External IP Lookup from Non-Browser Processedit

Identifies domains commonly used by adversaries for post-exploitation IP lookups. It is common for adversaries to test for Internet access and acquire their external IP address after they have gained access to a system. Among others, this has been observed in campaigns leveraging the information stealer, Trickbot.

Rule type: eql

Rule indices:

  • winlogbeat-*
  • logs-endpoint.events.*
  • logs-windows.*

Severity: low

Risk score: 21

Runs every: 5 minutes

Searches indices from: now-9m (Date Math format, see also Additional look-back time)

Maximum alerts per execution: 100

References:

Tags:

  • Elastic
  • Host
  • Windows
  • Threat Detection
  • Discovery

Version: 6 (version history)

Added (Elastic Stack release): 7.10.0

Last modified (Elastic Stack release): 7.15.0

Rule authors: Elastic

Rule license: Elastic License v2

Potential false positivesedit

If the domains listed in this rule are used as part of an authorized workflow, this rule will be triggered by those events. Validate that this is expected activity and tune the rule to fit your environment variables.

Rule queryedit

network where network.protocol == "dns" and process.name != null
and user.id not in ("S-1-5-19", "S-1-5-20") and event.action ==
"lookup_requested" and /* Add new external IP lookup services here
*/ dns.question.name : ( "*api.ipify.org",
"*freegeoip.app", "*checkip.amazonaws.com",
"*checkip.dyndns.org", "*freegeoip.app",
"*icanhazip.com", "*ifconfig.*", "*ipecho.net",
"*ipgeoapi.com", "*ipinfo.io", "*ip.anysrc.net",
"*myexternalip.com", "*myipaddress.com",
"*showipaddress.com", "*whatismyipaddress.com",
"*wtfismyip.com", "*ipapi.co", "*ip-lookup.net",
"*ipstack.com" ) and /* Insert noisy false positives here */
not process.executable : ( "?:\\Program Files\\*.exe",
"?:\\Program Files (x86)\\*.exe",
"?:\\Windows\\System32\\WWAHost.exe",
"?:\\Windows\\System32\\smartscreen.exe",
"?:\\Windows\\System32\\MicrosoftEdgeCP.exe",
"?:\\ProgramData\\Microsoft\\Windows
Defender\\Platform\\*\\MsMpEng.exe", "?:\\Users\\*\\AppData\\Loc
al\\Google\\Chrome\\Application\\chrome.exe",
"?:\\Users\\*\\AppData\\Local\\Programs\\Fiddler\\Fiddler.exe",
"?:\\Users\\*\\AppData\\Local\\Programs\\Microsoft VS Code\\Code.exe",
"?:\\Users\\*\\AppData\\Local\\Microsoft\\OneDrive\\OneDrive.exe"
)

Threat mappingedit

Framework: MITRE ATT&CKTM

Rule version historyedit

Version 6 (7.15.0 release)
  • Rule name changed from: External IP Lookup fron Non-Browser Process
Version 5 (7.14.0 release)
  • Updated query, changed from:

    network where network.protocol == "dns" and process.name != null
    and user.id not in ("S-1-5-19", "S-1-5-20") and event.action ==
    "lookup_requested" and /* Add new external IP lookup services here
    */ dns.question.name : ( "*api.ipify.org",
    "*freegeoip.app", "*checkip.amazonaws.com",
    "*checkip.dyndns.org", "*freegeoip.app",
    "*icanhazip.com", "*ifconfig.*", "*ipecho.net",
    "*ipgeoapi.com", "*ipinfo.io", "*ip.anysrc.net",
    "*myexternalip.com", "*myipaddress.com",
    "*showipaddress.com", "*whatismyipaddress.com",
    "*wtfismyip.com" ) and /* Insert noisy false positives here */
    not process.executable : ( "?:\\Program Files\\*.exe",
    "?:\\Program Files (x86)\\*.exe",
    "?:\\Windows\\System32\\WWAHost.exe",
    "?:\\Windows\\System32\\smartscreen.exe",
    "?:\\Windows\\System32\\MicrosoftEdgeCP.exe",
    "?:\\ProgramData\\Microsoft\\Windows
    Defender\\Platform\\*\\MsMpEng.exe", "?:\\Users\\*\\AppData\\Loc
    al\\Google\\Chrome\\Application\\chrome.exe",
    "?:\\Users\\*\\AppData\\Local\\Programs\\Fiddler\\Fiddler.exe",
    "?:\\Users\\*\\AppData\\Local\\Programs\\Microsoft VS Code\\Code.exe",
    "?:\\Users\\*\\AppData\\Local\\Microsoft\\OneDrive\\OneDrive.exe"
    )
Version 4 (7.13.0 release)
  • Rule name changed from: Public IP Reconnaissance Activity
  • Updated query, changed from:

    event.category:network AND event.type:connection AND
    server.domain:(ipecho.net OR ipinfo.io OR ifconfig.co OR ifconfig.me
    OR icanhazip.com OR myexternalip.com OR api.ipify.org OR
    bot.whatismyipaddress.com OR ip.anysrc.net OR wtfismyip.com) AND NOT
    http.response.status_code:302 AND status:OK AND NOT
    _exists_:http.request.referrer
Version 3 (7.12.0 release)
  • Formatting only
Version 2 (7.11.2 release)
  • Formatting only