Category: Malware-Traffic-Analysis.net – Blog Entries

2025-07-23: Ten days of scans and probes and web traffic hitting my web server

This post doesn’t have text content, please click on the link below to view the original article. This article has been indexed from Malware-Traffic-Analysis.net – Blog Entries Read the original article: 2025-07-23: Ten days of scans and probes and web…

2025-07-15: Lumma Stealer infection with SecTop RAT

This post doesn’t have text content, please click on the link below to view the original article. This article has been indexed from Malware-Traffic-Analysis.net – Blog Entries Read the original article: 2025-07-15: Lumma Stealer infection with SecTop RAT

2025-07-02: Lumma Stealer infection with follow-up Rsockstun malware

This post doesn’t have text content, please click on the link below to view the original article. This article has been indexed from Malware-Traffic-Analysis.net – Blog Entries Read the original article: 2025-07-02: Lumma Stealer infection with follow-up Rsockstun malware

2025-06-26: Lumma Stealer infection with follow-up malware

This post doesn’t have text content, please click on the link below to view the original article. This article has been indexed from Malware-Traffic-Analysis.net – Blog Entries Read the original article: 2025-06-26: Lumma Stealer infection with follow-up malware

2025-06-20: Malware disguised as cracked version of popular software

This post doesn’t have text content, please click on the link below to view the original article. This article has been indexed from Malware-Traffic-Analysis.net – Blog Entries Read the original article: 2025-06-20: Malware disguised as cracked version of popular software

2025-06-18: SmartApeSG to ClickFix lure to NetSupport RAT to StealC v2

This post doesn’t have text content, please click on the link below to view the original article. This article has been indexed from Malware-Traffic-Analysis.net – Blog Entries Read the original article: 2025-06-18: SmartApeSG to ClickFix lure to NetSupport RAT to…

2025-06-13: Traffic analysis exercise: It’s a trap!

This post doesn’t have text content, please click on the link below to view the original article. This article has been indexed from Malware-Traffic-Analysis.net – Blog Entries Read the original article: 2025-06-13: Traffic analysis exercise: It’s a trap!

2025-06-10: Ten days of scans and probes and web traffic hitting my web server

This post doesn’t have text content, please click on the link below to view the original article. This article has been indexed from Malware-Traffic-Analysis.net – Blog Entries Read the original article: 2025-06-10: Ten days of scans and probes and web…

2025-05-31: Ten days of scans and probes and web traffic hitting my web server

This post doesn’t have text content, please click on the link below to view the original article. This article has been indexed from Malware-Traffic-Analysis.net – Blog Entries Read the original article: 2025-05-31: Ten days of scans and probes and web…

2025-05-27: VIP Recovery infection from email attachment

This post doesn’t have text content, please click on the link below to view the original article. This article has been indexed from Malware-Traffic-Analysis.net – Blog Entries Read the original article: 2025-05-27: VIP Recovery infection from email attachment

2025-04-13: Twelve days of scans and probes and web traffic hitting my web server

This post doesn’t have text content, please click on the link below to view the original article. This article has been indexed from Malware-Traffic-Analysis.net – Blog Entries Read the original article: 2025-04-13: Twelve days of scans and probes and web…

2025-03-26: SmartApeSG traffic for fake browser update leads to NetSupport RAT and StealC

This post doesn’t have text content, please click on the link below to view the original article. This article has been indexed from Malware-Traffic-Analysis.net – Blog Entries Read the original article: 2025-03-26: SmartApeSG traffic for fake browser update leads to…

2025-03-03: Three days of scans and probes and web traffic hitting my web server

This post doesn’t have text content, please click on the link below to view the original article. This article has been indexed from Malware-Traffic-Analysis.net – Blog Entries Read the original article: 2025-03-03: Three days of scans and probes and web…

