{"id":57,"date":"2011-08-12T22:21:43","date_gmt":"2011-08-12T22:21:43","guid":{"rendered":"http:\/\/triplescomputers.com\/blog\/?p=57"},"modified":"2011-08-12T22:27:24","modified_gmt":"2011-08-12T22:27:24","slug":"%e2%80%9cinfected%e2%80%9d-routers-threaten-death-by-dns","status":"publish","type":"post","link":"https:\/\/www.triplescomputers.com\/blog\/casestudies\/%e2%80%9cinfected%e2%80%9d-routers-threaten-death-by-dns\/","title":{"rendered":"\u201cInfected\u201d routers threaten death by DNS"},"content":{"rendered":"<p>Recently, I took delivery of a client\u2019s PC which had been thoroughly scanned, but he was concerned that it might not be fully clean.\u00a0 If you\u2019ve followed my work, you already know that this is relatively common; scanners, for all their merits, can only access what they\u2019re <em>allowed <\/em>to access, and they can only detect what they\u2019re <em>written <\/em>to detect.\u00a0 Even heuristic detection can only go so far, and with today\u2019s polymorphic malware (a.k.a., malware which changes its form with every specimen), signature-based detection is hardly reliable for the ever-common zero-day threats.<\/p>\n<p>Such was indeed the case with this client\u2019s computer, which was indeed still infected, regardless of clean scans by Symantec, Ad-Aware, and other utilities. \u00a0Although nothing had identified them,\u00a0they were almost certainly a new variant of the <a href=\"http:\/\/www.microsoft.com\/security\/portal\/Threat\/Encyclopedia\/Entry.aspx?Name=TrojanDownloader%3aWin32%2fTracur.X\">Trojan.Tracur<\/a> family of malware.\u00a0 Previous versions of the Trojan have been known to create copies of local system services, using legitimate descriptions for legitimate services and even the same names\u2014just suffixed with the number \u201c32\u201d.\u00a0 Normally it drops related files in the <strong>system32<\/strong> directory, but this variant actually had created its sister files inside <strong>\\ProgramData <\/strong>\u2013 <em>over 30 of them<\/em>, one for nearly every single service on the system.<\/p>\n<p>But that isn\u2019t the subject of this blog post.\u00a0 More interesting was the phone call I received once this client had taken their PC back home and begun using it again: he was still having problems, he told me.\u00a0 Web sites were loading with weird formatting, and when using Chrome, login attempts at popular sites popped up another window prompting a second login.\u00a0 The behavior sounded very similar to what some rootkits attempt to steal passwords and financial data.<\/p>\n<p>This situation might not sound strange, but you have to understand: I <em>never <\/em>return infected computers.\u00a0 I had performed the same rigorous inspection on his before calling him to pick it up, including a full analysis of all OS loading points, drivers, services, and the master boot record of the system drive.\u00a0 I also check for policies, malicious proxies, faulty DNS caching, and infected critical system files\u2014nearly all of this manually, using tools which I have specially developed for the task.<\/p>\n<p>So I wasn\u2019t convinced that malware was still on the PC\u2014but I <em>was <\/em>concerned that perhaps we were missing something else.\u00a0 I reviewed his logs (of which I keep detailed copies for every client) and found no signs of any danger, so I began considering other possibilities.\u00a0 What else could possibly be the problem?\u00a0 His router.<\/p>\n<p>Router infections are nasty little things.\u00a0 Technically, they aren\u2019t <em>infections<\/em>, but rather, corrupted settings (thanks to malware) which <em>lead to <\/em>compromised PCs and information. They aren&#8217;t necessarily new; this has been a trend which <a title=\"Link to article about DNS-changing Trojans affecting routers \" href=\"http:\/\/voices.washingtonpost.com\/securityfix\/2008\/06\/malware_silently_alters_wirele_1.html\" target=\"_blank\">actually started a couple of years ago<\/a> and has become <a title=\"A random topic about a router infection\" href=\"http:\/\/www.geekstogo.com\/forum\/topic\/285780-redirect-virus-im-losing-my-mind-on-this-one\/\" target=\"_blank\">increasingly common<\/a> among malware.<\/p>\n<p>It\u2019s actually pretty simple how they work: once a client computer has been infected, the malware takes advantage of the fact that no one ever changes their default router password.\u00a0 Equipped with this information, it accesses the router configuration and changes the DNS servers to malicious servers of its own, which can filter and steal traffic passing through them or even redirect users to altogether different sites when they request a page.\u00a0 This can be made entirely transparent to the user, as the displayed web address (the so-called FQDN) is still the same\u2014only the resolved IP address has changed.<\/p>\n<p>It isn\u2019t uncommon for such router infections to reinfect clients even after they\u2019re cleaned, presenting a seriously hazardous situation.\u00a0 The solution involves simultaneously performing a hard reset on the router (by holding down the reset button for 15 seconds or longer) <em>and <\/em>disinfecting the PC (and <em>all <\/em>affected PCs on the network)\u00a0before connecting back to the router.\u00a0 Following that, the network must be reconfigured on the router, and a password needs to be set to prevent future infiltrations.<\/p>\n<p>In my client&#8217;s case, there really wasn\u2019t any proof that this was what was happening with his PC, but it was the next logical step after rechecking his PC remotely using some log-generating deep system scanning software.\u00a0 So we reset the router, which seemed to resolve the internet traffic issues.\u00a0 However, the problems with Chrome persisted, even without any extensions installed.\u00a0 Given the options, we eventually elected to uninstall Chrome, chalking up the additional problems to a possible unknown bug in the browser itself.\u00a0 Case in point: no other browsers, including Mozilla Firefox, had the same issue.\u00a0 Just to be certain, I rechecked all proxies, the master boot record, and system files.\u00a0 The PC was indeed 100% clean, and my client was happy.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Recently, I took delivery of a client\u2019s PC which had been thoroughly scanned, but he was concerned that it might not be fully clean.\u00a0 If you\u2019ve followed my work, you already know that this is relatively common; scanners, for all &hellip; <a href=\"https:\/\/www.triplescomputers.com\/blog\/casestudies\/%e2%80%9cinfected%e2%80%9d-routers-threaten-death-by-dns\/\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3,4],"tags":[7,50,52,11,35,34,51,49,53,54],"class_list":["post-57","post","type-post","status-publish","format-standard","hentry","category-casestudies","category-security","tag-advanced","tag-dns","tag-dns-changing-trojan","tag-malware","tag-network-problems","tag-networking","tag-router","tag-trojan","tag-trojan-tracur","tag-win32tracur"],"_links":{"self":[{"href":"https:\/\/www.triplescomputers.com\/blog\/wp-json\/wp\/v2\/posts\/57","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.triplescomputers.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.triplescomputers.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.triplescomputers.com\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.triplescomputers.com\/blog\/wp-json\/wp\/v2\/comments?post=57"}],"version-history":[{"count":0,"href":"https:\/\/www.triplescomputers.com\/blog\/wp-json\/wp\/v2\/posts\/57\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.triplescomputers.com\/blog\/wp-json\/wp\/v2\/media?parent=57"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.triplescomputers.com\/blog\/wp-json\/wp\/v2\/categories?post=57"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.triplescomputers.com\/blog\/wp-json\/wp\/v2\/tags?post=57"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}