<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>ポルトガル | ～下町物語～</title>
	<atom:link href="https://blog.rurineko.com/archives/tag/%e3%83%9d%e3%83%ab%e3%83%88%e3%82%ac%e3%83%ab/feed" rel="self" type="application/rss+xml" />
	<link>https://blog.rurineko.com</link>
	<description>入り組んだ現代社会に鋭いメスを入れ、おもしろおかしく書綴るブログである</description>
	<lastBuildDate>Sat, 12 Mar 2016 00:50:49 +0000</lastBuildDate>
	<language>ja</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	

<image>
	<url>https://blog.rurineko.com/wp-content/uploads/2017/04/cropped-image2_9-32x32.jpg</url>
	<title>ポルトガル | ～下町物語～</title>
	<link>https://blog.rurineko.com</link>
	<width>32</width>
	<height>32</height>
</image> 
<atom:link rel="hub" href="https://pubsubhubbub.appspot.com"/>
<atom:link rel="hub" href="https://pubsubhubbub.superfeedr.com"/>
<atom:link rel="hub" href="https://websubhub.com/hub"/>
<atom:link rel="self" href="https://blog.rurineko.com/archives/tag/%e3%83%9d%e3%83%ab%e3%83%88%e3%82%ac%e3%83%ab/feed"/>
	<item>
		<title>またきた！！ランサムウェアメール・・・</title>
		<link>https://blog.rurineko.com/archives/5892</link>
		
		<dc:creator><![CDATA[rurineko]]></dc:creator>
		<pubDate>Sat, 12 Mar 2016 00:50:49 +0000</pubDate>
				<category><![CDATA[3.ホットな話題]]></category>
		<category><![CDATA[日記]]></category>
		<category><![CDATA[invoice]]></category>
		<category><![CDATA[ウイルス.請求書]]></category>
		<category><![CDATA[スパム]]></category>
		<category><![CDATA[ポルトガル]]></category>
		<category><![CDATA[ランサムウェア]]></category>
		<guid isPermaLink="false">http://blog.rurineko.com/?p=5892</guid>

