Dynamic Resolution

T1568

Technique with 3 sub-techniques.View on attack.mitre.org

About this technique

Adversaries may dynamically establish connections to command and control infrastructure to evade common detections and remediations. This may be achieved by using malware that shares a common algorithm with the infrastructure the adversary uses to receive the malware's communications. These calculations can be used to dynamically adjust parameters such as the domain name, IP address, or port number the malware uses for command and control.

Adversaries may use dynamic resolution for the purpose of Fallback Channels. When contact is lost with the primary command and control server malware may employ dynamic resolution as a means to reestablishing command and control.

Detection rules5

Rules on DetectionCode tagged with T1568 or one of its sub-techniques.

Sigma3

RuleLevelLog sourceTechnique
Communication To Ngrok Tunneling Service - Linuxhighlinux / network_connectionT1568.002
Communication To Ngrok Tunneling Service Initiatedhighwindows / network_connectionT1568.002
Download from Suspicious Dyndns HostsmediumNULL / proxyT1568

Splunk2

Sub-techniques3

IDNameExamples
T1568.001Fast Flux DNS6
T1568.002Domain Generation Algorithms24
T1568.003DNS Calculation1

Groups8

Software10

Campaigns6

Procedure examples24

Groups8

Used byProcedure example
GroupAPT-C-36

APT-C-36 has used DDNS services such as DuckDNS, noip[.]com, and con-ip[.]com to redirect victims to sites or repositories hosting malware implants.

GroupAPT29

APT29 has used Dynamic DNS providers for their malware C2 infrastructure.

GroupBITTER

BITTER has used DDNS for C2 communications.

GroupGamaredon Group

Gamaredon Group has incorporated dynamic DNS domains in its infrastructure.

GroupKimsuky

Kimsuky has used Dynamic DNS (DDNS) services, such as FreeDNS or No-IP DDNS, to include servers located in South Korea.

GroupRedEcho

RedEcho used dynamic DNS domains associated with malicious infrastructure.

GroupTA2541

TA2541 has used dynamic DNS services for C2 infrastructure.

GroupTransparent Tribe

Transparent Tribe has used dynamic DNS services to set up C2.

Software10

Used byProcedure example
ToolAsyncRAT

AsyncRAT can be configured to use dynamic DNS.

MalwareBisonal

Bisonal has used a dynamic DNS service for C2.

MalwareBRICKSTORM

BRICKSTORM has utilized DNS services sslip.io and nip.io to resolve C2 IP addresses.

MalwareGelsemium

Gelsemium can use dynamic DNS domain names in C2.

MalwareMaze

Maze has forged POST strings with a random choice from a list of possibilities including "forum", "php", "view", etc. while making connection with the C2, hindering detection efforts.

MalwareNETEAGLE

NETEAGLE can use HTTP to download resources that contain an IP address and port number pair to connect to for C2.

ToolRemcos

Remcos has used dynamic DNS domains in C2 communications.

MalwareRTM

RTM has resolved Pony C2 server IP addresses by either converting Bitcoin blockchain transaction data to specific octets, or accessing IP addresses directly within the Namecoin blockchain.

View all 10 software examples

Campaigns6

Used byProcedure example
CampaignC0026

During C0026, the threat actors re-registered a ClouDNS dynamic DNS subdomain which was previously used by ANDROMEDA.

CampaignIndian Critical Infrastructure Intrusions

During Indian Critical Infrastructure Intrusions, RedEcho used dynamic DNS domains associated with malicious infrastructure.

CampaignNight Dragon

During Night Dragon, threat actors used dynamic DNS services for C2.

CampaignOperation Dust Storm

For Operation Dust Storm, the threat actors used dynamic DNS domains from a variety of free providers, including No-IP, Oray, and 3322.

CampaignOperation Spalax

For Operation Spalax, the threat actors used dynamic DNS services, including Duck DNS and DNS Exit, as part of their C2 infrastructure.

CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 used dynamic DNS resolution to construct and resolve to randomly-generated subdomains for C2.

References3

  1. ESET Sednit 2017 Activity Open source
    ESET. (2017, December 21). Sednit update: How Fancy Bear Spent the Year. Retrieved February 18, 2019.
  2. FireEye POSHSPY April 2017 Open source
    Dunwoody, M.. (2017, April 3). Dissecting One of APT29’s Fileless WMI and PowerShell Backdoors (POSHSPY). Retrieved April 5, 2017.
  3. Talos CCleanup 2017 Open source
    Brumaghin, E. et al. (2017, September 18). CCleanup: A Vast Number of Machines at Risk. Retrieved March 9, 2018.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.