Web abuse Tracker

On this page you can see the recent attackers which my honeypots have caputred. You can click on a IP address or a RFI script URL to see more inforamtion about the attack.

Recent RFI attackers (hijacked webservers)

Timestamp (UTC)IP addressHostnameCountryRFI URLNew?
2010-07-31 22:38:02195.42.120.131 vs120131.tuxtools.net
IE
 http://www.net-games.it/open.txtno
2010-07-31 22:11:02202.160.123.72 jobsupermart.com
SG
 http://progene.info/English/Fx29ID.txtno
2010-07-31 21:23:3983.216.190.83 
A2
 http://www.diakonia-jkt.sch.id/sk/image_galeri/a4DAc8C2___CIMG1122.jpgno
2010-07-31 20:39:4589.108.67.164 cp122.agava.net
RU
 http://constructor.ru/modules/goodid.txtyes
2010-07-31 19:56:1281.208.34.38 81-208-34-38.ip.fastwebnet.it
IT
 http://ssghost.com/ssg/id1.txtno
2010-07-31 19:45:23212.249.57.201 www.hugy.ch
CH
 http://impeel.com/impeel/web/css/r_jpg.txtno
2010-07-31 19:43:22222.236.47.182 
KR
 http://www.hydraumatec.com/mambots/editors/tinymce//jscripts/tiny_mce/no
2010-07-31 19:21:16203.147.62.92 
TH
 http://bcis.pacificu.edu/images/1no
2010-07-31 18:59:1064.15.156.75 
CA
 http://www.puddicombe.org/wedding/idxx.txtno
2010-07-31 18:58:3069.10.143.68 ns1.on-air.co.za
CA
 http://phamsight.com/docs/images/headyes
2010-07-31 18:11:3677.222.34.35 badi.ru
RU
 http://www.freediskspace.com/_inc/images/v4.5id1no
2010-07-31 17:45:3589.145.68.166 mtc.mtcmedia.co.uk
GB
 http://www.photos.or.kr/bbs/icon/id1.txtyes
2010-07-31 17:32:1270.38.11.39 
CA
 http://www.irishtoothache.com/ver1no
2010-07-31 17:13:3474.52.48.66 p14.ich-2.com
US
 http://cyb3rz.fileave.com/fx29id1.txtno
2010-07-31 17:02:2275.136.121.230 75-136-121-230.dhcp-v.spbg.sc.chart
US
 http://www.howtolisten.kr/lct/exam3/111/id1.txtno
2010-07-31 16:45:3074.55.96.234 server102.easyhostsolutions.net
US
 http://www.oschub.cn//plugins/system/tsno
2010-07-31 16:41:2282.192.65.135 esd536.easyserver.net
NL
 http://minarik-pila.cz//id1.txtno
2010-07-31 16:17:5189.161.174.100 v032104.home.net.pl
PL
 http://203.252.71.232/~edugraduate/data/file/sub3_1/ckrid1.txtyes
2010-07-31 14:42:31200.29.171.35 
CL
 http://www.biegaj.isp.net.pl/portal/media/id.txtno
2010-07-31 14:40:26119.235.18.12 server4239.masterweb.net
ID
 http://tjdhosp.co.kr/data/session/byz9991.txtno

Displayed: 20
New RFI attacks caputred today: 12
Total RFI attacks caputred today: 50

New RFI URLs

RFI script URLHashFilesize (Bytes)Counter
http://wjw.kr/.header/RFI/id1.txt725add22d937622a13654a97d8c04538861
http://www.photos.or.kr/bbs/icon/id1.txt725add22d937622a13654a97d8c04538861
http://surtifruverdelasabana.com/MC22.txt725add22d937622a13654a97d8c04538861
http://www.primer.hu/e107_languages/baner.txt725add22d937622a13654a97d8c04538863
http://milowfan.com/files/ckrid1.txt725add22d937622a13654a97d8c04538866
http://jy-lib.or.kr/bbs//skin/zero_vote/id.txt725add22d937622a13654a97d8c04538861
http://www.fileden.com/files/2010/7/14/2914741/echo.txt725add22d937622a13654a97d8c04538861
http://www.mln.mlc.edu.tw/appserv/p1.txtdc7b2fd7417f4ea1917ac8b7284fecba772
http://kesawan.fileave.com/irc/sh.txt725add22d937622a13654a97d8c04538861
http://www.africamissionsna.org//sc/as.txt725add22d937622a13654a97d8c04538861

Recent scanning drones

Timestamp (UTC)IP addressHostnameCountryNotesCounterNew?
2010-08-01 00:08:29187.45.214.10 xxxdnn1028.locaweb.com.br
BR
Scanning Drone (w00tw00t.at.ISC.SANS)2no
2010-07-31 23:22:4662.103.39.74 host10.halkidiki.gov.gr
GR
Scanning Drone (w00tw00t.at.ISC.SANS)5no
2010-07-31 17:10:3069.64.56.208 usloft1512
US
Scanning Drone (w00tw00t.at.ISC.SANS)9no
2010-07-31 14:17:5666.150.221.50 
US
Scanning Drone (w00tw00t.at.ISC.SANS)2no
2010-07-31 12:17:2391.121.136.191 ns355308.ovh.net
FR
Scanning Drone (w00tw00t.at.ISC.SANS)8no
2010-07-31 06:23:0895.130.172.152 host-95-130-172-152.routergate.com
TR
Scanning Drone (w00tw00t.at.ISC.SANS)2no
2010-07-31 03:09:56213.246.222.74 mail.davidts.be
BE
Scanning Drone (w00tw00t.at.ISC.SANS)85no
2010-07-31 00:53:0458.218.204.110 
CN
Open Proxy Scanner19no
2010-07-31 21:46:1381.201.60.169 router-zero.pilsfree.net
CZ
Open Proxy Scanner1yes
2010-07-31 20:53:0585.62.229.21 21.pool85-62-229.dynamic.orange.es
ES
Scanning Drone1yes

