Re: Winupdate2date.exe: New worm variant?

Benjamin Koch <[email protected]>
Newsgroups gmane.comp.security.intrusions
Organization Private
Message-ID <[email protected]>
Hello Anderson,

I had a 'prereleased' version of this bot...
Well, lets say 3 versions :)

1 script called installer.exe with a process called miroupdate.exe
1 called counterstrike_full_retail.exe with winupdate2.exe or
something like that. New feature: IRC botnet :)
And the last one xdcc-resume.exe with same process but improved.

I saw the same thing aehm 2 month ago - same DNS and i think the same
people...
They allready know me and won't be happy when i stress them a second
time :)
First time i told them to shut down their botnet or i'll f*ck up their
net...
Only angry response. So i sent a message to the hoster of those little
kids and 1 day later the network was down ;)

If you want some nice screenshots - no problem ;)

Let's stress them again >:D

Can you please submit me this new version of SDBot?
Symantec identifies now the old 'prereleased' versions since i sent
the script to them...

-- 
Best regards,
 Benjamin                            mailto:[email protected]

_______________________________________________
Intrusions mailing list
[email protected]
http://www.dshield.org/mailman/listinfo/intrusions
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.