Discussion:
strange queries incrementing letter by letter
Kevin Kretz
2021-05-07 17:32:23 UTC
Permalink
I see occasional series of queries like this, from within my network and among disparate types of host (linux, windows):

If there's a host called

hostname.mynet.com

I'll see a sequence of queries like

hostname.m
hostname.my
hostname.myn
hostname.myne
hostname.mynet
hostname.mynet.c
hostname.mynet.co
hostname.mynet.com

Can anyone tell me what this is?


thanks

Kevin
Kevin A. McGrail
2021-05-07 18:21:29 UTC
Permalink
Weird.

Thoughts are:

Bad software?  What we call ratware.

UDP/TCP Firewall issues?

Regards,

KAM
Post by Kevin Kretz
I see occasional series of queries like this, from within my network
If there's a host called
hostname.mynet.com
I'll see a sequence of queries like
hostname.m
hostname.my
hostname.myn
hostname.myne
hostname.mynet
hostname.mynet.c
hostname.mynet.co
hostname.mynet.com
Can anyone tell me what this is?
thanks
Kevin
_______________________________________________
Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list
ISC funds the development of this software with paid support subscriptions. Contact us at https://www.isc.org/contact/ for more information.
bind-users mailing list
https://lists.isc.org/mailman/listinfo/bind-users
--
*Kevin A. McGrail*
/CEO Emeritus/
*Peregrine Computer Consultants Corporation*
+1.703.798.0171 ***@pccc.com
 https://pccc.com/ https://raptoremailsecurity.com

10311 Cascade Lane, Fairfax, Virginia 22032-2357 USA
Mark Andrews
2021-05-07 19:11:30 UTC
Permalink
Some piece of software trying to speed up resolution by resolving names as you type.
--
Mark Andrews
Post by Kevin A. McGrail

Weird.
Bad software? What we call ratware.
UDP/TCP Firewall issues?
Regards,
KAM
Post by Kevin Kretz
If there's a host called
hostname.mynet.com
I'll see a sequence of queries like
hostname.m
hostname.my
hostname.myn
hostname.myne
hostname.mynet
hostname.mynet.c
hostname.mynet.co
hostname.mynet.com
Can anyone tell me what this is?
thanks
Kevin
_______________________________________________
Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list
ISC funds the development of this software with paid support subscriptions. Contact us at https://www.isc.org/contact/ for more information.
bind-users mailing list
https://lists.isc.org/mailman/listinfo/bind-users
--
<PCCC-Logo-Vertical-Blue-75x75.png>
<raptor-logo-vertical-blue-75x75.png>
Kevin A. McGrail
CEO Emeritus
Peregrine Computer Consultants Corporation
<phone_sig_icon_orange.png>
+1.703.798.0171
<email_sig_icon_orange.png>
<web_sig_icon_orange.png>
https://pccc.com/
<web_sig_icon_orange.png>
https://raptoremailsecurity.com
<location_sig_icon_orange.png>
10311 Cascade Lane, Fairfax, Virginia 22032-2357 USA
_______________________________________________
Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list
ISC funds the development of this software with paid support subscriptions. Contact us at https://www.isc.org/contact/ for more information.
bind-users mailing list
https://lists.isc.org/mailman/listinfo/bind-users
Ondřej Surý
2021-05-07 19:29:36 UTC
Permalink
aka browsers

--
Ondřej SurÃœ — ISC (He/Him)

My working hours and your working hours may be different. Please do not feel obligated to reply outside your normal working hours.
Some piece of software trying to speed up resolution by resolving names as you type.
--
Mark Andrews
Post by Kevin A. McGrail

