cNotes 検索 一覧 カテゴリ

MySpaceからのメッセージを騙るスパム - report.htm

Published: 2012/06/12

観測日: 2012/6/11

通数: 100通/day

手法: 誘導URL型

目的: マルウェア感染

特徴:

サイトに設置されるスクリプトファイルのファイル名が「report.htm」


文面。spaceの文字が抜けてますが。

文中のURL。wordpress系ですね。

 http://fireeu.cric-projects.com/wp-content/themes/default/report.htm
 http://www.mobicommz.com/wp-content/plugins/google-sitemap-generator/report.htm
 http://www.sleepandmeditation.com/wp-content/plugins/google-sitemap-generator/report.htm
 http://www.sophieluk.cn/wp-content/themes/fancy/report.htm 
 http://www.texastrophywildlife.com/wp-content/plugins/report.htm
 http://yourq4success.com/wp-content/themes/leaving/report.htm
 http://www.sitarcresta.co.za/modules/mod_wdbanners/report.htm
 http://www.sj-arifin.com/wp-content/themes/deserted/report.htm
 http://www.weddingdealstoday.com/wp-content/themes/classic/report.htm
 http://free-online-business.net/wp-content/plugins/report.htm
 http://giggoals.com/wp-content/themes/bukowski/report.htm
 http://indiancostumes.org/wp-content/plugins/wp-to-twitter/report.htm
 http://rose-island-bahamas.com/wp-content/themes/default/report.htm
 http://wordpressexperience.com/wp-content/plugins/report.htm
 http://www.kmlhomewares.com/wp-content/plugins/all-in-one-slideshow/report.htm
 http://www.koreagamewatch.com/wp/wp-content/uploads/report.htm
 http://www.neatylee.com/wp-content/plugins/akismet/report.htm
 http://www.ottzen.com/wp-content/themes/classic/report.htm
 http://www.pascalverbeke.be/wp-content/themes/45degrees/report.htm
 http://www.rvgsigns.com/wp-content/plugins/polldaddy/report.htm
 http://www.uipodcast.com/wp-content/themes/default/report.htm
 http://yash.cmyevents.com/wp-content/themes/twentyten/report.htm

domainIP逆引きASAS Namecountry
www.sitarcresta.co.za196.38.40.153mustafa.aserv.co.za.3741ISSouthAfrica
www.koreagamewatch.com222.122.86.218NONE4766KIXS-AS-KR_Korea_TelecomKoreaRepublic
www.kmlhomewares.com220.233.8.179179.8.233.220.static.exetel.com.au.10143EXETEL-AS-AP_Exetel_Pty_LtdAustralia
fireeu.cric-projects.com82.223.160.93mwwc933.servidoresdns.net.20718AS_ARSYS-EURO-1_arsys.esSpain
free-online-business.net174.120.149.98gator1024.hostgator.com.21844THEPLANET-AS_-_ThePlanet.com_Internet_Services_Inc.UnitedStates
rose-island-bahamas.com174.132.156.252fc.9c.84ae.static.theplanet.com.21844THEPLANET-AS_-_ThePlanet.com_Internet_Services_Inc.UnitedStates
wordpressexperience.com174.132.76.170aa.4c.84ae.static.theplanet.com.21844THEPLANET-AS_-_ThePlanet.com_Internet_Services_Inc.UnitedStates
www.sleepandmeditation.com174.120.116.221dd.74.78ae.static.theplanet.com.21844THEPLANET-AS_-_ThePlanet.com_Internet_Services_Inc.UnitedStates
yourq4success.com174.120.155.1247c.9b.78ae.static.theplanet.com.21844THEPLANET-AS_-_ThePlanet.com_Internet_Services_Inc.UnitedStates
www.uipodcast.com74.80.8.1374-80-8-13.MALL.stat.lusfiber.net.25921LAF-CONSOLIDATED-GOV_-_Lafayette_Consolidated_GovernmentUnitedStates
giggoals.com174.127.106.167slmp-550-12.slc.westdc.net.29854WESTHOST_-_WestHost_Inc.UnitedStates
www.sj-arifin.com208.43.165.48208.43.165.48-static.reverse.softlayer.com.36351SOFTLAYER_-_SoftLayer_Technologies_Inc.UnitedStates
www.weddingdealstoday.com96.125.162.102NONE36351SOFTLAYER_-_SoftLayer_Technologies_Inc.UnitedStates
yash.cmyevents.com96.125.164.29NONE36351SOFTLAYER_-_SoftLayer_Technologies_Inc.UnitedStates
www.pascalverbeke.be87.238.162.72vz14.stone-is.net.39234STONE-IS_Stone_Internet_Services_bvbaBelgium
indiancostumes.org66.147.244.129box829.bluehost.com.46606BLUEHOST-AS-2_-_Bluehost_Inc.UnitedStates
www.mobicommz.com70.40.215.4270-40-215-42.hostmonster.com.46606BLUEHOST-AS-2_-_Bluehost_Inc.UnitedStates
www.neatylee.com69.195.78.3969-195-78-39.bluehost.com.46606BLUEHOST-AS-2_-_Bluehost_Inc.UnitedStates
www.rvgsigns.com69.89.27.224box224.bluehost.com.46606BLUEHOST-AS-2_-_Bluehost_Inc.UnitedStates
www.sophieluk.cn69.89.27.228box228.bluehost.com.46606BLUEHOST-AS-2_-_Bluehost_Inc.UnitedStates
www.texastrophywildlife.com69.89.20.49box49.bluehost.com.46606BLUEHOST-AS-2_-_Bluehost_Inc.UnitedStates

[カテゴリ:spam観察日記]

by jyake