James, > Questions: > > - Is the author of the zombie planning to use my page to post updated > instructions to his program? Piclist.com is a wiki... I've locked the page > so it can not be modified just incase, but I am still alowing it to be > viewed. Looks like it. > - Is there some outfit that investigates things like this who would be > interested to know what I'm seeing? SANS as mentioned before, CERT might have a go at it, you might find some bit of the police department also looks into these kind of things. > - If this is a zombie program is its reference to my server going to > implicate me? In other words, could someone who is tracking the zombie and > looking for the author think that it is me since the program is looking > here? It will implicate you, but as you are running a known host with an open wiki, you won't be held liable. > - What would you do if you were me? Report to at least one of the above institutions to help law enforcement crack the botnet and make sure that you get an official note that you aren't related to it and that you've helped law enforcement. That should get you out even if the guy shouts out your name in court as accomplice. -- http://www.piclist.com PIC/SX FAQ & list archive View/change your membership options at http://mailman.mit.edu/mailman/listinfo/piclist