2025-03-03: Three days of scans and probes and web traffic hitting my web server

This post doesn’t have text content, please click on the link below to view the original article. This article has been indexed from Malware-Traffic-Analysis.net – Blog Entries Read the original article: 2025-03-03: Three days of scans and probes and web…

2025-02-18: SmartApeSG script for fake browser update leads to NetSupport RAT and StealC

This post doesn’t have text content, please click on the link below to view the original article. This article has been indexed from Malware-Traffic-Analysis.net – Blog Entries Read the original article: 2025-02-18: SmartApeSG script for fake browser update leads to…

2025-02-13: Quick post: ClickFix style infection for Lumma Stealer

This post doesn’t have text content, please click on the link below to view the original article. This article has been indexed from Malware-Traffic-Analysis.net – Blog Entries Read the original article: 2025-02-13: Quick post: ClickFix style infection for Lumma Stealer

2025-02-07: Three days of scans and probes and web traffic hitting my web server

This post doesn’t have text content, please click on the link below to view the original article. This article has been indexed from Malware-Traffic-Analysis.net – Blog Entries Read the original article: 2025-02-07: Three days of scans and probes and web…

2025-01-31: Two pcaps of AgentTesla-style data exfil, one using FTP and one using SMTP

This post doesn’t have text content, please click on the link below to view the original article. This article has been indexed from Malware-Traffic-Analysis.net – Blog Entries Read the original article: 2025-01-31: Two pcaps of AgentTesla-style data exfil, one using…

2025-01-28: Malware infection from web inject activity

This post doesn’t have text content, please click on the link below to view the original article. This article has been indexed from Malware-Traffic-Analysis.net – Blog Entries Read the original article: 2025-01-28: Malware infection from web inject activity

2025-01-28: Malwre infection from web inject activity

This post doesn’t have text content, please click on the link below to view the original article. This article has been indexed from Malware-Traffic-Analysis.net – Blog Entries Read the original article: 2025-01-28: Malwre infection from web inject activity

2025-01-23: Fake installer leads to Koi Loader/Koi Stealer

This post doesn’t have text content, please click on the link below to view the original article. This article has been indexed from Malware-Traffic-Analysis.net – Blog Entries Read the original article: 2025-01-23: Fake installer leads to Koi Loader/Koi Stealer

2025-01-22: Traffic Analysis Exercise – Download from fake software site

This post doesn’t have text content, please click on the link below to view the original article. This article has been indexed from Malware-Traffic-Analysis.net – Blog Entries Read the original article: 2025-01-22: Traffic Analysis Exercise – Download from fake software…

2025-01-21: Quick post for Koi Loader/Koi Stealer activity

This post doesn’t have text content, please click on the link below to view the original article. This article has been indexed from Malware-Traffic-Analysis.net – Blog Entries Read the original article: 2025-01-21: Quick post for Koi Loader/Koi Stealer activity

2025-01-09: CVE-2017-0199 XLS –> HTA –> VBS –> steganography –> DBatLoader/GuiLoader style malware

This post doesn’t have text content, please click on the link below to view the original article. This article has been indexed from Malware-Traffic-Analysis.net – Blog Entries Read the original article: 2025-01-09: CVE-2017-0199 XLS –> HTA –> VBS –> steganography…

2025-01-04: Four days of scans and probes and web traffic hitting my web server

This post doesn’t have text content, please click on the link below to view the original article. This article has been indexed from Malware-Traffic-Analysis.net – Blog Entries Read the original article: 2025-01-04: Four days of scans and probes and web…

2024-12-18 – One week of server scans and probes and web traffic

This post doesn’t have text content, please click on the link below to view the original article. This article has been indexed from Malware-Traffic-Analysis.net – Blog Entries Read the original article: 2024-12-18 – One week of server scans and probes…

2024-12-17 – SmartApeSG injected script leads to NetSupport RAT

This post doesn’t have text content, please click on the link below to view the original article. This article has been indexed from Malware-Traffic-Analysis.net – Blog Entries Read the original article: 2024-12-17 – SmartApeSG injected script leads to NetSupport RAT

2024-11-26 – Traffic Analysis Exercise: Nemotodes

This post doesn’t have text content, please click on the link below to view the original article. This article has been indexed from Malware-Traffic-Analysis.net – Blog Entries Read the original article: 2024-11-26 – Traffic Analysis Exercise: Nemotodes

2024-11-24 – Redline bash script for Linux malware

This post doesn’t have text content, please click on the link below to view the original article. This article has been indexed from Malware-Traffic-Analysis.net – Blog Entries Read the original article: 2024-11-24 – Redline bash script for Linux malware

2024-11-14 – Raspberry Robin infection using WebDAV server

This post doesn’t have text content, please click on the link below to view the original article. This article has been indexed from Malware-Traffic-Analysis.net – Blog Entries Read the original article: 2024-11-14 – Raspberry Robin infection using WebDAV server

2024-10-17 – Two days of server scans and probes and web traffic

This post doesn’t have text content, please click on the link below to view the original article. This article has been indexed from Malware-Traffic-Analysis.net – Blog Entries Read the original article: 2024-10-17 – Two days of server scans and probes…

2024-10-07 – Data dump (Formbook, possible Astaroth/Guildma, Redline Stealer, unidentified malware)

This post doesn’t have text content, please click on the link below to view the original article. This article has been indexed from Malware-Traffic-Analysis.net – Blog Entries Read the original article: 2024-10-07 – Data dump (Formbook, possible Astaroth/Guildma, Redline Stealer,…

2024-10-01 – Ukrainian language malspam pushes RMS-based malware

This post doesn’t have text content, please click on the link below to view the original article. This article has been indexed from Malware-Traffic-Analysis.net – Blog Entries Read the original article: 2024-10-01 – Ukrainian language malspam pushes RMS-based malware

2024-09-16 – Snake KeyLogger (VIP Recovery) infection, SMTP exfil

This post doesn’t have text content, please click on the link below to view the original article. This article has been indexed from Malware-Traffic-Analysis.net – Blog Entries Read the original article: 2024-09-16 – Snake KeyLogger (VIP Recovery) infection, SMTP exfil

2024-09-17 – Snake KeyLogger (VIP Recovery) infection, FTP exfil

This post doesn’t have text content, please click on the link below to view the original article. This article has been indexed from Malware-Traffic-Analysis.net – Blog Entries Read the original article: 2024-09-17 – Snake KeyLogger (VIP Recovery) infection, FTP exfil

2024-09-12 – Approximately 11 days of server scans and probes

This post doesn’t have text content, please click on the link below to view the original article. This article has been indexed from Malware-Traffic-Analysis.net – Blog Entries Read the original article: 2024-09-12 – Approximately 11 days of server scans and…

2024-09-11 – Data dump: Remcos RAT and XLoader (Formbook)

This post doesn’t have text content, please click on the link below to view the original article. This article has been indexed from Malware-Traffic-Analysis.net – Blog Entries Read the original article: 2024-09-11 – Data dump: Remcos RAT and XLoader (Formbook)

2024-09-04 – Traffic Analysis Exercise: Big Fish in a Little Pond

This post doesn’t have text content, please click on the link below to view the original article. This article has been indexed from Malware-Traffic-Analysis.net – Blog Entries Read the original article: 2024-09-04 – Traffic Analysis Exercise: Big Fish in a…

2024-08-30 – Approximately 11 days of server scans and probes

This post doesn’t have text content, please click on the link below to view the original article. This article has been indexed from Malware-Traffic-Analysis.net – Blog Entries Read the original article: 2024-08-30 – Approximately 11 days of server scans and…

2024-08-29 – Phishing email and traffic to fake webmail login page

This post doesn’t have text content, please click on the link below to view the original article. This article has been indexed from Malware-Traffic-Analysis.net – Blog Entries Read the original article: 2024-08-29 – Phishing email and traffic to fake webmail…

2024-08-15 – Traffic analysis exercise: WarmCookie

This post doesn’t have text content, please click on the link below to view the original article. This article has been indexed from Malware-Traffic-Analysis.net – Blog Entries Read the original article: 2024-08-15 – Traffic analysis exercise: WarmCookie

2024-07-30 – Traffic analysis exercise: You dirty rat!

