Your UPS derivery tracking - upy.htm
Published: 2012/06/18
観測日: 2012/6/16
通数: 200通/day
手法: 誘導URL型
目的: マルウェア感染
特徴:
サイトに設置されるスクリプトファイルのファイル名が「upy.htm」
UPS系のバリエーション
- CVE-2010-1885
- CVE-2012-0507
こんな文面。
URLはこのような感じ。
http://neuafrika.com/wp/wp-content/uploads/fgallery/upy.html http://targetyoursitelocally.com/upy.html http://leftneglected.com/upy.html http://barritshayes.co.uk/upy.html http://discounthandbags.bz6.org/upy.html http://112-gouda.nl/upy.html http://asktheunicorn.com/upy.html http://kay.lensjournal.com/upy.html http://everingwarcraft.com/upy.html http://sweetygreen33.sabahblog.com/upy.html http://bestcamera.iblog365.com/upy.html http://cincinnaticoupons.net/upy.html http://justynsmith.com/upy.html http://iworkwithmusic.com/upy.html http://newsinfo.iblog365.com/upy.html http://advancedesign.ie/upy.html http://twrichards.tateauthor.com/wp-content/uploads/fgallery/upy.html http://barritshayes.co.uk/upy.html http://donziboatsforsalefeaturedintvandfilm.myfirstblog.org/upy.html http://mayflowerquiz.co.uk/upy.html http://slick-deals.org/upy.html http://sneakydragon.com/upy.html http://surfrhythm.com/upy.html http://whistlerblackcombrealestate.com//upy.html http://homesfromepic.com//upy.html http://jamesfrancovideos.myfirstblog.org/upy.html http://skigogglesoakley.runskateboard.com/upy.html http://swtorcredits.b34.us/upy.html http://afterjia.bz6.org/upy.html http://greatblog.myfirstblog.org/upy.html http://homeandrenovation.ca//upy.html http://oralhistory.blogs.suffolk.edu/upy.html http://sundaymovies.iblog365.com/upy.html http://thelosttruthsaboutourlives.tateauthor.com/wp-content/uploads/fgallery/upy.html http://bckamloops.ca//upy.html http://brcine.net/upy.html http://iblog365.com/upy.html http://musiclib.myfirstblog.org/upy.html http://kitesurfstore.net/upy.html http://liveblog.classcaster.net/upy.html http://marketingco-opgroup.com/upy.html http://mubees.com/upy.html http://richpykecomputerservices.com/upy.html http://scarlettjohanssonnews.myfirstblog.org/upy.html http://texnolyze.se/upy.html http://viralcastmedia.com/upy.html http://apaqrashouse.bondageradio.com/upy.html http://blueridgemanorbnb.com/upy.html http://edwardbrownlee.tateauthor.com/wp-content/uploads/fgallery/upy.html http://elgallocomponents.com/upy.html http://espiti.com//upy.html http://goldsgee.sabahblog.com/upy.html http://kidsinternetsafetyguide.com/upy.html http://outboardboatmotor1.iblog365.com/upy.html http://seattlechili.com/upy.html http://solarzmr.nazwa.pl/petrolhearts/wp-content/uploads/fgallery/upy.html http://webdesign.echotam.com/upy.html http://broker.be//upy.html http://cheapiceskatingdresses.com/upy.html http://cyber2day.com//upy.html http://freelancewriterroad.com/upy.html http://freemoviednlds.com/upy.html http://guccioutletse9.sabahblog.com/upy.html http://ispyder.iblog365.com/upy.html http://jamesmac.ca/upy.html http://jimmydiets.iblog365.com/upy.html http://landonslaughter.com/upy.html http://seekrin.com//upy.html http://theharbinger.tateauthor.com/wp-content/uploads/fgallery/upy.html http://uggrao.sabahblog.com/upy.html http://canadagoosejakke.bz6.org/upy.html http://ebay.nuspc.com/upy.html http://neuafrika.com/wp/wp-content/uploads/fgallery/upy.html http://seeksafely.org/upy.html http://tv.nuspc.com/upy.html http://zt96.lifeblogs.org/upy.html http://anne-kerstin-busch.com/upy.html http://cebulifestyles.com/upy.html http://joen.superfastcashmachine.com/upy.html http://le-colombier.net/upy.html http://midwestballers.com/upy.html http://moviesathome.net/upy.html http://skateboardrampshalfpipe.runskateboard.com/upy.html http://targetyoursitelocally.com/upy.html http://terryhall.seobake.com//upy.html http://theservicedoffice.co.uk//upy.html http://totalitati.mug.ro/upy.html http://worship.mccchurch.org/upy.html
ドメインに関する情報。今回はUSが多いパターン。
| domain | IP | 逆引き | AS | AS Name | Country |
|---|---|---|---|---|---|
| everingwarcraft.com | 207.244.194.3 | 207.244.194.3.static.colo.hostirian.com. | 6428 | CDM_-_CDM | UnitedStates |
| edwardbrownlee.tateauthor.com | 209.217.63.29 | aux-209-217-63-29.webhero.com. | 7258 | CATALOG-AS7258_-_Catalog.com | UnitedStates |
| theharbinger.tateauthor.com | 209.217.63.29 | aux-209-217-63-29.webhero.com. | 7258 | CATALOG-AS7258_-_Catalog.com | UnitedStates |
| thelosttruthsaboutourlives.tateauthor.com | 209.217.63.29 | aux-209-217-63-29.webhero.com. | 7258 | CATALOG-AS7258_-_Catalog.com | UnitedStates |
| twrichards.tateauthor.com | 209.217.63.29 | aux-209-217-63-29.webhero.com. | 7258 | CATALOG-AS7258_-_Catalog.com | UnitedStates |
| mayflowerquiz.co.uk | 94.102.159.107 | server8.custardmedia.co.uk. | 8426 | CLARANET-AS_ClaraNET_LTD | UnitedKingdom |
| elgallocomponents.com | 87.106.157.212 | clienteservidor.es. | 8560 | ONEANDONE-AS_1&1_Internet_AG | Spain |
| totalitati.mug.ro | 82.77.241.5 | mug.xtekservers.net. | 8708 | RDSNET_RCS_&_RDS_S.A. | Romania |
| freelancewriterroad.com | 207.182.131.28 | 1c.83.b6.static.xlhost.com. | 10297 | ENET-2_-_eNET_Inc. | UnitedStates |
| cebulifestyles.com | 209.126.208.132 | omswebhosting.com. | 10439 | CARINET_-_CariNet_Inc. | UnitedStates |
| liveblog.classcaster.net | 184.72.251.64 | ec2-184-72-251-64.compute-1.amazonaws.com. | 14618 | AMAZON-AES_-_Amazon.com_Inc. | UnitedStates |
| asktheunicorn.com | 74.50.4.215 | kokab.lunarservers.com. | 15244 | ADDD2NET-COM-INC-DBA-LUNARPAGES_-_Lunar_Pages | UnitedStates |
| solarzmr.nazwa.pl | 85.128.230.241 | anv241.rev.netart.pl. | 15967 | NETART_NetArt_Spolka_Akcyjna_Spolka_Komandytowo-Akcyjna | Poland |
| freemoviednlds.com | 82.192.92.66 | hosted-by.leaseweb.com. | 16265 | LEASEWEB_LeaseWeb_B.V. | Netherlands |
| afterjia.bz6.org | 87.98.221.77 | 87-98-221-77.ovh.net. | 16276 | OVH_OVH_Systems | France |
| canadagoosejakke.bz6.org | 87.98.221.77 | 87-98-221-77.ovh.net. | 16276 | OVH_OVH_Systems | France |
| cyber2day.com | 37.49.227.33 | NONE | 16276 | OVH_OVH_Systems | Netherlands |
| discounthandbags.bz6.org | 87.98.221.77 | 87-98-221-77.ovh.net. | 16276 | OVH_OVH_Systems | France |
| le-colombier.net | 178.33.204.24 | http1.web4all.fr. | 16276 | OVH_OVH_Systems | France |
