logo

A Practical Guide to Uncovering Malicious Infrastructure With Hunt.io

ID: af18e449-1217-5dbc-9b6b-99218243bdcc

STIX ID: report--af18e449-1217-5dbc-9b6b-99218243bdcc

Feed Name: Hunt.io Blog

Date Published: 2026-02-16

Date Updated: 2026-04-28

...
...

This guide details a step-by-step workflow for hunting adversary infrastructure with the Hunt app—starting from a suspicious IP (`168.100.9.71`) and pivoting through domains, ports/services, HTTP behavior, and TLS (JA4X) to identify a small cluster of likely malware/C2 servers, with VirusTotal hints of Latrodectus; it concludes with practical hunting tips and a concise table of IP-based IOCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.