Malicious SUNBURST avsvmcloud.com C2 DNS Query

PremiumReviewedSigma · Critical · v1
Product
windows
Category
dns_query
Author
HuntRule
Published
2026-10-02
Updated
2026-10-02

ATT&CK techniques

C2
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Discovery

  10. Lateral Movement

  11. Collection

  12. Exfiltration

  13. Impact

What it detects

This rule detects DNS queries to the avsvmcloud.com domain used by SUNBURST for command-and-control via DGA-generated subdomains resolved through CNAME records. The command-and-control domain is a meaningful campaign constant. Any resolution attempt indicates a compromised SolarWinds Orion host beaconing to the adversary.

Related detections9 linkedT1071.004 — drag to rearrange
Suspicious Cobalt Strike DNS Beacon Default Subdomain Query Linked to Cozy Bear
Suspicious DNS Query to Interactsh OAST Callback Domains
Possible Out-of-Band OAST Callback Domain Resolution via DNS
Possible TrickBot Anchor DNS C2 Registration via HTTP URI (via proxy)
Possible TrickBot DNS Tunneling C2 to westurn.in (via dns_query)
Suspicious SlowStepper DNS TXT C2 Subdomain Lookup via DNS Query
Malicious PIPEDANCE Named Pipe Command and Control Channel via Pipe Created
Suspicious DNS Query for Tor Onion Domain
Possible DNS Tunneling via Excessively Long Query Name
Malicious SUNBURST avsvmcloud.com C2 DNS Query
Pivot detection · T1071.004 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.