Hello guys, during my attempts to analyze mebroot I've been found a pedantic exploiter that post on javacripts-analytics.com infected host info. Can anyone give me a feedback about correlation between a strange routes changing and an increasing of http request against the "info collector web site" ? I have post something about it. If tou are interested check http://extraexploit.blogspot.com
Thank you for your attention. Regards. _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/
