Авторизация  
kauhywka

ХАЛЯВА SIP VOIP

В теме 1 сообщение


Bot ID:                       STATION26_74DEB1E3CF5374B7

Botnet:                       0404114SA

Build:                        6

OS Version:                   Seven

OS Language:                  1033

Local time:                   06.04.2011 14:28:41

GMT:                          +0:00

Session time:                 29:09:50

Report time:                  06.04.2011 14:29:52

Country/Region/City/Postal code:SA

IPv4:                         188.48.41.150

Process name:                 C:Program FilesMozilla Firefoxfirefox.exe

Source:                       https://www.voipdisc...hp?part=tplogin

Type:                         HTTPS request

Size (bytes):                 526



----------------------------------------

https://www.voipdisc...hp?part=tplogin

Referer: https://www.voipdisc... your password?

User input: gooclock software for windows xpcalender←←ar for windows xpdesktop calen←ndar tcsgoogletcs pakistantcscourieTCS 2550178375←2550178375gb←epanutin side effec←←←←←←←←←←←voipvqsak3209

POST data:



user=vqed2725

pass=sak3209





========================================

Local time:                   06.04.2011 14:29:12

Session time:                 29:10:21

Report time:                  06.04.2011 14:49:59

Process name:                 C:Program FilesMozilla Firefoxfirefox.exe

Source:                       https://www.voipdisc...hp?part=tplogin

Type:                         HTTPS request

Size (bytes):                 534



----------------------------------------

https://www.voipdisc...hp?part=tplogin

Referer: https://www.voipdisc... your password?

User input: gooclock software for windows xpcalender←←ar for windows xpdesktop calen←ndar tcsgoogletcs pakistantcscourieTCS 2550178375←2550178375gb←epanutin side effec←←←←←←←←←←←voipvqsak3209vsak3209

POST data:



user=vqed2725

pass=sak3209





========================================

Local time:                   06.04.2011 14:29:32

Session time:                 29:10:41

Report time:                  06.04.2011 14:50:00

Process name:                 C:Program FilesMozilla Firefoxfirefox.exe

Source:                       https://www.voipdisc...hp?part=tplogin

Type:                         HTTPS request

Size (bytes):                 542



----------------------------------------

https://www.voipdisc...hp?part=tplogin

Referer: https://www.voipdisc... your password?

User input: gooclock software for windows xpcalender←←ar for windows xpdesktop calen←ndar tcsgoogletcs pakistantcscourieTCS 2550178375←2550178375gb←epanutin side effec←←←←←←←←←←←voipvqsak3209vsak3209vSAK3209

POST data:



user=vqed2725

pass=SAK3209





======================================== 07.04.2011 ========================================

Not founded.

======================================== 13.04.2011 ========================================

Not founded.

======================================== 14.04.2011 ========================================

Not founded.

======================================== 15.04.2011 ========================================



========================================

Bot ID:                       444-PC_E532648ABE3EC147

Botnet:                       0404114SA

Build:                        6

OS Version:                   Seven, SP 1

OS Language:                  1033

Local time:                   15.04.2011 08:41:50

GMT:                          +0:00

Session time:                 66:51:18

Report time:                  15.04.2011 08:52:42

Country/Region/City/Postal code:SA

IPv4:                         188.50.108.245

Process name:                 C:Program FilesInternet Exploreriexplore.exe

Source:                       https://www.voipgain...hp?part=tplogin

Type:                         HTTPS request

Size (bytes):                 331



----------------------------------------

https://www.voipgain...hp?part=tplogin

Referer: https://www.voipgain...1&bcolor=FF1384

User input:

POST data:



user=saudlugmani

pass=callmenow





======================================== 16.04.2011 ========================================

Not founded.

======================================== 17.04.2011 ========================================

Not founded.

======================================== 18.04.2011 ========================================



========================================

Bot ID:                       ACER-PC_74DEB1E347AECF72

Botnet:                       1704111SA1

Build:                        6

OS Version:                   Seven

OS Language:                  1033

Local time:                   18.04.2011 13:14:37

GMT:                          +0:00

Session time:                 00:08:34

Report time:                  18.04.2011 13:14:51

Country/Region/City/Postal code:SA

IPv4:                         188.249.53.77

Process name:                 C:Program FilesMozilla Firefoxfirefox.exe

Source:                       https://www.jumblo.c...hp?part=tplogin

Type:                         HTTPS request

Size (bytes):                 207



----------------------------------------

https://www.jumblo.c...hp?part=tplogin

Referer: https://www.jumblo.c...unt/gopanel.php

User input: jbo8958757565

POST data:



indexpanel=yes

user=jbo8958

pass=757565

submit=Login %C2%BB





========================================

Local time:                   18.04.2011 13:35:15

Session time:                 00:14:01

Report time:                  18.04.2011 20:40:03

Process name:                 C:Program FilesInternet Exploreriexplore.exe

Source:                       https://www.jumblo.c...hp?part=tplogin

Type:                         HTTPS request

Size (bytes):                 190



----------------------------------------

https://www.jumblo.c...hp?part=tplogin

Referer: https://www.jumblo.c...2loginpanel.php

User input: jumlabolo45jm259ab757565

POST data:



user=45jm259

pass=ab757565





========================================

Local time:                   18.04.2011 20:49:21

Session time:                 00:12:31

Report time:                  18.04.2011 21:00:07

Process name:                 C:Program FilesMozilla Firefoxfirefox.exe

Source:                       https://www.jumblo.c...hp?part=tplogin

Type:                         HTTPS request

Size (bytes):                 181



----------------------------------------

https://www.jumblo.c...hp?part=tplogin

Referer: https://www.jumblo.c...2loginpanel.php

User input: 45jm259ab757565

POST data:



user=45jm259

pass=ab757565





========================================

Local time:                   18.04.2011 21:28:58

Session time:                 00:52:08

Report time:                  18.04.2011 21:40:50

Process name:                 C:Program FilesMozilla Firefoxfirefox.exe

Source:                       https://www.jumblo.c...hp?part=tplogin

Type:                         HTTPS request

Size (bytes):                 211



----------------------------------------

https://www.jumblo.c...hp?part=tplogin

Referer: https://www.jumblo.c...unt/gopanel.php

User input: 45jm259ab757565

POST data:



indexpanel=yes

user=45jm259

pass=ab757565

submit=Login %C2%BB





======================================== 19.04.2011 ========================================

Not founded.

======================================== 20.04.2011 ========================================



========================================

Bot ID:                       ACER-PC_74DEB1E347AECF72

Botnet:                       1704111SA1

Build:                        6

OS Version:                   Seven

OS Language:                  1033

Local time:                   19.04.2011 23:13:50

GMT:                          +0:00

Session time:                 01:00:42

Report time:                  20.04.2011 21:25:40

Country/Region/City/Postal code:US

IPv4:                         69.31.50.222

Process name:                 C:Program FilesMozilla Firefoxfirefox.exe

Source:                       https://www.jumblo.c...hp?part=tplogin

Type:                         HTTPS request

Size (bytes):                 151



----------------------------------------

https://www.jumblo.c...hp?part=tplogin

Referer: https://www.jumblo.c...2loginpanel.php

User input:

POST data:



user=

pass=





========================================

Bot ID:                       ViP.ALAiN..X4X_B4DF76116B508ABB

Botnet:                       1704111SA1

Build:                        6

OS Version:                   XP, SP 2

OS Language:                  1033

Local time:                   20.04.2011 14:42:22

GMT:                          +0:00

Session time:                 05:10:18

Report time:                  20.04.2011 15:01:25

Country/Region/City/Postal code:SA

IPv4:                         188.54.101.121

Process name:                 C:Program FilesMozilla Firefoxfirefox.exe

Source:                       https://www.actionvo...hp?part=tplogin

Type:                         HTTPS request

Size (bytes):                 379



----------------------------------------

https://www.actionvo...hp?part=tplogin

Referer: https://www.actionvo...1&bcolor=FF1384

User input: actionvoipsellershahidssssdkpk77

POST data:



user=voipsellershahid

pass=ssssdkpk77





======================================== 21.04.2011 ========================================



========================================

Bot ID:                       HJG-9D8D9FEAFB2_B4DF761108089A3C

Botnet:                       1804111SA

Build:                        6

OS Version:                   XP, SP 2

OS Language:                  1033

Local time:                   21.04.2011 20:59:03

GMT:                          +0:00

Session time:                 00:18:49

Report time:                  21.04.2011 21:22:04

Country/Region/City/Postal code:SA

IPv4:                         94.99.16.162

Process name:                 C:Program FilesMozilla Firefoxfirefox.exe

Source:                       https://www.voipgain...count/index.php

Type:                         HTTPS request

Size (bytes):                 455



----------------------------------------

https://www.voipgain...count/index.php

Referer: https://www.voipgain...hp?part=tplogin

User input: 66 00966507815478 00966507815478 0096650781547850 00966507815478 00966507815478 00966507815478 00966507815478 00966507815478 0096650781547878 scanquery://http://78.129.144.67/vsrdvoi scanquery://https://www.voipgain.com/myaccount/index.php?part=tploginmonirnarsindi696

POST data:



part=menu

username=monir69630

password=narsindi696





======================================== 22.04.2011 ========================================



========================================

Bot ID:                       USER-38E9A27734_B4DF76111A6AEB85

Botnet:                       1804111SA1

Build:                        6

OS Version:                   XP, SP 2

OS Language:                  1033

Local time:                   22.04.2011 06:30:48

GMT:                          +0:00

Session time:                 00:07:17

Report time:                  22.04.2011 06:46:52

Country/Region/City/Postal code:SA

IPv4:                         46.152.162.95

Process name:                 C:Program FilesMozilla Firefox 4.0 Beta 8firefox.exe

Source:                       https://www.actionvo...hp?part=tplogin

Type:                         HTTPS request

Size (bytes):                 333



----------------------------------------

https://www.actionvo...hp?part=tplogin

Referer: https://www.actionvo...1&bcolor=FF1384

User input:

POST data:



user=act5249

pass=26279





========================================

Local time:                   22.04.2011 06:32:57

Session time:                 00:09:27

Report time:                  22.04.2011 06:47:05

Process name:                 C:Program FilesMozilla Firefox 4.0 Beta 8firefox.exe

Source:                       https://www.actionvo...hp?part=tplogin

Type:                         HTTPS request

Size (bytes):                 333



----------------------------------------

https://www.actionvo...hp?part=tplogin

Referer: https://www.actionvo...1&bcolor=FF1384

User input:

POST data:



user=act5249

pass=26279





======================================== 23.04.2011 ========================================



