Month: January 2012

xL.x1x2.in(ngrBot hosted in France Paris Gandi)

Uncategorized

Resolved : [xL.x1x2.in] To [95.142.167.131]port 4949 for irc Resolved : [xL.x1x2.in] To [95.142.166.253]port 4949 for irc Resolved : [xL.x1x2.in] To [92.243.15.137]port 4949 for irc Resolved : [xL.x1x2.in] To [103.1.184.45]port 4949 for irc Remote Host Port Number 176.9.42.247 8332 Bitcoin Malware 199.15.234.7 80 199.7.176.144 80 199.7.177.228 80 74.120.10.153 80 74.120.8.161 80 95.142.167.131 4949 irc port (beforeRead more...

118.69.220.81(irc botnet hosted in Viet Nam Ip Range For Xdsl Iptv Fixed Phone Service At Hcmc)

Uncategorized

Remote Host Port Number 118.69.220.81 6667 PASS weed Clients: I have 110 clients and 0 servers Local users: Current Local Users: 110 Max: 115 Global users: Current Global Users: 110 Max: 115 MODE [00|USA|XP|SP2]-8799 +x JOIN ##vam## vampir123 USERHOST [00|USA|XP|SP2]-8799 PONG :Vampir.hack-mx.ru.net NICK [00|USA|XP|SP2]-8799 USER pmlai 0 0 :[00|USA|XP|SP2]-8799 hosting infos: http://whois.domaintools.com/118.69.220.81

205.234.187.241(irc botnet hosted in United States Chicago Hostforweb Inc)

Uncategorized

205.234.187.241:2345 Nick: New[AUT|00|P|64491] Username: XP-9383 Joined Channel: #!loco! Channel Topic for Channel #!loco!: “.m.s|.m.e Foto http://goo.gl/TYFFS?=” Private Message to Channel #!loco!: “[M]: Thread Activated: Sending Message With Email.” Private Message to Channel #!loco!: “[M]: Thread Disabled.” Private Message to User New[AUT|00|P|64491]: “.hp http://domredi.com/1/” hosting infos: http://whois.domaintools.com/205.234.187.241

2.byinter.net(ngrBot hosted in United States Stafford Singlehop Inc)

Uncategorized

C&C Server: 69.175.32.237:6667 Server Password: Username: msgvvei Nickname: A[DE-XPC]msgvvei Channel: #KCA (Password: KCA) Channeltopic: :!j #X Now talking in #X Topic On: [ #X ] [ !j #XX !mdns http://69.175.32.237/~face/av.txt !mod usbi on ] Topic By: [ KCA ] UPDATE: PRIVMSG #aryan :[AryaN]: Successfully Executed Process: “C:Documents and SettingsUserNameApplication Data10915679120753.exe” NICK A[US-XPC]zjqsrws USER zjqsrws 0Read more...