{"id":42132,"date":"2018-03-05T05:00:00","date_gmt":"2018-03-05T05:00:00","guid":{"rendered":"https:\/\/www.cira.ca\/blog\/weekly-web-security-warning-mirai-leads-way\/"},"modified":"2023-03-10T10:57:10","modified_gmt":"2023-03-10T15:57:10","slug":"weekly-web-security-warning-mirai-leads-way","status":"publish","type":"cira_news","link":"https:\/\/stg-saas.cira.ca\/en\/resources\/news\/cybersecurity\/weekly-web-security-warning-mirai-leads-way\/","title":{"rendered":"Weekly web security warning: Mirai leads the way"},"content":{"rendered":"<p>While finding malware on your network is always an unwelcome surprise, this week&#8217;s top 10 blocks from D-Zone DNS Firewall are not really surprising at all.<\/p>\n<p><!--more--><\/p>\n<p>While finding malware on your network is always an unwelcome surprise, this week&#8217;s top 10 blocks from D-Zone DNS Firewall are not really surprising at all.<\/p>\n<p>We continue to see the Mirai botnet on wowrack.com name servers lead the list by query count. A Google search indicates that wowrack is a managed server hosting and cloud provider and seeing this type of issue on an ns address is not something we would expect to persist.<\/p>\n<p>Rounding out the top 10 we see a similar number of malware call home attempts as we see in most weeks, the continuing threat from Palevo, plus a return of jRAT, or Java Based Remote Access Trojans. These are particularly problematic as they are constantly evolving and run in a browser and can execute a malware payload download.<\/p>\n<p>And finally, a new entrant is a WPAD proxy hijack that can expose users online accounts through man-in-the-middle style attacks.<\/p>\n<table border=\"0\" cellpadding=\"0\" cellspacing=\"0\" style=\"width:623px\" width=\"0\">\n<tbody>\n<tr>\n<td style=\"width:228px;height:52px\">\n<p><strong>Domain Name<\/strong><\/p>\n<\/td>\n<td style=\"width:19px;height:52px\">\n<p><strong>Category<\/strong><\/p>\n<\/td>\n<td style=\"width:377px;height:52px\">\n<p><strong>Threat Type<\/strong><\/p>\n<\/td>\n<\/tr>\n<tr>\n<td style=\"width:228px;height:51px\">\n<p>ns6.wowrack.com<\/p>\n<\/td>\n<td style=\"width:19px;height:51px\">\n<p>BLOCK<\/p>\n<\/td>\n<td style=\"width:377px;height:51px\">\n<p>Mirai<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td style=\"width:228px;height:51px\">\n<p>ns5.wowrack.com<\/p>\n<\/td>\n<td style=\"width:19px;height:51px\">\n<p>BLOCK<\/p>\n<\/td>\n<td style=\"width:377px;height:51px\">\n<p>Mirai<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td style=\"width:228px;height:34px\">\n<p>superyou.zapto.org<\/p>\n<\/td>\n<td style=\"width:19px;height:34px\">\n<p>BLOCK<\/p>\n<\/td>\n<td style=\"width:377px;height:34px\">Spybot<\/td>\n<\/tr>\n<tr>\n<td style=\"width:228px;height:51px\">\n<p>pixeldgarui.xyz<\/p>\n<\/td>\n<td style=\"width:19px;height:51px\">\n<p>BLOCK<\/p>\n<\/td>\n<td style=\"width:377px;height:51px\">\n<p>Malware Call Home<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td style=\"width:228px;height:60px\">\n<p>zws12.com<\/p>\n<\/td>\n<td style=\"width:19px;height:60px\">\n<p>BLOCK<\/p>\n<\/td>\n<td style=\"width:377px;height:60px\">\n<p>Malware Call Home<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td style=\"width:228px;height:60px\">\n<p>redwassheptal.com<\/p>\n<\/td>\n<td style=\"width:19px;height:60px\">\n<p>BLOCK<\/p>\n<\/td>\n<td style=\"width:377px;height:60px\">\n<p>Malware Call Home<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td style=\"width:228px;height:51px\">\n<p>wpad.domain.name<\/p>\n<\/td>\n<td style=\"width:19px;height:51px\">\n<p>BLOCK<\/p>\n<\/td>\n<td style=\"width:377px;height:51px\">\n<p>WPAD proxy hijack<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td style=\"width:228px;height:51px\">\n<p>doingtracks.duckdns.org<\/p>\n<\/td>\n<td style=\"width:19px;height:51px\">\n<p>BLOCK<\/p>\n<\/td>\n<td style=\"width:377px;height:51px\">\n<p>jRAT<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td style=\"width:228px;height:51px\">\n<p>sandra.prichaonica.com<\/p>\n<\/td>\n<td style=\"width:19px;height:51px\">\n<p>BLOCK<\/p>\n<\/td>\n<td style=\"width:377px;height:51px\">\n<p>Palevo<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td style=\"width:228px;height:52px\">\n<p>l33t.brand-clothes.net<\/p>\n<\/td>\n<td style=\"width:19px;height:52px\">\n<p>BLOCK<\/p>\n<\/td>\n<td style=\"width:377px;height:52px\">\n<p>Palevo<\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n","protected":false},"excerpt":{"rendered":"<p>While finding malware on your network is always an unwelcome surprise, this week&#8217;s top 10 blocks from D-Zone DNS Firewall are not really surprising at all.<\/p>\n","protected":false},"featured_media":1949,"template":"","meta":{"_acf_changed":false,"content-type":"","inline_featured_image":false,"ngg_post_thumbnail":0,"slim_seo":{"title":"Weekly web security warning: Mirai leads the way - CIRA","description":"While finding malware on your network is always an unwelcome surprise, this week's top 10 blocks from D-Zone DNS Firewall are not really surprising at all. Whil"},"footnotes":""},"topic":[28],"class_list":["post-42132","cira_news","type-cira_news","status-publish","has-post-thumbnail","hentry","cira_news_type-cira-news-type-blog","cira_topic-cira-topic-cybersecurity","cira_author-rob-williamson"],"publishpress_future_workflow_manual_trigger":{"enabledWorkflows":[]},"_links":{"self":[{"href":"https:\/\/stg-saas.cira.ca\/en\/wp-json\/cira\/v1\/news\/42132","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/stg-saas.cira.ca\/en\/wp-json\/cira\/v1\/news"}],"about":[{"href":"https:\/\/stg-saas.cira.ca\/en\/wp-json\/wp\/v2\/types\/cira_news"}],"version-history":[{"count":0,"href":"https:\/\/stg-saas.cira.ca\/en\/wp-json\/cira\/v1\/news\/42132\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/stg-saas.cira.ca\/en\/wp-json\/wp\/v2\/media\/1949"}],"wp:attachment":[{"href":"https:\/\/stg-saas.cira.ca\/en\/wp-json\/wp\/v2\/media?parent=42132"}],"wp:term":[{"taxonomy":"cira_topic","embeddable":true,"href":"https:\/\/stg-saas.cira.ca\/en\/wp-json\/cira\/v1\/topic?post=42132"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}