========================================

Bot ID:                       DEAD-PC_775A658D6522DF69

Botnet:                       5

Build:                        6

OS Version:                   Seven x64

OS Language:                  1033

Local time:                   23.04.2011 10:04:44

GMT:                          -7:00

Session time:                 222:37:50

Report time:                  23.04.2011 17:19:42

Country/Region/City/Postal code:US

IPv4:                         24.59.163.178

Process name:                 C:Program Files (x86)Mozilla Firefoxfirefox.exe

Source:                       https://www.smartvoi...hp?part=tplogin

Type:                         HTTPS request

Size (bytes):                 1 561



----------------------------------------

https://www.smartvoi...hp?part=tplogin

Referer: https://www.smartvoi...&submit=sign in

User input: ?its ← was not only just yesterdayi think of u all the timebut yesterday was some what di←←←←←←←←←←←←←←←←←←←←←←←←←←←←←←←←←←←←←←←←←←←←←←←lollolallrite sweetyjust rember 1 thingsome where some1 alwaise wait for u to tal←←←←←←←←←←←←←←←←←want ←s u to be aroundlokgo get ready dont get d←←←←←←←←←←←←←←see yaget←←←←←may be a ←←←some drinks will help u outwhat u say?its ok←i was just trying to helplolcarry on with ur re←←sleeping programsee u latteramwelcome to lake placidbo←←←hara←←←←←slae←←←←bakadehinibgomygr4801282220074576421brush467prasheekngaikwadsr051198705902024583←100 main street ←←←←←←←←←←←←←←←←←←158 mikinley streetapp 3lake placid12946518←←←51853644``4364474158 mikinley streetp←lake placid129464801282220074576421round744480128222007457641←21board963prasheekngaikwaid=←←←d059024583i5←←158 mic←ca←inkly streetlke ←←←←lake l←placid12946s←159←8←101 oly,pi drive micni←,←micinkly streetlake la←←placid129465185364434←←←[email protected]←www.google.com←msmartvoipvasimdodiya786786

POST data:



user=vasimdodiya

pass=786786





========================================

Local time:                   23.04.2011 10:22:56

Session time:                 222:56:02

Report time:                  23.04.2011 17:41:27

Process name:                 C:Program Files (x86)Mozilla Firefoxfirefox.exe

Source:                       https://www.smartvoi...hp?part=tplogin

Type:                         HTTPS request

Size (bytes):                 1 558



----------------------------------------

https://www.smartvoi...hp?part=tplogin

Referer: https://www.smartvoi...&submit=sign in

User input: nly just yesterdayi think of u all the timebut yesterday was some what di←←←←←←←←←←←←←←←←←←←←←←←←←←←←←←←←←←←←←←←←←←←←←←←lollolallrite sweetyjust rember 1 thingsome where some1 alwaise wait for u to tal←←←←←←←←←←←←←←←←←want ←s u to be aroundlokgo get ready dont get d←←←←←←←←←←←←←←see yaget←←←←←may be a ←←←some drinks will help u outwhat u say?its ok←i was just trying to helplolcarry on with ur re←←sleeping programsee u latteramwelcome to lake placidbo←←←hara←←←←←slae←←←←bakadehinibgomygr4801282220074576421brush467prasheekngaikwadsr051198705902024583←100 main street ←←←←←←←←←←←←←←←←←←158 mikinley streetapp 3lake placid12946518←←←51853644``4364474158 mikinley streetp←lake placid129464801282220074576421round744480128222007457641←21board963prasheekngaikwaid=←←←d059024583i5←←158 mic←ca←inkly streetlke ←←←←lake l←placid12946s←159←8←101 oly,pi drive micni←,←micinkly streetlake la←←placid129465185364434←←←[email protected]←www.google.com←msmartvoipvasimdodiya786786vasimdoiya786786

POST data:



user=vasimdoiya

pass=786786





========================================

Local time:                   23.04.2011 10:23:31

Session time:                 222:56:37

Report time:                  23.04.2011 17:41:30

Process name:                 C:Program Files (x86)Mozilla Firefoxfirefox.exe

Source:                       https://www.smartvoi...hp?part=tplogin

Type:                         HTTPS request

Size (bytes):                 1 559



----------------------------------------

https://www.smartvoi...hp?part=tplogin

Referer: https://www.smartvoi...&submit=sign in

User input: yi think of u all the timebut yesterday was some what di←←←←←←←←←←←←←←←←←←←←←←←←←←←←←←←←←←←←←←←←←←←←←←←lollolallrite sweetyjust rember 1 thingsome where some1 alwaise wait for u to tal←←←←←←←←←←←←←←←←←want ←s u to be aroundlokgo get ready dont get d←←←←←←←←←←←←←←see yaget←←←←←may be a ←←←some drinks will help u outwhat u say?its ok←i was just trying to helplolcarry on with ur re←←sleeping programsee u latteramwelcome to lake placidbo←←←hara←←←←←slae←←←←bakadehinibgomygr4801282220074576421brush467prasheekngaikwadsr051198705902024583←100 main street ←←←←←←←←←←←←←←←←←←158 mikinley streetapp 3lake placid12946518←←←51853644``4364474158 mikinley streetp←lake placid129464801282220074576421round744480128222007457641←21board963prasheekngaikwaid=←←←d059024583i5←←158 mic←ca←inkly streetlke ←←←←lake l←placid12946s←159←8←101 oly,pi drive micni←,←micinkly streetlake la←←placid129465185364434←←←[email protected]←www.google.com←msmartvoipvasimdodiya786786vasimdoiya786786vasimdodiya786786

POST data:



user=vasimdodiya

pass=786786





========================================

Local time:                   23.04.2011 10:55:40

Session time:                 223:28:45

Report time:                  23.04.2011 18:02:48

Process name:                 C:Program Files (x86)Mozilla Firefoxfirefox.exe

Source:                       https://www.smartvoi...hp?part=tplogin

Type:                         HTTPS request

Size (bytes):                 1 527



----------------------------------------

https://www.smartvoi...hp?part=tplogin

Referer: https://www.smartvoi...&submit=sign in

User input: ngsome where some1 alwaise wait for u to tal←←←←←←←←←←←←←←←←←want ←s u to be aroundlokgo get ready dont get d←←←←←←←←←←←←←←see yaget←←←←←may be a ←←←some drinks will help u outwhat u say?its ok←i was just trying to helplolcarry on with ur re←←sleeping programsee u latteramwelcome to lake placidbo←←←hara←←←←←slae←←←←bakadehinibgomygr4801282220074576421brush467prasheekngaikwadsr051198705902024583←100 main street ←←←←←←←←←←←←←←←←←←158 mikinley streetapp 3lake placid12946518←←←51853644``4364474158 mikinley streetp←lake placid129464801282220074576421round744480128222007457641←21board963prasheekngaikwaid=←←←d059024583i5←←158 mic←ca←inkly streetlke ←←←←lake l←placid12946s←159←8←101 oly,pi drive micni←,←micinkly streetlake la←←placid129465185364434←←←[email protected]←www.google.com←msmartvoipvasimdodiya786786vasimdoiya786786vasimdodiya786786←5184810244MGMBMQPRA←←←prasheekgaikwad←←1←←1←←←←←←1←←←158 mikinly street12946lake placid←wwws,a←←mart voipvasimdodiya786786←←←←←←←←←←←786786

POST data:



user=vasimdodiya

pass=786786





========================================

Local time:                   23.04.2011 11:51:47

Session time:                 224:24:53

Report time:                  23.04.2011 20:38:37

Process name:                 C:Program Files (x86)Mozilla Firefoxfirefox.exe

Source:                       https://www.smartvoi...hp?part=tplogin

Type:                         HTTPS request

Size (bytes):                 1 659



----------------------------------------

https://www.smartvoi...hp?part=tplogin

Referer: https://www.smartvoi...&submit=sign in

User input: arry on with ur re←←sleeping programsee u latteramwelcome to lake placidbo←←←hara←←←←←slae←←←←bakadehinibgomygr4801282220074576421brush467prasheekngaikwadsr051198705902024583←100 main street ←←←←←←←←←←←←←←←←←←158 mikinley streetapp 3lake placid12946518←←←51853644``4364474158 mikinley streetp←lake placid129464801282220074576421round744480128222007457641←21board963prasheekngaikwaid=←←←d059024583i5←←158 mic←ca←inkly streetlke ←←←←lake l←placid12946s←159←8←101 oly,pi drive micni←,←micinkly streetlake la←←placid129465185364434←←←[email protected]←www.google.com←msmartvoipvasimdodiya786786vasimdoiya786786vasimdodiya786786←5184810244MGMBMQPRA←←←prasheekgaikwad←←1←←1←←←←←←1←←←158 mikinly street12946lake placid←wwws,a←←mart voipvasimdodiya786786←←←←←←←←←←←786786vasimvasimdodiya101 0lympic drive1294lak518523 ←←←←←85232556←←←←←←←←←←←←←←←←←←←←←←←5187235714=←+1←←←←←←←←←←←←←←←←+←←←←←←←← +1←1←←←←←←←←←←←←←←←←←←←←←←←←←←←←←←←←←←←+←wgreendot.com←←←←←←←←←←←←←←←←←smartvoip.comvasimdodiya786786

POST data:



user=vasimdodiya

pass=786786





========================================

Local time:                   23.04.2011 12:17:52

Session time:                 224:50:57

Report time:                  23.04.2011 20:38:43

Process name:                 C:Program Files (x86)Mozilla Firefoxfirefox.exe

Source:                       https://www.smartvoi...hp?part=tplogin

Type:                         HTTPS request

Size (bytes):                 1 815



----------------------------------------

https://www.smartvoi...hp?part=tplogin

Referer: https://www.smartvoi...&submit=sign in

User input: d744480128222007457641←21board963prasheekngaikwaid=←←←d059024583i5←←158 mic←ca←inkly streetlke ←←←←lake l←placid12946s←159←8←101 oly,pi drive micni←,←micinkly streetlake la←←placid129465185364434←←←[email protected]←www.google.com←msmartvoipvasimdodiya786786vasimdoiya786786vasimdodiya786786←5184810244MGMBMQPRA←←←prasheekgaikwad←←1←←1←←←←←←1←←←158 mikinly street12946lake placid←wwws,a←←mart voipvasimdodiya786786←←←←←←←←←←←786786vasimvasimdodiya101 0lympic drive1294lak518523 ←←←←←85232556←←←←←←←←←←←←←←←←←←←←←←←5187235714=←+1←←←←←←←←←←←←←←←←+←←←←←←←← +1←1←←←←←←←←←←←←←←←←←←←←←←←←←←←←←←←←←←←+←wgreendot.com←←←←←←←←←←←←←←←←←smartvoip.comvasimdodiya786786vasvasaysmarcasio←←←←←←←←←←←←←←←←←←←←←←←←←←←←←←←←←←←←←←←←←←←←←←gonevada univercity←←←←←←←←←←←←←←←←←←←←←←←←←indian reservation←so←←←indian reservatii←on maloo←←←←←← in←←near maloonr←roy←←←←casino managme←ent near la←←←←←←←←←←←←←←←←←near mallonindian reservation cassionbiggest cassionos←www←gsmartvoip.comvasimdodiya78686←←←←←←786786

