220.181.87.80( Trik v2.5 bot By snk Hosted in China Beijing Chinanet Beijing Province Network)

Thnx to Xylitol for sending me the first sample and helping to find more abt this botnet.
The net is probably more then 100k bots and u cant connect via mIRC, i dont know if u can with HexChat.
But here we are this time snk protected this bot with Steganos Live Encryption Engine.
snk was always a ddosing lamer but now he's into ransomware he's trying hard to join crim and other lamers in jail.

C:\Users\s\Desktop\Home\Code\Trik v2.5\Release\Trik.pdb  snk coding area lol.

Server : 220.181.87.80:5050

IRC Traffic :

>> NICK `|USA|XP|32|A|tefwonv
>> USER x "" "x" :x
>> PING 422 MOTD
<< 002 002
<< 003 003
<< 004 004
<< 005 005
<< 005 005
<< 005 005
>> JOIN #trik (null)
<< 332 `|USA|XP|32|A|tefwonv #trik :.j #t
<< 333 `|USA|XP|32|A|tefwonv #trik x 1462660625
>> PONG 422
>> JOIN #t (null)
<< 332 `|USA|XP|32|A|tefwonv #t :.d x |108|99|111|113|29|41|56|66|116|111|65|77|84|104|113|111|100|120|118|115|102|82|77|118|44|99|110|97|48|113|122|121|64|106|106|34|115|32|67|89|120|
<< 333 `|USA|XP|32|A|tefwonv #t x 1462806539
>> PING :x.x
>> PONG :x.x

Domains connected to this botnet :

"host5050.ru"
"host5051.ru"
"ouefuguefhuwuhs.ru"
"uwgfusubwbusswf.ru"
"oeuuguhwugfuuws.ru"

Samples :

sbox://www.combatnano.com.tw/img/s.exe
sbox://www.combatnano.com.tw/img/ss.exe
sbox://www.combatnano.com.tw/img/sss.exe
sbox://www.combatnano.com.tw/img/t8.exe
hxxp://davenportelectric.com/images/c.exe Cerber Ranswomware

Hosting Infos :
http://whois.domaintools.com/220.181.87.80


3 comments:

Ian French said...

does the real bv1 know you're posting as him. why would you even want to do that

Post a Comment