Webserver Incident Reporting and Termination(TM) Squad
NOTE: Web servers have logs and in those logs is evidence of attempted hacking. For instance, one may notice an attack that calls such a script from a remote server "r57.php??". Its these kinds of attacks we're looking to investigate. For a concrete example, see these reports.
Please do not submit phish, spam, or malware to WsIRT. Only submit attack signatures from web server logs. As this project hasn't officially been publicly launched, we are still reclassifying the tool and its verbiage.
This code is just another obfuscation of an earlier version worked in WsIRT in report number 195. It attempts to make
connections to the above and then gives the attacker the ability to compromise a remove web server. It should be
removed immediately, and any remaining domains (above) that aren't already taken care of should be immediately.
Handler Note: 09 Dec, 2007 18:45:28
Paul: Reference to original find: http://www.castlecops.com/IRC_Bot_Shell_attack195.html
Paul: Extended information for AS8342:
State/Province:
Country: ru
Responsible Domain: rtcomm.ru
Abuse Email: security@rtcomm.ru
Handler Note: 09 Dec, 2007 18:53:21
Paul: ;; QUESTION SECTION:
;mymusicband.weedns.com. IN A
;; ANSWER SECTION:
mymusicband.weedns.com. 300 IN A 80.53.30.234
mymusicband.weedns.com. 300 IN A 211.21.125.194
mymusicband.weedns.com. 300 IN A 202.123.84.169
mymusicband.weedns.com. 300 IN A 216.32.78.162
mymusicband.weedns.com. 300 IN A 80.247.203.96
mymusicband.weedns.com. 300 IN A 121.119.172.49
mymusicband.weedns.com. 300 IN A 87.236.196.115
mymusicband.weedns.com. 300 IN A 84.245.99.6
mymusicband.weedns.com. 300 IN A 88.191.26.64
mymusicband.weedns.com. 300 IN A 67.19.83.228
;; QUESTION SECTION:
;myphonenumber.weedns.com. IN A
;; ANSWER SECTION:
myphonenumber.weedns.com. 300 IN A 216.32.78.162
myphonenumber.weedns.com. 300 IN A 88.191.26.64
myphonenumber.weedns.com. 300 IN A 211.21.125.194
myphonenumber.weedns.com. 300 IN A 121.119.172.49
myphonenumber.weedns.com. 300 IN A 80.53.30.234
myphonenumber.weedns.com. 300 IN A 67.19.83.228
myphonenumber.weedns.com. 300 IN A 84.245.99.6
myphonenumber.weedns.com. 300 IN A 87.236.196.115
myphonenumber.weedns.com. 300 IN A 202.123.84.169
myphonenumber.weedns.com. 300 IN A 80.247.203.96
;; QUESTION SECTION:
;ieatironx.weedns.com. IN A
;; ANSWER SECTION:
ieatironx.weedns.com. 300 IN A 88.191.26.64
ieatironx.weedns.com. 300 IN A 216.32.78.162
ieatironx.weedns.com. 300 IN A 80.247.203.96
ieatironx.weedns.com. 300 IN A 84.245.99.6
ieatironx.weedns.com. 300 IN A 87.236.196.115
ieatironx.weedns.com. 300 IN A 202.123.84.169
ieatironx.weedns.com. 300 IN A 80.53.30.234
ieatironx.weedns.com. 300 IN A 121.119.172.49
ieatironx.weedns.com. 300 IN A 67.19.83.228
ieatironx.weedns.com. 300 IN A 211.21.125.194
;; QUESTION SECTION:
;himan.opendns.be. IN A
;; ANSWER SECTION:
himan.opendns.be. 2560 IN A 84.245.99.6
;; QUESTION SECTION:
;ko.dd.blueline.be. IN A
;; ANSWER SECTION:
ko.dd.blueline.be. 297 IN A 87.236.196.115
;; QUESTION SECTION:
;p4n33123e.dd.blueline.be. IN A
;; ANSWER SECTION:
p4n33123e.dd.blueline.be. 300 IN A 121.119.172.49
;; QUESTION SECTION:
;xphon3.opendns.be. IN A
;; ANSWER SECTION:
xphon3.opendns.be. 0 IN A 216.32.78.162
;; QUESTION SECTION:
;myphone3.dnip.net. IN A
;; ANSWER SECTION:
myphone3.dnip.net. 100 IN A 67.19.83.228
;; QUESTION SECTION:
;mymusics.dnip.net. IN A
;; ANSWER SECTION:
mymusics.dnip.net. 100 IN A 80.53.30.234
Handler Note: 09 Dec, 2007 18:55:42
Paul: Each of the domains in the script are mapped to one of ten unique IP addresses:
Paul: Extended information for AS35592:
State/Province:
Country: cz
Responsible Domain: network.cz
Abuse Email: abuse@network.cz
Handler Note: 09 Dec, 2007 19:04:52
Paul: To all the ISPs, please check for port connectivity on 8080, which this script attempts to establish a connection with
and take instructions for its enslavement of the compromised server it was injected into.
Handler Note: 09 Dec, 2007 19:10:41
Paul: Generated and sent email attack alert to respective parties.