# Authentication Source: https://docs.threatbook.io/api-reference/authentication Describes how users authenticate API requests using unified API keys for Investigator and ATI. ## Getting Access You can view your API quotas and request rate limits on the “[Account](https://i.threatbook.io/account)” page. ThreatBook CTI now uses a single unified API key for all users. With this key, you can access different sets of APIs based on your subscription level: * [**IP Report API**](/api-reference/enrichment/ip-report-v1)\ Available to all users by default, with 50 free requests per day. * **Premium APIs**\ Includes endpoints such as [**Compromise Detection**](/api-reference/enrichment/compromise-detection-v1), [**IP Intelligence**](/api-reference/enrichment/ip-intelligence-v1), [**Domain Intelligence**](/api-reference/enrichment/domain-intelligence-v1), [**File Intelligence**](/api-reference/enrichment/file-intelligence-v2) and [**URL Intelligence**](/api-reference/enrichment/url-intelligence-v2). These require a premium subscription. If you’ve purchased Premium, your existing key will grant access. * **Feeds APIs** \ Feeds subscribers can use the same API key to access the specific data packages included in their subscription, such as [**IP Reputation**](/api-reference/feeds/ip-reputation) or [**IOC feeds**](/api-reference/feeds/ioc). If you have any questions or wish to upgrade, please contact us at [contactus@threatbook.io](mailto:contactus@threatbook.io). ## API key Your API key is a unique identifier for authenticating requests. If you are using Investigator, you can obtain and manage your key from the “[My API](https://i.threatbook.io/my-api)” page. If you are using ATI, please use the “[API Console](https://ati.threatbook.io/apiconsole)” page. This key supports all available API types according to your subscription. ## Access IP Please bind your access IP to the key and check whether you have the authority quotas to access the specific API before you interact with it. # Compromise Detection Source: https://docs.threatbook.io/api-reference/enrichment/compromise-detection-v1 api-reference/enrichment/compromise-detection-v1.openapi.json POST /v1/ioc/query This API is used to detect if an outbound address requested from an internal host is malicious and corresponding threat intel labels. # Domain Intelligence(v1) Source: https://docs.threatbook.io/api-reference/enrichment/domain-intelligence-v1 api-reference/enrichment/domain-intelligence-v1.openapi.json POST /v1/domain/query Domain Intelligence(V1) API provides intelligence judgment, relevant threat actors, virus/trojan family, complete original intelligence, as well as associated DNS, whois and contextual data for each domain. # Domain Intelligence Source: https://docs.threatbook.io/api-reference/enrichment/domain-intelligence-v2 api-reference/enrichment/domain-intelligence-v2.openapi.json POST /v2/domain/query Domain Intelligence(V2) API provides detailed threat intelligence for verdict. This includes threat verdict and labes from **ThreatBook Lab**, as well as associated DNS, whois and contextual data for each domain. # File Intelligence Source: https://docs.threatbook.io/api-reference/enrichment/file-intelligence-v2 api-reference/enrichment/file-intelligence-v2.openapi.json POST /v2/file/query Retrieve detailed static and dynamic analysis reports of a file, including file summary information, network behavior, behavioral signatures, static information, dropped behavior, process behavior, and multi-engines detection results. # File Upload Source: https://docs.threatbook.io/api-reference/enrichment/file-upload-v2 api-reference/enrichment/file-upload-v2.openapi.json POST /v2/file/upload For potentially malicious files from office endpoints, Web/FTP/email attachments, or suspicious files on endpoints/servers, the system performs rapid detection using **22 antivirus scanning engines**. Based on the file type, the system automatically selects an appropriate sandbox environment for dynamic analysis. # IP Intelligence(v1) Source: https://docs.threatbook.io/api-reference/enrichment/ip-intelligence-v1 api-reference/enrichment/ip-intelligence-v1.openapi.json POST /v1/ip/query IP Intelligence(V1) API provides intelligence labels(intelligence type), relevant threat actors, virus/trojan family, complete original intelligence, as well as associated internet asset and contextual data for each IP address. # IP Intelligence Source: https://docs.threatbook.io/api-reference/enrichment/ip-intelligence-v2 api-reference/enrichment/ip-intelligence-v2.openapi.json POST /v2/ip/query IP Intelligence(V2) API provides detailed threat intelligence for both **inbound** and **outbound** IP addresses. This includes threat verdict and labes from **ThreatBook Lab**, as well as associated internet asset and contextual data for each IP address. # IP Report(Community) Source: https://docs.threatbook.io/api-reference/enrichment/ip-report-v1 api-reference/enrichment/ip-report-v1.openapi.json POST /v1/community/ip You are able to get an IP report with comprehensive intelligence labels, such as **C2, Malware, Zombie, Compromised Host, Scanner,** etc., and contextual information like **open ports, certificates,** and so on. # URL Intelligence Source: https://docs.threatbook.io/api-reference/enrichment/url-intelligence-v2 api-reference/enrichment/url-intelligence-v2.openapi.json POST /v2/url/query Retrieve URL scan engine detection results and the analysis results of downloaded files. # Actors Source: https://docs.threatbook.io/api-reference/feeds/actors api-reference/feeds/actors.openapi.json GET /v2/feeds/stix/actor This API provides all threat actor profiles. # Hash Source: https://docs.threatbook.io/api-reference/feeds/hash api-reference/feeds/hash.openapi.json GET /v2/feeds/stix/hash This API provides identified malicious file hashes. # IOC Source: https://docs.threatbook.io/api-reference/feeds/ioc api-reference/feeds/ioc.openapi.json GET /v2/feeds/stix/ioc This API provides outbound malicious or suspicious domains and IPs. # IP Reputation Source: https://docs.threatbook.io/api-reference/feeds/ip-reputation api-reference/feeds/ip-reputation.openapi.json GET /v2/feeds/stix/ip-reputation This API provides inbound malicious or suspicious IPs. # Reports Source: https://docs.threatbook.io/api-reference/feeds/reports api-reference/feeds/reports.openapi.json GET /v2/feeds/stix/reports This API provides structured threat intelligence reports and their associated objects, such as actors, indicators, vulnerabilities, and attack techniques. # URL Source: https://docs.threatbook.io/api-reference/feeds/url api-reference/feeds/url.openapi.json GET /v2/feeds/stix/url This API provides malicious URLs. # Splunk APP - ThreatBook TI Source: https://docs.threatbook.io/api-reference/integration/splunk-app-api # ThreatBook TI for Splunk **ThreatBook TI for Splunk** seamlessly integrates with your Splunk environment to provide continuous, high-fidelity threat intelligence enrichment. By connecting to ThreatBook's global intelligence APIs, security operations teams can easily identify, analyze, and pivot on malicious IPs, domains, URLs, and file hashes directly within their Splunk workflows. ## Download & Installation You can download the app directly from our official Splunkbase page: 👉 **[ThreatBook TI on Splunkbase](https://splunkbase.splunk.com/app/8541)** ## Core Capabilities ### 1. On-Demand SPL Enrichment Leverage powerful custom SPL commands (`tbcti`) to dynamically query ThreatBook APIs and enrich your security logs in real-time, aiding rapid incident triage. ### 2. Automated Correlation Tasks Configure periodic, automated index scanning or Splunk CIM Data Model correlation without writing complex code. Proactively hunt for historical and emerging threats in the background. ### 3. Comprehensive Analytics Dashboard Utilize out-of-the-box analytical dashboards that visualize your organization's threat landscape. Gain deep visibility into IP behaviors, malware families, and malicious domains tied to your infrastructure. ### 4. Efficient Caching & Enterprise Readiness Built with enterprise environments in mind. Features a highly customizable local KVStore cache to accelerate analytics and reduce redundant API calls, along with full proxy support and compatibility for Search Head and Indexer Clusters. ## Get Started 1. Download the App from [Splunkbase](https://splunkbase.splunk.com/app/8541). 2. Deploy onto your Splunk instance (Standalone, Indexer Cluster, or Search Head Cluster). 3. Navigate to the App configuration settings and input your ThreatBook API key to begin enriching your data. *For comprehensive instruction guides, please refer to the detailed user manuals available from Threatbook team.* # Report Detail Source: https://docs.threatbook.io/api-reference/reports/report-detail api-reference/reports/report-detail.openapi.json GET /v2/reports/{id} Retrieve the full details of a specific **threat intelligence report**. This endpoint returns comprehensive information including report **severity**, **threat and report types**, **summary**, **tags**, targeted **industries/regions/organizations/products**, **impacts**, **ATT&CK techniques**, etc. # Report List (v2) Source: https://docs.threatbook.io/api-reference/reports/report-list-v2 api-reference/reports/report-list.openapi.json GET /v2/reports/list # Report List Source: https://docs.threatbook.io/api-reference/reports/report-list-v3 api-reference/reports/report-list.openapi.json POST /v3/reports/list Retrieves a paginated list of threat intelligence reports from ThreatBook Lab and open-source intelligence sources. # Vulnerability Intelligence Source: https://docs.threatbook.io/api-reference/vulnerabilities/vulnerability-intelligence-v2 api-reference/vulnerabilities/vulnerability-intelligence-v2.openapi.json POST /v2/vulnerability/query Supports integrating vulnerability information into automated operations workflows, providing access to public vulnerability details, risk assessments, PoCs, remediation recommendations, patches, and more. # Account & Limit Source: https://docs.threatbook.io/guide/account&limits ## Account Registration & Login ThreatBook CTI provides multiple ways for users to register and sign in.Users can choose between **third-party login** or **manual registration**: ## Third-Party Login * Click **“Continue with Google”** or **“Continue with GitHub”**. * Authenticate with your third-party account. * You will be redirected to ThreatBook CTI and automatically signed in. ## Manual Registration/Login * Click **“Create an Account”**. * Enter your **email, password**, and confirm the password. * Click **"Sign Up"**, then check your email for a **verification link**. * Click the link to verify your email. * You will be **automatically logged into ThreatBook CTI**. ## Login for Existing Users * If you already have an account, enter your **email and password** on the login page. * If you forgot your password, click **"Forgot Password?"