Archivr Maggick
Archivr Maggick
Archivr Maggick
About Me
• Booz Allen Hamilton (2015- Present)
– Cyber4Sight- TechINT Lead
– Malware analysis
– Threat Hunting and Network Forensics
• Georgetown University
– McDonough School of Business (2013)
• Identify Wallet
• Export Data
• Identify Payments
• Cash outs?
https://github.com/kevinperlow/SANS-DFIR-2017
The same person who controls 1FzW likely controls the other two addresses.
• Address:
1SporaxoosUPYPEizY46t
8yquLfzyABRm
Separately, the ransom payments (bottom left) get sent to addresses in batches (bottom right)
Tracking Bitcoin Transactions on the Blockchain | Kevin Perlow
34
Bonus Example- Spora (4)
• Suspected affiliate program based
on its blockchain properties
Source: https://blog.cyber4sight.com/2017/01/blockchain-analysis-suggests-spora-
ransomware-operates-via-affiliate-program/spora/
http://researchcenter.paloaltonetworks.com/2017/01/unit42-2016-updates-shifu-banking-trojan/
New IOCs! What happens if we map out the rest of the Namecoin chain?
• Did my best to zoom in, but clearly graphing this isn’t *quite* enough
• We need to output some data to CSVs
• Timeline
• Infrastructure
Tracking Bitcoin Transactions on the Blockchain | Kevin Perlow
43