Sign in

𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲

@netresec.com
763 followers 285 following 91 posts

Experts in Network Forensics and Network Security Monitoring. Creators of #NetworkMiner, #PolarProxy, #FlowCarp, #CapLoader and RawCap. Website: www.netresec.com Mastodon: @netresec@infosec.exchange

PostsRepliesMedia
Reposted by 𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲
Nicholas Grossman @nicholasgrossman.bsky.social · 24/09/2026
Computer crimes are already illegal. I do not think “we knowingly deployed software we can’t control” is a legitimate defense against break those laws.
321013161
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec.com · 21/09/2026
Malware family identification is hard, especially when samples are packed, encrypted or poorly classified. FlowCarp can help identify the correct malware family and reduce alert overlap. netresec.com?b=2692109
netresec.com
Unmasking Malware Families
Identifying malware families is hard. Malware samples are often packed, strings encrypted and configurations may only appear after several stages of execution. Even experienced reverse engineers can g...
022
Reposted by 𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲
Saher @saffronsec.bsky.social · 09/09/2026
Exploits, zero-days, robots, oh my! New research from @threatinsight.proofpoint.com on multiple China-aligned actors using an exploit chain with Chrome (patch-gap) and Windows zero-days and indicators of AI-assisted development. Meet BlueMoon exploit kit: www.proofpoint.com/us/blog/thre...
proofpoint.com
Once in a BlueMoon: Multiple State-Aligned Threat Actors Rapidly Adopt Novel Exploit Chain Using Chrome and Windows Zero-Days | Proofpoint US
Analyst note: Proofpoint uses the UNK_ designator to define clusters of activity that are still developing and have not been observed for long enough to receive a numerical TA designation.
185
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec.com · 08/09/2026
PolarProxy 2.0.2 is out! 🧦 SOCKS proxy tunneling 🅿️ Environment variable support ⌛️ Improved timeouts 📜 SBOM for supply chain transparency netresec.com?b=2692ad6
netresec.com
PolarProxy 2.0.2 Released
A few more handy features have been added to PolarProxy, our TLS inspection proxy. PolarProxy can now tunnel outgoing connections through SOCKS proxies and supports environment variables as an alterna...
032
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec.com · 31/08/2026
OT networks still need monitoring. We examine the Polish CHP plant hack and show how better network security monitoring could have detected the attackers before they carried out destructive actions. netresec.com?b=2686c28
netresec.com
OT Networks Still Need Monitoring
CERT Polska recently published a follow-up report detailing the hack of a Polish combined heat and power (CHP) plant in December 2025. CERT Polskas report concludes with several important recommendati...
042
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec.com · 21/08/2026
New blog post: #CNCMachineRMS C2 Protocol We analyze the malware’s binary C2 protocol, DoH usage, related infrastructure and network detection opportunities. netresec.com?b=268ee19
netresec.com
CNCMachineRMS C2 Protocol
This post describes the binary command-and-control (C2) protocol used by CNCMachineRMS, a recently identified remote access trojan (RAT). We cover how the protocol was discovered, how its infrastructu...
021
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec.com · 27/07/2026
zgRAT is a confusing catch-all label: both #PureLogs and #PureRAT commonly trigger "zgRAT" detections. Please don't label malware as #zgRAT. netresec.com?b=267e877
netresec.com
PureLogs, PureRAT and misleading zgRAT
Please stop classifying malware as zgRAT. That malware label is confusing. As far as I know, there isnt a proper definition of what zgRAT actually is. Some claim that zgRAT is the same malware family ...
011
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec.com · 25/06/2026
Pivoting on hashes and IPs ➡️ Ping32 RMM and ValleyRAT 👾 d43fdaa1f0ee09d7e5f0f94ee9df7b6c 📡 143.92.37.168:18987 (UDP) 👾 8266b00c4e45d728cef78b3f5a865f68 📡 143.92.37.168:10086 (UDP) netresec.com?b=2666e31
netresec.com
Ping32 RMM and ValleyRAT
Fareed Radzi recently blogged about a malware campaign observed earlier in June by Kasperskys GReAT team. The malware campaign embedded malicious code in VBScripts, which were distributed through What...
021
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec.com · 08/06/2026
How do You maximize IOC sharing with minimal effort?
000
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec.com · 08/06/2026
