Web Scanner: Execute Queries Across 90+ Parameters
In this video, Product Manager Jonathan Peyster takes you through the Silent Push Web Scanner – discussing its benefits and providing a demonstration to help you get the most out of the tool.
In this video, Product Manager Jonathan Peyster takes you through the Silent Push Web Scanner – discussing its benefits and providing a demonstration to help you get the most out of the tool.
Silent Push Threat Analysts have used fuzzy hash scans and content similarity queries to uncover 24 control panel Indicators of Future Attack (IOFA) administering MaaS services, for a range of DukeEugene variants – including ERMAC, Hook, Loot, and Pegasus – targeting users of popular mobile banking software and crypto currency exchanges.
DukeEugene is the original threat actor behind the promotion of several android-based Malware-as-a-Service (MaaS) families, including both ERMAC and BlackRock, and later Hook which was published in early Jan 2023 on darknet[.]ug with bogus Russian-language commands hidden inside the malware that were later removed.
In April 2023, Duke Eugene claimed he was leaving the project for “SVO” (slang often used for Russian military service), however the project’s coder continued providing services and the HookBot builder panel’s code was leaked only three months later.
Since that leak, the proliferation of HookBot C2s offering a number of attack vectors (harvesting confidential information and login credentials, performing overlay attacks – where malware opens an active window over a legitimate program to intercept a victim’s interactions, and more) has spread wide. Even so, shared characteristics linking each of these MaaS families remain.
This blog contains a public overview of how we at Silent Push have uncovered a host of control panels actively administering MaaS services for this range of DukeEugene-linked variants, including Ermac, Hook, Loot, and Pegasus – all targeting users of popular mobile banking software and crypto currency exchanges.
Silent Push Enterprise users have access to a dedicated TLP Amber report, containing the specific data categories and queries we used to locate and traverse DukeEugene’s infrastructure, as well 4 dedicated Android malware IOFA feeds.

While conducting research into a suspicious Russian ASN using the Silent Push Web Scanner, we discovered infrastructure linked to an ERMAC control panel.
We then constructed a Web Scanner query that took a piece of data from the ERMAC page, and scanned for all associated DukeEugene ERMAC control panels that used the same page content.
Once we’d mapped out the ERMAC infrastructure, we were able to hash the content, and execute a query that scanned the Internet for matching DukeEugene control panels that are 75% similar to the initial discovery.
This produced a large dataset, on which we executed further enrichment queries utilizing fuzzy hash values linked to a specific website, to confirm a host of true positive IOFAs.
This pivot then led us to other hash types and selected data categories, returning even more true positive examples of both live and dormant IOFA infrastructure.
We then queried the enriched data to uncover 24 DukeEugene-linked control panels (see IOFA list at the end of this blog for a sample), with the following names:
Not all of the above represent active control panels, but the naming schemas are part of our detections for this particular threat actor and are being shared here to help the community with their own defenses.
When active panels with the new HTML titles show up on live pages, they will be immediately detected and exposed by our Android malware feeds.


All domains and IP IOFAs gathered from this research are populated in the following Silent Push IOFA feeds, which are constantly updated:

Silent Push Enterprise users can use data from the above feeds in three ways:
Note: A full list of domain and IP IOFAs linked to our DukeEugene research can be accessed via a Silent Push Enterprise subscription, across 4 dedicated Android malware feeds. This sample is provided to our readers to aid in their detections.
140.99.130[.]21
147.45.47[.]40
185.196.10[.]211
185.208.158[.]109
185.208.158[.]112
185.208.158[.]47
146.103.45[.]72
147.45.47[.]40
159.100.14[.]22
185.216.70[.]189
51.103.213[.]218
Indicators of Future Attack are domains, IP addresses and DNS records that act as real time, actionable, proactive indications of attacker behavior and intent.
Created using the power of our proprietary intelligence, IOFAs and their associated analytics are commonly used by security teams, analysts and researchers to improve their threat hunting efforts, proactively defend their digital assets or strengthen their security posture by integrating early detection feeds into their security stack.

As part of release 4.2, Silent Push introduced an exclusive page for its IOFA Feeds and associated feed analytics, allowing you to access timely, accurate and complete IOFA data to stop threats before they attack.
How are we able to get IOFAs in the first place? How do we know they are trustworthy indicators? Silent Push is able to provide these indicators by using our own first-party data that’s collected, clustered, scored and delivered without third-party intervention.
The ability to create, control and map the relationship between billions of disparate domains, IPs, DNS records and content hashes to identify emerging patterns is what makes our operational threat intelligence so valuable, and highly actionable.
Curated Feeds refer to feeds made by our own threat analysis research team at Silent Push. They are free of false positives, and only include indicators associated with real threats. This is done to ensure you’re getting the realtime data you need, and nothing else.
Our IOFA Feeds specifically contain IPs, domains, and URLs gathered from our research into global threat actors, specific threat campaigns and a range of attack vectors.
At Silent Push, we do a lot of work in the background to make sure you can instantly consume our data within the feed at the point of delivery.
Yes, we provide you with the raw data in a curated feed, but so do the other guys…
What we also provide you with simultaneously is realtime, associated context that is immediately available as actionable intelligence for your existing security stack. You are able to consume all the relevant information you need in one place, and action it, for example, by using rules to react our feeds in different ways or by using our enriched threat ranking data to inform your own internal scoring.
In this blog, we’ll walk you through how to access IOFA Feeds in Silent Push, how to interpret feed analytics, feed them into your security stack and utilize the data to improve your security posture.
Enterprise users have complete access to all 50+ IOFA Feeds in Silent Push.
To access the IOFA Feeds, simply navigate to Data Marketplace > IOFA Feeds. This will populate all of our available IOFA Feeds as cards that can be expanded.
You are able to filter the feeds by a particular term in the search bar, filter by IPv4, IPv6, domain or URL data, and sort the feeds into newer or older order.

Feed Analytics allow security teams to join the dots across the IPv4/6 space, acting as an early warning system populated with infrastructure.
The Feed Analytics screen contextualizes feed data across the following categories.
The Overview panel provides users with basic context of the Feed structure and export formats along with shortcuts to relevant threat articles.
The Feed Trend panel helps users to understand how the Feed has evolved overtime.

Users are able to quickly visualize the geo location of IOFAs on a world map, and download an SVG file of the image to share.

Feed Tags are useful shortcuts for users to explore different threat actors or types of criminal infrastructure.

Contextualizing feeds is critical in understanding patterns of behavior across a group of related IOFAs. Feed Analysis Indicators provide users with a thorough overview relating to the Feed’s average risk and repetitional scores, highlighting ‘hot spots’ or areas for concern to help map out attacker infrastructure.

To help understand the size and scale of threat landscapes and patterns, our Top Ten categories provide users with information regarding:

The enriched domains and IP addresses within each feed are also visible in Threat Ranking page under Threat Intelligence Management, providing you with corroborated IOFA data in one indexed and searchable screen. This page features additional risk and reputation scoring to support your analysis.
To navigate here from the IOFA Feed Analytics page, navigate to Threat Intelligence Management > Threat Ranking. Enter the specific IOFA you’d like to observe in the search bar, or, create an Advanced Filter with logical expressions to monitor a group of IOFAs.
In this view, each IOFA can be individually expanded to show detailed risk and reputation scores across three categories: Source Score, Enriched Score and Custom Score. These scores can be utilized to inform your own internal scoring systems, or act as reliable indicators of an IOFA’s maliciousness within the context of your organization.

Now you have access to our proprietary IOFA data, how can you use it in an actionable manner to stop threats before they’re weaponized? IOFA Feed data can be easily fed into your security stack (SOAR, Microsoft Azure Sentinel, Splunk etc.) and used for purposes such as traffic blocking, quarantining, ongoing monitoring and more.
IOFA Feed data can be exported in several ways, depending on how you wish to use it.
To manually export Feed data:
IOFA Feed data can also be externally fed into your security stack via Python, curl, and PHP.
After clicking ‘Automate Export’, simply select the cURL, Python or pHp tabs to copy code samples and call it from your desired security tool.
IOFA Feeds and their associated analytics are available as part of Silent Push Enterprise Edition – a powerful threat hunting and cyber defense tool used by security teams, threat analysts, and researchers. Request a demo here.
If you’d like to get a taster of the Silent Push platform, register for our free Community Edition that features 90+ data enrichment categories that you can use to track and monitor attacker activity across the global IPv4 space. Click here to sign-up for a free Community Edition account.
We’re thrilled to announce that today, Lionfish Tech Advisors published “Anticipating The Unseen: Elevating Cyber Defense with Silent Push Preemptive Threat Intelligence”.
Authored by Brad LaPorte, a Gartner veteran and CTI industry expert, the report provides a comprehensive evaluation of the evolving cyber threat landscape, and re-affirms the necessity for preemptive threat intelligence solutions.
Brad has developed a framework that outlines the evolution of threat intelligence, and conveys how the industry is evolving through several stages – From Level 1 (Proactive) to Level 2 (Predictive), before landing on a new era with Level 3 (Preemptive).
This framework demonstrates how Silent Push stacks up next to legacy threat intelligence providers.

We’ll be conducting a webinar in the coming weeks, where Brad will discuss his findings and talking about the topic of advanced threat intelligence. We’ll keep you posted with a date.
Objective: Move from a purely reactive posture to a proactive one, identifying potential threats before they fully materialize.
Sub-tasks and capabilities:
Objective: Use advanced analytics and modeling to predict potential threats based on historical data, and behavioral analysis.
Sub-tasks and capabilities:
Objective: Identify and neutralize threats before they can launch, effectively preventing attacks from occurring.
Sub-tasks and capabilities:
CryptoChameleon is a phishing kit first discovered in February 2024. As of publication, the identity of CryptoChameleon’s creator remains elusive.
The kit is used by unknown threat actors to harvest usernames, passwords, password reset URLs, and photo IDs from employees and customers’ mobile devices.
Silent Push Threat Analysts have conducted a wide-ranging research campaign that has revealed a large amount of CryptoChameleon fast flux Indicators of Future Attack (IOFAs) targeting Binance, Coinbase and FCC users, and a host of other platforms, including:
On 6th February 2024, Silent Push analysts noticed malicious activity targeting the FCC, and reported it confidentially to CISA.
Subsequent research, published by cloud security vendor Lookout, referenced the same domain as our FCC report, which we now know to be CryptoChameleon infrastructure.
Initial reports noted the targeting of employees at the FCC, Binance and Coinbase, among others, in sophisticated email, SMS, and voice phishing attacks.
A phishing kit can broadly be defined as a group of tools and files that work together to propagate phishing activity, and quickly deploy infrastructure.
CryptoChameleon phishing activity is propagated using a range of DNS-based and on-page TTPs.
Our research has discovered that CryptoChameleon makes almost exclusive use of DNSPod[.]com nameservers.
DNSPod are a self-proclaimed “intelligent DNS provider” that’s been used by botnets and bullet-proof hosting operators to propagate malicious activity for a number of years, with an estimated 30% of its infrastructure engaged in malicious activity, according to a recent Unit42 report.
DNSPod is owned by Tencent Cloud, and is based out of China.
CryptoChameleon uses DNSPod nameservers to engage in fast flux evasion techniques that allow threat actors to quickly cycle through large amounts of IPs linked to a single domain name.
Fast flux allows CryptoChameleon infrastructure to evade traditional countermeasures, and significantly reduces the operational value of legacy point-in-time IOCs.
For more information on fast flux techniques, read our Gamaredon report.
Silent Push has also tracked a number of additional TTPs that we aren’t able to divulge in a public blog, for OPSEC reasons.
These variables are linked to the deployment of phishing domains, and form a behavioural fingerprint that allows for quick and easy monitoring of all associated infrastructure.
Silent Push Enterprise users have access to a CryptoChameleon TLP Amber report that reveals these additional measures, along with the specific queries and parameters we’ve used to uncover CryptoChameleon infrastructure, and automated mitigation steps, including dedicated domain and IP feeds.
Analysis of the phishing kit indicates the ability to impersonate many different brands, across a range of sectors.
Our research aligns with other public research, which states that CryptoChameleon has separate phishing kits targeting public sector organizations.
The CryptoChameleon phishing kit copies the exact branding of legitimate websites and landing pages, with some key differences that allow the kit to evade standard countermeasures.
CryptoChameleon phishing pages contain slices of data that detail the C2 server that’s being used to intercept a user’s personal information, and the organizations that are being targeted.
Analyzing one such domain – lookoutsucks[.]com (likely a parody of Lookout[.]com – the research group that was first to publicize information about the phishing kit), we can see the following companies listed:
These details are stored alongside password reset prompts, sign-in prompts, OTP prompts, and 2FA flows that target any user who interacts with the domain.
Here’s a few screenshots that show CryptoChameleon phishing infrastructure across various websites.





We started by focusing our attention on DNSPod[.]com – the largest DNS provider in China, known to host a range of malicious infrastructure.
To traverse CryptoChameleon fast flux infrastructure, we executed an IP diversity query using *.dnspod[.]com nameservers as a primary parameter, and a range of secondary parameters informed by what we already know about CryptoChameleon’s deployment methods.
The full list of parameters are available in the aforementioned TLP Amber report.
Silent Push IP diversity queries return a list of IP addresses that a domain or URL has pointed to over a period of time, giving us a wealth of information that we used to map out associated infrastructure.
Silent Push DNS queries are built upon a first-party database that puts the emphasis on tracking the underlying infrastructure (nameservers, ASNs etc.) involved in an attack, rather than legacy IOCs that are the mainstay of most security teams’ brand defense workflows.
This allows defenders to anticipate and block pre-weaponized infrastructure by creating an automated early warning system that evaluates a domain or IP based in its relationship with a hosting provider or ASN.
Our IP diversity search allowed us to pinpoint numerous AS names and numbers that are actively involved in propagating CryptoChameleon attacks across the globe.
Our query returned 83 domains (as of writing) that are visibly similar to previous CryptoChameleon infrastructure, such as these domains targeting Coinbase:
Our team then analyzed the domains found via the DNSPod nameserver filtering process, and executed a Web Scanner query using a common set of characteristics, that allowed us to scan for matching infrastructrure.
CryptoChamelon appears to control all the domains hosted on 188.68.221[.]152, and several private IP ranges where 95% of the domains follow similar patterns, with the others being more random but potentially still owned by the same operators.
The phishing kit also controls all the domains on the following IPs:
Here’s a sample of IPs containing CryptoChameleon-controlled infrastructure, where many of the domains are mapped to multiple IP ranges:

All domains and IPs gathered from our research are populated in two dedicated CryptoChameleon IOFA feeds, which are constantly updated using the queries and scans discussed in this blog.
Enterprise users can use our API endpoints to feed CryptoChameleon IOFAs into their existing security stack, or access a time-limited API URL that returns a live data set.
Enterprise users can also use our TLP Amber report to pinpoint hostile ASNs and nameservers involved in CryptoChameleon activity.
Community and Enterprise users have access to a range of IP diversity queries – along with our Web Scanner – that allow security teams to quickly join the dots between billions of disparate data points, and form a complete picture of CryptoChameleon TTPs.
Silent Push Community Edition is a free threat hunting and cyber defense platform featuring a range of advanced offensive and defensive lookups, web content queries, and enriched data types, that we used to track CryptoChameleon phishing activity.
Click here to sign-up for a free Community Edition account.
A full list of CryptoChameleon IOFAs are available as part of a Silent Push Enterprise subscription, via two dedicated IOFA feeds and a TLP Amber report.
Image: Microsoft, 2024
We’re thrilled to announce our inclusion in the Microsoft Copilot for Security Partner Ecosystem.
The selection of Silent Push was based on our proven experience with Microsoft Security technologies, willingness to explore and provide feedback on cutting edge functionality, and close working relationship with Microsoft.
Copilot for Security is the industry’s first generative AI solution that will help security and IT professionals catch what others miss, move faster, and strengthen team expertise. Copilot is informed by large-scale data and threat intelligence, including more than 78 trillion security signals processed by Microsoft each day, and coupled with large language models to deliver tailored insights and guide next steps. Copilot allows organizations to protect using the speed and scale of AI, and transform their security operations.
Ken Bagnall, CEO of Silent Push, said: “Organizations are desperately trying to detect and block emerging attacker activity prior to an attack launching.
“Combining the power of our platform to expose Indicators of Future Attack (IOFA), with the ability to act through Copilot AI, allows customers to predict and block emerging threats before damage occurs.
Timely, accurate and complete first-party data is what sets Silent Push apart from legacy threat intel providers, and consuming data this via Copilot AI gives customers increased trust, accuracy, and speed, in detecting emerging threats”, Ken Bagnall said.
We’re working with Microsoft Product Teams to help shape Copilot for Security product development in several ways, including validation and refinement of new and upcoming scenarios, providing feedback on product development and operations to be incorporated into future product releases, and validation and feedback of APIs to assist with Copilot for Security extensibility.
Vasu Jakkal, Corporate Vice President of Microsoft Security, said: “In the context of security, AI’s impact is likely to be profound, tilting the scales in favor of defenders and empowering organizations to defend at machine speed.
“At Microsoft, we are privileged to have a leading role in advancing AI innovation, and we are so grateful to our incredible ecosystem of partners, whose mission-driven work is critical to helping customers secure their organizations and confidently bring the many benefits of AI into their environments”, Vasu Jakkal said.
CyberHUB-AM, an Armenian cyber security organization supporting regional NGO’s and journalists, recently published research about a Telegram phishing campaign conducted throughout 2023 and 2024.
Silent Push Threat Analysts have used this information to identify and monitor phishing infrastructure targeting Armenian and Uzbekistani Telegram users, including live phishing domains and portal spoofing infrastructure.
The attack chain begins with an Armenian Telegram message asking the user to cast a vote for the sender in a contest they claim to be participating in, and asking them to follow a link.
The link appears to resolve to the non-existent URL daxcearm[.]wve (there is no .wve top-level domain), but actually uses the cutt[.]ly URL shortener to send the user to a final malicious URL – https://dolbaebshesp[.]in/.
The final URL hosts a Telegram phishing page in the Uzbek language. 2023 phishing kits previously reported on by CyberHUB-AM used Armenian.
This recent campaign could indicate a unique threat actor, or an updated campaign using the wrong language on the landing page. Although it is unclear why a message in Armenian would link to an Uzbek phishing page, these kinds of mistakes are fairly commonplace in regional cybercrime.
Threat actors deploy their infrastructure to a set of definable (and searchable) parameters.
Our analysts were able to isolate the phishing infrastructure involved in the campaign using proprietary fingerprinting that maps out malicious domains, using a combination of content similarity checks, and the Silent Push Live Scan feature.
Using these methods, we discovered 26 phishing domains, three of which are still live at the point of investigation: uzgolos[.]shop, uzvvots[.]shop, and vote-uzbekistan48[.]top.
![Screenshot of vote-uzbekistan48[.]top using the Silent Push 'Live Scan' screenshot feature.](https://www.silentpush.com/wp-content/uploads/image-20240423-120846.png)
We confirmed the domains were actively phishing for Telegram login codes by accessing the URL in a browser, entering a phone number linked to a Telegram account, after which a code was sent to that account:

Though the three live URLs, and other domain names in the campaign, suggest that Uzbekistan is the geographic region that’s being targeted, we also discovered older URLs from August and September 2023 that can be reasonably linked to the same campaign.
These domain names, including tajikistan-vote[.]site, arm-vote[.]space, and ukr-vote[.]site, and the likely related http://uz-golos[.]shop/, suggest active targeting of other countries too.
Here’s a list of the domains involved:
The domains that are currently live have been added to a threat feed that is available to Silent Push Enterprise users – Phishing – Telegram Phishing Targeting Eastern Europe and Central Asia.
New domains that match the signature will be automatically added to the feed.
Silent Push Community Edition is a free threat hunting and cyber defense platform featuring a range of advanced offensive and defensive lookups, web content queries, and enriched data types, including Silent Push ‘Web Scanner’ and ‘Live Scan’ that we used to track the phishing campaign in this blog.
Click here to sign-up for a free Community Edition account.
Data enrichment allows security teams to pinpoint the origin, function and risk level of a domain, IP address, or Autonomous System (AS).
ASN enrichment returns multiple categories and sub-categories that provide significantly greater context than standard DNS lookups and queries are able to achieve.
In this blog, we’ll explore the concept of ASN enrichment via Silent Push. We’ll take you through how to enrich an ASN using the Silent Push console, what data is returned, our risk scoring methodology and how to turn enriched ASN data into actionable intelligence.
Just like a post office manages the mail it receives and delivers, Autonomous Systems manage a specified set of IP addresses, using a routing policy that dictates how traffic moves to and from their IP space to enable the efficient exchange of information across the globe.
In a hierarchical sense, Autonomous Systems identify entire networks, while subnets are divisions within those networks, managed by the AS itself.
An Autonomous System Number (ASN) is a unique numerical identifier (e.g. 5483), displayed as a 16 or 32 bit number, that allows networks to communicate with each other, and ensure that data packets are routed correctly.
Like a digital license plate, ASNs can be used by security analysts to attribute malicious activity to certain actors, or map relationships across an attack chain (i.e., between organizations, hosting providers and service providers).

ASN analysis features prominently throughout a range of threat hunting and cyber defense workflows.
Security teams search across ASN data to join the dots across the global IP space in a variety of ways, from establishing a geographical picture of where threats may be originating from, to behavioral analysis, internal scoring methodologies and general risk-based countermeasures.
These use cases, however, are not without their challanges. Analysts are faced with the obstacle of incomplete AS datasets that only provide a basic level of information, without the requisite categorization of risk levels, subnets and interval-based analysis that shine a light on malicious activity in amongst an ocean of irrelevant and distracting data.
What if a security analyst was able to enrich ASN data to provide all of this this information one place, from ASN reputation scoring to the parameters of each subnet address associated with an AS?
Silent Push achieves this by using our own first-party intelligence data that’s collected, clustered, scored and delivered without third-party intervention.
This allows us to add an infinite amount of context to each ASN that we encounter, drill down into actionable data, and provide this information alongside other key observables via an integrated console, saving valuable time and resources for frontline security teams and researchers across a range of CTI workflows.

There are two ways to enrich an ASN in Silent Push:
Enrich a domain or IP address and pivot into enrichment from the returned ASN.
Enter the ASN directly into the search bar, and click Enrich
ASN Enrichment Highlights are shown at the top of the ASN Enrichment page.
These are a group of scores and numerical values that act as reliable indicators of an ASN’s risk level.
ASN enrichment Highlights include:

The ASN Information category does does exactly what it says on the tin. It gives a basic overview of the enriched ASN, including its unique identifier number, size, provider name, density, maximum density, active IPs and active subnets.

The WHOIS RDAP category returns administrative data pulled from WHOIS and RDAP registration lookups in one centralized location, presented alongside other key data types.

ASN takedowns play a critical role in protecting the digital assets of an organization.
The ASN Takedown Reputation category details how efficiently malicious domains are being removed on the ASN.
ASN Allocation Age indicates the age of the ASN number in days, and the ASN Allocation Date indicates precisely when the Internet Assigned Numbers Authority (IANA) allocated the ASN.
The ASN Takedown Reputation Score is a Silent Push invention that measures the ability and willingness of a network’s service provider to take action to mitigate cyber threats associated with the network.
The score is calculated using a combination of attributes, including the service provider’s history of responding to abuse reports, and the time it takes to mitigate malicious activity associated with their network.


The ASN Reputation indicates the trustworthiness and legitimacy of the IPs associated a particular ASN. It’s calculated using the ratio of blacklisted IPs, taken from from the total number of IPs that have been observed as being active within an ASN, in the last 30 days.
This category highlights all active subnets associated with the ASN.
It details the size of the subnet, active IPs on the subnet, active density, max density and density standard deviation. This helps security teams map out the scope of an ASN’s subnets, and monitor for suspicious activity.

The ASN Takedown Reputation History and ASN Reputation History graphs provide a visual timeline that maps out the risk level associated with a specific ASN over a set period of time, providing further context for teams looking to asses the risk level associated with a given ASN.

ASN Enrichment is available as part of Silent Push Community Edition – a free threat hunting and cyber defense tool used by security teams, threat analysts, and researchers that features 90+ data enrichment categories that you can use to track and monitor attacker activity across the global IPv4 space.
Click the button below to sign-up for a free account.