Resolved n18b7273u1j.in to 22.214.171.124
Gate file: /M_jsh1/order.php
This is betabot version 1.5. This is the second betabot 1.5 botnet I have found, but the other one was just a different path on an already posted botnet, so it wasn’t worth a new post.
You may note that the domains used are only a day old.
Hosting infos: http://whois.domaintools.com/126.96.36.199
Related md5s (Search on Malwr.com to download samples)