Post

C2

Redirectors

  • Always have a redirector in front of each part of the attack infrastructure
  • Redirects traffic in order to obfuscate the backend systems

Always use domain names

Direct IP access will be blocked Domain names can be loaded to different IPs Domains are not tired to a specific domain provider

Use domains names related to health-care or finance

Azure / AWS cloud providers get allowed and its possible to use their SSL certs

• Direct access to IP addresses is often blocked outbound • Some outbound proxies block domains based on categories – Register domains and categorize them – Categorization sites BrightCloud: https://www.brightcloud.com/tools/url-ip-lookup.php FortiGuard: https://www.fortiguard.com/webfilter McAfee: https://trustedsource.org/ Palo Alto Networks: https://urlfiltering.paloaltonetworks.com/query/ Symantec/BlueCoat WebPulse: http://sitereview.bluecoat.com/ – Purchase categorized domain names that have expired https://www.expireddomains.net/ https://domainhuntergatherer.com/

This post is licensed under CC BY 4.0 by the author.