For an experiment, I created a script [1] that parses and send the TTY logs collected from actors or bots activity that run various commands after they successfully login the DShield sensor. Those TTY logs are sent daily at the end of each day to the DShield SIEM [2] to be correlated with all the data. 

The following ES|QL query provides a summary of all contab commands matching a TTYLog hash performed by different actors while logged in the sensor over a 90 day period. 

TTYLogs Correlation

FROM cowrie* 

| WHERE transaction.id == “f904275333aeac48d7df6cf53fe5fb9212c7d132a7d37253d2ab9321ba2690d8”

| WHERE event.hash IS NOT NULL

| KEEP transaction.id, event.hash

| STATS Total=COUNT(event.hash) BY event.hash, transaction.id

| SORT Total DESC


This transaction ID captured 5 similar crontab commands that are translated from its hash equivalent into this list executed by more than 3130 different actors (IPs):

TTYLogs Sources

transaction.id: f904275333aeac48d7df6cf53fe5fb9212c7d132a7d37253d2ab9321ba2690d8 over a 90 day period

Other example of Event Hash decoded and sent to DShield SIEM for analysis

Top 10 Indicators

      IP                      ASN

102.88.137.80        29465

42.96.20.16            131423

182.253.221.210    38482

46.188.119.26         8334

159.223.97.218       14061

185.158.22.150       210022

193.233.48.169       207713

209.99.190.200       402253

45.64.74.51              55933

202.152.148.27        23951

[1] https://github.com/bruneaug/DShield-Sensor/blob/main/sensor_scripts/daily_tty.sh

[2] https://github.com/bruneaug/DShield-SIEM

[3] https://www.elastic.co/docs/reference/query-languages/esql

———–

Guy Bruneau IPSS Inc.

My GitHub Page

Twitter: GuyBruneau

gbruneau at isc dot sans dot edu





Source link

#

No responses yet

Leave a Reply

Your email address will not be published. Required fields are marked *