CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
spacer spacer

WsIRT(TM)

Webserver Incident Reporting and Termination(TM) Squad

NOTE: Web servers have logs and in those logs is evidence of attempted hacking. For instance, one may notice an attack that calls such a script from a remote server "r57.php??". Its these kinds of attacks we're looking to investigate. For a concrete example, see these reports.

Please do not submit phish, spam, or malware to WsIRT. Only submit attack signatures from web server logs. As this project hasn't officially been publicly launched, we are still reclassifying the tool and its verbiage.

[ How-To / FAQ ]

WsIRT -> Confirmed Attacks | Terminated Attacks


status: terminated

HTTP Response
30 Nov, 2007
20:12:02
HTTP/1.1 200 OK
ID195 (termination link)
TitleIRC Bot Shell
Entry
WsIRT Squad
Reporter
Paul
Timestamp28 Nov, 2007 @ 19:39:12
Topic ID209332 - Read/respond to WsIRT commentary.
Handler Note:
01 Dec, 2007
01:31:00
Paul: Attackers are attempting to inject this script into vulnerable remote web servers. Once it is successfully installed illegally onto a web server, it attempts an fsockopen connection to one of the following destinations on port 8080:

sunnyplaces.weedns.com
mymusicplace.weedns.com
dns4.bpa.nu
dns3.bpa.nu
dns2.bpa.nu
dns1.bpa.nu
snes.dnip.ne
snes.opendns.be
nses1.dd.blueline.be
xamyx.dnip.net

At which point it randomly generates a user and a nick for what appears to be an IRC-like connection. A real sample is shown once it has logged in:

"MODE cafkassps -x i"
"JOIN ##p md5hash"
"NICK cafkassps"

One of its responses include:
"NOTICE :VERSION mIRC 6.26 BY Khaled Mardam-Bay"

This script is setup for the attacker to read in commands such as:

ls, cmd, pwd, chown, chmod, get, rm, cd, touch, cat, symlink, uname, opme

et cetera.

The script attempts to be obfuscated. It is nefarious in nature and should be removed immediately. All evidence surrounding the installation of the script should be preserved and sent to law enforcement referencing this ticket.

Handler Note:
01 Dec, 2007
01:31:47
Paul: View CIDR AS8342 Report: http://www.cidr-report.org/cgi-bin/as-report?as=8342

"8342 | RU | ripencc | 1997-06-11 | RTCOMM-AS RTComm.RU Autonomous System"

Handler Note:
01 Dec, 2007
01:31:48
Paul: Extended information for AS8342:
State/Province:
Country: ru
Responsible Domain: rtcomm.ru
Abuse Email: security@rtcomm.ru
Handler Note:
01 Dec, 2007
01:39:25
Paul: Generated and sent email attack alert to respective parties.
Handler Note:
01 Dec, 2007
14:21:16
Paul: From Yuri at 7:31 AM EST:

I removed site - http://hotraebywka.chat.ru/images/girl
Fetched URLs

Report for at 28 Nov, 2007 @ 19:51:00


fetched page

at 28 Nov, 2007 @ 19:51:05
MD5 Fingerprint: 6cfff36d525fc69af6157ce05d3b367d
SHA1 Fingerprint: 0e47291d6398aa8d97d3ef9ecd69aea8a1603fa5
Version 1.0
spacer spacer