maltrail icon indicating copy to clipboard operation
maltrail copied to clipboard

[wiki] trails contribution

Open MikhailKasimov opened this issue 3 years ago • 17 comments

Subj. All related materials go here.

MikhailKasimov avatar Jun 14 '22 11:06 MikhailKasimov

It is not available how to collaborate with trails in the wiki right? Thanks

conexioninversa avatar Jun 28 '22 10:06 conexioninversa

Hello! Currently no. :( Take a little bit of patience. Not much time to sit-and-do this wiki-chapter...

MikhailKasimov avatar Jun 28 '22 10:06 MikhailKasimov

maltrail-bases_folders maltrail-trail-structure trail-example

MikhailKasimov avatar Jul 03 '22 15:07 MikhailKasimov

Hi Mikhail,

I have organized much better and updated every hour and every 24 hours many more lists of the sources of my honeynet that I have distributed worldwide, can these sources be integrated into the Maltrail part? Here are the sources:

https://github.com/conexioninversa/MalwareIntel

Thanks

conexioninversa avatar Jul 27 '22 14:07 conexioninversa

Hi MikeHail,

I have organized much better and updated every hour and every 24 hours many more lists of the sources of my honeynet that I have distributed worldwide, can these sources be integrated into the Maltrail part? Here are the sources:

https://github.com/reverseconnection/MalwareIntel

Thanks

By the way I am integrating the honeypots with Maltrail :-)

conexioninversa avatar Jul 27 '22 14:07 conexioninversa

@conexioninversa what's the confidences level of C2_XXX lists at https://github.com/conexioninversa/MalwareIntel ?

i mean, this all looks like a fresh set of lists, while it would be pity to push FPs to regular users

stamparm avatar Jul 27 '22 19:07 stamparm

Hi Miroslav,

I think they are very reliable. However, I must say that I have found a Cobalt Strike-type product in a government agency and that is why I have included the supplier and certificate, that can help the analyst.

I also look for JARM traces, certificates and different characteristics of the reversing of the attacks received. However, I usually look for and analyze the beacon, which is the best characteristic that indicates the possible adversary.

I also have to say that the list of IPs that I have in MalwareIntel is a clean and tidy process of some raw files that have, among other things, URi, URL, country, jarm, certificates and many other things :-)

However, you have just given me an idea and I am going to put the raw data in case it can help someone by seeing more information from those files.

I send you a link file here so you can see the content and then once analyzed and processed I convert them to txt or csv with only the IPs to make it easier.

(https://raw.githubusercontent.com/conexioninversa/MalwareIntel/main/C2_CobaltStrikeBeacon.json)

With these files I have created pulses in OTX for AlientVault and the truth seems that they are very successful. I have also sent these files to Anomaly framework and to the bank where I currently work, with very good results.

In any case, I understand your position since it is a private investigation and it can generate doubts.

Anyway thank you very much.

conexioninversa avatar Jul 28 '22 13:07 conexioninversa

@conexioninversa you removed it? why? :D

stamparm avatar Aug 09 '22 12:08 stamparm

@conexioninversa if you would leave it updated and if you say that it is reliable, i could easily do a new "feed" out of it (in whatever form it would stay)

stamparm avatar Aug 09 '22 12:08 stamparm

wiki-article is not ready. reopen.

MikhailKasimov avatar Aug 09 '22 13:08 MikhailKasimov

@conexioninversa you removed it? why? :D

Hi Miroslav, I don't understand, all the files are in: https://github.com/conexioninversa/MalwareIntel

conexioninversa avatar Aug 10 '22 10:08 conexioninversa

@conexioninversa if you would leave it updated and if you say that it is reliable, i could easily do a new "feed" out of it (in whatever form it would stay)

Yes. My idea is to leave it updated as it says on the project page. It is wonderful to be able to collaborate with you.

conexioninversa avatar Aug 10 '22 10:08 conexioninversa

@conexioninversa you removed it? why? :D

Hi Miroslav, I don't understand, all the files are in: https://github.com/conexioninversa/MalwareIntel

Hello! I can confirm, that yesterday was 404 for these links.

