tetak
MIRT Team Lead Premium Member
 Joined: Jan 19, 2007 Posts: 5224
|
Posted: Tue Mar 25, 2008 9:21 pm Post subject: [MIRT#9130] Backdoor on home-loans-4you2choose.info AS14383 |
|
|
Malware Alert Full Report: /Backdoor_malware9130.html Changed status to confirmed malware.IP Converted: 205.234.98.73
dword = 3454689865
hex1 = 0xcdea6249
hex2 = 0xcd.0xea.0x62.0x49
oct = 0315.0352.0142.0111
postcards.gif.exe at this location is malware known as Backdoor:IRC/Zapchast.AN (Microsoft).View CIDR AS14383 Report: http://www.cidr-report.org/cgi-bin/as-report?as=14383
"14383 | US | arin | 2005-05-12 | DTGL-AS - Defender Technologies Group, LLC"<br />
Extended information for AS14383:
State/Province: va
Country: us
Responsible Domain: defenderhosting.com
Abuse Email: abuse@defenderhosting.com
| Quote: | | http://host.home-loans-4you2choose.info/postcards.gif.exe |
|
|