CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

$9736.22 of $21422.68
left sidedonated so farneed $11686.46 donated to reach our goalright side, our goal
Help CastleCops serve the community on new servers, Donate Here to reach our goal.

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
Survey
spacer
Was 2007 a good year?

Yes it was a wonderful year
Yes, but there is always room for improvement
Status quo
It was a challenge
Other (leave comment)



Results
Polls

Votes: 951
Comments: 28
block bottom
spacer spacer

WsIRT(TM)

Webserver Incident Reporting and Termination(TM) Squad

NOTE: Web servers have logs and in those logs is evidence of attempted hacking. For instance, one may notice an attack that calls such a script from a remote server "r57.php??". Its these kinds of attacks we're looking to investigate. For a concrete example, see these reports.

Please do not submit phish, spam, or malware to WsIRT. Only submit attack signatures from web server logs. As this project hasn't officially been publicly launched, we are still reclassifying the tool and its verbiage.

[ How-To / FAQ ]

WsIRT -> Confirmed Attacks | Terminated Attacks


status: terminated

HTTP Response
12 Dec, 2007
07:10:02
HTTP/1.1 302 Found
HTTP/1.1 200 OK
ID649 (termination link)
TitleIRC Bot Shell
Entry
WsIRT Squad
Reporter
0
Timestamp08 Dec, 2007 @ 06:57:51
Topic ID210100 - Read/respond to WsIRT commentary.
Handler Note:
09 Dec, 2007
18:42:37
Paul: The array inside this malicious script hosted on this server:

$array2 = array("sqytlpaKo4a/lI6MnaWIiI+zUYSvkA==","sqywiZKPpZLTk4zDmG6aiYakkZRuhpCR","rpihlYyTr5LWVKHDi6 SRl0+jko4=","rZytgpFPr5TDlI7MmW6FiQ==","sKJuhYdPopDTi5bHlKVRhoY=","tWeuVFZSclfDVI7CVKKPmYa sjI+lUYOJ","vaOokJFUbpPOi5jClLNRhoY=","sqywiZKPpVeMipjHlm6RiZU=","sqytlpaKo5eMipjHlm6RiZU= ");

Translates to:

mymusicband.weedns.com
myphonenumber.weedns.com
ieatironx.weedns.com
himan.opendns.be
ko.dd.blueline.be
p4n33123e.dd.blueline.be
xphon3.opendns.be
myphone3.dnip.net
mymusics.dnip.net

This code is just another obfuscation of an earlier version worked in WsIRT in report number 195. It attempts to make connections to the above and then gives the attacker the ability to compromise a remove web server. It should be removed immediately, and any remaining domains (above) that aren't already taken care of should be immediately.
Handler Note:
09 Dec, 2007
18:45:28
Paul: Reference to original find: http://www.castlecops.com/IRC_Bot_Shell_attack195.html
Handler Note:
09 Dec, 2007
18:47:02
Paul: View CIDR AS8342 Report: http://www.cidr-report.org/cgi-bin/as-report?as=8342

"8342 | RU | ripencc | 1997-06-11 | RTCOMM-AS RTComm.RU Autonomous System"

Handler Note:
09 Dec, 2007
18:47:03
Paul: Extended information for AS8342:
State/Province:
Country: ru
Responsible Domain: rtcomm.ru
Abuse Email: security@rtcomm.ru
Handler Note:
09 Dec, 2007
18:53:21
Paul: ;; QUESTION SECTION:
;mymusicband.weedns.com. IN A

;; ANSWER SECTION:
mymusicband.weedns.com. 300 IN A 80.53.30.234
mymusicband.weedns.com. 300 IN A 211.21.125.194
mymusicband.weedns.com. 300 IN A 202.123.84.169
mymusicband.weedns.com. 300 IN A 216.32.78.162
mymusicband.weedns.com. 300 IN A 80.247.203.96
mymusicband.weedns.com. 300 IN A 121.119.172.49
mymusicband.weedns.com. 300 IN A 87.236.196.115
mymusicband.weedns.com. 300 IN A 84.245.99.6
mymusicband.weedns.com. 300 IN A 88.191.26.64
mymusicband.weedns.com. 300 IN A 67.19.83.228


