[nsp-sec] New (?) chinese ddos bot ...

Jose Nazario jose at arbor.net
Thu May 8 10:19:05 EDT 2008


possibly related C&Cs:

"hello" is "FILE:2|1024"
host: a857.3322.org		TCP port 1800
AS      | IP               | AS Name
4837    | 218.61.18.153    | CHINA169-BACKBONE CNCGROUP China169 Backbone
4837    | 123.11.194.218   | CHINA169-BACKBONE CNCGROUP China169 Backbone

(the first IP is from yesterday, the second is current). no response at 
present.


-------------------------------------------------------------
jose nazario, ph.d.     <jose at arbor.net>
security researcher, office of the CTO,  arbor networks
v: (734) 821 1427 	      http://asert.arbornetworks.com/



More information about the nsp-security mailing list