Malware Traffic Analysis Net
2025-02-13: Quick post: ClickFix style infection for Lumma Stealer
6 days 14 hours ago
2025-02-10: StrelaStealer infection
1 week 1 day ago
2025-02-07: Three days of scans and probes and web traffic hitting my web server
1 week 6 days ago
2025-01-31: Two pcaps of AgentTesla-style data exfil, one using FTP and one using SMTP
2 weeks 5 days ago
2025-01-30: XLoader infection
3 weeks ago
2025-01-28: Malware infection from web inject activity
3 weeks 1 day ago
2025-01-23: Fake installer leads to Koi Loader/Koi Stealer
3 weeks 2 days ago
2025-01-22: Traffic Analysis Exercise - Download from fake software site
4 weeks ago
2025-01-21: Quick post for Koi Loader/Koi Stealer activity
4 weeks ago
2025-01-13: KongTuke campaign leads to infection abusing BOINC platform
1 month ago
2025-01-09: CVE-2017-0199 XLS --> HTA --> VBS --> steganography --> DBatLoader/GuiLoader style malware
1 month 1 week ago
2025-01-04: Four days of scans and probes and web traffic hitting my web server
1 month 2 weeks ago
2024-11-14 - Raspberry Robin infection using WebDAV server
3 months ago
2024-10-23 - Redline Stealer infection
3 months 3 weeks ago
2024-10-17 - Two days of server scans and probes and web traffic
3 months 3 weeks ago
2024-10-07 - Data dump (Formbook, possible Astaroth/Guildma, Redline Stealer, unidentified malware)
4 months 1 week ago
2024-10-03 - SmartLoader to Lumma Stealer
4 months 2 weeks ago
2024-10-01 - Ukrainian language malspam pushes RMS-based malware
4 months 2 weeks ago
2024-09-19 - File downloader to Lumma Stealer
4 months 4 weeks ago
Checked
1 hour 19 minutes ago
A malware traffic analysis blog
Malware Traffic Analysis Net feed