To report a botnet PRIVATELY please email: [EMAIL PROTECTED]
----------
Hello,
I believe they have modded the file for "fun.exe" as well as an null-padded
html loader file "fun.html". Also on the same site. However, if you try to
pull either exe file I get a redirect to a  "secsup.org" mirror file... you?


Jake


On 2/26/07, Elia Florio <[EMAIL PROTECTED]> wrote:

To report a botnet PRIVATELY please email: [EMAIL PROTECTED]
----------
Hi,
looks like a component dropped by the StormWorm/Peacomm (rsvp32_2.dll) is
infecting the web by injecting a malicious link to bulletin boards, forum,
blogs, etc.

Google for: "mailfreepostcards.com" to find some infected pages.
Infected users won't notice anything because the trojan acts as LSP and
injection
works at tcp/ip level.

EF


_______________________________________________
To report a botnet PRIVATELY please email: [EMAIL PROTECTED]
All list and server information are public and available to law
enforcement upon request.
http://www.whitestar.linuxbox.org/mailman/listinfo/botnets

_______________________________________________
To report a botnet PRIVATELY please email: [EMAIL PROTECTED]
All list and server information are public and available to law enforcement 
upon request.
http://www.whitestar.linuxbox.org/mailman/listinfo/botnets

Reply via email to