Friday, August 13, 2021

Quick Malware Analysis: malware-traffic-analysis.net pcap from 2021-05-21 Qakbot

Thanks to Brad Duncan for sharing this Qakbot pcap!
https://www.malware-traffic-analysis.net/2021/05/21/index2.html

We did a quick analysis of this pcap on the latest version of Security Onion via so-import-pcap:
https://docs.securityonion.net/en/2.3/so-import-pcap.html

Here are some of the interesting Suricata alerts, Zeek logs, and session transcripts:













No comments:

Search This Blog

Featured Post

Security Onion Documentation printed book now updated for Security Onion 2.4.110!

We've been offering our Security Onion documentation in book form on Amazon for a few years and it's now been updated for the recent...

Popular Posts

Blog Archive