5 ms·
> https://github.com/Quad9DNS/quad9-domains-top500/blob/main/top500-2025-07-10.json#L5C35-L5C48 https://github.com/Quad9DNS/quad9-domains-top500/blob/main/t...
by 0points 1y ago
> https://github.com/Quad9DNS/quad9-domains-top500/blob/main/top500-2025-07-10.json#L5C35-L5C48 https://github.com/Quad9DNS/quad9-domains-top500/blob/main/t...
{"position": 5, "domain_name": "kxulsrwcq.com", "date": "2025-07-10"}
What the
https://www.ipaddress.com/website/kxulsrwcq.com/ https://www.ipaddress.com/website/kxulsrwcq.com/
> Safety/Trust: Unknown
- 0points 1y agoMore: {"position": 26, "domain_name": "cmidphnvq.com", "date": "2025-07-10"} {"position": 28, "domain_name": "xmqkychtb.com", "date": "2025-07-10"} {"position": 37, "domain_name": "ezdrtpvsa.com", "date": "2025-07-10"} {"position": 38, "domain_name": "wvdbozpfc.com", "date": "2025-07-10"} {"position": 46, "domain_name": "bldrdoc.gov", "date": "2025-07-10"} {"position": 52, "domain_name": "gadf99632rm.xyz", "date": "2025-07-10"}
- netsharc 1y agobldrdoc.gov seems to be Cisco devices looking for a time server: https://community.cisco.com/t5/ipv6/cisco-switch-generating-requests-for-aaaa-records/td-p/4035396 https://community.cisco.com/t5/ipv6/cisco-switch-generating-... Geniuses...
- 0points 1y agoOh, hah. Well that doesn't seem intentionally malicious then. I added it in the first place as it was a non-resolving .gov in the top 50 list which seemed out of place to me. > bldrdoc.gov: No address associated with hostname I see that the time related subdomains in your link do resolve to the nist.gov timeserver. But I really am wondering what's up with all of the rest of these domains.
- netsharc 1y agoGoogling it, one of the results was https://library.bldrdoc.gov/ https://library.bldrdoc.gov/ , for Boulder Labs Library. More googling gave me https://www.boulder.doc.gov https://www.boulder.doc.gov > Boulder is the home of scientific laboratories for the U. S. Department of Commerce’s NOAA, NIST and NTIA. Clustered on the foothills of the Rocky Mountains in Boulder Colorado, these labs are the home of scientific research and engineering in the fields of electromagnetics, materials reliability, optoelectronics, quantum electronics and physics, time and frequency, earth systems, weather and telecommunications. Looks like a place full of scientific knowledge. I hope they haven't suffered much DOGEing.
- Matheus28 1y agoProbably some sort of command and control for a botnet. They calculate a random domain name based on the timestamp (so it’s constantly changing every X days in case it gets seized), and have some validation to make sure commands are signed (to prevent someone name squatting to control their botnet).
- threeducks 1y agoWow, that's smart. I was wondering whether there is a way for the bots to generate "unpredictable" domains such that security researchers could not predict them efficiently (even with source code), but the botnet controller can. Time-lock puzzles come close, but but it requires that the bots have computing power comparable to the security researchers.
- afandian 1y agoI can see a future where Cloudflare or similar offer a DNS + proxy + Root CA combo to intercept these. Maybe they already do.
- threeducks 1y agoThat might work for the current generation of bots, but it will become infeasible when the domain names are generated in such a way that they overlap with spellable and existing domain names.
- 0points 1y ago> it will become infeasible when the domain names are generated in such a way that they overlap with spellable and existing domain names. And why do you believe this will even happen?
- Tijdreiziger 1y agoQuad9 (the subject of this post) already offers ‘threat blocking’ by default. https://quad9.net/service/threat-blocking/ https://quad9.net/service/threat-blocking/
- miyuru 1y agogoogle the domains and you will find subdomains that point to cachefly. hiwd.kxulsrwcq.com is pointing to vdd.cachefly.net I am not sure, but my guess is they might be used by some kind of a streaming service.
- danudey 1y agoMost likely something like an ad service to prevent their content being caught by domain blocklists. That would be similar to how a lot of websites started using randomized strings for attributes like id and class so that users couldn't block page elements based on CSS selectors.
- gchamonlive 1y agoInteresting how ad services and botnets behave similarly in some aspects
- danielcid 1y agoAnd they are often used with random sub domains as well (but they did not include sub domains in their list). Ex: https://dnsarchive.net/search?q=cmidphnvq.com https://dnsarchive.net/search?q=cmidphnvq.com https://dnsarchive.net/search?q=xmqkychtb https://dnsarchive.net/search?q=xmqkychtb https://dnsarchive.net/ipv4/34.126.227.30 https://dnsarchive.net/ipv4/34.126.227.30
- reactordev 1y agoPoor Argentina… https://radar.cloudflare.com/domains/domain/kxulsrwcq.com https://radar.cloudflare.com/domains/domain/kxulsrwcq.com
- whalesalad 1y agoOne of the CNAME's defined for that domain is "hiwd.kxulsrwcq.com" which appears to be flagged for malware. https://www.securefeed.com/Content/WebLookup?host=hiwd.kxulsrwcq.com https://www.securefeed.com/Content/WebLookup?host=hiwd.kxuls...
- deleted 1y ago[deleted]