11.06.2015 Views

NTRG_ElasticBotnetReport_06102015

NTRG_ElasticBotnetReport_06102015

NTRG_ElasticBotnetReport_06102015

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

One common indicator of a BillGates infection is the existence of /tmp/moni.lock as well as<br />

/tmp/bill.lock files on the victim’s machine. Additionally, directories off the /usr/bin directory<br />

containing the name bsd-port may be suspect.<br />

THE ELASTIC BOTNET REPORT<br />

61

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!