Elektrine
EN
Log in Register
Paige Chat Timeline Communities Gallery Videos Email DNS VPN Uptime Kairo
Back to Timeline
Remote

𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲

@netresec@infosec.exchange
  • Open on infosec.exchange

Experts in Network Forensics and Network Security Monitoring. Creators of #NetworkMiner, #CapLoader, #PolarProxy, #FlowCarp and #RawCap.

#PCAP or it didn't happen!

0 Followers
0 Following
29 Posts
Joined November 01, 2022
Blog:
https://www.netresec.com/?page=Blog
Bluesky:
https://bsky.app/profile/netresec.com
Twitter:
https://x.com/netresec
GitHub:
https://github.com/Netresec
RSS:
https://www.netresec.com/rss.ashx

Posts

Open post
netresec
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec@infosec.exchange · 4d ago
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲
@netresec@infosec.exchange

Experts in Network Forensics and Network Security Monitoring. Creators of #NetworkMiner, #CapLoader, #PolarProxy, #FlowCarp and #RawCap. #PCAP or it didn't happen!

infosec.exchange
Replying to @malware_traffic@infosec.exchange
@malware_traffic@infosec.exchange Thank you for sharing! This is indeed Lumma Stealer/LummaC2. There's also a JoeSandbox execution of setup.exe: https://www.joesandbox.com/analysis/1955338/0/html
0
0
0
0
Open post
netresec
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec@infosec.exchange · 4d ago
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲
@netresec@infosec.exchange

Experts in Network Forensics and Network Security Monitoring. Creators of #NetworkMiner, #CapLoader, #PolarProxy, #FlowCarp and #RawCap. #PCAP or it didn't happen!

infosec.exchange
Replying to @bagder@mastodon.social
@bagder@mastodon.social At this speed the throughput bottleneck might actually be TCP rather than curl. If so, at least you did a great job plotting TCP performance over localhost 🤪
0
0
0
0
Open post
netresec
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec@infosec.exchange · 4d ago
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲
@netresec@infosec.exchange

Experts in Network Forensics and Network Security Monitoring. Creators of #NetworkMiner, #CapLoader, #PolarProxy, #FlowCarp and #RawCap. #PCAP or it didn't happen!

infosec.exchange
Replying to @bagder@mastodon.social
@bagder@mastodon.social Wow, that's more than 40Gbit/s! How far is this from the throughput limit caused by the underlying TCP layer?
0
1
0
0
Open post
netresec
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec@infosec.exchange · Aug 03, 2026
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲
@netresec@infosec.exchange

Experts in Network Forensics and Network Security Monitoring. Creators of #NetworkMiner, #CapLoader, #PolarProxy, #FlowCarp and #RawCap. #PCAP or it didn't happen!

infosec.exchange
Replying to @netresec@infosec.exchange
Update: There is now a win.pureminer malware family Malpedia, and 194.169.175.191:39002 has now been updated to the correct PureMiner tag on ThreatFox. 🎉 💃 😎
0
0
0
0
Open post
netresec
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec@infosec.exchange · Aug 03, 2026
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲
@netresec@infosec.exchange

Experts in Network Forensics and Network Security Monitoring. Creators of #NetworkMiner, #CapLoader, #PolarProxy, #FlowCarp and #RawCap. #PCAP or it didn't happen!

infosec.exchange
Replying to @james_inthe_box@infosec.exchange
@james_inthe_box@infosec.exchange AS200051 https://threatfox.abuse.ch/asn/200051/
1
0
0
0
Open post
netresec
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec@infosec.exchange · Aug 03, 2026
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲
@netresec@infosec.exchange

Experts in Network Forensics and Network Security Monitoring. Creators of #NetworkMiner, #CapLoader, #PolarProxy, #FlowCarp and #RawCap. #PCAP or it didn't happen!

