digital

uploadwith.me (Betabot http botnet hosted by datashack.net)

Resolved uploadwith.me to 63.141.233.107 Server:  uploadwith.me Gate file:  /ashg653/order.php Alternate domain: strike-file-hosting.us Hosting info:  http://whois.domaintools.com/63.141.233.107 Notice anything interesting about this IP? CustName: Chris Gravenstein Address: 201 E. 16th st City: North Kansas City StateProv: MO PostalCode: 64116 Country: US RegDate: 2013-10-21 Updated: 2013-10-21 Ref: http://whois.arin.net/rest/customer/C04738525 That’s right, Chris Gravenstein, aka digital has managed to top

hosting-bros.me (Athena irc botnet hosted by OVH.net)

Resolved hosting-bros.me to 198.245.51.109 Server:  hosting-bros.me Port:  2300 Channel:  #athena Hosting infos: http://whois.domaintools.com/198.245.51.109 Related md5s (Search on malwr.com to download samples) Athena: c6c1355e7af32c584a4959878bd2640a

filehelp.us (Various irc bots hosted by securedservers.com)

Resolved filehelp.us to 184.95.37.155 Athena Server:  filehelp.us Port:  7200 Channel:  #Athena Insomnia Server:  filehelp.us Port:  4242 Channel:  #insomnia Channel password:  k6geyzs Dixie bot Server:  filehelp.us Port:  4242 Channel:  #DDoS# hxxp://filehelp.us/Panel/gate.php aryan bot 184.95.37.155:5557 Server Password: Username: 5644413 Nickname: New{DE-XP-x86}5644413 Channel: #aryan (Password: k6geyzs) Channeltopic: :.dl hxxp://filehelp.us/upload/files/bin.exe 1 Other samples here hxxp://filehelp.us/upload/ Opers are Vapor and