View Single Post
  #2 (permalink)  
Old 08-13-2006, 04:49 AM
Detector's Avatar
Detector Detector is offline
DodgeBoard Commissioner
 

Join Date: Oct 2005
Posts: 2,528
Casino Cash: $100217
Disagrees: 0
Disagreed With 1 Time in 1 Post
Agreed With Other Posts: 43
Members Agreed 56 Times in 19 Posts
Officially in the wild. No name as of yet but it looks to be building a Botnet. Heres what is known.

Filename: wgareg.exe, MD5: 9928a1e6601cf00d0b7826d13fb556f0 (this is the bot)

Incoming traffic on 445/TCP but there is a lot of background noise on that port.

Outgoing traffic to bniu.househot.com:18067 (Command and Control center, multiple IPs, IRC)

Outgoing traffic to port 445/TCP (scanning for victims and exploiting them)
__________________
The real treasure is in the hunt...
Reply With Quote