Options

Signs of a script kiddie

lsud00dlsud00d Member Posts: 1,571
So I was reviewing some IIS logs for a customer and noticed some attempts at malicious activity...I got a chuckle out of the calling cards.

2013-12-17 03:15:51 X.X.X.X GET /w00tw00t.at.blackhats.romanian.anti-secicon_smile.gif - 80 - 203.171.229.184 ZmEu 404 0 2 250

2013-12-09 01:40:59 X.X.X.X GET /muieblackcat - 80 - 37.77.7.238 - 404 0 2 281

They're poking at the default site root and then try to poke around and see if they can get to php, cgi-bin, or WordPress resources:

2013-12-19 19:45:24 X.X.X.X GET /wp/wp-login.php - 80 - 202.117.1.240 Mozilla/5.0+(X11;+U;+Linux+i686;+pt-BR;+rv:1.9.0.15)+Gecko/2009102815+Ubuntu/9.04+(jaunty)+Firefox/3.0.15 404 0 2 328

2013-12-17 03:15:51 X.X.X.X GET /phpMyAdmin/scripts/setup.php - 80 - 203.171.229.184 ZmEu 404 0 2 250

2013-12-16 03:02:49 X.X.X.X GET /cgi-bin/php5 - 80 - 89.248.160.192 Mozilla/4.0+(compatible;+MSIE+6.0;+Windows+9icon_cool.gif 404 0 2 171

But these don't exist. What's interesting is the "Romanians" are coming from a China source, I think someone is trying to get fingers pointed the other way icon_twisted.gif

Comments

Sign In or Register to comment.