ワームによるウェブサーバへのアクセスがあったサーバも余裕があれば掲載していこうと思います。
- 61.115.200.156 → 株式会社イーステム
- 61.236.13.11 → CHINA RAILWAY TELECOMMUNICATIONS CENTER
- 61.92.182.51 → City Telecom (H.K.) Ltd.
- 61.182.248.126 → CHINANET Hebei province network(China Telecom)
- 61.177.29.42 → CHINANET jiangsu province network(China Telecom)
- 61.171.207.225 → CHINANET Shanghai province network(China Telecom)
- 61.252.130.100 → Internet Service Inc
- 66.27.153.101(sc-66-27-153-101.socal.rr.com) → ROADRUNNER
今回のログ
えーと、思わず「攻撃です!」と叫びたいようなログです。今回は詳しく調べてみることにします。以下は whois によって調べた結果です。
1行目から3行目 24.64.140.5(h24-64-140-5.cg.shawcable.net)
OrgName: Shaw Fiberlink
OrgID: FBCA
NetRange: 24.64.0.0 - 24.71.255.255
CIDR: 24.64.0.0/13
NetName: FIBERLINK-CABLE
NetHandle: NET-24-64-0-0-1
Parent: NET-24-0-0-0-0
NetType: Direct Allocation
NameServer: NS2SO.CG.SHAWCABLE.NET
NameServer: NS1SO.CG.SHAWCABLE.NET
Comment:
RegDate: 1996-06-03
Updated: 2002-08-12
4行目から6行目 61.218.88.235(61-218-88-235.HINET-IP.hinet.net)
inetnum: 61.218.88.232 - 61.218.88.239
netname: HO-CHEN-HUAI-E4-NET
descr: Ho, Chen Huai
descr: 9F-1, No. 121, Sec. 1, Chenshen S. Rd., Taipei
descr: Taipei Taiwan
country: TW
admin-c: CHH103-TW
tech-c: CHH103-TW
mnt-by: TWNIC-AP
remarks: This information has been partially mirrored by APNIC from
remarks: TWNIC. To obtain more specific information, please use the
remarks: TWNIC whois server at whois.twnic.net.
changed: network-adm@hinet.net 20010418
source: TWNIC
7行目から9行目 65.191.91.37
OrgName: Telocity
OrgID: TELO
NetRange: 65.184.0.0 - 65.191.255.255
CIDR: 65.184.0.0/13
NetName: TELOCITY-4
NetHandle: NET-65-184-0-0-1
Parent: NET-65-0-0-0-0
NetType: Direct Allocation
NameServer: NS1.TELOCITY.NET
NameServer: NS2.TELOCITY.NET
Comment: ADDRESSES WITHIN THIS BLOCK ARE NON-PORTABLE
RegDate: 2001-04-23
Updated: 2001-10-18
10行目から12行目 (adsl-67-116-117-59.dsl.lsan03.pacbell.net)
LPatracia SBC067116117056020423 (NET-67-116-117-56-1)
67.116.117.56 - 67.116.117.63
14行目から16行目 211.155.218.7
inetnum: 211.155.192.0 - 211.155.223.255
netname: GDSTINET
descr: Guangdong Sci & Tech Information Network
descr: Guangdong Jinke Network
country: CN
admin-c: IPAS1-AP
admin-c: FX18-AP
tech-c: WZ76-AP
mnt-by: MAINT-CNNIC-AP
changed: ipas@cnnic.net.cn 20010105
status: ALLOCATED PORTABLE
source: APNIC
role: CNNIC IPAS CONFEDERATION
address: No.4, Zhongguancun No.4 South Street, Haidian District, Beijing
country: CN
phone: +86-10-62553604
fax-no: +86-10-62559892
e-mail: ipas@cnnic.net.cn
admin-c: WZ2-AP
tech-c: WZ2-AP
tech-c: QX12-AP
nic-hdl: IPAS1-AP
mnt-by: MAINT-CNNIC-AP
changed: ipas@cnnic.net.cn 20000410
source: APNIC
16行目から18行目 12.18.124.252()
CARDELL CABINETS CARDELLNET25-124-224 (NET-12-18-124-224-1)
12.18.124.224 - 12.18.124.255
19行目から20行目 195.166.226.1
inetnum: 195.166.226.0 - 195.166.226.255
netname: LINKSERVE
descr: ISP
country: NG
admin-c: TO219-RIPE
tech-c: TO219-RIPE
status: ASSIGNED PA
notify: tunde@linkserve.com.ng
mnt-by: RIPE-NCC-NONE-MNT
changed: tunde@linkserve.com.ng 20000405
source: RIPE
21行目から23行目 207.212.165.102
DualGraphicsCorp SBCIS-20721216500025 (NET-207-212-165-0-1)
207.212.165.0 - 207.212.165.127
25行目から26行目 212.160.9.137(pa137.boguszow.sdi.tpnet.pl)
inetnum: 212.160.9.128 - 212.160.9.255
netname: BOGUSZOW-SDI
descr: TP S.A. SDI
descr: Boguszow Gorce Walbrzych
country: PL
admin-c: KB4987-RIPE
admin-c: KT1618-RIPE
tech-c: MM12786-RIPE
status: ASSIGNED PA
mnt-by: AS5617-MNT
changed: tkielb@cst.tpsa.pl 20010712
source: RIPE
route: 212.160.0.0/16
descr: TPNET (PL)
descr: Provider Local Registry
origin: AS5617
notify: konradpl@zt.piotrkow.tpsa.pl
mnt-by: AS5617-MNT
changed: konradpl@zt.piotrkow.tpsa.pl 19981028
source: RIPE
27行目から28行目 195.182.170.188
inetnum: 195.182.170.176 - 195.182.170.191
netname: AITS
descr: AITS
descr: Lincoln
country: GB
admin-c: DR1101-RIPE
tech-c: BB5622
status: Assigned PA
rev-srv: dns1.dccl.net
rev-srv: dns2.dccl.net
notify: b.bannard@dccl.net
mnt-by: AS12323-MNT
changed: b.bannard@dccl.net 19990804
changed: n.tomalin@dccl.net 20010521
source: RIPE
route: 195.182.160.0/19
descr: Diamond Cable Communications (UK) Ltd
descr: Diamond Plaza
descr: Daleside Road
descr: Nottingham
descr: NG2 3GG
descr: UK
origin: AS12323
notify: b.bannard@dccl.net
mnt-by: AS12323-MNT
changed: b.bannard@dccl.net 19990419
source: RIPE
29行目から30行目 211.152.24.5
inetnum: 211.152.24.0 - 211.152.24.255
netname: LEXUNNET
descr: Lexun network technology Inc.
