Tag: Andromeda Bot

painadiction.biz (Andromeda http botnet hosted by Ukraine Ukrainian Internet Names Center Ltd)

Uncategorized

Resolved painadiction.biz to 91.231.85.228 I found this bot running as an update on a few of the barracuda http nets that I had already posted. I would imagine someone has found a vulnerability in the panel. Server:  painadiction.biz Gate file:  /moneymaker/image.php There are a few other domains with the same registration email (soyperlman@live.com) on theRead more...

genhagroup.com (Andromeda http botnet hosted by United States Provo Unified Layer)

Uncategorized

Resolved genhagroup.com to 74.220.199.26 This looks like it’s hosted on a hacked server Server:  genhagroup.com Gate file:  /andro/image.php Plugins Rootkit:   genhagroup.com/andro/r.pack Socks:  genhagroup.com/andro/s.pack Formgrabber:  genhagroup.com/andro/f.pack    Gate file:  genhagroup.com/andro/fg.php Hosting infos: http://whois.domaintools.com/74.220.199.26

dinosaur.no-ip.org (Andromeda and barracuda http botnets hosted by Russian Federation Moscow Pallada Web Service Llc)

Uncategorized

Resolved dinosaur.no-ip.org to 37.0.123.119 I’ve been watching the barracuda for a while, and when I saw it load the andromeda I decided to post them both. Andromeda Server:   dinosaur.no-ip.org Gate file:   /andr/image.php  Plugins Rootkit:  dinosaur.no-ip.org/andr/r.pack Socks:  dinosaur.no-ip.org/andr/s.pack Formgrabber:  dinosaur.no-ip.org/andr/f.pack    Gate file:  dinosaur.no-ip.org/andr/fg.php Barracuda http Server:  dinosaur.no-ip.org Gate file:  dinosaur.no-ip.org/drgordon512/bot.php Here are someRead more...

37.221.163.175 (Andromeda http botnet hosted by Romania Voxility S.r.l.)

Uncategorized

The laziest skids don’t even bother getting a domain at all. Why hello Nicolas Moses. What do you have for us today? It’s andromeda again, this time hosted on a windows vps. Server:  37.221.163.175 Gate file:  /andro/image.php EDIT: Oh hey, bitcoin mining. Glad to see you’re still keeping the same old password. daily500:nigger123456@pool.bitclockers.com:8332 Also aRead more...

uberchat.no-ip.biz (Andromeda http botnet hosted by Romania Voxility S.r.l.)

Uncategorized

Resolved uberchat.no-ip.biz to 37.221.160.124 Yet another cracked andromeda. Skids don’t even bother to get a real domain for it. Server:   uberchat.no-ip.biz Gate file:  /chat/image.php Clicking on adf.ly links, someone’s clearly trying to make some big bucks. public void adfly() { this.WebBrowser1.Navigate("http://adf.ly/FHZcZ"); } Hosting infos: http://whois.domaintools.com/37.221.160.124