Server: blackhats.su
Gate file: /bb/order.php
Alternate domains:
aeonhf.net
aeonhf.me
You may recognize one of the domains, as it has appeared on the blog before. They used cloudflare that time as well. Lets see if we can get cloudflare to block access to it again.
Related md5s (search on malwr.com to download the samples):
Beta bot: 3b23b6637f0b37e00ed57db3c6d5af9f