Skip to main content
menatwork
Visitor III
June 28, 2024
Question

Botnetconnectionwarning polyfill.io - some brainstorming please ;-)

  • June 28, 2024
  • 4 replies
  • 3400 views

Hi folks,

I wonder if I interpret the following right. The "Domain" polyfill.io is listed at Fortiguardservices as "bad" since 26th of June 2024.  

 

See: Threat Signal Report | FortiGuard Labs

 

We recognized in our FGT, that we have logs about botnet-cc-connections exactly to this domain (polyfill.io). Our investigations show that our DC is trying to lookup the domain. When it tries it, the FGT redirects the request, which is good.

 

My assumption now is, that our clients (or some of them) are trying to lookup polyfill.io, ask our Domaincontroller/DNS and the DC/DNS is forwarding the request to the provider-dns. Then the FGT blocks it.

 

As polyfill.io was not "bad" before 26th of june and a lot of websites use the services of polyfill.io i further assume, that our clients are simply surfing to websites, which use this "tool" (polyfill) and then we got the botnetwarning.

 

We have not found any indication of a infection at our internal computers till now.

 

So, what do you think? Is my assumption something you say: Yes this is a way it might be, or do you think that this has to be an infection of our internal client(s)?

 

Thanks!

4 replies

pminarik
Staff
Staff
June 28, 2024

Given how fresh the advisory about polyfill.io being taken over by a malicious actor is, this is more likely to be innocent clients accessing regular websites that are using the polyfill JS library. Still, it won't hurt paying closer attention to your clients just to be safe.

 

Btw, according to the original source's updates ( https://sansec.io/research/polyfill-supply-chain-attack ), it looks like the cdn.polyfill.io domain has been withdrawn completely from DNS (doesn't resolve to anything anymore), so risks from this specific hostname should be mitigated for now. But look out for the others (mentioned in the same link).

FS1
Visitor III
July 23, 2024

I have the same kind of issue. Getting several IOC's where polyfill.io is blocked, which is good. But looking at the destination IP in the IOC message it looks like this IP is belonging to Fortinet? Can't put my finger on it.

pminarik
Staff
Staff
July 23, 2024

If the IP is 208.91.112.55, that means it was initially caught and blocked/redirected by the DNS filter, as this is the default redirect-IP for blocked DNS requests.

FS1
Visitor III
July 23, 2024

Ok, I get it now. This is indeed the IP. Thanks for the quick reply. 

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!