To report a botnet PRIVATELY please email: [EMAIL PROTECTED]
----------
Hi folks,

myhomepage1959.PassingG.as Port 7000 with a serverpass of Sm0KingDoPe hosts a 
nice botnet on channel #UltrA# with a Pass of el337n3ss. The md5 of the binary 
I and others catched is 2ddac84edf20852674fd429941923651, and according to 
Norman it's active since 16.05 at least.

The bots are named [UltrA-2005]-RANDOMNUMBER and spread via DCOM exploits and 
tftp to transport the bot.

Is there more info about this around already? Then I'd drop it to avoid 
redundant work ;)

Cheers,

Joerg
_______________________________________________
To report a botnet PRIVATELY please email: [EMAIL PROTECTED]
All list and server information are public and available to law enforcement 
upon request.
http://www.whitestar.linuxbox.org/mailman/listinfo/botnets

Reply via email to