Security Hero Rotating Header Image

Posts under ‘Botnet’

4088

4088 BAT/DelFiles.NAH, INF/Autorun (3), JS/Exploit.Pdfka.NCY (3), JS/TrojanDownloader.Agent.NQB (5), PDF/Exploit.Pidief.ASZ, PDF/Exploit.Pidief.AUU, PDF/Exploit.Pidief.OMT, REG/RunKeys.NAB, VBS/Runner.NAC, VBS/TrojanDownloader.Psyme.NFV (4), Win32/Adware.Coolezweb (3), Win32/Adware.PrivacyComponents (2), Win32/Agent.NGK (3), Win32/Agent.PKX (9), Win32/Agent.WPM, Win32/AutoRun.Autoit.AJ (4), Win32/AutoRun.FlyStudio.JI, Win32/Bifrose.NEL, Win32/Cimag.W, Win32/Delf.OIR, Win32/DNSChanger.NRZ (7), Win32/FakeInit.I (3), Win32/FlyStudio.NLO (2), Win32/FlyStudio.NLP (2), Win32/Hupigon.GVGO, Win32/Injector.OQ, Win32/Koobface.NBG, Win32/Koutodoor.Q (4), Win32/Merond.M (3), Win32/Nulprot, Win32/Olmarik.GW, Win32/Olmarik.HG (6), Win32/Olmarik.HW (2), Win32/Peerfrag.G, Win32/Poison.NAE, Win32/PowerReg, Win32/PSW.Agent.NLL [...]

4087

4087 BAT/StartPage.NAT (2), HTML/TrojanDownloader.IFrame, J2ME/TrojanSMS.Boxer.C (2), J2ME/TrojanSMS.Boxer.J (2), J2ME/TrojanSMS.Konov.E (2), PDF/Exploit.Pidief.OMS, Win32/Adware.BHO.NCX, Win32/Adware.JuSou.L (5), Win32/Adware.PersonalAntivirus (2), Win32/Adware.SpySnipe, Win32/Adware.SpywareProtect2009 (3), Win32/Adware.SystemSecurity (6), Win32/Agent.PFL, Win32/Agent.PKV, Win32/Agent.PKW, Win32/Autoit.NDM (3), Win32/AutoRun.Agent.NY, Win32/AutoRun.FakeAlert.BM, Win32/AutoRun.FakeAlert.M, Win32/AutoRun.FlyStudio.JH, Win32/AutoRun.Qhost.M, Win32/AutoRun.Qhost.P, Win32/Boberog.AA, Win32/FlyStudio.NLN, Win32/Hupigon.GTVV, Win32/IRCBot, Win32/Kryptik.PO, Win32/Obfuscated.NDF, Win32/Olmarik.GW, Win32/Olmarik.HG (2), Win32/PcClient, Win32/PcClient.NDP, Win32/PSW.OnLineGames.NTR (2), Win32/PSW.OnLineGames.OJT (2), Win32/PSW.QQPass.GYF, Win32/Qhost (2), Win32/Qhost.NJV, Win32/Rootkit.Agent.NLF, Win32/Rootkit.Agent.NLT, Win32/Rustock.NIH, Win32/Rustock.NIK, [...]

4076

4076 BAT/KillFiles.NBH (2), BAT/TrojanDownloader.Ftp.NBZ (2), INF/Autorun, PDF/Exploit.Pidief.OMN, VBS/KillFiles.C, Win32/Adware.Agent.NMS (4), Win32/Adware.Antivirus2008, Win32/Adware.Antivirus2009, Win32/Adware.InternetAntivirus (4), Win32/Adware.PersonalAntivirus, Win32/Adware.PrivacyComponents, Win32/Adware.SystemSecurity, Win32/Adware.Virtumonde.NEK, Win32/Adware.VirusDoctor, Win32/Agent.NYC (2), Win32/Agent.PKG (2), Win32/Agent.PKH (2), Win32/Agent.PKI (2), Win32/Agent.WPI, Win32/AntiAV.AZQ (2), Win32/AntiAV.NAH (2), Win32/AutoRun.IRCBot.AG (2), Win32/AutoRun.KS, Win32/BHO.NOV, Win32/BHO.NOZ (3), Win32/DDoS.Agent.NAF (2), Win32/Delf.OII (3), Win32/Delf.OIJ, Win32/FlyStudio.NLE (6), Win32/FlyStudio.NLF, Win32/FlyStudio.NLG (6), Win32/Hupigon.GUWZ, Win32/Hupigon.NOK, Win32/IRCBot.ANN, Win32/Koutodoor.N, Win32/Kryptik.PH, Win32/PSW.Delf.NPF, Win32/PSW.OnLineGames.NMP [...]

