CRITICAL SEVERITYCLOUDID: aws-elastic-beanstalk
AWS Elastic Beanstalk Dangling DNS Takeover Fingerprint
An Elastic Beanstalk environment was terminated, releasing the regional subdomain prefix back to the public pool. Attackers can provision a new Beanstalk app with the identical environment name.
CNAME Fingerprint Rule
*.elasticbeanstalk.com
NXDOMAIN / 404
Response Body Token
“Target Unallocated”
When SubdomainWatch scanner receives HTTP responses matching this token on a dangling CNAME, it raises a critical alert immediately.
Remediation Guide & Mitigation
Action Required: Delete the CNAME record or recreate the Elastic Beanstalk environment in the same AWS region.
Immediate Defensive Checklist:
- Audit authoritative DNS zone records for any CNAME records pointing to
*.elasticbeanstalk.com. - Verify whether the corresponding target resource is still active in your cloud tenant.
- If the service was deprecated, delete the DNS record immediately to prevent hijackers from claiming the endpoint.
- Add automated continuous monitoring to alert before third parties can register matching resource names.
Monitor AWS Elastic Beanstalk In Real-Time
SubdomainWatch continuously monitors your DNS zones for orphaned AWS Elastic Beanstalk pointers, expired certificates, and dangling records 24/7.
Related Cloud Takeover Signatures
CLOUDCRITICAL
AWS S3
*.s3.amazonaws.com / *.s3-website-*.amazonaws.com
HOSTINGCRITICAL
GitHub Pages
*.github.io
HOSTINGCRITICAL
Heroku App
*.herokudns.com / *.herokuapp.com
CLOUDCRITICAL
Microsoft Azure App Service
*.azurewebsites.net / *.cloudapp.net
CLOUDCRITICAL
AWS CloudFront
*.cloudfront.net
DNSHIGH
Fastly CDN
*.fastly.net