Gravity Falls
收藏资源简介:
Gravity Falls是由达科他州立大学团队构建的半合成DGA检测数据集,涵盖2022至2025年通过短信钓鱼(smishing)传播的恶意域名。该数据集包含4个技术集群共4万条数据,记录威胁行为者从随机字符串到词典拼接及主题组合抢注的技术演进。数据源自真实短信链接、开源情报及基础设施分析,采用混合方法(直接观测与正则预测)构建,主要用于评估传统启发式与机器学习模型在移动端钓鱼域名检测中的泛化能力,为对抗快速迭代的DGA战术提供基准。
Gravity Falls is a semi-synthetic Domain Generation Algorithm (DGA) detection dataset developed by the team at Dakota State University, covering malicious domains propagated via smishing between 2022 and 2025. The dataset includes 40,000 records across 4 technical clusters, documenting the technological evolution of threat actors' domain squatting tactics ranging from random string generation, dictionary concatenation to theme-based combination. Sourced from real SMS links, open-source intelligence (OSINT) and infrastructure analysis, the dataset is constructed using a hybrid approach (direct observation and regularized prediction). It is primarily designed to evaluate the generalization capabilities of traditional heuristic and machine learning models for mobile phishing domain detection, serving as a benchmark to counter fast-evolving DGA tactics.
Gravity Falls 数据集概述
数据集基本信息
- 数据集名称: Gravity Falls
- DOI: 10.5281/zenodo.17624554
- 数据来源: 通过 LevelBlue (AlienVault) OTX 枢轴分析获取的 FQDN,由 "MalwareMorghulis" 整理。
- 数据描述: 这是一个 DNS 黑洞列表,数据通过自动和手动枢轴分析整理,旨在发现可疑或潜在恶意的网络基础设施。列表中的活动集群命名基于观察到的战术、技术和程序(TTP),用于活动跟踪,与 CrowdStrike、Mandiant、Palo Alto 等公司无关。
- 关联威胁组织: 根据开源报告,这些域名生成算法(DGA)活动集群很可能与“Smishing Triad”(一个据信位于中国的网络犯罪组织)有关。
研究区块列表详情
DGA 追踪器 - 归因于 Smishing Triad
- Cats Cradle: 使用随机字符(约5-9个字符)的短信鱼叉式网络钓鱼。
- Double Helix: 使用双词拼接(偶数单词被截断)的短信鱼叉式网络钓鱼。
- Easy Rider: 使用随机字符拼接的、以收费或 EZ-Pass 为主题的短信鱼叉式网络钓鱼。
- Pandoras Box: 以美国邮政服务(USPS)为主题的短信鱼叉式网络钓鱼域名(通常是包裹跟踪或错别字抢注服务,如 Informed Delivery)。
诈骗追踪器 - 尚无定论
- Empty Promise: 来自电子邮件的虚假招聘人员垃圾信息,要求用户通过 Telegram、WhatsApp 等第三方通讯工具联系。
- Purple Rain: Indigo 营销和虚假账户通知,包括别名 Henry Fields 或 Daryl Huff。
文件与说明
- appendix.txt: 包含复制此实验所需的命令行步骤(因原始工具源页面存在文档问题)。
- 复制与结果: 有关输出表格或测试工具复制步骤,请参阅页面内指定位置。
使用与致谢
- 引用要求: 使用时请引用 Adam Dorian Wong 或 @MalwareMorghulis 以及 Dr. John Hastings。
- 特别感谢: DomainTools、ExtraHop、John Conwell、Dr. John Hastings。
- 荣誉提及: Sublime Security、Epeios、Daniel P at Malpedia、Paul B at MalBeacon、Hunt.io。
免责声明与警告
- “按原样”提供: 列表“按原样”提供,可能会破坏基础设施,因为某些名称服务器可能在此列表中。请自行分叉、修剪或承担使用风险。
- TLD 列表警告: 请根据需要并在您自己的仓库中修改这些顶级域(TLD)阻止列表。您必须将 PiHole 指向您自己的仓库以获取任何自定义 TLD 阻止列表,因为这些 TLD 列表几乎会阻止所有内容(甚至 *.com 等)。
- 效率说明: 存在更高效的方法(例如:地理位置列表)或优化条目来将 TLD 添加到黑洞中,例如使用管道 | 字符进行单行分组。
参考文献
- https://www.silentpush.com/blog/smishing-triad/
- https://krebsonsecurity.com/2025/04/china-based-sms-phishing-triad-pivots-to-banks/
- https://malpedia.caad.fkie.fraunhofer.de/actor/smishing_triad
- https://www.wired.com/story/smishing-triad-scam-group/
- https://www.resecurity.com/blog/article/smishing-triad-is-now-targeting-toll-payment-services-in-a-massive-fraud-campaign-expansion




