Remote Host Port Number 141.105.66.208 7654 PASS ngrBot 174.120.234.158 80 199.15.234.7 80 204.124.180.228 80 The data identified by the following URLs was then requested from the remote web server: http://panvalle.com/images/heater.pub.exe http://api.wipmania.com/ http://www.pompeya.gob.ec/includes/router.txt PRIVMSG #oldgold :[DNS]: Blocked 0 domain(s) – Redirected 49 domain(s) NICK n{US|XPa}buiwlhq USER buiwlhq 0 0 :buiwlhq JOIN #oldgold noKIDs JOIN #US PRIVMSGRead more...
212.7.214.130(irc botnet hosted in Netherlands Dediserv Dedicated Servers Sp. Z O.o)
Remote Host Port Number 212.7.214.130 2345 NICK New[USA|00|P|73920] PRIVMSG #!loco! :[M]: Thread Disabled. PRIVMSG #!loco! :[M]: Thread Activated: Sending Message With Email. USER XP-4958 * 0 :COMPUTERNAME MODE New[USA|00|P|73920] -ix JOIN #!loco! PONG 22 MOTD hosting infos: http://whois.domaintools.com/212.7.214.130
213.155.23.17(ngrBot hosted in Germany Bad Homburg Ghostnet Gmbh)
Remote Host Port Number 199.15.234.7 80 213.155.23.17 1865 PASS ngrBot NICK n{US|XPa}zjlmkun USER zjlmkun 0 0 :zjlmkun chanel:#main hosting infos: http://whois.domaintools.com/94.249.190.217
94.249.190.217(reptile bot hosted in Germany Bad Homburg Ghostnet Gmbh)
Remote Host Port Number 199.15.234.7 80 216.146.38.70 80 72.233.89.200 80 94.249.190.217 80 94.249.190.217 3108 PASS none NICK {iNF-00-USA-XP-COMP-0418} USER blaze * 0 :COMP PRIVMSG #AryaN :[AryaN]: Successfully Executed Process: “C:Documents and SettingsUserNameApplication Data90691630729786.exe” JOIN #rape nigger NICK {00-USA-XP-COMP-7768} PONG Gods.net PONG :Gods.net JOIN #AryaN none NICK New{US-XP-x86}5351008 USER 5351008 “” “5351008” :5351008 MODE New{US-XP-x86}5351008 +iMmRead more...
passeport-finances.biz(ngrBot hosted in France Paris Gandi)
Remote Host Port Number 199.15.234.7 80 92.243.18.75 5900 PASS ngrBot 92.243.5.149 3211 PASS ngrBot NICK n{US|XPa}bgepriu USER bgepriu 0 0 :bgepriu NICK n{US|XPa}jsifxwc USER jsifxwc 0 0 :jsifxwc hosting infos: http://whois.domaintools.com/92.243.18.75
olivares2006.noip.es(linux bots hosted in Panama Panama City Cali Internacional Overseas S.a)
Resolved : [olivares2006.noip.es] To [190.122.166.67] Remote Host Port Number 190.122.166.67 6667 NICK Linux[]320 NICK Linux[]895 NICK Linux[]822 NICK Linux[]746 NICK Linux[]174 NICK Linux[]858 NICK Linux[]710 NICK Linux[]513 NICK Linux[]303 NICK Linux[]14 NICK Linux[]91 USER Linux[]12 192.168.80.128 olivares2006.noip.es :Linux[]32 NICK Linux[]364 NICK Linux[]1 NICK Linux[]563 NICK Linux[]193 NICK Linux[]808 NICK Linux[]584 NICK Linux[]479 NICK Linux[]350 LocalRead more...
update.jebac.net(ngrBotnet hosted in Netherlands Amsterdam Dediserv Dedicated Servers Sp. Z O.o)
Resolved : [update.jebac.net] To [212.7.214.129] Resolved : [update.jebac.net] To [212.7.203.231] update.jebac.net 212.7.214.129 api.wipmania.com api.wipmania.com 199.15.234.7 data.fuskbugg.se data.fuskbugg.se 83.233.33.6 Download URLs http://199.15.234.7/ (api.wipmania.com) http://83.233.33.6/skalman02/4e28ae2064f07_av.txt (data.fuskbugg.se) C&C Server: 212.7.214.129:1866 Server Password: Username: jbxznyp Nickname: n{DE|XPa}jbxznyp Channel: #!hot! (Password: ngrBot) Channeltopic: :.http.int 3 .msn.int 2 .http.set omfg!!# LOL!#!* http://www.designthreadz.com/facebook-pic-#####-JPEG .msn.set lolol*!!# foto?!# http://www.designthreadz.com/facebook-pic-#####-JPEG .mdns http://data.fuskbugg.se/skalman02/4e28ae2064f07_av.txt -n Outgoing connectionRead more...
72.20.30.30(irc botnet hosted in United States Staminus Communications)
Remote Host Port Number 72.20.30.30 20 NICK NEW[XX][XP]9032364432 USER 9032 “” “TsGh” :9032 MODE NEW[XX][XP]9032364432 JOIN #galla PONG :irc.priv8net.com Now talking in #galla Topic On: [ #galla ] [ . ] Topic By: [ cakita ] NICK NEW[XX][XP]0445084461 USER 0445 “” “TsGh” :0445 MODE NEW[XX][XP]0445084461 JOIN #Mcl PONG :irc.priv8net.com hosting infos: http://whois.domaintools.com/72.20.30.30
irc.priv8.in(linux bots hosted in United States Network Operations Center Inc)
Resolved : [irc.priv8.in] To [96.9.170.253] my $processo = ‘[httpd]’; my $linas_max=’4′; my $sleep=’6′; my $cmd=”[PHP-SHELL]”; my $id=”http://www.cricermenate.it/id.txt?”; my @adms=(“chK_”); my @canais=(“#xcr3w”); my @nickname = (“xcR3w-“.int(rand(1-000))); my $nick = $nickname[rand scalar @nickname]; my $ircname =’xcr3w’; chop (my $realname = ‘bukan sesiapa’); $servidor=’irc.priv8.in’ unless $servidor; my $porta=’6667′; hosting infos: http://whois.domaintools.com/96.9.170.253
SpyEye Loader v1.3.41
From France with love another pwnage from Xylitol Found these samples into hecker’s ftp remember this is only for analysis purposes sorry i removed the builder for security purposes Download http://9598d5df.tubeviral.com