DarkShield / daProxy

Proxy boxes
0 stars 0 forks source link

Generate check for common automated attack w00tw00t.at.blackhats.romanion.anti-sec:) #2

Open mattjay opened 11 years ago

mattjay commented 11 years ago

Interesting automated attack scanning sequences. Resource: http://www.securityweek.com/hacked-mit-server-used-stage-attacks-scan-vulnerabilities

From our logs:

http proxying to http://184.73.162.139/MyAdmin/scripts/setup.php
Off Domain
http proxying to http://184.73.162.139/myadmin/scripts/setup.php
Off Domain
http proxying to http://184.73.162.139/
Off Domain
http proxying to http://184.73.162.139/HNAP1/
Off Domain
http proxying to http://184.73.162.139/manager/html
Request Connection Undefined
Request Connection Undefined
Request Connection Undefined
Request Connection Undefined
Request Connection Undefined
Off Domain
http proxying to http://184.73.162.139/w00tw00t.at.blackhats.romanian.anti-sec:)
Off Domain
http proxying to http://184.73.162.139/pma/scripts/setup.php
Off Domain
http proxying to http://184.73.162.139/phpmyadmin/scripts/setup.php
Off Domain
http proxying to http://184.73.162.139/phpMyAdmin/scripts/setup.php
Off Domain
http proxying to http://184.73.162.139/MyAdmin/scripts/setup.php
Request Connection Undefined
Request Connection Undefined
Request Connection Undefined
Request Connection Undefined
Request Connection Undefined
Off Domain
http proxying to http://184.73.162.139/
Off Domain
http proxying to http://184.73.162.139/HNAP1/
Off Domain
http proxying to http://184.73.162.139/manager/html
Off Domain
http proxying to http://184.73.162.139/w00tw00t.at.blackhats.romanian.anti-sec:)
Off Domain
http proxying to http://184.73.162.139/myadmin/scripts/setup.php