What security tool made this log output?

w1z4rd

Karmic Sangoma
Joined
Jan 17, 2005
Messages
49,747
Code:
/home/babaspor/public_html/Shaun$.php: PHP.Mailer-7 FOUND
/home/babaspor/public_html/products/index2.php: PHP.Mailer-7 FOUND
/home/starling/.htaccess: Worm.Redirect-1 FOUND
/home/starling/public_html/.htaccess: Worm.Redirect-1 FOUND
/home/ergotek4/mail/ergotekint.com/info/cur/1285614233.H267934P26118.server3.redsolution.org,S=32767:2,S: Heuristic.Trojan.SusPacked.TMS FOUND
/home/fazeespo/mail/fazeesports.com/info/new/1279045443.H141712P26146.server3.redsolution.org,S=108148: Heuristic.Trojan.SusPacked.TMS FOUND
/home/fazeespo/mail/fazeesports.com/info/new/1279018785.H826729P7790.server3.redsolution.org,S=108055: Heuristic.Trojan.SusPacked.TMS FOUND
/home/luckyind/mail/luckym-ind.com/info/new/1285163150.H956404P5528.server3.redsolution.org,S=34498: Heuristic.Trojan.SusPacked.TMS FOUND
/home/luckyind/mail/luckym-ind.com/info/new/1285165585.H698915P17478.server3.redsolution.org,S=34053: Heuristic.Trojan.SusPacked.TMS FOUND
/home/luckyind/mail/luckym-ind.com/info/new/1285145190.H374843P23589.server3.redsolution.org,S=34371: Heuristic.Trojan.SusPacked.TMS FOUND
/home/luckyind/mail/luckym-ind.com/info/new/1285155590.H891437P18226.server3.redsolution.org,S=34425: Heuristic.Trojan.SusPacked.TMS FOUND
/home/luckyind/mail/luckym-ind.com/info/new/1285159030.H498390P29774.server3.redsolution.org,S=34538: Heuristic.Trojan.SusPacked.TMS FOUND
/home/luckyind/mail/luckym-ind.com/info/new/1285160885.H604270P5716.server3.redsolution.org,S=34386: Heuristic.Trojan.SusPacked.TMS FOUND
/home/luckyind/mail/luckym-ind.com/info/new/1285692914.H156763P13637.server3.redsolution.org,S=73429: Heuristic.Trojan.SusPacked.TMS FOUND
/home/luckyind/mail/luckym-ind.com/info/new/1279040892.H109165P19662.server3.redsolution.org,S=108151: Heuristic.Trojan.SusPacked.TMS FOUND
/home/luckyind/mail/luckym-ind.com/info/new/1279028081.H119242P10225.server3.redsolution.org,S=108072: Heuristic.Trojan.SusPacked.TMS FOUND
/home/luckyind/mail/luckym-ind.com/info/new/1285084517.H74981P13958.server3.redsolution.org,S=33984: Heuristic.Trojan.SusPacked.TMS FOUND
/home/luckyind/mail/luckym-ind.com/info/new/1285118742.H249768P13863.server3.redsolution.org,S=34621: Heuristic.Trojan.SusPacked.TMS FOUND
/home/luckyind/mail/luckym-ind.com/info/new/1282601839.H482738P29875.server3.redsolution.org,S=56901: Heuristic.Trojan.SusPacked.TMS FOUND
/home/luckyind/mail/luckym-ind.com/info/new/1285057831.H662019P25839.server3.redsolution.org,S=32836: Heuristic.Trojan.SusPacked.TMS FOUND
/home/luckyind/mail/luckym-i
/home/crownglo/etc/crowngloves.com/info/boxtrapper/queue/N6cEa7lvmiKum4cDKhPZEe1KIrxSUd_l.msg: Trojan.JS-67 FOUND
/home/crownglo/etc/crowngloves.com/info/boxtrapper/queue/dn0EBC60so1qdyDTwrp6ZSowkbyR0SHG.msg: Email.Trojan-201 FOUND
/home/crownglo/etc/crowngloves.com/info/boxtrapper/queue/YdD8IbEwi9RzG3eZ_BjKij816l698cRR.msg: Trojan.JS-67 FOUND
/home/crownglo/etc/crowngloves.com/info/boxtrapper/queue/tJrJjIuoEt49zrEhpGTzs1OauM9OfNT8.msg: Trojan.JS-67 FOUND
/home/crownglo/etc/crowngloves.com/info/boxtrapper/queue/U03bdhZjVHE98v6Mmc4WbBVFWqeKTGwo.msg: Trojan.JS-67 FOUND
/home/crownglo/etc/crowngloves.com/info/boxtrapper/queue/PgPdwzsplsOgmws_PWMPfEHmnFQlOcPR.msg: Email.Trojan-201 FOUND
/home/crownglo/etc/crowngloves.com/info/boxtrapper/queue/_mqxIFk1QgJ2GXA2r9UlAjrzYMgAsmux.msg: Trojan.JS-67 FOUND
/home/crownglo/etc/crowngloves.com/info/boxtrapper/queue/Nrqk_As5auEZTMCLu2UsglkfdzjJIHto.msg: Trojan.JS-67 FOUND
/home/crownglo/etc/crowngloves.com/info/boxtrapper/queue/rbs8E7t8F4Y71LVFso3J6lvgiyGrz6mP.msg: Trojan.JS-67 FOUND
/home/crownglo/etc/crowngloves.com/info/boxtrapper/queue/Xf5iA7ICUYyCRoyGTAvYnD3CeoIKbsLP.msg: Trojan.JS-67 FOUND
/home/crownglo/etc/crowngloves.com/info/boxtrapper/queue/NJCsxz_gJXCm7J3vhWTlNTjfMLnq7lNF.msg: Trojan.JS-67 FOUND
/home/crownglo/etc/crowngloves.com/info/boxtrapper/queue/SNw1K4SFWreFs6rOXRXaRBs1hvDAvcku.msg: Trojan.JS-67 FOUND
/home/crownglo/etc/crowngloves.com/info/boxtrapper/queue/yWo1Uu0fWK5iM7CN8ipe398c4XGPRMJX.msg: Trojan.JS-67 FOUND
/home/crownglo/etc/crowngloves.com/info/boxtrapper/queue/z_G3CFXCoyJPCWh1f03WaoLzbNsld4LT.msg: Trojan.JS-67 FOUND
/home/crownglo/etc/crowngloves.com/info/boxtrapper/queue/SxOowtPtBnaXzfMz2NPrGvtf9DNtUCS6.msg: Trojan.JS-67 FOUND
/home/crownglo/etc/crowngloves.com/info/boxtrapper/queue/Gag6g1q_NLO1J2W32bb2ZbZXnmrD0D7G.msg: JS.Generic FOUND
/home/crownglo/etc/crowngloves.com/info/boxtrapper/queue/wwIXPyAL0GOBffTp40FPj7t7fnyuA2o0.msg: JS.Generic FOUND
/home/crownglo/etc/crowngloves.com/info/boxtrapper/queue/OIEXGELvKUAfth8uGE3hjS80h4jvxTbJ.msg: JS.Generic FOUND
/home/crownglo/etc/crowngloves.com/info/boxtrapper/queue/uNoY1c8DGXaLGG2pC01DX0D7R59qJJ2G.msg: JS.Generic FOUND
/home/crownglo/etc/crowngloves.com/info/boxtrapper/queue/KR53KpY9_wqaFrh4sWZqYoAOxNTvTwVW.msg: JS.Generic FOUND
/home/crownglo/etc/crowngloves.com/info/boxtrapper/queue/yHuvx50uHdYhj3o8rta0rNZqqHp9J7ZF.msg: JS.Generic FOUND
/home/crownglo/etc/crowngloves.com/info/boxtrapper/queue/C2lUExaQTUY8ZGLHDDZ1_TrdNwssdriG.msg: JS.Generic FOUND
/home/crownglo/etc/crowngloves.com/info/boxtrapper/queue/gLiGvb4YF0M3jW3YDyRUvC0G_Ls2yA08.msg: Heuristic.Trojan.SusPacked.TMS FOUND
/home/crownglo/etc/crowngloves.com/info/boxtrapper/queue/Nh_L7bBaCBi8JEabsJX1b8dqNJejCJ_w.msg: JS.Generic FOUND
/home/crownglo/etc/crowngloves.com/info/boxtrapper/queue/NmEWhkFwK6wDngs8MPixufK6jOlsbDmK.msg: Heuristic.Trojan.SusPacked.TMS FOUND
/home/crownglo/etc/crowngloves.com/info/boxtrapper/queue/nOo62b8rTN1TvaWBC8f4QoqQKQPQBKBM.msg: Heuristic.Trojan.SusPacked.TMS FOUND
/home/crownglo/etc/crowngloves.com/info/boxtrapper/queue/ymRwdb5hZODFrQteYBjdgjQkL3NAGtvk.msg: JS.Generic-1 FOUND
/home/crownglo/etc/crowngloves.com/info/boxtrapper/queue/Q1V2YoKZdTSNJQ5ACnqMwAkafLGm0qx3.msg: JS.Generic-1 FOUND
/home/crownglo/etc/crowngloves.com/info/boxtrapper/queue/fTuv_42VnMNa8j4hzXSAnXXKWTs7wbYD.msg: Heuristic.Trojan.SusPacked.TMS FOUND
/home/crownglo/etc/crowngloves.com/info/boxtrapper/queue/ZfRl31zcSGM4I8GVKKGFAyKiQUxocEl0.msg: JS.Generic-1 FOUND
/home/crownglo/etc/crowngloves.com/info/boxtrapper/queue/WmGa6ufr_Yjy5_DRy9fuxKLPTPVL1Em2.msg: JS.Generic-1 FOUND
/home/crownglo/etc/crowngloves.com/info/boxtrapper/queue/46MWd6QuiUpCp42gre60vf2Gl1v250Ic.msg: JS.Generic-1 FOUND
/home/crownglo/etc/crowngloves.com/info/boxtrapper/queue/oapstQ6J2ga4CnumSn1QrKi6Nz3xthcg.msg: Trojan.Downloader.Fraudload-31 FOUND
/home/crownglo/etc/crowngloves.com/info/boxtrapper/queue/upz1ktTzGVrJLXUJTUkZOkJPkn761Fts.msg: Trojan.Downloader.Fraudload-31 FOUND
/home/crownglo/etc/crowngloves.com/info/boxtrapper/queue/flJuXLXyiEVUnxfnECaT9U90vY52HLhZ.msg: Trojan.Downloader.Fraudload-31 FOUND
/home/crownglo/etc/crowngloves.com/info/boxtrapper/queue/yb_uW9Dg9Ior6uTO7Svga6zhiDS3OUWd.msg: Trojan.Downloader.Fraudload-31 FOUND
/home/crownglo/etc/crowngloves.com/info/boxtrapper/queue/SYBPFmusDygccE1Xp4SDrz9QFYm6xGxE.msg: Trojan.Downloader.Fraudload-31 FOUND
/home/crownglo/etc/crowngloves.com/info/boxtrapper/queue/qpIjqxATGmZxmwzAtRe6If5ZhvB_78wI.msg: Trojan.Downloader.Fraudload-31 FOUND
/home/crownglo/etc/crowngloves.com/info/boxtrapper/queue/n9tQQdQPdwj1gmO71tjHGgpj7WJwYq6d.msg: Heuristic.Trojan.SusPacked.TMS FOUND
/home/crownglo/etc/crowngloves.com/info/boxtrapper/queue/Eje02lM3w96MYzGlaCJmHTUHBvbdU4gA.msg: Heuristic.Trojan.SusPacked.TMS FOUND
/home/crownglo/etc/crowngloves.com/info/boxtrapper/queue/78ZbrQhkKDnrqeoFd2JO9UeQbbupMF2E.msg: Trojan.Agent-172734 FOUND
/home/crownglo/etc/crowngloves.com/info/boxtrapper/queue/BPGIoNyX8WKraoZLZnTv1xjRfWoZ15FW.msg: Trojan.Agent-172734 FOUND
/home/crownglo/etc/crowngloves.com/info/boxtrapper/queue/eznavAZvnRzGM5sFxI10QKnDlI5tQwoz.msg: Trojan.Agent-172734 FOUND
/home/crownglo/etc/crowngloves.com/info/boxtrapper/queue/CkjbQW2krEMRJw_4XLO9BzoSIx7hA0yl.msg: JS.Generic-2 FOUND
/home/crownglo/etc/crowngloves.com/info/boxtrapper/queue/cWNIJcZkC2YaDuCbUrJ2Uv9DgC0LSc0C.msg: JS.Generic-2 FOUND
/home/crownglo/etc/crowngloves.com/info/boxtrapper/queue/7lb1_6hVte2Kp73Qnn2L1NxJmcVCF1d0.msg: Trojan.Agent-172305 FOUND
/home/crownglo/etc/crowngloves.com/info/boxtrapper/queue/FXy6VDm52QHM4la5ezGF_2tjLSN1jE40.msg: JS.Generic FOUND
/home/crownglo/etc/crowngloves.com/info/boxtrapper/queue/ykz4XuqyP3Ue_0xOUpjgNatuj1l8Mnvt.msg: HTML.Iframe-46 FOUND
/home/crownglo/etc/crowngloves.com/info/boxtrapper/queue/2HRx3MWBA9MOIJNtsPio4_rBkJ4ydHNG.msg: HTML.Iframe-46 FOUND
/home/crownglo/mail/crowngloves.com/umer/cur/1285450522.H172531P5438.server3.redsolution.org,S=11769:2,: Trojan.Downloader.Fraudload-31 FOUND
/home/arkglove/public_html/shv.zip: Trojan.Rootkit-115 FOUND

It looks similar to rkthunter, but is different. When I run rootkit hunter I cant get this type of detail or search. Perhaps I am using it wrong or this is a completely different tool?

I notice our data center Alpha team uses this to search for exploited websites on servers. Anyone know what they are using?
 

w1z4rd

Karmic Sangoma
Joined
Jan 17, 2005
Messages
49,747
Do you know what to type to get that kind of out put?
 
Top