infosec.exchange
Replying to @james_inthe_box@infosec.exchange
@james_inthe_box@infosec.exchange Thank you for sharing! The #PureLogs C2 server seems to be on 2.27.62.123:4449 Turns out JoeSandbox has history for that C2 server since at least 2026-04-08. https://www.joesandbox.com/analysis/search?ioc-public-ip=2.27.62.123
1
1
0
0
Open post
netresec
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec@infosec.exchange · Jul 31, 2026
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲
@netresec@infosec.exchange

Experts in Network Forensics and Network Security Monitoring. Creators of #NetworkMiner, #CapLoader, #PolarProxy, #FlowCarp and #RawCap. #PCAP or it didn't happen!

infosec.exchange
Replying to @netresec@infosec.exchange
Update: The two zgRAT IOCs that are less than 6 months old were reported as false positives on ThreatFox. The first one has now been re-classified as PureRAT, while the second one is marked as (Unknown malware)[https://threatfox.abuse.ch/ioc/1750083/] The reason for the Unknown tag is probably because there is not yet a #PureMiner tag on Malpedia.
0
1
0
0
Open post
netresec
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec@infosec.exchange · Jul 30, 2026
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲
@netresec@infosec.exchange

Experts in Network Forensics and Network Security Monitoring. Creators of #NetworkMiner, #CapLoader, #PolarProxy, #FlowCarp and #RawCap. #PCAP or it didn't happen!

infosec.exchange
Replying to @netresec@infosec.exchange
More on why you shouldn't use the label/tag zgRAT https://netresec.com/?b=267e877
1
1
1
0
Open post
netresec
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec@infosec.exchange · Jul 30, 2026
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲
@netresec@infosec.exchange

Experts in Network Forensics and Network Security Monitoring. Creators of #NetworkMiner, #CapLoader, #PolarProxy, #FlowCarp and #RawCap. #PCAP or it didn't happen!

infosec.exchange
Replying to @netresec@infosec.exchange
The broken TLS implementation in PureRAT has been described in our blog post PureRAT = ResolverRAT = PureHVNC. Examples of such broken TLS traffic to 196.251.86.238:56001 can be found on JoeSandbox and ANY.RUN.
0
1
0
0
Open post
netresec
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec@infosec.exchange · Jul 30, 2026
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲
@netresec@infosec.exchange

Experts in Network Forensics and Network Security Monitoring. Creators of #NetworkMiner, #CapLoader, #PolarProxy, #FlowCarp and #RawCap. #PCAP or it didn't happen!

infosec.exchange
Replying to @netresec@infosec.exchange
FlowCarp classifies 79.110.49.15:39001 as PureMiner and the other ones as PureRAT or TLS, PureRAT. The TLS prefix means that PureRAT C2 traffic is encrypted using TLS. Some of the traffic sent to FlowCarp for 196.251.86.238:56001 used proper TLS, while other sessions used a defunct TLS implementation that FlowCarp identifies as just PureRAT.
0
1
0
0
Open post
netresec
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec@infosec.exchange · Jul 30, 2026
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲
@netresec@infosec.exchange

Experts in Network Forensics and Network Security Monitoring. Creators of #NetworkMiner, #CapLoader, #PolarProxy, #FlowCarp and #RawCap. #PCAP or it didn't happen!

infosec.exchange
Only 3 IOCs have been posted to ThreatFox for the confusing catch-all label zgRAT in the past 12 months. Let's clear up any issues and figure out what they actually are. 89.23.103.60:7001 is PureRAT 194.169.175.191:39002 is PureMiner (also tagged correctly as "PUREMINER" by Neiki 🎉 ) 196.251.86.238:56001 is PureRAT
0
1
0
0
Open post
netresec
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec@infosec.exchange · Jul 23, 2026
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲
@netresec@infosec.exchange

Experts in Network Forensics and Network Security Monitoring. Creators of #NetworkMiner, #CapLoader, #PolarProxy, #FlowCarp and #RawCap. #PCAP or it didn't happen!

