Bytes over DNS, (Mon, Oct 27th)

SANS Internet Storm Center, InfoCON: green 2025-10-27

Summary:

I was intrigued when Johannes talked about malware that uses BASE64 over DNS to communicate. Take a DNS request like this: label1.label2.tld. Labels in a request like this can only be composed with letters (not case-sensitive), digits and a hyphen character (-). While BASE64 is encoded with letters (uppercase and lowercase), digits and special characters + and /. And also a special padding character: =.

Link:

https://isc.sans.edu/diary/rss/32420

From feeds:

Intel Hub ยป T01 - SANS Internet Storm Center, InfoCON: green

Tags:

Date tagged:

10/27/2025, 06:09

Date published:

10/27/2025, 05:10