188.40.15.22 (Andromeda http botnet hosted by Up2vps.com)

This was loaded from snk’s latest irc net.
The bot is pretty strange, as it tries to connect to five unregistered domains before connecting to the ip.
Here they are: amnsreiuojy.ru amnsreiuojy.in amnsreiuojy.biz amnsreiuojy.com amnsreiuojy.nl 

Server:  188.40.15.22
Gate file:  /sg.php 

Plugin: http://188.40.15.22/uploads/is.s
It appears to be some sort of Facebook spreader.
 

hosting infos: http://whois.domaintools.com/188.40.15.22

3 Comments