<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>malware &#8211; ViriBack Blog</title>
	<atom:link href="https://viriback.com/tag/malware/feed/" rel="self" type="application/rss+xml" />
	<link>https://viriback.com</link>
	<description>Malware Tracker, IOCs &#38; more ...</description>
	<lastBuildDate>Mon, 26 Dec 2022 20:42:36 +0000</lastBuildDate>
	<language>en-CA</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.9.4</generator>

<image>
	<url>https://viriback.com/wp-content/uploads/2019/01/cropped-android-chrome-512x512-32x32.png</url>
	<title>malware &#8211; ViriBack Blog</title>
	<link>https://viriback.com</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>C2 Tracker : ++ScreenShots</title>
		<link>https://viriback.com/c2-tracker-screenshots/</link>
		
		<dc:creator><![CDATA[Viriback]]></dc:creator>
		<pubDate>Mon, 09 Dec 2019 02:17:14 +0000</pubDate>
				<category><![CDATA[News]]></category>
		<category><![CDATA[c2]]></category>
		<category><![CDATA[login]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[tracker]]></category>
		<guid isPermaLink="false">https://viriback.com/?p=176</guid>

					<description><![CDATA[  I added a new feature to the Malware C2 Tracker. Hovering with the mouse cursor over a specific C2 panel login page will provide a screenshot of the page when added to the crawler. This feature is powered by URLScan.io Whenever I add a new panel url to the tracker , it will also  [...]]]></description>
										<content:encoded><![CDATA[


<p>I added a new feature to the Malware C2 Tracker.</p>



<p>Hovering with the mouse cursor over a specific C2 panel login page will provide a screenshot of the page when added to the crawler. This feature is powered by <a href="https://urlscan.io/">URLScan.io</a></p>



<p>Whenever I add a new panel url to the tracker , it will also be added to URLScan for crawling. Furthermore, clicking on the panel url will open a new window to the URLScan report.<br /><br />Proper tags will be added to the submission on URLScan for better clustering.<br /><br />I hear good news and new features are coming to URLScan that will leverage tags and similarity between submissions.<br /><br />Here is an example provided by the tracker: <a href="https://urlscan.io/result/a0f1024f-8a47-47df-9d7b-10b3503f9ef5/">PredatorTheThief</a></p>



<figure class="wp-block-image size-large"><img fetchpriority="high" decoding="async" width="1024" height="566" class="wp-image-179" src="https://viriback.com/wp-content/uploads/2019/12/urlscan-1024x566.png" alt="Predator The Thief malware submission" srcset="https://viriback.com/wp-content/uploads/2019/12/urlscan-300x166.png 300w, https://viriback.com/wp-content/uploads/2019/12/urlscan-768x425.png 768w, https://viriback.com/wp-content/uploads/2019/12/urlscan-1024x566.png 1024w, https://viriback.com/wp-content/uploads/2019/12/urlscan.png 1183w" sizes="(max-width: 1024px) 100vw, 1024px" /></figure>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>After 1000 malware C2 panels</title>
		<link>https://viriback.com/after-a-1000-malware-c2-panels/</link>
		
		<dc:creator><![CDATA[Viriback]]></dc:creator>
		<pubDate>Sat, 02 Nov 2019 13:54:04 +0000</pubDate>
				<category><![CDATA[News]]></category>
		<category><![CDATA[c2]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[panels]]></category>
		<category><![CDATA[stats]]></category>
		<guid isPermaLink="false">https://viriback.com/?p=163</guid>

					<description><![CDATA[Its been 5 months since I started recording the malware C2 panels I see during my online endeavours... Today I busted the 1000 panels, here are quick stats about these panels: So far the number distince malware families is : 43Here is a pie chart of the Top 10 families I have seen live and  [...]]]></description>
										<content:encoded><![CDATA[
<p>Its been 5 months since I started recording the malware C2 panels I see during my online endeavours&#8230; Today I busted the 1000 panels, here are quick stats about these panels:</p>



<figure class="wp-block-image"><img decoding="async" width="852" height="714" class="wp-image-164" src="https://viriback.com/wp-content/uploads/2019/11/stats.png" alt="" srcset="https://viriback.com/wp-content/uploads/2019/11/stats-300x251.png 300w, https://viriback.com/wp-content/uploads/2019/11/stats-768x644.png 768w, https://viriback.com/wp-content/uploads/2019/11/stats.png 852w" sizes="(max-width: 852px) 100vw, 852px" /></figure>



<p>So far the number distince malware families is : 43<br /><br />Here is a pie chart of the Top 10 families I have seen live and recorded:</p>



<figure class="wp-block-image"><img decoding="async" width="735" height="682" class="wp-image-165" src="https://viriback.com/wp-content/uploads/2019/11/top10pie.png" alt="" srcset="https://viriback.com/wp-content/uploads/2019/11/top10pie-300x278.png 300w, https://viriback.com/wp-content/uploads/2019/11/top10pie.png 735w" sizes="(max-width: 735px) 100vw, 735px" /></figure>



<p>The worlwide geographical distribution of the IP addresses is similar to the first month of recording, however, Russia is far more colored this time.</p>



<figure class="wp-block-image"><img decoding="async" width="1024" height="539" class="wp-image-166" src="https://viriback.com/wp-content/uploads/2019/11/world-1024x539.png" alt="" srcset="https://viriback.com/wp-content/uploads/2019/11/world-300x158.png 300w, https://viriback.com/wp-content/uploads/2019/11/world-768x404.png 768w, https://viriback.com/wp-content/uploads/2019/11/world-1024x539.png 1024w, https://viriback.com/wp-content/uploads/2019/11/world.png 1087w" sizes="(max-width: 1024px) 100vw, 1024px" /></figure>



<p>These are the top 15 ips seen :</p>



<figure class="wp-block-image"><img decoding="async" width="1024" height="629" class="wp-image-170" src="https://viriback.com/wp-content/uploads/2019/11/topips-1-1024x629.png" alt="" srcset="https://viriback.com/wp-content/uploads/2019/11/topips-1-300x184.png 300w, https://viriback.com/wp-content/uploads/2019/11/topips-1-768x472.png 768w, https://viriback.com/wp-content/uploads/2019/11/topips-1-1024x629.png 1024w, https://viriback.com/wp-content/uploads/2019/11/topips-1.png 1043w" sizes="(max-width: 1024px) 100vw, 1024px" /></figure>



<p>Here is a Top 13 distribution according to respective ASN:</p>



<figure class="wp-block-image"><img decoding="async" width="1024" height="629" class="wp-image-172" src="https://viriback.com/wp-content/uploads/2019/11/topas-1024x629.png" alt="" srcset="https://viriback.com/wp-content/uploads/2019/11/topas-300x184.png 300w, https://viriback.com/wp-content/uploads/2019/11/topas-768x472.png 768w, https://viriback.com/wp-content/uploads/2019/11/topas-1024x629.png 1024w, https://viriback.com/wp-content/uploads/2019/11/topas.png 1151w" sizes="(max-width: 1024px) 100vw, 1024px" /></figure>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
