Your UPS derivery tracking - upy.htm
Published: 2012/06/18
観測日: 2012/6/16
通数: 200通/day
手法: 誘導URL型
目的: マルウェア感染
特徴:
サイトに設置されるスクリプトファイルのファイル名が「upy.htm」
UPS系のバリエーション
- CVE-2010-1885
- CVE-2012-0507
こんな文面。
URLはこのような感じ。
http://neuafrika.com/wp/wp-content/uploads/fgallery/upy.html http://targetyoursitelocally.com/upy.html http://leftneglected.com/upy.html http://barritshayes.co.uk/upy.html http://discounthandbags.bz6.org/upy.html http://112-gouda.nl/upy.html http://asktheunicorn.com/upy.html http://kay.lensjournal.com/upy.html http://everingwarcraft.com/upy.html http://sweetygreen33.sabahblog.com/upy.html http://bestcamera.iblog365.com/upy.html http://cincinnaticoupons.net/upy.html http://justynsmith.com/upy.html http://iworkwithmusic.com/upy.html http://newsinfo.iblog365.com/upy.html http://advancedesign.ie/upy.html http://twrichards.tateauthor.com/wp-content/uploads/fgallery/upy.html http://barritshayes.co.uk/upy.html http://donziboatsforsalefeaturedintvandfilm.myfirstblog.org/upy.html http://mayflowerquiz.co.uk/upy.html http://slick-deals.org/upy.html http://sneakydragon.com/upy.html http://surfrhythm.com/upy.html http://whistlerblackcombrealestate.com//upy.html http://homesfromepic.com//upy.html http://jamesfrancovideos.myfirstblog.org/upy.html http://skigogglesoakley.runskateboard.com/upy.html http://swtorcredits.b34.us/upy.html http://afterjia.bz6.org/upy.html http://greatblog.myfirstblog.org/upy.html http://homeandrenovation.ca//upy.html http://oralhistory.blogs.suffolk.edu/upy.html http://sundaymovies.iblog365.com/upy.html http://thelosttruthsaboutourlives.tateauthor.com/wp-content/uploads/fgallery/upy.html http://bckamloops.ca//upy.html http://brcine.net/upy.html http://iblog365.com/upy.html http://musiclib.myfirstblog.org/upy.html http://kitesurfstore.net/upy.html http://liveblog.classcaster.net/upy.html http://marketingco-opgroup.com/upy.html http://mubees.com/upy.html http://richpykecomputerservices.com/upy.html http://scarlettjohanssonnews.myfirstblog.org/upy.html http://texnolyze.se/upy.html http://viralcastmedia.com/upy.html http://apaqrashouse.bondageradio.com/upy.html http://blueridgemanorbnb.com/upy.html http://edwardbrownlee.tateauthor.com/wp-content/uploads/fgallery/upy.html http://elgallocomponents.com/upy.html http://espiti.com//upy.html http://goldsgee.sabahblog.com/upy.html http://kidsinternetsafetyguide.com/upy.html http://outboardboatmotor1.iblog365.com/upy.html http://seattlechili.com/upy.html http://solarzmr.nazwa.pl/petrolhearts/wp-content/uploads/fgallery/upy.html http://webdesign.echotam.com/upy.html http://broker.be//upy.html http://cheapiceskatingdresses.com/upy.html http://cyber2day.com//upy.html http://freelancewriterroad.com/upy.html http://freemoviednlds.com/upy.html http://guccioutletse9.sabahblog.com/upy.html http://ispyder.iblog365.com/upy.html http://jamesmac.ca/upy.html http://jimmydiets.iblog365.com/upy.html http://landonslaughter.com/upy.html http://seekrin.com//upy.html http://theharbinger.tateauthor.com/wp-content/uploads/fgallery/upy.html