cNotes 検索 一覧 カテゴリ

BBB - redirect to reven.html

Published: 2012/02/27

観測日: 2012/2/25 1日だけ

通数: 1000通/day

手法: メール文中に誘導リンク

目的: javaの脆弱性を利用した攻撃等→アカウント情報を盗む、FakeAV等と思われる。。

特徴: URLにreven.html

ひきつづきBBB系のバリエーションです。


いつもの文面。

今回はreven.html。

画面的には

以下はいつもどおり。

検体を収集できませんでした。。。。。


リンクの例。

domainpath
2001futon.comstore/images/reven.html
34chowringeelane.comreven.html
adolfhitler.atwp-content/plugins/is-human/reven.html
allfloridahosting.comoscommerce/images/reven.html
amazonandbeyond.comcatalog/reven.html
amiputabola.comwp-content/uploads/fgallery/reven.html
asttechno.comwp-content/uploads/fgallery/reven.html
banphuepit.ac.thwp-content/uploads/fgallery/reven.html
bestmonogram.comimages/reven.html
blog.portalmogiguacu.com.brwp-content/uploads/fgallery/reven.html
bottediferro.comblog/wp-content/plugins/is-human/reven.html
buytoyguns.comshop/reven.html
check-aribau.esShop/reven.html
con.callnet.dkextremchokes.dk/netbutik/images/reven.html
creaturecomfortsinc.comcatalog/reven.html
dcomlao.comapp/oscommerce/reven.html
dunkislife.zi-am.comwp-content/uploads/fgallery/reven.html
ehandelonline.comus/catalog/reven.html
goannatree.comwp-content/uploads/fgallery/reven.html
grupolafuente.com.mximages/reven.html
hermestools.eusklep/reven.html
home.alarak.netwp-content/uploads/fgallery/reven.html

あいかわらず改ざんされていると思われるサイトたくさんありますね。

domainip逆引きASAS NameCountry
128.241.193.233128.241.193.233www.hannhomes.com.2914NTT-COMMUNICATIONS-2914_-_NTT_America_Inc.UnitedStates
163.32.57.6163.32.57.6stu.kghs.kh.edu.tw.1659ERX-TANET-ASN1_Tiawan_Academic_Network_(TANet)_Information_CenterTaiwan
164.125.9.9164.125.9.9dnkim.ed.pusan.ac.kr.9274PUSAN-AS-KR_Pusan_National_UniversityKorea
194.226.148.40194.226.148.40km.ur.ru.3253OJSC__Vimpelcom_RussianFederation
198.106.106.113198.106.106.113www.hayadecoracoes.com.br.2914NTT-COMMUNICATIONS-2914_-_NTT_America_Inc.UnitedStates
198.106.108.74198.106.108.74www.pactosistemas.com.br.2914NTT-COMMUNICATIONS-2914_-_NTT_America_Inc.UnitedStates
198.106.109.144198.106.109.144www.viannaerios.com.br.2914NTT-COMMUNICATIONS-2914_-_NTT_America_Inc.UnitedStates
198.106.37.126198.106.37.126www.hojejornal.com.2914NTT-COMMUNICATIONS-2914_-_NTT_America_Inc.UnitedStates
198.106.74.184198.106.74.184www.antares.eng.br.2914NTT-COMMUNICATIONS-2914_-_NTT_America_Inc.UnitedStates
198.65.44.14198.65.44.14www.neno.com.br.2914NTT-COMMUNICATIONS-2914_-_NTT_America_Inc.UnitedStates
200.196.254.27200.196.254.27200-196-254-27.ticbrasil.com.br.11419Telefonica_Empresas_SABrazil
200.58.112.168200.58.112.168bariloche.dattaweb.com.27823Dattatec.comArgentina
202.30.32.221202.30.32.221micvod.kyungsung.ac.kr.9691KYUNGSUNG-AS_KYUNGSUNG_UNIVERSITYKorea
203.157.114.11203.157.114.11NONE9835GITS-TH-AS-AP_Government_Information_Technology_ServicesThailand
203.234.117.131203.234.117.131NONE4766KIXS-AS-KR_Korea_TelecomKorea
210.114.220.143210.114.220.143NONE4670HYUNDAI-KR_ShinbiroKorea
211.239.162.41211.239.162.41NONE9848GNGAS_Enterprise_NetworksKorea
216.119.84.104216.119.84.104NONE14992CRYSTALTECH_-_CrystalTech_Web_Hosting_Inc.UnitedStates
221.143.46.33221.143.46.33NONE9318HANARO-AS_Hanaro_Telecom_Inc.Korea
34chowringeelane.com184.172.15.146184.172.15.146-static.reverse.softlayer.com.36351SOFTLAYER_-_SoftLayer_Technologies_Inc.UnitedStates
3dclothing.co.uk91.103.220.47server.routeone-solutions.co.uk.29550SIMPLYTRANSIT_Simply_Transit_LtdUnitedKingdom
61.19.247.19261.19.247.192cat18.thaihostserver.com.9931CAT-AP_The_Communication_Authoity_of_Thailand_CATThailand
66.51.164.20066.51.164.200www9.pacificonline.com.13768PEER1_-_Peer_1_Network_Inc.Canada
93.88.240.20293.88.240.202imu212.infomaniak.ch.29222INFOMANIAK-AS_Infomaniak_Network_SASwitzerland
acsoftbiz2.net203.146.252.209siamwebhost.net.4750CSLOXINFO-AS-AP_CS_LOXINFO_PUBLIC_COMPANY_LIMITEDThailand
adolfhitler.at99.198.108.210server2.viabandwidth.com.32475SINGLEHOP-INC_-_SingleHopUnitedStates
allfloridahosting.com65.254.231.12965-254-231-129.yourhostingaccount.com.29873BIZLAND-SD_-_The_Endurance_International_Group_Inc.UnitedStates
altamiralogistica.com200.57.147.12cust-200-57-147-12.triara.com.19373Triara.com_S.A._de_C.V.Mexico
amazonandbeyond.com98.136.92.206p4p.geo.vip.ac4.yahoo.com.14778INKTOMI-LAWSON_-_Inktomi_CorporationUnitedStates
amiputabola.com188.165.135.74ns1.blogsting.com.16276OVH_OVH_SystemsSpain
amtex.com.pl46.29.22.161www.linux.webserwer.pl.197226SPRINT-SDCSPRINTS.A.Poland
asttechno.com61.19.246.34cat67.thaihostserver.com.9931CAT-AP_The_Communication_Authoity_of_Thailand_CATThailand
ballarte.com66.7.217.31wco1.hostdime.com.co.33182DIMENOC---HOSTDIME_-_HostDime.com_Inc.UnitedStates
