Posted to
Security
by
onionlips
on
04-18-2008, 10:25 AM
We have been hit by this as well. Lucky backup ran last night just prior to the attack.
Our initial investigations are pointing at an attack through IIS using ASP in an overload.
whois lookup showing nihaorr1 registered via Chinese registrar xinnet.com
I used the safety of a VM to look under the hood at the operations of the 1.js file. ...