MikhailKasimov avatar Aug 10 '22 10:08 MikhailKasimov

@conexioninversa if possible, you could contain all those findings inside one file (e.g. C2_All.csv), where you would put a new column with the name of each entry (e.g. metasploit). that way we would reduce the number of "feeds" (i.e. requests) required to fetch all the entries

stamparm avatar Aug 10 '22 12:08 stamparm

@conexioninversa if possible, you could contain all those findings inside one file (e.g. C2_All.csv), where you would put a new column with the name of each entry (e.g. metasploit). that way we would reduce the number of "feeds" (i.e. requests) required to fetch all the entries

Hi, I already have the file created and automated as C2_All.csv. Can you see if it's worth it?. Thanks https://github.com/conexioninversa/MalwareIntel/blob/main/C2_All.csv

conexioninversa avatar Aug 11 '22 13:08 conexioninversa

Currently goes as the updates for respective static trails:

[1] https://github.com/stamparm/maltrail/commit/9a155bfa41e24be62a839ea3de613ae134322354 [2] https://github.com/stamparm/maltrail/commit/99c9eea173614718d2d28edff99b4380d4c17939 [3] https://github.com/stamparm/maltrail/commit/c751ee1e8eb49f406608b3eaf9bf404a5330122f [4] https://github.com/stamparm/maltrail/commit/5a381ffe78786a0bff579632a921544eeac9269c [5] https://github.com/stamparm/maltrail/commit/a428a1bc979df2811588e5bde99d232f920ff709

MikhailKasimov avatar Aug 14 '22 07:08 MikhailKasimov

Actualmente va como las actualizaciones para los respectivos senderos estáticos:

[1] 9a155bf [2] 99c9eea [3] c751ee1 [4] 5a381ff [5] a428a1b

Perfect! Thanks

conexioninversa avatar Aug 15 '22 14:08 conexioninversa

photo_2022-09-23_16-06-10

MikhailKasimov avatar Sep 23 '22 13:09 MikhailKasimov

It is not available how to collaborate with trails in the wiki right? Thanks

Hello!

@conexioninversa Please, meet new wiki-articles, related to your question and to each other:

Maltrail trails structure - Information about Maltrail trails structure Maltrail trails base format - Information about Maltrail trails base format Maltrail trails contribution - Information about Maltrail trails contribution

Hope, you'll find useful and interesting information in them. If something is unclear in texts or some question(s) get be uncovered in articles, please, let me know -- will update the descriptions.

Thank you!

MikhailKasimov avatar Oct 02 '22 13:10 MikhailKasimov

It is not available how to collaborate with trails in the wiki right? Thanks

Hello!

@conexioninversa Please, meet new wiki-articles, related to your question and to each other:

Maltrail trails structure - Information about Maltrail trails structure Maltrail trails base format - Information about Maltrail trails base format Maltrail trails contribution - Information about Maltrail trails contribution

Hope, you'll find useful and interesting information in them. If something is unclear in texts or some question(s) get be uncovered in articles, please, let me know -- will update the descriptions.

Thank you!

Perfect. Next week I'll get to it in order to have a base of collaboration according to the indications of the wiki. Good work

conexioninversa avatar Oct 03 '22 16:10 conexioninversa

@conexioninversa Please, meet auxiliary tool, designed for trails contributing: https://github.com/MikhailKasimov/maltrail-dups-cleaner .

It would help to avoid adding trails (IP:port/domains/other type of trails), if they are already contained in static Maltrail bases. If any aspect of its usage would be unclear, please, let me know. Thank you!

MikhailKasimov avatar Oct 19 '22 14:10 MikhailKasimov

Hi Mikhail Perfect. I have read the document. I understand that once the filtered file for duplications and registrations in the white list has been obtained, a pull request must be made, ok?

conexioninversa avatar Oct 20 '22 10:10 conexioninversa

Hi Mikhail Perfect. I have read the document. I understand that once the filtered file for duplications and registrations in the white list has been obtained, a pull request must be made, ok?

... can be made. Generally this tool is optional: just to have a list for pull request for respective trail, which guaranteedly contains records are currently absent in Maltrail' static bases.

MikhailKasimov avatar Oct 20 '22 14:10 MikhailKasimov

Can be closed because all related article are done:

Maltrail trails structure - Information about Maltrail trails structure Maltrail trails base format - Information about Maltrail trails base format Maltrail trails contribution - Information about Maltrail trails contribution

MikhailKasimov avatar Nov 05 '22 12:11 MikhailKasimov