{"id":10133,"date":"2024-05-28T08:05:19","date_gmt":"2024-05-28T15:05:19","guid":{"rendered":"https:\/\/blogs.infoblox.com\/?p=10133"},"modified":"2024-05-28T08:26:28","modified_gmt":"2024-05-28T15:26:28","slug":"vextrio-viper-adds-a-new-dns-tds-domain","status":"publish","type":"post","link":"https:\/\/www.infoblox.com\/blog\/threat-intelligence\/vextrio-viper-adds-a-new-dns-tds-domain\/","title":{"rendered":"VexTrio Viper Adds a New DNS TDS Domain"},"content":{"rendered":"<h3 style=\"margin-bottom:20px;\">Author: Chance Tudor<\/h3>\n<p>With the introduction of Infoblox\u2019s innovative Zero Day DNS\u2122 feature in the Threat Insight module of BloxOne Threat Defence, customers can enjoy enhanced protection. This advanced system, paired with a human in the loop, empowers Infoblox Threat Intel to swiftly identify and respond to emerging threats, further strengthening our commitment to safeguarding our customers.<\/p>\n<p>One such example is the discovery of yet another domain acting as a VexTrio Viper, aka VexTrio, DNS-based traffic distribution system  (TDS) domain.<sup>1<\/sup> The actor behind VexTrio Viper does not register TDS domains very often, roughly once every three to six months. The domain in question, <span class=\"code-format\">airlogs[.]net<\/span>, follows the traditional VexTrio TDS domain naming convention:<\/p>\n<p><span class=\"code-format\"><i><span style=\"color:#993300;\">&lt;infected-site&gt;<\/span>.<span style=\"color:#000080;\">&lt;visitor-ip&gt;<\/span>.<span style=\"color:#0F8787;\">&lt;random-number&gt;<\/span>.<span style=\"color:#A51FFF;\">[nd|ni|nm]<\/span>.<span style=\"color:#F25E6B;\">airlogs[.]net<\/span><\/i><\/span><\/p>\n<p>In the above naming scheme, nd, ni, and nm represent whether the device is a desktop, iPhone, or other mobile device, respectively. We suspect that the actor created <span class=\"code-format\">airlogs[.]net<\/span> in direct response to an April 18, 2024  Sucuri report<sup>2<\/sup> that identified a fundamental change in how VexTrio operates its DNS TDS system. The TDS changed from a client side to a server side check and does not route queries through Google\u2019s public DNS resolvers any longer. We are confident that the VexTrio Viper actor, and not an affiliate, compromised the websites with this particular TDS configuration. Large scale detection of VexTrio Viper is difficult without DNS analysis. The actor\u2019s TTP change involves hiding the DNS queries for redirect domains in a compromised WordPress plugin. Now, neither a web crawl on the compromised website nor HTTP logs will yield information about the DNS TDS server.<\/p>\n<p>VexTrio Viper created <span class=\"code-format\">airlogs[.]net<\/span> on April 23, 2024, shortly after Sucuri published their article, and appeared to begin using it immediately. In fact, queries to <span class=\"code-format\">cloud-stats[.]com<\/span>, another VexTrio DNS TDS domain created on 2024-03-13, stopped after April 23, 2024. Query volume to <span class=\"code-format\">airlogs[.]net<\/span> spiked to nearly 50,000 queries on April 27, just four days after registration, but normalized afterward. <\/p>\n<p>The A records for the domain\u2019s name server point to two Russian IP addresses, <span class=\"code-format\">95[.]216[.]232[.]139<\/span> and <span class=\"code-format\">185[.]161[.]248[.]253<\/span>; these IP addresses were also seen tied to <span class=\"code-format\">cloud-stats[.]com<\/span> name servers.<\/p>\n<p>The dominant query type seen for <span class=\"code-format\">airlogs[.]net<\/span> was TXT, which tracks with the prior research published by Infoblox and Sucuri. Once a visitor to a compromised website is established to be a) not an admin or logged-in user of the site and b) a first-time visitor within a 24-hour period, the malware on the infected website creates a dynamic subdomain of <span class=\"code-format\">airlogs[.]net<\/span>. The malware then makes a TXT record request for that subdomain.