不正URLへのアクセス、不正メールの受信
-
メール受信した
弊社お客様0社 URLアクセスした
弊社お客様0社 -
2024/05/02
※2024/05/02 更新
マルウェア感染させると考えられるURLを検知(2024/05/02)
■IoC(※1)
| Type: | IOC: | Signature: |
|---|---|---|
| URL | hxxps://covid19help[.]top/SAMM[.]exe hxxps://alphaumi[.]com/content/images/size/w256h256/2021/03/favicon[.]png hxxps://pastebin[.]com/raw/zQdp8jhj hxxps://alphaumi[.]com/wp-contenth/theme/twentytwentyfr[.]php hxxps://107[.]172[.]31[.]6/28088/hrrm/havenewthingstounderstandwhichgivegreatthingsimeanbeautu=ifulthingseverfindedonearth____sheismygirlmywifemyheartsheis[.]doc hxxps://pasteio[.]com/raw/xN0V3UUcQRjw hxxps://pasteio[.]com/raw/xhIcktX7dTHP |
Remcos |
| URL | hxxps://dukeenergyltd[.]top/shar[.]scr hxxp://ebnsina[.]top/evie1/five/fre[.]php hxxp://tampabayllc[.]top/teamb/five/PvqDq929BSx_A_D_M1n_a[.]php hxxp://91[.]92[.]253[.]221/dtyedh/five/PvqDq929BSx_A_D_M1n_a[.]php hxxp://alphaumi[.]com/dek/vv5/PvqDq929BSx_A_D_M1n_a[.]php hxxp://roof[.]spencerstuartllc[.]top/alpha/five/PvqDq929BSx_A_D_M1n_a[.]php hxxp://91[.]92[.]252[.]146:4002/kioy/five/PvqDq929BSx_A_D_M1n_a[.]php hxxp://altaskifer[.]sbs/PWS/PvqDq929BSx_A_D_M1n_a[.]php hxxp://sempersim[.]su/ob/PvqDq929BSx_A_D_M1n_a[.]php hxxp://ebnsina[.]top/project/five/PvqDq929BSx_A_D_M1n_a[.]php hxxp://sempersim[.]su/c13/PvqDq929BSx_A_D_M1n_a[.]php hxxp://saldanha[.]top/t/project/five/PvqDq929BSx_A_D_M1n_a[.]php hxxp://meridianresourcellc[.]top/document/five/PvqDq929BSx_A_D_M1n_a[.]php |
LokiBot |
| URL | hxxps://nvw[.]demo[.]betterbuiltdogs[.]com/editContent hxxps://pdd888167[.]top/data[.]php hxxps://bug[.]anesthetics[.]biomedzglobal[.]com/editContent hxxps://gvw[.]demo[.]betterbuiltdogs[.]com/editContent hxxps://tyd[.]demo[.]betterbuiltdogs[.]com/editContent |
FAKEUPDATES |
| URL | hxxp://dianomefs[.]cfd/Ajai/a300[.]txt hxxp://dianomefs[.]cfd/Ajai/a29[.]txt hxxp://dianomefs[.]cfd/Ajai/a30[.]txt hxxps://pastebin[.]com/raw/mzNjW7w1 |
Formbook |
| URL | hxxp://106[.]54[.]47[.]178/svchosts[.]exe hxxp://78[.]153[.]140[.]96/xmrig[.]exe hxxp://103[.]171[.]181[.]117/test |
Coinminer |
| URL | hxxp://106[.]54[.]47[.]178/system[.]exe | FlyStudio |
| URL | hxxp://209[.]90[.]233[.]2/KaXATaApmZMt189[.]bin hxxp://94[.]156[.]79[.]214/AMeRvH79[.]bin hxxp://94[.]156[.]79[.]214/MrqyrIbqcevEmOSUIMAFMdd44[.]bin |
CloudEyE |
| URL | hxxp://45[.]81[.]242[.]10/arm5 hxxp://91[.]92[.]254[.]170/bot[.]ppc hxxp://85[.]239[.]33[.]65/arm5 hxxp://45[.]81[.]242[.]10/mips hxxp://45[.]81[.]242[.]10/mpsl hxxp://85[.]239[.]33[.]65/mpsl hxxp://85[.]239[.]33[.]65/mips hxxp://94[.]156[.]67[.]118//bot[.]arm7 hxxp://94[.]156[.]67[.]118//bot[.]ppc hxxp://23[.]165[.]104[.]126/i586 hxxp://104[.]128[.]64[.]16/m-i[.]p-s[.]SNOOPY hxxp://104[.]128[.]64[.]16/a-r[.]m-5[.]SNOOPY hxxp://104[.]128[.]64[.]16/x-8[.]6-[.]SNOOPY hxxp://23[.]165[.]104[.]126/armv4l hxxp://23[.]165[.]104[.]126/armv5l hxxp://104[.]128[.]64[.]16/p-p[.]c-[.]SNOOPY hxxp://23[.]165[.]104[.]126/x86_64 hxxp://104[.]128[.]64[.]16/a-r[.]m-6[.]SNOOPY hxxp://104[.]128[.]64[.]16/a-r[.]m-4[.]SNOOPY hxxp://104[.]128[.]64[.]16/i-5[.]8-6[.]SNOOPY hxxp://91[.]92[.]252[.]187/a-r[.]m-6[.]Sakura hxxp://104[.]128[.]64[.]16/m-p[.]s-l[.]SNOOPY |
Bashlite |
| URL | hxxp://193[.]233[.]132[.]167/lend/jfesawdr[.]exe hxxps://stiffraspyofkwsl[.]shop/api hxxps://acceptabledcooeprs[.]shop/api hxxps://obsceneclassyjuwks[.]shop/api hxxps://zippyfinickysofwps[.]shop/api hxxps://miniaturefinerninewjs[.]shop/api hxxps://plaintediousidowsko[.]shop/api hxxps://sweetsquarediaslw[.]shop/api hxxps://holicisticscrarws[.]shop/api hxxps://boredimperissvieos[.]shop/api hxxps://accountasifkwosov[.]shop/api |
Lumma Stealer |
| URL | hxxp://89[.]23[.]98[.]112/Wp/private/Wordpress3/VmmariadbSecureFlower/CdnSecure/multiimageSqlPhp/6Secure3vm/GamePythonmultiDownloads/ExternalGeneratorJavascript8/testtest8/0providerCdn/58/CpuPollPoll/5/imageLocal/TrackLongpoll/MultiDleUploads/localcdn[.]php hxxp://remotetable[.]top/vm_LongpollBasetraffictrackwordpressPrivateuploads[.]php |
DCRat |
| URL | hxxp://193[.]233[.]132[.]22:8081/login hxxp://77[.]221[.]151[.]20:8081/login hxxp://45[.]15[.]156[.]9:8081/login hxxp://185[.]172[.]128[.]65:8081/login hxxp://193[.]142[.]146[.]101:8081/login hxxp://193[.]233[.]132[.]222:8081/login hxxp://193[.]233[.]132[.]47:8081/login hxxp://147[.]45[.]47[.]102:8081/login hxxp://94[.]156[.]64[.]237:8081/login hxxp://193[.]233[.]132[.]217:8081/login hxxp://38[.]92[.]40[.]19:8081/login hxxp://64[.]94[.]85[.]165:8081/login hxxp://147[.]45[.]47[.]101:8081/login hxxp://147[.]45[.]47[.]93:8081/login hxxp://77[.]221[.]151[.]10:8081/login hxxp://217[.]195[.]207[.]156:8081/login hxxp://193[.]233[.]132[.]101:8081/login hxxp://77[.]221[.]151[.]12:8081/login |
RisePro |
