A guy on the apache user mailing list was able to talk with the guys
doing this scan, here is the response:
Okay Red-Tail Books, I got more information for you! This is the
latest response I got:
"The malware is installed via a range of vulnerabilities including
social engineering. This scan is really testing for the malware's
rendezvous protocol for command and control. As a rule, we have been
informing law enforcement about infected machines and they have been
doing victim notification and thus if your correspondent is infected
they will be contacted. However, I believe that this particular
malware works exclusively with IIS and thus an Apache user is unlikely
ot have much to worry about. Unfortunately, I don't know the precise
meaning of the string or what it elicits and Paul (cc'd) who is the
grad student lead on this project is currently away on his honeymoon,
but I'm sure we can respond more succinctly once he returns"
So, it seems that you're in the clear and have nothing to worry about,
mainly because you're running Apache and not IIS. I wish I could
answer what the actual hex string means and what Apache responded
with. Perhaps when Paul gets back from his honeymoon, we'll receive
an answer.
Best of luck.
Ken.
------------------------------------------------------------------------------
Attend Shape: An AT&T Tech Expo July 15-16. Meet us at AT&T Park in San
Francisco, CA to explore cutting-edge tech and listen to tech luminaries
present their vision of the future. This family event has something for
everyone, including kids. Get more information and register today.
http://sdm.link/attshape
_______________________________________________
Fail2ban-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/fail2ban-users