Silent Push free passive dns lookup tool

Using Silent Push to perform a passive DNS lookup


Performing a passive DNS lookup (PADNS) allows security teams to collect, analyze and share historical DNS data. Unlike traditional DNS which actively queries servers to translate domain names into IP addresses, passive DNS stores this information over time, creating a searchable historical record of how domains and IP addresses are associated with each other across the global IP space.

A ‘forward’ passive DNS lookup uses a domain or server name as the input parameter and returns an IP address as the ‘answer’, whereas a ‘reverse’ lookup uses an IP address to return a domain or server address.

Passive DNS lookups are the bread and butter of most threat hunting and cyber defense activities. There are, however, several challenges that security teams need to overcome when dealing with DNS records as pieces of digital infrastructure. These range from an over-reliance on incomplete and outdated datasets, to sorting through mountains of DNS records – particularly within enterprise organizations – to produce actionable intelligence.

Silent Push’s passive DNS lookup functionality allows you to perform a deep dive into enriched intelligence datasets, bolstering your cyber defenses, and uncovering emerging threats before they become a problem using a first-party dataset that’s uniquely designed to create searchable spaces related to specific DNS attack vectors.

Summary

In this blog, we’ll delve into different DNS record types, the role they play in the world of cyber threat intelligence, and how to maximise the Silent Push ‘Explore DNS Data’ feature to generate proactive threat intelligence. We’ll then discuss the outcome-focused tools available to you that make the most out of your organization’s passive DNS lookups, including pivoting on datapoints, monitoring results and more advanced query sets.

Understanding DNS record types

Attackers target different DNS record types using a variety of techniques to silently slip past an organization’s security measures. This makes it all the more important for security teams to diversify their defence mechanisms across multiple record types, encompassing their entire attack surface.

Let’s take a look at a selection of common DNS record types, and how attackers seek to exploit them…

A records

A records map a domain name to an IPv4 address. Passive A record lookups help analysts detail any IP addresses associated with a given domain name, detect changes in DNS activity, and associate domains and IPs with a specific threat campaign.

A records play a central role in the cat and mouse game of cyber attack and defense. Adversaries view A records as low hanging fruit, using them to propagate all manner of assaults on a public DNS presence, from domain hijacking, to typosquatting and email spoofing.

CNAME record

A Canonical Name (CNAME) record acts as an alias for another domain name, in lieu of a subdomain. You can’t use a CNAME record to point directly to an IP address – they’re used to map subdomains (such as www.) to apex domains (silentpush.com).

Attackers often use CNAME records when attempting a subdomain takeover – a DNS hijacking technique that can end up with an adversary obtaining access to an organization’s entire public DNS presence.

MX records

Mail Exchanger (MX) records identify which server is responsible for handling emails for a particular domain. Threat actors exploit MX records when propagating DMARC and email spoofing attacks, which involve an attacker making it appear as though an email has originated from a trusted source, when it’s actually been sent by the threat actor themselves.

Nameserver records

Nameserver (NS) records identify the authoritative DNS servers for a domain. NS records are particularly useful when an analyst wants to identify and monitor changes to registrars, hosts, or organizations associated with a particular domain.

Threat actors create searchable patterns by using the same set of nameservers to carry out attacks. By querying NS records via a passive DNS lookup, security teams are able to ascertain the risk level of a domain name, evaluate the reputation score of the NS associated with it, and view how many times a domain has jumped between different NS.

TXT records

TXT records contain any textual information that the domain owner wants to include, such as email addresses, contact information, or security-related information. By manipulating TXT records associated with specific email authentication protocols such as SPF, DKIM, and DMARC, attackers can make fraudulent emails appear legitimate.

SOA records

Start of Authority (SOA) records provide information about the DNS zone in which a particular domain is located, and hold administrative information about the domain. When a change is made to a DNS zone, the SOA serial number is incremented, indicating that an amendment has occurred.

This allows other DNS servers to detect and propagate the change, ensuring that all DNS information is consistent and up-to-date. Subsequently, security teams are able to detect changes to DNS information that may indicate malicious activity, such as the creation of new subdomains or changes to the IP addresses associated with a domain.

Executing a passive DNS lookup

Silent Push allows you to perform powerful passive DNS lookups across a range of record types. Security teams are able to use the console to establish links between disparate records, uncover attacker infrastructure, and obtain granular information on a given domain or IP.

Passive DNS lookup interface

The ‘Explore Indicator DNS Data’ page allows you to perform forward and reverse PADNS lookups, and execute advanced queries, all within a single screen. 

Forward and reverse lookups are performed on the ‘Explore Indicator DNS Data’ page, available to both Community and Enterprise users, for the following record types:

  • A/AAAA
  • CNAME
  • MX
  • NS
  • PTR4/6
  • SOA
the explore indicator dns data page allows you to enrich data and execute advanced queries

‘Explore’ table

Once you’ve executed a lookup, the Explore table populates results drawn from our first-party database that’s collected, clustered, scored and delivered without third-party intervention.

