|
|||||||||||
|
Nethief trojan http requests.
From: Marc <marc(at)egwn.net>
Date: Mon Nov 11 2002 - 06:07:52 EST Hi, A few days ago my webserver started to catch dozens of the below pasted requests per minute :
XXX.XXX.XXX.XXX - - [11/Nov/2002:11:44:08 +0100] "GET
XXX.XXX.XXX.XXX - - [11/Nov/2002:11:44:08 +0100] "GET
The .jpg files doesn't exist in the user directory. I've pasted the name of the file in google and found that it probably belongs to a virus/trojan called Nethief. But I haven't found why my webserver is getting those requests. What I've found is that the trojan copies itself with the name IEXPLORER.EXE (the real one is IEXPLORE.EXE), and seems to be using it as the USER-AGENT if you look to the webserver log files. The trojan is (apparently) only for Win32, so that would mean I'm not the infected end, because we don't use any single Win32 SO. Then why the hell we're getting those requests ? Has anyone had the same problem ?
Thanks in advance,
This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:01:38 EDT |
||||||||||
|
|||||||||||