· 11 years ago · Aug 10, 2015, 04:26 PM
1
2
3Fuck you Ukraine Scriptkiddy
4
5Ukraine tried to access non-existent page
6IP: 81.163.131.57 Hostname: 81.163.131.57
7Browser: IE version 7.0
8
9
10Berdyans'k, Ukraine
11IP: 37.115.4.71
12Hostname: 37-115-4-71-broadband.kyivstar.net
13
14
15Scanning 81.163.131.57 [1000 ports]
16Discovered open port 21/tcp on 81.163.131.57
17Discovered open port 4000/tcp on 81.163.131.57
18Completed Connect Scan 1.96s elapsed (1000 total ports)
19Nmap scan report for 81.163.131.57
20Host is up (0.073s latency).
21Not shown: 995 closed ports
22PORT STATE SERVICE
2321/tcp open ftp
24135/tcp filtered msrpc
25139/tcp filtered netbios-ssn
26445/tcp filtered microsoft-ds
274000/tcp open remoteanything
28
29reported at abuse@kyivstar.net
30http://pastebin.com/4w0DMrP6
31IE7.0 & remoteanything srsly?
32http://anti-hacker-alliance.com/index.php?details=81.163.131.57
33
34Start: Mon Aug 10 11:11:21 2015
35HOST: htapi Loss% Snt Last Avg Best Wrst StDev
361.|-- router2-nac.linode.com 0.0% 4 0.6 0.7 0.5 0.7 0.0
372.|-- 207.99.53.45 0.0% 4 0.3 0.3 0.3 0.5 0.0
383.|-- 0.e1-1.tbr2.tl9.nac.net 0.0% 4 1.7 1.6 1.4 1.8 0.0
394.|-- 0.e2-2.pr2.tl9.nac.net 0.0% 4 1.5 2.0 1.4 2.9 0.6
405.|-- nyiix.retn.net 0.0% 4 8.3 3.3 1.5 8.3 3.3
416.|-- ae2-10.RT.ATR.DOK.UA.retn.net 0.0% 4 151.0 150.1 147.1 151.4 1.9
427.|-- GW-DataInternet.retn.net 0.0% 4 152.0 150.7 147.9 152.0 1.8
438.|-- didan.ints.net 0.0% 4 143.4 142.3 140.2 143.5 1.4
449.|-- 81.163.131.57 25.0% 4 138.2 138.7 138.2 139.1 0.0
45
46
47Country: UA
48Registration Date: 2008-08-04
49Registrar: ripencc
50Owner: DIDAN-AS Didan Group LTD,UA
51
52
53Comments
54
55Thank you for commenting!
56
57Post another comment
58(within the last minute) open ports said:
59Nmap scan report for 81.163.131.57
60Host is up (0.073s latency).
61Not shown: 995 closed ports
62PORT STATE SERVICE
6321/tcp open ftp
64135/tcp filtered msrpc
65139/tcp filtered netbios-ssn
66445/tcp filtered microsoft-ds
674000/tcp open remoteanything
68flag like reply
69(1 minutes ago) someone said:
70also uses this ip:
71Ukraine tried to access non-existent page
72IP: 81.163.131.57 Hostname: 81.163.131.57
73Browser: IE version 7.0
74
75
76Berdyans'k, Ukraine
77IP: 37.115.4.71
78Hostname: 37-115-4-71-broadband.kyivstar.net
79
80(12 hours ago) Paul said:
81Attacked our photo gallery site. To the point that our Database pool ran out of connections. Even after the server started sending error messages, it continued to run for the next 5 minutes. Attempted to hit over 2000 pages on our website in under 5 minutes. Firewalled them. If it happends again I will firewall their entire network.
82
83(16 hours ago) cyberspace said:
84is a nice place to visit..but I am glad dont live here. I want to speak to you in person
85
86(4 days ago) lol said:
87lol
88
89(4 days ago) Anonymous said:
90112.198.77.138 attacks me also. what a fact.
91
92(5 days ago) Gatta Fabiano said:
93HI EVERYBODY I AM FABIANO A MUSICIAN FROM BRESCIA ITALY, AND I LIKE THE IDEA OF THIS SITE WHERE I CAN REPORT ANY E-MAIL ADDRESS OF SPAMMERS TO ADD AT A BLACK DATABASE ... GREAT I THINK, BUILD A BEST TOMORROW ONLINE TOGETHER .
94C I A O
95
96(5 days ago) Gabriela a Ji said:
97Nerozum�m - kohosi hled�te? Brepuse? IP?
