DNS Deep Dive: How Attackers Use DNS to Find C2 Servers, Control Compromised Systems, and Exfiltrate Your Data

10/24/2017 12:00:00 PM [(UTC-05:00) Eastern Time (US & Canada)] - Can't make the live event? Register anyway to receive a link to the recording.

Show/Hide All Time Zones

All Time Zones

Dateline Standard Time-(UTC-12:00) International Date Line West 10/24/2017 4:00:00 AM
UTC-11-(UTC-11:00) Coordinated Universal Time-11 10/24/2017 5:00:00 AM
Aleutian Standard Time-(UTC-10:00) Aleutian Islands 10/24/2017 7:00:00 AM
Hawaiian Standard Time-(UTC-10:00) Hawaii 10/24/2017 6:00:00 AM
Marquesas Standard Time-(UTC-09:30) Marquesas Islands 10/24/2017 6:30:00 AM
Alaskan Standard Time-(UTC-09:00) Alaska 10/24/2017 8:00:00 AM
UTC-09-(UTC-09:00) Coordinated Universal Time-09 10/24/2017 7:00:00 AM
Pacific Standard Time (Mexico)-(UTC-08:00) Baja California 10/24/2017 9:00:00 AM
UTC-08-(UTC-08:00) Coordinated Universal Time-08 10/24/2017 8:00:00 AM
Pacific Standard Time-(UTC-08:00) Pacific Time (US & Canada) 10/24/2017 9:00:00 AM
US Mountain Standard Time-(UTC-07:00) Arizona 10/24/2017 9:00:00 AM
Mountain Standard Time (Mexico)-(UTC-07:00) Chihuahua, La Paz, Mazatlan 10/24/2017 10:00:00 AM
Mountain Standard Time-(UTC-07:00) Mountain Time (US & Canada) 10/24/2017 10:00:00 AM
Central America Standard Time-(UTC-06:00) Central America 10/24/2017 10:00:00 AM
Central Standard Time-(UTC-06:00) Central Time (US & Canada) 10/24/2017 11:00:00 AM
Easter Island Standard Time-(UTC-06:00) Easter Island 10/24/2017 11:00:00 AM
Central Standard Time (Mexico)-(UTC-06:00) Guadalajara, Mexico City, Monterrey 10/24/2017 11:00:00 AM
Canada Central Standard Time-(UTC-06:00) Saskatchewan 10/24/2017 10:00:00 AM
SA Pacific Standard Time-(UTC-05:00) Bogota, Lima, Quito, Rio Branco 10/24/2017 11:00:00 AM
Eastern Standard Time (Mexico)-(UTC-05:00) Chetumal 10/24/2017 11:00:00 AM
Eastern Standard Time-(UTC-05:00) Eastern Time (US & Canada) 10/24/2017 12:00:00 PM
Haiti Standard Time-(UTC-05:00) Haiti 10/24/2017 12:00:00 PM
Cuba Standard Time-(UTC-05:00) Havana 10/24/2017 12:00:00 PM
US Eastern Standard Time-(UTC-05:00) Indiana (East) 10/24/2017 12:00:00 PM
Paraguay Standard Time-(UTC-04:00) Asuncion 10/24/2017 1:00:00 PM
Atlantic Standard Time-(UTC-04:00) Atlantic Time (Canada) 10/24/2017 1:00:00 PM
Venezuela Standard Time-(UTC-04:00) Caracas 10/24/2017 12:00:00 PM
Central Brazilian Standard Time-(UTC-04:00) Cuiaba 10/24/2017 1:00:00 PM
SA Western Standard Time-(UTC-04:00) Georgetown, La Paz, Manaus, San Juan 10/24/2017 12:00:00 PM
Pacific SA Standard Time-(UTC-04:00) Santiago 10/24/2017 1:00:00 PM
Turks And Caicos Standard Time-(UTC-04:00) Turks and Caicos 10/24/2017 12:00:00 PM
Newfoundland Standard Time-(UTC-03:30) Newfoundland 10/24/2017 1:30:00 PM
Tocantins Standard Time-(UTC-03:00) Araguaina 10/24/2017 1:00:00 PM
E. South America Standard Time-(UTC-03:00) Brasilia 10/24/2017 2:00:00 PM
SA Eastern Standard Time-(UTC-03:00) Cayenne, Fortaleza 10/24/2017 1:00:00 PM
Argentina Standard Time-(UTC-03:00) City of Buenos Aires 10/24/2017 1:00:00 PM
Greenland Standard Time-(UTC-03:00) Greenland 10/24/2017 2:00:00 PM
Montevideo Standard Time-(UTC-03:00) Montevideo 10/24/2017 1:00:00 PM
Magallanes Standard Time-(UTC-03:00) Punta Arenas 10/24/2017 1:00:00 PM
Saint Pierre Standard Time-(UTC-03:00) Saint Pierre and Miquelon 10/24/2017 2:00:00 PM
Bahia Standard Time-(UTC-03:00) Salvador 10/24/2017 1:00:00 PM
