Autoit Bot

Found this sample  and decompiled so have fun with the source wich is partially encrypted. Here the sample: hxxp:// And here the source decompiled and partially encrypted  with BitXOR password for the link is : exposedbotnets Bot hosted in Netherlands International Widespread Services Limited)

Sample found by ALiSs urls’s: hxxp:// hxxp:// Plugins: hxxp:// hxxp:// hxxp:// hxxp:// /joomla/f.pack hxxp:// /joomla/s.pack  hxxp:// /joomla/r.pack hxxp:// Love Poem dedicated to Brian Krebs here: hxxp:// Same Poem here : hxxp:// Samples: hxxp:// hxxp:// hxxp:// hxxp:// miner.exe downloads: hxxp:// ( hosting infos: hosted in Ukraine Odessa Tehnologii Budushego Llc)

Botnet found by rolls Server: Server Password: Username: uiswnri Nickname: n{DE|XPa}uiswnri Channel: #moon (Password: 4m3r1k) Channeltopic: :.up hxxp:// b2790c7513a2efbf7cb34f64c4f49ff0 Inactive domain hosting infos: (Betabot http botnet hosted by

Resolved to Server: Gate file:  /bronk/order.php Alternate domains: We have a real HF hecker here folks. I can see a Java “driveby” site, shitty crypter site, shitty CPA network site and a shitty hackforums clone site just from the domain names. Looks like he’s running a shitty hosting company as well: (Betabot http botnet hosted by

Resolved to Server: Gate file:  /b/order.php Alternative domain: I wonder who this could belong to? Name Server:NS2.HOSTING-MARVID.ME Name Server:NS1.HOSTING-MARVID.ME An idiot, obviously Related md5s (search on to download the samples): Betabot: 2662af32e5d58d471bd16dc3202db284 Hosting infos: Bots hosted in Germany Frankfurt Am MainVoxility S.r.l.)

Found by Yewnix <? set_time_limit(0); error_reporting(0); class Anxiety { var $config = array(“server”=>””, // Server IP Address “port”=>443, “pass”=>””, // Server Password “prefix”=>”[r00t]-“, “maxrand”=>3, “chan”=>”#exploit”, // Channel “key”=>”lolmoney”, // Channel Key “modes”=>”+p”, “password”=>”lolmoney”, // Bot Password “trigger”=>”.”, “hostauth”=>”” // * For Any Hostname //Leave all of this shit down here alone, unless you know what