cNotes 検索 一覧 カテゴリ

AICPA Fake spam

Published: 2012/12/10

約一年前にもBHEKで利用されていたネタです。

Subjectはこんな感じ。

 Income faked tax return accusations. 
 Income sham tax return accusations. 
 Income incorrect tax return accusations. 
 Income fake tax return accusations. 
 Income phony tax return accusations. 
 Income false tax return accusations. 
 Income improper tax return accusations. 
 Income counterfeit tax return accusations.

誘導URLの特徴はこれ。10月頃からあるBHEK2で利用されているパターンです。

 http://polycliniqueidimed.com/components/com_ag_google_analytics2/aicpataxcompl.html
 http://auto-serviser.com/components/com_ag_google_analytics2/aicpataxcompl.html
 http://kentplus-temizlik.com/components/com_ag_google_analytics2/aicpataxcompl.html

細かい点で他の攻撃に比べて少し高度です。


主にアメリカです。

nameIP逆引きASAS NameCountry
wohnbau-rastatt.com195.78.76.157server157.star-server.info.5464NETDISCOUNTER_Netdiscounter_GmbH_autonomous_systemGermany
asociaciondesarrolloruraldosvalles.com82.165.18.165clienteservidor.es.8560ONEANDONE-AS_1&1_Internet_AGGermany
printer2you.com27.254.55.110cs17.hostneverdie.com.9891CSLOX-IDC-AS-AP_CS_LOXINFO_Public_Company_Limited.Thailand
myprotext.com184.170.135.195NONE10929NETELLIGENT_-_Netelligent_Hosting_Services_Inc.Canada
kenzeo.com69.90.162.140hp45.hostpapa.com.13768PEER1_-_Peer_1_Network_Inc.Canada
xn--b1aeonhcx.com91.236.118.192s18.domen.com.ua.15497COLOCALL_Internet_Data_Center__ColoCALL_Ukraine
aserto.org95.211.20.87x78.alfaservers.com.16265LEASEWEB_LeaseWeb_B.V.Netherlands
claryfix.com213.186.33.3cluster015.ovh.net.16276OVH_OVH_SystemsFrance
kanienpub.com188.165.199.16ks310048.kimsufi.com.16276OVH_OVH_SystemsFrance
polycliniqueidimed.com213.186.33.17cluster006.ovh.net.16276OVH_OVH_SystemsFrance
quintessence-formation.com178.33.122.76ns223952.ovh.net.16276OVH_OVH_SystemsFrance
discoveryville.com204.12.48.19NONE20021LNH-INC_-_HostMySiteUnitedStates
dowienet.com174.120.194.13486.c2.78ae.static.theplanet.com.21844THEPLANET-AS_-_ThePlanet.com_Internet_Services_Inc.UnitedStates
huashangsrl.com174.121.78.194thorpe.webserversystems.com.21844THEPLANET-AS_-_ThePlanet.com_Internet_Services_Inc.UnitedStates
tajhealth.com46.4.73.16static.16.73.4.46.clients.your-server.de.24940HETZNER-AS_Hetzner_Online_AG_RZGermany
atlasgeomatic.com79.175.163.57afranet.com.25184AFRANET_AFRANET_Co._Tehran_IranIranIslamic
chooum.com146.255.39.1n1nlhg422c1422.shr.prod.ams1.secureserver.net.26496AS-26496-GO-DADDY-COM-LLC_-_GoDaddy.com_LLCNetherlands
dauthentic.com97.74.198.127ip-97-74-198-127.ip.secureserver.net.26496AS-26496-GO-DADDY-COM-LLC_-_GoDaddy.com_LLCUnitedStates
intemporeconsulting.com184.168.184.1p3nlhg206c1206.shr.prod.phx3.secureserver.net.26496AS-26496-GO-DADDY-COM-LLC_-_GoDaddy.com_LLCUnitedStates
qebelemescidi.com184.168.206.1p3nlhg130c1130.shr.prod.phx3.secureserver.net.26496AS-26496-GO-DADDY-COM-LLC_-_GoDaddy.com_LLCUnitedStates
