issue with malwaredomainlist.ip

Reply
L4 Transporter

issue with malwaredomainlist.ip

Dear,

 

I added the "malwaredomainlist.ip" as miner.

This is working (shows that it has mined about 1500 IPs), but when I add the miner input to a ipv4 or domain aggregator I do not get any output...

 

2016-04-18 16_09_21-minemeld.png

L7 Applicator

Re: issue with malwaredomainlist.ip

Dear mr.linus,

malwaredomainlist.ip generates IPv4 addresses only, that's the reason domain aggregator does not accept any of the generated indicators. If you check the prototype for stdlib.aggregatorDomain you will see the inbound filters applied to all the indicators. These filters accept WITHDRAWS and indicators with type domain. Evertyhing else is dropped. 

Screen Shot 2016-04-18 at 16.51.26.png

 

The IPv4 aggregator instead should accept, but again it depends on the prototype you used to create the aggregator. malwaredomainlist.ip provides C2 IPs, and the indictors are marked as "outbound". Please, could you check that the IPv4 aggregator accepts "outbound" indicators ? You can look at the inbound filters inside the prototype.

 

It would be a good idea to add a new miner to poll the CSV file provided by malwaredomainlist instead of the IP list. I have created an ER (#8) to track this.

L7 Applicator

Re: issue with malwaredomainlist.ip

I am also working on a tracing function, to let the admin trace the flow of indicators across the graph. Should happen in a week or two.

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!