[nsp-sec] Some more compromised ftp accounts

Thomas Hungenberg th.lab at hungenberg.net
Thu Sep 10 10:51:31 EDT 2009


Hi teams,

Roman from abuse.ch came across another list of stolen ftp credentials
on a server hosting a Zeus controller.

Please find attached a sanitized list (pw removed) of 391 ftp accounts
that were not included in the lists I recently posted here.

Format: ASN | IP | CC | ftp username | AS name

Top 10 country codes:

    139  US
     29  RU
     29  DE
     25  FR
     22  TR
     20  NL
     17  PL
     13  HU
     12  KR
     11  TH
     10  GB


     - Thomas

CERT-Bund Incident Response & Anti-Malware Team

-------------- next part --------------
An embedded and charset-unspecified text was scrubbed...
Name: ftp_asn_20090910.txt
URL: <https://puck.nether.net/mailman/private/nsp-security/attachments/20090910/6bfa8ab1/attachment-0001.txt>


More information about the nsp-security mailing list