<\/p>\n<p>We saw base64 encoded responses that decoded to specific URLs on <span class=\"code-format\">web-hosts[.]io<\/span>, as seen in previous research, as well as a base64 encoded response value that decoded to \u201cerr.\u201d This \u201cerr\u201d was the response value to the majority of queries that we have seen and we believe this to be the default response when the above criteria are not met for a visitor.<\/p>\n<p>With the move to a server-side redirect to VexTrio Viper domains, identifying what\u2019s triggering the redirect and identifying a specific query to one of its domains becomes even more challenging. A DNS-based security solution like BloxOne Threat Defense offers continued protection from VexTrio Viper and other DNS threat actors. And, through continued collaboration and information sharing, the cybersecurity community can adapt and fortify defenses, even as threat actors change their tactics.<\/p>\n<h3 style=\"font-size: 18px;\">Footnotes<\/h3>\n<ol style=\"font-size: 14px;\">\n<li><a href=\"https:\/\/www.infoblox.com\/threat-intel\/threat-actors\/vextrio\/\" target=\"_blank\" rel=\"noopener\">https:\/\/www.infoblox.com\/threat-intel\/threat-actors\/vextrio\/<\/a><\/li>\n<li><a href=\"https:\/\/blog.sucuri.net\/2024\/04\/javascript-malware-switches-to-server-side-redirects-dns-txt-records-tds.html\" target=\"_blank\" rel=\"noopener\">https:\/\/blog.sucuri.net\/2024\/04\/javascript-malware-switches-to-server-side-redirects-dns-txt-records-tds.html<\/a><\/li>\n<\/ol>\n<p><script>\njQuery('.single h1').html('<span class=\"gradient\">VexTrio Viper<\/span> Adds a New DNS TDS Domain');\n<\/script><\/p>\n<style>\n.code-format {\n    font-family: 'Courier New';\n}\n<\/style>\n","protected":false},"excerpt":{"rendered":"<p>Author: Chance Tudor With the introduction of Infoblox\u2019s innovative Zero Day DNS\u2122 feature in the Threat Insight module of BloxOne Threat Defence, customers can enjoy enhanced protection. This advanced system, paired with a human in the loop, empowers Infoblox Threat Intel to swiftly identify and respond to emerging threats, further strengthening our commitment to safeguarding [&hellip;]<\/p>\n","protected":false},"author":397,"featured_media":10143,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"inline_featured_image":false,"_genesis_hide_title":false,"_genesis_hide_breadcrumbs":false,"_genesis_hide_singular_image":false,"_genesis_hide_footer_widgets":false,"_genesis_custom_body_class":"","_genesis_custom_post_class":"","_genesis_layout":"","footnotes":""},"categories":[254],"tags":[930,32,16,1036,1037,902,780,40,30,855,709,1038,1039,1040],"class_list":{"0":"post-10133","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-threat-intelligence","8":"tag-cybercrime","9":"tag-malware","10":"tag-infoblox","11":"tag-infoblox-threat-intel","12":"tag-scams","13":"tag-tds","14":"tag-threat-intel","15":"tag-threat-intelligence","16":"tag-dns","17":"tag-dns-intel","18":"tag-vextrio","19":"tag-vextrio-viper","20":"tag-viper","21":"tag-dns-threat-intelligence","22":"entry"},"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v27.3 (Yoast SEO v27.3) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>Unveiling VexTrio Viper\u2019s New DNS TDS Domain: How Infoblox Threat Intel stays one step ahead<\/title>\n<meta name=\"description\" content=\"Learn how VexTrio Viper adapts to industry reporting and about the role of Infoblox Threat Intel in identifying and responding to these changes. Despite their adaptations, VexTrio Viper is still detectable.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/live-infoblox-blog.pantheonsite.io\/threat-intelligence\/vextrio-viper-adds-a-new-dns-tds-domain\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Unveiling VexTrio Viper\u2019s New DNS TDS Domain: How Infoblox Threat Intel stays one step ahead\" \/>\n<meta property=\"og:description\" content=\"Learn how VexTrio Viper adapts to industry reporting and about the role of Infoblox Threat Intel in identifying and responding to these changes. Despite their adaptations, VexTrio Viper is still detectable.