cNotes 検索 一覧 カテゴリ

Canadian farmacy homeへのリダイレクト - follow.html

Published: 2012/07/16

観測日: 2012/7/13

通数: 100通/day

手法: 誘導URL型

目的: 広告誘導

特徴:

サイトに設置されるスクリプトファイルのファイル名が「follow.html」


文面。文章はないですが、サブジェクトがそのまま薬屋さんです。

誘導URLはこのような感じで、最近の流行っぽいもの。

特徴は「follow.html」というファイル名。

URL
http://elnagh.com.pl/follow.html
http://intranet.rbb-dortmund.de/~diederich/follow.html
http://k66.ru/~antway2006@k66.ru/follow.html
http://karatedo48.ru/follow.html
http://apokalipso.com/follow.html
http://txwifi.com/~1touch/follow.html
http://1124design.com/follow.html
http://169.207.67.16/~cc6106/follow.html
http://64.119.178.220/~cadgis/follow.html
http://93.125.30.55/~addvert/follow.html
http://angelfire.com/~callavsg/follow.html
http://arr.sos-fl.com/follow.html
http://barmasters.de/follow.html
http://bobsboneyard.com/follow.html
http://btf.jino.ru/follow.html
http://d2009883.instant.xoom.it/follow.html
http://denali.websitewelcome.com/~q6470ato/follow.html
http://dishahr.com/follow.html
http://doctorbosom.bos.ru/follow.html
http://edu.bdcom.com/follow.html
http://fam-weimer.de/follow.html
http://ftp2.localtime.com.tr/follow.html
http://garanttm.ru/follow.html
http://gjgg.de/follow.html
http://gvo23699.gvodatacenter.com/~comhelp/follow.html
http://hosting104.perpetualprogress.com/~demo/follow.html
http://leads4free.nl/follow.html
http://lowassociates.co.uk/follow.html
http://members.optusnet.com.au/~p.berrett/follow.html
http://members.upc.nl/~j.hogchem1/follow.html
http://perso.numericable.fr/~berthod-photos/follow.html
http://sc5roman.ro/follow.html
http://secdesign.nl/follow.html
http://sirinu.co.uk/follow.html
http://thurayya.de/follow.html
http://visualprintpanama.com/~visualprint/follow.html
http://www.ceramichesestesi.it/follow.html
http://www.cpdse.com.ar/follow.html
http://www.kolumbus.fi/~g609838/follow.html
http://www.kolumbus.fi/~w409644/follow.html
http://www.mila-volleyball.de/follow.html
http://www.torbo-design.de/follow.html
http://www.users.freenetname.co.uk/~davidwear/follow.html

