International Revenue Share Fraud (IRSF)

(knock-knock.net)

52 points | by djkurlander 2 hours ago ago

8 comments

  • sciencejerk 2 hours ago

    Thanks for sharing your interesting research! Can you explain your honeypotting approach further? How are you "presenting" as a SIP relay? What other honeypots or protocols can you detect?

    • djkurlander an hour ago

      I set up servers on the net that masquerade as a SIP relay by essentially supporting the protocol but with few authentication protections. Malware bots scan the IPv4 space looking for such machines that they can use as a relay. My honeypot is actually an extensible framework, and we also can mimic SSH, Telnet, HTTP, SMB, FTP, RDP, SMTP, MQTT, Node-Red, MODB, S7, and SNMP. Individual servers can easily be set up to scan any subset of those. Check out https://knock-knock.net to get a visual sense of what the honeypot is doing!

  • Oarch 2 hours ago

    Hell of an opening on this blog post. Solid write up! Glad honeypots like this exist.

    • djkurlander an hour ago

      Much appreciated! Trying to help out the community with the honeypot & API, and it's always fascinating what attack patterns show up.

  • richwater 2 hours ago

    This is quite the claim (and I'm not saying you are wrong from making it).

    I just would have expected some of these institutions to be better.

    • djkurlander 2 hours ago

      Yes - I would have expected better from these institutions as well, but there's always going to be someone who brings their rogue laptop onto the corporate net. The key is how fast the security catches it. They can use the api that I describe in the blog to check my honeypot for their IPs. Very simple to put into a daily or hourly script.

  • kibwen 2 hours ago

    Shades of "KENNEDY SLAIN BY CIA, MAFIA, CASTRO, LBJ, TEAMSTERS, FREEMASONS": https://theonion.com/november-22-1963-1819587981/

    • djkurlander an hour ago

      Ha! Love it. Totally believe in it too.