Resolved ns1.androha.com to 162.213.250.141
Server: ns1.androha.com
Gate file: /cgi/image.php
Plugins:
Rootkit: hxxp://ns1.androha.com/cgi/r.pack
Socks: hxxp://ns1.androha.com/cgi/s.pack
Formgrabber: hxxp://ns1.androha.com/cgi/f.pack
Gate file: /cgi/fg.php
First cracked andromeda I’ve seen in a while.
Hosting infos: http://whois.domaintools.com/162.213.250.141
Related md5s (Search on malwr.com to download the sample)
Andromeda: c5598dd742b5504084779ccfda0b207c