POST data:



user=vasimdodiya

pass=786786





========================================

Bot ID:                       MUSTHAFA-0B8793_B4DF761197E8ACF0

Botnet:                       220411SA2

Build:                        6

OS Version:                   XP, SP 2

OS Language:                  1033

Local time:                   23.04.2011 16:29:36

GMT:                          +0:00

Session time:                 02:45:18

Report time:                  23.04.2011 16:30:15

Country/Region/City/Postal code:SA

IPv4:                         94.97.112.105

Process name:                 C:Program FilesInternet Exploreriexplore.exe

Source:                       https://www.jumblo.c...hp?part=tplogin

Type:                         HTTPS request

Size (bytes):                 173



----------------------------------------

https://www.jumblo.c...hp?part=tplogin

Referer: https://www.jumblo.c...2loginpanel.php

User input: dala6039090

POST data:



user=dala603

pass=9090





======================================== 24.04.2011 ========================================



========================================

Bot ID:                       ARORA_B4DF76110C834089

Botnet:                       220411SA2

Build:                        6

OS Version:                   XP, SP 2

OS Language:                  1033

Local time:                   24.04.2011 15:39:34

GMT:                          +0:00

Session time:                 02:12:24

Report time:                  24.04.2011 15:39:58

Country/Region/City/Postal code:SA

IPv4:                         77.30.72.184

Process name:                 C:Program FilesInternet ExplorerIEXPLORE.EXE

Source:                       https://www.voipdisc...hp?part=tplogin

Type:                         HTTPS request

Size (bytes):                 353



----------------------------------------

https://www.voipdisc...hp?part=tplogin

Referer: https://www.voipdisc... your password?

User input: ←www.voipdiscount.comvqmfj392vbg5423

POST data:



user=vqmfj392

pass=vbg5423





========================================

Bot ID:                       COM22_7875768F02656D15

Botnet:                       220411SA2

Build:                        6

OS Version:                   XP, SP 3

OS Language:                  1033

Local time:                   24.04.2011 10:06:41

GMT:                          -8:00

Session time:                 08:31:08

Report time:                  24.04.2011 18:06:48

Country/Region/City/Postal code:SA

IPv4:                         94.99.91.216

Process name:                 C:Program FilesInternet Exploreriexplore.exe

Source:                       https://www.actionvo...hp?part=tplogin

Type:                         HTTPS request

Size (bytes):                 321



----------------------------------------

https://www.actionvo...hp?part=tplogin

Referer: https://www.actionvo...1&bcolor=FF1384

User input:

POST data:



========================================

Bot ID:                       DASS-PC_74DEB1E3E9BAC8F9

Botnet:                       220411SA2

Build:                        6

OS Version:                   Seven

OS Language:                  1033

Local time:                   23.04.2011 15:39:45

GMT:                          +0:00

Session time:                 07:36:40

Report time:                  24.04.2011 15:19:17

Country/Region/City/Postal code:SA

IPv4:                         2.91.151.111

Process name:                 C:Program FilesMozilla Firefoxfirefox.exe

Source:                       https://www.actionvo...hp?part=tplogin

Type:                         HTTPS request

Size (bytes):                 375



----------------------------------------

https://www.actionvo...hp?part=tplogin

Referer: https://www.actionvo...1&bcolor=FF1384

User input: YGACTACTACTION VOIPBE←←←beer_boygood

POST data:



user=beer_boy

pass=good





========================================

Bot ID:                       DELL_7875768F71161360

Botnet:                       220411SA2

Build:                        6

OS Version:                   XP, SP 3

OS Language:                  1033

Local time:                   24.04.2011 17:13:29

GMT:                          +0:00

Session time:                 00:02:41

Report time:                  24.04.2011 17:13:57

Country/Region/City/Postal code:SA

IPv4:                         188.48.53.210

Process name:                 C:Program FilesInternet Exploreriexplore.exe

Source:                       https://www.voipdisc...hp?part=tplogin

Type:                         HTTPS request

Size (bytes):                 316



----------------------------------------

https://www.voipdisc...hp?part=tplogin

Referer: https://www.voipdisc... your password?

User input:

POST data:



user=sinu201910

pass=201910





========================================

Bot ID:                       SAFA_7875768F5500106F

Botnet:                       230411SA3

Build:                        6

OS Version:                   XP, SP 3

OS Language:                  1033

Local time:                   24.04.2011 14:56:52

GMT:                          +0:00

Session time:                 07:38:09

Report time:                  24.04.2011 14:56:52

Country/Region/City/Postal code:SA

IPv4:                         188.51.137.26

Process name:                 C:Program FilesInternet ExplorerIEXPLORE.EXE

Source:                       https://www.voipdisc...hp?part=tplogin

Type:                         HTTPS request

Size (bytes):                 336



----------------------------------------

https://www.voipdisc...hp?part=tplogin

Referer: https://www.voipdisc... your password?

User input: voipdiscount14vr653w7363

POST data:



user=14vr653

pass=w7363





========================================

Local time:                   24.04.2011 18:07:52

Session time:                 10:49:13

Report time:                  24.04.2011 18:07:56

IPv4:                         188.55.14.106

Process name:                 C:Program FilesInternet ExplorerIEXPLORE.EXE

Source:                       https://www.actionvo...hp?part=tplogin

Type:                         HTTPS request

Size (bytes):                 375



----------------------------------------

https://www.actionvo...hp?part=tplogin

Referer: https://www.actionvo...1&bcolor=FF1384

User input: youtubeactionactsafavoipsellerfahad

POST data:



user=safavoipseller

pass=fahad





========================================

Bot ID:                       TSHAIKLT_7875768FAB551A54

Botnet:                       220411SA2

Build:                        6

OS Version:                   XP, SP 3

OS Language:                  1033

Local time:                   24.04.2011 17:08:54

GMT:                          +0:00

Session time:                 01:20:19

Report time:                  24.04.2011 17:11:37

Country/Region/City/Postal code:SA

IPv4:                         94.98.181.150

Process name:                 C:Program FilesInternet Exploreriexplore.exe

Source:                       https://www.voipdisc...hp?part=tplogin

Type:                         HTTPS request

Size (bytes):                 315



----------------------------------------

https://www.voipdisc...hp?part=tplogin

Referer: https://www.voipdisc... your password?

User input:

POST data:



user=tareqhere

pass=123123





========================================

Local time:                   24.04.2011 17:09:58

Session time:                 01:21:23

Report time:                  24.04.2011 17:31:39

Process name:                 C:Program FilesInternet Exploreriexplore.exe

Source:                       https://www.voipdisc...hp?part=tplogin

Type:                         HTTPS request

Size (bytes):                 320



----------------------------------------

https://www.voipdisc...hp?part=tplogin

Referer: https://www.voipdisc... your password?

User input:

POST data:



user=tareqhere

pass=myureddress





========================================

Local time:                   24.04.2011 17:11:12

Session time:                 01:22:37

Report time:                  24.04.2011 17:31:42

Process name:                 C:Program FilesInternet Exploreriexplore.exe

Source:                       https://www.voipdisc...hp?part=tplogin

Type:                         HTTPS request

Size (bytes):                 264



----------------------------------------

https://www.voipdisc...hp?part=tplogin

Referer: https://www.voipdisc...&submit=sign in

User input:

POST data:



user=tareqhere

pass=123123





========================================

Local time:                   24.04.2011 17:11:40

Session time:                 01:23:05

Report time:                  24.04.2011 17:31:43

Process name:                 C:Program FilesInternet Exploreriexplore.exe

Source:                       https://www.voipdisc...hp?part=tplogin

Type:                         HTTPS request

Size (bytes):                 266



----------------------------------------

https://www.voipdisc...hp?part=tplogin

Referer: https://www.voipdisc...&submit=sign in

User input:

POST data:



user=tareqhere

pass=tareq123





========================================

Local time:                   24.04.2011 17:12:06

Session time:                 01:23:31

Report time:                  24.04.2011 17:31:45

Process name:                 C:Program FilesInternet Exploreriexplore.exe

Source:                       https://www.voipdisc...hp?part=tplogin

Type:                         HTTPS request

Size (bytes):                 268



----------------------------------------

https://www.voipdisc...hp?part=tplogin

Referer: https://www.voipdisc...&submit=sign in

User input:

POST data:



user=tareqhere

pass=myreddress





======================================== 25.04.2011 ========================================



========================================

Bot ID:                       ACER-PC_74DEB1E347AECF72

Botnet:                       1704111SA1

Build:                        6

OS Version:                   Seven

OS Language:                  1033

Local time:                   24.04.2011 21:37:42

GMT:                          +0:00

Session time:                 01:19:53

Report time:                  25.04.2011 20:49:24

Country/Region/City/Postal code:SA

IPv4:                         188.249.53.77

Process name:                 C:Program FilesMozilla Firefoxfirefox.exe

Source:                       https://www.jumblo.c...hp?part=tplogin

Type:                         HTTPS request

Size (bytes):                 177



----------------------------------------

https://www.jumblo.c...hp?part=tplogin

Referer: https://www.jumblo.c...2loginpanel.php

User input: jbo8958757565

POST data:



user=jbo8958

pass=757565





========================================

Bot ID:                       COMPAQ-10042011_B4DF76110E6C94C8

Botnet:                       1804111SA

Build:                        6

OS Version:                   XP, SP 2

OS Language:                  1033

Local time:                   25.04.2011 20:07:05

GMT:                          +0:00

Session time:                 00:42:45

Report time:                  25.04.2011 20:07:21

Country/Region/City/Postal code:SA

IPv4:                         77.31.90.174

Process name:                 C:Program FilesInternet Exploreriexplore.exe

Source:                       https://www.voipdisc...hp?part=tplogin

Type:                         HTTPS request

Size (bytes):                 328



----------------------------------------

https://www.voipdisc...hp?part=tplogin

Referer: https://www.voipdisc... your password?

