[nsp-sec] compromised websites (ZeuS drive-by downloads)

Dirk Stander dst+nsp-sec at glaskugel.org
Mon Apr 27 12:13:25 EDT 2009


.: Dirk Stander (Mon, Apr 27, 2009 at 06:02:07PM +0200)
> Please find attached a list of ~10.000 compromised websites that showed up in the Referers.

ACK 8560 15418

I guess the FTP-credentials of those users are `in the wild',
some peeking into the FTP logs revealed frequent connections from
213.155.10.176 (at for example 20/Apr/2009:09:00:00 UTC).

    regards, Dirk Stander (1&1) :.



More information about the nsp-security mailing list