ZOMBIES_HTTP_GET

From: Kee Hinckley (nazgulat_private)
Date: Sun Jun 23 2002 - 09:45:16 PDT

  • Next message: Bill Royds: "RE: Unusual proxy port scan"

    Does anyone know what this is about?
    
    80.14.144.19 - - [17/Jun/2002:17:40:42 -0400] "GET /instructions.txt HTTP/1.1" 302 332 "-" "ZOMBIES_HTTP_GET"
    80.14.144.19 - - [17/Jun/2002:17:41:16 -0400] "GET /instructions.txt HTTP/1.1" 302 332 "-" "ZOMBIES_HTTP_GET"
    67.218.5.187 - - [17/Jun/2002:18:04:11 -0400] "GET /infector.exe HTTP/1.1" 302 332 "-" "ZOMBIES_HTTP_GET"
    67.218.5.187 - - [17/Jun/2002:18:04:32 -0400] "GET /infector.exe HTTP/1.1" 302 332 "-" "ZOMBIES_HTTP_GET"
    80.14.144.19 - - [17/Jun/2002:18:23:38 -0400] "GET /instructions.txt HTTP/1.1" 302 332 "-" "ZOMBIES_HTTP_GET"
    80.14.144.19 - - [17/Jun/2002:18:24:54 -0400] "GET /instructions.txt HTTP/1.1" 302 332 "-" "ZOMBIES_HTTP_GET"
    195.131.106.186 - - [17/Jun/2002:18:25:12 -0400] "GET /instructions.txt HTTP/1.1" 302 332 "-" "ZOMBIES_HTTP_GET"
    195.131.106.186 - - [17/Jun/2002:18:28:42 -0400] "GET /instructions.txt HTTP/1.1" 302 332 "-" "ZOMBIES_HTTP_GET"
    
    
    -- 
    
    Kee Hinckley - Somewhere.Com, LLC
    http://consulting.somewhere.com/
    
    I'm not sure which upsets me more: that people are so unwilling to accept
    responsibility for their own actions, or that they are so eager to regulate
    everyone else's.
    
    ----------------------------------------------------------------------------
    This list is provided by the SecurityFocus ARIS analyzer service.
    For more information on this free incident handling, management 
    and tracking system please see: http://aris.securityfocus.com
    



    This archive was generated by hypermail 2b30 : Sun Jun 23 2002 - 12:16:23 PDT