So let's try to shed light onto the C&C server.
At first I want again to thank Chae Jong Bin! With his brief network analysis of this botnet, he gave me a solid background.
The first thing you realize when visiting http://xlamzju-lrychj.info is directory listing was activated. This gives us the chance to explore files and folders.
There are a lot of PHP Scripts, 3 .dat files and 3 subfolders.
At first I want again to thank Chae Jong Bin! With his brief network analysis of this botnet, he gave me a solid background.
The first thing you realize when visiting http://xlamzju-lrychj.info is directory listing was activated. This gives us the chance to explore files and folders.
There are a lot of PHP Scripts, 3 .dat files and 3 subfolders.
Figure 1: Directory Listing of ".com/.info" unit |