中身はこのようなスクリプトで、マルウェア感染で見られるものとは異なります。

このスクリプトにより、たとえばこのURLへ飛ばされます。

 http://fastrxmeds.ru/secure.php?cmd=home

そこはいつもの薬屋さん。


リダイレクタが設置されているdomainについて調べてみるとこんな感じ。

domainIP逆引きASAS namecountry
doctorbosom.bos.ru194.186.208.8as3.centre.ru.3216SOVAM-AS_OJSC__Vimpelcom_RussianFederation
garanttm.ru194.186.2.30mail.barstrade.ru.3216SOVAM-AS_OJSC__Vimpelcom_RussianFederation
intranet.rbb-dortmund.de87.139.221.128p578bdd80.dip0.t-ipconnect.de.3320DTAG_Deutsche_Telekom_AGGermany
www.kolumbus.fi193.229.9.132www.kolumbus.fi.3336ELISA-AS_Elisa_OyjFinland
angelfire.com209.202.252.41www.angelfire.com.3561SAVVIS_-_SavvisUnitedStates
hosting104.perpetualprogress.com64.129.185.104hosting104.perpetualprogress.com.4323TWTC_-_tw_telecom_holdings_inc.UnitedStates
members.optusnet.com.au211.29.152.71members.optusnet.com.au.4804MPX-AS_Microplex_PTY_LTDAustralia
arr.sos-fl.com63.250.48.128unix01.hsphere.cc.4906FDS-01_-_Frontline_Data_Services_IncUnitedStates
barmasters.de81.169.145.162wa2.rzone.de.6724STRATO_STRATO_AGGermany
members.upc.nl80.109.240.71members.chello.nl.6830LGI-UPC_UPC_Broadband_Holding_B.V.Austria
www.users.freenetname.co.uk212.159.8.151www.users.freenetname.co.uk.6871PLUSNET_PlusNet_PLCUnitedKingdom
www.users.freenetname.co.uk212.159.9.151www.users.freenetname.co.uk.6871PLUSNET_PlusNet_PLCUnitedKingdom
btf.jino.ru81.177.139.35NONE8342RTCOMM-AS_OJSC_RTComm.RURussianFederation
fam-weimer.de82.165.125.53kundenserver.de.8560ONEANDONE-AS_1&1_Internet_AGGermany
gjgg.de82.165.214.148kundenserver.de.8560ONEANDONE-AS_1&1_Internet_AGGermany
www.mila-volleyball.de82.165.108.93kundenserver.de.8560ONEANDONE-AS_1&1_Internet_AGGermany
www.torbo-design.de82.165.117.64kundenserver.de.8560ONEANDONE-AS_1&1_Internet_AGGermany
d2009883.instant.xoom.it212.48.16.85NONE8660MATRIX-AS_Matrix_S.p.A.Italy
elnagh.com.pl62.75.153.12s61.linuxpl.com.8972PLUSSERVER-AS_intergenia_AGPoland
sc5roman.ro86.35.15.211www1.beonline.ro.9050RTD_ROMTELECOM_S.ARomania
johtobirds.de83.125.75.200edna.bces.de.13237LAMBDANET-AS_Lambdanet_Communications_Deutschland_GmbHGermany
www.ceramichesestesi.it62.48.32.139NONE13284BRT-AS_Brain_Technology_S.p.A.Italy
lowassociates.co.uk213.171.218.115server213-171-218-115.livedns.org.uk.15418FASTHOSTS-INTERNET_Fasthosts_Internet_Ltd._Gloucester_UK.UnitedKingdom
sirinu.co.uk91.215.185.44ns44.supremeservers.co.uk.15510CWCS-PS_Compuweb_Communications_Services_LimitedUnitedKingdom
leads4free.nl62.129.139.135ws14.hosting.nl.15535VIRTUALXS-AS_VirtualXS_Internet_BV_The_NetherlandsNetherlands
secdesign.nl62.129.139.123ws04.hosting.nl.15535VIRTUALXS-AS_VirtualXS_Internet_BV_The_NetherlandsNetherlands
thurayya.de89.31.143.116NONE15598IP-EXCHANGE_IP_Exchange_GmbHGermany
dishahr.com173.231.40.197173-231-40-197.hosted.static.webnx.com.18450WEBNX_-_WebNXUnitedStates
denali.websitewelcome.com69.93.227.34denali.websitewelcome.com.21844THEPLANET-AS_-_ThePlanet.com_Internet_Services_Inc.UnitedStates
edu.bdcom.com210.4.73.254edu.bdcom.com.24122BDCOM-BD-AS-AP_BDCOM_Online_LimitedBangladesh
apokalipso.com176.9.32.71jelena.srv16.com.24940HETZNER-AS_Hetzner_Online_AG_RZGermany
karatedo48.ru90.156.201.100fe.shared.masterhost.ru.25532MASTERHOST-AS_.masterhost_autonomous_systemRussianFederation
karatedo48.ru90.156.201.15fe.shared.masterhost.ru.25532MASTERHOST-AS_.masterhost_autonomous_systemRussianFederation
karatedo48.ru90.156.201.45fe.shared.masterhost.ru.25532MASTERHOST-AS_.masterhost_autonomous_systemRussianFederation
karatedo48.ru90.156.201.82fe.shared.masterhost.ru.25532MASTERHOST-AS_.masterhost_autonomous_systemRussianFederation
1124design.com173.201.169.1p3nlhg72c1008.shr.prod.phx3.secureserver.net.26496AS-26496-GO-DADDY-COM-LLC_-_GoDaddy.com_LLCUnitedStates
www.cpdse.com.ar200.58.112.218kansas.dattaweb.com.27823Dattatec.comArgentina
visualprintpanama.com190.123.192.108NONE27990Hosting_PanamaPanama
k66.ru87.224.128.21k66.ru.35154TELENET-AS_Autonomous_System_of_Teleset-Servis_Ltd.RussianFederation
txwifi.com66.160.208.67none.txwifi.com.36049TX-SKYBEAM_-_JAB_Wireless_INC.UnitedStates
gvo23699.gvodatacenter.com97.79.236.99gvo23699.gvodatacenter.com.46549GVO_-_Global_Virtual_OpportunitiesUnitedStates
bobsboneyard.com66.147.240.179host379.hostmonster.com.46606BLUEHOST-AS-2_-_Bluehost_Inc.UnitedStates
cresenity.com101.50.1.3steady1.lazeon.com.55688BEON-AS-ID_PT._Beon_IntermediaIndonesia
decorbis.pl109.234.111.23az0043.srv.az.pl.196763KEY-SYSTEMS-AS_Key-Systems_GmbHPoland

はやりの改竄のようにも見えますが若干傾向が違うのでサイト自体専用に準備されたものも含まれている可能性があります。


広告サイト本体はドメインはロシア、サイト自体は韓国にあります。

 domain:        FASTRXMEDS.RU
 nserver:       ns1.netegg.ru.
 nserver:       ns2.everserver.ru.
 state:         REGISTERED, DELEGATED, UNVERIFIED
 person:        Private Person
 registrar:     NAUNET-REG-RIPN
 admin-contact: https://client.naunet.ru/c/whoiscontact
 created:       2012.07.11
 paid-till:     2013.07.11
 free-date:     2013.08.11
 source:        TCI
 
 180.70.9.78
 
 inetnum:        180.64.0.0 - 180.71.255.255
 netname:        broadNnet
 descr:          Hanaro Telecom
 descr:          Shindongah Bldg, 43, Taepyeongno2ga, Junggu, Seoul
 descr:          ****************************************
 descr:          Allocated to KRNIC Member.
 descr:          If you would like to find assignment
 descr:          information in detail please refer to
 descr:          the KRNIC Whois Database at:
 descr:          http://whois.nic.or.kr/english/index.htm
 descr:          ****************************************
 country:        KR

[カテゴリ:spam観察日記]

by jyake