Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

INDICATOR-COMPROMISE Suspicious .tk dns query

So I am getting emails about some bad DNS queries:

"INDICATOR-COMPROMISE Suspicious .tk dns query"

I have looked in to this, and for the most part, these are "legit" drops, but not ALL are...

Myself, I have signed up for a free .tk domain, and set it to my external IP, but I cannot resolve my domain to an IP because of these drops.


How can I "whitelist" MY .tk domain, while still blocking the others?



This thread was automatically locked due to age.
Parents
  • I had just the same:

    Message........: INDICATOR-COMPROMISE Suspicious .tk dns query

    Details........: https://www.snort.org/search?query=39867

    Time...........: 2016-09-07 00:00:42

    Packet dropped.: yes

    Priority.......: high

    Classification.: A Network Trojan was Detected IP protocol....: 17 (UDP)

    Originating IP is my internal DNS Server, destination is my upstream DNS server (ORSN public DNS).

    Strange, the snort URL goes into Nirvana, and nothing can by found about that SID.

Reply
  • I had just the same:

    Message........: INDICATOR-COMPROMISE Suspicious .tk dns query

    Details........: https://www.snort.org/search?query=39867

    Time...........: 2016-09-07 00:00:42

    Packet dropped.: yes

    Priority.......: high

    Classification.: A Network Trojan was Detected IP protocol....: 17 (UDP)

    Originating IP is my internal DNS Server, destination is my upstream DNS server (ORSN public DNS).

    Strange, the snort URL goes into Nirvana, and nothing can by found about that SID.

Children
No Data