[nsp-sec] New (?) chinese ddos bot ...
Jose Nazario
jose at arbor.net
Thu May 8 10:19:05 EDT 2008
possibly related C&Cs:
"hello" is "FILE:2|1024"
host: a857.3322.org TCP port 1800
AS | IP | AS Name
4837 | 218.61.18.153 | CHINA169-BACKBONE CNCGROUP China169 Backbone
4837 | 123.11.194.218 | CHINA169-BACKBONE CNCGROUP China169 Backbone
(the first IP is from yesterday, the second is current). no response at
present.
-------------------------------------------------------------
jose nazario, ph.d. <jose at arbor.net>
security researcher, office of the CTO, arbor networks
v: (734) 821 1427 http://asert.arbornetworks.com/
More information about the nsp-security
mailing list