strange root@(ip address) found
While doing the commands from this post, I found this within the output...
A whois returns this...
Code:
OrgName: Global Net Access, LLC
OrgID: GNAL-2
Address: 1100 White St SW
City: Atlanta
StateProv: GA
PostalCode: 30310
Country: US
ReferralServer: rwhois://rwhois.gnax.net:4321
NetRange: 72.9.224.0 - 72.9.255.255
CIDR: 72.9.224.0/19
OriginAS: AS3595, AS16626
NetName: GNAXNET
NetHandle: NET-72-9-224-0-1
Parent: NET-72-0-0-0-0
NetType: Direct Allocation
NameServer: DNS1.GNAX.NET
NameServer: DNS2.GNAX.NET
NameServer: NS1.GNAX.NET
NameServer: NS2.GNAX.NET
Comment: ADDRESSES WITHIN THIS BLOCK ARE NON-PORTABLE
Comment: ********************************************
Comment: Reassignment information for this block is
Comment: available at rwhois.gnax.net port 4321
Comment: ********************************************
RegDate: 2004-10-11
Updated: 2007-06-01
RAbuseHandle: ABUSE745-ARIN
RAbuseName: GNAX ABUSE
RAbusePhone: +1-404-230-9150
RAbuseEmail: abuse@gnax.net
RNOCHandle: ENGIN7-ARIN
RNOCName: GNAX ENGINEERING
RNOCPhone: +1-404-230-9150
RNOCEmail: engineering@gnax.net
RTechHandle: ENGIN7-ARIN
RTechName: GNAX ENGINEERING
RTechPhone: +1-404-230-9150
RTechEmail: engineering@gnax.net
OrgAbuseHandle: ABUSE745-ARIN
OrgAbuseName: GNAX ABUSE
OrgAbusePhone: +1-404-230-9150
OrgAbuseEmail: abuse@gnax.net
OrgNOCHandle: ENGIN7-ARIN
OrgNOCName: GNAX ENGINEERING
OrgNOCPhone: +1-404-230-9150
OrgNOCEmail: engineering@gnax.net
OrgTechHandle: ENGIN7-ARIN
OrgTechName: GNAX ENGINEERING
OrgTechPhone: +1-404-230-9150
OrgTechEmail: engineering@gnax.net
# ARIN WHOIS database, last updated 2007-09-11 19:10
# Enter ? for additional hints on searching ARIN's WHOIS database.
Found a referral to rwhois.gnax.net:4321.
%rwhois V-1.5:003fff:00 rwhois.gnax.net (by Network Solutions, Inc. V-1.5.7.3)
network:Class-Name:network
network:ID:108.72.9.224.0/19
network:Auth-Area:72.9.224.0/19
network:Network-Name:RackWan
network:IP-Network:72.9.233.128/26
network:Organization;I:RackWan
network:Tech-Contact;I:soporte@rackwan.com
network:Admin-Contact;I:sebastian@rackwan.com
network:Created:20041213
network:Updated:20060417
network:Updated-By:engineering@gnax.net
I ran rkhunter and it didn't return anything out of the ordinary. When I checked my router, all ports are closed and nmap revealed that only port 80 was open.
I ssh'd root@72.9.233.132 and it asked for a password. I have no idea who this is. Why would this be on my Ubuntu box as a command? Any ideas about this? Any thoughts or help appreciated.