					<description><![CDATA[<p><span class="span-reading-time rt-reading-time" style="display: block;"><span class="rt-label rt-prefix">この記事を読む およそ時間</span> <span class="rt-time"> 2</span> <span class="rt-label rt-postfix">分</span></span>今のトレンドですねぇ。請求書メールに載せてランサムウェアが・・・。 ある意味間違ってはいないんですが、ランサムウェアが実行された後に 請求書が出ますから・・・ｗ ☆subject FW: Payment 16-03-#6 [&#8230;]</p>
<p>The post <a href="https://blog.rurineko.com/archives/5892">またきた！！ランサムウェアメール・・・</a> first appeared on <a href="https://blog.rurineko.com">～下町物語～</a>.</p>]]></description>
										<content:encoded><![CDATA[<span class="span-reading-time rt-reading-time" style="display: block;"><span class="rt-label rt-prefix">この記事を読む およそ時間</span> <span class="rt-time"> 2</span> <span class="rt-label rt-postfix">分</span></span><p>今のトレンドですねぇ。請求書メールに載せてランサムウェアが・・・。<br />
ある意味間違ってはいないんですが、ランサムウェアが実行された後に<br />
請求書が出ますから・・・ｗ</p>
<p>☆subject<br />
FW: Payment 16-03-#65191807</p>
<p>☆本文<br />
Dear rurineko,</p>
<p>We have received this documents from your bank, please review attached documents.</p>
<p>Yours sincerely,</p>
<p>Tabatha Watkins<br />
Account Manager<br />
______________________________________________________________________<br />
This email has been scanned by the Symantec Email Security.cloud service.</p>
<p>☆ヘッダー<br />
Return-Path: &lt;WatkinsTabatha62645@telepac.pt&gt;<br />
X-Spam-Checker-Version: SpamAssassin 3.3.1 (2010-03-16) on mx.hogehoge.com<br />
X-Spam-Level:<br />
X-Spam-Status: No, score=-6.1 required=13.0 tests=BAYES_00, CONTENT_TYPE_PRESENT,NO_RECEIVED,NO_RELAYS autolearn=ham version=3.3.1<br />
X-Original-To: rurineko@hogehoge.com<br />
Delivered-To: rurineko@hogehoge.com<br />
X-Virus-Scanned: amavisd-new at hogehoge.com<br />
X-DomainKeys: Sendmail DomainKeys Filter v1.0.1 mx.hogehoge.com B9B0C61A3E0<br />
From: Tabatha Watkins &lt;WatkinsTabatha62645@telepac.pt&gt;<br />
X-DomainKeys: Sendmail DomainKeys Filter v1.0.1 mx.hogehoge.com EE64961A3DF<br />
To: rurineko &lt;rurineko@hogehoge.com&gt;<br />
Subject: FW: Payment 16-03-#659807<br />
MIME-Version: 1.0<br />
Message-Id: &lt;14915ｄ0022927732.07F1BD06DE@hogehoge.com&gt;<br />
Date: Fri, 11 Mar 2016 11:31:26 +0100<br />
Content-Type: multipart/mixed; boundary=&#8221;&#8212;-==&#8211;bound.320ｄ98.d6551ca5.hogehoge.com&#8221;</p>
<p>☆サーバログ　実データ　サーバに入ってデータを引っ張ってきました。<br />
－－－－　検索結果　－－－－<br />
Mar 11 20:31:30 mx postfix/cleanup[13557]: EE6ss4961A3DF: message-id=&lt;1491500229277ss32.07F1BD06DE@higehige.com&gt;<br />
Mar 11 20:31:30 mx postfix/cleanup[13557]: B9B0C61A3E0: message-id=&lt;149150022927732.0ss7F1BD06DE@higehige.com&gt;<br />
Mar 11 20:31:31 mx amavis[12376]: (12376-16) Passed CLEAN {RelayedInbound}, [82.154.1.54] &lt;WatkinsTabatha62645@telepac.pt&gt; -&gt; &lt;rurineko@higehige.com&gt;, Message-ID: &lt;1491500229277ss32.07F1BD06DE@higehige.com&gt;, mail_id: SmmIguTc12II, Hits: -, size: 6925, queued_as: B9B0C61dsadsaA3E0, 544 ms<br />
Mar 11 20:31:31 mx spamd[450]: spamd: processing message &lt;149150022927s732.s07F1BDs06DE@higehige.com&gt; for rurineko:102<br />
Mar 11 20:31:31 mx spamd[450]: spamd: result: . -6 &#8211; BAYES_00,CONTENT_TYPE_PRESENT,NO_RECEIVED,NO_RELAYS scantime=0.5,size=7113,user=rurineko,uid=102,required_score=13.0,rhost=localhost.localdomain,raddr=127.0.0.1,rport=38241,mid=&lt;149150022927732.07F1aaBD06DE@higehige.com&gt;,bayes=0.000001,autolearn=ham<br />
－－－－　検索結果終了　－－－－</p>
<p>ランサムウェアは、サーバに入れているウイルス対策ソフトでは、<br />
ヒットしないっぽいです。CLEANってでちゃってますね。</p>
<p>しかも、スパムフィルターも通過してるし<br />
うまくつくってますねぇ。</p>
<p>☆送信ホスト情報<br />
82.154.1.54</p>
<p>送信国 ポルトガル　遠路はるばる・・・。</p>
<p>☆プロバイダ－情報<br />
% This is the RIPE Database query service.<br />
% The objects are in RPSL format.<br />
%<br />
% The RIPE Database is subject to Terms and Conditions.<br />
% See http://www.ripe.net/db/support/db-terms-conditions.pdf</p>
<p>% Note: this output has been filtered.<br />
% To receive output for a database update, use the &#8220;-B&#8221; flag.</p>
<p>% Information related to &#8216;82.154.0.0 &#8211; 82.154.243.255&#8217;</p>
<p>% Abuse contact for &#8216;82.154.0.0 &#8211; 82.154.243.255&#8217; is &#8216;abuse@mail.telepac.pt&#8217;</p>
<p>inetnum: 82.154.0.0 &#8211; 82.154.243.255<br />
netname: MEO-BROADBAND<br />
descr: PT Comunicacoes S.A.<br />
descr: Dynamic Address Range<br />
country: PT<br />
remarks: NCC #2004061957<br />
admin-c: TP3302-RIPE<br />
tech-c: TP3302-RIPE<br />
status: ASSIGNED PA<br />
mnt-by: TELEPAC-MNT<br />
mnt-routes: TELEPAC-MNT<br />
created: 2004-06-17T15:23:31Z<br />
last-modified: 2016-02-05T17:37:06Z<br />
source: RIPE # Filtered</p>
<p>role: MEO-RESIDENCIAL<br />
org: ORG-TCIS1-RIPE<br />
address: Local Internet Registry Management<br />
address: MEO &#8211; SERVICOS DE COMUNICACOES E MULTIMEDIA S.A.<br />
address: Av. Fontes Pereira de Melo, 40 &#8211; 3 Bl A<br />
address: Forum Picoas &#8211; 1069-300 Lisboa<br />
address: Portugal<br />
phone: +351-215000000<br />
admin-c: LL1052-RIPE<br />
admin-c: MCN5-RIPE<br />
admin-c: HCR20-RIPE<br />
admin-c: NPM17-RIPE<br />
admin-c: DPM37-RIPE<br />
admin-c: LAS102-RIPE<br />
admin-c: TPM7-RIPE<br />
tech-c: RTM15-RIPE<br />
tech-c: FSG53-RIPE<br />
tech-c: JCO39-RIPE<br />
tech-c: PPB29-RIPE<br />
tech-c: HAC24-RIPE<br />
tech-c: HCO6-RIPE<br />
tech-c: AA2895-RIPE<br />
tech-c: PG259-RIPE<br />
nic-hdl: TP3302-RIPE<br />
abuse-mailbox: abuse@mail.telepac.pt<br />
mnt-by: TELEPAC-MNT<br />
created: 2002-08-12T09:57:20Z<br />
last-modified: 2015-06-05T10:59:42Z<br />
source: RIPE # Filtered</p>
<p>% Information related to &#8216;82.154.0.0/15AS3243&#8217;</p>
<p>route: 82.154.0.0/15<br />
descr: PT Comunicacoes S.A.<br />
origin: AS3243<br />
mnt-by: TELEPAC-MNT<br />
created: 2003-11-20T15:22:56Z<br />
last-modified: 2014-01-31T16:21:38Z<br />
source: RIPE</p>
<p>% This query was served by the RIPE Database Query Service version 1.85.1 (DB-2)</p>
<p>とまぁ、２通ランサムウェアが入っていましたので<br />
くれぐれも、こういうたぐいのメールが来ても開かないようにご注意ください。</p>
<p>☆興味深い記事がでていた！Macだから大丈夫だよね？　危ないですねぇ。<br />
[blogcard url=&#8221;http://www.itmedia.co.jp/enterprise/articles/1603/07/news068.html&#8221;]</p><p>The post <a href="https://blog.rurineko.com/archives/5892">またきた！！ランサムウェアメール・・・</a> first appeared on <a href="https://blog.rurineko.com">～下町物語～</a>.</p>]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
