Tag: Andromeda Bot

fahfasd.pw (Andromeda http botnet hosted by xeneurope.com)

Uncategorized

Resolved fahfasd.pw to 109.235.51.249 Server:  fahfasd.pw Gate file:  /Panel/image.php Plugins Rootkit:  hxxp://fahfasd.pw/Panel/plugins/r.pack Socks:  hxxp://fahfasd.pw/Panel/plugins/s.pack Formgrabber:  hxxp://fahfasd.pw/Panel/plugins/f.pack   Gate file:  /Panel/fg.php Hosting infos: http://whois.domaintools.com/109.235.51.249

hardstunt.com (Andromeda http botnet proxied by cloudflare.com)

Uncategorized

Resolved hardstunt.com to 108.162.198.113, 108.162.199.113 Server:  hardstunt.com Gate file:  /blob/image.php Hosting a botnet behind cloudflare seems like a bad idea.Lets see if I can get this blocked. EDIT: CloudFlare received your malware report dated April 28, 2013 regarding: hardstunt.com Please be aware CloudFlare is a network provider offering a reverse proxy, pass-through security service. WeRead more...

199.168.136.116(Andromeda hosted in United States Scranton Volumedrive)

Uncategorized

Panel:hxxp://199.168.136.116/andro/image.php Plugins: hxxp://199.168.136.116/andro/r.pack hxxp://199.168.136.116/andro/s.pack hxxp://199.168.136.116/andro/f.pack Andromeda path need user and login :hxxp://199.168.136.116/andro/ Other: http://199.168.136.116/andro/fg.php?id=1880376902 sample:hxxp://199.168.136.116/andro/and.exe hosting infos: http://whois.domaintools.com/199.168.136.116