Linux Botnet Hosted In blackunix.us

This is the bot used to scan for vulnerabilities:
hxxp://pastebin.com/dEMULiQV

Now talking in #botnets
Topic On : [ #botnets ] [ hajar irc.predone.cz dan irc.drogs.pl ]
Topic By : [ uyap ]
Modes On : [ #botnets ] [ +smntrMuk fcuked ]

The Bot is hosted here hxxp://visionafricamagazine.com/scripts/x.log

onetimes27s.com(Reverse Dns Bot hosted in Russian Federation Saint Petersburg Majordomo Llc)



This package was posted in one hacking board as http bot.
After checking the file here results:

Domains used :

hoseen454r.com inactive
onetimes27s.com active

Resolved : [ onetimes27s.com ] To [ 178.250.245.186 ]

Panel:
hxxp://178.250.245.186/pref1/  password protected

Sample here

Hosting infos:
http://whois.domaintools.com/178.250.245.186


gki2mpdt3rsokbmv.onion (Irc botnet hosted on a Tor hidden service)

Server:  gki2mpdt3rsokbmv.onion
Port:  6667
Channel:  #channel

Oper:
[wac] (wac@9bedb2.host): ac
[wac] #channel
[wac] lair.hell.net :Cerberus Server
[wac] idle 00:00:18, signon: Tue May 13 18:24:47
[wac] End of WHOIS list.

The owner must have used very old bot code to create this, as it fails to work properly on windows 7 and higher.

Related md5s (Download sample from Malwr.com)
Ircbot: c94783e10995197f9177e6c72ae53e6a

sinsec.net (Betabot http botnet hosted by alibabahost.com)

Resolved sinsec.net to 37.221.170.96

Server:  sinsec.net
Gate file:  /turndown/order.php

Alternate domains:
divinestresser.info
radicalpkz.com
perp.pw
thefox.pw
uploadme.pw
perp.se

Domain info: sinsec.net
Domain Name: SINSEC.NET
Registry Domain ID: 1814650535_DOMAIN_NET-VRSN
Registrar WHOIS Server: whois.enom.com
Registrar URL: www.enom.com
Updated Date: 2013-07-12 10:27:24Z
Creation Date: 2013-07-12 17:27:00Z
Registrar Registration Expiration Date: 2014-07-12 17:27:00Z
Registrar: ENOM, INC.
Registrar IANA ID: 48
Registrar Abuse Contact Email: abuse@enom.com
Registrar Abuse Contact Phone: +1.4252744500
Reseller: NAMECHEAP.COM
Domain Status: ok
Registry Registrant ID: 
Registrant Name: WHOISGUARD PROTECTED
Registrant Organization: WHOISGUARD, INC.
Registrant Street: P.O. BOX 0823-03411
Registrant City: PANAMA
Registrant State/Province: PANAMA
Registrant Postal Code: NA
Registrant Country: PA
Registrant Phone: +507.8365503
Registrant Phone Ext: 
Registrant Fax: +51.17057182
Registrant Fax Ext:
Registrant Email: 073C843934E64FB380EF8B3AB027CCD1.PROTECT@WHOISGUARD.COM
Registry Admin ID: 
Admin Name: WHOISGUARD PROTECTED
Admin Organization: WHOISGUARD, INC.
Admin Street: P.O. BOX 0823-03411
Admin City: PANAMA
Admin State/Province: PANAMA
Admin Postal Code: NA
Admin Country: PA
Admin Phone: +507.8365503
Admin Phone Ext: 
Admin Fax: +51.17057182
Admin Fax Ext:
Admin Email: 073C843934E64FB380EF8B3AB027CCD1.PROTECT@WHOISGUARD.COM
Registry Tech ID: 
Tech Name: WHOISGUARD PROTECTED
Tech Organization: WHOISGUARD, INC.
Tech Street: P.O. BOX 0823-03411
Tech City: PANAMA
Tech State/Province: PANAMA
Tech Postal Code: NA
Tech Country: PA
Tech Phone: +507.8365503
Tech Phone Ext: 
Tech Fax: +51.17057182
Tech Fax Ext: 
Tech Email: 073C843934E64FB380EF8B3AB027CCD1.PROTECT@WHOISGUARD.COM
Name Server: RAY.NS.CLOUDFLARE.COM
Name Server: RUTH.NS.CLOUDFLARE.COM
DNSSEC: unSigned
URL of the ICANN WHOIS Data Problem Reporting System: http://wdprs.internic.net/
Last update of WHOIS database: 2013-07-12 10:27:24Z

