Skip to content
Threat Feed
low advisory

DNS Request to Suspicious Top Level Domain

This threat brief details how Linux systems making DNS queries to commonly abused top-level domains may indicate malware-related command and control (C2) communications, data exfiltration, or payload downloads, often blending into normal name resolution, signaling a potential compromise of servers, workstations, or containerized workloads.

This brief focuses on the detection of suspicious DNS queries originating from Linux systems to Top Level Domains (TLDs) frequently exploited by malicious actors. These TLDs, such as .xyz, .top, .ru, and numerous others including .onion, are chosen by malware authors to host command and control (C2) infrastructure, facilitate data exfiltration, or serve as distribution points for additional malicious payloads. The presence of such DNS lookups can be a critical indicator of compromise on a Linux server, workstation, or containerized workload, revealing hidden malicious network activity that may otherwise blend into legitimate name resolution traffic. The pattern often observed is a compromised Linux host resolving one of these TLDs just before a downloader, backdoor, or script beacon initiates communication, exchanges instructions, or attempts to upload collected data. This activity, while not an initial access vector, is a strong signal of post-exploitation activity, highlighting the need for vigilance against such network behaviors.

Attack Chain

  1. An attacker gains initial access to a Linux system through various means, such as exploiting a vulnerability, phishing, or compromised credentials.
  2. Malware is deployed and executed on the compromised Linux host, establishing a foothold within the environment.
  3. The malicious process initiates a DNS lookup to resolve a command and control (C2) server or data exfiltration endpoint.
  4. The DNS query targets a domain residing under a suspicious or commonly abused Top Level Domain (TLD), such as malicious.xyz or beacon.ru, attempting to blend with legitimate network traffic.
  5. The DNS request is resolved, providing the malware with the IP address of its C2 infrastructure or data drop point.
  6. The malware establishes an outbound connection to the resolved malicious IP address for data exfiltration, payload download, or receiving further commands.
  7. Data is exfiltrated from the compromised system, or additional malware components are downloaded and executed, furthering the attacker's objectives.
  8. The attacker maintains persistence and control over the compromised Linux system, continuing C2 communications through domains within suspicious TLDs.

Impact

The successful execution of an attack leveraging suspicious TLDs for C2 or data exfiltration can lead to significant impact, including unauthorized access to sensitive data, installation of further malicious software like ransomware, and establishment of persistent access for future exploitation. Compromised Linux servers or workstations could become part of a botnet, serve as launchpads for lateral movement, or be used to disrupt critical services. While this brief does not detail specific victim counts or sectors, the use of such TLDs is prevalent across various cybercrime and advanced persistent threat (APT) campaigns targeting any organization operating Linux environments. The primary damage is data breach, system compromise, and potential financial and reputational losses due to attacker control and malicious actions.

Recommendation

  • Deploy the provided Sigma rule to your SIEM and tune for your environment to detect DNS queries to commonly abused TLDs on Linux systems.
  • Ensure DNS logging is enabled on all Linux endpoints and network devices to capture dns.question.name data, which is crucial for the rule to function.
  • Enrich the queried domain and any resolved IPs with passive DNS, registration age, reputation, ASN, or geolocation information to distinguish newly created or low-reputation infrastructure from known business services, as suggested in the "Investigating DNS Request to Suspicious Top Level Domain" guide.
  • Block the suspicious Top Level Domains (TLDs) listed in the IOC table at your network's DNS resolver and firewall controls to prevent connections to known malicious infrastructure.
  • Isolate any Linux host or container flagged by the "DNS Request to Suspicious Top Level Domain" rule from the network, except for approved management access, and immediately block associated suspicious domains and IP addresses.

Detection coverage 1

DNS Request to Suspicious Top Level Domain

low

Detects DNS queries originating from Linux systems to commonly abused top-level domains that malware authors frequently use for command and control (C2), data exfiltration, or payload delivery.

sigma tactics: command_and_control, exfiltration techniques: T1071.004, T1567 sources: dns_query, linux

Detection queries are available on the platform. Get full rules →

Indicators of compromise

50

domain

TypeValue
domain*.forum
domain*.pro
domain*.team
domain*.lol
domain*.kr
domain*.ke
domain*.nu
domain*.space
domain*.capital
domain*.in
domain*.cfd
domain*.online
domain*.ru
domain*.info
domain*.top
domain*.buzz
domain*.xyz
domain*.rest
domain*.ml
domain*.cf
domain*.gq
domain*.ga
domain*.onion
domain*.network
domain*.monster
domain*.marketing
domain*.cyou
domain*.quest
domain*.cc
domain*.bar
domain*.click
domain*.cam
domain*.surf
domain*.tk
domain*.shop
domain*.club
domain*.icu
domain*.pw
domain*.ws
domain*.fun
domain*.life
domain*.boats
domain*.store
domain*.hair
domain*.mom
domain*.beauty
domain*.bond
domain*.biz
domain*.live
domain*.zone