Kunai Analysis Report - Malware Sample Abusing Open Recursive DNS for Exfiltration
Kunai Analysis Report - Malware Sample Abusing Open Recursive DNS for Exfiltration
AI Analysis
Technical Summary
The Kunai Analysis Report details a malware sample that leverages open recursive DNS servers to perform data exfiltration. This technique involves sending data through DNS queries to external recursive resolvers, bypassing some traditional network defenses. The report does not specify affected software versions or known active exploitation. The malware's use of DNS for exfiltration aligns with the MITRE ATT&CK pattern T1438 (Exfiltration Over Other Network Medium).
Potential Impact
The primary impact is unauthorized data exfiltration through open recursive DNS servers, which can lead to data leakage from compromised systems. There are no reports of active exploitation or direct system compromise beyond the exfiltration vector. The threat may evade detection by using DNS traffic, which is often allowed through firewalls.
Mitigation Recommendations
No patch is available for this malware sample. Mitigation should focus on restricting access to open recursive DNS servers within the network and monitoring DNS traffic for unusual patterns. Since this is a malware behavior report rather than a vulnerability in software, remediation involves network configuration and monitoring rather than patching. No vendor advisory or official fix is provided.
Indicators of Compromise
- text: AF_INET
- text: TCP
- ip: 8.8.8.8
- port: 443
- text: AF_INET
- text: TCP
- ip: 8.8.4.4
- port: 443
- text: AF_INET
- text: TCP
- ip: 9.9.9.9
- port: 443
- text: AF_INET
- text: TCP
- ip: 45.90.28.160
- port: 443
- text: AF_INET
- text: TCP
- ip: 45.90.30.160
- port: 443
- text: AF_INET
- text: TCP
- ip: 149.112.112.112
- port: 443
- text: AF_INET
- text: TCP
- ip: 9.9.9.11
- port: 443
- text: AF_INET
- text: TCP
- ip: 1.1.1.1
- port: 443
- text: AF_INET
- text: TCP
- ip: 1.0.0.1
- port: 443
- text: AF_INET
- text: TCP
- ip: 149.112.112.11
- port: 443
- domain: service.systemsvcs.com
- datetime: 2025-12-15T10:44:44.964728+00:00
- domain: service.systemsvcs.com
- datetime: 2025-12-15T10:44:44.965450+00:00
- file: bb71e285-75ad-4682-8fe7-903b0742e3a0
- size-in-bytes: 5976064
- float: 6.0021875680609
- hash: 9c44bc9373377831c45dd0ac2661a28e
- hash: b439749a581ac5a29b5c9d91fc092bf4ceaa76a4
- hash: 320a0b5d4900697e125cebb5ff03dee7368f8f087db1c1570b0b62f5a986d759
- hash: a4e6614000d02dcaa8f18bf34f630f7b7c4c6b00bd4251144a961e67b4c5f71b42395910f678287b7b7b88beeb43692bfa9b618426117bdd2b4d8ebf54d6e309
- malware-sample: bb71e285-75ad-4682-8fe7-903b0742e3a0|9c44bc9373377831c45dd0ac2661a28e
- file: activity-graph.svg
- file: kunai.json.gz
Kunai Analysis Report - Malware Sample Abusing Open Recursive DNS for Exfiltration
Description
Kunai Analysis Report - Malware Sample Abusing Open Recursive DNS for Exfiltration
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Kunai Analysis Report details a malware sample that leverages open recursive DNS servers to perform data exfiltration. This technique involves sending data through DNS queries to external recursive resolvers, bypassing some traditional network defenses. The report does not specify affected software versions or known active exploitation. The malware's use of DNS for exfiltration aligns with the MITRE ATT&CK pattern T1438 (Exfiltration Over Other Network Medium).
Potential Impact
The primary impact is unauthorized data exfiltration through open recursive DNS servers, which can lead to data leakage from compromised systems. There are no reports of active exploitation or direct system compromise beyond the exfiltration vector. The threat may evade detection by using DNS traffic, which is often allowed through firewalls.
Defensive Guidance
No patch is available for this malware sample. Mitigation should focus on restricting access to open recursive DNS servers within the network and monitoring DNS traffic for unusual patterns. Since this is a malware behavior report rather than a vulnerability in software, remediation involves network configuration and monitoring rather than patching. No vendor advisory or official fix is provided.
Technical Details
- Uuid
- 9c2ec5f6-afa1-4753-891b-d130b4539648
- Original Timestamp
- 1765803222
Indicators of Compromise
Text
| Value | Description | Copy |
|---|---|---|
textAF_INET | — | |
textTCP | — | |
textAF_INET | — | |
textTCP | — | |
textAF_INET | — | |
textTCP | — | |
textAF_INET | — | |
textTCP | — | |
textAF_INET | — | |
textTCP | — | |
textAF_INET | — | |
textTCP | — | |
textAF_INET | — | |
textTCP | — | |
textAF_INET | — | |
textTCP | — | |
textAF_INET | — | |
textTCP | — | |
textAF_INET | — | |
textTCP | — |
Ip
| Value | Description | Copy |
|---|---|---|
ip8.8.8.8 | — | |
ip8.8.4.4 | — | |
ip9.9.9.9 | — | |
ip45.90.28.160 | — | |
ip45.90.30.160 | — | |
ip149.112.112.112 | — | |
ip9.9.9.11 | — | |
ip1.1.1.1 | — | |
ip1.0.0.1 | — | |
ip149.112.112.11 | — |
Port
| Value | Description | Copy |
|---|---|---|
port443 | — | |
port443 | — | |
port443 | — | |
port443 | — | |
port443 | — | |
port443 | — | |
port443 | — | |
port443 | — | |
port443 | — | |
port443 | — |
Domain
| Value | Description | Copy |
|---|---|---|
domainservice.systemsvcs.com | — | |
domainservice.systemsvcs.com | — |
Datetime
| Value | Description | Copy |
|---|---|---|
datetime2025-12-15T10:44:44.964728+00:00 | — | |
datetime2025-12-15T10:44:44.965450+00:00 | — |
File
| Value | Description | Copy |
|---|---|---|
filebb71e285-75ad-4682-8fe7-903b0742e3a0 | — | |
fileactivity-graph.svg | sample activity graph | |
filekunai.json.gz | kunai logs for sample |
Size in-bytes
| Value | Description | Copy |
|---|---|---|
size-in-bytes5976064 | — |
Float
| Value | Description | Copy |
|---|---|---|
float6.0021875680609 | — |
Hash
| Value | Description | Copy |
|---|---|---|
hash9c44bc9373377831c45dd0ac2661a28e | — | |
hashb439749a581ac5a29b5c9d91fc092bf4ceaa76a4 | — | |
hash320a0b5d4900697e125cebb5ff03dee7368f8f087db1c1570b0b62f5a986d759 | — | |
hasha4e6614000d02dcaa8f18bf34f630f7b7c4c6b00bd4251144a961e67b4c5f71b42395910f678287b7b7b88beeb43692bfa9b618426117bdd2b4d8ebf54d6e309 | — |
Malware sample
| Value | Description | Copy |
|---|---|---|
malware-samplebb71e285-75ad-4682-8fe7-903b0742e3a0|9c44bc9373377831c45dd0ac2661a28e | — |
Threat ID: 69405ab7d9bcdf3f3dfb1be4
Added to database: 12/15/2025, 19:00:07 UTC
Last enriched: 07/30/2026, 15:36:30 UTC
Last updated: 09/09/2026, 15:36:46 UTC
Views: 2013
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.