This post doesn’t have text content, please click on the link below to view the original article. This article has been indexed from Malware-Traffic-Analysis.net – Blog Entries Read the original article: 2024-07-30 – Traffic analysis exercise: You dirty rat!

2024-06-25 – Latrodectus infection with BackConnect and Keyhole VNC

This post doesn’t have text content, please click on the link below to view the original article. This article has been indexed from Malware-Traffic-Analysis.net – Blog Entries Read the original article: 2024-06-25 – Latrodectus infection with BackConnect and Keyhole VNC

2024-06-24 – ClickFix popup leads to Lumma Stealer

This post doesn’t have text content, please click on the link below to view the original article. This article has been indexed from Malware-Traffic-Analysis.net – Blog Entries Read the original article: 2024-06-24 – ClickFix popup leads to Lumma Stealer

2024-06-17 – Google ad –> fake unclaimed funds site –> Matanbuchus with Danabot

This post doesn’t have text content, please click on the link below to view the original article. This article has been indexed from Malware-Traffic-Analysis.net – Blog Entries Read the original article: 2024-06-17 – Google ad –> fake unclaimed funds site…

2024-06-12 – Google ad –> fake unclaimed funds site –> Matanbuchus with Danabot

This post doesn’t have text content, please click on the link below to view the original article. This article has been indexed from Malware-Traffic-Analysis.net – Blog Entries Read the original article: 2024-06-12 – Google ad –> fake unclaimed funds site…

2024-06-11 – Traffic example of a CVE-2024-4577 probe

This post doesn’t have text content, please click on the link below to view the original article. This article has been indexed from Malware-Traffic-Analysis.net – Blog Entries Read the original article: 2024-06-11 – Traffic example of a CVE-2024-4577 probe

2024-06-10 – Malspam pushing OriginLogger (AgentTesla)

This post doesn’t have text content, please click on the link below to view the original article. This article has been indexed from Malware-Traffic-Analysis.net – Blog Entries Read the original article: 2024-06-10 – Malspam pushing OriginLogger (AgentTesla)

2024-04-18: Word macro –> SSLoad –> Cobalt Strike

This post doesn’t have text content, please click on the link below to view the original article. This article has been indexed from Malware-Traffic-Analysis.net – Blog Entries Read the original article: 2024-04-18: Word macro –> SSLoad –> Cobalt Strike

2024-04-15: Contact Forms campaign leads to SSLoad malware

This post doesn’t have text content, please click on the link below to view the original article. This article has been indexed from Malware-Traffic-Analysis.net – Blog Entries Read the original article: 2024-04-15: Contact Forms campaign leads to SSLoad malware

2024-04-09: Data dump from Latrodectus malware infection

This post doesn’t have text content, please click on the link below to view the original article. This article has been indexed from Malware-Traffic-Analysis.net – Blog Entries Read the original article: 2024-04-09: Data dump from Latrodectus malware infection

2024-04-05: Data dump from Astaroth (Guildma) malware infection

This post doesn’t have text content, please click on the link below to view the original article. This article has been indexed from Malware-Traffic-Analysis.net – Blog Entries Read the original article: 2024-04-05: Data dump from Astaroth (Guildma) malware infection

2024-03-26: Google ad leads to Matanbuchus infection with Danabot

This post doesn’t have text content, please click on the link below to view the original article. This article has been indexed from Malware-Traffic-Analysis.net – Blog Entries Read the original article: 2024-03-26: Google ad leads to Matanbuchus infection with Danabot

