Skip to main content

Turning DFIR into leads - Part 1

· 7 min read

Incident response investigations often start with a large amount of raw data spread across multiple sources. Forensic images will contain lots of valuable information, but identifying the relevant indicators can easily become overwhelming and time-consuming.

We took a set of playbooks provided by our partner NRD Cyber Security and used them as a starting point to improve our forensics workflows. Our ultimate goal is to turn qcow2 snapshots into investigation leads as easily as possible.

Malicious network activity detection with Zeek

· One min read

Join us Monday, the 23rd of February, for "Malicious network activity detection with Zeek". The presentation will show you how we use Zeek, an open-source tool, to monitor the network activity of the sites that are publicly exposed to the Internet. We will show the infrastructure we deployed and the integrations we have made for Zeek to detect malicious traffic.

As threat intelligence sources, we use MISP, FireHOL and some in-house developed scripts.

Don't miss out, we have juicy threat intelligence stuff as well (but only for your eyes)! Register on indico.upb.ro and we'll send you an invite!

IRC Bots Still Lurking Around

· 10 min read

Some adversaries never get bored of the same, old techniques. This month, we caught in our honeypot a self-spreading Linux malware targeting Raspberry Pi devices.

The script we investigated is a bash-based IRC bot that self-propagates by abusing weak or default SSH passwords. Once enrolled in the botnet, the infected victim awaits for base64 encoded commands signed with the adversary RSA key, effectively enabling authenticated remote command execution over IRC. What makes this incident interesting is not the complexity of the attack - quite the opposite. It highlights how low‑effort techniques still succeed in the wild, especially poorly configured IoT systems.

How to configure Dissect for Cowrie snapshots

· 5 min read

Honeypots like Cowrie are a great source of knowledge about attack vectors and new IOCs, but analyzing them can become a cumbersome task - especially because their number can get quite big. That’s where Dissect comes into play. By leveraging its API, you can streamline forensic analysis and automate snapshot processing. This opens up the road to fully automated IOC extraction pipelines that are able to analyze honeypot data and publish threat intelligence to be further processed by IDS tools.

This post is a short guide on how to configure Dissect API to work with Cowrie's snapshots.

Yet Another Wordpress Victim - Investigating a Command and Control Attack

· 10 min read

Once again, we found ourselves investigating a compromised WordPress server. In this blog post, you'll see how we investigated the attack and what useful information we have uncovered.

alt text

This time, the attack was discovered after a manual inspection on the hosting facility, where we observed several connections initiated by the hosting server to external IPs. This is not something we expected to see, so we did some further inspection. First, we extracted the executable files that started the processes and we upload their hashes on Virustotal. Most of them are flagged as malicious, and we could see some connected IP addresses, but nothing more (a report for one of the files is here).

Dissecting the Breach - Investigating a Web Shell Infection in WordPress

· 12 min read

This time, we've been requested to take a look into a compromised WordPress server. In this blog post, you'll see how we approached the post-incident forensics and what interesting artifacts we've uncovered.

For this incident, we were provided with a disk snapshot of a compromised Wordpress server stored as a qcow2 image. Extracting forensic data from a snapshot is a great task for using Dissect because it allows us to analyze targets without mounting or booting them. Dissect is actually a collection of modular tools that can be combined or extended to retrieve common information from the targets (users, cron jobs, services, history, filesystem entries).