DNS Calculation

T1568.003

Sub-technique of T1568 Dynamic Resolution.View on attack.mitre.org

About this technique

Adversaries may perform calculations on addresses returned in DNS results to determine which port and IP address to use for command and control, rather than relying on a predetermined port number or the actual returned IP address. A IP and/or port number calculation can be used to bypass egress filtering on a C2 channel.

One implementation of DNS Calculation is to take the first three octets of an IP address in a DNS response and use those values to calculate the port for command and control traffic.

Detection rules0

Rules on DetectionCode tagged with T1568.003.

Sigma0

No Sigma rules are mapped to this technique yet.

Splunk0

No Splunk rules are mapped to this technique yet.

Groups1

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples1

Groups1

Used byProcedure example
GroupAPT12

APT12 has used multiple variants of DNS Calculation including multiplying the first two octets of an IP address and adding the third octet to that value in order to get a resulting command and control port.

References3

  1. Meyers Numbered Panda Open source
    Meyers, A. (2013, March 29). Whois Numbered Panda. Retrieved January 14, 2016.
  2. Moran 2014 Open source
    Moran, N., Oppenheim, M., Engle, S., & Wartell, R.. (2014, September 3). Darwin’s Favorite APT Group [Blog]. Retrieved November 12, 2014.
  3. Rapid7G20Espionage Open source
    Rapid7. (2013, August 26). Upcoming G20 Summit Fuels Espionage Operations. Retrieved March 6, 2017.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.