Friday, February 28, 2025

Quick Malware Analysis: SMARTAPESG / NETSUPPORT RAT / STEALC pcap from 2025-02-18

Thanks to Brad Duncan for sharing this pcap from 2025-02-18 on his malware traffic analysis site! Due to issues with Google flagging a warning for the site, we're not including the actual hyperlink but it should be easy to find.


We did a quick analysis of this pcap using Security Onion 2.4.120:

https://blog.securityonion.net/2025/02/security-onion-24120-now-available.html


If you'd like to follow along, you can do the following:



The screenshots at the bottom of this post show some of the interesting alerts, metadata logs, and session transcripts. Want more practice? Check out our other Quick Malware Analysis posts at:

https://blog.securityonion.net/search/label/quick%20malware%20analysis


About Security Onion


Security Onion is a versatile and scalable platform that can run on small virtual machines and can also scale up to the opposite end of the hardware spectrum to take advantage of extremely powerful server-class machines.  Security Onion can also scale horizontally, growing from a standalone single-machine deployment to a full distributed deployment with tens or hundreds of machines as dictated by your enterprise visibility needs. To learn more about Security Onion, please see:
https://securityonion.net


Screenshots


First, we start with the overview of all alerts and logs:


Next, let's look at just the alerts:


If we ungroup the alerts, we can see timestamps:


Let's take a look at one of the DLL downloads by pivoting to PCAP and then switching to ASCII transcript:


Next let's look at one of the POSTs:


Looks like some of the POST data is base64 encoded so let's send that to CyberChef and decode it:


Let's look at an example of HTTP POST on port 443:


Let's look at the sqlite3.dll download:


Next let's review the Stealc alerts:


and let's pivot to PCAP for one of those:


Now let's review the Zeek metadata:


Now let's look at each of those Zeek metadata types in order starting with file transfers:


HTTP transactions:


Connections:


SSL:


PE transfers:


DNS lookups:


x509 logs:


DPD (Dynamic Protocol Detection) logs:


Software detected:


Weird logs (traffic anomalies):



No comments:

Search This Blog

Featured Post

Quick Malware Analysis: SMARTAPESG / NETSUPPORT RAT / STEALC pcap from 2025-02-18

Thanks to Brad Duncan for sharing this pcap from 2025-02-18 on his malware traffic analysis site! Due to issues with Google flagging a warni...

Popular Posts

Blog Archive