Paul
CastleCops Founder
 Joined: Feb 22, 2002 Posts: 27351
|
Posted: Tue Dec 04, 2007 7:22 pm Post subject: [WsIRT#575] r57shell @AS30968 |
|
|
Attack Alert Full Report: /r57shell_attack575.html Changed status to confirmed attack. IP Converted: 85.249.131.114
dword = 1442415474
hex1 = 0x55f98372
hex2 = 0x55.0xf9.0x83.0x72
oct = 0125.0371.0203.0162
View CIDR AS30968 Report: http://www.cidr-report.org/cgi-bin/as-report?as=30968
"30968 | RU | ripencc | 2004-01-29 | DATAP-AS Infobox company network, hosting service provider,"<br />
Extended information for AS30968:
State/Province:
Country: ru
Responsible Domain: infobox.ru
Abuse Email: support@infobox.ru
Attackers are attemping to inject this script into exploitable web servers in order to compromise them and take ownership.
| Quote: | | http://giks.net/php/x/rst.txt?cmd=id |
|
|