XOR DDoS
Malware Family24 indicators of compromise attributed to XOR DDoS across abuse.ch threat intelligence feeds.
Domains
15
IPs
7
URLs
1
Hashes
1
Download indicators
Indicator lists for this family. Free and anonymous downloads are a 10% sample.
Need continuous updates instead of static lists? The same IOCs ship in the STIX/TAXII threat feed, ready for OpenCTI and MISP.
Threat types
Botnet C&CpayloadPayload Delivery
Sample indicators
| Indicator | Type |
|---|---|
| cloud-init-config.tj | domain |
| core-sync-io.tj | domain |
| db-sync-service.ru | domain |
| dist-patch-log.vg | domain |
| flux-net-node.to | domain |
| host-metrics-rev.su | domain |
| legacy-data-stream.su | domain |
| metadata-fetcher.vg | domain |
| net-sync-cache.md | domain |
| nexus-bridge.to | domain |
| proc-mem-status.md | domain |
| relay-agent-v4.am | domain |
| stellar-sync.to | domain |
| system-patch-node.am | domain |
| srv-stat-node.ru | domain |
| 158.51.96.38 | ip |
| 31.177.110.228 | ip |
| 150.138.182.190 | ip |
| 115.231.236.150 | ip |
| 118.182.166.128 | ip |
| 188.32.210.218 | ip |
| 141.98.10.115 | ip |
| http://182.52.51.239/scripts/23 | url |
| 06fffeea93435328949a102e15496f92e4dddb66cdb8a351d7efb31e0a0b5049 | hash |
Another file to check? Run a file hash reputation check.