Difference between revisions of "Devdar"
Jump to navigation
Jump to search
m (1 revision imported) |
m (Text replacement - "=Unknown" to "=") |
||
Line 15: | Line 15: | ||
|Infrastructure= | |Infrastructure= | ||
|Commercialisation= | |Commercialisation= | ||
|UserAgent= | |UserAgent= | ||
|UserAgent2= | |UserAgent2= | ||
|UserAgent3= | |UserAgent3= | ||
Line 30: | Line 30: | ||
|OS3= | |OS3= | ||
|OS4= | |OS4= | ||
|Status= | |Status= | ||
|BeginYear=2013-03 | |BeginYear=2013-03 | ||
|EndYear= | |EndYear= | ||
|Group=Police lock | |Group=Police lock | ||
|Groupe2= | |Groupe2= |
Latest revision as of 15:47, 8 August 2015
(Botnet) Link to the old Wiki page : [1] / Google search: [2]
Devdar | |
---|---|
Alias | |
Group | Police lock |
Parent | |
Sibling | |
Family | |
Relations | Variants: Sibling of: |
Target | Microsoft Windows |
Origin | |
Distribution vector | Styx |
UserAgent | |
CCProtocol | HTTP (Centralized) |
Activity | 2013-03 / |
Status | |
Language | |
Programming language | |
Operation/Working group |
Introduction
Germany, Portugal, and Italy are ignored (502) Switzerland, Ukraine and Lithuania get a "DIE" reply.
md5
5b495e3b68757dc44668b5193a74499e 2013-04-09 11322b25f97134a81f800fbe0cb14b2b 2013-05-19
httpget
95.141.35.52 http://readion.deaftone .com:4666/qFbRCa0Xa2R0YsrK0NMFA0fWNf08q5D139Kt0Mu7r0DKsn0vQUc09gvU0zOvO0VqWw 2013-04-09 http://youhappenes.flnet .org:4666/lnd/template=1/AcMY_a0owCM0pJV40kTCb04NSI0N7Zj0FS8K0osvQ0i7Qp0R5GG0tNNZ0z1Ga0HEJM0W5310heLL08hEg18iUy0nfit0ROrD0pwvO11efa0N4pO 2013-04-09