
Dangling CNAME Attacks and Sub-domain Takeovers

TLDR; we detected a sizable number of sub-domain takeovers affecting many educational establishments and some popular domains, a list is provided below.

Things have been very busy around here lately; this week, we’ve quietly released a completely re-written and re-architected backend to our Guardian platform using the experience that we’ve gained in the 5 years since it was first launched and has taken over a year to complete.

This new backend will provide the foundation for Guardian Mail to continue to grow over the coming years, and has already provided some interesting discoveries, and one that I want to share with you now.

Blocking A Spam Gang

For some years now, the team and I have been tracking a fairly prolific spam gang, who have been relatively successful in evading other companies’ spam detection but we have been successfully blocking, thanks to many of our customers sharing anonymised SMTP transaction data with us to help us track this gang.

During the recent testing phase of our new processing infrastructure; we started to see popular domains unexpectedly appearing in our detections related to this particular spam gang.

Upon closer inspection, we discovered that they had taken over portions of some very popular domains by means of dangling CNAME attacks.   This is where an attacker discovers a CNAME in a company’s domain which points to a hostname of a domain that has expired, they then register that domain name and set-up infrastructure on that hostname, effectively taking over the sub-domain for themselves.

This is obviously very dangerous for the domains concerned because it opens them up to Phishing and Malware attacks, cookie harvesting, and reputational damage.


Abusix Does Not Gatekeep

Luckily for these domains, in this case, this particular gang appears to simply use the domains to “fly under the radar” to send spam, phishing and malware to others, rather than using these to attack the parent domain, which would likely be far more damaging.  They also mixed the infrastructure, making it easier for us to discover other CNAMEs that they had taken over.

At Abusix, rather than gatekeep intelligence like this, our goal is to get stuff shared and taken down, so we’ve copied all the relevant security teams with this information and we’re providing it here to make it known to others.

Here is the list of affected entities, the hostnames and CNAMEs that they point to:

