{"id":4506,"date":"2024-07-17T11:53:39","date_gmt":"2024-07-17T16:53:39","guid":{"rendered":"https:\/\/blogs.infoblox.com\/?p=10346"},"modified":"2024-07-17T11:53:39","modified_gmt":"2024-07-17T16:53:39","slug":"rdgas-the-next-chapter-in-domain-generation-algorithms","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2024\/07\/17\/rdgas-the-next-chapter-in-domain-generation-algorithms\/","title":{"rendered":"RDGAs: The Next Chapter in Domain Generation Algorithms"},"content":{"rendered":"<h3><strong>Author: James Barnett<\/strong><\/h3>\n<p>This trailblazing report explores a burgeoning technique that threat actors are using to covertly transform the DNS threat landscape with millions of new domains. You\u2019ll learn how traditional malware-based domain generation algorithms (DGAs) have evolved into registered DGAs (RDGAs) that can be used for malware, phishing, spam, scams, gambling, traffic distribution systems (TDS), virtual private networks (VPNs), and more. We\u2019ll unveil a new RDGA threat actor named Revolver Rabbit who\u2019s associated with XLoader malware. We\u2019ll also reveal how the notorious Hancitor malware used an RDGA to generate its C2 domains for years while most of the security industry remained oblivious to their methods. This blog discusses some of the highlights from our full research paper, which is available <a href=\"https:\/\/insights.infoblox.com\/resources-research-report\/infoblox-research-report-registered-dgas-the-prolific-new-menace-no-one-is-talking-about\" rel=\"noopener\" target=\"_blank\">here<\/a>.<\/p>\n<p>For nearly two decades, threat actors have used domain generation algorithms (DGAs) to distribute malware. In recent years, threat actors have been employing a technique we call registered domain generation algorithms (RDGAs), in which the actor uses an algorithm to register many domain names at one time. RDGAs are considerably harder to detect and defend against than traditional DGAs, and despite their prevalence on the internet, they have been woefully underreported by the security community. We originally described RDGAs in October 2023 and have published on the topic multiple times since then.<\/p>\n<h3>What Exactly Are RDGAs?<\/h3>\n<p>RDGAs are a programmatic mechanism that allows threat actors to create many domain names at once, or over time, to register for use in their criminal infrastructure. These differ significantly from the traditional domain generation algorithms (DGAs) that have long been associated with malware. In an RDGA, the algorithm is a secret kept by the threat actor, and they register all the domain names. In a traditional DGA, the malware contains an algorithm that can be discovered and most of the domain names will not be registered.<\/p>\n<table>\n<tbody readability=\"1.5\">\n<tr>\n<td>\n<img data-recalc-dims=\"1\" fetchpriority=\"high\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/rdgas-the-next-chapter-in-domain-generation-algorithms.jpg?resize=640%2C300&#038;ssl=1\" alt width=\"640\" height=\"300\" class=\"aligncenter size-full wp-image-10358\" srcset=\"https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/rdgas-the-next-chapter-in-domain-generation-algorithms.jpg 750w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/rdgas-the-next-chapter-in-domain-generation-algorithms-2.jpg 300w\" sizes=\"(max-width: 750px) 100vw, 750px\"> <\/td>\n<\/tr>\n<tr readability=\"3\">\n<td>Figure 1. Illustration of the difference in domain registration behaviors of traditional DGAs and registered DGAs.<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>While traditional DGAs are used exclusively for connection to a malware controller, RDGAs can be used for a wide range of purposes including malware, phishing, spam, scams, gambling, traffic distribution systems (TDS), virtual private networks (VPNs), or essentially any activity that benefits from having large numbers of domain names. We\u2019ll cover a couple interesting cases of RDGA usage for this blog, but there are far more examples in our full research paper.