cNotes 検索 一覧 カテゴリ

Citibankを騙るフィッシング

Published: 2012/12/15

観測日: 2012/12/14

通数: 300通/day

手法: 誘導URL型

目的: マルウェア感染、個人情報搾取

フィッシングとかExploitKit利用した攻撃だとかマルウェア感染だとか手法的な違いはありますが、最近はなんでもかんでも送信元を騙って騙して個人情報奪い取るものばかりなので同じといえば同じ。。。


12/13から大量発生中のフィッシングネタの一つ。年末だから?

こういう時は、ここでは検出できていないたくさんのフィッシングが発生していると思われます。

BHEK2でやられてる改竄サイトが利用されています。

citibankについては「com_ag_google_analytics2」のパターンがほとんです。(一部別のパターンも含まれるようです)

 http://tumrubtong.com/components/com_ag_google_analytics2/alert-service-citi-sign_in.html
 http://bakaymuhendislik.com/images/alert-service-citi-sign_in.html 
 http://ceipfernandogavilan.com/components/com_ag_google_analytics2/alert-service-citi-sign_in.html 

domainip逆引きASAS NameCountry
ancienslps.org41.228.38.39NONE2609TN-BB-AS_Tunisia_BackBone_ASTunisia
pinkfinancialgroup.com117.104.160.137vip-web9-3.ilisys.com.au.7474OPTUSCOM-AS01-AU_SingTel_Optus_Pty_LtdAustralia
proliconplus.com202.142.220.206sith.chaiyohosting.com.7654SIAMGLOBE-AS-AP_Internet_Service_Provider_Co._Ltd.Thailand
taxipuertollano.com217.160.246.129clienteservidor.es.8560ONEANDONE-AS_1&1_Internet_AGGermany
simasultana.com84.95.248.125tpirsum.starltd.net.9116GOLDENLINES-ASN_012_Smile_Communications_Main_Autonomous_SystemIsrael
thairath92.net27.254.38.219dg0038ns1.dragonhispeed.com.9891CSLOX-IDC-AS-AP_CS_LOXINFO_Public_Company_Limited.Thailand
chousehotel.com122.155.13.19ns1-15513019.dragonhispeed.com.9931CAT-AP_The_Communication_Authoity_of_Thailand_CATThailand
kaewjewelry.com122.155.17.187cat17187.thaihostserver.com.9931CAT-AP_The_Communication_Authoity_of_Thailand_CATThailand
massstation.com122.155.0.183NONE9931CAT-AP_The_Communication_Authoity_of_Thailand_CATThailand
miinni.net122.155.7.77server.nanowebhost.com.9931CAT-AP_The_Communication_Authoity_of_Thailand_CATThailand
nettec-solution.com122.155.6.21ns1-1556021.dragonhispeed.com.9931CAT-AP_The_Communication_Authoity_of_Thailand_CATThailand
ukimura.com122.155.1.83server-1551083.dragonhispeed.com.9931CAT-AP_The_Communication_Authoity_of_Thailand_CATThailand
cyprusconx.com209.140.18.132server14.idealhost.ws.11042LANDIS-HOLDINGS-INC_-_Landis_Holdings_IncUnitedStates
maccamsarl.com69.73.165.200roguelj.co.uk.11042LANDIS-HOLDINGS-INC_-_Landis_Holdings_IncUnitedStates
addright-ng.com209.105.246.119NONE13354ASN-EBLGLOBAL_-_EBL_Global_Networks_Inc.UnitedStates
expresspcsupport.com54.234.37.25ec2-54-234-37-25.compute-1.amazonaws.com.14618AMAZON-AES_-_Amazon.com_Inc.UnitedStates
open-ukraine.com31.24.209.34034.vps.ho.ua.15497COLOCALL_Internet_Data_Center__ColoCALL_Ukraine
toddi73.net80.190.202.172web40.heiko-rudolf.de.15598IP-EXCHANGE_IP_Exchange_GmbHGermany
tamilarog.com109.237.132.6alfa3064.alfahosting-server.de.16097HLKOMM_HL_komm_Telekommunikations_GmbHGermany
lafarramedellin.com198.27.78.193hydra.cehis.net.16276OVH_OVH_SystemsCanada
varambon.com87.98.153.75serveur3.3go.fr.16276OVH_OVH_SystemsFrance
911pcs.com173.199.189.36server27.ecuhosting.org.19066WIREDTREE_-_Cogswell_Enterprises_Inc.UnitedStates
themixradioextra.com66.45.255.234server7.datalength.com.19318NJIIX-AS-1_-_NEW_JERSEY_INTERNATIONAL_INTERNET_EXCHANGE_LLCUnitedStates
sithra.com208.76.243.50s307.c4.crucialx.net.20202CRUCIAL_-_Crucial_ParadigmUnitedStates
