Month: October 2011

microsoft-ftp.com(CCTEAM botnet hosted in Russian Federation Moscow State Institute Of Information Technologies And Telecommunications (siit&t Informika))

Uncategorized

Resolved : [microsoft-ftp.com] To [85.143.50.132] Remote Host Port Number 201.151.191.146 21 201.151.191.146 80 204.0.5.57 80 85.143.50.132 80 USER microsoft JOIN #L0bby 9208i1533G MODE #L0bby PRIVMSG #L0bby :I’m New 0wned Bot PRIVMSG #L0bby :USB Spread file not found in my system. Downloading now… PRIVMSG #L0bby :Starting download… (Total size: 1.22MB) PRIVMSG #L0bby :Download of disk.exe completedRead more...

158.38.8.251(irc botnet hosted in Norway Trondheim Uninett)

Uncategorized

Remote Host Port Number 158.38.8.251 6667 NICK eprfkw421 USER eprfkw421 localhost irc.quakenet.org: eprfkw421 PONG :3023209735 JOIN #jdsun NICK eehjrp476 USER eehjrp476 localhost irc.quakenet.org: eehjrp476 PONG :2512891925 hosting infos: http://whois.domaintools.com/158.38.8.251

91.121.204.203(ngrBot hosted in France Ovh Systems)

Uncategorized

Remote Host Port Number 199.15.234.7 80 83.233.33.6 80 91.121.204.203 4242 PASS secret NICK n{US|XPa}riqmriq USER riqmriq 0 0 :riqmriq PONG :446AE763 JOIN ##m secret PRIVMSG ##m :[DNS]: Blocked 1310 domain(s) – Redirected 0 domain(s) hosting infos: http://whois.domaintools.com/91.121.204.203

189.236.84.161(ngrBot hosted in Mexico Uninet S.a. De C.v)

Uncategorized

Remote Host Port Number 189.236.84.161 6567 PASS hell16 199.15.234.7 80 NICK n{US|XPa}uoauybk USER uoauybk 0 0 :uoauybk PONG :D9F0B22F JOIN #cont ngrBot PRIVMSG #cont :[DNS]: Redirecting “www.bancofrances.com.ar” to “computo164.laweb.es” hosting infos: http://whois.domaintools.com/189.236.84.161