Results 1 to 7 of 7
-
19th Dec 2010, 07:59 PM #1OPBanned
Seems someone hacked my vps
today i have received an abuse letter from DC and they forward to me.
On 2010-12-18, someone uploaded multiple ZeuS trojan files to your network:
http://update.shuwhyyu.com/update/hh...ffepfkpkzz.exe
http://ns1.syegyege.com/8d6srxzq5kef37b9b49b9fh64jqj
IP: 91.215.159.108
We're kindly requesting that you remove these malware files, or that you
null route 91.215.159.108.
Googling for either "update.shuwhyyu.com" or "ns1.syegyege.com" shows
only references to malware.
Additional evidence can be found here:
https://zeustracker.abuse.ch/monitor...e.shuwhyyu.com
https://zeustracker.abuse.ch/monitor...1.syegyege.com
Thank you for your help,
-Konrads
PhishLabs Security OperationsThe Dude Reviewed by The Dude on . Seems someone hacked my vps today i have received an abuse letter from DC and they forward to me. now how can i know where is the trojan file located. Rating: 5
-
19th Dec 2010, 08:46 PM #2loki
What panel you use? You don't have a virus scanner?
Sponsored Links
19th Dec 2010, 08:57 PM
#3
OP
Banned
i guess i don't have any virus scanner.
ps: atm downloading all files on my computer then will scan using my antivirus
one question, is it possible someone uploaded the trojan on root folder e.g. /var/ and abuse.ch track it?
19th Dec 2010, 09:01 PM
#4
loki
it could be any where, check for shells, AND, change password ASAP
you can install ClamAv, just have to manual config
themaManager - edit and manage...
Version 4.04 released. Open older version (or...