Security company ESET has published new details and features about the Win32/Sality DNS changer on its blog
Win32 /Sality is a family of malware used by a peer-to-peer botnet since at least 2003. It is a file infector and a trojan downloader, primarily used to send spam, although it has been used for various purposes, such as mimicking advertising network traffic, distributed denial of service attacks, or cracking VoIP accounts. All commands and files exchanged over the Sality P2P network are digitally signed. Its architecture, as well as the longevity of the botnet, indicate that it has been designed and programmed flawlessly.
ESET has been monitoring the Win32/Sality network for some time and has recorded more than 115,000 IP addresses that are used by so-called “super peers” to keep the botnet alive. The botnet thus transmits its commands to regular peers.
The security company has been monitoring and recording the network behavior for quite some time now. Recently, researchers have discovered some new features: it has acquired the ability to change the primary DNS address of routers, which is very different from the usual FTP password theft or spambot functionality we know from Win32/Sality. According to ESET telemetry data, the new feature first appeared at the end of October 2013. It was first reported then by Dr. Web, which published a technical analysis of a feature, the IP address scanner. They named it Win32/RBrute.
The new goal: changing a router's primary DNS
This feature adds a new dimension to the functionality of Win32/Sality. The first component, detected by ESET as Win32/RBrute.A, scans the Internet for router administration pages to change the primary DNS server entry. The DNS servers added by the malware redirect users to a fake Google Chrome installation page whenever they try to open pages with the words “google” or “facebook” in the URL. The binary distributed via this installation page is actually Win32/Sality, thus providing a way for the owners of the Sality botnet to further increase the size of their victim base with infected routers.
The IP address used as the primary DNS on the victim's router is part of the Win32/Sality network. In reality, Win32/Sality installs another malware, detected by ESET as Win32/RBrute.B. Win32/RBrute.B operates as a DNS or HTTP proxy to deliver the fake Google Chrome installer.
the company
ESET has published a list of routers that are vulnerable to the Win32/RBrute.A malware:
- Cisco routers matching “level_15_” in the HTTP realm attribute
- D-Link DSL-2520U
- D-Link DSL-2542B
- D-Link DSL-2600U
- Huawei EchoLife
- TP-LINK
- TP-Link TD-8816
- TP-Link TD-8817
- TP-Link TD-8817 2.0
- TP-Link TD-8840T
- TP-Link TD-8840T 2.0
- TP-Link TD-W8101G
- TP-Link TD-W8151N
- TP-Link TD-W8901G
- TP-Link TD-W8901G 3.0
- TP-Link TD-W8901GB
- TP-Link TD-W8951ND
- TP-Link TD-W8961ND
- TP-Link TD-W8961ND
- ZTE ZXDSL 831CII
- ZTE ZXV10 W300
When the malware discovers the router’s admin page, the command and control (C&C) center sends a short list of about ten passwords to the bot and instructs it to perform a brute force attack to discover the router’s password. When the bot manages to connect, it immediately changes the router’s primary DNS server settings. Once it does, all DNS queries made by users go through the “hacked” DNS server, which redirects them to a fake Chrome installation page.
If you are interested in the technical analysis of Win32/Sality DNS changer, you can find it on the ESET


