DDNS beaconing to malware site?
Posted: Mon Nov 19, 2012 12:06 pm
So I have configured DDNS and everything seems to be working fine except that I noticed in my OpenDNS logs that my network has been trying to resolve a couple of domains blocked under the category of Proxy/Anonymizer. The first of these 2 domains shows to be malicious per McAfee and Norton's link checkers:
Domain | Requests
cmyip.com 16 <----- Contains drive-by download per Norton's report: http://safeweb.norton.com/report/show?url=cmyip.com
checkmyip.com 10
This seemed weird to me because it didn't seem like that should be happening on my small home network. I checked further and found that OpenDNS logged an abundance of websites that check your IP address, though it didn't block them:
http://www.ip-address.org 10
whatismyip.org 10
http://www.tracemyip.org 17
my-ip-address.com 17
checkip.org 16
myip.dk 16
http://www.ip-1.com 19
automation.whatismyip.com 18
Then it hit me, this must be the DDNS service going out to check my IP address in such a way that it doesn't query my DDNS provider. In the webGUI it puts it like this:
"The check interval specifies how often the router will check whether your current IP matches the one currently associated with your domain name. This check is performed without connecting to your dynamic DNS service provider, which means that this will not cause problems with providers that ban users who connect too frequently (e.g. dyndns.com). However, a network connection is established to perform this check, so this value should not be too low. A check interval between 10 and 20 minutes is usually appropriate."
Does that sound like a correct explanation for the beaconing to all these IP address checker sites? If so, why would Gargoyle talk to this potentially malicious domain? Is it a false-positive? Did the developers just not know that one of the sites they use for checking my IP is kinda iffy?
Please help shed some light on this. Thanks!!
James
Domain | Requests
cmyip.com 16 <----- Contains drive-by download per Norton's report: http://safeweb.norton.com/report/show?url=cmyip.com
checkmyip.com 10
This seemed weird to me because it didn't seem like that should be happening on my small home network. I checked further and found that OpenDNS logged an abundance of websites that check your IP address, though it didn't block them:
http://www.ip-address.org 10
whatismyip.org 10
http://www.tracemyip.org 17
my-ip-address.com 17
checkip.org 16
myip.dk 16
http://www.ip-1.com 19
automation.whatismyip.com 18
Then it hit me, this must be the DDNS service going out to check my IP address in such a way that it doesn't query my DDNS provider. In the webGUI it puts it like this:
"The check interval specifies how often the router will check whether your current IP matches the one currently associated with your domain name. This check is performed without connecting to your dynamic DNS service provider, which means that this will not cause problems with providers that ban users who connect too frequently (e.g. dyndns.com). However, a network connection is established to perform this check, so this value should not be too low. A check interval between 10 and 20 minutes is usually appropriate."
Does that sound like a correct explanation for the beaconing to all these IP address checker sites? If so, why would Gargoyle talk to this potentially malicious domain? Is it a false-positive? Did the developers just not know that one of the sites they use for checking my IP is kinda iffy?
Please help shed some light on this. Thanks!!
James