** to reset it. ## Usage Limits & Query Restrictions ThreatBook CTI enforces different limits based on whether a user is logged in and their account plan. Query limits apply to both Research & Chat modules. | User Type | Query Limit | Reset Time | | ---------------- | ----------------------- | ---------------------------- | | Guest (No Login) | 5 queries per day | Daily at 00:00 UTC | | Basic Account | 10 queries per 4 hours | Every 4 hours from 00:00 UTC | | Pro Account | 100 queries per 4 hours | Every 4 hours from 00:00 UTC | ## Upgrading to a Pro Account Users who need higher query limits can redeem an invite code to upgrade to a Pro account. 1. Click on the **profile avatar** in the bottom-left corner of the page. 2. Click **“Upgrade”** in the menu.Enter your **invite code**. 3. Click **“Redeem”** to activate **Pro-tier benefits**. ## Pro Benefits **✅100 queries every 4 hours** For additional details, please contact us. # Chat Source: https://docs.threatbook.io/guide/chat The ThreatBook CTI Chat module allows you to interact with an AI assistant to retrieve threat intelligence, analyze data, and generate reports. Instead of manually searching across multiple sources, you can ask questions or input indicators directly and receive structured intelligence responses. ## Generating In-Depth Threat Intelligence Reports Users can obtain detailed intelligence reports on IP addresses, domains, vulnerabilities, and hacker groups by selecting a structured query template. These reports provide comprehensive threat assessments, including analysis insight, historical activity, and attribution info. ### How to use it? 1. Open the ThreatBook CTI Chat interface. 2. Choose a template-based query (e.g., IP, Domain, Vulnerability, or Hacker Group). 3. Enter the relevant entity (e.g., an IP address or CVE ID). 4. The AI will generate a comprehensive threat intelligence report, which can be downloaded as a full report. ## Performing General Threat Intelligence Lookups Users can also enter IP addresses, domains, or vulnerabilities without using templates. The AI will analyze the input and return relevant intelligence. ### How to use it? 1. Type a question of specific address or vulnerability in the chat. 2. The AI will automatically identify the entity type and return the most relevant intelligence. ## Engaging in General Security Q\&A Beyond structured lookups, the Chat module supports general cybersecurity-related inquiries, including: * Explaining security concepts (e.g., “What is an APT group?”). * Understanding attack techniques (e.g., “How does an SQL injection work?”). * Investigating threat actor behaviors (e.g., “Which APT groups target financial institutions?”). ### How to use it? 1. Simply type any cybersecurity-related question. 2. The AI will generate a concise, context-aware response. 💡 Example: Asking “What is Cobalt Strike?” will return an overview of the tool, its legitimate use cases, and how attackers misuse it. ## Analyzing Logs and Scripts Users can paste logs or scripts into the chat for automated analysis. The AI can: Identify suspicious activity in logs. Explain code behavior in scripts. Highlight potential attack techniques or vulnerabilities. ### How to use it? 1. Choose the Script/Log template and paste a log file snippet or a script into the chat. 2. The AI will analyze its contents, highlight security risks, and provide interpretations. ## Get Started with ThreatBook CTI Chat Start chatting now at [https://i.threatbook.io/chat](https://i.threatbook.io/chat) . For additional details, please contact us. # Compromise Detection Source: https://docs.threatbook.io/guide/compromise-detection ## What is Compromise Detection? Compromise in cybersecurity signifies a situation where the security of a system or network has been breached. This can involve unauthorized access, data loss, modification, or policy violation. Early detection is crucial to minimize damage and attacker dwell time. Monitoring for Indicators of Compromise (IOCs) helps identify past attacks and improve future security. A strong security strategy combines reactive and proactive measures. ## The Significance of Domain Names and IP Addresses as IOCs Network-based IOCs like domain names and IP addresses are vital for detecting compromises because attackers, regardless of the initial intrusion method, often rely on network connections for command and control (C2), data exfiltration, or phishing campaigns. Malicious domains and IPs serve as communication channels. Monitoring outbound network traffic for connections to unfamiliar or suspicious destinations can help identify such activity; blocking access to these destinations is crucial for preventing further impact. Sharing these IOCs as threat intelligence helps others proactively defend against the same attackers. ## Leveraging ThreatBook IOC Datasets for Compromise Detection within Your Organization Enhance your organization's compromise detection with ThreatBook's IOC datasets, boasting **99.99% accuracy**. ThreatBook delivers a comprehensive and highly reliable collection of Indicators of Compromise, including C\&C domains and IP addresses, associated malware families, related threat actors and campaigns, attribution to APTs where available, and malware hash values. **Updated on a minute-by-minute basis**, this accurate, real-time, rich, and precise contextual information empowers more effective identification of security breaches and informed incident response. Use ThreatBook CTI to directly query specific domains or IP addresses and identify IOCs. This allows for quick checks or targeted investigations and a deeper understanding of potential threats relevant to your organization. Furthermore, to seamlessly integrate this timely data into your existing security infrastructure, ThreatBook's IOC data can be ingested via **SaaS API** or **data feeds**(both coming soon). This involves feeding ThreatBook's IOC data into your security tools, such as Security Information and Event Management (SIEM) systems and Threat Intelligence Platforms (TIPs). SIEM systems can correlate ThreatBook's IOCs with your network traffic, system logs, and other relevant data for enhanced and up-to-the-minute analysis. TIPs can centralize, enrich, and disseminate ThreatBook's threat intelligence to various security controls within your organization, enabling proactive blocking and detection capabilities with the latest threat intelligence delivered through your preferred integration method. # Differentiator Source: https://docs.threatbook.io/guide/differentiator ThreatBook CTI offers key capabilities for analyzing IPs and domains across threat detection and investigation scenarios. The platform combines structured data, threat context, behavior history, and AI-based interpretation to support efficient security workflows. ## Verdicts ThreatBook CTI assigns a risk verdict to each queried IP or domain, categorized as malicious, suspicious, benign, or unknown. Verdicts are determined through a rule-based system built on internal and external intelligence sources, including intels, historical behaviors, and more contextual data. The verdict provides an immediate judgment of the entity’s risk level and can serves as a reference for processes such as alert validation, IOC management, and policy response. ## Contexts Each entity is enriched with threat labels and supporting contextual data to help analysts understand its role and potential threat associations. Tag categories include: * Threat categories * Network Information * Inbound Activities & Contexts * Malware * Attribution to APT or eCrime groups * Involvement in known attack campaigns Context includes data such as Whois, DNS records, certificates, malware samples, cybermapping, and web indexing. Both ThreatBook CTI’s internal intelligence and third-party data sources are integrated and normalized. ## Historical Activities ThreatBook CTI maintains a record of historical attack-related activity for IP addresses. This includes observed attack techniques, targeted ports and services, behavioral patterns, and reuse of infrastructure over time. This capability can be used to identify persistent threats, infrastructure reuse, and attack trend patterns. ## Data Aggregation ThreatBook CTI aggregates and standardizes data from multiple third-party intelligence platforms, scanning systems, reputation sources, and public search engines, presenting them in a unified format within query results. Users can also link their API keys via the Integration module to access more comprehensive external intelligence and enhance the completeness and reliability of their analysis. ## Insight Summary This module provides AI-generated summaries and judgments based on multi-dimensional inputs related to an IP or domain. It integrates: * Intelligence tags and metadata * Web search and indexing information * Phishing detection * Certificate, historical behaviors and more contextual information The AI model synthesizes these data sources to offer a structured interpretation of the indicator and gives a corresponding judgment aligned with the underlying evidence. # Feeds Introduction Source: https://docs.threatbook.io/guide/feeds_introduction ThreatBook CTI Threat Intelligence Feeds provide actionable threat intelligence in STIX 2.1 format. ## ThreatBook CTI Threat Intelligence Feeds Bundles * IOC Bundle: This bundle includes curated domains and IP indicators (with ports when applicable) for compromise detection. It contains C\&C addresses, malware distribution sites, fraud and phishing sites, crypto mining addresses, and DNS logs domains communicating with malware or threat actors/APT groups. Each indicator includes threat verdicts, threat labels (related malware, threat actors/groups, threat campaigns), and lifecycle times.
