[nsp-sec] Ping AS8001/AS36351 - possible botnet C&C

Rob Thomas robt at cymru.com
Thu Mar 13 11:34:54 EDT 2008


Hey, Zoe.

> 8001    | 64.21.181.87     | NET-ACCESS-CORP - Net Access Corporation

Unsurprising DNS RR:

       timestamp      |        dns_name        |      ip
--------------------- ------------------------ --------------
  2008-02-22 07:57:13 | lfiavsbyntu.dyndns.org | 64.21.181.87

Malware, natch:

       timestamp      |                   sha1                    
|               md5                |    dst_ip    | dst_port |  
protocol | size
--------------------- ------------------------------------------  
---------------------------------- -------------- ----------  
---------- ------
  2008-03-07 07:09:45 | f78da76ff8f75b20e2f6d09e1a39cb35aedaca5f |  
bd4d709723ae6a052e1d57144db6ac99 | 64.21.181.87 |      447 |       17  
|   82

> 36351   | 75.126.189.178   | SOFTLAYER - SoftLayer Technologies Inc.

We've got bupkes on this one, sorry.

Thanks,
Rob.
-- 
Rob Thomas
Team Cymru
http://www.cymru.com/
cmn_err(do_panic, "Out of coffee!");







More information about the nsp-security mailing list