fre[.]php hxxp://tequilacofradiamx[.]com/minyhug/fxgsfhsdtytdjfudyjfjewrwsejyt/Panel/five/fre[.]php |
LokiBot |
URL | hxxps://gihibml[.]org/vl[.]php hxxps://www[.]mlmigration[.]com/wp-content/plugins/hot-random-image/index[.]html hxxps://iespppomabamba[.]edu[.]pe/wp-content/plugins/hot-random-image/index[.]html hxxps://prominencedigiworld[.]com/wp-content/plugins/hot-random-image/index[.]html hxxps://rummyking24[.]com/wp-content/plugins/hot-random-image/index[.]html hxxps://akshayascientifics[.]com/wp-content/plugins/hot-random-image/index[.]html hxxps://www[.]prottahobarta[.]com/wp-content/plugins/hot-random-image/index[.]html |
SSLoad |