Resolved kankarmz.ru to 188.8.131.52
Gate file: /Duf67/H8938_827.php
Alternate domains (both are currently unregistered):
This is one of only three or so betabots that I have seen rename the gate file from order.php to something less obvious. I guess that might be a bit too advanced for the average HF skid.
Hosting infos: http://whois.domaintools.com/184.108.40.206
Related md5s (search on malwr.com to download samples):