4075

4075 BAT/Agent.NBT (2), JS/Exploit.Pdfka.IP, JS/Exploit.Pdfka.JF, JS/Exploit.Pdfka.NJV (2), JS/Exploit.Pdfka.NJW, JS/Exploit.Pdfka.NJX, JS/Exploit.Pdfka.NJY (3), JS/TrojanClicker.Agent.NAG, JS/TrojanClicker.Agent.NAH, JS/TrojanDownloader.Agent.NQC, JS/TrojanDownloader.Agent.NQD, JS/TrojanDownloader.Agent.NQE, JS/TrojanDownloader.Iframe.NEF, JS/TrojanDownloader.Iframe.NEG, JS/TrojanDownloader.Iframe.NEH, JS/TrojanDownloader.Iframe.NEI, JS/TrojanDownloader.Iframe.NEJ, JS/TrojanDownloader.Iframe.NEK, JS/TrojanDownloader.Iframe.NEL, JS/TrojanDownloader.SWFlash.NBL, PDF/Exploit.Pidief.ODH, PDF/Exploit.Pidief.ODW, PDF/Exploit.Pidief.OFM (2), PDF/Exploit.Pidief.OGV, PDF/Exploit.Pidief.OMM, PHP/PHPInfo.G, Win32/Adware.Agent.NMR (3), Win32/Adware.AntiSpyware2008, Win32/Adware.BHO.NEO, Win32/Adware.BHO.NGL, Win32/Adware.BHO.NGN, Win32/Adware.PrivacyComponents, Win32/Adware.SystemSecurity (5), Win32/Agent.NYB (2), Win32/Agent.OKU, Win32/Agent.PKC (2), Win32/Agent.PKD, Win32/Agent.PKE, Win32/Agent.PKF, Win32/AntiAV.AZQ (2), Win32/AntiAV.NAE, Win32/Autoit.CM, Win32/AutoRun.FlyStudio.IY, Win32/AutoRun.Qhost.N, Win32/ClickLocker [...]

4074

4074 JS/Exploit.Pdfka.NJU (3), PDF/Exploit.Pidief.AUA, Win32/Agent.PKA, Win32/Agent.PKB (3), Win32/Delf.NSM (7), Win32/Delf.ODU, Win32/Delf.OFG, Win32/FlyStudio.NLB (3), Win32/FlyStudio.NLC (2), Win32/FlyStudio.NLD, Win32/Kryptik.LE, Win32/Kryptik.LR, Win32/Kryptik.MT, Win32/Kryptik.MU, Win32/Kryptik.MW, Win32/Kryptik.NB, Win32/Kryptik.ND, Win32/Kryptik.NG, Win32/Kryptik.NH, Win32/Kryptik.NM, Win32/Kryptik.NT, Win32/Kryptik.NV, Win32/Kryptik.NW, Win32/Kryptik.OC, Win32/Kryptik.OD, Win32/Kryptik.OQ, Win32/Kryptik.OR, Win32/Kryptik.OT, Win32/Kryptik.OU, Win32/Kryptik.OV, Win32/Kryptik.PA, Win32/LockScreen.F (2), Win32/Mypis.AH, Win32/Olmarik.HG, Win32/Pacex.Gen, Win32/PSW.OnLineGames.NMP, Win32/PSW.OnLineGames.NNU (2), Win32/PSW.OnLineGames.NUL, Win32/PSW.OnLineGames.NZD, Win32/PSW.OnLineGames.NZM, Win32/Randon.E, Win32/Rustock.NIH, Win32/Spy.VB.NEH, Win32/Spy.Zbot.NJ, Win32/Spy.Zbot.PG, Win32/Spy.Zbot.PT, Win32/TrojanClicker.VB.NFM, [...]

4070

4070 BAT/TrojanDownloader.Ftp.NDD, PDF/Exploit.Pidief.OMJ, Win32/Adware.Coolezweb, Win32/Adware.InternetAntivirus (3), Win32/Adware.PersonalAntivirus, Win32/Adware.VirusAlarmPro, Win32/Adware.WinPCDefender (2), Win32/Agent.NYA (2), Win32/Agent.WPI, Win32/AutoRun.Agent.NR, Win32/Delf.OHR, Win32/Delf.OHS, Win32/Delf.OIE (3), Win32/Injector.OI, Win32/IRCBot.AGP, Win32/Kryptik.OK, Win32/Kryptik.OL, Win32/Kryptik.OP, Win32/Olmarik.HG, Win32/PSW.OnLineGames.NSU, Win32/PSW.OnLineGames.NTZ, Win32/PSW.OnLineGames.NZD (2), Win32/PSW.OnLineGames.NZN, Win32/PSW.OnLineGames.NZS, Win32/PSW.OnLineGames.NZT (2), Win32/Ransom.I, Win32/Rootkit.Agent.NLH, Win32/Spy.Banker.AFFJ, Win32/Spy.Banker.QLG, Win32/Spy.Banker.QLP, Win32/Spy.Banker.QRT (3), Win32/Spy.Pophot.NAO (55), Win32/Spy.Zbot.JF, Win32/TrojanClicker.VB.NFM, Win32/TrojanDownloader.Bredolab.AA, Win32/TrojanDownloader.FakeAlert.UM, Win32/VB.OCY (3) URL: http://www.eset.com/joomla/index.php?option=com_content&task=view&id=6021&Itemid=26

4069

4069 BAT/Shutdown.NAJ, VBS/TrojanDownloader.Agent.NAT, Win32/Adware.InternetAntivirus (3), Win32/Adware.PersonalAntivirus, Win32/Adware.SpywareProtect2009 (2), Win32/Adware.SystemSecurity, Win32/Adware.WinPCDefender, Win32/Agent.NXG, Win32/Agent.NXT, Win32/Agent.PJU, Win32/Agent.PJV, Win32/Agent.PJW, Win32/AutoRun.Qhost.M, Win32/Delf.OHJ, Win32/Delf.OHR (2), Win32/FlyStudio.NKX, Win32/Hupigon.AENO, Win32/Hupigon.NOJ, Win32/Injector.IM, Win32/Injector.OF (2), Win32/Injector.OG, Win32/Injector.OH, Win32/IRCBot.ADZ, Win32/IRCBot.AGP, Win32/KillAV.NDR, Win32/Koobface.FX (2), Win32/Kryptik.OZ, Win32/PSW.LdPinch.NEL, Win32/PSW.LdPinch.NKV, Win32/PSW.OnLineGames.NMP, Win32/PSW.OnLineGames.NMY (4), Win32/PSW.OnLineGames.NTZ (3), Win32/PSW.OnLineGames.NUA (2), Win32/PSW.OnLineGames.NZA, Win32/PSW.OnLineGames.NZM (2), Win32/PSW.OnLineGames.ODJ (2), Win32/PSW.OnLineGames.OJO, Win32/PSW.WOW.NKC (2), Win32/Rootkit.Agent.KIR, Win32/Rootkit.Ressdt.NAY, Win32/Spy.Banbra.IBP (4), Win32/Spy.Banker.QEO, [...]

4068

4068 BAT/StartPage.NAT (3), HTML/TrojanClicker.IFrame.NAL, INF/Autorun, IRC/SdBot, JS/Exploit.Pdfka.JF (2), JS/Exploit.Pdfka.JG, JS/Exploit.Pdfka.NCY, PDF/Exploit.Pidief.OMI, VBS/Spy.Osmac.A (3), Win32/Adware.Agent.NMR (7), Win32/Adware.BHO.NCX, Win32/Adware.BHO.NGM, Win32/Adware.Cinmus, Win32/Adware.Coolezweb (6), Win32/Adware.InternetAntivirus (3), Win32/Adware.PersonalAntivirus (4), Win32/Adware.SystemSecurity (4), Win32/Adware.WinWebSecurity, Win32/Agent.AGIC (2), Win32/Agent.NXT, Win32/Agent.NXY (5), Win32/Agent.NXZ (2), Win32/Agent.WPI, Win32/AntiAV.NAE (2), Win32/AntiAV.NAF (2), Win32/AutoRun.ADR, Win32/AutoRun.Agent.NQ, Win32/AutoRun.DA, Win32/AutoRun.FlyStudio.IU (2), Win32/AutoRun.FlyStudio.IV, Win32/AutoRun.Qhost.M, Win32/BHO.NOV (6), Win32/BHO.NOW, Win32/BHO.NOX, Win32/Delf.OIB (3), Win32/Delf.OIC, Win32/DoS.Sypak, Win32/FlyStudio.NKW [...]

4065

4065 JS/Exploit.Pdfka.NJR (3), JS/Exploit.Pdfka.NJS (3), JS/TrojanDownloader.Agent.NQB (4), MSIL/TrojanDownloader.Agent.G, PDF/Exploit.Pidief.OMG, PDF/Exploit.Pidief.OMH, SWF/TrojanDownloader.Agent.NAU (2), SWF/TrojanDownloader.Agent.NAV (2), Win32/Adware.PersonalAntivirus, Win32/Adware.SpywareProtect2009 (2), Win32/Adware.WinPCAntivirus, Win32/Agent.NXW, Win32/Agent.PJQ, Win32/Agent.PJR, Win32/Agent.PJS, Win32/Agent.PJT, Win32/AntiAV.AZQ, Win32/AntiAV.NAD (2), Win32/Autoit.DK, Win32/Autoit.EB, Win32/AutoRun.Agent.EU, Win32/AutoRun.Autoit.P, Win32/AutoRun.Delf.BJ (2), Win32/AutoRun.FlyStudio.IS, Win32/AutoRun.IRCBot.AF, Win32/AutoRun.Qhost.L (2), Win32/Delf.NMM, Win32/Delf.NSN (2), Win32/Delf.NSO (4), Win32/Delf.OFA (2), Win32/Delf.OHS, Win32/Delf.OHY (2), Win32/Delf.OHZ, Win32/Delf.OIA, Win32/Hupigon.NOF, Win32/IDefense, Win32/Injector.OC, Win32/IRCBot, Win32/IRCBot.ADZ, Win32/Koobface.FX (2), [...]

4064

4064 IRC/SdBot, SWF/TrojanDownloader.Agent.NAT (2), Win32/Adware.Coolezweb (7), Win32/Adware.Virtumonde.NEK, Win32/Adware.Virtumonde.NFF, Win32/Agent.CCUK (3), Win32/Agent.PAR (2), Win32/Agent.PHN (2), Win32/Agent.PHO, Win32/Agent.PJN, Win32/Agent.PJO (2), Win32/Agent.PJP (2), Win32/Autoit.AG, Win32/Autoit.CT, Win32/Autoit.FO, Win32/Autoit.FP, Win32/AutoRun.ADC, Win32/AutoRun.Agent.EU, Win32/AutoRun.Agent.IK, Win32/AutoRun.Agent.JA, Win32/AutoRun.Agent.NO, Win32/AutoRun.Autoit.AI (3), Win32/Delf.OHJ, Win32/DelfOHX, Win32/FlyStudio.NKV, Win32/Injector.OB, Win32/Poison (4), Win32/PSW.LdPinch.NEL, Win32/PSW.OnLineGames.NMP (2), Win32/PSW.OnLineGames.NMY, Win32/PSW.OnLineGames.NNU (3), Win32/PSW.WOW.DZI, Win32/Qhost, Win32/Qhost.NJP, Win32/Rootkit.Agent.NLK (4), Win32/Spy.Banker.KSO, Win32/Spy.Banker.QXL, Win32/Spy.Banker.QXM, Win32/Spy.Delf.NTZ, Win32/Spy.Delf.NUA, Win32/Spy.Zbot.NJ, Win32/Spy.Zbot.PT, [...]

4063

4063 BAT/KillFiles.NBG, BAT/Restart.NAA (2), HTML/Exploit.IESlice.BT (5), JS/Exploit.Pdfka.NJQ, JS/TrojanDownloader.Agent.NLL, JS/TrojanDownloader.Agent.NQB (4), JS/TrojanDownloader.Psyme.NFC (4), PDF/Exploit.Pidief.OLZ, PDF/Exploit.Pidief.OMA, PDF/Exploit.Pidief.OMB, PDF/Exploit.Pidief.OMC, PDF/Exploit.Pidief.OMD, PDF/Exploit.Pidief.OME, PDF/Exploit.Pidief.OMF, SWF/Exploit.Agent.AI, SWF/Exploit.Agent.AJ, SWF/TrojanDownloader.Agent.NAP (2), SWF/TrojanDownloader.Agent.NAQ (2), SWF/TrojanDownloader.Agent.NAR (2), SWF/TrojanDownloader.Agent.NAS (2), VBS/TrojanDownloader.Psyme.NFU (2), Win32/Adware.Antivirus2008, Win32/Adware.Coolezweb, Win32/Adware.PersonalAntivirus (2), Win32/Adware.Virtumonde.NEH, Win32/Adware.Virtumonde.NEI, Win32/Adware.Virtumonde.NEK (3), Win32/Adware.VirusDoctor, Win32/Agent.NGC, Win32/Agent.NGJ (4), Win32/Agent.NXU (6), Win32/Agent.NXV, Win32/AutoRun.ADC (2), Win32/AutoRun.Delf.BU (5), Win32/AutoRun.FakeAlert.AF, Win32/Delf.OHS, Win32/Delf.OHV (2), Win32/Delf.OHW [...]