http://uggrao.sabahblog.com/upy.html http://canadagoosejakke.bz6.org/upy.html http://ebay.nuspc.com/upy.html http://neuafrika.com/wp/wp-content/uploads/fgallery/upy.html http://seeksafely.org/upy.html http://tv.nuspc.com/upy.html http://zt96.lifeblogs.org/upy.html http://anne-kerstin-busch.com/upy.html http://cebulifestyles.com/upy.html http://joen.superfastcashmachine.com/upy.html http://le-colombier.net/upy.html http://midwestballers.com/upy.html http://moviesathome.net/upy.html http://skateboardrampshalfpipe.runskateboard.com/upy.html http://targetyoursitelocally.com/upy.html http://terryhall.seobake.com//upy.html http://theservicedoffice.co.uk//upy.html http://totalitati.mug.ro/upy.html http://worship.mccchurch.org/upy.html
ドメインに関する情報。今回はUSが多いパターン。
domain | IP | 逆引き | AS | AS Name | Country |
---|---|---|---|---|---|
everingwarcraft.com | 207.244.194.3 | 207.244.194.3.static.colo.hostirian.com. | 6428 | CDM_-_CDM | UnitedStates |
edwardbrownlee.tateauthor.com | 209.217.63.29 | aux-209-217-63-29.webhero.com. | 7258 | CATALOG-AS7258_-_Catalog.com | UnitedStates |
theharbinger.tateauthor.com | 209.217.63.29 | aux-209-217-63-29.webhero.com. | 7258 | CATALOG-AS7258_-_Catalog.com | UnitedStates |
thelosttruthsaboutourlives.tateauthor.com | 209.217.63.29 | aux-209-217-63-29.webhero.com. | 7258 | CATALOG-AS7258_-_Catalog.com | UnitedStates |
twrichards.tateauthor.com | 209.217.63.29 | aux-209-217-63-29.webhero.com. | 7258 | CATALOG-AS7258_-_Catalog.com | UnitedStates |
mayflowerquiz.co.uk | 94.102.159.107 | server8.custardmedia.co.uk. | 8426 | CLARANET-AS_ClaraNET_LTD | UnitedKingdom |
elgallocomponents.com | 87.106.157.212 | clienteservidor.es. | 8560 | ONEANDONE-AS_1&1_Internet_AG | Spain |
totalitati.mug.ro | 82.77.241.5 | mug.xtekservers.net. | 8708 | RDSNET_RCS_&_RDS_S.A. | Romania |
freelancewriterroad.com | 207.182.131.28 | 1c.83.b6.static.xlhost.com. | 10297 | ENET-2_-_eNET_Inc. | UnitedStates |
cebulifestyles.com | 209.126.208.132 | omswebhosting.com. | 10439 | CARINET_-_CariNet_Inc. | UnitedStates |
liveblog.classcaster.net | 184.72.251.64 | ec2-184-72-251-64.compute-1.amazonaws.com. | 14618 | AMAZON-AES_-_Amazon.com_Inc. | UnitedStates |
asktheunicorn.com | 74.50.4.215 | kokab.lunarservers.com. | 15244 | ADDD2NET-COM-INC-DBA-LUNARPAGES_-_Lunar_Pages | UnitedStates |
solarzmr.nazwa.pl | 85.128.230.241 | anv241.rev.netart.pl. | 15967 | NETART_NetArt_Spolka_Akcyjna_Spolka_Komandytowo-Akcyjna | Poland |
freemoviednlds.com | 82.192.92.66 | hosted-by.leaseweb.com. | 16265 | LEASEWEB_LeaseWeb_B.V. | Netherlands |
afterjia.bz6.org | 87.98.221.77 | 87-98-221-77.ovh.net. | 16276 | OVH_OVH_Systems | France |
canadagoosejakke.bz6.org | 87.98.221.77 | 87-98-221-77.ovh.net. | 16276 | OVH_OVH_Systems | France |
cyber2day.com | 37.49.227.33 | NONE | 16276 | OVH_OVH_Systems | Netherlands |
discounthandbags.bz6.org | 87.98.221.77 | 87-98-221-77.ovh.net. | 16276 | OVH_OVH_Systems | France |
le-colombier.net | 178.33.204.24 | http1.web4all.fr. | 16276 | OVH_OVH_Systems | France |
