Tag: citadel

sisisu.su (Citadel banking malware hosted by he.net)

Uncategorized

Resolved sisisu.su to 64.62.210.103 Server:  sisisu.su Config file:  /wheelbarrow/file.php Gate file:  /wheelbarrow/prism.php Currently being downloaded by this betabot. This is his second attempt at a citadel net, the first one can be found here. Hosting infos: http://whois.domaintools.com/64.62.210.103 Related md5s (search on malwr.com to download the samples): Citadel: 5707e28e79f6b6d469874f8b87ecb3b9  Edit: The moron forgot to remove theRead more...

64.85.233.8 (Citadel banking malware hosted by home ip?)

Uncategorized

Server:   64.85.233.8 Config file:  /hide/1355/file.php Gate file:  /hide/1355/enter.php According to whois, this is a home cable internet ip (United States Concord Astound Broadband). Also on the server, smoke loader and pony Smoke Server:  64.85.233.8 Gate file:  /smokeldr/index.php Pony Server:  64.85.233.8 Gate file:  /js/gate.php The moron running this has Pony downloading itself, creating a continuousRead more...

betabros.in (Several http botnets hosted by hostkey.ru)

Uncategorized

Resolved betabros.in to 146.0.78.4 Server:  betabros.in Gate file:  /beta/order.php The owner should keep a closer eye on the fake forum he setup for cover. 1071 pages of pharmacy spam and counting. Hosting infos: http://whois.domaintools.com/146.0.78.4 EDIT: Bitcoin and litecoin mining. macromedia.exe -a scrypt -o http://us.litecoinpool.org:9332 -u marvid.disfig -p x shell.exe -o stratum+tcp://stratum.btcguild.com:3333 -u vapor_3 -p xRead more...

googlesafebrowsing-counter.org (Citadel banking malware hosted by Fastflux botnet)

Uncategorized

Server:  googlesafebrowsing-counter.org Config dropper:  /file.php The server seems to be poorly configured and it never returns a config file. Backup domain:  googlesafebrowsing-cache.org Example fastflux info ;; QUESTION SECTION: ;googlesafebrowsing-counter.org. IN A ;; ANSWER SECTION: googlesafebrowsing-counter.org. 150 IN A 94.158.73.89 googlesafebrowsing-counter.org. 150 IN A 94.230.198.162 googlesafebrowsing-counter.org. 150 IN A 99.231.159.61 googlesafebrowsing-counter.org. 150 IN A 176.8.252.213 googlesafebrowsing-counter.org.Read more...