cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
9031
Views
0
Helpful
6
Replies

MALWARE-CNC Torpig bot sinkhole server DNS lookup

antonioa
Level 1
Level 1

I'm trying to figure out an interesting case I have on hand. Our SF IPS-es running on 6.1.0.3 (build 57) are detecting this  CNC torpig bot  sinkhole server DNS lookup events coming from our Internal Barracuda ESGs. We had called Barracuda technical support but they can't find from their side what is causing the issue.  I talked to Cisco TAC and they believe there is a client relaying DNS queries thru these barracuda boxes.  Has anyone experienced this same issue I'm having? 

6 Replies 6

jgallegos74
Level 1
Level 1

Hello antonioa, I am experiencing this issue as well right now.  Was this issue ever resolved?

Hello, 

 

We are seeing a similar issue, did either manage to find the problem?

Still not resolved on my end.

Elijh80
Level 1
Level 1

I am also seeing this particular situation.

RingoC
Level 1
Level 1
Any update on this?...I'm also seeing this

pmello
Level 1
Level 1

I had the same issue/event.

From previous inquiries to Barracuda support I know that the Barracuda will parse an email and follow the links looking for nefarious content 

 

Googling the error I find that what's happening is someone is doing a DNS lookup on a known Botnet, that lookup is being redirected to a "sinkhole" server that will blackhole the attempted Bobnet connection.

Unless your Firepower is in Drop mode, you should see that the Barracuda (hopefully) blocks this email.

 

Pete