Malware Traffic Analysis Net
2025-02-07: Three days of scans and probes and web traffic hitting my web server
9 months 3 weeks ago
2025-01-31: Two pcaps of AgentTesla-style data exfil, one using FTP and one using SMTP
10 months ago
2025-01-30: XLoader infection
10 months ago
2025-01-28: Malware infection from web inject activity
10 months 1 week ago
2025-01-23: Fake installer leads to Koi Loader/Koi Stealer
10 months 1 week ago
2025-01-22: Traffic Analysis Exercise - Download from fake software site
10 months 1 week ago
2025-01-21: Quick post for Koi Loader/Koi Stealer activity
10 months 1 week ago
2025-01-13: KongTuke campaign leads to infection abusing BOINC platform
10 months 3 weeks ago
2025-01-09: CVE-2017-0199 XLS --> HTA --> VBS --> steganography --> DBatLoader/GuiLoader style malware
10 months 3 weeks ago
2025-01-04: Four days of scans and probes and web traffic hitting my web server
11 months ago
2024-11-14 - Raspberry Robin infection using WebDAV server
1 year ago
2024-10-23 - Redline Stealer infection
1 year 1 month ago
2024-10-17 - Two days of server scans and probes and web traffic
1 year 1 month ago
2024-10-07 - Data dump (Formbook, possible Astaroth/Guildma, Redline Stealer, unidentified malware)
1 year 1 month ago
2024-10-03 - SmartLoader to Lumma Stealer
1 year 2 months ago
2024-10-01 - Ukrainian language malspam pushes RMS-based malware
1 year 2 months ago
2024-09-19 - File downloader to Lumma Stealer
1 year 2 months ago
2024-09-17 - Snake KeyLogger (VIP Recovery) infection, FTP exfil
1 year 2 months ago
2024-09-16 - Snake KeyLogger (VIP Recovery) infection, SMTP exfil
1 year 2 months ago
Checked
1 hour 37 minutes ago
A malware traffic analysis blog
Malware Traffic Analysis Net feed