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/live-infoblox-blog.pantheonsite.io\/threat-intelligence\/vextrio-viper-adds-a-new-dns-tds-domain\/\" \/>\n<meta property=\"og:site_name\" content=\"Infoblox Blog\" \/>\n<meta property=\"article:published_time\" content=\"2024-05-28T15:05:19+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2024-05-28T15:26:28+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/live-infoblox-blog.pantheonsite.io\/wp-content\/uploads\/infoblox-blog-vextrio-viper-adds-a-new-dns-tds-domain.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"612\" \/>\n\t<meta property=\"og:image:height\" content=\"408\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Infoblox Threat Intel\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:title\" content=\"Unveiling VexTrio Viper\u2019s New DNS TDS Domain: How Infoblox Threat Intel stays one step ahead\" \/>\n<meta name=\"twitter:description\" content=\"Learn how VexTrio Viper adapts to industry reporting and about the role of Infoblox Threat Intel in identifying and responding to these changes. Despite their adaptations, VexTrio Viper is still detectable.\" \/>\n<meta name=\"twitter:image\" content=\"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/infoblox-blog-vextrio-viper-adds-a-new-dns-tds-domain.jpg\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Infoblox Threat Intel\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/live-infoblox-blog.pantheonsite.io\\\/threat-intelligence\\\/vextrio-viper-adds-a-new-dns-tds-domain\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/live-infoblox-blog.pantheonsite.io\\\/threat-intelligence\\\/vextrio-viper-adds-a-new-dns-tds-domain\\\/\"},\"author\":{\"name\":\"Infoblox Threat Intel\",\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/#\\\/schema\\\/person\\\/b6aed8965e3298a0817c16d32c0a67ae\"},\"headline\":\"VexTrio Viper Adds a New DNS TDS Domain\",\"datePublished\":\"2024-05-28T15:05:19+00:00\",\"dateModified\":\"2024-05-28T15:26:28+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/live-infoblox-blog.pantheonsite.io\\\/threat-intelligence\\\/vextrio-viper-adds-a-new-dns-tds-domain\\\/\"},\"wordCount\":591,\"publisher\":{\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/live-infoblox-blog.pantheonsite.io\\\/threat-intelligence\\\/vextrio-viper-adds-a-new-dns-tds-domain\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/wp-content\\\/uploads\\\/infoblox-blog-vextrio-viper-adds-a-new-dns-tds-domain.jpg\",\"keywords\":[\"Cybercrime\",\"Malware\",\"Infoblox\",\"infoblox threat intel\",\"scams\",\"TDS\",\"Threat Intel\",\"Threat Intelligence\",\"DNS\",\"DNS intel\",\"VexTrio\",\"VexTrio Viper\",\"Viper\",\"DNS Threat Intelligence\"],\"articleSection\":[\"Infoblox Threat Intel\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/live-infoblox-blog.pantheonsite.io\\\/threat-intelligence\\\/vextrio-viper-adds-a-new-dns-tds-domain\\\/\",\"url\":\"https:\\\/\\\/live-infoblox-blog.pantheonsite.io\\\/threat-intelligence\\\/vextrio-viper-adds-a-new-dns-tds-domain\\\/\",\"name\":\"Unveiling VexTrio Viper\u2019s New DNS TDS Domain: How Infoblox Threat Intel stays one step ahead\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/live-infoblox-blog.pantheonsite.io\\\/threat-intelligence\\\/vextrio-viper-adds-a-new-dns-tds-domain\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/live-infoblox-blog.pantheonsite.io\\\/threat-intelligence\\\/vextrio-viper-adds-a-new-dns-tds-domain\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/wp-content\\\/uploads\\\/infoblox-blog-vextrio-viper-adds-a-new-dns-tds-domain.jpg\",\"datePublished\":\"2024-05-28T15:05:19+00:00\",\"dateModified\":\"2024-05-28T15:26:28+00:00\",\"description\":\"Learn how VexTrio Viper adapts to industry reporting and about the role of Infoblox Threat Intel in identifying and responding to these changes. Despite their adaptations, VexTrio Viper is still detectable.