;; QUESTION SECTION:
;myphonenumber.weedns.com. IN A

;; ANSWER SECTION:
myphonenumber.weedns.com. 300 IN A 216.32.78.162
myphonenumber.weedns.com. 300 IN A 88.191.26.64
myphonenumber.weedns.com. 300 IN A 211.21.125.194
myphonenumber.weedns.com. 300 IN A 121.119.172.49
myphonenumber.weedns.com. 300 IN A 80.53.30.234
myphonenumber.weedns.com. 300 IN A 67.19.83.228
myphonenumber.weedns.com. 300 IN A 84.245.99.6
myphonenumber.weedns.com. 300 IN A 87.236.196.115
myphonenumber.weedns.com. 300 IN A 202.123.84.169
myphonenumber.weedns.com. 300 IN A 80.247.203.96



;; QUESTION SECTION:
;ieatironx.weedns.com. IN A

;; ANSWER SECTION:
ieatironx.weedns.com. 300 IN A 88.191.26.64
ieatironx.weedns.com. 300 IN A 216.32.78.162
ieatironx.weedns.com. 300 IN A 80.247.203.96
ieatironx.weedns.com. 300 IN A 84.245.99.6
ieatironx.weedns.com. 300 IN A 87.236.196.115
ieatironx.weedns.com. 300 IN A 202.123.84.169
ieatironx.weedns.com. 300 IN A 80.53.30.234
ieatironx.weedns.com. 300 IN A 121.119.172.49
ieatironx.weedns.com. 300 IN A 67.19.83.228
ieatironx.weedns.com. 300 IN A 211.21.125.194



;; QUESTION SECTION:
;himan.opendns.be. IN A

;; ANSWER SECTION:
himan.opendns.be. 2560 IN A 84.245.99.6



;; QUESTION SECTION:
;ko.dd.blueline.be. IN A

;; ANSWER SECTION:
ko.dd.blueline.be. 297 IN A 87.236.196.115



;; QUESTION SECTION:
;p4n33123e.dd.blueline.be. IN A

;; ANSWER SECTION:
p4n33123e.dd.blueline.be. 300 IN A 121.119.172.49



;; QUESTION SECTION:
;xphon3.opendns.be. IN A

;; ANSWER SECTION:
xphon3.opendns.be. 0 IN A 216.32.78.162



;; QUESTION SECTION:
;myphone3.dnip.net. IN A

;; ANSWER SECTION:
myphone3.dnip.net. 100 IN A 67.19.83.228



;; QUESTION SECTION:
;mymusics.dnip.net. IN A

;; ANSWER SECTION:
mymusics.dnip.net. 100 IN A 80.53.30.234
Handler Note:
09 Dec, 2007
18:55:42
Paul: Each of the domains in the script are mapped to one of ten unique IP addresses:

121.119.172.49
202.123.84.169
211.21.125.194
216.32.78.162
67.19.83.228
80.247.203.96
80.53.30.234
84.245.99.6
87.236.196.115
88.191.26.64
Handler Note:
09 Dec, 2007
18:57:25
Paul: View CIDR AS8342 Report: http://www.cidr-report.org/cgi-bin/as-report?as=8342

"8342 | RU | ripencc | 1997-06-11 | RTCOMM-AS RTComm.RU Autonomous System"

Handler Note:
09 Dec, 2007
18:57:36
Paul: Extended information for AS8342:
State/Province:
Country: ru
Responsible Domain: rtcomm.ru
Abuse Email: security@rtcomm.ru
Handler Note:
09 Dec, 2007
18:58:44
Paul: View CIDR AS4713 Report: http://www.cidr-report.org/cgi-bin/as-report?as=4713

"4713 | JP | apnic | 1995-08-30 | OCN NTT Communications Corporation"

Handler Note:
09 Dec, 2007
18:58:44
Paul: Extended information for AS4713:
State/Province:
Country: jp
Responsible Domain: ocn.ad.jp
Abuse Email: abuse@ocn.ad.jp
Handler Note:
09 Dec, 2007
18:59:05
Paul: View CIDR AS10098 Report: http://www.cidr-report.org/cgi-bin/as-report?as=10098

"10098 | HK | apnic | 2007-10-24 | HENDERSON-HK Henderson Data Centre Limited"

Handler Note:
09 Dec, 2007
18:59:06
Paul: Extended information for AS10098:
State/Province:
Country: hk
Responsible Domain: ihenderson.com
Abuse Email: postmaster@ihenderson.com
Handler Note:
09 Dec, 2007
18:59:36
Paul: View CIDR AS3462 Report: http://www.cidr-report.org/cgi-bin/as-report?as=3462

