EILMELDUNGEN LIVE
🔧 AI Nachrichten Generate playable HTML5 games with Mistral Medium and GLM(28.08.2026 um 16:00 Uhr)
🔧 AI Nachrichten Claude Fable 5.1 Just Set a New AI Performance Record(02.09.2026 um 11:00 Uhr)
🔧 AI Nachrichten Sam Altman Says This AI Agent Could Run Forever(02.09.2026 um 14:00 Uhr)
🔧 AI Nachrichten New Qwen 3.8 Max Update Is SCARY GOOD!(02.09.2026 um 18:00 Uhr)
🔧 AI Nachrichten Generate playable HTML5 games with Mistral Medium and GLM(28.08.2026 um 16:00 Uhr)
🔧 AI Nachrichten Claude Fable 5.1 Just Set a New AI Performance Record(02.09.2026 um 11:00 Uhr)
🔧 AI Nachrichten Sam Altman Says This AI Agent Could Run Forever(02.09.2026 um 14:00 Uhr)
🔧 AI Nachrichten New Qwen 3.8 Max Update Is SCARY GOOD!(02.09.2026 um 18:00 Uhr)
1 Tag Serie
12 🕛 kürzlich 9 Min Lesezeit CVE-RADAR
0

MMD-0038-2015 - ChinaZ and ddos123.xyz

↗ Quelle (blog.malwaremustdie.org)
🗣️ Stimme:
📑 Inhaltsübersicht

Background

Sorry to keep on saying this, previous posts about ChinaZ are in []. A loy of effort was done to this threat, we grabbed its builder in some CNC we spotted, and we also PoC "a suspected" coder of the ChinaZ malware turned out to be high-schooler 3rd grade in his effort of improving source code of ChinaZ in GitHub DDoSClient repository early in this year, but it seems the real actors is still out there continuing his malicious scheme. And this post is having information that may lead to him.

As team, we must say this post is not so technical, but more to the investigation of one of ChinaZ suspected bad actor, so our apology for some of you may not be interested to read this topic. We also know that many of security folks don't agree on pointing out a suspect in cyber crime for the OPSEC purpose.

However. the information posted here was passed to the authorities and enforcement for more than 10days by now. And the information contains many useful threat indicators that can be used by security entity to mitigate or blocking the infrastructure used, or for the good people in PRC can trace the threat deeper, which are reasons to share it too as per it is.

Infection and malware CNC analysis result

It is (always) started from the HFS panel with the infection distribution of the shellshock. Below is the panel, and the shellshock method is as per previously posted cases detail, nothing new. Thank's @benkow for the information sharing.
] and [

The interesting part is, the hostname (the www pointer) www.ddos123.xyz and domain (the "@" pointer) ddos123.xyz are not pointing to the same IP. I.e. the ddos123.xyz is with A record in 43.249.11.171:

;; ANSWER SECTION:
ddos123.xyz. 3600 IN A "43.249.11.171"
;; AUTHORITY SECTION:
ddos123.xyz. 3600 IN NS ns1.72dns.com.
ddos123.xyz. 3600 IN NS ns2.idc1.cn.
;; ADDITIONAL SECTION:
ns1.72dns.com. 600 IN A 101.226.167.174
Which is served in a VPS in the very different location and service under this BGP [ previously we had [email protected] that leads to mass 103 .XYZ domains for being used by ChinaZ too.. OK, checking further..each domain was registered in the "same way" too, please see how registration was written as per below snipped WHOIS record:
Domain Name:ZHMR.ORG
Domain ID: D173189409-LROR
Creation Date: 2014-07-04T07:27:48Z
Updated Date: 2015-07-05T01:32:50Z
Registry Expiry Date: 2016-07-04T07:27:48Z
Sponsoring Registrar:PDR Ltd. d/b/a PublicDomainRegistry.com (R27-LROR)
Sponsoring Registrar IANA ID: 303
WHOIS Server:
Referral URL:
Domain Status: clientTransferProhibited -- http://www.icann.org/epp#clientTransferProhibited
Domain Status: autoRenewPeriod -- http://www.icann.org/epp#autoRenewPeriod
Registrant ID:DI_37377779
Registrant Name:"hu lu"
Registrant Organization:"hu lu"
Registrant Street: beijingxinchengshishi
Registrant City:xincheng
Registrant State/Province:Beijing
Registrant Postal Code:071800
Registrant Country:CN
Registrant Phone:+86.5555555
Registrant Phone Ext:
Registrant Fax: +86.5555555
Registrant Fax Ext:
Registrant Email:"[email protected]"

