#CapLoader
CapLoader 2.0.1 Released
⚠️ IP lookup alert
🔎 Better protocol identification
🐛 Bug fixes
netresec.com?b=2571527
CapLoader 2.0.1 Released
This update resolves several minor bugs, but also brings better protocol identification and a new IP lookup alert to CapLoader. Alert for IP lookup using ip-api.com in PCAP from tria.ge Transcript of ...
netresec.com
July 1, 2025 at 1:58 PM
Downloaded a fresh pcap from any.​run to verify that #CapLoader identifies this traffic as ​Socks5Systemz backconnect ✅
app.any.run/tasks/c1b2dc...
December 5, 2024 at 3:35 PM
New release of CapLoader
🫆 JA3/JA4/SNI extraction from multi-segment TLS handshakes
🚨 Alerts on IOCs from Rösti (rosti.​dev)
👀 OSINT lookup on BGP.​Tools/IPinfo/Netify/ScanMalware
📦️ Extracts packets from more encapsulation protocols
netresec.com?b=265c041
CapLoader 2.1.0 Released
CapLoader has been updated to version 2.1.0. The new release comes with better JA3/JA4 extraction and integration of additional threat-intel and OSINT services. We have also added support for more enc...
netresec.com
May 27, 2026 at 9:36 AM
CapLoader 2.0 released today!
🔎 Identifies over 250 protocols in #PCAP
🎨 Define protocols from example traffic
🇶 Extracts JA3, JA4 and SNI from QUIC
💻 10x faster user interface
netresec.com?b=256dbbc
CapLoader 2.0 Released
I am thrilled to announce the release of CapLoader 2.0 today! This major update includes a lot of new features, such as a QUIC parser, alerts for threat hunting and a feature that allow users to defin...
netresec.com
June 2, 2025 at 3:56 PM
Video: Detecting #XenoRAT C2 connections using example traffic from known malware sample.
🔥 e0b465d3bd1ec5e95aee016951d55640
🔥 5ab23ac79ede02166d6f5013d89738f9
📡 Huy1612-24727.portmap[.]io:24727
📡 193.161.193.99:24727
📡 147.185.221.30:54661
netresec.com?b=258f641
Define Protocol from Traffic (XenoRAT)
This video shows how to define a protocol in CapLoader just by providing examples of what the protocol looks like. CapLoader can then identify that protocol in other traffic, regardless of IP address ...
netresec.com
August 21, 2025 at 1:22 PM
C2 servers of newly discovered Aurotun Stealer:
👾 45.227.252.199:7712
👾 46.4.119.125:7712
👾 62.60.226.101:40101
👾 62.60.226.101:40105
👾 62.60.226.114:40101
👾 146.190.108.105:7712
👾 155.138.150.12:7712
👾 198.251.84.107:7712
#aurotunstealer #threatintel
April 16, 2025 at 7:36 AM
Is this a new ValleyRAT variant from #silverfox (银狐) or a completely new malware?
Custom protocol over TCP 443. C2 traffic starts with `BFuck\0\0\0` = `42 46 75 63 6b 00 00 00`

IOCs:
`38.76.177.46:443`
`43.99.101.175:443`

https://tria.ge/260527-lq3gjscw4t
https://tria.ge/260525-t6jclsdv5m
June 9, 2026 at 10:22 AM
@james_inthe_box Here are some network indicators for the Overlord RAT C2 traffic:
IP and port: `64.89.161.167:5173`
ASN: 205759 GHOSTYNETWORKS
JA3: `725543c78edf669194c11dc7a039b56e`
JA3S: `eb1d94daa7e0344597e756a1fb6e7054`
JA4: `t13i131000_f57a46bbacb6_ab7e3b40a677`
June 2, 2026 at 8:29 AM
New release of CapLoader
🫆 JA3/JA4/SNI extraction from multi-segment TLS handshakes
🚨 Alerts on IOCs from @viql's Rösti
👀 OSINT lookup on @jonasl's ScanMalware
📦 Extracts packets from more encapsulation protocols
https://netresec.com/?b=265c041
CapLoader 2.1.0 Released
CapLoader has been updated to version 2.1.0. The new release comes with better JA3/JA4 extraction and integration of additional threat-intel and OSINT services. We have also added support for more encapsulation protocols. TLS Client Hello Reassembly TLS handshakes no longer reliably fit in a single[...]
www.netresec.com
May 27, 2026 at 9:29 AM
Found two more C2 servers with the same `Accept: */*` and `frAQBc8Wsa1xVPfvJcrgRYwTiizs2tr` strings. These ones run on TCP 5050 as well.
👾 192.253.229.223:5050 (last active December 2025)
👾 156.254.20.94:5050 (last active December 2025)

#threatintel
February 10, 2026 at 1:12 PM
Here's the full infection chain:

* `198.211.110.107:79` finger connects to finger[.]cloudyape[.]com
* `172.67.190.68:80` curl tries `cloudyape[.]com/uvey.php?holt=2` but server responds with `301 Moved Permanently` and redirects to HTTPS
* `172.67.190 […]

[Original post on infosec.exchange]
November 20, 2025 at 9:58 AM
The use of TLS is pretty much mandatory for HTTP/2, yet this #nezha backoor POSTS HTTP/2 data over TCP port 80 without encryption!
🔥 172.245.52[.]169:80
🔥 c.mid[.]al:80
https://tria.ge/251009-j26bgacj7s
https://app.any.run/tasks/952bf595-caf6-4445-b302-513295214e76
October 9, 2025 at 8:48 AM
CapLoader 2.0.1 Released
⚠️ IP lookup alert
🔎 Better protocol identification
🐛 Bug fixes
https://netresec.com/?b=2571527
@netresec
netresec.com
July 1, 2025 at 1:58 PM
@netresec
netresec.com
June 9, 2025 at 2:32 PM
@Ichinin It's probably time to record some malware hunting videos with CapLoader.
June 3, 2025 at 7:42 AM
CapLoader 2.0 released today!
🔎 Identifies over 250 protocols in #pcap
🎨 Define protocols from example traffic
🇶 Extracts JA3, JA4 and SNI from QUIC
💻 10x faster user interface
https://netresec.com/?b=256dbbc
@netresec
netresec.com
June 2, 2025 at 3:56 PM