A Beginner's Guide to Tracking Malware Infrastructure
ID: b4503259-b1ee-5d76-b713-0dbeeb6a9cef
STIX ID: report--b4503259-b1ee-5d76-b713-0dbeeb6a9cef
Feed Name: Censys Blog
This write-up explains methods for building infrastructure queries to discover malware command-and-control and distribution servers by leveraging recurring indicators such as TLS certificate fields, HTTP titles/bodies, service banners, ASN/location, open directories, and regular expressions; it provides concrete examples and prebuilt Censys queries for several malware families (AsyncRAT, Cobalt Strike, Mythic, Havoc, DarkComet, Amadey, Qakbot, BianLian, Viper) to aid hunting and IOC generation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