fastinmatesearch.com198.58.85.2stats.iguana.arvixe.com.21788NOC_-_Network_Operations_Center_Inc.UnitedStates
abyssinianflights.com174.121.134.190be.86.79ae.static.theplanet.com.21844THEPLANET-AS_-_ThePlanet.com_Internet_Services_Inc.UnitedStates
addgoal.com69.93.231.3826.e7.5d45.static.theplanet.com.21844THEPLANET-AS_-_ThePlanet.com_Internet_Services_Inc.UnitedStates
europa-coaches-international.com174.132.79.195c3.4f.84ae.static.theplanet.com.21844THEPLANET-AS_-_ThePlanet.com_Internet_Services_Inc.UnitedStates
gpstrackingtoday.com174.121.37.1267e.25.79ae.static.theplanet.com.21844THEPLANET-AS_-_ThePlanet.com_Internet_Services_Inc.UnitedStates
green-traders.com174.121.134.915b.86.79ae.static.theplanet.com.21844THEPLANET-AS_-_ThePlanet.com_Internet_Services_Inc.UnitedStates
iafethiopia.com174.121.134.189bd.86.79ae.static.theplanet.com.21844THEPLANET-AS_-_ThePlanet.com_Internet_Services_Inc.UnitedStates
konkanibhashamandal.com174.121.85.1589e.55.79ae.static.theplanet.com.21844THEPLANET-AS_-_ThePlanet.com_Internet_Services_Inc.UnitedStates
rslfiji.com74.52.72.432b.48.344a.static.theplanet.com.21844THEPLANET-AS_-_ThePlanet.com_Internet_Services_Inc.UnitedStates
vertilexbd.com174.120.117.187bb.75.78ae.static.theplanet.com.21844THEPLANET-AS_-_ThePlanet.com_Internet_Services_Inc.UnitedStates
ruaxekhongcannuoc.com202.78.227.162mail.atpcorporation.com.vn.24085QTSC-AS-VN_Quang_Trung_Software_City_Development_CompanyVietnam
wiese-steuerberater.com88.84.158.30mv1867.1blu.de.24989IXEUROPE-DE-FRANKFURT-ASN_Equinix_Germany_(Previously_IX_Europe_Germany_AS)Germany
safi-ro.com207.58.135.22server5.jsrhost.com.25847SERVINT_-_ServIntUnitedStates
retablospesce.com200.58.119.117inglaterra.dattaweb.com.27823Dattatec.comArgentina
cpaamerican.org66.96.160.154154.160.96.66.static.eigbox.net.29873BIZLAND-SD_-_The_Endurance_International_Group_Inc.UnitedStates
define-designpreneur.com204.197.246.138host.f3nd.com.30496COLO4_-_Colo4_LLCUnitedStates
mediaworkstudios.com78.142.63.134vps.swaminarayan.in.31083TELEPOINT_Powernet_LtdBulgaria
takarafze.com78.110.50.148cl1-w.ht-systems.ru.31240OLD-HT-SYSTEMS-AS_JSC_Hosting_Telesystems_autonomous_systemRussianFederation
psdtoxhtmlcode.com79.170.44.95web95.extendcp.co.uk.31727NODE4-AS_Node4_Ltd_UKUnitedKingdom
transportjogja.com142.54.184.27NONE32097WII-KC_-_WholeSale_Internet_Inc.UnitedStates
nihapa.com199.48.254.56smart.mambogroup.net.32748STEADFAST_-_Steadfast_NetworksUnitedStates
abonoselbuensembrador.com199.168.186.154alpha.superdnssite.com.33182DIMENOC_-_HostDime.com_Inc.UnitedStates
rajenengg.com119.18.57.67jet.websitedns.in.33480WEBWERKSAS1_-_Web_WerksIndia
haksanotomat.com94.73.146.8094-73-146-80.cizgi.net.tr.34619CIZGI_Cizgi_Telekomunikasyon_Hizmetleri_Sanayi_Ve_Ticaret_Limited_SirketiTurkey
konyafotografevi.com94.73.146.10094-73-146-100.cizgi.net.tr.34619CIZGI_Cizgi_Telekomunikasyon_Hizmetleri_Sanayi_Ve_Ticaret_Limited_SirketiTurkey
evigoldhaliperde.com149.3.131.8585-131-3-149.rackcentre.redstation.net.uk.35662REDSTATION_Redstation_LimitedUnitedKingdom
detectall.com100.42.59.77100.42.59.77-static.reverse.mysitehosted.com.36351SOFTLAYER_-_SoftLayer_Technologies_Inc.UnitedStates
