Post #3859115
2026-07-16 13:05 UTC
@james_inthe_box@infosec.exchange C2 server seems to be on 141.98.10.150:14642
curl -s --data-binary @260716-pq5hpadv4p-behavioral1.pcapng https://demo.flowcarp.com | jq -s -c 'map(select(.event_type=="alert")|[(.dest_ip + ":" + (.dest_port|tostring)), .alert.signature])|unique[]'
["141.98.10.150:14642","MALWARE protocol detected: TLS, Remcos"]
Replies (0)
No replies.