Remote
Experts in Network Forensics and Network Security Monitoring. Creators of #NetworkMiner, #CapLoader, #PolarProxy, #FlowCarp and #RawCap.
#PCAP or it didn't happen!
0
Followers
0
Following
29
Posts
Joined November 01, 2022
Twitter:
GitHub:
Posts
Replying to
@malware_traffic@infosec.exchange
@malware_traffic@infosec.exchange Thank you for sharing! This is indeed Lumma Stealer/LummaC2.
There's also a JoeSandbox execution of setup.exe:
https://www.joesandbox.com/analysis/1955338/0/html
Open post
Replying to
@bagder@mastodon.social
@bagder@mastodon.social At this speed the throughput bottleneck might actually be TCP rather than curl. If so, at least you did a great job plotting TCP performance over localhost 🤪
0
0
0
0
Open post
Replying to
@bagder@mastodon.social
@bagder@mastodon.social Wow, that's more than 40Gbit/s! How far is this from the throughput limit caused by the underlying TCP layer?
0
1
0
0
Open post
Replying to
@netresec@infosec.exchange
Update: There is now a win.pureminer malware family Malpedia, and 194.169.175.191:39002 has now been updated to the correct PureMiner tag on ThreatFox. 🎉 💃 😎
0
0
0
0
Open post
Replying to
@james_inthe_box@infosec.exchange
1
0
0
0
Open post
Replying to
@james_inthe_box@infosec.exchange
@james_inthe_box@infosec.exchange Thank you for sharing! The #PureLogs C2 server seems to be on 2.27.62.123:4449
Turns out JoeSandbox has history for that C2 server since at least 2026-04-08.
https://www.joesandbox.com/analysis/search?ioc-public-ip=2.27.62.123
1
1
0
0
Open post
Replying to
@netresec@infosec.exchange
Update:
The two zgRAT IOCs that are less than 6 months old were reported as false positives on ThreatFox. The first one has now been re-classified as PureRAT, while the second one is marked as (Unknown malware)[https://threatfox.abuse.ch/ioc/1750083/] The reason for the Unknown tag is probably because there is not yet a #PureMiner tag on Malpedia.
0
1
0
0
Open post
Replying to
@netresec@infosec.exchange
More on why you shouldn't use the label/tag zgRAT
https://netresec.com/?b=267e877
1
1
1
0
Open post
Replying to
@netresec@infosec.exchange
The broken TLS implementation in PureRAT has been described in our blog post PureRAT = ResolverRAT = PureHVNC. Examples of such broken TLS traffic to 196.251.86.238:56001 can be found on JoeSandbox and ANY.RUN.
0
1
0
0
Open post
Replying to
@netresec@infosec.exchange
FlowCarp classifies 79.110.49.15:39001 as PureMiner and the other ones as PureRAT or TLS, PureRAT. The TLS prefix means that PureRAT C2 traffic is encrypted using TLS. Some of the traffic sent to FlowCarp for 196.251.86.238:56001 used proper TLS, while other sessions used a defunct TLS implementation that FlowCarp identifies as just PureRAT.
0
1
0
0
Open post
Only 3 IOCs have been posted to ThreatFox for the confusing catch-all label zgRAT in the past 12 months. Let's clear up any issues and figure out what they actually are.
89.23.103.60:7001 is PureRAT
194.169.175.191:39002 is PureMiner (also tagged correctly as "PUREMINER" by Neiki 🎉 )
196.251.86.238:56001 is PureRAT
0
1
0
0
Open post
Replying to
@abuse_ch@ioc.exchange
@abuse_ch@ioc.exchange Here's another sample from December 2025 using the same technique.
https://hybrid-analysis.com/sample/8b516c5c05ddbfbb2022976f049b73a8ad909f0db4a65a720fe5d9ce0bea9c95/693161ad4c5505cf7405d2da
0
0
0
0
Open post
Replying to
@Hackread@mstdn.social
@Hackread@mstdn.social The samples analyzed in the FortiGuard publication all date back to 2020. These aren’t new samples, nor is this a new tunneling method. The TrickBot anchor_dns campaign has already been documented in detail, around six years ago, across multiple reports and blog posts.
https://www.cisa.gov/sites/default/files/publications/AA20-302A_Ransomware%20_Activity_Targeting_the_Healthcare_and_Public_Health_Sector.pdf
https://www.netscout.com/blog/asert/dropping-anchor
0
0
0
0
Open post
Replying to
@netresec@infosec.exchange
@neurovagrant@masto.deoan.org The C2 commands were also documented back in 2020.
