webhostingprotection.info (Betabot http botnet hosted by Santrex.net)

Resolved webhostingprotection.info to

Server:  webhostingprotection.info
Gate file:  /icool/order.php

This was from the closed beta of the betabot http bot. The server files have been taken down now so not much point visiting the site. There wasn’t much to see except evidence of the coder’s man crush on the steely gaze of Brian Krebs.

For something that apparently took so long to code, the bot seems to be pretty shitty. It injects to skype to bypass the windows firewall, and for some reason this makes it kill skype as soon as you attempt to login. I’m assuming this will negatively affect the skype spreader that is apparently included.
Anyone who want to check out the “userkit” or formgrabbers or any other supposed feature can examine one of the binaries below.

Sample Download    Mirror

Hosting infos: http://whois.domaintools.com/

