· 11 years ago · Aug 10, 2015, 04:28 PM
1Fuck you Ukraine Scriptkiddy
2
3Ukraine tried to access non-existent page
4IP: 81.163.131.57 Hostname: 81.163.131.57
5Browser: IE version 7.0
6
7
8Berdyans'k, Ukraine
9IP: 37.115.4.71
10Hostname: 37-115-4-71-broadband.kyivstar.net
11
12
13Scanning 81.163.131.57 [1000 ports]
14Discovered open port 21/tcp on 81.163.131.57
15Discovered open port 4000/tcp on 81.163.131.57
16Completed Connect Scan 1.96s elapsed (1000 total ports)
17Nmap scan report for 81.163.131.57
18Host is up (0.073s latency).
19Not shown: 995 closed ports
20PORT STATE SERVICE
2121/tcp open ftp
22135/tcp filtered msrpc
23139/tcp filtered netbios-ssn
24445/tcp filtered microsoft-ds
254000/tcp open remoteanything
26
27reported at abuse@kyivstar.net
28http://pastebin.com/4w0DMrP6
29http://pastebin.com/V96aASgX
30IE7.0 & remoteanything srsly?
31http://anti-hacker-alliance.com/index.php?details=81.163.131.57
32
33Start: Mon Aug 10 11:11:21 2015
34HOST: htapi Loss% Snt Last Avg Best Wrst StDev
351.|-- router2-nac.linode.com 0.0% 4 0.6 0.7 0.5 0.7 0.0
362.|-- 207.99.53.45 0.0% 4 0.3 0.3 0.3 0.5 0.0
373.|-- 0.e1-1.tbr2.tl9.nac.net 0.0% 4 1.7 1.6 1.4 1.8 0.0
384.|-- 0.e2-2.pr2.tl9.nac.net 0.0% 4 1.5 2.0 1.4 2.9 0.6
395.|-- nyiix.retn.net 0.0% 4 8.3 3.3 1.5 8.3 3.3
406.|-- ae2-10.RT.ATR.DOK.UA.retn.net 0.0% 4 151.0 150.1 147.1 151.4 1.9
417.|-- GW-DataInternet.retn.net 0.0% 4 152.0 150.7 147.9 152.0 1.8
428.|-- didan.ints.net 0.0% 4 143.4 142.3 140.2 143.5 1.4
439.|-- 81.163.131.57 25.0% 4 138.2 138.7 138.2 139.1 0.0
44
45
46Country: UA
47Registration Date: 2008-08-04
48Registrar: ripencc
49Owner: DIDAN-AS Didan Group LTD,UA
50
51
52Comments
53
54Thank you for commenting!
55
56Post another comment
57(within the last minute) open ports said:
58Nmap scan report for 81.163.131.57
59Host is up (0.073s latency).
60Not shown: 995 closed ports
61PORT STATE SERVICE
6221/tcp open ftp
63135/tcp filtered msrpc
64139/tcp filtered netbios-ssn
65445/tcp filtered microsoft-ds
664000/tcp open remoteanything
67flag like reply
68(1 minutes ago) someone said:
69also uses this ip:
70Ukraine tried to access non-existent page
71IP: 81.163.131.57 Hostname: 81.163.131.57
72Browser: IE version 7.0
73
74
75Berdyans'k, Ukraine
76IP: 37.115.4.71
77Hostname: 37-115-4-71-broadband.kyivstar.net
78
79(12 hours ago) Paul said:
80Attacked our photo gallery site. To the point that our Database pool ran out of connections. Even after the server started sending error messages, it continued to run for the next 5 minutes. Attempted to hit over 2000 pages on our website in under 5 minutes. Firewalled them. If it happends again I will firewall their entire network.
81
82(16 hours ago) cyberspace said:
83is a nice place to visit..but I am glad dont live here. I want to speak to you in person
84
85(4 days ago) lol said:
86lol
87
88(4 days ago) Anonymous said:
89112.198.77.138 attacks me also. what a fact.
90
91(5 days ago) Gatta Fabiano said:
92HI EVERYBODY I AM FABIANO A MUSICIAN FROM BRESCIA ITALY, AND I LIKE THE IDEA OF THIS SITE WHERE I CAN REPORT ANY E-MAIL ADDRESS OF SPAMMERS TO ADD AT A BLACK DATABASE ... GREAT I THINK, BUILD A BEST TOMORROW ONLINE TOGETHER .
93C I A O
94
95(5 days ago) Gabriela a Ji said:
96Nerozum�m - kohosi hled�te? Brepuse? IP?