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/live-infoblox-blog.pantheonsite.io\\\/threat-intelligence\\\/vextrio-viper-adds-a-new-dns-tds-domain\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/live-infoblox-blog.pantheonsite.io\\\/threat-intelligence\\\/vextrio-viper-adds-a-new-dns-tds-domain\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/live-infoblox-blog.pantheonsite.io\\\/threat-intelligence\\\/vextrio-viper-adds-a-new-dns-tds-domain\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/wp-content\\\/uploads\\\/infoblox-blog-vextrio-viper-adds-a-new-dns-tds-domain.jpg\",\"contentUrl\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/wp-content\\\/uploads\\\/infoblox-blog-vextrio-viper-adds-a-new-dns-tds-domain.jpg\",\"width\":612,\"height\":408},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/live-infoblox-blog.pantheonsite.io\\\/threat-intelligence\\\/vextrio-viper-adds-a-new-dns-tds-domain\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Infoblox Threat Intel\",\"item\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/category\\\/threat-intelligence\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"VexTrio Viper Adds a New DNS TDS Domain\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/\",\"name\":\"infoblox.com\\\/blog\\\/\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/#organization\",\"name\":\"Infoblox\",\"url\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/wp-content\\\/uploads\\\/infoblox-logo-2.svg\",\"contentUrl\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/wp-content\\\/uploads\\\/infoblox-logo-2.svg\",\"width\":137,\"height\":30,\"caption\":\"Infoblox\"},\"image\":{\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/#\\\/schema\\\/person\\\/b6aed8965e3298a0817c16d32c0a67ae\",\"name\":\"Infoblox Threat Intel\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/blogs.infoblox.com\\\/wp-content\\\/uploads\\\/avatar_user_397_1714162589-96x96.png\",\"url\":\"https:\\\/\\\/blogs.infoblox.com\\\/wp-content\\\/uploads\\\/avatar_user_397_1714162589-96x96.png\",\"contentUrl\":\"https:\\\/\\\/blogs.infoblox.com\\\/wp-content\\\/uploads\\\/avatar_user_397_1714162589-96x96.png\",\"caption\":\"Infoblox Threat Intel\"},\"description\":\"Infoblox Threat Intel is the leading creator of original DNS threat intelligence, distinguishing itself in a sea of aggregators. What sets us apart? Two things: mad DNS skills and unparalleled visibility. DNS is notoriously tricky to interpret and hunt from, but our deep understanding and unique access to the internet's inner workings allow us to track down threat actors that others can't see. We're proactive, not just defensive, using our insights to disrupt cybercrime where it begins. We also believe in sharing knowledge to support the broader security community by publishing detailed research and releasing indicators on GitHub. In addition, our intel is seamlessly integrated into our Infoblox Protective DNS solutions, so customers automatically get its benefits, along with ridiculously low false positive rates.\",\"url\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/author\\\/infoblox-threat-intel\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"Unveiling VexTrio Viper\u2019s New DNS TDS Domain: How Infoblox Threat Intel stays one step ahead","description":"Learn how VexTrio Viper adapts to industry reporting and about the role of Infoblox Threat Intel in identifying and responding to these changes. Despite their adaptations, VexTrio Viper is still detectable.