Hosting info: 37.221.170.96
    

inetnum:        37.221.170.0 - 37.221.170.255
netname:        alibabahost
descr:          alibabahost
country:        RO
admin-c:        AM23273-RIPE
tech-c:         AM23273-RIPE
status:         ASSIGNED PA
mnt-by:         VOXILITY-MNT
source:         RIPE # Filtered
remarks:        INFRA -AW

person:         Anurag Mishra
address:        No:30,F2,Deccan Heritage ,ITI Layout, New BEL Road   ,Bangalore
address:        India
phone:          +919741887870
nic-hdl:        AM23273-RIPE
mnt-by:         VOXILITY-MNT
abuse-mailbox:  info@alibabahost.com
source:         RIPE # Filtered

route:          37.221.170.0/23
descr:          voxility.net
origin:         AS39743
mnt-by:         VOXILITY-MNT
source:         RIPE # Filtered

Related md5s (Download samples from Malwr.com)
Betabot: 4620d8a164ec31681a54b00a4bb9da7e

api.wifi-update.biz (Betabot http botnet hosted by oneandone.net)

Resolved api.wifi-update.biz to 87.106.241.22

Server:  api.wifi-update.biz
Gate file:  /cdn/img.php

Alternate domains:
api-radio-def.de
api.lul.pw
api.tba.pw

Domain info: wifi-update.biz
Domain Name:                                 WIFI-UPDATE.BIZ
Domain ID:                                   D58641421-BIZ
Sponsoring Registrar:                        BIZCN.COM, INC.
Sponsoring Registrar IANA ID:                471
Registrar URL (registration services):       www.bizcn.com
Domain Status:                               clientTransferProhibited
Registrant ID:                               ORGEH90335606834
Registrant Name:                             Erkki Hagstrom
Registrant Organization:                     ErkkiHagstrom
Registrant Address1:                         Gesterbyntie 51
Registrant City:                             HYVINKAA
Registrant State/Province:                   HYVINKAA
Registrant Postal Code:                      05460
Registrant Country:                          Finland
Registrant Country Code:                     FI
Registrant Phone Number:                     +86.506454350
Registrant Facsimile Number:                 +86.506454350
Registrant Email:                            info@wifi-update.biz
Administrative Contact ID:                   ORGEH90335607831
Administrative Contact Name:                 Erkki Hagstrom
Administrative Contact Organization:         Erkki Hagstrom
Administrative Contact Address1:             Gesterbyntie 51
Administrative Contact City:                 HYVINKAA
Administrative Contact State/Province:       HYVINKAA
Administrative Contact Postal Code:          05460
Administrative Contact Country:              Finland
Administrative Contact Country Code:         FI
Administrative Contact Phone Number:         +86.506454350
Administrative Contact Facsimile Number:     +86.506454350
Administrative Contact Email:                info@wifi-update.biz
Billing Contact ID:                          ORGEH90335609498
Billing Contact Name:                        Erkki Hagstrom
Billing Contact Organization:                Erkki Hagstrom
Billing Contact Address1:                    Gesterbyntie 51
Billing Contact City:                        HYVINKAA
Billing Contact State/Province:              HYVINKAA
Billing Contact Postal Code:                 05460
Billing Contact Country:                     Finland
Billing Contact Country Code:                FI
Billing Contact Phone Number:                +86.506454350
Billing Contact Facsimile Number:            +86.506454350
Billing Contact Email:                       info@wifi-update.biz
Technical Contact ID:                        ORGEH90335608666
Technical Contact Name:                      Erkki Hagstrom
Technical Contact Organization:              Erkki Hagstrom
Technical Contact Address1:                  Gesterbyntie 51
Technical Contact City:                      HYVINKAA
Technical Contact State/Province:            HYVINKAA
Technical Contact Postal Code:               05460
Technical Contact Country:                   Finland
Technical Contact Country Code:              FI
Technical Contact Phone Number:              +86.506454350
Technical Contact Facsimile Number:          +86.506454350
Technical Contact Email:                     info@wifi-update.biz
Name Server:                                 NS3.CNMSN.COM
Name Server:                                 NS4.CNMSN.COM
Created by Registrar:                        BIZCN.COM, INC.
Last Updated by Registrar:                   BIZCN.COM, INC.
Domain Registration Date:                    Tue Jan 21 20:20:12 GMT 2014
Domain Expiration Date:                      Tue Jan 20 23:59:59 GMT 2015
Domain Last Updated Date:                    Tue Jan 21 20:20:13 GMT 2014

