Linux and BSD Web Servers at Risk of Sophisticated Mumblehard Infection(eset.com)
eset.com
Linux and BSD Web Servers at Risk of Sophisticated Mumblehard Infection
http://www.eset.com/int/about/press/articles/malware/article/linux-and-bsd-web-servers-at-risk-of-sophisticated-mumblehard-infection-says-eset/
3 comments
That pirated copy of DirectMailer that you loaded onto your server also sends spam?! Whoda thunk it?
I know what you're saying... but this is odd:
"... we found that IP addresses hard-coded in the malware are closely tied to those of Yellsoft"
"... we found that IP addresses hard-coded in the malware are closely tied to those of Yellsoft"
Learned a couple of things from linked research paper like always mount /tmp and /var/tmp as noexec, and some `dig` fu.
8,500 unique IP addresses during 7 months. How is this not trivial?