| oralhistory.blogs.suffolk.edu | 192.138.214.163 | studentgroups.suffolk.edu. | 20143 | SUNET-1_-_Suffolk_University | UnitedStates |
| jamesmac.ca | 69.27.99.162 | madalsa.com. | 20218 | BLACKSUN_-_BlackSun_Inc. | Canada |
| donziboatsforsalefeaturedintvandfilm.myfirstblog.org | 184.82.154.211 | 211.allbee.com.br. | 21788 | NOC_-_Network_Operations_Center_Inc. | UnitedStates |
| greatblog.myfirstblog.org | 184.82.154.211 | 211.allbee.com.br. | 21788 | NOC_-_Network_Operations_Center_Inc. | UnitedStates |
| jamesfrancovideos.myfirstblog.org | 184.82.154.211 | 211.allbee.com.br. | 21788 | NOC_-_Network_Operations_Center_Inc. | UnitedStates |
| musiclib.myfirstblog.org | 184.82.154.211 | 211.allbee.com.br. | 21788 | NOC_-_Network_Operations_Center_Inc. | UnitedStates |
| scarlettjohanssonnews.myfirstblog.org | 184.82.154.211 | 211.allbee.com.br. | 21788 | NOC_-_Network_Operations_Center_Inc. | UnitedStates |
| homesfromepic.com | 174.120.189.220 | dc.bd.78ae.static.theplanet.com. | 21844 | THEPLANET-AS_-_ThePlanet.com_Internet_Services_Inc. | UnitedStates |
| joen.superfastcashmachine.com | 174.122.52.9 | 9.34.7aae.static.theplanet.com. | 21844 | THEPLANET-AS_-_ThePlanet.com_Internet_Services_Inc. | UnitedStates |
| justynsmith.com | 74.54.110.186 | ba.6e.364a.static.theplanet.com. | 21844 | THEPLANET-AS_-_ThePlanet.com_Internet_Services_Inc. | UnitedStates |
| mubees.com | 69.56.136.40 | 28.88.3845.static.theplanet.com. | 21844 | THEPLANET-AS_-_ThePlanet.com_Internet_Services_Inc. | UnitedStates |
| seeksafely.org | 74.53.44.138 | 8a.2c.354a.static.theplanet.com. | 21844 | THEPLANET-AS_-_ThePlanet.com_Internet_Services_Inc. | UnitedStates |
| targetyoursitelocally.com | 174.120.43.218 | da.2b.78ae.static.theplanet.com. | 21844 | THEPLANET-AS_-_ThePlanet.com_Internet_Services_Inc. | UnitedStates |
| terryhall.seobake.com | 74.53.44.138 | 8a.2c.354a.static.theplanet.com. | 21844 | THEPLANET-AS_-_ThePlanet.com_Internet_Services_Inc. | UnitedStates |
| theservicedoffice.co.uk | 174.132.149.185 | b9.95.84ae.static.theplanet.com. | 21844 | THEPLANET-AS_-_ThePlanet.com_Internet_Services_Inc. | UnitedStates |
| viralcastmedia.com | 74.54.77.244 | f4.4d.364a.static.theplanet.com. | 21844 | THEPLANET-AS_-_ThePlanet.com_Internet_Services_Inc. | UnitedStates |
| webdesign.echotam.com | 174.120.202.222 | de.ca.78ae.static.theplanet.com. | 21844 | THEPLANET-AS_-_ThePlanet.com_Internet_Services_Inc. | UnitedStates |
| worship.mccchurch.org | 174.120.136.187 | bb.88.78ae.static.theplanet.com. | 21844 | THEPLANET-AS_-_ThePlanet.com_Internet_Services_Inc. | UnitedStates |
| zt96.lifeblogs.org | 174.122.106.103 | 67.6a.7aae.static.theplanet.com. | 21844 | THEPLANET-AS_-_ThePlanet.com_Internet_Services_Inc. | UnitedStates |
| seekrin.com | 204.93.165.4 | robinhood.my-hosting-panel.com. | 23352 | SERVERCENTRAL_-_Server_Central_Network | UnitedStates |
| leftneglected.com | 100.42.59.15 | stats.weasel.arvixe.com. | 25653 | FORTRESSITX_-_FortressITX | UnitedStates |
| iworkwithmusic.com | 65.254.250.103 | 65-254-250-103.yourhostingaccount.com. | 29873 | BIZLAND-SD_-_The_Endurance_International_Group_Inc. | UnitedStates |
