Back to list
*Note: Email address will appear as "user domain ext" to prevent harvesting.
RE: RE: Worm attack on our network this morning -- anyone else see this?
Dec 13 2006 10:56PM
David Gillett (gillettdavid fhda edu)
What I've got so far is that the 7654 IRC connection is
typical of the "SDBot" family of malware.
The number of infections has stabilized -- only one new
infected machine in the last three hours. That strongly
suggests that machines with up to date patches and/or
antivirus and/or non-blank pa...
[ more ]
Copyright 2010, SecurityFocus