logo

DGA botnet domains: malicious usage of pseudo random domains

ID: 2bc8cc72-4685-538c-9140-988f6717d084

STIX ID: report--2bc8cc72-4685-538c-9140-988f6717d084

Feed Name: CERT Polska

Date Published: 2015-05-06

Date Updated: 2026-04-19

Author: CERT Polska

...
...

The report surveys multiple sources of pseudo-random domains that can be mistaken for DGA botnet activity, including pseudo-random subdomain DDoS attacks on authoritative DNS, DNS tunneling for covert channels and exfiltration, Tor proxy access to .onion services, malicious IDN/Punycode abuse (including IDN-based DGAs), domain shadowing for exploit kit delivery, and subdomain brute forcing. It explains how these techniques generate high-entropy queries, complicate detection, and increase false positives, and it offers context to guide network defenders in refining DGA detection and prioritizing follow-up analysis.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.