infosec.exchange
Replying to @abuse_ch@ioc.exchange
@abuse_ch@ioc.exchange Here's another sample from December 2025 using the same technique. https://hybrid-analysis.com/sample/8b516c5c05ddbfbb2022976f049b73a8ad909f0db4a65a720fe5d9ce0bea9c95/693161ad4c5505cf7405d2da
0
0
0
0
Open post
netresec
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec@infosec.exchange · Jul 23, 2026
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲
@netresec@infosec.exchange

Experts in Network Forensics and Network Security Monitoring. Creators of #NetworkMiner, #CapLoader, #PolarProxy, #FlowCarp and #RawCap. #PCAP or it didn't happen!

infosec.exchange
Replying to @Hackread@mstdn.social
@Hackread@mstdn.social The samples analyzed in the FortiGuard publication all date back to 2020. These aren’t new samples, nor is this a new tunneling method. The TrickBot anchor_dns campaign has already been documented in detail, around six years ago, across multiple reports and blog posts. https://www.cisa.gov/sites/default/files/publications/AA20-302A_Ransomware%20_Activity_Targeting_the_Healthcare_and_Public_Health_Sector.pdf https://www.netscout.com/blog/asert/dropping-anchor
0
0
0
0
Open post
netresec
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec@infosec.exchange · Jul 23, 2026
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲
@netresec@infosec.exchange

Experts in Network Forensics and Network Security Monitoring. Creators of #NetworkMiner, #CapLoader, #PolarProxy, #FlowCarp and #RawCap. #PCAP or it didn't happen!

infosec.exchange
Replying to @netresec@infosec.exchange
@neurovagrant@masto.deoan.org The C2 commands were also documented back in 2020. https://www.netscout.com/blog/asert/dropping-anchor
0
0
0
0
Open post
netresec
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec@infosec.exchange · Jul 23, 2026
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲
@netresec@infosec.exchange

Experts in Network Forensics and Network Security Monitoring. Creators of #NetworkMiner, #CapLoader, #PolarProxy, #FlowCarp and #RawCap. #PCAP or it didn't happen!

infosec.exchange
Replying to @neurovagrant@masto.deoan.org
@neurovagrant@masto.deoan.org They analyzed 6 year old TrickBot samples. The anchor_dns campaign was studied and reported on to great length back in 2019/2020. I can recommend reading CISA's AA20-302A report from October 2020 for more details. https://www.cisa.gov/sites/default/files/publications/AA20-302A_Ransomware%20_Activity_Targeting_the_Healthcare_and_Public_Health_Sector.pdf
0
1
0
0
Open post
netresec
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec@infosec.exchange · Jul 21, 2026
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲
@netresec@infosec.exchange

Experts in Network Forensics and Network Security Monitoring. Creators of #NetworkMiner, #CapLoader, #PolarProxy, #FlowCarp and #RawCap. #PCAP or it didn't happen!

infosec.exchange
Replying to @netresec@infosec.exchange
@threatinsight@infosec.exchange Here's another good sandbox execution on Triage with the same PureRAT C2. https://tria.ge/260702-f3fwesat5n/behavioral2
0
0
0
0
Open post
netresec
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec@infosec.exchange · Jul 21, 2026
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲
@netresec@infosec.exchange

Experts in Network Forensics and Network Security Monitoring. Creators of #NetworkMiner, #CapLoader, #PolarProxy, #FlowCarp and #RawCap. #PCAP or it didn't happen!

infosec.exchange
Replying to @netresec@infosec.exchange
@threatinsight@infosec.exchange PCAP from https://app.any.run/tasks/5e178f26-657d-4d0f-ab14-6f87f1212662
0
1
0
0
Open post
netresec
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec@infosec.exchange · Jul 21, 2026
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲
@netresec@infosec.exchange

