#infosec community
I've recorded the #threatactoremail from each #phishingkit for the last year & started tracking them out on @GitHub to share with you. My hope is this can somehow be used to fight the onslaught of #phishing seen daily
See the list
https://github.com/neonprimetime/PhishingKitTracker/blob/master/PhishingKitTracker.csv
I have 500 phishing kits so far and the data paints some interesting pictures. Such as 82% of the phishing kits I tracked use a @Gmail account to receive the stolen creds. I've also found threat actors that re-use so you can perhaps link together campaigns.
A big thank you, all the credit for the data goes to the #infosec community on twitter that hunts and finds all the evil #phishing sites such as
@TechHelpListCom
@IpNigh
@ANeilan
@leunammejii
@ActorExpose
@n0p1shing
@dave_daves
@FewAtoms
@nullcookies
@PhishingAi@jcybersec_
@JonSelman
@MaelSecurity
@demonslay335
@dms1899
@malware_traffic
@olihough86
@packet_Wire
@ps66uk
@Ring0x0
@sS55752750
@teoseller
@tiketiketikeke
@ViriBack
@WifiRumHam
@PhishTank_Bot
and everyone else in the community
If anybody knows people @Gmail , @Yandex, @Yahoo, @Zoho, @ProtonMail that care about this type of data and could perhaps help the #infosec community start streamline reporting or detection of these email accounts that receive stolen creds daily that's be sweet.
If anybody knows a better place to upload zipped up phishing kits than VT , I'd love to be sharing and archiving them somewhere the whole community has access to.
If anybody every has #phishing threat actor emails they wanted appended to this list just CC me and I'll do my best to get them added
If anybody has suggestions on better ways to do this & share w/ the community, extra data/fields to track, etc. I'm all open ears, for example if somebody wanted to build a tracker website for the community to use you'd be my hero !
Otherwise, HAPPY FRIDAY
Friday, November 30, 2018
PhishingKitTracker by neonprimetime
Labels:
Github,
Phishing,
Phishing Kit,
PhishingKitTracker,
threatactoremail
Wednesday, November 28, 2018
LogParser basic syntax
LogParser.exe -i:EVT -h [prints the columns available on that event log type]
# Windows Auth (Security)
# Windows Auth (Security)
select where LogonType <> '3'
LogParser.exe -i:EVT "SELECT TimeGenerated as LoginTime,EXTRACT_TOKEN(Strings,5,'|') as username,EXTRACT_TOKEN(Strings, 8, '|') as LogonType,EXTRACT_TOKEN(Strings, 17, '|') AS ProcessName,EXTRACT_TOKEN(Strings, 18, '|') AS SourceIP FROM logs.evtx where EventID=4624 and EXTRACT_TOKEN(Strings, 8, '|') <> '3'"
LogParser.exe -i:EVT "SELECT TimeGenerated as LoginTime,EXTRACT_TOKEN(Strings,5,'|') as username,EXTRACT_TOKEN(Strings, 8, '|') as LogonType,EXTRACT_TOKEN(Strings, 17, '|') AS ProcessName,EXTRACT_TOKEN(Strings, 18, '|') AS SourceIP FROM logs.evtx where EventID=4624 and EXTRACT_TOKEN(Strings, 8, '|') <> '3'"
# Windows Task Scheduler
LogParser.exe -i:EVT "SELECT EXTRACT_TOKEN(Strings, 0, '|') as TaskName, EXTRACT_TOKEN(Strings, 1, '|') as Path, EXTRACT_TOKEN(Strings, 2, '|') as ProcessId, EXTRACT_TOKEN(Strings, 3, '|') AS Priority FROM Microsoft-Windows-TaskScheduler%4Operational.evtx where EventID = 129 and EXTRACT_TOKEN(Strings, 1, '|') not like '%Sophos%' and EXTRACT_TOKEN(Strings, 1, '|') not like '%GoogleUpdate%' and EXTRACT_TOKEN(Strings, 0, '|') not like '%Database One%' and EXTRACT_TOKEN(Strings, 1, '|') not like '%Small Business%' and EXTRACT_TOKEN(Strings, 1, '|') not like '%Solutions BPA%'
LogParser.exe -i:EVT "select * from security.evtx" -rtp:-1
LogParser.exe -i:EVT "select * from security.evtx_ where eventid=4703" -rtp:-1
LogParser.exe -i:EVT "select eventid, count(*) from security.evtx_ group by eventid order by count(*) desc" -rtp:-1
LogParser.exe -i:EVT "select eventid, count(*) from security.evtx_ group by eventid order by count(*) desc" -rtp:-1 -o:csv > out.csv
LogParser.exe -i:EVT "select timegenerated from system.evtx_ where message not like '%description for%' AND timegenerated >= '2018-11-26 05:00:00' and timegenerated <= '2018-11-26 18:00:00'" -rtp:-1
LogParser.exe -i:EVT "select timegenerated, strings from security.evtx_ where strings not like '%privilege%'" -rtp:-1 -o:csv > out.csv
NOTE:
The rtp parameter suppresses the "press a key" paging feature that is default for log parser
-rtp:-1
NOTE:
If you get "The description for event id ... cannot be found" for every message it might be because
LogParser.exe -i:EVT "select * from security.evtx" -rtp:-1
LogParser.exe -i:EVT "select * from security.evtx_ where eventid=4703" -rtp:-1
LogParser.exe -i:EVT "select eventid, count(*) from security.evtx_ group by eventid order by count(*) desc" -rtp:-1
LogParser.exe -i:EVT "select eventid, count(*) from security.evtx_ group by eventid order by count(*) desc" -rtp:-1 -o:csv > out.csv
LogParser.exe -i:EVT "select timegenerated from system.evtx_ where message not like '%description for%' AND timegenerated >= '2018-11-26 05:00:00' and timegenerated <= '2018-11-26 18:00:00'" -rtp:-1
LogParser.exe -i:EVT "select timegenerated, strings from security.evtx_ where strings not like '%privilege%'" -rtp:-1 -o:csv > out.csv
NOTE:
The rtp parameter suppresses the "press a key" paging feature that is default for log parser
-rtp:-1
NOTE:
If you get "The description for event id ... cannot be found" for every message it might be because
user account needs the"Manage auditing and security log." permission
Sunday, November 25, 2018
#phishingkit 10/2017 to 11/26/2018 from Twitter
This summary is not available. Please
click here to view the post.
Monday, November 12, 2018
IDA common locations to put breakpoints
I'm learning that if you're looking for somewhere to breakpoint in confusing malware try
jmp eax ; // or any register for that matter, it's jumping to a dynamic address
call eax ; // or any register for that matter, it's jumping to a dynamic address
call dword_xxx; // it's jumping to an address saved in data, perhaps dynamically loaded
Also a breakpoint in
ntdll.dll -> ResumeThread ; // malware may suspend and then restart when completed editing
ntdll.dll -> ResumeProcess ; // malware may suspend and then restart when completed editing
Also look at the IDA color coded graph across the top, look for a large chunk of data, which is probably the packed code, find the label for it, for xrefs to that label, then breakpoint there.
jmp eax ; // or any register for that matter, it's jumping to a dynamic address
call eax ; // or any register for that matter, it's jumping to a dynamic address
call dword_xxx; // it's jumping to an address saved in data, perhaps dynamically loaded
Also a breakpoint in
ntdll.dll -> ResumeThread ; // malware may suspend and then restart when completed editing
ntdll.dll -> ResumeProcess ; // malware may suspend and then restart when completed editing
Also look at the IDA color coded graph across the top, look for a large chunk of data, which is probably the packed code, find the label for it, for xrefs to that label, then breakpoint there.
IDA Error "The instruction at ... referenced memory at ... The memory could not be written"
If you're running malware in IDA and get a error such as
8A1EE: The instruction at 0x8A1EE referenced memory at 0x0. The memory could not be written -> 0000000000000000 (exc.code c0000006, tid 2268)
Per the OALabs youtube video
https://www.youtube.com/watch?v=ScBB-Hi7NxQ
This might be caused by the Debugger holding a handle to malware sample and the malware itself wanting its own exclusive handle to the file.
Thus the malware errors out because it cannot collect an exclusive handle to the malware sample since the debugger already has a handle.
To remediate, one potential fix is to try ...
- Set a breakpoint in IDA on startup
- In the debugger "Modules" window, find "ntdll.dll" and the "NtCreateFile" function, set a breakpoint
- Continue the debugger, it will eventually hit NtCreateFile
- Then "Continue until Return" multiple times until you return to the malware code
- In my case it was a call to "kernel32.dll" "CreateFileA" that triggered this call
- If you look at the parameters to "CreateFileA", the 3rd parameter was set to 0 which means an exclusive handle
- If you look in the return result of CreateFileA it returned FFFFFFFF which means an "invalid file handle" which is what's causing the error
- So, add a breakpoint to this CreateFileA call
- Kill the debugging process
- Re-launch the program until it hits your new breakpoint
- Change that 3rd parameter from 0x0 to 0x7 to give yourself full access
- Now allow it to run, and notice the return value is no longer FFFFFFFF , it's a valid file handle now, and thus you've gotten past that error caused by the exclusive handle!
8A1EE: The instruction at 0x8A1EE referenced memory at 0x0. The memory could not be written -> 0000000000000000 (exc.code c0000006, tid 2268)
Per the OALabs youtube video
https://www.youtube.com/watch?v=ScBB-Hi7NxQ
This might be caused by the Debugger holding a handle to malware sample and the malware itself wanting its own exclusive handle to the file.
Thus the malware errors out because it cannot collect an exclusive handle to the malware sample since the debugger already has a handle.
To remediate, one potential fix is to try ...
- Set a breakpoint in IDA on startup
- In the debugger "Modules" window, find "ntdll.dll" and the "NtCreateFile" function, set a breakpoint
- Continue the debugger, it will eventually hit NtCreateFile
- Then "Continue until Return" multiple times until you return to the malware code
- In my case it was a call to "kernel32.dll" "CreateFileA" that triggered this call
- If you look at the parameters to "CreateFileA", the 3rd parameter was set to 0 which means an exclusive handle
- If you look in the return result of CreateFileA it returned FFFFFFFF which means an "invalid file handle" which is what's causing the error
- So, add a breakpoint to this CreateFileA call
- Kill the debugging process
- Re-launch the program until it hits your new breakpoint
- Change that 3rd parameter from 0x0 to 0x7 to give yourself full access
- Now allow it to run, and notice the return value is no longer FFFFFFFF , it's a valid file handle now, and thus you've gotten past that error caused by the exclusive handle!
#phishingkit threat actor emails 2018-11-12
#phishingkit actor emails https://twitter.com/Techhelplistcom/status/1061885792027586560 185.52.3.156 http://routelabel.net hosting 12\12\12\authenticate.php:$email= "cforeplyto@gmail.com"; 12\12\12\login.php:$email= "cforeplyto@gmail.com"; drop\newdropbox\00\000\001\index\gm33ail\geemail.php: $to ="andyjames009@yandex.com"; 2019box\SA\drop\newdropbox\00\000\001\index\li33ve\li33ve.php: $to ="gdaan7@gmail.com"; 2019box\SA\drop\newdropbox\00\000\001\index\off33ice\off33ice.php: $to ="gdaan7@gmail.com"; 2019box\SA\drop\newdropbox\00\000\001\index\others\otherother.php: $to ="gdaan7@gmail.com"; 2019box\SA\drop\newdropbox\00\000\001\index\yah33oo\yah33oo.php: $to ="gdaan7@gmail.com"; Anymail%20Magnet\magnet\loader.php:$to = "mchlliving@gmail.com"; Anymail%20Magnet\magnet\Verify.php:$to = "mchlliving@gmail.com"; Anymail%20Magnet%20-%20zilo\magnet\loader.php:$to = "zakichahul@gmail.com"; Anymail%20Magnet%20-%20zilo\magnet\Verify.php:$to = "zakichahul@gmail.com"; luno\index2.php: $to = "markjamesons717@gmail.com"; luno\index2.php: "CC:markjamesons717@gmail.com"; microsoftonline.secured\m1soft\verify.php:$mail_to = "feminist008@gmail.com"; sharep\final.php:$send = "steveaustin1234@gmail.com"; http://uahowias.com/12.zip http://zahwes.com/microsoftonline.secured.zip http://qtoksa.com/verify.login.microsoftonline/sharep.zip http://taowlk.com/Luno/luno.zip http://hanlskes.com/Anymail%20Magnet.zip http://hanlskes.com/forum/Anymail%20Magnet.zip http://hanlskes.com/invoice/Anymail%20Magnet.zip http://hanlskes.com/admin/Anymail%20Magnet.zip http://hanlskes.com/Confirmation/Anymail%20Magnet%20-%20zilo.zip http://hanlskes.com/Proposal%20/Anymail%20Magnet.zip http://kalusm.com/2019box.zip
#phishingkit actor emails https://twitter.com/Techhelplistcom/status/1061845780791726081 103.75.189.106 vpsmalaysia[.]com[.]my hosting amiro\includes\my_email.php:$my_email = "madauthy@protonmail.com"; Excel23\next.php:$send = "paulm.petromin@gmail.com"; HotmailOfficeNew\next.php:$send = "paulm.petromin@gmail.com"; microsoftonline.secured\m1soft\verify.php:$mail_to = "feminist008@gmail.com"; NAVER\oku.php:$send = "ddonwise1010@yandex.com, maria.hirschberghof@gmail.com"; office365\next.php:$send = "anny.duweivices@gmail.com"; wetransfers\next.php:$send = "anny.duweivices@gmail.com"; http://chowusi.com/download/OUTLOOKNEW.zip http://batwoks.com/test/test_files.zip http://swealsk.com/11/NAVER.zip http://swealsk.com/13/NAVER.zip http://swealsk.com/6/NAVER.zip http://swealsk.com/10/NAVER.zip http://swealsk.com/7/NAVER.zip http://swealsk.com/8/NAVER.zip http://swealsk.com/2/NAVER.zip http://swealsk.com/5/NAVER.zip http://swealsk.com/9/NAVER.zip http://swealsk.com/3/NAVER.zip http://swealsk.com/12/NAVER.zip http://swealsk.com/1/NAVER.zip http://swealsk.com/4/NAVER.zip http://bahlowk.com/amiro.zip http://ualkws.com/microsoftonline.secured.zip http://gaklosk.com/microsoftonline.secured.zip http://ouiask.com/HotmailOfficeNew.zip http://ouiask.com/office365.zip http://ouiask.com/Excel23.zip http://ouiask.com/wetransfers.zip
#phishingkit threat actor emails https://twitter.com/Techhelplistcom/status/1061840412883722240 35.183.119.114 @digitalocean hosting 1\1\1\1\passportx.php:$send = "zzxxccah22@gmail.com"; domain_updated\review\connectID.php:$own = 'cleanestresults@gmail.com'; form\bringitback.php:$send = "ladi.pupo@yandex.com"; office\office365\bringitback.php:$send = "ladi.pupo@yandex.com"; office365\form\bringitback.php:$send = "ladi.pupo@yandex.com"; Review\file\site\process.php:$to = "info.contactsss01@gmail.com"; http://fbg6.cf/qw/General.zip http://b6y76.ga/feyi/newestyahoo.zip http://b6y76.ga/uu/Docusign%20_1.zip http://b6y76.ga/faith/secure01c.chase.web.auth.dashboard..zip http://b6y76.cf/ll/domain_updated.zip http://sfdgvr65.ga/hot-auto.zip http://sfdgvr65.cf/ourtimet%20_1.zip http://fbg6.ga/office365/form.zip http://fbg6.ga/office365.zip http://fbg6.ga/office.zip http://fbg6.ga/office/office365.zip http://gb667u76.tk/1.zip http://gb667u76.tk/review/Review.zip
Subscribe to:
Posts (Atom)