216.73.216.233

Detecting PureLogs traffic with CapLoader

· Published 10/06/2025 09:18 · Modified 10/06/2025 11:13

Export JSON

Essential information

Published
10/06/2025 09:18
Modified
10/06/2025 11:13
Tags
2025-06-10 c2 traffic caploader network forensics pipi protocol identification purelogs purelogs stealer stealer malware
Related entities
3 observables, 4 techniques (mitre), 1 malware

Description

's Port Independent feature can now detect the C2 protocol used by malware without relying on port numbers. This capability was added in the recent 2.0 release. The blog post demonstrates this functionality using a PCAP file from malware-traffic-analysis.net. It highlights 's ability to identify protocols in TCP and UDP sessions, enhancing network security monitoring and forensics. The post also provides indicators of compromise, including a domain and IP address associated with traffic.

External references