From here you can monitor and save observables to a feed, perform additional lookups on individual pieces of data, export raw data, obtain risk scores and enrich observables to gather further intelligence across 90+ categories, most of which are unique to Silent Push:

Passive DNS Lookup in Silent Push shows the explore screen and populated results

A secondary tab on the Explore screen allows you to view and copy the raw data, either for offline analysis or to facilitate integration with your security stack:

Silent Push shows the Basic Raw Data view in the Explore screen

Utilizing results from a passive DNS lookup

Unlike other passive DNS lookup platforms that provide queries in isolation, Silent Push features outcome-focused screens that enable security teams to gather intelligence that can be accessed, saved, and shared in just a few clicks. 

Filtering and searching through results

Filters help you sort data using a range of parameters, including:

  • Domain
  • IPv4 address
  • First seen date (When an observable was first seen in the dataset).
  • Last seen date (when an observable was last seen in the dataset).
  • DNS record type 

Filters can be accessed at the top of the Explore screen. You can also search through individual columns for specific pieces of data:

Passive DNS Lookup on Silent Push shows the Explore screen with different dataset filtering options.

Pivoting on passive DNS data

‘Pivoting’ involves performing additional queries on a single piece of data, including forward and reverse lookups, and domain or IP Enrichment queries.

Pivoting allows you to unearth intelligence that reveals the origin, function and risk level of a piece of data across a range of categories and sub-categories.

Clicking on an observable opens a pop-up window, featuring a bank of lookups relevant to the data type:

Silent Push shows the Explore screen with option to perform additional forward and reverse lookups.

Monitoring a passive DNS lookup

Once you’ve used a lookup to generate a set of results, you can enable ongoing monitoring that alerts you to changes in the dataset every 24 hours. By automating key queries across a range of internal workflows, security teams can save valuable time and resources, and eliminate repetitive tasks to focus on more pressing matters.

Clicking the ‘Monitor’ button on the top right of the Explore screen lets you assign a monitor to a set of results:

Passive DNS lookup monitoring on the Explore screen.

Saving and exporting passive DNS data

Critical to any security operation is the ability to share information amongst team members. You can save any piece of data – or even entire datasets – obtained from a passive DNS lookup either to an existing feed, or to a new feed, using a simple drop-down menu.

Feeds can be shared globally throughout your organization:

Passive DNS lookup saving on the Explore screen.

Passive DNS data can also be exported in raw format, as a JSON, or as a CSV:

Silent Push passive DNS lookup download feature on the Explore screen.

Advanced queries

The ’Explore Queries’ menu features a range of advanced DNS queries that allow you to analyze the historical characteristics of a piece of data, including the relationship it has with other data types, and build a behavioural fingerprint of attacker TTPS, including:

  • All domains hosted on specific server.
  • All domains hosted on an IP address.
  • IPs hosting a domain.
  • The IP ‘diversity’ of domain (the number of unique IP addresses associated with a particular domain).
  • Any nameserver changes.
  • All TXT records associated with a domain.
Passive DNS lookup on Silent Push shows the explore queries menu with advanced query options.

Register for Silent Push Community Edition

Silent Push passive DNS lookups allow you to explore your organization’s and supply chain’s DNS presence in a more timely, accurate and detailed way, and hunt for malicious infrastructure before it’s weaponized.

Silent Push Community Edition is a free threat hunting and cyber defense tool used by security teams, threat analysts, and researchers that features a range of basic and advanced DNS queries which interrogate the Silent Push database, built from our daily scans of the Internet’s global IP range.

Click the button below to sign-up for a free account.

Cyber padlock in tron colours

‘Data independence’: The new standard in global threat intelligence.

The questionable quality of most threat intelligence data is an open secret within the cyber threat intelligence industry.

Security teams are tasked with ingesting and analyzing domain, IP and website data that’s been collected from numerous disparate sources, and forced through multiple aggregation layers without a concerted effort along the way to arrange it in the form of actionable intelligence.

For CISOs, attempting to pin down the ROI of an unquantifiable and subjective element of their security operation can be a daunting task. Feed data is inherently difficult to evaluate, and it’s often impossible to establish precisely where intelligence data has originated from. It’s no wonder that 46% of CISOs do not regularly read threat intelligence reports, when most of their intelligence data isn’t easily operationalized and their teams are starting on the back foot.

Summary

In this blog, we’ll explain why ‘data independence’ – the concept of a threat intelligence provider collecting and owning 100% of their own data – is set to change the way organizations perceive and use cyber threat intelligence by affecting a paradigm shift in intelligence methodologies from reactive to proactive, and some of the inherent problems seen in current methods of distributing and using intelligence data.

Issues with legacy threat intelligence

Most threat intelligence platforms are content with relying on public IOCs, OSINT data, crowdsourced intelligence and passive DNS sensors to gather intelligence – only a smattering of which is collected in realtime to produce actionable intelligence, if at all.

This approach leads to numerous problems.

