4 ms·
IPv6 DNS C2 is pretty easy to spot. ISMDoor for instance throws an exclamation point in its "sync" messages with the C2 which gives it away since that's an inva
by piffey 7y ago
IPv6 DNS C2 is pretty easy to spot. ISMDoor for instance throws an exclamation point in its "sync" messages with the C2 which gives it away since that's an invalid character in the spec. Other C2s use IPv6 responses which are encoded which often drops them outside of the global unicast scope or returns an IPv6 address on an unassigned network. IPv6 has such a huge address space that you can check responses with something like ipv6calc and catch anomalies really fast. As far as I've analyzed there isn't a malware family using IPv6 DNS tunneling that actually attempts to be always in an address range that makes sense/valid in its responses or produce a query that couldn't be easily spotted as a blob of base-64/encrypted data. Though given that you get 16 bytes in a AAAA record to work with it would be pretty trivial to make an encoding that uses those 16 bytes to fill with English word combinations that look like valid hostnames then ensure encoded responses are always in say Google's ::/32.
Edit: If you're looking to passively monitor your DNS I'm a big fan of CIRCL's D4 project that's just getting up and running. Check it out! https://www.d4-project.org/ https://www.d4-project.org/