Resolved n18b7273u1j.in to 220.127.116.11
Gate file: /M_jsh1/order.php
This is betabot version 1.5. This is the second betabot 1.5 botnet I have found, but the other one was just a different path on an already posted botnet, so it wasn’t worth a new post.
You may note that the domains used are only a day old.
Hosting infos: http://whois.domaintools.com/18.104.22.168
Related md5s (Search on Malwr.com to download samples)