Paul
CastleCops Founder
 Joined: Feb 22, 2002 Posts: 27351
|
Posted: Thu Nov 29, 2007 7:50 pm Post subject: [WsIRT#105] OS Disclosure, id Disclosure @21844 |
|
|
Attack Alert Full Report: /OS_Disclosure_id_Disclosure_attack105.html Changed status to confirmed attack. IP Converted: 74.54.19.194
dword = 1245057986
hex1 = 0x4a3613c2
hex2 = 0x4a.0x36.0x13.0xc2
oct = 0112.066.023.0302
Attackers are brute forcing their way into remote servers and if successful are downloading this script on your server. Once downloaded, this script tells attackers what the remote web server is in preparation for a full on attack. Please have it removed.
.info domains, the whois on this record was registered in October of this year, please confirm if this is a fraud domain or not. View CIDR AS21844 Report: http://www.cidr-report.org/cgi-bin/as-report?as=21844
"21844 | US | arin | 2001-06-29 | THEPLANET-AS - THE PLANET"<br />
Extended information for AS21844:
State/Province: tx
Country: us
Responsible Domain: theplanet.com
Abuse Email: abuse@theplanet.com
| Quote: | | http://www.sitestorage.info/templates/rhuk_solarflare_ii/images/cmd.txt?? |
|
|