logo

A Beginner's Guide to Tracking Malware Infrastructure

ID: b4503259-b1ee-5d76-b713-0dbeeb6a9cef

STIX ID: report--b4503259-b1ee-5d76-b713-0dbeeb6a9cef

Feed Name: Censys Blog

Threat Score
70/100

Date Published: 2024-02-09

Date Updated: 2026-04-27

Author: Ivonne Francia; Embee Research

...
...

This write-up explains methods for building infrastructure queries to discover malware command-and-control and distribution servers by leveraging recurring indicators such as TLS certificate fields, HTTP titles/bodies, service banners, ASN/location, open directories, and regular expressions; it provides concrete examples and prebuilt Censys queries for several malware families (AsyncRAT, Cobalt Strike, Mythic, Havoc, DarkComet, Amadey, Qakbot, BianLian, Viper) to aid hunting and IOC generation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.