Really interesting to know though.
Some just look way high up and could mean buggy implementation without proper cache usage or persistently banging the domain.
71–80 of 100 posts
Really interesting to know though.
Some just look way high up and could mean buggy implementation without proper cache usage or persistently banging the domain.
Earlier quoted context omitted.
> Wow, that's smart. I was wondering whether there is a way for the bots to generate "unpredictable" domains such that security researchers could not predict them efficiently (even with source code), but the botnet controller can. There is a fairly simple method which achieves the same advantage for a botnet controller. 1. Use a hash of the current day to derive, for that day, an infinite stream of domain names. This…
I've definitely heard of cnc using a plural of domains for this reason. the bots have a list of domains they reach out to, searching for one that is valid. I believe one issue with this strategy is many corporate VPNs block fresh domains. I guess if the software was pinned to use encrypted DNS instead of whatever the OS recommends, then the DNS blocking could be avoided...
example.com #17 ?
Isn't part of the reasons to run a public DNS to sell these hard earned info for profit to marketers etc but they just release publicly? Of course this is just the tip of the iceberg of the information they gather. Really interesting to know though. Some just look way high up and could mean buggy implementation without proper cache usage or persistently banging the domain.
54.in-addr.arpa looks to be Amazon's range and there are several others.
Earlier quoted context omitted.
I've definitely heard of cnc using a plural of domains for this reason. the bots have a list of domains they reach out to, searching for one that is valid. I believe one issue with this strategy is many corporate VPNs block fresh domains. I guess if the software was pinned to use encrypted DNS instead of whatever the OS recommends, then the DNS blocking could be avoided...
How would a corporate DNS block new domains, exactly?
https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?...
Earlier quoted context omitted.
I've definitely heard of cnc using a plural of domains for this reason. the bots have a list of domains they reach out to, searching for one that is valid. I believe one issue with this strategy is many corporate VPNs block fresh domains. I guess if the software was pinned to use encrypted DNS instead of whatever the OS recommends, then the DNS blocking could be avoided...
How would a corporate DNS block new domains, exactly?
In technical terms, the device asks the private corporate DNS server for the IP address of the hostname. The private DNS server checks the requested domain against a threat intelligence feed that tracks domain registration dates (and security risks). If the domain is deemed a threat, either return an IP address which points at a server that shows a warning message (if http traffic) or return an invalid IP (0.0.0.0).
Earlier quoted context omitted.
I've definitely heard of cnc using a plural of domains for this reason. the bots have a list of domains they reach out to, searching for one that is valid. I believe one issue with this strategy is many corporate VPNs block fresh domains. I guess if the software was pinned to use encrypted DNS instead of whatever the OS recommends, then the DNS blocking could be avoided...
How would a corporate DNS block new domains, exactly?
When getting a query for a domain you have not heard about, query whois for it. Store it's registration date in the cache.
> https://github.com/Quad9DNS/quad9-domains-top500/blob/main/t... {"position": 5, "domain_name": "kxulsrwcq.com", "date": "2025-07-10"} What the https://www.ipaddress.com/website/kxulsrwcq.com/ > Safety/Trust: Unknown
Seems like it'd be a good addition to the Tranco list: https://tranco-list.eu/