User input: bajranglal4265

POST data:



user=bajranglal4265

pass=





========================================

Local time:                   25.04.2011 20:08:17

Session time:                 00:43:56

Report time:                  25.04.2011 20:28:15

Process name:                 C:Program FilesInternet Exploreriexplore.exe

Source:                       https://www.voipdisc...count/index.php

Type:                         HTTPS request

Size (bytes):                 216



----------------------------------------

https://www.voipdisc...count/index.php

Referer: https://www.voipdisc...hp?part=tplogin

User input: bajranglal4265bajranglal4265

POST data:



part=menu

username=bajranglal4265

password=





========================================

Bot ID:                       HOME-D988BD5F44_7875768F6A2FFC68

Botnet:                       220411SA2

Build:                        6

OS Version:                   XP, SP 3

OS Language:                  1033

Local time:                   25.04.2011 13:46:12

GMT:                          +0:00

Session time:                 01:47:41

Report time:                  25.04.2011 13:46:44

Country/Region/City/Postal code:SA

IPv4:                         2.88.238.189

Process name:                 C:Program FilesInternet Exploreriexplore.exe

Source:                       https://www.actionvo...hp?part=tplogin

Type:                         HTTPS request

Size (bytes):                 351



----------------------------------------

https://www.actionvo...hp?part=tplogin

Referer: https://www.actionvo...1&bcolor=FF1384

User input: useract176saudi

POST data:



user=useract176

pass=saudi





========================================

Bot ID:                       TSHAIKLT_7875768FAB551A54

Botnet:                       220411SA2

Build:                        6

OS Version:                   XP, SP 3

OS Language:                  1033

Local time:                   25.04.2011 18:58:23

GMT:                          +0:00

Session time:                 00:02:38

Report time:                  25.04.2011 19:37:18

Country/Region/City/Postal code:SA

IPv4:                         2.89.87.92

Process name:                 C:Program FilesInternet Exploreriexplore.exe

Source:                       https://www.voipinfo....com/Login.aspx

Type:                         HTTPS request

Size (bytes):                 15 189



----------------------------------------

https://www.voipinfo....com/Login.aspx

Referer: https://www.voipinfo....com/Login.aspx

User input: voipinfocentertareqhere*ranu_voip123123

POST data:



========================================

Bot ID:                       WIN7_74DEB1E35FA18813

Botnet:                       220411SA2

Build:                        6

OS Version:                   Seven

OS Language:                  1033

Local time:                   27.04.2011 16:57:46

GMT:                          +0:00

Session time:                 00:06:31

Report time:                  27.04.2011 16:57:44

Country/Region/City/Postal code:SA

IPv4:                         188.49.46.107

Process name:                 C:Program FilesInternet Exploreriexplore.exe

Source:                       https://www.jumblo.c...hp?part=tplogin

Type:                         HTTPS request

Size (bytes):                 190



----------------------------------------

https://www.jumblo.c...hp?part=tplogin

Referer: https://www.jumblo.c...2loginpanel.php

User input: amnwarp3140748465670

POST data:



user=anwarp314074

pass=8465670





========================================

Local time:                   27.04.2011 17:15:20

Session time:                 00:24:05

Report time:                  27.04.2011 17:17:47

Process name:                 C:Program FilesInternet Exploreriexplore.exe

Source:                       https://www.jumblo.c...hp?part=tplogin

Type:                         HTTPS request

Size (bytes):                 239



----------------------------------------

https://www.jumblo.c...hp?part=tplogin

Referer: https://www.jumblo.c...unt/gopanel.php

User input: amnwarp3140748465670anwarp3140748465670

POST data:



indexpanel=yes

user=anwarp314074

pass=8465670

submit=Login %C2%BB





========================================

Local time:                   27.04.2011 17:51:17

Session time:                 01:00:03

Report time:                  27.04.2011 17:51:20

Process name:                 C:Program FilesInternet Exploreriexplore.exe

Source:                       https://www.jumblo.c...hp?part=tplogin

Type:                         HTTPS request

Size (bytes):                 175



----------------------------------------

https://www.jumblo.c...hp?part=tplogin

Referer: https://www.jumblo.c...2loginpanel.php

User input: anwarp314074

POST data:



user=anwarp314074

pass=





========================================

Local time:                   27.04.2011 17:51:52

Session time:                 01:00:38

Report time:                  27.04.2011 18:11:22

Process name:                 C:Program FilesInternet Exploreriexplore.exe

Source:                       https://www.jumblo.c...hp?part=tplogin

Type:                         HTTPS request

Size (bytes):                 201



----------------------------------------

https://www.jumblo.c...hp?part=tplogin

Referer: https://www.jumblo.c...2loginpanel.php

User input: anwarp314074anwarp3140748465670

POST data:



user=anwarp314074

pass=8465670





========================================

Bot ID:                       XP-B17EB7BE08F0_B4DF76117AD6027E

Botnet:                       220411SA2

Build:                        6

OS Version:                   XP, SP 2

OS Language:                  1033

Local time:                   27.04.2011 10:23:01

GMT:                          -7:00

Session time:                 00:05:58

Report time:                  27.04.2011 19:41:40

Country/Region/City/Postal code:SA

IPv4:                         188.55.121.248

Process name:                 C:Program FilesMozilla Firefoxfirefox.exe

Source:                       https://www.voipdisc...hp?part=tplogin

Type:                         HTTPS request

Size (bytes):                 365



----------------------------------------

https://www.voipdisc...hp?part=tplogin

Referer: https://www.voipdisc... your password?

User input: [email protected]←oo.comezaz8←58munxs9937682812345

POST data:



user=ezaz58

pass=12345





======================================== 28.04.2011 ========================================



========================================

Bot ID:                       AL-D34D34B503BD_B4DF7611F11F5999

Botnet:                       220411SA2

Build:                        6

OS Version:                   XP, SP 2

OS Language:                  1033

Local time:                   28.04.2011 02:46:35

GMT:                          -7:00

Session time:                 00:57:09

Report time:                  28.04.2011 11:48:46

Country/Region/City/Postal code:SA

IPv4:                         188.48.29.212

Process name:                 C:Program FilesInternet Exploreriexplore.exe

Source:                       https://www.jumblo.c...hp?part=tplogin

Type:                         HTTPS request

Size (bytes):                 181



----------------------------------------

https://www.jumblo.c...hp?part=tplogin

Referer: https://www.jumblo.c...2loginpanel.php

User input: jusy60736690387

POST data:



user=jusy6073

pass=6690387





========================================

Bot ID:                       ANONYMOUS_7875768FF8F52068

Botnet:                       220411SA2

Build:                        6

OS Version:                   XP, SP 3

OS Language:                  1033

Local time:                   28.04.2011 08:14:02

GMT:                          -5:00

Session time:                 236:19:31

Report time:                  28.04.2011 13:29:18

Country/Region/City/Postal code:SA

IPv4:                         188.50.103.94

Process name:                 C:Program FilesInternet ExplorerIEXPLORE.EXE

Source:                       https://www.jumblo.c...hp?part=tplogin

Type:                         HTTPS request

Size (bytes):                 181



----------------------------------------

https://www.jumblo.c...hp?part=tplogin

Referer: https://www.jumblo.c...2loginpanel.php

User input: naseerali843212

POST data:



user=naseerali84

pass=3212





========================================

Bot ID:                       ARCAD3_B4DF7611B019826C

Botnet:                       220411SA2

Build:                        6

OS Version:                   XP, SP 2

OS Language:                  1033

Local time:                   28.04.2011 17:54:09

GMT:                          +0:00

Session time:                 02:33:06

Report time:                  28.04.2011 17:54:32

Country/Region/City/Postal code:SA

IPv4:                         188.54.18.75

Process name:                 C:Program FilesInternet Exploreriexplore.exe

Source:                       https://www.actionvo...hp?part=tplogin

Type:                         HTTPS request

Size (bytes):                 302



----------------------------------------

https://www.actionvo...hp?part=tplogin

Referer: https://www.actionvo...2&bcolor=FFFFFF

User input: actionvoipjs8354191221

POST data:



user=js8354

pass=191221





========================================

Bot ID:                       JAAN-6737F5CDEF_B4DF76112BACB4E8

Botnet:                       220411SA2

Build:                        6

OS Version:                   XP, SP 2

OS Language:                  1033

Local time:                   28.04.2011 11:51:50

GMT:                          -7:00

Session time:                 00:23:25

Report time:                  28.04.2011 18:52:01

Country/Region/City/Postal code:SA

IPv4:                         188.54.22.116

Process name:                 C:Program FilesInternet Exploreriexplore.exe

Source:                       https://www.jumblo.c...hp?part=tplogin

Type:                         HTTPS request

Size (bytes):                 192



----------------------------------------

https://www.jumblo.c...hp?part=tplogin

Referer: https://www.jumblo.c...2loginpanel.php

User input: 1111111111111111←HUS11221122

POST data:



user=HUS1122

pass=1122





========================================

Local time:                   28.04.2011 12:02:13

Session time:                 00:33:48

Report time:                  28.04.2011 19:16:42

Process name:                 C:Program FilesInternet Exploreriexplore.exe

Source:                       https://www.actionvo...hp?part=tplogin

Type:                         HTTPS request

Size (bytes):                 343



----------------------------------------

https://www.actionvo...hp?part=tplogin

Referer: https://www.actionvo...1&bcolor=FF1384

User input: sad10041004

POST data:



user=sad1004

pass=1004





========================================

Local time:                   28.04.2011 12:02:13

Session time:                 00:33:48

Report time:                  28.04.2011 19:16:43

Process name:                 C:Program FilesInternet Exploreriexplore.exe

Source:                       https://www.actionvo...hp?part=tplogin

Type:                         HTTPS request

Size (bytes):                 343



----------------------------------------

https://www.actionvo...hp?part=tplogin

Referer: https://www.actionvo...1&bcolor=FF1384

User input: sad10041004

POST data:



user=sad1004

pass=1004





========================================

Local time:                   28.04.2011 12:03:03

Session time:                 00:34:38

Report time:                  28.04.2011 19:16:47

Process name:                 C:Program FilesInternet Exploreriexplore.exe

Source:                       https://www.actionvo...hp?part=tplogin

Type:                         HTTPS request

Size (bytes):                 301



----------------------------------------

https://www.actionvo...hp?part=tplogin

Referer: https://www.actionvo...2&bcolor=FFFFFF

User input: sad10041004sad10041004

POST data:



user=sad1004

pass=1004





========================================

Local time:                   28.04.2011 12:05:58

Session time:                 00:37:34

Report time:                  28.04.2011 19:16:50

Process name:                 C:Program FilesInternet Exploreriexplore.exe

Source:                       https://www.actionvo...hp?part=tplogin

Type:                         HTTPS request

Size (bytes):                 365



----------------------------------------

https://www.actionvo...hp?part=tplogin

Referer: https://www.actionvo...1&bcolor=FF1384

User input: sad10041004sad10041004sad10041004

POST data:



user=sad1004

pass=1004





========================================

Local time:                   28.04.2011 12:09:39

Session time:                 00:41:15

Report time:                  28.04.2011 19:16:52

Process name:                 C:Program FilesInternet Exploreriexplore.exe

Source:                       https://www.actionvo...hp?part=tplogin

Type:                         HTTPS request

Size (bytes):                 383



----------------------------------------

https://www.actionvo...hp?part=tplogin

Referer: https://www.actionvo...1&bcolor=FF1384

User input: sad10041004sad10041004sad10041004sad1004sad10041004

POST data:



user=sad1004

pass=1004





========================================

Local time:                   28.04.2011 12:12:35

Session time:                 00:01:54

Report time:                  28.04.2011 21:32:43

IPv4:                         188.50.25.217

Process name:                 C:Program FilesInternet Exploreriexplore.exe

Source:                       https://www.actionvo...hp?part=tplogin

Type:                         HTTPS request

Size (bytes):                 343



----------------------------------------

https://www.actionvo...hp?part=tplogin

Referer: https://www.actionvo...1&bcolor=FF1384

User input: sad10041004

POST data:



user=sad1004

pass=1004





========================================

Local time:                   28.04.2011 12:17:26

Session time:                 00:03:03

Report time:                  28.04.2011 21:32:45

Process name:                 C:Program FilesInternet Exploreriexplore.exe

Source:                       https://www.actionvo...hp?part=tplogin

Type:                         HTTPS request

Size (bytes):                 343



----------------------------------------

https://www.actionvo...hp?part=tplogin

Referer: https://www.actionvo...1&bcolor=FF1384

User input: sad10041004

POST data:



user=sad1004

pass=1004





========================================

Local time:                   28.04.2011 12:22:51

Session time:                 00:08:27

Report time:                  28.04.2011 21:32:46

Process name:                 C:Program FilesInternet Exploreriexplore.exe

Source:                       https://www.jumblo.c...hp?part=tplogin

Type:                         HTTPS request

Size (bytes):                 173



----------------------------------------

https://www.jumblo.c...hp?part=tplogin

Referer: https://www.jumblo.c...2loginpanel.php

User input: hus11221122

POST data:



user=hus1122

pass=1122





========================================

Local time:                   28.04.2011 12:26:55

Session time:                 00:12:32

Report time:                  28.04.2011 21:32:48

Process name:                 C:Program FilesInternet Exploreriexplore.exe

Source:                       https://www.actionvo...hp?part=tplogin

Type:                         HTTPS request

Size (bytes):                 344



----------------------------------------

https://www.actionvo...hp?part=tplogin

Referer: https://www.actionvo...1&bcolor=FF1384

User input: saDd10041004

POST data:



user=sad1004

pass=1004





========================================

Local time:                   28.04.2011 13:48:29

Session time:                 00:09:23

Report time:                  28.04.2011 21:52:53

Process name:                 C:Program FilesInternet Exploreriexplore.exe

Source:                       https://www.jumblo.c...hp?part=tplogin

Type:                         HTTPS request

Size (bytes):                 173



----------------------------------------

https://www.jumblo.c...hp?part=tplogin

Referer: https://www.jumblo.c...2loginpanel.php

User input: sad10041004

POST data:



user=sad1004

pass=1004





========================================

Bot ID:                       JAF-42CCB7DE4FF_7875768FCF5E956E

Botnet:                       220411SA2

Build:                        6

OS Version:                   XP, SP 3

OS Language:                  1033

Local time:                   28.04.2011 07:12:01

GMT:                          +0:00

Session time:                 01:09:17

Report time:                  28.04.2011 12:56:30

Country/Region/City/Postal code:SA

IPv4:                         94.98.221.103

Process name:                 C:Program FilesInternet Exploreriexplore.exe

Source:                       https://www.jumblo.c...hp?part=tplogin

Type:                         HTTPS request

Size (bytes):                 198



----------------------------------------

https://www.jumblo.c...hp?part=tplogin

Referer: https://www.jumblo.c...2loginpanel.php

User input: dainikipl pointjumblosaud444danish

POST data:



user=saud444

pass=danish





========================================

Local time:                   28.04.2011 18:59:52

Session time:                 06:04:51

Report time:                  28.04.2011 19:00:46

Process name:                 C:Program FilesInternet Exploreriexplore.exe

Source:                       https://www.jumblo.c...hp?part=tplogin

Type:                         HTTPS request

Size (bytes):                 243



----------------------------------------

https://www.jumblo.c...hp?part=tplogin

Referer: https://www.jumblo.c...2loginpanel.php

User input: bhavana  hindi movie billu bachchan ek dil jalakhalejajumblodr.javeed3809876

POST data:



user=dr.javeed38

pass=09876





========================================

Bot ID:                       JAVALAK_B4DF7611B24FDFF7

Botnet:                       220411SA2

Build:                        6

OS Version:                   XP, SP 2

OS Language:                  1033

Local time:                   28.04.2011 11:27:59

GMT:                          +0:00

Session time:                 04:08:17

Report time:                  28.04.2011 11:45:07

Country/Region/City/Postal code:SA

IPv4:                         188.249.222.11

Process name:                 C:Program FilesMozilla Firefoxfirefox.exe

Source:                       https://www.jumblo.c...hp?part=tplogin

Type:                         HTTPS request

Size (bytes):                 174



----------------------------------------

https://www.jumblo.c...hp?part=tplogin

Referer: https://www.jumblo.c...2loginpanel.php

User input: jjiqo9014307

POST data:



user=jiqo901

pass=4307





========================================

Local time:                   28.04.2011 11:31:00

Session time:                 04:11:19

Report time:                  28.04.2011 11:45:16

Process name:                 C:Program FilesMozilla Firefoxfirefox.exe

Source:                       https://www.jumblo.c...hp?part=tplogin

Type:                         HTTPS request

Size (bytes):                 195



----------------------------------------

https://www.jumblo.c...hp?part=tplogin

Referer: https://www.jumblo.c...2loginpanel.php

User input: jjiqo90143079746730453jiqo9014307

POST data:



user=jiqo901

pass=4307





========================================

Local time:                   28.04.2011 18:04:37

Session time:                 10:44:55

Report time:                  28.04.2011 18:05:42

Process name:                 C:Program FilesMozilla Firefoxfirefox.exe

Source:                       https://www.jumblo.c...hp?part=tplogin

Type:                         HTTPS request

Size (bytes):                 273



----------------------------------------

https://www.jumblo.c...hp?part=tplogin

Referer: https://www.jumblo.c...2loginpanel.php

User input: 0483274021704832740217p10203040s04832740217res←j←zx←api←← at←rdiaraza ardiajumblo.comjuupw47437711

POST data:



user=jupw4743

pass=7711





========================================

Bot ID:                       MUSTHAFA-0B8793_B4DF761197E8ACF0

Botnet:                       220411SA2

Build:                        6

OS Version:                   XP, SP 2

OS Language:                  1033

Local time:                   28.04.2011 17:54:43

GMT:                          +0:00

Session time:                 04:25:35

Report time:                  28.04.2011 17:55:15

Country/Region/City/Postal code:SA

IPv4:                         77.30.176.137

Process name:                 C:Program FilesInternet Exploreriexplore.exe

Source:                       https://www.jumblo.c...hp?part=tplogin

Type:                         HTTPS request

Size (bytes):                 173



----------------------------------------

https://www.jumblo.c...hp?part=tplogin

Referer: https://www.jumblo.c...2loginpanel.php

User input: dala9509090

POST data:



user=dala950

pass=9090





========================================

Bot ID:                       SHEFY_B4DF7611936E5661

Botnet:                       220411SA2

Build:                        6

OS Version:                   XP, SP 2

OS Language:                  1033

Local time:                   28.04.2011 05:55:14

GMT:                          +0:00

Session time:                 06:03:23

Report time:                  28.04.2011 06:25:07

Country/Region/City/Postal code:SA

IPv4:                         2.89.178.245

Process name:                 C:Program FilesInternet ExplorerIEXPLORE.EXE

Source:                       https://www.actionvo...hp?part=tplogin

Type:                         HTTPS request

Size (bytes):                 355



----------------------------------------

https://www.actionvo...hp?part=tplogin

Referer: https://www.actionvo...1&bcolor=FF1384

User input: gactionvmalas123shefy

POST data:



user=malas123

pass=shefy





========================================

Bot ID:                       UCL-ZHAOYU_B4DF76113F29AC51

Botnet:                       1103114

Build:                        6

OS Version:                   XP, SP 2

OS Language:                  1033

Local time:                   15.04.2011 17:58:37

GMT:                          +0:00

Session time:                 119:27:06

Report time:                  28.04.2011 15:29:33

Country/Region/City/Postal code:KE

IPv4:                         41.222.163.159

Process name:                 C:Program FilesMozilla Firefoxfirefox.exe

Source:                       https://www.voipgain...hp?part=tplogin

Type:                         HTTPS request

Size (bytes):                 500



----------------------------------------

https://www.voipgain...hp?part=tplogin

Referer: https://www.voipgain...1&bcolor=FF1384

User input: facc147896ha aaby←ti abti macne fiican sa ii tahay ha amaxeey tahayhey amaley whts up iana  dhalod  gareeyo ayoow iga rabaa so wmahan waa sameynoy  i suga  ha issadin4444moh

POST data:



user=issadin

pass=4444moh





========================================

Local time:                   15.04.2011 17:59:34

Session time:                 119:28:02

Report time:                  28.04.2011 15:29:35

Process name:                 C:Program FilesMozilla Firefoxfirefox.exe

Source:                       https://www.voipgain...hp?part=tplogin

Type:                         HTTPS request

Size (bytes):                 469



----------------------------------------

https://www.voipgain...hp?part=tplogin

Referer: https://www.voipgain...2&bcolor=FFFFFF

User input: facc147896ha aaby←ti abti macne fiican sa ii tahay ha amaxeey tahayhey amaley whts up iana  dhalod  gareeyo ayoow iga rabaa so wmahan waa sameynoy  i suga  ha issadin4444mohu←issadin4444moh

POST data:



user=issadin

pass=4444moh





========================================

Local time:                   15.04.2011 18:06:47

Session time:                 119:35:16

Report time:                  28.04.2011 15:29:37

Process name:                 C:Program FilesMozilla Firefoxfirefox.exe

Source:                       https://www.voipgain...hp?part=tplogin

Type:                         HTTPS request

Size (bytes):                 456



----------------------------------------

https://www.voipgain...hp?part=tplogin

Referer: https://www.voipgain...1&bcolor=FF1384

User input: www.vwww.vyusuf←←←←←← yusufhassan28 [20:06:18] yusuf muhumud: muhumud5000

POST data:



user=yusufhassan28

pass=%5B20%3A06%3A18%5D yusuf muhumud%3A muhumud5000





========================================

Local time:                   15.04.2011 18:09:24

Session time:                 119:37:52

Report time:                  28.04.2011 15:29:38

Process name:                 C:Program FilesMozilla Firefoxfirefox.exe

Source:                       https://www.voipgain...hp?part=tplogin

Type:                         HTTPS request

Size (bytes):                 497



----------------------------------------

https://www.voipgain...hp?part=tplogin

Referer: https://www.voipgain...1&bcolor=FF1384

User input: www.vwww.vyusuf←←←←←← yusufhassan28 [20:06:18] yusuf muhumud: muhumud5000← [20:06:18] yusuf muhumud: muhumud5000

POST data:



user=yusufhassan28

pass=%5B20%3A06%3A18%5D yusuf muhumud%3A muhumud5000





========================================

Local time:                   15.04.2011 18:11:00

Session time:                 119:39:28

Report time:                  28.04.2011 15:29:51

Process name:                 C:Program FilesMozilla Firefoxfirefox.exe

Source:                       https://www.voipgain...hp?part=tplogin

Type:                         HTTPS request

Size (bytes):                 472



----------------------------------------

https://www.voipgain...hp?part=tplogin

Referer: https://www.voipgain...1&bcolor=FF1384

User input: www.vwww.vyusuf←←←←←← yusufhassan28 [20:06:18] yusuf muhumud: muhumud5000← [20:06:18] yusuf muhumud: muhumud5000muhmud30000

POST data:



user=yusufhassan28

pass=muhmud30000





========================================

Bot ID:                       YOUR-EFAAD99D1F_B4DF7611A2560E3E

Botnet:                       220411SA2

Build:                        6

OS Version:                   XP, SP 2

OS Language:                  1033

Local time:                   28.04.2011 11:10:30

GMT:                          +0:00

Session time:                 00:57:12

Report time:                  28.04.2011 11:19:55

Country/Region/City/Postal code:SA

IPv4:                         188.55.137.168

Process name:                 C:Program FilesMozilla Firefoxfirefox.exe

Source:                       https://secure.fastvoip.com/login

Type:                         HTTPS request

Size (bytes):                 377



----------------------------------------

https://secure.fastvoip.com/login

Referer: https://secure.fastvoip.com/en/

User input: www.focuskerwapmasala←←←←←←←←←←←←←←←←←←←←←←←www.123music.com←qwww.freewapzone.com←www.fastvoip.comisas←www.google.comww←←←fast voip creshaireview

POST data:



login%5Busername%5D=shaimacp

login%5Bpassword%5D=review

submit_login=Login





========================================

Local time:                   28.04.2011 11:16:13

Session time:                 01:02:54

Report time:                  28.04.2011 11:20:09

Process name:                 C:Program FilesMozilla Firefoxfirefox.exe

Source:                       https://secure.fastvoip.com/login

Type:                         HTTPS request

Size (bytes):                 405



----------------------------------------

https://secure.fastvoip.com/login

Referer: https://secure.fastv...ler/show/id/192

User input: www.focuskerwapmasala←←←←←←←←←←←←←←←←←←←←←←←www.123music.com←qwww.freewapzone.com←www.fastvoip.comisas←www.google.comww←←←fast voip creshaireviewsshaireview

POST data:



login%5Busername%5D=shaimacp

login%5Bpassword%5D=review

submit_login=Login





========================================

Local time:                   28.04.2011 11:24:19

Session time:                 01:11:01

Report time:                  28.04.2011 11:42:39

IPv4:                         90.148.3.207

Process name:                 C:Program FilesMozilla Firefoxfirefox.exe

Source:                       https://secure.fastv...payment/confirm

Type:                         HTTPS request

Size (bytes):                 232



----------------------------------------

https://secure.fastv...payment/confirm

Referer: https://secure.fastv.../payment/amount

User input:



Local time:                   28.04.2011 11:25:36

Session time:                 01:12:18

Report time:                  28.04.2011 11:42:42

Process name:                 C:Program FilesMozilla Firefoxfirefox.exe

Source:                       https://secure.fastv...payment/confirm

Type:                         HTTPS request

Size (bytes):                 233



----------------------------------------

https://secure.fastv...payment/confirm

Referer: https://secure.fastv.../payment/amount

User input:

POST data:



payment%5Bmethod%5D=122

payment%5Bamount%5D=1000

payment%5Bcoupon_code%5D=

payment_form_submit=start payment %3E





========================================

Local time:                   28.04.2011 11:25:40

Session time:                 01:12:21

Report time:                  28.04.2011 11:42:43

Process name:                 C:Program FilesMozilla Firefoxfirefox.exe

Source:                       https://secure.fastv.../payment/create

Type:                         HTTPS request

Size (bytes):                 233



----------------------------------------

https://secure.fastv.../payment/create

Referer: https://secure.fastv...payment/confirm

User input:

POST data:



payment%5Bmethod%5D=122

payment%5Bamount%5D=1000

payment%5Bcoupon_code%5D=

payment_form_submit=start payment %3E





======================================== 29.04.2011 ========================================



========================================

Bot ID:                       ARABSWELL_7875768F1032C982

Botnet:                       230411SA2

Build:                        6

OS Version:                   XP, SP 3

OS Language:                  1033

Local time:                   29.04.2011 16:36:59

GMT:                          +2:00

Session time:                 1193:02:47

Report time:                  29.04.2011 14:37:27

Country/Region/City/Postal code:SA

IPv4:                         94.98.140.195

Process name:                 C:Program FilesInternet Exploreriexplore.exe

Source:                       https://www.actionvo...hp?part=tplogin

Type:                         HTTPS request

Size (bytes):                 358



----------------------------------------

https://www.actionvo...hp?part=tplogin

Referer: https://www.actionvo...1&bcolor=FF1384

User input: ←jobincy5011223344

POST data:



user=jobincy50

pass=11223344





========================================

Bot ID:                       ARORA_B4DF76110C834089

Botnet:                       220411SA2

Build:                        6

OS Version:                   XP, SP 2

OS Language:                  1033

Local time:                   29.04.2011 16:09:57

GMT:                          +0:00

Session time:                 00:55:59

Report time:                  29.04.2011 16:10:42

Country/Region/City/Postal code:SA

IPv4:                         188.49.150.136

Process name:                 C:Program FilesInternet ExplorerIEXPLORE.EXE

Source:                       https://www.actionvo...hp?part=tplogin

Type:                         HTTPS request

Size (bytes):                 361



----------------------------------------

https://www.actionvo...hp?part=tplogin

Referer: https://www.actionvo...1&bcolor=FF1384

User input: www.actions25122872761738

POST data:



user=s2512287

pass=2761738





========================================

Bot ID:                       ROYALMUS-4779B7_B4DF76112906B294

Botnet:                       220411SA2

Build:                        6

OS Version:                   XP, SP 2

OS Language:                  1033

Local time:                   29.04.2011 13:37:16

GMT:                          +0:00

Session time:                 04:30:44

Report time:                  29.04.2011 13:38:36

Country/Region/City/Postal code:SA

IPv4:                         77.31.86.179

Process name:                 C:Program FilesMozilla Firefoxfirefox.exe

Source:                       https://www.voipdisc...hp?part=tplogin

Type:                         HTTPS request

Size (bytes):                 354



----------------------------------------

https://www.voipdisc...hp?part=tplogin

Referer: https://www.voipdisc... your password?

User input: voipdivi←oipdiscountm←vmubs930112233

POST data:



user=vmubs930

pass=112233





========================================

Bot ID:                       USER-0804A47DA5_B4DF761107A3AB2B

Botnet:                       220411SA2

Build:                        6

OS Version:                   XP, SP 2

OS Language:                  1033

Local time:                   28.04.2011 20:33:31

GMT:                          +0:00

Session time:                 00:03:42

Report time:                  29.04.2011 18:00:05

Country/Region/City/Postal code:SA

IPv4:                         188.51.89.111

Process name:                 C:Program FilesInternet Exploreriexplore.exe

Source:                       https://www.actionvo...hp?part=tplogin

Type:                         HTTPS request

Size (bytes):                 369



----------------------------------------

https://www.actionvo...hp?part=tplogin

Referer: https://www.actionvo...1&bcolor=FF1384

User input: acton vaip.comcvr ksa838sabeena

POST data:



user=cvr ksa838

pass=sabeena





========================================

Local time:                   28.04.2011 20:33:31

Session time:                 00:03:42

Report time:                  29.04.2011 18:00:12

Process name:                 C:Program FilesInternet Exploreriexplore.exe

Source:                       https://www.actionvo...hp?part=tplogin

Type:                         HTTPS request

Size (bytes):                 369



----------------------------------------

https://www.actionvo...hp?part=tplogin

Referer: https://www.actionvo...1&bcolor=FF1384

User input: acton vaip.comcvr ksa838sabeena

POST data:



user=cvr ksa838

pass=sabeena





========================================

Local time:                   29.04.2011 11:43:40

Session time:                 01:52:58

Report time:                  29.04.2011 18:00:16

Process name:                 C:Program FilesInternet Exploreriexplore.exe

Source:                       https://www.actionvo...hp?part=tplogin

Type:                         HTTPS request

Size (bytes):                 368



----------------------------------------

https://www.actionvo...hp?part=tplogin

Referer: https://www.actionvo...1&bcolor=FF1384

User input: acton vaip.comvcvrksa838sabeena

POST data:



user=cvrksa838

pass=sabeena





========================================

Local time:                   29.04.2011 18:11:35

Session time:                 00:34:25

Report time:                  29.04.2011 18:20:22

Process name:                 C:Program FilesInternet Exploreriexplore.exe

Source:                       https://www.actionvo...hp?part=tplogin

Type:                         HTTPS request

Size (bytes):                 368



----------------------------------------

https://www.actionvo...hp?part=tplogin

Referer: https://www.actionvo...1&bcolor=FF1384

User input: acton  vaip.comcvrksa838sabeena

POST data:



user=cvrksa838

pass=sabeena





========================================

Local time:                   29.04.2011 18:13:56

Session time:                 00:36:47

Report time:                  29.04.2011 18:21:06

Process name:                 C:Program FilesInternet Exploreriexplore.exe

Source:                       https://www.actionvo...hp?part=tplogin

Type:                         HTTPS request

Size (bytes):                 368



----------------------------------------

https://www.actionvo...hp?part=tplogin

Referer: https://www.actionvo...1&bcolor=FF1384

User input: acton  vaip.comcvrksa838sabeena

POST data:



