🕵️ HackingReopening im Loft: Was ist neu da oben? - Wien - Kurier(17.09.2026 um 05:14 Uhr)
🕵️ HackingTangerhütte: Hacker greifen Verwaltung an - radio SAW(17.09.2026 um 06:32 Uhr)
🕵️ HackingReopening im Loft: Was ist neu da oben? - Wien - Kurier(17.09.2026 um 05:14 Uhr)
🕵️ HackingTangerhütte: Hacker greifen Verwaltung an - radio SAW(17.09.2026 um 06:32 Uhr)
🎥 Video 🕛 vor 11 Jahren 8 Min Lesezeit
0

MMD-0033-2015 - Linux/XorDDoS infection incident report (CNC: HOSTASA.ORG)

↗ Quelle (blog.malwaremustdie.org)
🗣️ Stimme:
📑 Inhaltsübersicht

Background

This post is an actual malware infection incident of the"Linux/XOR.DDoS" malware (please see previous post as reference-->[

..and then the malware initiation commands was executed on the compromised system:

The IP info of this panel:


"ip": "198.15.234.66",
"hostname": "No Hostname",
"city": "Nanjing",
"region": "Jiangsu",
"country": "CN",
"loc": "32.0617,118.7778",
"org": "AS11282 SERVERYOU INC",
"postal": "210004"
(Additional) The domain information:

;; QUESTION SECTION:
;44ro4.cn. IN A

;; ANSWER SECTION:
44ro4.cn. 600 IN A 23.228.238.131
44ro4.cn. 600 IN A 198.15.234.66

;; AUTHORITY SECTION:
44ro4.cn. 3596 IN NS ns2.51dns.com.
44ro4.cn. 3596 IN NS ns1.51dns.com.
Below is more proof of the domain's used, a check mate:

Rule number 1 in MMD is : Always check under the hood :) ], the post-infection of this malware made the infected machine to act as bot, remotely controlled for malicious process, config, deny IP, daemon and configurations. They are using XOR'ed encryption communication, processes are sent with md5 encoded beforehand. The main function of this malware ELF is for a stealth DDoS attacker botnet.

The important highlight of this incident and the malware used are:

(1) The usage of US infrastructure used for this malware infection (attacker IP from US host, one IP of panel used for infection, two servers for CNC, with the abuse of .ORG domain registration) with the new scheme worth to be exposed & followed in as incident response and awareness of what this threat does. And all of these just happened about 12h ago..

(2) The usage of multiple hosts in this Linux/XorDDoS, in total: four CNCs. Three of those CNCs are hard coded in hostnames (has domain related) and are receiving the callback from the infected machine, while one of the host is functioned as download server which the infected machine is requesting backdoor to download suspected malicious files.

(3) XOR encryption function is used now to decrypt the drops, reading the configuration file downloaded from the remote hosts (yes, what it downloaded seems to be the config file), and for sending the CNC communication data.

Here is the PoC:

These are the CNC interactive calls trapped in the kernels:

- in tcpdump with the timestamp:

08:21:20.078878 IP mmd.bangs.xorddos.40274 > 8.8.8.8: 27458+ A? aa.hostasa.org. (32)
08:21:20.080602 IP mmd.bangs.xorddos.38988 > 8.8.8.8: 44387+ A? ns4.hostasa.org. (33)
08:21:25.092061 IP mmd.bangs.xorddos.45477 > 8.8.8.8: 58191+ A? ns3.hostasa.org. (33)
08:21:25.269790 IP mmd.bangs.xorddos.51687 > 8.8.8.8: 22201+ A? ns2.hostasa.org. (33)

Calls to CNC establishment, I pick only one, each callback does this, noted the way it uses Google DNS:

Some decrypting for memo:

Downloader...

And also the hard evidence in traffic too:)

The malware autorun installer shell script hard coded in the binary, this is so generic..many ELF malware made in China is using this concept:

Spotted the XOR encryption to be run from installer and "supposedly" to be used on decrypting configuration data, in the sample I cracked the key is BB2FA36AAA9541F0

-and this..

Investigation for legals & cleanup process:

The hosts serving CNC are as per checked in the DNS record below:

;; ANSWER SECTION:
aa.hostasa.org. 300 IN A 23.234.60.143
ns2.hostasa.org. 300 IN A 103.240.140.152
ns3.hostasa.org. 300 IN A 103.240.141.54
ns4.hostasa.org. 300 IN A 192.126.126.64

;; AUTHORITY SECTION:
hostasa.org. 3600 IN NS ns4lny.domain-resolution.net.
hostasa.org. 3600 IN NS ns1cnb.domain-resolution.net.
hostasa.org. 3600 IN NS ns3cna.domain-resolution.net.
hostasa.org. 3600 IN NS ns2dky.domain-resolution.net.

;; ADDITIONAL SECTION:
ns3cna.domain-resolution.net. 2669 IN A 98.124.246.2
ns2dky.domain-resolution.net. 649 IN A 98.124.246.1
ns1cnb.domain-resolution.net. 159 IN A 50.23.84.77
ns4lny.domain-resolution.net. 2772 IN A 98.124.217.1

Up and alive CNCs are in USA:


"ip": "23.234.60.143",
"hostname": "No Hostname",
"city": "Newark",
"region": "Delaware",
"country": "US",
"loc": "39.7151,-75.7306",
"org": "AS26484 HOSTSPACE NETWORKS LLC",
"postal": "19711"

"ip": "192.126.126.64",
"hostname": "No Hostname",
"city": "Los Angeles",
"region": "California",
"country": "US",
"loc": "34.0530,-118.2642",
"org": "AS26484 HOSTSPACE NETWORKS LLC",
"postal": "90017"
These other two CNCs are allocated in Hongkong network:

