A threat hunter reviews DNS resolver logs and observes a single infected host querying hundreds of unique, algorithmically generated hostnames such as 'xk93jdla.com', 'plq82basd.net', and 'vt4mqzo.org' within a five-minute window, most returning NXDOMAIN. Which technique is most likely being used by the malware?
- ADomain generation algorithm (DGA)
- BDNS cache poisoning
- CDNS tunneling
- DFast flux DNS
Show answer & explanationAnswer & explanation
Correct answer: A. Domain generation algorithm (DGA)
Malware using a DGA generates large numbers of pseudo-random domain names on a schedule so it can locate its C2 server even if some domains are taken down or blocklisted; most attempts fail (NXDOMAIN) until the correct active domain is reached. DNS tunneling encodes data in queries to a single fixed domain, fast flux rapidly rotates IP addresses behind a stable domain name, and cache poisoning corrupts a resolver's cache with false records.
Why the other options are wrong
- B. Cache poisoning injects false records into a resolver, unrelated to random domain generation.
- C. Tunneling uses a consistent domain to exfiltrate data in subdomain labels, not many random domain names.
- D. Fast flux rotates IP addresses for one domain, not the domain names themselves.
Domain Generation Algorithm (DGA)
An algorithm malware uses to generate a large number of pseudo-random domain names, one or a few of which the attacker has registered as active C2 infrastructure, making blocklisting difficult.
- High volume of NXDOMAIN responses is a key indicator
- Domains often have random-looking, unpronounceable strings
- Seeded by date/time so both malware and attacker can compute matching domains
Memory trick: 'DGA rolls dice on domains' - most rolls miss (NXDOMAIN), one hits the C2 jackpot.