https://www.netscout.com/blog/asert/dropping-anchor
0
0
0
0
Open post
Replying to
@neurovagrant@masto.deoan.org
@neurovagrant@masto.deoan.org They analyzed 6 year old TrickBot samples. The anchor_dns campaign was studied and reported on to great length back in 2019/2020. I can recommend reading CISA's AA20-302A report from October 2020 for more details.
https://www.cisa.gov/sites/default/files/publications/AA20-302A_Ransomware%20_Activity_Targeting_the_Healthcare_and_Public_Health_Sector.pdf
0
1
0
0
Open post
Replying to
@netresec@infosec.exchange
@threatinsight@infosec.exchange Here's another good sandbox execution on Triage with the same PureRAT C2.
https://tria.ge/260702-f3fwesat5n/behavioral2
0
0
0
0
Open post
Replying to
@netresec@infosec.exchange
0
1
0
0
Open post
Replying to
@netresec@infosec.exchange
@threatinsight@infosec.exchange Here's the output from FlowCarp for that C2 traffic.
1
1
0
0
Open post
Replying to
@netresec@infosec.exchange
@threatinsight@infosec.exchange PureRAT often gets misclassified as zgRAT. Possibly due to the EmergingThreats 2035595 signature, which is very prone to false positives.
0
1
0
0
Open post
Replying to
@threatinsight@infosec.exchange
@threatinsight@infosec.exchange The C2 server on 89.34.90.99:56001 is classified as zgRAT in the IOC section of the Cruciferra report. That's most likely a misclassification. This looks very much like PureRAT C2 traffic. It's even using the default PureRAT TCP port 56001.
0
1
0
0
Open post
Replying to
@james_inthe_box@infosec.exchange
@james_inthe_box@infosec.exchange @da_667@infosec.exchange Nice! Another alternative is to use FlowCarp. It has really good detection for ScreenConnect in TLS. Here's the output from the free FlowCarp demo service.
2
0
0
0
Open post
Replying to
@james_inthe_box@infosec.exchange
@james_inthe_box@infosec.exchange C2 server seems to be on 141.98.10.150:14642
curl -s --data-binary @260716-pq5hpadv4p-behavioral1.pcapng https://demo.flowcarp.com | jq -s -c 'map(select(.event_type=="alert")|[(.dest_ip + ":" + (.dest_port|tostring)), .alert.signature])|unique[]'
["141.98.10.150:14642","MALWARE protocol detected: TLS, Remcos"]
1
0
0
0
Open post
Replying to
@james_inthe_box@infosec.exchange
@james_inthe_box@infosec.exchange Thanks! Looks like the Vidar C2 is here:
📡 172.67.216.246:443 (CLOUDFLARENET ASN 13335)
🌐 hxxps://lot.terangsm188[.]top
a0e9f5d64349fb13191bc781f81f42e1 (JA3)
6d6b821affda5de6562d217770a7ead0 (JA3S)
t12d190800_d83cc789557e_7af1ed941c26 (JA4)
2
0
0
0
Open post
Replying to
@da_667@infosec.exchange
@da_667@infosec.exchange @james_inthe_box@infosec.exchange Great work, thanks!
0
0
0
0
Open post
Replying to
@da_667@infosec.exchange
@da_667@infosec.exchange @james_inthe_box@infosec.exchange Here's another older PureRAT C2 from JoeSandbox with the same CN = PureRAT Agent, but on the classic 56001 PureRAT port.
0
0
0
0
Open post
Replying to
@james_inthe_box@infosec.exchange
@james_inthe_box@infosec.exchange @da_667@infosec.exchange FlowCarp classifies 104.249.10.71:2555 as #PureRAT inside of TLS
Feel free to verify with:
curl -s --data-binary @4bd07f35-3a29-477a-8e2b-7e4d31182cd7.pcap https://demo.flowcarp.com | jq -s -c 'map(select(.event_type=="alert")|[(.dest_ip + ":" + (.dest_port|tostring)), .alert.signature])|unique[]'
0
0
0
0
Open post
Replying to
@bagder@mastodon.social
@bagder@mastodon.social LOL!
The report concluded it found five “Confirmed security vulnerabilities”. I think using the term confirmed is a little amusing when the AI says it confidently by itself. Yes, the AI thinks they are confirmed, but the curl security team has a slightly different take.
1
0
1
0
Open post
21 of the world's best intelligence and security agencies cannot be wrong... right?
https://netresec.com/?b=26233f4
8
1
2
0
Open post
The technical detail in this PureRAT analysis by Heejae Hwang (황희재) is fantastic! The analyzed #PureRAT sample looks very similar to the one James Northey recently blogged about for @huntress@infosec.exchange. It even uses the same C2 server 157.66.26.209:56001.
1
0
3
0
Remote instance
infosec.exchange
Open on original server