{"id":42092,"date":"2018-04-18T04:00:00","date_gmt":"2018-04-18T04:00:00","guid":{"rendered":"https:\/\/www.cira.ca\/blog\/weekly-web-security-warning-a-focus-dns-tunneling\/"},"modified":"2023-03-10T10:57:07","modified_gmt":"2023-03-10T15:57:07","slug":"weekly-web-security-warning-a-focus-dns-tunneling","status":"publish","type":"cira_news","link":"https:\/\/www.cira.ca\/en\/resources\/news\/cybersecurity\/weekly-web-security-warning-a-focus-dns-tunneling\/","title":{"rendered":"Weekly web security warning &#8211; a focus on DNS tunneling"},"content":{"rendered":"<p>Every week, we examine the top trends in malicious activity we have seen in Canada using data obtained through CIRA&#8217;s D-Zone DNS Firewall.<\/p>\n<p><!--more--><\/p>\n<p>The top blocked domains this week is a virtual carbon-copy of last week&#8217;s list. If you&#8217;re unfamiliar with some of the threat types, you can read their definitions in <a href=\"\/blog\/cybersecurity\/weekly-web-security-warning-malware-queries-continue-upward-trend\">last week&#8217;s post<\/a>.<\/p>\n<p>Of note this week is that there are three .ru (the Russian ccTLD) domains all related to Trojan downloaders that are used to deliver payloads to machines unlucky enough to be infected. These don&#8217;t necessarily always come through a click on a bad link but can be distributed along with other software like legitimate games or other programs that are downloaded online. It is an important lesson about being careful where you download from.<\/p>\n<h2>Top ten domains blocked last week<\/h2>\n<figure>\n<div>\n<table border=\"1\" cellpadding=\"0\" style=\"width:449px\" width=\"0\">\n<thead>\n<tr>\n<th style=\"width:190px\">\n<p><strong>Domain Name<\/strong><\/p>\n<\/th>\n<th style=\"width:254px\">\n<p><strong>Threat Type<\/strong><\/p>\n<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td style=\"width:190px\">\n<p>superyou.zapto.org<\/p>\n<\/td>\n<td style=\"width:254px\">\n<p>Spybot<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td style=\"width:190px\">\n<p>76236osm1.ru<\/p>\n<\/td>\n<td style=\"width:254px\">\n<p>Trojan downloaders<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td style=\"width:190px\">\n<p>dj1.jfrmt.net<\/p>\n<\/td>\n<td style=\"width:254px\">\n<p>Morto<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td style=\"width:190px\">\n<p>api-restlet.com<\/p>\n<\/td>\n<td style=\"width:254px\">\n<p>Xavier<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td style=\"width:190px\">\n<p>dzhacker15.no-ip.org<\/p>\n<\/td>\n<td style=\"width:254px\">\n<p>Hworm<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td style=\"width:190px\">\n<p>brenz.pl<\/p>\n<\/td>\n<td style=\"width:254px\">\n<p>Suspected malware<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td style=\"width:190px\">\n<p>soplifan.ru<\/p>\n<\/td>\n<td style=\"width:254px\">\n<p>Trojan downloaders<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td style=\"width:190px\">\n<p>diplicano.ru<\/p>\n<\/td>\n<td style=\"width:254px\">\n<p>Trojan downloaders<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td style=\"width:190px\">\n<p>ns6.wowrack.com<\/p>\n<\/td>\n<td style=\"width:254px\">\n<p>Mirai<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td style=\"width:190px\">\n<p>ns5.wowrack.com<\/p>\n<\/td>\n<td style=\"width:254px\">\n<p>Mirai<\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<\/figure>\n<h2>Operating a public Wi-Fi network? Be aware of DNS tunnels<\/h2>\n<p>We took a look at DNS tunnel activity and this one is of particular interest to anyone operating a public Wi-Fi network, typically found at public spaces such as schools, municipalities and hotels. Among D-Zone DNS Firewall users with public networks, we see a high prevalance of DNS tunnel attempts. DNS tunnels can be used to <a href=\"https:\/\/demgeeks.com\/hack-get-free-wifi-on-paid-access-hotspots\/\">go around paid Wi-Fi or login-based Wi-Fi<\/a>. Blocking these queries is therefore quite important to those operating a public Wi-Fi service.<\/p>\n<figure>\n<h3>Tunnels<\/h3>\n<p><img decoding=\"async\" class=\" size-full wp-image-2412\" src=\"https:\/\/www.cira.ca\/uploads\/2018\/04\/D-zone-blog-tunnels.PNG\" alt=\"\" title=\"\" width=\"1249\" height=\"539\" srcset=\"https:\/\/www.cira.ca\/uploads\/2018\/04\/D-zone-blog-tunnels.PNG 1249w, https:\/\/www.cira.ca\/uploads\/2018\/04\/D-zone-blog-tunnels-300x129.png 300w, https:\/\/www.cira.ca\/uploads\/2018\/04\/D-zone-blog-tunnels-1024x442.png 1024w, https:\/\/www.cira.ca\/uploads\/2018\/04\/D-zone-blog-tunnels-768x331.png 768w\" sizes=\"(max-width: 1249px) 100vw, 1249px\" \/><figcaption>\n<p>The total number of queries is hidden from this chart, but we see that they are highly related to a common theme of domains (.in).<\/p>\n<\/figcaption><\/figure>\n<hr \/>\n<p>Learn more about <a href=\"\/cybersecurity-services\/firewall\/d-zone-dns-firewall\">D-Zone DNS Firewall<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Every week, we examine the top trends in malicious activity we have seen in Canada using data obtained through CIRA&#8217;s D-Zone DNS Firewall.<\/p>\n","protected":false},"featured_media":1949,"template":"","meta":{"_acf_changed":false,"content-type":"","inline_featured_image":false,"ngg_post_thumbnail":0,"slim_seo":{"title":"Weekly web security warning - a focus on DNS tunneling - CIRA","description":"Every week, we examine the top trends in malicious activity we have seen in Canada using data obtained through CIRA's D-Zone DNS Firewall. The top blocked domai"},"footnotes":""},"topic":[28],"class_list":["post-42092","cira_news","type-cira_news","status-publish","has-post-thumbnail","hentry","cira_news_type-cira-news-type-blog","cira_topic-cira-topic-cybersecurity","cira_author-rob-williamson"],"publishpress_future_workflow_manual_trigger":{"enabledWorkflows":[]},"_links":{"self":[{"href":"https:\/\/www.cira.ca\/en\/wp-json\/cira\/v1\/news\/42092","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.cira.ca\/en\/wp-json\/cira\/v1\/news"}],"about":[{"href":"https:\/\/www.cira.ca\/en\/wp-json\/wp\/v2\/types\/cira_news"}],"version-history":[{"count":0,"href":"https:\/\/www.cira.ca\/en\/wp-json\/cira\/v1\/news\/42092\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.cira.ca\/en\/wp-json\/wp\/v2\/media\/1949"}],"wp:attachment":[{"href":"https:\/\/www.cira.ca\/en\/wp-json\/wp\/v2\/media?parent=42092"}],"wp:term":[{"taxonomy":"cira_topic","embeddable":true,"href":"https:\/\/www.cira.ca\/en\/wp-json\/cira\/v1\/topic?post=42092"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}