OPTIONAL: Sinkhole DNS Events Report

LAST UPDATED:  2021-04-01

OPTIONAL REPORT

This report lists DNS queries seen from recursive DNS servers for sinkholed domains. Please note that the IP listed are not the same as the actual source IP of the client that is making the query and hence are likely not infected hosts. This report therefore is to be used primarily to support investigations into a threat, and not as a source of direct identification of infected  hosts.

The Sinkhole DNS Events report is not a default report, you need to explicitly request it.

Filename: event4-sinkhole-dns

Fields

  • timestamp
    Timestamp in UTC+0 of the DNS query
  • protocol
    Protocol of the connection traffic (UDP/TCP)
  • src_ip
    IP of the recursive resolver making the query
  • src_port
    Source port of the query
  • src_asn
    ASN of the recursive resolver
  • src_geo
    Country location of the recursive resolver
  • src_region
    Region of the recursive resolver
  • src_city
    City of the recursive resolver
  • src_hostname
    Reverse DNS of the recursive resolver
  • src_naic
    North American Industry Classification System Code
  • src_sector
    Sector to which the IP in question belongs; e.g. Communications, Commercial
  • device_vendor
    Source device vendor
  • device_type
    Source device type
  • device_model
    Source device model
  • infection
    Description of the malware/infection
  • family
    Malware family or campaign associated with the event
  • tag
    Tagging information, such as information on which threat is associated with the sinkholed domain
  • query_type
    DNS query type (eg. NS, SOA, A)
  • query
    Sinkholed domain name being queried
  • count
    Number of queries seen

Sample

"timestamp","protocol","src_ip","src_port","src_asn","src_geo","src_region","src_city","src_hostname","src_naics","src_sector","device_vendor","device_type","device_model","infection","family","tag","query_type","query","count"
"2021-04-05 00:00:01","udp","34.204.x.x",22732,14618,"US","VIRGINIA","ASHBURN",,454110,"Retail Trade",,,,"avalanche-unknown","avalanche-unknown","avalanche","A","nS1.TEStTeStTesT.COM",1
"2021-04-05 00:00:01","udp","197.155.x.x",54448,30844,"KE","NAIROBI CITY","NAIROBI",,,,,,,"boaxxe","boaxxe","3ve","A","5.k5service.org",1
"2021-04-05 00:00:01","udp","138.246.x.x",47214,12816,"DE","BAYERN","MUNICH",,,"Communications, Service Provider, and Hosting Service",,,,"avalanche-ranbyus","avalanche-ranbyus","avalanche","TYPE65","nsyrpuhwibcindkpf.net",1
"2021-04-05 00:00:01","udp","96.96.x.x",23482,7922,"US","NEW JERSEY","MOUNT LAUREL",,517311,"Communications, Service Provider, and Hosting Service",,,,"unityminer","unityminer","qnap,iot","A","aquamangts.tk",1
"2021-04-05 00:00:01","udp","202.163.x.x",25277,9541,"PK","SINDH - SOUTH","KARACHI",,517919,"Government",,,,"modpack","modpack","modpack","AAAA","76236osm1.ru",1
"2021-04-05 00:00:01","udp","172.253.x.x",38910,15169,"PL","MAZOWIECKIE","WARSAW",,519130,"Communications, Service Provider, and Hosting Service",,,,"ranbyus","ranbyus","ranbyus","AAAA","xdpvetcalkgyqjwqw.org",1

Our 105 Report Types