Recent referer spammers

Timestamp (UTC)IP addressHostnameRefererCountryCounterNew?
2010-07-31 23:57:5091.201.66.104 
RU
http://www.pinyen.com/member/Acai_Berry_Testimonials7no
2010-07-31 23:57:0495.134.10.89 89-10-134-95.pool.ukrtel.net
UA
http://www.hqtube.com/?5736000000/6yes
2010-07-31 23:52:3795.134.7.141 141-7-134-95.pool.ukrtel.net
UA
http://www.hqtube.com/?5736000000/22yes
2010-07-31 23:36:48143.93.43.2 pat-2.umwelt-campus.de
DE
http://www.sizzling-hot.de4no
2010-07-31 19:12:2095.134.142.75 75-142-134-95.pool.ukrtel.net
UA
http://www.hqtube.com/?5736000000/20yes
2010-07-31 12:34:4841.190.16.17 
NG
http://smokefreeonline.com15no
2010-07-31 07:37:5395.134.13.85 85-13-134-95.pool.ukrtel.net
UA
http://www.hqtube.com/?5736000000/2yes
2010-07-31 06:46:5898.165.72.66 ip98-165-72-66.ph.ph.cox.net
US
http://www.SeoMarketingServicesOnline.com2yes
2010-07-31 05:53:23212.241.176.94 ds3296.dedicated.turbodns.co.uk
GB
http://makeupsuppliers.weebly.com3yes
2010-07-31 02:02:5195.134.234.45 45-234-134-95.pool.ukrtel.net
UA
http://www.hqtube.com/?5736000000/2no
2010-07-31 01:11:30120.35.19.29 
CN
http://holidaystream.com/category/hotel-guides/17no
2010-07-31 21:20:25173.208.70.134 173.208.70.134.rdns.ubiquityservers
US
http://www.packagefromsanta.com/1yes
2010-07-31 21:14:3259.149.227.44 059149227044.ctinets.com
HK
http://www.squidoo.com/raeuchermischung1yes
2010-07-31 19:08:36203.172.168.40 
TH
http://highestdecoration.com1yes
2010-07-31 18:45:58173.208.13.100 rdns173-208-13-100.xninet.com
US
http://dicale.com1yes
2010-07-31 18:43:0094.181.219.64 dynamicip-94-181-219-64.pppoe.kirov
RU
http://grou.ps/cigarettes/blogs/item/buy-cigarettes-overseas1yes
2010-07-31 18:19:5659.120.5.235 mail.brightwear.com.tw
TW
http://www.pornhub4u.com1yes
2010-07-31 18:19:09173.234.31.149 173.234.31.149.rdns.ubiquityservers
US
http://dicale.com1yes
2010-07-31 15:21:14117.79.83.161 
CN
http://www.replicahandbagsite.com1yes
2010-07-31 15:10:5666.249.82.2 
US
http://translate.googleusercontent.com/translate_c?hl=en&ie=1yes

Recent catched Script Kiddies

Timestamp (UTC)IP addressHostnameCountryModuleUserAgentCounterNew?
2010-07-31 23:56:0966.219.58.41 net66-219-58-41.static-customer.cor
US
phpMyAdminMLBot (www.metadatalabs.com/mlbot)7no
2010-07-31 17:10:0141.230.223.246 
TN
r57ShellMozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/12yes
2010-07-31 16:29:49188.104.171.201 
DE
r57ShellMozilla/5.0 (Windows; U; Windows NT 6.1; de; rv:1.9.2.8) Gec5yes
2010-07-31 15:10:5841.227.96.235 
TN
r57ShellMozilla/5.0 (Windows; U; Windows NT 5.1; fr; rv:1.9.1.11) Ge33yes
2010-07-31 13:21:5092.74.2.211 dslb-092-074-002-211.pools.arcor-ip
DE
r57ShellMozilla/5.0 (Windows; U; Windows NT 6.1; de; rv:1.9.2.8) Gec24yes
2010-07-31 06:34:4687.210.239.104 ip104-239-210-87.adsl2.static.versa
NL
r57ShellJava/1.6.0_2040no
2010-07-31 03:17:4292.74.13.151 dslb-092-074-013-151.pools.arcor-ip
DE
r57ShellMozilla/5.0 (Windows; U; Windows NT 6.1; de; rv:1.9.2.8) Gec44yes
2010-07-31 02:55:28213.46.140.38 d140038.upc-d.chello.nl
NL
r57ShellJava/1.6.0_1514yes
2010-07-31 01:31:36173.203.198.31 173-203-198-31.static.cloud-ips.com
US
PHPShellMozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.3) 43no
2010-07-31 20:07:1841.224.197.151 
TN
r57ShellMozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/1yes

Questions? Your IP address is listed here? You don't know what a RFI attack is? Then take a look at the FAQ.

economics-recluse
Urgent!