BBB - compl.html
Published: 2012/02/22
観測日: 2012/2/21~
通数: 500通~/day
目的: javaの脆弱性を利用した攻撃等→アカウント情報を盗む、FakeAV等
特徴: URLにcompl.html
継続中の攻撃のバリエーションの一つ。ちょっとずつ変えてきます。
メール文中のリンクに使われているサイトは、アカウントを盗まれたサイト系だと思われます。次から次へとたくさんあります。
アンチウィルスの反応が鈍いので、マルウェア自体は改変なくそのまま?
こんな文面。
compl.htmlの中身。
ここから先はいつもどおり。
ダウンロードされるファイル。
jav.jar
(5/43) CVE-2011-3544
obe.jar
(13/43) CVE-2010-0840
メール文面中のリンクに利用されているサイト。アカウントを盗まれたサイトでしょう。
domain | ip | 逆引き | AS | AS Name | Country |
---|---|---|---|---|---|
lege.com.tw | 122.117.4.205 | 122-117-4-205.HINET-IP.hinet.net. | 3462 | HINET_Data_Communication_Business_Group | Taiwan |
magazinfengshui.ro | 89.42.219.102 | vps086.whmpanels.com. | 5606 | KQRO_GTS_Telecom_SRL | Romania |
ninetynine.be | 176.28.21.199 | lvps176-28-21-199.dedicated.hosteurope.de. | 20773 | HOSTEUROPE-AS_Host_Europe_GmbH | Germany |
askerimalzemeleri.com | 127.0.0.1 | localhost. | NONE | HOSTEUROPE-AS_Host_Europe_GmbH | Addressnot |
grupolafuente.com.mx | 72.32.187.62 | mail.estrasol.com.mx. | 33070 | RMH-14_-_Rackspace_Hosting | UnitedStates |
pupilion.pl | 89.161.236.160 | v047912.home.net.pl. | 12824 | HOMEPL-AS_home.pl_autonomous_system | Poland |
crisalide.com | 193.201.171.7 | atargatis.agmasys.com. | 3313 | INET-AS_BT_Italia_S.p.A. | Italy |
jainarayan.in | 75.126.196.199 | 75.126.196.199-static.reverse.softlayer.com. | 36351 | SOFTLAYER_-_SoftLayer_Technologies_Inc. | UnitedStates |
messages.altervista.org | 78.46.89.66 | ns106.altervista.org. | 24940 | HETZNER-AS_Hetzner_Online_AG_RZ | Germany |
woodworkx.co.za | 41.86.104.250 | 41-86-104-250-hosted.hadar.za-dns.com. | 10474 | MWEB-10474 | SouthAfrica |
lmlr.fr | 193.33.169.138 | web24.synten.com. | 35344 | SYNTEN-AS_SYNTEN_SARL | France |
quady-matrix.freehostia.com | 66.40.52.187 | NONE | 11388 | MAXIM_-_Peer_1_Dedicated_Hosting | UnitedStates |
shop-anzeiger.de | 195.225.236.162 | jmnetcreation.viennaweb.at. | 31239 | VIENNAWEB-AS_Internet_Viennaweb_Service_GmbH | Austria |
shop.irancg.com | 174.36.84.92 | ns1.persianservices.com. | 36351 | SOFTLAYER_-_SoftLayer_Technologies_Inc. | UnitedStates |
hermestools.eu | 217.97.216.17 | www.internetdsl.pl. | 5617 | TPNET_Telekomunikacja_Polska_S.A. | Poland |
neu.rautemusik-shop.de | 80.67.28.165 | tarazet.ispgateway.de. | 34011 | DOMAINFACTORY_domainfactory_GmbH | Germany |
richportfordlincoln.com | 207.96.225.40 | virtuals.auto123.com. | 5769 | VIDEOTRON_-_Videotron_Telecom_Ltee | Canada |
shop.aselectro.ro | 188.240.2.85 | 85-2-static.mxserver.ro. | 35818 | WEBFACTOR-AS_Webfactor_SRL | Romania |
wear.illusion-pictures.cz | 88.86.107.79 | mysak.core.mujhost.net. | 39392 | SUPERNETWORK-AS_SuperNetwork_s.r.o. | CzechRepublic |
dime.org | 65.182.101.125 | yuma2.brinkster.com. | 33055 | BCC-65-182-96-0-PHX_-_Brinkster_Communications_Corporation | UnitedStates |
proagris.pl | 95.211.54.140 | da21.domeny.com. | 16265 | LEASEWEB_LeaseWeb_B.V. | Netherlands |
searchcolleges.info | 184.168.53.1 | p3nlhg244c1244.shr.prod.phx3.secureserver.net. | 26496 | AS-26496-GO-DADDY-COM-LLC_-_GoDaddy.com_Inc. | UnitedStates |
shop.latoi.com | 68.178.235.107 | ip-68-178-235-107.ip.secureserver.net. | 26496 | AS-26496-GO-DADDY-COM-LLC_-_GoDaddy.com_Inc. | UnitedStates |
