Saturday, July 25, 2009

74.40.134.42 (ms08-067) exploit botnet (BLAZEBOT)

74.40.134.42:9595
Channel: ##esp, ##rus
NICK: {00-RUS-XP-SKLA-1644}
IDENT: MEAT

Wednesday, July 22, 2009

high.jweles.cn (Hidden)

*** IP of : 85.131.154.57 host high.jweles.cn
85.131.154.57:5555

Channel: #!high! h1ghsh1t
@hidz .msn.msg questa รจ la tua foto?? :P http://myspace-image.info/viewimage.php?=
NICK [00|USA|171262]
USER 2K-8552 * 0 :DDD-4C95834455D
MODE: [00|USA|171262] -ix

Autostart Path
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Windows Update Service = "msupdate32.exe"

Extract Path
"C:\DOCUME~1\User\LOCALS~1\Temp\IXP000.TMP\reptile.exe"
"C:\WINDOWS\msupdate32.exe"

Monday, July 20, 2009

mail.bestservicestores.com

*** IP of : 76.12.178.4 host mail.bestservicestores.com
76.12.178.4:8890
Nick: b0FAkmaUntzFn1EVh65f45Y1m
Username: XP-SP3
Server Pass: fak
Joined Channel: #zUPLEX with Password fuck

Autostart
HKLM\​SOFTWARE\​Microsoft\​Windows\​CurrentVersion\​Shell Extensions Melt
C:\​Zuplex_025725.exe
HKLM\​SYSTEM\​CurrentControlSet\​Control\​SafeBoot\​Minimal Windows Service Control C:\​Documents and Settings\​Administrator\​Application Data\​zupazxx.exe
HKLM\​SYSTEM\​CurrentControlSet\​Control\​SafeBoot\​Network Windows Service Control C:\​Documents and Settings\​Administrator\​Application Data\​zupazxx.exe

Thursday, July 16, 2009

labtec.stupidnsm.cn (Hidden)

*** IP of : 85.131.154.57 host labtec.stupidnsm.cn
85.131.154.57:5555

NICK [00|USA|480852]
USER XP-8638 * 0 :DDD-4C95834455D
MODE [00|USA|480852] -ix
JOIN #!lab! labr0x

The new window was created, as shown below:


Autostart
LM\Software\Microsoft\Windows\CurrentVersion\Run\Windows Dynamic Library Cache "dllcaches.exe"

Wednesday, July 15, 2009

cr4ckr0x.net

*** IP of : 61.136.69.197 host cr4ckr0x.net
61.136.69.197:81

[ Changes to registry ]
* Creates key "HKLM\Software\\Microsoft\\Windows".
* Sets value "Windows Updates"="C:\PROGRA~1\COMMON~1\System\winlogo.exe" in key "HKLM\Software\\Microsoft\\Windows".
* Creates key "HKCU\Software\\Microsoft\\Windows".
* Sets value "Windows Updates"="C:\PROGRA~1\COMMON~1\System\winlogo.exe" in key "HKCU\Software\\Microsoft\\Windows".

Connects to IRC Server.
IRC: Uses nickname mlflODMDdlflhDM.
IRC: Uses username ckmpwuyac.
IRC: Joins channel #scanvnc with password rage.

Tuesday, July 14, 2009

axesor.no-ip.org

*** IP of : 208.77.191.41 host axesor.no-ip.org
208.77.191.41:6667
Nick: pc1426611183
Username: AUT5
Joined Channel: #dbs with Password pwneds
Channel Topic for Channel #dbs: "How knows"

To mark the presence in the system, the following Mutex object was created:
12cFx2FF
The following port was open in the system:

Port Protocol Process
1033 TCP iexplorer.exe (%Windir%\iexplorer.exe)

Monday, July 13, 2009

oao.th3kings.net

*** IP of : 203.154.27.139 host oao.th3kings.net
203.154.27.139:3333
Channel:#!zx!#
Password:zidanag
NICK [00|USA|947039]
USER XP-3986 * 0 :COMPUTERNAME
The newly created Registry Value is:
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
windows Live Messenger = "madbbcre.exe"

so that madbbcre.exe runs every time Windows starts

Malware Url
* CK changes topic to '.msn.msg Estas photo so tuyo? http://picture-sex1.com/myfotohi5.exe?='


Powered by Blogger