BBB - bbb-0923.html
Published: 2012/02/25
観測日: 2012/2/22 1日だけ
通数: 400通/day
手法: メール文中に誘導リンク
目的: javaの脆弱性を利用した攻撃等→アカウント情報を盗む、FakeAV等
特徴: URLにbbb-0923.html
ひきつづきBBB系+java系の脆弱性狙いのバリエーションです。
手法は全く同じなので省略。
文中のリンクに使われるサイトですが
様々な国のサイトが利用されていますが、htmlファイルを設置する場所が下記のようになっていて、改竄に利用するサイトのカテゴリがonlineshop系を多く含まむようになっているようにも見えます。
XXXXX/catalog/bbb-0923.html XXXXX/store/images/bbb-0923.html XXXXX/bookshop/images/bbb-0923.html XXXXX/shop/bbb-0923.html XXXXX/images/bbb-0923.html XXXXX/catalog/images/bbb-0923.html
まぁ、攻撃に利用しているサイトリストの影響だとは思いますが。。。
domain | ip | 逆引き | AS | AS Name | 国 |
---|---|---|---|---|---|
dcinformatica.it | 46.28.4.21 | spartacus.dnshigh.com. | 1267 | ASN-INFOSTRADA_Infostrada_S.p.A. | Italy |
apps.mona.uwi.edu | 196.3.0.143 | NONE | 3586 | UWI_ASN-UWI | Jamaica |
bookshop.mona.uwi.edu | 196.3.0.143 | NONE | 3586 | UWI_ASN-UWI | Jamaica |
parfumuri.shopclick.ro | 89.42.216.150 | server-0119.whmpanels.com. | 5606 | KQRO_GTS_Telecom_SRL | Romania |
buytoyguns.com | 216.164.205.63 | www.buytoyguns.com. | 6079 | RCN-AS_-_RCN_Corporation | UnitedStates |
check-aribau.es | 62.57.72.99 | 62.57.72.99.dyn.user.ono.com. | 6739 | ONO-AS_Cableuropa_-_ONO | Spain |
redhotnights.com | 109.108.135.125 | mail.weaveaweb.co.uk. | 8553 | AVENSYS_Avensys_Networks_Ltd | UnitedKingdom |
access2roues.com | 213.165.85.44 | s15313326.onlinehome-server.info. | 8560 | ONEANDONE-AS_1&1_Internet_AG | Germany |
katzfarm.katzandco.com | 74.208.105.59 | NONE | 8560 | ONEANDONE-AS_1&1_Internet_AG | UnitedStates |
secure.hosts.co.uk | 85.233.160.70 | lb1.namesco.net. | 8622 | ISIONUK_Namesco_Limited | UnitedKingdom |
thelogoworkshop.co.uk | 85.233.160.70 | lb1.namesco.net. | 8622 | ISIONUK_Namesco_Limited | UnitedKingdom |
vivasportt.ro | 86.35.15.216 | www6.linux.romtelecom.net. | 9050 | RTD_ROMTELECOM_S.A | Romania |
ehandelonline.com | 212.97.132.142 | ws42.surf-town.net. | 9120 | COHAESIONET_Cohaesio_A/S | Denmark |
vcmaudio.com | 27.254.36.215 | linux1.ibiznetwork.com. | 9891 | CSLOX-IDC-AS-AP_CS_LOXINFO_Public_Company_Limited. | Thailand |
oscommerce.elektrohurt.net.pl | 89.161.250.238 | v2081514.home.net.pl. | 12824 | HOMEPL-AS_home.pl_autonomous_system | Poland |
redspotdeals.com | 107.22.170.103 | ec2-107-22-170-103.compute-1.amazonaws.com. | 14618 | AMAZON-AES_-_Amazon.com_Inc. | UnitedStates |
amazonandbeyond.com | 98.136.92.206 | p4p.geo.vip.ac4.yahoo.com. | 14778 | INKTOMI-LAWSON_-_Inktomi_Corporation | UnitedStates |
vault1.secured-url.com | 213.171.193.251 | server213-171-193-251.livedns.org.uk. | 15418 | FASTHOSTS-INTERNET_Fasthosts_Internet_Ltd._Gloucester_UK. | UnitedKingdom |
mniammniam.com | 62.121.130.115 | klopsik.mniammniam.pl. | 15541 | CETI-AS_CETI_s.c. | Poland |
mjmm.nazwa.pl | 77.55.50.70 | aby70.rev.netart.pl. | 15967 | NETART_NetArt_Spolka_Akcyjna_Spolka_Komandytowo-Akcyjna | Poland |
proagrinca.corpwakd.net | 64.8.113.13 | web05.rcahost.net. | 17393 | TRIPNET-HOU_-_Trip.net_Inc. | UnitedStates |
pcinfo.rs.ba | 173.199.177.84 | mdm.fantasticno.com. | 19066 | WIREDTREE_-_Cogswell_Enterprises_Inc. | UnitedStates |
megamakeupstore.com | 216.171.167.152 | megamakeupstore.com. | 20155 | OCO-1_-_ORANGE_COUNTY_ONLINE | UnitedStates |
republicofgamers.com.ar | 96.9.162.3 | 96-9-162-3.static.hostnoc.net. | 21788 | NOC_-_Network_Operations_Center_Inc. | UnitedStates |
kickinggearstore.com | 217.15.81.27 | 27-81-15-217.reverse.alphalink.fr. | 25540 | ALPHALINK-AS_Alphalink_ISP | France |
creaturecomfortsinc.com | 72.18.198.99 | lasvegas-nv-datacenter.com. | 26277 | PREMIANET_-_Las_Vegas_NV_Datacenter | UnitedStates |
sexxxvault.com | 173.236.246.149 | sexxxvault.com. | 26347 | DREAMHOST-AS_-_New_Dream_Network_LLC | UnitedStates |
dragon-software.info | 50.63.75.1 | p3nlhg372c1372.shr.prod.phx3.secureserver.net. | 26496 | AS-26496-GO-DADDY-COM-LLC_-_GoDaddy.com_Inc. | UnitedStates |
oldbitpc.it | 188.121.58.1 | n1nlhg64c118.shr.prod.ams1.secureserver.net. | 26496 | AS-26496-GO-DADDY-COM-LLC_-_GoDaddy.com_Inc. | Netherlands |
bestmonogram.com | 173.239.7.190 | NONE | 27257 | WEBAIR-INTERNET_-_Webair_Internet_Development_Company_Inc. | UnitedStates |
bramygarazowe.biz.pl | 94.152.8.10 | host10.kei.pl. | 29522 | KEI_Krakowskie_e-Centrum_Informatyczne_JUMP | Poland |
allfloridahosting.com | 65.254.231.129 | 65-254-231-129.yourhostingaccount.com. | 29873 | BIZLAND-SD_-_The_Endurance_International_Group_Inc. | UnitedStates |
dcomlao.com | 65.254.250.103 | 65-254-250-103.yourhostingaccount.com. | 29873 | BIZLAND-SD_-_The_Endurance_International_Group_Inc. | UnitedStates |
taylored.startlogic.com | 66.96.134.40 | 40.134.96.66.static.eigbox.net. | 29873 | BIZLAND-SD_-_The_Endurance_International_Group_Inc. | UnitedStates |
cravattificioitaliano.it | 62.149.128.151 | mxavas.aruba.it. | 31034 | ARUBA-ASN_Aruba_S.p.A._-_Network | Italy |
cravattificioitaliano.it | 62.149.128.154 | mxd7.aruba.it. | 31034 | ARUBA-ASN_Aruba_S.p.A._-_Network | Italy |
cravattificioitaliano.it | 62.149.128.157 | mxd8.aruba.it. | 31034 | ARUBA-ASN_Aruba_S.p.A._-_Network | Italy |
cravattificioitaliano.it | 62.149.128.160 | mxd1.aruba.it. | 31034 | ARUBA-ASN_Aruba_S.p.A._-_Network | Italy |
cravattificioitaliano.it | 62.149.128.163 | mxd2.aruba.it. | 31034 | ARUBA-ASN_Aruba_S.p.A._-_Network | Italy |
cravattificioitaliano.it | 62.149.128.166 | mxd3.aruba.it. | 31034 | ARUBA-ASN_Aruba_S.p.A._-_Network | Italy |
jadefashion.com | 67.225.234.241 | NONE | 32244 | LIQUID-WEB-INC_-_Liquid_Web_Inc. | UnitedStates |
in.somnia.us | 98.131.36.2 | rev.opentransfer.com.2.36.131.98.in-addr.arpa. | 32392 | OPENTRANSFER-ECOMMERCE_-_Ecommerce_Corporation | UnitedStates |
musiciansmall.in | 180.149.240.79 | RX2117.rapidns.com. | 33480 | WEBWERKSAS1_-_Web_Werks | India |
ksauctiononline.com | 173.165.54.52 | web2.beckteck.net. | 33491 | COMCAST-33491_-_Comcast_Cable_Communications_Inc. | UnitedStates |
electro-magi.ro | 188.240.3.156 | 156-3-static.mxserver.ro. | 35818 | WEBFACTOR-AS_Webfactor_SRL | Romania |
winnerscirclesoftware.com | 65.99.207.15 | winnerscirclesoftware.com. | 36024 | COLO4-CO_-_Colo4_LLC | UnitedStates |
34chowringeelane.com | 184.172.15.146 | 184.172.15.146-static.reverse.softlayer.com. | 36351 | SOFTLAYER_-_SoftLayer_Technologies_Inc. | UnitedStates |
jainarayan.in | 75.126.196.199 | 75.126.196.199-static.reverse.softlayer.com. | 36351 | SOFTLAYER_-_SoftLayer_Technologies_Inc. | UnitedStates |
trendyfashion.ro | 31.14.179.28 | 31.14.179.28.paginieuropene.ro. | 40975 | CHML-AS_CHML_WEB_SERVICES_SRL | Romania |
users.atw.hu | 88.151.96.4 | users.atw.hu. | 41075 | ATW-AS_ATW_Internet_Kft. | Hungary |
jlservice.fr | 195.114.18.160 | 195-114-18-160.ispfr.net. | 41186 | ISPFR-AS_AZURA_NETWORKS | France |
ondevit.com | 195.20.9.29 | mamola.eatserver.nl. | 42949 | WWW-EATSERVER-NL_Eatserver.nl | Netherlands |
indiangiftbazaar.com | 115.124.123.216 | NONE | 45815 | HOSTCOIN-AS-IN-AP_ESDS_Software_Solution_Pvt._Ltd. | India |
bookworld.no | 188.94.217.55 | sherman.teknograd.no. | 56867 | TEKNOGRAD-AS_Teknograd_AS | Norway |
by jyake