udonvan.com50.63.69.1p3nlhg362c1362.shr.prod.phx3.secureserver.net.26496AS-26496-GO-DADDY-COM-LLC_-_GoDaddy.com_LLCUnitedStates
absofrigginlutely.com77.232.91.22477-232-91-224.static.servage.net.29671SERVAGE_Servage_GmbHEurope
4cservices.net66.96.147.113113.147.96.66.static.eigbox.net.29873BIZLAND-SD_-_The_Endurance_International_Group_Inc.UnitedStates
clinicasdentalesvalrod.com66.96.160.152152.160.96.66.static.eigbox.net.29873BIZLAND-SD_-_The_Endurance_International_Group_Inc.UnitedStates
advanced-directions.com76.163.16.170NONE32392OPENTRANSFER-ECOMMERCE_-_Ecommerce_CorporationUnitedStates
india-computing.com50.6.201.114NONE32392OPENTRANSFER-ECOMMERCE_-_Ecommerce_CorporationUnitedStates
unidadmedicayennire.com173.236.43.155server2.serverhostingmonagas.com.32475SINGLEHOP-INC_-_SingleHopUnitedStates
hunteresmiol.com75.150.17.52webhost3.impalanetworks.com.33654CMCS_-_Comcast_Cable_Communications_Inc.UnitedStates
tiyatrocezve.com94.73.148.18094-73-148-180.cizgi.net.tr.34619CIZGI_Cizgi_Telekomunikasyon_Hizmetleri_Sanayi_Ve_Ticaret_Limited_SirketiTurkey
countrycharmrealty.net216.172.169.37NONE36351SOFTLAYER_-_SoftLayer_Technologies_Inc.UnitedStates
egyscout.com50.22.11.30stormont.accountservergroup.com.36351SOFTLAYER_-_SoftLayer_Technologies_Inc.UnitedStates
kuzsms.com50.116.98.212ns1640.websitewelcome.com.36351SOFTLAYER_-_SoftLayer_Technologies_Inc.UnitedStates
nanakmatta.org50.22.131.15850.22.131.158-static.reverse.softlayer.com.36351SOFTLAYER_-_SoftLayer_Technologies_Inc.UnitedStates
rajivmishra.com50.23.47.20850.23.47.208-static.reverse.softlayer.com.36351SOFTLAYER_-_SoftLayer_Technologies_Inc.UnitedStates
sportsturnout.com184.172.170.98184.172.170.98-static.reverse.softlayer.com.36351SOFTLAYER_-_SoftLayer_Technologies_Inc.UnitedStates
acitcpatiala.com199.79.62.149bh-cp-9.webhostbox.net.40034CONFLUENCE-NETWORK-INC_-_Confluence_Networks_IncUnitedStates
javaenterprises.net208.91.199.120bh-11.webhostbox.net.40034CONFLUENCE-NETWORK-INC_-_Confluence_Networks_IncUnitedStates
erkaauto.com46.235.9.15046.235.9.150.static.teknikdata.com.42910SADECEHOSTING-COM_Hosting_Internet_Hizmetleri_Ltd_StiTurkey
kentplus-temizlik.com93.187.206.11mail.sitedinamik.com.43391NETDIREKT-TR_Netdirekt_A.S.Turkey
drbvreddy.com66.147.242.174box574.bluehost.com.46606UNIFIEDLAYER-AS-1_-_Unified_LayerUnitedStates
myvisioninformatics.com74.220.199.22fast22.fastdomain.com.46606UNIFIEDLAYER-AS-1_-_Unified_LayerUnitedStates
auto-serviser.com94.231.107.137linux33.unoeuro.com.48854ZITCOM_ZITCOM_A/SDenmark
residenzaalponte.com95.141.36.4lnx24.ion.it.49367ASSEFLOW_Seflow_S.N.C._Di_Marco_Brame__&_C.Italy
tropicasolar.com84.243.195.250NONE51088A2B_A2B_Internet_B.V.Netherlands

[カテゴリ:spam観察日記]

by jyake