<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom"
	xml:lang="en-us">
	<title>Comments on NOC4HOSTS and the Grum Botnet</title>
	<subtitle></subtitle>
	<link rel="self" type="application/atom+xml" title="Comments on NOC4HOSTS and the Grum Botnet" href="http://blog.fireeye.com/research/2008/12/noc4host-and-the-grum-botnet/comments/atom.xml" />
	<link rel="alternate" type="text/html" title="NOC4HOSTS and the Grum Botnet" href="http://blog.fireeye.com/research/2008/12/noc4host-and-the-grum-botnet.html"/>
	<generator uri="http://www.typepad.com/">TypePad</generator>
	<xhtml:meta xmlns:xhtml="http://www.w3.org/1999/xhtml" name="robots" content="noindex" />
	<updated>2008-12-06T00:28:21Z</updated>
	<author>
		<name>FireEye</name>
		<uri>http://blog.fireeye.com/research/</uri>
	</author>
	<id>tag:typepad.com,2003:http://blog.fireeye.com/research/2008/12/noc4host-and-the-grum-botnet/comments/atom.xml/</id>
    
		<entry>
			<title>kai commented on &#39;NOC4HOSTS and the Grum Botnet&#39;</title>
			<link rel="alternate" type="text/html" title="this is another of their scam sites with a search I did http://www.nowtorrents.com/torrents/this+is+a+scam+site+.html hosted by NOC4HOSTS you may find the..." href="http://blog.fireeye.com/research/2008/12/noc4host-and-the-grum-botnet.html?cid=6a00d835018afd53ef01116866ad5f970c#comment-6a00d835018afd53ef01116866ad5f970c" />
			<id>tag:typepad.com,2003:6a00d835018afd53ef01116866ad5f970c</id>
			<published>2009-02-16T01:16:28Z</published>
			<updated>2009-02-16T19:23:10Z</updated>
			<author>
				<name>kai</name>
                
			</author>
			<summary>this is another of their scam sites with a search I did http://www.nowtorrents.com/torrents/this+is+a+scam+site+.html hosted by NOC4HOSTS you may find the...</summary>
			<content type="html" xml:base="http://blog.fireeye.com/research/2008/12/noc4host-and-the-grum-botnet.html">&lt;p&gt;this is another of their scam sites with a search I did &lt;a href=&quot;http://www.nowtorrents.com/torrents/this+is+a+scam+site+.html&quot; rel=&quot;nofollow&quot;&gt;http://www.nowtorrents.com/torrents/this+is+a+scam+site+.html&lt;/a&gt; hosted by NOC4HOSTS you may find the search results interesting! There should be an easier way to shut these sort of sites and companies down&lt;/p&gt;</content>
		</entry>
	
		<entry>
			<title>Andrew commented on &#39;NOC4HOSTS and the Grum Botnet&#39;</title>
			<link rel="alternate" type="text/html" title="There&#39;s a cutwail C&amp;C also running in HI velocity @ 69.46.20.65. The traffic is to port 2065 and looks like..." href="http://blog.fireeye.com/research/2008/12/noc4host-and-the-grum-botnet.html?cid=6a00d835018afd53ef01053657ab68970b#comment-6a00d835018afd53ef01053657ab68970b" />
			<id>tag:typepad.com,2003:6a00d835018afd53ef01053657ab68970b</id>
			<published>2008-12-12T21:17:25Z</published>
			<updated>2008-12-12T21:17:25Z</updated>
			<author>
				<name>Andrew</name>
                
			</author>
			<summary>There&#39;s a cutwail C&amp;C also running in HI velocity @ 69.46.20.65. The traffic is to port 2065 and looks like...</summary>
			<content type="html" xml:base="http://blog.fireeye.com/research/2008/12/noc4host-and-the-grum-botnet.html">&lt;p&gt;There&amp;#39;s a cutwail C&amp;amp;C also running in HI velocity @ 69.46.20.65. The traffic is to port 2065 and looks like obfuscated traffic. The only discernible text in the stream is &amp;quot;L.....9ifnospam.0.exe_url..exe_url........&amp;quot;&lt;/p&gt;

&lt;p&gt;The other portion of the cutwail C&amp;amp;C is in SoftLayer, also in the US. I posted some of the details on my blog: &lt;a href=&quot;http://realsecurity.wordpress.com/&quot; rel=&quot;nofollow&quot;&gt;http://realsecurity.wordpress.com/&lt;/a&gt;&lt;/p&gt;</content>
		</entry>
	
		<entry>
			<title>Martin commented on &#39;NOC4HOSTS and the Grum Botnet&#39;</title>
			<link rel="alternate" type="text/html" title="Hivelocity response team is actually decently responsive, they null routed all mentionned IPs yesterday." href="http://blog.fireeye.com/research/2008/12/noc4host-and-the-grum-botnet.html?cid=142052090#comment-6a00d835018afd53ef0105364a51f1970b" />
			<id>tag:typepad.com,2003:6a00d835018afd53ef0105364a51f1970b</id>
			<published>2008-12-09T09:28:13Z</published>
			<updated>2008-12-09T09:28:13Z</updated>
			<author>
				<name>Martin</name>
                
			</author>
			<summary>Hivelocity response team is actually decently responsive, they null routed all mentionned IPs yesterday.</summary>
			<content type="html" xml:base="http://blog.fireeye.com/research/2008/12/noc4host-and-the-grum-botnet.html">&lt;p&gt;Hivelocity response team is actually decently responsive, they null routed all mentionned IPs yesterday.&lt;/p&gt;</content>
		</entry>
	
		<entry>
			<title>Skudd commented on &#39;NOC4HOSTS and the Grum Botnet&#39;</title>
			<link rel="alternate" type="text/html" title="Out of curiosity, do you folks report this sort of thing to the DC&#39;s abuse team? Where I work (an..." href="http://blog.fireeye.com/research/2008/12/noc4host-and-the-grum-botnet.html?cid=141663096#comment-6a00d835018afd53ef0105364a2bef970c" />
			<id>tag:typepad.com,2003:6a00d835018afd53ef0105364a2bef970c</id>
			<published>2008-12-07T00:06:27Z</published>
			<updated>2008-12-07T00:06:27Z</updated>
			<author>
				<name>Skudd</name>
                <uri>http://www.skudd.com/</uri>
			</author>
			<summary>Out of curiosity, do you folks report this sort of thing to the DC&#39;s abuse team? Where I work (an...</summary>
			<content type="html" xml:base="http://blog.fireeye.com/research/2008/12/noc4host-and-the-grum-botnet.html">&lt;p&gt;Out of curiosity, do you folks report this sort of thing to the DC&amp;#39;s abuse team? Where I work (an unnamed leader in the hosting industry), our abuse team takes this sort of thing _very_ seriously. If the NOC won&amp;#39;t do anything about it, hand the packet logs over to the upstream provider(s) along with copies of the messages submitted to the DC.&lt;/p&gt;</content>
		</entry>
	
</feed>
<!-- ph=1 -->
<!-- nhm:from_kauri -->