San Diego Supercomputer Center (UC San Diego)brak.sdsc.eduwww.biologicalnetworks.org.
University of California (UCLA)user2014.stat.ucla.eduucla.user2014.org.
Georgetown Universitygerms.georgetown.eduwww.georgetownems.COM.
SOMMARØY Hotelmeny.sommaroy.notasti.store.
Heriot Watt Universitytransition.hw.ac.uktransitionheriot-watt.org.uk.
Olivet Nazarene Universityglimmerglass.olivet.eduonuglimmerglass.com.
Vodafone Italyhackdays.vodafone.itwww.hackdays.it.
University of California, Davis (UC Davis)ucdim.ucdavis.eduwww.ucdim.com.
Fantasyland Hotelinfo.fantasylandhotel.comfanatyslandhotel.com.
UKRAINE FOOTBALL CORPORATIONgames.ukrainefootball.neteforbgames.com.
Falmouth Universityrane.falmouth.ac.ukrane-research.org.
The George Washington Universitygsehd-online.gwu.edu.account.hobsonsms.com.
Georgetown Universityjournal.georgetown.edudigitalleadershipcouncil.com.
Illinois Techcourseconstruct.iit.edu.courseconstruct.mass-hosting.com.
International Data Groupsafeguard.idg.comcentral.crashpan.com.
University of La Vernedining.laverne.eduwww.lavernedining.com.
Kentucky Community & Technical College Systemlegacy.bigsandy.kctcs.edu.www.bsctcapps.com.
Greenville Universityprofessionals.greenville.edu.account.hobsonsms.com.
New York Medical Collegeshspprograms.nymc.edu.account.hobsonsms.com.
Bacone Collegeonline.bacone.edu.account.hobsonsms.com.
University of Bordeauxwww.sb2.u-bordeaux.fr.synthetic-biology-bordeaux.fr.
Connecticut’s Official State Websitecdcsstage.doc.ct.gov.doccdcsstage.ctdoc.org.
King Juan Carlos Universityclubdeportivo.urjc.es.clubdeportivourjc.es.
AUDI UKplayout.audi.co.ukplayout.mioeverywhere.tv.
CNN Moneym.cnnmoney.commcnnmoney.codewithsnow.com.
University of Nicemiage.unice.frwww.miage-nice.fr
KODI Collectivealliancetitleprint.digitallizard.comwww.alliancetitleprint.com
Essec Business Schoolcampus2020.essec.edu.www.campus2020.fr.
Dave’s Runningstore.davesrunning.com.davesrunning.store.erunsolutions.com.
Gemological Institute of Americawww.logowear.gia.edu.gia.logsoftwear.com.
International Association of Business Communicatorsnorthnz.iabc.com.www.iabc-northnz.org.
MDsave Incorporatedstaging-api-documentation.mdsave.com.hubs.docql.io.
Pusan National Universityasiahpst2016.pusan.ac.kr.asiahpst2016.com.
NEXT Universitypromo.nextuniversity.com.ubouncepages.com.
Université Lavalwww.dipublique.chaire.ulaval.ca.chaire-dipublique.djosse.fr.
Universidade Federal do Rio de Janeiromx3.limc.ufrj.br.tabulae.net.
Universitat Politècnica de Catalunya BarcelonaTechinnotex.upc.edu.innotexcenter.com.
CZECH ATHLETIC ASSOCIATIONkviz.atletika.cz.csatletika.brandzfriendz.net
IdecNet SAarnedonet.idecnet.com.www.arnedonet.com.
Chicco Italiacataloghi.chicco.com.drake.ipaperitaly.com.
UC Santa Cruzwww.soar.ucsc.edu.www.soarucsc.org.
Launch Medicaltrack.getmyphoenix.com.morthelorpowasure.com.
Artsana Groupmedicalcenter.artsana.it.drake.ipaperitaly.com.
Weber Shandwickahub-qa.webershandwick.comahub-qa.wsbinfra.net
Orderfox Schweiz AGapi.orderfox.comorderfox-api.orderfox-prod.com
Seoul National University of Science & Technologyasrri.seoultech.ac.krasrri.kr
Nexstar Media Inc.blogs.wane.comlb.linapps.io.
Wine Aligncru.winealign.comatmr.ch.
GovAssist, LLCgo.visaexpress.us.comknomomain-enquate.com.
JFK School of Law at National Universitygo.jfku.edumkto-ab040129.com
Savvy + Co. Real Estateimg.savvyandcompany.comimb.ggwz.us
The George Washington Universitym.digitalcommunity.gwu.edu web-01.influence-technologies.com.
Ashford Luxury Watchesmail.ashford.commail1.hswwco.net
Orange Belgiummtv.mobistar.bemobistar.telemak.mobi
Tiscali Italianemexia.giochionline.tiscali.itwww.nemexia.it
IS4U, s.r.o.roger.is4u.cztime-tables.com
Roof Maxxsmbtrack.roofmaxx.comamerontenquiry.com
PACESETTER SPORTSstore.pacesettersports.compacesettersports.store.erunsolutions.com
Eskişehir Osmangazi Universityukmk11.ogu.edu.trukmk.teknokongre.com
D-BOX Technologieswww1.d-box.comlivetheaction.ws
University of Alicantewww.master-guitar-alicante.ua.eswww.master-guitar-alicante.com

All of the active infrastructure of this gang is automatically tracked and listed by our Guardian products, much of it unique to our service.

The IPs that the CNAMEs point to are hosted in various places; but using our ContactDB service to normalize the IPs by Abuse desk; the top 10 networks are:

Most of the domains registered for the purposes of the CNAME takeover used NameCheap, WildWestDomains and two used Dynamic IP name services ddns.net and dyndns.org.

It should also be noted that many of the SPF records published on these CNAMEs are pointed to domains hosted by Cloudflare (healtheweb.co.uk) along with several eu.org sub-domains in which Cloudflare is also used for name services.

Let this post serve as a reminder to check your DNS for dead CNAMEs that should be removed, otherwise your domain could end up being used in this way!

Lastly, if you are receiving abuse but you don’t have the time or patience to report it, then we want to help!   You can use our free Global Reporting service; you send us the abuse report which we will validate to make sure all the basic requirements are met and then send it to the appropriate abuse desk on your behalf.

We can also do the same with user feedback from your email system; if you have a “Report Spam” function, then you can report this to us and we will report as a Feedback Loop to the originating mail system, provided they abide by RFC9477 and we know they’re trustworthy.

You can find out more about both of these services on our website.

