什么是muieblackcat?


34

我最近在一个小型.NET MVC网站上安装了ELMAH,但我一直收到错误报告

System.Web.HttpException: A public action method 'muieblackcat' was not found on controller...

显然,这是尝试访问不存在的页面。但是为什么要尝试访问此页面?

这是一种攻击,还是仅是一种自动扫描程序以查看我是否已被感染?“ muieblackcat”到底是什么?为什么尝试访问此URL?


13
FYI Muie在罗马尼亚语中是指口交。
Elzo Valugi 2012年

Answers:


26

这只是一个寻孔脚本。发出的请求通常是以下请求,如果您的服务器以404错误回答了所有请求,则您无需担心。

111.221.1.140 - - [20/Nov/2013:10:15:56 +0000] "GET //xampp/phpmyadmin/scripts/setup.php HTTP/1.1" 404 1787 "-" "-"
111.221.1.140 - - [20/Nov/2013:10:15:55 +0000] "GET //websql/scripts/setup.php HTTP/1.1" 404 1787 "-" "-"
111.221.1.140 - - [20/Nov/2013:10:15:55 +0000] "GET //web/scripts/setup.php HTTP/1.1" 404 1787 "-" "-"
111.221.1.140 - - [20/Nov/2013:10:15:54 +0000] "GET //web/phpMyAdmin/scripts/setup.php HTTP/1.1" 404 1787 "-" "-"
111.221.1.140 - - [20/Nov/2013:10:15:53 +0000] "GET //typo3/phpmyadmin/scripts/setup.php HTTP/1.1" 404 1787 "-" "-"
111.221.1.140 - - [20/Nov/2013:10:15:51 +0000] "GET //scripts/setup.php HTTP/1.1" 404 1787 "-" "-"
111.221.1.140 - - [20/Nov/2013:10:15:50 +0000] "GET //pma/scripts/setup.php HTTP/1.1" 404 1787 "-" "-"
111.221.1.140 - - [20/Nov/2013:10:15:49 +0000] "GET //phpmyadmin2/scripts/setup.php HTTP/1.1" 404 1787 "-" "-"
111.221.1.140 - - [20/Nov/2013:10:15:48 +0000] "GET //phpmyadmin1/scripts/setup.php HTTP/1.1" 404 1787 "-" "-"
111.221.1.140 - - [20/Nov/2013:10:15:47 +0000] "GET //phpmyadmin/scripts/setup.php HTTP/1.1" 404 1787 "-" "-"
111.221.1.140 - - [20/Nov/2013:10:15:47 +0000] "GET //phpadmin/scripts/setup.php HTTP/1.1" 404 1787 "-" "-"
111.221.1.140 - - [20/Nov/2013:10:15:46 +0000] "GET //phpMyAdmin/scripts/setup.php HTTP/1.1" 404 1787 "-" "-"
111.221.1.140 - - [20/Nov/2013:10:15:45 +0000] "GET //phpMyAdmin-2/scripts/setup.php HTTP/1.1" 404 1787 "-" "-"
111.221.1.140 - - [20/Nov/2013:10:15:44 +0000] "GET //phpMyAdmin-2.5.5/index.php HTTP/1.1" 404 1787 "-" "-"
111.221.1.140 - - [20/Nov/2013:10:15:44 +0000] "GET //phpMyAdmin-2.5.5-pl1/index.php HTTP/1.1" 404 1787 "-" "-"
111.221.1.140 - - [20/Nov/2013:10:15:43 +0000] "GET //php-my-admin/scripts/setup.php HTTP/1.1" 404 1787 "-" "-"
111.221.1.140 - - [20/Nov/2013:10:15:42 +0000] "GET //mysqladmin/scripts/setup.php HTTP/1.1" 404 1787 "-" "-"
111.221.1.140 - - [20/Nov/2013:10:15:41 +0000] "GET //mysql/scripts/setup.php HTTP/1.1" 404 1787 "-" "-"
111.221.1.140 - - [20/Nov/2013:10:15:41 +0000] "GET //myadmin/scripts/setup.php HTTP/1.1" 404 1787 "-" "-"
111.221.1.140 - - [20/Nov/2013:10:15:40 +0000] "GET //dbadmin/scripts/setup.php HTTP/1.1" 404 1787 "-" "-"
111.221.1.140 - - [20/Nov/2013:10:15:39 +0000] "GET //db/scripts/setup.php HTTP/1.1" 404 1787 "-" "-"
111.221.1.140 - - [20/Nov/2013:10:15:38 +0000] "GET //admin/scripts/setup.php HTTP/1.1" 404 1787 "-" "-"
111.221.1.140 - - [20/Nov/2013:10:15:37 +0000] "GET //admin/pma/scripts/setup.php HTTP/1.1" 404 1787 "-" "-"
111.221.1.140 - - [20/Nov/2013:10:15:36 +0000] "GET //admin/phpmyadmin/scripts/setup.php HTTP/1.1" 404 1787 "-" "-"
111.221.1.140 - - [20/Nov/2013:10:15:35 +0000] "GET //MyAdmin/scripts/setup.php HTTP/1.1" 404 1787 "-" "-"
111.221.1.140 - - [20/Nov/2013:10:15:34 +0000] "GET /muieblackcat HTTP/1.1" 404 1787 "-" "-"

3
同意。我正在观看,并发送报告滥用emai。我的下一步是为我执行的csf脚本。我会在每次攻击时滥发垃圾邮件:D
m3nda 2015年

10

muieblackcat是脚本/机器人,据说是乌克兰起源的,试图利用PHP漏洞或配置错误。有关更多详细信息,请参见SUC027:Muieblackcat setup.php Web扫描程序/机器人

如果您不使用PHP且已停用mod_php,那么您是安全的。但是,请求/ muieblackcat可能意味着该机器人已经(可能已经成功)访问了您的站点。我建议您仔细检查您的配置和Web内容(如果可能,请全部删除并从受信任的源集中重新安装)。

另一方面,原始IP地址可能没有用。大多数攻击来自未受感染的Windows用户。


1
您为什么要重新安装?
克莱门特

1
因为很难确保在清理后绝对没有任何痕迹,而且只需要一个被忽略的php文件即可复活。擦除安装并从已知正常状态恢复将更加彻底。
Cornelius

4

我用另一种方式做:在同一个URI上将他们重定向到他们的IP

Somethig喜欢:

redirect301 = http://hackerIP/muieblackcat

我认为服务器发送301重定向比每次生成404页面都容易。


3

根据每日更新摘要6/24/2011Emerging Threat Pro博客),这是一台扫描程序,它正在寻找服务器中的某些漏洞。这绝对是您应该阻止的入侵者。查找您的访问日志,您应该获取其IP地址。


13
为什么要阻止它们?这是免费的笔试。使用攻击配置文件可以增强安全性。无论如何,他们将从现在起5分钟内拥有一个新IP。;)
By using our site, you acknowledge that you have read and understand our Cookie Policy and Privacy Policy.
Licensed under cc by-sa 3.0 with attribution required.