So far, the URLs where the malware is coming from all seem to have in common that port 7777 is used. This is rare enough that trolling through your proxy logs for any of your users going to a URL containing :7777/dt might give you a better indication than your anti-virus. Because AV coverage (VirusTotal) is only slowly improving.
|
Daniel 385 Posts ISC Handler Dec 5th 2008 |
Thread locked Subscribe |
Dec 5th 2008 1 decade ago |
Sign Up for Free or Log In to start participating in the conversation!