Showing posts with label quick malware analysis. Show all posts
Showing posts with label quick malware analysis. Show all posts

Friday, October 31, 2025

Spooky malware analysis!

It's October 31, so let's analyze some spooky malware!


Thanks to Brad Duncan for sharing this pcap from 2025-10-08 on his malware traffic analysis site! Due to issues with Google flagging a warning for the site, we're not including the actual hyperlink but it should be easy to find.


We did a quick analysis of this pcap using Security Onion 2.4.190:

https://blog.securityonion.net/2025/10/security-onion-24190-now-available.html


If you'd like to follow along, you can do the following:



The screenshots at the bottom of this post show some of the interesting alerts and their associated AI Summaries and Guided Analysis. Keep in mind that this is not some contrived demo, we simply downloaded a recent malware PCAP from Brad Duncan's site and imported it into Security Onion. Also keep in mind that this was just a PCAP and so there was no endpoint data. Had there been endpoint data, the results would have been even more in-depth.



Want more practice? Check out our other Quick Malware Analysis posts at:

https://blog.securityonion.net/search/label/quick%20malware%20analysis


About Security Onion


Security Onion is a versatile and scalable platform that can run on small virtual machines and can also scale up to the opposite end of the hardware spectrum to take advantage of extremely powerful server-class machines.  Security Onion can also scale horizontally, growing from a standalone single-machine deployment to a full distributed deployment with tens or hundreds of machines as dictated by your enterprise visibility needs. To learn more about Security Onion, please see:
https://securityonion.net


Screenshots


Let's start with an overview of all logs generated by Security Onion:



Now let's look at just the alerts sorted by severity:


Next we'll drill into the high severity alerts and review the AI Summaries and AI Playbooks:


Here's the second high severity alert:


And the third high severity alert:


And the fourth high severity alert:


All of the above can be done with our standard free version. 

Now let's look at our new Onion AI feature available for Security Onion Pro customers. First, we ask Onion AI to summarize the activity in the date range:


(Onion AI response continued):


We can then ask Onion AI to investigate the traffic to non-standard ports:


(Onion AI response continued):


Next, we ask Onion AI to investigate specific high severity alerts starting with the CnC Checkin alert:


(Onion AI response continued):


Finally, we ask Onion AI to investigate another high severity alert for a RAT SSL Cert:


(Onion AI response continued):


Additional analysis is left as an exercise to the reader!


Monday, August 25, 2025

Quick Malware Analysis: NETSUPPORT RAT pcap from 2025-08-20

Thanks to Brad Duncan for sharing this pcap from 2025-08-20 on his malware traffic analysis site! Due to issues with Google flagging a warning for the site, we're not including the actual hyperlink but it should be easy to find.


We did a quick analysis of this pcap using Security Onion 2.4.170:

https://blog.securityonion.net/2025/08/security-onion-24170-now-available.html


If you'd like to follow along, you can do the following:



The screenshots at the bottom of this post show some of the interesting alerts and their associated AI Summaries and Guided Analysis. Keep in mind that this is not some contrived demo, we simply downloaded a recent malware PCAP from Brad Duncan's site and imported it into Security Onion. Also keep in mind that this was just a PCAP and so there was no endpoint data. Had there been endpoint data, the results would have been even more in-depth.



Want more practice? Check out our other Quick Malware Analysis posts at:

https://blog.securityonion.net/search/label/quick%20malware%20analysis


About Security Onion


Security Onion is a versatile and scalable platform that can run on small virtual machines and can also scale up to the opposite end of the hardware spectrum to take advantage of extremely powerful server-class machines.  Security Onion can also scale horizontally, growing from a standalone single-machine deployment to a full distributed deployment with tens or hundreds of machines as dictated by your enterprise visibility needs. To learn more about Security Onion, please see:
https://securityonion.net


Screenshots


Let's start with an overview of all logs generated by Security Onion:


Next, let's focus on just the alerts:


Let's start at the top of the list and work our way down. The first alert is "ET REMOTE_ACCESS NetSupport Remote Admin Checkin". We first review the AI Summary on the right and then we go through the Guided Analysis:


Continuing through the Guided Analysis:


Finishing the Guided Analysis:


Now let's move on to the "ET REMOTE_ACCESS NetSupport Remote Admin Response" alert. We start with AI Summary on the right and then go through the Guided Analysis:


Finishing the Guided Analysis:


Our next alert is "ET EXPLOIT_KIT ZPHP Domain in DNS Lookup (isonline[.]org). We start with the AI Summary on the right and then go through the Guided Analysis:


The next alert is "ET EXPLOIT_KIT ZPHP Domain in TLS SNI (isonline[.]org). We start with the AI Summary on the right and then go through the Guided Analysis:


Finishing the Guided Analysis:


Our next alert is "ET INFO DNS Query for Suspicous .icu Domain". We start with the AI Summary on the right and then go through the Guided Analysis:


Finishing the Guided Analysis:


Our final alert is "ET REMOTE_ACCESS NetSupport GeoLocation Lookup Request". We start with the AI Summary on the right and then go through the Guided Analysis:


Continuing through the Guided Analysis:


Finishing the Guided Analysis:



Thursday, July 17, 2025

Quick Malware Analysis: KOI LOADER/KOI STEALER INFECTION pcap from 2025-07-08

Thanks to Brad Duncan for sharing this pcap from 2025-07-08 on his malware traffic analysis site! Due to issues with Google flagging a warning for the site, we're not including the actual hyperlink but it should be easy to find.


We did a quick analysis of this pcap using Security Onion 2.4.160:

https://blog.securityonion.net/2025/06/security-onion-24160-now-available.html


If you'd like to follow along, you can do the following:



The screenshots at the bottom of this post show some of the interesting alerts and their associated AI Summaries and Guided Analysis. At the end, we use the new MCP server (available to Security Onion Pro customers) to ask a few questions and get some nicely formatted reports back. 



Keep in mind that this is not some contrived demo, we simply downloaded a recent malware PCAP from Brad Duncan's site and imported it into Security Onion. Also keep in mind that this was just a PCAP and so there was no endpoint data. Had there been endpoint data, the results would have been even more in-depth.


Want more practice? Check out our other Quick Malware Analysis posts at:

https://blog.securityonion.net/search/label/quick%20malware%20analysis


About Security Onion


Security Onion is a versatile and scalable platform that can run on small virtual machines and can also scale up to the opposite end of the hardware spectrum to take advantage of extremely powerful server-class machines.  Security Onion can also scale horizontally, growing from a standalone single-machine deployment to a full distributed deployment with tens or hundreds of machines as dictated by your enterprise visibility needs. To learn more about Security Onion, please see:
https://securityonion.net


Screenshots


Let's start with an overview of all logs generated by Security Onion:


Now let's look at just the alerts:


We can switch the view to Ungroup to see a little more detail:


Next, let's drill into the first alert ("ET MALWARE Win32/Koi Stealer CnC Checkin (GET)"), review the AI Summary on the right, and then start going through its Guided Analysis questions:








Now let's drill into the second alert ("ET ATTACK_RESPONSE Koi Loader/Stealer CnC Config Inbound"), review the AI Summary on the right, and then start going through its Guided Analysis questions:





Now let's drill into the third alert ("ET INFO Windows Powershell User-Agent Usage"), review the AI Summary on the right, and then start going through its Guided Analysis questions:





If you're a Security Onion Pro customer, then you can set up our MCP Server (https://docs.securityonion.net/en/2.4/mcp.html) and then start asking questions and getting nicely formatted reports. For example, we can ask to investigate all alerts for July 8:



Finally, we can ask to investigate all HTTP traffic for July 8:





Search This Blog

Featured Post

Registration Now Open for Augusta Cyber Week 2026!

Registration is now open for Augusta Cyber Week in beautiful Augusta GA from October 19, 2026 through October 24, 2026! This includes: 4-day...

Popular Posts

Blog Archive