tetak
MIRT Team Lead Premium Member
 Joined: Jan 19, 2007 Posts: 5766
|
Posted: Thu Feb 21, 2008 3:50 am Post subject: [MIRT#8181] Backdoor on sleepbootmensen.nl AS25596 |
|
|
Malware Alert Full Report: /Backdoor_malware8181.html Changed status to confirmed malware.IP Converted: 84.245.22.39
dword = 1425348135
hex1 = 0x54f51627
hex2 = 0x54.0xf5.0x16.0x27
oct = 0124.0365.026.047
E-Greeting.exe at this location is malware known as IRC/BackDoor.Flood (AVG)View CIDR AS25596 Report: http://www.cidr-report.org/cgi-bin/as-report?as=25596
"25596 | NL | ripencc | 2003-01-24 | CAMBRIUM-AS CAMBRIUM BV."<br />
Extended information for AS25596:
State/Province:
Country: nl
Responsible Domain: cambrium.nl
Abuse Email: abuse@cambrium.nl
| Quote: | | http://sleepbootmensen.nl/icons/E-Greeting.exe |
|
|