gamedaytickets.com173.193.177.187173.193.177.187-static.reverse.softlayer.com.36351SOFTLAYER_-_SoftLayer_Technologies_Inc.UnitedStates
kenandbamboooz.com216.172.186.201NONE36351SOFTLAYER_-_SoftLayer_Technologies_Inc.UnitedStates
lvcufamily.com173.193.85.77hostvillenigeria.hostvillenigeria.com.36351SOFTLAYER_-_SoftLayer_Technologies_Inc.UnitedStates
siescolombia.org174.37.136.219174.37.136.219-static.reverse.softlayer.com.36351SOFTLAYER_-_SoftLayer_Technologies_Inc.UnitedStates
spiritofqurban.com50.22.174.23250.22.174.232-static.reverse.softlayer.com.36351SOFTLAYER_-_SoftLayer_Technologies_Inc.UnitedStates
sextabletka.com37.140.192.23spl18.hosting.reg.ru.39134SKYMEDIA_United_Network_LLCRussianFederation
jb-solution.com46.182.216.8keurigonline09.nl.39704CJ2-AS_CJ2_Hosting&DevelopmentNetherlands
parlaitalia.com31.31.196.35scp7.hosting.reg.ru.39792ANDERS-AS_Anders_Telecom_Ltd.RussianFederation
artocrafts.com208.91.199.19bh-10.webhostbox.net.40034CONFLUENCE-NETWORK-INC_-_Confluence_Networks_IncUnitedStates
omshivind.com208.91.198.47md-6.webhostbox.net.40034CONFLUENCE-NETWORK-INC_-_Confluence_Networks_IncUnitedStates
pbcwebhosting.com208.91.198.96bh-1.webhostbox.net.40034CONFLUENCE-NETWORK-INC_-_Confluence_Networks_IncUnitedStates
langkawi-carrent.com124.217.248.26NONE45839PIRADIUS-AS_PIRADIUS_NET_AS45839Malaysia
agilemaxima.com69.89.25.169box169.bluehost.com.46606UNIFIEDLAYER-AS-1_-_Unified_LayerUnitedStates
coiffurelifestyle.com173.254.28.136just136.justhost.com.46606UNIFIEDLAYER-AS-1_-_Unified_LayerUnitedStates
hissesor.com66.147.244.94box794.bluehost.com.46606UNIFIEDLAYER-AS-1_-_Unified_LayerUnitedStates
rjewelryd.com66.147.244.107box807.bluehost.com.46606UNIFIEDLAYER-AS-1_-_Unified_LayerUnitedStates
santai-sabang.com69.89.31.218box418.bluehost.com.46606UNIFIEDLAYER-AS-1_-_Unified_LayerUnitedStates
skngas.com50.87.117.4350-87-117-43.unifiedlayer.com.46606UNIFIEDLAYER-AS-1_-_Unified_LayerUnitedStates
windwavessoln.com66.147.244.135box835.bluehost.com.46606UNIFIEDLAYER-AS-1_-_Unified_LayerUnitedStates
softwarehit.com195.88.75.11sh1-n1-gmdc.datacenter.bg.48900INFODATACENTER_Info_Data_Center_Ltd.Bulgaria
stickere.info93.115.203.215215.203.115.93.static.spatiul.ro.50939SPACE-AS_Space_Ro_SrlRomania
bakaymuhendislik.com95.173.165.3030tas5h3.ni.net.tr.51559NETINTERNET_Netinternet_Bilgisayar_ve_Telekomunikasyon_San._ve_Tic._Ltd._Sti.Turkey
beylikduzundekoltukdoseme.com94.102.11.233233k1y77e.ni.net.tr.51559NETINTERNET_Netinternet_Bilgisayar_ve_Telekomunikasyon_San._ve_Tic._Ltd._Sti.Turkey
sandalyegiydirme.net94.102.11.238238zxyogh.ni.net.tr.51559NETINTERNET_Netinternet_Bilgisayar_ve_Telekomunikasyon_San._ve_Tic._Ltd._Sti.Turkey
viabensolutions.com173.205.127.190ehub29.webhostinghub.com.54641INMOTI-1_-_InMotion_Hosting_Inc.UnitedStates
saifakarnkaset.com119.59.120.15ns95.hostinglotus.net.56067METRABYTE-TH_453_Ladplacout_JorakhaebuaThailand
tumrubtong.com119.59.120.8ns83.hostinglotus.net.56067METRABYTE-TH_453_Ladplacout_JorakhaebuaThailand
doitacvang.com103.28.36.191share28-r4.nhanhoa.com.131353NHANHOA-AS-VN_NhanHoa_Software_companyVietnam
ceipfernandogavilan.com86.109.162.236h0101.hostytec.com.196713ABANSYS_AND_HOSTYTEC-AS_Abansys_&_Hostytec_S.L.Spain

[カテゴリ:spam観察日記]

by jyake