Jump to: 🔥 Challenge News ⚡ Intel 🔬 Research Labs 📡 All News →
🔍 OSINT Challenge

🔐 Daily Cyber Challenge

Monday, 21 September 2026  ·  Challenge #264
🔥
0
Day streak
0
Solved
0
Best streak
DNS History Investigation
suspicious-campaign-site.com DNS history: Current: 185.220.101.45 (Tor exit — blocked) 3 months: 45.33.32.156 (Shodan: C2 panel) 6 months: 104.21.14.131 (Cloudflare fronting) CNAME: *.cdn-delivery.net Created: 8 months ago MX records: Never configured Registrant: Changed 3 times in 8 months
What does this DNS history pattern reveal?
60s
+3
points
✅ Correct!
Threat Actor Infrastructure Analysis (T1583): DNS history reveals: (1) Progression C2 panel -> CDN fronting -> Tor exit = OPSEC escalation as actor feared detection. (2) Three registrant changes = avoiding WHOIS attribution. (3) No MX = not used for email (rules out business). (4) 8 months old. Tools: SecurityTrails, WhoisFreaks, VirusTotal graph, RiskIQ.
MITRE T1583
📚 Archive