<\/p>\n<p><strong>Threat actors, criminal enterprises, and legitimate businesses all use RDGAs.<\/strong> Registrars like Namecheap even offer tools to generate variants of a chosen domain name, and these tools can be leveraged by anyone \u2014 legitimate customers or threat actors. <\/p>\n<table>\n<tbody readability=\"1.5\">\n<tr>\n<td>\n<img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/rdgas-the-next-chapter-in-domain-generation-algorithms-1.jpg?resize=640%2C516&#038;ssl=1\" alt width=\"640\" height=\"516\" class=\"aligncenter size-full wp-image-10359\" srcset=\"https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/rdgas-the-next-chapter-in-domain-generation-algorithms-1.jpg 2128w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/rdgas-the-next-chapter-in-domain-generation-algorithms-3.jpg 300w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/rdgas-the-next-chapter-in-domain-generation-algorithms-4.jpg 1024w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/rdgas-the-next-chapter-in-domain-generation-algorithms-5.jpg 768w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/rdgas-the-next-chapter-in-domain-generation-algorithms-6.jpg 1536w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/rdgas-the-next-chapter-in-domain-generation-algorithms-7.jpg 2048w\" sizes=\"(max-width: 2128px) 100vw, 2128px\"> <\/td>\n<\/tr>\n<tr readability=\"3\">\n<td>Figure 2. Namecheap\u2019s \u201cBeast Mode\u201d is a fully-featured graphical RDGA builder available to all customers<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h3>Why Call It RDGA?<\/h3>\n<p><strong>We coined this phrase and acronym because the term \u201cDGA\u201d has become broadly overused<\/strong> in the years since the concept was introduced, effectively serving as an umbrella term for any domain that is (or appears to be) algorithmically generated. In the same way that the concept of dictionary DGAs (DDGAs) was introduced to distinguish algorithms that generate domains using real words rather than random characters, <strong>we\u2019re using the concept of RDGAs to distinguish algorithms that threat actors use to privately register large numbers of domains from algorithms embedded in publicly-available malware<\/strong> to make their C2 communications more difficult to disrupt. <\/p>\n<h3>What Do RDGAs Look Like?<\/h3>\n<p><strong>Just like traditional DGAs, RDGAs come in all shapes and sizes.<\/strong> Some look like prototypical DGAs with seemingly random characters and a high degree of entropy, as <strong>Tables 1 and 2<\/strong> show: <\/p>\n<table>\n<tbody readability=\"2.5\">\n<tr readability=\"3\">\n<td class=\"code-format\">6rnd9mitqt1rz82[.]top<br \/>7r7suw52ls00i20[.]top<br \/>9w9ohb5vky5p3dz[.]top<br \/>bjbntaxmh09r09e[.]top<br \/>qcj4pirltkpqrcu[.]top\n<\/td>\n<\/tr>\n<tr readability=\"2\">\n<td>Table 1. Prototypical DGA used by a SocGholish\/TA569 affiliate <\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<table>\n<tbody readability=\"2.5\">\n<tr readability=\"3\">\n<td class=\"code-format\">h87e1mbm0u5f85[.]xyz<br \/>n8j1nau3os4otr[.]xyz<br \/>xnnxr1jquyupjc[.]xyz<br \/>xqajkr8fbrdryp0[.]xyz<br \/>xryqcgcb2upb28k[.]xyz\n<\/td>\n<\/tr>\n<tr readability=\"2\">\n<td>Table 2. RDGA for a weight loss pill scam <\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p><strong>Table 3<\/strong> shows that other RDGAs use nonsensical combinations of dictionary words like a traditional DDGA: <\/p>\n<table>\n<tbody readability=\"2.5\">\n<tr readability=\"3\">\n<td class=\"code-format\">arriveplanetsnow[.]buzz<br \/>coatthinkverb[.]buzz<br \/>debtgenepub[.]live<br \/>poemtrainsurprise[.]top<br \/>quarterneighbourforward[.]xyz\n<\/td>\n<\/tr>\n<tr readability=\"2\">\n<td>Table 3. VexTrio Viper RDGA <\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>Some RDGAs use a limited set of dictionary words in a more structured format in order to fit a theme, like this set of domains in <strong>Table 4<\/strong>, whose names correspond to various regional jails: <\/p>\n<table>\n<tbody readability=\"2.5\">\n<tr readability=\"3\">\n<td class=\"code-format\">castrocountyjail[.]org<br \/>killeencityjail[.]org<br \/>lasalleparishjail[.]org<br \/>miamidadecountyjail[.]org<br \/>northcentralregionaljail[.]org\n<\/td>\n<\/tr>\n<tr readability=\"2\">\n<td>Table 4. RDGA with a regional jail theme<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>Still other RDGAs generate variations of a single domain name by inserting, shifting, or deleting characters from the base domain name (<strong>see Table 5<\/strong>). More often than not, the character changes in these variant domain names follow some sort of structure so that the generated domains are still somewhat intelligible and similar to the base domain, like the following set of RDGA domains for a Russian diploma mill: <\/p>\n<table>\n<tbody readability=\"3\">\n<tr readability=\"4\">\n<td class=\"code-format\">arenadiploma[.]com<br \/>area-diploman24[.]com<br \/>area-diplomans24[.]com<br \/>area-diploms24[.]com<br \/>area-diplomy24[.]com<br \/>areas-diplom[.]com<br \/>areas-diplom24[.]com<br \/>areas-diplomy24[.]com<br \/>arena-diplomsy24[.]com<br \/>arena-diplomy24[.]com\n<\/td>\n<\/tr>\n<tr readability=\"2\">\n<td>Table 5. RDGA for a Russian diploma mill <\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p><strong>Clearly, RDGAs come in a variety of forms and their domains may not be immediately recognizable when viewed in isolation. This is why researching and identifying RDGAs requires access to large-scale DNS data and enough DNS expertise to properly analyze it. <\/strong><\/p>\n<h3>Hancitor: Using RDGAs Before It Was Cool<\/h3>\n<p><strong>If you\u2019re reading this blog, there\u2019s a good chance you\u2019ve heard of Hancitor malware.<\/strong> Although it hasn\u2019t been active recently, it was an incredibly popular malware loader with prolific malspam campaigns that regularly delivered booby-trapped documents to unsuspecting victims for the better part of a decade. <strong>What most people don\u2019t realize about Hancitor is that they were using an RDGA to generate all of their C2 domains,<\/strong> which meant they could be detected in DNS and blocked before their campaigns even became active. <\/p>\n<p>Looking at the C2 domains embedded in a single sample of Hancitor (<strong>Table 6<\/strong>), the pattern isn\u2019t obvious. <\/p>\n<table>\n<tbody readability=\"2\">\n<tr readability=\"2\">\n<td class=\"code-format\">chopprousite[.]ru<br \/>patiennerrhe[.]com<br \/>thougolograrly[.]ru\n<\/td>\n<\/tr>\n<tr readability=\"2\">\n<td>Table 6. Hancitor C2 domains from one sample<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>The C2s are nonsensical and look like DGA domains, but they don\u2019t contain numbers or lots of high-entropy strings like a randomized traditional DGA. Some of them appear to contain English words like a DDGA, but they\u2019re not exclusively made of intelligible words like a standard DDGA. While all of these observations are true, and they may even help identify Hancitor domains during manual threat hunting, they aren\u2019t enough to fully characterize the algorithm and build an automated detector for it. <\/p>\n<p>If we look at a larger list of Hancitor C2 domains taken from multiple samples, however, the underlying patterns of its RDGA become more apparent (<strong>Table 7<\/strong>): <\/p>\n<table>\n<tbody readability=\"3\">\n<tr