googlecode.com abused by Andromeda/Gamarue botnet

2014-07-07 Thread Moritz Kroll
Hi, I'm a security researcher at Avira and would like to inform you, that schw4rzz.googlecode.com is used for hosting plugins of the Andromeda botnet. At 2014-07-04 16:57:10 (CET) we found a command and control server returning download commands for them. The .mod files are plugin packs with a

Re: googlecode.com abused by Andromeda/Gamarue botnet

2014-07-07 Thread 'Mike Williams' via Project Hosting on Google Code
Thanks for the report On Fri, Jul 4, 2014 at 12:01 PM, Moritz Kroll wrote: > Hi, > > I'm a security researcher at Avira and would like to inform you, that > > schw4rzz.googlecode.com > > is used for hosting plugins of the Andromeda botnet. At 2014-07-04 > 16:57:10 (CET) we found a command and c