Inside a Botnet's Phishing Activities
2008-02-25 09:34:49 by HASH0x8b44f48 in Dancho Danchev's Blog - Mind Streams of Information Security Knowledge
...BKDR AGENT.AKJZ, Backdoor.Agent.AJU, Proxy-Agent.af.gen and Proxy-Agent.af.gen, BKDR AGENT.AKJZ , both binaries attempt to connect to several IPs, one's that's resolving to the entire ecosystem's name servers, namely 72.46.130.154 . This KISS strategy allows us to quickly expand the entire domain portfolio and the associated phishing...





