Files
Patrick Bareiss 7cbc9a9ba6 WIP
2020-04-30 10:34:18 +02:00

31 lines
1.6 KiB
YAML

name: Dynamic DNS
id: 8169f17b-ef68-4b59-aae8-586907301221
version: 2
date: '2018-09-06'
description: Detect and investigate hosts in your environment that may be communicating
with dynamic domain providers. Attackers may leverage these services to help them
avoid firewall blocks and blacklists.
narrative: Dynamic DNS services (DDNS) are legitimate low-cost or free services that
allow users to rapidly update domain resolutions to IP infrastructure. While their
usage can be benign, malicious actors can abuse DDNS to host harmful payloads or
interactive-command-and-control infrastructure. These attackers will manually update
or automate domain resolution changes by routing dynamic domains to IP addresses
that circumvent firewall blocks and blacklists and frustrate a network defender's
analytic and investigative processes. These searches will look for DNS queries made
from within your infrastructure to suspicious dynamic domains and then investigate
more deeply, when appropriate. While this list of top-level dynamic domains is not
exhaustive, it can be dynamically updated as new suspicious dynamic domains are
identified.
author: Bhavin Patel, Splunk
type: ESCU
references:
- https://www.fireeye.com/blog/threat-research/2017/09/apt33-insights-into-iranian-cyber-espionage.html
- https://umbrella.cisco.com/blog/2013/04/15/on-the-trail-of-malicious-dynamic-dns-domains/
- http://www.noip.com/blog/2014/07/11/dynamic-dns-can-use-2/
- https://www.splunk.com/blog/2015/08/04/detecting-dynamic-dns-domains-in-splunk.html
tags:
analytics_story: Dynamic DNS
usecase: Security Monitoring
category:
- Malware