| URL | hxxps://teckmarkanmdas4[.]shop/ZDQyN2NmOGEZOTIK/ hxxps://marababrtdas[.]shop/ZDQyN2NmOGEZOTIK/ hxxps://teckmarkanary1[.]shop/ZDQyN2NmOGEZOTIK/ hxxps://adiletasarim[.]com/OTM5ZWJiZGQyNzJh/ hxxps://3adiletasarim[.]com/OTM5ZWJiZGQyNzJh/ hxxps://2adiletasarim[.]com/OTM5ZWJiZGQyNzJh/ hxxps://4adiletasarim[.]com/OTM5ZWJiZGQyNzJh/ hxxps://5adiletasarim[.]com/OTM5ZWJiZGQyNzJh/ hxxps://karakutuoynlar[.]top/MjE2YTczY2MxNjA0/ hxxps://karaaslancamping[.]xyz/MjE2YTczY2MxNjA0/ hxxps://oyunlarlemmi[.]top/MjE2YTczY2MxNjA0/ hxxps://candancanda[.]top/MjE2YTczY2MxNjA0/ hxxps://kaderdegulmzx[.]top/MjE2YTczY2MxNjA0/ hxxps://sevmekdeacilar[.]top/MjE2YTczY2MxNjA0/ hxxps://huzunluponsimm[.]top/MjE2YTczY2MxNjA0/ hxxps://kaderimyaziklar[.]top/MjE2YTczY2MxNjA0/ hxxps://mkkaoooama[.]top/MjE2YTczY2MxNjA0/ hxxps://ataseiorunaa[.]top/MjE2YTczY2MxNjA0/ hxxps://oyungouardman[.]com/MjE2YTczY2MxNjA0/ hxxps://sevmenenenaaa[.]top/MjE2YTczY2MxNjA0/ hxxps://canozturkkaka[.]top/MjE2YTczY2MxNjA0/ hxxps://biggiyenim[.]top/MjE2YTczY2MxNjA0/ hxxps://cigkoftebedavahizmetim[.]top/MjE2YTczY2MxNjA0/ hxxps://vasathastalari[.]top/MjE2YTczY2MxNjA0/ hxxps://kenedabirnumaratedavicisi[.]xyz/MjE2YTczY2MxNjA0/ hxxps://kediseakiyoruz[.]top/MjE2YTczY2MxNjA0/ hxxps://yavuzllarmarketim[.]shop/MjE2YTczY2MxNjA0/ hxxps://yeniuygarckaportaci[.]top/MjE2YTczY2MxNjA0/ hxxps://servisdepaketlemem[.]top/MjE2YTczY2MxNjA0/ hxxps://panssiyoncukuryesi[.]top/MjE2YTczY2MxNjA0/ hxxps://hizlimkaretdealisveris[.]com/MjE2YTczY2MxNjA0/ hxxps://45[.]88[.]91[.]119/Yzg2OGJiOGU5OWQy/ hxxps://agambenikoviyoryav[.]net/Yzg2OGJiOGU5OWQy/ hxxps://agambeniseviyoryav[.]com/Yzg2OGJiOGU5OWQy/ hxxps://kardesimbenikoviyoryav[.]net/Yzg2OGJiOGU5OWQy/ hxxps://kardesimbeniseviyoryav[.]com/Yzg2OGJiOGU5OWQy/ hxxps://kekembeniseviyoryav[.]com/Yzg2OGJiOGU5OWQy/ hxxps://marababrtdakand4[.]shop/ZDQyN2NmOGEZOTIK/ hxxps://marabkanatlarda2[.]shop/ZDQyN2NmOGEZOTIK/ hxxps://seniseverdimbenenaz[.]xyz/ZDQyN2NmOGEzOTlk/ hxxps://yenihacamattedavicisi[.]top/ZDQyN2NmOGEzOTlk/ hxxps://benkadereyenikdustum[.]top/ZDQyN2NmOGEzOTlk/ hxxps://asperonilaclari[.]top/ZDQyN2NmOGEzOTlk/ hxxps://fitildeyenilerdin[.]top/ZDQyN2NmOGEzOTlk/ hxxps://kaderbizegulmezmi[.]top/ZDQyN2NmOGEzOTlk/ hxxps://seningibiadamlarbenisev[.]top/ZDQyN2NmOGEzOTlk/ hxxps://saglemkzanlar[.]top/ZDQyN2NmOGEzOTlk/ hxxps://akuaakveryum[.]top/ZDQyN2NmOGEzOTlk/ hxxps://yeniseylerdenememelan[.]xyz/ZDQyN2NmOGEzOTlk/ hxxps://bebeklerdeoynarx[.]top/ZDQyN2NmOGEzOTlk/ hxxps://atasehirkkuaforu[.]top/ZDQyN2NmOGEzOTlk/ hxxps://canankarataylabebek[.]com/ZDQyN2NmOGEzOTlk/ hxxps://sevsenneolurduuuu[.]top/ZDQyN2NmOGEzOTlk/ hxxps://sevmesenneeeolur[.]top/ZDQyN2NmOGEzOTlk/ hxxps://kopekuyuztedavicisi[.]xyz/ZDQyN2NmOGEzOTlk/ hxxps://hayvanyemekveriyoruz[.]top/ZDQyN2NmOGEzOTlk/ hxxps://topcularaktaricisisedat[.]shop/ZDQyN2NmOGEzOTlk/ hxxps://evcilkusbesleme[.]shop/ZDQyN2NmOGEzOTlk/ hxxps://verdilerbizeikiadam[.]shop/ZDQyN2NmOGEzOTlk/ hxxps://tokatmotorcukuryesi[.]top/ZDQyN2NmOGEzOTlk/ hxxps://arackiralamacankiri[.]com/ZDQyN2NmOGEzOTlk/ |
Coper |
| URL | hxxp://proxy[.]heleh[.]vn/abwdsac3c[.]sh hxxp://103[.]174[.]73[.]85/abwdsac3c[.]sh hxxp://103[.]174[.]73[.]85/abwdsac3bw[.]sh hxxp://103[.]174[.]73[.]85/abwdsac3w[.]sh hxxp://proxy[.]heleh[.]vn/abwdsac3w[.]sh hxxp://proxy[.]heleh[.]vn/abwdsac3bw[.]sh hxxp://178[.]128[.]212[.]58/and hxxp://178[.]128[.]212[.]58/a hxxp://178[.]128[.]212[.]58/bot[.]arm7 hxxp://178[.]128[.]212[.]58/bot[.]mips hxxp://178[.]128[.]212[.]58/bot[.]arm5 hxxp://178[.]128[.]212[.]58/bot[.]arm hxxp://178[.]128[.]212[.]58/bot[.]x86 hxxp://178[.]128[.]212[.]58/bot[.]arm6 hxxp://178[.]128[.]212[.]58/bot[.]mpsl hxxp://178[.]128[.]212[.]58/bot[.]sh4 hxxp://178[.]128[.]212[.]58/bot[.]m68k hxxp://178[.]128[.]212[.]58/bot[.]ppc hxxp://94[.]156[.]67[.]118/ohshit[.]sh hxxp://94[.]156[.]67[.]118/bot[.]mips hxxp://94[.]156[.]67[.]118/bot[.]x86 hxxp://94[.]156[.]67[.]118/bot[.]arm7 hxxp://94[.]156[.]67[.]118/bot[.]x86_64 hxxp://94[.]156[.]67[.]118/bot[.]arm hxxp://94[.]156[.]67[.]118/bot[.]ppc hxxp://94[.]156[.]67[.]118/bot[.]m68k hxxp://94[.]156[.]67[.]118/bot[.]arm6 hxxp://94[.]156[.]67[.]118/bot[.]arm5 hxxp://94[.]156[.]67[.]118/bot[.]mpsl hxxp://94[.]156[.]67[.]118/bot[.]spc hxxp://94[.]156[.]67[.]118/bot[.]sh4 |
MooBot |
| URL | hxxp://192[.]3[.]243[.]154/lationooooonooooooon[.]txt hxxps://paste[.]ee/d/gaYMw hxxp://192[.]3[.]243[.]154/prnportlatinos[.]vbs hxxp://192[.]3[.]243[.]154/reallylovelyladylovedfishermanwithasweetkissingonhereyesshewasbeautifulgirlalwayswholovedotherstrulyfromtheheart__sheisbeautifulgirlformeireallylovedher[.]doc hxxp://192[.]3[.]243[.]154/lalallalallalallala[.]txt hxxps://paste[.]ee/d/tPdeE hxxp://192[.]3[.]243[.]154/vistatharagreatgirlwholovedafishermanwithallkindofkisssheisverybeautifulladywhoilovedtrulyfromtheeheartiwantthattruly___sheisnicegirlfromtheheartlovedtruly[.]doc hxxp://192[.]3[.]243[.]154/lalalawgome[.]vbs hxxp://192[.]3[.]239[.]4/see[.]exe hxxp://192[.]3[.]239[.]4/xampp/weg/creatednewthingstounderstandhowgoodfishingdowithaboatwenotunderstandthatgirl___beautifulgirlkissedmelove[.]doc hxxp://198[.]12[.]81[.]139/3505/CNN[.]exe hxxp://198[.]12[.]81[.]139/1355/HJCC[.]exe hxxp://198[.]12[.]81[.]139/xampp/hgh/wanthearthatbeautifulgirlilovedheralotofthingsneedtodobutsheisverybeautifulgirlwhoilovedheralotmygirlsheis___iwantshewillbehappy[.]doc |
