androhosting.info (Athena irc botnet hosted by voxility.net)

Resolved androhosting.info to 37.221.170.211

Mystical is right back into the irc game, with a different server and domain.
This is on the same ip as _Stoner’s Athena test server which was previously posted.

Google indicates that the domain once hosted a blackhole exploit kit panel

Server: androhosting.info
Port:  44
Current global users 119, max 910
Channel:  #smoke
Channel password:  verified
#smoke           116     [+smntCuT]

Opers:
[`] (dro@asus): …
[`] @#smoke
[`] irc.server.net :IRC server
[`] is a Bot on IRC server
[`] idle 01:32:24, signon: Mon Jan 28 21:57:15
[`] End of WHOIS list.
[E] (E@asus): …
[E] @#smoke
[E] irc.server.net :IRC server
[E] is a Bot on IRC server
[E] idle 06:08:25, signon: Mon Jan 28 13:46:46
[E] End of WHOIS list.
` is _Stoner, and E is Mystical

Hosting infos: http://whois.domaintools.com/37.221.170.211

 EDIT:
Mystical is still booting away

Mystical gives channel operator status to Mystical

E: !ddos.http.rapidget http://www.nako.me 80 500
E: !ddos.browser http://www.downcenter.me/ 300
E: !ddos.stop
E: !ddos.http.rapidget http://www.downcenter.me/ 80 500
E: !ddos.http.rapidget http://www.nako.me 80 500
E: !ddos.http.rapidget http://www.downcenter.me/ 80 500
E: !ddos.http.rapidget http://www.nako.me 80 500
E: !ddos.http.rapidget http://www.nako.me 80 500
E: !ddos.http.rapidget http://www.downcenter.me/ 80 500
E: !ddos.http.rapidget http://www.downcenter.me/ 80 500
E: !ddos.http.rapidget http://www.nako.me 80 500
E: !ddos.stop

E: !ddos.browser http://trojanforge.com/forum.php 300
E: !ddos.http.rapidget http://trojanforge.com/forum.php 80 1000
E: !ddos.http.rapidget http://trojanforge.com/forum.php 80 1000
E: !ddos.browser http://trojanforge.com/forum.php 1000
E: !ddos.http.rapidget http://108.162.193.125/ 80 1000
E: !ddos.http.rapidget http://trojanforge.com/forum.php 80 1000
E: !ddos.http.rapidget http://173.245.60.37/ 80 1000
E: !ddos.http.rapidget http://173.245.60.37/ 80 1000
E: !ddos.stop
E: !ddos.stop
E: !ddos.stop
E: !ddos.stop

Categories: Uncategorized

5 Comments

Anonymous - January 30, 2013 at 7:04 pm

hxxp://directxex.com/uploads/1127421367.test.exe

Pig - January 30, 2013 at 8:14 pm

thank you for the sample:-)

Anonymous - January 31, 2013 at 1:48 am

@I_Post

Fail ddos, how many bots you had because TF wasn't affected by your fail ddos.

Pig - January 31, 2013 at 4:48 pm

noob it wasnt him ddosing tf read better next time

Anonymous - February 19, 2013 at 8:52 pm

ooohhh yeeeah aby new flame war page

Comments are closed