There’s often significant overlap across data streams, with a considerable amount of false positives for SOC teams to sift through. Operational efficiency is also affected. Data drawn from multiple sources that isn’t designed to work together is inherently slower to search across, and lacks a unifying set of characteristics that allow teams to organize it quickly and efficiently into pre-arranged searchable spaces, to combat specific attack vectors.

The number one barrier to achieving data independence is the sheer amount of effort it takes from a standing start. Building an all-encompassing collection, aggregation and enrichment engine from scratch, with zero precedent, and delivering it at scale to produce timely, accurate and complete intelligence is no mean feat. It takes a great deal of ingenuity and innovation, and a hell of a lot of work.

Data independence as a threat intelligence solution

Silent Push is on a mission to defragment organizational security operations by providing our customers with first-party threat intelligence data that’s collected, clustered, scored and delivered without third-party intervention, and with specific use cases in mind.

We provide timely, accurate and complete cyber threat intelligence datasets that allow security teams to track emerging TTPs and pre-weaponized infrastructure. Threat actors assemble their infrastructure using a series of traceable patterns. Owning and controlling our own data allows us to add an infinite amount of context to each observable that we collect, and where there are patterns to be found, make those links across the global IPv4 space to produce actionable intelligence.

There’s no rigidity to worry about. We’re not beholden to third-party collection and storage methods. We pass the data through to our console and API as a searchable space designed to output Indicators of Future Attack (IOFA) – a global early warning system that promotes situational awareness amongst the C-Suite, and directs security teams to where an attack is coming from, not where it’s been.

Let’s take a look at some of the problems with legacy threat intelligence, and how data independence can help to solve them:

Multiple tools required to extract any kind of value

Silent Push is a self-contained and self-reliant threat hunting and threat intelligence platform. Our UI and API is designed with our data in mind, and caters to a range of use cases. Ingesting and analyzing first-party data at source is inherently more resource and cost efficient.

Data is collected at specific points in time

OSINT data dumps and legacy IOCs are inflexible and mostly relevant to a single point in time. Silent Push data collection features far lower intervals, allowing teams to respond to emerging threats as they develop. This enables teams to prioritize the most dangerous threat types and focus their efforts on attack vectors that are unique to their organization. 

Data isn’t easily arranged based on threat type

Threat intelligence that’s gathered from multiple disconnected sources needs a lot of work before it can be considered actionable. First-party data is automatically sorted into searchable, self-contained, threat-specific spaces that require minimal intervention. 

The myth that more data equals a more efficient threat intelligence posture

Data independence is less about volume, and more about creating and controlling the relationship between billions of disparate domains, IPs, DNS records and content hashes. This is impossible to achieve unless ownership resides within the platform itself, and categorization is considered alongside delivery.

Lack of provenance = a lack of trust

If SOC teams and security analysts aren’t entirely sure of where data has originated from, this makes it inherently less trustworthy, regardless of the reputation of the platform or vendor that’s delivering it – especially true for OSINT and crowdsourced intelligence. Increased trust derived from first-party data gives teams more peace of mind.

Multiple aggregation layers

Legacy threat intelligence often passes through multiple platforms and aggregation layers before it’s presented to the end user for ingestion and analysis. Silent Push’s first-party data is original, unadulterated and categorized in real-time.

Mass data streams are not outcome focused

First-party data is agile, allowing us to innovate and counteract emerging TTPs with new categorizations, and with a higher degree of accuracy. All too often, legacy intelligence hampers a security team’s ability to generate meaningful insights quickly and with a high degree of accuracy.

Get in touch

Silent Push Community Edition is a free threat hunting and cyber defense platform that features a huge range of advanced offensive and defensive lookups, web content queries, and enriched data types.

Silent Push Enterprise exposes Indicators of Future Attack (IoFA) by applying unique behavioral fingerprints to attacker activity and searching our dataset. Security teams can identify impending attacks, rather than relying upon out of date IOCs delivered by legacy cyber threat intelligence platforms.

Webinar: How to locate the new scattered spider phishing infrastructure

Webinar: How to Locate the New Scattered Spider Phishing Infrastructure

Webinar details

Date released: Friday 22 December 2023

Level: Advanced

Duration: 30 mins (25 mins + 5 mins Q&A)

In this webinar, CEO, Ken Bagnall, explores how to track and monitor Scattered Spider’s Okta phishing infrastructure, using the Silent Push platform, including:

Scattered Spider’s deployment methods feature identifiable patterns and commonalities that allow Silent Push users to discover associated infrastructure and enumerate the threat actor’s online presence, using an array of lookups that can be tailored to a unique set of requirements.

The webinar demonstrates how to track the underlying infrastructure that accommodates a Scattered Spider phishing attack – apex domains, ASNs, registrars etc. – and extrapolate correlative datasets that allow security teams to identify patterns in attacker behaviour, including ASN data, naming conventions etc.

Access the webinar

This webinar is no longer available.

Background

Scattered Spider are a financially motivated threat group who has been active since the second quarter of 2022.

The group is known for launching sophisticated social engineering attacks designed to obtain login credentials and MFA tokens from employees.

