Categorized | Security

Mitigating the DNSTrojan Threat

A few days ago I’ve published a short analysis of a Trojan dropper which I call DNSTrojan (see New Dropper Uses DNS To Communicate). During this week I’ve tried to mitigate the threat by nuking at least some of the DNSTrojan C&C domain names by pointing them to my sinkhole.

In the first attempt I was able to redirect the traffic of the C&C servers to my sinkhole for around 9 hours. Afterwards the cybercriminals propagated a new C&C domain to the infected clients using httpdsconfig.com (the infected clients regularly contacting httpdsconfig.com using DNS to receive a list of C&C domains they should use).

A few hours later I was able to sinkhole the new domain name as well. Below is a chart showing the number of Apache handlers during the time the domain names have pointed to the sinkhole:

As you can see, the sinkhole had a huge server load. In totally, the C&C traffic has been redirected to my sinkhole for 10 hours. During this time I was able to count 23’000 unique IPs hitting the sinkhole. So I estimate the botnet size to 35k-50k unique IPs per day. This seems to be a huge number but in fact this isn’t a really BIG botnet (let’s compare: recently I was able to monitor a botnet which had a size of over 320’000 unique IPs per day).

Below is a chart which shows the botnet Geo location of the Trojan:

During the sinkhole action I was confronted with a unexpected problem: The botnet size wasn’t a problem but the fact that each bot queries the C&C every 30 seconds struggled my server into some performance problems. As you can see on the chart above, it ended with a downtime of the sinkhole server. In cooperation with Shadowserver I’ve now moved the domain names over to the Shadowservers sinkhole which should be able to handle that amount of requests easily.

In the last blog post I’ve published a list of C&C domains which are associated with the Trojan. Below is a updated list with additional domain names which I’ve came across so fare:

counterslocal.com
httpdsconfig.com
httpsquer.com
httpconfig.com
httpsbee.in
httpsgate.in
httpsget.in
httpsload.in
httpsport.in
httpssite.in
httpssresrun.com
httpsstarss.in
httpssun.in
httpstatsconfig.com
httpsxy.in
httpslink.in
httpszero.in
newsafetyplace.com
securitysoftwaretechltd2010.com

Another interesting find which I’ve made during the sinkholing action is that the cybercriminals are obviously using some kind of monitoring server. They periodically calling a PHP file called check.php on the C&C domain names to check whether the servers are still accessible:

95.143.192.14 “HEAD /check.php HTTP/1.1″ 200 “curl/7.18.2 (x86_64-pc-linux-gnu) libcurl/7.18.2 OpenSSL/0.9.8g zlib/1.2.3.3 libidn/1.8 libssh2/0.18″
94.75.197.209 “HEAD /check.php HTTP/1.1″ 200 “curl/7.18.2 (x86_64-pc-linux-gnu) libcurl/7.18.2 OpenSSL/0.9.8g zlib/1.2.3.3 libidn/1.8 libssh2/0.18″ “

The two monitoring servers are located in Sweden and the Netherlands:

IP address: 95.143.192.14
AS number: AS49770
AS name: SERVERCONNECT-AS ServerConnect Sweden AB
Country: Sweden

IP address: 94.75.197.209
AS number: AS16265
AS name: LEASEWEB AS
Country: Netherlands

If we put the things together we can draw the following picture:

As shown above, the C&C servers are obviously just acting as nginx proxies which are redirecting the to the real mothership (which is currently unknown). Here is the list of nginx proxies which I’ve identified so far:

69.197.147.186 | US | AS32097 | WII-KC – WholeSale Internet, Inc.
69.197.147.187 | US | AS32097 | WII-KC – WholeSale Internet, Inc.
69.197.147.188 | US | AS32097 | WII-KC – WholeSale Internet, Inc.
69.197.147.189 | US | AS32097 | WII-KC – WholeSale Internet, Inc.
69.197.147.190 | US | AS32097 | WII-KC – WholeSale Internet, Inc.
204.12.223.186 | US | AS32097 | WII-KC – WholeSale Internet, Inc.
204.12.223.187 | US | AS32097 | WII-KC – WholeSale Internet, Inc.
204.12.223.188 | US | AS32097 | WII-KC – WholeSale Internet, Inc.
204.12.223.190 | US | AS32097 | WII-KC – WholeSale Internet, Inc.

