tetak
MIRT Team Lead Premium Member
 Joined: Jan 19, 2007 Posts: 5866
|
Posted: Sat May 24, 2008 4:49 pm Post subject: [MIRT#11368] Trojan on 217.170.77.150 AS20597 |
|
|
Malware Alert Full Report: /Trojan_malware11368.html Consumed following related reports:
[11371] http://217.170.77.150/rom/crldr.exe
pibzero.exe at this location is malware known as Trojan:Win32/Vundo.gen!I (Microsoft).Changed status to confirmed malware.IP Converted: 217.170.77.150
dword = 3651816854
hex1 = 0xd9aa4d96
hex2 = 0xd9.0xaa.0x4d.0x96
oct = 0331.0252.0115.0226
crldr.exe at this location is malware known as Trojan-Downloader.Win32.Agent.qos (Kaspersky).View CIDR AS20597 Report: http://www.cidr-report.org/cgi-bin/as-report?as=20597
"20597 | RU | ripencc | 2001-04-18 | ELTEL-AS ELTEL.net Autonomous System"<br />
Extended information for AS20597:
State/Province:
Country:
Responsible Domain: eltel.net
Abuse Email: abuse@eltel.net
| Quote: | | http://217.170.77.150/hjk/pibzero.exe |
|
|