Anzeige
Mehr »
Sonntag, 07.09.2025 - Börsentäglich über 12.000 News
Tokenisierung entfesselt: Republic führt die Ethereum-Revolution
Anzeige

Indizes

Kurs

%
News
24 h / 7 T
Aufrufe
7 Tage

Aktien

Kurs

%
News
24 h / 7 T
Aufrufe
7 Tage

Xetra-Orderbuch

Fonds

Kurs

%

Devisen

Kurs

%

Rohstoffe

Kurs

%

Themen

Kurs

%

Erweiterte Suche
PR Newswire
844 Leser
Artikel bewerten:
(2)

Infoblox Inc.: Infoblox Uncovers DNS Malware Toolkit & Urges Companies to Block Malicious Domains

  • Infoblox releases report findings on "Decoy Dog" and collaborates across the industry to help raise awareness and problem solve
  • Command-and-control (C2) domain over DNS went undiscovered for a year as part of a single toolkit
  • Threat spotlights dangers of malware traffic on networks and importance of a DNS security strategy
  • Infoblox BloxOne® Threat Defense protects customers from these suspicious C2 domains

SANTA CLARA, Calif., April 20, 2023 /PRNewswire/ -- Infoblox Inc. the company that delivers a simplified, cloud- enabled networking and security platform for improved performance and protection, today published a threat report blog on a remote access trojan (RAT) toolkit with DNS command and control (C2). The toolkit created an anomalous DNS signature observed in enterprise networks in the U.S., Europe, South America, and Asia across technology, healthcare, energy, financial and other sectors. Some of these communications go to a controller in Russia.

Infoblox Uncovers DNS Malware Toolkit & Urges Companies to Block Malicious Domains

Coined "Decoy Dog," Infoblox's Threat Intelligence Group was the first to discover this toolkit and is collaborating with other security vendors, as well as customers, to disrupt this activity, identify the attack vector, and secure global networks. The critical insight is that DNS anomalies measured over time not only surfaced the RAT, but ultimately tied together seemingly independent C2 communications. A technical analysis of Infoblox's findings is here.

"Decoy Dog is a stark reminder of the importance of having a strong, protective DNS strategy," said Renée Burton, Senior Director of Threat Intelligence for Infoblox. "Infoblox is focused on detecting threats in DNS, disrupting attacks before they start, and allowing customers to focus on their own business."

As a specialized DNS-based security vendor, Infoblox tracks adversary infrastructure and can see suspicious activity early in the threat lifecycle, where there is "intent to compromise' and before the actual attack starts. As a normal course of business, any indicators that are deemed suspicious are included in Infoblox's Suspicious domain feeds, direct to customers, to help them preemptively protect themselves against new and emerging threats.

Threat Discovery, Anatomy & Mitigation:

  • Infoblox discovered activity from the remote access trojan (RAT) Pupy active in multiple enterprise networks in early April 2023. This C2 communication went undiscovered since April 2022.

  • The RAT was detected from anomalous DNS activity on limited networks and in network devices such as firewalls; not user devices such as laptops or mobile devices.

  • The RAT creates a footprint in DNS that is extremely hard to detect in isolation but, when analyzed in a global cloud-based protective DNS system like Infoblox's BloxOne® Threat Defense, demonstrates strong outlier behavior. Further it allowed Infoblox to tie the disparate domains together.

  • C2 communications are made over DNS and are based on an open-source RAT called Pupy. While this is an open-source project, it has been consistently associated with nation-state actors.

  • Organizations with protective DNS can mitigate their risk. BloxOne Threat Defense customers are protected from these suspicious domains.

  • In this case, Russian C2 domains were already included in the Suspicious domains feeds in BloxOne Threat Defense (Advanced) back in the fall of 2022. In addition to the Suspicious Domains feed, these domains have now been added to Infoblox's anti-malware feed.

  • Infoblox continues to urge organizations to block the following domains:
    • claudfront.net
    • allowlisted.net
    • atlas-upd.com
    • ads-tm-glb.click
    • cbox4.ignorelist.com
    • hsdps.cc

"While we automatically detect thousands of suspicious domains every day at the DNS level - and with this level of correlation, it's rare to discover these activities all originating from the same toolkit leveraging DNS for command-and-control," added Burton.

