{"id":2412,"date":"2017-03-06T00:55:00","date_gmt":"2017-03-05T23:55:00","guid":{"rendered":"http:\/\/borncity.com\/win\/?p=2412"},"modified":"2024-10-05T23:22:34","modified_gmt":"2024-10-05T21:22:34","slug":"dnsmessenger-trojan-is-using-dns-queries-for-its-orders","status":"publish","type":"post","link":"https:\/\/borncity.com\/win\/2017\/03\/06\/dnsmessenger-trojan-is-using-dns-queries-for-its-orders\/","title":{"rendered":"DNSMessenger Trojan is using DNS queries for its orders"},"content":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" style=\"float: left; margin: 0px 10px 0px 0px; display: inline\" src=\"http:\/\/www.borncity.com\/blog\/wp-content\/uploads\/2015\/01\/Schutz.jpg\" width=\"40\" align=\"left\" height=\"47\">[<a href=\"http:\/\/www.borncity.com\/blog\/2017\/03\/05\/dnsmessenger-trojaner-nutzt-dns-eintrge-fr-befehle\/\" target=\"_blank\" rel=\"noopener\">German<\/a>]Security researchers has discovered a new file less malware that comes as a PowerShell script and uses DNS queries to receive its orders.<\/p>\n<p><!--more--><\/p>\n<p>The malware was discovered from researcher of Cisco`s Talos project and has been documented <a href=\"http:\/\/blog.talosintelligence.com\/2017\/03\/dnsmessenger.html\" target=\"_blank\" rel=\"noopener\">here<\/a>. The infection starts with a phishing campain, where&nbsp; an e-mail has been send to many users. The e-mail contains a Word attachment, claiming to be protected by Mc Afee. <\/p>\n<p><img decoding=\"async\" src=\"https:\/\/3.bp.blogspot.com\/-DTpwsJXIU9I\/WLhLuqCsdvI\/AAAAAAAAAOg\/XJYzin2RJi86B2AyKOlzvkBzGrHrik-4gCLcB\/s640\/image16.png\"><br \/>(Source: Cisco\/Talos) <\/p>\n<p>If the user clicks the link, a PowerShell script will be executed and loads the Trojan into memory. Then it checks the scripts environment (if the user has admin rights) and loads a 2nd PowerShell script. This script will be stored within Alternate Data Stream (ADS) of the NTFS file system or within the registry.  <\/p>\n<p>A third PowerShell script establishes a communication channel using DNS records to send data and receiving commands from a C&amp;C server. Further details may be found within <a href=\"http:\/\/blog.talosintelligence.com\/2017\/03\/dnsmessenger.html\" target=\"_blank\" rel=\"noopener\">this blog post<\/a>. (<a href=\"https:\/\/web.archive.org\/web\/20181203000439\/https:\/\/www.computerworld.com\/article\/3176669\/security\/fileless-powershell-malware-uses-dns-as-covert-channel.html\" target=\"_blank\" rel=\"noopener\">via<\/a>)<\/p>\n","protected":false},"excerpt":{"rendered":"<p>[German]Security researchers has discovered a new file less malware that comes as a PowerShell script and uses DNS queries to receive its orders.<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[580,2],"tags":[244,69,245,194],"class_list":["post-2412","post","type-post","status-publish","format-standard","hentry","category-security","category-windows","tag-malware","tag-security","tag-trojan","tag-windows"],"_links":{"self":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts\/2412","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/comments?post=2412"}],"version-history":[{"count":1,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts\/2412\/revisions"}],"predecessor-version":[{"id":36047,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts\/2412\/revisions\/36047"}],"wp:attachment":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/media?parent=2412"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/categories?post=2412"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/tags?post=2412"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}