ATT&CKReferencesPalo Alto DNS Requests

Palo Alto DNS Requests

Grunzweig, J., et al. (2016, May 24). New Wekby Attacks Use DNS Requests As Command and Control Mechanism. Retrieved August 17, 2016.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples9

TechniqueUsed byProcedure example
T1016
System Network Configuration Discovery
MalwarePisloader

Pisloader has a command to collect the victim's IP address.

T1027
Obfuscated Files or Information
MalwarePisloader

Pisloader obfuscates files by splitting strings into smaller sub-strings and including "garbage" strings that are never used. The malware also uses return-oriented programming (ROP) technique and single-byte XOR to obfuscate data.

T1059.003
Windows Command Shell
MalwarePisloader

Pisloader uses cmd.exe to set the Registry Run key value. It also has a command to spawn a command shell.

T1071.004
DNS
MalwarePisloader

Pisloader uses DNS as its C2 protocol.

T1082
System Information Discovery
MalwarePisloader

Pisloader has a command to collect victim system information, including the system name and OS version.

T1083
File and Directory Discovery
MalwarePisloader

Pisloader has commands to list drives on the victim machine and to list file information for a given directory.

T1105
Ingress Tool Transfer
MalwarePisloader

Pisloader has a command to upload a file to the victim machine.

T1132.001
Standard Encoding
MalwarePisloader

Responses from the Pisloader C2 server are base32-encoded.

T1547.001
Registry Run Keys / Startup Folder
MalwarePisloader

Pisloader establishes persistence via a Registry Run key.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.