TTY Logs and the Data it Captures, (Sun, Oct 4th)
SANS diary correlates DShield honeypot TTY logs, finding one crontab pattern used by over 3,130 IPs.
Guy Bruneau describes a script that parses Cowrie TTY logs from the DShield honeypot and sends them daily to a DShield SIEM. An ES|QL query over 90 days tied one transaction hash to five similar crontab commands. Those commands were executed by more than 3,130 distinct actor IP addresses. The diary lists the top 10 source IPs and their ASNs.
- Daily script ships Cowrie TTY logs from DShield sensors into a SIEM.
- One event hash matched five similar crontab commands.
- More than 3,130 actor IPs ran that pattern over 90 days.
- Top sources include IPs in ASNs 29465, 14061, and 38482.
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| ipv4 | 102.88.137.80 | sent to DShield SIEM for analysis Top 10 Indicators IP ASN 102.88.137.80 29465 42.96.20.16 131423 182.253.221.210 38482 46.188.119.2 |
| ipv4 | 182.253.221.210 | 10 Indicators IP ASN 102.88.137.80 29465 42.96.20.16 131423 182.253.221.210 38482 46.188.119.26 8334 159.223.97.218 14061 185.158.22.15 |
| ipv4 | 42.96.20.16 | M for analysis Top 10 Indicators IP ASN 102.88.137.80 29465 42.96.20.16 131423 182.253.221.210 38482 46.188.119.26 8334 159.223.97. |
| sha256 | f904275333aeac48d7df6cf53fe5fb9212c7d132a7d37253d2ab9321ba2690d8 | TTYLogs Correlation FROM cowrie* | WHERE transaction.id == "f904275333aeac48d7df6cf53fe5fb9212c7d132a7d37253d2ab9321ba2690d8" | WHERE event.hash IS NOT NULL | KEEP transaction.id, even |
Full article227 words · extracted from isc.sans.edu · click to collapse
For an experiment, I created a script [1] that parses and send the TTY logs collected from actors or bots activity that run various commands after they successfully login the DShield sensor. Those TTY logs are sent daily at the end of each day to the DShield SIEM [2] to be correlated with all the data.
The following ES|QL query provides a summary of all contab commands matching a TTYLog hash performed by different actors while logged in the sensor over a 90 day period.
TTYLogs Correlation
FROM cowrie*
| WHERE transaction.id == "f904275333aeac48d7df6cf53fe5fb9212c7d132a7d37253d2ab9321ba2690d8"
| WHERE event.hash IS NOT NULL
| KEEP transaction.id, event.hash
| STATS Total=COUNT(event.hash) BY event.hash, transaction.id
| SORT Total DESC
This transaction ID captured 5 similar crontab commands that are translated from its hash equivalent into this list executed by more than 3130 different actors (IPs):

TTYLogs Sources
transaction.id: f904275333aeac48d7df6cf53fe5fb9212c7d132a7d37253d2ab9321ba2690d8 over a 90 day period

Other example of Event Hash decoded and sent to DShield SIEM for analysis

Top 10 Indicators
IP ASN
102.88.137.80 29465
42.96.20.16 131423
182.253.221.210 38482
46.188.119.26 8334
159.223.97.218 14061
185.158.22.150 210022
193.233.48.169 207713
209.99.190.200 402253
45.64.74.51 55933
202.152.148.27 23951
[1] https://github.com/bruneaug/DShield-Sensor/blob/main/sensor_scripts/daily_tty.sh
[2] https://github.com/bruneaug/DShield-SIEM
[3] https://www.elastic.co/docs/reference/query-languages/esql
-----------
Guy Bruneau IPSS Inc.
My GitHub Page
Twitter: GuyBruneau
gbruneau at isc dot sans dot edu