UTC-02-(UTC-02:00) Coordinated Universal Time-02 10/24/2017 2:00:00 PM
Mid-Atlantic Standard Time-(UTC-02:00) Mid-Atlantic - Old 10/24/2017 2:00:00 PM
Azores Standard Time-(UTC-01:00) Azores 10/24/2017 4:00:00 PM
Cape Verde Standard Time-(UTC-01:00) Cabo Verde Is. 10/24/2017 3:00:00 PM
UTC-(UTC) Coordinated Universal Time 10/24/2017 4:00:00 PM
Morocco Standard Time-(UTC+00:00) Casablanca 10/24/2017 5:00:00 PM
GMT Standard Time-(UTC+00:00) Dublin, Edinburgh, Lisbon, London 10/24/2017 5:00:00 PM
Greenwich Standard Time-(UTC+00:00) Monrovia, Reykjavik 10/24/2017 4:00:00 PM
W. Europe Standard Time-(UTC+01:00) Amsterdam, Berlin, Bern, Rome, Stockholm, Vienna 10/24/2017 6:00:00 PM
Central Europe Standard Time-(UTC+01:00) Belgrade, Bratislava, Budapest, Ljubljana, Prague 10/24/2017 6:00:00 PM
Romance Standard Time-(UTC+01:00) Brussels, Copenhagen, Madrid, Paris 10/24/2017 6:00:00 PM
Central European Standard Time-(UTC+01:00) Sarajevo, Skopje, Warsaw, Zagreb 10/24/2017 6:00:00 PM
W. Central Africa Standard Time-(UTC+01:00) West Central Africa 10/24/2017 5:00:00 PM
Namibia Standard Time-(UTC+01:00) Windhoek 10/24/2017 6:00:00 PM
Jordan Standard Time-(UTC+02:00) Amman 10/24/2017 7:00:00 PM
GTB Standard Time-(UTC+02:00) Athens, Bucharest 10/24/2017 7:00:00 PM
Middle East Standard Time-(UTC+02:00) Beirut 10/24/2017 7:00:00 PM
Egypt Standard Time-(UTC+02:00) Cairo 10/24/2017 6:00:00 PM
E. Europe Standard Time-(UTC+02:00) Chisinau 10/24/2017 7:00:00 PM
Syria Standard Time-(UTC+02:00) Damascus 10/24/2017 7:00:00 PM
West Bank Standard Time-(UTC+02:00) Gaza, Hebron 10/24/2017 7:00:00 PM
South Africa Standard Time-(UTC+02:00) Harare, Pretoria 10/24/2017 6:00:00 PM
FLE Standard Time-(UTC+02:00) Helsinki, Kyiv, Riga, Sofia, Tallinn, Vilnius 10/24/2017 7:00:00 PM
Israel Standard Time-(UTC+02:00) Jerusalem 10/24/2017 7:00:00 PM
Kaliningrad Standard Time-(UTC+02:00) Kaliningrad 10/24/2017 6:00:00 PM
Libya Standard Time-(UTC+02:00) Tripoli 10/24/2017 6:00:00 PM
Arabic Standard Time-(UTC+03:00) Baghdad 10/24/2017 7:00:00 PM
Turkey Standard Time-(UTC+03:00) Istanbul 10/24/2017 7:00:00 PM
Arab Standard Time-(UTC+03:00) Kuwait, Riyadh 10/24/2017 7:00:00 PM
Belarus Standard Time-(UTC+03:00) Minsk 10/24/2017 7:00:00 PM
Russian Standard Time-(UTC+03:00) Moscow, St. Petersburg, Volgograd 10/24/2017 7:00:00 PM
E. Africa Standard Time-(UTC+03:00) Nairobi 10/24/2017 7:00:00 PM
Iran Standard Time-(UTC+03:30) Tehran 10/24/2017 7:30:00 PM
Arabian Standard Time-(UTC+04:00) Abu Dhabi, Muscat 10/24/2017 8:00:00 PM
Astrakhan Standard Time-(UTC+04:00) Astrakhan, Ulyanovsk 10/24/2017 8:00:00 PM
Azerbaijan Standard Time-(UTC+04:00) Baku 10/24/2017 8:00:00 PM
Russia Time Zone 3-(UTC+04:00) Izhevsk, Samara 10/24/2017 8:00:00 PM
Mauritius Standard Time-(UTC+04:00) Port Louis 10/24/2017 8:00:00 PM
Saratov Standard Time-(UTC+04:00) Saratov 10/24/2017 8:00:00 PM
Georgian Standard Time-(UTC+04:00) Tbilisi 10/24/2017 8:00:00 PM
Caucasus Standard Time-(UTC+04:00) Yerevan 10/24/2017 8:00:00 PM
Afghanistan Standard Time-(UTC+04:30) Kabul 10/24/2017 8:30:00 PM
West Asia Standard Time-(UTC+05:00) Ashgabat, Tashkent 10/24/2017 9:00:00 PM
Ekaterinburg Standard Time-(UTC+05:00) Ekaterinburg 10/24/2017 9:00:00 PM
Pakistan Standard Time-(UTC+05:00) Islamabad, Karachi 10/24/2017 9:00:00 PM
India Standard Time-(UTC+05:30) Chennai, Kolkata, Mumbai, New Delhi 10/24/2017 9:30:00 PM
Sri Lanka Standard Time-(UTC+05:30) Sri Jayawardenepura 10/24/2017 9:30:00 PM
