Month: October 2012 (Andromeda http hosted by France Roubaix Ovh Sas)

Resolved to This is the new andromeda of the french guy. It is the full version with all of the plugins. Server: Gate file:  /google/image.php Plugins: Formgrabber: Gate file: /google/fg.php Socks: Rootkit: Downloads files from hxxp:// and hxxp:// He also has a new smoke loader up Server: Gate (Andromeda http bot hosted by Ukraine Ukrainian Internet Names Center Ltd)

Resolved to  New andromeda from this guy. Server: Gate file: /mario/root.php This is the full version of andromeda, with all of the plugins. Plugins: Formgrabber plugin: Gate file: /mario/fg.php Socks plugin: Rootkit plugin: Hosting infos: Edit: Plugins are now at I think you can guess what each (Barracuda irc bot hosted by Turkey Istanbul Radore Hosting Telekomunikasyon Hizmetleri San. Ve Tic. Ltd. Sti.)

Resolved to Server: Port:  4667 Channel: #yoloswag Owner: Paradoxun This is the latest irc of the barracuda .net irc bot. After trolling around for a bit, it’s time for this one to be posted. The Authost on the bot only checks for the nick, so just wait for Paradoxun to leave, /nick

boris and hf hecker

boris a guy who idle into our irc channel #security had a conversation with a botnet owner we had alot of fun reading now is your turn lol <boris> If you want to keep this ircd to yourself, I suggest you listen very carefully. <boris> firstly, a whois will not give you my real (Lilyjade script hiding behind/proxied by cloudflare)

I was looking at some of the files being installed from a recent posting, when I found something interesting. It looks like someone else is trying out lilyjade. The extensions are held in a self extracting archive and installed via a batch file. @echo off //Kill Proccess TASKKILL /F /IM firefox.exe TASKKILL /F /IM chrome.exe hosted in United States Missoula Sharktech)

IRC Server: Server Pass: m3ga2012Nick: L2-[hfqUsername: tdviyflbb Joined Channel: #ghostChannel Topic for Channel #ghost: “.scan 75 1 189.x.x.x 2 1 189.x.x.x”Private Message to Channel #ghost: “Scanning: 189.x.x.x, 75 threads. Using CFTP.” Hosting Infos: (Multiple http bots hosted by Romania Torben Diehr)

Posting some french heckers stuff Andromeda loader Server: Gate file: /xbox/image.php Rootkit plugin:  hxxp:// Socks plugin:  hxxp:// Backup domains: kbot Server: redirects to: Gate file: /joomla/gate.php Server: Redirects to: Gate file:  /kb/gate.php Server: Gate file:  /kb/gate.php Smoke loader (Currently down) Server: Gate file: /s2/control.php Hostbooter