Windows Network Connections to External IP Lookup Service APIs
Alerts on non-browser outbound connections from Windows hosts to public IP lookup API domains.
FreeUnreviewedSigmamediumv1
windows-network-connections-to-external-ip-lookup-service-apis-edf3485d
title: Windows Network Connections to External IP Lookup Service APIs
id: 69703635-e88b-4167-ab4a-797c7b0ad1bc
related:
- id: ec82e2a5-81ea-4211-a1f8-37a0286df2c2
type: derived
- id: edf3485d-dac4-4d50-90e4-b0e5813f7e60
type: derived
status: test
description: This rule flags Windows processes making outbound network connections to known external IP lookup and geolocation API hostnames (for example api.ipify.org and ipinfo.io). Attackers may use these services to discover the source public IP during reconnaissance or post-compromise connectivity testing. The detection relies on network_connection telemetry identifying DestinationHostname matches, while excluding common browser executables to focus on non-browser activity.
references:
- https://github.com/rsp/scripts/blob/c8bb272d68164a9836e4f273d8f924927f39b8c6/externalip-benchmark.md
- https://www.cisa.gov/news-events/cybersecurity-advisories/aa20-302a
- https://thedfirreport.com/2022/11/28/emotet-strikes-again-lnk-file-leads-to-domain-wide-ransomware/
- https://www.trendmicro.com/en_us/research/23/e/managed-xdr-investigation-of-ducktail-in-trend-micro-vision-one.html
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/network_connection/net_connection_win_domain_external_ip_lookup.yml
author: Janantha Marasinghe, Nasreddine Bencherchali (Nextron Systems), Huntrule Team
date: 2023-04-24
modified: 2024-03-22
tags:
- attack.discovery
- attack.t1016
logsource:
category: network_connection
product: windows
detection:
selection:
- DestinationHostname:
- www.ip.cn
- l2.io
- DestinationHostname|contains:
- api.2ip.ua
- api.bigdatacloud.net
- api.ipify.org
- bot.whatismyipaddress.com
- canireachthe.net
- checkip.amazonaws.com
- checkip.dyndns.org
- curlmyip.com
- db-ip.com
- edns.ip-api.com
- eth0.me
- freegeoip.app
- geoipy.com
- getip.pro
- icanhazip.com
- ident.me
- ifconfig.io
- ifconfig.me
- ip-api.com
- ip.360.cn
- ip.anysrc.net
- ip.taobao.com
- ip.tyk.nu
- ipaddressworld.com
- ipapi.co
- ipconfig.io
- ipecho.net
- ipinfo.io
- ipip.net
- ipof.in
- ipv4.icanhazip.com
- ipv4bot.whatismyipaddress.com
- ipv6-test.com
- ipwho.is
- jsonip.com
- myexternalip.com
- seeip.org
- wgetip.com
- whatismyip.akamai.com
- whois.pconline.com.cn
- wtfismyip.com
filter_optional_brave:
Image|endswith: \brave.exe
filter_optional_chrome:
Image:
- C:\Program Files\Google\Chrome\Application\chrome.exe
- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
filter_optional_firefox:
Image:
- C:\Program Files\Mozilla Firefox\firefox.exe
- C:\Program Files (x86)\Mozilla Firefox\firefox.exe
filter_optional_ie:
Image:
- C:\Program Files (x86)\Internet Explorer\iexplore.exe
- C:\Program Files\Internet Explorer\iexplore.exe
filter_optional_maxthon:
Image|endswith: \maxthon.exe
filter_optional_edge_1:
- Image|startswith: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\
- Image|endswith: \WindowsApps\MicrosoftEdge.exe
- Image:
- C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
- C:\Program Files\Microsoft\Edge\Application\msedge.exe
filter_optional_edge_2:
Image|startswith:
- C:\Program Files (x86)\Microsoft\EdgeCore\
- C:\Program Files\Microsoft\EdgeCore\
Image|endswith:
- \msedge.exe
- \msedgewebview2.exe
filter_optional_opera:
Image|endswith: \opera.exe
filter_optional_safari:
Image|endswith: \safari.exe
filter_optional_seamonkey:
Image|endswith: \seamonkey.exe
filter_optional_vivaldi:
Image|endswith: \vivaldi.exe
filter_optional_whale:
Image|endswith: \whale.exe
condition: selection and not 1 of filter_optional_*
falsepositives:
- Legitimate use of the external websites for troubleshooting or network monitoring
level: medium
license: DRL-1.1
What it detects
This rule flags Windows processes making outbound network connections to known external IP lookup and geolocation API hostnames (for example api.ipify.org and ipinfo.io). Attackers may use these services to discover the source public IP during reconnaissance or post-compromise connectivity testing. The detection relies on network_connection telemetry identifying DestinationHostname matches, while excluding common browser executables to focus on non-browser activity.
Known false positives
- Legitimate use of the external websites for troubleshooting or network monitoring
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.