Author Topic: 195.88.190.42  (Read 15787 times)

0 Members and 1 Guest are viewing this topic.

February 26, 2010, 10:08:18 pm
Read 15787 times

eoin.miller

  • Sr. Member

  • Offline
  • ****

  • 179
Infected clients will post to this IP about every three minutes at this time with the hostname dikoool.com.

Code: [Select]
POST /g86f3cbi2.php HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 1.1.4322; .NET CLR 2.0.50727; .NET CLR 3.0.04506.30; .NET CLR 3.0.04506.648)
Host: dikoool.com
Content-Length: 25595
Connection: Keep-Alive
Cache-Control: no-cache

February 26, 2010, 10:16:50 pm
Reply #1

SysAdMini

  • Administrator
  • Hero Member

  • Offline
  • *****

  • 3335
Ruining the bad guy's day