The Infoblox team is working around the clock to understand the DNS activity. Complex problems like this one highlight the need for an industry-wide intelligence-in-depth strategy where everyone contributes to understanding the entire scope of a threat.

For the full threat summary titled "Dog Hunt: Finding Decoy Dog Toolkit via Anomalous DNS Traffic" click here.

About Infoblox's Threat Intelligence Group:
The Threat Intelligence Group at Infoblox is dedicated to creating high fidelity "block-and-forget" domain name service (DNS) intelligence data for use in BloxOne Threat Defense. Core to Infoblox's protection strategy is the identification of suspicious domains. Infoblox's Threat Intelligence Group uses a patented machine learning algorithm to minimize the risk of enterprise outages while enabling maximum coverage of threats. Infoblox identifies suspicious domains through several custom-built algorithms and DNS based threat hunting.

The organization focuses on DNS and infrastructure actors. The team can identify suspicious behavior before its impact is known by the adjacent areas of the industry (endpoint, netflow vendors), and can track persistent actors to block their DNS infrastructure before it becomes a problem for our customers. Threat actors often register domains well in advance of using them for attacks, typically 14-120 days in advance, but we have seen domains held dormant for upwards of two years - like this case in point.

About Infoblox
Infoblox unites networking and security to deliver unmatched performance and protection. Trusted by Fortune 100 companies and emerging innovators, we provide real-time visibility and control over who and what connects to your network, so your organization runs faster and stops threats earlier. Visit infoblox.com, or follow-us on LinkedIn or Twitter.

Media Contacts
Ashley Kusowski
Head of Corporate Communications

Hannah Mautz
Account Supervisor
infoblox@ruderfinn.com

Infoblox's New Logo

Photo - https://mma.prnewswire.com/media/2059745/Infoblox_Inc.jpg
Logo - https://mma.prnewswire.com/media/2057499/Infoblox_NEW_Logo.jpg

Cision View original content:https://www.prnewswire.co.uk/news-releases/infoblox-uncovers-dns-malware-toolkit--urges-companies-to-block-malicious-domains-301803662.html

© 2023 PR Newswire
Solarbranche vor dem Mega-Comeback?
Lange galten Solaraktien als Liebling der Börse, dann kam der herbe Absturz: Zinsschock, Überkapazitäten aus China und ein Preisverfall, der selbst Marktführer wie SMA Solar, Enphase Energy oder SolarEdge massiv unter Druck setzte. Viele Anleger haben der Branche längst den Rücken gekehrt.

Doch genau das könnte jetzt die Chance sein!
Die Kombination aus KI-Explosion und Energiewende bringt die Branche zurück ins Rampenlicht:
  • Rechenzentren verschlingen Megawatt – Solarstrom bietet den günstigsten Preis je Kilowattstunde
  • Moderne Module liefern Wirkungsgrade wie Atomkraftwerke
  • hina bremst Preisdumping & pusht massiv den Ausbau
Gleichzeitig locken viele Solar-Aktien mit historischen Tiefstständen und massiven Short-Quoten, ein perfekter Nährboden für Kursrebound und Squeeze-Rally.

In unserem exklusiven Gratis-Report zeigen wir dir, welche 4 Solar-Aktien besonders vom Comeback profitieren dürften und warum jetzt der perfekte Zeitpunkt für einen Einstieg sein könnte.

Laden Sie jetzt den Spezialreport kostenlos herunter, bevor die Erholung am Markt beginnt!

Dieses Angebot gilt nur für kurze Zeit – also nicht zögern, jetzt sichern!
Werbehinweise: Die Billigung des Basisprospekts durch die BaFin ist nicht als ihre Befürwortung der angebotenen Wertpapiere zu verstehen. Wir empfehlen Interessenten und potenziellen Anlegern den Basisprospekt und die Endgültigen Bedingungen zu lesen, bevor sie eine Anlageentscheidung treffen, um sich möglichst umfassend zu informieren, insbesondere über die potenziellen Risiken und Chancen des Wertpapiers. Sie sind im Begriff, ein Produkt zu erwerben, das nicht einfach ist und schwer zu verstehen sein kann.