brutinhoesilkster.servegame.com(Linux bots hosted in United States Dallas Limestone Networks Inc.)

Resolved : [brutinhoesilkster.servegame.com] To [63.143.41.236] var $config = array(“server”=>”brutinhoesilkster.servegame.com”, “port”=>”443”, “pass”=>””, “prefix”=>”[BET][RLZ]”, “maxrand”=>”4”, “chan”=>”#betorlz”, “chan2″=>””, “key”=>””, “modes”=>”+iB-x”, “password”=>”betinho”, “trigger”=>”.”, “hostauth”=>”*” // Clients: I have 297 clients and 0 servers Local users: Current local users: 297 Max: 607 Global users: Current global users: 297 Max: 607 Now talking in #betorlz ([[BET][RLZ]2706) [UdpFlood Finalizado!]: 1687 MB enviados

esta4.info(ngr botnet hosted in United States San Jose Serveryou.com – Oow)

Resolved : [esta4.info] To [216.172.132.123] other domain names used from same guy: jer0002.in Resolved : [jer0002.in] To [216.172.132.123] jer0003.in Resolved : [jer0003.in] To [216.172.132.123] ratk01.com Resolved : [ratk01.com] To [216.172.132.123] Remote Host Port Number 199.15.234.7 80 216.172.132.123 1887 PASS powned NICK n{US|XPa}rqrrlpw USER rqrrlpw 0 0 :rqrrlpw JOIN #sbsb powned JOIN #XP JOIN #US Now

85.95.247.26(Wolk-Panel HTTP Bot hosted in Turkey Izmir Inetmar Internet Hizmetleri San. Tic. Ltd. Sti)

Remote Host Port Number 85.95.247.26 80 Panel: http://85.95.247.26/~estacion/Panel/Web-Panel/priv8/ u can download web panel from here:http://85.95.247.26/~estacion/ if the file is removed go to http://www.secret-zone.net/f124/volk-http-botnet-%5B-%5Dpharming-%5Bver-4-0%5D-4212/ to download server source and web panel hosting infos: http://whois.domaintools.com/85.95.247.26

tv.yaerwal.com(irc botnet hosted in China Guiyang China Telecom)

Resolved : [tv.yaerwal.com] To [111.123.180.3] Resolved : [tv.yaerwal.com] To [124.232.146.32] Remote Host Port Number tv.yaerwal.com 3323 PASS eee Nick ntaxmbs ssrr ataihfj “” “ufa” :ataihfj Chanels:#s,#i,#dpi,#ng,#j hosting infos: http://whois.domaintools.com/111.123.180.3

109mb samples

This package contains mostly irc bots,banking trojans,RATS,worms,bitcoin miners Download samples: Download Download

Trojan-Ransom.Win32.Birele.wjr

Traffic – by TCP/IP Connections:97 outbound connection found Country IP Port IP 0.200.255.255 16471 BG 109.199.234.255 16471 UA 109.200.250.38 16471 JP 110.132.246.252 16471 JP 112.139.29.252 16471 CN 113.194.255.255 16471 IN 117.194.100.255 16471 JP 119.231.224.249 16471 JP 121.101.116.250 16471 IN 122.176.255.255 16471 JP 122.18.253.121 16471 JP 122.21.100.202 16471 JP 126.11.125.253 16471 US 146.115.56.251 16471 KG 158.181.255.255

anastasia.servequake.com(Insomnia 2.5.0 bot hosted in Spain Ovh Systems)

This is one report from Zazu here is the original link and all credits go to Zazu for this report DNS: anastasia.servequake.com DNS Provider: http://www.no-ip.com/ DNS resolved: 37.59.129.195 Port: 50111 Server Password: l33thack Channel #choi Bot Master’s Nickname: andrew Hosted By: http://www.vpsdeploy.com/ Location: Spain Sample: “https://dl.dropbox.com/u/9386997/andrew1.exe” Sample Status: The sample seems to be encrypted and