C2 hunting: part 1
More in General
- Operation Chewbacca
At the end of June, the PT ESC team, during incident investigations, discovered a new group…
- Ding, ding — who's there?
Ding, ding — who's there? 🔔 The cyber intelligence group of Positive Technologies' expert security center…
- Enterprise-grade validation system with schema support
Enterprise-grade validation system with schema support (c) The author of a dozen trojans who forgot to…
- One less feathered thief — plus one hundred rating points!
One less feathered thief — plus one hundred rating points! 😵 The Threat Intelligence team at…
- DragonDoll: a matryoshka in the world of Android spies
DragonDoll: a matryoshka in the world of Android spies 🪆 At the beginning of this spring,…
C2 hunting: part 1. Expanding visibility of hackers’ network infrastructure 😜
Often when investigating an attack, performing TI analysis, or DFIR, a specialist encounters network indicators of compromise (IP addresses, domains, subdomains, URLs) that are not identified by TIPs, feeds, or third-party services, yet are malicious within the context of the investigation. What can a specialist do in this case? First and foremost, it is necessary to expand the scope of visibility around the indicator.
💡 Expanding visibility is the process of obtaining new network indicators related to the attack or potentially associated with it, which can help establish a link to a known attacker or malware, as well as assist the DFIR team in discovering other compromised nodes.
This can be done in several main ways:
1. Searching for connections using basic indicator metadata.
2. Subdomain brute-forcing.
3. Searching for connections based on external characteristics of the command-and-control server.
4. Active internet scanning using a malware network protocol emulator.
🤨 Let’s start with the first method.
Each type of network indicator has its own metadata that allows narrowing down the pool of potential candidates or finding an exact match.
• For an IP address, this is ASN, provider.
• For a domain — subdomains, WHOIS information, whether it is DDNS or not, naming style, resolution time to a specific IP, DNS records.
• For a URL — length, parameters, values.
The primary system that includes virtually all of the above parameters and allows searching by them is Passive DNS.
Passive DNS (PDNS) — a system that stores the history of domain resolutions to IP addresses, their DNS records, subdomains, and WHOIS history. A proper PDNS allows a researcher to find new C2s using virtually any type of information described above. For example, the system allows finding all domains:
— that have ever resolved or currently resolve to a specific IP.
— that have a specific mail server in their MX record.
— that have a specific phone number in their WHOIS information, etc.
🏴☠️ Let’s look at an example with the Space Pirates group. Its infrastructure previously consisted mainly of fourth-level DDNS hostnames. In practice, this is quite rare, but this example is ideal for demonstrating the search for new hacker servers.
Let’s take one of the servers, namely chip.serviechelp.changeip[.]us.
On VT we see resolutions to several IP addresses. Let’s open the very first one — 45.32.106[.]247 — and we will see that a large number of similar fourth-level subdomains are hosted on this IP.
For the IP address, we see ASN (20473) and the provider name (AS-CHOOPA), which will help in the future to more accurately investigate the group’s network infrastructure. Next, we simply need to collect the entire list of indicators and repeat the iteration of searching for new IPs and similar domains for each one.
😎 For the original subdomain, you can go down one level lower and find all fourth-level subdomains for the third-level subdomain. In this case, the interface will show us the resolution history for the next-level domains, which will help save some time in the investigation.
All these methods work for any other metadata of network indicators: WHOIS, DNS records, ASN, provider. Some metadata is better used as a limiter (e.g., ASN), because otherwise the search will return too many results.
In fact, when investigating network infrastructure, we are dealing with a graph with many edges and vertices. However, this graph is finite. Naturally, such processes are better automated, as an attacker’s infrastructure can number thousands of nodes, as with Space Pirates, for example. But often, for the same adversary, the infrastructure for different attacks can be different and independent, and investigating it solely based on metadata will be limited.
We will discuss other ways to search for related hacker C2s in future posts.
💡Basic, conditionally free tooling that will help in searching for new C2s:
virustotal.com/gui/home/search
securitytrails.com/
whoisxmlapi.com/
whoxy.com/
urlhaus.abuse.ch/
bgp.he.net/
Maltego
#TI #C2 #tips #hunt #ioc
@ptescalator
More in General
- Operation Chewbacca
At the end of June, the PT ESC team, during incident investigations, discovered a new group…
- Ding, ding — who's there?
Ding, ding — who's there? 🔔 The cyber intelligence group of Positive Technologies' expert security center…
- Enterprise-grade validation system with schema support
Enterprise-grade validation system with schema support (c) The author of a dozen trojans who forgot to…
- One less feathered thief — plus one hundred rating points!
One less feathered thief — plus one hundred rating points! 😵 The Threat Intelligence team at…
- DragonDoll: a matryoshka in the world of Android spies
DragonDoll: a matryoshka in the world of Android spies 🪆 At the beginning of this spring,…



