Loading...
KSI Digital
XorDDoS: the 15th C2 domain the public list was missing
Threat Research

XorDDoS: the 15th C2 domain the public list was missing

A XorDDoS sample uploaded to our SSH honeypot looked up 15 command-and-control domains. Fourteen were already on ThreatFox. We reported the one that was not, and this is how we found it.

KSI Digital Solutions
2026-10-05
5 min

Shared threat-intelligence feeds are only as complete as what their contributors report, and a blocklist built from a feed can only block what has been listed. On 3 October 2026 a XorDDoS sample was uploaded to our SSH honeypot. When we ran it offline, it looked up 15 command-and-control (C2) domains. Fourteen were already on ThreatFox. One, srv-stat-node[.]ru, was not on ThreatFox, URLhaus or MalwareBazaar, and a web search found nothing about it. We reported it to ThreatFox on 4 October 2026.

XorDDoS itself is not new: the sample and the other 14 domains were all already on abuse.ch's platforms. It reached our honeypot through an SSH login as root. For an organisation running Linux servers, the finding is a reminder of two things: harden SSH, and make sure your blocklists get the whole set of a family's domains, not most of it.

How it reached our honeypot

At 19:13 UTC on 3 October 2026, an actor logged in to our Cowrie SSH honeypot as root and uploaded a file over SFTP. It was a 32-bit x86 Linux executable (ELF, 114,768 bytes), written to /bin/skhqwensw. Its SHA-256 hash begins 3064ca5f0f00. The sample itself was not new: abuse.ch had added it to MalwareBazaar on 1 October 2026.

What the analysis showed

We ran the sample offline in our isolated lab, with no internet access. Its DNS queries and connection attempts went to a sinkhole and were logged. In that run it:

  • copied itself to /tmp under a random name;

  • installed a script named gcc.sh in cron.hourly, set to run every three minutes, with a gcc.pid lock file. This is classic XorDDoS persistence;

  • issued DNS lookups for 15 C2 domains;

  • sent about 123 connection attempts (TCP SYN packets) to the sinkhole on TCP port 1531, its C2 port.

The 15 domains follow one naming pattern. They use service-like names built around words such as node, sync and status (for example system-patch-node, core-sync-io, proc-mem-status) on less common top-level domains: .ru, .su, .to, .tj, .am, .md and .vg.

We then checked each domain against the public feeds. Fourteen had been added to ThreatFox by abuse.ch on 29 September 2026 (IDs 1941525 to 1941538). srv-stat-node[.]ru was the gap: no ThreatFox, URLhaus or MalwareBazaar entry, and no web hits. We reported it to ThreatFox as a XorDDoS C2 domain.

Because the run was fully offline, what we observed is that the sample is configured to look up this domain. We did not contact any C2, so we make no claim about what server, if any, answered behind it at the time.

What defenders can do

  • Harden SSH. This sample arrived through a root login and a file upload. Disable password logins for root, prefer key-based authentication, and limit who can reach SSH.

  • Block the full domain set. Add all 15 domains to your DNS blocklist or response-policy zone, not only the 14 that were already listed. DNS lookups for these node / sync style names on the TLDs above are worth alerting on.

  • Watch outbound TCP port 1531. Outbound connections to this port match this family's C2 traffic and are worth alerting on.

  • Check cron. A file named gcc.sh in cron.hourly, or a gcc.pid lock file, on a server that has no compiler-related scheduled jobs, deserves a closer look.

  • Use the published rules. Our repository has Suricata and Sigma rules for the signals above.

Key indicators

IndicatorRoleReference
srv-stat-node[.]ruXorDDoS C2 domain (previously unlisted)ThreatFox
3064ca5f0f0099f9...XorDDoS sample, ELF 32-bit i386, 114,768 bytes (SHA-256 prefix)MalwareBazaar
1531/tcpC2 portiocs.csv
cron.hourly/gcc.sh, gcc.pidPersistence filesiocs.csv

The full list of 15 domains, defanged, is in the finding's iocs.csv, with the full technical write-up alongside.

How we work

KSI Digital runs a WordPress bait and a Cowrie SSH/Telnet honeypot that record attacks and keep the files attackers upload or download. We analyse samples in an isolated lab whose default is fully offline: it records what a sample tries to reach without letting the connections complete. Before we report an indicator, we check it against existing feeds, so we add what is missing rather than duplicating what others have already shared. More on our research page and in our methodology.


Indicators shared with ThreatFox, URLhaus and AbuseIPDB as ksi_digital. For this finding we reported srv-stat-node[.]ru to ThreatFox on 4 October 2026; the sample and the other 14 domains were already indexed by abuse.ch. Corrections are welcome: open an issue on GitHub or email christophe@ksi-digital.com.

Tags

Threat ResearchCybersecurityBotnetDDoSLinuxHoneypot

Concerned about these threats?

We test and monitor Indonesian organisations against the attacks our sensors see every day.

Our cybersecurity services