{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/tags/dns-query/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":[],"_cs_severities":["medium"],"_cs_tags":["reconnaissance","malware","dns-query","windows"],"_cs_type":"advisory","_cs_vendors":[],"content_html":"\u003cp\u003eThreat actors deploy malware, such as Trickbot, Azorult, DarkCrystal RAT, and other information stealers, that perform reconnaissance by querying public web services to ascertain the victim machine's external IP address. This activity, identifiable through Sysmon Event ID 22 logs, involves processes initiating DNS requests to a predefined list of IP-checking domains like \u0026quot;wtfismyip.com,\u0026quot; \u0026quot;ipinfo.io,\u0026quot; and \u0026quot;icanhazip.com.\u0026quot; This behavior is a common preliminary step for malware to gather environmental information, which is crucial for subsequent attack phases such as command and control (C2) communication, target profiling, or planning lateral movement within a compromised network. Detecting such reconnaissance early allows defenders to identify potentially malicious activity before more damaging stages of an attack unfold.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eMalware successfully executes on the victim's Windows endpoint, typically delivered via phishing or drive-by download.\u003c/li\u003e\n\u003cli\u003eThe malicious process initiates internal reconnaissance to identify initial system characteristics and prepares to determine its external network presence.\u003c/li\u003e\n\u003cli\u003eThe malware constructs a DNS query for a known public IP address checking web service, such as \u003ccode\u003eipecho.net\u003c/code\u003e or \u003ccode\u003eapi.ipify.org\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eThe operating system's DNS resolver processes this query, attempting to resolve the domain to an IP address.\u003c/li\u003e\n\u003cli\u003eUpon successful resolution, the malware receives the IP address of the external IP checking service.\u003c/li\u003e\n\u003cli\u003eThe malware establishes an outbound network connection to the resolved IP address to communicate with the IP checking web service.\u003c/li\u003e\n\u003cli\u003eThe IP checking service responds with the victim's external public IP address, which the malware parses and extracts.\u003c/li\u003e\n\u003cli\u003eThe malware leverages this newly acquired external IP for various purposes, including reporting to its C2 server or tailoring subsequent attack steps like targeting specific external infrastructure.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful IP reconnaissance by malware allows threat actors to gain critical network context about their victims. This information can be used to bypass network security controls, establish more reliable command and control channels, or tailor subsequent attack stages, such as targeting specific external-facing services or planning lateral movement from an internet-facing host. While this activity alone does not directly cause immediate data loss or system compromise, it is a foundational step for many malware families, making its detection vital for early threat intervention and preventing more severe consequences like data exfiltration, ransomware deployment, or widespread network compromise.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eDeploy the \u003ccode\u003eDetect Malware IP Reconnaissance via DNS Queries\u003c/code\u003e Sigma rule to your SIEM and configure Sysmon to log Event ID 22 for DNS queries.\u003c/li\u003e\n\u003cli\u003eMonitor for DNS queries to the domains listed in the IOC table and investigate any hits, especially from non-browser processes.\u003c/li\u003e\n\u003cli\u003eTune the \u003ccode\u003eDetect Malware IP Reconnaissance via DNS Queries\u003c/code\u003e rule by creating allowlists for known legitimate applications, such as internet browsers, that might query these services, as noted in the rule's \u003ccode\u003efalsepositives\u003c/code\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-24T09:10:19Z","date_published":"2026-07-24T09:10:19Z","id":"https://feed.craftedsignal.io/briefs/2026-07-malware-ip-reconnaissance/","summary":"Malware, including Trickbot and various stealers, utilizes DNS queries to public IP checking web services for reconnaissance purposes, aiming to determine the victim's external IP address, which can facilitate further attacks or lateral movement.","title":"Malware Employs Web Services for Victim IP Reconnaissance","url":"https://feed.craftedsignal.io/briefs/2026-07-malware-ip-reconnaissance/"}],"language":"en","title":"CraftedSignal Threat Feed - Dns-Query","version":"https://jsonfeed.org/version/1.1"}