3 ms·
>In certain sandbox environments traffic is intercepted by replying to all URL lookups with an IP address belonging to the sandbox rather than the real IP addre
by trendoid 9y ago
>In certain sandbox environments traffic is intercepted by replying to all URL lookups with an IP address belonging to the sandbox rather than the real IP address the URL points to, a side effect of this is if an unregistered domain is queried it will respond as it it were registered (which should never happen).
Can someone please explain this? I have no idea what was said there.
- godmodus 9y agoPrivate dns server connected to the vm malware host
- mmalone 9y agoIn a sandbox environment (e.g., in a lab trying to deconstruct malware) they'll have a private DNS infrastructure setup to resolve all domains to some local IP address. That way they can intercept and reverse engineer the command & control traffic. The author of this malware tried to slow down security analysts by trying to resolve a "fake" (unregistered) domain. Probably just pounded on the keyboard and added a .com. The idea is that the domain should not resolve. If it does, it's an indication that they're in a sandbox / lab environment so the malware doesn't trigger. Again, this is an attempt to slow down analysis. Of course this was a stupid tactic because registering the domain and setting up DNS stopped the malware from triggering globally.