不正URLへのアクセス、不正メールの受信
-
メール受信した
弊社お客様0社 URLアクセスした
弊社お客様1社 -
2025/05/21
※2025/05/21 更新
マルウェア感染させると考えられるURLを検知(2025/05/21)
■IoC(※1)
Type: | IOC: | Signature: |
---|---|---|
URL | hxxps://lclarmodq[.]top/qoxo hxxps://kfishgh[.]digital/tequ hxxps://jparakehjet[.]run/kewk hxxps://yescczlv[.]top/bufi hxxps://scaitraohvi[.]bet/adks hxxps://github[.]com/a1stemm1/glory/raw/refs/heads/main/cclib02[.]exe hxxp://185[.]156[.]72[.]2/files/6691015685/fPbjy1Q[.]exe hxxp://185[.]156[.]72[.]2/files/5494432675/XEIxGFE[.]exe hxxps://unnameddownloadddd[.]xyz/frtas[.]exe hxxps://unnameddownloadddd[.]xyz/privated[.]exe hxxps://quaterujrb[.]shop/fasj hxxps://enarrathfpt[.]top/tekq hxxps://9gettoknwg[.]life/xapd hxxps://w2bhaircuirfm[.]top/aldk hxxps://nwinterghzp[.]digital/ywq hxxps://bubblezdjw[.]live/kudf hxxp://62[.]60[.]226[.]165/public_files/nohaaAp[.]txt hxxp://62[.]60[.]226[.]165/public_files/dfmimog[.]txt hxxp://62[.]60[.]226[.]165/public_files/dgSdgbp[.]txt hxxp://62[.]60[.]226[.]165/public_files/nFmdpAg[.]txt hxxp://62[.]60[.]226[.]165/public_files/idfpmmd[.]txt hxxp://62[.]60[.]226[.]165/public_files/nmdrgfm[.]txt hxxp://62[.]60[.]226[.]165/public_files/FaoShbd[.]txt hxxps://ubtcgeared[.]live/lbak hxxps://rparakehjet[.]run/kewk hxxps://catsuiqdmn[.]live/euwq hxxps://2posseswsnc[.]top/akds hxxps://definitnve[.]run/ioqn hxxp://62[.]60[.]226[.]165/public_files/rmdjcbr[.]txt hxxp://62[.]60[.]226[.]165/public_files/dmSIIij[.]txt hxxp://62[.]60[.]226[.]165/public_files/pfjefcb[.]txt hxxp://62[.]60[.]226[.]165/public_files/hefkkib[.]txt hxxps://ibtcgeared[.]live/lbak hxxps://escapadue[.]live/SPzkwq hxxps://ktlaminaflbx[.]shop/twoq hxxps://hdjackthyfuc[.]run/xpas hxxp://185[.]156[.]72[.]2/files/462853517/SPpr8Zz[.]exe hxxps://tjgalijd[.]shop/anbf hxxps://vmaxmtsq[.]bet/xzid hxxps://wintrerfeast[.]live/xzbi hxxps://2araucahkbm[.]live/baneb hxxps://xtestcawepr[.]run/dsap hxxps://oqlaminaflbx[.]shop/twoq hxxps://parrisrohy[.]digital/alb hxxps://fhunterinrx[.]run/mnbt hxxps://4easterxeen[.]run/zavc hxxps://greleaswrlf[.]run/jadz hxxps://5iorjinalecza[.]net/lxaz hxxps://5easterxeen[.]run/zavc hxxps://nsearchilyo[.]run/gsna hxxps://0unlimirxam[.]digital/qop hxxps://vflowerexju[.]bet/lanz hxxps://teczamedikal[.]org/vax hxxps://o8racxilb[.]digital/ozi hxxps://nblackljjwc[.]run/banj hxxps://afeaturlyin[.]top/pdal hxxps://3blackswmxc[.]top/bgry hxxps://hposseswsnc[.]top/akds hxxps://9testcawepr[.]run/dsap hxxps://caraucahkbm[.]live/baneb hxxps://6featurlyin[.]top/pdal hxxps://lkeasterxeen[.]run/zavc