
â» æ¬èšäºã¯ãCriminal IPãŠãŒã¶ãŒãé »ç¹ã«çŽé¢ããæ€çŽ¢å€±æã®äºäŸãããã£ã«ã¿ãŒäœ¿çšæã®äœæãã¹ããŸãšããå®è·µçãªã¬ã€ãã§ãã
ä»åŸã¯ããã倿§ãªã¯ãšãªãæè»ã«æŽ»çšã§ãããããCriminal IPãç¶ç¶çã«æ¹åããŠè¡ããŸãã
Criminal IPã§ã¯ãã¿ã°ïŒtagïŒãšãã£ã«ã¿ãŒïŒfilterïŒãçµã¿åãããããšã§ã倿§ãªè åšã€ã³ãã©ãæ€åºã§ããŸããããããå Žåã«ãã£ãŠã¯ãŸã£ããæå³ããçµæãåŸãããªãããšããããŸããæãŸããçµæããŸã£ããåºãŠããªãããšããããŸãã
ãã®ãããªå Žåãå€ãã¯å®éã®ã»ãã¥ãªãã£ã€ã³ãã©ã«åé¡ãããããã§ã¯ãªããææ³ãã¹ããã£ãŒã«ãã®èª€äœ¿çšãåªå é äœã®èª€è§£ãšãã£ããåºæ¬çãªã¯ãšãªäœæãã¹ã«èµ·å ããŠããŸãã
æ¬èšäºã§ã¯ãé »ç¹ã«çºçããã¯ãšãªäœæãã¹ãæŽçããCriminal IPãããæ£ç¢ºãã€å¹æçã«æŽ»çšããæ¹æ³ã玹ä»ããŸãã
ãã¹ 1ïŒåœåã®ä»£ããã«ããã¹ããå ¥å
- â country: JapanÂ
- â country: JP
Criminal IPã®ãcountryããã£ã«ã¿ãŒã¯ãISO 3166-1 alpha-2圢åŒã®åœåã³ãŒãã®ã¿ãèªèããŸãããJapanãã®ãããªäžè¬çãªããã¹ãã¯ãã£ã«ã¿ãŒãšããŠæ©èœãããå¿ ã以äžã®ããã«2æåã®ã³ãŒãã§å ¥åããå¿ èŠããããŸãã
| åœå | æ£ããã³ãŒã |
|---|---|
| æ¥æ¬ | JP |
| éåœ | KR |
| ã¢ã¡ãªã« | US |
| ãã€ã | DE |
| äžåœ | CN |
| ãã·ã¢ | RU |
| ãã©ã³ã¹ | FR |
| ã€ã³ã | IN |
| ãããã | VN |
| ãã©ãžã« | BR |
| ã«ãã | CA |
| ã·ã³ã¬ããŒã« | SG |
| ã€ã©ã³ | IR |
| ãŠã¯ã©ã€ã | UA |
| ãã«ã³ | TR |
ð¡ äŸïŒcountry:JP AND tag:C2 â æ¥æ¬å ã®C2ãµãŒããŒãæ€åº
ãã¹ 2ïŒãã£ãŒã«ãåã®ã¿ã€ãããŸãã¯æªå¯Ÿå¿ã®ãã£ãŒã«ã
- â ssl:expired
- â ssl_expired:true
Criminal IPã§ã¯ãå®çŸ©ããããã£ãŒã«ãåã®ã¿ãèªèãããååšããªããã£ãŒã«ããã¿ã€ãïŒå ¥åãã¹ïŒã¯æ€çŽ¢çµæã«åæ ãããŸãããããšãã°ãSSLèšŒææžã®æå¹æéåããæ€åºããã«ã¯ãæ£ç¢ºãªãã£ãŒã«ãåã§ãããssl_expiredãã䜿çšããå¿ èŠããããŸãã
ð ãã¹ãŠã®ãã£ãŒã«ãäžèЧã¯ããCriminal IP > ãªãœãŒã¹ > ãã£ã«ã¿ãŒãã¿ã°ãã§ç¢ºèªã§ããŸãã
ãã¹ 3ïŒANDã»ORã®åªå é äœã®èª€è§£
- å ¥åã¯ãšãªïŒtag:C2 AND port:80 OR port:443
ãã®ã¯ãšãªã§ã¯ãC2ã¿ã°ãä»äžãããã€ã³ãã©ã®ãã¡ããŒã80ãéããŠãããã®ã«å ããŠãC2ã¿ã°ã®æç¡ã«é¢ä¿ãªãããŒã443ãéããŠãããã¹ãŠã®ã€ã³ãã©ãæ€åºãããŸãã
ð¡ Criminal IPã®æ€çŽ¢ããžãã¯ã§ã¯ããANDãããORããããå ã«é©çšãããŸãã
ã€ãŸããäžèšã®ã¯ãšãªã¯å
éšçã«ã¯æ¬¡ã®ãããªããžãã¯ãšããŠè§£éãããŸãïŒ
