Tag: beta bot

kankarmz.ru (betabot http botnet hosted by Alibabahost.com)

Uncategorized

Resolved kankarmz.ru to 37.221.170.35 Server:  kankarmz.ru Gate file:  /Duf67/H8938_827.php Alternate domains (both are currently unregistered): u023sjasj.netiodijsakj.net This is one of only three or so betabots that I have seen rename the gate file from order.php to something less obvious. I guess that might be a bit too advanced for the average HF skid. Hosting infos:Read more...

bitcoinglobalbanking.com (Betabot http botnet hosted by leaseweb.com)

Uncategorized

Resolved bitcoinglobalbanking.com to 82.192.92.5 Server:  bitcoinglobalbanking.com Gate file:  /b/order.php Alternate domain:  bitcointradingdepot.com This botnet wasn’t actually mining bitcoins when I checked it. I’m very surprised. Hosting infos: http://whois.domaintools.com/82.192.92.5 Related md5s (search on malwr.com to download the samples): Beta bot bbfdbd53810751401b720641687a6116 EDIT: It finally started bitcoin mining Mining infos: macromedia.exe” -a scrypt -o http://mine.pool-x.eu:8080 -u jc2244.crRead more...

smokelessbooter.tk (Betabot http botnet hosted by ecatel.net)

Uncategorized

Resolved smokelessbooter.tk to 94.102.51.123 Server:  smokelessbooter.tk Gate file:  /bronk/order.php Alternate domains: watchonlinecams.comssh-products.comfudfiles.comtheprofitnet.com1337hackers.comcash-networks.com We have a real HF hecker here folks. I can see a Java “driveby” site, shitty crypter site, shitty CPA network site and a shitty hackforums clone site just from the domain names. Looks like he’s running a shitty hosting company as well:Read more...

bigtoys.pw (Betabot http botnet hosted by namecheap.com)

Uncategorized

Resolved bigtoys.pw to 198.187.28.72 Server:  bigtoys.pw Gate file:  /b/order.php Alternative domain: smalltoys.pw I wonder who this could belong to? Name Server:NS2.HOSTING-MARVID.ME Name Server:NS1.HOSTING-MARVID.ME An idiot, obviously Related md5s (search on malwr.com to download the samples): Betabot: 2662af32e5d58d471bd16dc3202db284 Hosting infos: http://whois.domaintools.com/198.187.28.72

cthulhuhf.net (Betabot http botnet hosted by warez-host.com)

Uncategorized

Resolved cthulhuhf.net to 91.223.82.43 Server:  cthulhuhf.net Gate file:  /misc/order.php Alternate domains: cthulhuhf.eu cthulhuhf.org.uk cthulhuhf.co.uk cthulhuhf.xxx Hosting infos: http://whois.domaintools.com/91.223.82.43 Related md5s (search on malwr.com to download the samples):  Beta bot: aa07b845981ba53b6100dba745ba5c1a

s5.6d6f6e65797072696e746572.com (Betabot http botnet hosted by infiumhost.com)

Uncategorized

Resolved s5.6d6f6e65797072696e746572.com to 188.190.127.160 Server:  s5.6d6f6e65797072696e746572.com Gate file:  /wp-admin/order.php Alternate domains: ripraktec147.com youdbeproud228.com wyomiriding928.com Mining info: svchost.exe’ -I 100 -T 200 -t 2 -o stratum+tcp://s2.6d6f6e65797072696e746572.com:3333 -u mp187.her -p lex Hosting infos: http://whois.domaintools.com/188.190.127.160 Related md5s (search on malwr.com to download the samples): Betabot: db9a816d58899f1ba92bc338e89f856a