98
99(6 days ago) PEDRO said:
100Estimados al bajar el softphone Zoiper e instalar en telefono, luego logear el servdor de telefonia IP , tomaron la IP y han intentado robar trafico telefonico al proveedor IP,,, Zoiper esta detras de esto................ tambien
101
102(Aug 3, 2015) U MAD BRO said:
103That 's an DYNAMIC IP, that Telefonica grants to their ADSL2 customers.
104
105(Aug 2, 2015) Luke said:
106Performed an ANY DNS query on my nameserver for commerce.gov.
107
108(July 31, 2015) sime said:
109Sime
110
111(July 31, 2015) sime said:
112Sime
113
114(July 31, 2015) Cyberghost (mod) said:
115You do realise that the ip 198.7.59.110 is from a public vpn named cyberghost with more than a million users you can't put us all in the same bag for 1 or 2 guys using that ip it's like if a guy in phoenix did a robbery and the police send the entire town to jail. Leave us alone.
116
117(July 31, 2015) CKB (mod) said:
118The assholes at IP ripped my small business off of 18,130.10! I couldn't find much on them except they own www.pinacsolutions.org and have a google phone number 231-660-1354 I am not a hacker or anything but admire the work of AHA, hopefully something can be done to prevent this from happening to others. The delivery address of the $18,130.10 was:
119
12050B 8th Street
121Taunton, MA. 02780
122
123Any info (or retaliation) is welcomed
124
125(July 31, 2015) ahmet (mod) said:
126h have an email .is that dangerous.same ip adress u mention.nformatons about :x-store-info:sbevkl2QZR7OXo7WID5ZcV65/pkDWk7T3Fc8OPySipF03G0nmHfsn9CHZLKvAtyh1As9uIyzPfYPIwz+GPKT03i67hBwbC6CwN+tfGFFreO623DmlztnLyR7qmonPMKgcQ1JOAkDstQ=
127Authentication-Results: hotmail.com; spf=pass (sender IP is 209.85.218.54; identity alignment result is pass and alignment mode is relaxed) smtp.mailfrom=gm.ben01@gmail.com; dkim=pass (identity alignment result is pass and alignment mode is relaxed) header.d=gmail.com; x-hmca=pass header.id=gm.ben01@gmail.com
128X-SID-PRA: gm.ben01@gmail.com
129X-AUTH-Result: PASS
130X-SID-Result: PASS
131
132(July 31, 2015) VICTOR (mod) said:
133Good afternoon
134
135IP 148.235.52.21 is blacklisted, unfortunately I am connected to this list my mail provider that is PRODIGY America Movil and for this reason I am being blocked by sending emails from the company where I work, and try to detach the IP and work in other yet remain bounced emails that I send to my suppliers and customers.
136Thanks
137
138(July 31, 2015) Elen (mod) said:
139Please, help.
140With this address for many years already sent porn and spam to the guest. Long did not dare to write to you, but patience when it has a limit. I'll clean up the guest after his visit, I want you to see it for yourself. You are my last hope. Administration is not able to deal with this user. I sincerely believe that you wrote is not in vain. Thank you.
141(addressed to my guest privet.ru/user/Lana_0100/guestbook as proof)
142
143(July 31, 2015) Victim (mod) said:
144I was configuring my old router and forget change the default password admin/admin. So in the next day i was browsing and can't login to many websites, after this I figure out something was happening. Then I check my dns server: 208.43.56.42 and 5.10.108.203 and it's not the dns servers of my ISP. love pishing scams kiddies, they are scanning probably the entire world searching for default user/passwords and pishing to get the passwords. BE AWAKE WITH THIS loveING KIDS!! (obs.: they can even make the entire pishing website that works without being detected haha)
145
146(July 31, 2015) Peruvian (mod) said:
147Thank you so much, that ip adress 104.236.205.233 tried to sign into my google account twice and i didnt even know why somebody from New York, US would want to sign into a peruvian account but i felt the need to search for it and discovered this. Thank you it really helped me. Now i now some stupid hoes are trying to hack me.
148
149(July 31, 2015) Midnight (mod) said:
150These folks at 192.185.2.112 tried to target me several times through email hacking (Yes, they tried and got my email account locked through failed attempts), then they went for my secondary FB and PayPal. Now they keep harassing me, keeps sending me emails. You'd think that these "hackers" would be more discreet.
151
152(July 31, 2015) linlin (mod) said:
153Hi, I have 85.25.43.94 connected to my router, those guys are a huge group with deep know how of loads of hardware. If I should name how many hardware they did poisoned including my iMac and iPhones you would think I'm a crazy peson. However their attack is usually led from Chinese IP addresses covering by SPAM attack but I do not believe they are from China. I have drawn their attention by my forum www.8a8f8.com, somebody asked them to hack and so I brought them home... I have many of their IP having done a small trap for them. I will add them to your web page database soon. My conclusion of those guys is they serve to some powerful organization like NAGRA TV is... however I have got no evidence... just my conclusion...
154
155(July 31, 2015) Agi (mod) said:
156I'm not a hacker or spammer, and also not scammer! I searching the IP "mistery shopper" letter, (I got this letter, from: Mystery Shopper , and when I replay his e-mail address is: my_shop01@aol.com) and I see your page say I'm in your black list in JustSpan, SORBS SPAM, SPAMSCANNIBAL! That is your mistake, first of all I'm in Europe and not in USA (your page say I'm in KANSAS, not fare from Wichita)! Your system is wrong. You mast know if someone use "deep web" then very difficult to find the starting point for the real IP address! If you do not know you unnecessary organize this page. In any case, I check the sender if I do not know or suspect. That's how I got to the side of you. My down message you can see full header that letter I paste you! All the best. Agi
157
158(July 31, 2015) PhI (mod) said:
159Hello.
160
161My FW. list:
162
163fresh dos attack - balack seo engine ips..
164if your site increases - (SEO) expect these:
16593.104.213.28 # F.W. 1.6: (DOS) DOS -Attack 93.104.213.28 (DE/Germany/vmd4661.contabo.host):Date - Tue Jul 21 20:26:20 2015
16693.104.213.28 # F.W. 1.6: (DOS) DOS -Attack 93.104.213.28 (DE/Germany/vmd4661.contabo.host):Date - Tue Jul 21 20:26:26 2015
167174.1.128.54 # F.W. 1.6: (DOS) DOS -Attack 174.1.128.54 (CA/Canada/S0106001c1019bff8.vf.shawcable.net):Date - Tue Jul 21 22:08:35 2015
168174.1.128.54 # F.W. 1.6: (DOS) DOS -Attack 174.1.128.54 (CA/Canada/S0106001c1019bff8.vf.shawcable.net):Date - Tue Jul 21 22:08:41 2015
169198.211.30.100 # F.W. 1.6: (pop3d) Failed POP3 login from 198.211.30.100 (US/United States/100-30-211-198-dedicated.multacom.com): Date - Wed Jul 22 04:10:56 2015
17098.193.198.164 # F.W. 1.6: (DOS) DOS -Attack 98.193.198.164 (US/United States/c-98-193-198-164.hsd1.tn.comcast.net):Date - Wed Jul 22 05:14:40 2015
171178.208.77.51 # F.W. 1.6: (DOS) DOS -Attack 178.208.77.51 (RU/Russian Federation/v26079.vps.mcdir.ru):Date - Wed Jul 22 07:55:14 2015
172178.208.77.51 # F.W. 1.6: (DOS) DOS -Attack 178.208.77.51 (RU/Russian Federation/v26079.vps.mcdir.ru):Date - Wed Jul 22 07:55:19 2015
173208.172.112.14 # F.W. 1.6: (DOS) DOS -Attack 208.172.112.14 (US/United States/-):Date - Thu Jul 23 05:39:51 2015
1745.189.128.248 # F.W. 1.6: (DOS) DOS -Attack 5.189.128.248 (DE/Germany/-):Date - Thu Jul 23 10:41:30 2015
1755.189.128.248 # F.W. 1.6: (DOS) DOS -Attack 5.189.128.248 (DE/Germany/-):Date - Thu Jul 23 10:41:35 2015
17680.64.173.162 # F.W. 1.6: (DOS) DOS -Attack 80.64.173.162 (RU/Russian Federation/80.64.173.162.sta.211.ru):Date - Thu Jul 23 12:33:25 2015
177114.45.153.209 # F.W. 1.6: (DOS) DOS -Attack 114.45.153.209 (TW/Taiwan/114-45-153-209.dynamic.hinet.net):Date - Thu Jul 23 13:08:17 2015
17846.4.89.214 # F.W. 1.6: (DOS) DOS -Attack 46.4.89.214 (DE/Germany/static.214.89.4.46.clients.your-server.de):Date - Thu Jul 23 14:36:06 2015
179204.101.161.160 # F.W. 1.6: (DOS) DOS -Attack 204.101.161.160 (CA/Canada/-):Date - Thu Jul 23 15:04:18 2015
18093.104.209.2 # F.W. 1.6: (DOS) DOS -Attack 93.104.209.2 (DE/Germany/vmd7552.contabo.host):Date - Fri Jul 24 00:23:50 2015
1811.161.191.20 # F.W. 1.6: (DOS) DOS -Attack 1.161.191.20 (TW/Taiwan/1-161-191-20.dynamic.hinet.net):Date - Fri Jul 24 09:47:30 2015
182178.168.117.97 # F.W. 1.6: (DOS) DOS -Attack 178.168.117.97 (MD/Moldova, Republic of/178-168-117-97.nordlinks.net):Date - Fri Jul 24 15:07:08 2015
1831.164.52.226 # F.W. 1.6: (DOS) DOS -Attack 1.164.52.226 (TW/Taiwan/1-164-52-226.dynamic.hinet.net):Date - Sat Jul 25 02:25:58 2015
184212.224.0.0/16 # F.W. 1.6: (NETBLOCK) 212.224.0.0/16 Date - Sat Jul 25 08:54:13 2015
18586.105.1.105 # F.W. 1.6: (pop3d) Failed POP3 login from 86.105.1.105 (IT/Italy/-): Date - Sat Jul 25 17:50:26 2015
186206.99.94.230 # F.W. 1.6: (DOS) DOS -Attack 206.99.94.230 (US/United States/-):Date - Sun Jul 26 10:12:19 2015
18771.108.245.211 # F.W. 1.6: (DOS) DOS -Attack 71.108.245.211 (US/United States/pool-71-108-245-211.lsanca.dsl-w.verizon.net):Date - Sun Jul 26 14:41:36 2015
18871.108.245.211 # Manually denied: 71.108.245.211 (US/United States/pool-71-108-245-211.lsanca.dsl-w.verizon.net) - Sun Jul 26 14:51:50 2015
189109.81.181.238 # F.W. 1.6: (pop3d) Failed POP3 login from 109.81.181.238 (CZ/Czech Republic/238.181.broadband18.iol.cz): Date - Sun Jul 26 15:39:50 2015
190180.249.251.53 # F.W. 1.6: (DOS) DOS -Attack 180.249.251.53 (ID/Indonesia/-):Date - Mon Jul 27 09:47:50 2015
19137.236.140.177 # F.W. 1.6: (DOS) DOS -Attack 37.236.140.177 (IQ/Iraq/-):Date - Mon Jul 27 16:00:07 2015
192178.207.170.80 # F.W. 1.6: (DOS) DOS -Attack 178.207.170.80 (RU/Russian Federation/-):Date - Mon Jul 27 20:33:57 2015
19327.153.248.75 # F.W. 1.6: (DOS) DOS -Attack 27.153.248.75 (CN/China/75.248.153.27.broad.pt.fj.dynamic.163data.com.cn):Date - Tue Jul 28 01:37:16 2015
19458.23.232.52 # F.W. 1.6: (DOS) DOS -Attack 58.23.232.52 (CN/China/-):Date - Tue Jul 28 01:37:18 2015
195212.83.148.114 # F.W. 1.6: (DOS) DOS -Attack 212.83.148.114 (FR/France/ttjitu.needlelead.com):Date
196
197(July 31, 2015) Freddie (mod) said:
198Our windows server slowed to a crawl for no apparent reason. Reviewing the logs, we found that the machine was being hit with automated attempts to log in via remote desktop from IP 121.12.126.60. The attempts all failed but they were being performed so rapidly (one every couple of seconds) that the machine was almost unresponsive. After setting the firewall to block all traffic from that block of IPs, performance returned to normal. Something should be done about these people.
199
200(July 31, 2015) Ghanesh MV (mod) said:
201137.116.140.13 is my IP. Someone hacked my server and I'm not finding a way to rectify my server. Can someone help cleanup my website?
202
203(July 31, 2015) Anonymous (mod) said:
204i am a noob. this ip has been trying to get into my cp for the past 24h. using a fake skype.exe
205
206(July 31, 2015) Anonymous (mod) said:
207Name of this PC in Romania = BOGDAN-PC
208Transmit by this msg = voicemessage@yourvm.co.uk
209
210(July 31, 2015) alex (mod) said:
211Bruteforcing SSH.
212
213(July 31, 2015) Voluntaryist (mod) said:
214These comments LOOK specific to the IP address you entered (if any) but they ARE NOT. Try a different IP address and you'll see that the same list of comments shows up.
215
216(July 31, 2015) Ben (mod) said:
217I need Help here is hacker making an "unstoppable" script that will destroy my systems and my friends systems we need all hacking power we can get to make a script better then theirs contact me, Skype > Superbenji2002
218
219(July 31, 2015) Mister Ukuli (mod) said:
220Bruteforcing SSH all the time. Fry him!
221
222(July 31, 2015) Anonymous (mod) said:
223@RuaBangChu,
224
225(July 31, 2015) RuaBangChu (mod) said:
226cho to sin cai ma core
227
228(July 31, 2015) Anon (mod) said:
229I have an email that this IP address tried to logon 5 times to a forum I belong to but did not input the correct password. IPm address is 96.44.189.101
230
231(July 31, 2015) Jefferson (mod) said:
232My router is hacked as well as my devices, I need some way to get rid of it and finally work in peace
233
234(July 31, 2015) John Smith (mod) said:
235Jul 18 00:21:13 sshd[18844]: input_userauth_request: invalid user mcserver [preauth]
236Jul 18 00:21:13 sshd[18844]: Received disconnect from 195.154.9.92: 11: Bye Bye [preauth]
2372015-07-18 00:21:15,431 fail2ban.actions: WARNING [ssh] Ban 195.154.9.92
238
239(July 31, 2015) 178.197.235.174 (mod) said:
240178.197.235.174 is one of Switzerland (not Germany) strongest IP.
241U will fail... or Bluewin will change there IP and the Kids using Bluewin will attack from the new Bluewin-IP...
242
243(July 31, 2015) Bob (mod) said:
244This site is spamming me spoofing my name as the sender. The email account used does not exist at Gmail.com.
245
246(July 31, 2015) Ipcop (mod) said:
247From 125.163.172.55 - 72 packets
248To 93.xxx.xxx.xxx - 66 packets
249Service: 49405 (tcp/49405) (NEW not SYN?,ppp0,none) - 3 packets
250Service: 49483 (tcp/49483) (NEW not SYN?,ppp0,none) - 3 packets
251Service: 49670 (tcp/49670) (NEW not SYN?,ppp0,none) - 3 packets
252Service: 49914 (tcp/49914) (NEW not SYN?,ppp0,none) - 3 packets
253Service: 63198 (tcp/63198) (NEW not SYN?,ppp0,none) - 3 packets
254Service: 63309 (tcp/63309) (NEW not SYN?,ppp0,none) - 3 packets
255Service: 63473 (tcp/63473) (NEW not SYN?,ppp0,none) - 2 packets
256Service: 63588 (tcp/63588) (NEW not SYN?,ppp0,none) - 3 packets
257Service: 63700 (tcp/63700) (NEW not SYN?,ppp0,none) - 3 packets
258Service: 63939 (tcp/63939) (NEW not SYN?,ppp0,none) - 3 packets
259Service: 64030 (tcp/64030) (NEW not SYN?,ppp0,none) - 3 packets
260Service: 64235 (tcp/64235) (NEW not SYN?,ppp0,none) - 2 packets
261Service: 64339 (tcp/64339) (NEW not SYN?,ppp0,none) - 3 packets
262Service: 64581 (tcp/64581) (NEW not SYN?,ppp0,none) - 3 packets
263Service: 64665 (tcp/64665) (NEW not SYN?,ppp0,none) - 3 packets
264Service: 64735 (tcp/64735) (NEW not SYN?,ppp0,none) - 3 packets
265Service: 64854 (tcp/64854) (NEW not SYN?,ppp0,none) - 3 packets
266Service: 64871 (tcp/64871) (NEW not SYN?,ppp0,none) - 2 packets
267Service: 65083 (tcp/65083) (NEW not SYN?,ppp0,none) - 3 packets
268Service: 65204 (tcp/65204) (NEW not SYN?,ppp0,none) - 3 packets
269Service: 65281 (tcp/65281) (NEW not SYN?,ppp0,none) - 3 packets
270Service: 65354 (tcp/65354) (NEW not SYN?,ppp0,none) - 3 packets
271Service: 65496 (tcp/65496) (NEW not SYN?,ppp0,none) - 3 packets
272To 192.168.xxx.124 - 6 packets
273Service: 26846 (tcp/26846) (NEW not SYN?,ppp0,eth0) - 6 packets
274
275(July 31, 2015) Hostingprovider (mod) said:
276Attack on wordpress site. Reported to hoster.
277
278(July 31, 2015) Skipper Blue (mod) said:
279attacked my ftp