r/computerforensics 7d ago

Looking for Malware Logs in relation to POS devices

I am currently busy doing a course for my university, and have a project to analyse and correlate different log sources with indicators of compromise specific to point-of-sale (pos) devices. I managed to find a 24 hour pcap of the backoff malware (c2 beconing), but overall I am struggling to find any datasets of an attack specific to pos devices. I am mostly looking at research papers, but perhaps I need to reach out to some of the researchers, as I can't find actual datasets.

Is there anyone that knows where I could find datasets to do a proper writeup? It can be of any pos malware, but we require 3 different log sources (e.g. firewall logs, authentication logs, system logs). I can also generate my own logs, but my professor advised against this unless I really can't manage to find any meaningful data online, as I'd essentially be engineering my own scenario instead of doing analysis.

Please advise. Any help is welcome.

8 Upvotes

9 comments sorted by

6

u/Quality_Qontrol 7d ago

Here’s a database of forensic images for testing…https://4n6img.com

2

u/illyterate 7d ago

There are places, but I’m afraid what u looking for doesn’t come cheap lol

2

u/illyterate 7d ago

This might not be the right platform to look for that 😂

2

u/AddendumWorking9756 5d ago

You will not find one, and that is not on you. POS breach artifacts go into PFI reports under NDA and basically never reach a public corpus, which is why you keep hitting papers instead of data. Take the Backoff IOCs you already have and map them onto a generic multi source incident dataset, then argue the POS relevance from the malware behaviour rather than the host. Same correlation exercise, and it defends fine in a writeup.

2

u/carmelburro 5d ago

I'm not gonna dump my full background but I've worked lots of POS investigations throughout my career. Typically threat actors get in via some vulnerable or poorly configured remote admin service, access the back-of-house (BOH) server, and then might access the POS terminals. Skimmers back in the day would save card dumps locally or aggregate them at the BOH server prior to exfiltration. Often times tho the malware would just sit on the BOH server since traffic typically passes through that system when card data goes out for authorization. Data could be stored locally or exfiltrated in real-time. I'd recommend reading up on groups like FIN7 or even the Target breach since there's a lot of publicly available info for those topics.

1

u/krizd 7d ago

I’m unclear on how specific your task is. Does it also encompass skimmers / IOT devices physically deployed? If so, I think it was one of the Magnet CTFs a few years ago that had a skimmer scenario that provided images of several devices involved. I think it was maybe the device or a RPI located nearby, a computer from a search warrant etc. so not looking at malware but evidence of the deployment, info it stole etc, who was involved kinda thing. I don’t have a link handy at the moment sorry.

1

u/No_Pin7764 1d ago

It is extremely broad, so as long as it's related to POS devices being compromised I can use that, thank you for this I will see if I can't find the Magnet CTFs

1

u/Budget_Artichoke_548 3d ago

Easy answer is it’s embedded c2 as a lot of the tech is made in China or whatever saying this because I’ve seen this is it the guaranteed answer far from it but it’s an easy answer lol