89.248.172.240(30k botnet hosted in Netherlands Amsterdam Ecatel Ltd)

Botnet found by sPy.

Only server and port no channels here because no exe file to see for more.
Feel free to check for channels ur self.

Connecting to 89.248.172.240 (6667)

Invisible Users 12: 12 3554
Operators: 2 operator(s) online
Channels: 12 channels formed
Clients: I have 3555 clients and 0 servers
Local users: 3555 29989 Current local users 3555, max 29989
Global users: 3555 15450 Current global users 3555, max 15450

Hosting infos:
http://whois.domaintools.com/89.248.172.240

Linux Botnet Hosted In blackunix.us

This is the bot used to scan for vulnerabilities:
hxxp://pastebin.com/dEMULiQV

Now talking in #botnets
Topic On : [ #botnets ] [ hajar irc.predone.cz dan irc.drogs.pl ]
Topic By : [ uyap ]
Modes On : [ #botnets ] [ +smntrMuk fcuked ]

The Bot is hosted here hxxp://visionafricamagazine.com/scripts/x.log

onetimes27s.com(Reverse Dns Bot hosted in Russian Federation Saint Petersburg Majordomo Llc)



This package was posted in one hacking board as http bot.
After checking the file here results:

Domains used :

hoseen454r.com inactive
onetimes27s.com active

Resolved : [ onetimes27s.com ] To [ 178.250.245.186 ]

Panel:
hxxp://178.250.245.186/pref1/  password protected

Sample here

Hosting infos:
http://whois.domaintools.com/178.250.245.186


gki2mpdt3rsokbmv.onion (Irc botnet hosted on a Tor hidden service)

Server:  gki2mpdt3rsokbmv.onion
Port:  6667
Channel:  #channel

Oper:
[wac] (wac@9bedb2.host): ac
[wac] #channel
[wac] lair.hell.net :Cerberus Server
[wac] idle 00:00:18, signon: Tue May 13 18:24:47
[wac] End of WHOIS list.

The owner must have used very old bot code to create this, as it fails to work properly on windows 7 and higher.

Related md5s (Download sample from Malwr.com)
Ircbot: c94783e10995197f9177e6c72ae53e6a

sinsec.net (Betabot http botnet hosted by alibabahost.com)

Resolved sinsec.net to 37.221.170.96

Server:  sinsec.net
Gate file:  /turndown/order.php

Alternate domains:
divinestresser.info
radicalpkz.com
perp.pw
thefox.pw
uploadme.pw
perp.se

Domain info: sinsec.net
Domain Name: SINSEC.NET
Registry Domain ID: 1814650535_DOMAIN_NET-VRSN
Registrar WHOIS Server: whois.enom.com
Registrar URL: www.enom.com
Updated Date: 2013-07-12 10:27:24Z
Creation Date: 2013-07-12 17:27:00Z
Registrar Registration Expiration Date: 2014-07-12 17:27:00Z
Registrar: ENOM, INC.
Registrar IANA ID: 48
Registrar Abuse Contact Email: abuse@enom.com
Registrar Abuse Contact Phone: +1.4252744500
Reseller: NAMECHEAP.COM
Domain Status: ok
Registry Registrant ID: 
Registrant Name: WHOISGUARD PROTECTED
Registrant Organization: WHOISGUARD, INC.
Registrant Street: P.O. BOX 0823-03411
Registrant City: PANAMA
Registrant State/Province: PANAMA
Registrant Postal Code: NA
Registrant Country: PA
Registrant Phone: +507.8365503
Registrant Phone Ext: 
Registrant Fax: +51.17057182
Registrant Fax Ext:
Registrant Email: 073C843934E64FB380EF8B3AB027CCD1.PROTECT@WHOISGUARD.COM
Registry Admin ID: 
Admin Name: WHOISGUARD PROTECTED
Admin Organization: WHOISGUARD, INC.
Admin Street: P.O. BOX 0823-03411
Admin City: PANAMA
Admin State/Province: PANAMA
Admin Postal Code: NA
Admin Country: PA
Admin Phone: +507.8365503
Admin Phone Ext: 
Admin Fax: +51.17057182
Admin Fax Ext:
Admin Email: 073C843934E64FB380EF8B3AB027CCD1.PROTECT@WHOISGUARD.COM
Registry Tech ID: 
Tech Name: WHOISGUARD PROTECTED
Tech Organization: WHOISGUARD, INC.
Tech Street: P.O. BOX 0823-03411
Tech City: PANAMA
Tech State/Province: PANAMA
Tech Postal Code: NA
Tech Country: PA
Tech Phone: +507.8365503
Tech Phone Ext: 
Tech Fax: +51.17057182
Tech Fax Ext: 
Tech Email: 073C843934E64FB380EF8B3AB027CCD1.PROTECT@WHOISGUARD.COM
Name Server: RAY.NS.CLOUDFLARE.COM
Name Server: RUTH.NS.CLOUDFLARE.COM
DNSSEC: unSigned
URL of the ICANN WHOIS Data Problem Reporting System: http://wdprs.internic.net/
Last update of WHOIS database: 2013-07-12 10:27:24Z

Hosting info: 37.221.170.96
    

inetnum:        37.221.170.0 - 37.221.170.255
netname:        alibabahost
descr:          alibabahost
country:        RO
admin-c:        AM23273-RIPE
tech-c:         AM23273-RIPE
status:         ASSIGNED PA
mnt-by:         VOXILITY-MNT
source:         RIPE # Filtered
remarks:        INFRA -AW

person:         Anurag Mishra
address:        No:30,F2,Deccan Heritage ,ITI Layout, New BEL Road   ,Bangalore
address:        India
phone:          +919741887870
nic-hdl:        AM23273-RIPE
mnt-by:         VOXILITY-MNT
abuse-mailbox:  info@alibabahost.com
source:         RIPE # Filtered

route:          37.221.170.0/23
descr:          voxility.net
origin:         AS39743
mnt-by:         VOXILITY-MNT
source:         RIPE # Filtered

Related md5s (Download samples from Malwr.com)
Betabot: 4620d8a164ec31681a54b00a4bb9da7e