Author: Pig

xxlaa.com(ngrBot hosted in Russian Federation Selectel Ltd)

Uncategorized

My estimation for this botnet size is 30-50k aproximatly Domains used to control bots: xxlaa.com active Sabukenke.com not active Alufina.com not activ xxlss.com not active xxlcc.com not active Resolved : [xxlaa.com] To [31.186.102.170] C&C Server: 222.187.221.243:7777 PASS laekin0505x Server Password: Username: ynuvlog Nickname: n{DE|XPa}ynuvlog Channel: (Password: ) Channeltopic: C&C Server: 31.186.102.170:7777 PASS laekin0505x Server Password:Read more...

188.138.84.90(ngrBot hosted in Germany Intergenia Ag)

Uncategorized

Remote Host Port Number 188.138.84.90 9996 PASS .. 199.15.234.7 80 NICK n{US|XPa}ehftjhj USER ehftjhj 0 0 :ehftjhj PONG :34405528 JOIN #Bots ngrBot PRIVMSG #Bots :[HTTP]: Updated HTTP spread message to “http://www.twom-pc.com” Now talking in #Bots Topic On: [ #Bots ] [ !http.set http://www.twom-pc.com ] Topic By: [ Juicers2 ] Modes On: [ #Bots ] [Read more...

elperro23.net(ngrBot hosted in United States Seattle Dme Hosting Llc)

Uncategorized

Domains used to control bots: elperro23.net elperro3.net Resolved : [elperro23.net] To [74.221.210.169] Remote Host Port Number 199.15.234.7 80 217.160.124.219 80 74.221.210.169 5236 PASS ROCKR PRIVMSG #rockspread :[HTTP]: Updated HTTP spread message to “Mira esta postal de amor q me enviaron http://www.anrodphoto.com/entretenimiento.terra.com/postaldeamor esta muy linda :)” PRIVMSG #ROCK :[DNS]: Blocked 0 domain(s) – Redirected 20 domain(s)Read more...

paradoxnet.ru(SpyEye v1.3 hosted in Ukraine Lugansk Fop Opria Ruslan Dmitrievich)

Uncategorized

Now alot of idiots are using spyeye here is the example SpyEye Panels http://sna.paradoxnet.ru/spy/gate.php http://paradoxnet.ru/spy/gate.php SpyEye Directory Back-connect server SpyEye Collector v0.3.9 SpyEye Collector v0.3.9 configuration file SpyEye Collector v0.3.9 sql tables Formgraber panel SpyEye Gate Installer Picture1 Picture2 SpyEye Control Panel u can also have the full SpyEye installer from this panel the problemRead more...

lookshit.info(irc botnet hosted in Netherlands Amsterdam Ecatel Ltd)

Uncategorized

Resolved : [lookshit.info] To [80.82.65.96] Remote Host Port Number 80.82.65.96 65485 PASS biology Local users: Current Local Users: 390 Max: 418 Global users: Current Global Users: 390 Max: 418 USER bot 0 * : Merqy[UserName@COMPUTERNAME] NICK [wXP|EN|53124|M] JOIN #Merqy s3xy 89 bots inside JOIN #Merqy.EN s3xy 37 bots inside hosting infos: http://whois.domaintools.com/80.82.65.96