The DGA of BumbleBee

September 15, 2023 This very short post shows the Domain Generation Algorithm of BumbleBee, a loader for Cobalt Strike or other malware.

The Domain Generation Algorithm of Orchard v3 A DGA Seeded by the Bitcoin Genesis Block

July 24, 2022 The Orchard malware uses a domain generation algorithm (DGA) that is seeded both by the current date, and also by the current balance of the Bitcoin genesis block.

The Domain Generation Algorithms of SharkBot

June 4, 2022 SharkBot uses a DGA for communication, which was changed several times during the development of SharkBot. This blogpost shows four versions of the DGA, and their differences.

