Month: December 2012

rat-forums.net (Ice 9 banking malware proxied by cloudflare)

Uncategorized

Resolved rat-forums.net to 108.162.194.61, 108.162.194.161 Server:  rat-forums.net Gate file:   /web/adm/gate.php Config file:  /web/config/index.php This is the first time I’ve seen the ice 9 zeus mod in the wild. I guess all the skiddies are trying it out now that it’s cracked. Hopefully cloudflare will put a stop to their experimenting.

starhf.com (Andromeda http botnet proxied by cloudflare)

Uncategorized

Resolved starhf.com to 108.162.193.86, 108.162.193.186 Server:  starhf.com Gate file:   /andro/image.php This is the second andromeda net I’ve seen hosted on cloudflare. They wouldn’t take down the first one for want of evidence. I guess their bot detection technology has some trouble if it can’t even detect when cloudflare is acting as a C&C proxy.Read more...

irc.zypur.com (Insomnia irc botnet hosted by linode.com)

Uncategorized

Resolved irc.zypur.com to 178.79.164.173 Server:  irc.zypur.com Port:  6667 * I have 195 clients and 1 servers * Current Local Users: 195  Max: 1006 * Current Global Users: 196  Max: 1017 Channel:  #bots  #bots            195     [+ntrk]  Channel password:  Insomnia Oper: * [Daily] (Daily@Daily.com): … * [Daily] is a registered nick * [Daily] ~#bots * [Daily] irc.zypur.comRead more...

Survey winlocker (FileIce.net)

Uncategorized

Here’s another winlocker based around having the victim complete surveys to unlock their computer. This one has the user download a file with a password rather than have them just complete the survey in the locker. It requires .net 4.0 to run. The locker doesn’t block the whole screen, but inserts itself across the middleRead more...

blazehost.net (Andromeda and Smoke http botnets hosted by Seychelles Victoria Business Dialogue Ltd)

Uncategorized

Resolved blazehost.net to  91.217.178.32 Andromeda Server:  Blazehost.net gate file:  /andro/image.php Plugins Rootkit:   blazehost.net/andro/r.pack Socks:  blazehost.net/andro/s.pack Formgrabber:   blazehost.net/andro/f.pack   Gate file:  /andro/fg.php Smoke Server:  Blazehost.net Gate file:  /index.php Hosting infos: http://whois.domaintools.com/91.217.178.32