{"id":"T1102.001","name":"Dead Drop Resolver","url":"https://attack.mitre.org/techniques/T1102/001","tactics":["command-and-control"],"platforms":["ESXi","Linux","macOS","Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0058","stix_id":"x-mitre-detection-strategy--70abbe3f-797d-495b-8f76-371408a0f929","name":"Detection Strategy for Web Service: Dead Drop Resolver","url":"https://attack.mitre.org/detectionstrategies/DET0058","analytics":[{"id":"AN0158","stix_id":"x-mitre-analytic--55ec66de-8146-4fd0-a423-0954d6ba33ef","name":"Analytic 0158","description":"Detection of a process or script that accesses a common web service to retrieve content containing obfuscated indicators of a secondary C2 server (dead drop resolver behavior).","url":"https://attack.mitre.org/detectionstrategies/DET0058#AN0158","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Sysmon","channel":"EventCode=3, 22","data_component":"DC0082","data_component_name":"Network Connection Creation","log_source_slug":"wineventlog-sysmon"},{"name":"etw:Microsoft-Windows-NDIS-PacketCapture","channel":"TLS Handshake/Network Flow","data_component":"DC0085","data_component_name":"Network Traffic Content","log_source_slug":"etw-microsoft-windows-ndis-packetcapture"}],"mutable_elements":[{"field":"TargetDomain","description":"FQDN or IP for the hosting site of the dead drop (e.g., pastebin.com, twitter.com)"},{"field":"TimeWindow","description":"Defines how close in time the suspicious network and process behavior must occur"},{"field":"UserContext","description":"Filter by user or system accounts to reduce noise"}],"live":true,"detection_strategies":["DET0058"],"techniques":["T1102.001"]},{"id":"AN0159","stix_id":"x-mitre-analytic--dc4096a9-b89d-4bef-b20d-58cf5e87f6bf","name":"Analytic 0159","description":"Detection of a process or script that accesses a common web service to retrieve content containing obfuscated indicators of a secondary C2 server (dead drop resolver behavior).","url":"https://attack.mitre.org/detectionstrategies/DET0058#AN0159","platforms":["Linux"],"log_source_references":[{"name":"auditd:SYSCALL","channel":"connect","data_component":"DC0082","data_component_name":"Network Connection Creation","log_source_slug":"auditd-syscall"},{"name":"NSM:Flow","channel":"HTTP/TLS Logs","data_component":"DC0085","data_component_name":"Network Traffic Content","log_source_slug":"nsm-flow"}],"mutable_elements":[{"field":"TargetDomain","description":"Dead drop hosting domain (e.g., GitHub, Google Docs)"},{"field":"PayloadEntropyThreshold","description":"Detects high entropy in payloads signaling obfuscation"},{"field":"TimeWindow","description":"Causal proximity between access to resolver and follow-up connections"}],"live":true,"detection_strategies":["DET0058"],"techniques":["T1102.001"]},{"id":"AN0160","stix_id":"x-mitre-analytic--671050c7-7e86-4be7-9ab4-aa9c763fad44","name":"Analytic 0160","description":"Detection of a process or script that accesses a common web service to retrieve content containing obfuscated indicators of a secondary C2 server (dead drop resolver behavior).","url":"https://attack.mitre.org/detectionstrategies/DET0058#AN0160","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"subsystem: com.apple.network","data_component":"DC0085","data_component_name":"Network Traffic Content","log_source_slug":"macos-unifiedlog"},{"name":"macos:osquery","channel":"process_events/socket_events","data_component":"DC0082","data_component_name":"Network Connection Creation","log_source_slug":"macos-osquery"}],"mutable_elements":[{"field":"TargetService","description":"Known services abused for D2 (e.g., iCloud, Dropbox)"},{"field":"UserContext","description":"Useful to isolate rare users accessing web services for C2"},{"field":"TimeWindow","description":"Max time gap between dead drop resolver fetch and follow-on traffic"}],"live":true,"detection_strategies":["DET0058"],"techniques":["T1102.001"]},{"id":"AN0161","stix_id":"x-mitre-analytic--aae03a6c-b308-49cb-bb85-7be4a5c2a4bb","name":"Analytic 0161","description":"Detection of a process or script that accesses a common web service to retrieve content containing obfuscated indicators of a secondary C2 server (dead drop resolver behavior).","url":"https://attack.mitre.org/detectionstrategies/DET0058#AN0161","platforms":["ESXi"],"log_source_references":[{"name":"esxi:vobd","channel":"Network Events","data_component":"DC0078","data_component_name":"Network Traffic Flow","log_source_slug":"esxi-vobd"},{"name":"NSM:Firewall","channel":"Outbound Connections","data_component":"DC0082","data_component_name":"Network Connection Creation","log_source_slug":"nsm-firewall"}],"mutable_elements":[{"field":"DestinationIP","description":"Identifies unusual IP destinations embedded in traffic"},{"field":"Protocol","description":"Used to detect uncommon protocols (e.g., DNS over HTTPS)"},{"field":"TimeWindow","description":"Used to correlate outbound web requests with process execution"}],"live":true,"detection_strategies":["DET0058"],"techniques":["T1102.001"]}],"live":true,"version":"1.0","techniques":["T1102.001"]}],"sigma_rules":[{"id":"297ae038-edc2-4b2e-bb3e-7c5fc94dd5c7","title":"New Connection Initiated To Potential Dead Drop Resolver Domain","author":"Sorina Ionescu, X__Junior (Nextron Systems)","status":"test","level":"high","date":"2022-08-17","modified":"2026-03-29","description":"Detects an executable, which is not an internet browser or known application, initiating network connections to legit popular websites, which were seen to be used as dead drop resolvers in previous attacks.\nIn this context attackers leverage known websites such as \"facebook\", \"youtube\", etc. In order to pass through undetected.\n","references":["https://web.archive.org/web/20220830134315/https://content.fireeye.com/apt-41/rpt-apt41/","https://securelist.com/the-tetrade-brazilian-banking-malware/97779/","https://blog.bushidotoken.net/2021/04/dead-drop-resolvers-espionage-inspired.html","https://github.com/kleiton0x00/RedditC2","https://twitter.com/kleiton0x7e/status/1600567316810551296","https://www.linkedin.com/posts/kleiton-kurti_github-kleiton0x00redditc2-abusing-reddit-activity-7009939662462984192-5DbI/?originalSubdomain=al"],"logsource":{"product":"windows","category":"network_connection"},"tags":["attack.command-and-control","attack.t1102","attack.t1102.001"],"path":"rules/windows/network_connection/net_connection_win_domain_dead_drop_resolvers.yml","techniques":["T1102","T1102.001"],"cves":[]},{"id":"2b1ee7e4-89b6-4739-b7bb-b811b6607e5e","title":"PwnDrp Access","author":"Florian Roth (Nextron Systems)","status":"test","level":"critical","date":"2020-04-15","modified":"2021-11-27","description":"Detects downloads from PwnDrp web servers developed for red team testing and most likely also used for criminal activity","references":["https://breakdev.org/pwndrop/"],"logsource":{"category":"proxy"},"tags":["attack.command-and-control","attack.t1071.001","attack.t1102.001","attack.t1102.003"],"path":"rules/web/proxy_generic/proxy_pwndrop.yml","techniques":["T1071.001","T1102.001","T1102.003"],"cves":[]},{"id":"5468045b-4fcc-4d1a-973c-c9c9578edacb","title":"Raw Paste Service Access","author":"Florian Roth (Nextron Systems)","status":"test","level":"high","date":"2019-12-05","modified":"2023-01-19","description":"Detects direct access to raw pastes in different paste services often used by malware in their second stages to download malicious code in encrypted or encoded form","references":["https://www.virustotal.com/gui/domain/paste.ee/relations"],"logsource":{"category":"proxy"},"tags":["attack.command-and-control","attack.t1071.001","attack.t1102.001","attack.t1102.003"],"path":"rules/web/proxy_generic/proxy_raw_paste_service_access.yml","techniques":["T1071.001","T1102.001","T1102.003"],"cves":[]},{"id":"5c80b618-0dbb-46e6-acbb-03d90bcb6d83","title":"Network Connection Initiated To AzureWebsites.NET By Non-Browser Process","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"medium","date":"2024-06-24","modified":"2024-07-16","description":"Detects an initiated network connection by a non browser process on the system to \"azurewebsites.net\". The latter was often used by threat actors as a malware hosting and exfiltration site.\n","references":["https://www.sentinelone.com/labs/wip26-espionage-threat-actors-abuse-cloud-infrastructure-in-targeted-telco-attacks/","https://symantec-enterprise-blogs.security.com/threat-intelligence/harvester-new-apt-attacks-asia","https://www.ptsecurity.com/ww-en/analytics/pt-esc-threat-intelligence/higaisa-or-winnti-apt-41-backdoors-old-and-new/","https://intezer.com/blog/research/how-we-escaped-docker-in-azure-functions/"],"logsource":{"product":"windows","category":"network_connection"},"tags":["attack.command-and-control","attack.t1102","attack.t1102.001"],"path":"rules/windows/network_connection/net_connection_win_domain_azurewebsites.yml","techniques":["T1102","T1102.001"],"cves":[]}],"kev_cves":[],"_built":"2026-08-24 19:45 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}