Jump to content

Recommended Posts

Posted (edited)

Dear All.

 

I have a windows server running AD and DNS services. I have detected in the fiewall that the server is sending confickr packets through it, but after various antivirus checks (I even had the visit from a panda antivirus engeneer and couldn't find anything) nothing came up so I think that the maybe the problem is that when an infected user connects to the network using the win server as the DNS server, the client sends the confickr udp packets through the DNS server....

 

Is there anyway of checking who is doing these requests in the DNS server I tried in the event viwer and in system32\dns\dns.log but couldn't find anything....

 

Here is a sample of the firewall capture:

 

02/18 12:26:13 spyware Conficker DNS Request 20000 LAN WAN 192.168.111.2 80.58.61.254 55264 53 dns alert high

 

Any ideas???

 

Thanks :)

Edited by joseph
Posted
Would it be possible to get a NIC MAC address from the LAN IP (I'm assuming the one shown is for the device sending the packet) either from the captured packets or by doing an nslookup? You could then use Nmap or similar to search for that MAC address and track the machine from there.
Posted

The lan Ip is the ip of the DNS Server...

 

Since I don't get any suspicious traffic over the weekend I think I'm sure the packets come from an infected client... but how to track who is sending those packets???

 

:(

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...