Samples Download
* IP Reputation Bundle: This bundle provides IP reputation context for inbound visitors. It includes IP addresses with threat verdicts, threat labels (asset category, malicious behaviors, network information), geolocations, and lifecycle times.
Samples Download
* Hash Feeds: This bundle provides newly identified malicious file hashes on a daily basis. Each feed package includes threat classification, threat name, verdict, and scan time information for reliable file-based detection.
Samples Download
* URL Feeds: This bundle provides newly identified malicious URLs on a daily basis. Each feed package includes verdict and scan time information to support automated URL detection and monitoring.
Samples Download
* Reports Feeds: This bundle provides newly published threat intelligence reports on a daily basis. Each feed package includes structured intelligence related to the reported incidents, such as associated threat actors, indicators, CVE information, MITRE ATT\&CK techniques, victims, malware, and attack tools.
Samples Download
* Actors Feeds: This API provides threat actor intelligence as a full dataset. Each feed package includes foundational actor information, such as actor name, aliases, actor type, motivations, and other basic attributes.
Samples Download
## Update Frequency The IOC bundle is updated hourly, while the File and IP Reputation bundles are updated daily. ## Get the Data You can fetch incremental data via the Feeds API (API key and subscription required). You can retrieve incremental packages by specifying time parameters and access data for up to 90 days. # Inbound IP Enrichment Source: https://docs.threatbook.io/guide/inbound-enrichment ## What is Inbound IP Enrichment? IP enrichment is the process of enhancing basic IP address information with additional context and details obtained from a variety of sources . This process transforms a simple numerical identifier into a rich source of intelligence, providing valuable insights for security and analytics. The context added through enrichment can encompass a wide range of attributes, including the geographical location of the IP address, the Internet Service Provider (ISP) responsible for the IP range, the organization or company associated with the IP, the privacy status indicating if the IP is associated with a proxy, VPN, or the Tor network, and importantly, reputation scores that reflect the historical behavior and trustworthiness of the IP address . This additional information converts rudimentary IP logs into actionable intelligence, empowering organizations to make data-driven decisions and proactively address potential security risks. **Note:** Inbound IP enrichment focuses on adding context to IP addresses of incoming network traffic, unlike outbound enrichment which analyzes IPs of external communications. ## Why Inbound IP Enrichment Matters for Security Operations? IP Enrichment can be used to: * **Improving Threat Detection:** Provides context (geolocation, proxy/VPN/Tor use, reputation) to identify malicious sources and activities. * **Accelerating Incident Response:** Offers immediate context for faster alert triage, prioritization, and proactive defense with Indicators of Future Attack (IOFAs), enabling automated initial responses. * **Enhancing Correlation and Detection:** Enables better correlation of events in SIEM systems for identifying sophisticated attacks by providing a comprehensive threat landscape view. * **Reducing Workload:** Automates data gathering, allowing analysts to focus on complex threats, and enables IPS to block known malicious traffic. ## Integrating IP Reputation Datasets into Your Security Infrastructure To effectively leverage the intelligence provided by IP reputation datasets, you should integrate them into your existing security infrastructure: * **Security Information and Event Management (SIEM) Systems:** SIEM platforms ingest IP reputation feeds and correlate this intelligence with other security logs and events to provide a more comprehensive view of the threat landscape and enhance alert prioritization.For example, SIEM uses IP reputation to identify and filter out inbound connections from legitimate internet scanners, reducing alert noise for security analysts. * **Threat Intelligence Platforms (TIPs):** TIPs allow organizations to aggregate and manage IP reputation data from multiple sources, enrich it with other forms of threat intelligence, and disseminate it to various security tools. For example, TIP automatically blocks inbound connections from IPs flagged by multiple feeds as malicious (e.g., malware distributors), preventing potential attacks. * **Security Orchestration, Automation and Response (SOAR) Platforms:** SOAR platforms automate incident response workflows based on IP reputation data. For example SOAR automatically blocks malicious inbound IPs detected by firewalls and enriched with IP reputation data, blocks the inbound IP address on all network firewalls, or generates a ticket for the security team with the enriched information and automated actions taken. Such automated response minimizes the window of opportunity for an attack. ThreatBook CTI provides high fidelity IP reputation datasets, you can using our portal query the data or integrate them into your existing security infrastructure via **SaaS API** or **data feeds**(both coming soon). # Welcome to ThreatBook CTI Source: https://docs.threatbook.io/guide/introduction As a security intelligence analyst or security operations professional, you're constantly facing the challenge of making sense of a vast and ever-growing amount of threat information. Sifting through data to identify real threats and understand their context can be time-consuming and overwhelming, often leading to an "information gap" that hinders effective decision-making. ThreatBook CTI is designed to address this challenge. It's an intelligence analysis platform built specifically for professionals like you, providing **high-quality threat intelligence data** and leveraging the power of **AI** to help you **eliminate information gaps** and make **more informed decisions** in your daily threat analysis. ## Get started today ThreatBook CTI is **free to use** for limited queries. By registering for an account, you'll unlock more queries and powerful features. Start exploring the platform and experience how ThreatBook CTI can transform your threat analysis workflow. ## Here's how ThreatBook CTI empowers you * **Identify Threats:** Quickly analyze IP addresses and domains to determine their threat level. Gain immediate insights into associated threat context, trace historical attack behaviors, and understand how threat verdicts have changed over time. * **Filter Out the Noise:** Beyond identifying threats, ThreatBook CTI helps you distinguish legitimate activity from malicious behavior. Access network infrastructure and ownership information to identify and filter out benign sources, reducing false positives and focusing your efforts on genuine threats. * **Centralized Intelligence:** For every indicator you investigate, ThreatBook CTI aggregates crucial network and contextual information in one place. This includes IP geolocation, SSL certificates, current and historical DNS records, asset discovery data, and associated malicious file samples. Similarly, for domains, you can access current and historical WHOIS information, DNS resolution history, SSL certificates, website asset details, and linked malware samples – all without having to pivot between multiple tools. * **Unlock Deeper Insights with AI:** ThreatBook CTI goes beyond simply presenting data. We've incorporated the knowledge and experience of seasoned threat analysts into our AI models. This enables the platform to help you extract valuable insights from raw intelligence, allowing for a deeper understanding of the threats you're investigating. Additionally, our ThreatBook CTI Chat feature acts as an intelligent co-pilot for your security operations. * **Rely on Timely and Accurate Data:** Our intelligence is sourced from continuous monitoring of global attack activities, malware captures, and proactive tracking of APT groups and cybercriminal campaigns. We provide data on both outbound malicious connections and historical inbound attack records, with updates occurring at minute-level frequency. While we also incorporate open-source intelligence, we employ a rigorous quality control process to identify and remove noise, ensuring the timeliness and accuracy of the intelligence you receive. # Overview Source: https://docs.threatbook.io/guide/overview ThreatBook CTI provides comprehensive global threat intelligence, with a significant emphasis on the **Asia-Pacific (APAC) region**. This focus ensures you Gain critical insights into threats prevalent in the region, alongside a comprehensive global perspective. ## Data Collection * **Uncover C\&C Indicators from Massive Malwares :** We analyze over one million new suspicious files daily, extracting critical information like Command and Control (C\&C) addresses used by malware. * **Proactive C\&C Detection:** We actively scan the internet for patterns associated with Command and Control (C\&C) servers, enabling us to identify newly active infrastructure and their network addresses, providing early warnings to disrupt potential attacks. * **Honeypot Network for Real-Time Intelligence:** Our global network of over 100k+ honeypots passively captures live attack attempts, giving us direct insights into attacker tactics and currently active C\&C servers. * **Extensive Domain Data :** We collect an extensive inventory of DNS domains, including registrar details, resolved IP addresses, subdomains, and SSL/TLS certificates. This allows you to understand domain infrastructure, identify potentially malicious domains, and see relationships between online assets. * **Global IPv4 Scanning:** Our continuous scan of the entire IPv4 space reveals internet-connected devices, their open ports, running services (including VPNs and Tor), geolocation, and more. * **Real-time OSINT Aggregation:** Our system continuously monitors over 500+ global security information sources, ensuring you are always updated on the latest threats, vulnerabilities, and attacker tactics. * **Threat Pivoting to Reveal Hidden Connections:** We use graph techniques to analyze relationships between data points, uncovering hidden connections and identifying additional potential C\&C servers and IP addresses. ## Datasets * **IP Reputation:** Our IP reputation data provides granular insights into the IP addresses. This includes identifying IPs involved in recent exploit attempts, brute-force attacks, botnet activity, and spam. We also categorize IPs based on their infrastructure characteristics, such as being proxy servers, scanners, VPNs, CDNs, dynamic IPs, backbone networks, IoT devices, cloud WAF entry/exit points, Tor nodes, BT trackers, educational network IPs, gateway exits, mobile base stations, and even identify network mapping tools and search engine crawlers. Crucially, we also capture details about the recent attack methods associated with these IPs. * **IOCs (Indicators of Compromise):** Our IOC data provides you with the C\&C domains and IP addresses, their associated malware families, related threat actors and campaigns, attribution to APTs(Advanced Persistent Threats) where applicable, and the hash values of the malware involved in communication. This rich context allows for more effective compromise detection and incident response. * **Aggregated Network Information:** We offer a consolidated view of fundamental network information for both IP addresses and domains. This includes historical Passive DNS (PDNS) records, historical WHOIS data, internet asset fingerprints, and SSL/TLS certificate details. This historical perspective and asset profiling helps you understand the evolution of network infrastructure and identify potential anomalies. # Pivoting Analysis Source: https://docs.threatbook.io/guide/pivoting-analysis ## What is Pivoting Analysis? Pivoting analysis is an investigative technique used in cybersecurity threat intelligence. It involves using known pieces of information (Indicators of Compromise - IoCs) such as IP addresses, domains, or malware hashes, to discover related, previously unknown indicators, infrastructure, or threat actor activity. The goal is to expand the scope of an investigation, uncover the full extent of an attack campaign, and identify potential future threats linked to the same adversary. ## How to Perform Pivoting Analysis with IP/Domain Datasets and Threat Intelligence Pivoting analysis typically starts with an initial known data point, often an IP address or a domain associated with malicious activity. Analysts then leverage various datasets and threat intelligence sources to find connections and related entities. Key data types used include: 1. **IP Address and Domain Data:** Identifying current and historical resolutions (PDNS), associated domains hosted on the same IP, or IPs resolving to the same domain over time. 2. **WHOIS Records:** Examining domain registration details like registrant name, email address, organization, registrar, and creation/expiration dates. Threat actors sometimes reuse registration information across multiple domains. 3. **SSL/TLS Certificates:** Finding other domains or IPs that share the same SSL/TLS certificate or certificates with similar subject information or issuer details. 4. **Internet Asset Characteristics:** Analyzing features of the hosting infrastructure, such as open ports, running services, web server banners, operating systems, or specific web technologies used. Shared infrastructure characteristics can link seemingly unrelated assets. 5. **Domain Naming Patterns:** Identifying conventions or patterns in how domains are named (e.g., specific keywords, structures, use of dynamic DNS providers). 6. **Associated Malware Samples:** Linking domains or IPs to specific malware families or samples that communicate with them. 7. **Threat Intelligence Feeds:** Correlating findings with known malicious indicators, threat actor profiles, and reported campaigns from external threat intelligence sources. By querying these datasets with a known indicator, analysts can "pivot" from one piece of information to another, systematically mapping out the adversary's network infrastructure. ## Why Pivoting Analysis is Useful for Uncovering Hidden Threats Pivoting analysis is highly effective for proactively identifying and neutralizing threats, often before they become fully operational. Here's why: * **Exploits Attacker Reuse:** Threat actors often reuse infrastructure components (like email addresses for registration, specific hosting providers, name servers, or IP subnets) and tactics (like domain naming conventions) to minimize costs and effort. Pivoting analysis directly leverages this operational pattern. * **Reveals Latent Infrastructure:** It allows security teams to uncover infrastructure that an attacker has set up but may not yet be actively using for malicious purposes (e.g., C\&C servers, phishing sites). * **Provides Early Warning:** Identifying these "sleeper" assets provides an early warning, enabling organizations to block or monitor them before they are weaponized in an attack. **Example: Uncovering Unused C\&C Domains** Imagine an analyst identifies an active Command and Control (C\&C) domain: malicious-update-123.com. Through pivoting analysis: * **WHOIS Lookup:** The analyst examines the WHOIS record for malicious-update-123.com, noting the registrant email (e.g., [hacker@protonmail.com](mailto:hacker@protonmail.com)) and the registration date. * **Naming Pattern Analysis:** The analyst observes the pattern \[keyword]-\[purpose]-\[number].com. * **Infrastructure Analysis:** The domain resolves to IP address 198.51.100.10, hosted on a specific ASN, and uses a self-signed SSL certificate with particular subject details. * **Pivoting Action:** The analyst uses threat intelligence tools to search for: Other domains registered with [hacker@protonmail.com](mailto:hacker@protonmail.com). * Other domains following the \[keyword]-\[purpose]-\[number].com pattern, especially those registered around the same time. * Other domains hosted on 198.51.100.0/24 or the same ASN, particularly those newly registered or exhibiting similar asset characteristics (e.g., similar open ports, server banners). * Other domains using SSL certificates with similar subject information or fingerprints. * **Result:** This process might reveal domains like malicious-control-456.net and system-service-789.org. These domains might already be online ("live") and configured but not yet observed communicating with malware in the wild. They were likely registered by the same actor for future C\&C operations. * **Benefit:** By identifying these domains proactively through pivoting, security teams can block access to them, preventing future infections or command communication channels from being established. ## How to Use ThreatBook CTI for Pivoting Analysis ThreatBook CTI provides powerful capabilities to facilitate efficient pivoting analysis: * **Unified Data Access:** Use the ThreatBook CTI portal to query any IP address or domain of interest. * **Rich Contextual Data:** For any queried indicator, ThreatBook CTI provides access to linked datasets crucial for pivoting, including: **PDNS (Passive DNS):** View historical IP-domain resolution relationships to see infrastructure changes over time. * **Internet Asset Characteristics:** Examine detailed profiles of associated network assets, including open ports, services, software versions, and server configurations. * **WHOIS Information:** Access current and historical domain registration records. * **Associated Samples:** Identify malware samples known to communicate with the IP or domain. * **Related Certificates:** Find associated SSL/TLS certificates and pivot to other assets sharing them. * **AI-Powered Attribution:** Leverage the **Attribution** feature within ThreatBook CTI. This function uses AI algorithms to analyze connections across these diverse datasets automatically. It intelligently identifies and suggests potentially related infrastructure or activity, significantly speeding up the pivoting process and helping you discover relevant connections you might otherwise miss. By utilizing these features, analysts can effectively use ThreatBook CTI to conduct in-depth pivoting analysis, map out threat actor infrastructure, and uncover hidden threats. # Reports Glossaries Source: https://docs.threatbook.io/guide/reports-glossaries Detailed reference for CTI Threat Report properties and query fields, including report categories, threat types, industry classifications, and region codes. This page provides a comprehensive reference of fields and attributes associated with **Threat Intelligence Reports** (CTI Reports). Use these values when filtering and querying reports via CTI APIs or searching within ThreatBook console. *** ## Report Category (`category` / `category_list`) The `category` and `category_list` fields represent the primary classification of the threat intelligence report. | **Category Value** | **Description** | | :------------------------- | :----------------------------------------------------------------------------------------------------------- | | **Incident Analysis** | Analysis reports focusing on a single, specific cyber attack incident. | | **Malware Analysis** | Detailed analysis reports targeting a specific family or type of malicious software. | | **Vulnerability Analysis** | In-depth technical analysis and mitigation guidelines for a specific security vulnerability. | | **Summary Report** | High-level aggregated threat intelligence, such as security trends, event roundups, and landscape reports. | | **Incident Response** | Reports detailing incident response procedures, actions taken, and lesson-learned summaries. | | **Security News** | General security-related news, advisories, or bulletins not fitting the precise analytical categories above. | *** ## Threat Type (`threat_type` / `threat_type_list`) The `threat_type` and `threat_type_list` indicate the nature of the cyber threat or attacker behavior documented in the report. * **APT** (Advanced Persistent Threat) * **Ransomware** * **Supply Chain Attack** * **Phishing** * **Data Leakage** * **Data Breach** * **Crypto Mining** * **DDoS** * **Financial Theft** * **Others** — Any cyber threat type not covered by the categories above. *** ## Industry Classifications (`target_industry` / `target_industry_list`, `industry_of_target_org`, and `org_industry`) Industry properties categorize target entities impacted by the threat. The supported parameters and response fields utilizing these industry values include: * **Target Industry (`target_industry` / `target_industry_list`)**: The target sectors mentioned in the threat report. * **Industry of Target Org (`industry_of_target_org`)**: Filter by the industry sectors of the targeted organization. * **Target Org Industry (`target_orgs[].org_industry`)**: Response field showing the industries of the affected organization. The reports mainly aligns with the **STIX 2.1** industry standards, supporting a structured Level-1 and Level-2 classification: | Level-1 Industry | Level-2 Industries | | :---------------------- | :--------------------------------------------------------------------------------------------------------- | | **Agriculture** | Farming, Livestock, Agri Supply Chain, AgriTech | | **Aerospace** | Aerospace Manufacturing, Satellite Systems, Space Operations | | **Automotive** | Car Manufacturers, Auto Parts, Dealerships, EV & Autonomous Tech | | **Chemical** | Chemical Manufacturing, Industrial Chemicals, Specialty Chemicals | | **Commercial** | Corporate Services, B2B Services, Trade & Distribution, Legal Services | | **Communications** | News Media, Magazines, Radio / FM, TV & Broadcasting, Digital Media | | **Construction** | Building Construction, Engineering, Infrastructure Construction, Architectural Services | | **Defense** | Defense Contractors, Military Manufacturing, Weapons Systems, Military Electronics | | **Education** | Higher Education, K12 Schools, Online Education, Vocational Training | | **Energy** | Oil & Gas, Electric Power, Renewables, Nuclear Energy | | **Entertainment** | Streaming, Gaming, Film & TV, Sports Entertainment | | **Financial-services** | Banking, Investment Banking, Securities, Payments, Wealth Management, Fintech | | **Government** | emergency-services, government-local, government-national, government-public-services, government-regional | | **Healthcare** | Hospitals, Clinics, Medical Devices, Healthcare Services | | **Hospitality-leisure** | Hotels, Restaurants, Tourism, Theme Parks, Resorts | | **Infrastructure** | dams, nuclear, water | | **Insurance** | Life Insurance, Property & Casualty, Reinsurance, Insurance Brokers | | **Manufacturing** | Industrial Manufacturing, Electronics Manufacturing, Machinery, Precision Manufacturing | | **Mining** | Mineral Extraction, Metal Processing, Mining Operations | | **Non-profit** | NGOs, Foundations | | **Pharmaceuticals** | Drug Manufacturing, Biotechnology, Pharma R\&D, Pharma Supply Chain | | **Retail** | E-commerce, Supermarkets, Department Stores, Convenience Stores, Consumer Brands | | **Technology** | Software, Hardware, Cloud Computing, Cybersecurity, AI/ML, Semiconductors | | **Telecommunications** | Mobile Operators, ISP/Broadband, Satellite Communications, Network Operators | | **Transportation** | Airlines, Railways, Logistics & Freight, Public Transit, Maritime Shipping, Ports | | **Utilities** | Electric Utilities, Gas Utilities, Water Utilities, Waste & Sewage | | **Web3** | Crypto Exchanges, Blockchain Infrastructure, Wallets & Custody, DeFi Platforms, NFT / Digital Assets | *** ## Country & Region (`hq_region_of_target_org` / `target_region_list` / `target_region_code` / `hq_region`) Country and region codes must comply with the **ISO 3166-1 alpha-2** standard (two-letter country codes). The supported parameters and response fields utilizing these ISO country codes include: * **Target Region Code (`target_region_code` / `target_region_list`)**: Filter by the country codes of the targeted entities. * **HQ Region of Target Org (`hq_region_of_target_org`)**: Filter by the country codes of the targeted organization's headquarters. * **Target Org HQ Region (`target_orgs[].hq_region`)**: Response field showing the headquarters country codes of the targeted organization. * **Standard**: [ISO 3166-1 alpha-2](https://www.iso.org/obp/ui/#search) (e.g., `US`, `CN`, `JP`, `GB`, `DE`). * **Usage**: Used to identify both the origin of threats/actors and the geographical locations of target entities. # Research Source: https://docs.threatbook.io/guide/research The ThreatBook CTI Research module provides a platform for querying and analyzing IP and domain intelligence. Users can retrieve information such as verdicts, threat labels, historical activity, and various metadata related to an address. ## How to Use? ### 1. Searching for an IP or Domain * Enter an IP address or domain in the search bar. * Click Search to view the intelligence results. * The results include verdicts, tags, Whois, attack history, passive DNS, certificates, and more. ### 2. Get Instant Threat Verdicts Each queried IP or domain receives a verdict indicating its security status: * **Malicious** – Associated with known threats or attacks. * **Suspicious** – Exhibits behavior that may indicate risk. * **Benign** – No detected malicious activity. * **Unknown** – Insufficient data available. The verdict is determined based on rule-based detection. Also, ThreatBook CTI integrates well-known external intelligence providers to enhance accuracy like VirusTotal, Greynoise and urlscan, etc. Users can configure third-party API keys in the Integration settings to unlock additional verdicts and enrich their analysis with external intelligence sources. ### 3.Investigate with Threat Intelligence Labels Each IP or domain comes with automated intelligence labels that categorize its risk profile.Including but not limited to the following categories: * **Threat Attribution:** Identifies links to APT groups, botnets, or malware campaigns. * **Infrastructure Role:** Determines whether the entity is a C2 server, proxy, VPN, or residential IP. * **Behavioral Insights:** Detects use in phishing, DDoS attacks, or credential stuffing operations. These tags help you quickly assess risk and determine next steps. ### 4. Multi-Dimensional Data ThreatBook CTI aggregates intelligence data to provide a comprehensive view of an address. The available data includes, but is not limited to: * **Whois & Registration History** – Domain ownership and changes over time. * **Passive DNS (pDNS)** – Historical DNS resolutions linking domains and IPs. * **Certificate** – SSL/TLS certificate relationships. * **Port Scans & Service Banners** – Information from global scanning data. * **Related Malware Files** – Identified threats communicating with the address. * **Historical Activity** – Previously observed attack methods, targeted ports/services, and connections to other infrastructure. * **Web Search Results** – Extracted data from indexed webpages associated with the address. This information allows for deeper analysis and correlation across different data points. ## Accessing Research Data Currently, ThreatBook CTI Research is accessible through: * **Web Interface** – Users can perform manual searches via the platform. * **API Integration** – Support for automated queries. * **Feeds (Coming Soon)** – Continuous intelligence updates for external integration. These options provide flexibility in how intelligence is accessed and utilized. Get Started with ThreatBook CTI Research Start searching now at [https://i.threatbook.io/research](https://i.threatbook.io/research) . For additional details, please contact us. # Threat Labels Source: https://docs.threatbook.io/guide/threat-labels Unified guide of threat intelligence labels and categories, simplified and categorized for clear referencing. ## Threat Categories | **Type** | **Description** | **Verdict** | | :-------------- | :--------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | :---------- | | **C2** | A Command and Control (C\&C) server set up by attackers to issue commands to compromised hosts and receive stolen data. Active connections indicate the host is compromised. | Malicious | | **Botnet** | A node within a botnet, which is a network of malware-infected computers controlled remotely to execute coordinated malicious activities. | Malicious | | **Hijacked** | A compromised network address where an attacker has hijacked communications to impersonate a trusted entity. | Malicious | | **Phishing** | A phishing site that mimics legitimate websites to deceive users into disclosing sensitive personal, account, or financial information. | Malicious | | **Malware** | A distribution point for malicious software. Proactive connections by hosts typically suggest malware infection. | Malicious | | **Exploit** | Attempted to exploit system vulnerabilities using malicious scripts or payloads to gain unauthorized access or execute arbitrary tasks. | Malicious | | **Scanner** | Initiated network scanning activities to identify vulnerable systems, explore exploits, or gather network intelligence, typically by bots, worms, or attackers. | Malicious | | **Zombie** | A compromised host functioning as a bot, controlled remotely to initiate cyber attacks, spread malware, or harvest data. | Malicious | | **Spam** | Associated with disseminating bulk unsolicited spam/malicious content, often using automated bots or email harvesting systems. | Malicious | | **Compromised** | Belongs to a host infiltrated and controlled by attackers. It may be used for launching cyber attacks, spreading malware, data theft, or botnets. | Suspicious | | **Brute Force** | Initiated a brute force attack, attempting to gain unauthorized access by exhaustively trying passwords or credentials, often using automated tools. | Malicious | | **Suspicious** | A dubious site containing undesirable or illegal content, though not actively involved in the remote control of users. | Suspicious | | **Trusted** | Belongs to a trusted network service. | Safe | ## Sub-type of “C2” | **Type** | **Description** | **Verdict** | | :-------------- | :------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | :---------- | | **Sinkhole C2** | A former Command and Control (C2) server now controlled by security institutions. Traffic from compromised hosts is redirected here to collect threat intelligence and assist in mitigation. | Malicious | ## Sub-type of “Suspicious”: Mining related | **Type** | **Description** | **Verdict** | | :------------- | :---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | :---------- | | **CoinMiner** | A private mining pool service set up by attackers to receive data from hosts infected with cryptojacking malware. Key indicator for unauthorized cryptocurrency mining and resource exhaustion. | Malicious | | **MiningPool** | A public mining pool server bridging miners and pools. Often abused by attackers for unauthorized cryptocurrency mining. Unapproved traffic warrants investigation. | Malicious | ## Sub-type of “Suspicious”: Others | **Type** | **Description** | **Verdict** | | :--------------------------- | :------------------------------------------------------------------------------------------------------------------------------------------------------- | :---------- | | **Suspicious Application** | A potentially harmful application or site associated with malware, phishing, deceptive content, unauthorized data harvesting, or malicious ads. | Suspicious | | **Suspicious Website** | A potentially harmful website that may host malware. | Suspicious | | **Reverse Proxy** | A reverse proxy server. Can potentially be exploited by attackers for intranet penetration or bypassing network boundaries. | Suspicious | | **C2 Panel** | Associated with a Command and Control (C2) web interface, allowing attackers to remotely manage infected systems, execute commands, and exfiltrate data. | Suspicious | | **Fake Software Downloader** | This network address hosts a fake software site that mimics legitimate platforms to trick users into downloading malware. | Suspicious | ## Sub-type of “Phishing” | **Type** | **Description** | **Verdict** | | :--------------- | :--------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | :---------- | | **Fake Website** | An imitation website designed to mimic reputable sites (replicating branding, design, and domains) to trick users into providing sensitive credentials or financial details. | Malicious | ## Sub-type of “Brute Force” | **Type** | **Description** | **Verdict** | | :------------------------ | :-------------------------------------------------------------------------------------- | :---------- | | **SSH Brute Force** | Initiated a brute force attack targeting SSH services. | Malicious | | **FTP Brute Force** | Initiated a brute force attack targeting FTP services. | Malicious | | **SMTP Brute Force** | Initiated a brute force attack targeting SMTP services. | Malicious | | **Http Brute Force** | This network address attempted HTTP brute-force attacks to bypass Basic Authentication. | Malicious | | **Web Login Brute Force** | Initiated a brute force attack targeting web login portals. | Malicious | ## Network Information | **Type** | **Description** | | :------------------------- | :------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | | **Proxy** | An intermediary proxy server used to relay network traffic. Often abused by attackers to conceal their identity and geographic location. | | **HTTP Proxy** | Provides HTTP Proxy services. | | **HTTP Proxy In** | An inbound gateway providing HTTP Proxy services. | | **HTTP Proxy Out** | An outbound gateway providing HTTP Proxy services. | | **Socks Proxy** | Provides Socks Proxy services. | | **Socks Proxy In** | An inbound gateway providing Socks Proxy services. | | **Socks Proxy Out** | An outbound gateway providing Socks Proxy services. | | **VPN** | Provides Virtual Private Network (VPN) services, routing encrypted traffic to hide real IP addresses. Often abused by attackers to mask their origin. | | **VPN In** | An inbound gateway providing VPN services. | | **VPN Out** | An outbound gateway providing VPN services. | | **Tor** | A node running Tor (The Onion Router) service for anonymous communication. Due to high anonymity, it is frequently used by attackers to host malicious services or hide traffic. | | **Tor Proxy In** | An inbound entry point (Guard/Bridge node) to the Tor network. | | **Tor Proxy Out** | An outbound exit point (Exit node) from the Tor network. | | **Bogon** | An IP address not allocated for public Internet use (e.g., private networks, loopbacks, broadcast). Rarely represents a valid Internet threat indicator. | | **FullBogon** | An unassigned IP address that is neither allocated to any organization nor registered in private address spaces by IANA. | | **Gateway** | A gateway device facilitating data exchange and routing between a local network and the Internet. | | **IDC** | Belongs to an Internet Data Center. Since IDC servers rarely initiate outbound user requests directly, any unexpected traffic from them should be monitored as they may be rented/compromised by attackers. | | **Dynamic IP** | A temporary, changeable IP address assigned dynamically by an ISP using DHCP. | | **Edu** | Originates from an educational network or institution. | | **DDNS** | Associated with Dynamic Domain Name System (DDNS). Frequently exploited by attackers to map dynamic IPs to fixed domains for resilient C2 infrastructure. | | **Mobile** | A transmission/reception node (such as a base station) within a mobile communication network (GSM, CDMA, LTE, etc.). | | **CDN** | Belongs to a Content Delivery Network (CDN). Attackers sometimes exploit CDN infrastructures via techniques like domain fronting to bypass security detection. | | **DNS** | A Domain Name System (DNS) server that resolves human-readable domain names into IP addresses. | | **BTtracker** | A BitTorrent Tracker used for P2P file sharing. P2P networks are sometimes abused for malware distribution. | | **Backbone** | Part of a network service provider's high-capacity backbone network. | | **ICP** | A website that has successfully completed the Internet Content Provider (ICP) registration required in Mainland China. | | **NRD3M** | A domain name that has been newly registered within the last 3 months. | | **IoT Device** | Belongs to an Internet of Things (IoT) smart device. | | **Game Server** | Belongs to an online internet gaming server. | | **Search Engine Crawler** | A search engine spider or crawler. Generally poses no cyber security threat, though high volume visits might affect server stability. | | **Advertisement** | Belongs to an online advertising service. | | **CloudWAF** | A cloud-based Web Application Firewall (WAF) service protecting web applications from exploits. Website traffic is routed through the Cloud WAF before reaching the destination server. | | **AI Gateway Service** | An intermediary service positioned between client applications and AI model providers. It offers unified API access. These services typically aggregate multiple upstream models or accounts behind a standardized API interface for applications, developer tools, and AI agents. | | **Remote Management Tool** | Remote management tool nodes are network infrastructure components that support remote control and remote operation and maintenance services. Their main functions include client connection coordination, online device status maintenance, session establishment, and encrypted traffic routing. These nodes typically belong to the global service network of commercial remote control software, and their associated IP addresses may change dynamically. | ## Inbound Activities & Contexts | **Type** | **Description** | | ------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | | Censys | This IP address is part of Censys infrastructure. Censys scans public IPs and domains for security analysis. | | Shodan | This IP address is part of Shodan infrastructure. Shodan indexes Internet-connected devices for security intelligence. | | PetalBot | This IP address is part of PetalBot infrastructure. PetalBot is the crawler for Huawei's Petal Search. | | BingBot | This IP address is part of Bingbot infrastructure. Bingbot is Microsoft's web crawler for Bing search. | | Reacher-scanner | This IP address is part of Reacher-scanner infrastructure. Reacher-scanner scans for SSH host keys and JARM hashes. | | BinaryEdge.io | This IP address is part of BinaryEdge infrastructure. BinaryEdge collects, analyzes, and categorizes Internet data through cybersecurity, engineering, and data science efforts. | | Yandex Search Engine | This IP address is part of Yandex Search infrastructure. Yandex Search is a major Russian search engine. | | GoogleBot | This IP address is part of Googlebot infrastructure. Googlebot is Google's web crawler. | | Rapid7 Project Sonar | This IP address is part of Rapid7 Project Sonar infrastructure. Project Sonar scans public networks for security vulnerabilities. | | AppleBot | This IP address is part of Applebot infrastructure. Applebot is Apple's web crawler. | | IPIPNET | This IP address is part of IPIP.NET infrastructure. IPIP.NET provides IP geolocation and profiling. | | IPinfo.io | This IP address is part of IPinfo infrastructure. IPinfo provides IP intelligence, including geolocation and ISP data. | | DataGrid Surface | This IP address is part of DataGrid Surface infrastructure. DataGrid Surface scans for vulnerable devices. | | Onyphe | This IP address is part of Onyphe infrastructure. Onyphe is a cybersecurity search engine. | | ShadowServer.org | This IP address is part of ShadowServer.org infrastructure. ShadowServer.org provides threat intelligence and cybercrime monitoring. | | Driftnet | This IP address is part of Driftnet infrastructure. Driftnet tracks Internet footprints. | | Bitsight | This IP address is part of Bitsight infrastructure. Bitsight provides cybersecurity risk management. | | Malware Patrol | This IP address is part of Malware Patrol infrastructure. Malware Patrol collects malware and threat intelligence. | | Ahrefs | This IP address is part of Ahrefs infrastructure. Ahrefs analyzes website traffic and SEO. | | SOCRadar | This IP address is part of SOCRadar infrastructure. SOCRadar provides extended threat intelligence. | | Babbar | This IP address is part of Babbar infrastructure. Babbar analyzes backlinks for SEO. | | Mojeek | This IP address is part of MojeekBot infrastructure. MojeekBot is the crawler for Mojeek search engine. | | Seznam | This IP address is part of Seznam infrastructure. Seznam is a major Czech search engine. | | OpenIntel.nl | This IP address is part of OpenIntel.nl infrastructure. OpenIntel.nl is an OSINT platform. | | Archive.org | This IP address is part of Archive.org infrastructure. Archive.org is a digital library. | | CyberGreen | This IP address is part of CyberGreen infrastructure. CyberGreen focuses on cybersecurity public health. | | Facebook Crawler | This IP address is part of Facebook Crawler infrastructure. Facebook Crawler indexes web content for Facebook. | | SouGou Crawler | This IP address is part of Sogou Crawler infrastructure. Sogou Crawler is the crawler for chinese search engine Sogou . | | DataForSEO Link Bot | This IP address is part of DataForSEO Link Bot infrastructure. DataForSEO Link Bot is a web crawler for SEO. | | BLEXBOT | This IP address is part of BLEXBot infrastructure. BLEXBot analyzes web content. | | SBA Research Scanner | This IP address is part of SBA Research Scanner infrastructure. SBA Research Scanner conducts network reconnaissance. | | SEMrush Bot | This IP address is part of SemrushBot infrastructure. SemrushBot collects web data for SEO. | | CriminalIP | This IP address is part of CriminalIP infrastructure. CriminalIP provides threat intelligence on Internet-connected assets. | | Asset Reconnaissance Lighthouse | This IP address has been associated with ARL activity. ARL is a tool that maps Internet assets for security. | | AWVS | This IP address is part of AWVS infrastructure. AWVS scans web applications for vulnerabilities. | | Xray | This IP address has been associated with Xray activity. Xray is a security assessment tool. | | Gophish | This IP address has been part of Gophish infrastructure. Gophish is a phishing awareness framework. | | BeEF | This IP address has been associated with BeEF activity. BeEF is a browser exploitation framework. | | Metasploit | This IP address has been associated with Metasploit activity. Metasploit is a penetration testing framework. | | Rengine | This IP address has been associated with Rengine activity. Rengine is a web application reconnaissance framework. | | Dcrat | This IP address has been associated with DCRat activity. DCRat is a remote access Trojan (RAT). | | QakBot | This IP address has been associated with QakBot activity. QakBot is a banking Trojan. | | QuasarRAT | This IP address has been associated with QuasarRAT activity. QuasarRAT is a remote administration tool. | | SuperShell | This IP address has been associated with SuperShell activity. SuperShell is a C2 remote control platform. | | Hak5 | This IP address has been associated with Hak5 Cloud C² activity. Hak5 Cloud C² is a cloud-based management tool. | | Empire | This IP address has been associated with Empire activity. Empire is a post-exploitation framework. | | RedGuard | This IP address has been associated with RedGuard activity. RedGuard is a C2 traffic obfuscation tool. | | Mrrobot | This IP address has been associated with Mrrobot activity. Mrrobot is a phishing tool. | | Unknown | Unknown refers to entities where insufficient characteristics exist to determine a definitive classification. | | Nmap | This IP address has been associated with Nmap activity. Nmap is a network scanner. | | XunfengScan | This IP address has been associated with XunfengScan activity. XunfengScan is a vulnerability scanner. | | GoHTTPServer | This IP address has been associated with GoHTTPServer activity. GoHTTPServer is a lightweight HTTP server. | | Enterprise | This IP address belongs to a private commercial organization. | | Security Vendor | This IP address belongs to a cybersecurity company providing security products or services. | | Medical institution | This IP address belongs to a healthcare organization. | | Financial Institutions | This IP address belongs to a financial service provider. | | Research Institutions | This IP address belongs to a research institution. | | Government | This IP address belongs to a government or public service institution. | | Educational institution | This IP address belongs to an educational institution. | | Others | This IP address belongs to an organization not classified under the main categories. | | Active | This IP address has been highly active recently. | | Nondirected Attack | This IP address has been captured by a honeypot recently. | ## Malwares | **Type** | **Description** | | ----------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | | Fobber | Fobber is a Trojan that steals sensitive information from infected computers. It spreads through malicious downloads, links, and spam attachments. | | SBDHToolkit | The SBDH Espionage Toolkit represents an advanced threat. Some of the techniques applied by the malware bear a resemblance to the techniques used in Operation Buhtrap. The SBDH toolkit focuses on theft of information and credentials from victims. | | Odinaff | Odinaff is a lightweight backdoor Trojan targeting banks and financial institutions since January 2016. It spreads via spear-phishing emails and botnets, executing commands and downloading malicious files. | | Dridex | Dridex is a type of banking malware that uses macros in Microsoft Office to infect systems. Once infected, it can steal banking credentials and other personal information to access financial records. | | Shylock | Shylock is a banking Trojan that is designed to intercept online banking transactions and steal victims' credentials. | | DroidJack | DroidJack is a remote access trojan (RAT) on the Android platform that allows malicious users to gain full control of an infected smartphone. | | Ploutus | Ploutus is an advanced ATM malware first discovered in Mexico in 2013. It allows attackers to empty ATMs using an external keyboard or SMS messages, employing a previously unseen technique. | | Isrstealer | ISR Stealer is used to steal saved cookies and passwords from browsers like IE, Chrome, and Firefox, as well as from messaging applications. | | PcClient | PcClient is a backdoor Trojan horse program with rootkit functionality that allows a remote attacker unauthorized access to the compromised computer. | | Conficker | Conficker is a computer worm targeting Microsoft Windows, first detected in November 2008. It exploits Windows OS flaws and uses dictionary attacks on passwords to spread, forming a botnet and infecting millions globally. | | Dorkbot | Dorkbot is a malware family that steals online credentials from infected systems. It downloads other malware and blocks access to security-related websites. It spreads via social media and infected USB devices. | | Kelihos | Kelihos is a botnet involved in distributing spam emails that may contain links to malware like ransomware. It is a peer-to-peer botnet where infected systems communicate to execute tasks like sending spam and launching DDoS attacks. | | Tinytyphon | Tinytyphon is a family of malware used in Operation Monsoon. | | HydraCrypt | HydraCrypt is a ransomware that encrypts personal documents on a victim's computer using RSA-2048 and AES CBC 256-bit encryption, appending the .hydracrypt\_ID\_\[8 random characters] extension to the files. | | KHRAT | KHRAT is a custom remote access trojan (RAT) discovered by Forcepoint Security Labs. It was used in the DragonOK campaign targeting political parties in Cambodia and other countries like Taiwan, Japan, Tibet, and Russia. | ## Threat Groups | **Type** | **Description** | | ---------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | | UnitedCyberCaliphate | United Cyber Caliphate is a hacktivist group acting as the cyber army for the Islamic State. The group pledged allegiance to the Islamic State and its objectives, emerging in late 2014. | | CopyKittens | CopyKittens is a spy group that has been attacking Israeli targets since at least August 2014, including senior diplomats from the Israeli Ministry of Foreign Affairs and academic researchers in Middle East studies. | | Patchwork | Patchwork, also known as Chinastrats or Drooping Elephant, is an Indian hacker group exposed in July 2016. They conduct network attacks using office vulnerabilities and phishing websites, targeting industries in China and South Asian government departments. | | LulzSec | LulzSec is a black hat hacking group known for high-profile attacks, including the 2011 Sony Pictures breach. | | SyrianElectronicArmy | The Syrian Electronic Army (SEA) is a hacker group that emerged in 2011 to support Syrian President Bashar al-Assad. They use spamming, website defacement, malware, phishing, and DDoS attacks against political opponents, western media, human rights groups, and neutral websites. They have also targeted government websites in the Middle East, Europe, and US defense contractors. | | SixLittleMonkeys | SixLittleMonkeys is a cyber espionage group discovered in July 2016 targeting Russia. They use social engineering, exploits, and custom tools, primarily focusing on military and government sectors. | | Turla | Turla is a Russian APT group linked to the Russian government, active since 2007. Known for attacks on the US Central Command in 2008 and Swiss military contractor RUAG from 2014 to 2016. | | RussianBusinessNetwork | RussianBusinessNetwork The Russian Business Network (RBN) is a notorious cybercrime organization known for identity theft, phishing, cyber attacks, and malware distribution. It is linked to the MPack exploit kit and the Storm botnet. | | VolatileCedar | VolatileCedar is a persistent attacker group possibly originating from Lebanon with political affiliations, known for conducting politically motivated cyber attacks. | | CultoftheDeadCow | Cult of the Dead Cow is a hacker group and DIY media organization founded in 1984 in Lubbock, Texas. They release new media and share member opinions through their weblog titled "Cult of the Dead Cow". | | MuddyWater | MuddyWater is suspected to be a hacking group from Iran, active since September 2017, targeting government, telecom, and energy companies in the Middle East. | | PhineasFisher | PhineasFisher: This tag identifies activity associated with the Phineas Fisher hacking group, known for breaches targeting government contractors like Hacking Team and Gamma Group. | | PassCV | PassCV is a cyber-espionage group that uses stolen Authenticode-signing certificates to avoid detection. They deploy commercial RATs and custom malware like Kitkiot and Sabresac, targeting the US, Taiwan, China, and Russia. | | KONNI | KONNI The Konni organization first became active in 2014 and was exposed by the Cisco security team in 2017. It mainly launched attacks against Korean financial companies. | | FriendlyBird | FriendlyBird is a threat actor group, identified by Kaspersky, targeting Iranian organizations in sectors like media, energy, transportation, and industry with cyberattacks. | ## Threat Campaigns | **Type** | **Description** | | ----------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | | FinSpy\_attack | FinSpy attack indicates activity associated with the FinSpy spyware suite. This powerful tool is known for surveillance and data exfiltration capabilities, often employed by nation-states. | | FreeMilk | FreeMilk is a cyber espionage campaign targeting government and private sector organizations, primarily in East Asia, using spear-phishing emails to deliver malware for data exfiltration. | | Subaat\_Operation | Subaat\_Operation is a small phishing campaign targeting US government agencies, utilizing Crimson Downloader and CVE-2012-0158 vulnerabilities, ultimately delivering malicious software like QuasarRAT. | | BlackWater | BlackWater is an APT attack by the MuddyWater group targeting the Middle East. Attackers use phishing emails with malicious VBA scripts in documents to execute PowerShell scripts and collect victim data. | | XshellGhost | XshellGhost is a backdoor discovered in the Xshell software in 2017. It uses DGA to generate new C\&C domains monthly and communicates via DNS TXT requests to transmit victim information and receive commands. | | EyePyramid | EyePyramid is a cyberattack targeting top Italian government members and institutions using malware named "EyePyramid" to compromise politicians, bankers, freemasons, and law enforcement in Italy. | | Phpstudy | Phpstudy is a 2016 incident where attackers compromised the official Phpstudy website, embedding backdoors in nearly all online versions. They illegally controlled over 670,000 computers and stole over 100,000 sets of data. | | Cmstar\_Campaign | Cmstar\_Campaign refers to an attack on the Belarusian government by the Cmstar Trojan, which acted as a downloader and ultimately delivered the Pylot and Byeby backdoors. | | VBS\_Campaign | VBS\_Campaign is a cyber-espionage operation targeting the Middle East. Attackers use scripting languages (VBScript, PowerShell, VBA) to load and execute scripts from a Command & Control server, demonstrating strong operational security. | | WildPressure | WildPressure is a targeted attack campaign discovered in August 2019 by Kaspersky, using a C++ Trojan named Milum. It primarily targets industrial organizations in the Middle East. | | AttackOnBithumb | AttackOnBithumb Involved attacks on the Korean digital currency industry using CobaltStrike payloads and a white-black backdoor Trojan. Early attacks linked to domestic hackers, suggesting possible ties to local groups. | | XCSSET | XCSSET is malware that inserts malicious code into Xcode projects, performs UXSS backdoor planting in Safari, and leverages two zero-day exploits. | | MysterySnail | MysterySnail In late August and early September 2021, Kaspersky detected attacks exploiting privilege escalation vulnerabilities on multiple Microsoft Windows servers, linked to the IronHusky hacker group. | | OnionPoison | OnionPoison A link to a malicious Tor installer was posted on a popular Chinese-language YouTube channel focused on internet anonymity. The channel has over 180,000 subscribers and the video has over 64,000 views. |