Author: Pig

mypanelftp.co.cc

Uncategorized

mypanelftp.co.cc mypanelftp.co.cc 91.215.170.45 Opened listening TCP connection on port: 27217Download URLs http://91.215.170.45/banner.tif (mypanelftp.co.cc) Data posted to URLs http://91.215.170.45/vorota.php (mypanelftp.co.cc) Outgoing connection to remote server: mypanelftp.co.cc TCP port 80 Outgoing connection to remote server: mypanelftp.co.cc TCP port 80 Outgoing connection to remote server: mypanelftp.co.cc TCP port 80 Outgoing connection to remote server: mypanelftp.co.cc TCP port 80Read more...

www.claudia-ferrer.com

Uncategorized

www.claudia-ferrer.com 200.98.197.72 Download URLs http://200.98.197.72/site/javawhelper.jpg (www.claudia-ferrer.com) http://200.98.197.72/site/huntermails.jpg (www.claudia-ferrer.com) http://200.98.197.72/site/msgnlive.jpg (www.claudia-ferrer.com) Outgoing connection to remote server: www.claudia-ferrer.com TCP port 80 Outgoing connection to remote server: www.claudia-ferrer.com TCP port 80 Outgoing connection to remote server: www.claudia-ferrer.com TCP port 80 Registry Changes by all processes Create or Open Changes HKEY_LOCAL_MACHINESOFTWAREClassesCLSID{ECA9A748-EC22-4405-9F94-19CADCD27081} “” = HKEY_LOCAL_MACHINESOFTWAREClassesCLSID{ECA9A748-EC22-4405-9F94-19CADCD27081}InprocServer32 “” = C:WINDOWSsystem32javawhelper.dll HKEY_LOCAL_MACHINESOFTWAREClassesCLSID{ECA9A748-EC22-4405-9F94-19CADCD27081}InprocServer32 “ThreadingModel”Read more...

akgjsudim.com

Uncategorized

akgjsudim.com 195.226.220.123 Data posted to URLs http://195.226.220.123/t0.php (akgjsudim.com) Outgoing connection to remote server: akgjsudim.com TCP port 80 Registry Changes by all processes Create or Open Changes Reads HKEY_LOCAL_MACHINESOFTWAREMicrosoftCTFSystemShared “CUAS” HKEY_CURRENT_USERKeyboard LayoutToggle “Language Hotkey” HKEY_CURRENT_USERKeyboard LayoutToggle “Layout Hotkey” HKEY_LOCAL_MACHINESOFTWAREMicrosoftCTF “EnableAnchorContext” HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionApp PathsIEXPLORE.EXE “” HKEY_LOCAL_MACHINESOFTWAREMicrosoftInternet ExplorerSetup “IExploreLastModifiedLow” HKEY_LOCAL_MACHINESOFTWAREMicrosoftInternet ExplorerSetup “IExploreLastModifiedHigh” HKEY_LOCAL_MACHINESOFTWAREClassesInterface{EAB22AC1-30C1-11CF-A7EB-0000C05BAE0B}TypeLib “” HKEY_LOCAL_MACHINESOFTWAREClassesInterface{B722BCCB-4E68-101B-A2BC-00AA00404770}ProxyStubClsid32 “” HKEY_LOCAL_MACHINESOFTWAREClassesInterface{79EAC9C4-BAF9-11CE-8C82-00AA004BA90B}ProxyStubClsid32 “” HKEY_LOCAL_MACHINESOFTWAREClassesInterface{000214E6-0000-0000-C000-000000000046}ProxyStubClsid32Read more...

alpha1.fortalezahost.com(IM worm)

Uncategorized

205.234.138.152:2345 Nick: NEW-[AUT|00|P|88830] Username: XP-8003 Server Pass: xxx Joined Channel: #!gf! with Password test Channel Topic for Channel #!gf!: “d http://lmysapace.net/profile.php?=” Private Message to User NEW-[AUT|00|P|88830]: “.s.p http://domredi.com/1/” Channel Topic for Channel #!gf!: “D http://facellbook.net/profile.php?=” Private Message to User NEW-[AUT|00|P|01785]: “.s.p http://domredi.com/1/”

210.170.62.115(IM worm)

Uncategorized

Remote Host Port Number 204.0.5.35 80 204.0.5.40 80 204.0.5.42 80 204.0.5.51 80 204.0.5.58 80 204.0.5.59 80 207.38.101.12 80 208.43.117.134 80 216.178.38.103 80 216.178.38.168 80 210.170.62.115 2345 PASS xxx NICK NEW-[USA|00|P|39876] USER XP-0115 * 0 :COMPUTERNAME MODE NEW-[USA|00|P|39876] -ix JOIN #!gf! test PONG 22 MOTD * The data identified by the following URLs was then requestedRead more...

f19dd4abb8b8bdf2.cn

Uncategorized

us.cnn.com 157.166.255.19 f19dd4abb8b8bdf2.cn 194.0.245.66 us.cnn.com 157.166.255.18 Download URLs http://157.166.255.19/ (us.cnn.com) http://157.166.255.18/ (us.cnn.com) Outgoing connection to remote server: us.cnn.com TCP port 80 Outgoing connection to remote server: f19dd4abb8b8bdf2.cn TCP port 80 Outgoing connection to remote server: f19dd4abb8b8bdf2.cn TCP port 80 Outgoing connection to remote server: us.cnn.com TCP port 80 Outgoing connection to remote server: f19dd4abb8b8bdf2.cn TCPRead more...

prmifgfgd.dnsdojo.org(banking malware)

Uncategorized

prmifgfgd.dnsdojo.org 222.66.209.98 222.66.209.98 UDP Connections Remote IP Address: 127.0.0.1 Port: 1049 Send Datagram: 7 packet(s) of size 1 Recv Datagram: 7 packet(s) of size 1 Download URLs http://222.66.209.98/netanalyst/images/readme.txt (222.66.209.98) Data posted to URLs http://212.189.144.121/c/job.php () Outgoing connection to remote server: 212.189.144.121 TCP port 80 Outgoing connection to remote server: 222.66.209.98 TCP port 80 Registry ChangesRead more...

178.211.53.6

Uncategorized

Remote Host Port Number 178.211.53.6 9595 PASS prison 72.233.89.199 80 91.198.22.71 80 PONG leaf.35204.com NICK {iNF-00-USA-XP-COMP-6996} USER MEAT * 0 :COMP JOIN ###mini NICK {00-USA-XP-COMP-5663} Now talking in ###mini Topic On: [ ###mini ] [ .banner ] Topic By: [ pe[ro ] Modes On: [ ###mini ] [ +smntu ] Other details * The followingRead more...

reportaboutbosn.com

Uncategorized

reportaboutbosn.com 91.217.162.174 UDP Connections Remote IP Address: 127.0.0.1 Port: 1043 Send Datagram: 2 packet(s) of size 1 Recv Datagram: 2 packet(s) of size 1 Download URLs http://91.217.162.174/inst.php?id=abs_01 (reportaboutbosn.com) Outgoing connection to remote server: reportaboutbosn.com TCP port 80 Registry Changes by all processes Create or Open Changes HKEY_CURRENT_USERSoftwareMicrosoftWindows NTCurrentVersionWinlogon “Shell” = C:Dokumente und EinstellungenAdministratorAnwendungsdatenhotfix.exe HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionInternet SettingsRead more...