[Updates on 2017-11-28]
* Both C2s have been sink-holed now by security community.
* admin/CentryL1nk is a typo for admin/CenturyL1nk.
About 60 hours ago, since 2017-11-22 11:00, we noticed big upticks on port 2323 and 23 scan traffic, with almost 100k unique scanner IP came from Argentina. After investigation,