« W32/agony.exe-1 Rootkit | Main | DC3 Challenge Rankings »

IRC bot action

Not really exciting, but I found it interesting anyway. I usually see traffic giving IRC bots on campus instructions to scan and exploit various vulnerabilities. Today I got one that was trying to pass on malware using, predictably, a MySpace picture request:


:sv-5.s3cr3t.net 332 [A07|USA|37152] ##vap1d## :.aim I was going to put this pic of us on
myspace. Is that ok with you? A H - REF="http://www.do not follow.dk/includes/picture-
ustogether.002.com">http://myspace/userphotos/us-together/picture-ustogether.002.jpg

:sv-5.s3cr3t.net 333 [A07|USA|37152] ##vap1d## H0AX 1168997693

I broke up the HTML so it would display properly. Not sure what the second command string does, the H0AX one.

About

This page contains a single entry from the blog posted on January 19, 2007 1:07 PM.

The previous post in this blog was W32/agony.exe-1 Rootkit.

The next post in this blog is DC3 Challenge Rankings.

Many more can be found on the main index page or by looking through the archives.

Creative Commons License
This weblog is licensed under a Creative Commons License.
Powered by
Movable Type 3.33