oralhistory.blogs.suffolk.edu | 192.138.214.163 | studentgroups.suffolk.edu. | 20143 | SUNET-1_-_Suffolk_University | UnitedStates |
jamesmac.ca | 69.27.99.162 | madalsa.com. | 20218 | BLACKSUN_-_BlackSun_Inc. | Canada |
donziboatsforsalefeaturedintvandfilm.myfirstblog.org | 184.82.154.211 | 211.allbee.com.br. | 21788 | NOC_-_Network_Operations_Center_Inc. | UnitedStates |
greatblog.myfirstblog.org | 184.82.154.211 | 211.allbee.com.br. | 21788 | NOC_-_Network_Operations_Center_Inc. | UnitedStates |
jamesfrancovideos.myfirstblog.org | 184.82.154.211 | 211.allbee.com.br. | 21788 | NOC_-_Network_Operations_Center_Inc. | UnitedStates |
musiclib.myfirstblog.org | 184.82.154.211 | 211.allbee.com.br. | 21788 | NOC_-_Network_Operations_Center_Inc. | UnitedStates |
scarlettjohanssonnews.myfirstblog.org | 184.82.154.211 | 211.allbee.com.br. | 21788 | NOC_-_Network_Operations_Center_Inc. | UnitedStates |
homesfromepic.com | 174.120.189.220 | dc.bd.78ae.static.theplanet.com. | 21844 | THEPLANET-AS_-_ThePlanet.com_Internet_Services_Inc. | UnitedStates |
joen.superfastcashmachine.com | 174.122.52.9 | 9.34.7aae.static.theplanet.com. | 21844 | THEPLANET-AS_-_ThePlanet.com_Internet_Services_Inc. | UnitedStates |
justynsmith.com | 74.54.110.186 | ba.6e.364a.static.theplanet.com. | 21844 | THEPLANET-AS_-_ThePlanet.com_Internet_Services_Inc. | UnitedStates |
mubees.com | 69.56.136.40 | 28.88.3845.static.theplanet.com. | 21844 | THEPLANET-AS_-_ThePlanet.com_Internet_Services_Inc. | UnitedStates |
seeksafely.org | 74.53.44.138 | 8a.2c.354a.static.theplanet.com. | 21844 | THEPLANET-AS_-_ThePlanet.com_Internet_Services_Inc. | UnitedStates |
targetyoursitelocally.com | 174.120.43.218 | da.2b.78ae.static.theplanet.com. | 21844 | THEPLANET-AS_-_ThePlanet.com_Internet_Services_Inc. | UnitedStates |
terryhall.seobake.com | 74.53.44.138 | 8a.2c.354a.static.theplanet.com. | 21844 | THEPLANET-AS_-_ThePlanet.com_Internet_Services_Inc. | UnitedStates |
theservicedoffice.co.uk | 174.132.149.185 | b9.95.84ae.static.theplanet.com. | 21844 | THEPLANET-AS_-_ThePlanet.com_Internet_Services_Inc. | UnitedStates |
viralcastmedia.com | 74.54.77.244 | f4.4d.364a.static.theplanet.com. | 21844 | THEPLANET-AS_-_ThePlanet.com_Internet_Services_Inc. | UnitedStates |
webdesign.echotam.com | 174.120.202.222 | de.ca.78ae.static.theplanet.com. | 21844 | THEPLANET-AS_-_ThePlanet.com_Internet_Services_Inc. | UnitedStates |
worship.mccchurch.org | 174.120.136.187 | bb.88.78ae.static.theplanet.com. | 21844 | THEPLANET-AS_-_ThePlanet.com_Internet_Services_Inc. | UnitedStates |
zt96.lifeblogs.org | 174.122.106.103 | 67.6a.7aae.static.theplanet.com. | 21844 | THEPLANET-AS_-_ThePlanet.com_Internet_Services_Inc. | UnitedStates |
seekrin.com | 204.93.165.4 | robinhood.my-hosting-panel.com. | 23352 | SERVERCENTRAL_-_Server_Central_Network | UnitedStates |
leftneglected.com | 100.42.59.15 | stats.weasel.arvixe.com. | 25653 | FORTRESSITX_-_FortressITX | UnitedStates |
iworkwithmusic.com | 65.254.250.103 | 65-254-250-103.yourhostingaccount.com. | 29873 | BIZLAND-SD_-_The_Endurance_International_Group_Inc. | UnitedStates |
