Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- 29* Looking up 29skeu1.xyz
- 20* Unknown host. Maybe you misspelled it?
- 20* Disconnected (20)
- 29* Looking up 29skeu2.xyz
- 23* Connecting to 29skeu2.xyz (23162.255.119.153:7778)
- 23* Stopped previous connection attempt (242460)
- 29* Looking up 29skeu2.xyz
- 23* Connecting to 29skeu2.xyz (23162.255.119.153:7778)
- 23* Stopped previous connection attempt (245608)
- 29* Looking up 29skeu2.xyz
- 23* Connecting to 29skeu2.xyz (23162.255.119.153:7778)
- 23* Stopped previous connection attempt (2420500)
- 29* Looking up 29skeu2.xyz
- 23* Connecting to 29skeu2.xyz (23162.255.119.153:7778)
- 23* Stopped previous connection attempt (2422624)
- 29* Looking up 29skeu2.xyz
- 23* Connecting to 29skeu2.xyz (23162.255.119.153:7778)
- 23* Stopped previous connection attempt (2424352)
- 29* Looking up 29skeu2.xyz
- 23* Connecting to 29skeu2.xyz (23162.255.119.153:7778)
- 23* Stopped previous connection attempt (245248)
- 29* Looking up 29skeu2.xyz
- 23* Connecting to 29skeu2.xyz (23162.255.119.153:7778)
- 23* Stopped previous connection attempt (2418076)
- 29* Looking up 29skeu2.xyz
- 23* Connecting to 29skeu2.xyz (23162.255.119.153:7778)
- 23* Stopped previous connection attempt (2422232)
- 29* Looking up 29skeu2.xyz
- 23* Connecting to 29skeu2.xyz (23162.255.119.153:7778)
- 23* Stopped previous connection attempt (2423564)
- 29* Looking up 29185.61.138.151\7778
- 20* Unknown host. Maybe you misspelled it?
- 20* Disconnected (20)
- 29* Looking up 29185.61.138.151
- 23* Connecting to 29185.61.138.151:7778 (23185.61.138.151:7778)
- 23* Connected. Now logging in.
- 29* *** Looking up your hostname...
- 29* *** Couldn't resolve your hostname; using your IP address instead
- 23* Capabilities supported: 29userhost-in-names multi-prefix away-notify account-notify tls
- 23* Capabilities requested: 29userhost-in-names multi-prefix away-notify account-notify
- 29* Capabilities acknowledged: 29userhost-in-names multi-prefix away-notify account-notify
- 29* Welcome to the he IRC Network admin!890089@89.238.186.238
- 29* Your host is wee.wee.wee, running version UnrealIRCd-4.0.1
- 29* This server was created Tue May 15 2018 at 11:19:39 GMT
- 29* wee.wee.wee UnrealIRCd-4.0.1 iowrsxzdHtIRqpWGTSB lvhopsmntikraqbeIzMQNRTOVKDdGLPZSCcf
- 29* UHNAMES NAMESX SAFELIST HCN MAXCHANNELS=10 CHANLIMIT=#:10 MAXLIST=b:60,e:60,I:60 MAXNICKLEN=30 NICKLEN=30 CHANNELLEN=32 TOPICLEN=307 KICKLEN=307 AWAYLEN=307 :are supported by this server
- 29* MAXTARGETS=20 WALLCHOPS WATCH=128 WATCHOPTS=A SILENCE=15 MODES=12 CHANTYPES=# PREFIX=(qaohv)~&@%+ CHANMODES=beI,kLf,l,psmntirzMQNRTOVKDdGPZSCc NETWORK=he CASEMAPPING=ascii EXTBAN=~,SOcaRrnqj ELIST=MNUCT :are supported by this server
- 29* STATUSMSG=~&@%+ EXCEPTS INVEX CMDS=USERIP,STARTTLS,KNOCK,DCCALLOW,MAP :are supported by this server
- 29* 1B0D66B9.999BD695.C5CE82FF.IP :is now your displayed host
- 29* There are 1 users and 325 invisible on 1 servers
- 29* 1 :operator(s) online
- 29* 11 :unknown connection(s)
- 29* 2 :channels formed
- 29* I have 326 clients and 0 servers
- 29* 326 959 :Current local users 326, max 959
- 29* 326 355 :Current global users 326, max 355
- 29* 29MOTD File is missing
- 22* 26admin sets mode 24+i on 22admin
- 22* 26admin sets mode 24+w on 22admin
- 22* 26admin sets mode 24+x on 22admin
- Linked binaries: https://www.hybrid-analysis.com/sample/644b64ec7261bace555c0f3b7b32c6a09c20217f11773dc5b0a96f0bc437069e
- https://www.virustotal.com/#/file-analysis/OWIwZjk5ZDZkZjdmZTI0MzVmODgyZDEwOTUzNWI0OGY6MTUyOTU5MTg1OA==
- Current direct-ip connection:
- Connecting to 185.61.138.151:7778 (185.61.138.151:7778)
- The mentioned domains seem to be part of a failback mechanism, as soon as primary ip goes down, botnet will use the domains:
- "185.61.138.151",
- "skeu1.xyz",
- "skeu2.xyz",
- "skeu3.xyz",
- "skeu4.xyz",
- "skeu5.xyz",
- In order of priority.
- Botnet is being used to launch attacks worldwide, a simple honeypot has recovered the following logs:
- * [IN]shahrukh|12635 (~INshahru@CF392AB1.BCF7C58D.3919FC61.IP) has joined
- * [FR]pc|37342 has quit (Read error)
- * [user][41420]|F (~user414@6ED884A1.8BCD64B3.30AD9F70.IP) has joined
- * [BR]NOTE|4447 (~BRNOTE4@he-BCDEEEA2.ondaagil.net.br) has joined
- * [pericolu (~pericolu@DD6CBEC3.54EA1F29.567A64C2.IP) has joined
- * [GH]Nagyeo|94730 (~GHNagyeo@DEE8028.8E5A799F.AB0D808F.IP) has joined
- * [SD]awab|67426 (~SDawab6@AA2156F3.692FD7D5.26EEF2DC.IP) has joined
- * [BR]User|94276 (~BRUser9@414AF2A8.B496FC66.CF9E86AF.IP) has joined
- * [IN]Welcome|54872 (~INWelcom@1C11B708.BA42402A.255EECA8.IP) has joined
- * [RO]Vali|42964 has quit (Read error)
- * [IN]Welcome|98011 has quit (Read error)
- * [PS]work-9|12391 has quit (Ping timeout: 380 seconds)
- * [VN]TD105|59997 (~VNTD105@C61BFAB3.31B610E7.F28EB75A.IP) has joined
- * [ID]Win7|88112 has quit (Read error)
- * [IQ]asmar|76037 has quit (Read error)
- * [IN]hp|9849 (~INhp984@he-38DFA587.rev.pcpli.net) has joined
- * [PH]pisonet|74972 has quit (Read error)
- * [Admin][53357]|F (~Admin53@8A8FBDAF.3FFA0445.D6720A6C.IP) has joined
- * [FR]pc|13531 (~FRpc135@he-73A63BE1.abo.bbox.fr) has joined
- <[Tudor][74470]|F> Running tasks: 12 >> Layer7 : Target https://mollerbil.se/ : Total time: 7200 : Elapsed time 5217 : Running method HTTPSTRONG | Layer7 : Target https://mollerbil.se/ : Total time: 7200 : Elapsed time 4792 : Running method HTTPNULL | Layer7 : Target https://mollerbil.se/ : Total time: 7200 : Elapsed time 4348 : Running method HTTP | Layer7 : Target https://mollerbil.se/ : Total time: 7200 : Elapsed time 4327 : Running method HTTP
- * [GR]PC1|55063 (~GRPC155@he-66BD4403.access.hol.gr) has joined
- * [MK]Shaban|2452 has quit (Read error)
- <[Tudor][74470]|F> Running tasks: 11 >> Layer7 : Target https://mollerbil.se/ : Total time: 7200 : Elapsed time 5223 : Running method HTTPSTRONG | Layer7 : Target https://mollerbil.se/ : Total time: 7200 : Elapsed time 4798 : Running method HTTPNULL | Layer7 : Target https://mollerbil.se/ : Total time: 7200 : Elapsed time 4354 : Running method HTTP | Layer7 : Target https://mollerbil.se/ : Total time: 7200 : Elapsed time 4333 : Running method HTTP
- * [JERAL][38494]|F (~JERAL38@E0AF18A0.59DD991B.13C645EB.IP) has joined
- * [VN]TD105|59997 has quit (Read error)
- * [Sandeep][76703]|F (~Sandeep@47F6066E.5AEFD61F.B527F152.IP) has joined
- * [ID]OPERATOR|39311 has quit (Ping timeout: 380 seconds)
- * [GAMER_ONE][51054]|F has quit (Read error)
- * [BR]User|2730 has quit (Ping timeout: 380 seconds)
- * [IN]windows|47797 (~INwindow@70593D1.B7AA9CAC.C5249ABA.IP) has joined
- * [BG]Gokhii|5522 has quit (Ping timeout: 380 seconds)
- <TOXICO> STOPALL
- * [work-3][15561]|F has quit (Ping timeout: 380 seconds)
- * [AR]user|77745 (~ARuser7@he-FA541017.telecom.net.ar) has joined
- * [IN]RJ_DoI_AL_NS272235|8830 has quit (Read error)
- * [EG]7|9538 (~EG79538@F00EDEE0.C6E1E800.BEF5D00A.IP) has joined
- * [PH]ThisPC|28976 (~PHThisPC@469CF8D3.FBABB69E.B896DFC4.IP) has joined
- * [E2][7266]|F (~E27266@381A3C87.C466A920.EBECB751.IP) has joined
- * [RU]i|20640 (~RUi2064@D437A95.B0694387.36CD865D.IP) has joined
- \<TOXICO> INFORMATION
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement