🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

ThreatFox IOC Database

You are viewing the ThreatFox database entry for domain srv-stat-node.ru.

Database Entry


IOC ID:1949590
IOC: srv-stat-node.ru
IOC Type :domain
Threat Type :botnet_cc
Malware: XOR DDoS
Malware alias:XORDDOS
Confidence Level : Confidence level is elevated (75%)
Is compromised? : False
First seen:2026-10-04 06:54:27 UTC
Last seen:never
UUID:165fe955-bfa2-11f1-bd81-42010aa4000a
Reporter ksi_digital
Reward 5 credits from ThreatFox
Tags:cowrie elf honeypot ssh-honeypot x86 xorddos
Reference: https://bazaar.abuse.ch/sample/3064ca5f0f0099f9bb98503e0bcb42a2824da2be5c5c2549eea6c2511bea577a/

Avatar
ksi_digital
XorDDoS C2 domain (TCP 1531). Delivered to our Cowrie SSH honeypot on 2026-10-03 19:13 UTC by 23.160.56.10 (SSH-2.0-PUTTY, root login): SFTP upload of ELF32 i386 sample 3064ca5f0f0099f9bb98503e0bcb42a2824da2be5c5c2549eea6c2511bea577a as /bin/skhqwensw (on MalwareBazaar, sig XorDDoS). Run in our offline sandbox (DNS sinkholed, no internet) on 2026-10-04 03:13 UTC: textbook XorDDoS install (self-copy to /tmp/<random>, /etc/cron.hourly/gcc.sh every 3 min, /var/run/gcc.pid), then DNS queries for 15 C2 domains, followed by 123 TCP connect attempts to the sinkholed answers on port 1531. 14 of the 15 are already on ThreatFox (ids 1941525-1941538, abuse_ch, 2026-09-29: cloud-init-config.tj, core-sync-io.tj, db-sync-service.ru, ...); srv-stat-node.ru is the one not yet listed. Confidence 75 = observed as a C2 lookup in a sandbox run of the sample; the domain was not resolved or contacted from our side, liveness not verified.