This web server is visiting our web sites:
66.208.26.98 resolves to"nflplayers.com"
Top Level Domain: "nflplayers.com"
Trends from the trenches of Internet traffic. Hackers, spammers and Internet abuse. IP address database. DNS sightings. Views and opinions expressed are my own. ~ Teri Radichel @teriradichel
This web server is visiting our web sites:
66.208.26.98 resolves to"nflplayers.com"
Top Level Domain: "nflplayers.com"
Here's a web server that is being used to surf our web sites:
207.234.208.96 resolves to"ap-art.com"Top Level Domain: "ap-art.com"
Hmm, should this IP address be surging the web? Seems to have an interest in our web sites.
212.159.42.175 resolves to"liggins.plus.com"
Top Level Domain: "plus.com"
Proxy server surfing our web sites?
83.217.229.147 resolves to"proxy2.xter.net"
Top Level Domain: "xter.net"
Working away here suddenly my printer started making noise for no apparent reason. I'm guessing someone got on my network or my machine here and they are snooping around and hit the device on that port / local IP.
I looked at IPs my machine is connected to and for no apparent reason it is connected to this IP:
205.178.145.1
InQuent Technologies Inc. INQUENT-2 (NET-205-178-128-0-1) 205.178.128.0 - 205.178.191.255Network Solutions, LLC NSLLC01 (NET-205-178-145-0-1) 205.178.145.0 - 205.178.145.255
Hmmm....hacked or?
Here's an interesting dns resolution. Hide? Hmm.
195.10.45.155 resolves to"hide-155.nhs.uk"
Top Level Domain: "nhs.uk"
This IP was surfing our web sites. Looks like something good to block.
203.97.46.29 resolves to"proxy.hosting.co.nz"
Top Level Domain: "co.nz"
Hmm, websherpas.com needs to consult a higher power to prevent their server from surfing the web. This server was sniffing around our web sites:
209.102.67.2 resolves to"www.websherpas.com"
Top Level Domain: "websherpas.com"
This is another web server surfing our web site. Probably hackers or hacked.
212.20.253.212 resolves to"euro-hostels.co.uk"
Top Level Domain: "co.uk"
Here are some interesting results looking up the information about this IP range:
inetnum: 156.54.0.0 - 156.54.255.255
remarks: This inetnum has been transfered as part of the ERX. It was present in both the ARIN and RIPE databases, so the information from both databases has been merged. If you are the mntner of this object, please update it to reflect the correct information.
If this is an Exchange server what is it doing surfing our web sites?
Perhaps this stands for something else however:
64.65.150.210 resolves to"exch.seattlearch.org"
Top Level Domain: "seattlearch.org"
Here's a bank server in Sweden surfing the web....is this right? That's a little scary...but perhaps since I don't speak the language this is referring to a modem bank..so I'll let it slide for now =)
195.242.56.2 resolves to"clients.kaupthing.se"
Top Level Domain: "kaupthing.se
This one looks a little funny ...is this really the IP of an end user surfing or a server?
128.250.172.175 resolves to"guyd.psych.unimelb.edu.au"
Top Level Domain: "edu.au"
Here's an IP with an interesting resolution:
202.7.145.118 resolves to"william.aeoncyberclub.com"
Top Level Domain: "aeoncyberclub.com"
This server appears to be surfing the web and appears to be a web server, though by the looks of the "site" it may be an amateur at home hosting his or her own site.
88.198.38.230 resolves to"www.adressendeutschland.de"
Top Level Domain: "adressendeutschland.de"
Is this really an email domain or a dsl domain? It says ozemail but then it has dsl in the URL as well. Hopefully someone in Australia can alert this email / dsl provider to find out if this server is hacked.
203.102.242.189 resolves to"189.fip-4.dsl.ozemail.com.au"
Top Level Domain: "com.au"
Here's a proxy server in the Philippines surfing around our web sites...
202.44.136.50 resolves to"proxy.thapra.su.ac.th"
Top Level Domain: "ac.th"
A SpeakEasy IP with some scanalert.com application is surfing our web sites...
66.92.26.98 resolves to"scan0.scanalert.com"
Top Level Domain: "scanalert.com"
This is the latest blatant abusing network:
inetnum: 85.255.112.0 - 85.255.127.255
netname: inhoster
descr: Inhoster hosting company
descr: OOO Inhoster, Poltavskij Shliax 24, Kharkiv, 61000, Ukraine
country: UA
There appears to be a hacker at arrival communications on this IP 69.84.207.35 targeting one of our real estate web sites.
