Month: September 2013

winblowservice.hopto.org (Betabot http botnet hosted by nyi.net)

Uncategorized

 Resolved winblowservice.hopto.org to 207.12.89.154 Server:  winblowservice.hopto.org Gate file:  /service/order.php Alternate domains:  imafaggot.pw imtheop.redirectme.net Thanks to this commentor for the report Hosting infos: http://whois.domaintools.com/207.12.89.154 Related md5s (Search on malwr.com to download samples) Betabot: c994461c69b02a63d0f1bbcd2a56ba54

liveinsurance.org (Betabot http botnet hosted by worldstream.nl)

Uncategorized

Resolved liveinsurance.org to 109.236.84.150 Server:  liveinsurance.org Gate file:  /loverboy/order.php freegamebox.us, a domain from a previous betabot is hosted on the same IP, so both are probably owned by the same person. Hosting infos: http://whois.domaintools.com/109.236.84.150 Related md5s (search on malwr.com to download samples) Betabot: 655b1833bfe7dc80391287ae6d568318

5.133.180.103 (Athena irc botnet hosted by bhost.co.uk)

Uncategorized

Server:  5.133.180.103 Port:  6667 Current global users 104, max 387 Channel:  #razbot #razbot          102     Oper:  [n[ARE|U|L|WIN7|x64|2c]loruybe] (rusho@i.hate.microsefrs.com): … [n[ARE|U|L|WIN7|x64|2c]loruybe] #strike #razbot  [n[ARE|U|L|WIN7|x64|2c]loruybe] irc.foonet.com :FooNet Server [n[ARE|U|L|WIN7|x64|2c]loruybe] is a Network Administrator [n[ARE|U|L|WIN7|x64|2c]loruybe] is available for help. [n[ARE|U|L|WIN7|x64|2c]loruybe] idle 00:09:52, signon: Tue Sep 03 11:45:07 [n[ARE|U|L|WIN7|x64|2c]loruybe] End of WHOIS list. This is the same authhost as another posted athena botnet. Hosting infos:Read more...

Predhost.in (Smokeloader hosted by Digitalocean.com)

Uncategorized

Resolved predhost.in to 198.199.109.163 Server:  Predhost.in Gate file:  /sm/index.php Logging into hxxp://predhost.in/sm/guest.php with guest:guest works. Anyone want to test if the sqli got fixed? Hosting infos: http://whois.domaintools.com/198.199.109.163 Related md5s (Search on malwr.com to download samples) Smokeloader: 4c438005e17b968813f3df1fb2e15f4a