Detecting PureLogs traffic with CapLoader
Essential information
- Published
- 10/06/2025 09:18
- Modified
- 10/06/2025 11:13
- Tags
- 2025-06-10 c2 traffic caploader network forensics pipi protocol identification purelogs purelogs stealer stealer malware
- Related entities
- 3 observables, 4 techniques (mitre), 1 malware
Description
CapLoader's Port Independent Protocol Identification feature can now detect the C2 protocol used by PureLogs Stealer malware without relying on port numbers. This capability was added in the recent 2.0 release. The blog post demonstrates this functionality using a PCAP file from malware-traffic-analysis.net. It highlights CapLoader's ability to identify protocols in TCP and UDP sessions, enhancing network security monitoring and forensics. The post also provides indicators of compromise, including a domain and IP address associated with PureLogs traffic.