T1568.003 — DNS Calculation
T1568.003: DNS Calculation
MITRE ATT&CK® Enterprise technique
| Tactics | Command And Control |
| Platforms | ESXi, Linux, macOS, Windows |
| Permissions required | — |
| Version | 1.1 |
| Parent technique | T1568 |
Description
Adversaries may perform calculations on addresses returned in DNS results to determine which port and IP address to use for command and control, rather than relying on a predetermined port number or the actual returned IP address. A IP and/or port number calculation can be used to bypass egress filtering on a C2 channel.(Citation: Meyers Numbered Panda)
One implementation of DNS Calculation is to take the first three octets of an IP address in a DNS response and use those values to calculate the port for command and control traffic.(Citation: Meyers Numbered Panda)(Citation: Moran 2014)(Citation: Rapid7G20Espionage)
Detection
(no detection guidance published)
Data sources
- (none listed)
References
- ATT&CK page: https://attack.mitre.org/techniques/T1568/003
- ATT&CK Enterprise matrix: https://attack.mitre.org/matrices/enterprise/