介绍对Sinkhole的节点进行识别,有助于提供威胁情报,获取Sinkhole IP地址后可减缓和预防相关恶意事件的影响。
掌握的Sinkhole IP地址
35.186.238.101
45.61.228.167
50.63.202.43
173.231.184.56
216.218.185.162
173.231.184.54
208.100.26.251
198.54.117.198
198.54.117.199
87.106.18.112
117.20.41.86
198.185.159.145
198.54.117.197
27.255.65.123
198.54.117.200
104.200.23.95
103.224.182.207
23.253.126.58
173.231.184.55
50.63.202.35
196.61.204.185
185.119.173.50
144.168.124.19
157.56.161.162
45.56.79.23
50.63.202.92
45.79.19.196
131.253.18.11
209.249.180.243
199.2.137.20
199.2.137.21
199.2.137.24
23.253.46.64
131.253.18.12
195.22.26.248
185.53.178.9
89.185.44.100
184.168.221.90
104.151.57.188
178.162.217.107
46.165.220.148
88.218.200.99
96.126.123.244
64.71.166.50
50.63.202.62
104.223.176.165
35.231.151.7
13.90.196.81
216.218.208.114
204.95.99.251
216.218.135.114
199.2.137.5
198.185.159.144
104.200.22.130
66.203.144.122
199.2.137.201
46.165.221.136
192.64.147.171
154.223.205.102
87.106.18.141
184.168.221.58
104.197.104.56
38.102.150.29
23.82.101.160
35.225.160.245
204.95.99.228
85.17.31.122
5.79.71.225
199.2.137.213
91.195.240.126
23.108.156.88
184.105.192.2
50.63.202.40
203.129.25.152
193.187.130.38
184.168.221.48
192.42.116.41
87.106.190.165
87.106.190.169
50.63.202.60
204.95.99.232
69.172.201.153
103.219.59.45
156.227.160.211
213.186.33.5
18.211.9.206
178.162.203.202
85.214.228.140
172.120.17.157
63.251.106.22
63.251.106.21
63.251.106.20
23.20.239.12
52.58.78.16
87.106.190.153
35.170.58.11
45.33.23.183
173.231.184.61
204.11.56.48
50.3.238.206
193.166.255.171
153.154.107.186
198.49.23.144
198.49.23.145
3.112.25.222
5.79.71.205
178.162.203.211
198.58.118.167
148.81.111.91
185.43.205.2
104.149.235.246
45.33.2.79
104.223.177.22
154.208.74.225
104.151.57.241
104.239.157.210
104.27.174.148
13.250.56.252
46.165.229.164
204.95.99.216
35.224.11.86
85.214.83.150
178.162.203.226
127.0.0.1
104.27.175.148
50.63.202.54
156.255.41.182
50.63.202.50
146.148.42.217
173.234.252.28
54.83.43.69
38.229.70.125
206.189.61.126
85.17.31.82
138.197.100.242
35.229.93.46
192.42.119.41
199.2.137.29
63.251.235.69
威胁情报IOC应用思路: 匹配即告警
由于sinkhole IP本身会发生“迁移”,因此需要阶段性的评估。给出几点思路:
- PDNS数据验证,如vt的pdns数据。如果大量的恶意域名解析到IP地址,则基本既可以确定;
- 解析的报文字段,也可以判断出来
- 访问IP地址的主页,如http://ip:80
- 解析的hostname,会含sinkhole信息 待续...
- 参考链接 https://sinkdb.abuse.ch/api/5035c187e9dd1fb9b543/json https://sinkdb.abuse.ch/api/5035c187e9dd1fb9b543/csv https://data.netlab.360.com/feeds/dga/dga.txt https://github.com/brakmic/Sinkholes