Last Updated: 2006-12-12 21:20:49 UTC
by Swa Frantzen (Version: 1)
It seems like there is a revival going on of the botnet exploiting the Symantec Anti-Virus vulnerability. It was originally reported on by Joel on Nov 27th.
But the traffic scanning for port 2967 is back. It seems new Command and Control centers are active for it as well.
Swa Frantzen -- Section 66