Saturday, 24 December 2011

Merry christmas and happy new year

(yeah, no Temari this year)

One year of cybercrime tracking...
At the beginning my blog was dedicated to fakeAV/winlock cracking, I met many new friends/readers this year with good ideas and who pushed/helped me to continue.
So, thank you very much (you know who you are)

And a special 'hello' to (in no particular order)
rkhunter, markusg, frank_boldewin, Mila, Kafeine, Onthar, Gof, EP_X0FF, Jerome Segura, Tigzy, siri, Nicolas Brulez, Loucif, Remixed, Sean, Horgh, Vyacheslav Zakorzhevsky, Brian Krebs, mrbelyash, Sanjar Satsura, SysAdMini, mc0blck, Corkami, Secubox Labs, MalwareIntelligence, all tripfags of /g/, those who idle in Rizon and EFnet, and to you.

As xmas present i have absolutely no idea, so let's hunt blackhole exploit kit.

62.76.191.148:

46.4.228.132:

87.255.73.19:

141.101.239.82:

 188.66.6.120:

 109.236.81.244:

 91.196.216.51:

130.0.232.46:

66.199.237.116:

193.39.78.170 (lulz):

91.211.117.83:


Batch file for search and download files from BH (you must have wget):
@echo off
color 17
cls
set target=193.200.193.80/files/
set droppath=files
set start=1
set end=200
set step=1
if not exist %droppath% (
mkdir %droppath% )
FOR /L %%G IN (%start%, %step%, %end%) DO wget -U "Mozilla/4.0 (compatible; MSIE 5.01; Windows NT 5.0)" -S -t 100 -P / "%target%%%G" -O "%droppath%/%%G"
FOR %%i IN (%droppath%\*) do if %%~zi LEQ 2 DEL %%i
echo Done.
pause


Stay leet.

7 comments:

  1. Thanks you, one of the best malware blog i know, merry christmas Xylitol :D

    ReplyDelete
  2. Merry Christmas Xylitol!Have a Happy New Year! :)
    You did a great job this year btw...

    ReplyDelete
  3. Merry Christmas Xylibox!

    ReplyDelete
  4. merry christmas Xylitol, take a break you have do alot this year.

    ReplyDelete
  5. merry christmas from /g/ !

    ReplyDelete
  6. Merry Christmas! And Happy new year :)
    (btw where does the pic come from? °-°)

    ReplyDelete
  7. merry christmas Xylitol, And Happy new year :)
    mfg
    Marijuana

    ReplyDelete