Sign in

Brad

@malware-traffic-analysis.net
992 followers 95 following 189 posts

Sharing information on malicious network traffic and malware samples at www.malware-traffic-analysis.net

PostsRepliesMedia
Reposted by Brad
SANS.edu Internet Storm Center @sansisc.bsky.social · 25/09/2026
ISC Diary: A Closer Look at Malware From the Macfinger ClickFix Campaign isc.sans.edu/diary/33368
ISC Logo
012
Brad @malware-traffic-analysis.net · 23/09/2026
To combat the spread of AI slop, I've hand-crafted an image to represent a ClickFix campaign I'm calling "Macfinger ClickFix." Think of the movie Goldfinger, but with macOS malware and the internet instead of James Bond and Miss Galore. More info at: isc.sans.edu/diary/33360
031
Reposted by Brad
SANS.edu Internet Storm Center @sansisc.bsky.social · 23/09/2026
ISC diary: #Macfinger #ClickFix campaign isc.sans.edu/diary/33360
ISC Logo
011
Brad @malware-traffic-analysis.net · 21/09/2026
026-09-21 (Monday): Some IOCs from today's #KongTuke #ClickFix activity: github.com/malware-traf...
Example of a KongTuke ClickFix fake verification page.
000
Brad @malware-traffic-analysis.net · 21/09/2026
2026-09-21 (Monday): IOCs for #SmartApeSG #ClickFix activity pushing #CNCMachineRMS RAT: github.com/malware-traf...
Example of a SmartApeSG ClickFix fake verification page.
010
Brad @malware-traffic-analysis.net · 21/09/2026
Caught up on some blog posts with #pcap files, malware samples and further info. www.malware-traffic-analysis.net/2026/index.h...
Screenshot of my blog page with the three most recent posts.
000
Brad @malware-traffic-analysis.net · 12/09/2026
2026-09-11 (Friday): Traffic analysis exercise. I generated an infection through #KongTuke #ClickFix activity. Not sure what the malware is, but I'm sharing #pcap as an exercise, while others might find the malware files and other info useful. www.malware-traffic-analysis.net/2026/09/11/i...
Screenshot of the fake verification page used for Kongtuke ClickFix activity
031
Brad @malware-traffic-analysis.net · 10/09/2026
Two new posts with #pcap, #malware, other files and #indicators for #XWorm (Tuesday, 2026-09-08) and #AMOS #Stealer (Thursday, 2026-09-10). www.malware-traffic-analysis.net/2026/index.h...
Screenshot of my blog page with the two most recent posts.
040
Brad @malware-traffic-analysis.net · 04/09/2026
2026-09-01 (Tuesday): Essential macOS Stealer infection Details at at malware-traffic-analysis.net/2026/09/01/i... The Polygon blockchain address with the C2 server info is 0x363AeAF1F67f1FB7ABdDC3f9806a301f1C64AbE3 Check the transactions for a history of the C2 servers.
Screenshot of the a macOS software page with text to paste into a macOS Terminal window.Text from the fake software page pasted into a macOS Terminal window.Traffic from the infection filtered in Wireshark.Transaction information from the Polygon blockchain address with C2 server domain name.
050
Reposted by Brad
SANS.edu Internet Storm Center @sansisc.bsky.social · 01/09/2026
ISC diary: Guildma (Astaroth) malware infection from Brazilian Portuguese email isc.sans.edu/diary/33300
ISC Logo
021
Brad @malware-traffic-analysis.net · 21/08/2026
2026-08-21 (Friday): #SmartApeSG #ClickFix campaign leads to two RATs. A #pcap of the network traffic, some files from the infected Windows host, and a list of indicators are available at www.malware-traffic-analysis.net/2026/08/21/i...
SmartApeSG script injected into page from a legitimate website.Fake CAPTCHA/verification page generatted by the SmartApeSG traffic, showing the injected ClickFix text to paste into a Run window.Traffic from the infection filtered in Wireshark.
042
Brad @malware-traffic-analysis.net · 13/08/2026
2026-08-12 (Wednesday): #SmartApeSG #ClickFix leads to two RATs. A #pcap of the traffic, malware, artifacts and more info available at www.malware-traffic-analysis.net/2026/08/12/i...