user=cvrksa838

pass=sabeena





========================================

Local time:                   29.04.2011 18:14:05

Session time:                 00:36:56

Report time:                  29.04.2011 18:21:08

Process name:                 C:Program FilesInternet Exploreriexplore.exe

Source:                       https://www.actionvo...hp?part=tplogin

Type:                         HTTPS request

Size (bytes):                 368



----------------------------------------

https://www.actionvo...hp?part=tplogin

Referer: https://www.actionvo...1&bcolor=FF1384

User input: acton  vaip.comcvrksa838sabeena

POST data:



user=cvrksa838

pass=sabeena





========================================

Local time:                   29.04.2011 18:14:30

Session time:                 00:37:20

Report time:                  29.04.2011 18:22:00

Process name:                 C:Program FilesInternet Exploreriexplore.exe

Source:                       https://www.actionvo...hp?part=tplogin

Type:                         HTTPS request

Size (bytes):                 375



----------------------------------------

https://www.actionvo...hp?part=tplogin

Referer: https://www.actionvo...1&bcolor=FF1384

User input: acton  vaip.comcvrksa838sabeenasabeena

POST data:



user=cvrksa838

pass=sabeena





========================================

Bot ID:                       XP-B55BC9A05D8B_B4DF7611C49F6E00

Botnet:                       220411SA2

Build:                        6

OS Version:                   XP, SP 2

OS Language:                  1033

Local time:                   29.04.2011 05:24:55

GMT:                          +0:00

Session time:                 03:27:31

Report time:                  29.04.2011 13:39:28

Country/Region/City/Postal code:SA

IPv4:                         2.91.233.70

Process name:                 C:Program FilesMozilla Firefoxfirefox.exe

Source:                       https://www.jumblo.c...hp?part=tplogin

Type:                         HTTPS request

Size (bytes):                 226



----------------------------------------

https://www.jumblo.c...hp?part=tplogin

Referer: https://www.jumblo.c...unt/gopanel.php

User input: hassancp74hassanentcghassan787482

POST data:



indexpanel=yes

user=hassan

pass=787482

submit=Login %C2%BB





========================================

Local time:                   29.04.2011 05:25:39

Session time:                 03:28:15

Report time:                  29.04.2011 14:00:01

Process name:                 C:Program FilesMozilla Firefoxfirefox.exe

Source:                       https://www.jumblo.c...hp?part=tplogin

Type:                         HTTPS request

Size (bytes):                 238



----------------------------------------

https://www.jumblo.c...hp?part=tplogin

Referer: https://www.jumblo.c...unt/gopanel.php

User input: hassancp74hassanentcghassan787482hassan787482

POST data:



indexpanel=yes

user=hassan

pass=787482

submit=Login %C2%BB





========================================

Local time:                   29.04.2011 05:25:54

Session time:                 03:28:30

Report time:                  29.04.2011 14:00:31

Process name:                 C:Program FilesMozilla Firefoxfirefox.exe

Source:                       https://www.jumblo.c...hp?part=tplogin

Type:                         HTTPS request

Size (bytes):                 238



----------------------------------------

https://www.jumblo.c...hp?part=tplogin

Referer: https://www.jumblo.c...unt/gopanel.php

User input: hassancp74hassanentcghassan787482hassan787482

POST data:



indexpanel=yes

user=hassan

pass=787482

submit=Login %C2%BB





========================================

Bot ID:                       ZACKY-70A31579B_7875768F01029330

Botnet:                       220411SA2

Build:                        6

OS Version:                   XP, SP 3

OS Language:                  1033

Local time:                   29.04.2011 07:07:39

GMT:                          -7:00

Session time:                 00:12:09

Report time:                  29.04.2011 15:05:36

Country/Region/City/Postal code:SA

IPv4:                         77.30.76.249

Process name:                 C:Program FilesMozilla Firefoxfirefox.exe

Source:                       https://www.actionvo...hp?part=tplogin

Type:                         HTTPS request

Size (bytes):                 318



----------------------------------------

https://www.actionvo...hp?part=tplogin

Referer: https://www.actionvo...2&bcolor=FFFFFF

User input: actionviopather_zoheabfootball

POST data:



user=ather_zoheab

pass=football





======================================== 30.04.2011 ========================================



========================================

Bot ID:                       ABDUL_7875768F5666CAAB

Botnet:                       220411SA2

Build:                        6

OS Version:                   XP, SP 3

OS Language:                  1033

Local time:                   30.04.2011 14:18:56

GMT:                          +0:00

Session time:                 09:28:58

Report time:                  30.04.2011 14:19:46

Country/Region/City/Postal code:SA

IPv4:                         94.98.190.255

Process name:                 C:Program FilesInternet Exploreriexplore.exe

Source:                       https://www.actionvo...hp?part=tplogin

Type:                         HTTPS request

Size (bytes):                 348



----------------------------------------

https://www.actionvo...hp?part=tplogin

Referer: https://www.actionvo...1&bcolor=FF1384

User input:

POST data:



user=abdullaskl%60

pass=farveenabdul15





========================================

Local time:                   30.04.2011 14:19:18

Session time:                 09:29:21

Report time:                  30.04.2011 16:41:52

IPv4:                         2.91.19.127

Process name:                 C:Program FilesInternet Exploreriexplore.exe

Source:                       https://www.actionvo...hp?part=tplogin

Type:                         HTTPS request

Size (bytes):                 348



----------------------------------------

https://www.actionvo...hp?part=tplogin

Referer: https://www.actionvo...1&bcolor=FF1384

User input:

POST data:



user=abdullaskl%60

pass=farveenabdul15





========================================

Bot ID:                       ARORA_B4DF76110C834089

Botnet:                       220411SA2

Build:                        6

OS Version:                   XP, SP 2

OS Language:                  1033

Local time:                   30.04.2011 19:27:05

GMT:                          +0:00

Session time:                 13:13:27

Report time:                  30.04.2011 19:45:39

Country/Region/City/Postal code:SA

IPv4:                         188.49.150.136

Process name:                 C:Program FilesInternet ExplorerIEXPLORE.EXE

Source:                       https://www.actionvo...hp?part=tplogin

Type:                         HTTPS request

Size (bytes):                 352



----------------------------------------

https://www.actionvo...hp?part=tplogin

Referer: https://www.actionvo...1&bcolor=FF1384

User input: ss25122872761738

POST data:



user=s2512287

pass=2761738





========================================

Bot ID:                       JAF-42CCB7DE4FF_7875768FCF5E956E

Botnet:                       220411SA2

Build:                        6

OS Version:                   XP, SP 3

OS Language:                  1033

Local time:                   30.04.2011 17:55:28

GMT:                          +0:00

Session time:                 04:58:20

Report time:                  30.04.2011 17:58:32

Country/Region/City/Postal code:SA

IPv4:                         2.89.20.224

Process name:                 C:Program FilesInternet Exploreriexplore.exe

Source:                       https://www.jumblo.c...hp?part=tplogin

Type:                         HTTPS request

Size (bytes):                 207



----------------------------------------

https://www.jumblo.c...hp?part=tplogin

Referer: https://www.jumblo.c...2loginpanel.php

User input: jumbloatheralihyderabadunilever

POST data:



user=atheralihyderabad

pass=unilever





========================================

Local time:                   30.04.2011 17:55:28

Session time:                 04:58:20

Report time:                  30.04.2011 18:52:57

Process name:                 C:Program FilesInternet Exploreriexplore.exe

Source:                       https://www.jumblo.c...hp?part=tplogin

Type:                         HTTPS request

Size (bytes):                 207



----------------------------------------

https://www.jumblo.c...hp?part=tplogin

Referer: https://www.jumblo.c...2loginpanel.php

User input: jumbloatheralihyderabadunilever

POST data:



user=atheralihyderabad

pass=unilever





========================================

Bot ID:                       WELCOME_B4DF7611F10D270F

Botnet:                       220411SA2

Build:                        6

OS Version:                   XP, SP 2

OS Language:                  1033

Local time:                   30.04.2011 18:53:57

GMT:                          +0:00

Session time:                 05:09:30

Report time:                  30.04.2011 18:54:09

Country/Region/City/Postal code:SA

IPv4:                         188.54.35.142

Process name:                 C:Program FilesInternet Exploreriexplore.exe

Source:                       https://www.actionvo...hp?part=tplogin

Type:                         HTTPS request

Size (bytes):                 331



----------------------------------------

https://www.actionvo...hp?part=tplogin

Referer: https://www.actionvo...1&bcolor=FF1384

User input:

POST data:



user=tamil3

pass=3030





========================================

Local time:                   30.04.2011 19:01:00

Session time:                 05:16:33

Report time:                  30.04.2011 19:14:49

Process name:                 C:Program FilesInternet Exploreriexplore.exe

Source:                       https://www.actionvo...hp?part=tplogin

Type:                         HTTPS request

Size (bytes):                 337



----------------------------------------

https://www.actionvo...hp?part=tplogin

Referer: https://www.actionvo...1&bcolor=FF1384

User input:

POST data:



user=nazeer_107

pass=shiraj





======================================== 01.05.2011 ========================================



========================================

Bot ID:                       ABDUL_7875768F5666CAAB

Botnet:                       220411SA2

Build:                        6

OS Version:                   XP, SP 3

OS Language:                  1033

Local time:                   30.04.2011 14:19:18

GMT:                          +0:00

Session time:                 09:29:21

Report time:                  01.05.2011 06:23:57

Country/Region/City/Postal code:SA

IPv4:                         2.90.215.51

Process name:                 C:Program FilesInternet Exploreriexplore.exe

Source:                       https://www.actionvo...hp?part=tplogin

Type:                         HTTPS request

Size (bytes):                 348



----------------------------------------

https://www.actionvo...hp?part=tplogin

Referer: https://www.actionvo...1&bcolor=FF1384

User input:

POST data:



user=abdullaskl%60

pass=farveenabdul15





========================================

Bot ID:                       ANIL_7875768F0619C781

Botnet:                       220411SA2

Build:                        6

OS Version:                   XP, SP 3

OS Language:                  1033

Local time:                   01.05.2011 11:14:05

GMT:                          +0:00

Session time:                 00:15:00

Report time:                  01.05.2011 11:31:48

Country/Region/City/Postal code:SA

IPv4:                         2.90.85.81

Process name:                 C:Program FilesInternet Exploreriexplore.exe

Source:                       https://www.voipdisc...hp?part=tplogin

Type:                         HTTPS request

Size (bytes):                 334



----------------------------------------

https://www.voipdisc...hp?part=tplogin

Referer: https://www.voipdisc... your password?

