Zeek DNS Lookups for Known Cryptocurrency Mining Pool Domains

Alert on Zeek DNS queries ending in mining-pool-related domains, excluding local/rejected answers.

FreeUnreviewedSigmalowv1
title: Zeek DNS Lookups for Known Cryptocurrency Mining Pool Domains
id: 5151c346-7996-4707-8297-c2b4018b2bd0
status: test
description: This rule flags DNS query activity where the queried name ends with domains commonly associated with cryptocurrency mining pools. Such lookups can indicate host participation in mining-related infrastructure or attempts to reach mining services using domain-based discovery. It relies on Zeek DNS logs capturing the query name and query outcomes, and applies exclusions for local resolver answers and rejected lookups to reduce noise.
references:
  - https://github.com/Azure/Azure-Sentinel/blob/fa0411f9424b6c47b4d5a20165e4f1b168c1f103/Detections/ASimDNS/imDNS_Miners.yaml
  - https://github.com/SigmaHQ/sigma/blob/master/rules/network/zeek/zeek_dns_mining_pools.yml
author: Saw Winn Naung, Azure-Sentinel, @neu5ron, Huntrule Team
date: 2021-08-19
modified: 2022-07-07
tags:
  - attack.execution
  - attack.t1569.002
  - attack.impact
  - attack.t1496
logsource:
  service: dns
  product: zeek
detection:
  selection:
    query|endswith:
      - monerohash.com
      - do-dear.com
      - xmrminerpro.com
      - secumine.net
      - xmrpool.com
      - minexmr.org
      - hashanywhere.com
      - xmrget.com
      - mininglottery.eu
      - minergate.com
      - moriaxmr.com
      - multipooler.com
      - moneropools.com
      - xmrpool.eu
      - coolmining.club
      - supportxmr.com
      - minexmr.com
      - hashvault.pro
      - xmrpool.net
      - crypto-pool.fr
      - xmr.pt
      - miner.rocks
      - walpool.com
      - herominers.com
      - gntl.co.uk
      - semipool.com
      - coinfoundry.org
      - cryptoknight.cc
      - fairhash.org
      - baikalmine.com
      - tubepool.xyz
      - fairpool.xyz
      - asiapool.io
      - coinpoolit.webhop.me
      - nanopool.org
      - moneropool.com
      - miner.center
      - prohash.net
      - poolto.be
      - cryptoescrow.eu
      - monerominers.net
      - cryptonotepool.org
      - extrmepool.org
      - webcoin.me
      - kippo.eu
      - hashinvest.ws
      - monero.farm
      - linux-repository-updates.com
      - 1gh.com
      - dwarfpool.com
      - hash-to-coins.com
      - pool-proxy.com
      - hashfor.cash
      - fairpool.cloud
      - litecoinpool.org
      - mineshaft.ml
      - abcxyz.stream
      - moneropool.ru
      - cryptonotepool.org.uk
      - extremepool.org
      - extremehash.com
      - hashinvest.net
      - unipool.pro
      - crypto-pools.org
      - monero.net
      - backup-pool.com
      - mooo.com
      - freeyy.me
      - cryptonight.net
      - shscrypto.net
  exclude_answers:
    answers:
      - 127.0.0.1
      - 0.0.0.0
  exclude_rejected:
    rejected: "true"
  condition: selection and not 1 of exclude_*
falsepositives:
  - A DNS lookup does not necessarily  mean a successful attempt, verify a) if there was a response using the zeek answers field, if there was then verify the connections (conn.log) to those IPs. b) verify if HTTP, SSL, or TLS activity to the domain that was queried. http.log field is 'host' and ssl/tls is 'server_name'.
level: low
license: DRL-1.1
related:
  - id: bf74135c-18e8-4a72-a926-0e4f47888c19
    type: derived

What it detects

This rule flags DNS query activity where the queried name ends with domains commonly associated with cryptocurrency mining pools. Such lookups can indicate host participation in mining-related infrastructure or attempts to reach mining services using domain-based discovery. It relies on Zeek DNS logs capturing the query name and query outcomes, and applies exclusions for local resolver answers and rejected lookups to reduce noise.

Known false positives

  • A DNS lookup does not necessarily mean a successful attempt, verify a) if there was a response using the zeek answers field, if there was then verify the connections (conn.log) to those IPs. b) verify if HTTP, SSL, or TLS activity to the domain that was queried. http.log field is 'host' and ssl/tls is 'server_name'.

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.