Elektrine
Log in Register
Paige Chat Timeline Gallery Friends Email Drive DNS Private DNS Domains VPN Kairo Nerve
Remote

𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲

@netresec@infosec.exchange
mastodon 4.8.0-alpha.3+glitch
  • Open on infosec.exchange

Experts in Network Forensics and Network Security Monitoring. Creators of #NetworkMiner, #CapLoader, #PolarProxy, #FlowCarp and #RawCap.

#PCAP or it didn't happen!

1268 Followers
675 Following
30 Posts
Joined November 01, 2022
Blog:
https://www.netresec.com/?page=Blog
Bluesky:
https://bsky.app/profile/netresec.com
Twitter:
https://x.com/netresec
GitHub:
https://github.com/Netresec
RSS:
https://www.netresec.com/rss.ashx
Open post
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec@infosec.exchange
· 5mo ago
Replying to
@bagder@mastodon.social LOL! The report concluded it found five “Confirmed security vulnerabilities”. I think using the term confirmed is a little amusing when the AI says it confidently by itself. Yes, the AI thinks they are confirmed, but the curl security team has a slightly different take.
12
0
1
0
Open post
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec@infosec.exchange
· 2mo ago
Replying to
@james_inthe_box@infosec.exchange @da_667@infosec.exchange Nice! Another alternative is to use FlowCarp. It has really good detection for ScreenConnect in TLS. Here's the output from the free FlowCarp demo service.
2
0
0
0
Open post
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec@infosec.exchange
· 3mo ago
Replying to
@james_inthe_box@infosec.exchange Thanks! Looks like the Vidar C2 is here: 📡 172.67.216.246:443 (CLOUDFLARENET ASN 13335) 🌐 hxxps://lot.terangsm188[.]top 🫆 a0e9f5d64349fb13191bc781f81f42e1 (JA3) 🫆 6d6b821affda5de6562d217770a7ead0 (JA3S) 🫆 t12d190800_d83cc789557e_7af1ed941c26 (JA4)
2
0
0
0
Open post
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec@infosec.exchange
· 2mo ago
Replying to
@james_inthe_box@infosec.exchange AS200051 https://threatfox.abuse.ch/asn/200051/
threatfox.abuse.ch
1
0
0
0
Open post
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec@infosec.exchange
· 2mo ago
Replying to
@james_inthe_box@infosec.exchange Thank you for sharing! The #PureLogs C2 server seems to be on 2.27.62.123:4449 Turns out JoeSandbox has history for that C2 server since at least 2026-04-08. https://www.joesandbox.com/analysis/search?ioc-public-ip=2.27.62.123
joesandbox.com
1
2
0
0
Open post
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec@infosec.exchange
· 2mo ago
Replying to
More on why you shouldn't use the label/tag zgRAT https://netresec.com/?b=267e877
netresec.com
1
1
1
0
Open post
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec@infosec.exchange
· 7mo ago

21 of the world's best intelligence and security agencies cannot be wrong... right?
https://netresec.com/?b=26233f4

netresec.com
8
1
2
0
Open post
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec@infosec.exchange
· 2mo ago
Replying to
@abuse_ch@ioc.exchange Here's another sample from December 2025 using the same technique. https://hybrid-analysis.com/sample/8b516c5c05ddbfbb2022976f049b73a8ad909f0db4a65a720fe5d9ce0bea9c95/693161ad4c5505cf7405d2da
hybrid-analysis.com
1
0
0
0
Open post
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec@infosec.exchange
· 2mo ago
Replying to
@threatinsight@infosec.exchange Here's the output from FlowCarp for that C2 traffic.
1
1
0
0
Open post
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec@infosec.exchange
· 2mo ago
Replying to
@james_inthe_box@infosec.exchange C2 server seems to be on 141.98.10.150:14642 curl -s --data-binary @260716-pq5hpadv4p-behavioral1.pcapng https://demo.flowcarp.com | jq -s -c 'map(select(.event_type=="alert")|[(.dest_ip + ":" + (.dest_port|tostring)), .alert.signature])|unique[]' ["141.98.10.150:14642","MALWARE protocol detected: TLS, Remcos"]
demo.flowcarp.com
1
0
0
0
Open post
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec@infosec.exchange
· 11mo ago

The technical detail in this PureRAT analysis by Heejae Hwang (황희재) is fantastic! The analyzed #PureRAT sample looks very similar to the one James Northey recently blogged about for @huntress@infosec.exchange. It even uses the same C2 server 157.66.26.209:56001.

저작권 위반 안내 메일로 위장한 PureHVNC 악성코드 유포 사례
PLAINBIT

저작권 위반 안내 메일로 위장한 PureHVNC 악성코드 유포 사례

1. 개요 지난 6월 13일경, 자사 대표 메일 계정으로 ‘웹사이트에 게시된 콘텐츠와 관련된 공식 안내문’이라는 제목의 메일이 수신되었다. 본 글에서는 해당 스피어피싱 이메일에 대한 메일 헤더, 본문, 첨부된 악성 링크와 다운로드 되는 파일들에 대한 분석 내용을 기술한다. 2. 수신된 메일 분석 2.1. 메일 헤더 * 발신자 이메일 주소는 deunofujioemnipeggymaxim4085@

1
0
3
0
Open post
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec@infosec.exchange
· 2mo ago
Replying to
@threatinsight@infosec.exchange PureRAT often gets misclassified as zgRAT. Possibly due to the EmergingThreats 2035595 signature, which is very prone to false positives.
0
3
0
0
Open post
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec@infosec.exchange
· 2mo ago
Replying to
@threatinsight@infosec.exchange PCAP from https://app.any.run/tasks/5e178f26-657d-4d0f-ab14-6f87f1212662
Analysis jenniferloeffler(1).zip (MD5: B5D8C31CF8ECCBA98632038764748B2B) Malicious activity - Interactive analysis ANY.RUN
app.any.run

Analysis jenniferloeffler(1).zip (MD5: B5D8C31CF8ECCBA98632038764748B2B) Malicious activity - Interactive analysis ANY.RUN

Interactive malware hunting service. Live testing of most type of threats in any environments. No installation and no waiting necessary.

0
1
0
0
Open post
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec@infosec.exchange
· 2mo ago
Replying to
@threatinsight@infosec.exchange Here's another good sandbox execution on Triage with the same PureRAT C2. https://tria.ge/260702-f3fwesat5n/behavioral2
tria.ge

 14381889755a603d08a3191c48912cdddf7e0fce3ad244966789abf8d1390550 | Triage™

Check this report malware sample 14381889755a603d08a3191c48912cdddf7e0fce3ad244966789abf8d1390550, with a score of 8 out of 10.

