Unusual Activity with Double Base64 Encoding, (Sun, Oct 27th)

This week I found this traffic in my honeypot, my first impression, it didn’t look that unusual since Base64 encoding is used quite a bit to encode traffic to a web server. Using CyberChef, I decoded the Base64 portion to see what it was all about only to find out it was further encoded in Base64. Decoding the second Base64 revealed two IP address in it.

Article Link: https://isc.sans.edu/diary/rss/25458