Passive DNS in the Analyst's Hands

The Domain Name System (DNS) is akin to a phone book that translates user-friendly names like 'ussc.ru' into IP addresses. Since DNS activity is present in almost all communication sessions, regardless of the protocol, DNS logging serves as a valuable data source for information security specialists, allowing them to detect anomalies or gather additional information about the system under investigation.

In 2004, Florian Weimer proposed a logging method called Passive DNS, which allows for the reconstruction of the history of DNS data changes, enabling indexing and searching that can provide access to the following data:

  • Domain Name
  • IP address of the requested domain name
  • Date and time of the response
  • Type of response
  • etc.

Passive DNS data is collected from recursive DNS servers by integrated modules or by intercepting responses from DNS servers responsible for the zone.

Passive DNS in the Analyst's Hands

Figure 1. Passive DNS (taken from the site Ctovision.com)

The feature of Passive DNS is that there is no need to register the client's IP address, which helps protect user privacy.

Currently, there are many services providing access to Passive DNS data:

DNSDB
VirusTotal
PassiveTotal
Octopus
SecurityTrails
Umbrella Investigate

Company
Farsight Security
VirusTotal
Riskiq
SafeDNS
SecurityTrails
Cisco

Access
On request
No registration required
Free registration
On request
No registration required
On request

API
Available
Available
Available
Available
Available
Available

Client availability
Available
Available
Available
Not present
Not present
Not present

Data collection start
2010
2013
2009
Displays only the last 3 months
2008
2006

Table 1. Services with access to Passive DNS data

Use Cases of Passive DNS

Using Passive DNS, one can establish connections between domain names, NS servers, and IP addresses. This allows for the construction of maps of investigated systems and tracking changes to such a map from the first detection to the present.

Passive DNS also facilitates the detection of anomalies in traffic. For instance, tracking changes in NS zones and A and AAAA records can help identify malicious sites using the fast flux method, which is intended to hide C&C from detection and blocking. Since legitimate domain names (except those used for load balancing) do not frequently change their IP addresses, and most legitimate zones seldom change their NS servers.

Unlike direct subdomain enumeration through dictionaries, Passive DNS can even find the most exotic domain names, such as "222qmxacaiqaaaaazibq4aaidhmbqaaa0undefined7140c0.p.hoff.ru." It can also sometimes uncover test (and vulnerable) areas of a website, developer materials, and so on.

Investigating a link from an email using Passive DNS

Currently, spam is one of the primary ways through which attackers gain access to a victim's computer or steal confidential information. Let's try to investigate a link from such an email using Passive DNS to assess the effectiveness of this method.

Passive DNS in the Analyst's Hands

Figure 2. Spam email

The link from this email directed to the website magnit-boss.rocks, which offered an automated way to collect bonuses and earn money:

Passive DNS in the Analyst's Hands

Figure 3. Page hosted on the domain magnit-boss.rocks

To investigate this site, the Riskiq API, which already has 3 ready clients on Python, Ruby and Rust.

First, let's find out the entire history of this domain name by using the command:

pt-client pdns —query magnit-boss.rocks

This command will provide information about all DNS resolutions associated with this domain name.

Passive DNS in the Analyst's Hands

Figure 4. Response from the Riskiq API

Let's present the response from the API in a more visual form:

Passive DNS in the Analyst's Hands

Figure 5. All records from the response

For further investigation, the IP addresses that this domain name resolved to at the time of receiving the email on 01.08.2019 were taken. These IP addresses are 92.119.113.112 and 85.143.219.65.

Using the command:

pt-client pdns —query

you can retrieve all the domain names associated with these IP addresses.
The IP address 92.119.113.112 has 42 unique domain names that resolved to this IP address, including the following names:

  • magnit-boss.club
  • igrovie-avtomaty.me
  • pro-x-audit.xyz
  • zep3-www.xyz
  • and others.

The IP address 85.143.219.65 has 44 unique domain names that resolved to this IP address, including the following names:

  • cvv2.name (a site for selling credit card data)
  • emaills.world
  • www.mailru.space
  • and others.

Connections with these domain names suggest phishing, but we believe in good people, so let's try to get a bonus of 332,501.72 rubles? After clicking the “YES” button, the site asks us to transfer 300 rubles from the card to unlock the account and redirects us to the site as-torpay.info to enter our details.

Passive DNS in the Analyst's Hands

Figure 6. The main page of the website ac-pay2day.net

On the surface, it appears to be a legitimate site, has an HTTPS certificate, and the main page offers to connect this payment system to your site. However, unfortunately, all connection links do not work. This domain name resolves only to one IP address — 190.115.19.74. It in turn has 1,475 unique domain names that resolved to this IP address, including names such as:

  • ac-pay2day.net
  • ac-payfit.com
  • as-manypay.com
  • fletkass.net
  • as-magicpay.com
  • and others.

As we can see, Passive DNS allows for the quick and effective collection of data about the resource being investigated, and even creates a kind of fingerprint that helps reveal an entire scheme for stealing personal data, from its acquisition to the probable place of sale.

Passive DNS in the Analyst's Hands

Figure 7. Map of the investigated system

It's not all rosy, as we would like. For example, such investigations can easily run into CloudFlare or similar services. The effectiveness of the gathered database heavily depends on the number of DNS queries passing through the module for collecting Passive DNS data. Nevertheless, Passive DNS serves as a source of additional information for the researcher.

Author: Specialist of the Ural Center for System Security

Source: habr.com

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster