Tag: Andromeda Bot

www.yahgodz.com (Andromeda http botnet hosted by dataclub.biz)

Uncategorized

Resolved www.yahgodz.com to 46.183.217.148 Server:  www.yahgodz.com Gate file:  /http/image.php Additional domains: bighecks.net/http/image.php (Missing gate file, hosted at worldstream.nl 217.23.4.155) sonic4us.ru/http/image.php (Pointed at 127.0.0.1) imageshells.com/admin/image.php (Missing gate file, hosted at worldstream.nl 217.23.4.107) All of these are mystical’s domains, used for various nefarious purposes in the past. A quick google shows that he’s been loading onto thisRead more...

188.40.15.22 (Andromeda http botnet hosted by Up2vps.com)

Uncategorized

This was loaded from snk’s latest irc net. The bot is pretty strange, as it tries to connect to five unregistered domains before connecting to the ip. Here they are: amnsreiuojy.ru amnsreiuojy.in amnsreiuojy.biz amnsreiuojy.com amnsreiuojy.nl  Server:  188.40.15.22 Gate file:  /sg.php  Plugin: http://188.40.15.22/uploads/is.s It appears to be some sort of Facebook spreader.   hosting infos: http://whois.domaintools.com/188.40.15.22

zeonyx.info (Andromeda http botnet hosted by voxility.net)

Uncategorized

Resolved zeonyx.info to 37.221.170.240 Server:  zeonyx.info Gate file:  /Balls/Panel/Panel/image.php Some bitcoin mining infos: http://Slinky:abc123@pool.bitclockers.com:8332 http://Zeroexe7_Zero8:nigger1@eu.triplemining.com:8344 http://Zeroexe7_Indian:nigger1@us2.eclipsemc.com:8337 Hosting infos: http://whois.domaintools.com/37.221.170.240