Suspicious DNS Activity to High-Risk Top-Level Domains
This detection identifies suspicious DNS queries from Windows processes to high-risk top-level domains commonly used for command and control infrastructure.
This detection identifies DNS queries directed toward high-risk Top Level Domains (TLDs) such as .top, .xyz, .onion, and .click originating from Windows endpoints. Malicious actors frequently leverage these less restrictive TLDs to host command and control (C2) infrastructure and phishing landing pages. The detection logic triggers when specific Living-off-the-Land binaries (LOLBins) - including powershell.exe, rundll32.exe, mshta.exe, and others - or unsigned and suspiciously located binaries (such as those in C:\Users\Public or C:\ProgramData) perform these lookups. This behavior is a common indicator of unauthorized network communication or staging activity. Defenders should investigate these events to differentiate between malicious C2 beacons and legitimate developer or security tooling. The rule is tuned to ignore established Microsoft Defender update traffic, reducing noise in enterprise environments.
Impact
Successful exploitation of the network by C2 infrastructure using these TLDs can lead to unauthorized data exfiltration, remote command execution, or the deployment of secondary payloads. By monitoring these specific domain patterns, organizations can intercept attacker communication at the early stages of a campaign before significant damage is sustained.
Recommendation
- Deploy the provided detection logic to your SIEM/EDR platform to monitor for DNS activity to the listed high-risk TLDs.
- Prioritize alerts where the originating process is unsigned or resides in a user-writable directory (e.g., C:\Users\Public\).
- Cross-reference DNS queries with subsequent network connection events to the resolved IPs to confirm active C2 communication.
- Investigate the process launch chain for suspicious parents, such as document-handling applications or browser processes starting scripting engines.
- Tune the detection by creating exceptions based on process signature and host-specific administrative workflows rather than suppressing the TLD or process name globally.
Immediate actions
Deploy the Sigma detection rule to monitor high-risk TLD queries.
Threat Hunt
Identify processes executing from C:\Users\Public or C:\ProgramData performing network activity.
Mitigations
Implement DNS filtering to block known malicious high-risk TLDs at the resolver level.
Detection coverage 1
Detect Network Activity to a Suspicious Top Level Domain
highDetects DNS queries to high-risk TLDs from known LOLBins or suspicious/unsigned binaries on Windows hosts.
Detection queries are available on the platform. Get full rules →