Maximizing IOC Impact: Advice on extracting, verifying, and sharing IOCs for fast, broad protection. netresec.com?b=26653f3
netresec.com
Maximizing IOC Impact
Ive been thinking about threat intelligence lately. Specifically: indicators of compromise (IOC), how and where to share them to cause maximum pain to adversaries and help as many organizations as pos...
111
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec.com · 05/06/2026
PolarProxy 2.0.1 Released 🐻‍❄️ 💨 Improved performance 🐞 Bug fixes ⚖️ Prioritizes PCAP output over throughput netresec.com?b=266dc11
netresec.com
PolarProxy 2.0.1 Released
Our TLS inspection proxy PolarProxy has been updated with bug fixes, improved performance and more reliable PCAP output. The recent PolarProxy 2.0 release added musl/Alpine compatibility and support f...
031
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec.com · 27/05/2026
New release of CapLoader 🫆 JA3/JA4/SNI extraction from multi-segment TLS handshakes 🚨 Alerts on IOCs from Rösti (rosti.​dev) 👀 OSINT lookup on BGP.​Tools/IPinfo/Netify/ScanMalware 📦️ Extracts packets from more encapsulation protocols netresec.com?b=265c041
netresec.com
CapLoader 2.1.0 Released
CapLoader has been updated to version 2.1.0. The new release comes with better JA3/JA4 extraction and integration of additional threat-intel and OSINT services. We have also added support for more enc...
022
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec.com · 22/05/2026
Tell me ChatGPT writes your articles without telling me ChatGPT writes your articles
Article in English with mixed in Persian text
052
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec.com · 18/05/2026
PolarProxy 2.0 TLS inspection proxy released 📦️ Single self-contained binary release 🔀 Improved HTTP proxy 🐳 Builds for Linux musl (Alpine) ARM/ARM64 🪄 Simplified deployment netresec.com?b=2658a26
netresec.com
PolarProxy 2.0 Released
A new major release of PolarProxy is out with a self-contained single-file binary, expanded platform support (musl/ARM), and improved container and service plumbing. PolarProxy is a transparent TLS/SS...
012
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec.com · 08/05/2026
Viewing #remcos alerts from FlowCarp in @unx.ca's #EveBox netresec.com?b=2659fc0
netresec.com
Remcos Alerts from FlowCarp in EveBox
There is a wonderful little web based alert and event front-end called EveBox, which renders Eve JSON formatted data to a graphical user interface. This blog post demonstrates how EveBox can be used t...
022
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec.com · 04/05/2026
New tool released: FlowCarp 🔍 Identifies protocols without port numbers 🔨 Build protocol detection from example traffic ➡️ Input: PCAP or PcapNG ⬅️ Output: Flows and/or Alerts netresec.com?b=265d268
netresec.com
FlowCarp Identifies Protocols
I am thrilled to announce the release of a brand new tool called FlowCarp! FlowCarp is a simple command line tool that performs a very complicated task. It identifies the application layer protocol in...
032
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec.com · 19/03/2026
This "JWT_SESSION" cookie sure looks funky, with base64 encoded data between "metaPrefix" and "metaSuffix"! 🔥 66.234.147.10:8080
GET /get HTTP/1.1
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/129.0.0.0 Safari/537.36 Edg/129.0.0.0
Cookie: JWT_SESSION=metaPrefixkiACAAABAQAAAAECEAAAAM1L1tiH44Qy0RLSmNgJuY4QAAIAAGbloIHH+mFaj0lcz5n4qezBWJ153yqgkbCxfXF6oP4a1+shwkC4ToE86FJdFnQqNqxVL+29sp1QbADpt7Pv3hV2qcZu39eKZYFtUXLIuJzQrZbKkcvDM+iG+FLLTVfFofWNOlZzTPIQVrZVwGmKr+6UIyjjKUVN8cKKY7YB3WBWLaAlAumJQxBXzTTASLK7PRel9WiO4+3z0JYvbuNpZE+FK+3ljC5594M52ArlKS4wnPdUqzsaO2t3HBDJ+A5eukIpfI2ThFWO9prBTb2bifHuOgQRqwT5aR5TzYCWrsLUs33zhHd6YFFREfLiInfefKhWnCSgRgp+43d0gRnHBVB34m7dPQpHmDeO/wKHc41E3Gvg4+I0yw/KDtJgiKjIc04Tl1+wqZXgGEyC9W0E9MiNriQv99wBroE7T2/fH17bgXCp1ob6JAmDLSQMa/T/ZPVPznYMsvWJ5ZoTFPyjFHu9sBmA59CpxthViHR//0FPDodAmhzNxO0SlGHI1OW8pGMWSqWL8ZV68SvmV03xj1J+ZfEcspHAToXo3b3II9UfMzUsllaL+6SijY327qoWLQWRmeqa31s6c7Dabp64WZqBp+xduWcN6ZG3SnKDbp1N43o5SMLMJdrqf4n0Ech6tD1ZRKHpuTaAZ59Xw6aG+9igd3Vjgap8I/+75zJsmADwmetaSuffix
Host: 66.234.147.10:8080
Connection: Keep-Alive
031
Reposted by 𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲
DFRWS @dfrws.bsky.social · 10/03/2026
✨ DFRWS EU 2026 Workshops Led by Erik Hjelmvik (Netresec, Sweden), the session is designed for practitioners and researchers working with network and memory forensics in real-world investigations. 📍 Workshop Dates 23–24 March 2026 🧿 Details here: buff.ly/oT8OtbE #MemoryForensics #PCAP #TOR
✨ DFRWS EU 2026 Workshops