4062

4062 JS/Exploit.Pdfka.A, JS/TrojanDownloader.Agent.NQB, PDF/Exploit.Pidief.GX, SWF/TrojanDownloader.Agent.NAO (2), Win32/Adware.BHO.GKZ, Win32/Adware.BHO.GLG, Win32/Adware.Coolezweb (3), Win32/Adware.InternetAntivirus, Win32/Adware.PersonalAntivirus, Win32/Agent.NFX, Win32/Agent.NXT (2), Win32/Agent.PHC, Win32/AutoRun.ABH, Win32/AutoRun.Agent.EU, Win32/Exploit.MS08-067.BT, Win32/FlyStudio.NKT (2), Win32/Hupigon, Win32/Inject.NCM, Win32/Injector.HP, Win32/Injector.LK, Win32/KillAV.NDC, Win32/Peerfrag.AR, Win32/PSW.LdPinch.NEL, Win32/PSW.OnLineGames.NMP, Win32/PSW.OnLineGames.NMY (2), Win32/PSW.OnLineGames.NNU (2), Win32/PSW.OnLineGames.ODJ, Win32/Qhost, Win32/Rootkit.Agent.NLD, Win32/Rustock.NIF (3), Win32/Spy.Banker.QRJ (2), Win32/Spy.Banker.QRK (2), Win32/Spy.Banker.QRL, Win32/Spy.Banker.QRM (2), Win32/Spy.Zbot.JF, Win32/TrojanClicker.Delf.NGO, Win32/TrojanClicker.VB.NFM, Win32/TrojanClicker.VB.QF, Win32/TrojanDownloader.Agent.PBI (2), Win32/TrojanDownloader.Banload.OOC, Win32/TrojanDownloader.Bredolab.AA, Win32/TrojanDownloader.Small.OOC (3), [...]

A packet challenge and how I solved it, (Thu, May 7th)

A packet challenge and how I solved it, (Thu, May 7th) Yesterday morning (EDT in the US), our friend Chris Christianson twittered the following: 4500 0036 308b 0000 4001 0000 7f00 0001 7f00 0001 0800 89f3 5a27 0200 3173 7432 444d 6d65 6765 7473 4153 7461 7262 7563 6b73 6361 7264 I didn’t see it [...]

Botnet hijacking reveals 70GB of stolen data, (Thu, May 7th)

Botnet hijacking reveals 70GB of stolen data, (Thu, May 7th) Thanks to our reader Crill today. He gave us a heads up on an interesting research project recently conducted at a large university. newsfeedresearcher.com/data/articles_t19/botnet-torpig-researchers.html It appears that the university infiltrated a Torpig botnet and for 10 days they watched the botnet activity they discovered: During [...]

4060

4060 BAT/TrojanDownloader.Agent.NAH (2), INF/Autorun (2), IRC/SdBot (2), JS/Exploit.Pdfka.NJM, JS/Exploit.Pdfka.NJN (2), JS/Exploit.Pdfka.NJO (2), JS/Exploit.Pdfka.NJP (2), JS/TrojanDownloader.Agent.NJO, JS/TrojanDownloader.Agent.NQA (2), PDF/Exploit.Pidief.ASZ, PDF/Exploit.Pidief.OLS, PDF/Exploit.Pidief.OLT, PDF/Exploit.Pidief.OLU, PDF/Exploit.Pidief.OLV, PDF/Exploit.Pidief.OLW, PDF/Exploit.Pidief.OLX, PHP/Rst.AK, VBS/StartPage.NAE, VBS/TrojanDownloader.Agent.NAS, Win32/Adware.AVSystemCare, Win32/Adware.BHO.NCX, Win32/Adware.ProDM (6), Win32/Adware.SystemSecurity (5), Win32/Adware.Virtumonde, Win32/Adware.Virtumonde.NCB, Win32/Adware.Virtumonde.NEK, Win32/Adware.WinAntivirusPro, Win32/Adware.WinPCDefender, Win32/Agent.CCWW (2), Win32/Agent.NGB, Win32/Agent.PDP, Win32/Agent.PHC, Win32/AntiAV.NAC, Win32/AutoRun.Agent.NN, Win32/AutoRun.FlyStudio.IR (2), Win32/AutoRun.IRCBot.AE, Win32/AutoRun.Qhost.K, Win32/AutoRun.VB.DF (2), Win32/BHO.SFS, Win32/Delf.OFG (3), Win32/Delf.OHS, [...]

Bad Behavior has blocked 209 access attempts in the last 7 days.