hxxps://gposseswsnc[.]top/akds hxxps://ytouvrlane[.]bet/ASKwjq hxxps://mwovercovtcg[.]top/juhd hxxps://unnatue[.]digital/prl hxxps://mbegindecafer[.]world/QwdZdf hxxps://0insidegrah[.]run/ieop hxxps://ktestcawepr[.]run/dsap hxxps://5uovercovtcg[.]top/juhd hxxps://sposseswsnc[.]top/akds hxxps://r1travelilx[.]top/GSKAiz hxxps://40posseswsnc[.]top/akds hxxps://8equatorf[.]run/reiq hxxps://ubearjk[.]live/benj hxxps://lorijinalecza[.]net/kazd hxxps://pfeaturlyin[.]top/pdal hxxps://7blackswmxc[.]top/bgry hxxps://c5overcovtcg[.]top/juhd hxxps://gesccapewz[.]run/ANSbwqy hxxps://acladwybn[.]digital/pts hxxps://zcornerdurv[.]top/adwq hxxps://aatomicsmet[.]run/api hxxps://03onehunqpom[.]life/zpxd hxxps://oclatteqrpq[.]digital/kljz hxxps://5blackswmxc[.]top/bgry hxxps://varaucahkbm[.]live/baneb hxxps://qblackswmxc[.]top/bgry hxxps://neasterxeen[.]run/zavc hxxps://iaraucahkbm[.]live/baneb hxxps://aj7flowerexju[.]bet/lanz hxxps://ldarjkafsg[.]digital/aoiz hxxps://nninepicchf[.]bet/lznd hxxps://7cornerdurv[.]top/adwq hxxps://yaraucahkbm[.]live/baneb hxxps://horijinalecza[.]org/jub hxxps://5featurlyin[.]top/pdal hxxps://cflowerexju[.]bet/lanz hxxps://post-post[.]top/api hxxps://0blackswmxc[.]top/bgry hxxps://3posseswsnc[.]top/akds hxxps://undertsoky[.]run/xanr hxxps://0bflowerexju[.]bet/lanz hxxps://cblackswmxc[.]top/bgry hxxps://2overcovtcg[.]top/juhd hxxps://modenoww[.]run/odus hxxps://8featurlyin[.]top/pdal hxxps://garaucahkbm[.]live/baneb hxxps://1flowerexju[.]bet/lanz hxxps://businessposuteit[.]buzz/api hxxps://xnarrathfpt[.]top/tekq hxxps://1insidegrah[.]run/ieop hxxps://7cpblackswmxc[.]top/bgry hxxps://ojackthyfuc[.]run/xpas hxxps://dposseswsnc[.]top/akds hxxps://eatomicsmet[.]run/api hxxps://tposseswsnc[.]top/akds hxxps://fsovercovtcg[.]top/juhd hxxps://ncornerdurv[.]top/adwq hxxps://kmtestcawepr[.]run/dsap hxxps://reasterxeen[.]run/zavc hxxps://k1dovercovtcg[.]top/juhd hxxps://8grizzlqzuk[.]live/qhbu hxxps://slaminaflbx[.]shop/twoq hxxps://rbfeaturlyin[.]top/pdal hxxps://8insidegrah[.]run/ieop hxxps://sblackswmxc[.]top/bgry hxxps://ttravewlio[.]shop/ZNxbHi hxxps://busincesposteit[.]help/api hxxps://seasterxeen[.]run/zavc hxxps://iblackswmxc[.]top/bgry hxxps://uposseswsnc[.]top/akds hxxps://cgeographys[.]run/eirq hxxps://x0easterxeen[.]run/zavc hxxps://represpnzj[.]live/gsiz hxxps://wposseswsnc[.]top/akds hxxps://ccornerdurv[.]top/adwq hxxps://jtestcawepr[.]run/dsap hxxps://wbardcauft[.]run/tured hxxps://aktblackswmxc[.]top/bgry hxxps://deasterxeen[.]run/zavc hxxps://azmedtipp[.]live/mnvzx