Infected clients will post to this IP about every three minutes at this time with the hostname dikoool.com.
POST /g86f3cbi2.php HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 1.1.4322; .NET CLR 2.0.50727; .NET CLR 3.0.04506.30; .NET CLR 3.0.04506.648)
Host: dikoool.com
Content-Length: 25595
Connection: Keep-Alive
Cache-Control: no-cache