Windows DNS Queries for IP Lookup Service Domains from Non-Browser Processes
Flags suspicious DNS lookups to IP-check API domains on Windows when they come from non-browser executables.
- Product
- windows
- Category
- dns_query
- Author
- Brandon George (blog post), Thomas Patzke (SigmaHQ), DRL 1.1
- Published
- 2021-07-08
- Updated
- 2026-07-31
ATT&CK techniques
ReconResource Dev
Initial Access
Execution
Persistence
Priv Esc
Defense Evasion
Cred Access
Discovery
Lateral Movement
Collection
C2
Exfiltration
Impact
What it detects
This rule flags DNS queries on Windows for well-known IP lookup and “what is my IP” service domains, while excluding queries issued by common web browsers. Attackers frequently use these services to detect or validate their outbound public IP and infrastructure during reconnaissance and automation. It relies on Windows DNS query telemetry, matching query names against a fixed list and applying optional process-image exclusions to reduce benign browser activity.
Reporting behind it
- binarydefense.comhttps://www.binarydefense.com/analysis-of-hancitor-when-boring-begets-beacon
- twitter.comhttps://twitter.com/neonprimetime/status/1436376497980428318
- trendmicro.comhttps://www.trendmicro.com/en_us/research/23/e/managed-xdr-investigation-of-ducktail-in-trend-micro-vision-one.html
- github.comhttps://github.com/SigmaHQ/sigma/blob/master/rules/windows/dns_query/dns_query_win_susp_external_ip_lookup.yml
Changelog
v2- v2Candidate ingested via manual entry.2026-07-31
- v1No changelog recorded for this version.2026-07-30
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
title: Windows DNS Queries for IP Lookup Service Domains from Non-Browser Processes
id: aaa21c8d-84cf-4d9f-b2b3-1dea6dbc1894
status: test
description: This rule flags DNS queries on Windows for well-known IP lookup and “what is my IP” service domains, while excluding queries issued by common web browsers. Attackers frequently use these services to detect or validate their outbound public IP and infrastructure during reconnaissance and automation. It relies on Windows DNS query telemetry, matching query names against a fixed list and applying optional process-image exclusions to reduce benign browser activity.
references:
- https://www.binarydefense.com/analysis-of-hancitor-when-boring-begets-beacon
- https://twitter.com/neonprimetime/status/1436376497980428318
- https://www.trendmicro.com/en_us/research/23/e/managed-xdr-investigation-of-ducktail-in-trend-micro-vision-one.html
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/dns_query/dns_query_win_susp_external_ip_lookup.yml
author: Brandon George (blog post), Thomas Patzke, Huntrule Team
date: 2021-07-08
modified: 2024-03-22
tags:
- attack.reconnaissance
- attack.t1590
logsource:
product: windows
category: dns_query
detection:
selection:
- QueryName:
- www.ip.cn
- l2.io
- QueryName|contains:
- api.2ip.ua
- api.bigdatacloud.net
- api.ipify.org
- bot.whatismyipaddress.com
- canireachthe.net
- checkip.amazonaws.com
- checkip.dyndns.org
- curlmyip.com
- db-ip.com
- edns.ip-api.com
- eth0.me
- freegeoip.app
- geoipy.com
- getip.pro
- icanhazip.com
- ident.me
- ifconfig.io
- ifconfig.me
- ip-api.com
- ip.360.cn
- ip.anysrc.net
- ip.taobao.com
- ip.tyk.nu
- ipaddressworld.com
- ipapi.co
- ipconfig.io
- ipecho.net
- ipinfo.io
- ipip.net
- ipof.in
- ipv4.icanhazip.com
- ipv4bot.whatismyipaddress.com
- ipv6-test.com
- ipwho.is
- jsonip.com
- myexternalip.com
- seeip.org
- wgetip.com
- whatismyip.akamai.com
- whois.pconline.com.cn
- wtfismyip.com
filter_optional_brave:
Image|endswith: \brave.exe
filter_optional_chrome:
Image:
- C:\Program Files\Google\Chrome\Application\chrome.exe
- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
filter_optional_firefox:
Image:
- C:\Program Files\Mozilla Firefox\firefox.exe
- C:\Program Files (x86)\Mozilla Firefox\firefox.exe
filter_optional_ie:
Image:
- C:\Program Files (x86)\Internet Explorer\iexplore.exe
- C:\Program Files\Internet Explorer\iexplore.exe
filter_optional_maxthon:
Image|endswith: \maxthon.exe
filter_optional_edge_1:
- Image|startswith: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\
- Image|endswith: \WindowsApps\MicrosoftEdge.exe
- Image:
- C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
- C:\Program Files\Microsoft\Edge\Application\msedge.exe
filter_optional_edge_2:
Image|startswith:
- C:\Program Files (x86)\Microsoft\EdgeCore\
- C:\Program Files\Microsoft\EdgeCore\
Image|endswith:
- \msedge.exe
- \msedgewebview2.exe
filter_optional_opera:
Image|endswith: \opera.exe
filter_optional_safari:
Image|endswith: \safari.exe
filter_optional_seamonkey:
Image|endswith: \seamonkey.exe
filter_optional_vivaldi:
Image|endswith: \vivaldi.exe
filter_optional_whale:
Image|endswith: \whale.exe
condition: selection and not 1 of filter_optional_*
falsepositives:
- Legitimate usage of IP lookup services such as ipify API
level: medium
license: DRL-1.1
related:
- id: ec82e2a5-81ea-4211-a1f8-37a0286df2c2
type: derived