Sign in

Brad

@malware-traffic-analysis.net
995 followers 95 following 189 posts

Sharing information on malicious network traffic and malware samples at www.malware-traffic-analysis.net

PostsRepliesMedia
Brad @malware-traffic-analysis.net · 23/09/2026
To combat the spread of AI slop, I've hand-crafted an image to represent a ClickFix campaign I'm calling "Macfinger ClickFix." Think of the movie Goldfinger, but with macOS malware and the internet instead of James Bond and Miss Galore. More info at: isc.sans.edu/diary/33360
031
Brad @malware-traffic-analysis.net · 21/09/2026
026-09-21 (Monday): Some IOCs from today's #KongTuke #ClickFix activity: github.com/malware-traf...
Example of a KongTuke ClickFix fake verification page.
000
Brad @malware-traffic-analysis.net · 21/09/2026
2026-09-21 (Monday): IOCs for #SmartApeSG #ClickFix activity pushing #CNCMachineRMS RAT: github.com/malware-traf...
Example of a SmartApeSG ClickFix fake verification page.
020
Brad @malware-traffic-analysis.net · 21/09/2026
Caught up on some blog posts with #pcap files, malware samples and further info. www.malware-traffic-analysis.net/2026/index.h...
Screenshot of my blog page with the three most recent posts.
000
Brad @malware-traffic-analysis.net · 12/09/2026
2026-09-11 (Friday): Traffic analysis exercise. I generated an infection through #KongTuke #ClickFix activity. Not sure what the malware is, but I'm sharing #pcap as an exercise, while others might find the malware files and other info useful. www.malware-traffic-analysis.net/2026/09/11/i...
Screenshot of the fake verification page used for Kongtuke ClickFix activity
031
Brad @malware-traffic-analysis.net · 10/09/2026
Two new posts with #pcap, #malware, other files and #indicators for #XWorm (Tuesday, 2026-09-08) and #AMOS #Stealer (Thursday, 2026-09-10). www.malware-traffic-analysis.net/2026/index.h...
Screenshot of my blog page with the two most recent posts.
040
Brad @malware-traffic-analysis.net · 04/09/2026
2026-09-01 (Tuesday): Essential macOS Stealer infection Details at at malware-traffic-analysis.net/2026/09/01/i... The Polygon blockchain address with the C2 server info is 0x363AeAF1F67f1FB7ABdDC3f9806a301f1C64AbE3 Check the transactions for a history of the C2 servers.
Screenshot of the a macOS software page with text to paste into a macOS Terminal window.Text from the fake software page pasted into a macOS Terminal window.Traffic from the infection filtered in Wireshark.Transaction information from the Polygon blockchain address with C2 server domain name.
050
Brad @malware-traffic-analysis.net · 21/08/2026
2026-08-21 (Friday): #SmartApeSG #ClickFix campaign leads to two RATs. A #pcap of the network traffic, some files from the infected Windows host, and a list of indicators are available at www.malware-traffic-analysis.net/2026/08/21/i...
SmartApeSG script injected into page from a legitimate website.Fake CAPTCHA/verification page generatted by the SmartApeSG traffic, showing the injected ClickFix text to paste into a Run window.Traffic from the infection filtered in Wireshark.
042
Brad @malware-traffic-analysis.net · 13/08/2026
2026-08-12 (Wednesday): #SmartApeSG #ClickFix leads to two RATs. A #pcap of the traffic, malware, artifacts and more info available at www.malware-traffic-analysis.net/2026/08/12/i...
Page from compromised site with ClickFix instructions  from SmartApeSG campaign.Traffic from the infection filtered in Wireshark.
060
Brad @malware-traffic-analysis.net · 11/08/2026
2026-08-10 (Monday) Lumma Stealer or variant A #pcap of the infection and the associated malware samples are available at www.malware-traffic-analysis.net/2026/08/10/i...
screenshot 1 where the viewer sees buttons to download the file.screenshot 2 where it provides a link to download the file.screenshot 3, where the file is finally downloadedTraffic from the infection filtered in Wireshark
020
Brad @malware-traffic-analysis.net · 09/08/2026
2026-08-09 - Traffic analysis exercise - First to Last You get a #pcap and are asked to identify an infected Windows host. Join the fun at www.malware-traffic-analysis.net/2026/08/09/i...
Pcap from the infection opened in Wireshark
030
Brad @malware-traffic-analysis.net · 31/07/2026
2026-07-31 (Friday): #SmartApeSG #ClickFix campaign pushes unidentified #RAT malware. A #pcap of the infection traffic, the associated #malware files, and further info available at www.malware-traffic-analysis.net/2026/07/31/i...
Page from compromised site with injected SmartApeSG script.Fake CAPTCHA/human verification page from site compromised through the SmartApeSG campaign.Traffic from an infection filtered in Wireshark.
000
Brad @malware-traffic-analysis.net · 10/06/2026
2026-06-09 (Tuesday): Documented an Atomic macOS ( #AMOS ) Stealer infection in my lab. A #pcap of the traffic, the associated malware, and a list of indicators are available at www.malware-traffic-analysis.net/2026/06/09/i...
Fake Homebrew (Brew) page with ClickFix style instructions that would infect a potential victim's macOS host with AMOS Stealer.Pasting text from the fake Homebrew page into a macOS terminal windowArtifacts in an infected macOS host's /tmp directory, which includes the AMOS installer (a Mach-O file) and a plist file that reveals the location of the persistent malware.Location of the persistent AMOS Stealer malware on an infected macOS host.
162
Brad @malware-traffic-analysis.net · 12/05/2026
2026-05-11 (Monday) #Malvertizing: Another ad in Google search results leads to a page impersonating a Claude download but distributing #macOS #malware. A #pcap of the infection traffic, some of the indicators and associated files are available at www.malware-traffic-analysis.net/2026/05/11/i...
Screenshot of Google search results with an ad leading to the fake Claude page.ClickFix style instructions for the malware download from the fake Claude page.Command copied from the fake Claude installation page and pasted into a terminal window.Traffic from the infection filtered in Wireshark.
040
Brad @malware-traffic-analysis.net · 09/05/2026
2026-05-08 (Friday): Fake Homebrew page on nycaihong[.]com for #macOS #malware Possibly distributing #MacSyncStealer using an initial loader from hxxp[:]//longbeachmartialarts[.]com/curl/116f3b0bd8053eead15479f4b04bd2d9bc050f282eceeec87fd7908458ad3abe
Fake Homebrew page pushing malwareCommand from the fake Homebrew page revealing a URL for macOS malware
030
Brad @malware-traffic-analysis.net · 08/05/2026
2026-05-08 (Friday): #macOS #ShubStealer infection #pcap, malware files, and a list of indicators available at malware-traffic-analysis.net/2026/05/08/i...
Screenshot of the blog page documenting my Shub Stealer infection
010
Brad @malware-traffic-analysis.net · 29/04/2026
2026-04-22: Malicious ad ( #Malvertizing ) for Claude leads to #ClickFix style page for #macOS #malware Details at www.malware-traffic-analysis.net/2026/04/22/i... I've read about this activity from other sources, but this is the infection I generated in my lab and finally got around to posting.
ClickFix style page for macOS malware disguised as Claude download.ClickFix instructions pasted into a terminal window on a macOS host.Malware payload saved to the infected macOS host.Traffic from the infection filtered in Wireshark.
061
Brad @malware-traffic-analysis.net · 24/04/2026
2026-04-23 (Thursday): #SmartApeSG campaign using #ClickFix instructions to push some sort of #RAT. Not sure what this #malware is yet, but it looks like a RAT. Details at www.malware-traffic-analysis.net/2026/04/23/i...
SmartApeSG fake CAPTCHA (verify you are human page) when viewing a legitimate but compromised website.ClickFix instructions from the SmartApeSG fake CAPTCHA (verify you are human page).ClickFix instructions pasted into a Run window on a Windows 11 host.Traffic from the infection filtered in Wireshark.
142
Brad @malware-traffic-analysis.net · 17/04/2026
2026-04-16 (Thursday): #pcap and #malware samples from the #LummaStealer infection with #SectopRAT ( #ArechClient2 ) that I documented in an ISC diary at isc.sans.edu/diary/Lumma+...
141
Brad @malware-traffic-analysis.net · 14/04/2026
2026-04-13 (Monday): #XLoader ( #Formbook ) infection. A #pcap of the traffic, along with the associated email and malware samples are available at malware-traffic-analysis.net/2026/index.h...
Screenshot of and email distributing XLoader (Formbook)Attachment for XLoader (Formbook) from the email showing the malicious script file contained in the archive.PowerShell script file dropped and deleted during the XLoader (Formbook) infection.Traffic from the XLoader (Formbook) infection filtered in Wireshark.
120
Brad @malware-traffic-analysis.net · 06/04/2026
2026-04-06 (Monday): #ClickFix activity from the #SmartApeSG campaign. Not sure what malware was sent through the fake CAPTCHA page is this time, but it's not the usual. Indicators, a #pcap of the traffic, malware samples and other info available at malware-traffic-analysis.net/2026/04/06/i...
SmartApeSG script injected into page from compromised website.SmartApeSG fake CAPTCHA page with ClickFix instructions.Malware delivered through SmartApeSG persistent on an infected Windows host.
031
Brad @malware-traffic-analysis.net · 23/03/2026
2026-03-23: #PhantomStealer malware sent as an email attachment. .js file sample from the attachment: bazaar.abuse.ch/sample/8606c... PowerShell script retrieved by the above .js file: bazaar.abuse.ch/sample/a0d72...
Screenshot of the initial email with the malicious attachment.Traffic from the infection filtered in Wireshark.he Phantom Stealer infection.
021
Brad @malware-traffic-analysis.net · 19/03/2026
#CVE_2017_11882 in this day and age? Saw this or some similar very old exploit from an Excel file attached to a message sent to my blog email address. Sample available at bazaar.abuse.ch/sample/263b3... It's for a #Snake KeyLogger infection. Thanks to @jamesinthebox.bsky.social for identifying it!
Screenshot of the emailTraffic from an infection, filtered in WiresharkSnake, who would do keylogging, if we wasn't illiterate.
010
Brad @malware-traffic-analysis.net · 01/03/2026
February 2026 #TrafficAnalysisExercise You get a pcap, you find your kidnapped daughter--I mean, you find the infected Windows host! Join the fun at www.malware-traffic-analysis.net/2026/02/28/i...
"Where is she!??!!??"  Wait a minute, that's Batman.  This is Liam Neeson.
021
Brad @malware-traffic-analysis.net · 03/02/2026
2026-02-03 (Tuesday): #GuLoader for #AgentTesla style malware with FTP data exfiltration. A #pcap of the infection traffic, associated files, and a list of indicators are available at www.malware-traffic-analysis.net/2026/02/03/i...
Screenshot of my blog post with the files and information from this infection.Screenshot of the email with an attached RAR archive.The malware, extracted from the attached RAR archive.Traffic from the infection filtered in Wireshark.
041
Brad @malware-traffic-analysis.net · 03/02/2026
Reposted with correct malware names: 2026-02-02 (Monday) #KongTuke #ClickFix activity leads to #MintsLoader and #GhostWeaver RAT Today's ClickFix uses the "finger" command, a tactic seen in previous ClickFix activity. Further details available at www.malware-traffic-analysis.net/2026/02/02/i...
Fake "Verify You Are Human" CAPTCHA page that can appear when viewing a page from a legitimate but compromised website.Text from KongTuke's fake CAPTCHA page injected into the viewer's clipboard, and the CAPTCHA page contains instructions to run the text as a command in Window's Run window.Traffic from the KongTuke activity and resulting infection filtered in Wireshark.