hxxps://4dparakehjet[.]run/kewk hxxps://1overcovtcg[.]top/juhd hxxps://9overcovtcg[.]top/juhd hxxps://yfeaturlyin[.]top/pdal hxxps://ymeteorplyp[.]live/lekp hxxps://amniotjnrt[.]run/tquh hxxps://mposseswsnc[.]top/akds hxxps://6testcawepr[.]run/dsap hxxps://leasterxeen[.]run/zavc hxxps://nblackswmxc[.]top/bgry hxxps://odrbettere[.]live/aniodg hxxps://yeasterxeen[.]run/zavc hxxps://sonehunqpom[.]life/zpxd hxxps://7emphatakpn[.]bet/ladk hxxps://ltestcawepr[.]run/dsap hxxps://itflowerexju[.]bet/lanz hxxps://iemphatakpn[.]bet/ladk hxxps://3atomicsmet[.]run/api hxxps://8testcawepr[.]run/dsap hxxps://9ffeaturlyin[.]top/pdal hxxps://0laminaflbx[.]shop/twoq hxxps://lnovercovtcg[.]top/juhd hxxps://autpostat[.]cyou/api hxxps://mtmmeteorplyp[.]live/lekp hxxps://fuemphatakpn[.]bet/ladk hxxps://cxesccapewz[.]run/ANSbwqy hxxps://ufeaturlyin[.]top/pdal hxxps://jaeneasq[.]live/nmgj hxxps://0advennture[.]top/GKsiio hxxps://efeaturlyin[.]top/pdal hxxps://eposseswsnc[.]top/akds hxxps://xlaminaflbx[.]shop/twoq hxxps://dancioluffaro[.]com/api hxxps://qaraucahkbm[.]live/baneb hxxps://6vflowerexju[.]bet/lanz hxxps://ehfeaturlyin[.]top/pdal hxxps://6zmedtipp[.]live/mnvzx hxxps://horijinalecza[.]net/kazd hxxps://ofeaturlyin[.]top/pdal hxxps://asaxecocnak[.]live/manj hxxps://sjackthyfuc[.]run/xpas hxxps://correosuyg[.]top/api hxxps://9flowerexju[.]bet/lanz hxxps://rvoznessxyy[.]life/bnaz hxxps://blameaowi[.]run/twiu hxxps://dblackswmxc[.]top/bgry hxxps://0emphatakpn[.]bet/ladk hxxps://iwposseswsnc[.]top/akds hxxps://zeasterxeen[.]run/zavc hxxps://xblackswmxc[.]top/bgry hxxps://feasterxeen[.]run/zavc hxxps://vovercovtcg[.]top/juhd hxxps://bposseswsnc[.]top/akds hxxps://9homewappzb[.]top/tqba hxxps://mfeaturlyin[.]top/pdal hxxps://paraucahkbm[.]live/baneb hxxps://kovercovtcg[.]top/juhd hxxps://xqtestcawepr[.]run/dsap hxxps://5zenithcorde[.]top/auid hxxps://rfeaturlyin[.]top/pdal hxxps://wonehunqpom[.]life/zpxd hxxps://34blackswmxc[.]top/bgry hxxps://iovercovtcg[.]top/juhd hxxps://0tortoisgfe[.]top/paxk hxxps://vblackswmxc[.]top/bgry hxxps://bxaraucahkbm[.]live/baneb hxxps://mzmedtipp[.]live/mnvzx hxxps://stestcawepr[.]run/dsap hxxps://rsearchilyo[.]run/gsna hxxps://2zmedtipp[.]live/mnvzx hxxps://lflowerexju[.]bet/lanz hxxps://jlaminaflbx[.]shop/twoq hxxps://7araucahkbm[.]live/baneb hxxps://2easterxeen[.]run/zavc hxxps://7dzmedtipp[.]live/mnvzx hxxps://25ninepicchf[.]bet/lznd hxxps://psnakejh[.]top/adsk hxxps://ftestcawepr[.]run/dsap hxxps://2iblackswmxc[.]top/bgry hxxps://fsnakejh[.]top/adsk hxxps://vracxilb[.]digital/ozi