intuit incからのオーダー確認を騙るスパム
Published: 2012/03/03
観測日: 2012/3/2
通数: 300通/day
手法: メール文中に誘導リンク
目的: 誘導先でマルウェアダウンロード
特徴: 誘導URLが「http://xxxxxxxx/wp-includes/int-market.html」
これもjava、acrobat等の脆弱性を狙うタイプのバリエーションですが、わずかですが異なる点があります。
攻撃サイトは「.ru:8080」ではないです。
このような文面。
リンクは、このような形でhtmlファイルの中身はいつもと同じスクリプト。
*/wp-includes/int-market.html
アクセスしてからの流れはいつものパターンなので省略。
ダウンロードされるファイルは若干変わりました。
viewer.jar
(6/41)
ap2.php?f=f7d19
(8/43)
リンク先のドメイン。
domain | ip | 逆引き | AS | AS Name | 国 |
---|---|---|---|---|---|
drivefitnessbootcamp.com | 66.104.201.121 | cpanel.tdmg.mx.thornedigital.com. | 2828 | XO-AS15_-_XO_Communications | UnitedStates |
yvondurelle.com | 207.210.85.226 | nuclear.dnsprotect.com. | 3595 | GNAXNET-AS_-_Global_Net_Access_LLC | UnitedStates |
phatsonic.de | 82.165.76.52 | kundenserver.de. | 8560 | ONEANDONE-AS_1&1_Internet_AG | Germany |
pierreaugier.com | 82.165.117.229 | kundenserver.de. | 8560 | ONEANDONE-AS_1&1_Internet_AG | Germany |
test.theoryenterprises.com | 74.208.200.250 | perfora.net. | 8560 | ONEANDONE-AS_1&1_Internet_AG | UnitedStates |
tigerdirectgadgets.com | 50.21.178.174 | perfora.net. | 8560 | ONEANDONE-AS_1&1_Internet_AG | UnitedStates |
tigerdirectgps.com | 50.21.178.174 | perfora.net. | 8560 | ONEANDONE-AS_1&1_Internet_AG | UnitedStates |
tigerdirectkeyboardsandmice.com | 50.21.178.174 | perfora.net. | 8560 | ONEANDONE-AS_1&1_Internet_AG | UnitedStates |
tigerdirectlaptopaccessories.com | 50.21.178.174 | perfora.net. | 8560 | ONEANDONE-AS_1&1_Internet_AG | UnitedStates |
tiltstudios.net | 216.250.114.105 | perfora.net. | 8560 | ONEANDONE-AS_1&1_Internet_AG | UnitedStates |
traverseetours.com | 74.208.242.40 | perfora.net. | 8560 | ONEANDONE-AS_1&1_Internet_AG | UnitedStates |
tiretowheel.com | 209.190.7.66 | 42.7.be.static.xlhost.com. | 10297 | ENET-2_-_eNET_Inc. | UnitedStates |
thompsonnorthwest.com | 184.170.145.135 | NONE | 11051 | CYBERVERSE_-_Cyberverse_Inc. | UnitedStates |
perevod.com.pl | 79.96.45.27 | v062257.home.net.pl. | 12824 | HOMEPL-AS_home.pl_autonomous_system | Poland |
traducteur.com.pl | 79.96.45.27 | v062257.home.net.pl. | 12824 | HOMEPL-AS_home.pl_autonomous_system | Poland |
traduzioni.com.pl | 79.96.45.27 | v062257.home.net.pl. | 12824 | HOMEPL-AS_home.pl_autonomous_system | Poland |
tlh.up45.com | 205.161.30.55 | ip-205-161-30-55.nckcn.com. | 14174 | NCKCN_-_North_Central_Kansas_Community_Network_Co. | UnitedStates |
testing.astutetraveler.com | 174.129.37.255 | ec2-174-129-37-255.compute-1.amazonaws.com. | 14618 | AMAZON-AES_-_Amazon.com_Inc. | UnitedStates |
topsmartphones.de | 89.31.143.116 | NONE | 15598 | IP-EXCHANGE_IP_Exchange_GmbH | Germany |
tlumacz-francuski.eu | 85.232.237.26 | unused-85.232.237.26.greener.pl. | 15694 | ATMAN_ATMAN_Autonomous_System | Poland |
tlumaczenia-ukrainski.eu | 213.189.41.226 | host-213.189.41.226.greener.pl. | 15694 | ATMAN_ATMAN_Autonomous_System | Poland |
tlumaczenia-ukrainski.eu | 217.149.245.178 | host-217.149.245.178.greener.pl. | 15694 | ATMAN_ATMAN_Autonomous_System | Poland |
tophotelfrance.com | 188.165.209.105 | server1.hostamus.com. | 16276 | OVH_OVH_Systems | France |
thisplanet.ru | 85.249.230.35 | NONE | 20597 | ELTEL-AS_ELTEL.NET_Autonomous_System | RussianFederation |
textureandtype.com | 78.129.163.32 | box2.pixeno.com. | 20860 | IOMART-AS_Iomart | UnitedKingdom |
bmwheadquarters.com | 174.121.164.66 | jin.webserversystems.com. | 21844 | THEPLANET-AS_-_ThePlanet.com_Internet_Services_Inc. | UnitedStates |
