[nsp-sec] Attack on www.betinternet.com TCP/80
Stephen Gill
gillsr at cymru.com
Sun Aug 30 16:56:10 EDT 2009
> Timestamp 2009-08-28 23:02:50
> C&C IP 91.212.220.242
> C&C Hostname tatoshko.biz
Has anyone contacted Neustar to nuke the .biz?
> C&C Port 80
> C&C ASN 49365
> C&C CC RU
> C&C Channel http:machbot
> Command URL
> Command Given rgttp www.betinternet.com
> Target IP 83.218.15.254
> Target Hostname www.betinternet.com
> Target ASN 15766
> Target CC UK
Added both C&C Ips to the ddos-rs for 7 days.
--
Stephen Gill, Chief Scientist, Team Cymru
http://www.cymru.com | +1 630 230 5423 | gillsr at cymru.com
More information about the nsp-security
mailing list