Re: Winupdate2date.exe: New worm variant?
Benjamin Koch <[email protected]>
| Newsgroups | gmane.comp.security.intrusions |
|---|---|
| Organization | Private |
| Message-ID | <[email protected]> |
Hello Anderson, I had a 'prereleased' version of this bot... Well, lets say 3 versions :) 1 script called installer.exe with a process called miroupdate.exe 1 called counterstrike_full_retail.exe with winupdate2.exe or something like that. New feature: IRC botnet :) And the last one xdcc-resume.exe with same process but improved. I saw the same thing aehm 2 month ago - same DNS and i think the same people... They allready know me and won't be happy when i stress them a second time :) First time i told them to shut down their botnet or i'll f*ck up their net... Only angry response. So i sent a message to the hoster of those little kids and 1 day later the network was down ;) If you want some nice screenshots - no problem ;) Let's stress them again >:D Can you please submit me this new version of SDBot? Symantec identifies now the old 'prereleased' versions since i sent the script to them... -- Best regards, Benjamin mailto:[email protected] _______________________________________________ Intrusions mailing list [email protected] http://www.dshield.org/mailman/listinfo/intrusions