[ << ALL_FEED ]

C2 hunting: part 2.

More in General

C2 hunting: part 2. Hunting for hacker servers by external signs 😁

In the previous part, we talked about how to expand knowledge about hackers’ infrastructure using PDNS and Whois.

Today we’ll discuss how to find hacker servers not only when they have already started using their infrastructure in attacks, but also at the moment of its deployment.

Right before an attack, hackers typically prepare their tooling and network infrastructure. In threat models, this stage is usually called weaponization or resource development.

Almost any malware has, in one form or another, a mechanism for communicating with C2. The C2 itself has a number of characteristics that can be obtained by scanning it or simply connecting to a specific port, such as 443. This way, we will most likely obtain the TLS certificate parameters, TLS connection parameters, server response headers, and web page content.

Accordingly, by analyzing hackers’ malware and examining their network infrastructure, we will have an understanding of the unique characteristics they use on their C2 for specific malware, which will allow us in some cases to detect their C2 at the moment of deploying network infrastructure for an attack and preemptively block these indicators on security tools.

List of the most popular characteristics that can be used to identify C2:

✅ TLS certificate parameters
✅ TLS connection parameters (JA3, JA4, JARM, etc.)
✅ Response headers from the server
✅ Page content and title
✅ Set of open ports
✅ Favicon

You can always narrow down your search by specifying ASN, hoster, or country.

List of services that will help you search for C2 this way:

✅ Shodan
✅ Censys
✅ FOFA
✅ ZoomEye
✅ BinaryEdge
✅ Netlas
✅ ONYPHE
✅ Custom scanner

Searching manually across all services is labor-intensive, but still necessary, since each service may produce different results. To reduce manual labor costs, automation is needed. We developed the SCANDAT system internally, which has its own internal search syntax and automatically generates search rules for each service.

😠 In screenshots 1–3 you can see examples of queries for detecting C2 for the GoRed malware, which the ExCobalt group uses.

Additionally, there is a basic open-source solution for automating queries.

Ultimately, all identified C2 from our system end up in the company’s products, increasing the level of threat detection.

💡 It’s worth noting that some MaaS developers try to counter such detection methods. For example, starting from a certain version of Medusa Stealer, its developers removed the title, some content on the page, and added generation of random data in the TLS certificate so that the stealer’s control panel couldn’t be identified through popular services.

You can not only collect such servers and send them to feeds for security tools, but also write emulators of malware network protocols to obtain a payload or some module from a fresh C2. This will allow you to obtain additional indicators and attribution characteristics.

#TI #C2 #tips #hunt #malware
@ptescalator

More from ti_author

More from ti_author

More in General