An increasing amount of malware is using non-ICANN domains (e.g. .bazar as used by Team9) for C2, which are resolved via OpenNIC servers that we mark within Wisdom as alt_dns. We should register alphasoc.bazar via EmerDNS and update the hijack module so that it:
An increasing amount of malware is using non-ICANN domains (e.g.
.bazaras used by Team9) for C2, which are resolved via OpenNIC servers that we mark within Wisdom asalt_dns. We should registeralphasoc.bazarvia EmerDNS and update thehijackmodule so that it:alt_dnslistalphasoc.bazar