cNotes 検索 一覧 カテゴリ

AT&Tを騙るスパム

Published: 2012/08/07

観測日: 2012/8/3

通数: 300通/day

手法: 誘導URL型

目的: マルウェア感染

特徴:

サイトに設置されるスクリプトファイルのファイル名が「atbilred.html」


AT&Tの課金情報を騙る感じ。

久しぶりにみるネタではありますが、結局いつものパターンの攻撃で、誘導URLはこのような感じです。

 http://adif.ro/wp-content/plugins/zumtekuuvef/atbilred.html
 http://adviko.ru/doc/atbilred.html
 http://americafinanciallyenslaved.com/modules/atbilred.html
 http://autismspeech.com/blog/wp-content/plugins/zeuiieoouow/atbilred.html
 http://bigdeal.ro/wp-content/plugins/zeepmjnaoom/atbilred.html
 http://dansvoorhetleven.nl/audio/atbilred.html
 http://deafplus.us/wp/wp-content/plugins/zfoorahmuib/atbilred.html
 http://elecok.de/modules/atbilred.html
 http://flashinlabs.biz/modules/atbilred.html
 http://grandcanyoncelticarts.org/wp-content/plugins/zeexwrufdor/atbilred.html
 http://hexbugnano.co.uk/wp-content/plugins/zexjtehgupg/atbilred.html
 http://hostingtag.com/wp-content/plugins/zuspkmioloe/atbilred.html
 http://indreams.pl/wp-includes/atbilred.html
 http://insuranceforca.com/wp-includes/atbilred.html
 http://issueswithaging.com/wp-content/plugins/zeaaiumxqqi/atbilred.html
 http://jasonrich.com/wp-includes/atbilred.html
 http://lostsoul.ro/wp-content/plugins/zdopwbrdkyv/atbilred.html
 http://masoncerbone.com/wp-content/plugins/zeeyseapoee/atbilred.html
 http://montecorneo.com/images/atbilred.html
 http://nerantzis.gr/modules/atbilred.html
 http://notfallapotheken.ch/modules/atbilred.html
 http://odessa-ua.net/modules/atbilred.html
 http://ooesv.at/modules/atbilred.html
 http://opelgombos.hu/images/atbilred.html
 http://parkhotelpotenza.com/modules/atbilred.html
 http://pmuc.cm/images/atbilred.html
 http://rugia-greifswald.de/images/atbilred.html
 http://sahkosuomilammi.fi/modules/atbilred.html
 http://search-edu.net/wp-admin/atbilred.html
 http://shomrat.net/modules/atbilred.html
 http://solstadhotell.no/modules/atbilred.html
 http://spaconcept.ca/modules/atbilred.html
 http://tevrom.ro/modules/atbilred.html
 http://tfbayonet.com/wp-admin/atbilred.html
 http://thebiographyauthority.com/blog/wp-content/plugins/zupsxcelope/atbilred.html
 http://uedstar.com/wp-content/plugins/zeoxolbbptk/atbilred.html
 http://ukr-vestnik.com/modules/atbilred.html
 http://wavyboy.com/site/wp-content/plugins/zmiufagcija/atbilred.html
domainipnameASAS nameCountry
dansvoorhetleven.nl82.94.206.45www02.netrex.nl.3265XS4ALL-NL_XS4ALL_Internet_BVNetherlands
americafinanciallyenslaved.com173.230.138.27li178-27.members.linode.com.3595GNAXNET-AS_-_Global_Net_Access_LLCUnitedStates
tevrom.ro85.9.56.197wp05.myhost.ro.5606KQRO_GTS_Telecom_SRLRomania
tevrom.ro85.9.56.202wp05.myhost.ro.5606KQRO_GTS_Telecom_SRLRomania
adviko.ru93.125.99.9vh39.hoster.by.6697BELPAK-AS_Republican_Association_BELTELECOMBelarus
solstadhotell.no81.27.45.87phoenix.adept.no.8542BKKB_BKK_Fiber_ASNorway
sahkosuomilammi.fi81.90.69.69u69.myrootshell.com.8624TENUE-AS_Tenue_OyFinland
ooesv.at82.220.34.22330.hostserv.eu.9044SOLNET_BSE_Software_GmbHSwitzerland
