Wednesday, December 17, 2014



If you are seeing queries for this domain, than you are likely participating in DNS Amplification attacks and your DNS server is probably reachable from the internet and has recursion enabled.

If you are seeing responses for this domain.. unlucky. You are currently beeing DDOS-ed! Good luck.


There are two iptable rules available. If your distribution supports Iptables 'u32' module pick this one, otherwise use the 'string' rule.

iptables --insert INPUT -p udp --dport 53 -m u32 --u32 "0x28&0xFFDFDFDF=0x04564c43 && 0x2c&0xDFFFDFDF=0x48034e45 && 0x30&0xDFFFFFFF=0x540000FF" -j DROP -m comment --comment "DROP DNS Q"

More U32 rules can be found here:

iptables --insert INPUT -p udp --dport 53 -m string --from 40 --to 52 --algo bm --hex-string '|04766c6368036e65740000ff|' -j DROP -m comment --comment "DROP DNS Q"
More Iptables rules for the STRING module can be found here:


No IP source for this domain

Name server:

;; ANSWER SECTION: 3599 IN NS 3599 IN NS 3599 IN NS 3599 IN NS


NS 4
Rsize 4400


Whois Server Version 2.0

Domain names in the .com and .net domains can now be registered
with many different competing registrars. Go to
for detailed information.

Domain Name: VLCH.NET
Registrar: BIZCN.COM, INC.
Whois Server:
Referral URL:
Name Server: NS.RU-TLD.COM
Name Server: NS.RU-TLD.NET
Name Server: NS.RU-TLD.ORG
Name Server: NS.RU-TLD.RU
Status: clientDeleteProhibited
Status: clientTransferProhibited
Updated Date: 06-dec-2014
Creation Date: 05-dec-2014
Expiration Date: 05-dec-2015

>>> Last update of whois database: Wed, 17 Dec 2014 20:21:53 GMT <<<

NOTICE: The expiration date displayed in this record is the date the
registrar's sponsorship of the domain name registration in the registry is
currently set to expire. This date does not necessarily reflect the expiration
date of the domain name registrant's agreement with the sponsoring
registrar. Users may consult the sponsoring registrar's Whois database to
view the registrar's reported date of expiration for this registration.

The Registry database contains ONLY .COM, .NET, .EDU domains and
Domain name:
Registry Domain ID: 1888849831_DOMAIN_NET-VRSN
Registrar WHOIS Server:
Registrar URL:
Updated Date: 2014-12-05T18:40:38Z
Creation Date: 2014-12-05T18:40:34Z
Registrar Registration Expiration Date: 2015-12-05T18:40:34Z
Registrar IANA ID: 471
Registrar Abuse Contact Email:
Registrar Abuse Contact Phone: +86.5922577888
Reseller: Cnobin Technology HK Limited
Domain Status: clientDeleteProhibited
Domain Status: clientTransferProhibited
Registry Registrant ID:
Registrant Name: Zhong Si
Registrant Organization: Xicheng Co.
Registrant Street: Huixindongjie 15 2
Registrant City: Beijing
Registrant State/Province: Chaoyang
Registrant Postal Code: 101402
Registrant Country: cn
Registrant Phone: +01.01066569215
Registrant Phone Ext:
Registrant Fax: +01.01066549216
Registrant Fax Ext:
Registrant Email:
Registry Admin ID:
Admin Name: Zhong Si
Admin Organization: Xicheng Co.
Admin Street: Huixindongjie 15 2
Admin City: Beijing
Admin State/Province: Chaoyang
Admin Postal Code: 101402
Admin Country: cn
Admin Phone: +01.01066569215
Admin Phone Ext:
Admin Fax: +01.01066549216
Admin Fax Ext:
Admin Email:
Registry Tech ID:
Tech Name: Zhong Si
Tech Organization: Xicheng Co.
Tech Street: Huixindongjie 15 2
Tech City: Beijing
Tech State/Province: Chaoyang
Tech Postal Code: 101402
Tech Country: cn
Tech Phone: +01.01066569215
Tech Phone Ext:
Tech Fax: +01.01066549216
Tech Fax Ext:
Tech Email:
Name Server:
Name Server:
Name Server:
Name Server:
DNSSEC: unsignedDelegation
URL of the ICANN WHOIS Data Problem Reporting System:
>>> Last update of WHOIS database: 2014-12-17T20:22:12Z

1 comment:

  1. I just found this in my logs from two hours ago. "named[1741]: client ( query (cache) '' denied"

    I don't really understand. Does that mean they attempted to do something and were blocked?