"ip": "103.240.140.152",
"hostname": "No Hostname",
"city": "Central District",
"country": "HK",
"loc": "22.2833,114.1500",
"org": "AS62466 ClearDDoS Technologies"

"ip": "103.240.141.54",
"hostname": "No Hostname",
"city": "Central District",
"country": "HK",
"loc": "22.2833,114.1500",
"org": "AS62466 ClearDDoS Technologies"

The domain HOSTASA.ORG is beyond doubt proven to be used for this malicious purpose, three hostnames fake themself with hostname to look like a DNS servers, which is NOT. Below is the registration data from NAME.COM where it is registered as .ORG, with the Privacy Protection:


Domain Name:"HOSTASA.ORG"
Domain ID: 2D175880649-LROR"
"Creation Date: 2015-03-31T06:56:01Z
Updated Date: 2015-05-31T03:45:36Z"
Registry Expiry Date: 2016-03-31T06:56:01Z
Sponsoring Registrar:"Name.com, LLC (R1288-LROR)"
Sponsoring Registrar IANA ID: 625
WHOIS Server:
Referral URL:
Domain Status: clientTransferProhibited -- http://www.icann.org/epp#clientTransferProhibited
Registrant ID:necwp72276k4nva0
Registrant Name:Whois Agent
Registrant Organization:Whois Privacy Protection Service, Inc.
Registrant Street: PO Box 639
Registrant City:Kirkland
Registrant State/Province:WA
Registrant Postal Code:98083
Registrant Country:US
Registrant Phone:+1.4252740657
Registrant Phone Ext:
Registrant Fax: +1.4259744730
Registrant Fax Ext:
Registrant Email:[email protected]
Tech Email:[email protected]
Name Server:NS3CNA.DOMAIN-RESOLUTION.NET
Name Server:NS1CNB.DOMAIN-RESOLUTION.NET
Name Server:NS2DKY.DOMAIN-RESOLUTION.NET
Name Server:NS4LNY.DOMAIN-RESOLUTION.NET
DNSSEC:Unsigned

Additionally, for the 44RO4.CN domain used, which is registered in DNS pointing to the malware payloads web panel, that is not a coincidence, it is registered under below QQ ID and (maybe fake) name;

Domain Name: 44ro4.cn
ROID: 20141229s10001s73492202-cn
Domain Status: ok
Registrant ID: ji27ikgt6kc203
Registrant: "蔡厚泉 (Cai Hou Sien/Quan)"
Registrant Contact Email: "[email protected]"
Sponsoring Registrar: 北京新网数码信息技术有限公司
Name Server: ns1.51dns.com
Name Server: ns2.51dns.com
Registration Time: 2014-12-29 10:13:43
Expiration Time: 2015-12-29 10:13:43
DNSSEC: unsigned
ps: CNNIC has more information of this registration, I took liberty to query them to find this crook is using the same and other ID to several poor reputation .CN domains, under the same and different name too, on the same QQ:
Domain   RegistrantID     Name
------------------------------
n1o9n.cn ej55v35357p95m 沈涛
u7ju0.cn ej55v35357p95m 沈涛
568b5.cn ej55v35357p95m 沈涛
93t9i.cn ej55v35357p95m 沈涛
5ntdu.cn ej55v35357p95m 沈涛
v90b8.cn ej55v35357p95m 沈涛
av732.cn ej55v35357p95m 沈涛
iqny7.cn ej55v35357p95m 沈涛
ewkp7.cn ej55v35357p95m 沈涛
8vu55.cn ji27ikgt6kc203 蔡厚泉
tj17e.cn ej55v35357p95m 沈涛
o88pn.cn ji27ikgt6kc203 蔡厚泉
And after seeking for a while, all of these reference lead to the individual identification here:

I will leave this data for the authority to follow this lead further.

Detection ratio and samples

ELF samples are all in Virus Total with the below links:
(a06.zip) =
(a08.zip) =
(a10.zip) = ]

#MalwareMustDie!

Vollständiger Original-Artikel
Den kompletten Beitrag mit allen Details direkt auf blog.malwaremustdie.org lesen.
↗ Original-Artikel auf blog.malwaremustdie.org lesen
Wie bewertest du diesen Beitrag?
1 Klick Feedback
Teilen mit Netzwerk & Team:

Community-Analysen & Experten-Meinungen 0

Verfasse deine eigene Analyse, teile Workarounds oder diskutiere diesen Vorfall im Blog.
Noch keine Community-Analyse verfasst. Markiere einen Textabschnitt oder klicke oben auf Eigene Analyse verfassen“!
Community Pulse: Relevanz-Einschätzung
1 Klick Experten-Votum
🔴 Akute Relevanz 0%
🟡 In Evaluierung 0%
🟢 Keine Auswirkung 0%
Spannende Innovation 0%
Verwandte Story-Cluster & Quellen (Vektor-KI)
Port 8095 Engine
1 Quelle
Built a PPL-aware ALPC enumerator because standard handle duplication was leaving blind spots in the attack surface
1 Quelle
SindriKit V2.0.0 (C framework to decouple technique logic from execution mechanics)
1 Quelle
Heap-Buffer-Überlauf im Discord-Backend
Ähnliche Beiträge
🔍 Verwandte News

Ähnliche Beiträge zu MMD-0033-2015 - Linux/XorDDoS infection incident report (CNC: HOSTASA.ORG)

Thematisch verwandte Begriffe: MMD00332015, LinuxXorDDoS, infection, incident · 6 Treffer

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...