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/live-infoblox-blog.pantheonsite.io\/threat-intelligence\/vextrio-viper-adds-a-new-dns-tds-domain\/","og_locale":"en_US","og_type":"article","og_title":"Unveiling VexTrio Viper\u2019s New DNS TDS Domain: How Infoblox Threat Intel stays one step ahead","og_description":"Learn how VexTrio Viper adapts to industry reporting and about the role of Infoblox Threat Intel in identifying and responding to these changes. Despite their adaptations, VexTrio Viper is still detectable.","og_url":"https:\/\/live-infoblox-blog.pantheonsite.io\/threat-intelligence\/vextrio-viper-adds-a-new-dns-tds-domain\/","og_site_name":"Infoblox Blog","article_published_time":"2024-05-28T15:05:19+00:00","article_modified_time":"2024-05-28T15:26:28+00:00","og_image":[{"width":612,"height":408,"url":"https:\/\/live-infoblox-blog.pantheonsite.io\/wp-content\/uploads\/infoblox-blog-vextrio-viper-adds-a-new-dns-tds-domain.jpg","type":"image\/jpeg"}],"author":"Infoblox Threat Intel","twitter_card":"summary_large_image","twitter_title":"Unveiling VexTrio Viper\u2019s New DNS TDS Domain: How Infoblox Threat Intel stays one step ahead","twitter_description":"Learn how VexTrio Viper adapts to industry reporting and about the role of Infoblox Threat Intel in identifying and responding to these changes. Despite their adaptations, VexTrio Viper is still detectable.","twitter_image":"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/infoblox-blog-vextrio-viper-adds-a-new-dns-tds-domain.jpg","twitter_misc":{"Written by":"Infoblox Threat Intel","Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/live-infoblox-blog.pantheonsite.io\/threat-intelligence\/vextrio-viper-adds-a-new-dns-tds-domain\/#article","isPartOf":{"@id":"https:\/\/live-infoblox-blog.pantheonsite.io\/threat-intelligence\/vextrio-viper-adds-a-new-dns-tds-domain\/"},"author":{"name":"Infoblox Threat Intel","@id":"https:\/\/www.infoblox.com\/blog\/#\/schema\/person\/b6aed8965e3298a0817c16d32c0a67ae"},"headline":"VexTrio Viper Adds a New DNS TDS Domain","datePublished":"2024-05-28T15:05:19+00:00","dateModified":"2024-05-28T15:26:28+00:00","mainEntityOfPage":{"@id":"https:\/\/live-infoblox-blog.pantheonsite.io\/threat-intelligence\/vextrio-viper-adds-a-new-dns-tds-domain\/"},"wordCount":591,"publisher":{"@id":"https:\/\/www.infoblox.com\/blog\/#organization"},"image":{"@id":"https:\/\/live-infoblox-blog.pantheonsite.io\/threat-intelligence\/vextrio-viper-adds-a-new-dns-tds-domain\/#primaryimage"},"thumbnailUrl":"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/infoblox-blog-vextrio-viper-adds-a-new-dns-tds-domain.jpg","keywords":["Cybercrime","Malware","Infoblox","infoblox threat intel","scams","TDS","Threat Intel","Threat Intelligence","DNS","DNS intel","VexTrio","VexTrio Viper","Viper","DNS Threat Intelligence"],"articleSection":["Infoblox Threat Intel"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/live-infoblox-blog.pantheonsite.io\/threat-intelligence\/vextrio-viper-adds-a-new-dns-tds-domain\/","url":"https:\/\/live-infoblox-blog.pantheonsite.io\/threat-intelligence\/vextrio-viper-adds-a-new-dns-tds-domain\/","name":"Unveiling VexTrio Viper\u2019s New DNS TDS Domain: How Infoblox Threat Intel stays one step ahead","isPartOf":{"@id":"https:\/\/www.infoblox.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/live-infoblox-blog.pantheonsite.io\/threat-intelligence\/vextrio-viper-adds-a-new-dns-tds-domain\/#primaryimage"},"image":{"@id":"https:\/\/live-infoblox-blog.pantheonsite.io\/threat-intelligence\/vextrio-viper-adds-a-new-dns-tds-domain\/#primaryimage"},"thumbnailUrl":"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/infoblox-blog-vextrio-viper-adds-a-new-dns-tds-domain.jpg","datePublished":"2024-05-28T15:05:19+00:00","dateModified":"2024-05-28T15:26:28+00:00","description":"Learn how VexTrio Viper adapts to industry reporting and about the role of Infoblox Threat Intel in identifying and responding to these changes. Despite their adaptations, VexTrio Viper is still