CRITICAL: Sinkhole HTTP Referer Events Report

DESCRIPTION LAST UPDATED: 2023-12-07

DEFAULT SEVERITY LEVEL: CRITICAL

This report contains events (connections) to HTTP sinkholes that arrived via a HTTP Referer. Sinkholing is a technique whereby a resource used by malicious actors to control malware is taken over and redirected to a benign listener that can (to a varying degree) understand connections coming from infected devices.

Since a sinkhole server is only accessed through previously malicious domain names, only infected systems or security researchers should be seen in this list. However, the sinkholes may also pick up web crawlers requesting malicious domains.

Severity levels are described here.

This report can come in 2 versions, one for IPv4 only connections, the other for IPv6 only connections.

File names: event4_sinkhole_http_referer and event6_sinkhole_http_referer

As of March 30th 2021, the list of infections being observed and shared is as follows:

andromeda-b66
beebone
boaxxe
calypso
caphaw
cobaltstrike
comment
cve-2009-4324
dltminer
downadup
emissary-panda
enfal-apt
ghost-push
goldmax
iframe exploit
infy-apt
jdk-update-apt
kovter
machbot
machete-apt
necurs
sality
sality_old
sality2
shadowpad
skunkx
spyeye
sunburst
sykipot-apt
threatneedle
tick
tinba
tonto-team
torpig
tsifiri
unityminer
unknown-apt
vpnfilter
winnti
xcodeghost
yash rat
yzf
zeus

Fields

  • timestamp
    Timestamp when the IP was seen in UTC+0
  • protocol
    Packet type of the connection traffic (UDP/TCP)
  • http_referer_ip
    IP of the HTTP referer
  • http_referer_asn
    ASN of the IP of the HTTP referer
  • http_referer_geo
    Country of the IP of the HTTP referer
  • http_referer_region
    Region of the IP of the HTTP referer
  • http_referer_city
    City of the IP of the HTTP referer
  • http_referer_hostname
    Reverse DNS of the HTTP referer
  • http_referer_naics
    North American Industry Classification System Code
  • http_referer_sector
    Sector to which the IP in question belongs; e.g. Communications, Commercial
  • severity
    Severity level
  • dst_ip
    Destination IP
  • dst_port
    Destination port of the IP connection
  • dst_asn
    ASN of the destination IP
  • dst_geo
    Country of the destination IP
  • dst_region
    Region of the destination IP
  • dst_city
    City of the destination IP
  • dst_hostname
    Reverse DNS of the destination IP
  • dst_naics
    North American Industry Classification System Code
  • dst_sector
    Sector to which the IP in question belongs; e.g. Communications, Commercial
  • public_source
    Source of the event data
  • infection
    Description of the malware/infection
  • family
    Malware family or campaign associated with the event
  • tag
    Event attributes
  • application
    Application name associated with the event
  • version
    Software version associated with the event
  • event_id
    Unique identifier assigned to the source IP or event
  • http_url
    HTTP request
  • http_host
    HTTP host extracted from the URL
  • http_referer
    Content of the HTTP referer
  • ssl_servername
    SSL servername

Sample

"timestamp","protocol","http_referer_ip","http_referer_port","http_referer_asn","http_referer_geo","http_referer_region","http_referer_city","http_referer_hostname","http_referer_naics","http_referer_sector","severity","dst_ip","dst_port","dst_asn","dst_geo","dst_region","dst_city","dst_hostname","dst_naics","dst_sector","public_source","infection","family","tag","application","version","event_id","http_url","http_host","http_referer","ssl_servername"
"2010-02-10 00:00:00",tcp,192.168.0.1,80,64512,ZZ,Region,City,example.net,0,"Communications, Service Provider, and Hosting Service",critical,172.16.0.1,80,65534,ZZ,Region,City,node01.example.net,0,"Communications, Service Provider, and Hosting Service",,sality,sality,sality,,,1700870512,/api/v1/update,node01.example.com,http://example.net,
"2010-02-10 00:00:01",tcp,192.168.0.2,80,64512,ZZ,Region,City,example.net,0,"Communications, Service Provider, and Hosting Service",critical,172.16.0.2,80,65534,ZZ,Region,City,node02.example.net,0,"Communications, Service Provider, and Hosting Service",,sality,sality,sality,,,1700870512,/api/v1/update,node02.example.com,http://example.net,
"2010-02-10 00:00:02",tcp,192.168.0.3,80,64512,ZZ,Region,City,example.net,0,"Communications, Service Provider, and Hosting Service",critical,172.16.0.3,80,65534,ZZ,Region,City,node03.example.net,0,"Communications, Service Provider, and Hosting Service",,sality,sality,sality,,,1700870515,/api/v1/update,node03.example.com,http://example.net,

Our 132 Report Types