220.181.87.80( Trik v2.5 bot By snk Hosted in China Beijing Chinanet Beijing Province Network)

Thnx to Xylitol for sending me the first sample and helping to find more abt this botnet.
The net is probably more then 100k bots and u cant connect via mIRC, i dont know if u can with HexChat.
But here we are this time snk protected this bot with Steganos Live Encryption Engine.
snk was always a ddosing lamer but now he's into ransomware he's trying hard to join crim and other lamers in jail.

C:\Users\s\Desktop\Home\Code\Trik v2.5\Release\Trik.pdb  snk coding area lol.

Server : 220.181.87.80:5050

IRC Traffic :

>> NICK `|USA|XP|32|A|tefwonv
>> USER x "" "x" :x
>> PING 422 MOTD
<< 002 002
<< 003 003
<< 004 004
<< 005 005
<< 005 005
<< 005 005
>> JOIN #trik (null)
<< 332 `|USA|XP|32|A|tefwonv #trik :.j #t
<< 333 `|USA|XP|32|A|tefwonv #trik x 1462660625
>> PONG 422
>> JOIN #t (null)
<< 332 `|USA|XP|32|A|tefwonv #t :.d x |108|99|111|113|29|41|56|66|116|111|65|77|84|104|113|111|100|120|118|115|102|82|77|118|44|99|110|97|48|113|122|121|64|106|106|34|115|32|67|89|120|
<< 333 `|USA|XP|32|A|tefwonv #t x 1462806539
>> PING :x.x
>> PONG :x.x

Domains connected to this botnet :

"host5050.ru"
"host5051.ru"
"ouefuguefhuwuhs.ru"
"uwgfusubwbusswf.ru"
"oeuuguhwugfuuws.ru"

Samples :

sbox://www.combatnano.com.tw/img/s.exe
sbox://www.combatnano.com.tw/img/ss.exe
sbox://www.combatnano.com.tw/img/sss.exe
sbox://www.combatnano.com.tw/img/t8.exe
hxxp://davenportelectric.com/images/c.exe Cerber Ranswomware

Hosting Infos :
http://whois.domaintools.com/220.181.87.80


WisdomEyes(Hosted In Kazakhstan Almaty Ps Internet Company Llc)