Led by Erik Hjelmvik (Netresec, Sweden), the session is designed for practitioners and researchers working with network and memory forensics in real-world investigations.

📍 Workshop Dates 23–24 March 2026 
🧿 Details here:  https://buff.ly/oT8OtbE
011
Reposted by 𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲
DFRWS @dfrws.bsky.social · 05/03/2026
✨DFRWS EU 2026 Workshops All DFRWS #Workshops and Social Events are inclusive in Registration. 👍 📍 Workshop Dates 23–24 March 2026 📍 Hybrid • Linköping, Sweden Explore workshop details 👉 buff.ly/Q45nyji Register 👉 buff.ly/lsQrqiZ #NetworkTrafficAnalysis #MemoryForensics #DFIR #TorAnalysis
✨DFRWS EU 2026 Workshops

📍 Workshop Dates 23–24 March 2026
📍 Hybrid • Linköping, Sweden

Explore workshop details 👉 https://buff.ly/Q45nyji
Register 👉 https://buff.ly/lsQrqiZ
031
Reposted by 𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲
Europol @europol.europa.eu · 04/03/2026
🔐 A major phishing-as-a-service platform disrupted. Tycoon2FA enabled large-scale account compromise by bypassing MFA protections. Through Europol’s Cyber Intelligence Extension Programme, industry intelligence was turned into operational results. Read more here: ow.ly/GECE50YoZIO
084
Reposted by 𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲
Snorre Fagerland @snoffle.bsky.social · 01/03/2026
I'm interested in getting in touch with anyone who was involved in the WANK/OILZ worm outbreak at NASA/CERN/DoE in 1989. I've talked to a few folks, but there are still blanks in this story - if you were part of that please ping me.
068
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec.com · 27/02/2026
netresec.com?b=26233f4
netresec.com
CISA mixup of IOC domains
Googles Threat Intelligence Group (GTIG) and Mandiants recent Disrupting the GRIDTIDE Global Cyber Espionage Campaign report is great and it has lots of good Indicators of Compromise (IOC). Many of th...
001
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec.com · 27/02/2026
21 of the world's best intelligence and security agencies cannot be wrong... right? netresec.com?b=26233f4
GRU unit 26165 domains:
accesscan[.]org  glize[.]com
You’ve verified them, right?
You’ve verified them, right?
121
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec.com · 26/02/2026
Do CISA analysts type out IOC domains by hand? netresec.com?b=26233f4
netresec.com
CISA mixup of IOC domains
Google's Threat Intelligence Group (GTIG) and Mandiant's recent Disrupting the GRIDTIDE Global Cyber Espionage Campaign report is great and it has lots of good Indicators of Compromise (IOC). ...
001
Reposted by 𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲
DFRWS @dfrws.bsky.social · 06/02/2026
✨ DFRWS EU 2026 Workshops Led by Erik Hjelmvik (Netresec, Sweden), the session is designed for practitioners and researchers working with network and memory forensics in real-world investigations. 📍 Workshop Dates 23–24 March 2026 📍 Details here: 👉 buff.ly/oT8OtbE
✨ DFRWS EU 2026 Workshops

Hands-on Analysis of Network Packets Carved from Memory & PCAP Analysis of Unencrypted Tor Traffic

Led by Erik Hjelmvik (Netresec, Sweden), the session is designed for practitioners and researchers working with network and memory forensics in real-world investigations.

📍 Workshop Dates 23–24 March 2026 
Details here: 👉 https://buff.ly/oT8OtbE
011
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec.com · 05/02/2026
Erik Hjelmvik will run a hands-on network forensic workshop at the upcoming Digital Forensics Research Conference in Sweden. Participants will get the chance to analyze: 🔪 Packets carved from memory dumps 🧅 Unencrypted Tor traffic dfrws.org/dfrws-eu-202...
dfrws.org
DFRWS EU 2026 Workshop – Hands-on Analysis of Network Packets Carved from Memory & PCAP Analysis of Unencrypted Tor Traffic - DFRWS
021
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec.com · 02/02/2026
Decoding #njRAT C2 traffic to extract screenshots, commands and transferred files netresec.com?b=262adb9
netresec.com
njRAT runs MassLogger
njRAT is a remote access trojan that has been around for more than 10 years and still remains one of the most popular RATs among criminal threat actors. This blog post demonstrates how NetworkMiner Pr...
032
Reposted by 𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲
Joe Slowik @pylos.co · 31/01/2026
Some initial thoughts on recent disclosures concerning the December 2025 incident targeting the Polish electric sector - with a focus on #CTI elements such as attribution implications and methodology: pylos.co/2026/01/31/a...
pylos.co
Attributive Questions in High Profile Incidents
On 30 January 2026, CERT.PL published findings concerning an electric sector attack on Poland in December 2025. This report, presumably the most complete on the incident covering multiple sources a…
172
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec.com · 27/01/2026
Thank you for those kind words! 💜 www.linkedin.com/pulse/issue-...
NetworkMiner has been around for a long time, and it shows — in a good way.

It feels opinionated. It feels calm. It feels like a tool made by people who’ve already had a few bad days in incident response.