2024-02-09, 02-22 and 02-23 – Data dump: Latrodectus from Contact Forms campaign

This post doesn’t have text content, please click on the link below to view the original article. This article has been indexed from Malware-Traffic-Analysis.net – Blog Entries Read the original article: 2024-02-09, 02-22 and 02-23 – Data dump: Latrodectus from…

2024-02-21 – Parrot TDS –> SogGholish –> Aysnc RAT

This post doesn’t have text content, please click on the link below to view the original article. This article has been indexed from Malware-Traffic-Analysis.net – Blog Entries Read the original article: 2024-02-21 – Parrot TDS –> SogGholish –> Aysnc RAT

2024-02-14 – Danabot infection from Italian malspam

This post doesn’t have text content, please click on the link below to view the original article. This article has been indexed from Malware-Traffic-Analysis.net – Blog Entries Read the original article: 2024-02-14 – Danabot infection from Italian malspam

2023-11-29 – email –> JinxLoader –> Formbook/XLoader

This post doesn’t have text content, please click on the link below to view the original article. This article has been indexed from Malware-Traffic-Analysis.net – Blog Entries Read the original article: 2023-11-29 – email –> JinxLoader –> Formbook/XLoader

2023-11-27 – TA577 pushes IcedID (Bokbot) variant

This post doesn’t have text content, please click on the link below to view the original article. This article has been indexed from Malware-Traffic-Analysis.net – Blog Entries Read the original article: 2023-11-27 – TA577 pushes IcedID (Bokbot) variant

2023-11-22 – AgentTesla infection with FTP data exfil

This post doesn’t have text content, please click on the link below to view the original article. This article has been indexed from Malware-Traffic-Analysis.net – Blog Entries Read the original article: 2023-11-22 – AgentTesla infection with FTP data exfil

2023-10-23 – 404 TDS URL chain leads to Async RAT variant

This post doesn’t have text content, please click on the link below to view the original article. This article has been indexed from Malware-Traffic-Analysis.net – Blog Entries Read the original article: 2023-10-23 – 404 TDS URL chain leads to Async…

2023-10-17 – TA577 Pikabot infection with Cobalt Strike

This post doesn’t have text content, please click on the link below to view the original article. This article has been indexed from Malware-Traffic-Analysis.net – Blog Entries Read the original article: 2023-10-17 – TA577 Pikabot infection with Cobalt Strike

2023-10-03 – Pikabot infection with Cobalt Strike

This post doesn’t have text content, please click on the link below to view the original article. This article has been indexed from Malware-Traffic-Analysis.net – Blog Entries Read the original article: 2023-10-03 – Pikabot infection with Cobalt Strike

2023-09-28 – IcedID (Bokbot) infection with Keyhole VNC and Cobalt Strike

This post doesn’t have text content, please click on the link below to view the original article. This article has been indexed from Malware-Traffic-Analysis.net – Blog Entries Read the original article: 2023-09-28 – IcedID (Bokbot) infection with Keyhole VNC and…

2023-09-21 thru 09-25 – malspam examples pushing AgentTesla

This post doesn’t have text content, please click on the link below to view the original article. This article has been indexed from Malware-Traffic-Analysis.net – Blog Entries Read the original article: 2023-09-21 thru 09-25 – malspam examples pushing AgentTesla

2023-08-03 – .msix file –> IcedID (Bokbot) –> BackConnect and Keyhole VNC

This post doesn’t have text content, please click on the link below to view the original article. This article has been indexed from Malware-Traffic-Analysis.net – Blog Entries Read the original article: 2023-08-03 – .msix file –> IcedID (Bokbot) –> BackConnect…

2023-08-03 – Google ad –> TurboTax site –> DanaBot

This post doesn’t have text content, please click on the link below to view the original article. This article has been indexed from Malware-Traffic-Analysis.net – Blog Entries Read the original article: 2023-08-03 – Google ad –> TurboTax site –> DanaBot