Website: https://www.netresec.com/
Mastodon: @netresec@infosec.exchange
Also, I really like @netresec.com's ASCII art Pyramid. 😀
📆 Include "last seen" date when publishing IOCs
❌ Prune old IOCs
📜 Prioritize long lived IOCs over short lived ones
netresec.com?b=25Be9dd
Also, I really like @netresec.com's ASCII art Pyramid. 😀
📆 Include "last seen" date when publishing IOCs
❌ Prune old IOCs
📜 Prioritize long lived IOCs over short lived ones
netresec.com?b=25Be9dd
📆 Include "last seen" date when publishing IOCs
❌ Prune old IOCs
📜 Prioritize long lived IOCs over short lived ones
netresec.com?b=25Be9dd
Submit your paper showcasing cutting-edge digital forensics research.
📤 Submit here: buff.ly/BN8Jlnb
ℹ️ Conference details: buff.ly/KOw9Xpr
#DFRWS #DigitalForensics #CFP
Submit your paper showcasing cutting-edge digital forensics research.
📤 Submit here: buff.ly/BN8Jlnb
ℹ️ Conference details: buff.ly/KOw9Xpr
#DFRWS #DigitalForensics #CFP
netresec.com?b=259a5af
netresec.com?b=259a5af
🔥 e0b465d3bd1ec5e95aee016951d55640
🔥 5ab23ac79ede02166d6f5013d89738f9
📡 Huy1612-24727.portmap[.]io:24727
📡 193.161.193.99:24727
📡 147.185.221.30:54661
netresec.com?b=258f641
🔥 e0b465d3bd1ec5e95aee016951d55640
🔥 5ab23ac79ede02166d6f5013d89738f9
📡 Huy1612-24727.portmap[.]io:24727
📡 193.161.193.99:24727
📡 147.185.221.30:54661
netresec.com?b=258f641
⛳️ C2 port is often 56001, 56002 or 56003
🔢 Bot sends 04 00 00 00, then TLS handshake
🔑 Client and server run TLS 1.0
🖊️ X.509 cert is self signed
📅 X.509 cert expires 9999-12-31
netresec.com?b=2589522
⛳️ C2 port is often 56001, 56002 or 56003
🔢 Bot sends 04 00 00 00, then TLS handshake
🔑 Client and server run TLS 1.0
🖊️ X.509 cert is self signed
📅 X.509 cert expires 9999-12-31
netresec.com?b=2589522
📄 Fake PDF is downloaded over HTTPS
💾 Fake PDF is decrypted to a #PureLogs DLL
⚙️ InstallUtil.exe or RegAsm.exe is started
💉 PureLogs DLL is injected into the running process
👾 PureLogs connects to C2 server
netresec.com?b=257eead
📄 Fake PDF is downloaded over HTTPS
💾 Fake PDF is decrypted to a #PureLogs DLL
⚙️ InstallUtil.exe or RegAsm.exe is started
💉 PureLogs DLL is injected into the running process
👾 PureLogs connects to C2 server
netresec.com?b=257eead
⚠️ IP lookup alert
🔎 Better protocol identification
🐛 Bug fixes
netresec.com?b=2571527
⚠️ IP lookup alert
🔎 Better protocol identification
🐛 Bug fixes
netresec.com?b=2571527
C2 domains:
🔥 event-time-microsoft[.]org
🔥 windows-msgas[.]com
🔥 event-datamicrosoft[.]live
🔥 eventdata-microsoft[.]live
PCAP from @malware-traffic-analysis.net
infosec.exchange/@netresec/11...
C2 domains:
🔥 event-time-microsoft[.]org
🔥 windows-msgas[.]com
🔥 event-datamicrosoft[.]live
🔥 eventdata-microsoft[.]live
PCAP from @malware-traffic-analysis.net
infosec.exchange/@netresec/11...
🔎 Identifies over 250 protocols in #PCAP
🎨 Define protocols from example traffic
🇶 Extracts JA3, JA4 and SNI from QUIC
💻 10x faster user interface
netresec.com?b=256dbbc
🔎 Identifies over 250 protocols in #PCAP
🎨 Define protocols from example traffic
🇶 Extracts JA3, JA4 and SNI from QUIC
💻 10x faster user interface
netresec.com?b=256dbbc
www.cisa.gov/news-events/...
www.cisa.gov/news-events/...
📖 #Chaosreader
⛏️ #NetworkMiner
🐿️ #Suricata
🌊 #tcpflow
🦈 #Wireshark
👁️ #Zeek
netresec.com?b=255329f
📖 #Chaosreader
⛏️ #NetworkMiner
🐿️ #Suricata
🌊 #tcpflow
🦈 #Wireshark
👁️ #Zeek
netresec.com?b=255329f
🖥️ Screenshots of victim computer
📁 Transferred files
👾 Commands from C2 server
🤖 Replies from bot
🔑 Stolen credentials/passwords
⌨️ Keylog data
netresec.com?b=2541a39
🖥️ Screenshots of victim computer
📁 Transferred files
👾 Commands from C2 server
🤖 Replies from bot
🔑 Stolen credentials/passwords
⌨️ Keylog data
netresec.com?b=2541a39
netresec.com?b=2542784
netresec.com?b=2542784
🔐 QUIC
🏭 CIP (EtherNet/IP)
🏭 UMAS (over Mobdus)
👾 Remcos RAT
🔍 Improved OS fingerprinting
🐧 Better Linux integration
netresec.com?b=254caa9
🔐 QUIC
🏭 CIP (EtherNet/IP)
🏭 UMAS (over Mobdus)
👾 Remcos RAT
🔍 Improved OS fingerprinting
🐧 Better Linux integration
netresec.com?b=254caa9
📝 Edit
📃 Preferences
💡 Advanced
✍️ Change capture.pcap_ng to FALSE
netresec.com?b=2523d40
📝 Edit
📃 Preferences
💡 Advanced
✍️ Change capture.pcap_ng to FALSE
netresec.com?b=2523d40
gitlab.com/wireshark/wi...
gitlab.com/wireshark/wi...
🆔 More #JA4
🔂 Fail-open on #TLS errors
⏩ Better performance
netresec.com?b=2523c96
🆔 More #JA4
🔂 Fail-open on #TLS errors
⏩ Better performance
netresec.com?b=2523c96
netresec.com?b=2515cf0
netresec.com?b=2515cf0
📅 Dates: May 12-15, 2025
🕑 Duration: Four half-days
🌐 Type: Live Online Network Forensics Training
💵 Price: € 960 EUR
www.netresec.com?page=Training
📅 Dates: May 12-15, 2025
🕑 Duration: Four half-days
🌐 Type: Live Online Network Forensics Training
💵 Price: € 960 EUR
www.netresec.com?page=Training
Thanks to @feikeh.bsky.social and @sjhilt.hilt.zip for sharing indicators!
www.trendmicro.com/en_us/resear...
tria.ge/241023-qpfnl...
Thanks to @feikeh.bsky.social and @sjhilt.hilt.zip for sharing indicators!
www.trendmicro.com/en_us/resear...
tria.ge/241023-qpfnl...
www.helpnetsecurity.com/2024/12/05/p...
www.helpnetsecurity.com/2024/12/05/p...