Dynamic DNS Abuse Chris Baker Senior Principal Data Analyst dig @slide.deck chris.baker ; <<>> DiG 9.8.3-P1 <<>> datumrich.com ;; global options: +cmd ;; Got answer: ;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 1337H@X0R ;; flags: qr aa ra; QUERY: 1, ANSWER: 1, AUTHORITY: 1, ADDITIONAL: 0 ;; QUESTION SECTION: chris.baker. 3600 chris.baker. 138547 chris.baker. 3600 IN NS ns1.dyn.com. IN MX cbaker@dyn.combaker@dyn.com IN TWEET @datumrich ;; Query time: 111 msec ;; SERVER: 127.0.0.1#53(127.0.0.1) ;; WHEN: Wed Aug 16 12:00:00 2016 ;; MSG SIZE rcvd: 99 Overview Contents 1. Dynamic DNS Service • Criminal Cost Model 2. Data Available for Analysis 3. Interaction Patterns 4. Adapting Methodology • Jscript Infection • DNS Beaconing Why Dynamic DNS? Frank Denis @jedisct1: “The price of an IP Address ( V4 of course ) is greater than the price of a domain name and the price of a domain is greater than the price of a subdomain.” The business of Dynamic DNS is providing sub domains as a service Investment Model A criminal expends an account or a credit card when they create an account on our platform The operating cost needs to be dwarfed by the profitability their activity otherwise wouldn’t they do something else? ddns.hostname.tld ddns.hostname.tld ddns.hostname.tld ddns.hostname.tld Overview / Summary Creates: fj7e.is-an-actor.com Phished person requests fj7e.is-an-actor.com They are redirect to: http://themanicnomad.com/wordpress/wp-content/plugins/rthytrghf/index.htm Example Page Mile High Technical Summary Modifies: fj7e.is-an-actor.com Change fj7e.is-an-actor.com to sinkhole Sinkhole -> http://<Sinkhole-IP>/campaigntag-html.htm Total Possible Audience ( everyone in the spam list ) Audience Solicited Message reached inbox Message Opened Link Clicked Credentials Submitted Apple Accounts We have some sample data related to Apple phishing that are interesting Sample Set of 45 Campaigns Summary stats: Users who clicked the link / visited the redirection landing page –Min: 18 –Median: 187 –Mean: 467 –Max 1689 Resale Value of Accounts Min: Median: Mean: Max 90% $88.00 $924.00 $2,310.00 $8,360.00 70% $71.50 $720.50 $1,798.50 $6,501.00 50% $49.50 $517.00 $1,287.00 $4,647.50 30% $27.50 $308.00 $770.00 $2,788.50 If we take the median price of $5.50 per account we can estimate the profitability of various rates of credential submission and resale Data Trail: DDNS Host Creation Username Date time IP Address User Agent String Datetime Hostname IP Address URL What is the rate of hostname creation? How many different end points? How many different hostnames? End User Data Trail: Contrast Account Creation Username Date time IP Address User Agent Hostname Creation Datetime Hostname IP Address URL User Agent Was the account created from an IP in the same netblock as the IP the hostname is set to resolve to? Does the GeoIP of address place them in the same country? Continent? Example: Phishing Hostname Created u876trtr.fuettertdasnetz.de uy85rr.is-a-candidate.org 3yi87.is-a-geek.org awu7o.is-a-soxfan.org hguy5434rer.is-with-theband.com ui783ert.from-ok.com d3678iyhgfd.space-to-rent.com xey6hg.is-a-socialist.com 2hmmn7.from-wv.com a54hgh.from-ky.com yu74er.isa-geek.net 3gtij5.ham-radio-op.net If we strip off the domain portion u876trtr uy85rr 3yi87 awu7o hguy5434rer ui783ert d3678iyhgfd xey6hg 2hmmn7 a54hgh yu74er 3gtij5 Names and Endpoints Lets review the data •User created a total of 12 domains •User’s account contains 12 domain names •Names appear to be pseudo-randomly generated •All created within 10 mins of purchasing the service •All of the domains resolve to the same wordpress instance • Wordpress instance URI contains string “wp-content” • Wordpress instance URI contains pseudo-random generated html end point Rate of name creation, number of persistent names, and the end points all point to phishing

pdf文档 2016-《Chris Baker-Dynamic DNS Abuse》

安全研究库 > 网络论坛材料 > 2016ISC-威胁情报技术与趋势论坛 > 文档预览
58 页 0 下载 37 浏览 0 评论 0 收藏 3.0分
温馨提示:如果当前文档出现乱码或未能正常浏览,请先下载原文档进行浏览。
2016-《Chris Baker-Dynamic DNS Abuse》 第 1 页 2016-《Chris Baker-Dynamic DNS Abuse》 第 2 页 2016-《Chris Baker-Dynamic DNS Abuse》 第 3 页 2016-《Chris Baker-Dynamic DNS Abuse》 第 4 页 2016-《Chris Baker-Dynamic DNS Abuse》 第 5 页
下载文档到电脑,方便使用
还有 53 页可预览,继续阅读
本文档由 张玉竹2022-04-08 10:02:43上传分享
给文档打分
您好可以输入 255 个字符
安信天行文库的中文名是什么?( 答案:安信天行 )
评论列表
  • 暂时还没有评论,期待您的金玉良言