| neuafrika.com | 66.96.134.29 | 29.134.96.66.static.eigbox.net. | 29873 | BIZLAND-SD_-_The_Endurance_International_Group_Inc. | UnitedStates |
| sneakydragon.com | 66.96.160.145 | 145.160.96.66.static.eigbox.net. | 29873 | BIZLAND-SD_-_The_Endurance_International_Group_Inc. | UnitedStates |
| bestcamera.iblog365.com | 209.236.126.123 | 209.236.126.123.tailormadeservers.com. | 30496 | COLO4_-_Colo4_LLC | Singapore |
| iblog365.com | 209.236.126.123 | 209.236.126.123.tailormadeservers.com. | 30496 | COLO4_-_Colo4_LLC | Singapore |
| ispyder.iblog365.com | 209.236.126.123 | 209.236.126.123.tailormadeservers.com. | 30496 | COLO4_-_Colo4_LLC | Singapore |
| jimmydiets.iblog365.com | 209.236.126.123 | 209.236.126.123.tailormadeservers.com. | 30496 | COLO4_-_Colo4_LLC | Singapore |
| newsinfo.iblog365.com | 209.236.126.123 | 209.236.126.123.tailormadeservers.com. | 30496 | COLO4_-_Colo4_LLC | Singapore |
| outboardboatmotor1.iblog365.com | 209.236.126.123 | 209.236.126.123.tailormadeservers.com. | 30496 | COLO4_-_Colo4_LLC | Singapore |
| sundaymovies.iblog365.com | 209.236.126.123 | 209.236.126.123.tailormadeservers.com. | 30496 | COLO4_-_Colo4_LLC | Singapore |
| anne-kerstin-busch.com | 87.118.114.210 | server16.dmsolutionsonline.de. | 31103 | KEYWEB-AS_Keyweb_AG | Germany |
| barritshayes.co.uk | 89.187.66.156 | 156-66-187-89.keepnet.net. | 31708 | COREIX-UK-AS_Coreix_Limited | UnitedKingdom |
| richpykecomputerservices.com | 79.170.44.103 | web103.extendcp.co.uk. | 31727 | NODE4-AS_Node4_Ltd_UK | UnitedKingdom |
| kidsinternetsafetyguide.com | 67.227.156.197 | host.dumagueteinfo.com. | 32244 | LIQUID-WEB-INC_-_Liquid_Web_Inc. | UnitedStates |
| bckamloops.ca | 184.154.82.154 | server2.icanhost.ca. | 32475 | SINGLEHOP-INC_-_SingleHop | UnitedStates |
| marketingco-opgroup.com | 208.117.45.193 | marketingco-opgroup.com. | 32748 | STEADFAST_-_Steadfast_Networks | UnitedStates |
| brcine.net | 50.115.163.101 | feirabrasileira.feirabrasileira.com.br. | 32875 | VIRPUS_-_DNSSLAVE.COM | UnitedStates |
| broker.be | 217.21.184.210 | 217.21.184.210.static.hosted.by.combell.com. | 34762 | COMBELL-AS_Combell_group_NV | Belgium |
| kitesurfstore.net | 96.43.91.180 | NONE | 35916 | MULTA-ASN1_-_MULTACOM_CORPORATION | UnitedStates |
| apaqrashouse.bondageradio.com | 184.173.213.64 | ns2958.hostgator.com. | 36351 | SOFTLAYER_-_SoftLayer_Technologies_Inc. | UnitedStates |
| ebay.nuspc.com | 108.167.172.206 | NONE | 36351 | SOFTLAYER_-_SoftLayer_Technologies_Inc. | UnitedStates |
| goldsgee.sabahblog.com | 173.193.108.152 | 173.193.108.152-static.reverse.softlayer.com. | 36351 | SOFTLAYER_-_SoftLayer_Technologies_Inc. | UnitedStates |
| guccioutletse9.sabahblog.com | 173.193.108.152 | 173.193.108.152-static.reverse.softlayer.com. | 36351 | SOFTLAYER_-_SoftLayer_Technologies_Inc. | UnitedStates |
| kay.lensjournal.com | 216.172.166.234 | NONE | 36351 | SOFTLAYER_-_SoftLayer_Technologies_Inc. | UnitedStates |
| landonslaughter.com | 96.125.174.27 | NONE | 36351 | SOFTLAYER_-_SoftLayer_Technologies_Inc. | UnitedStates |
