Author Topic: Suggestions for analysing a possible APT  (Read 1636 times)

0 Members and 1 Guest are viewing this topic.

Offline discountlionsafari

  • NULL
  • Posts: 1
  • Cookies: 0
    • View Profile
Suggestions for analysing a possible APT
« on: June 07, 2015, 11:49:04 pm »
Hey all,
I've suspected my router and some of my hosts have been hacked for months, as far as I know they still are, but I dropped a gateway firewall with bro nsm and iptables between them and my LAN a couple days ago.


I think this is someone I know with an axe to grind, and first and foremost I'd like suggestions on how to (relatively easily) honeypot them / observe them in more detail. The gateway is an Ubuntu server so I can go to town on installing tooling to monitor traffic, like I say I already have bro and tcpdump, nmap on there.


Actually first and foremost is to work out exactly what's being done... If I ARP on the internal Nated LAN (192.168.2.0/24) I keep seeing an IP address with an incomplete MAC address. It changes IP address constantly. Also, there is a lot of outgoing SSL traffic to web servers serving up fake copies of amazon pages. Also, on BRO in the notices.log there have been loads of SSL certificate errors.


What do, guys?  INB4 UNPLUG EVERYTHING!!! I know I should totally kill the hosts and isolate whats going on methodically, but I am more interested in analysing the attack for a few more days, if there even is one... I'm pretty certain there's redirecting / url snarfing going on, but I've never had to chase that issue down before. Any help would be genuinely appreciated!

Offline proxx

  • Avatarception
  • Global Moderator
  • Titan
  • *
  • Posts: 2803
  • Cookies: 256
  • ФФФ
    • View Profile
Re: Suggestions for analysing a possible APT
« Reply #1 on: June 08, 2015, 08:24:23 am »
Lol I think you are paranoia.


Quote
Actually first and foremost is to work out exactly what's being done... If I ARP on the internal Nated LAN (192.168.2.0/24) I keep seeing an IP address with an incomplete MAC address. It changes IP address constantly. Also, there is a lot of outgoing SSL traffic to web servers serving up fake copies of amazon pages. Also, on BRO in the notices.log there have been loads of SSL certificate errors.
I don't think this is reason to believe you are 'hacked' as you like to call it.
Sounds to me like you have some outdated SSL cache or empty cmos etc.
So some ssl cert errors and a changing IPaddr ??? what did you smoke?

Sound to me like you got the idea went looking for evidence and found it.
Nevertheless I suggest you do malware scans.
What are those domains you are talking about?
« Last Edit: June 08, 2015, 08:25:26 am by proxx »
Wtf where you thinking with that signature? - Phage.
This was another little experiment *evillaughter - Proxx.
Evilception... - Phage

Offline nozzlechunks

  • Serf
  • *
  • Posts: 22
  • Cookies: -3
    • View Profile
Re: Suggestions for analysing a possible APT
« Reply #2 on: June 17, 2015, 09:15:20 pm »
Are you sure its an APT? Cuz it sounds like, you know, just a PT.