Domain Generation Algorithms

T1568.002

Sub-technique of T1568 Dynamic Resolution.View on attack.mitre.org

About this technique

Adversaries may make use of Domain Generation Algorithms (DGAs) to dynamically identify a destination domain for command and control traffic rather than relying on a list of static IP addresses or domains. This has the advantage of making it much harder for defenders to block, track, or take over the command and control channel, as there potentially could be thousands of domains that malware can check for instructions.

DGAs can take the form of apparently random or “gibberish” strings (ex: istgmxdejdnxuyla.ru) when they construct domain names by generating each letter. Alternatively, some DGAs employ whole words as the unit by concatenating words together instead of letters (ex: cityjulydish.net). Many DGAs are time-based, generating a different domain for each time period (hourly, daily, monthly, etc). Others incorporate a seed value as well to make predicting future domains more difficult for defenders.

Adversaries may use DGAs for the purpose of Fallback Channels. When contact is lost with the primary command and control server malware may employ a DGA as a means to reestablishing command and control.

Detection rules4

Rules on DetectionCode tagged with T1568.002.

Sigma2

RuleLevelLog source
Communication To Ngrok Tunneling Service - Linuxhighlinux / network_connection
Communication To Ngrok Tunneling Service Initiatedhighwindows / network_connection

Splunk2

Groups2

Software22

Campaigns0

None recorded.

Procedure examples24

Groups2

Used byProcedure example
GroupAPT41

APT41 has used DGAs to change their C2 servers monthly.

GroupTA551

TA551 has used a DGA to generate URLs from executed macros.

Software22

Used byProcedure example
MalwareAria-body

Aria-body has the ability to use a DGA for C2 communications.

MalwareAstaroth

Astaroth has used a DGA in C2 communications.

ToolAsyncRAT

AsyncRAT use a DGA to generate a C2 domains.

MalwareBazar

Bazar can implement DGA using the current date as a seed variable.

MalwareBONDUPDATER

BONDUPDATER uses a DGA to communicate with command and control servers.

MalwareCCBkdr

CCBkdr can use a DGA for Fallback Channels if communications with the primary command and control server are lost.

MalwareCHOPSTICK

CHOPSTICK can use a DGA for Fallback Channels, domains are generated by concatenating words from lists.

MalwareConficker

Conficker has used a DGA that seeds with the current UTC victim system date to generate domains.

View all 22 software examples

References7

  1. Akamai DGA Mitigation Open source
    Liu, H. and Yuzifovich, Y. (2018, January 9). A Death Match of Domain Generation Algorithms. Retrieved February 18, 2019.
  2. Cisco Umbrella DGA Open source
    Scarfo, A. (2016, October 10). Domain Generation Algorithms – Why so effective?. Retrieved February 18, 2019.
  3. Cybereason Dissecting DGAs Open source
    Sternfeld, U. (2016). Dissecting Domain Generation Algorithms: Eight Real World DGA Variants. Retrieved February 18, 2019.
  4. ESET Sednit 2017 Activity Open source
    ESET. (2017, December 21). Sednit update: How Fancy Bear Spent the Year. Retrieved February 18, 2019.
  5. FireEye POSHSPY April 2017 Open source
    Dunwoody, M.. (2017, April 3). Dissecting One of APT29’s Fileless WMI and PowerShell Backdoors (POSHSPY). Retrieved April 5, 2017.
  6. Talos CCleanup 2017 Open source
    Brumaghin, E. et al. (2017, September 18). CCleanup: A Vast Number of Machines at Risk. Retrieved March 9, 2018.
  7. Unit 42 DGA Feb 2019 Open source
    Unit 42. (2019, February 7). Threat Brief: Understanding Domain Generation Algorithms (DGA). Retrieved February 19, 2019.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.