0
0
0
0
Open post
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec@infosec.exchange
· 2mo ago
Replying to
@neurovagrant@masto.deoan.org The C2 commands were also documented back in 2020. https://www.netscout.com/blog/asert/dropping-anchor
netscout.com
0
0
0
0
Open post
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec@infosec.exchange
· 2mo ago
Replying to
FlowCarp classifies 79.110.49.15:39001 as PureMiner and the other ones as PureRAT or TLS, PureRAT. The TLS prefix means that PureRAT C2 traffic is encrypted using TLS. Some of the traffic sent to FlowCarp for 196.251.86.238:56001 used proper TLS, while other sessions used a defunct TLS implementation that FlowCarp identifies as just PureRAT.
0
4
0
0
Open post
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec@infosec.exchange
· 2mo ago
Replying to
The broken TLS implementation in PureRAT has been described in our blog post PureRAT = ResolverRAT = PureHVNC. Examples of such broken TLS traffic to 196.251.86.238:56001 can be found on JoeSandbox and ANY.RUN.
netresec.com
0
1
0
0
Open post
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec@infosec.exchange
· 2mo ago
Replying to
Update: There is now a win.pureminer malware family Malpedia, and 194.169.175.191:39002 has now been updated to the correct PureMiner tag on ThreatFox. 🎉 💃 😎
0
0
0
0
Open post
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec@infosec.exchange
· 2mo ago
Replying to
Update: The two zgRAT IOCs that are less than 6 months old were reported as false positives on ThreatFox. The first one has now been re-classified as PureRAT, while the second one is marked as (Unknown malware)[https://threatfox.abuse.ch/ioc/1750083/] The reason for the Unknown tag is probably because there is not yet a #PureMiner tag on Malpedia.
threatfox.abuse.ch
0
1
0
0
Open post
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec@infosec.exchange
· 3mo ago
Replying to
@da_667@infosec.exchange @james_inthe_box@infosec.exchange Here's another older PureRAT C2 from JoeSandbox with the same CN = PureRAT Agent, but on the classic 56001 PureRAT port.
0
2
0
0
Open post
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec@infosec.exchange
· 3mo ago
Replying to
@da_667@infosec.exchange @james_inthe_box@infosec.exchange Great work, thanks!
0
0
0
0
Open post
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec@infosec.exchange
· 3mo ago
Replying to
@james_inthe_box@infosec.exchange @da_667@infosec.exchange FlowCarp classifies 104.249.10.71:2555 as #PureRAT inside of TLS Feel free to verify with: curl -s --data-binary @4bd07f35-3a29-477a-8e2b-7e4d31182cd7.pcap https://demo.flowcarp.com | jq -s -c 'map(select(.event_type=="alert")|[(.dest_ip + ":" + (.dest_port|tostring)), .alert.signature])|unique[]'
demo.flowcarp.com
0
0
0
0
Open post
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec@infosec.exchange
· 1w ago
Replying to
@james_inthe_box@infosec.exchange 🔥 hxxps://billowing-boat-0c0f.piloty194.workers[.]dev
0
0
0
0
Open post
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec@infosec.exchange
· 1mo ago
Replying to
@malware_traffic@infosec.exchange Thank you for sharing! This is indeed Lumma Stealer/LummaC2. There's also a JoeSandbox execution of setup.exe: https://www.joesandbox.com/analysis/1955338/0/html
joesandbox.com
0
0
0
0
Open post
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec@infosec.exchange
· 2mo ago
Replying to
@threatinsight@infosec.exchange The C2 server on 89.34.90.99:56001 is classified as zgRAT in the IOC section of the Cruciferra report. That's most likely a misclassification. This looks very much like PureRAT C2 traffic. It's even using the default PureRAT TCP port 56001.
0
4
0
0
Open post
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec@infosec.exchange
· 2mo ago
Replying to
@neurovagrant@masto.deoan.org They analyzed 6 year old TrickBot samples. The anchor_dns campaign was studied and reported on to great length back in 2019/2020. I can recommend reading CISA's AA20-302A report from October 2020 for more details. https://www.cisa.gov/sites/default/files/publications/AA20-302A_Ransomware%20_Activity_Targeting_the_Healthcare_and_Public_Health_Sector.pdf
cisa.gov
0
1
0
0
Open post
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec@infosec.exchange
· 1mo ago
Replying to
@bagder@mastodon.social Wow, that's more than 40Gbit/s! How far is this from the throughput limit caused by the underlying TCP layer?
0
1
0
0
Open post
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec@infosec.exchange
· 1mo ago
Replying to
@bagder@mastodon.social At this speed the throughput bottleneck might actually be TCP rather than curl. If so, at least you did a great job plotting TCP performance over localhost 🤪
0
0
0
0
Open post
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec@infosec.exchange
· 2mo ago
Replying to
@Hackread@mstdn.social The samples analyzed in the FortiGuard publication all date back to 2020. These aren’t new samples, nor is this a new tunneling method. The TrickBot anchor_dns campaign has already been documented in detail, around six years ago, across multiple reports and blog posts. https://www.cisa.gov/sites/default/files/publications/AA20-302A_Ransomware%20_Activity_Targeting_the_Healthcare_and_Public_Health_Sector.pdf https://www.netscout.com/blog/asert/dropping-anchor
cisa.gov
0
0
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

I2P eepsite

j6b6cyk6gjmepjih7jjadxgxvvf3lzzujljuu2v4biemzpg3naya.b32.i2p

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)

Legal

  • Terms of Service
  • Privacy Policy
  • Transparency Report
  • Report Abuse
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 17:48:54 UTC