Educause Security Discussion mailing list archives
Re: bestfriends.scr AIM virus
From: Peter Moody <peter () UCSC EDU>
Date: Sat, 22 Jan 2005 15:13:56 -0800
81.91.66.220 to be a Command and Control for a bot drone army.
Thought I sent this out yesterday but I just noticed it in my drafts folder. oh well. Yes, this ip address is a C&C for sure. Other's have noticed something on the order of 10k drones. Check those flows. A bit about this guy: * associated with this botnet is the malware distribution site http://www. adare.ca/ I haven't checked today, but yesterday you could find spybot.exe and bestfriends.scr there. * the malware, when run, does lots of little nasty things to your computer including but not limited to trying to connect to a C&C @ tx.abeautifultragedy.com (already shut). So, to summarize: * check flows to that ip (not just to 6667, I was told other ports were open as well like 6666, 8888, 8080) * check your dns logs for adare.ca and tx.abeautifultragedy.com. you're logging ns queries, right? Regards, -Peter -- Peter Moody <peter () ucsc edu> Information Security Administrator 831/459.5409 Information and Technology Services. UC, Santa Cruz http://security.ucsc.edu/pgp/peter.moody.pub AS5739 :wq ********** Participation and subscription information for this EDUCAUSE Discussion Group discussion list can be found at http://www.educause.edu/groups/.
Attachment:
_bin
Description:
Current thread:
- bestfriends.scr AIM virus Mark Wilson (Jan 21)
- <Possible follow-ups>
- Re: bestfriends.scr AIM virus Jason Brooks (Jan 21)
- Re: bestfriends.scr AIM virus Jason Brooks (Jan 21)
- Re: bestfriends.scr AIM virus Mark Wilson (Jan 21)
- Re: bestfriends.scr AIM virus Mark Wilson (Jan 21)
- Re: bestfriends.scr AIM virus Jason Richardson (Jan 21)
- Re: bestfriends.scr AIM virus Anderson, Brandie (Jan 21)
- Re: bestfriends.scr AIM virus Brock, Adam (Jan 22)
- Re: bestfriends.scr AIM virus RLVaughn (Jan 22)
- Re: bestfriends.scr AIM virus H. Morrow Long (Jan 22)
- Re: bestfriends.scr AIM virus Peter Moody (Jan 22)
- Re: bestfriends.scr AIM virus Cam Beasley, ISO (Jan 23)
- Re: bestfriends.scr AIM virus Cam Beasley, ISO (Jan 23)
- Re: bestfriends.scr AIM virus Jeff Kell (Jan 23)
- Re: bestfriends.scr AIM virus Jason Brooks (Jan 24)
- Re: bestfriends.scr AIM virus Jason Richardson (Jan 24)
- Re: bestfriends.scr AIM virus Mark Wilson (Jan 24)
- Re: bestfriends.scr AIM virus Jason Richardson (Jan 25)