CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
spacer spacer

WsIRT(TM)

Webserver Incident Reporting and Termination(TM) Squad

NOTE: Web servers have logs and in those logs is evidence of attempted hacking. For instance, one may notice an attack that calls such a script from a remote server "r57.php??". Its these kinds of attacks we're looking to investigate. For a concrete example, see these reports.

Please do not submit phish, spam, or malware to WsIRT. Only submit attack signatures from web server logs. As this project hasn't officially been publicly launched, we are still reclassifying the tool and its verbiage.

[ How-To / FAQ ]

WsIRT -> Confirmed Attacks | Terminated Attacks


status: confirmed attack

HTTP Response
21 Nov, 2008
20:30:20
408 - SIRT Operation Timed Out
ID94 (termination link)
TitleOS Disclosure, Qe3shell, id Disclosure
Entry
WsIRT Squad
Reporter
Paul
Timestamp28 Nov, 2007 @ 19:39:12
Topic ID209387 - Read/respond to WsIRT commentary.
Handler Note:
01 Dec, 2007
19:03:30
Paul: View CIDR AS30340 Report: http://www.cidr-report.org/cgi-bin/as-report?as=30340

"30340 | US | arin | 2003-09-12 | AS-TIER - Tierpoint, LLC"

Handler Note:
01 Dec, 2007
19:03:49
Paul: Extended information for AS30340:
State/Province: wa
Country: us
Responsible Domain: llix.net
Abuse Email: postmaster@llix.net
Handler Note:
01 Dec, 2007
19:05:02
Paul: The 1.jpg file for download upon inspection reveals a <title>#ulil security tester on dalnet Qe3</title> name.
Handler Note:
01 Dec, 2007
19:09:24
Paul: The Qe3Shell not only permits access to the exploited web server, but it also established sql database connections. It is claimed By * Ulil Hacker Security Tester* * http://ulga.by.ru in the source.
Handler Note:
01 Dec, 2007
19:12:34
Paul: One of the commands the Qe3shell executes is:

("insert into Qe3_temp_table EXEC master.dbo.xp_cmdshell '".$_POST['test4_file']."'",$db)

Another one of the many things it attempts is:

readfile(\"/etc/passwd\");

There is also a reference to:

o---[ HDTEAM shell Ulga/Ulil | http://ulil.xlphp.net
Handler Note:
01 Dec, 2007
19:14:26
Paul: We have found attackers attempting to inject the 3.jpg script to exploitable web servers. While investigating we found files 2.jpg and 1.jpg which are also nefarious in nature. All scripts, if successfully injected into a remote web server, permits criminals to gather intelligence on those systems, and even take control via the Qe3shell. Please remove these immediately.
Handler Note:
01 Dec, 2007
19:17:38
Paul: Generated and sent email attack alert to respective parties.
Handler Note:
02 Dec, 2007
00:23:32
Paul: There are a handful of base64 encoded variables, which when decoded contain perl scripts that make Internet connections, to say the least.
Fetched URLs

Report for at 28 Nov, 2007 @ 19:40:28


fetched page

at 28 Nov, 2007 @ 19:40:29
MD5 Fingerprint: 241322ae84ad606ce1bb083af3c1336d
SHA1 Fingerprint: 5370d07406828acf5c8ac2287c6c8b8c5b76357e

fetched page

at 01 Dec, 2007 @ 19:02:19
MD5 Fingerprint: bb722ebb7a4b81a02c5bc0ff4de271aa
SHA1 Fingerprint: a90d4c0abea0bdfbb541652f7d494ff8144b8d65

fetched page

at 01 Dec, 2007 @ 19:03:30
MD5 Fingerprint: d277c9bfa2a10602ab312a8f72b74710
SHA1 Fingerprint: 0a98918f4e02e6584043575ceb7032ab27c8ed0b
Version 1.0
spacer spacer