cadys.nexenservices.com | 217.174.203.4 | pauillac.nexen.net. | 16128 | AGARIK-BULLPI-NETWORK_AGARIK_and_BULLPI_provide_WEB_Servers_Hosting_and_dedicated_Internet_Connection | France |
shanebradley.com.au | 198.104.61.25 | shanebradley.com.au. | 2914 | NTT-COMMUNICATIONS-2914_-_NTT_America_Inc. | UnitedStates |
fendleyflowers.com | 209.87.224.150 | colo-a1flowers.storm.ca. | 13319 | S-I-S_-_Storm_Internet_Services | Canada |
glycopyc.com | 41.86.104.183 | hosted.gamma.za-dns.com. | 10474 | MWEB-10474 | SouthAfrica |
studijko.eu | 95.168.205.158 | rio03.vas-server.cz. | 39392 | SUPERNETWORK-AS_SuperNetwork_s.r.o. | CzechRepublic |
avtotrgovina.com | 91.185.211.69 | avtotrgovina.com. | 41828 | TUSMOBIL_TUSMOBIL_network | Slovenia |
blog.livetattva.com | 190.98.219.12 | power52.powerhost.cl. | 14259 | Gtd_Internet_S.A. | Chile |
caramba38.ru | 149.154.67.58 | firstvds.ru. | 29182 | ISPSYSTEM-AS_ISPsystem_Autonomous_System | RussianFederation |
jmgsystemas.com | 127.0.0.1 | localhost. | NONE | ISPSYSTEM-AS_ISPsystem_Autonomous_System | Addressnot |
sophiamichelen.com | 184.168.53.1 | p3nlhg244c1244.shr.prod.phx3.secureserver.net. | 26496 | AS-26496-GO-DADDY-COM-LLC_-_GoDaddy.com_Inc. | UnitedStates |
zaira.ts9.ru | 91.223.216.66 | NONE | 46636 | NATCOWEB_-_NatCoWeb_Corp. | Ukraine |
home.alarak.net | 209.190.61.19 | sv31.byethost31.org. | 10297 | ENET-2_-_eNET_Inc. | UnitedKingdom |
ibdi-edu.com.br | 187.45.207.85 | NONE | 27715 | LocaWeb_Ltda | Brazil |
shoptuning.altervista.org | 78.129.205.116 | ns75.altervista.org. | 20860 | IOMART-AS_Iomart | Italy |
co-basics.nl | 217.18.75.165 | hosted.by.qweb.nl. | 20495 | WEDARE_We_Dare_BV_Autonomous_System | Netherlands |
inframob.com | 82.97.15.156 | 156-receptnet.15-cust.tasfrance.com. | 8554 | ATSAT_TAS_France | France |
casamama.nl | 109.72.86.5 | nl05.pcextreme.nl. | 48635 | PCEXTREME_PCextreme_B.V. | Netherlands |
eprom.wroclaw.pl | 85.128.150.124 | akt124.rev.netart.pl. | 15967 | NETART_NetArt_Spolka_Akcyjna_Spolka_Komandytowo-Akcyjna | Poland |
spicyshop.altervista.org | 78.46.36.176 | ns91.altervista.org. | 24940 | HETZNER-AS_Hetzner_Online_AG_RZ | Germany |
filateliaplebani.it | 193.41.235.41 | slc.servrent.net. | 16257 | REGDOM_Servizi_Internet | Italy |
ome.altervista.org | 78.46.36.176 | ns91.altervista.org. | 24940 | HETZNER-AS_Hetzner_Online_AG_RZ | Germany |
pccamelotshop.altervista.org | 178.63.47.209 | ns114.altervista.org. | 24940 | HETZNER-AS_Hetzner_Online_AG_RZ | Germany |
stigmawear.com | 198.107.28.71 | stigmawear.com. | 2914 | NTT-COMMUNICATIONS-2914_-_NTT_America_Inc. | UnitedStates |
in.somnia.us | 98.131.36.2 | rev.opentransfer.com.2.36.131.98.in-addr.arpa. | 32392 | OPENTRANSFER-ECOMMERCE_-_Ecommerce_Corporation | UnitedStates |
pcbuyit.de | 46.252.27.231 | j21655.servers.jiffybox.net. | 34011 | DOMAINFACTORY_domainfactory_GmbH | Germany |
bransales.com.br | 200.98.246.148 | cpweb0035.servidorwebfacil.com. | 7162 | Itanet_-_Itamarati_On-Line_Ltda. | Brazil |
condemnedtohell.com | 184.168.138.1 | p3nlhg186c1186.shr.prod.phx3.secureserver.net. | 26496 | AS-26496-GO-DADDY-COM-LLC_-_GoDaddy.com_Inc. | UnitedStates |
kriiac.altervista.org | 78.46.70.119 | ns112.altervista.org. | 24940 | HETZNER-AS_Hetzner_Online_AG_RZ | Germany |
by jyake