Hacker Newsnew | past | comments | ask | show | jobs | submit | Robbedoes's commentslogin

Good suggestion. To be honest, Cgo was the easiest for me to implement, as I originally wrote the tool in a different language. Also, most of the documentation for Netfilter and SO_ORIGINAL_DST is in C.

As for results: I’m seeing about one 'hit' per second on a standard VPS. It's a constant stream of bots looking for exploitable systems and probes from scanners like Shodan and Censys. It’s actually surprising how quickly a new IP gets picked up by these crawlers.


Am a fan of your work! Would it be useful if I throw these domains directly to URLScan? For retrieving the results I'll probably have to setup a proper DB and a workflow around parsing the Twitter content. Now, it's just a simple script.


Sure, I don't see why not, the worst thing that could happen is that the domain doesn't resolve or the webserver doesn't respond, but at least there will be a record of the domain having been scanned! Thanks for the kind words ;)


Thanks!


It appears that some URLs are cut off by Twitter. You might have to add some code to expand those URLs.

For example: https://xunmaus.xn--rvg

In the meantime, I'm using a modified command like so: `curl https://twitter.threatintel.rocks/ --silent | jq -r '.malicious_urls | .[]' | sort -u | grep -v …`


It seems this is only the case if it's a tweet that contains a retweet. These are now removed from the stream as they're not of relevance.


Interesting! Will have a look on what they can freely offer.


Plan in the future is to visit the links, download malware and upload it to VirusTotal, Malwarebazaar, etc.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: