<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>SectopRat on Saksham Anand</title>
    <link>/tags/sectoprat/</link>
    <description>Recent content in SectopRat on Saksham Anand</description>
    <generator>Hugo -- gohugo.io</generator>
    <language>en-us</language>
    <lastBuildDate>Sun, 23 Mar 2025 00:00:00 +0000</lastBuildDate>
    <atom:link href="/tags/sectoprat/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>A Game Of Probabilities | Discovering ClickFix Infrastructure</title>
      <link>/blog/clickfix-infrastructure-discovery/</link>
      <pubDate>Sun, 23 Mar 2025 00:00:00 +0000</pubDate>
      <guid>/blog/clickfix-infrastructure-discovery/</guid>
      <description>What is ClickFix? ClickFix is a social engineering technique increasingly being used by actors in the past few months. The technique relies on fooling users to run PowerShell or Terminal commands on their computers, through the use of fake error dialogue boxes. This post will look at how the domains involved in ClickFix script can be latched onto to discover additional infrastructure. The ClickFix script in this case was used to download the SectopRAT malware, you can read more about the malware itself on my friend Chris&amp;rsquo;s blog here.</description>
    </item>
  </channel>
</rss>
