tetak
MIRT Team Lead Premium Member
 Joined: Jan 19, 2007 Posts: 5800
|
Posted: Sun Feb 24, 2008 3:26 am Post subject: [MIRT#6742] Backdoor on h1.ripway.com/postcard/ AS6939 |
|
|
Malware Alert Full Report: /Backdoor_malware6742.html Changed status to confirmed malware.IP Converted: 216.218.135.131
dword = 3638200195
hex1 = 0xd8da8783
hex2 = 0xd8.0xda.0x87.0x83
oct = 0330.0332.0207.0203
postcard.gif.exe at this location is malware known as Backdoor:IRC/Zapchast.AN (Microsoft)View CIDR AS6939 Report: http://www.cidr-report.org/cgi-bin/as-report?as=6939
"6939 | US | arin | 1996-06-28 | HURRICANE - Hurricane Electric"<br />
Extended information for AS6939:
State/Province: ca
Country: us
Responsible Domain: he.net
Abuse Email: abuse@he.net
| Quote: | | http://h1.ripway.com/postcard/postcard.gif.exe |
|
|