Wednesday, February 9, 2011

m3rcil3ss.co.cc ( infeCTeD )

Botnet C&C irc
m3rcil3ss.co.cc DNS_TYPE_A 212.252.34.199
212.252.34.199:6667
Nick: [AUS|XP|620207]
Username: onfkyav
Server Pass: m3rc
Joined Channel: #m3rc with Password k\xfcrt
Channel Topic for Channel #m3rc: ".p2p"
Private Message to Channel #m3rc: "[p2p]: Spreading to p2p folders."
Private Message to User [AUS|XP|620207]: "VERSION"

Process Created:
C:\WINDOWS\upterd.exe

Registry Created:
HKLM\​SOFTWARE\​Microsoft\​Windows NT\​CurrentVersion\​Terminal Server\​Install\​Software\​Microsoft\​Windows\​CurrentVersion\​Run\​ info Windows Services upterd.exe
HKLM\​SOFTWARE\​Microsoft\​Windows\​CurrentVersion\​Run\​ info Windows Services upterd.exe

0 comments:


Powered by Blogger