www.w0000t.com (Betabot http botnet hosted by ecatel.net)

Resolved www.w0000t.com to 80.82.64.25 Server:  www.w0000t.com Gate file:  /000003/order.php Alternate domains: www.modmarkgoldshop.com www.mogians.com Hosting infos: http://whois.domaintools.com/80.82.64.25 Related md5s (search on malwr.com to download the samples): a1286fd94984fd2de857f7b846062b5e

xogogo.org (Paradise ddos botnet hosted by adman.com)

Resolved xogogo.org to 93.170.131.114 Server:  xogogo.org Gate file:  /par/bfg.php Hosting infos: http://whois.domaintools.com/93.170.131.114 Related md5s (search on malwr.com to download the samples): Paradise bot: 5724c61a33708b5fdefa3125ea32b2d0 EDIT: The botnet is currently attacking a site POST /par/bfg.php HTTP/1.1 Host: xogogo.org User-Agent: PARADISE Content-Type: application/x-www-form-urlencoded Connection: close Content-Length: 10 status=get HTTP/1.1 200 OK Date: Tue, 28 May 2013 13:31:16

gamingplanet.us (Betabot http botnet hosted by worldstream.nl)

Resolved gamingplanet.us to 109.236.82.200 Server:  gamingplanet.us Gate file:  /codeserver/order.php Alternative domain:  freegamebox.us Hosting infos: http://whois.domaintools.com/109.236.82.200 Related md5s (search on malwr.com to download the samples): Betabot: ebf466da7b5f7ed3390f4c68f880bb68

www.vbvx.com (Betabot http botnet hosted by ovh.net)

Resolved  www.vbvx.com to 94.23.56.186 Server:  www.vbvx.com Gate file:  /remote/order.php Bitcoin mining info: Shell.exe” -o http://vbvx.com:8344 -u shubhank008_work -p plawasthi -t 0 -I 10 macromedia.exe” -o http://vbvx.com:8344 -u shubhank008_work -p plawasthi -g no -t 2 Looks like he’s running a mining proxy on his vps. Hosting infos: http://whois.domaintools.com/94.23.56.186 Related md5s (search on malwr.com to download the

securityspecialiastinc.in(Pony hosted in Japan Tokyo Linode Llc)

Resolved : [securityspecialiastinc.in] To [106.187.88.52] Gate: securityspecialiastinc.in/p/gate.php Admin:securityspecialiastinc.in/p/admin.php sample: hxxp://106.187.88.52/p/p.exe Online Crypter: hxxp://securityspecialiastinc.in/crypt.php hosting infos: http://whois.domaintools.com/106.187.88.52

hackattaksuceuse.biz (Betabot http botnet hosted by Fastflux)

Server:  hackattaksuceuse.biz Gate file:  /~.homo/analytics.php Alternate domains: lavidalocapd.biz allahwouakbaaahhh.co.in amemeuch.biz betazbraxxx.co.in hacktipucov2.org jesaispastropkoimettre.org laradimcrelou.co.in thebossinfly.org tktlamifa.co.in whatdaaafuckinyourhead.biz x42v72.biz zbraaadanstfesse.org suxme.itsprosolutions.org This is the source of the citadel and pony just posted. I’m not sure why the owner would set up his betabot for fastflux and not his citadel though. Hosting infos: ;; QUESTION SECTION: ;hackattaksuceuse.biz.