97
98(6 days ago) PEDRO said:
99Estimados al bajar el softphone Zoiper e instalar en telefono, luego logear el servdor de telefonia IP , tomaron la IP y han intentado robar trafico telefonico al proveedor IP,,, Zoiper esta detras de esto................ tambien
100
101(Aug 3, 2015) U MAD BRO said:
102That 's an DYNAMIC IP, that Telefonica grants to their ADSL2 customers.
103
104(Aug 2, 2015) Luke said:
105Performed an ANY DNS query on my nameserver for commerce.gov.
106
107(July 31, 2015) sime said:
108Sime
109
110(July 31, 2015) sime said:
111Sime
112
113(July 31, 2015) Cyberghost (mod) said:
114You do realise that the ip 198.7.59.110 is from a public vpn named cyberghost with more than a million users you can't put us all in the same bag for 1 or 2 guys using that ip it's like if a guy in phoenix did a robbery and the police send the entire town to jail. Leave us alone.
115
116(July 31, 2015) CKB (mod) said:
117The assholes at IP ripped my small business off of 18,130.10! I couldn't find much on them except they own www.pinacsolutions.org and have a google phone number 231-660-1354 I am not a hacker or anything but admire the work of AHA, hopefully something can be done to prevent this from happening to others. The delivery address of the $18,130.10 was:
118
11950B 8th Street
120Taunton, MA. 02780
121
122Any info (or retaliation) is welcomed
123
124(July 31, 2015) ahmet (mod) said:
125h have an email .is that dangerous.same ip adress u mention.nformatons about :x-store-info:sbevkl2QZR7OXo7WID5ZcV65/pkDWk7T3Fc8OPySipF03G0nmHfsn9CHZLKvAtyh1As9uIyzPfYPIwz+GPKT03i67hBwbC6CwN+tfGFFreO623DmlztnLyR7qmonPMKgcQ1JOAkDstQ=
126Authentication-Results: hotmail.com; spf=pass (sender IP is 209.85.218.54; identity alignment result is pass and alignment mode is relaxed) smtp.mailfrom=gm.ben01@gmail.com; dkim=pass (identity alignment result is pass and alignment mode is relaxed) header.d=gmail.com; x-hmca=pass header.id=gm.ben01@gmail.com
127X-SID-PRA: gm.ben01@gmail.com
128X-AUTH-Result: PASS
129X-SID-Result: PASS
130
131(July 31, 2015) VICTOR (mod) said:
132Good afternoon
133
134IP 148.235.52.21 is blacklisted, unfortunately I am connected to this list my mail provider that is PRODIGY America Movil and for this reason I am being blocked by sending emails from the company where I work, and try to detach the IP and work in other yet remain bounced emails that I send to my suppliers and customers.
135Thanks
136
137(July 31, 2015) Elen (mod) said:
138Please, help.
139With this address for many years already sent porn and spam to the guest. Long did not dare to write to you, but patience when it has a limit. I'll clean up the guest after his visit, I want you to see it for yourself. You are my last hope. Administration is not able to deal with this user. I sincerely believe that you wrote is not in vain. Thank you.
140(addressed to my guest privet.ru/user/Lana_0100/guestbook as proof)
141
142(July 31, 2015) Victim (mod) said:
143I was configuring my old router and forget change the default password admin/admin. So in the next day i was browsing and can't login to many websites, after this I figure out something was happening. Then I check my dns server: 208.43.56.42 and 5.10.108.203 and it's not the dns servers of my ISP. love pishing scams kiddies, they are scanning probably the entire world searching for default user/passwords and pishing to get the passwords. BE AWAKE WITH THIS loveING KIDS!! (obs.: they can even make the entire pishing website that works without being detected haha)
144
145(July 31, 2015) Peruvian (mod) said:
146Thank you so much, that ip adress 104.236.205.233 tried to sign into my google account twice and i didnt even know why somebody from New York, US would want to sign into a peruvian account but i felt the need to search for it and discovered this. Thank you it really helped me. Now i now some stupid hoes are trying to hack me.
147
148(July 31, 2015) Midnight (mod) said:
149These folks at 192.185.2.112 tried to target me several times through email hacking (Yes, they tried and got my email account locked through failed attempts), then they went for my secondary FB and PayPal. Now they keep harassing me, keeps sending me emails. You'd think that these "hackers" would be more discreet.
150
151(July 31, 2015) linlin (mod) said:
152Hi, I have 85.25.43.94 connected to my router, those guys are a huge group with deep know how of loads of hardware. If I should name how many hardware they did poisoned including my iMac and iPhones you would think I'm a crazy peson. However their attack is usually led from Chinese IP addresses covering by SPAM attack but I do not believe they are from China. I have drawn their attention by my forum www.8a8f8.com, somebody asked them to hack and so I brought them home... I have many of their IP having done a small trap for them. I will add them to your web page database soon. My conclusion of those guys is they serve to some powerful organization like NAGRA TV is... however I have got no evidence... just my conclusion...
153
154(July 31, 2015) Agi (mod) said:
155I'm not a hacker or spammer, and also not scammer! I searching the IP "mistery shopper" letter, (I got this letter, from: Mystery Shopper , and when I replay his e-mail address is: my_shop01@aol.com) and I see your page say I'm in your black list in JustSpan, SORBS SPAM, SPAMSCANNIBAL! That is your mistake, first of all I'm in Europe and not in USA (your page say I'm in KANSAS, not fare from Wichita)! Your system is wrong. You mast know if someone use "deep web" then very difficult to find the starting point for the real IP address! If you do not know you unnecessary organize this page. In any case, I check the sender if I do not know or suspect. That's how I got to the side of you. My down message you can see full header that letter I paste you! All the best. Agi
156
157(July 31, 2015) PhI (mod) said:
158Hello.
159
160My FW. list:
161
162fresh dos attack - balack seo engine ips..
163if your site increases - (SEO) expect these:
16493.104.213.28 # F.W. 1.6: (DOS) DOS -Attack 93.104.213.28 (DE/Germany/vmd4661.contabo.host):Date - Tue Jul 21 20:26:20 2015
16593.104.213.28 # F.W. 1.6: (DOS) DOS -Attack 93.104.213.28 (DE/Germany/vmd4661.contabo.host):Date - Tue Jul 21 20:26:26 2015
166174.1.128.54 # F.W. 1.6: (DOS) DOS -Attack 174.1.128.54 (CA/Canada/S0106001c1019bff8.vf.shawcable.net):Date - Tue Jul 21 22:08:35 2015
167174.1.128.54 # F.W. 1.6: (DOS) DOS -Attack 174.1.128.54 (CA/Canada/S0106001c1019bff8.vf.shawcable.net):Date - Tue Jul 21 22:08:41 2015
168198.211.30.100 # F.W. 1.6: (pop3d) Failed POP3 login from 198.211.30.100 (US/United States/100-30-211-198-dedicated.multacom.com): Date - Wed Jul 22 04:10:56 2015
16998.193.198.164 # F.W. 1.6: (DOS) DOS -Attack 98.193.198.164 (US/United States/c-98-193-198-164.hsd1.tn.comcast.net):Date - Wed Jul 22 05:14:40 2015
170178.208.77.51 # F.W. 1.6: (DOS) DOS -Attack 178.208.77.51 (RU/Russian Federation/v26079.vps.mcdir.ru):Date - Wed Jul 22 07:55:14 2015
171178.208.77.51 # F.W. 1.6: (DOS) DOS -Attack 178.208.77.51 (RU/Russian Federation/v26079.vps.mcdir.ru):Date - Wed Jul 22 07:55:19 2015
172208.172.112.14 # F.W. 1.6: (DOS) DOS -Attack 208.172.112.14 (US/United States/-):Date - Thu Jul 23 05:39:51 2015
1735.189.128.248 # F.W. 1.6: (DOS) DOS -Attack 5.189.128.248 (DE/Germany/-):Date - Thu Jul 23 10:41:30 2015
1745.189.128.248 # F.W. 1.6: (DOS) DOS -Attack 5.189.128.248 (DE/Germany/-):Date - Thu Jul 23 10:41:35 2015
17580.64.173.162 # F.W. 1.6: (DOS) DOS -Attack 80.64.173.162 (RU/Russian Federation/80.64.173.162.sta.211.ru):Date - Thu Jul 23 12:33:25 2015
176114.45.153.209 # F.W. 1.6: (DOS) DOS -Attack 114.45.153.209 (TW/Taiwan/114-45-153-209.dynamic.hinet.net):Date - Thu Jul 23 13:08:17 2015
17746.4.89.214 # F.W. 1.6: (DOS) DOS -Attack 46.4.89.214 (DE/Germany/static.214.89.4.46.clients.your-server.de):Date - Thu Jul 23 14:36:06 2015
178204.101.161.160 # F.W. 1.6: (DOS) DOS -Attack 204.101.161.160 (CA/Canada/-):Date - Thu Jul 23 15:04:18 2015
17993.104.209.2 # F.W. 1.6: (DOS) DOS -Attack 93.104.209.2 (DE/Germany/vmd7552.contabo.host):Date - Fri Jul 24 00:23:50 2015
1801.161.191.20 # F.W. 1.6: (DOS) DOS -Attack 1.161.191.20 (TW/Taiwan/1-161-191-20.dynamic.hinet.net):Date - Fri Jul 24 09:47:30 2015
181178.168.117.97 # F.W. 1.6: (DOS) DOS -Attack 178.168.117.97 (MD/Moldova, Republic of/178-168-117-97.nordlinks.net):Date - Fri Jul 24 15:07:08 2015
1821.164.52.226 # F.W. 1.6: (DOS) DOS -Attack 1.164.52.226 (TW/Taiwan/1-164-52-226.dynamic.hinet.net):Date - Sat Jul 25 02:25:58 2015
183212.224.0.0/16 # F.W. 1.6: (NETBLOCK) 212.224.0.0/16 Date - Sat Jul 25 08:54:13 2015
18486.105.1.105 # F.W. 1.6: (pop3d) Failed POP3 login from 86.105.1.105 (IT/Italy/-): Date - Sat Jul 25 17:50:26 2015
185206.99.94.230 # F.W. 1.6: (DOS) DOS -Attack 206.99.94.230 (US/United States/-):Date - Sun Jul 26 10:12:19 2015
18671.108.245.211 # F.W. 1.6: (DOS) DOS -Attack 71.108.245.211 (US/United States/pool-71-108-245-211.lsanca.dsl-w.verizon.net):Date - Sun Jul 26 14:41:36 2015
18771.108.245.211 # Manually denied: 71.108.245.211 (US/United States/pool-71-108-245-211.lsanca.dsl-w.verizon.net) - Sun Jul 26 14:51:50 2015
188109.81.181.238 # F.W. 1.6: (pop3d) Failed POP3 login from 109.81.181.238 (CZ/Czech Republic/238.181.broadband18.iol.cz): Date - Sun Jul 26 15:39:50 2015
189180.249.251.53 # F.W. 1.6: (DOS) DOS -Attack 180.249.251.53 (ID/Indonesia/-):Date - Mon Jul 27 09:47:50 2015
19037.236.140.177 # F.W. 1.6: (DOS) DOS -Attack 37.236.140.177 (IQ/Iraq/-):Date - Mon Jul 27 16:00:07 2015
191178.207.170.80 # F.W. 1.6: (DOS) DOS -Attack 178.207.170.80 (RU/Russian Federation/-):Date - Mon Jul 27 20:33:57 2015
19227.153.248.75 # F.W. 1.6: (DOS) DOS -Attack 27.153.248.75 (CN/China/75.248.153.27.broad.pt.fj.dynamic.163data.com.cn):Date - Tue Jul 28 01:37:16 2015
19358.23.232.52 # F.W. 1.6: (DOS) DOS -Attack 58.23.232.52 (CN/China/-):Date - Tue Jul 28 01:37:18 2015
194212.83.148.114 # F.W. 1.6: (DOS) DOS -Attack 212.83.148.114 (FR/France/ttjitu.needlelead.com):Date
195
196(July 31, 2015) Freddie (mod) said:
197Our windows server slowed to a crawl for no apparent reason. Reviewing the logs, we found that the machine was being hit with automated attempts to log in via remote desktop from IP 121.12.126.60. The attempts all failed but they were being performed so rapidly (one every couple of seconds) that the machine was almost unresponsive. After setting the firewall to block all traffic from that block of IPs, performance returned to normal. Something should be done about these people.
198
199(July 31, 2015) Ghanesh MV (mod) said:
200137.116.140.13 is my IP. Someone hacked my server and I'm not finding a way to rectify my server. Can someone help cleanup my website?
201
202(July 31, 2015) Anonymous (mod) said:
203i am a noob. this ip has been trying to get into my cp for the past 24h. using a fake skype.exe
204
205(July 31, 2015) Anonymous (mod) said:
206Name of this PC in Romania = BOGDAN-PC
207Transmit by this msg = voicemessage@yourvm.co.uk
208
209(July 31, 2015) alex (mod) said:
210Bruteforcing SSH.
211
212(July 31, 2015) Voluntaryist (mod) said:
213These comments LOOK specific to the IP address you entered (if any) but they ARE NOT. Try a different IP address and you'll see that the same list of comments shows up.
214
215(July 31, 2015) Ben (mod) said:
216I need Help here is hacker making an "unstoppable" script that will destroy my systems and my friends systems we need all hacking power we can get to make a script better then theirs contact me, Skype > Superbenji2002
217
218(July 31, 2015) Mister Ukuli (mod) said:
219Bruteforcing SSH all the time. Fry him!
220
221(July 31, 2015) Anonymous (mod) said:
222@RuaBangChu,
223
224(July 31, 2015) RuaBangChu (mod) said:
225cho to sin cai ma core
226
227(July 31, 2015) Anon (mod) said:
228I have an email that this IP address tried to logon 5 times to a forum I belong to but did not input the correct password. IPm address is 96.44.189.101
229
230(July 31, 2015) Jefferson (mod) said:
231My router is hacked as well as my devices, I need some way to get rid of it and finally work in peace
232
233(July 31, 2015) John Smith (mod) said:
234Jul 18 00:21:13 sshd[18844]: input_userauth_request: invalid user mcserver [preauth]
235Jul 18 00:21:13 sshd[18844]: Received disconnect from 195.154.9.92: 11: Bye Bye [preauth]
2362015-07-18 00:21:15,431 fail2ban.actions: WARNING [ssh] Ban 195.154.9.92
237
238(July 31, 2015) 178.197.235.174 (mod) said:
239178.197.235.174 is one of Switzerland (not Germany) strongest IP.
240U will fail... or Bluewin will change there IP and the Kids using Bluewin will attack from the new Bluewin-IP...
241
242(July 31, 2015) Bob (mod) said:
243This site is spamming me spoofing my name as the sender. The email account used does not exist at Gmail.com.
244
245(July 31, 2015) Ipcop (mod) said:
246From 125.163.172.55 - 72 packets
247To 93.xxx.xxx.xxx - 66 packets
248Service: 49405 (tcp/49405) (NEW not SYN?,ppp0,none) - 3 packets
249Service: 49483 (tcp/49483) (NEW not SYN?,ppp0,none) - 3 packets
250Service: 49670 (tcp/49670) (NEW not SYN?,ppp0,none) - 3 packets
251Service: 49914 (tcp/49914) (NEW not SYN?,ppp0,none) - 3 packets
252Service: 63198 (tcp/63198) (NEW not SYN?,ppp0,none) - 3 packets
253Service: 63309 (tcp/63309) (NEW not SYN?,ppp0,none) - 3 packets
254Service: 63473 (tcp/63473) (NEW not SYN?,ppp0,none) - 2 packets
255Service: 63588 (tcp/63588) (NEW not SYN?,ppp0,none) - 3 packets
256Service: 63700 (tcp/63700) (NEW not SYN?,ppp0,none) - 3 packets
257Service: 63939 (tcp/63939) (NEW not SYN?,ppp0,none) - 3 packets
258Service: 64030 (tcp/64030) (NEW not SYN?,ppp0,none) - 3 packets
259Service: 64235 (tcp/64235) (NEW not SYN?,ppp0,none) - 2 packets
260Service: 64339 (tcp/64339) (NEW not SYN?,ppp0,none) - 3 packets
261Service: 64581 (tcp/64581) (NEW not SYN?,ppp0,none) - 3 packets
262Service: 64665 (tcp/64665) (NEW not SYN?,ppp0,none) - 3 packets
263Service: 64735 (tcp/64735) (NEW not SYN?,ppp0,none) - 3 packets
264Service: 64854 (tcp/64854) (NEW not SYN?,ppp0,none) - 3 packets
265Service: 64871 (tcp/64871) (NEW not SYN?,ppp0,none) - 2 packets
266Service: 65083 (tcp/65083) (NEW not SYN?,ppp0,none) - 3 packets
267Service: 65204 (tcp/65204) (NEW not SYN?,ppp0,none) - 3 packets
268Service: 65281 (tcp/65281) (NEW not SYN?,ppp0,none) - 3 packets
269Service: 65354 (tcp/65354) (NEW not SYN?,ppp0,none) - 3 packets
270Service: 65496 (tcp/65496) (NEW not SYN?,ppp0,none) - 3 packets
271To 192.168.xxx.124 - 6 packets
272Service: 26846 (tcp/26846) (NEW not SYN?,ppp0,eth0) - 6 packets
273
274(July 31, 2015) Hostingprovider (mod) said:
275Attack on wordpress site. Reported to hoster.
276
277(July 31, 2015) Skipper Blue (mod) said:
278attacked my ftp