Weird.
Bad software? What we call ratware.
UDP/TCP Firewall issues?
Regards,
KAM
Post by Kevin Kretz
If there's a host called
hostname.mynet.com
I'll see a sequence of queries like
hostname.m
hostname.my
hostname.myn
hostname.myne
hostname.mynet
hostname.mynet.c
hostname.mynet.co
hostname.mynet.com
Can anyone tell me what this is?
thanks
Kevin
_______________________________________________
Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list
ISC funds the development of this software with paid support subscriptions. Contact us at https://www.isc.org/contact/ for more information.
bind-users mailing list
https://lists.isc.org/mailman/listinfo/bind-users
--
<PCCC-Logo-Vertical-Blue-75x75.png>
<raptor-logo-vertical-blue-75x75.png>
Kevin A. McGrail
CEO Emeritus
Peregrine Computer Consultants Corporation
<phone_sig_icon_orange.png>
+1.703.798.0171
<email_sig_icon_orange.png>
<web_sig_icon_orange.png>
https://pccc.com/
<web_sig_icon_orange.png>
https://raptoremailsecurity.com
<location_sig_icon_orange.png>
10311 Cascade Lane, Fairfax, Virginia 22032-2357 USA
_______________________________________________
Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list
ISC funds the development of this software with paid support subscriptions. Contact us at https://www.isc.org/contact/ for more information.
bind-users mailing list
https://lists.isc.org/mailman/listinfo/bind-users
_______________________________________________
Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list
ISC funds the development of this software with paid support subscriptions. Contact us at https://www.isc.org/contact/ for more information.
bind-users mailing list
https://lists.isc.org/mailman/listinfo/bind-users
Charles Elliott
2021-05-08 11:09:23 UTC
Permalink
It could also be a really cleaver security ploy to see if there are any close matches to your domain name or URL that turn up copycats or bad guys.

For example, typing Walmrat into Chrome and pressing Ctrl+Enter used turn up a copycat Walmart site, but now one accesses a correctly spelled

Walmart URL and the actual website. As another illustration, at least it used to be common with misspelled bank names to access a copycat

website or one or more claiming a special connection to the actual bank.



The Web is like Europe before and during the 1100 s when it was common for unemployed soldiers to roam the highways and byways looking

for people to rob and damsels to distress. We need something like knighthood, the first state police.



Charles Elliott

From: bind-users [mailto:bind-users-***@lists.isc.org] On Behalf Of Ondrej SurÜ
Sent: Friday, May 7, 2021 3:30 PM
To: Mark Andrews <***@isc.org>
Cc: bind-***@lists.isc.org
Subject: Re: [External] strange queries incrementing letter by letter



aka browsers

--

Ondřej SurÃœ — ISC (He/Him)



My working hours and your working hours may be different. Please do not feel obligated to reply outside your normal working hours.





On 7. 5. 2021, at 21:11, Mark Andrews <***@isc.org <mailto:***@isc.org> > wrote:

Some piece of software trying to speed up resolution by resolving names as you type.
--
Mark Andrews





On 8 May 2021, at 04:21, Kevin A. McGrail <***@pccc.com <mailto:***@pccc.com> > wrote:



Weird.

Thoughts are:

Bad software? What we call ratware.

UDP/TCP Firewall issues?

Regards,

KAM

On 5/7/2021 1:32 PM, Kevin Kretz wrote:

I see occasional series of queries like this, from within my network and among disparate types of host (linux, windows):



If there's a host called



hostname.mynet.com



I'll see a sequence of queries like



hostname.m

hostname.my

hostname.myn

hostname.myne

hostname.mynet

hostname.mynet.c

hostname.mynet.co

hostname.mynet.com



Can anyone tell me what this is?



thanks


Kevin







_______________________________________________
Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list

ISC funds the development of this software with paid support subscriptions. Contact us at https://www.isc.org/contact/ for more information.


bind-users mailing list
bind-***@lists.isc.org <mailto:bind-***@lists.isc.org>
https://lists.isc.org/mailman/listinfo/bind-users
--
<PCCC-Logo-Vertical-Blue-75x75.png>



<raptor-logo-vertical-blue-75x75.png>



Kevin A. McGrail
CEO Emeritus
Peregrine Computer Consultants Corporation



<phone_sig_icon_orange.png>

+1.703.798.0171

<email_sig_icon_orange.png>

***@pccc.com <mailto:***@pccc.com>


<web_sig_icon_orange.png>

https://pccc.com/

<web_sig_icon_orange.png>

https://raptoremailsecurity.com




<location_sig_icon_orange.png>

10311 Cascade Lane, Fairfax, Virginia 22032-2357 USA

_______________________________________________
Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list

ISC funds the development of this software with paid support subscriptions. Contact us at https://www.isc.org/contact/ for more information.


bind-users mailing list
bind-***@lists.isc.org <mailto:bind-***@lists.isc.org>
https://lists.isc.org/mailman/listinfo/bind-users

_______________________________________________
Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list

ISC funds the development of this software with paid support subscriptions. Contact us at https://www.isc.org/contact/ for more information.


bind-users mailing list
bind-***@lists.isc.org <mailto:bind-***@lists.isc.org>
https://lists.isc.org/mailman/listinfo/bind-users
Loading...