| midwestballers.com | 216.172.184.240 | ns3278.hostgator.com. | 36351 | SOFTLAYER_-_SoftLayer_Technologies_Inc. | UnitedStates |
| moviesathome.net | 184.172.188.195 | 184.172.188.195-static.reverse.softlayer.com. | 36351 | SOFTLAYER_-_SoftLayer_Technologies_Inc. | UnitedStates |
| skateboardrampshalfpipe.runskateboard.com | 216.172.186.167 | NONE | 36351 | SOFTLAYER_-_SoftLayer_Technologies_Inc. | UnitedStates |
| skigogglesoakley.runskateboard.com | 216.172.186.167 | NONE | 36351 | SOFTLAYER_-_SoftLayer_Technologies_Inc. | UnitedStates |
| slick-deals.org | 184.173.229.64 | ns3002.hostgator.com. | 36351 | SOFTLAYER_-_SoftLayer_Technologies_Inc. | UnitedStates |
| surfrhythm.com | 216.172.171.166 | NONE | 36351 | SOFTLAYER_-_SoftLayer_Technologies_Inc. | UnitedStates |
| sweetygreen33.sabahblog.com | 173.193.108.152 | 173.193.108.152-static.reverse.softlayer.com. | 36351 | SOFTLAYER_-_SoftLayer_Technologies_Inc. | UnitedStates |
| tv.nuspc.com | 108.167.172.206 | NONE | 36351 | SOFTLAYER_-_SoftLayer_Technologies_Inc. | UnitedStates |
| uggrao.sabahblog.com | 173.193.108.152 | 173.193.108.152-static.reverse.softlayer.com. | 36351 | SOFTLAYER_-_SoftLayer_Technologies_Inc. | UnitedStates |
| advancedesign.ie | 78.153.215.161 | pemlinweb68.blacknight.com. | 39122 | BLACKNIGHT-AS_Blacknight_Internet_Solutions_Ltd | Ireland |
| swtorcredits.b34.us | 193.93.205.98 | ip98-205.efuzja.net.pl. | 39760 | EFUZJA-AS_Autonomous_System_for_eFUZJA | Poland |
| cincinnaticoupons.net | 67.23.123.130 | mail.hscapcorp.com. | 40015 | MOVECLICKLLC_-_Yellow_Fiber_Networks | UnitedStates |
| texnolyze.se | 188.95.227.20 | atapache.citynetwork.se. | 42695 | CNHAB_City_Network_Hosting_AB | Sweden |
| cheapiceskatingdresses.com | 97.79.237.230 | 230.237.79.97.gvodatacenter.com. | 46549 | GVO_-_Global_Virtual_Opportunities | UnitedStates |
| blueridgemanorbnb.com | 173.254.28.94 | just94.justhost.com. | 46606 | BLUEHOST-AS-2_-_Bluehost_Inc. | UnitedStates |
| espiti.com | 69.195.68.95 | 69-195-68-95.bluehost.com. | 46606 | BLUEHOST-AS-2_-_Bluehost_Inc. | UnitedStates |
| homeandrenovation.ca | 69.195.93.51 | 69-195-93-51.bluehost.com. | 46606 | BLUEHOST-AS-2_-_Bluehost_Inc. | UnitedStates |
| seattlechili.com | 70.40.198.16 | 70-40-198-16.bluehost.com. | 46606 | BLUEHOST-AS-2_-_Bluehost_Inc. | UnitedStates |
| whistlerblackcombrealestate.com | 66.147.244.152 | box652.bluehost.com. | 46606 | BLUEHOST-AS-2_-_Bluehost_Inc. | UnitedStates |
| 112-gouda.nl | 194.247.30.103 | picard11.deziweb.com. | 48539 | OXILION-AS_Oxilion_B.V. | Netherlands |
本体サイト。
Domain Name: AUTOBOURACKY.NET Registrar: REGISTER.COM, INC. Whois Server: whois.register.com Referral URL: http://www.register.com Name Server: SK.S5.CM.NS1.37.ZTOMY.COM Name Server: SK.S5.CM.NS2.37.ZTOMY.COM Status: clientTransferProhibited Updated Date: 16-jun-2012 Creation Date: 08-jun-2012 Expiration Date: 08-jun-2013
| IP | 逆引き | AS | AS Name | Country |
|---|---|---|---|---|
| 208.91.197.54 | 208.91.197-54.confluence-networks.com. | 40034 | CONFLUENCE-NETWORK-INC_-_Confluence_Networks_Inc | VirginIslands |
by jyake