Skip to content

Hide Navigation Hide TOC

Dynamic DNS resolution: Fast flux (5a99f82a-48c8-5f89-836f-78901e764677)

Dynamic DNS resolution: Fast flux (as obfuscation technique) - Adversaries may use Fast Flux DNS to hide a command and control channel behind an array of rapidly changing IP addresses linked to a single domain resolution. This technique uses a fully qualified domain name with multiple IP addresses assigned to it which are swapped with high frequency using a combination of round robin IP addressing and short Time-To-Live (TTL) for a DNS resource record.

Cluster A Galaxy A Cluster B Galaxy B Level
Dynamic DNS resolution: Fast flux (5a99f82a-48c8-5f89-836f-78901e764677) FIRST DNS Abuse Techniques Matrix Fast Flux DNS - T1568.001 (29ba5a15-3b7b-4732-b817-65ea8f6468e6) Attack Pattern 1
Fast Flux DNS - T1568.001 (29ba5a15-3b7b-4732-b817-65ea8f6468e6) Attack Pattern Dynamic Resolution - T1568 (7bd9c723-2f78-4309-82c5-47cad406572b) Attack Pattern 2