ENS Ethereum C2 Resolution
Malware resolves its command-and-control endpoint by querying an Ethereum Name Service (ENS) text record via public Ethereum RPC endpoints. The ENS name itself may be hardcoded, derived from a seed, or decoded at runtime. This technique leverages legitimate public infrastructure (Ethereum mainnet RPC nodes) for C2 discovery, making blocking or takedown difficult without disabling all public Ethereum access.
Detection / Fingerprint
- Hardcoded ENS Public Resolver contract address:
0x00000000000C2E074eC69A0dFb2997BA6C7d2e1e - Function signatures in strings:
resolver(bytes32),text(bytes32,string) - Multiple hardcoded public Ethereum RPC endpoints (e.g.,
https://ethereum.publicnode.com,https://rpc.ankr.com/eth,https://eth-mainnet.public.blastapi.io) - JSON-RPC method strings:
eth_blockNumber,eth_call - WebSocket or HTTPS outbound connections to Ethereum RPC nodes from a non-browser process
Implementation Patterns
Sample ec95bcf4 implements the full ENS resolution chain:
- Queries 15+ public RPC endpoints for redundancy
- Calls
resolver(bytes32)on the ENS registry to get the resolver for the target name - Calls
text(bytes32,string)on the resolver to retrieve the C2 URL stored as an ENS text record - Connects to the retrieved C2 via WebSocket-over-TLS (
wss://)
The ENS name (bytes32 hash) and decryption key (JfR9z1!XMKjs#Ln0PqWe48@k2dFm7Yvz) are likely campaign-specific.
Defensive Countermeasures
- Monitor non-browser processes making HTTPS requests to known public Ethereum RPC endpoints
- Alert on
eth_callpayloads containing the ENS resolver address ortext(bytes32,string)selector - DNS/URL filtering for
*.ethnames if observed in network telemetry - Network segmentation to block outbound Ethereum RPC access from endpoint workstations
Pages Where Observed
- unclassified-pe64-modular-builder
ec95bcf4^[/intel/analyses/ec95bcf427c8082f97928eebd0084f31fb008c19cbb27670afedfb6533470d8c.html]