id: 70b12a3b-4899-42cb-910c-5ffaf9d7997d
name: Known Barium domains
description: |
‘Identifies a match across various data feeds for domains IOCs related to the Barium activity group.’
severity: High
requiredDataConnectors:
– connectorId: DNS
dataTypes:
– DnsEvents
– connectorId: AzureMonitor(VMInsights)
dataTypes:
– VMConnection
– connectorId: CiscoASA
dataTypes:
– CommonSecurityLog
– connectorId: PaloAltoNetworks
dataTypes:
– CommonSecurityLog
– connectorId: Microsoft 365 Defender
dataTypes:
– DeviceNetworkEvents
queryFrequency: 1d
queryPeriod: 1d
triggerOperator: gt
triggerThreshold: 0
tactics:
– CommandAndControl
query: |
let timeframe = 1d;
let DomainNames = dynamic([“0.ns1.dns-info.gq”, “1.ns1.dns-info.gq”, “10.ns1.dns-info.gq”, “102.ns1.dns-info.gq”,
“104.ns1.dns-info.gq”, “11.ns1.dns-info.gq”, “110.ns1.dns-info.gq”, “115.ns1.dns-info.gq”, “116.ns1.dns-info.gq”,
“117.ns1.dns-info.gq”, “118.ns1.dns-info.gq”, “12.ns1.dns-info.gq”, “120.ns1.dns-info.gq”, “122.ns1.dns-info.gq”,
“123.ns1.dns-info.gq”, “128.ns1.dns-info.gq”, “13.ns1.dns-info.gq”, “134.ns1.dns-info.gq”, “135.ns1.dns-info.gq”,
“138.ns1.dns-info.gq”, “14.ns1.dns-info.gq”, “144.ns1.dns-info.gq”, “15.ns1.dns-info.gq”, “153.ns1.dns-info.gq”,
“157.ns1.dns-info.gq”, “16.ns1.dns-info.gq”, “17.ns1.dns-info.gq”, “18.ns1.dns-info.gq”, “19.ns1.dns-info.gq”,
“1a9604fa.ns1.feedsdns.com”, “1c7606b6.ns1.steamappstore.com”, “2.ns1.dns-info.gq”, “20.ns1.dns-info.gq”,
“201.ns1.dns-info.gq”, “202.ns1.dns-info.gq”, “204.ns1.dns-info.gq”, “207.ns1.dns-info.gq”, “21.ns1.dns-info.gq”,
“210.ns1.dns-info.gq”, “211.ns1.dns-info.gq”, “216.ns1.dns-info.gq”, “22.ns1.dns-info.gq”, “220.ns1.dns-info.gq”,
“223.ns1.dns-info.gq”, “23.ns1.dns-info.gq”, “24.ns1.dns-info.gq”, “25.ns1.dns-info.gq”, “26.ns1.dns-info.gq”,
“27.ns1.dns-info.gq”, “28.ns1.dns-info.gq”, “29.ns1.dns-info.gq”, “3.ns1.dns-info.gq”, “30.ns1.dns-info.gq”,
“31.ns1.dns-info.gq”, “32.ns1.dns-info.gq”, “33.ns1.dns-info.gq”, “34.ns1.dns-info.gq”, “35.ns1.dns-info.gq”,
“36.ns1.dns-info.gq”, “37.ns1.dns-info.gq”, “39.ns1.dns-info.gq”, “3d6fe4b2.ns1.steamappstore.com”,
“4.ns1.dns-info.gq”, “40.ns1.dns-info.gq”, “42.ns1.dns-info.gq”, “43.ns1.dns-info.gq”, “44.ns1.dns-info.gq”,
“45.ns1.dns-info.gq”, “46.ns1.dns-info.gq”, “48.ns1.dns-info.gq”, “5.ns1.dns-info.gq”, “50.ns1.dns-info.gq”,
“50417.service.gstatic.dnset.com”, “51.ns1.dns-info.gq”, “52.ns1.dns-info.gq”, “53.ns1.dns-info.gq”,
“54.ns1.dns-info.gq”, “55.ns1.dns-info.gq”, “56.ns1.dns-info.gq”, “57.ns1.dns-info.gq”, “58.ns1.dns-info.gq”,
“6.ns1.dns-info.gq”, “60.ns1.dns-info.gq”, “62.ns1.dns-info.gq”, “63.ns1.dns-info.gq”, “64.ns1.dns-info.gq”,