descr: .com
descr: Beijing,China
country: CN
admin-c: YY86-AP
tech-c: YY86-AP
mnt-by: MAINT-CN-YANGYT
changed: yangyt@21vianet.com 20010427
status: ALLOCATED PORTABLE
source: APNIC
31行目から32行目 62.95.14.112
inetnum: 62.95.14.0 - 62.95.14.127
netname: CHECKDATA-NET
descr: Check Data KB
country: SE
admin-c: SS11337-RIPE
tech-c: SS11337-RIPE
status: ASSIGNED PA
notify: registry@songnetworks.se
mnt-by: TELE1-SE-MNT
changed: anna.eriksson@songnetworks.se 20010801
source: RIPE
route: 62.95.0.0/17
descr: Song Networks AB
origin: AS3246
mnt-by: TELE1-SE-MNT
source: RIPE
changed: registry@songnetworks.se 20011015
34行目から36行目 213.96.152.243(213-96-152-243.uc.nombres.ttd.es)
inetnum: 213.96.0.0 - 213.97.255.255
netname: RIMA
descr: Telefonica De Espana SAU (NCC#2000013794)
descr: Red de servicios IP
descr: Spain
country: ES
admin-c: LJP5-RIPE
tech-c: FLT14-RIPE
rev-srv: scmrro3.nombres.ttd.es
rev-srv: scmrro4.nombres.ttd.es
rev-srv: ns.ripe.net
status: ASSIGNED PA
remarks: ***************************************************
remarks: For ABUSE/SPAM/INTRUSION issues
remarks: PLEASE CONTACT THROUGH LINK
remarks: http://www.telefonicaonline.com/nemesys/
remarks: or send mail to nemesys@telefonica.es
remarks: any mail to adminis.ripe@telefonica.es will be ignored
remarks: ***************************************************
notify: adminis.ripe@telefonica.es
mnt-by: MAINT-AS3352
changed: adminis.ripe@telefonica.es 20000302
changed: adminis.ripe@telefonica.es 20020530
source: RIPE
route: 213.96.128.0/18
descr: TTDNET (Red de servicios IP)
origin: AS3352
mnt-by: MAINT-AS3352
mnt-routes: MAINT-AS3352
mnt-lower: MAINT-AS3352
changed: administracion.ripe@telefonica-data.com 20010306
changed: administracion.ripe@telefonica-data.com 20020118
changed: administracion.ripe@telefonica-data.com 20020313
source: RIPE
37行目から39行目 211.167.97.47
inetnum: 211.167.97.1 - 211.167.97.255
netname: COLNET
descr: Cable OnLine Network
descr: Internet Service Provider
descr: Shanghai China
country: CN
admin-c: HL6-CN
tech-c: YM2-CN
mnt-by: MAINT-CNNIC-AP
changed: cjj@cableplus.com.cn 20000930
status: ASSIGNED NON-PORTABLE
source: APNIC
changed: hm-changed@apnic.net 20020827
person: Huaiyu Li
address: Computer Center
address: Shanghai Cable TV Station
address: 487#, East Luo Chuan Road, Shanghai 200072, China
country: CN
phone: +86 21 56729282
e-mail: fyma@shnet.edu.cn
nic-hdl: HL6-CN
mnt-by: MAINT-CN-CJJ
changed: cjj@cableplus.com.cn 20010609
source: APNIC
40行目から42行目 202.98.143.21
inetnum: 202.98.96.0 - 202.98.159.255
netname: CHINANET-SC
descr: CHINANET Sichuan province network
descr: Data Communication Division
descr: China Telecom
country: CN
admin-c: CH93-AP
tech-c: XS16-AP
mnt-by: MAINT-CHINANET
mnt-lower: MAINT-CHINANET-SC
changed: hostmaster@ns.chinanet.cn.net 20000101
status: ALLOCATED PORTABLE
source: APNIC
これは不審なものだけを取り出したものですが、Microsoft-SQL-Server は相変わらず多いです。海外ばかりですのでここで言ってもどうしようもないのですが・・・。