[nsp-sec] Attack on www.betinternet.com TCP/80
Jose Nazario
jose at arbor.net
Sun Aug 30 09:08:51 EDT 2009
oops, there's also been a machbot controller in there too:
Timestamp 2009-08-28 23:02:50
C&C IP 91.212.220.242
C&C Hostname tatoshko.biz
C&C Port 80
C&C ASN 49365
C&C CC RU
C&C Channel http:machbot
Command URL
Command Given rgttp www.betinternet.com
Target IP 83.218.15.254
Target Hostname www.betinternet.com
Target ASN 15766
Target CC UK
hope this helps.
--
-------------------------------------------------------------
jose nazario, ph.d. <jose at arbor.net>
manager of security research arbor networks
v: (734) 821 1427 http://asert.arbor.net/
More information about the nsp-security
mailing list