W32.Spacefam(malware hosted in Latvia Users)

Uncategorized

Remote Host Port Number 46.252.131.8 80 The data identified by the following URLs was then requested from the remote web server: http://ddk100.com/v3/setup.php?act=fb_get http://ddk100.com/v3/setup.php?act=fb_start&id=Se7bwTG6pzBi2DpYW5Sw8vtv exe file: http://49005903.tinylinks.co infos about hosting: http://whois.domaintools.com/46.252.131.8

63.223.127.191(around 1700 linux bots hosted in United States Seattle Sentris Network Llc)

Uncategorized

var $config = array(“server”=>”63.223.127.191”, “port”=>”6667”, “pass”=>”nuvoletta”, “prefix”=>”DooS|”, “maxrand”=>”4”, “chan”=>”#php”, “chan2″=>”#php”, “key”=>”coglione”, “modes”=>”+iwx”, “password”=>”nuvoletta”, “trigger”=>”.”, “hostauth”=>”*” // Current Local Users: 501 Max: 1747 Current Global Users: 978 Max: 1669 infos about hosting: http://whois.domaintools.com/63.223.127.191

forwardmotionconcepts.com(SpyEye banking trojan hosted in United States Dallas Softlayer Technologies Inc)

Uncategorized

Remote Host Port Number 173.192.41.194 80 The data identified by the following URL was then requested from the remote web server: http://forwardmotionconcepts.com/wip5/main/gate.php?guid=UserName!COMPUTERNAME!00CD1A40&ver=10299&stat=ONLINE&ie=6.0.2900.2180&os=5.1.2600&ut=Admin&plg=billinghammer;creditgrab;ftpbc;socks5;USBSpread&cpu=100&ccrc=0D98E50E&md5=fc5531793ca5bebd917e6ef85d709272 SpyEye Panel: http://forwardmotionconcepts.com/wip5/main/ exe file: http://9d0a7f4d.tinylinks.co infos about hosting: http://whois.domaintools.com/173.192.41.194

twtw.toh.info(chinese malware hosted in Hong Kong Nwt Idc Data Service)

Uncategorized

Name Query Type Query Result Successful Protocol twtw.toh.info DNS_TYPE_A 58.64.203.53 YES udp – Unknown TCP Traffic: 58.64.203.53:443 State: Connection established, not terminated – Transferred outbound Bytes: 672 – Transferred inbound Bytes: 14657 Data sent: exe file: http://a3dc4d85.theseblogs.com infos about hosting: http://whois.domaintools.com/58.64.203.53

one.123back.com(botnet hosted in Lithuania Webhosting Collocation Services)

Uncategorized

Remote Host Port Number 77.79.6.83 6667 NICK [XP-5771910] NOTICE [XP-5771910] : PING 1303048457 PRIVMSG [XP-5771910] : PING 1303048487 PING 1303048519 USER Tulkarm “” “one.123back.com” :Crack GT [Evolution] -=- Version 4.1 USERHOST [XP-5771910] MODE #Chats NICK :i386[XP]25677 MODE [XP-5771910] +i-x JOIN #KSA# coded.v MODE #KSA# UPDATE: Remote Host Port Number 77.79.6.83 1863 NICK |NeW|-{USA-XP|594283} USER 5942Read more...