logo

Autoencoder Is All You Need: Profiling and Detecting Malicious DNS Traffic

ID: cca0010b-cb18-5531-a2b3-0992f16cd922

STIX ID: report--cca0010b-cb18-5531-a2b3-0992f16cd922

Feed Name: Palo Alto Networks Unit 42

Threat Score
65/100

Date Published: 2024-08-21

Date Updated: 2026-04-28

Author: Zhanhao Chen, Reethika Ramesh and Daiping Liu

...
...

This Unit 42 report describes an autoencoder-based DNS traffic profiling and detection system that converts DNS time-series into fixed-dimensional vectors to identify malicious domains in real time; it presents classification, clustering, and anomaly detection modules and several case studies (C2/Trojan, malicious DDNS, strategically aged domains, typosquatting, and scam sites). The detector identified 170 emerging suspicious domains in May 2024 and the resulting signatures blocked roughly 374,000 malicious DNS requests per day, with listed IOCs including run.sh, biillpi.com, robotatten.com, pococo.cc, comcadt.net, carollewis.network, and a malicious URL path.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.