Hosting info: 87.106.241.22
inetnum:        87.106.240.0 - 87.106.255.255
netname:        SCHLUND-CUSTOMERS
descr:          1&1 Internet AG
country:        DE
org:            ORG-SA12-RIPE
admin-c:        IPAD-RIPE
tech-c:         IPOP-RIPE
status:         ASSIGNED PA
remarks:        For abuse issues, please use only abuse@oneandone.net
mnt-by:         AS8560-MNT
source:         RIPE # Filtered

organisation:   ORG-SA12-RIPE
org-name:       1&1 Internet AG
org-type:       LIR
address:        1&1 Internet AG Axel Fischer Brauerstr.48 76135 Karlsruhe GERMANY
phone:          +49 721 91374 0
fax-no:         +49 721 91374 212
mnt-ref:        RIPE-NCC-HM-MNT
mnt-ref:        AS8560-MNT
mnt-ref:        SCHLUND-MNT
mnt-by:         RIPE-NCC-HM-MNT
admin-c:        IPAD-RIPE
admin-c:        RME9-RIPE
admin-c:        AFI5-RIPE
admin-c:        JR2342-RIPE
abuse-c:        ABDE2-RIPE
source:         RIPE # Filtered

role:           IP Administration
address:        1&1 Internet AG
admin-c:        AFI5-RIPE
admin-c:        RME9-RIPE
admin-c:        JR2342-RIPE
admin-c:        LTO3-RIPE
admin-c:        ZIG-RIPE
admin-c:        MI-RIPE
admin-c:        MINK-RIPE
admin-c:        VR-RIPE
tech-c:         AFI5-RIPE
tech-c:         RME9-RIPE
tech-c:         JR2342-RIPE
tech-c:         LTO3-RIPE
nic-hdl:        IPAD-RIPE
abuse-mailbox:  abuse@oneandone.net
mnt-by:         AS8560-MNT
source:         RIPE # Filtered

role:           IP Operations
address:        1&1 Internet AG
admin-c:        AFI5-RIPE
admin-c:        RME9-RIPE
admin-c:        JR2342-RIPE
admin-c:        LTO3-RIPE
tech-c:         AFI5-RIPE
tech-c:         RME9-RIPE
tech-c:         JR2342-RIPE
tech-c:         LTO3-RIPE
nic-hdl:        IPOP-RIPE
abuse-mailbox:  abuse@oneandone.net
mnt-by:         AS8560-MNT
source:         RIPE # Filtered

route:          87.106.0.0/16
descr:          SCHLUND-PA-5
origin:         AS8560
mnt-by:         AS8560-MNT
source:         RIPE # Filtered

Related md5s (Download samples from Malwr.com)
Betabot: 6327517dec04821d2416081937cf55fe