mypanelftp.co.cc mypanelftp.co.cc 91.215.170.45 Opened listening TCP connection on port: 27217Download URLs http://91.215.170.45/banner.tif (mypanelftp.co.cc) Data posted to URLs http://91.215.170.45/vorota.php (mypanelftp.co.cc) Outgoing connection to remote server: mypanelftp.co.cc TCP port 80 Outgoing connection to remote server: mypanelftp.co.cc TCP port 80 Outgoing connection to remote server: mypanelftp.co.cc TCP port 80 Outgoing connection to remote server: mypanelftp.co.cc TCP port 80Read more...
www.claudia-ferrer.com
www.claudia-ferrer.com 200.98.197.72 Download URLs http://200.98.197.72/site/javawhelper.jpg (www.claudia-ferrer.com) http://200.98.197.72/site/huntermails.jpg (www.claudia-ferrer.com) http://200.98.197.72/site/msgnlive.jpg (www.claudia-ferrer.com) Outgoing connection to remote server: www.claudia-ferrer.com TCP port 80 Outgoing connection to remote server: www.claudia-ferrer.com TCP port 80 Outgoing connection to remote server: www.claudia-ferrer.com TCP port 80 Registry Changes by all processes Create or Open Changes HKEY_LOCAL_MACHINESOFTWAREClassesCLSID{ECA9A748-EC22-4405-9F94-19CADCD27081} “” = HKEY_LOCAL_MACHINESOFTWAREClassesCLSID{ECA9A748-EC22-4405-9F94-19CADCD27081}InprocServer32 “” = C:WINDOWSsystem32javawhelper.dll HKEY_LOCAL_MACHINESOFTWAREClassesCLSID{ECA9A748-EC22-4405-9F94-19CADCD27081}InprocServer32 “ThreadingModel”Read more...
akgjsudim.com
akgjsudim.com 195.226.220.123 Data posted to URLs http://195.226.220.123/t0.php (akgjsudim.com) Outgoing connection to remote server: akgjsudim.com TCP port 80 Registry Changes by all processes Create or Open Changes Reads HKEY_LOCAL_MACHINESOFTWAREMicrosoftCTFSystemShared “CUAS” HKEY_CURRENT_USERKeyboard LayoutToggle “Language Hotkey” HKEY_CURRENT_USERKeyboard LayoutToggle “Layout Hotkey” HKEY_LOCAL_MACHINESOFTWAREMicrosoftCTF “EnableAnchorContext” HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionApp PathsIEXPLORE.EXE “” HKEY_LOCAL_MACHINESOFTWAREMicrosoftInternet ExplorerSetup “IExploreLastModifiedLow” HKEY_LOCAL_MACHINESOFTWAREMicrosoftInternet ExplorerSetup “IExploreLastModifiedHigh” HKEY_LOCAL_MACHINESOFTWAREClassesInterface{EAB22AC1-30C1-11CF-A7EB-0000C05BAE0B}TypeLib “” HKEY_LOCAL_MACHINESOFTWAREClassesInterface{B722BCCB-4E68-101B-A2BC-00AA00404770}ProxyStubClsid32 “” HKEY_LOCAL_MACHINESOFTWAREClassesInterface{79EAC9C4-BAF9-11CE-8C82-00AA004BA90B}ProxyStubClsid32 “” HKEY_LOCAL_MACHINESOFTWAREClassesInterface{000214E6-0000-0000-C000-000000000046}ProxyStubClsid32Read more...
alpha1.fortalezahost.com(IM worm)
205.234.138.152:2345 Nick: NEW-[AUT|00|P|88830] Username: XP-8003 Server Pass: xxx Joined Channel: #!gf! with Password test Channel Topic for Channel #!gf!: “d http://lmysapace.net/profile.php?=” Private Message to User NEW-[AUT|00|P|88830]: “.s.p http://domredi.com/1/” Channel Topic for Channel #!gf!: “D http://facellbook.net/profile.php?=” Private Message to User NEW-[AUT|00|P|01785]: “.s.p http://domredi.com/1/”
210.170.62.115(IM worm)
Remote Host Port Number 204.0.5.35 80 204.0.5.40 80 204.0.5.42 80 204.0.5.51 80 204.0.5.58 80 204.0.5.59 80 207.38.101.12 80 208.43.117.134 80 216.178.38.103 80 216.178.38.168 80 210.170.62.115 2345 PASS xxx NICK NEW-[USA|00|P|39876] USER XP-0115 * 0 :COMPUTERNAME MODE NEW-[USA|00|P|39876] -ix JOIN #!gf! test PONG 22 MOTD * The data identified by the following URLs was then requestedRead more...
davidserverrat.no-ip.biz
davidserverrat.no-ip.biz 70.161.219.229 Outgoing connection to remote server: davidserverrat.no-ip.biz TCP port 5555
f19dd4abb8b8bdf2.cn
us.cnn.com 157.166.255.19 f19dd4abb8b8bdf2.cn 194.0.245.66 us.cnn.com 157.166.255.18 Download URLs http://157.166.255.19/ (us.cnn.com) http://157.166.255.18/ (us.cnn.com) Outgoing connection to remote server: us.cnn.com TCP port 80 Outgoing connection to remote server: f19dd4abb8b8bdf2.cn TCP port 80 Outgoing connection to remote server: f19dd4abb8b8bdf2.cn TCP port 80 Outgoing connection to remote server: us.cnn.com TCP port 80 Outgoing connection to remote server: f19dd4abb8b8bdf2.cn TCPRead more...
prmifgfgd.dnsdojo.org(banking malware)
prmifgfgd.dnsdojo.org 222.66.209.98 222.66.209.98 UDP Connections Remote IP Address: 127.0.0.1 Port: 1049 Send Datagram: 7 packet(s) of size 1 Recv Datagram: 7 packet(s) of size 1 Download URLs http://222.66.209.98/netanalyst/images/readme.txt (222.66.209.98) Data posted to URLs http://212.189.144.121/c/job.php () Outgoing connection to remote server: 212.189.144.121 TCP port 80 Outgoing connection to remote server: 222.66.209.98 TCP port 80 Registry ChangesRead more...
178.211.53.6
Remote Host Port Number 178.211.53.6 9595 PASS prison 72.233.89.199 80 91.198.22.71 80 PONG leaf.35204.com NICK {iNF-00-USA-XP-COMP-6996} USER MEAT * 0 :COMP JOIN ###mini NICK {00-USA-XP-COMP-5663} Now talking in ###mini Topic On: [ ###mini ] [ .banner ] Topic By: [ pe[ro ] Modes On: [ ###mini ] [ +smntu ] Other details * The followingRead more...
reportaboutbosn.com
reportaboutbosn.com 91.217.162.174 UDP Connections Remote IP Address: 127.0.0.1 Port: 1043 Send Datagram: 2 packet(s) of size 1 Recv Datagram: 2 packet(s) of size 1 Download URLs http://91.217.162.174/inst.php?id=abs_01 (reportaboutbosn.com) Outgoing connection to remote server: reportaboutbosn.com TCP port 80 Registry Changes by all processes Create or Open Changes HKEY_CURRENT_USERSoftwareMicrosoftWindows NTCurrentVersionWinlogon “Shell” = C:Dokumente und EinstellungenAdministratorAnwendungsdatenhotfix.exe HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionInternet SettingsRead more...