ïŒtag:C2 AND port:80ïŒOR port:443
ãŠãŒã¶ãŒã®æå³ãšã¯ç°ãªãããtag:C2ãã®æ¡ä»¶ã¯ãport:443ãã«ã¯é©çšãããªãããã
äžèŠãªçµæãå«ãŸãããã誀æ€åºã®å¯èœæ§ãé«ããªãæãããããŸãã
æ£ç¢ºãªæ¡ä»¶ã®çµã¿åãããå¿ èŠãªå Žåã¯ããANDãã§çµåãããã¯ãšãªãåå¥ã«åããŠå®è¡ããã®ãæã確å®ã§ãïŒ
- â Â tag:C2 AND port:80
- â Â tag:C2 AND port:443
ð ãã®ããã«æ¡ä»¶ãæç¢ºã«åé¢ããããšã§ã誀æ€åºãæžãããç®çã®çµæã«ããè¿ éã«ãã©ãçãããšãã§ããŸãã
ãã¹ 4ïŒããã«ã¯ã©ãŒããŒã·ã§ã³æªäœ¿çšã®ãã£ãŒã«ã
- â tag: SSL VPN
- â Â tag: âSSL VPNâ
ã¹ããŒã¹ïŒç©ºçœïŒãå«ãæååã¯ãããã«ã¯ã©ãŒããŒã·ã§ã³ïŒâ âïŒã§å²ãããšã§1ã€ã®æ¡ä»¶ãšããŠèªèãããŸãã
ããããªãå ŽåããSSLããšãVPNãã¯ããããå¥ã®æ¡ä»¶ãšããŠè§£éãããŠããŸããŸãã
ð¡ 該åœãã£ãŒã«ãïŒãtitleãããas_nameãããssl_issuer_organizationããªã©
ãã¹ 5ïŒå€§æåã»å°æåã®åºå¥ïŒ
Criminal IPã®ãã£ã«ã¿ãŒã¯ã倧æåãšå°æåãåºå¥ããŸããã
ã€ãŸããæ¬¡ã®3ã€ã®ã¯ãšãªã¯ãã¹ãŠåãããã«åäœããŸãã
- tag: cobalt strike
- tag: Cobalt Strike
- tag: COBALT STRIKE
ãã ãããâ âãã®æç¡ãªã©ãæ§æã®æ§é ã¯å¿ ãå®ãå¿ èŠããããŸãã
ä»é²ïŒäŸ¿å©ãªãã£ã«ã¿ãŒããŒã¯ãŒãé
| ãã£ãŒã«ãå | 説æ |
|---|---|
| ã¿ã° | ITè³ç£ã®ç¹æ§ïŒäŸïŒC2ãIoTãDevOps ãªã©ïŒ |
| port | éããŠããããŒãçªå·ïŒäŸïŒ80ã443ã2375 ãªã©ïŒ |
| ssl_expired | SSLèšŒææžã®æå¹æéåãã®æç¡ïŒtrueã»falseïŒ |
| cloud_provider | AWSãAzureãGoogle ãªã©ã®ã¯ã©ãŠããããã€ã㌠|
| hostname | ãã¹ãåïŒäŸïŒec2ãvultrïŒ |
| as_name | éä¿¡ãã£ãªã¢ãŸãã¯ã¯ã©ãŠãäŒæ¥åïŒäŸïŒAmazon.com Inc.ïŒ |
| country | 2æåã®åœåã³ãŒãïŒäŸïŒJPãUSãRUïŒ |
çµè«
Criminal IPã¯ãåãªãããŒã¯ãŒãæ€çŽ¢ã§ã¯ãªããæ£ç¢ºãªãã£ã«ã¿ãŒã®çµã¿åãããšæ¡ä»¶æ§æã«ãã£ãŠãé«åºŠãªè åšã€ã³ãã©ãæ€åºã§ãããã©ãããã©ãŒã ã§ãã
æ§æãæ£ããçè§£ãããã£ãŒã«ããæ£ç¢ºã«äœ¿ãã ãã§ããããå€ãã®è åšãããéãçºèŠããããšãã§ããŸãã
ä»åã®ãã¹ãã§ãã¯ãªã¹ããåèã«ãã¯ãšãªãã¹ãæžãããããå¹ççãªè åšãã³ãã£ã³ã°æŠç¥ãç«ãŠãŠã¿ãŸãããã
é¢é£å 容ã«ã€ããŠã¯ããCriminal IP DorksããŒãã·ãŒã : å®è·µçãªè åšã€ã³ããªãžã§ã³ã¹ã¯ãšãªã¬ã€ãïŒç¬¬2åïŒãããã²ãåç §ãã ããã
ããŒã¿ãœãŒã¹ïŒCriminal IPïŒhttps://www.criminalip.io/jaïŒ
é¢é£èšäºïŒ
