Aug. 1, 2023, 2:25 p.m. | MalBot

Malware Analysis, News and Indicators - Latest topics malware.news

Our honeypots see a lot of DNS over HTTP(s) requests against the “/dns-query” endpoint. This endpoint is used by DNS over HTTPs requests to receive queries. Queries can use different encodings. You may either see the more readable URL encoding, like “?name=google.com&type=A” or the raw DNS data encoding, like “?dns=mNwBAAABAAAAAAAABmdvb2dsZQNjb20AAAEAAQ”.


Article Link: https://isc.sans.edu/diary/rss/30084


1 post - 1 participant


Read full topic

amp data dns dns over https encoding endpoint google honeypots http https may name query requests url

Director, Cyber Risk

@ Kroll | South Africa

Security Engineer, XRM

@ Meta | New York City

Security Analyst 3

@ Oracle | Romania

Internship - Cyber Security Operations

@ SES | Betzdorf, LU

Principal Product Manager (Network/Security Management) - NetSec

@ Palo Alto Networks | Bengaluru, India

IT Security Engineer

@ Timocom GmbH | Erkrath, Germany