kankarmz.ru (betabot http botnet hosted by Alibabahost.com)

Resolved kankarmz.ru to 37.221.170.35

Server:  kankarmz.ru
Gate file:  /Duf67/H8938_827.php

Alternate domains (both are currently unregistered):
u023sjasj.net
iodijsakj.net

This is one of only three or so betabots that I have seen rename the gate file from order.php to something less obvious. I guess that might be a bit too advanced for the average HF skid.

Hosting infos: http://whois.domaintools.com/37.221.170.35

Related md5s (search on malwr.com to download samples):
Betabot 397cd0b8c2738dcab9261aac0fc9554c