DNS Request to Suspicious Top Level Domain
This threat brief details how Linux systems making DNS queries to commonly abused top-level domains may indicate malware-related command and control (C2) communications, data exfiltration, or payload downloads, often blending into normal name resolution, signaling a potential compromise of servers, workstations, or containerized workloads.
This brief focuses on the detection of suspicious DNS queries originating from Linux systems to Top Level Domains (TLDs) frequently exploited by malicious actors. These TLDs, such as .xyz, .top, .ru, and numerous others including .onion, are chosen by malware authors to host command and control (C2) infrastructure, facilitate data exfiltration, or serve as distribution points for additional malicious payloads. The presence of such DNS lookups can be a critical indicator of compromise on a Linux server, workstation, or containerized workload, revealing hidden malicious network activity that may otherwise blend into legitimate name resolution traffic. The pattern often observed is a compromised Linux host resolving one of these TLDs just before a downloader, backdoor, or script beacon initiates communication, exchanges instructions, or attempts to upload collected data. This activity, while not an initial access vector, is a strong signal of post-exploitation activity, highlighting the need for vigilance against such network behaviors.
Attack Chain
- An attacker gains initial access to a Linux system through various means, such as exploiting a vulnerability, phishing, or compromised credentials.
- Malware is deployed and executed on the compromised Linux host, establishing a foothold within the environment.
- The malicious process initiates a DNS lookup to resolve a command and control (C2) server or data exfiltration endpoint.
- The DNS query targets a domain residing under a suspicious or commonly abused Top Level Domain (TLD), such as
malicious.xyzorbeacon.ru, attempting to blend with legitimate network traffic. - The DNS request is resolved, providing the malware with the IP address of its C2 infrastructure or data drop point.
- The malware establishes an outbound connection to the resolved malicious IP address for data exfiltration, payload download, or receiving further commands.
- Data is exfiltrated from the compromised system, or additional malware components are downloaded and executed, furthering the attacker's objectives.
- The attacker maintains persistence and control over the compromised Linux system, continuing C2 communications through domains within suspicious TLDs.
Impact
The successful execution of an attack leveraging suspicious TLDs for C2 or data exfiltration can lead to significant impact, including unauthorized access to sensitive data, installation of further malicious software like ransomware, and establishment of persistent access for future exploitation. Compromised Linux servers or workstations could become part of a botnet, serve as launchpads for lateral movement, or be used to disrupt critical services. While this brief does not detail specific victim counts or sectors, the use of such TLDs is prevalent across various cybercrime and advanced persistent threat (APT) campaigns targeting any organization operating Linux environments. The primary damage is data breach, system compromise, and potential financial and reputational losses due to attacker control and malicious actions.
Recommendation
- Deploy the provided Sigma rule to your SIEM and tune for your environment to detect DNS queries to commonly abused TLDs on Linux systems.
- Ensure DNS logging is enabled on all Linux endpoints and network devices to capture
dns.question.namedata, which is crucial for the rule to function. - Enrich the queried domain and any resolved IPs with passive DNS, registration age, reputation, ASN, or geolocation information to distinguish newly created or low-reputation infrastructure from known business services, as suggested in the "Investigating DNS Request to Suspicious Top Level Domain" guide.
- Block the suspicious Top Level Domains (TLDs) listed in the IOC table at your network's DNS resolver and firewall controls to prevent connections to known malicious infrastructure.
- Isolate any Linux host or container flagged by the "DNS Request to Suspicious Top Level Domain" rule from the network, except for approved management access, and immediately block associated suspicious domains and IP addresses.
Detection coverage 1
DNS Request to Suspicious Top Level Domain
lowDetects DNS queries originating from Linux systems to commonly abused top-level domains that malware authors frequently use for command and control (C2), data exfiltration, or payload delivery.
Detection queries are available on the platform. Get full rules →
Indicators of compromise
50
domain
| Type | Value |
|---|---|
| domain | *.forum |
| domain | *.pro |
| domain | *.team |
| domain | *.lol |
| domain | *.kr |
| domain | *.ke |
| domain | *.nu |
| domain | *.space |
| domain | *.capital |
| domain | *.in |
| domain | *.cfd |
| domain | *.online |
| domain | *.ru |
| domain | *.info |
| domain | *.top |
| domain | *.buzz |
| domain | *.xyz |
| domain | *.rest |
| domain | *.ml |
| domain | *.cf |
| domain | *.gq |
| domain | *.ga |
| domain | *.onion |
| domain | *.network |
| domain | *.monster |
| domain | *.marketing |
| domain | *.cyou |
| domain | *.quest |
| domain | *.cc |
| domain | *.bar |
| domain | *.click |
| domain | *.cam |
| domain | *.surf |
| domain | *.tk |
| domain | *.shop |
| domain | *.club |
| domain | *.icu |
| domain | *.pw |
| domain | *.ws |
| domain | *.fun |
| domain | *.life |
| domain | *.boats |
| domain | *.store |
| domain | *.hair |
| domain | *.mom |
| domain | *.beauty |
| domain | *.bond |
| domain | *.biz |
| domain | *.live |
| domain | *.zone |