
π½π΄πππ΄ππ΄π²
@netresec
Experts in Network Forensics and Network Security Monitoring. Creators of #NetworkMiner, #CapLoader, #PacketCache, #PolarProxy and #RawCap.
ID: 416995874
https://www.netresec.com/ 20-11-2011 11:40:57
3,3K Tweet
8,8K TakipΓ§i
803 Takip Edilen


Take π½π΄πππ΄ππ΄π² course if you are interested in learning the dark magic of analyzing PCAPs and understanding malware protocols


Did you know that NetworkMiner parses the #njRAT protocol? The following artefacts are extracted from njRAT C2 traffic: π₯οΈ Screenshots of victim computer π Transferred files πΎ C2 commands and replies π Stolen credentials/passwords β¨οΈ Keylog data netresec.com/?b=2541a39









π§ Dropper connects to legitimate website π Fake PDF is downloaded over HTTPS πΎ Fake PDF is decrypted to a #PureLogs DLL βοΈ InstallUtil.exe or RegAsm.exe is started π PureLogs DLL is injected into the running process πΎ PureLogs connects to C2 server netresec.com/?b=257eead

IOCs in blog post: π‘ 91.92.120.101:62520 π‘ 91.92.120.101:65535 πΎ 711d9cbf1b1c77de45c4f1b1a82347e6 πΎ 6ff95e302e8374e4e1023fbec625f44b πΎ e6d7bbc53b718217b2de1b43a9193786 πΎ a9bc0fad0b1a1d6931321bb5286bf6b7 πΎ 09bb5446ad9055b9a1cb449db99a7302 πΎ 38d29f5ac47583f39a2ff5dc1c366f7d