“65.ns1.dns-info.gq”, “67.ns1.dns-info.gq”, “7.ns1.dns-info.gq”, “70.ns1.dns-info.gq”, “71.ns1.dns-info.gq”,
“73.ns1.dns-info.gq”, “77.ns1.dns-info.gq”, “77075.service.gstatic.dnset.com”, “7c1947fa.ns1.steamappstore.com”,
“8.ns1.dns-info.gq”, “81.ns1.dns-info.gq”, “86.ns1.dns-info.gq”, “87.ns1.dns-info.gq”, “9.ns1.dns-info.gq”,
“94343.service.gstatic.dnset.com”, “9939.service.gstatic.dnset.com”, “aa.ns.mircosoftdoc.com”,
“aaa.feeds.api.ns1.feedsdns.com”, “aaa.googlepublic.feeds.ns1.dns-info.gq”,
“aaa.resolution.174547._get.cache.up.sourcedns.tk”, “acc.microsoftonetravel.com”,
“accounts.longmusic.com”, “admin.dnstemplog.com”, “agent.updatenai.com”,
“alibaba.zzux.com”, “api.feedsdns.com”, “app.portomnail.com”, “asia.updatenai.com”,
“battllestategames.com”, “bguha.serveuser.com”, “binann-ce.com”, “bing.dsmtp.com”,
“blog.cdsend.xyz”, “brives.minivineyapp.com”, “bsbana.dynamic-dns.net”,
“californiaforce.000webhostapp.com”, “californiafroce.000webhostapp.com”,
“cdn.freetcp.com”, “cdsend.xyz”, “cipla.zzux.com”, “cloudfeeddns.com”, “comcleanner.info”,
“cs.microsoftsonline.net”, “dns-info.gq”, “dns05.cf”, “dns22.ml”, “dns224.com”,
“dnsdist.org”, “dnstemplog.com”, “doc.mircosoftdoc.com”, “dropdns.com”,
“eshop.cdn.freetcp.com”, “exchange.dumb1.com”, “exchange.misecure.com”, “exchange.mrbasic.com”,
“facebookdocs.com”, “facebookint.com”, “facebookvi.com”, “feed.ns1.dns-info.gq”, “feedsdns.com”,
“firejun.freeddns.com”, “ftp.dns-info.dyndns.pro”, “goallbandungtravel.com”, “goodhk.azurewebsites.net”,
“googlepublic.feed.ns1.dns-info.gq”, “gp.spotifylite.cloud”, “gskytop.com”, “gstatic.dnset.com”,
“gxxservice.com”, “helpdesk.cdn.freetcp.com”, “id.serveuser.com”, “infestexe.com”, “item.itemdb.com”,
“m.mircosoftdoc.com”, “mail.transferdkim.xyz”, “mcafee.updatenai.com”, “mecgjm.mircosoftdoc.com”,
“microdocs.ga”, “microsock.website”, “microsocks.net”, “microsoft.sendsmtp.com”,
“microsoftbook.dns05.com”, “microsoftcontactcenter.com”, “microsoftdocs.dns05.com”, “microsoftdocs.ml”,
“microsoftonetravel.com”, “microsoftonlines.net”, “microsoftprod.com”, “microsofts.dns1.us”, “microsoftsonline.net”,
“minivineyapp.com”, “mircosoftdoc.com”, “mircosoftdocs.com”, “mlcrosoft.ninth.biz”, “mlcrosoft.site”,
“mm.portomnail.com”, “msdnupdate.com”, “msecdn.cloud”, “mtnl1.dynamic-dns.net”, “ns.gstatic.dnset.com”,
“ns.microsoftprod.com”, “ns.steamappstore.com”, “ns1.cdn.freetcp.com”, “ns1.comcleanner.info”, “ns1.dns-info.gq”,
“ns1.dns05.cf”, “ns1.dnstemplog.com”, “ns1.dropdns.com”, “ns1.microsoftonetravel.com”,
“ns1.microsoftonlines.net”, “ns1.microsoftprod.com”, “ns1.microsoftsonline.net”, “ns1.mlcrosoft.site”,
“ns1.teams.wikaba.com”, “ns1.windowsdefende.com”, “ns2.comcleanner.info”, “ns2.dnstemplog.com”,
“ns2.microsoftonetravel.com”, “ns2.microsoftprod.com”, “ns2.microsoftsonline.net”, “ns2.mlcrosoft.site”,
“ns2.windowsdefende.com”, “ns3.microsoftprod.com”, “ns3.mlcrosoft.site”, “nutrition.mrbasic.com”,
“nutrition.youdontcare.com”, “online.mlcrosoft.site”, “online.msdnupdate.com”, “outlookservce.site”,
“owa.jetos.com”, “owa.otzo.com”, “pornotime.co”, “portomnail.com”,
“post.1a0.066e063ac.7c1947fa.ns1.steamappstore.com”, “pricingdmdk.com”, “prod.microsoftprod.com”,
“product.microsoftprod.com”, “ptcl.yourtrap.com”, “query.api.sourcedns.tk”, “rb.itemdb.com”, “redditcdn.com”,
“rss.otzo.com”, “secure.msdnupdate.com”, “service.dns22.ml”, “service.gstatic.dnset.com”, “service04.dns04.com”,
“settings.teams.wikaba.com”, “sip.outlookservce.site”, “sixindent.epizy.com”, “soft.msdnupdate.com”, “sourcedns.ml”,
“sourcedns.tk”, “sport.msdnupdate.com”, “spotifylite.cloud”, “static.misecure.com”, “steamappstore.com”,
“store.otzo.com”, “survey.outlookservce.site”, “team.itemdb.com”, “temp221.com”, “test.microsoftprod.com”,
“thisisaaa.000webhostapp.com”, “token.dns04.com”, “token.dns05.com”, “transferdkim.xyz”,
“travelsanignacio.com”, “update08.com”, “updated08.com”, “updatenai.com”, “wantforspeed.com”,
“web.mircosoftdoc.com”, “webmail.pornotime.co”, “webwhois.team.itemdb.com”, “windowsdefende.com”, “wnswindows.com”,
“ashcrack.freetcp.com”, “battllestategames.com”, “binannce.com”, “cdsend.xyz”, “comcleanner.info”, “microsock.website”,
“microsocks.net”, “microsoftsonline.net”, “mlcrosoft.site”, “notify.serveuser.com”, “ns1.microsoftprod.com”,
“ns2.microsoftprod.com”, “pricingdmdk.com”, “steamappstore.com”, “update08.com”, “wnswindows.com”,
“youtube.dns05.com”, “z1.zalofilescdn.com”, “z2.zalofilescdn.com”, “zalofilescdn.com”]);
(union isfuzzy=true
(CommonSecurityLog
| where TimeGenerated >= ago(timeframe)
| parse Message with * ‘(‘ DNSName ‘)’ *
| where DNSName in~ (DomainNames)
| extend Account = SourceUserID, Computer = DeviceName, IPAddress = DestinationIP
),
(DnsEvents
| where TimeGenerated >= ago(timeframe)
| extend DNSName = Name
| where isnotempty(DNSName)
| where DNSName in~ (DomainNames)
| extend IPAddress = ClientIP
),
(VMConnection
| where TimeGenerated >= ago(timeframe)
| parse RemoteDnsCanonicalNames with * ‘[“‘ DNSName ‘”]’ *
| where isnotempty(DNSName)
| where DNSName in~ (DomainNames)
| extend IPAddress = RemoteIp
),
(
DeviceNetworkEvents
| where isnotempty(RemoteUrl)
| where RemoteUrl in~ (DomainNames)
| extend IPAddress = RemoteIP
| extend Computer = DeviceName
)
)
| extend timestamp = TimeGenerated, AccountCustomEntity = Account, HostCustomEntity = Computer, IPCustomEntity = IPAddress
Recent Comments