Hacker News new | ask | show | jobs
by throwawayapples 1252 days ago
ycxrl.com (registered at godaddy with privacy) is the command-and-control domain mentioned in the article, which currently resolves to 192.53.113.52 (Linode). DNS is run through DOMAINCONTROL.COM, which seems to be a nextcloud instance?
2 comments

Looks like 139.162.63.161 may also be involved, it has the same ssh server key:

https://search.censys.io/search?q=services.ssh.server_host_k...

The domaincontrol.com nameservers are operated by GoDaddy.