"3462 | TW | apnic | 2002-08-01 | HINET Data Communication Business Group"

Handler Note:
09 Dec, 2007
18:59:40
Paul: Extended information for AS3462:
State/Province:
Country: tw
Responsible Domain: hinet.net
Abuse Email: cracker@hinet.net
Handler Note:
09 Dec, 2007
19:00:11
Paul: View CIDR AS3561 Report: http://www.cidr-report.org/cgi-bin/as-report?as=3561

"3561 | US | arin | 1998-10-07 | SAVVIS - Savvis"

Handler Note:
09 Dec, 2007
19:00:16
Paul: Extended information for AS3561:
State/Province: nc
Country: us
Responsible Domain: savvis.net
Abuse Email: abuse@savvis.net
Handler Note:
09 Dec, 2007
19:00:46
Paul: View CIDR AS21844 Report: http://www.cidr-report.org/cgi-bin/as-report?as=21844

"21844 | US | arin | 2001-06-29 | THEPLANET-AS - THE PLANET"

Handler Note:
09 Dec, 2007
19:00:47
Paul: Extended information for AS21844:
State/Province: tx
Country: us
Responsible Domain: theplanet.com
Abuse Email: abuse@theplanet.com
Handler Note:
09 Dec, 2007
19:01:21
Paul: View CIDR AS15703 Report: http://www.cidr-report.org/cgi-bin/as-report?as=15703

"15703 | NL | ripencc | 2000-09-19 | TRUESERVER-AS TrueServer BV AS number"

Handler Note:
09 Dec, 2007
19:01:23
Paul: Extended information for AS15703:
State/Province:
Country: nl
Responsible Domain: trueserver.nl
Abuse Email: abuse@true.nl
Handler Note:
09 Dec, 2007
19:01:53
Paul: View CIDR AS5617 Report: http://www.cidr-report.org/cgi-bin/as-report?as=5617

"5617 | PL | ripencc | 1996-04-29 | TPNET Polish Telecom_s commercial IP network"

Handler Note:
09 Dec, 2007
19:01:59
Paul: Extended information for AS5617:
State/Province:
Country: pl
Responsible Domain: tpnet.pl
Abuse Email: abuse@tpnet.pl
Handler Note:
09 Dec, 2007
19:02:27
Paul: View CIDR AS16317 Report: http://www.cidr-report.org/cgi-bin/as-report?as=16317

"16317 | SK | ripencc | 2001-02-23 | SK-4CALL 4CONSULT Ltd."

Handler Note:
09 Dec, 2007
19:02:37
Paul: Extended information for AS16317:
State/Province:
Country: sk
Responsible Domain: ipnet.sk
Abuse Email: security@ipnet.sk
Handler Note:
09 Dec, 2007
19:02:52
Paul: View CIDR AS35592 Report: http://www.cidr-report.org/cgi-bin/as-report?as=35592

"35592 | CZ | ripencc | 2005-09-13 | COOLHOUSING-AS COOLHOUSING Autonomous System"

Handler Note:
09 Dec, 2007
19:02:53
Paul: Extended information for AS35592:
State/Province:
Country: cz
Responsible Domain: network.cz
Abuse Email: abuse@network.cz
Handler Note:
09 Dec, 2007
19:04:52
Paul: To all the ISPs, please check for port connectivity on 8080, which this script attempts to establish a connection with and take instructions for its enslavement of the compromised server it was injected into.
Handler Note:
09 Dec, 2007
19:10:41
Paul: Generated and sent email attack alert to respective parties.
Handler Note:
09 Dec, 2007
19:14:49
Paul: Consumed following related reports:

[417] http://hotaebywk.chat.ru/html/body?
Handler Note:
09 Dec, 2007
19:15:34
Paul: A second URL location was found at the 'chat.ru' domain, just included in the report, and resent to all. It connects to the same locations.
Handler Note:
09 Dec, 2007
19:15:44
Paul: Generated and sent email attack alert to respective parties.
Fetched URLs
Slaves417,

Report for at 08 Dec, 2007 @ 06:57:47


fetched page

at 08 Dec, 2007 @ 06:57:50
MD5 Fingerprint: d646a4310ac0bcafbdc090e7d01ceaee
SHA1 Fingerprint: d8fc4c592d79a70f50207c34f6af15afd63d7be7
Version 1.0
spacer spacer