How to Deal with Conficker using DNS Sinkhole

How to Deal with Conficker using DNS Sinkhole

Created On 09/25/18 17:15 PM - Last Modified 04/20/20 23:38 PM


PAN-OS 6.0, 6.1


Conficker was first detected in November 2008, and is one of the most widespread worms that infects machines running Windows OS. Palo Alto Networks has created signatures that can detect and block the Conficker worm. Among them are Anti-Virus/Anti-Spyware signatures that detect the DNS domains used by Conficker variants. These domains are updated as soon as Conficker variants are discovered. If a WildFire license is used, the newly discovered domains are pushed to the Palo Alto Networks firewall every hour through the WildFire signatures. If a license is not used, the signatures are pushed every 24 hours and downloaded by dynamic updates to for all Palo Alto Networks devices. Updates will also be implemented in the new AV signatures in the next update interval. This protection detects when a user in the network is requesting “bad” domains. When an analysis of the logs is completed, it can be reviewed and determined that the request for the infected domain came from the local DNS server. This is possible because of the hierarchical nature of DNS.


All Palo Alto Networks platforms have an implementation of sinkhole action for queries towards malicious domains. Using this capability, the Palo Alto Networks firewall can detect the infected host in the network and send notification to the security administrator. This enables the infected workstation to be removed from the network.

How it works:

  1. The infected machine asks for a DNS resolution of an infected domain from the local DNS server.
  2. The local DNS forwards the query to the public DNS server.
  3. The Palo Alto Networks device sees the query and detects the malicious domain using the newest signatures.
  4. It overrides the DNS response with an IP address that the administrator dedicates, (sinkhole address) and sends the spoofed response to the client.
  5. The client attempts a connection to the sinkhole IP address.
  6. The Palo Alto Networks blocks the traffic and logs the attempt.
  7. The firewall administrator receives a notification about the event.
  8. The malicious client is removed from the network and cleaned.


To  configure the DNS sinkhole action, see: How to Configure DNS Sinkholing on PAN-OS 6.0

Using a Palo Alto Networks device that is dedicated to an L3 interface as a sinkhole interface, (the loopback interface can be used) perform the following steps:

  1. Add the interface to a virtual router and to a security zone, as shown in the example. This zone is different because it is where users are initiating connections. A best practice is to create a new sinkhole zone for this interface, as it is never certain where the malicious machines will send traffic.
    Screen Shot 2014-01-28 at 12.52.12 AM.png
    The creation of the new "sinkhole" zone places the created loopback interface as loopback.222.
    Screen Shot 2014-01-28 at 12.55.17 AM.png
  2. Add an IP address to the interface that is not currently being used and that is well known to the administrator.
  3. If IPv6 is used throughout the company, also assign an IPv6 address to the interface.
    Screen Shot 2014-01-28 at 12.52.53 AM.png
  4. Go to Objects > Security Profiles > Anti-Spyware, choose (or create) the Profile that will be assigned to the internet user.
  5. Under DNS Signatures, select sinkhole as an action on DNS queries. If block is chosen, it will block the queries to the malicious domains. In the logs, only the local DNS will be shown as an attacker. Choose the sinkhole IP address that was generated before ( Choose the IPv6 IP address for the IPv6 DNS queries.
  6. Select extended-capture in packet capture to allow more packets to be captured than only the one that triggered the signature. This value is defined under Device > Setup > Content-ID > Threat Detection Settings.
    Screen Shot 2014-01-28 at 12.57.58 AM.png
  7. Apply the Anti-Spyware Profile to a security rule and enable log at session end.
  8. Commit the configuration.


After the configuration is complete, validate if the traffic is captured and identify the malicious workstation.

  1. Open a test machine behind the firewall.
  2. Initiate DNS traffic for one of the Conficker domains (for this test will be used).
    Note: To check for more Conficker domains, open the Antivirus Release Notes of the dynamic updates that have been installed on the Palo Alto Networks devices. Palo Alto Networks updates these domains on a regular basis and they can be found in the Release Notes for the Antivirus signatures.
  3. Go to Devices > Dynamic-Updates > Antivirus > Release Notes and search for “conficker." There should be around 1,000 domains to review.
  4. Check the threat logs for any logs with action sinkhole.
    Screen Shot 2014-01-28 at 1.16.27 AM.png
  5. If needed, check the packet capture.
    Screen Shot 2014-01-28 at 1.17.19 AM.png
  6. Generate a custom report using the "sinkhole action" as a filter in the query builder and schedule it to run daily.
    Screen Shot 2014-01-28 at 1.19.38 AM.png
  7. Check the report the following day to confirm it's collecting and displaying data.
    Screen Shot 2014-01-28 at 1.21.10 AM.png

Following the steps above tracks and isolates malicious workstations in the designated network.

owner: ialeksov

  • Print
  • Copy Link

Choose Language