(Athena http botnet hosted by

Resolved to

Gate file:  /1ds2541svc/gate.php

This domain was previously used as a backup domain for a now defunct betabot. I guess the owner is trying all the L33T hackforums bots.

Hosting infos:

Related md5s (Search on to see the sample in action. You can’t download it as someone hates sharing)
Athena: eb5d8e62eaafd10467d30d7e2919362b