Bots are looking for /muieblackcat on my web-server -> anyone know why?

Discussion in 'Anti-Virus' started by Virus Guy, May 25, 2012.

  1. Virus Guy

    Virus Guy Guest

    I noticed some strange log entries in the web-server at $Dayjob today,
    and instead of typing it up I'll just point to these:

    Others have seen it on their servers too.

    Whether or not these hits from (comprimised?) remote hosts (bots?)
    always start with a request for /muieblackcat - I don't know. After
    requesting it, they fire off several dozen requests (each being a
    different path) but always looking for setup.php.

    A search of our web-logs going back to 2007 shows that this activity
    started on May 17 / 2011, and there have been 43 such sequences (the
    most recent being just a few days ago).

    I'd have to run a different search to see if there's any similar
    activity where the remote machine requests setup.php without ever asking
    for /muieblackcat.

    All attempts resulted in a 404 error (file not found).

    What's strange is that you'd expect that any given host would not
    attempt to perform this penetration test twice, yet I see examples where
    the same host (same IP) ran the same sequence 2 and 4 times in the space
    of a few minutes to a few hours on the same day. An example of bad

    All told, this happened on 21 separate days - from 21 unique IP
    addresses (see sorted list below).

    See also:

    We don't have any php scripts running on our server, so this is no real
    issue for us. But I'm wondering what sort of exploit can be performed
    on server where these hits don't result in a 404 error. ?

    Would something or someone have planted or created /muieblackcat on a
    comprimized server at some point in the past - and hence these scans are
    looking for it?

    ------------------------- ( ( (GuardLayer.Com?)
    Virus Guy, May 25, 2012
  2. Virus Guy

    Whoever Guest

    They're looking for a PHPMyAdmin installation.
    Whoever, May 25, 2012
