Tuesday, August 24, 2021

Quick Malware Analysis: malware-traffic-analysis.net TA551/SHATHAK + ICEDID/BOKBOT pcap from 2021-04-29

Thanks to Brad Duncan for sharing this pcap!
https://www.malware-traffic-analysis.net/2021/04/29/index.html

We did a quick analysis of this pcap on the latest version of Security Onion via so-import-pcap:
https://docs.securityonion.net/en/2.3/so-import-pcap.html

Here are some of the interesting Suricata alerts, Zeek logs, and session transcripts:









No comments:

Post a Comment

Note: Only a member of this blog may post a comment.