Possible DNS Queries to Public Ethereum RPC Endpoints for EtherHiding Payload Retrieval (via dns_query)

PremiumReviewedSigma · Low · v1
Product
windows
Category
dns_query
Author
HuntRule
Published
2026-09-01
Updated
2026-09-01

ATT&CK techniques

C2
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Discovery

  10. Lateral Movement

  11. Collection

  12. Exfiltration

  13. Impact

What it detects

This rule detects DNS resolution of public Ethereum RPC provider domains queried by EtherRAT to read its command and control configuration from a smart contract using the EtherHiding technique. Adversaries leverage blockchain RPC endpoints as a resilient dead drop that resists takedown while blending with legitimate crypto traffic, making this a heuristic signal worth reviewing on hosts with no expected blockchain activity.

Related detections5 linkedT1102.001 — drag to rearrange
Suspicious Command and Control via Discord or Telegram Bot API
Windows Network Connections to azurewebsites.net from Non-Browser Processes
Windows Executable Connections to Dead Drop Resolver Domains Excluding Common Browsers
Proxy Downloads Containing /pwndrop/ (PwnDrp Web Server)
Proxy access to raw paste endpoints on paste.ee and Pastebin-style services
Possible DNS Queries to Public Ethereum RPC Endpoints for EtherHiding Payload Retrieval (via dns_query)
Pivot detection · T1102.001 · 5 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.