Scattered Spider have been responsible for hundreds of incidents in the past year, two of which generated a large amount of media interested and caused significant financial and reputational harm for the organizations involved: the Twilio/Okta breach of August 2022 and the MGM breach of September 2023.

Webinar: Reverse engineering Gamaredon's infrastructure

Webinar: Reverse Engineering Gamaredon’s Infrastructure

Webinar details

Date released: Monday 6 November 2023

Level: Intermediate

Duration: 30 mins (25 mins + 5 mins Q&A)

In this webinar, lead Threat Analyst, Inês Véstia, will be exploring Gamaredon’s use of wildcard A records, ASN providers and name servers to evade conventional detection methods that rely on IOCs linked to a single point in time.

The webinar will demonstrate how to track the underlying infrastructure that accommodates an attack – apex domains, ASNs, registrars, authoritative name servers etc. – and extrapolate correlative datasets that allow security teams to identify patterns in attacker behaviour – ASN and IP diversity data, naming conventions etc.

Access the webinar

This webinar can be accessed by filling out the form below. Due to the contents of this webinar, we manually approve each individual who requests access. This means you may have to wait up to 24 hours to receive your personal login code. Thank you for your understanding. 

Background

Gamaredon – also known as Primitive Bear, Actinium or Shuckworm – are a Russian Advanced Persistent Threat (APT) group that has been active since at least 2013, historically across the US and the Indian Subcontinent, and more recently in Ukraine, including reported attacks on Western government entities.

Gamaredon are a highly-belligerent threat group who deviate from the standard-hit and-run tactics used by other APT groups, by propagating sustained attacks that are both heavily obfuscated and uniquely aggressive.

Binary code with a spider silhouette in the center

Eight-legged Phreaks: Silent Push DNS and content scans discover new Scattered Spider phishing infrastructure.

Key Points

  • New Scattered Spider infrastructure discovered on Hostinger
  • Silent Push content scans confirm the re-use of 2022 infrastructure to propagate new attacks
  • Malicious domains parked prior to weaponization, possibly to avoid reputation degradation
  • Silent Push HTML header and favicon scans used to pinpoint phishing kits across hundreds of new domains

Background

Scattered Spider are a financially motivated threat group who has been active since the second quarter of 2022.

The group is known for launching sophisticated social engineering attacks designed to obtain login credentials and MFA tokens from employees.

Scattered Spider have been responsible for hundreds of incidents in the past year, two of which generated a large amount of media interested and caused significant financial and reputational harm for the organizations involved: the Twilio/Okta breach of August 2022 and the MGM breach of September 2023.

Attacks commonly commence with sustained SMS phishing messages sent to the mobile phones of both current and former employees of the targeted organization.

Infrastructure and attack vectors

Scattered Spider phishing pages are hosted on short-lived domains that are created and hosted using bitcoin-friendly services, featuring typosquats of the targeted brand or the exact brand name followed or preceded by keywords such as ‘okta’, ‘help’, ‘sso’, and ‘servicedesk’.

The use of US registrars and providers, US carrier networks for voice and SMS phishing campaigns, the clear North American accent reported by the victims and the modus operandi of targeting US enterprises, indicates that Scattered Spider is focused on targets within the USA.

Throughout last year’s attacks, Scattered Spider used a small number of services to create and host malicious infrastructure:

2022 registrars:

  • Porkbun
  • NAMECHEAP

2022 ASNs

  • DIGITALOCEAN (AS14061)
  • AS-CHOOPA (AS20473)
  • AKAMAI-LINODE-AP (AS63949)
  • NAMECHEAP-NET (AS22612)

Data is exfiltrated once the threat actor obtains login credentials that provide an opportunity for lateral or elevated network movement, via a combination of techniques including a signed driver that terminates security processes, and VM admin console access via Azure Serial Console.

Front-end infrastructure shares the same code, e.g. the same favicon, ssdeep data and HTML title (‘Sign In’). The threat actor performs a call to the C2 server to obtain the target company’s name and logo, and the kit calls two legitimate Okta scripts.

Motivation

Scattered Spider uses stolen data to propagate secondary attacks across the user base of the affected company, and its supply chain operation.

This, in part, explains why the group focuses their efforts on organizations with a large amount of downstream users that aren’t directly attributed with the target organization: telecommunications providers, software and technology companies, Business Process Outsourcing (BPO) providers, and cryptocurrency platforms.

Using Silent Push data to uncover new infrastructure deployed via Hostinger

Over the past 90 days, Threat Analysts working with Silent Push first-party data have observed an increase in the number of domains created by Scattered Spider targeting organizations in the financial, insurance, investment, food ordering and delivery, retail and entertainment sectors.

Silent Push offers a monitoring feature that allows analysts to setup rules for domains or IPs that triggers an alert when a specific DNS change is detected. Silent Push analysts were researching Scattered Spider’s 2022 Twilio attack, and noticed new domains appearing in the results set.