Domain                                IP

ejug.bjksfohseaguu.org 185.22.65.81
ipecho.net                 146.255.36.1
rcelafy.bjksfohseaguu.org 185.22.65.81
plipjpuceco.bjksfohseaguu.org 185.22.65.81
uhewu.bjksfohseaguu.org 185.22.65.81
elqzujudynu.bjksfohseaguu.org 185.22.65.81
axonjcedep.bjksfohseaguu.org 185.22.65.81
wtfismyip.com 69.30.217.90
ydeji.bjksfohseaguu.org 185.22.65.81
ytarjrozi.bjksfohseaguu.org 185.22.65.81
sdyfigi.bjksfohseaguu.org 185.22.65.81
ycxjefssozo.bjksfohseaguu.org 185.22.65.81
wmizo.bjksfohseaguu.org 185.22.65.81
amozityxam.bjksfohseaguu.org 185.22.65.81
oxxh.bjksfohseaguu.org 185.22.65.81
ezizzhah.bjksfohseaguu.org 185.22.65.81
flefuxelbny.bjksfohseaguu.org 185.22.65.81
yvox.bjksfohseaguu.org 185.22.65.81
exipevi.bjksfohseaguu.org 185.22.65.81
udikufy.bjksfohseaguu.org 185.22.65.81
awele.bjksfohseaguu.org 185.22.65.81
ubevudotaso.bjksfohseaguu.org 185.22.65.81
isere.bjksfohseaguu.org 185.22.65.81
uxukaro.bjksfohseaguu.org 185.22.65.81
ulutyti.bjksfohseaguu.org 185.22.65.81
onusyha.bjksfohseaguu.org 185.22.65.81
asoti.bjksfohseaguu.org 185.22.65.81
rlatewuguh.bjksfohseaguu.org 185.22.65.81
uneqav.bjksfohseaguu.org 185.22.65.81
aryrihy.bjksfohseaguu.org 185.22.65.81
epyqak.bjksfohseaguu.org 185.22.65.81
assrowa.bjksfohseaguu.org 185.22.65.81
epasupk.bjksfohseaguu.org 185.22.65.81
ymazibuq.bjksfohseaguu.org 185.22.65.81
yjozywepyw.bjksfohseaguu.org 185.22.65.81
yxemir.bjksfohseaguu.org 185.22.65.81
ilazafeh.bjksfohseaguu.org 185.22.65.81
ekitvmoszg.bjksfohseaguu.org 185.22.65.81
ujgrewedu.bjksfohseaguu.org 185.22.65.81
ovefeqev.bjksfohseaguu.org 185.22.65.81
arus.bjksfohseaguu.org 185.22.65.81
ugiresisomu.bjksfohseaguu.org 185.22.65.81
eqyswf.bjksfohseaguu.org 185.22.65.81
adutymycyj.bjksfohseaguu.org 185.22.65.81
agltupitah.bjksfohseaguu.org 185.22.65.81
otekicopf.bjksfohseaguu.org 185.22.65.81
egizacyci.bjksfohseaguu.org 185.22.65.81
uhacajopixu.bjksfohseaguu.org 185.22.65.81
ujibomyp.bjksfohseaguu.org 185.22.65.81
ipecho.net 146.255.36.1
ahuvagiq.bjksfohseaguu.org 185.22.65.81
scoha.bjksfohseaguu.org 185.22.65.81
enokitehix.bjksfohseaguu.org 185.22.65.81
myexternalip.com 78.47.139.102
ewevrrepokp.bjksfohseaguu.org 185.22.65.81
tsewvkuhyr.bjksfohseaguu.org 185.22.65.81
ufgk.bjksfohseaguu.org 185.22.65.81
ehifygyror.bjksfohseaguu.org 185.22.65.81

Samples here : hxxp://194.58.40.121/hideme/

Hosting Infos :

http://whois.domaintools.com/185.22.65.81

avtobizz.ru(Locky Ransomware Hosted In Romania Craiova Nforce Entertainment B.v.)

Protected by cloudflare but not hard to find the hoster.

avtobizz.ru 104.31.89.136

Use hxxp://www.skypeipresolver.net/cloudflare.php to find the real ip.

Locky here is hosted by blazinfast.io

Logs from infected computers and samples here : hxxp://213.108.44.167/logiplya/

Hosting Infos :

http://whois.domaintools.com/185.11.145.10

serv6625.servep2p.com(Win32.Trojan.WisdomEyes Hosted In Colombia Bogota Unus Inc.)

Domain : serv6625.servep2p.com

Port : 6625

Sample : hxxp://107.170.8.163/dwn/winsys.exe

Hosting Infos :
http://whois.domaintools.com/128.90.115.105

myfirstdatibon.ru(UDS:DangerousObject.Multi.Generic)

Domain : myfirstdatibon.ru

domain:        MYFIRSTDATIBON.RU
nserver:       ns1.uldiok.at.
nserver:       ns2.uldiok.at.
nserver:       ns3.uldiok.at.
nserver:       ns4.uldiok.at.
state:         REGISTERED, NOT DELEGATED, UNVERIFIED
person:        Private Person
registrar:     ARDIS-RU
admin-contact: http://ardis.ru/whois/
created:       2016.02.20
paid-till:     2017.02.20
free-date:     2017.03.23
source:        TCI

Sample : hxxp://85.93.31.152/files/IeH4uk.exe

The rest of samples : hxxp://85.93.31.152/files/


Hosting Infos :
http://who.is/whois/myfirstdatibon.ru