117. Hunting for Malicious IP Lookups

Hello everyone! I'm sure you know that various malware performs IP lookups to identify the compromised system's location. Usually the adversaries use legitimate services to solve this problem.

What does it mean from threat hunting perspective? We can use it to build our hunting queries! I've collected some of commonly abused services for you, here you go:

event_type: "dnsreq"

AND

dns_rname: ("wtfismyip.com" OR "ipify.org" OR "icanhazip.com" OR "ip-api.com" OR "checkip.dyndns.org" OR "reallyfreegeoip.org")

You WILL get some false positives, but we are talkng about hunting, right?

See you tomorrow!

Comments

Popular posts from this blog

033. Free Google Threat Intelligence Course

082. Huniting for Malicious Browser Extensions

001. The Zeltser Challenge