<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>onHacks &#187; Nepenthes</title>
	<atom:link href="http://onhacks.org/lang/en/tag/nepenthes/feed/" rel="self" type="application/rss+xml" />
	<link>http://onhacks.org</link>
	<description>On Hacking Across Boundaries</description>
	<lastBuildDate>Wed, 02 Jun 2010 05:48:30 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>Who is hacking me? ~A Glance into The Log~</title>
		<link>http://onhacks.org/lang/en/2009/07/15/who-is-hacking-me-a-glance-into-the-log</link>
		<comments>http://onhacks.org/lang/en/2009/07/15/who-is-hacking-me-a-glance-into-the-log#comments</comments>
		<pubDate>Wed, 15 Jul 2009 14:48:48 +0000</pubDate>
		<dc:creator>log0</dc:creator>
				<category><![CDATA[Honeypot]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Nepenthes]]></category>

		<guid isPermaLink="false">http://onhacks.org/?p=408</guid>
		<description><![CDATA[Nepenthes has been collecting data these few days, and I&#8217;d like to share some of the rough data now. Since it is just a single server, do not generalize it over the banks&#8217;, corporates&#8217;, significantly valued servers&#8217; situation, but this is what YOUR computer can see. Remember, I never exposed the honeypot, so ALL connections [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://onhacks.org/wp-content/uploads/2009/07/poohhoney.jpg"><img class="aligncenter size-full wp-image-423" title="poohhoney" src="http://onhacks.org/wp-content/uploads/2009/07/poohhoney.jpg" alt="poohhoney" width="350" height="350" /></a></p>
<p><span><br />
</span></p>
<p><span lang="en">Nepenthes has been collecting data these few days, and I&#8217;d like to share some of the rough data now. Since it is just a single server, do not generalize it over the banks&#8217;, corporates&#8217;, significantly valued servers&#8217; situation, but this is what YOUR computer can see. Remember, I never exposed the honeypot, so ALL connections are malicious.<br />
</span></p>


<pre>** Most Attacks Region **
[       Russian Federation] has 57 attacks on you.
[                   Taiwan] has 36 attacks on you.
[                   Brazil] has 32 attacks on you.
[                  Germany] has 21 attacks on you.
[            United States] has 20 attacks on you.
[                    Italy] has 16 attacks on you.
[                  Romania] has 15 attacks on you.
[           United Kingdom] has 14 attacks on you.
[       Korea, Republic of] has 13 attacks on you.
[                    India] has 11 attacks on you.
[                   Poland] has 10 attacks on you.
[              Philippines] has 10 attacks on you.
[                    Japan] has 10 attacks on you.
[                   Canada] has 9 attacks on you.
[                 Bulgaria] has 9 attacks on you.
[                  Hungary] has 8 attacks on you.
[                 Malaysia] has 8 attacks on you.
[                   France] has 6 attacks on you.
[                Argentina] has 6 attacks on you.
[                    China] has 6 attacks on you.</pre>
<p><span lang="en">This is 12 July 2009.<br />
</span></p>
<p><span lang="en">Apparently, Russian seems to be the largest supplier of zombies (much like Resident Evil!), being steadily the first ( I have a week of data ). Next, surprisingly (to me), comes Taiwan. The next one is easy, Brazil, as Microsoft SIR 5th report geolocation section has suggested. The next one is Germany, which is not like what I&#8217;ve seen on Microsoft SIR 5th. Afterall, this is just too weak to generalize, but you can check it out.</span></p>
<p><span lang="en">Remember, IP address has no national boundaries. </span></p>






<pre>** Most Visited Ports **
[  445] : 385
[  135] : 39
[  139] : 7
[   25] : 1</pre>
<p><span lang="en">Port 445 and Port 135 score highest. Very likely to be :</span></p>
<p><span lang="en">Port 445 &#8211; MS04-011 at http://www.microsoft.com/technet/security/bulletin/ms04-011.mspx</span></p>
<p><span lang="en">Port 135 -MS03-026, a.k.a W32 Blaster at http://www.microsoft.com/technet/security/bulletin/MS03-026.mspx</span></p>
<p><span lang="en">I am still in the middle of making sense of all the data, but the above is something you may glimpse from the mess.</span></p>
<p><span lang="en">(Yes, I think I should write an English version for the previous &#8220;Who is hacking me?&#8221; post.)</span></p>
<p><span lang="en">(7/16/2009 Updated title, and read <a href="http://onhacks.org/lang/en/2009/07/12/%e8%aa%b0%e5%9c%a8%e5%85%a5%e4%be%b5%e6%88%91%e7%9a%84%e7%b3%bb%e7%b5%b1" target="_blank">here</a> for the first story.)<br />
</span></p>










<p>===</p>
<p>Reference / 參考 / 参考 / さんこう / Referencia / Referenz / Справка  :</p>
<p><a href="http://www.microsoft.com/downloads/details.aspx?FamilyId=B2984562-47A2-48FF-890C-EDBEB8A0764C&#38;displaylang=en" target="_blank">Microsoft Security Intelligence Report volume 5</a><br />
<a href="http://en.wikipedia.org/wiki/Zombie_computer" target="_blank">Zombie Computer &#8211; Wikipedia</a><br />
<a href="http://zh.wikipedia.org/wiki/%E6%AE%AD%E5%B1%8D%E9%9B%BB%E8%85%A6" target="_blank">殭屍電腦 &#8211; 維基百科</a></p>
<div id="_mcePaste" style="overflow: hidden; position: absolute; left: -10000px; top: 214px; width: 1px; height: 1px;">
<pre>** Most Visited Ports **
[  445] : 385
[  135] : 39
[  139] : 7
[   25] : 1</pre>
</div>
]]></content:encoded>
			<wfw:commentRss>http://onhacks.org/lang/en/2009/07/15/who-is-hacking-me-a-glance-into-the-log/feed</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
	</channel>
</rss>