They hit our contact request form about 70 times in one day.
Shortly thereafter the publishing of the site was altered, but we were able to easily republish.
OrgName: Arrival Communication, Inc
OrgID: ARRV
Address: 5100 California Ave Suite 104
City: Bakersfield
StateProv: CA
PostalCode: 93309
Country: US
NetRange: 69.84.192.0 - 69.84.207.255
Per our records, PHP is far and away the most attacked language - and we don't even host it.
These are the URLS various hackers have been scanning our boxes for in the past few months:
/phpAdsNew/adxmlrpc.php
/index.php
/profile.php
/cmd.php
/Ads/adxmlrpc.php
/register.php
/thisdoesnotexistahaha.php
/stats/cmd.php
/portal/cmd.php
/adserver/adxmlrpc.php
/adxmlrpc.php
/a1b2c3d4e5f6g7h8i9/nonexistentfile.php
/phpads/adxmlrpc.php
/web/e-commerce/database/index.php/administration/module/module/index.php
/portal/cacti/cmd.php
/xmlrpc.php
/xmlrpc/xmlrpc.php
/xmlsrv/xmlrpc.php
/blog/xmlrpc.php
/cacti/cmd.php
/drupal/xmlrpc.php
/web/phpMyAdmin/main.php
/web/phpMyAdmin/main.phpmain.php
/w3c/p3p.xml
/_vti_bin/_vti_aut/author.dll
/admin/login/index.php
/admin/pages/index.php
/admin/pages/settings.php
/admin/start/index.php
/public.php
/web/.../work/index.php
/web//work/index.php
And here are the IPs that have been up to this mischeif along with number of hits:
72.232.194.66
NetRange: 72.232.0.0 - 72.232.255.255
CIDR: 72.232.0.0/16
NetName: LAYERED-TECH-
NetHandle: NET-72-232-0-0-1
Parent: NET-72-0-0-0-0
NetType: Direct Allocation
NameServer: NS1.LAYEREDTECH.COM
NameServer: NS2.LAYEREDTECH.COM
Comment: Please send all abuse complaints to
Comment: abuse@layeredtech.com
RegDate: 2005-09-07
Updated: 2006-03-07
72.14.75.44
ISP Alliance, INC. ZCORUM (NET-72-14-64-0-1)
72.14.64.0 - 72.14.127.255
Millry.net MILLRY (NET-72-14-75-0-1)
72.14.75.0 - 72.14.75.255
___________________________
66.102.66.148
OrgName: Cingular Wireless
OrgID: CINW
Address: Cingular Wireless, LLC
Address: 12555 Cingular Way, Suite 4360
City: Alpharetta
StateProv: GA
PostalCode: 30004
Country: US
NetRange: 66.102.160.0 - 66.102.191.255
________________________________
66.102.186.15
OrgID: INKG
Address: 177 Wellington Street
Address: Suite 302
City: Kingston
StateProv: ON
PostalCode: K7L-3E3
Country: CA
NetRange: 66.102.64.0 - 66.102.95.255
__________________________________
217.160.230...
inetnum: 217.160.224.0 - 217.160.239.255
netname: SCHLUND-CUSTOMERSdescr: Schlund + Partner AGcountry: US
This looks promising. Symantec is using brains instead of a database to figure out if software is malicious or not. Something like this is definitely needed - over and above a database approach. It is too easy to change a file name - let's say if you know xyz.exe is a known hack - the hacker can simply post that file all over the place for the unwary user to download with countless other names. Zero day attacks need more than a known list of hacks because their goal is to get out and do damage in one day - before they get into that database. Also with an FBI representative claiming that 15% of the world's computers are hacked and/or controlled by command and control servers doing dirty work - and new hacked servers coming online every day, it is impossible to block out hackers based on IP address or other identifying information alone.
You'll probably never believe this but had it in my head for a while to write about the huge amount of traffic I see coming from universities that is obviously hacker traffic. I was going to suggest that maybe someone was paying students to do dirty work or possibly download "cool new stuff" which is unknowling running worms, viruses or malware. Something has to be going on at Universities because I cannot believe they are all just hacked to such a high extreme.
Lo and behold I found this article today: