C2
Redirectors
- Always have a redirector in front of each part of the attack infrastructure
- Redirects traffic in order to obfuscate the backend systems
Always use domain names
Direct IP access will be blocked Domain names can be loaded to different IPs Domains are not tired to a specific domain provider
Use domains names related to health-care or finance
Azure / AWS cloud providers get allowed and its possible to use their SSL certs
• Direct access to IP addresses is often blocked outbound • Some outbound proxies block domains based on categories – Register domains and categorize them – Categorization sites BrightCloud: https://www.brightcloud.com/tools/url-ip-lookup.php FortiGuard: https://www.fortiguard.com/webfilter McAfee: https://trustedsource.org/ Palo Alto Networks: https://urlfiltering.paloaltonetworks.com/query/ Symantec/BlueCoat WebPulse: http://sitereview.bluecoat.com/ – Purchase categorized domain names that have expired https://www.expireddomains.net/ https://domainhuntergatherer.com/