·

Dangling CNAME Attacks and Sub-domain Takeovers

TLDR; we detected a sizable number of sub-domain takeovers affecting many educational establishments and some popular domains, a list is provided below.

Things have been very busy around here lately; this week, we’ve quietly released a completely re-written and re-architected backend to our Guardian platform using the experience that we’ve gained in the 5 years since it was first launched and has taken over a year to complete.

This new backend will provide the foundation for Guardian Mail to continue to grow over the coming years, and has already provided some interesting discoveries, and one that I want to share with you now.


Blocking A Spam Gang

For some years now, the team and I have been tracking a fairly prolific spam gang, who have been relatively successful in evading other companies’ spam detection but we have been successfully blocking, thanks to many of our customers sharing anonymised SMTP transaction data with us to help us track this gang.

During the recent testing phase of our new processing infrastructure; we started to see popular domains unexpectedly appearing in our detections related to this particular spam gang.

Upon closer inspection, we discovered that they had taken over portions of some very popular domains by means of dangling CNAME attacks.   This is where an attacker discovers a CNAME in a company’s domain which points to a hostname of a domain that has expired, they then register that domain name and set-up infrastructure on that hostname, effectively taking over the sub-domain for themselves.

This is obviously very dangerous for the domains concerned because it opens them up to Phishing and Malware attacks, cookie harvesting, and reputational damage.

 

Abusix Does Not Gatekeep

Luckily for these domains, in this case, this particular gang appears to simply use the domains to “fly under the radar” to send spam, phishing and malware to others, rather than using these to attack the parent domain, which would likely be far more damaging.  They also mixed the infrastructure, making it easier for us to discover other CNAMEs that they had taken over.

At Abusix, rather than gatekeep intelligence like this, our goal is to get stuff shared and taken down, so we’ve copied all the relevant security teams with this information and we’re providing it here to make it known to others.

Here is the list of affected entities, the hostnames and CNAMEs that they point to:

EntityHostnameCNAME
San Diego Supercomputer Center (UC San Diego)brak.sdsc.eduwww.biologicalnetworks.org.
University of California (UCLA)user2014.stat.ucla.eduucla.user2014.org.
Georgetown Universitygerms.georgetown.eduwww.georgetownems.COM.
SOMMARØY Hotelmeny.sommaroy.notasti.store.
Heriot Watt Universitytransition.hw.ac.uktransitionheriot-watt.org.uk.
Olivet Nazarene Universityglimmerglass.olivet.eduonuglimmerglass.com.
Vodafone Italyhackdays.vodafone.itwww.hackdays.it.
University of California, Davis (UC Davis)ucdim.ucdavis.eduwww.ucdim.com.
comethmeta.cometh.iocometh.auxo.world.
Fantasyland Hotelinfo.fantasylandhotel.comfanatyslandhotel.com.
UKRAINE FOOTBALL CORPORATIONgames.ukrainefootball.neteforbgames.com.
Falmouth Universityrane.falmouth.ac.ukrane-research.org.
kingHostwp.pecil.kinghost.net.r0ute.ddns.net.
The George Washington Universitygsehd-online.gwu.edu.account.hobsonsms.com.
Georgetown Universityjournal.georgetown.edudigitalleadershipcouncil.com.
Illinois Techcourseconstruct.iit.edu.courseconstruct.mass-hosting.com.
International Data Groupsafeguard.idg.comcentral.crashpan.com.
University of La Vernedining.laverne.eduwww.lavernedining.com.
Kentucky Community & Technical College Systemlegacy.bigsandy.kctcs.edu.www.bsctcapps.com.
NILUesticc.nilu.no.esticc.net.
Greenville Universityprofessionals.greenville.edu.account.hobsonsms.com.
New York Medical Collegeshspprograms.nymc.edu.account.hobsonsms.com.
Bacone Collegeonline.bacone.edu.account.hobsonsms.com.
mail.rumystagetv-admin-page.imgsmail.ru.mystage.tv.
University of Bordeauxwww.sb2.u-bordeaux.fr.synthetic-biology-bordeaux.fr.
Connecticut’s Official State Websitecdcsstage.doc.ct.gov.doccdcsstage.ctdoc.org.
King Juan Carlos Universityclubdeportivo.urjc.es.clubdeportivourjc.es.
AUDI UKplayout.audi.co.ukplayout.mioeverywhere.tv.
CNN Moneym.cnnmoney.commcnnmoney.codewithsnow.com.
OpenWesthsctf.openwest.orgutahstatetech.com
University of Nicemiage.unice.frwww.miage-nice.fr
Asuqumarketsquare.asuqu.comasuqu.stream
Liberationlibetwitt.liberation.frwww.tweetclash.com.
Intermarcheproducteursdici.intermarche.comwww.demarcheproducteursdici.fr
KODI Collectivealliancetitleprint.digitallizard.comwww.alliancetitleprint.com
Namogoocdn.namogoo.com.cdn1.nmgcdn.com
Essec Business Schoolcampus2020.essec.edu.www.campus2020.fr.
Dave’s Runningstore.davesrunning.com.davesrunning.store.erunsolutions.com.
Unknownwww.darkpatternstipline.org.darkpatternstipline.com
Gemological Institute of Americawww.logowear.gia.edu.gia.logsoftwear.com.
International Association of Business Communicatorsnorthnz.iabc.com.www.iabc-northnz.org.
MDsave Incorporatedstaging-api-documentation.mdsave.com.hubs.docql.io.
Pusan National Universityasiahpst2016.pusan.ac.kr.asiahpst2016.com.
NEXT Universitypromo.nextuniversity.com.ubouncepages.com.
Université Lavalwww.dipublique.chaire.ulaval.ca.chaire-dipublique.djosse.fr.
ORACLEgo.bigmachines.com.mkto-d0103.com.
Universidade Federal do Rio de Janeiromx3.limc.ufrj.br.tabulae.net.
Universitat Politècnica de Catalunya BarcelonaTechinnotex.upc.edu.innotexcenter.com.
CZECH ATHLETIC ASSOCIATIONkviz.atletika.cz.csatletika.brandzfriendz.net
IdecNet SAarnedonet.idecnet.com.www.arnedonet.com.
Chicco Italiacataloghi.chicco.com.drake.ipaperitaly.com.
Insureongo.insureon.com.mkto-sj080250.com.
UC Santa Cruzwww.soar.ucsc.edu.www.soarucsc.org.
Launch Medicaltrack.getmyphoenix.com.morthelorpowasure.com.
Artsana Groupmedicalcenter.artsana.it.drake.ipaperitaly.com.
Weber Shandwickahub-qa.webershandwick.comahub-qa.wsbinfra.net
Orderfox Schweiz AGapi.orderfox.comorderfox-api.orderfox-prod.com
Seoul National University of Science & Technologyasrri.seoultech.ac.krasrri.kr
Nexstar Media Inc.blogs.wane.comlb.linapps.io.
Atlas.cz*.dev1.atlas.czwebdev1.atlasdev.cz
SPORTbstories.sport.esbstories.sport.es.s.lb.appnbs.cloud
mydayschat.mydays.demydays-chatwebservice-first.com
Wine Aligncru.winealign.comatmr.ch.
GovAssist, LLCgo.visaexpress.us.comknomomain-enquate.com.
JFK School of Law at National Universitygo.jfku.edumkto-ab040129.com
Savvy + Co. Real Estateimg.savvyandcompany.comimb.ggwz.us
KPNimode.planet.nlwww.myimode.nl
The George Washington Universitym.digitalcommunity.gwu.edu web-01.influence-technologies.com.
Ashford Luxury Watchesmail.ashford.commail1.hswwco.net
Unknownmail.invitinginbox.cominb.myvinmail.com
Unknownmembersarea.13premiumbeardcare.commf.invanto.io.
Orange Belgiummtv.mobistar.bemobistar.telemak.mobi
Tiscali Italianemexia.giochionline.tiscali.itwww.nemexia.it
IS4U, s.r.o.roger.is4u.cztime-tables.com
Roof Maxxsmbtrack.roofmaxx.comamerontenquiry.com
Step2steppingstones.step2.comatmr.ch.
PACESETTER SPORTSstore.pacesettersports.compacesettersports.store.erunsolutions.com
Eskişehir Osmangazi Universityukmk11.ogu.edu.trukmk.teknokongre.com
StreetSignalswealth.streetsignals.comdrobvided-metylight.com
MicroSmallCapwealth.microsmallcap.comdrobvided-metylight.com
D-BOX Technologieswww1.d-box.comlivetheaction.ws
University of Alicantewww.master-guitar-alicante.ua.eswww.master-guitar-alicante.com
Unknownwww.crownchristianuniversity.comcr.invanto.io


All of the active infrastructure of this gang is automatically tracked and listed by our Guardian products, much of it unique to our service.

The IPs that the CNAMEs point to are hosted in various places; but using our ContactDB service to normalize the IPs by Abuse desk; the top 10 networks are:


Most of the domains registered for the purposes of the CNAME takeover used NameCheap, WildWestDomains and two used Dynamic IP name services ddns.net and dyndns.org.

It should also be noted that many of the SPF records published on these CNAMEs are pointed to domains hosted by Cloudflare (healtheweb.co.uk) along with several eu.org sub-domains in which Cloudflare is also used for name services.

Let this post serve as a reminder to check your DNS for dead CNAMEs that should be removed, otherwise your domain could end up being used in this way!

Lastly, if you are receiving abuse but you don’t have the time or patience to report it, then we want to help!   You can use our free Global Reporting service; you send us the abuse report which we will validate to make sure all the basic requirements are met and then send it to the appropriate abuse desk on your behalf.

We can also do the same with user feedback from your email system; if you have a “Report Spam” function, then you can report this to us and we will report as a Feedback Loop to the originating mail system, provided they abide by RFC9477 and we know they’re trustworthy.

You can find out more about both of these services on our website.

Read More

·

We often wonder how Network Providers (ISPs and hosting providers) can best triage abuse reports and focus on appropriate reports...

·

Network Providers (ISPs and Hosting Providers) often prioritize inbound threats but overlook outbound security and threats from their customers’ devices,...

·

Email is the backbone of business communication, but it also poses significant risks with the rise of cyber threats. While...