Agent Tesla |
| URL | hxxp://45[.]142[.]112[.]240/arm hxxp://209[.]141[.]36[.]242/arm |
MrBlack |
| URL | hxxp://5[.]42[.]65[.]64/files/EU[.]file hxxp://193[.]163[.]7[.]88/a69d09b357e06b52[.]php |
Stealc |
| URL | hxxp://173[.]211[.]46[.]172:4444/push hxxp://47[.]96[.]252[.]193:5555/pixel[.]gif hxxps://120[.]48[.]96[.]69/g[.]pixel hxxp://47[.]99[.]182[.]25:8888/ptj hxxp://47[.]108[.]153[.]69:7777/ptj hxxp://120[.]48[.]96[.]69:9001/dot[.]gif hxxp://sz-sourcetail-v4[.]volcmlt[.]com/mall_100_100[.]html hxxps://8[.]147[.]132[.]135:8443/api/x hxxp://60[.]204[.]220[.]208/__utm[.]gif hxxp://service-8lop3tot-1321953982[.]sh[.]tencentapigw[.]com/api/x hxxps://update[.]micromain[.]cfd:2053/462c30d592f23b18/jquery/3[.]7[.]1/jquery[.]min[.]js hxxp://106[.]14[.]141[.]234:12662/zOMGAPT hxxps://ikea0[.]com:8443/Dequeue/mqseries/D7W0GTJFY hxxps://lebondogicoin[.]com:8443/Dequeue/mqseries/D7W0GTJFY hxxps://91[.]238[.]181[.]230:8443/Dequeue/mqseries/D7W0GTJFY hxxps://43[.]140[.]37[.]49/api/x hxxps://159[.]75[.]104[.]157:8880/api/3 hxxp://123[.]57[.]85[.]206:50000/IE9CompatViewList[.]xml hxxps://54[.]82[.]65[.]203/c/msdownload/update/others/2016/12/29136388_ hxxps://154[.]9[.]246[.]151/match hxxp://84[.]247[.]155[.]115/bU2t hxxp://84[.]247[.]155[.]115/match hxxp://28489294[.]xyz/activity |
Cobalt Strike |
| URL | hxxp://23[.]94[.]54[.]101/EPQ[.]exe | OriginLogger |
| URL | hxxp://93[.]123[.]85[.]108/VenomRAT%206[.]0[.]3%20HVNC%20Final[.]exe | Venom RAT |
| URL | hxxps://raw[.]githubusercontent[.]com/frexoff/efefwefwwf/main/cock[.]exe hxxps://github[.]com/frexoff/efefwefwwf/raw/main/cock[.]exe hxxp://193[.]233[.]132[.]167/lend/bild_redlain[.]exe |
RedLine Stealer |
| URL | hxxps://files[.]offshore[.]cat/jSB8SNaV[.]exe | SmokeLoader |
| URL | hxxp://193[.]233[.]132[.]175/server/k/l2[.]exe | Raccoon |
| URL | hxxp://disk[.]hostz1[.]com/mimikatz[.]exe | XWorm |
| URL | hxxps://rtattack[.]ralyjya9[.]online/mf/am[.]exe hxxp://carthewasher[.]net/7f2b25ae3e35529e1dcef7c2b1f6bce9/cad54ba5b01423b1af8ec10ab5719d97[.]exe |
Amadey |
| URL | hxxp://80[.]66[.]89[.]146/task/OWYsN2YsN2YsYTAsOWUsODYsOGMsOTYsNjQsN2Ms | SmartLoader |
| URL | hxxp://93[.]123[.]85[.]108/Venom[.]exe hxxp://93[.]123[.]85[.]108/Pogingenc[.]exe hxxp://93[.]123[.]85[.]108/VenomRAT%206[.]0[.]3%20HVNC[.]exe hxxp://93[.]123[.]85[.]108/Clientt[.]exe hxxp://93[.]123[.]85[.]108/Encrypted[.]exe |
