Analysis of Malicious Website and Actors Objective: Full Recon on Website hosted on GitHub Initial Recon Domain: bullibai.github.io Platform: GitHub IO Domain for GitHub Page DNS: hosted over github.io Sitemap: (total 9 files in static website hosted on GitHub page platform) Timeline: From Dec 11 2021 to Jan 01 2022 * (based on assessed archive page web crawler) URL MIME TYPE FROM TO CAPTURES DUPLICATES UNIQUE’S http://bullibai.github.io/ text/html Dec 31, 2021 Jan 1, 2022 5 2 3 http://bullibai.github.io/favicon.ico text/html Dec 31, 2021 Dec 31, 2021 1 0 1 http://bullibai.github.io/robots.txt text/html Dec 31, 2021 Jan 1, 2022 2 0 2 https://bullibai.github.io/db.js application/javascript Jan 1, 2022 Jan 1, 2022 1 0 1 https://bullibai.github.io/img/btn.png image/png Jan 1, 2022 Jan 1, 2022 1 0 1 https://bullibai.github.io/img/button_get-me-a-bulli.png image/png Jan 1, 2022 Jan 1, 2022 1 0 1 https://bullibai.github.io/img/logo.png image/png Jan 1, 2022 Jan 1, 2022 1 0 1 https://bullibai.github.io/img/main.jpg image/jpeg Jan 1, 2022 Jan 1, 2022 1 0 1 https://bullibai.github.io/upload.html text/html Dec 11, 2021 Dec 11, 2021 1 0 1 (Reference: http://web.archive.org/web/*/http://bullibai.github.io//*) Website Analysis The website hosted at GitHub page which provide static webpage application based on JavaScript(html, css, js and images). The initial website behaviour analysis based on review of source code(static) here the step follows; ● http://bullibai.github.io/ ○ File used as the main page with include static webpage using standard html, js code. ● http://bullibai.github.io/favicon.ico ○ File used for identified basic web application identity and other elements in websites, it was seen first on December 11, 2021 and last January 01, 2022 ● http://bullibai.github.io/robots.txt ○ File used for adding config for web crawler to give basic identity for scanning the websites, it was seen first on December 31, 2021 and last January 01, 2022 ● https://bullibai.github.io/db.js ○ File used for main database stored as JS script for Twitter username with images in website, It was seen first and last January 01, 2022. ● https://bullibai.github.io/img/btn.png ○ File used as static image button which used to click and perform task as share on Twitter. It was seen first and last at January 01, 2022. But created on 14 December 2021 based on forensic analysis. ● https://bullibai.github.io/img/button_get-me-a-bulli.png ○ File used as static image button which used to click and perform task. It was seen first and last at January 01, 2022. ● https://bullibai.github.io/img/logo.png ○ File used as static image for logo, and it was seen first and last at January 01, 2022. ● https://bullibai.github.io/img/main.jpg ○ File used as static image in main(home) page. It was seen first and last at January 01, 2022. ● https://bullibai.github.io/upload.html ○ File used as web page for uploading images via local system and choice of username, after the submit button it creates static page with displaying banner logo-header, pre-added text message "Your Bulli Bai of the Day is" , uploaded image as static crafted photo, and @username, and Footer "MADE ON {$WEBSITE}". It was seen first at December 11, 2021 and last was also same day. Forensic Analysis A) Forensic analysis of source code The Forensic analysis of website, source code and images was concluded as it seems the main logic of page was obfuscated code online using snap builder service provider and identified by code line // == Begin Free HTML Source Code Obfuscation Protection from https://snapbuilder.com == // in main page. The source code written by some premature coder(might not even coder) who has access to internet and some pre-defined dilemma of motive which conclude on website. The obfuscated JS code snippet is simple code which had; ● Main page ○ Cloudflare CDN for fonts ○ googleapis for style fonts ○ JavaScript logic for random Twitter username from database with images and pre-crefted poor design of page which renders as pre-defined headers, Twitter user ID, image and footer. The logic is as simple as get by creating design of images using Twitter username and share over twitter, and rendering images as logo, main image and get me a bulli image. The only sense make after looking into script of logic which used to generate or select images with username of Twitter username which it seems stored on db.js and uploaded as static database on December 11, 2021 when it started working on it the website, or it might be as early on those timelines. ● upload.html ○ logic seems four main function which used for uploading images with username and also creating canvas from it. ○ downloadBase64File for downloading files as base64 encoded images designed canvas design ○ handleFileSelect for handling files type and loading into further process ○ resizeCanvas for final creating and crafting-design of images-photo canvas which load images, with header(logo), footer(made with {} text) and main centre image with above text ""Your Bulli Bai of the Day is" and below username. ○ generateCanvas for creating default canvas ● db.js ○ JS script with main logic which stored all username and generator of how to render all them in main page using random logic on function ○ Logic of db.js seems someone who has understanding of how the JavaScript works which indicated there might be more than one coder or people behind the website development ○ The username is around 100 from twitter, which indicated they have planned the craft before development. So the main character might be the behind the idea of this website. The main JS inbuilt logic which select random Twitter profile and images and renders to page as Header, Pre-crafed main image with pre-added text message line "Your Bulli Bai of the Day is {twitter_user_id}", Image and Footer. As the logic seems premature code and designed for in spare time. B) Forensic analysis on Images ● logo.png written in Hewlett-Packard system with Microsoft Corporation(Windows OS) machine with Adobe Photoshop CC Software. Same conclusion come from btn.png which indicated created image on 14 December 2021. ● main.jpg was repeated used and modified based on decode images pixel. It indicated that the image is being used repeated and copied from somewhere else, and then modified as needed. ● button_get-me-a-bulli.png is static images created and modified using online images creator platform. The images also are tiles which based on word of images and from those word images, the final image is being created online. Conclusion The project so called "bullibai" behind are more than one person which has knowledge of coding (premature) as someone who has idea about JavaScript programming language and obfuscated code for showing they are tech-savvy, but early indication seen in analysis that this actor(so called cyber criminal) are just premature/kids who have access to resources like internet, computer, and evil ideological dilemma of anti-religion, anti-social phycological environment where they cultivated the idea about doing this kind of task.