Brad · @malware_traffic
2362 followers · 140 posts · Server infosec.exchange

Originally posted at: twitter.com/malware_traffic/st

2023-03-08 (Wednesday): () infection with and traffic. Email --> PDF with link --> downloaded zip --> extracted .msi --> IcedID infection. 1 malspam example, from an infection, associated malware & IOCs available at malware-traffic-analysis.net/2

#icedid #bobkot #backconnect #vnc #pcap

Last updated 1 year ago

Bonjour !

We've spotted a new C2 server being set up on:

5.196.196.252 (🇫🇷)

Expect to see this IP in infection chains in the coming days / hours.

👀

cc @netresec

#icedid #backconnect #recon

Last updated 2 years ago

Brad · @malware_traffic
2176 followers · 96 posts · Server infosec.exchange

Posted at: twitter.com/malware_traffic/st

2023-01-16 (Monday): An () infection I did thanks to @pr0xylife
sharing a PDF on Malware Bazaar. This one has traffic with activity, and there's too! The was too good -not- to share! Have a peek at: malware-traffic-analysis.net/2

#icedid #Bokbot #backconnect #vnc #cobaltstrike #pcap

Last updated 2 years ago