Paul
CastleCops Founder
 Joined: Feb 22, 2002 Posts: 27351
|
Posted: Tue Dec 04, 2007 7:53 pm Post subject: [WsIRT#533] JA1290shell @AS27823 |
|
|
Attack Alert Full Report: /JA1290shell_attack533.html Changed status to confirmed attack. <title>JA1290 #gebe Hackerlink</title> This is an r57shell derivative. Once an attacker successfully gets this script onto a remote web server thru a vulnerability, and it executes, it'll give the attacker shell connectivity. Plus upon run time, it'll also send an email to the attacker alerting them of a successful compromise. IP Converted: 200.58.115.64
dword = 3359273792
hex1 = 0xc83a7340
hex2 = 0xc8.0x3a.0x73.0x40
oct = 0310.072.0163.0100
View CIDR AS27823 Report: http://www.cidr-report.org/cgi-bin/as-report?as=27823
"27823 | AR | lacnic | 2006-05-12 | Dattatec.com"<br />
Extended information for AS27823:
State/Province:
Country: ar
Responsible Domain: dattatec.com
Abuse Email: marketing@dattatec.com
Domain reported to PDR for invalid WHOIS: http://www.publicdomainregistry.com/contactus/report-false-whois/
Registrant:
xxxx
xxxx (marucci05@hotmail.com)
xxxx
xxxx
null,99301
US
Tel. +00.4218328
Creation Date: 13-Jun-2007
Expiration Date: 13-Jun-2008
Domain servers in listed order:
ns2.electrobox106.com
ns1.electrobox106.com
Administrative Contact:
xxxx
xxxx (marucci05@hotmail.com)
xxxx
xxxx
null,99301
US
Tel. +00.4218328
Technical Contact:
xxxx
xxxx (marucci05@hotmail.com)
xxxx
xxxx
null,99301
US
Tel. +00.4218328
Billing Contact:
xxxx
xxxx (marucci05@hotmail.com)
xxxx
xxxx
null,99301
US
Tel. +00.4218328
| Quote: | | http://electrobox106.com/7.txt?? |
|
|