BASE64 Over DNS, (Wed, Sep 10th)
ID: 4ca0c8c1-041e-5726-a448-e735ccc56409
STIX ID: report--4ca0c8c1-041e-5726-a448-e735ccc56409
Feed Name: SANS ISC Diary
A researcher demonstrates that although RFC 1035 disallows +, /, and = in DNS labels, direct DNS queries (e.g., nslookup) can still pass these labels through, whereas Windows DNS APIs reject them (error 9560), enabling DNS-based C2 for malware that talks directly to DNS servers. The post advises hunting DNS logs for labels containing these special characters as a detection opportunity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
