213.239.195.4(irc botnet hosted in Germany Gunzenhausen Hetzner Online Ag)

Uncategorized

Remote Host Port Number 213.239.195.4 2345 MODE New[USA|00|P|46215] -ix PRIVMSG #!loco! :[M]: Thread Disabled. PRIVMSG #!loco! :[M]: Thread Activated: Sending Message With Email. JOIN #!loco! PONG 22 MOTD Channel Topic for Channel #!loco!: “.m.s|.m.e ehaha foto http://goo.gl/ymh4i?=” Private Message to Channel #!loco!: “[M]: Thread Activated: Sending Message With Email.” Private Message to Channel #!loco!: “[M]:Read more...

61.31.99.67(irc botnet hosted in Taiwan Taipei Taiwan Fixed Network Co. Ltd)

Uncategorized

Remote Host Port Number 173.255.237.110 80 199.15.234.7 80 76.73.3.162 80 61.31.99.67 1863 PASS boss 61.31.99.67 4042 PASS boss NICK [USA|00||324811] USER xp-2815 * 0 :COMPUTERNAME MODE [USA|00||324811] -ix JOIN #new PRIVMSG #new : Now talking in #new Topic On: [ #new ] [ ] Topic By: [ chk ] hosting infos: http://whois.domaintools.com/61.31.99.67

c4t3ring.info(ngrBot hosted in United States Herndon Road Runner Holdco Llc)

Uncategorized

Domains used to control bots: pedoapestoso.info not active c4t3ring.info ramen4all.info Resolved : [c4t3ring.info] To [74.62.152.211] Resolved : [ramen4all.info] To [74.62.152.211] c4t3ring.info:6161 Botnet server here ramen4all.info:6161 Botnet server here Clients: I have 247 clients and 0 servers Local users: Current Local Users: 247 Max: 1261 Global users: Current Global Users: 247 Max: 280 PASS p3p1n0 NICKRead more...

rlz1lola.info(ngrBot hosted in Germany Hetzner Online Ag)

Uncategorized

Large ngrBot server hosted in Germany Here u have strings from 2 executable samples 30upjmrlzz.exe Processes: PID ParentPID User Path -------------------------------------------------- 2872 1236 C:Documents and SettingsMes documents30upjmrlzz.exe Ports: Port PID Type Path -------------------------------------------------- Explorer Dlls: DLL Path Company Name File Description -------------------------------------------------- No changes Found IE Dlls: DLL Path Company Name File Description -------------------------------------------------- NoRead more...

pool.dload.asia(Bitcoin Miner Botnet hosted in France Paris Gandi)

Uncategorized

Very big net here the gay behind the net is making alot of money from infected machines Resolved : [pool.dload.asia] To [95.142.174.210] Resolved : [pool.dload.asia] To [92.243.3.252] Resolved : [pool.dload.asia] To [95.142.175.27] Resolved : [pool.dload.asia] To [95.142.161.74] Resolved : [pool.dload.asia] To [95.142.174.205] Resolved : [pool.dload.asia] To [95.142.170.142] Resolved : [pool.dload.asia] To [95.142.174.64] Resolved : [pool.dload.asia]Read more...