Real-world descriptions of how a group, tool or campaign used a technique.
10 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1568 Dynamic Resolution |
MalwareBRICKSTORM | BRICKSTORM has utilized DNS services sslip.io and nip.io to resolve C2 IP addresses. |
| T1568 Dynamic Resolution |
MalwareTomiris | Tomiris has connected to a signalization server that provides a URL and port, and then Tomiris sends a GET request to that URL to establish C2. |
| T1568 Dynamic Resolution |
MalwareNETEAGLE | NETEAGLE can use HTTP to download resources that contain an IP address and port number pair to connect to for C2. |
| T1568 Dynamic Resolution |
MalwareBisonal | Bisonal has used a dynamic DNS service for C2. |
| T1568 Dynamic Resolution |
MalwareRTM | RTM has resolved Pony C2 server IP addresses by either converting Bitcoin blockchain transaction data to specific octets, or accessing IP addresses directly within the Namecoin blockchain. |
| T1568 Dynamic Resolution |
MalwareSUNBURST | SUNBURST dynamically resolved C2 infrastructure for randomly-generated subdomains within a parent domain. |
| T1568 Dynamic Resolution |
MalwareMaze | Maze has forged POST strings with a random choice from a list of possibilities including "forum", "php", "view", etc. while making connection with the C2, hindering detection efforts. |
| T1568 Dynamic Resolution |
MalwareGelsemium | Gelsemium can use dynamic DNS domain names in C2. |
| T1568 Dynamic Resolution |
ToolAsyncRAT | AsyncRAT can be configured to use dynamic DNS. |
| T1568 Dynamic Resolution |
ToolRemcos | Remcos has used dynamic DNS domains in C2 communications. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.