To report a botnet PRIVATELY please email: [EMAIL PROTECTED] ---------- Hi folks,
myhomepage1959.PassingG.as Port 7000 with a serverpass of Sm0KingDoPe hosts a nice botnet on channel #UltrA# with a Pass of el337n3ss. The md5 of the binary I and others catched is 2ddac84edf20852674fd429941923651, and according to Norman it's active since 16.05 at least. The bots are named [UltrA-2005]-RANDOMNUMBER and spread via DCOM exploits and tftp to transport the bot. Is there more info about this around already? Then I'd drop it to avoid redundant work ;) Cheers, Joerg _______________________________________________ To report a botnet PRIVATELY please email: [EMAIL PROTECTED] All list and server information are public and available to law enforcement upon request. http://www.whitestar.linuxbox.org/mailman/listinfo/botnets
