[nsp-sec] Attack on www.betinternet.com TCP/80

Jose Nazario jose at arbor.net
Sun Aug 30 09:08:51 EDT 2009


oops, there's also been a machbot controller in there too:

Timestamp	2009-08-28 23:02:50
C&C IP		91.212.220.242
C&C Hostname	tatoshko.biz
C&C Port	80
C&C ASN		49365
C&C CC		RU
C&C Channel	http:machbot
Command URL
Command Given	rgttp www.betinternet.com
Target IP	83.218.15.254
Target Hostname	www.betinternet.com
Target ASN	15766
Target CC	UK


hope this helps.

-- 
-------------------------------------------------------------
jose nazario, ph.d.     	<jose at arbor.net>
manager of security research 	arbor networks
v: (734) 821 1427 	      	http://asert.arbor.net/



More information about the nsp-security mailing list