Tag: Andromeda Bot

apoctechnology.com (Andromeda http botnet hosted by Seychelles Victoria Business Dialogue Ltd)

Uncategorized

Resolved apoctechnology.com to 91.217.178.32 I think this is the same guy from here. What is it with him and having his nick in the domain? Server:  apoctechnology.com Gate file:   /Grind/Boom/Lancer/Panel/image.php He’s trying out a survey winlocker annoyance program. It ‘s a really shitty one though. See it in action: http://malwr.com/analysis/4ceff448b85855dbb824a1098cdeea39/ Hosting infos: http://whois.domaintools.com/91.217.178.32

jackhammermusic.com (Andromeda http botnet hosted by justhost.com)

Uncategorized

Resolved jackhammermusic.com to 173.254.28.39 Server:  jackhammermusic.com Gate file:  /images/id/image.php There’s also a shell booter located at jackhammermusic.com/test/ Looks like it’s out of shells though. jackhammermusic.com/test/shells.php Hosting infos: http://whois.domaintools.com/173.254.28.39 EDIT:  Now with 100% more bitcoin mining. Mining infos: http://Juan:Johnxd32ssS@pool.bitclockers.com:8332

76.191.97.100 (Multiple http botnets hosted by sentris.com)

Uncategorized

Andromeda Server:   76.191.97.100 Gate file:  /andro/image.php Plugins Rootkit:  http://76.191.97.100/andro/r.pack Socks:  http://76.191.97.100/andro/s.pack Formgrabber:  http://76.191.97.100/andro/f.pack   Gate file:  /andro/fg.php Smoke loader Server:   76.191.97.100 Gate file:  /smoke/index.php Pony Server:  76.191.97.100 Gate file:  /p/gate.php POE stealer Server:  76.191.97.100 Gate file /poe/index.php Login details are admin:admin Hosting infos: http://whois.domaintools.com/76.191.97.100 EDIT: I see he’s trying bitcoin mining Mining infos:Read more...