bmwheadquarters.com | 174.121.164.66 | jin.webserversystems.com. | 21844 | THEPLANET-AS_-_ThePlanet.com_Internet_Services_Inc. | UnitedStates |
thedizzybaker.com | 174.122.37.98 | zemni.site5.com. | 21844 | THEPLANET-AS_-_ThePlanet.com_Internet_Services_Inc. | UnitedStates |
nsi-architects.com | 46.228.193.238 | phl098.http.ph. | 24961 | FIBREONE-AS_fibre_one_networks_GmbH_Duesseldorf | Germany |
alternateendingstudios.net | 184.168.234.1 | p3nlhg144c1144.shr.prod.phx3.secureserver.net. | 26496 | AS-26496-GO-DADDY-COM-LLC_-_GoDaddy.com_Inc. | UnitedStates |
nationalcampaignforqualityeducation.org | 69.161.141.42 | host-69-161-141-42.in2net.com. | 26753 | IN2NET-NETWORK_In2Net_network_inc. | Canada |
emilyquerin.com | 64.29.151.221 | hostedc40.carrierzone.com. | 30447 | INFB2-AS_-_InternetNamesForBusiness.com | UnitedStates |
pinckneysummercamps.com | 209.236.123.205 | us5.dal.thewebhostserver.com. | 30496 | COLO4_-_Colo4_LLC | UnitedStates |
piapara.com | 216.70.71.205 | anguspoint.com.br. | 31815 | MEDIATEMPLE_-_Media_Temple_Inc. | UnitedStates |
spiratechperformancemarketing.com | 50.28.91.182 | host.wealthytouch.com. | 32244 | LIQUID-WEB-INC_-_Liquid_Web_Inc. | UnitedStates |
thegreenagebook.com | 50.28.33.81 | NONE | 32244 | LIQUID-WEB-INC_-_Liquid_Web_Inc. | UnitedStates |
topproteinpowders.org | 50.28.27.219 | NONE | 32244 | LIQUID-WEB-INC_-_Liquid_Web_Inc. | UnitedStates |
travislogie.com | 50.56.220.218 | 50-56-220-218.static.cloud-ips.com. | 33070 | RMH-14_-_Rackspace_Hosting | UnitedStates |
todaystoptrends.com | 67.23.166.102 | unknown.static.avl.netriplex.com. | 36167 | NETRIPLEX01_-_NETRIPLEX_LLC | India |
employment.rfidblocker.info | 173.192.206.4 | 173.192.206.4-static.reverse.softlayer.com. | 36351 | SOFTLAYER_-_SoftLayer_Technologies_Inc. | UnitedStates |
thebestsearchengine.org | 173.233.69.208 | 173-233-69-208.STATIC.turnkeyinternet.net. | 40244 | TURNKEY-INTERNET_-_Turnkey_Internet_Inc. | UnitedStates |
amettucuman.com.ar | 66.147.242.150 | box550.bluehost.com. | 46606 | BLUEHOST-AS-2_-_Bluehost_Inc. | UnitedStates |
deadworry.com | 67.20.73.37 | 67-20-73-37.bluehost.com. | 46606 | BLUEHOST-AS-2_-_Bluehost_Inc. | UnitedStates |
increaseverticaljumptoday.com | 66.147.244.83 | box783.bluehost.com. | 46606 | BLUEHOST-AS-2_-_Bluehost_Inc. | UnitedStates |
nathansphere.com | 74.220.215.242 | host242.hostmonster.com. | 46606 | BLUEHOST-AS-2_-_Bluehost_Inc. | UnitedStates |
theweedreview.com | 74.220.215.65 | host265.hostmonster.com. | 46606 | BLUEHOST-AS-2_-_Bluehost_Inc. | UnitedStates |
thepepteam.com | 31.170.163.183 | 31-170-163-183.main-hosting.com. | 47583 | HOSTING-MEDIA_Aurimas_Rapalis_trading_as__II_Hosting_Media_ | UnitedStates |
terziphoto.com | 178.236.176.69 | yutex04.yutex.ru. | 48232 | RSERVERS-AS_RSERVERS_TECH_S.R.L. | Netherlands |
tlumacz-holenderski.eu | 212.91.6.51 | web1.47.pl. | 48707 | GREENER-AS_Greener_Marcin_Waligorski | Poland |
tlumaczenia-chinski.eu | 212.91.6.51 | web1.47.pl. | 48707 | GREENER-AS_Greener_Marcin_Waligorski | Poland |
tlumaczenia-ekspresowe.eu | 195.2.209.54 | web1.47.pl. | 48707 | GREENER-AS_Greener_Marcin_Waligorski | Poland |
tlumaczenia-marketingowe.eu | 212.91.6.51 | web1.47.pl. | 48707 | GREENER-AS_Greener_Marcin_Waligorski | Poland |
traductor.com.pl | 212.91.6.51 | web1.47.pl. | 48707 | GREENER-AS_Greener_Marcin_Waligorski | Poland |
traffic-web.ru | 46.161.31.160 | shared.srv4.majorhost.net. | 52201 | TCTEL_LLC__TC_TEL_ | RussianFederation |
今回はポーランドのホスティングが少し多めにまざってますね。
by jyake