Quasar RAT |
| URL | hxxp://147[.]45[.]47[.]44:8080/getfile[.]php?download=YXBwLXJlbGVhc2UtNA==&id=63a9f0ea7bb98050796b649e85481845 hxxp://147[.]45[.]47[.]44:8080/getfile[.]php?download=YXBwLXJlbGVhc2UtMQ==&id=63a9f0ea7bb98050796b649e85481845 hxxp://147[.]45[.]47[.]44:8080/getfile[.]php?download=YXBwLXJlbGVhc2UtMg==&id=63a9f0ea7bb98050796b649e85481845 hxxp://147[.]45[.]47[.]44:8080/getfile[.]php?download=YXBwLXJlbGVhc2UtMw==&id=63a9f0ea7bb98050796b649e85481845 hxxp://37[.]60[.]238[.]252:8085/getfile[.]php?download=YXBwLXJlbGVhc2UtMS5hcGs= hxxp://31[.]172[.]87[.]239:8082/getfile[.]php?download=YXBwLXJlbGVhc2UtMS5hcGs= hxxp://91[.]151[.]88[.]209:8082/getfile[.]php?download=YXBwLXJlbGVhc2UtMi5hcGs= hxxp://54[.]36[.]113[.]159:8082/getfile[.]php?download=YXBwLXJlbGVhc2UtMy5hcGs= hxxp://37[.]60[.]238[.]252:8085/getfile[.]php?download=YXBwLXJlbGVhc2UtNi5hcGs= hxxp://54[.]36[.]113[.]159:8082/getfile[.]php?download=YXBwLXJlbGVhc2UtMS5hcGs= hxxp://37[.]60[.]238[.]252:8085/getfile[.]php?download=YXBwLXJlbGVhc2UtMi5hcGs= hxxp://37[.]60[.]238[.]252:8085/getfile[.]php?download=YXBwLXJlbGVhc2UtNS5hcGs= hxxp://37[.]60[.]238[.]252:8085/getfile[.]php?download=YXBwLXJlbGVhc2UtMy5hcGs= hxxp://54[.]36[.]113[.]159:8082/getfile[.]php?download=YXBwLXJlbGVhc2UtNi5hcGs= hxxp://54[.]36[.]113[.]159:8082/getfile[.]php?download=YXBwLXJlbGVhc2UtMi5hcGs= hxxp://91[.]151[.]88[.]209:8082/getfile[.]php?download=YXBwLXJlbGVhc2UtMS5hcGs= hxxp://45[.]93[.]137[.]201:8082/getfile[.]php?download=YXBwLXJlbGVhc2UtMS5hcGs= hxxp://103[.]67[.]163[.]33:8082/getfile[.]php?download=YXBwLXJlbGVhc2UtMS5hcGs= hxxp://54[.]36[.]113[.]159:8082/getfile[.]php?download=YXBwLXJlbGVhc2UtNC5hcGs= hxxp://37[.]60[.]238[.]252:8085/getfile[.]php?download=YXBwLXJlbGVhc2UtNC5hcGs= hxxp://54[.]36[.]113[.]159:8082/getfile[.]php?download=YXBwLXJlbGVhc2UtNS5hcGs= |
Chrysaor |
| URL | hxxps://eprst281[.]boo/files/LexisNexis[.]msix hxxps://eprst251[.]boo/files/Asana[.]msix hxxp://138[.]124[.]184[.]250/files/Asana[.]msix hxxps://138[.]124[.]184[.]250/files/Asana[.]msix hxxp://138[.]124[.]184[.]247/files/blackrock[.]msix hxxps://eprst281[.]boo/files/blackrock[.]msix hxxps://138[.]124[.]184[.]247/files/blackrock[.]msix hxxps://eprst281[.]boo/files/netsupport28[.]zip hxxps://eprst251[.]boo/files/netsupport25[.]zip hxxps://lexisnexis[.]day/download[.]php |
NetSupportManager RAT |







