Strange attacks over the weekend

Nov. 1, 2010
4:25 p.m.
Hi, We in the Honeynet Project has been following this for the last 4-5 months. We call it sundayddr because of the User-Agent. Ben in Australia has written more about it here: http://honeynet.org.au/ I have also written about it here (back in July) http://www.usken.no/2010/07/using-botnets-to-do-sip-scanning/ It is a botnet client with both a SSH and a SIP scanner (based on SIPVicious by Sandro Gauci) (www.sipvicious.org) Most infected machines doing this scanning are located in China contact me if you need any more information. cheers sjur www.usken.no
5389
Age (days ago)
5389
Last active (days ago)
0 comments
1 participants
participants (1)
-
sjur@usken.no