Author: Pig

68.53.67.92(ngrBot hosted in United States Murfreesboro Comcast Cable Communications Inc)

Uncategorized

Remote Host Port Number 199.15.234.7 80 68.53.67.92 6667 PASS .. NICK n{US|XPa}uqslazq USER uqslazq 0 0 :uqslazq PONG :9D3E1772 JOIN #!hot ngrBot Now talking in #!hot Topic On: [ #!hot ] [ !mdns http://data.fuskbugg.se/skalman02/4e28ae2064f07_av.txt -n ] Topic By: [ qwerty ] Modes On: [ #!hot ] [ +smntMu ] Quits: qwerty [qwerty@netadmin.ownage.net] (Quit:) heckers inside:Read more...

109.68.191.168(ngrBot hosted in Russian Federation Moscow Jsc Tel Company)

Uncategorized

Remote Host Port Number 109.68.191.168 7654 PASS ngrBot 199.15.234.7 80 74.52.121.37 80 NICK n{US|XPa}woqkvpd USER woqkvpd 0 0 :woqkvpd JOIN #oldgold noKIDs JOIN #US PRIVMSG #oldgold :[d=”http://muralihostal.com/clientes/fu66.exe” s=”7455 bytes”] Update error: MD5 mismatch (5B6D6ED8BFC9B90BF020566BED59FB14 != 00bbd4ef64ffca28833b1d173b29c3e6) * The data identified by the following URLs was then requested from the remote web server: o http://api.wipmania.com/ oRead more...

109.68.191.185(ngrBot hosted in Russian Federation Moscow Jsc Tel Company)

Uncategorized

Remote Host Port Number 109.68.191.185 7777 PASS laekin0505x 199.115.229.189 80 199.15.234.7 80 NICK n{US|XPa}lwndarv USER lwndarv 0 0 :lwndarv JOIN #totalrenovation2011 ngrBot PRIVMSG #totalrenovation2011 :[d=”http://juazjuaz.com/cipha.exe” s=”114688 bytes”] Executed file “C:Documents and SettingsUserNameApplication Data1.exe” – Download retries: 0 PRIVMSG #totalrenovation2011 :[d=”http://juazjuaz.com/Winsoft.exe” s=”167936 bytes”] Updated bot file “C:Documents and SettingsUserNameApplication DataMcxaxm.exe” – Download retries: 0 * TheRead more...

Trojan.Win32.Jorik.Zbot.vf(hosted in Lithuania Siauliai Splius Uab)

Uncategorized

HTTP malware spreading through networks know as palevo worm exe files: http://fa715921.urlbeat.net http://b7b0380e.goneviral.com config file: http://04ed4837.tubeviral.com Bot panel used to control zombies: Download panel: http://cec3f665.ultrafiles.net http://8b47fd59.tinylinks.co virustotal scan: 4 /43 (9.3%) http://www.virustotal.com/file-scan/report.html?id=31cf7e82afe834189765aadb4d3b057c8a5bdbafd0236ac3717945de644ea134-1319067167

ng.albanianetwork.com(ngrBot hosted in Netherlands Amsterdam Ecatel Ltd)

Uncategorized

Real heckers and very hard to know from where lamers belong(look at domain name) ng.albanianetwork.com 89.248.168.87 api.wipmania.com api.wipmania.com 199.15.234.7 gn.albacrew.com 89.248.168.87 Download URLs http://199.15.234.7/ (api.wipmania.com) Outgoing connection to remote server: ng.albanianetwork.com TCP port 6869 Outgoing connection to remote server: api.wipmania.com TCP port 80 Outgoing connection to remote server: ng.albanianetwork.com TCP port 9731 Outgoing connection toRead more...