Real-world descriptions of how a group, tool or campaign used a technique.
22 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1568.002 Domain Generation Algorithms |
MalwareUrsnif | Ursnif has used a DGA to generate domain names for C2. |
| T1568.002 Domain Generation Algorithms |
MalwareAria-body | Aria-body has the ability to use a DGA for C2 communications. |
| T1568.002 Domain Generation Algorithms |
MalwareSombRAT | SombRAT can use a custom DGA to generate a subdomain for C2. |
| T1568.002 Domain Generation Algorithms |
MalwareDoki | Doki has used the DynDNS service and a DGA based on the Dogecoin blockchain to generate C2 domains. |
| T1568.002 Domain Generation Algorithms |
MalwareConficker | Conficker has used a DGA that seeds with the current UTC victim system date to generate domains. |
| T1568.002 Domain Generation Algorithms |
MalwarePOSHSPY | POSHSPY uses a DGA to derive command and control URLs from a word list. |
| T1568.002 Domain Generation Algorithms |
MalwareMiniDuke | MiniDuke can use DGA to generate new Twitter URLs for C2. |
| T1568.002 Domain Generation Algorithms |
MalwareDarkWatchman | DarkWatchman has used a DGA to generate a domain name for C2. |
| T1568.002 Domain Generation Algorithms |
MalwareGrandoreiro | Grandoreiro can use a DGA for hiding C2 addresses, including use of an algorithm with a user-specific key that changes daily. |
| T1568.002 Domain Generation Algorithms |
MalwareShark | Shark can send DNS C2 communications using a unique domain generation algorithm. |
| T1568.002 Domain Generation Algorithms |
MalwareBazar | Bazar can implement DGA using the current date as a seed variable. |
| T1568.002 Domain Generation Algorithms |
MalwareHiddenFace | HiddenFace has used dynamic domain generation algorithms in C2. |
| T1568.002 Domain Generation Algorithms |
MalwareMilan | Milan can use hardcoded domains as an input for domain generation algorithms. |
| T1568.002 Domain Generation Algorithms |
MalwareCCBkdr | CCBkdr can use a DGA for Fallback Channels if communications with the primary command and control server are lost. |
| T1568.002 Domain Generation Algorithms |
MalwareCHOPSTICK | CHOPSTICK can use a DGA for Fallback Channels, domains are generated by concatenating words from lists. |
| T1568.002 Domain Generation Algorithms |
MalwareBONDUPDATER | BONDUPDATER uses a DGA to communicate with command and control servers. |
| T1568.002 Domain Generation Algorithms |
MalwareEbury | Ebury has used a DGA to generate a domain name for C2. |
| T1568.002 Domain Generation Algorithms |
MalwareShadowPad | ShadowPad uses a DGA that is based on the day of the month for C2 servers. |
| T1568.002 Domain Generation Algorithms |
MalwareAstaroth | Astaroth has used a DGA in C2 communications. |
| T1568.002 Domain Generation Algorithms |
MalwareQakBot | QakBot can use domain generation algorithms in C2 communication. |
| T1568.002 Domain Generation Algorithms |
Toolngrok | ngrok can provide DGA for C2 servers through the use of random URL strings that change every 12 hours. |
| T1568.002 Domain Generation Algorithms |
ToolAsyncRAT | AsyncRAT use a DGA to generate a C2 domains. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.