CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

$9466.22 of $21422.68
left sidedonated so farneed $11956.46 donated to reach our goalright side, our goal
Help CastleCops serve the community on new servers, Donate Here to reach our goal.

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
Survey
spacer
Was 2007 a good year?

Yes it was a wonderful year
Yes, but there is always room for improvement
Status quo
It was a challenge
Other (leave comment)



Results
Polls

Votes: 917
Comments: 22
block bottom
spacer spacer

WsIRT(TM)

Webserver Incident Reporting and Termination(TM) Squad

NOTE: Web servers have logs and in those logs is evidence of attempted hacking. For instance, one may notice an attack that calls such a script from a remote server "r57.php??". Its these kinds of attacks we're looking to investigate. For a concrete example, see these reports.

Please do not submit phish, spam, or malware to WsIRT. Only submit attack signatures from web server logs. As this project hasn't officially been publicly launched, we are still reclassifying the tool and its verbiage.

[ How-To / FAQ ]

WsIRT -> Confirmed Attacks | Terminated Attacks


status: confirmed attack

HTTP Response
11 May, 2008
15:12:32
HTTP/1.1 404 Not Found
ID1102 (termination link)
TitleC99Shell
Entry
WsIRT Squad
Reporter
tetak
Timestamp19 Dec, 2007 @ 11:36:16
Topic ID211113 - Read/respond to WsIRT commentary.
Handler Note:
22 Dec, 2007
18:18:06
Paul: View CIDR AS7514 Report: http://www.cidr-report.org/cgi-bin/as-report?as=7514

"7514 | JP | apnic | 1997-03-03 | MEX Media EXchange, Inc."

Handler Note:
22 Dec, 2007
18:18:07
Paul: Extended information for AS7514:
State/Province:
Country: jp
Responsible Domain: mex.ad.jp
Abuse Email: security@mex.ad.jp
Handler Note:
22 Dec, 2007
18:18:07
Paul: This domain has been compromised, it is running a known hijacking shell called c99. Please investigate your system as this shell permits criminals to conduct spam, phish, malware and other nefarious campaigns.
Handler Note:
22 Dec, 2007
18:18:48
Paul: Generated and sent email attack alert to respective parties.
Handler Note:
29 Dec, 2007
01:21:14
Robin: ATTN JP CERT:

We have attempted to notify the owner of this domain as well as the ISP without success in having the shell or any related malware removed. Please contact them. This server very urgently needs to be secured.
Fetched URLs

Report for at 19 Dec, 2007 @ 11:40:01


fetched page

at 19 Dec, 2007 @ 11:40:03
MD5 Fingerprint: f4ed192840c0f05d646d11a4eee5005a
SHA1 Fingerprint: a2298aeb74054bcbd9bc82abd9831c0de3f28abe
Version 1.0
spacer spacer