So i heard through the chatter box grapevine that no one here could reproduce the tdl3 DNS Hijack to the router....thanks to Ades Sample from last week, which I just got around to running, inside a VM, none the less, I wish to show you why people should not do crack!
No. Time Source Destination Protocol Info
29 262.900713 192.168.239.1 239.255.255.250 SSDP NOTIFY * HTTP/1.1
30 262.911011 fe80::744c:a02f:85bb:3c84 ff02::c SSDP NOTIFY * HTTP/1.1
31 262.911635 192.168.239.1 239.255.255.250 SSDP NOTIFY * HTTP/1.1
32 262.911986 fe80::744c:a02f:85bb:3c84 ff02::c SSDP NOTIFY * HTTP/1.1
33 262.912325 192.168.239.1 239.255.255.250 SSDP NOTIFY * HTTP/1.1
34 262.912646 fe80::744c:a02f:85bb:3c84 ff02::c SSDP NOTIFY * HTTP/1.1
35 262.912961 192.168.239.1 239.255.255.250 SSDP NOTIFY * HTTP/1.1
36 262.913251 fe80::744c:a02f:85bb:3c84 ff02::c SSDP NOTIFY * HTTP/1.1
37 265.911602 192.168.239.1 239.255.255.250 SSDP NOTIFY * HTTP/1.1
38 265.911982 fe80::744c:a02f:85bb:3c84 ff02::c SSDP NOTIFY * HTTP/1.1
39 265.912432 192.168.239.1 239.255.255.250 SSDP NOTIFY * HTTP/1.1
40 265.912758 fe80::744c:a02f:85bb:3c84 ff02::c SSDP NOTIFY * HTTP/1.1
41 265.913198 192.168.239.1 239.255.255.250 SSDP NOTIFY * HTTP/1.1
42 265.913624 fe80::744c:a02f:85bb:3c84 ff02::c SSDP NOTIFY * HTTP/1.1
43 265.913969 192.168.239.1 239.255.255.250 SSDP NOTIFY * HTTP/1.1
44 265.914263 fe80::744c:a02f:85bb:3c84 ff02::c SSDP NOTIFY * HTTP/1.1
45 268.912466 192.168.239.1 239.255.255.250 SSDP NOTIFY * HTTP/1.1
46 268.913029 fe80::744c:a02f:85bb:3c84 ff02::c SSDP NOTIFY * HTTP/1.1
47 268.913460 192.168.239.1 239.255.255.250 SSDP NOTIFY * HTTP/1.1
48 268.913827 fe80::744c:a02f:85bb:3c84 ff02::c SSDP NOTIFY * HTTP/1.1
49 268.914183 192.168.239.1 239.255.255.250 SSDP NOTIFY * HTTP/1.1
50 268.914518 fe80::744c:a02f:85bb:3c84 ff02::c SSDP NOTIFY * HTTP/1.1
51 268.915200 192.168.239.1 239.255.255.250 SSDP NOTIFY * HTTP/1.1
52 268.915597 fe80::744c:a02f:85bb:3c84 ff02::c SSDP NOTIFY * HTTP/1.1
60 322.924984 192.168.239.129 lb1.
www.ms.akadns.net HTTP GET / HTTP/1.0
79 336.979825 192.168.239.129 lb1.
www.ms.akadns.net HTTP GET / HTTP/1.0
94 427.809128 192.168.239.129 ip-174-142-51-9.static.privatedns.com HTTP POST /nfoc.php HTTP/1.0
Above is TDL3 posting to its C&C
2238 477.174639 192.168.239.129 239.255.255.250 SSDP M-SEARCH * HTTP/1.1
2240 480.170658 192.168.239.129 239.255.255.250 SSDP M-SEARCH * HTTP/1.1
2243 483.173646 192.168.239.129 239.255.255.250 SSDP M-SEARCH * HTTP/1.1
2247 486.194265 192.168.239.129 192.168.239.2 HTTP GET /index.asp HTTP/1.0
2257 486.216580 192.168.239.129 192.168.239.2 HTTP GET /dlink/hwiz.html HTTP/1.0
2267 486.247775 192.168.239.129 192.168.239.2 HTTP GET / HTTP/1.0
2277 486.252723 192.168.239.129 192.168.239.2 HTTP GET /home.asp HTTP/1.0
2287 486.258471 192.168.239.129 192.168.239.2 HTTP GET /wizard.htm HTTP/1.0
2297 486.263769 192.168.239.129 192.168.239.2 HTTP GET /login.asp HTTP/1.0
2307 486.268686 192.168.239.129 192.168.239.2 HTTP GET /cgi/b/users/switchpopup/ HTTP/1.0
O my, whats this above, could it be, certainly not since everyone else seems not to be able to reproduce it.
No other malware dropped, no nadda nuttin, Kaput!
What you see is what you get, for me, this is on a hardened router, so Im not worried about the router itself getting jacked.
You all make your own judgement, but previous comments in the thread leave me to believe that the issue it totally PEBKAC