Nepal Standard Time-(UTC+05:45) Kathmandu 10/24/2017 9:45:00 PM
Central Asia Standard Time-(UTC+06:00) Astana 10/24/2017 10:00:00 PM
Bangladesh Standard Time-(UTC+06:00) Dhaka 10/24/2017 10:00:00 PM
Omsk Standard Time-(UTC+06:00) Omsk 10/24/2017 10:00:00 PM
Myanmar Standard Time-(UTC+06:30) Yangon (Rangoon) 10/24/2017 10:30:00 PM
SE Asia Standard Time-(UTC+07:00) Bangkok, Hanoi, Jakarta 10/24/2017 11:00:00 PM
Altai Standard Time-(UTC+07:00) Barnaul, Gorno-Altaysk 10/24/2017 11:00:00 PM
W. Mongolia Standard Time-(UTC+07:00) Hovd 10/24/2017 11:00:00 PM
North Asia Standard Time-(UTC+07:00) Krasnoyarsk 10/24/2017 11:00:00 PM
N. Central Asia Standard Time-(UTC+07:00) Novosibirsk 10/24/2017 11:00:00 PM
Tomsk Standard Time-(UTC+07:00) Tomsk 10/24/2017 11:00:00 PM
China Standard Time-(UTC+08:00) Beijing, Chongqing, Hong Kong, Urumqi 10/25/2017 12:00:00 AM
North Asia East Standard Time-(UTC+08:00) Irkutsk 10/25/2017 12:00:00 AM
Singapore Standard Time-(UTC+08:00) Kuala Lumpur, Singapore 10/25/2017 12:00:00 AM
W. Australia Standard Time-(UTC+08:00) Perth 10/25/2017 12:00:00 AM
Taipei Standard Time-(UTC+08:00) Taipei 10/25/2017 12:00:00 AM
Ulaanbaatar Standard Time-(UTC+08:00) Ulaanbaatar 10/25/2017 12:00:00 AM
North Korea Standard Time-(UTC+08:30) Pyongyang 10/25/2017 12:30:00 AM
Aus Central W. Standard Time-(UTC+08:45) Eucla 10/25/2017 12:45:00 AM
Transbaikal Standard Time-(UTC+09:00) Chita 10/25/2017 1:00:00 AM
Tokyo Standard Time-(UTC+09:00) Osaka, Sapporo, Tokyo 10/25/2017 1:00:00 AM
Korea Standard Time-(UTC+09:00) Seoul 10/25/2017 1:00:00 AM
Yakutsk Standard Time-(UTC+09:00) Yakutsk 10/25/2017 1:00:00 AM
Cen. Australia Standard Time-(UTC+09:30) Adelaide 10/25/2017 2:30:00 AM
AUS Central Standard Time-(UTC+09:30) Darwin 10/25/2017 1:30:00 AM
E. Australia Standard Time-(UTC+10:00) Brisbane 10/25/2017 2:00:00 AM
AUS Eastern Standard Time-(UTC+10:00) Canberra, Melbourne, Sydney 10/25/2017 3:00:00 AM
West Pacific Standard Time-(UTC+10:00) Guam, Port Moresby 10/25/2017 2:00:00 AM
Tasmania Standard Time-(UTC+10:00) Hobart 10/25/2017 3:00:00 AM
Vladivostok Standard Time-(UTC+10:00) Vladivostok 10/25/2017 2:00:00 AM
Lord Howe Standard Time-(UTC+10:30) Lord Howe Island 10/25/2017 3:00:00 AM
Bougainville Standard Time-(UTC+11:00) Bougainville Island 10/25/2017 3:00:00 AM
Russia Time Zone 10-(UTC+11:00) Chokurdakh 10/25/2017 3:00:00 AM
Magadan Standard Time-(UTC+11:00) Magadan 10/25/2017 3:00:00 AM
Norfolk Standard Time-(UTC+11:00) Norfolk Island 10/25/2017 3:00:00 AM
Sakhalin Standard Time-(UTC+11:00) Sakhalin 10/25/2017 3:00:00 AM
Central Pacific Standard Time-(UTC+11:00) Solomon Is., New Caledonia 10/25/2017 3:00:00 AM
Russia Time Zone 11-(UTC+12:00) Anadyr, Petropavlovsk-Kamchatsky 10/25/2017 4:00:00 AM
New Zealand Standard Time-(UTC+12:00) Auckland, Wellington 10/25/2017 5:00:00 AM
UTC+12-(UTC+12:00) Coordinated Universal Time+12 10/25/2017 4:00:00 AM
Fiji Standard Time-(UTC+12:00) Fiji 10/25/2017 4:00:00 AM
Kamchatka Standard Time-(UTC+12:00) Petropavlovsk-Kamchatsky - Old 10/25/2017 5:00:00 AM
Chatham Islands Standard Time-(UTC+12:45) Chatham Islands 10/25/2017 5:45:00 AM
UTC+13-(UTC+13:00) Coordinated Universal Time+13 10/25/2017 5:00:00 AM
Tonga Standard Time-(UTC+13:00) Nuku'alofa 10/25/2017 5:00:00 AM
Samoa Standard Time-(UTC+13:00) Samoa 10/25/2017 6:00:00 AM
Line Islands Standard Time-(UTC+14:00) Kiritimati Island 10/25/2017 6:00:00 AM