Experts in Network Forensics and Network Security Monitoring. Creators of #NetworkMiner, #CapLoader, #PolarProxy, #FlowCarp and #RawCap. #PCAP or it didn't happen!

infosec.exchange
Replying to @netresec@infosec.exchange
@threatinsight@infosec.exchange Here's the output from FlowCarp for that C2 traffic.
1
1
0
0
Open post
netresec
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec@infosec.exchange · Jul 21, 2026
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲
@netresec@infosec.exchange

Experts in Network Forensics and Network Security Monitoring. Creators of #NetworkMiner, #CapLoader, #PolarProxy, #FlowCarp and #RawCap. #PCAP or it didn't happen!

infosec.exchange
Replying to @netresec@infosec.exchange
@threatinsight@infosec.exchange PureRAT often gets misclassified as zgRAT. Possibly due to the EmergingThreats 2035595 signature, which is very prone to false positives.
0
1
0
0
Open post
netresec
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec@infosec.exchange · Jul 21, 2026
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲
@netresec@infosec.exchange

Experts in Network Forensics and Network Security Monitoring. Creators of #NetworkMiner, #CapLoader, #PolarProxy, #FlowCarp and #RawCap. #PCAP or it didn't happen!

infosec.exchange
Replying to @threatinsight@infosec.exchange
@threatinsight@infosec.exchange The C2 server on 89.34.90.99:56001 is classified as zgRAT in the IOC section of the Cruciferra report. That's most likely a misclassification. This looks very much like PureRAT C2 traffic. It's even using the default PureRAT TCP port 56001.
0
1
0
0
Open post
netresec
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec@infosec.exchange · Jul 21, 2026
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲
@netresec@infosec.exchange

Experts in Network Forensics and Network Security Monitoring. Creators of #NetworkMiner, #CapLoader, #PolarProxy, #FlowCarp and #RawCap. #PCAP or it didn't happen!

infosec.exchange
Replying to @james_inthe_box@infosec.exchange
@james_inthe_box@infosec.exchange @da_667@infosec.exchange Nice! Another alternative is to use FlowCarp. It has really good detection for ScreenConnect in TLS. Here's the output from the free FlowCarp demo service.
2
0
0
0
Open post
netresec
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec@infosec.exchange · Jul 16, 2026
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲
@netresec@infosec.exchange

Experts in Network Forensics and Network Security Monitoring. Creators of #NetworkMiner, #CapLoader, #PolarProxy, #FlowCarp and #RawCap. #PCAP or it didn't happen!

infosec.exchange
Replying to @james_inthe_box@infosec.exchange
@james_inthe_box@infosec.exchange C2 server seems to be on 141.98.10.150:14642 curl -s --data-binary @260716-pq5hpadv4p-behavioral1.pcapng https://demo.flowcarp.com | jq -s -c 'map(select(.event_type=="alert")|[(.dest_ip + ":" + (.dest_port|tostring)), .alert.signature])|unique[]' ["141.98.10.150:14642","MALWARE protocol detected: TLS, Remcos"]
1
0
0
0
Open post
netresec
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec@infosec.exchange · Jul 03, 2026
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲
@netresec@infosec.exchange

Experts in Network Forensics and Network Security Monitoring. Creators of #NetworkMiner, #CapLoader, #PolarProxy, #FlowCarp and #RawCap. #PCAP or it didn't happen!

infosec.exchange
Replying to @james_inthe_box@infosec.exchange
@james_inthe_box@infosec.exchange Thanks! Looks like the Vidar C2 is here: 📡 172.67.216.246:443 (CLOUDFLARENET ASN 13335) 🌐 hxxps://lot.terangsm188[.]top 🫆 a0e9f5d64349fb13191bc781f81f42e1 (JA3) 🫆 6d6b821affda5de6562d217770a7ead0 (JA3S) 🫆 t12d190800_d83cc789557e_7af1ed941c26 (JA4)
2
0
0
0
Open post
netresec
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec@infosec.exchange · Jul 03, 2026
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲
@netresec@infosec.exchange

Experts in Network Forensics and Network Security Monitoring. Creators of #NetworkMiner, #CapLoader, #PolarProxy, #FlowCarp and #RawCap. #PCAP or it didn't happen!

infosec.exchange
Replying to @da_667@infosec.exchange
@da_667@infosec.exchange @james_inthe_box@infosec.exchange Great work, thanks!
0
0
0
0
Open post
netresec
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec@infosec.exchange · Jul 03, 2026
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲
@netresec@infosec.exchange

Experts in Network Forensics and Network Security Monitoring. Creators of #NetworkMiner, #CapLoader, #PolarProxy, #FlowCarp and #RawCap. #PCAP or it didn't happen!

infosec.exchange
Replying to @da_667@infosec.exchange
@da_667@infosec.exchange @james_inthe_box@infosec.exchange Here's another older PureRAT C2 from JoeSandbox with the same CN = PureRAT Agent, but on the classic 56001 PureRAT port.
0
0
0
0
Open post
netresec
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec@infosec.exchange · Jul 03, 2026
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲
@netresec@infosec.exchange

Experts in Network Forensics and Network Security Monitoring. Creators of #NetworkMiner, #CapLoader, #PolarProxy, #FlowCarp and #RawCap. #PCAP or it didn't happen!

infosec.exchange
Replying to @james_inthe_box@infosec.exchange
@james_inthe_box@infosec.exchange @da_667@infosec.exchange FlowCarp classifies 104.249.10.71:2555 as #PureRAT inside of TLS Feel free to verify with: curl -s --data-binary @4bd07f35-3a29-477a-8e2b-7e4d31182cd7.pcap https://demo.flowcarp.com | jq -s -c 'map(select(.event_type=="alert")|[(.dest_ip + ":" + (.dest_port|tostring)), .alert.signature])|unique[]'
0
0
0
0
Open post
netresec
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec@infosec.exchange · May 11, 2026
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲
@netresec@infosec.exchange

Experts in Network Forensics and Network Security Monitoring. Creators of #NetworkMiner, #CapLoader, #PolarProxy, #FlowCarp and #RawCap. #PCAP or it didn't happen!

infosec.exchange
Replying to @bagder@mastodon.social
@bagder@mastodon.social LOL! The report concluded it found five “Confirmed security vulnerabilities”. I think using the term confirmed is a little amusing when the AI says it confidently by itself. Yes, the AI thinks they are confirmed, but the curl security team has a slightly different take.
1
0
1
0
Open post
netresec
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec@infosec.exchange · Feb 27, 2026
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲
@netresec@infosec.exchange

Experts in Network Forensics and Network Security Monitoring. Creators of #NetworkMiner, #CapLoader, #PolarProxy, #FlowCarp and #RawCap. #PCAP or it didn't happen!

infosec.exchange

21 of the world's best intelligence and security agencies cannot be wrong... right?
https://netresec.com/?b=26233f4

8
1
2
0
Open post
netresec
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec@infosec.exchange · Oct 16, 2025
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲
@netresec@infosec.exchange

Experts in Network Forensics and Network Security Monitoring. Creators of #NetworkMiner, #CapLoader, #PolarProxy, #FlowCarp and #RawCap. #PCAP or it didn't happen!

infosec.exchange

The technical detail in this PureRAT analysis by Heejae Hwang (황희재) is fantastic! The analyzed #PureRAT sample looks very similar to the one James Northey recently blogged about for @huntress@infosec.exchange. It even uses the same C2 server 157.66.26.209:56001.

1
0
3
0

Remote instance

infosec.exchange
Open on original server

Media

313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

Platform

  • Email
  • Chat
  • Timeline
  • Communities
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ

Legal

  • Terms of Service
  • Privacy Policy
  • Warrant Canary
  • Lite (no JS)
  • VPN Policy
  • Source code

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 15:01:33 UTC