banphuepit.ac.th203.114.108.213203-114-108-213.totisp.net.9737TOTNET-TH-AS-AP_TOT_Public_Company_LimitedThailand
bestmonogram.com173.239.7.190NONE27257WEBAIR-INTERNET_-_Webair_Internet_Development_Company_Inc.UnitedStates
bitinfosys.com209.237.151.15wdpfarm001.sites.myregisteredsite.com.36476WEB-COM-ASN1_-_Web.com_Inc.UnitedStates
bottediferro.com158.58.172.5www.bottediferro.com.49367ASSEFLOW_Seflow_S.N.C._Di_Marco_Brame__&_C.Italy
buytoyguns.com216.164.205.63www.buytoyguns.com.6079RCN-AS_-_RCN_CorporationUnitedStates
cantaci.com85.159.68.118googlebilisim.com.34619CIZGI_Cizgi_Telekomunikasyon_Hizmetleri_Sanayi_Ve_Ticaret_Limited_SirketiTurkey
capgateway.net92.48.108.50NONE29550SIMPLYTRANSIT_Simply_Transit_LtdUnitedKingdom
check-aribau.es62.57.72.9962.57.72.99.dyn.user.ono.com.6739ONO-AS_Cableuropa_-_ONOSpain
citizenphil.co.uk194.79.28.133ohwebserver3.openhosts.com.33970OPENHOSTING_M247_LtdUnitedKingdom
colegioaprendiz.com.br204.16.1.200sites-manaus-braslink-com-manaus.braslink.com.20406BRASLINK_-_Braslink_Network_IncUnitedStates
con.callnet.dk91.197.250.21NONE174COGENT_Cogent/PSIDenmark
creaturecomfortsinc.com72.18.198.99lasvegas-nv-datacenter.com.26277PREMIANET_-_Las_Vegas_NV_DatacenterUnitedStates
creditsanook.com122.155.10.153ns37.hostingdynamo.net.9931CAT-AP_The_Communication_Authoity_of_Thailand_CATThailand
dcomlao.com65.254.250.10365-254-250-103.yourhostingaccount.com.29873BIZLAND-SD_-_The_Endurance_International_Group_Inc.UnitedStates
dir-con.cz217.11.237.122chinook.internetservice.cz.15685CASABLANCA-AS_Casablanca_INT_Autonomous_systemCzech
dunkislife.zi-am.com61.19.252.222mail.getideahost.com.9931CAT-AP_The_Communication_Authoity_of_Thailand_CATThailand
dunkislife.zi-am.com61.19.252.222mail.thai-dns4.net.9931CAT-AP_The_Communication_Authoity_of_Thailand_CATThailand
ebookzforsale.com63.250.48.85nt22.hsphere.cc.4906FDS-01_-_Frontline_Data_Services_IncUnitedStates
ecofrost.gr88.198.26.162main.hellashost.info.24940HETZNER-AS_Hetzner_Online_AG_RZGermany
edremitzeytinyagi.com94.73.129.214www.garantiweb.com.34619CIZGI_Cizgi_Telekomunikasyon_Hizmetleri_Sanayi_Ve_Ticaret_Limited_SirketiTurkey
ehandelonline.com212.97.132.142ws42.surf-town.net.9120COHAESIONET_Cohaesio_A/SDenmark
elecgeepmi.com188.39.7.236188-39-7-236.static.enta.net.8468ENTANET_ENTANET_International_LtdUnitedKingdom
electricbrochures.com63.250.54.136hsphere.cc.4906FDS-01_-_Frontline_Data_Services_IncUnitedStates
emhart.org.uk81.21.74.208ds5898.dedicated.turbodns.co.uk.20738AS20738_Webfusion_Internet_SolutionsUnitedKingdom
energymosbat.com67.205.96.39ip-67-205-96-39.static.privatedns.com.32613IWEB-AS_-_iWeb_Technologies_Inc.Canada
enginelektronik.com94.73.129.216www.garantiweb.com.34619CIZGI_Cizgi_Telekomunikasyon_Hizmetleri_Sanayi_Ve_Ticaret_Limited_SirketiTurkey
expense.pheno.com203.146.43.80WH-SH01.csloxinfo.com.9891CSLOX-IDC-AS-AP_CS_LOXINFO_Public_Company_Limited.Thailand
fiber.interbgc.com217.18.240.143unknown.interbgc.com.13124IBGC_Blizoo_Media_and_Broadband_EADBulgaria
fotokvadrat.ru77.221.140.10077.221.140.100.addr.datapoint.ru.30968INFOBOX-AS_Infobox.ru_Autonomous_SystemRussianFederation
g.lapresle.perso.sfr.fr86.65.123.7070.123.65.86.rev.sfr.net.15557LDCOMNET_Societe_Francaise_du_Radiotelephone_S.AFrance
goannatree.com109.235.146.19thrace.decodegrid.net.57168ICH-AS_BBS_Commerce_LtdUnitedKingdom
grolimond.ch84.16.80.56www.grolimond.ch.29222INFOMANIAK-AS_Infomaniak_Network_SASwitzerland
grupolafuente.com.mx72.32.187.62mail.estrasol.com.mx.33070RMH-14_-_Rackspace_HostingUnitedStates
hermestools.eu217.97.216.17www.internetdsl.pl.5617TPNET_Telekomunikacja_Polska_S.A.Poland
home.alarak.net209.190.61.19sv31.byethost31.org.10297ENET-2_-_eNET_Inc.UnitedKingdom
in.somnia.us98.131.36.2rev.opentransfer.com.2.36.131.98.in-addr.arpa.32392OPENTRANSFER-ECOMMERCE_-_Ecommerce_CorporationUnitedStates
innerharmonyyoga.org207.148.241.1212.241.148.207.static.yourhostingaccount.com.29873BIZLAND-SD_-_The_Endurance_International_Group_Inc.UnitedStates
ipos.net.pk63.250.48.74nt11.hsphere.cc.4906FDS-01_-_Frontline_Data_Services_IncUnitedStates
itjiankang.com106.187.35.50li378-50.members.linode.com.2516KDDI_KDDI_CORPORATIONJapan
jvlv.demvar.lv80.90.12.62mail.demvar.lv.21156DATAGRUPA_SIADatagrupa.lvMarijas_7_-_412a_Riga_LV-1050_LATVIALatvia
katzfarm.katzandco.com74.208.105.59NONE8560ONEANDONE-AS_1&1_Internet_AGUnitedStates
kingkledshop.pl91.203.134.42h091203134042.nephax.net.43333NEPHAX-AS_CIS_NEPHAXPoland
klantenmonitor.nl212.78.185.210eswp04.easyserver.net.8220COLT_COLT_Technology_Services_Group_LimitedNetherlands
klausbiedermann.com92.43.96.130cluster.vim.at.49322VIM-AS_ViM_Internetdienstleistungen_GmbHAustria
km.ur.ru194.226.148.40km.ur.ru.3253OJSC__Vimpelcom_RussianFederation
ladtechprojects2.com63.250.48.74nt11.hsphere.cc.4906FDS-01_-_Frontline_Data_Services_IncUnitedStates
larive.pascal.perso.neuf.fr86.65.123.7070.123.65.86.rev.sfr.net.15557LDCOMNET_Societe_Francaise_du_Radiotelephone_S.AFrance
masscardsaa.com72.167.140.141ip-72-167-140-141.ip.secureserver.net.26496AS-26496-GO-DADDY-COM-LLC_-_GoDaddy.com_Inc.UnitedStates
mba.lpru.ac.th202.29.58.15NONE24214RAJABHATLAMPANGCSLOX-AS-TH_Rajabhat_LampangThailand
michaeljlira.com74.50.94.23474-50-94-234.static.hostdepartment.com.19318NJIIX-AS-1_-_NEW_JERSEY_INTERNATIONAL_INTERNET_EXCHANGE_LLCUnitedStates
monkey2011.web-144.com111.67.201.170NONE4847CNIX-AP_China_Networks_Inter-ExchangeChina
mp3servis.com31.210.77.22server-31.210.77.22.as42926.net.42926RADORE_Radore_Hosting_Telekomunikasyon_Hizmetleri_San._ve_Tic._Ltd._Sti.Turkey
mumbaiprod.com80.248.217.39NONE13193ASN-NERIM_Nerim_SASFrance
musiciansmall.in180.149.240.79RX2117.rapidns.com.33480WEBWERKSAS1_-_Web_WerksIndia
nervedjsemf.com69.64.76.175mail.nervedjsemf.com.10316CODERO-AS_-_CoderoUnitedStates
nonghai.net122.155.169.42NONE9931CAT-AP_The_Communication_Authoity_of_Thailand_CATThailand
oberoi-is.org75.125.188.66NONE21844THEPLANET-AS_-_ThePlanet.com_Internet_Services_Inc.UnitedStates
oldbitpc.it188.121.58.1n1nlhg64c118.shr.prod.ams1.secureserver.net.26496AS-26496-GO-DADDY-COM-LLC_-_GoDaddy.com_Inc.Netherlands
orgovan.eu80.250.5.74server.nethouse.cz.21430WIA-AS_WIA_spol._s_r.o._Prague_Czech_Czech
oroexcel.com72.32.187.62mail.estrasol.com.mx.33070RMH-14_-_Rackspace_HostingUnitedStates
propetglobal.com209.237.151.16wdpfarm002.sites.myregisteredsite.com.36476WEB-COM-ASN1_-_Web.com_Inc.UnitedStates
psafrica.com173.0.139.251NONE53628APYLI-AS_-_Apyl_IncUnitedStates
psthechildren.org.my202.75.40.197mail5.e-globalhosting.com.17971TMVADS-AP_TM-VADS_Datacenter_ManagementMalaysia
pupilion.pl89.161.236.160v047912.home.net.pl.12824HOMEPL-AS_home.pl_autonomous_systemPoland
quady-matrix.freehostia.com66.40.52.187NONE11388MAXIM_-_Peer_1_Dedicated_HostingUnitedStates
redhotnights.com109.108.135.125mail.weaveaweb.co.uk.8553AVENSYS_Avensys_Networks_LtdUnitedKingdom
rhinotoughgraphics.com204.177.187.202NONE4208THE-ISERV-COMPANY_-_The_Iserv_Company_LLCUnitedStates
scan.com.sg209.237.151.17wdpfarm003.sites.myregisteredsite.com.36476WEB-COM-ASN1_-_Web.com_Inc.UnitedStates
shakuf.biz212.199.166.181212.199.166.181.forward.012.net.il.9116GOLDENLINES-ASN_012_Smile_Communications_Main_Autonomous_SystemIsrael
shanebradley.com.au198.104.61.25shanebradley.com.au.2914NTT-COMMUNICATIONS-2914_-_NTT_America_Inc.UnitedStates
shop.latoi.com68.178.235.107ip-68-178-235-107.ip.secureserver.net.26496AS-26496-GO-DADDY-COM-LLC_-_GoDaddy.com_Inc.UnitedStates
sp-moulding.com.pl83.16.167.14agl14.internetdsl.tpnet.pl.5617TPNET_Telekomunikacja_Polska_S.A.Poland
stigmawear.com198.107.28.71stigmawear.com.2914NTT-COMMUNICATIONS-2914_-_NTT_America_Inc.UnitedStates
stinehk.net193.202.110.204srv204.one.com.51468ONECOM_One.com_A/SDenmark
studioaudiovisual.com.ar64.8.117.52win14.securedc.com.17393TRIPNET-HOU_-_Trip.net_Inc.UnitedStates
the-dro.com69.50.215.84server.thewebdesignhub.com.18866ATJEU_-_atjeu_publishing_llcUnitedStates
thenearlynaturalcollection.com98.139.134.174p9p.geo.vip.bf1.yahoo.com.26101YAHOO-3_-_Yahoo!UnitedStates
tools4schools.org.uk78.129.138.153NONE20860IOMART-AS_IomartUnitedKingdom
topmis.com.tw61.221.67.9661-221-67-96.HINET-IP.hinet.net.3462HINET_Data_Communication_Business_GroupTaiwan
vault1.secured-url.com213.171.193.251server213-171-193-251.livedns.org.uk.15418FASTHOSTS-INTERNET_Fasthosts_Internet_Ltd._Gloucester_UK.UnitedKingdom
vspcupsandplates.com64.71.180.16intecons.dns247.com.6939HURRICANE_-_Hurricane_Electric_Inc.UnitedStates
wordpress.xpsserver.poweredbyclear.com24.118.64.149c-24-118-64-149.hsd1.mn.comcast.net.13367COMCAST-13367_-_Comcast_Cable_Communications_Holdings_IncUnitedStates
www.adm-ahtuba.astranet.ru62.183.104.5www2.astranet.ru.35177ASI-AS_OJSC_RostelecomRussianFederation
www.anconacastellaneta.it62.149.130.236webs226.aruba.it.31034ARUBA-ASN_Aruba_S.p.A._-_NetworkItaly
www.burofis.com.tr213.142.141.58213-142-141-058.reverse.adeox.com.16265LEASEWEB_LeaseWeb_B.V.Turkey
www.dakspeurders.nl91.184.0.1591-184-0-15.shared.hostnet.nl.197902HOSTNET_Hostnet_B.V.Netherlands
www.genioyfigura.com62.13.225.19hoswww05.mundivia.es.24856MUNDIVIA-AS_Mundivia_ASSpain
www.ineksulugu.com80.93.221.134windows1.anadoluweb.com.20649TEKLAN-AS_Teklan_Internet_Autonomus_SystemTurkey
www.khokkha.com66.7.193.146saturn.host-care.com.33182DIMENOC---HOSTDIME_-_HostDime.com_Inc.UnitedStates
www.vectorbureau.com.br200.195.192.138dominios.onda.com.br.12140Lanis_LtdaBrazil
www.viorel.fdx.ro80.97.51.85NONE34416FDX-AS_Full_Duplex_SRLRomania
www.zdes-i-teper.ru88.212.201.50vega.mtw.ru.39134SKYMEDIA_United_Network_LLCRussianFederation
www.zfdm.com61.155.152.150NONE23650CHINANET-JS-AS-AP_AS_Number_for_CHINANET_jiangsu_province_backboneChina
wyndhamhall.com66.199.162.12NONE13768PEER1_-_Peer_1_Network_Inc.Canada
xenogoddess.com184.154.12.138cx26.justhost.com.32475SINGLEHOP-INC_-_SingleHopUnitedStates
yoursstuff.com184.105.237.215NONE6939HURRICANE_-_Hurricane_Electric_Inc.UnitedStates
za-armiu.ru46.17.40.108neo.ru-hoster.com.51659ASBAXET_LLC_BAXETRussianFederation
zbornik.cz93.185.104.27www17.pipni.cz.43541VSHOSTING_VSHosting_s.r.o.Czech

[カテゴリ:spam観察日記]

by jyake