I’ve seen it before. There’s a C&C server at 3apa3a.[redacted].tw/c/ (3apa3a, correctly spelled зараза in Russian means infection, virus, contagion – hell a name for C&C center). I’ve searched for bots from there and I discovered a few machines on public IP address nearby. So I’ve nmapped them – two of them were Macs. Either parallels or native ZeuS/SpyEye 64 bit client for OS X. 64bit! Better than Safari!
I’ve seen it before. There’s a C&C server at 3apa3a.[redacted].tw/c/ (3apa3a, correctly spelled зараза in Russian means infection, virus, contagion – hell a name for C&C center). I’ve searched for bots from there and I discovered a few machines on public IP address nearby. So I’ve nmapped them – two of them were Macs. Either parallels or native ZeuS/SpyEye 64 bit client for OS X. 64bit! Better than Safari!