FORENSIA

ATT&CK · T1568

Dynamic Resolution

Tactics: command-and-control

About

Adversaries may dynamically establish connections to command and control infrastructure to evade common detections and remediations. This may be achieved by using malware that shares a common algorithm with the infrastructure the adversary uses to receive the malware's communications. These calculations can be used to dynamically adjust parameters such as the domain name, IP address, or port number the malware uses for command and control. Adversaries may use dynamic resolution for the purpose of Fallback Channels. When contact is lost with the primary command and control server malware may employ dynamic resolution as a means to reestablishing command and control.

Platforms: ESXi, Linux, macOS, WindowsMITRE ATT&CK ↗

Used by actors

8 known groups

Software

10 malware/tools implement this

NETEAGLERTMBisonalRemcosMazeSUNBURSTGelsemiumTomirisAsyncRATBRICKSTORM

Corpus indicators tagged with this technique

90 indicators in the corpus carry T1568.

IndicatorTypeFamilySevSrc
d425e4583cc6185d41e95c45eda00550045a5d1919b9a012236a4520d009dbd7sha256supply_chain803
9b2e65db653ca8575c9b10eefb9a80c6006404812c2ec212bf5675e3c690233bsha256supply_chain803
eb4e1394d537d8eba509dd5c57e7aaf4c1df57715c7161330012a11f6202af84sha256supply_chain801
34014776d3d3ff11bc4439b02fd7ac0f02a887eb3a052eeafff236e2f6db8ad1sha256supply_chain803
fc17d5b4d64cb61a5aa8fb6bbe1e94885f129b2bf8ee91bca1ccca2b537f6616sha256phishing802
9f1a709310824f9110c6203d861a721ebefba8b204a8657057fe57efb961c850sha256supply_chain801
4b188d179e50e8208a6efec85e273e88d8fc390c836f299ba12915e0840408fdsha256supply_chain801
c6651d6ce31c3a00357e579981d48c0da942b5bbe1582bf3d612a07dc3bc0ff6sha256phishing802
10ddbbae0070267b8d15888b09a3cdb19fa74d861315b71f21c9ace8b9f85c75sha256supply_chain801
4a040770fd81d0db9e04cb8dbd2e07e61969072962bb4e736b7c7001444cc2fasha256phishing802
b0fcd7d9396e70b89e8292f6b80f933607b6fc9a9d3d4dd4ca69b408a2625932sha256phishing802
eccff5c026a01cbe91db45cd0289f8822985aa5183f096d8add69762696d100dsha256phishing802
9e214f38537e69bf51c7fa1ddd35ae495e9cb897231ec010baf9e4f29407ee9asha256supply_chain801
550af477c12192a22f5c9edb9c8081c0a789b3a1a2992a7ecb157cca1c975e10sha256supply_chain801
5e97f7c17bf0466355be0438c7cc3e2e4d125e31368f2fbcb8e1d79cb97f137asha256phishing802
6c774188a54ae07ae896abdf1ea6695cc29f529388888665e05322af3e9178e1sha256phishing802
7e142c8fa614cc39d0453aa648b12209821c6bcbb77ee02094f70161b40d50aesha256phishing802
a8614dfad5fd2a79302a7c4829a0fed6f3a0a46b11beb28f89531cdfa83d32b3sha256phishing802
19ca5fe04ca45a18c5bad9658ff73a8f39fe20ced78f690595f1b4c5a90af324sha256phishing802
589aa1f7252cae74538343cd35443c0a8f58ed280f2016918b6e539a0c09529asha256phishing802
2f2f8f92af86fb962c30c4c1c9d673f9d94886373d0fcf78f8d105c051ffc643sha256phishing802
34d1231a3bf1e13a9b90daecb5c74d52aea94ca54427b203d77e1adc61a5c4f9sha256phishing802
5a00485968679dc0ed6d80b659f48287603864c223e952918d2c2aaddfa2d280sha256phishing802
8ed95259300ca268279867d2999d9c4f6585c6c45308635fc39af87da27546b5sha256phishing802
c6fc06db6a1318152c09200352b40c8fa794f1089988835c1df92174347be8ecsha256phishing802
ec5d4103b3d97885e9575ad045b2ef5467bf9fccf71828e418e6488d78983146sha256phishing802
6e78713b75bd34828d49896176627f7face7aa9036cd874f2e02d9f23a9a9c71sha256supply_chain802
bfaeb987faa6de2b5a5eb63b1233d055215b09b0349a9394f2175fd7cdf385e4sha256supply_chain803
b9993a8ad0518849416798cf29668256ccb96598fc4423501ccab5312812653asha256supply_chain802
082d733db0687dcd768104972b065d4b58cb1e6043688c6c20fa3702337f36absha256supply_chain803

Showing the top 30 by severity of 90.