Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

INDICATOR-COMPROMISE Suspicious .tk dns query

So I am getting emails about some bad DNS queries:

"INDICATOR-COMPROMISE Suspicious .tk dns query"

I have looked in to this, and for the most part, these are "legit" drops, but not ALL are...

Myself, I have signed up for a free .tk domain, and set it to my external IP, but I cannot resolve my domain to an IP because of these drops.


How can I "whitelist" MY .tk domain, while still blocking the others?



This thread was automatically locked due to age.
Parents Reply
  • you could try to edit this file:

    /etc/snort/rules/astaro.rules


    Remove this line:

    drop udp $HOME_NET any -> any 53 (msg:"D INDICATOR-COMPROMISE Suspicious .tk dns query " group="241"; flow:to_server; byte_test:1,!&,0xF8,2; content:"|02|tk|00|"; fast_pattern:only; metadata:policy security-ips drop, service dns; classtype:trojan-activity; sid:39867;)

    I don't know how long this lasts, probably until next pattern update...

Children
No Data
Share Feedback
×

Submitted a Tech Support Case lately from the Support Portal?