hxxps://2cornerdurv[.]top/adwq hxxps://elaminaflbx[.]shop/twoq hxxps://1eposseswsnc[.]top/akds hxxps://0xxposseswsnc[.]top/akds hxxps://nflowerexju[.]bet/lanz hxxps://aovercovtcg[.]top/juhd hxxps://postnlpost[.]help/api hxxps://actortoesuz[.]help/api hxxps://kflowerexju[.]bet/lanz hxxps://llaminaflbx[.]shop/twoq hxxps://0bqtestcawepr[.]run/dsap hxxps://temphatakpn[.]bet/ladk hxxps://xflowerexju[.]bet/lanz hxxps://njackthyfuc[.]run/xpas hxxps://nlflowerexju[.]bet/lanz hxxps://einovercovtcg[.]top/juhd hxxps://atomicsmet[.]run/api hxxps://hfeaturlyin[.]top/pdal hxxps://tithethrv[.]run/qtby hxxps://jposseswsnc[.]top/akds hxxps://6easterxeen[.]run/zavc hxxps://vlaminaflbx[.]shop/twoq hxxps://kmeteorplyp[.]live/lekp hxxps://fkposseswsnc[.]top/akds hxxps://racxilb[.]digital/ozi hxxps://ftracxilb[.]digital/ozi hxxps://jfeaturlyin[.]top/pdal hxxps://0araucahkbm[.]live/baneb hxxps://1uaraucahkbm[.]live/baneb hxxps://2flowerexju[.]bet/lanz hxxps://hemphatakpn[.]bet/ladk hxxps://wbearjk[.]live/benj hxxps://pzenithcorde[.]top/auid hxxps://cfeaturlyin[.]top/pdal hxxps://github[.]com/legendary99999/fdbvsdfbsdfbsdb/releases/download/bsdgfbsdfbsdf/alex123121221[.]exe hxxps://github[.]com/legendary99999/fdgvbdfgsbsfgb-/releases/download/fdsbsgdfbsgbfd/cron12213[.]exe hxxps://github[.]com/legendary99999/knjknkjdsvsd/releases/download/fdvsdfvsdfv/cron1221222222[.]exe hxxps://github[.]com/legendary99999/fdbvdfvdsfbvsd/releases/download/cron1212122112/cron12213[.]exe hxxps://github[.]com/legendary99999/dfbgvsdfbvsdfgb/releases/download/dmvkmsdfvmsdfv/cron1221222222[.]exe hxxps://ngescczlv[.]top/bufi hxxps://5threatqjqy[.]top/nybe hxxps://rblackswmxc[.]top/bgry hxxps://ztechguidet[.]digital/apdo hxxps://5techguidet[.]digital/apdo hxxps://3clarmodq[.]top/qoxo hxxps://rsnakejh[.]top/adsk |
Lumma Stealer |
URL | hxxp://94[.]156[.]177[.]41/ugop/five/fre[.]php hxxp://94[.]156[.]177[.]41/ugop/five/PvqDq929BSx_A_D_M1n_a[.]php hxxp://213[.]209[.]150[.]18/qwalphaqw[.]exe hxxp://94[.]156[.]177[.]41/droid/five/fre[.]php |
LokiBot |
URL | hxxp://47[.]121[.]222[.]227:9999/02[.]08[.]2022[.]exe hxxp://77[.]246[.]107[.]11/02[.]08[.]2022[.]exe hxxp://120[.]76[.]238[.]109:800/02[.]08[.]2022[.]exe hxxp://118[.]26[.]39[.]237:8081/02[.]08[.]2022[.]exe hxxp://152[.]136[.]17[.]91:5214/02[.]08[.]2022[.]exe hxxp://118[.]31[.]16[.]216:443/02[.]08[.]2022[.]exe hxxp://39[.]106[.]152[.]200/02[.]08[.]2022[.]exe hxxp://101[.]133[.]229[.]117:443/02[.]08[.]2022[.]exe |
Cobalt Strike |
URL | hxxps://snapcans[.]top/vv/ddas[.]php hxxps://upgradegc[.]com/rsrs[.]zip hxxp://sti-salyk[.]com/update/NSM[.]lic hxxp://sti-salyk[.]com/update/client32[.]ini hxxp://sti-kg[.]com/settings/client32[.]ini hxxps://k2bsc[.]top/lvl/select[.]js hxxps://k2bsc[.]top/lvl/ddas[.]php hxxps://k2bsc[.]top/lvl/trumper[.]js hxxps://viralmarketingsuite[.]com/mimi[.]zip |
NetSupportManager RAT |
URL | hxxps://windowsmsncn[.]org/nlOs24YoL hxxps://chproduct[.]com/4e2e[.]js hxxps://chproduct[.]com/js[.]php hxxps://windowsmsncn[.]org/Z9JThRRIL |
KongTuke |
URL | hxxps://feedback[.]greeneconsultinggroup[.]com/profileLayout hxxps://app[.]nerduptechnology[.]com/profileLayout |
FAKEUPDATES |
URL | hxxp://103[.]199[.]205[.]78:51996/Mozi[.]m | Mozi |
URL | hxxp://texprosa[.]com/it[.]bin hxxps://mack-concord[.]hr/OyWUdRtjEtLv84[.]bin hxxps://mack-concord[.]hr/Zuzan[.]xsn hxxps://107[.]175[.]246[.]32/xampp/cno/bestpeopleswithbestskillforthenewowrking[.]hta hxxps://107[.]175[.]246[.]32/xampp/wvgf/wedecidedtoreleasegoodthingsforme[.]hta hxxp://107[.]175[.]246[.]32/xampp/cno/bestpeopleswithbestskillforthenewowrking[.]hta hxxp://107[.]175[.]246[.]32/xampp/wvgf/wedecidedtoreleasegoodthingsforme[.]hta |
Formbook |
URL | hxxp://209[.]54[.]102[.]157/ZnkxiGIQh214[.]bin hxxp://185[.]29[.]9[.]64/MPWmjVzfhCfRxu8[.]bin |
Agent Tesla |
URL | hxxp://75[.]127[.]7[.]164/sLUnzeWidMaa112[.]bin hxxp://192[.]3[.]176[.]134/nLHweaRZ10[.]bin hxxp://192[.]3[.]176[.]134/OeujsmDZh46[.]bin hxxps://mack-concord[.]hr/rosalindas[.]deploy hxxps://mack-concord[.]hr/RbVQBy60[.]bin hxxps://mack-concord[.]hr/NpcldmLMbepYQCGc38[.]bin hxxps://mack-concord[.]hr/Promythic[.]mix hxxps://mack-concord[.]hr/Wasabi[.]psp hxxps://mack-concord[.]hr/ApAJrIehI163[.]bin hxxp://107[.]172[.]132[.]57/bXlKggyOFScfGZqu115[.]bin hxxp://109[.]248[.]144[.]218/zlbNAgJayvCwpS252[.]bin hxxp://proarte[.]rs/Polyprism[.]psd hxxps://artacom[.]com[.]br/admin-pc/Stikpille[.]psp hxxps://artacom[.]com[.]br/admin-pc/QsllCXnOgWI52[.]bin hxxps://mack-concord[.]hr/MCqSwh42[.]bin hxxps://mack-concord[.]hr/Identitetsflelses[.]hhk |
CloudEyE |
URL | hxxp://185[.]209[.]21[.]111/download/photoshop-v2[.]exe hxxps://github[.]com/legendary99999/nknkjnkj/releases/download/bhjvjhvjhvjh/2[.]exe |
Vidar |
URL | hxxp://107[.]173[.]47[.]164/960/seeingwithfutrwewillrunnigwedohope[.]txt hxxp://176[.]65[.]142[.]222/web/va[.]exe hxxps://107[.]175[.]246[.]32/340/uhnb/givemebestthingsforbetterwaygoodformebest_______givemebestthingsforbetterwaygoodformebest________givemebestthingsforbetterwaygoodformebest[.]doc hxxp://107[.]175[.]246[.]32/340/uhnb/givemebestthingsforbetterwaygoodformebest_______givemebestthingsforbetterwaygoodformebest________givemebestthingsforbetterwaygoodformebest[.]doc hxxp://62[.]60[.]226[.]165/public_files/kgbIdeb[.]txt hxxp://62[.]60[.]226[.]165/public_files/kemhbcb[.]txt hxxp://62[.]60[.]226[.]165/public_files/dekkgbk[.]txt hxxp://62[.]60[.]226[.]165/public_files/SgIdmkb[.]txt hxxp://62[.]60[.]226[.]165/public_files/Fkdjkbm[.]txt hxxp://62[.]60[.]226[.]165/public_files/dipdIid[.]txt hxxp://62[.]60[.]226[.]165/public_files/FSffImf[.]txt hxxps://107[.]173[.]47[.]164/800/bnm/bestkingsgivenmegoodgreatbestthingsbestking_________bestkingsgivenmegoodgreatbestthingsbestkingsg________________bestkingsgivenmegoodgreatbestthingsbestkingsgivenmegoodgreatbestthings[.]doc hxxps://107[.]175[.]246[.]32/xampp/wvgf/wedecidedtoreleasegoodthingsformewedecid______wedecidedtoreleasegoodthingsformewede_____wedecidedtoreleasegoodthingsformewedecidedtoreleasegoodthings[.]doc hxxps://107[.]173[.]47[.]164/900/wcg/weneedbetterperofmancewithgoodthings________weneedbetterperofmancewithgoodthings__________weneedbetterperofmancewithgoodthings[.]doc hxxps://67[.]217[.]240[.]53/157/hrd/bestthingshappeningentiretimeforgoodthings_____bestthingshappeningentiretimeforgoodthings______bestthingshappeningentiretimeforgoodthings[.]doc hxxps://67[.]217[.]240[.]53/160/hbo/givemesuchabestoutputmyspritualnetowkr____[.]doc hxxps://107[.]173[.]47[.]164/950/wec/withnodenczgirlfriendcvghgohunirthingskindtrue__________withnodenczgirlfriendcvghgohunirthingskindtrue_________withnodenczgirlfriendcvghgohunirthingskindtrue[.]doc hxxps://74[.]208[.]45[.]193/680/uhb/bgoodnewwithgreatexperiencebecomerichmanenergygivenmebest_________goodnewwithgreatexperiencebecomerichmanenergygivenmebest_________goodnewwithgreatexperiencebecomerichmanenergygivenmebest[.]doc hxxps://67[.]217[.]240[.]53/170/meto/greatkindesswithgoodspritualworkgreatkindesswith________greatkindesswithgoodspritualworkgreatki________greatkindesswithgoodspritualworkgreatkindesswithgoods[.]doc hxxp://67[.]217[.]240[.]53/157/hrd/bestthingshappeningentiretimeforgoodthings_____bestthingshappeningentiretimeforgoodthings______bestthingshappeningentiretimeforgoodthings[.]doc hxxp://74[.]208[.]45[.]193/680/uhb/bgoodnewwithgreatexperiencebecomerichmanenergygivenmebest_________goodnewwithgreatexperiencebecomerichmanenergygivenmebest_________goodnewwithgreatexperiencebecomerichmanenergygivenmebest[.]doc