neuafrika.com | 66.96.134.29 | 29.134.96.66.static.eigbox.net. | 29873 | BIZLAND-SD_-_The_Endurance_International_Group_Inc. | UnitedStates |
sneakydragon.com | 66.96.160.145 | 145.160.96.66.static.eigbox.net. | 29873 | BIZLAND-SD_-_The_Endurance_International_Group_Inc. | UnitedStates |
bestcamera.iblog365.com | 209.236.126.123 | 209.236.126.123.tailormadeservers.com. | 30496 | COLO4_-_Colo4_LLC | Singapore |
iblog365.com | 209.236.126.123 | 209.236.126.123.tailormadeservers.com. | 30496 | COLO4_-_Colo4_LLC | Singapore |
ispyder.iblog365.com | 209.236.126.123 | 209.236.126.123.tailormadeservers.com. | 30496 | COLO4_-_Colo4_LLC | Singapore |
jimmydiets.iblog365.com | 209.236.126.123 | 209.236.126.123.tailormadeservers.com. | 30496 | COLO4_-_Colo4_LLC | Singapore |
newsinfo.iblog365.com | 209.236.126.123 | 209.236.126.123.tailormadeservers.com. | 30496 | COLO4_-_Colo4_LLC | Singapore |
outboardboatmotor1.iblog365.com | 209.236.126.123 | 209.236.126.123.tailormadeservers.com. | 30496 | COLO4_-_Colo4_LLC | Singapore |
sundaymovies.iblog365.com | 209.236.126.123 | 209.236.126.123.tailormadeservers.com. | 30496 | COLO4_-_Colo4_LLC | Singapore |
anne-kerstin-busch.com | 87.118.114.210 | server16.dmsolutionsonline.de. | 31103 | KEYWEB-AS_Keyweb_AG | Germany |
barritshayes.co.uk | 89.187.66.156 | 156-66-187-89.keepnet.net. | 31708 | COREIX-UK-AS_Coreix_Limited | UnitedKingdom |
richpykecomputerservices.com | 79.170.44.103 | web103.extendcp.co.uk. | 31727 | NODE4-AS_Node4_Ltd_UK | UnitedKingdom |
kidsinternetsafetyguide.com | 67.227.156.197 | host.dumagueteinfo.com. | 32244 | LIQUID-WEB-INC_-_Liquid_Web_Inc. | UnitedStates |
bckamloops.ca | 184.154.82.154 | server2.icanhost.ca. | 32475 | SINGLEHOP-INC_-_SingleHop | UnitedStates |
marketingco-opgroup.com | 208.117.45.193 | marketingco-opgroup.com. | 32748 | STEADFAST_-_Steadfast_Networks | UnitedStates |
brcine.net | 50.115.163.101 | feirabrasileira.feirabrasileira.com.br. | 32875 | VIRPUS_-_DNSSLAVE.COM | UnitedStates |
broker.be | 217.21.184.210 | 217.21.184.210.static.hosted.by.combell.com. | 34762 | COMBELL-AS_Combell_group_NV | Belgium |
kitesurfstore.net | 96.43.91.180 | NONE | 35916 | MULTA-ASN1_-_MULTACOM_CORPORATION | UnitedStates |
apaqrashouse.bondageradio.com | 184.173.213.64 | ns2958.hostgator.com. | 36351 | SOFTLAYER_-_SoftLayer_Technologies_Inc. | UnitedStates |
ebay.nuspc.com | 108.167.172.206 | NONE | 36351 | SOFTLAYER_-_SoftLayer_Technologies_Inc. | UnitedStates |
goldsgee.sabahblog.com | 173.193.108.152 | 173.193.108.152-static.reverse.softlayer.com. | 36351 | SOFTLAYER_-_SoftLayer_Technologies_Inc. | UnitedStates |
guccioutletse9.sabahblog.com | 173.193.108.152 | 173.193.108.152-static.reverse.softlayer.com. | 36351 | SOFTLAYER_-_SoftLayer_Technologies_Inc. | UnitedStates |
kay.lensjournal.com | 216.172.166.234 | NONE | 36351 | SOFTLAYER_-_SoftLayer_Technologies_Inc. | UnitedStates |
landonslaughter.com | 96.125.174.27 | NONE | 36351 | SOFTLAYER_-_SoftLayer_Technologies_Inc. | UnitedStates |
midwestballers.com | 216.172.184.240 | ns3278.hostgator.com. | 36351 | SOFTLAYER_-_SoftLayer_Technologies_Inc. | UnitedStates |
moviesathome.net | 184.172.188.195 | 184.172.188.195-static.reverse.softlayer.com. | 36351 | SOFTLAYER_-_SoftLayer_Technologies_Inc. | UnitedStates |
skateboardrampshalfpipe.runskateboard.com | 216.172.186.167 | NONE | 36351 | SOFTLAYER_-_SoftLayer_Technologies_Inc. | UnitedStates |
skigogglesoakley.runskateboard.com | 216.172.186.167 | NONE | 36351 | SOFTLAYER_-_SoftLayer_Technologies_Inc. | UnitedStates |
slick-deals.org | 184.173.229.64 | ns3002.hostgator.com. | 36351 | SOFTLAYER_-_SoftLayer_Technologies_Inc. | UnitedStates |
surfrhythm.com | 216.172.171.166 | NONE | 36351 | SOFTLAYER_-_SoftLayer_Technologies_Inc. | UnitedStates |
sweetygreen33.sabahblog.com | 173.193.108.152 | 173.193.108.152-static.reverse.softlayer.com. | 36351 | SOFTLAYER_-_SoftLayer_Technologies_Inc. | UnitedStates |
tv.nuspc.com | 108.167.172.206 | NONE | 36351 | SOFTLAYER_-_SoftLayer_Technologies_Inc. | UnitedStates |
uggrao.sabahblog.com | 173.193.108.152 | 173.193.108.152-static.reverse.softlayer.com. | 36351 | SOFTLAYER_-_SoftLayer_Technologies_Inc. | UnitedStates |
advancedesign.ie | 78.153.215.161 | pemlinweb68.blacknight.com. | 39122 | BLACKNIGHT-AS_Blacknight_Internet_Solutions_Ltd | Ireland |
swtorcredits.b34.us | 193.93.205.98 | ip98-205.efuzja.net.pl. | 39760 | EFUZJA-AS_Autonomous_System_for_eFUZJA | Poland |
cincinnaticoupons.net | 67.23.123.130 | mail.hscapcorp.com. | 40015 | MOVECLICKLLC_-_Yellow_Fiber_Networks | UnitedStates |
texnolyze.se | 188.95.227.20 | atapache.citynetwork.se. | 42695 | CNHAB_City_Network_Hosting_AB | Sweden |
cheapiceskatingdresses.com | 97.79.237.230 | 230.237.79.97.gvodatacenter.com. | 46549 | GVO_-_Global_Virtual_Opportunities | UnitedStates |
blueridgemanorbnb.com | 173.254.28.94 | just94.justhost.com. | 46606 | BLUEHOST-AS-2_-_Bluehost_Inc. | UnitedStates |
espiti.com | 69.195.68.95 | 69-195-68-95.bluehost.com. | 46606 | BLUEHOST-AS-2_-_Bluehost_Inc. | UnitedStates |
homeandrenovation.ca | 69.195.93.51 | 69-195-93-51.bluehost.com. | 46606 | BLUEHOST-AS-2_-_Bluehost_Inc. | UnitedStates |
seattlechili.com | 70.40.198.16 | 70-40-198-16.bluehost.com. | 46606 | BLUEHOST-AS-2_-_Bluehost_Inc. | UnitedStates |
whistlerblackcombrealestate.com | 66.147.244.152 | box652.bluehost.com. | 46606 | BLUEHOST-AS-2_-_Bluehost_Inc. | UnitedStates |
112-gouda.nl | 194.247.30.103 | picard11.deziweb.com. | 48539 | OXILION-AS_Oxilion_B.V. | Netherlands |
本体サイト。
Domain Name: AUTOBOURACKY.NET Registrar: REGISTER.COM, INC. Whois Server: whois.register.com Referral URL: http://www.register.com Name Server: SK.S5.CM.NS1.37.ZTOMY.COM Name Server: SK.S5.CM.NS2.37.ZTOMY.COM Status: clientTransferProhibited Updated Date: 16-jun-2012 Creation Date: 08-jun-2012 Expiration Date: 08-jun-2013
IP | 逆引き | AS | AS Name | Country |
---|---|---|---|---|
208.91.197.54 | 208.91.197-54.confluence-networks.com. | 40034 | CONFLUENCE-NETWORK-INC_-_Confluence_Networks_Inc | VirginIslands |
by jyake