Days from launch

by

I have been working on this project for well over a month and have run over 150,000 scans of known threat URLs. The site began from an investigation into malware distribution on a corporation's lapsed domain. I have a few articles I'll be posting in the coming weeks on with my findings, but enough of that for now.

During my investigation, I noticed the existence of the TDS (Traffic Direction System) and kept digging further to find out as much information as I could. Doing this manually was a big hassle as every URL scanner out there uses datacenter-based egress IPs, which were being blocked, while the sites were still serving malware to my home connection. I reported my findings within hours to the FBI IC3 on Monday, June 15th; three days later, a TDS PSA was sent out by IC3.

This is what gave me the idea. The early version was very basic, but it was able to do exactly what I needed: diff the HAR files of the same URL from different categorized ASNs. Additionally, the TDS doesn't only work at the redirect layer. During the investigation, I came across a few TDS systems that used TDS-over-TDS; redirect + payload delivery level. This means malicious actors are either using real-time API calls or a local compressed file of IP intelligence to determine different payload types (Windows / Mobile + Android + Chrome / Mobile + iOS + Safari).

Found threats are automatically published.

I would love to hear some feedback.

34 views

Add a comment

Replies

Be the first to comment