Silent Push logs and tracks registrar and ASN information, including hosting changes, for every domain on the IPv4 scope. A large number of the new domains were registered through, and hosted on, providers not previously used by the group, indicating a notable expansion of infrastructure.

Identifying and tracking a new phishing kit

Whilst scanning for new domains, we discovered that two legacy domains which were created and used by the threat actor during 2022, t-mobile-okta[.]com and rogers-rci[.]com, had recently been re-registered via Hostinger on October 1 2023 and October 16 2023 respectively – a new registrar that Scattered Spider are not known for using (usually the group registers their infrastructure via Porkbun and NAMECHEAP).

It’s not uncommon for malicious domains to be re-registered – organizations acquire previously weaponized domains to analyze traffic or prevent them being re-used by threat actors – but we discovered that t-mobile-okta[.]com featured an active Okta-themed phishing page, one week after creation.

Scattered Spider T-Mobile phishing page on t-mobile-okta[.]com

Scattered Spider are known to use a variety of phishing kits, including ones available on underground forums. A quick search through the Silent Push hash content database established that the above domain contains a new phishing kit that’s deployed on all Scattered Spider domains registered since September 20223 (neither the Silent Push database nor third-party URL scanners such as urlscan.io show any matches pre-September).

Domain scans revealed that the phishing page was up for a little over a day – a common characteristic of most Scattered Spider domains.

Historical scan results also revealed that the domain was aged, given that it displayed the Hostinger parked paged in the days prior to the attack. The threat actor likely uses this technique to avoid reputation degradation across global scoring systems.

To recap:

  1. We discovered re-registered Scattered Spider phishing domains
  2. One of them hosted a phishing kit with content resembling the type found in previous attacks
  3. The TTL of the phishing page was in line with historical activity
  4. The Registrar was DIFFERENT than previously seen from Scattered Spider (Hostinger in 2023 vs Namecheap or Porkbun in 2022)
  5. The domains were aged, possibly after re-registration

Validating malicious domains using the Silent Push Domain Search

To confirm our hypothesis, we searched the Silent Push database for any domains created and hosted on Hostinger since September 2023, that matched Scattered Spider naming conventions, using custom regex parameters on the Silent Push Domain Search Query.

Regex examples:

  • ^([^.]{1,}(-|)ss(o|p)|ss(o|p)(-|)[^.]{1,})\.(com|co|net|us|help)$
  • ^([^.]{1,}(-|)okta|okta(-|)[^.]{1,})\.(com|co|net|us|help)$
  • ^([^.]{1,}(-|)h(e|1)lp(|desk|now)|h(e|1)lp(|desk|now)(-|)[^.]{1,})\.(com|co|net|us|help)$
  • ^([^.]{1,}(-|)my|my(-|)[^.]{1,})\.(com|co|net|us|help)$
Silent Push Domain Search with regex

Working with false positives

In the above syntax, we included the hyphen character as optional, given that Scattered Spider doesn’t always enforce a hyphen between the brand name and the keyword. This results in a broader results set that may return a higher number of false positives.

Enforcing the hyphen as mandatory between the keyword and the brand name returns a smaller amount of domain that whilst not covering the maximum amount of infrastructure, returns a fewer false positives.

Confirming the presence of malicious infrastructure

The above search returned hundreds of suspicious domains. We used some query parameters available through the Silent Push API and our custom query language, SPQL, to interrogate the dataset and discovered that a large number of the returned domains featured matching content and scripts, indicating the presence of a common phishing kit.

We accessed these domains using a browser and confirmed it is highly likely that they were created and launched by Scattered Spider – they all contained an Okta phishing page targeting commercial sectors that Scattered Spider have historically gone after, including Financial, Telecommunications, Software/Cloud Communications Platforms and CMR.

Here’s a sample of what we discovered:

  • 53help[.]org
  • aitice-usa[.]com
  • att-my[.]com
  • att-networks[.]net
  • bbt-work[.]com
  • cashsso[.]com
  • fedsso[.]net
  • freshworks-sso[.]com
  • freshworks-sso[.]net
  • freshworksso[.]com
  • grayscale-sso[.]com
  • grayscalesso[.]com
  • graysso[.]com
  • my-twilio[.]com
  • podiumsso[.]com
  • ssopodium[.]com
  • ssotelnyx[.]com
  • telnyx-sso[.]com
  • telnyxsso[.]com
  • victrasso[.]com
  • victrasso[.]net
  • workbbt[.]com
aitice-use[.]com
my-twilio[.]com

Investigating the re-use of old infrastructure

Some of the above domains were weaponized the moment they were created, whilst others were aged for days or weeks, suggesting that Scattered Spider were either in a hurry to deploy elements of their infrastructure or are possibly weaponizing domains to deliberately erratic schedules in order to avoid detection. rogers-rci[.]com was re-registered more than two months ago, yet still presents the Hostinger parked page.

