Remote Host Port Number 70.107.249.167 7000 NICK GL983668621949 USER mioubypigigz 0 0 :GL983668621949 MODE GL286772458982 +i JOIN #GL .x. USERHOST GL286772458982 USERHOST GL983668621949 MODE GL983668621949 +i NICK GL286772458982 USER xbjpsqcwhywo 0 0 :GL286772458982 Now talking in #GL Topic On: [ #GL ] [ .advscan asn1smbnt 100 5 0 -b -r -s ] Topic By: [Read more...
apple.com(botnet hosted in United States Crystal River Ispsystem At Nac)
Remote Host Port Number 82.146.51.121 6667 Invisible Users: 422 Operators: 9 operator(s) online Channels: 18 channels formed Clients: I have 423 clients and 0 servers Local users: Current Local Users: 423 Max: 613 Global users: Current Global Users: 423 Max: 613 NICK {N}|USA|XP|COMPUTERNAME|054249 USER syadpo “” “kjhx” :COMPUTERNAME JOIN #meelisv PRIVMSG #meelisv :New Servant. infosRead more...
tacettin.no-ip.biz(rat hosted in Turkey Istanbul Istanbul Datacenter Ltd. Sti)
tacettin.no-ip.biz: type A, class IN, addr 178.211.38.245 port:100
1e2.bmobile-free.co.cc (botnet hosted in United States Miami Fdcservers.net)
1e2.bmobile-free.co.cc DNS_TYPE_A 76.73.100.211 76.73.100.211:2241 Nick: [AUT|00|P|22493] Username: XP-1133 Server Pass: password Joined Channel: ##Net##Man## with Password HaCkers.For.PC Channel Topic for Channel ##Net##Man##: “$seed.utorrent” Topic By: [ Emperador ] Modes On: [ ##Net##Man## ] [ +smntu ] infos about hosting here: http://whois.domaintools.com/76.73.100.211
server.gasbian.com(botnet hosted in United States Chicago Hostforweb Inc)
Remote Host Port Number 174.37.200.82 80 216.178.38.224 80 63.135.80.46 80 64.208.241.41 80 69.63.181.15 80 205.234.145.229 1234 PASS xxx MODE NEW-[USA|00|P|57896] -ix JOIN #!nn! test PONG 22 MOTD NICK NEW-[USA|00|P|57896] USER XP-0495 * 0 :COMPUTERNAME Other details * The following ports were open in the system: Port Protocol Process 1059 TCP nvsvc32.exe (%Windir%nvsvc32.exe) 1062 TCP nvsvc32.exeRead more...
main.logmebaby.com(bfbot hosted in United States Dallas Theplanet.com Internet Services Inc)
main.logmebaby.com DNS_TYPE_A: 174.122.138.170 174.121.62.122 174.122.138.154 174.122.138.162 – TCP Connection Attempts: 174.122.138.170:8800 174.121.62.122:8800 174.122.138.154:8800 174.122.138.162:8800 more here: http://anubis.iseclab.org/?action=result&task_id=1d7b1f13eb62a9bd461f71d0a04dfd8ac&format=html infos about hosting: http://whois.domaintools.com/174.122.138.170
173-163-151-27-cpennsylvania2.hfc.comcastbusiness.net(botnet hosted in United States Mechanicsburg Comcast Business Communications Inc)
Remote Host Port Number 173.163.151.27 9595 PASS prison 208.78.69.70 80 72.233.89.199 80 PRIVMSG {iNF-00-USA-XP-C` =~@ :HTTP SET http://211.232.30.165/http.exe JOIN ###meat PRIVMSG {00-USA-XP-COMP-` =~@ :SC// Sequential Port Scan started on 192.168.0.0:445 with a delay of 10 seconds for 0 minutes using 100 threads. PONG leaf.12774.com NICK {iNF-00-USA-XP-COMP-5508} USER MEAT * 0 :COMP JOIN #http NICK {00-USA-XP-COMP-1284}Read more...
d0x.me(botnet hosted in United States Crystal River Ispsystem At Nac)
Remote Host Port Number 82.146.51.22 1338 PONG :BEBD508C NICK qvdzl JOIN #foxes USER oivWsEmBCEZmpoAn0d2mosEhevNqtbdYEaV7QsQFjlGN8ZB * * :Q5RyK NICK GUqSpR66 PONG :7B532196 USER pyN4tVLUw705CTxc2BAJuV * * :d3WvenjZK9mrMR1P Registry Modifications * The newly created Registry Value is: o [HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRun] + System = “C:Ppbn.exe” so that pbn.exe runs every time Windows starts Memory Modifications * There was aRead more...
204.15.252.199.icertified.net(botnet hosted in United States Henderson Trashy Media)
keshmoney.biz api.wipmania.com usakesh.biz heytherebitch.com these dns come from ngrbot exe to Remote Host Port Number 204.15.252.199 4042 NICK new[USA|XP|COMPUTERNAME]nrrkpsz USER hh “” “lol” :hh JOIN #chronic PONG 422 NICK new[USA|XP|COMPUTERNAME]hpfclbk USER y0 “” “lol” :y0 JOIN #usakesh PONG 422 UPDATE: PRIVMSG #boss :[HTTP]: Updated HTTP spread message to “haha, facebook photos? :p http://tinyurl.com/Pic-15-04-2011” JOIN #USRead more...
corp-200-105-228-106-uio.punto.net.ec(botnet hosted in Ecuador Quito Puntonet S.a)
Remote Host Port Number 200.105.228.106 8888 NICK inf444945 USER usrlsr 8 * : .: usrlsr :. JOIN #java PRIVMSG #java :GET / HTTP/1.0 Remote Host Port Number 200.105.228.106 8181 NICK bmi16146850 USER psdrman 8 * : .: psdrman :. JOIN #help PRIVMSG #help :Ready! File System Modifications * The following files were created in theRead more...