Inside a TrickBot Variant Using DNS Tunneling for C2
A TrickBot variant has been identified that uses DNS tunneling for command-and-control communications instead of traditional HTTP protocols. The malware maintains persistence through Windows Task Scheduler, creating disguised tasks that execute at startup and repeat every five minutes. Configuration data is stored in NTFS Alternate Data Streams to evade detection. The malware employs multiple obfuscation techniques including encrypted strings, runtime API resolution via hash-based lookups, and dynamically calculated constants. Its modular architecture supports twelve different control commands enabling capabilities such as module downloads, process injection through hollowing and doppelgänging techniques, PowerShell execution, and raw machine code execution. The variant transfers data through specially crafted DNS queries to public DNS servers, encoding command data in malformed domain names and receiving responses embedded within multiple IPv4 addresses, achieving transfer speeds of approximately 30.7 KB/s.
AI Analysis
Technical Summary
This TrickBot variant employs DNS tunneling for C2 communications instead of conventional HTTP protocols, enhancing stealth and evasion. It maintains persistence through Windows Task Scheduler by creating disguised tasks that execute at startup and every five minutes. Configuration data is stored in NTFS Alternate Data Streams, complicating detection. The malware uses encrypted strings, hash-based runtime API resolution, and dynamically calculated constants for obfuscation. Its modular design supports twelve control commands, enabling capabilities such as downloading modules, process injection via hollowing and doppelgänging techniques, PowerShell script execution, and raw machine code execution. Command and control data is transmitted via specially crafted DNS queries to public DNS servers, encoding commands in malformed domain names and receiving responses embedded in multiple IPv4 addresses, with transfer speeds around 30.7 KB/s.
Potential Impact
The malware enables persistent, stealthy control over infected Windows systems, allowing attackers to execute arbitrary code, inject into processes, download additional modules, and run PowerShell scripts. Its use of DNS tunneling for C2 communications can evade traditional network security monitoring focused on HTTP/S traffic. The obfuscation techniques and storage of configuration data in NTFS Alternate Data Streams further complicate detection and forensic analysis. This increases the difficulty of identifying and mitigating infections, potentially allowing prolonged unauthorized access and control.
Mitigation Recommendations
No official patch or remediation is indicated for this malware variant. Mitigation should focus on detecting and blocking suspicious DNS tunneling activity, monitoring for unusual scheduled tasks especially those disguised or running frequently, and scanning for NTFS Alternate Data Streams containing hidden data. Endpoint detection and response (EDR) solutions capable of identifying process injection techniques such as hollowing and doppelgänging, as well as PowerShell abuse, can aid in detection. Network defenses should be configured to monitor and restrict anomalous DNS queries to public DNS servers. Since this is malware, standard patching does not apply; incident response and malware removal procedures are recommended upon detection.
Indicators of Compromise
- domain: westurn.in
- hash: 8d5b3a0512744efc132afa6fc75c64d8
- hash: f7f2f482f3bc6345a44e4a6d647731ae
- hash: 48fd2036b6556c6747197e07f1706bcf58a27518
- hash: 105f652e6b8f31c371f2385877e43b6772aff5d3168d5d4635f8a1fcbb321421
- hash: 33c331ededbf8ee9829895424423ce3fd17e359d2e784fcbce396aacff458cf5
- hash: 3b19a82e1354ac14a3da7c840cbdd0ce50db38432d78e767b36f08e45024c23d
- hash: 6c677eb2b3ffd288083c59a13d7bb712d4754af61a5563873f76c440962346f4
- hash: bf80245ba792992fbfe24abac33f8fd66f24cdeb5f0f21cfdf45a29d107c8d3b
- hash: df527a5c2fbde43816cd02f4cd49eee4bb82fb4a3c7045021360888c7d504c98
Inside a TrickBot Variant Using DNS Tunneling for C2
Description
A TrickBot variant has been identified that uses DNS tunneling for command-and-control communications instead of traditional HTTP protocols. The malware maintains persistence through Windows Task Scheduler, creating disguised tasks that execute at startup and repeat every five minutes. Configuration data is stored in NTFS Alternate Data Streams to evade detection. The malware employs multiple obfuscation techniques including encrypted strings, runtime API resolution via hash-based lookups, and dynamically calculated constants. Its modular architecture supports twelve different control commands enabling capabilities such as module downloads, process injection through hollowing and doppelgänging techniques, PowerShell execution, and raw machine code execution. The variant transfers data through specially crafted DNS queries to public DNS servers, encoding command data in malformed domain names and receiving responses embedded within multiple IPv4 addresses, achieving transfer speeds of approximately 30.7 KB/s.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This TrickBot variant employs DNS tunneling for C2 communications instead of conventional HTTP protocols, enhancing stealth and evasion. It maintains persistence through Windows Task Scheduler by creating disguised tasks that execute at startup and every five minutes. Configuration data is stored in NTFS Alternate Data Streams, complicating detection. The malware uses encrypted strings, hash-based runtime API resolution, and dynamically calculated constants for obfuscation. Its modular design supports twelve control commands, enabling capabilities such as downloading modules, process injection via hollowing and doppelgänging techniques, PowerShell script execution, and raw machine code execution. Command and control data is transmitted via specially crafted DNS queries to public DNS servers, encoding commands in malformed domain names and receiving responses embedded in multiple IPv4 addresses, with transfer speeds around 30.7 KB/s.
Potential Impact
The malware enables persistent, stealthy control over infected Windows systems, allowing attackers to execute arbitrary code, inject into processes, download additional modules, and run PowerShell scripts. Its use of DNS tunneling for C2 communications can evade traditional network security monitoring focused on HTTP/S traffic. The obfuscation techniques and storage of configuration data in NTFS Alternate Data Streams further complicate detection and forensic analysis. This increases the difficulty of identifying and mitigating infections, potentially allowing prolonged unauthorized access and control.
Defensive Guidance
No official patch or remediation is indicated for this malware variant. Mitigation should focus on detecting and blocking suspicious DNS tunneling activity, monitoring for unusual scheduled tasks especially those disguised or running frequently, and scanning for NTFS Alternate Data Streams containing hidden data. Endpoint detection and response (EDR) solutions capable of identifying process injection techniques such as hollowing and doppelgänging, as well as PowerShell abuse, can aid in detection. Network defenses should be configured to monitor and restrict anomalous DNS queries to public DNS servers. Since this is malware, standard patching does not apply; incident response and malware removal procedures are recommended upon detection.
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://www.fortinet.com/blog/threat-research/inside-a-trickbot-variant-using-dns-tunneling-for-c2"]
- Adversary
- null
- Pulse Id
- 6a6120390f602b6ee56739c3
- Threat Score
- null
Indicators of Compromise
Domain
| Value | Description | Copy |
|---|---|---|
domainwesturn.in | — |
Hash
| Value | Description | Copy |
|---|---|---|
hash8d5b3a0512744efc132afa6fc75c64d8 | — | |
hashf7f2f482f3bc6345a44e4a6d647731ae | — | |
hash48fd2036b6556c6747197e07f1706bcf58a27518 | — | |
hash105f652e6b8f31c371f2385877e43b6772aff5d3168d5d4635f8a1fcbb321421 | — | |
hash33c331ededbf8ee9829895424423ce3fd17e359d2e784fcbce396aacff458cf5 | — | |
hash3b19a82e1354ac14a3da7c840cbdd0ce50db38432d78e767b36f08e45024c23d | — | |
hash6c677eb2b3ffd288083c59a13d7bb712d4754af61a5563873f76c440962346f4 | — | |
hashbf80245ba792992fbfe24abac33f8fd66f24cdeb5f0f21cfdf45a29d107c8d3b | — | |
hashdf527a5c2fbde43816cd02f4cd49eee4bb82fb4a3c7045021360888c7d504c98 | — |
Threat ID: 6a61429b9c2644c7f8c94c89
Added to database: 07/22/2026, 22:22:19 UTC
Last enriched: 07/22/2026, 22:42:20 UTC
Last updated: 09/05/2026, 00:41:08 UTC
Views: 156
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.