A Practical Guide to Uncovering Malicious Infrastructure With Hunt.io
ID: af18e449-1217-5dbc-9b6b-99218243bdcc
STIX ID: report--af18e449-1217-5dbc-9b6b-99218243bdcc
Feed Name: Hunt.io Blog
This guide details a step-by-step workflow for hunting adversary infrastructure with the Hunt app—starting from a suspicious IP (`168.100.9.71`) and pivoting through domains, ports/services, HTTP behavior, and TLS (JA4X) to identify a small cluster of likely malware/C2 servers, with VirusTotal hints of Latrodectus; it concludes with practical hunting tips and a concise table of IP-based IOCs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