User input:  Harlev erik7777

POST data:



user=tecanishlal

pass=anil123





========================================

Bot ID:                       HASIB-PC_74DEB1E3457D5F6C

Botnet:                       220411SA2

Build:                        6

OS Version:                   Seven

OS Language:                  1025

Local time:                   01.05.2011 18:10:45

GMT:                          +0:00

Session time:                 00:17:21

Report time:                  01.05.2011 18:12:04

Country/Region/City/Postal code:SA

IPv4:                         188.48.20.203

Process name:                 C:Program FilesInternet Exploreriexplore.exe

Source:                       https://www.jumblo.c...hp?part=tplogin

Type:                         HTTPS request

Size (bytes):                 209



----------------------------------------

https://www.jumblo.c...hp?part=tplogin

Referer: https://www.jumblo.c...unt/gopanel.php

User input: Psahbn40858414

POST data:



indexpanel=yes

user=Psahbn408

pass=58414

submit=Login %C2%BB





========================================

Local time:                   01.05.2011 18:10:45

Session time:                 00:17:21

Report time:                  01.05.2011 18:12:05

Process name:                 C:Program FilesInternet Exploreriexplore.exe

Source:                       https://www.jumblo.c...hp?part=tplogin

Type:                         HTTPS request

Size (bytes):                 209



----------------------------------------

https://www.jumblo.c...hp?part=tplogin

Referer: https://www.jumblo.c...unt/gopanel.php

User input: Psahbn40858414

POST data:



indexpanel=yes

user=Psahbn408

pass=58414

submit=Login %C2%BB





========================================

Local time:                   01.05.2011 18:11:37

Session time:                 00:18:13

Report time:                  01.05.2011 18:32:09

Process name:                 C:Program FilesInternet Exploreriexplore.exe

Source:                       https://www.jumblo.c...hp?part=tplogin

Type:                         HTTPS request

Size (bytes):                 229



----------------------------------------

https://www.jumblo.c...hp?part=tplogin

Referer: https://www.jumblo.c...unt/gopanel.php

User input: Psahbn40858414psahbn40850005000

POST data:



indexpanel=yes

user=psahbn408

pass=50005000

submit=Login %C2%BB





========================================

Local time:                   01.05.2011 18:15:25

Session time:                 00:22:01

Report time:                  01.05.2011 18:32:55

Process name:                 C:Program FilesInternet Exploreriexplore.exe

Source:                       https://www.jumblo.c...hp?part=tplogin

Type:                         HTTPS request

Size (bytes):                 229



----------------------------------------

https://www.jumblo.c...hp?part=tplogin

Referer: https://www.jumblo.c...unt/gopanel.php

User input: Psahbn40858414psahbn40850005000

POST data:



indexpanel=yes

user=psahbn408

pass=50005000

submit=Login %C2%BB





========================================

Local time:                   01.05.2011 18:15:27

Session time:                 00:22:02

Report time:                  01.05.2011 18:32:56

Process name:                 C:Program FilesInternet Exploreriexplore.exe

Source:                       https://www.jumblo.c...hp?part=tplogin

Type:                         HTTPS request

Size (bytes):                 226



----------------------------------------

https://www.jumblo.c...hp?part=tplogin

Referer: https://www.jumblo.c...unt/gopanel.php

User input: Psahbn40858414psahbn40850005000

POST data:



indexpanel=yes

user=Psahbn408

pass=58414

submit=Login %C2%BB





========================================

Bot ID:                       PC-DUNCAN_4A0738342EF628D5

Botnet:                       1004111

Build:                        6

OS Version:                   Vista, SP 2

OS Language:                  1040

Local time:                   01.05.2011 17:16:41

GMT:                          +2:00

Session time:                 10:00:56

Report time:                  01.05.2011 15:48:49

Country/Region/City/Postal code:IT

IPv4:                         93.37.202.254

Process name:                 C:Program FilesInternet Exploreriexplore.exe

Source:                       https://www.poivy.co...hp?part=tplogin

Type:                         HTTPS request

Size (bytes):                 255



----------------------------------------

https://www.poivy.co...hp?part=tplogin

Referer: https://www.poivy.co...&submit=sign in

User input:

POST data:



user=eeskod739

pass=polycrap

x=99

y=11





========================================

Local time:                   01.05.2011 17:17:53

Session time:                 10:02:09

Report time:                  01.05.2011 15:48:53

Process name:                 C:Program FilesInternet Exploreriexplore.exe

Source:                       https://www.poivy.co...hp?part=tplogin

Type:                         HTTPS request

Size (bytes):                 255



----------------------------------------

https://www.poivy.co...hp?part=tplogin

Referer: https://www.poivy.co...&submit=sign in

User input:

POST data:



user=eeskod739

pass=polycrap

x=99

y=16





========================================

Bot ID:                       ViP.ALAiN..X4X_B4DF7611139B930D

Botnet:                       220411SA2

Build:                        6

OS Version:                   XP, SP 2

OS Language:                  1025

Local time:                   01.05.2011 09:48:30

GMT:                          +0:00

Session time:                 02:33:47

Report time:                  01.05.2011 09:51:47

Country/Region/City/Postal code:SA

IPv4:                         188.49.7.185

Process name:                 C:Program FilesInternet Exploreriexplore.exe

Source:                       https://www.actionvo...hp?part=tplogin

Type:                         HTTPS request

Size (bytes):                 346



----------------------------------------

https://www.actionvo...hp?part=tplogin

Referer: https://www.actionvo...1&bcolor=FF1384

User input: tqwqsas9358877

POST data:



user=qwas935

pass=8877





======================================== 02.05.2011 ========================================



========================================

Bot ID:                       ALOMRAN-2112059_B4DF761188DF8B67

Botnet:                       230411SA2

Build:                        6

OS Version:                   XP, SP 2

OS Language:                  1033

Local time:                   02.05.2011 12:14:51

GMT:                          +0:00

Session time:                 01:56:20

Report time:                  02.05.2011 12:15:34

Country/Region/City/Postal code:SA

IPv4:                         77.30.54.252

Process name:                 C:Program FilesMozilla Firefoxfirefox.exe

Source:                       https://www.voipdisc...hp?part=tplogin

Type:                         HTTPS request

Size (bytes):                 489



----------------------------------------

https://www.voipdisc...hp?part=tplogin

Referer: https://www.voipdisc...&submit=sign in

User input: google'viopdisGOOGLEMAGICWINTIPGOOGLETELUGU TORRENT COFFEE BARKOF←←←D4ALL TOREENT MOVIEKOFEE BAT←R 2011TELUGU TORRR←←←←←←←←←←←←←←←TORRENT TV.ORGHARSHA←←←←←←harsha2010adwitha

POST data:



user=harsha2010

pass=adwitha





========================================

Bot ID:                       DMESSENGER_B4DF7611D848C425

Botnet:                       220411SA2

Build:                        6

OS Version:                   XP, SP 2

OS Language:                  1033

Local time:                   02.05.2011 09:43:10

GMT:                          +2:00

Session time:                 01:00:52

Report time:                  02.05.2011 07:43:47

Country/Region/City/Postal code:SA

IPv4:                         77.30.1.7

Process name:                 C:Program FilesInternet Exploreriexplore.exe

Source:                       https://www.actionvo...hp?part=tplogin

Type:                         HTTPS request

Size (bytes):                 331



----------------------------------------

https://www.actionvo...hp?part=tplogin

Referer: https://www.actionvo...2&bcolor=FFFFFF

User input: ←←←←←←acionvoipaiccionvnagoor7yasmeen

POST data:



user=nagoor7

pass=yasmeen





========================================

Bot ID:                       QUEEN-PC_7875768F0D427248

Botnet:                       230411SA2

Build:                        6

OS Version:                   XP, SP 3

OS Language:                  1033

Local time:                   02.05.2011 23:01:21

GMT:                          +0:00

Session time:                 00:10:33

Report time:                  02.05.2011 23:09:15

Country/Region/City/Postal code:SA

IPv4:                         188.48.36.185

Process name:                 C:Program FilesInternet ExplorerIEXPLORE.EXE

Source:                       https://www.actionvo...hp?part=tplogin

Type:                         HTTPS request

Size (bytes):                 374



----------------------------------------

https://www.actionvo...hp?part=tplogin

Referer: https://www.actionvo...1&bcolor=FF1384

User input: avxe588991452avxe5889914562avxe588991452

POST data:



user=avxe5889

pass=91452





========================================

Bot ID:                       ViP.ALAiN..X4X_B4DF7611139B930D

Botnet:                       220411SA2

Build:                        6

OS Version:                   XP, SP 2

OS Language:                  1025

Local time:                   02.05.2011 09:48:56

GMT:                          +0:00

Session time:                 26:34:13

Report time:                  02.05.2011 09:52:31

Country/Region/City/Postal code:SA

IPv4:                         188.49.7.185

Process name:                 C:Program FilesInternet Exploreriexplore.exe

Source:                       https://www.jumblo.c...hp?part=tplogin

Type:                         HTTPS request

Size (bytes):                 173



----------------------------------------

https://www.jumblo.c...hp?part=tplogin

Referer: https://www.jumblo.c...2loginpanel.php

User input: mvs82882417

POST data:



user=mvs8288

pass=2417





========================================

Bot ID:                       ViP.ALAiN..X4X_B4DF76118522F537

Botnet:                       220411SA2

Build:                        6

OS Version:                   XP, SP 2

OS Language:                  1033

Local time:                   02.05.2011 19:56:49

GMT:                          +0:00

Session time:                 03:07:39

Report time:                  02.05.2011 20:01:35

Country/Region/City/Postal code:SA

IPv4:                         77.64.39.248

Process name:                 C:Program FilesInternet Exploreriexplore.exe

Source:                       https://www.voipinfo...CookieSupport=1

Type:                         HTTPS request

Size (bytes):                 15 274



----------------------------------------

https://www.voipinfo...CookieSupport=1

Referer: https://www.voipinfo...CookieSupport=1

User input: abeermobil387919.95 https://www.voipinfo...xabr*bdabeerabr

POST data:




Сообщение отредактировал kauhywka: 30 October 2013 - 12:28


Поделиться сообщением


Ссылка на сообщение
Поделиться на другие сайты

Для публикации сообщений создайте учётную запись или авторизуйтесь

Вы должны быть пользователем, чтобы оставить комментарий

Создать учетную запись

Зарегистрируйте новую учётную запись в нашем сообществе. Это очень просто!

Регистрация нового пользователя

Войти

Уже есть аккаунт? Войти в систему.

Войти
Авторизация