detectable.","breadcrumb":{"@id":"https:\/\/live-infoblox-blog.pantheonsite.io\/threat-intelligence\/vextrio-viper-adds-a-new-dns-tds-domain\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/live-infoblox-blog.pantheonsite.io\/threat-intelligence\/vextrio-viper-adds-a-new-dns-tds-domain\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/live-infoblox-blog.pantheonsite.io\/threat-intelligence\/vextrio-viper-adds-a-new-dns-tds-domain\/#primaryimage","url":"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/infoblox-blog-vextrio-viper-adds-a-new-dns-tds-domain.jpg","contentUrl":"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/infoblox-blog-vextrio-viper-adds-a-new-dns-tds-domain.jpg","width":612,"height":408},{"@type":"BreadcrumbList","@id":"https:\/\/live-infoblox-blog.pantheonsite.io\/threat-intelligence\/vextrio-viper-adds-a-new-dns-tds-domain\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.infoblox.com\/blog\/"},{"@type":"ListItem","position":2,"name":"Infoblox Threat Intel","item":"https:\/\/www.infoblox.com\/blog\/category\/threat-intelligence\/"},{"@type":"ListItem","position":3,"name":"VexTrio Viper Adds a New DNS TDS Domain"}]},{"@type":"WebSite","@id":"https:\/\/www.infoblox.com\/blog\/#website","url":"https:\/\/www.infoblox.com\/blog\/","name":"infoblox.com\/blog\/","description":"","publisher":{"@id":"https:\/\/www.infoblox.com\/blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.infoblox.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.infoblox.com\/blog\/#organization","name":"Infoblox","url":"https:\/\/www.infoblox.com\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.infoblox.com\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/infoblox-logo-2.svg","contentUrl":"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/infoblox-logo-2.svg","width":137,"height":30,"caption":"Infoblox"},"image":{"@id":"https:\/\/www.infoblox.com\/blog\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/www.infoblox.com\/blog\/#\/schema\/person\/b6aed8965e3298a0817c16d32c0a67ae","name":"Infoblox Threat Intel","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/blogs.infoblox.com\/wp-content\/uploads\/avatar_user_397_1714162589-96x96.png","url":"https:\/\/blogs.infoblox.com\/wp-content\/uploads\/avatar_user_397_1714162589-96x96.png","contentUrl":"https:\/\/blogs.infoblox.com\/wp-content\/uploads\/avatar_user_397_1714162589-96x96.png","caption":"Infoblox Threat Intel"},"description":"Infoblox Threat Intel is the leading creator of original DNS threat intelligence, distinguishing itself in a sea of aggregators. What sets us apart? Two things: mad DNS skills and unparalleled visibility. DNS is notoriously tricky to interpret and hunt from, but our deep understanding and unique access to the internet's inner workings allow us to track down threat actors that others can't see. We're proactive, not just defensive, using our insights to disrupt cybercrime where it begins. We also believe in sharing knowledge to support the broader security community by publishing detailed research and releasing indicators on GitHub. In addition, our intel is seamlessly integrated into our Infoblox Protective DNS solutions, so customers automatically get its benefits, along with ridiculously low false positive rates.","url":"https:\/\/www.infoblox.com\/blog\/author\/infoblox-threat-intel\/"}]}},"_links":{"self":[{"href":"https:\/\/www.infoblox.com\/blog\/wp-json\/wp\/v2\/posts\/10133","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.infoblox.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.infoblox.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.infoblox.com\/blog\/wp-json\/wp\/v2\/users\/397"}],"replies":[{"embeddable":true,"href":"https:\/\/www.infoblox.com\/blog\/wp-json\/wp\/v2\/comments?post=10133"}],"version-history":[{"count":6,"href":"https:\/\/www.infoblox.com\/blog\/wp-json\/wp\/v2\/posts\/10133\/revisions"}],"predecessor-version":[{"id":10141,"href":"https:\/\/www.infoblox.com\/blog\/wp-json\/wp\/v2\/posts\/10133\/revisions\/10141"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.infoblox.com\/blog\/wp-json\/wp\/v2\/media\/10143"}],"wp:attachment":[{"href":"https:\/\/www.infoblox.com\/blog\/wp-json\/wp\/v2\/media?parent=10133"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.infoblox.com\/blog\/wp-json\/wp\/v2\/categories?post=10133"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.infoblox.com\/blog\/wp-json\/wp\/v2\/tags?post=10133"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}