Month: January 2011

nokia2mon2.markaz-royal.net(shellbooter hosted in Saudi Arabia Riyadh Dsl Home Subscribers_dynamic Ips)

Uncategorized

Remote Host Port Number 77.30.55.134 3086 Other details * The following port was open in the system: Port Protocol Process 1051 TCP svchost.exe (%AppData%Microsoftsvchost.exe) Registry Modifications * The following Registry Key was created: o HKEY_CURRENT_USERSoftwareeeptfs2 * The newly created Registry Values are: o [HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRun] + Startup = “%AppData%Microsoftsvchost.exe” so that svchost.exe runs every time WindowsRead more...

websiteex.com(botnet hosted in United States Chicago Hostforweb Inc)

Uncategorized

Remote Host Port Number 174.37.200.82 80 63.135.80.224 80 63.135.80.46 80 66.220.147.11 80 96.17.164.187 80 64.202.102.10 1234 PASS xxx MODE NEW-[USA|00|P|42884] -ix JOIN #!nn! test PONG 22 MOTD NICK NEW-[USA|00|P|42884] USER XP-9086 * 0 :COMPUTERNAME infos about hosting: http://whois.domaintools.com/64.202.102.10

cancanmt2.no-ip.biz(RAT hosted in Turkey Antalya Tt Adsl-ttnet-ulus-static)

Uncategorized

cancanmt2.no-ip.biz: type A, class IN, addr 95.9.90.39 Dest Port:100 Summary Creates temporary files Queries a list of all running processes Performs DNS lookups Enables debug privileges Creates files inside the system directory Loads the internet automation component (ieframe.dll) Creates an autostart registry key Checks for debuggers (Devices) Creates a thread in another existing process (threadRead more...

static-70-107-249-167.ny325.east.verizon.net(botnet hosted in United States Whitestone Verizon Online Llc)

Uncategorized

Remote Host Port Number 70.107.249.167 7000 NICK GL983668621949 USER mioubypigigz 0 0 :GL983668621949 MODE GL286772458982 +i JOIN #GL .x. USERHOST GL286772458982 USERHOST GL983668621949 MODE GL983668621949 +i NICK GL286772458982 USER xbjpsqcwhywo 0 0 :GL286772458982 Now talking in #GL Topic On: [ #GL ] [ .advscan asn1smbnt 100 5 0 -b -r -s ] Topic By: [Read more...

apple.com(botnet hosted in United States Crystal River Ispsystem At Nac)

Uncategorized

Remote Host Port Number 82.146.51.121 6667 Invisible Users: 422 Operators: 9 operator(s) online Channels: 18 channels formed Clients: I have 423 clients and 0 servers Local users: Current Local Users: 423 Max: 613 Global users: Current Global Users: 423 Max: 613 NICK {N}|USA|XP|COMPUTERNAME|054249 USER syadpo “” “kjhx” :COMPUTERNAME JOIN #meelisv PRIVMSG #meelisv :New Servant. infosRead more...