If you are seeing queries for this domain, than you are likely participating in DNS Amplification attacks and your DNS server is probably reachable from the internet and has recursion enabled.
If you are seeing responses for this domain.. unlucky. You are currently beeing DDOS-ed! Good luck.
IPtables:
There are two iptable rules available. If your distribution supports Iptables 'u32' module pick this one, otherwise use the 'string' rule.
*Fixed typo in rule
U32:
iptables --insert INPUT -p udp --dport 53 -m u32 --u32 "0x28&0xFFDFDFDF=0x0b434845 && 0x2c&0xDFDFDFDF=0x41545348 && 0x30&0xDFDFDFDF=0x4152455a && 0x34&0xFFDFDFDF=0x03434f4d && 0x38&0xFF000000=0x00000000" -j DROP -m comment --comment "DROP DNS Q cheatsharez.com"
More U32 rules can be found here:
https://github.com/smurfmonitor/dns-iptables-rules/blob/master/domain-blacklist.txt
String:
iptables --insert INPUT -p udp --dport 53 -m string --from 40 --to 57 --algo bm --hex-string '|0B636865617473686172657a03636f6d00|' -j DROP -m comment --comment "DROP DNS Q cheatsharez.com"
More Iptables rules for the STRING module can be found here:
https://github.com/smurfmonitor/dns-iptables-rules/blob/master/domain-blacklist-string.txt
Source:
94.102.49.37
Name server:
;; ANSWER SECTION:
cheatsharez.com. 17508 IN NS ns2.cheatsharez.com.
cheatsharez.com. 17508 IN NS ns1.cheatsharez.com.
;; ADDITIONAL SECTION:
ns2.cheatsharez.com. 17508 IN A 89.248.168.94
ns1.cheatsharez.com. 17508 IN A 89.248.168.94
Response:
A 242
NS 2
SOA 1
Rsize 3969
Whois
Whois Server Version 2.0
Domain names in the .com and .net domains can now be registered
with many different competing registrars. Go to http://www.internic.net
for detailed information.
Domain Name: CHEATSHAREZ.COM
Registrar: ENOM, INC.
Whois Server: whois.enom.com
Referral URL: http://www.enom.com
Name Server: NS1.CHEATSHAREZ.COM
Name Server: NS2.CHEATSHAREZ.COM
Status: clientTransferProhibited
Updated Date: 11-nov-2013
Creation Date: 11-nov-2013
Expiration Date: 11-nov-2014
>>> Last update of whois database: Tue, 12 Nov 2013 06:48:31 UTC <<<
NOTICE: The expiration date displayed in this record is the date the
registrar's sponsorship of the domain name registration in the registry is
currently set to expire. This date does not necessarily reflect the expiration
date of the domain name registrant's agreement with the sponsoring
registrar. Users may consult the sponsoring registrar's Whois database to
view the registrar's reported date of expiration for this registration.
The Registry database contains ONLY .COM, .NET, .EDU domains and
Registrars.
Domain Name: CHEATSHAREZ.COM
Creation Date: 2013-11-11 16:29:00Z
Registrar Registration Expiration Date: 2014-11-11 16:29:00Z
Registrar: ENOM, INC.
Reseller: NAMECHEAP.COM
Registrant Name: WHOISGUARD PROTECTED
Registrant Organization: WHOISGUARD, INC.
Registrant Street: P.O. BOX 0823-03411
Registrant City: PANAMA
Registrant State/Province: PANAMA
Registrant Postal Code: NA
Registrant Country: PA
Admin Name: WHOISGUARD PROTECTED
Admin Organization: WHOISGUARD, INC.
Admin Street: P.O. BOX 0823-03411
Admin City: PANAMA
Admin State/Province: PANAMA
Admin Postal Code: NA
Admin Country: PA
Admin Phone: +507.8365503
Admin Phone Ext:
Admin Fax: +51.17057182
Admin Fax Ext:
Admin Email: 33A60AC6876943FBB733252AE9E1386D.PROTECT@WHOISGUARD.COM
Tech Name: WHOISGUARD PROTECTED
Tech Organization: WHOISGUARD, INC.
Tech Street: P.O. BOX 0823-03411
Tech City: PANAMA
Tech State/Province: PANAMA
Tech Postal Code: NA
Tech Country: PA
Tech Phone: +507.8365503
Tech Phone Ext:
Tech Fax: +51.17057182
Tech Fax Ext:
Tech Email: 33A60AC6876943FBB733252AE9E1386D.PROTECT@WHOISGUARD.COM
Name Server: NS1.CHEATSHAREZ.COM
Name Server: NS2.CHEATSHAREZ.COM
We reserve the right to modify these terms at any time. By submitting
this query, you agree to abide by these terms.
Version 6.3 4/3/2002
No comments:
Post a Comment