During investigating ELF malware I met this Windows PE binary, it contains an important infrastructure information used by Mr. Black actor (the one who loves attacking our MIPS routers), so I decided to check and post a bit here.
Win32/Zegost.rfn [
The actor who put the PE binary in the picture was attacking my "router" with the other ELF binary one, a MIPS architecture of Linux/Mr.Black, a family of Linux/AES.DDoS, a China ELF backdoor and DDoS'er variant, with the source IP of attacker and CNC lead to that panel's address.
/Mr.Black : 210.92.18.118
2. ATTK graph attached
— ☩MalwareMustDie (@MalwareMustDie) ], It drops, self deleted, auto-start set in registry, starting service (also set in registry..as many of the other boring stuff, and the point of interest of I am writing here is contacting mother hosts as backdoor.Below are some reversing snips I did during ID-ing the threat..
The infrastructure
The PE has the CNC hostname permutated DGA function and I managed to extract some of them:
conf.f.360.cn
'qi89.f3322.org'
qup.f.360.cn
u.qurl.f.360.cn
qurl.f.360.cn
qurl.qh-lb.com
qup.qh-lb.com
sdupm.360.cn
sdup.360.cn
sdup.qh-lb.com
Noted: The callback hostnames increased after we allow several CNC downloads. The malware DGA is generating many other fake domains.. For the botnet dissection, please focus is with the actual CNC established IP addresses only.
And each domains I checked as per snipped picture below:
..and get the ID :-)
So..I have collected the first three (3) DGA generated basis domains from malware sample which are:
360.cn
'f3322.org'
qh-lb.com
but the #1 and #3 are legit services. There is only one domain that is really being used as CNC (see the PCAP), the other domains are just being used as decoys to confuse the investigation. And the real CNC hostname is :
"f3322.org" w/Registrant email: "[email protected]"
So now we learn more about the nature of Zegost in generating DGA and faking CNC domains. Malware is served under domain f3322.org which is having a super bad reputation in being used by Mr.Black ELF attacks and many more ELF attacks, for example:
(222.186.34.220), posted details I have at
Thanks to reddit folks to inform that the f3322.org is a part of a Chinese dynamic hostname/DNS (DDNS) service provider.

We didn't know this detail until now. So it looks like that their services is used by the malware activities. It means the actor can be traced via contacting the f3322.org abuse accordingly. We're on it for we have long list of malicious subdomains used now.
#MalwareMustDie!
Vollständiger Original-Bericht Ausführliche Details, Code-Beispiele & Hersteller-Stellungnahme auf blog.malwaremustdie.org. ↗ Original-Artikel auf blog.malwaremustdie.org lesen
SOCIAL SHARE CARD GENERATOR