About Derp
Derp is a malware infrastructure tracker and research notebook, run by one researcher and updated daily. Everything published here comes from sandbox output, malware configuration data, and community threat intelligence.
Derp.ca brings together sandbox results, malware configuration data, and community threat intelligence to give a daily view of where malware is calling home, where payloads are being served from, and which families are active right now.
The C2 tracker covers command-and-control hosts, the servers a sample is built to contact after it runs. The distribution tracker covers where payloads are served from. Those two usually look different and sit on different networks, and some families appear in one and never the other, so each gets its own count. Every day Derp publishes a rolling seven-day view across families, hosting providers, countries, ASNs, and infrastructure types, and family pages show daily unique C2 counts with added context where we have it.
The ransomware tracker follows active groups, recent victim claims, and the sectors and countries they turn up in. The ClickFix tracker follows domains serving the ClickFix lure, and the PhaaS tracker follows the ones running rented phishing kits. The npm tracker lists registry releases flagged as malicious, labelled by how far each investigation has got.
The research page is where the longer work goes: original malware analysis and threat intelligence writeups on specific samples, campaigns, infrastructure, and tradecraft. New reports go out on the RSS feed.
Derp is built and maintained by Matt Kirkland, an independent malware researcher and infrastructure analyst focused on command-and-control tracking, sandbox-derived telemetry, and practical threat intelligence. You can find him as @KirkDerpca on X and on LinkedIn. He is also in the Matrix Project Discord.
Got something interesting to share, or want to work together? Reach out at kirk@derp.ca.