Community discussions

MikroTik App
 
User avatar
webasdf
Frequent Visitor
Frequent Visitor
Topic Author
Posts: 87
Joined: Mon Jan 26, 2009 6:37 pm

DNS is changing to 195.3.144.115

Tue Jul 21, 2015 6:38 pm

Has anybody else seen a Mikrotik router change its DNS IP to 195.3.144.115? We have several out in the field that apparently have changed themselves.
 
User avatar
pukkita
Trainer
Trainer
Posts: 3051
Joined: Wed Dec 04, 2013 11:09 am
Location: Spain

Re: DNS is changing to 195.3.144.115

Tue Jul 21, 2015 6:49 pm

Does any have a dhcp-client, or any kind of VPN tunnel interface running?
 
User avatar
webasdf
Frequent Visitor
Frequent Visitor
Topic Author
Posts: 87
Joined: Mon Jan 26, 2009 6:37 pm

Re: DNS is changing to 195.3.144.115

Tue Jul 21, 2015 7:12 pm

No DHCP clients. I just checked the routers that were affected this last round where it was somehow changed automatically. Good thought though.
 
andyanthoine
newbie
Posts: 43
Joined: Wed Jun 12, 2013 3:41 am

Re: DNS is changing to 195.3.144.115

Wed Jul 22, 2015 2:00 am

Has anybody else seen a Mikrotik router change its DNS IP to 195.3.144.115? We have several out in the field that apparently have changed themselves.
I guess you use PPPOE on it ? Did you check the USE PEER DNS checkbox ?

If yes, your DNS should be dynamic, if the provider changes them, it will update yours.

If not, be careful that you are not attacked, change your password etc.

Andy
 
User avatar
karlisi
Member
Member
Posts: 439
Joined: Mon May 31, 2004 8:09 am
Location: Latvia

Re: DNS is changing to 195.3.144.115

Wed Jul 22, 2015 2:04 pm

It can be some malware, this IP address belongs to RN Data SIA (195.3.144.0/22) and it is connected with ZeroAccess Botnet.
 
User avatar
pants6000
Frequent Visitor
Frequent Visitor
Posts: 87
Joined: Fri Sep 26, 2014 5:30 am

Re: DNS is changing to 195.3.144.115

Thu Jul 23, 2015 8:09 am

Do you have UPNP enabled on these routers?
 
User avatar
webasdf
Frequent Visitor
Frequent Visitor
Topic Author
Posts: 87
Joined: Mon Jan 26, 2009 6:37 pm

Re: DNS is changing to 195.3.144.115

Thu Jul 23, 2015 7:13 pm

I found the issue. Unfortunately, there was a password defaulted on these routers. SSH scanners associated with this ugly botnet probably found them and changed DNS for their own nefarious purposes. Scary stuff. Passwords have been changed :)

Thanks for the tips everyone!

Who is online

Users browsing this forum: anav, Bing [Bot], maldridge and 82 guests