[nsp-sec] dlink router worm or dlink compromise leads to infectedPCs?

Rob Thomas robt at cymru.com
Sat Mar 22 13:20:49 EDT 2008


Hi, team.

We've more insight to share.

The bot has a name - Hydra.

The author has been giving live demonstrations from his botnet to  
potential buyers.  It was hosted on 212.233.39.46 TCP 1337, but  
appears to have migrated.  Time to check those flows!

Thanks,
Rob.
-- 
Rob Thomas
Team Cymru
http://www.cymru.com/
ASSERT(coffee != empty);







More information about the nsp-security mailing list