Giter VIP home page Giter VIP logo

threat_data's Introduction

Animus Threat Data Repository

Summary

This is a centralized repository for threat data collected by the Animus threat intelligence system. This repository contains reports generated by the Animus system on a daily basis. Additionally, this repository contains a set of master files which include all data collected historically by the honeypot sensors distributed around the Internet.

Currently, Animus threat reports only contain data on SSH threat actors and tactics. Other methods and vulnerabilities are currently being developed.

Stats

The following are some numbers surrounding Animus activity to date. These stats were last updated on September 28, 2015. All activity is fully automated.

  • Attacker IP addresses collected: 27545
  • Total SSH attempts observed: 36660857
  • Unique malware samples captured: 1800
  • Malicious domains identified: 499
  • Unique passwords collected from sensors: 885960
  • Unique usernames collected from sensors: 38507
  • SSH library versions observed from SSH bruteforce tools: 207

Features

Current version: 0.1.1 - Added malware URLs to Animus Threat Report

Attacker IP address threat feed

Animus publishes daily reports containing attacker IP addresses which can be preemptively blocked in your environment

Malware Artifact Reporting

Animus threat reports include a list of all URLs attackers attempted to download malware from.

C2 Mass Scan

Animus mass scans the Internet once per week to locate known-malicious command and control servers which can serve as indicators of compromise (IOCs).

DDOS Target Tracking

Once Animus discovers a C2 server using software it knows how to communicate with, it will connect to the C2 server and begin logging distributed denial-of-service target IP addresses. This allows Animus to track who different adversary groups are targeting with denial-of-service attacks in real time.

Threatbot

Animus collects all data in a centralized repository. This repository can be queried on a per-IP basis via a Twitter bot, @threatbot.

Threatbot will parse one or more IP addresses in a tweet, query the Animus database, and response back with a summarized report of that IP address. This report includes first sighting of attacks from the IP address and most recent attacks from this IP address.

Threatbot will tweet once per day with a link to the daily Animus threat report. This tweet will include the total number of attacks received, as well as the most aggresive attacker IP address of the day.

Threatbot also will tweet once per day with a summary of malware URLs captured

TODO

Animus will be expanding the threat reports to include data on the following threats:

  • Shellshock
  • Heartbleed
  • Wordpress attacks

Version History

Current: 0.1.1

  • 0.1.1 - Added malware URLs to Animus Threat Report
  • 0.1.0 - Initial version, publish reports on SSH attacker IP addresses and surrounding metadata.

Contact

If you have any questions or feedback about the Animus threat intelligence system, don't hesitate to reach out to the main developer via email or Twitter.

License

All rights reserved by Andrew Morris under Creative Commons Non-Commercial 4.0 license, 2014-2015.
Contact me if you'd like to use this data for commercial purposes.

threat_data's People

Contributors

threatbot avatar andrew-morris avatar

Watchers

James Cloos avatar y1r0nz avatar

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    ๐Ÿ–– Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. ๐Ÿ“Š๐Ÿ“ˆ๐ŸŽ‰

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google โค๏ธ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.