{"id":42095,"date":"2018-04-10T04:00:00","date_gmt":"2018-04-10T08:00:00","guid":{"rendered":"https:\/\/stg.cira.ca\/blog\/weekly-web-security-warning-malware-queries-continue-upward-trend-2\/"},"modified":"2023-03-10T10:57:08","modified_gmt":"2023-03-10T15:57:08","slug":"weekly-web-security-warning-malware-queries-continue-upward-trend-2","status":"publish","type":"cira_news","link":"https:\/\/stg.cira.ca\/fr\/ressources\/nouvelles\/cybersecurite\/weekly-web-security-warning-malware-queries-continue-upward-trend-2\/","title":{"rendered":"Weekly web security warning \u2013 malware queries continue upward trend"},"content":{"rendered":"<p>Every week, we examine the top trends in malicious activity we have seen in Canada using data obtained through CIRA&#8217;s D-Zone DNS Firewall.<\/p>\n<p><!--more--><\/p>\n<p>Many of the&nbsp;top blocked domains this week are indicative of only a handful of infected IP addresses calling out many, many times, while others are more pervasive. Looking at widespread trends can help us analyze cybersecurity trends across Canada&nbsp;\u2013 at least among the 800,000 strong user base of <a href=\"\/cybersecurity-services\/firewall\/d-zone-dns-firewall\">D-Zone DNS Firewall<\/a>.<\/p>\n<p>If we look at the top five threats impacting the largest number of unique IP addresses (or customers) over the last 30 days, one common trend is malware on a network trying to call home. We see this frequently with first-time users of our <a href=\"\/cybersecurity-services\/firewall\/d-zone-dns-firewall\">DNS firewall<\/a> service who find malware that was already on their network. Another growing trend among hackers&nbsp;is to surreptitiously use corporate networks for bitcoin mining \u2026which I suppose many hackers could consider a \u201cvictimless\u201d crime, but I doubt IT managers would feel the same.<\/p>\n<h2>Top ten blocked&nbsp;domains last week<\/h2>\n<div>\n<table border=\"1\" cellpadding=\"0\" style=\"width:449px\" width=\"0\">\n<thead>\n<tr>\n<th style=\"width:190px\">\n<p><strong>Domain Name<\/strong><\/p>\n<\/th>\n<th style=\"width:254px\">\n<p><strong>Threat Type<\/strong><\/p>\n<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td style=\"width:190px\">\n<p>superyou.zapto.org<\/p>\n<\/td>\n<td style=\"width:254px\">\n<p>Spybot<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td style=\"width:190px\">\n<p>76236osm1.ru<\/p>\n<\/td>\n<td style=\"width:254px\">\n<p>Trojan downloaders<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td style=\"width:190px\">\n<p>dzhacker15.no-ip.org<\/p>\n<\/td>\n<td style=\"width:254px\">\n<p>Hworm<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td style=\"width:190px\">\n<p>dj1.jfrmt.net<\/p>\n<\/td>\n<td style=\"width:254px\">\n<p>Morto<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td style=\"width:190px\">\n<p>api-restlet.com<\/p>\n<\/td>\n<td style=\"width:254px\">\n<p>Xavier<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td style=\"width:190px\">\n<p>soplifan.ru<\/p>\n<\/td>\n<td style=\"width:254px\">\n<p>Trojan downloaders<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td style=\"width:190px\">\n<p>diplicano.ru<\/p>\n<\/td>\n<td style=\"width:254px\">\n<p>Trojan downloaders<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td style=\"width:190px\">\n<p>pumpmywallet.com<\/p>\n<\/td>\n<td style=\"width:254px\">\n<p>Malware Call Home<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td style=\"width:190px\">\n<p>ns6.wowrack.com<\/p>\n<\/td>\n<td style=\"width:254px\">\n<p>Mirai<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td style=\"width:190px\">\n<p>ns5.wowrack.com<\/p>\n<\/td>\n<td style=\"width:254px\">\n<p>Mirai<\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<h2>Definitions of threat types<\/h2>\n<p>With all of these different types of threats being shown, we thought it would be helpful to provide a quick description of each.&nbsp;<\/p>\n<dl>\n<dt><strong>Spybot<\/strong><\/dt>\n<dd>A diverse family of worms that allow malicious actions on Windows computers.<\/dd>\n<dt><strong>Trojan downloaders<\/strong><\/dt>\n<dd>Botnets that (can) wait for available connections to download malware of various types.<\/dd>\n<dt><strong>Hworm<\/strong><\/dt>\n<dd>Microsoft Windows malware that gives an attacker control over the victim&#8217;s computer.<\/dd>\n<dt><strong>Morto<\/strong><\/dt>\n<dd>A worm that spreads via RDP between Windows machines that have weak passwords \u2013 impacts older versions of Windows.<\/dd>\n<dt><strong>Xavier<\/strong><\/dt>\n<dd>A Trojan Android ad library that steals and leaks a user&#8217;s information silently.<\/dd>\n<dt><strong>Malware Call Home<\/strong><\/dt>\n<dd>Domains that are known to be accessed for post-infection communications.<\/dd>\n<dt><strong>Mara<\/strong><\/dt>\n<dd>An IoT botnet that is used primarily to launch DDoS attacks. This block also includes variants (e.g. Persirai).<\/dd>\n<\/dl>\n<h2>Top four threats in the last 30 days<\/h2>\n<dl>\n<dt><strong>Malware Call Home<\/strong><\/dt>\n<dd>Domains used for malware post-infection communications<\/dd>\n<dt><strong>Bitcoin Miner<\/strong><\/dt>\n<dd>Any malware whose primary function is using victim computers&#8217; CPUs and electricity to mine bitcoin.<\/dd>\n<dt><strong>Malware-Adware\/A<\/strong><\/dt>\n<dd>Cluster of malware\/adware domains used by hijacked web browsers.<\/dd>\n<dt><strong>Suspected Malware<\/strong><\/dt>\n<dd>Suspected malware\/botnet activity that is in the process of being classified.<\/dd>\n<\/dl>\n<p>Are things getting better or worse? Lets take a look at the total number of queries over a longer period of time.<\/p>\n<h2>Total queries blocked<\/h2>\n<figure>\n<img decoding=\"async\" class=\" size-full wp-image-2416\" src=\"https:\/\/stg.cira.ca\/uploads\/2018\/04\/dzone-queries-blocked.png\" alt=\"\" title=\"\" width=\"1071\" height=\"469\" srcset=\"https:\/\/stg.cira.ca\/uploads\/2018\/04\/dzone-queries-blocked.png 1071w, https:\/\/stg.cira.ca\/uploads\/2018\/04\/dzone-queries-blocked-300x131.png 300w, https:\/\/stg.cira.ca\/uploads\/2018\/04\/dzone-queries-blocked-1024x448.png 1024w, https:\/\/stg.cira.ca\/uploads\/2018\/04\/dzone-queries-blocked-768x336.png 768w\" sizes=\"(max-width: 1071px) 100vw, 1071px\" \/><figcaption>\n<p>The total number of queries we are blocking \u2013&nbsp;up until the last few weeks, there&#8217;s been in a steady-state.<\/p>\n<\/figcaption><\/figure>\n<p>Now to be clear, we aren&#8217;t normalizing data and as new customers use our service, the baseline increases but you can see that the last few weeks, malicious query traffic has really stepped up.<\/p>\n<p>Notably, when reviewing the chart, the huge spike was associated with an anonymizer (VPN) that got added to the block list for a very short time before the information was analyzed and rectified. Its prevalence is notable because it illustrates the pervasiveness of VPN technology among users in the educational sector. People using VPNs are often visiting sites associated with risky content and so many corporate users prefer to block anonymizers altogether.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Every week, we examine the top trends in malicious activity we have seen in Canada using data obtained through CIRA&#8217;s D-Zone DNS Firewall.<\/p>\n","protected":false},"featured_media":1949,"template":"","meta":{"_acf_changed":false,"content-type":"","inline_featured_image":false,"ngg_post_thumbnail":0,"slim_seo":{"title":"Weekly web security warning \u2013 malware queries continue upward trend - CIRA","description":"Every week, we examine the top trends in malicious activity we have seen in Canada using data obtained through CIRA's D-Zone DNS Firewall. Many of the&nbsp;top"},"footnotes":""},"topic":[1066],"class_list":["post-42095","cira_news","type-cira_news","status-publish","has-post-thumbnail","hentry","cira_news_type-cira-news-type-blogue","cira_topic-cira-topic-cybersecurite","cira_author-robwilliamson-fr"],"publishpress_future_workflow_manual_trigger":{"enabledWorkflows":[]},"_links":{"self":[{"href":"https:\/\/stg.cira.ca\/fr\/wp-json\/cira\/v1\/news\/42095","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/stg.cira.ca\/fr\/wp-json\/cira\/v1\/news"}],"about":[{"href":"https:\/\/stg.cira.ca\/fr\/wp-json\/wp\/v2\/types\/cira_news"}],"version-history":[{"count":0,"href":"https:\/\/stg.cira.ca\/fr\/wp-json\/cira\/v1\/news\/42095\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/stg.cira.ca\/fr\/wp-json\/wp\/v2\/media\/1949"}],"wp:attachment":[{"href":"https:\/\/stg.cira.ca\/fr\/wp-json\/wp\/v2\/media?parent=42095"}],"wp:term":[{"taxonomy":"cira_topic","embeddable":true,"href":"https:\/\/stg.cira.ca\/fr\/wp-json\/cira\/v1\/topic?post=42095"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}