After confirming that Scattered Spider are now using a different method of registering and hosting their infrastructure, we scanned for newly registered domains that used the old infrastructure, on the following parameters:

  1. Registered on Porkbun and NAMECHEAP (i.e. the 2022 Registrars)
  2. Registered from September 2023
  3. Featured HTML content that indicated a Scattered Spider phishing page
  4. Used the following ASNs from 2022:
  • DIGITALOCEAN (AS14061)
  • AS-CHOOPA(AS20473)
  • AKAMAI-LINODE-AP(AS63949)
  • NAMECHEAP-NET(AS22612)

Here’s a sample of the hundreds of domains we discovered:

  • activesso[.]com
  • actlvecampaign[.]net
  • assurionsso[.]net
  • asurionsso[.]com
  • bbt-hr[.]com
  • bbtemps[.]com
  • bbthour[.]com
  • bbtplus[.]com
  • bbtvpn[.]com
  • connect-cox[.]com
  • dashsso[.]com
  • hubsso[.]net
  • intercomsso[.]net
  • klaviyocorp[.]net
  • postmarksso[.]com
  • telesignsso[.]com
  • trustsso[.]com
  • workatbbt[.]com
  • xn--gryscale-ox0d[.]com
activesso[.]com
workatbbt[.]com

Prevention

All of the domains that we have listed in this blog contained active phishing pages at the point of discovery, but there are potentially hundreds of others that are being aged in preparation for an attack.

Scattered Spider’s deployment methods feature identifiable patterns and commonalities that allow Silent Push users to discover associated infrastructure and enumerate the threat actor’s online presence, using an array of lookups that can be tailored to a unique set of requirements.

Applicable queries

Silent Push Community and Enterprise users should execute the following Brand Impersonation queries to detect and monitor Scattered Spider brand spoofing campaigns that feature common naming conventions, targeting their own infrastructure:

  • ^(BRANDNAME(-|)ss(o|p)|(o|p)(-|)BRANDNAME)\.(com|co|net|us|help)$Looks for a domain as a brand name, followed or preceded by SSO or SSP (typosquatted version of SSO), with an optional hyphen between company name and keyword, on those 5 TLDs.
  • ^(BRANDNAME(-|)okta|okta(-|)BRANDNAME)\.(com|co|net|us|help)$Looks for a domain as a brand name followed or preceded by Okta, with an optional hyphen between company name and keyword, on those 5 TLDs.
  • ^(BRANDNAME(-|)h(e|1)lp(|desk|now)|h(e|1)lp(|desk|now)(-|)BRANDNAME)\.(com|co|net|us|help)$Looks for a domain as a brand name followed or preceded by a typosquatted version of ‘helpdesknow’, with an optional hyphen between company name and keyword, on those 5 TLDs.
  • ^(BRANDNAME(-|)my|my(-|)BRANDNAME)\.(com|co|net|us|help)$Looks for a domain as a brand name followed or preceded by “my”, with an optional hyphen between company name and keyword, on those 5 TLDs.
Brand Impersonation query run on the Silent Push console, targeting Scattered Spider infrastructure

Silent Push users should also make use of the platform’s On-Demand Endpoint Scan to locate infrastructure featuring the same phishing kit content, by harvesting HTML title, page content, SSL information and favicon hash data from a single URL.

On-demand scanning of granular HTML data, using the Silent Push console

Early Detection Feeds

Silent Push Enterprise users benefit from two Early Detection Feeds – ‘Scattered Spider Domains and IPs’ and ‘Scattered Spider Suspected Domains and IPs’ – that allow security teams to track and monitor Scattered Spider infrastructure either using the Silent Push console, or via an API that enriches an existing security stack with realtime threat data.

Register for Silent Push Community Edition

All of the lookups and datasets we used to detect and traverse Scattered Spider’s phishing infrastructure are available via Silent Push Community Edition – a free threat hunting platform available to security pros, researchers and analysts, including:

  • Brand Impersonation queries
  • Advanced domain searches
  • URL-based HTML content scans

IOFAs

  • actlvecampaign[.]net
  • activesso[.]comassurionsso[.]net
  • asurionsso[.]com
  • bbt-hr[.]com
  • bbtemps[.]com
  • bbthour[.]com
  • bbtplus[.]com
  • bbtvpn[.]com
  • connect-cox[.]com
  • dashsso[.]com
  • hubsso[.]net
  • intercomsso[.]net
  • klaviyocorp[.]net
  • postmarksso[.]com
  • telesignsso[.]com
  • trustsso[.]com
  • workatbbt[.]com
  • xn--gryscale-ox0d[.]com
  • 53help[.]org
  • aitice-usa[.]com
  • att-my[.]com
  • att-networks[.]net
  • bbt-work[.]com
  • cashsso[.]com
  • fedsso[.]net
  • freshworks-sso[.]com
  • freshworks-sso[.]net
  • freshworksso[.]com
  • grayscale-sso[.]com
  • grayscalesso[.]com
  • graysso[.]com
  • my-twilio[.]com
  • podiumsso[.]com
  • ssopodium[.]com
  • ssotelnyx[.]com
  • telnyx-sso[.]com
  • telnyxsso[.]com
  • victrasso[.]com
  • victrasso[.]net
  • workbbt[.]com
Red 3D email with phishing hook attached to it.

"Ad-versaries": Tracking new Google malvertising and brand spoofing campaigns. New MaaS DarkGate loader, DanaBot, IcedID and more.

  • Content scans show an increase in malvertising activity from Q3 2023 onwards.
  • New MaaS DarkGate variant adapted for malvertising purposes.
  • Brand impersonation TTPs used to inject infostealers, including DanaBot and IcedID.
  • Evidence of threat actors targeting various network tools, tech utilities and multimedia suites.

Background

Let’s start with some context. From Q4 2022 through to Q1 2023, Silent Push Threat Analysts tracked a series of malvertisment campaigns that acted as a delivery method for several banking trojans and infostealers – including Ursnif and Vidar – targeting a broad range of organizations and sectors.

Activity peaked between January-March 2023, before tailing off in the wake of a concerted collaborative effort by the security industry to hunt, track and counteract malvertisment infrastructure.

So what’s changed since then? Despite the lull in activity, our Threat Analysts have remained on the trail of trojan/infostealer-based brand impersonation campaigns. Our content scans have recently pinpointed a resurgence in malvertisment activity, not limited to the attack vectors and brands discussed in our previous blogs.

Our research shows conclusive evidence of Google ads being used to propagate malvertisment campaigns specifically constructed to deliver a range of malicious executables, including a new variant of the DarkGate commodity loader and two modular banking trojans – IcedID (a.k.a. BokBot) and Danabot.

Let’s take a look at how we used Silent Push to traverse attacker infrastructure, how the malicious code behaves and what organizations need to do in order to counteract this latest spate of attacks.

Tracking new threats

Our previous research focused on the use of spoofed AnyDesk domains and crypto-related browser extensions, among other attack vectors. This time around, threat actors have cast their nets far wider.

Here’s an up top date breakdown of the latest brands affected, gathered from our most recent scan data repositories:

2023 malvertisment campaigns (Source – Silent Push scan data)

Threat actors have regrouped to focus on remote desktop platforms, network tools and miscellaneous tech utilities, including multimedia suites and browsers.

From our dataset, TradingView – the popular financial charting platform – emerges as the most heavily targeted brand throughout 2023. AnyDesk remains a popular attack vector, comprising nearly a quarter of all malicious domains.

Silent Push is actively tracking these new domains, and all associated infrastructure, in a dedicated malvertisment feed. Here’s a snapshot of spoofing domains related to TradingView:

Snapshot of scam domains related to TradingView (Source: Silent Push malvertisement feed)

Google malvertising: Advanced IP Scanner

Our brand impersonation scans are consistently outputting newly registered malicious domains that are appearing as sponsored ads at the top of a Google search.

Let’s take a look at one such brand affected by Google malvertising – the LAN traffic analyzer Advanced IP Scanner.

We discovered a scam domain – advanced-ip-scanner[.]top – attempting to capture traffic intended for the legitimate site advanced-ip-scanner[.]com. As you can see, only the TLD has been changed:

Brand Impersonation scan on advanced-ip-scanner[.]com (Source: Silent Push)

advanced-ip-scanner[.]top redirects to the malicious domain shouman-acc[.]com:

advanced-ip-scanner[.]top redirecting user to shouman-acc[.]com

A quick Google search for ‘scanner IP’ returns a sponsored advertisement for ‘Advanced Scanner IP’, utilising domain that redirects to shouman-acc[.]com:

Active malvertisment on Google.com (as of 15 October 2023)

Malvertisement domain using a 302 redirect to shouman-acc[.]com

In this instance, shouman-acc[.]com acts as a delivery method for the IcedID banking trojan, with the hash 86bcd250b70e261d29a20538ffaf9ea3b27b510f02721cc6853bda227deeb118:

IcedID hash value (Source: VirusTotal)

The content consists of ‘Free Download’ button that instigates the delivery, with a grammatically incorrect CAPTCHA box included for crawler protection:

shouman-acc[.]com delivering IcedID trojan

DanaBot (a.k.a. BokBot) malvertising

In July, security researchers unearthed a new variant of the Malware-as-a-Service infostealer, DanaBot, featuring a modular subscription model and adversary support utilities, via the Russian language ‘Exploit’ forum.

Our investigation shows evidence of threat actors adapting this new variant for malvertising purposes, again targeting Advanced IP Scanner.

Let’s take a look at how it’s being used. In September, we observed sponsored Google ads for ‘scanner IP download’ pointing to domains spoofing Advanced IP Scanner:

Malvertising results for ‘scanner ip download’ on Google

A Fiddler traffic capture shows traffic redirected from google[.]com leading to the typosquatting domain advancde-ip-scanner[.]com:

Fiddler traffic analysis of advancde-ip-scanner[.]com

As is the case with the IcedID attack, the destination domain, advancde-ip-scanner[.]com, features a download link that injects a malicious file with a hash value of 123b285236757f7ac0c4f2107756a0ed661c9190aad81914c54debdd3bfa00f4.

