cNotes 検索 一覧 カテゴリ

Wire Transferスパム - infourl.htm

Published: 2012/11/15

観測日: 2012/11/14

通数: 100通/day

手法: 誘導URL型

目的: マルウェア感染


誘導URLの特徴がこんな感じです。

 http://zakazpaleniatytoniu.pl/infourl.htm
 http://ochronaprawkonsumenta.pl/infourl.htm 
 http://www.leenbeke.be/lb1/sites/default/files/infourl.htm 
 http://de.berenika.biz/sites/default/files/infourl.htm 
 http://erotictrust.info/sites/all/themes/infourl.htm 

いつもどおりBHEK2がらみです。


domainIP逆引きASAS NameCountry
itu.sci.cu.edu.eg193.227.5.25APPL.SCI.CU.EDU.EG.2561EUNEgypt
shliangfan.com61.152.239.145NONE4812CHINANET-SH-AP_China_Telecom_(Group)China
ec.drupal-c.info210.253.109.19NONE7506INTERQ_GMO_InternetIncJapan
mmarketing.ru195.54.209.54father.rinet.ru.8331RINET-AS_Cronyx_Plus_LtdRussianFederation
www.tszh.rinet.ru195.54.209.44vm-5.rinet.ru.8331RINET-AS_Cronyx_Plus_LtdRussianFederation
www.vlankas.ru213.178.50.74mx1.vlankas.ru.8439AISTRussianFederation
jantarstargard.pl89.146.199.169main9.lh.pl.8495INTERNET_AG_INTERNET_AG_Global_NetworkGermany
www.albrock-cafe.de82.165.113.73kundenserver.de.8560ONEANDONE-AS_1&1_Internet_AGGermany
www.cardissa.fr217.160.235.92s15433216.domainepardefaut.fr.8560ONEANDONE-AS_1&1_Internet_AGGermany
www.srtreffen.de82.165.113.73kundenserver.de.8560ONEANDONE-AS_1&1_Internet_AGGermany
nikand.se212.97.132.168ws54.surf-town.net.9120SURFTOWNNET_Surftown_A/SDenmark
www.catriders.com173.245.60.141cf-173-245-60-141.cloudflare.com.13335CLOUDFLARENET_-_CloudFlare_Inc.UnitedStates
www.catriders.com173.245.60.54cf-173-245-60-54.cloudflare.com.13335CLOUDFLARENET_-_CloudFlare_Inc.UnitedStates
erotictrust.info184.73.232.107erotictrust.com.14618AMAZON-AES_-_Amazon.com_Inc.UnitedStates
www.leenbeke.be95.211.20.85x79.alfaservers.com.16265LEASEWEB_LeaseWeb_B.V.Netherlands
18606685528.com115.47.67.112NONE17964DXTNET_Beijing_Dian-Xin-Tong_Network_Technologies_Co._Ltd.China
www.jhrdt.com61.4.83.39NONE17964DXTNET_Beijing_Dian-Xin-Tong_Network_Technologies_Co._Ltd.China
mercurycube.com208.180.24.23park01.gkg.net.18710GKG-NET_-_GKG.NET_INCUnitedStates
www.funasasaude.com.br187.115.161.170mail.funasasaude.com.br.18881Global_Village_TelecomBrazil
soyflaca.com184.106.6.161NONE19994RACKSPACE_-_Rackspace_HostingUnitedStates
www.soyflaca.com.mx184.106.6.161NONE19994RACKSPACE_-_Rackspace_HostingUnitedStates
www.shiftinggearspet.com68.169.52.11NONE20141QUALITYTECH-SUW-300_-_Quality_Technology_Services_LLC.UnitedStates
www.taosalon.co.uk109.104.93.234lvps109-104-93-234.vps.webfusion.co.uk.20738AS20738_Webfusion_Internet_SolutionsUnitedKingdom
www.fayetteimpressions.com75.151.205.4175-151-205-41-Memphis.hfc.comcastbusiness.net.22258COMCAST-22258_-_Comcast_Cable_Communications_Holdings_IncUnitedStates
bammagazine.es78.47.74.165server.beatsandmotion.com.24940HETZNER-AS_Hetzner_Online_AG_RZGermany
de.berenika.biz78.47.176.115kotu.pl.24940HETZNER-AS_Hetzner_Online_AG_RZGermany
www.mv-ettlingenweier.de78.46.109.52imp03.fandert-eservices.de.24940HETZNER-AS_Hetzner_Online_AG_RZGermany
srkopus.com64.131.66.103server.krakenasia.com.25847SERVINT_-_ServIntUnitedStates
www.lab-in-a-box.cc207.58.143.19cle.angellight.net.25847SERVINT_-_ServIntUnitedStates
www.lamperthomes.com69.163.237.211apache2-argon.moscow.dreamhost.com.26347DREAMHOST-AS_-_New_Dream_Network_LLCUnitedStates
solymossandor.hu87.229.26.124x124.dataglobe.eu.29278DENINET-HU-AS_Deninet_KFTHungary
www.radclivecumchackmore.org.uk213.175.211.240vps.cmkemail.net.29550SIMPLYTRANSIT_Simply_Transit_LtdUnitedKingdom
www.arquiestructuras.es67.222.2.40NONE30496COLO4_-_Colo4_LLCUnitedStates
new.tksoluzioni.it82.113.204.37ip6.tell.customers.twt.it.30848IT-TWT-AS_TWT_S.p.A.Italy
www.voiceofpeace.org.uk70.38.122.218NONE32613IWEB-AS_-_iWeb_Technologies_Inc.Canada
www.kcofficials.com65.182.101.165yuma4.brinkster.com.33055BCC-65-182-96-0-PHX_-_Brinkster_Communications_CorporationUnitedStates
printingcheaper.com50.56.134.228NONE33070RMH-14_-_Rackspace_HostingUnitedStates
www.garylinton.com72.29.84.27server.gsdcc.org.33182DIMENOC_-_HostDime.com_Inc.UnitedStates
www.livingtogetherlaw.com72.29.84.27server.gsdcc.org.33182DIMENOC_-_HostDime.com_Inc.UnitedStates
www.villasdeandalucia.com217.12.24.3333.zone-217.12.24.juntadeandalucia.es.34285JJAA-AS_Sociedad_Andaluza_para_el_Desarrollo_de_las_Telecomunicaciones_S.A.Spain
redbridge.whorunslondon.org.uk94.229.167.25magic.effusion.co.uk.34934UKFAST_UKFast.Net_LtdUnitedKingdom
www.mujapple.com89.187.131.48maserati.isol.cz.35592COOLHOUSING-AS_COOLHOUSING_Autonomous_SystemCzechRepublic
finko.ykt.ru77.242.4.74host7.ykt.ru.42451SSN-AS_Limited_Company_Sakha_Sprint_NetworkRussianFederation
www.fest-for-alle.dk193.202.110.86srv86.one.com.51468ONECOM_One.com_A/SDenmark
www.argrp.ru109.68.190.83ns1.gilhost.ru.52201TCTEL_LLC__TC_TEL_RussianFederation
ochronaprawkonsumenta.pl91.228.199.142wirt04.biznes-host.pl.198414BIZNESHOST-AS_Biznes-Host.pl_sp._z_o.o.Poland
xn--zakazmiecenia-0rc.pl91.228.199.142wirt04.biznes-host.pl.198414BIZNESHOST-AS_Biznes-Host.pl_sp._z_o.o.Poland
xn--zakazspoywaniaalkoholu-3ze.pl91.228.199.142wirt04.biznes-host.pl.198414BIZNESHOST-AS_Biznes-Host.pl_sp._z_o.o.Poland
zakazpaleniatytoniu.pl91.228.199.142wirt04.biznes-host.pl.198414BIZNESHOST-AS_Biznes-Host.pl_sp._z_o.o.Poland

改竄された一般サイトなので、CloudFlareのユーザーもこのリストに載ってしまうのは仕方ないですかね。

[カテゴリ:spam観察日記]

by jyake