Author Topic: New Zeus server  (Read 396742 times)

0 Members and 2 Guests are viewing this topic.

January 06, 2010, 02:23:56 pm
Reply #15

jackberri

  • Special Members
  • Hero Member

  • Offline
  • *

  • 1508
Code: [Select]
hxxp://chocolatery.info/config.bin
hxxp://chocolatery.info/bot.exe
hxxp://chocolatery.info/gate.php

January 07, 2010, 10:34:26 am
Reply #16

jackberri

  • Special Members
  • Hero Member

  • Offline
  • *

  • 1508
New files for 
Code: [Select]
193.104.27.171
Code: [Select]
hxxp://193.104.27.171/uk/ukk1.bin
hxxp://193.104.27.171/moneyuk1.exe
hxxp://193.104.27.171/ukk/gg1.php


January 07, 2010, 11:24:35 am
Reply #17

jackberri

  • Special Members
  • Hero Member

  • Offline
  • *

  • 1508
Only the config file  >:(

Code: [Select]
hxxp://wermacht.net/12/c1.bin

January 07, 2010, 12:01:46 pm
Reply #18

SysAdMini

  • Administrator
  • Hero Member

  • Offline
  • *****

  • 3335
Only the config file  >:(

Code: [Select]
hxxp://wermacht.net/12/c1.bin

No problem. Found.
Ruining the bad guy's day

January 07, 2010, 08:21:54 pm
Reply #19

jackberri

  • Special Members
  • Hero Member

  • Offline
  • *

  • 1508
Code: [Select]
hxxp://history03kf.com/P0rtL1ps/657n8y4trb887.bin
hxxp://history03kf.com/P0rtL1ps/MNcs6d5rcw4CWEWE54weh5EJt5j6TSDY5.php

January 09, 2010, 11:59:06 am
Reply #20

jackberri

  • Special Members
  • Hero Member

  • Offline
  • *

  • 1508
Only the config file  >:(

Code: [Select]
hxxp://silence7.homeip.net/zx/config.bin
IP
Code: [Select]
95.169.186.103
Code: [Select]
silence7.homeip.net has one IP number , but the reverse is ns.km34517.keymachine.de. homeip.net is a domain controlled by five nameservers at dyndns.org. All of them are on different IP networks. Incoming mail for homeip.net is handled by two mailservers having a total of 14 IP numbers. Two mailservers have the same IP number. All of them are on the same IP network. homeip.net has one IP number. silence7.homeip.net is hosted on a server in Russian Federation.

January 11, 2010, 05:37:35 pm
Reply #21

jackberri

  • Special Members
  • Hero Member

  • Offline
  • *

  • 1508
Code: [Select]
http://donccapone.com/tmp/check.php
Code: [Select]
IP: 195.78.108.50
And:

Code: [Select]
1211news.com/index.exe
Code: [Select]
1211news.com//tmp/check.php
Code: [Select]
promoalp.ru

January 12, 2010, 12:41:02 pm
Reply #22

jackberri

  • Special Members
  • Hero Member

  • Offline
  • *

  • 1508
Code: [Select]
hxxp://vifiogod7com.net/vgame/logo.jpgIP:
Code: [Select]
115.100.250.114
AS9811

January 14, 2010, 07:34:34 am
Reply #23

jackberri

  • Special Members
  • Hero Member

  • Offline
  • *

  • 1508
Code: [Select]
hxxp://cashing-s.com/exp/cfg.binIP
Code: [Select]
122.115.63.45Route
Code: [Select]
122.115.60.0/22AS9803

January 14, 2010, 11:00:58 am
Reply #24

jackberri

  • Special Members
  • Hero Member

  • Offline
  • *

  • 1508
Code: [Select]
hxxp://www.traffsearch.com/zecp/cfg2.bin
hxxp://www.traffsearch.com/zecp/gate.php

IP
Code: [Select]
212.95.38.98
Create: 2010-01-09 01:13:18
Reverse Lookup
Code: [Select]
ns3.erikmedya.comCreation Date: 08-jan-2010
AS28753

January 14, 2010, 11:55:44 am
Reply #25

jackberri

  • Special Members
  • Hero Member

  • Offline
  • *

  • 1508
Code: [Select]
hxxp://britishsupport.net/bx/vlc.exe
hxxp://britishsupport.net/bx/cgi.bin

IP
Code: [Select]
222.122.60.186AS4766

January 14, 2010, 07:44:21 pm
Reply #26

jackberri

  • Special Members
  • Hero Member

  • Offline
  • *

  • 1508
Code: [Select]
hxxp://businesscosult4u.comCreation Date: 10-jan-2010
IP: 122.115.63.4
Reverse: netnic.com.cn
AS: AS9803

binary url
Code: [Select]
hxxp://businesscosult4u.com/load/load.exe
http://www.virustotal.com/es/analisis/33e1dae365ac4c0a643eb542d9e705cc181f5b754e7c73e4b1486515075fee03-1263497416
VT 8/41 (19.52%)

dropzone
Code: [Select]
hxxp://businesscosult4u.com/include/linkstat.php

January 15, 2010, 08:04:48 pm
Reply #27

jackberri

  • Special Members
  • Hero Member

  • Offline
  • *

  • 1508
Code: [Select]
hxxp://zexmad.com
Creation Date: 12-jan-2010

IP: 91.213.174.13

config file
Code: [Select]
hxxp://zexmad.com/web/cfg.bin
binary url

dropzone
Code: [Select]
hxxp://zexmad.com/web/gate.php

January 15, 2010, 08:56:40 pm
Reply #28

jackberri

  • Special Members
  • Hero Member

  • Offline
  • *

  • 1508
config file
Code: [Select]
hxxp://pilonoc.cn/web/cfg.bin
binary url
Code: [Select]
hxxp://pilonoc.cn/web/ldr.exe
dropzone
Code: [Select]
hxxp://pilonoc.cn/web/gate.php
Are now online

January 15, 2010, 09:00:14 pm
Reply #29

SysAdMini

  • Administrator
  • Hero Member

  • Offline
  • *****

  • 3335
config file
Code: [Select]
hxxp://pilonoc.cn/web/cfg.bin
binary url
Code: [Select]
hxxp://pilonoc.cn/web/ldr.exe
dropzone
Code: [Select]
hxxp://pilonoc.cn/web/gate.php
Are now online

Thank you, but already on list.

http://www.malwaredomainlist.com/mdl.php?search=pilonoc.cn&colsearch=All&quantity=50
Ruining the bad guy's day