This new DanaBot version attempts to read credentials and cached browser data:

DanaBot analysis (Source: any.run)

The malware uses the following C2 IPs to exfiltrate data:

  • 172[.]86[.]121[.]218
  • 45[.]61[.]160[.]115
  • 172[.]86[.]97[.]119
  • 91[.]212[.]166[.]96

In the above case, the Google ad remained active for more than a week. We also observed another DanaBot hash – 183276d2ea0740a8e92b3cff7abef725 – featuring the same ad, and the same domain, using the following C2 IPs:

  • 185[.]225[.]69[.]33
  • 5[.]189[.]253[.]176
  • 5[.]189[.]253[.]131
  • 185[.]225[.]69[.]230

New DarkGate variant

In July of this year, our content scans started to return large datasets that indicated a resurgence in malvertising activity. This renewed activity coincided with the emergence of a new variant of the DarkGate loader, also observed by other malware analysts and threat researchers throughout August.

TreeSize spoofing

Among the brands targeted with DarkGate injections in our dataset is Jam Software’s popular disk management too TreeSize Free. Here’s a domain – jam-software[.]net – that was flagged in our malvertisement sweeps as being malicious:

Scam TreeSize domain hosting DarkGate loader

Sandbox analysis of an executable downloaded from the above domain identifies the hash as a DarkGate variant:

Sandbox analysis of an executable from jam-software[.]net (Source: tria.ge)

Remote desktop spoofing

Threat actors have always considered network tool impersonation to be low-hanging fruit, and this latest series of campaigns is no different.

Recent content scans have flagged up numerous domains impersonating winscp[.]net the open source FTP, scripting and file manager utility, WinSCP

One such domain is winscphub[.]com (currently offline). Here’s a Silent Push DNS scan for the aforementioned domain, including reputational data:

DNS and reputation data for winscphub[.]com (Source: Silent Push)

The website features a download link that delivers a DarkGate variant with evasion and credential harvesting capabilities, with the file hash 2b6830970820af8d43ab710507ee19ca:

Spoofed WinSCP domain – winscphub[.]com

Malware analysis

Created in the host machine’s temporary files, the malware uses ICACLS.EXE (a Windows command-line utility that IT admins use to change access control lists on files and folders) to provide the malware with elevated privileges:

C:\Windows\system32\ICACLS.EXE” “C:\Users\Admin\AppData\Local\Temp\MW-c7688c81-6868-4efd-899f-aa889e84eda9.” /SETINTEGRITYLEVEL (CI)(OI)HIGH

Consistent with other DarkGate variants, the dropped file also contains an AutoIt executable and a corresponding .AU3 script in the same location:

AutoIt script (Source: tria.ge sandbox report)

To embed itself in the host machine and maintain optimal persistence levels, the malicious executable ‘regsvr32.exe’ loads it’s DLL with a COM entry in registries containing a CLSID (a serial number that represents a globally unique identifier for any application component in Windows):

Persistence activity (Source: tria.ge sandbox report)

The variant also creates a shortcut file under ‘C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\’.

The malware also attempts to read the location of Putty passwords, by attempting to locate registry paths used by the application:

  • HKLM\SOFTWARE\WOW6432Node\Martin Prikryl\WinSCP 2\DisablePasswordStoring
  • HKCU\SOFTWARE\Martin Prikryl\WinSCP 2\Configuration\Interface\PuttyPassword
  • HKCU\SOFTWARE\Martin Prikryl\WinSCP 2\Configuration\Interface\AutoSaveWorkspacePasswords

Conclusion

Our scans show a noticeable and worrying uptick in the use of sponsored Google ads to deliver infostealing malware in the third quarter of this year, most notably IcedID and a new version of the DarkGate loader adapted for malvertising purposes.

Threat actors are continuing to spoof legitimate domains through Google using a variety of TTPs, including typosquatting, the strategic placement of malicious links and hidden redirects.

To combat such tactics, affected organizations need to adopt security protocols that track the underlying infrastructure involved in the attack – registrars, ASN data, nameservers etc. – rather than relying on isolated lists of IOCs that are easily replaced by any adversary that uses them.

IOCs

  • winscphub[.]com
  • jam-software[.]net
  • advancede-ip-scanner[.]com
  • advanced-ip-scanner[.]top
  • shouman-acc[.]com
  • aptekoagraliy[.]com
  • 172[.]86[.]121[.]218
  • 45[.]61[.]160[.]115
  • 172[.]86[.]97[.]119
  • 91[.]212[.]166[.]96
  • 185[.]225[.]69[.]33
  • 5[.]189[.]253[.]176
  • 5[.]189[.]253[.]131
  • 185[.]225[.]69[.]230

Using Silent Push to combat malvertising

Silent Push Community Edition features many of the queries and enriched data types that we used to track malvertising activity. Sign-up free here.

Silent Push Enterprise customers benefit from curated feeds that track malvertising infrastructure as it’s deployed, prior to weaponization (Tags: #seo-poisoning, #malvertising).