Webinar Registration

DNS is woven into the fabric of both the Internet and corporate intranets. It works so well that we forget it even exists, until it doesn’t work or is used against us.

The bad guys haven’t forgotten or ignored DNS, and it’s become an increasingly abused protocol. In fact, they are using, leveraging and exploiting DNS more and more to hide their communication right under our nose. In this real training for free event we will use network forensics tools and full packet captures to analyze and compare legitimate, innocent DNS traffic with suspicious DNS packets – all to show you how to recognize malicious DNS when you see it.

First though, I’ll give you a brief but technical introduction to DNS itself. You’ll learn how it’s normally a simply session-less question and answer protocol. I’ll also explain how DNS supports more than just the standard “What is the IP address for this domain name?” question (for example, via TXT queries). And we’ll actually dive deep into samples of this legitimate DNS traffic so you see what it actually looks like on the wire.

Then we’ll transition to the malicious use of DNS and show you more samples of:

  • Domain-generation-algorithm (DGA) queries
  • Command and control (C2) data tunneled through DNS
  • Data exfiltration via tunneled DNS

Attackers often obfuscate date before sending it in DNS packets so we’ll decode some samples of that as well.

Finally, we’ll talk about detection and explain the value to these correlation points

  • Inferring sessions on a session-less protocol
  • Packet quantity
  • Total bytes
  • Comparing domain names to lists like Alexa’s Top 500 sites
  • Least queried domain names

LogRhythm is our sponsor and Rob McGovern (Senior Technical Product Manager, Network Monitoring) and Erika Noerenberg (Senior Malware Analyst) are joining me, and we’ll use their Network Monitor Freemium tool to show you these DNS samples and demonstrate how to analyze DNS traffic for malicious activity. Ahead of our training feel free to download their NetMon Freemium so you can mirror our searches and DNS discovery.

First Name:   
Last Name:   
Work Email:  
Job Title:

Your information will be shared with the sponsor.



Additional Resources