Thanks Spork for the detailed reply you got from Berkeley, I got a similar one, though not quite as detailed. I think the problem with Apache is that it is simply an index.html sending a 200 “OK” and not actually replying to say yes I am infected with whatever it is they are looking for. At the time when I first noticed this I looked into various ways of getting Apache to send a 400 or 403 but it involved messy rewrite rules which I just hate. Seeing that I am now seeing this same string in various different formats coming in daily now from IP’s all over the globe I would say whatever infected servers out there who have been already been implanted with this malicious software are now perhaps being called into action, possibly a big DDOS attack planned or something else of a more sinister nature. Seeing that Berkeley are working with and reporting this to law enforcement makes me believe there is something quite sinister behind all of this. Anyways, certainly a very interesting one to keep an eye on. I am now also seeing similarly formatted strings now coming in over the past few days as per the example below which now also seem to be targetting SQL servers. Luckily none of mine are open to the public and only run as localhost but I am a sure a lot of people which port 3306 exposed are in for something being planned. This example below came in as a User-Agent string this morning in my logs, so not only are they sending crazy formatted strings via normal http / https requests but also now forging user agent string with similar stuff. "}__test|O:21:\x22JDatabaseDriverMysqli\x22:3:{s:2:\x22fc\x22;O:17:\x22JSimplepieFactory\x22:0:{}s:21:\x22\x5C0\x5C0\x5C0disconnectHandlers\x22;a:1:{i:0;a:2:{i:0;O:9:\x22SimplePie\x22:5:{s:8:\x22sanitize\x22;O:20:\x22JDatabaseDriverMysql\x22:0:{}s:8:\x22feed_url\x22;s:46:\x22eval($_REQUEST[1]);JFactory::getConfig();exit;\x22;s:19:\x22cache_name_function\x22;s:6:\x22assert\x22;s:5:\x22cache\x22;b:1;s:11:\x22cache_class\x22;O:20:\x22JDatabaseDriverMysql\x22:0:{}}i:1;s:4:\x22init\x22;}}s:13:\x22\x5C0\x5C0\x5C0connection\x22;b:1;}\xFD\xFD\xFD\xFD “ I must say every morning there is always something interesting to be found in one’s logs, sadly a great deal of people running servers out there don’t seem to monitor their logs as frequently as they should if at all. Kind Regards Mitchell From: Spork Schivago <sporkschivago@xxxxxxxxx> Reply: users@xxxxxxxxxxxxxxxx <users@xxxxxxxxxxxxxxxx> Date: 07 October 2016 at 8:10:58 AM To: users@xxxxxxxxxxxxxxxx <users@xxxxxxxxxxxxxxxx> Subject: Re: [users@httpd] Unknown accepted traffic to my site
|