Hunting adversary infrastructure with issued.live and WorldIP.io
Software & Apps

Hunting adversary infrastructure with issued.live and WorldIP.io

| | 4 min read
Share: Twitter Facebook LinkedIn

Hunting adversary infrastructure starts from one indicator, usually an IP address, and works outward to the operator's other servers and domains. Two Tuxxin tools cover that work. WorldIP.io enriches the address: who holds it, how it is routed and what kind of traffic leaves it. issued.live pivots from it: every hostname seen answering there and the certificates behind them. Until WorldIP.io's paid plans launch, every issued.live Plus or Pro subscription includes a free beta key to the WorldIP.io premium API.

The offer

  • issued.live Plus ($99 a month) includes a WorldIP.io Pro key: 200,000 enriched lookups a month with VPN, proxy, Tor and datacenter classification, a trust score and blocklist hits.
  • issued.live Pro ($199 a month) includes a WorldIP.io Business key: 1,000,000 enriched lookups a month, adding live BGP prefixes and MOAS conflicts, BGP anomaly events and Web3 node roles.
  • The key is emailed within one business day to the address on the issued.live subscription. It works through the WorldIP.io beta and for 30 days after the paid plans launch, which is planned within the next 30 days.

IOC enrichment: what the address is

An IP address from an alert carries little on its own. A WorldIP.io lookup enriches it with the organization, ASN and ASN type, regional registry ownership, city-level geolocation where it exists, the network's access type, blocklist hits, a trust score from 0 to 100 and a proxy verdict. The Business key adds routing context: whether the prefix has a multiple-origin conflict and whether it appeared in a recent BGP anomaly.

Pivoting threat intelligence: what has run at the address

issued.live turns the address into infrastructure. Its reverse IP lookup returns every hostname its resolvers have recorded answering there, with first-seen and last-seen times, and a range lookup does the same for up to 256 addresses at once. Certificate pivots return the other names on each certificate. SPKI pivots return every certificate issued for the same key pair, which reaches servers on other addresses.

A worked hunt from one IP address

Most hunts start from a firewall hit, an EDR callback or a sender address in a phishing email header. From there:

  1. Enrich the address. The WorldIP.io profile says whether it sits on a hosting provider's range, on a home ISP or behind a proxy, and whether its route is under dispute. That decides how much weight the rest of the hunt carries.
  2. List what runs there. An issued.live reverse IP lookup returns the hostnames with their first-seen dates. A burst of new names inside a few days is the usual sign of a fresh campaign, and one lookup mapped 532 hostnames this way.
  3. Pivot on certificates and keys. The certificates behind those names lead to other names and, through shared public keys, to other addresses. Each new address goes back to step one.
  4. Search the naming grammar. On Pro, pattern search matches the shape of the names, such as a short word followed by agent in .com, against every registrable domain in the corpus.

issued.live's guide to find domains in an IP range covers the range endpoint and the certificate pivots in detail.

Bug bounty reconnaissance

Certificate Transparency and reverse IP data map a target's hostnames without sending a packet to it. issued.live lists the names on the target's certificates and the hostnames that share its addresses. WorldIP.io's organization and ASN fields then show which of those addresses sit on the target's own network and which belong to a CDN or a cloud provider, which decides where the in-scope servers are.

Fraud and sign-up screening

The same WorldIP.io classification can gate a form. One lookup per sign-up returns is_proxy, is_vpn, is_tor, is_datacenter and a verdict, so a form can deny detected proxies, send datacenter traffic to review or log the verdict next to each account. WorldIP.io's guide explains how to detect residential proxies and mobile proxies with those fields.

Free threat intel API tiers

Both tools also answer without a key. WorldIP.io's keyless API returns the owner, ASN, country, reverse DNS and CIDR block for any address, plus the number of domains hosted on an IPv4 address, up to 1,000 lookups a day:

curl worldip.io/8.8.8.8

issued.live's free public record covers any domain's certificate, issuer, expiry, hosting address and current DNS, plus its registration dates and registrar, also at 1,000 requests a day per client address. The paid tiers and the beta key add the pivots and the enriched profile.

Terms

  • The offer covers issued.live Plus and Pro. issued.live Basic is not included.
  • The WorldIP.io key stays active while the issued.live subscription does.
  • The beta carries the monthly quotas above and has no uptime guarantee.
  • The WorldIP.io limits may change during the beta; key holders are emailed before any change.

Plans are on the issued.live pricing page.

Share: 𝕏 Twitter Facebook LinkedIn