Let’s see where they are moving to during the next few days…

Bookmark, tagg it or email it to a friend:

View full post on abuse.ch

Related Posts
  • Touchy Security Topics: Insider Threat
    Information security professionals often disagree on the prevalence of insider threat with respect to attacks that originate from outside of the organization. Let’s explore why that might be the case ...
  • Touchy Security Topics: Advanced Persistent Threat (APT)
    Several topics seem to cause a stir when mentioned among information security professionals and are sometimes avoided in conversations altogether. And no, I am not referring to sex, religion and polit...
  • Battling the Zbot Threat (with MSRT)
    Hello Internet! As you may recall, last October we updated MSRT to include the well-known malware Zbot (aka Zeus), one of the more prolific bots we see in the wild today. Today, we released a special-...
  • Security Threat Report 2011 web seminar – now online
    Last month Sophos published its annual threat report, looking back over the biggest security stories of 2010 and ahead to some of the challenges companies may face in protecting their systems in the y...
  • High-level Attention on the Growing Cyber Crime Threat
    A couple of weeks ago we warned that small businesses and local governments are being ripped off by online thieves who have learned to tap into commercial bank accounts by infecting computers with cri...
  • This Month in the Threat Webscape – December 2010
    This Month In The Threat Webscape - Monthly roundup for December 2010...(read more) Full story: Security Labs...
  • This Month in the Threat Webscape – November 2010
    Month of November Major Hits Amnesty International's Web site in Hong Kong was compromised and was attempting to infect its visitors using various exploits for Adobe Flash, Adobe Shockwave, Apple...
  • Analysis: IT Threat Evolution for Q3-2010
    The third quarter of 2010 turned out to be more eventful than the preceding quarter. Over 600 million attempts to infect users’ computers with malicious and potentially unwanted programs were ...
  • Trend Micro 2011 Threat Predictions
    With the growing diversity of operating systems among companies, as well as the growing use of mobile devices, cybercriminals should have a very profitable 2011. Their tactic will be to put a new spi...
  • Cyber Threat Analysis Center news
    This blog has always been research-oriented. Not that we don't cover such issues as product information when appropriate, but we figure that in general, our readers don't look here for t...

One Response to “Mitigating the DNSTrojan Threat”

  1. ax0n says:

    Those C&C Proxies are in a cheap-ass data center a few miles away from me!

Trackbacks/Pingbacks


Security Status

Beware Facebook "Timeline" scams http://t.co/W5EW0cVv
5 months ago
Nigerian government (unknowingly) hosts phishing website http://t.co/uQd42ENw
5 months ago
PCMag Awards McAfee All Access its Editors’ Choice: SANTA CLARA, Calif.--(BUSINESS WIRE)--McAfee today announced... http://t.co/FakV7Vd8
5 months ago
RT @mikko: I hadn't noticed Google Maps has added 3D models of buildings. Here's a (very accurate) view of F-Secure HQ in Helsinki http://t.co/IKfAZlak
5 months ago
North Koreans aren't known for their online presence. But others may be lured into clicking Kim Jong-Il 'videos' too http://t.co/yQOon6YT
5 months ago
How to Protect Your Professional Reputation on Facebook Timeline http://t.co/I4bcR2VN
5 months ago
This is pretty impressive from @Softpedia: Facebook scans 2 trillion link clicks and blocks 220 million posts each day http://t.co/vKsn9gNl
5 months ago
Need for integrated approach to security in industrial control systems - http://t.co/tPBCNOow with @PikeResearch
5 months ago
Some free-based music we play at work http://t.co/xu5agZfc
5 months ago
Japan’s cyber defense weapon: a virus. It includes quotes by @Luis_Corrons via @InfosecurityMag
5 months ago