No hype. No buzzwords. Just packets telling you what happened.
022
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec.com · 26/01/2026
The early bird discount, for our live online network forensics class, expires by the end of this week. Sign up if you’d like to analyze PCAP files together with Erik Hjelmvik (creator of NetworkMiner and PolarProxy). netresec.com?b=25A2e4f
netresec.com
Online Network Forensics Class
I will teach a live online network forensics training on February 23-26. The full title of the class is Network Forensics for Incident Response, where we will analyze PCAP files containing network tra...
001
Reposted by 𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲
DFRWS @dfrws.bsky.social · 21/01/2026
DFRWS EU 2026 is seeking posters showcasing interesting digital forensics research for presentation in Linköping, Sweden, 24–27th March 2026. 📥 Submit via EasyChair (PDF) - Rolling notification until the program is full! #DFRWSEU2026 #DFRWS #DigitalForensics
001
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec.com · 20/01/2026
🎬 Video: Decoding malware C2 with #CyberChef netresec.com?b=261f535
netresec.com
Decoding malware C2 with CyberChef
This video tutorial demonstrates how malware C2 traffic can be decoded with CyberChef. The PCAP files with the analyzed network traffic can be downloaded from malware-traffic-analysis.net. CyberChef r...
022
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec.com · 10/12/2025
Big thank you to @thedfirreport.bsky.social for capturing this intrusion traffic! 🎉
010
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec.com · 10/12/2025
Keylog of attacker's hands-on keyboard actions from BackConnect VNC session
Keylog extracted from BackConnect VNC network traffic by NetworkMiner
101
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec.com · 10/12/2025
Here's one of the screenshots from the BackConnect VNC sessions in the blog post
Attacker fails to inspect ad_users.txt
100
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec.com · 10/12/2025
Extracting VNC screenshots and keylog data from #Latrodectus 🕷️ BackConnect netresec.com?b=25Cfd08
netresec.com
Latrodectus BackConnect
I recently learned that the great folks from The DFIR Report have done a writeup covering the Latrodectus backdoor. Their report is titled From a Single Click: How Lunar Spider Enabled a Near Two-Mont...
162
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec.com · 01/12/2025
NetworkMiner 3.1 Released! 🔑 More usernames, passwords and hostnames from #PCAP 💻 Improved user interface 👾 Better details from malware C2 traffic netresec.com?b=25C4039
netresec.com
NetworkMiner 3.1 Released
This NetworkMiner release brings improved extraction of artifacts like usernames, passwords and hostnames from network traffic. We have also made some updates to the user interface and continued our e...
022
Reposted by 𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲
StrikeReady Labs @strikereadylabs.com · 20/11/2025
CN #APT targeting attendees of a diabetes conference in Singapore in December attd.z23.web.core[.]windows[.]net/ATTD-ASIA-2025.zip (live link, careful!) ATTD-ASIA-2025.lnk a12357ff6c0f7b021f32b0c9cd3d01c4 ATTD-ASIA-2025.zip a8082a80cef9ccee9d7a35f5366e3afb gzv.msi 32e7dcbd26b6455974d5b2c52c3ca421 🐴
231
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec.com · 20/11/2025
C2 runs on: 🔥 portabalbufe[.]com 🔥 172.67.212.147:443 Other C2 indicators: 🔥 JA3 a0e9f5d64349fb13191bc781f81f42e1 🔥 JA4 t12d190800_d83cc789557e_7af1ed941c26 🔥 Cert hash 25aa00e75ca12bc66ff475ebe9c6bfbd466e91ed
020
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec.com · 10/11/2025
That's great! Long lived IOCs like that are golden.
000
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec.com · 06/11/2025
The boring answer is of course "it depends". But most incident responders would probably agree that a C2 IP address can be considered "old" when a couple of weeks have passed since it was last seen active.
100
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec.com · 06/11/2025
Agreed, real-world IOC decay/score varies depending on TA choices as well as the actions we take as defenders. Fantastic that you like our ASCII Pyramid of Pain 😊 Here's a CC0 licensed copy-paste friendly version: infosec.exchange/@netresec/11...
infosec.exchange
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 (@netresec@infosec.exchange)
Here's a copy-paste friendly version of our ASCII Pyramid of Pain License: CC0 ``` ,/\ ,´V_-\ IOC Pyramid ,´\/-__-\ of Pain ,´\\/-_--_-\ ,´\\\V_--TTP-_...
000
Reposted by 𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲
David J. Bianco @davidjbianco.bsky.social · 06/11/2025
I love the idea of calculating the decay rate of an IOC. It's not always strictly mathematical, because it also relies on threat actors' choices about how they use the IOCs, but as an estimate and for decision making, this seems promising. Also, I really like @netresec.com's ASCII art Pyramid. 😀
261
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec.com · 06/11/2025
Monitoring for too many old indicators not only costs money, it can even inhibit detection of real intrusions. 📆 Include "last seen" date when publishing IOCs ❌ Prune old IOCs 📜 Prioritize long lived IOCs over short lived ones netresec.com?b=25Be9dd
netresec.com
Optimizing IOC Retention Time
Are you importing indicators of compromise (IOC) in the form of domain names and IP addresses into your SIEM, NDR or IDS? If so, have you considered for how long you should keep looking for those IOCs...
131
Reposted by 𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲
DFRWS @dfrws.bsky.social · 24/09/2025
🚨 The #DFRWSEU 2026 paper submission deadline has been extended to 10th October 2025 🎉 Submit your paper showcasing cutting-edge digital forensics research. 📤 Submit here: buff.ly/BN8Jlnb ℹ️ Conference details: buff.ly/KOw9Xpr #DFRWS #DigitalForensics #CFP
031
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec.com · 24/09/2025
Gh0stKCP is a C2 transport protocol based on KCP. It has been used by malware families such as #PseudoManuscrypt and #ValleyRAT. netresec.com?b=259a5af
netresec.com
Gh0stKCP Protocol
Gh0stKCP is a command-and-control (C2) transport protocol based on KCP. It has been used by malware families such as PseudoManuscrypt and ValleyRAT/Winos4.0. @Jane_0sint recently tweeted about ValleyR...
032
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec.com · 21/08/2025
Video: Detecting #XenoRAT C2 connections using example traffic from known malware sample. 🔥 e0b465d3bd1ec5e95aee016951d55640 🔥 5ab23ac79ede02166d6f5013d89738f9 📡 Huy1612-24727.portmap[.]io:24727 📡 193.161.193.99:24727 📡 147.185.221.30:54661 netresec.com?b=258f641
netresec.com
Define Protocol from Traffic (XenoRAT)
This video shows how to define a protocol in CapLoader just by providing examples of what the protocol looks like. CapLoader can then identify that protocol in other traffic, regardless of IP address ...
011
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec.com · 15/08/2025
The threat actor then drops #PureRAT on the victim's PC infosec.exchange/@netresec/11...
infosec.exchange
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 (@netresec@infosec.exchange)
Attached: 1 image @BleepingComputer It then drops #PureRAT aka #ResolverRAT on the victim's PC.
000
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec.com · 12/08/2025
IOCs from the blog post: 🔥 193.26.115.125:8883 🔥 purebase.ddns[.]net:8883 🔥 45.74.10.38:56001 🔥 139.99.83.25:56001
010