117. Hunting for Malicious IP Lookups
Hello everyone! I'm sure you know that various malware performs IP lookups to identify the compromised system's location. Usually the adversaries use legitimate services to solve this problem.
What does it mean from threat hunting perspective? We can use it to build our hunting queries! I've collected some of commonly abused services for you, here you go:
event_type: "dnsreq"
AND
dns_rname: ("wtfismyip.com" OR "ipify.org" OR "icanhazip.com" OR "ip-api.com" OR "checkip.dyndns.org" OR "reallyfreegeoip.org")
You WILL get some false positives, but we are talkng about hunting, right?
See you tomorrow!
Comments
Post a Comment