comegetrocked.servequake.com(ngrBot hosted in United States Palo Alto Amazon.com Inc)

comegetrocked.servequake.com DNS_TYPE_A 184.72.34.219

Remote Host Port Number
184.72.34.219 6667 PASS
184.72.34.219 80
199.15.234.7 80
199.27.135.43 80
50.16.211.169 80
67.212.77.12 80
66.74.69.200 4420

NICK n{US|XPa}tyhkmln
USER tyhkmln 0 0 :tyhkmln
PONG :37D21D0F
JOIN #fuck myass

* The data identified by the following URLs was then requested from the remote web server:
o http://comegetrocked.servequake.com/comune.php?logdata=Downloaded%20payload
o http://comegetrocked.servequake.com/comune.php?logdata=Executed%20payload
o http://comegetrocked.servequake.com/comune.php?logdata=Infected
o http://comegetrocked.servequake.com/comune.php?logdata=RAR%20archives%20infected
o http://api.wipmania.com/
o http://bshades.com/crypt/temp/3ivupxjavkv3pq9b
o http://bshades.com/crypt/temp/tpwfx8k4k5k22t9
o http://dl.dropbox.com/u/15672117/theboss.exe
o http://dl.dropbox.com/u/15672117/tpwfx8k4k5k22t9.exe
o http://dl.dropbox.com/u/15672117/msservice.exe
o http://dl.dropbox.com/u/15672117/vn4rb9pe2mq2fpn.exe
o http://dl.dropbox.com/u/15672117/poopstiff.exe
o http://dl.dropbox.com/u/15672117/nighthawk.exe
o http://dl.dropbox.com/u/15672117/aids.exe
o http://dl.dropbox.com/u/15672117/services.exe
o http://dl.dropbox.com/u/15672117/services.ex
o http://api.ipinfodb.com/v2/ip_query_country.php?key=1d1bb511aed00402daada8d8706f74b477e3172d0ca020deab3b43c16441a73d&timezone=off

hosting infos:
http://whois.domaintools.com/184.72.34.219

Categories: Uncategorized