163
Brad @malware-traffic-analysis.net · 02/02/2026
2026-02-01 (Sunday): It's easy enough to find #LummaStealer malware samples. Just do a Google search for cracked versions of popular software and specify site:drive.google.com. Details on today's haul at github.com/malware-traf...
Screenshot showing Google search results for a cracked version of ArcGIS where I specify site:drive.google.com. The results shown here all lead to PDF files hosted on Google Drive, and these PDF files contains links that lead to malware.Here's an example of one of these PDF files hosted on Google Drive with a link that leads to malware.Here's the page that pushes a password-protected 7-zip archive that contains an inflated EXE padded with null bytes. This EXE is for Lumma Stealer malware.Lumma Stealer traffic generated by the extracted malware. This is filtered in Wireshark to focus on the Lumma Stealer C2 traffic.
042
Brad @malware-traffic-analysis.net · 31/01/2026
2026-01-31 (Friday): I've posted a new traffic analysis exercise. It's Lumma in the room-ah! Join the fun at www.malware-traffic-analysis.net/2026/01/31/i... I mean, this guy looks like he's having fun.
053
Brad @malware-traffic-analysis.net · 29/01/2026
2026-01-22 (Thursday): #RemcosRAT infection persistent on an infected Windows host. This was caused by #ClickFix instructions from #SmartApeSG through a fake CAPTCHA page. Details of this #Remcos #RAT infection are available at www.malware-traffic-analysis.net/2026/01/06/i...
Screenshot from an infected Windows host showing Remcos RAT and how it is persistent.
032
Brad @malware-traffic-analysis.net · 20/01/2026
2026-01-19 (Monday): Catching up on two infections in my lab from last week, and I added an entry with a #pcap of scans and probes and web traffic hitting my web server. Feel free to check out my latest posts at www.malware-traffic-analysis.net/2026/index.h... Or not. I'm not the boss of you.
151
Brad @malware-traffic-analysis.net · 11/01/2026
2026-01-10 (Saturday): Ten days of scans, probes, and web traffic hitting my web server. A #pcap of the traffic is available at www.malware-traffic-analysis.net/2026/01/10/i...
Some of the scans, probes, and web traffic from the pcap filtered in Wireshark.HTTP stream of the last HTTP request in the pcap showing a POST request that retrieves malicious content from a server at 91.92.241[.]10.Using the wget command to retrieve one of the malicious files from the server at 91.92.241[.]10 on Sunday, 2026-01-11.Example of a shell script downloaded from 91.92.241[.]10 on Sunday, 2026-01-11, likely for Mirai botnet malware.
030
Brad @malware-traffic-analysis.net · 09/01/2026
2026-01-09 (Friday): #VIPRecovery infection from an email attachment. A #pcap of the infection traffic, associated files, and more information are available at www.malware-traffic-analysis.net/2026/01/09/i...
Screenshot of the email, its attachment, and the VBS file within the attachment for VIP Recovery malware.Traffic from the infection filtered in Wireshark.TCP stream of the unencrypted SMTP traffic from one of the data exfiltration emails sent by my infected lab host.Screenshot of the start of my blog post with information on this VIP Recovery infection.
050
Brad @malware-traffic-analysis.net · 08/01/2026
2026-01-08 (Thursday): Got a full infection from #KongTuke campaign #ClickFix activity today. Traffic from the infection in two #pcap files, the associated malware, artifacts, and further information is available at www.malware-traffic-analysis.net/2026/01/08/i...
Fake CAPTCHA window and ClickFix script after visiting legitimate, but compromised website.Traffic from the infection filtered in Wireshark (part 1 of 2).Traffic from the infection filtered in Wireshark (part 2 of 2).Screenshot from the start of the page for this blog post.
030
Brad @malware-traffic-analysis.net · 08/01/2026
2026-01-07 (Wednesday): #MassLogger infection from email attachment. Copies of the emails, associated malware, indicators, and a #pcap of the infection traffic are available at www.malware-traffic-analysis.net/2026/01/07/i...
