Thursday, August 26, 2021

Quick Malware Analysis: ICEDID/BOKBOT pcap from 2021-04-23

Thanks to Brad Duncan for sharing this pcap!

We did a quick analysis of this pcap on the latest version of Security Onion via so-import-pcap:

Some of the interesting Suricata alerts, Zeek logs, and session transcripts can be seen below. Want to follow along? All you need is a minimal virtual machine with 4GB RAM and you can follow the screenshots here:

No comments: