In the logs several not related to each other logically and geographically, servers are beginning to appear regularly is:
69.162.99.144 — - [25/Sep/2010:01:40:27 +0400] "GET /w00tw00t.at.ISC.SANS.DFind:) HTTP/1.1" 400 173 "-" "-" "-"
Probably some kind of skanlika, but something much this. Maybe someone knows more precisely what is it?