Windows – Weird wpad DNS queries, anyone seen this

internal-dnswindowswpad

I noticed that one computer (Windows 10) on our company network does some strange looking queries to our (internal) DNS server (dns.company.com).

I see the wpad-query every minute, and then every 10min or so a bunch or weird hostnames show up.

I searched for "wpad"… Web-Proxy Auto Discovery…
I turned that Off in settings->network/internet->proxy on that computer.

Now the wpad entries are less, but still occur.
Every 10min or so I still see these weird looking hostnames.

All these hostnames are the name of our DNS server, with something prepended to them.
Does anyone know what this could be?

We don't have any Windows Server/controller here. DHCP and routing is Linux, and DNS too (dnsmasq).

(the AV scan came up empty…)

Feb 17 12:57:16 dns dnsmasq[18678]: query[A] wpad.dns.company.com from 10.10.2.42
Feb 17 13:01:40 dns dnsmasq[18678]: query[A] wpad.dns.company.com from 10.10.2.42
Feb 17 13:01:40 dns dnsmasq[18678]: query[A] wpad.dns.company.com from 10.10.2.42
Feb 17 13:01:42 dns dnsmasq[18678]: query[A] tauidkyonnprqc.dns.company.com from 10.10.2.42
Feb 17 13:01:42 dns dnsmasq[18678]: query[A] ukvdexscffer.dns.company.com from 10.10.2.42
Feb 17 13:01:42 dns dnsmasq[18678]: query[A] gspmcswgglvski.dns.company.com from 10.10.2.42
Feb 17 13:01:42 dns dnsmasq[18678]: query[A] gspmcswgglvski.dns.company.com from 10.10.2.42
Feb 17 13:01:42 dns dnsmasq[18678]: query[A] tauidkyonnprqc.dns.company.com from 10.10.2.42
Feb 17 13:01:42 dns dnsmasq[18678]: query[A] ukvdexscffer.dns.company.com from 10.10.2.42
Feb 17 13:01:42 dns dnsmasq[18678]: query[A] tauidkyonnprqc.dns.company.com from 10.10.2.42
Feb 17 13:01:48 dns dnsmasq[18678]: query[A] wpad.dns.company.com from 10.10.2.42
Feb 17 13:01:48 dns dnsmasq[18678]: query[A] wpad.dns.company.com from 10.10.2.42
Feb 17 13:01:55 dns dnsmasq[18678]: query[A] wpad.dns.company.com from 10.10.2.42
Feb 17 13:01:55 dns dnsmasq[18678]: query[A] wpad.dns.company.com from 10.10.2.42

Best Answer

How does the DNS resolver setup look like on the client sending those queries? Is it part of multiple domains? Does it have a huge search list?

The way how the proxy settings are discovered is documented at https://en.wikipedia.org/wiki/Web_Proxy_Auto-Discovery_Protocol#Context

The reason why the queries just got less after you configured the browser may be that multiple browsers are installed which did not all get reconfigured by your action.

Related Topic