PULSE NAME
Detour Dog: DNS Malware Powers Strela Stealer Campaigns.
WHITE Hive0145 PetrP.73 2025-09-30 Modified: 2025-10-30
22
IOCs
MEDIUM VOLUME
The malware known as "Detour Dog" utilizes the Domain Name System (DNS) to execute redirection tactics on tens of thousands of compromised websites globally. Since August 2023, the threat actor behind this malware has been identified and continues to enhance its functionalities beyond simple redirections, now evolving to incorporate remote execution commands via a DNS-based command-and-control (C2) system. The operational methodology involves making server-side DNS requests that remain undetectable to visitors and conditionally redirect users based on their geographic location and device type. The two primary malware components linked to this campaign are the "StarFish Backdoor" and "Strela Stealer." Strela Stealer, first documented in late 2022, predominantly targets European nations with a focus on Germany.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
MALWARE FAMILIES
MikroTik Golo Second StarFish Strela
Indicators of Compromise (22)
All URL domain hostname
TYPEINDICATORDESCRIPTIONCREATED
URL http://176.65.138.152/script.php?u=j6cwaj0h67 2025-09-30
URL http://updatemsdnserver.com/script.php. 2025-09-30
URL http://updatemsdnserver.com/script.php?u= 2025-09-30
URL https://advertipros.com//?u=script 2025-09-30
domain advertipros.com 2025-09-30
domain aeroarrows.io 2025-09-30
domain airlogs.net 2025-09-30
domain braraildye.live 2025-09-30
domain cdn-routing.com 2025-09-30
domain domainzone123.com 2025-09-30
domain ecomicrolab.com 2025-09-30
domain flow-distributor.com 2025-09-30
domain infosystemsllc.com 2025-09-30
domain msdnupdate.com 2025-09-30
domain mssoftupdateserver.com 2025-09-30
domain nupdate0625.com 2025-09-30
domain thinkpadwork.com 2025-09-30
domain updatemsdnserver.com 2025-09-30
domain updatemssoft.com 2025-09-30
domain webdmonitor.io 2025-09-30
domain ywcanevada.org 2025-09-30
hostname nwuuj6cwaj0h67.webmonitor.io 2025-09-30