One of the emails and its associated attachment for MassLogger malware.Traffic from the infection filtered in Wireshark.Example of a data exfiltration email sent from an infected host in my lab.
031
Brad @malware-traffic-analysis.net · 06/01/2026
2026-01-06 (Tuesday): #SmartApeSG CAPTCHA page uses #ClickFix technique to push #RemcosRAT, with #Remcos #RAT C2 server at 192.144.56[.]80. A #pcap of the traffic, the Remcos RAT #malware, and a list of indicators are available at www.malware-traffic-analysis.net/2026/01/06/i...
Example of a legitimate but compromised site showing the SmartApeSG fake CAPTCHA page.HTTPS URLs from the infection run.Traffic from an infection filtered in Wireshark.Remcos RAT infection persistent on an infected Windows host.
062
Brad @malware-traffic-analysis.net · 05/01/2026
2026-01-05 (Monday): #KongTuke domain scrroeder[.]com generated #ClickFix script for 144.31.221[.]71, but I didn't get a malware infection when I tried it today.
Injected KongTuke script in page from compromised website.Fake CAPTCHA page from KongTuke domain, scrroeder[.]com.KongTuke's "ClickFix" command injected into the viewer's clipboard.Traffic from the activity filtered in Wireshark. I did not get the malware from this.
071
Brad @malware-traffic-analysis.net · 01/01/2026
2026-01-01 (Thursday): #LummaStealer infection with follow-up malware. A #pcap of the infection traffic, the #Lumma #Stealer files, and a list of IOCs are available at www.malware-traffic-analysis.net/2026/01/01/i...
A screenshot of my blog post for the Lumma Stealer infectionTraffic from the Lumma Stealer infection filtered in Wireshark.
031
Brad @malware-traffic-analysis.net · 31/12/2025
2025-12-30 (Tuesday): #LummaStealer infection with follow-up malware. A #pcap of the infection traffic, the associated #Lumma with follow-up #malware samples, and some IOCs are available at www.malware-traffic-analysis.net/2025/12/30/i...
Screenshot of my blog post to share information on this Lumma Stealer infection with follow-up malware.
073
Brad @malware-traffic-analysis.net · 29/12/2025
2025-12-29 (Monday): #ClickFix page leads to #NetSupportRAT infection. Details at www.malware-traffic-analysis.net/2025/12/29/i...
Example of initial URL from sites.google[.]com.Example of a fake CAPTCHA page with ClickFix-style instructions and the ClickFix script.Traffic from the infection filtered in Wireshark.NetSupport RAT persistent on an infected Windows host.
011
Brad @malware-traffic-analysis.net · 23/12/2025
2025-12-23 (Tuesday): Based on yesterday's Jamf article, I ran the fake installer for #MacSyncStealer in my lab on a macOS host. A #pcap of the #MacSync #Stealer traffic, the associated IOCs, the #malware sample, and a link to the Jamf article are at www.malware-traffic-analysis.net/2025/12/23/i...
Downloading the initial file, a DMG image.Screenshot showing the malicious downloaded DMG image and the associated malicious Mach-O file within the installer.app content.Traffic generated by the MacSync Stealer malware, filtered in Wireshark.Example of the data exfiltrated through the MacSync Stealer C2 traffic.
030
Brad @malware-traffic-analysis.net · 23/12/2025
I finished compiling the information for #Kongtuke #ClickFix activity using the finger command on 2025-12-11, and it's now live at www.malware-traffic-analysis.net/2025/12/11/i... I'd already posted the #SmartApeSG ClickFix activity using finger that same day, so now both are available.
Screenshot of the post with the pcaps, files, and other info from the Kongtuke ClickFix activity using the finger command on 2025-12-11.
041
Brad @malware-traffic-analysis.net · 22/12/2025
I recently completed a long-term project to deindex old web pages on my blog, and I can now turn my attention back to sharing pcaps and malware samples. I've posted 3 for December 2025, and I hope to get some more posted before the end of the year. www.malware-traffic-analysis.net/2025/index.h...
Screenshot showing links for the three December 2025 blog posts I have so far.
1134
Brad @malware-traffic-analysis.net · 12/11/2025
2025-11-11 (Tuesday): Cryptocurrency #scam starts with an email. Potential victims must click through several web pages to finish the process. I recorded a video showing what I did after the last image in this post at youtu.be/yUV7OkQqSBk More info on this activity at github.com/PaloAltoNetw...
The scam starts with an email that links to a suspicious web page.  I've somehow earned $138,246.83 USD...  Let's go down this rabbit hole!Hey, these pages say I already have an account, but I've not been on it for 364 days...  Those fools!  I'd better click my way through this.Wow, an account I didn't even know I had!  I just want my money.  Better keep on clicking!A progress bar?  What the what???  This made me wait several minutes before I could continue.  See the video at https://youtu.be/yUV7OkQqSBk for what happened after.
131
Brad @malware-traffic-analysis.net · 16/10/2025
2025-10-16 (Thursday): Unidentified #stealer/#Loader found when searching for URLs that follow patterns previously seen for Koi Loader/Koi Stealer. Details at github.com/malware-traf...
Page to download the initial file.HTTPS URLs seen from the infection.Traffic from the infection filtered in Wireshark.Example of post-infection data exfiltration traffic.
011
Brad @malware-traffic-analysis.net · 11/10/2025
2025-10-10 (Friday): Was looking for Koi Loader/Koi Stealer, and I found this #WebDAV server that hosted malicious Windows shortcut (#LNK) files. Not sure what type of #malware this is, but it's not Koi Stealer. Details at github.com/malware-traf...
Malicious Windows shortcut (LNK) files on the WebDAV server.  Both are the same file with different names.Traffic from the initial infection filtered in Wireshark.Malware that was persistent on the infected Windows host.Post-infection traffic generated by the peristent malware.
142
Brad @malware-traffic-analysis.net · 09/10/2025
2025-10-08 (Wednesday): #Kongtuke campaign fake CAPTCHA page with #ClickFix instructions. Got a full infection chain, this time. A 205MB zip download makes the #pcap take a while to load in Wireshark. Some IOCs and associated malware/artifacts at www.malware-traffic-analysis.net/2025/10/08/i...
Traffic from the infection filtered in Wireshark.Page from a compromised site with injected Kongtuke script.Fake CAPTCHA page, courtesy of the Kongtuke campaign.Following instructions from the Kongtuke campaign's fake CAPTCHA page.
031
Brad @malware-traffic-analysis.net · 07/10/2025
2025-10-06 (Monday): A collection of 200+ phishing emails in Japanese that were sent to my blog email addresses. Available at www.malware-traffic-analysis.net/2025/10/06/i...
Screen shot of the blog post.
031
Brad @malware-traffic-analysis.net · 07/10/2025
2025-10-02 (Thursday): #pcap and some images from an Android malware infection at www.malware-traffic-analysis.net/2025/10/02/i...
Screenshot of icon for the malicious app on a cell phone.Screenshot of the login screen for the malicious app on a cell phone.It's asking me to place a credit card on the phone.Traffic from an infection filtered in Wireshark.
022
Brad @malware-traffic-analysis.net · 06/10/2025
2025-10-01 (Wed) I've posted #malware samples and a #pcap of the post-infection traffic from an infection by possible #Rhadamanthys malware at www.malware-traffic-analysis.net/2025/10/01/i... This is from a file disguised as a cracked version of software, and I usually see #LummaStealer from this.
Screenshot of the page from my website with the post for this information.Example of path to download the initial 7-zip archive for the malware.Page with the download for the initial 7-zip archive.Traffic from the possible Rhadamanthys malware, filtered in Wireshark.
123
Brad @malware-traffic-analysis.net · 02/10/2025
Time to update this movie for Halloween.
030