nomoguz.su (Betabot http botnet hosted by fastflux)

Server:  nomoguz.su
Gate file:  /SDF9his/yefgvrtu.php

Alternate domain:
cooncatcher245.com

The same fastflux setup is also hosting this betabot.

Hosting infos:

;; QUESTION SECTION:
;nomoguz.su.            IN    A

;; ANSWER SECTION:
nomoguz.su.        131    IN    A    5.165.17.205
nomoguz.su.        131    IN    A    176.194.193.47
nomoguz.su.        131    IN    A    66.231.16.101
nomoguz.su.        131    IN    A    145.255.33.9
nomoguz.su.        131    IN    A    188.0.98.100
nomoguz.su.        131    IN    A    213.109.88.104
nomoguz.su.        131    IN    A    176.36.149.62
nomoguz.su.        131    IN    A    176.67.20.1
nomoguz.su.        131    IN    A    109.185.142.125
nomoguz.su.        131    IN    A    31.135.136.247

Related md5s (Download sample from Malwr.com)
Betabot: 21d21eed740525aa30c0ab1dd799a8a9

Categories: Uncategorized