🔍 OSINT Challenge
🔐 Daily Cyber Challenge
Monday, 21 September 2026 · Challenge #264
🔥
0
Day streak
0
Solved
0
Best streak
DNS History Investigation
suspicious-campaign-site.com DNS history:
Current: 185.220.101.45 (Tor exit — blocked)
3 months: 45.33.32.156 (Shodan: C2 panel)
6 months: 104.21.14.131 (Cloudflare fronting)
CNAME: *.cdn-delivery.net
Created: 8 months ago
MX records: Never configured
Registrant: Changed 3 times in 8 months
What does this DNS history pattern reveal?
60s
+3
points
✅ Correct!
Threat Actor Infrastructure Analysis (T1583): DNS history reveals: (1) Progression C2 panel -> CDN fronting -> Tor exit = OPSEC escalation as actor feared detection. (2) Three registrant changes = avoiding WHOIS attribution. (3) No MX = not used for email (rules out business). (4) 8 months old. Tools: SecurityTrails, WhoisFreaks, VirusTotal graph, RiskIQ.
MITRE T1583