ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1568×

10 examples

TechniqueUsed byProcedure example
T1568
Dynamic Resolution
MalwareBRICKSTORM

BRICKSTORM has utilized DNS services sslip.io and nip.io to resolve C2 IP addresses.

T1568
Dynamic Resolution
MalwareTomiris

Tomiris has connected to a signalization server that provides a URL and port, and then Tomiris sends a GET request to that URL to establish C2.

T1568
Dynamic Resolution
MalwareNETEAGLE

NETEAGLE can use HTTP to download resources that contain an IP address and port number pair to connect to for C2.

T1568
Dynamic Resolution
MalwareBisonal

Bisonal has used a dynamic DNS service for C2.

T1568
Dynamic Resolution
MalwareRTM

RTM has resolved Pony C2 server IP addresses by either converting Bitcoin blockchain transaction data to specific octets, or accessing IP addresses directly within the Namecoin blockchain.

T1568
Dynamic Resolution
MalwareSUNBURST

SUNBURST dynamically resolved C2 infrastructure for randomly-generated subdomains within a parent domain.

T1568
Dynamic Resolution
MalwareMaze

Maze has forged POST strings with a random choice from a list of possibilities including "forum", "php", "view", etc. while making connection with the C2, hindering detection efforts.

T1568
Dynamic Resolution
MalwareGelsemium

Gelsemium can use dynamic DNS domain names in C2.

T1568
Dynamic Resolution
ToolAsyncRAT

AsyncRAT can be configured to use dynamic DNS.

T1568
Dynamic Resolution
ToolRemcos

Remcos has used dynamic DNS domains in C2 communications.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.