Month: July 2011

91.211.117.155(ngrBot hosted in Ukraine Zharkov Mukola Mukolayovuch)

Uncategorized

Remote Host Port Number 213.251.170.52 80 91.211.117.153 80 91.211.117.155 1865 PASS ngrBot NICK n{US|XPa}rwslldg USER rwslldg 0 0 :rwslldg JOIN #main 4m3r1k4 QUIT :rebooting * The data identified by the following URLs was then requested from the remote web server: o http://api.wipmania.com/ o http://91.211.117.153/070711.exe hosting infos: http://whois.domaintools.com/91.211.117.155

gangbang.angels-agency.nl(large botnet linux bots hosted in China Anhui Chinanet Anhui Province Network)

Uncategorized

Resolved : [gangbang.angels-agency.nl] To [223.244.227.2] Resolved : [gangbang.angels-agency.nl] To [117.211.84.155] UPDATE: Resolved : [ gangbang.angels-agency.nl ] To [ 78.47.59.194 ] Resolved : [ gangbang.angels-agency.nl ] To [ 223.244.227.2 ] Resolved : [ gangbang.angels-agency.nl ] To [ 117.211.84.155 ] var $config = array(“server”=>”gangbang.angels-agency.nl”, “port”=>”25343”, “pass”=>””, “maxrand”=>”1”, “chan”=>”#wWw#”, “chan2″=>”#wWw#”, “key”=>”scan”, “modes”=>”+p”, “password”=>”41aa15390e2efa34ac693c3bd7cb8e88”,//p0w3r “trigger”=>”.”, “hostauth”=>”0wn3d.3u” hosting infos: http://whois.domaintools.com/223.244.227.2

www.chatcity2011.net(irc botnet hosted in Turkey Radore Hosting Telekomunikasyon Hizmetleri San. Ve Tic. Ltd. Sti)

Uncategorized

Resolved : [www.chatcity2011.net] To [176.53.19.44] Resolved : [www.chatcity2011.net] To [176.53.19.45] Remote Host Port Number 176.53.19.44 81 irc here 213.131.252.251 80 74.206.242.164 80 NICK [N00_USA_XP_2228330] PRIVMSG [N00_USA_XP_2228 @ :scan; Trying to get external IP. USER SP2-988 * 0 :COMPUTERNAME @ :scan; Sequential Port Scan started on 174.133.89.0:445 with a delay of 5 seconds for 0 minutesRead more...

85.17.180.218(irc botnet hosted in Netherlands Amsterdam Leaseweb B.v)

Uncategorized

Remote Host Port Number 85.17.180.218 7775 NICK {XPUSA338226} PONG irc.foonet.com USER COMPUTERNAME * 0 :COMPUTERNAME MODE {XPUSA338226} -ix JOIN #karakirli MODE #karakirli -ix UPDATE: NICK n{Ganja-USA|XP}011539 PRIVMSG #c :http://www.r0kettube.com/kategori/Fantazi-Porno Has Been Visited! USER 0115 “” “TsGh” :0115 JOIN #o3 PRIVMSG #d :http://www.r0kettube.com/kategori/Hemsire-Porno Has Been Visited! JOIN #a,#b,#c,#d,#e,#f,#g,#h,# ,#j,#k,#l (null) PRIVMSG #e :http://r0kettube.com/eski-porno-filmi.html Has Been Visited!Read more...