Torpig Phone home DNS request

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Torpig Phone home DNS request

Not applicable

Been seeing lots of detection for this threat, but the attackers are external and are trying to reach our internal DNS servers.  We have checked those dns servers along with going over other traffic and AV consoles looking for bots/trojans.  Any ideas why I would be seeing the Torpig phone home dns request threat from outside attempting to reach internal dns servers?

1 REPLY 1

L6 Presenter

If outside means Internet then you will most likely see all sort of shit thats out there.

It seems not uncommon that the noise level on the Internet (various bots and other junk) is 1-3kbit/s per ipaddress (based on own experience, might vary in your area 😉

So in your case if some internet ipaddresses tries to get to your DNS servers (which happends to have public ip's but security rules will block incoming requests from Internet) then you can use tcpdump through your internet router to verify the content of these packets and if you belive they are false positives then send it to the appid team?

  • 3597 Views
  • 1 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!