flashinlabs.biz89.163.175.3489.163.175.34.static.rdns-uclo.net.13301UNITEDCOLO-AS_UNITED_COLO_GmbHItaly
shomrat.net69.65.119.148usa3.hostbaron.com.14383VCS-AS_-_Virtacore_Systems_IncUnitedStates
deafplus.us216.97.237.203philip.lunariffic.com.15244ADDD2NET-COM-INC-DBA-LUNARPAGES_-_Lunar_PagesUnitedStates
elecok.de80.190.188.144web04.sysfire.de.15598IP-EXCHANGE_IP_Exchange_GmbHGermany
pmuc.cm213.186.33.4cluster003.ovh.net.16276OVH_OVH_SystemsFrance
wavyboy.com94.136.40.103linux.lb.123-reg.co.uk.20738AS20738_Webfusion_Internet_SolutionsUnitedKingdom
notfallapotheken.ch80.74.139.2arvandus.ch-meta.net.21069ASN-METANET_METANET_AG_SwitzerlandSwitzerland
search-edu.net173.212.222.114cloud-la.nextweb.co.in.21788NOC_-_Network_Operations_Center_Inc.UnitedStates
tfbayonet.com173.212.222.114cloud-la.nextweb.co.in.21788NOC_-_Network_Operations_Center_Inc.UnitedStates
nerantzis.gr174.121.78.38dre.dreamwebhellas.com.21844THEPLANET-AS_-_ThePlanet.com_Internet_Services_Inc.UnitedStates
montecorneo.com64.38.37.51cf.surgeservers.net.22576LAYER3-ASN_-_Layered_Technologies_Inc.UnitedStates
odessa-ua.net178.63.61.77static.77.61.63.178.clients.your-server.de.24940HETZNER-AS_Hetzner_Online_AG_RZGermany
parkhotelpotenza.com62.141.39.80apollo.voxweb.it.24961FIBREONE-AS_myLoc_managed_IT_AGGermany
grandcanyoncelticarts.org75.119.205.103apache2-nads.biggs.dreamhost.com.26347DREAMHOST-AS_-_New_Dream_Network_LLCUnitedStates
issueswithaging.com69.163.236.49apache2-twiddle.manila.dreamhost.com.26347DREAMHOST-AS_-_New_Dream_Network_LLCUnitedStates
lostsoul.ro75.119.216.175apache2-blow.storm.dreamhost.com.26347DREAMHOST-AS_-_New_Dream_Network_LLCUnitedStates
opelgombos.hu212.52.180.13schlotter.lanten.hu.28924INTEGRITY-HU-AS_INTEGRITY_Informatics_Ltd.Hungary
indreams.pl94.152.194.355.ires.pl.29522KEI_Krakowskie_e-Centrum_Informatyczne_JUMPPoland
autismspeech.com65.254.248.12865-254-248-128.yourhostingaccount.com.29873BIZLAND-SD_-_The_Endurance_International_Group_Inc.UnitedStates
insuranceforca.com64.29.151.221hostedc40.carrierzone.com.30447INFB2-AS_-_InternetNamesForBusiness.comUnitedStates
hexbugnano.co.uk79.170.44.142web142.extendcp.co.uk.31727NODE4-AS_Node4_Ltd_UKUnitedKingdom
masoncerbone.com69.175.41.2node01.tmdhosting210.com.32475SINGLEHOP-INC_-_SingleHopUnitedStates
jasonrich.com72.29.75.223mac.dizinc.com.33182DIMENOC_-_HostDime.com_Inc.UnitedStates
adif.ro94.60.136.151151-136-static.mxserver.ro.35818WEBFACTOR-AS_Webfactor_SRLRomania
hostingtag.com108.167.149.185NONE36351SOFTLAYER_-_SoftLayer_Technologies_Inc.UnitedStates
spaconcept.ca184.173.11.91184.173.11.91-static.reverse.softlayer.com.36351SOFTLAYER_-_SoftLayer_Technologies_Inc.UnitedStates
bigdeal.ro89.36.25.61NONE39756ROHOSTWAY-AS_HOSTWAY_ROMANIA_SRLRomania
ukr-vestnik.com91.206.200.78d150.ukraine.com.ua.47781ANSUA-AS_DELTA-X_LtdUkraine
rugia-greifswald.de193.202.110.123srv123.one.com.51468ONECOM_One.com_A/SNetherlands

[カテゴリ:spam観察日記]

by jyake