216.73.216.233

Suspicious DNS Probing Operation Amplified

· Published 06/06/2024 07:41 · Modified 06/06/2024 08:07

Export JSON

Essential information

Published
06/06/2024 07:41
Modified
06/06/2024 08:07
Tags
2024-06-06 amplification dns open resolvers probing reconnaissance
Related entities
17 observables, 1 intrusion sets (apt), 8 techniques (mitre)

Description

This analysis discusses a large-scale domain name system () operation that targets globally. An actor operating from the China Education and Research Network is conducting these probes, sending queries with encoded IP addresses to identify and measure responses from open resolvers. The probes utilize selective wildcard responses, returning random IP addresses that inadvertently trigger by Palo Alto's Cortex Xpanse product, polluting passive data sources. This hinders analysis of malicious activity and imposes resource burdens on networks worldwide.

External references