Domain Name: DDOS123.XYZ
Domain ID: D7151240-CNIC
WHOIS Server: whois.72dns.com
Referral URL: http://www.72e.net
Updated Date: 2015-06-25T09:27:23.0Z
Creation Date: 2015-03-12T10:27:23.0Z
Registry Expiry Date: 2016-03-12T23:59:59.0Z
Sponsoring Registrar: Foshan YiDong Network Co.LTD
Sponsoring Registrar IANA ID: 1563
Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
Domain Status: serverTransferProhibited https://icann.org/epp#serverTransferProhibited
Registrant ID: pi68yf15rg63o3zq
Registrant Name: "wo wo"
Registrant Organization: "wo wo"
Registrant Street: beijingbeijingbeijing
Registrant City: beijing
Registrant State/Province: beijing
Registrant Postal Code: 000101
Registrant Country: CN
Registrant Phone: +86.105801000
Registrant Phone Ext:
Registrant Fax: +86.15121231
Registrant Fax Ext:
Registrant Email: "[email protected]"

Domain Name: DDOSCC.XYZ
Domain ID: D7465669-CNIC
WHOIS Server: whois.72dns.com
Referral URL: http://www.72e.net
Updated Date: 2015-06-25T09:27:24.0Z
Creation Date: 2015-04-06T10:27:24.0Z
Registry Expiry Date: 2016-04-06T23:59:59.0Z
Sponsoring Registrar: Foshan YiDong Network Co.LTD
Sponsoring Registrar IANA ID: 1563
Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
Domain Status: serverTransferProhibited https://icann.org/epp#serverTransferProhibited
Registrant ID: 2lkqa4quhzht2pcg
Registrant Name: "wo wo"
Registrant Organization: "wo wo"
Registrant Street: beijingbeijingbeijing
Registrant City: beijing
Registrant State/Province: beijing
Registrant Postal Code: 000101
Registrant Country: CN
Registrant Phone: +86.105801000
Registrant Phone Ext:
Registrant Fax: +86.15121231
Registrant Fax Ext:
Registrant Email: "[email protected]"
We can see some attempts to "fake" whois information up there. Made those look suspicious. Seeking more malicious record linked to these domains might lead us to something else, but I will focus to the case we ChinaZ CNC verdict in hand.. ] as a contact information. Below is the screenshots and please noted that I am not accusing anyone with anything (yet) here.

This was a posted in December 2014, a request on searching for a source [
He was seeking solution for Linux related problem [
interesting tweet discussion regarding to the message posted by the suspected actor:

— ☩MalwareMustDie (@MalwareMustDie)

— sachin (@essachin)
&

— ☩MalwareMustDie (@MalwareMustDie) ]

#MalwareMustDie

Vollständiger Original-Bericht
Ausführliche Details, Code-Beispiele & Hersteller-Stellungnahme auf blog.malwaremustdie.org.
↗ Original-Artikel auf blog.malwaremustdie.org lesen
Wie bewertest du diesen Beitrag?
1 Klick Feedback
Teilen mit Netzwerk & Team:

Community-Analysen & Experten-Meinungen 0

Verfasse deine eigene Analyse, teile Workarounds oder diskutiere diesen Vorfall im Blog.
Noch keine Community-Analyse verfasst. Markiere einen Textabschnitt oder klicke oben auf Eigene Analyse verfassen“!
Community Pulse: Relevanz-Einschätzung
1 Klick Experten-Votum
🔴 Akute Relevanz 40%
🟡 In Evaluierung 34%
🟢 Keine Auswirkung 19%
Spannende Innovation 7%
Verwandte Story-Cluster & Quellen (Vektor-KI)
Port 8095 Engine
1 Quelle
Generate playable HTML5 games with Mistral Medium and GLM
1 Quelle
New AI waifus, new Deepseek, realtime worlds, Happy Shrimp, tiny TTS: AI NEWS
1 Quelle
Ox Alpha reveal, realtime Minimax, Qwen Next, Hy4, robot olympics: AI NEWS
Ähnliche Beiträge
🔍 Verwandte News

Ähnliche Beiträge zu MMD-0038-2015 - ChinaZ and ddos123.xyz

Thematisch verwandte Begriffe: MMD00382015, ChinaZ, ddos123xyz · 6 Treffer

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...