Re: [botnets] QoS and bot traffic

2006-10-24 Thread Desai, Ashish
a botnet PRIVATELY please email: [EMAIL PROTECTED] -- I assume you guys keep logs of who calls, and when? Or at least when the deactivations occur on which client ip's? Would be a nice sample set to learn malware propagation patterns from. Desai, Ashish wrote: To report a botnet

Re: [botnets] Finding zombies?

2007-01-08 Thread Desai, Ashish
To report a botnet PRIVATELY please email: [EMAIL PROTECTED] -- If you machines go through a http proxy, you can check the proxy logs for crud. Ashish -Original Message- From: Sean Zadig [mailto:[EMAIL PROTECTED] Sent: Monday, January 08, 2007 8:36 AM To:

Re: [botnets] fake AV (malicious) sites

2008-08-28 Thread Desai, Ashish
Hi All, To detect if your customers/employees are infected, check the HTTP useragent string in your web logs and proxy logs for the following new tokens that this thing adds to a machines existing useragent string AntivirXP08 3P_UVRM 3P_UASE 3P_PCPC