readability=\"4\">\n<td class=\"code-format\">dintretonid[.]com<br \/>dintretrewor[.]com<br \/>dintrolletone[.]com<br \/>dintromparsup[.]com<br \/>direnrolpar[.]ru<br \/>hadhecrecled[.]com<br \/>hadrecrolof[.]ru<br \/>hadsparmirat[.]com<br \/>hanparolhar[.]com<br \/>rofromandfor[.]ru<br \/>rowrorofrat[.]com\n<\/td>\n<\/tr>\n<tr readability=\"2\">\n<td>Table 7. Selected Hancitor C2 domains taken from various samples<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>From this set of domains we can see that <strong>Hancitor\u2019s RDGA has a tendency to repeat specific sequences of characters,<\/strong> such as \u201cdi\u201d and \u201cha.\u201d We could infer that the reason its domains appear random while having fairly low entropy is that <strong>the character sequences it uses are common in English words.<\/strong> <\/p>\n<p><strong>Infoblox recognized these peculiarities of the Hancitor RDGA in 2018<\/strong> and created a statistical model to identify domains that follow Hancitor\u2019s RDGA pattern. By combining this with our knowledge of Hancitor\u2019s registration patterns and DNS signatures, we created a predictive analytic to identify and block Hancitor C2 domains before they were used in active campaigns. <\/p>\n<h3>Meet Revolver Rabbit<\/h3>\n<p><strong>One of the most prolific unclassified RDGA actors we\u2019ve found, which we\u2019ve named Revolver Rabbit, has registered over 500k domains on the .bond TLD alone. <\/strong>Their RDGA pattern is unique but also highly variable, which makes some of their domains difficult to identify without additional DNS context. <\/p>\n<p>The most common RDGA pattern this actor uses is a series of one or more dictionary words followed by a five-digit number, with each word or number separated by a dash (see <strong>Table 8<\/strong>). When multiple dictionary words are used, they usually form coherent phrases rather than appearing completely random. <\/p>\n<table>\n<tbody readability=\"2.5\">\n<tr readability=\"3\">\n<td class=\"code-format\">assisted-living-11607[.]bond<br \/>online-jobs-42681[.]bond<br \/>perfumes-76753[.]bond<br \/>security-surveillance-cameras-42345[.]bond<br \/>yoga-classes-35904[.]bond\n<\/td>\n<\/tr>\n<tr readability=\"2\">\n<td>Table 8. Examples of most common RDGA pattern for Revolver Rabbit<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>Sometimes the actor uses ISO 3166-1 country codes, full country names, or numbers corresponding to years instead of dictionary words (see <strong>Tables 9A and 9B<\/strong>). They tend to use these elements as prefixes or suffixes, and the domains that use them generally omit the standard five-digit numerical suffix regardless of whether the element is being used as a prefix or suffix.<\/p>\n<table>\n<tbody readability=\"7.5\">\n<tr readability=\"9\">\n<td class=\"code-format\">ai-courses-12139[.]bond<br \/>ai-courses-13069[.]bond<br \/>ai-courses-14729[.]bond<br \/>ai-courses-16651[.]bond<br \/>ai-courses-17621[.]bond<br \/>app-software-development-training-52686[.]bond<br \/>app-software-development-training-54449[.]bond<br \/>app-software-development-training-55554[.]bond<br \/>app-software-development-training-57549[.]bond<\/td>\n<td class=\"code-format\">ai-courses-2024-pe[.]bond<br \/>ai-courses-2024-pk[.]bond<br \/>ai-courses-2024sa[.]bond<br \/>ai-courses2023-in[.]bond<br \/>ai-courses2023in[.]bond<br \/>ai-courses2024in[.]bond<br \/>app-software-development-italy[.]bond<br \/>app-software-development-training-usa[.]bond<\/td>\n<\/tr>\n<tr readability=\"6\">\n<td>Table 9A. Domains using the basic pattern<\/td>\n<td>Table 9B. Domains using country codes, country names, and year numbers <\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p><strong>Tables 10A and 10B<\/strong> show how the actor occasionally replaces their standard five-digit suffix with one or two digits followed by a single character.<\/p>\n<table>\n<tbody readability=\"5\">\n<tr readability=\"6\">\n<td class=\"code-format\">online-degrees-16099[.]bond<br \/>portable-air-conditioner-12322[.]bond<br \/>river-cruises-13890[.]bond<br \/>roofing-services-10175[.]bond<br \/>travel-insurance-43494[.]bond<\/td>\n<td class=\"code-format\">usa-online-degree-29o[.]bond<br \/>bra-portable-air-conditioner-9o[.]bond<br \/>uk-river-cruises-8n[.]bond<br \/>rsa-roofing-services-8n[.]bond<br \/>col-travel-insurance-3n[.]bond<\/td>\n<\/tr>\n<tr readability=\"4\">\n<td>Table 10A. Domains using the basic pattern<\/td>\n<td>Table 10B. Domains using 1-2 digits and a single letter<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p><strong>Tables 11A and 11B<\/strong> show that in some cases the actor uses two dashes in a row rather than the single dash they normally use. <\/p>\n<table readability=\"2\">\n<tbody readability=\"7\">\n<tr readability=\"6\">\n<td class=\"code-format\">welding-machines-10120[.]bond<br \/>welding-machines-35450[.]bond<br \/>welding-machines-56397[.]bond<br \/>welding-machines-76813[.]bond<br \/>welding-machines-99146[.]bond<\/td>\n<td class=\"code-format\">welding-machines\u2212\u221211015[.]bond<br \/>welding-machines\u2212\u221231109[.]bond<br \/>welding-machines\u2212\u221256717[.]bond<br \/>welding-machines\u2212\u221275378[.]bond<br \/>welding-machines\u2212\u221297422[.]bond<\/td>\n<\/tr>\n<td>Table 11A. Domains using the basic pattern<\/td>\n<td>Table 11B. Domains using two dashes instead of one<\/td>\n<\/tbody>\n<\/table>\n<p>The amount of variation in this actor\u2019s RDGA highlights the need for advanced DNS expertise and visibility when implementing automated RDGA detection. While many of their domains follow a basic pattern that could be detected with regular expressions or other string-based matching, they also have a number of domains that use different patterns. The similarities between this actor\u2019s patterns may be obvious to a human observer, but for an automated detector to accurately group these somewhat disparate domains together, additional DNS context is required. <\/p>\n<p>We initially planned to publish Revolver Rabbit as an example of an interesting but unclassified RDGA actor, but during our research we found their domains being used as both active C2s and decoy domains in XLoader (a.k.a. Formbook) malware samples.i, ii This discovery further underscores the importance of RDGA detection and analysis, as without it actors like Revolver Rabbit can operate undetected despite their massive network footprints.<\/p>\n<h3>Unknown RDGAs Are on the Rise<\/h3>\n<p>For every RDGA like <a href=\"https:\/\/www.infoblox.com\/threat-intel\/threat-actors\/vextrio\/\" rel=\"noopener\" target=\"_blank\">VexTrio Viper<\/a> that we\u2019ve extensively researched and published on, we\u2019ve detected thousands of other RDGAs whose purposes remain largely unknown. Given the wide array of malicious activity we\u2019ve observed from the RDGAs we know, the sheer quantity of unknown RDGAs is a matter of significant interest and concern. The patterns and DNS signatures that tie RDGA domains together can only be identified by large-scale analysis, so unknown RDGA domains are able to function largely unimpeded on networks that aren\u2019t protected by advanced DNS analytics like ours. <\/p>\n<p>In the six-month period from October 17, 2023 to April 17, 2024, our RDGA detectors identified over 2M unique RDGA domains, or an average of over 11k new RDGA domains per day (<strong>see Figure 3<\/strong>). <\/p>\n<table>\n<tbody readability=\"2\">\n<tr>\n<td>\n<img data-recalc-dims=\"1\" loading=\"lazy\" loading=\"lazy\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/rdgas-the-next-chapter-in-domain-generation-algorithms.png?resize=640%2C172&#038;ssl=1\" alt width=\"640\" height=\"172\" class=\"aligncenter size-full wp-image-10357\" srcset=\"https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/rdgas-the-next-chapter-in-domain-generation-algorithms.png 2976w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/rdgas-the-next-chapter-in-domain-generation-algorithms-2.png 300w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/rdgas-the-next-chapter-in-domain-generation-algorithms-3.png 1024w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/rdgas-the-next-chapter-in-domain-generation-algorithms-4.png 768w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/rdgas-the-next-chapter-in-domain-generation-algorithms-5.png 1536w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/rdgas-the-next-chapter-in-domain-generation-algorithms-6.png 2048w\" sizes=\"auto, (max-width: 2976px) 100vw, 2976px\">\n<\/td>\n<\/tr>\n<tr readability=\"4\">\n<td>Figure 3. Daily RDGA domain detection counts from October 17, 2023 to April 17, 2024 <\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>Our detectors initially clustered these domains into roughly 117k unique actor groups, which we later reduced to roughly 52k actor groups using a combination of automated refinements and manual analysis (<strong>see Figure 4<\/strong>). <\/p>\n<table>\n<tbody readability=\"2\">\n<tr>\n<td>\n<img data-recalc-dims=\"1\" loading=\"lazy\" loading=\"lazy\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/rdgas-the-next-chapter-in-domain-generation-algorithms-1.png?resize=640%2C172&#038;ssl=1\" alt width=\"640\" height=\"172\" class=\"aligncenter size-full wp-image-10356\" srcset=\"https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/rdgas-the-next-chapter-in-domain-generation-algorithms-1.png 2976w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/rdgas-the-next-chapter-in-domain-generation-algorithms-7.png 300w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/rdgas-the-next-chapter-in-domain-generation-algorithms-8.png 1024w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/rdgas-the-next-chapter-in-domain-generation-algorithms-9.png 768w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/rdgas-the-next-chapter-in-domain-generation-algorithms-10.png 1536w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/rdgas-the-next-chapter-in-domain-generation-algorithms-11.png 2048w\" sizes=\"auto, (max-width: 2976px) 100vw, 2976px\">\n<\/td>\n<\/tr>\n<tr readability=\"4\">\n<td>Figure 4. Daily RDGA actor cluster counts from October 17, 2023 to April 17, 2024 <\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>The key takeaway from these statistics is that <strong>there are so many RDGA domains being registered that the security industry will never be able to research them all.<\/strong> It can take months for human researchers to understand a threat to the point that they can publish on it, but <strong>it only takes a day for RDGA actors to register tens of thousands of new domains for researchers to investigate.<\/strong> This is why <strong>automated detection is the only viable defense against RDGA threats.<\/strong> <\/p>\n<p>Learn more about RDGAs in our full research report <a href=\"https:\/\/insights.infoblox.com\/resources-research-report\/infoblox-research-report-registered-dgas-the-prolific-new-menace-no-one-is-talking-about\" rel=\"noopener\" target=\"_blank\">here<\/a>.<\/p>\n<h3>Conclusion<\/h3>\n<p><strong>RDGA domains are associated with a panoply of dubious activities that most organizations don\u2019t want on their networks.<\/strong> But despite being used to register millions of new domains, RDGAs have gone almost entirely unrecognized by the security industry. This lack of reporting is likely due to the fact that RDGA detection requires both significant DNS expertise and access to large volumes of DNS data. <strong>Organizations should be aware of the threat that RDGAs pose to their networks, and should implement security solutions that include automated RDGA detection. <\/strong><\/p>\n<h3>Indicators of Activity<\/h3>\n<p>Below is a sample of indicators used by the RDGA threat actors we mentioned in this blog. Indicators are also available in our GitHub repository\u202f<a href=\"https:\/\/github.com\/infobloxopen\/threat-intelligence\/tree\/main\/indicators\" rel=\"noopener\" target=\"_blank\">here<\/a>.<\/p>\n<table>\n<thead>\n<tr>\n<th>Indicator<\/th>\n<th>Type of Indicator <\/th>\n<\/tr>\n<\/thead>\n<tbody readability=\"21\">\n<tr readability=\"5\">\n<td class=\"code-format\">6rnd9mitqt1rz82[.]top<br \/>7r7suw52ls00i20[.]top 9w9ohb5vky5p3dz[.]top <br \/>bjbntaxmh09r09e[.]top <br \/>qcj4pirltkpqrcu[.]top<\/td>\n<td>SocGholish\/TA569 affiliate traditional DGA domains<\/td>\n<\/tr>\n<tr readability=\"5\">\n<td class=\"code-format\">h87e1mbm0u5f85[.]xyz <br \/>n8j1nau3os4otr[.]xyz <br \/>xnnxr1jquyupjc[.]xyz <br \/>xqajkr8fbrdryp0[.]xyz <br \/>xryqcgcb2upb28k[.]xyz <\/td>\n<td>Weight loss pill scam RDGA domains <\/td>\n<\/tr>\n<tr readability=\"5\">\n<td class=\"code-format\">arriveplanetsnow[.]buzz <br \/>coatthinkverb[.]buzz <br \/>debtgenepub[.]live <br \/>poemtrainsurprise[.]top <br \/>quarterneighbourforward[.]xyz<\/td>\n<td>VexTrio Viper RDGA domains<\/td>\n<\/tr>\n<tr readability=\"5\">\n<td class=\"code-format\">castrocountyjail[.]org <br \/>killeencityjail[.]org <br \/>lasalleparishjail[.]org <br \/>miamidadecountyjail[.]org <br \/>northcentralregionaljail[.]org<\/td>\n<td>Regional jail RDGA domains<\/td>\n<\/tr>\n<tr readability=\"6\">\n<td class=\"code-format\">arenadiploma[.]com <br \/>area-diploman24[.]com <br \/>area-diplomans24[.]com <br \/>area-diploms24[.]com <br \/>area-diplomy24[.]com <br \/>areas-diplom[.]com <br \/>areas-diplom24[.]com <br \/>areas-diplomy24[.]com <br \/>arena-diplomsy24[.]com <br \/>arena-diplomy24[.]com <\/td>\n<td>Russian diploma scam RDGA domains <\/td>\n<\/tr>\n<tr readability=\"4\">\n<td class=\"code-format\">chopprousite[.]ru <br \/>patiennerrhe[.]com <br \/>thougolograrly[.]ru <br \/>dintretonid[.]com <br \/>dintretrewor[.]com <br \/>dintrolletone[.]com <br \/>dintromparsup[.]com <br \/>direnrolpar[.]ru <br \/>hadhecrecled[.]com <br \/>hadrecrolof[.]ru <br \/>hadsparmirat[.]com <br \/>hanparolhar[.]com <br \/>rofromandfor[.]ru <br \/>rowrorofrat[.]com <\/td>\n<td>Hancitor C2 RDGA domains<\/td>\n<\/tr>\n<tr readability=\"9.5\">\n<td class=\"code-format\" readability=\"8\">assisted-living-11607[.]bond <br \/>online-jobs-42681[.]bond <br \/>perfumes-76753[.]bond <br \/>security-surveillance-cameras-42345[.]bond <br \/>yoga-classes-35904[.]bond <br \/>ai-courses-12139[.]bond <br \/>ai-courses-13069[.]bond <br \/>ai-courses-14729[.]bond <br \/>ai-courses-16651[.]bond <br \/>ai-courses-17621[.]bond <br \/>app-software-development-training-52686[.]bond <br \/>app-software-development-training-54449[.]bond <br \/>app-software-development-training-55554[.]bond <br \/>app-software-development-training-57549[.]bond <br \/>ai-courses-2024-pe[.]bond <br \/>ai-courses-2024-pk[.]bond <br \/>ai-courses-2024sa[.]bond <br \/>ai-courses2023-in[.]bond <br \/>ai-courses2023in[.]bond <br \/>ai-courses2024in[.]bond <br \/>app-software-development-italy[.]bond <br \/>app-software-development-training-usa[.]bond<\/p>\n<p>online-degrees-16099[.]bond <br \/>portable-air-conditioner-12322[.]bond <br \/>river-cruises-13890[.]bond <br \/>roofing-services-10175[.]bond <br \/>travel-insurance-43494[.]bond <br \/>usa-online-degree-29o[.]bond <br \/>bra-portable-air-conditioner-9o[.]bond <br \/>uk-river-cruises-8n[.]bond <br \/>rsa-roofing-services-8n[.]bond <br \/>col-travel-insurance-3n[.]bond <br \/>welding-machines-10120[.]bond <br \/>welding-machines-35450[.]bond <br \/>welding-machines-56397[.]bond <br \/>welding-machines-76813[.]bond <br \/>welding-machines-99146[.]bond <br \/>welding-machines\u2212\u221211015[.]bond <br \/>welding-machines\u2212\u221231109[.]bond <br \/>welding-machines\u2212\u221256717[.]bond <br \/>welding-machines\u2212\u221275378[.]bond <br \/>welding-machines\u2212\u221297422[.]bond <\/p>\n<\/td>\n<td>Revolver Rabbit RDGA domains <\/td>\n<\/tr>\n<tr readability=\"5\">\n<td class=\"code-format\">tires-book-robust[.]bond <br \/>laser-skin-treatment-19799[.]bond <br \/>pool-repair-35063[.]bond <br \/>apartments-for-rent-72254[.]bond <br \/>hemophilia-treatment-41433[.]bond <\/td>\n<td>Revolver Rabbit RDGA domains used as C2 \/ decoy domains for XLoader malware <\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<style>\n.green {color: #00bd4d;}\n.code-format { font-family: 'Courier New';\n}\ntable{\nfont-size: 16px;\nword-break: keep-all;\n}\n<\/style>\n<p> <a href=\"https:\/\/blogs.infoblox.com\/threat-intelligence\/rdgas-the-next-chapter-in-domain-generation-algorithms\/\">Infoblox Original<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Author: James Barnett This trailblazing report explores a burgeoning technique<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[78,495,30,790,2340,1945,168,75,60,995,2339],"tags":[86,502,38,800,2342,1950,169,83,67,998,2341],"class_list":["post-4506","post","type-post","status-publish","format-standard","hentry","category-cybersecurity","category-dga","category-dns","category-domain-name-system","category-formbook","category-infoblox-threat-intel","category-malware","category-network-security","category-phishing","category-rdga","category-xloader","tag-cybersecurity","tag-dga","tag-dns","tag-domain-name-system","tag-formbook","tag-infoblox-threat-intel","tag-malware","tag-network-security","tag-phishing","tag-rdga","tag-xloader"],"featured_image_urls":{"full":"","thumbnail":"","medium":"","medium_large":"","large":"","1536x1536":"","2048x2048":"","chromenews-featured":"","chromenews-large":"","chromenews-medium":""},"author_info":{"display_name":"Infoblox","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/infoblox\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/cybersecurity\/\" rel=\"category tag\">Cybersecurity<\/a> <a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/dga\/\" rel=\"category tag\">DGA<\/a> <a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/dns\/\" rel=\"category tag\">DNS<\/a> <a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/domain-name-system\/\" rel=\"category tag\">Domain Name System<\/a> <a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/formbook\/\" rel=\"category tag\">formbook<\/a> <a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/infoblox-threat-intel\/\" rel=\"category tag\">Infoblox Threat Intel<\/a> <a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/malware\/\" rel=\"category tag\">Malware<\/a> <a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/network-security\/\" rel=\"category tag\">Network Security<\/a> <a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/phishing\/\" rel=\"category tag\">phishing<\/a> <a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/rdga\/\" rel=\"category tag\">RDGA<\/a> <a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/xloader\/\" rel=\"category tag\">XLoader<\/a>","tag_info":"XLoader","comment_count":"0","jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/4506","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=4506"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/4506\/revisions"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=4506"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=4506"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=4506"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}