Resolved n18b7273u1j.in to 184.108.40.206
Gate file: /M_jsh1/order.php
This is betabot version 1.5. This is the second betabot 1.5 botnet I have found, but the other one was just a different path on an already posted botnet, so it wasn’t worth a new post.
You may note that the domains used are only a day old.
Hosting infos: http://whois.domaintools.com/220.127.116.11
Related md5s (Search on Malwr.com to download samples)
Anonymous - September 20, 2013 at 9:06 pm
Downloads this skiddy "Survey Builder": https://malwr.com/analysis/ZmFhYjcwNjBmMjFmNDgxY2I1NDZmZDZlYWM0MmZkYjY/
This is the survey the user must do to unlock their PC: http://speedyfiles.net/file/0SR559
Please report this file! His account will be banned!
Anonymous - September 21, 2013 at 1:50 am