Page from compromised site with ClickFix instructions  from SmartApeSG campaign.Traffic from the infection filtered in Wireshark.
060
Brad @malware-traffic-analysis.net · 11/08/2026
2026-08-10 (Monday) Lumma Stealer or variant A #pcap of the infection and the associated malware samples are available at www.malware-traffic-analysis.net/2026/08/10/i...
screenshot 1 where the viewer sees buttons to download the file.screenshot 2 where it provides a link to download the file.screenshot 3, where the file is finally downloadedTraffic from the infection filtered in Wireshark
020
Brad @malware-traffic-analysis.net · 09/08/2026
2026-08-09 - Traffic analysis exercise - First to Last You get a #pcap and are asked to identify an infected Windows host. Join the fun at www.malware-traffic-analysis.net/2026/08/09/i...
Pcap from the infection opened in Wireshark
030
Reposted by Brad
SANS.edu Internet Storm Center @sansisc.bsky.social · 02/08/2026
Atomic MacOS (AMOS) stealer infection isc.sans.edu/diary/33208
ISC Logo
011
Brad @malware-traffic-analysis.net · 31/07/2026
2026-07-31 (Friday): #SmartApeSG #ClickFix campaign pushes unidentified #RAT malware. A #pcap of the infection traffic, the associated #malware files, and further info available at www.malware-traffic-analysis.net/2026/07/31/i...
Page from compromised site with injected SmartApeSG script.Fake CAPTCHA/human verification page from site compromised through the SmartApeSG campaign.Traffic from an infection filtered in Wireshark.
000
Brad @malware-traffic-analysis.net · 10/06/2026
2026-06-09 (Tuesday): Documented an Atomic macOS ( #AMOS ) Stealer infection in my lab. A #pcap of the traffic, the associated malware, and a list of indicators are available at www.malware-traffic-analysis.net/2026/06/09/i...
Fake Homebrew (Brew) page with ClickFix style instructions that would infect a potential victim's macOS host with AMOS Stealer.Pasting text from the fake Homebrew page into a macOS terminal windowArtifacts in an infected macOS host's /tmp directory, which includes the AMOS installer (a Mach-O file) and a plist file that reveals the location of the persistent malware.Location of the persistent AMOS Stealer malware on an infected macOS host.
162
Reposted by Brad
SANS.edu Internet Storm Center @sansisc.bsky.social · 01/06/2026
ISC Diary: Unidentified RAT pushes NetSupport RAT isc.sans.edu/diary/33034
ISC Logo
041
Reposted by Brad
SANS.edu Internet Storm Center @sansisc.bsky.social · 26/05/2026
ISC Diary: #ACRStealer from web page impersonating Claude isc.sans.edu/diary/33018
ISC Logo
022
Brad @malware-traffic-analysis.net · 12/05/2026
2026-05-11 (Monday) #Malvertizing: Another ad in Google search results leads to a page impersonating a Claude download but distributing #macOS #malware. A #pcap of the infection traffic, some of the indicators and associated files are available at www.malware-traffic-analysis.net/2026/05/11/i...
Screenshot of Google search results with an ad leading to the fake Claude page.ClickFix style instructions for the malware download from the fake Claude page.Command copied from the fake Claude installation page and pasted into a terminal window.Traffic from the infection filtered in Wireshark.
040
Brad @malware-traffic-analysis.net · 09/05/2026
2026-05-08 (Friday): Fake Homebrew page on nycaihong[.]com for #macOS #malware Possibly distributing #MacSyncStealer using an initial loader from hxxp[:]//longbeachmartialarts[.]com/curl/116f3b0bd8053eead15479f4b04bd2d9bc050f282eceeec87fd7908458ad3abe
Fake Homebrew page pushing malwareCommand from the fake Homebrew page revealing a URL for macOS malware
030
Brad @malware-traffic-analysis.net · 08/05/2026
2026-05-08 (Friday): #macOS #ShubStealer infection #pcap, malware files, and a list of indicators available at malware-traffic-analysis.net/2026/05/08/i...
Screenshot of the blog page documenting my Shub Stealer infection
010
Reposted by Brad
SANS.edu Internet Storm Center @sansisc.bsky.social · 01/05/2026
ISC Diary: Malicious ad for Homebrew leads to #MacSync #Stealer isc.sans.edu/diary/32942
ISC Logo
011
Brad @malware-traffic-analysis.net · 29/04/2026
2026-04-22: Malicious ad ( #Malvertizing ) for Claude leads to #ClickFix style page for #macOS #malware Details at www.malware-traffic-analysis.net/2026/04/22/i... I've read about this activity from other sources, but this is the infection I generated in my lab and finally got around to posting.
ClickFix style page for macOS malware disguised as Claude download.ClickFix instructions pasted into a terminal window on a macOS host.Malware payload saved to the infected macOS host.Traffic from the infection filtered in Wireshark.
061
Brad @malware-traffic-analysis.net · 24/04/2026
2026-04-23 (Thursday): #SmartApeSG campaign using #ClickFix instructions to push some sort of #RAT. Not sure what this #malware is yet, but it looks like a RAT. Details at www.malware-traffic-analysis.net/2026/04/23/i...
SmartApeSG fake CAPTCHA (verify you are human page) when viewing a legitimate but compromised website.ClickFix instructions from the SmartApeSG fake CAPTCHA (verify you are human page).ClickFix instructions pasted into a Run window on a Windows 11 host.Traffic from the infection filtered in Wireshark.
142
Brad @malware-traffic-analysis.net · 17/04/2026
2026-04-16 (Thursday): #pcap and #malware samples from the #LummaStealer infection with #SectopRAT ( #ArechClient2 ) that I documented in an ISC diary at isc.sans.edu/diary/Lumma+...
141
Reposted by Brad
SANS.edu Internet Storm Center @sansisc.bsky.social · 17/04/2026
ISC Diary: #LummaStealer infection with #SectopRAT (#ArechClient2) isc.sans.edu/diary/32904
ISC Logo
021
Brad @malware-traffic-analysis.net · 14/04/2026
2026-04-13 (Monday): #XLoader ( #Formbook ) infection. A #pcap of the traffic, along with the associated email and malware samples are available at malware-traffic-analysis.net/2026/index.h...
Screenshot of and email distributing XLoader (Formbook)Attachment for XLoader (Formbook) from the email showing the malicious script file contained in the archive.PowerShell script file dropped and deleted during the XLoader (Formbook) infection.Traffic from the XLoader (Formbook) infection filtered in Wireshark.
120
Brad @malware-traffic-analysis.net · 06/04/2026
2026-04-06 (Monday): #ClickFix activity from the #SmartApeSG campaign. Not sure what malware was sent through the fake CAPTCHA page is this time, but it's not the usual. Indicators, a #pcap of the traffic, malware samples and other info available at malware-traffic-analysis.net/2026/04/06/i...
SmartApeSG script injected into page from compromised website.SmartApeSG fake CAPTCHA page with ClickFix instructions.Malware delivered through SmartApeSG persistent on an infected Windows host.
031
Reposted by Brad
SANS.edu Internet Storm Center @sansisc.bsky.social · 25/03/2026
ISC Diary: #SmartApeSG campaign pushes #Remcos #RAT, #NetSupportRAT, #StealC and #SectopRAT (#ArechC isc.sans.edu/diary/32826
ISC Logo
022
Brad @malware-traffic-analysis.net · 23/03/2026
2026-03-23: #PhantomStealer malware sent as an email attachment. .js file sample from the attachment: bazaar.abuse.ch/sample/8606c... PowerShell script retrieved by the above .js file: bazaar.abuse.ch/sample/a0d72...
Screenshot of the initial email with the malicious attachment.Traffic from the infection filtered in Wireshark.he Phantom Stealer infection.
021
Brad @malware-traffic-analysis.net · 19/03/2026
#CVE_2017_11882 in this day and age? Saw this or some similar very old exploit from an Excel file attached to a message sent to my blog email address. Sample available at bazaar.abuse.ch/sample/263b3... It's for a #Snake KeyLogger infection. Thanks to @jamesinthebox.bsky.social for identifying it!
Screenshot of the emailTraffic from an infection, filtered in WiresharkSnake, who would do keylogging, if we wasn't illiterate.
010
Reposted by Brad
SANS.edu Internet Storm Center @sansisc.bsky.social · 14/03/2026
ISC diary: #SmartApeSG campaign uses #ClickFix page to push #Remcos #RAT (#RemcosRAT) isc.sans.edu/diary/32796
ISC Logo
011
Brad @malware-traffic-analysis.net · 01/03/2026
February 2026 #TrafficAnalysisExercise You get a pcap, you find your kidnapped daughter--I mean, you find the infected Windows host! Join the fun at www.malware-traffic-analysis.net/2026/02/28/i...
"Where is she!??!!??"  Wait a minute, that's Batman.  This is Liam Neeson.
021
Brad @malware-traffic-analysis.net · 03/02/2026
2026-02-03 (Tuesday): #GuLoader for #AgentTesla style malware with FTP data exfiltration. A #pcap of the infection traffic, associated files, and a list of indicators are available at www.malware-traffic-analysis.net/2026/02/03/i...
Screenshot of my blog post with the files and information from this infection.Screenshot of the email with an attached RAR archive.The malware, extracted from the attached RAR archive.Traffic from the infection filtered in Wireshark.
041
Brad @malware-traffic-analysis.net · 03/02/2026
Reposted with correct malware names: 2026-02-02 (Monday) #KongTuke #ClickFix activity leads to #MintsLoader and #GhostWeaver RAT Today's ClickFix uses the "finger" command, a tactic seen in previous ClickFix activity. Further details available at www.malware-traffic-analysis.net/2026/02/02/i...
Fake "Verify You Are Human" CAPTCHA page that can appear when viewing a page from a legitimate but compromised website.Text from KongTuke's fake CAPTCHA page injected into the viewer's clipboard, and the CAPTCHA page contains instructions to run the text as a command in Window's Run window.Traffic from the KongTuke activity and resulting infection filtered in Wireshark.
163
Brad @malware-traffic-analysis.net · 02/02/2026
2026-02-01 (Sunday): It's easy enough to find #LummaStealer malware samples. Just do a Google search for cracked versions of popular software and specify site:drive.google.com. Details on today's haul at github.com/malware-traf...
Screenshot showing Google search results for a cracked version of ArcGIS where I specify site:drive.google.com. The results shown here all lead to PDF files hosted on Google Drive, and these PDF files contains links that lead to malware.Here's an example of one of these PDF files hosted on Google Drive with a link that leads to malware.Here's the page that pushes a password-protected 7-zip archive that contains an inflated EXE padded with null bytes. This EXE is for Lumma Stealer malware.Lumma Stealer traffic generated by the extracted malware. This is filtered in Wireshark to focus on the Lumma Stealer C2 traffic.
042
Brad @malware-traffic-analysis.net · 31/01/2026
2026-01-31 (Friday): I've posted a new traffic analysis exercise. It's Lumma in the room-ah! Join the fun at www.malware-traffic-analysis.net/2026/01/31/i... I mean, this guy looks like he's having fun.
053
Brad @malware-traffic-analysis.net · 29/01/2026
2026-01-22 (Thursday): #RemcosRAT infection persistent on an infected Windows host. This was caused by #ClickFix instructions from #SmartApeSG through a fake CAPTCHA page. Details of this #Remcos #RAT infection are available at www.malware-traffic-analysis.net/2026/01/06/i...
Screenshot from an infected Windows host showing Remcos RAT and how it is persistent.
032
Brad @malware-traffic-analysis.net · 20/01/2026
2026-01-19 (Monday): Catching up on two infections in my lab from last week, and I added an entry with a #pcap of scans and probes and web traffic hitting my web server. Feel free to check out my latest posts at www.malware-traffic-analysis.net/2026/index.h... Or not. I'm not the boss of you.
151
Reposted by Brad
SANS.edu Internet Storm Center @sansisc.bsky.social · 14/01/2026
ISC Diary: Infection repeatedly adds scheduled tasks & increases traffic to same C2 domain isc.sans.edu/diary/32628
ISC Logo
032
Brad @malware-traffic-analysis.net · 11/01/2026
2026-01-10 (Saturday): Ten days of scans, probes, and web traffic hitting my web server. A #pcap of the traffic is available at www.malware-traffic-analysis.net/2026/01/10/i...
Some of the scans, probes, and web traffic from the pcap filtered in Wireshark.HTTP stream of the last HTTP request in the pcap showing a POST request that retrieves malicious content from a server at 91.92.241[.]10.Using the wget command to retrieve one of the malicious files from the server at 91.92.241[.]10 on Sunday, 2026-01-11.Example of a shell script downloaded from 91.92.241[.]10 on Sunday, 2026-01-11, likely for Mirai botnet malware.
030
Brad @malware-traffic-analysis.net · 09/01/2026
2026-01-09 (Friday): #VIPRecovery infection from an email attachment. A #pcap of the infection traffic, associated files, and more information are available at www.malware-traffic-analysis.net/2026/01/09/i...
Screenshot of the email, its attachment, and the VBS file within the attachment for VIP Recovery malware.Traffic from the infection filtered in Wireshark.TCP stream of the unencrypted SMTP traffic from one of the data exfiltration emails sent by my infected lab host.Screenshot of the start of my blog post with information on this VIP Recovery infection.
050
Brad @malware-traffic-analysis.net · 08/01/2026
2026-01-08 (Thursday): Got a full infection from #KongTuke campaign #ClickFix activity today. Traffic from the infection in two #pcap files, the associated malware, artifacts, and further information is available at www.malware-traffic-analysis.net/2026/01/08/i...
Fake CAPTCHA window and ClickFix script after visiting legitimate, but compromised website.Traffic from the infection filtered in Wireshark (part 1 of 2).Traffic from the infection filtered in Wireshark (part 2 of 2).Screenshot from the start of the page for this blog post.
030
Brad @malware-traffic-analysis.net · 08/01/2026
2026-01-07 (Wednesday): #MassLogger infection from email attachment. Copies of the emails, associated malware, indicators, and a #pcap of the infection traffic are available at www.malware-traffic-analysis.net/2026/01/07/i...
One of the emails and its associated attachment for MassLogger malware.Traffic from the infection filtered in Wireshark.Example of a data exfiltration email sent from an infected host in my lab.
031
Brad @malware-traffic-analysis.net · 06/01/2026
2026-01-06 (Tuesday): #SmartApeSG CAPTCHA page uses #ClickFix technique to push #RemcosRAT, with #Remcos #RAT C2 server at 192.144.56[.]80. A #pcap of the traffic, the Remcos RAT #malware, and a list of indicators are available at www.malware-traffic-analysis.net/2026/01/06/i...
Example of a legitimate but compromised site showing the SmartApeSG fake CAPTCHA page.HTTPS URLs from the infection run.Traffic from an infection filtered in Wireshark.Remcos RAT infection persistent on an infected Windows host.
062
Brad @malware-traffic-analysis.net · 05/01/2026
2026-01-05 (Monday): #KongTuke domain scrroeder[.]com generated #ClickFix script for 144.31.221[.]71, but I didn't get a malware infection when I tried it today.
Injected KongTuke script in page from compromised website.Fake CAPTCHA page from KongTuke domain, scrroeder[.]com.KongTuke's "ClickFix" command injected into the viewer's clipboard.Traffic from the activity filtered in Wireshark. I did not get the malware from this.
071
Reposted by Brad
SANS.edu Internet Storm Center @sansisc.bsky.social · 04/01/2026
ISC Diary: Cryptocurrency Scam Emails and Web Pages As We Enter 2026 isc.sans.edu/diary/32594
ISC Logo
022
Brad @malware-traffic-analysis.net · 01/01/2026
2026-01-01 (Thursday): #LummaStealer infection with follow-up malware. A #pcap of the infection traffic, the #Lumma #Stealer files, and a list of IOCs are available at www.malware-traffic-analysis.net/2026/01/01/i...
A screenshot of my blog post for the Lumma Stealer infectionTraffic from the Lumma Stealer infection filtered in Wireshark.
031
Brad @malware-traffic-analysis.net · 31/12/2025
2025-12-30 (Tuesday): #LummaStealer infection with follow-up malware. A #pcap of the infection traffic, the associated #Lumma with follow-up #malware samples, and some IOCs are available at www.malware-traffic-analysis.net/2025/12/30/i...
Screenshot of my blog post to share information on this Lumma Stealer infection with follow-up malware.
073