Elektrine lite

โ† Feed

๐™ฝ๐™ด๐šƒ๐š๐™ด๐š‚๐™ด๐™ฒ

netresec@infosec.exchange

<p>Experts in Network Forensics and Network Security Monitoring. Creators of <a href="https://infosec.exchange/tags/NetworkMiner" class="mention hashtag" rel="tag">#<span>NetworkMiner</span></a>, <a href="https://infosec.exchange/tags/CapLoader" class="mention hashtag" rel="tag">#<span>CapLoader</span></a>, <a href="https://infosec.exchange/tags/PolarProxy" class="mention hashtag" rel="tag">#<span>PolarProxy</span></a>, <a href="https://infosec.exchange/tags/FlowCarp" class="mention hashtag" rel="tag">#<span>FlowCarp</span></a> and <a href="https://infosec.exchange/tags/RawCap" class="mention hashtag" rel="tag">#<span>RawCap</span></a>.</p><p><a href="https://infosec.exchange/tags/PCAP" class="mention hashtag" rel="tag">#<span>PCAP</span></a> or it didn&#39;t happen!</p>

Posts

  • Post #4244094

    Only 3 IOCs have been posted to ThreatFox for the confusing catch-all label zgRAT in the past 12 months. Let&#39;s clear up any issues and figure out what they actually are. 89.23.103.60:7001 is PureRAT 194.169.175.191:39002 is PureMiner (also tagged correctly as &quot;PUREMINER&quot; by Neiki ๐ŸŽ‰ ) 196.251.86.238:56001 is PureRAT

  • Post #707455

    The technical detail in this PureRAT analysis by Heejae Hwang (ํ™ฉํฌ์žฌ) is fantastic! The analyzed #PureRAT sample looks very similar to the one James Northey recently blogged about for @huntress. It even uses the same C2 server 157.66.26.209:56001.

  • Post #444504

    21 of the world&amp;#39;s best intelligence and security agencies cannot be wrong... right? https://netresec.com/?b=26233f4