hxxp://107[.]173[.]47[.]164/950/wec/withnodenczgirlfriendcvghgohunirthingskindtrue__________withnodenczgirlfriendcvghgohunirthingskindtrue_________withnodenczgirlfriendcvghgohunirthingskindtrue[.]doc hxxp://107[.]173[.]47[.]164/800/bnm/bestkingsgivenmegoodgreatbestthingsbestking_________bestkingsgivenmegoodgreatbestthingsbestkingsg________________bestkingsgivenmegoodgreatbestthingsbestkingsgivenmegoodgreatbestthings[.]doc hxxp://107[.]173[.]47[.]164/900/wcg/weneedbetterperofmancewithgoodthings________weneedbetterperofmancewithgoodthings__________weneedbetterperofmancewithgoodthings[.]doc hxxp://107[.]175[.]246[.]32/xampp/wvgf/wedecidedtoreleasegoodthingsformewedecid______wedecidedtoreleasegoodthingsformewede_____wedecidedtoreleasegoodthingsformewedecidedtoreleasegoodthings[.]doc hxxp://67[.]217[.]240[.]53/170/meto/greatkindesswithgoodspritualworkgreatkindesswith________greatkindesswithgoodspritualworkgreatki________greatkindesswithgoodspritualworkgreatkindesswithgoods[.]doc hxxp://67[.]217[.]240[.]53/160/hbo/givemesuchabestoutputmyspritualnetowkr____[.]doc hxxps://huadongrubbercable[.]com/priests/r[.]txt hxxp://62[.]60[.]226[.]165/public_files/dcibbij[.]txt hxxps://67[.]217[.]240[.]53/155/greatnesswegivebestthingswithgood[.]vbe hxxp://67[.]217[.]240[.]53/155/greatnesswegivebestthingswithgood[.]vbe hxxps://huadongrubbercable[.]com/priests/ucbqysnsl[.]txt hxxps://huadongrubbercable[.]com/johnson/rdadcqyxj[.]txt |
Remcos |
URL | hxxp://176[.]65[.]142[.]222/web/build[.]exe hxxps://api[.]telegram[.]org/bot7570930688:AAEEhkb1rFIdA2hk0ztCRx_9xZAYRHImCoQ/sendMessage?chat_id=7886581547 hxxp://213[.]209[.]150[.]18/xtonyee2[.]exe hxxp://213[.]209[.]150[.]18/agodee[.]exe hxxp://213[.]209[.]150[.]18/agodee2[.]exe |
Snake Keylogger |
URL | hxxp://185[.]156[.]72[.]2/files/6033609309/L7m5WH3[.]exe hxxp://831471cm[.]nyashvibe[.]ru/eternalvmPipe_serverProtectsqlFlowerDleLocal[.]php |
DCRat |
URL | hxxps://sf[.]grantmangy[.]top/ujs/f1575b64-8492-4e8b-b102-4d26e8c70371 hxxps://sf[.]grantmangy[.]top/Up/b hxxps://sf[.]grantmangy[.]top/Up |
ACR Stealer |
URL | hxxp://62[.]60[.]226[.]165/public_files/Adikngm[.]txt hxxp://62[.]60[.]226[.]165/public_files/hnaomnm[.]txt hxxp://62[.]60[.]226[.]165/public_files/SmncdmA[.]txt hxxp://62[.]60[.]226[.]165/public_files/jIcpeak[.]txt |
Lumar |
URL | hxxp://62[.]60[.]226[.]165/public_files/pfddfdI[.]txt hxxps://openport[.]io/l/47667/al1l7OYeyPO2uZo6 |
Quasar RAT |
URL | hxxp://213[.]209[.]150[.]18/catee[.]exe hxxps://api[.]telegram[.]org/bot7812605943:AAGhpycjqXSbua5lcFqANAT0bHzPMZPrUnE/sendMessage?chat_id=6334190867 |
MASS Logger |
URL | hxxps://khavar[.]com/acheck3[.]txt hxxps://khavar[.]com/Atata[.]txt hxxp://khavar[.]com/acheck3[.]txt hxxps://huadongrubbercable[.]com/johnson/r[.]txt |
DBatLoader |
URL | hxxps://helpsscodds[.]in/cms/ | SmokeLoader |
URL | hxxps://cnbcanalysis[.]com/themes/base/cybersecs/zen/sroc[.]ps1 | XWorm |
URL | hxxps://software-server[.]online/Get?q=Zenmap | BumbleBee |
URL | hxxps://api[.]telegram[.]org/bot7801493167:AAEB4WXJGTJOHMz0AiJb2sT4xWzkAygrtn0/sendMessage hxxps://api[.]telegram[.]org/bot7797407004:AAEYC2RZ1ttS1JHgNzVc2G5WsWDj-lbDScs/sendMessage hxxps://api[.]telegram[.]org/bot7513972954:AAEWIqVh5OE72B5cSVUwg4AjVqS97dlZPsg/sendMessage |
AsyncRAT |
URL | hxxps://h4[.]ripcordbuffalo[.]run/sh[.]ext[.]bin hxxp://1[.]tattlererun[.]life/88[.]ext[.]bin hxxp://h4[.]groutlandlady[.]top/88[.]ext[.]bin hxxp://h4[.]fringezipping[.]bet/88[.]ext[.]bin hxxp://h4[.]tattlererun[.]life/88[.]ext[.]bin hxxp://h4[.]ripcordbuffalo[.]run/88[.]ext[.]bin hxxp://h4[.]fringezipping[.]bet/sh[.]ext[.]bin hxxp://h4[.]tattlererun[.]life/sh[.]ext[.]bin hxxp://h4[.]groutlandlady[.]top/sh[.]ext[.]bin hxxp://h4[.]ripcordbuffalo[.]run/sh[.]ext[.]bin |
HijackLoader |
URL | hxxps://h4iizliveguvenimserviceds[.]com/MzMxNzE5MjExY2Q3/ hxxps://hi7zliveguuvenimserviceds[.]com/MzMxNzE5MjExY2Q3/ hxxps://hhi3zliveguvenimserviceds[.]com/MzMxNzE5MjExY2Q3/ hxxps://hiz11liveguuvenimserviceds[.]com/MzMxNzE5MjExY2Q3/ hxxps://hi9zliveguuvenimserviceds[.]com/MzMxNzE5MjExY2Q3/ hxxps://hiz42liveguuvenimserviceds[.]com/MzMxNzE5MjExY2Q3/ hxxps://hizl12iveguuvenimserviceds[.]com/MzMxNzE5MjExY2Q3/ hxxps://hizliv31eguuvenimserviceds[.]com/MzMxNzE5MjExY2Q3/ |
Coper |
URL | hxxp://92[.]112[.]125[.]62/leet[.]sh4 hxxp://92[.]112[.]125[.]62/leet[.]arm4 hxxp://92[.]112[.]125[.]62/leet[.]i586 hxxp://92[.]112[.]125[.]62/leet[.]x86 hxxp://92[.]112[.]125[.]62/leet[.]mips hxxp://92[.]112[.]125[.]62/leet[.]ppc hxxp://92[.]112[.]125[.]62/leet[.]arm6 hxxp://92[.]112[.]125[.]62/leet[.]m68k hxxp://92[.]112[.]125[.]62/leet[.]x32 hxxp://92[.]112[.]125[.]62/leet[.]mpsl hxxp://92[.]112[.]125[.]62/leet[.]sh |
Bashlite |
URL | hxxp://185[.]236[.]24[.]192/openssh hxxp://185[.]236[.]24[.]192/sshd hxxp://185[.]236[.]24[.]192/tftp hxxp://185[.]236[.]24[.]192/%20 hxxp://185[.]236[.]24[.]192/ftp hxxp://185[.]236[.]24[.]192/cron hxxp://185[.]236[.]24[.]192/bash hxxp://185[.]236[.]24[.]192/ntpd hxxp://185[.]236[.]24[.]192/sh hxxp://185[.]236[.]24[.]192/n hxxp://185[.]236[.]24[.]192/wget hxxp://185[.]236[.]24[.]192/pftp hxxp://185[.]236[.]24[.]192/apache2 |
Tsunami |