On 2024-11-26, a Windows host was infected with NetSupport RAT, likely delivered from modandcrackedapk.com after viewing a site named classicgrand.com. The infection involved a ZPHP malware campaign, with the host engaging in command and control (C2) communications and geo-location lookups indicative of malicious activity.
- IP Address: 10.11.26.183
- MAC Address: d0:57:7b:ce:fc:8b
- Hostname: DESKTOP-B8TQK49
- User Account Observed: oboomwald
All findings were derived from the analysis of Suricata alerts and network traffic using Wireshark and tshark filters and aggregation.
- Method: Directly taken from the provided Suricata alerts file.
- Result: The IP address
10.11.26.183was identified as the infected host.
- Method: Filtered browser protocol packets using the filter
browser. - Result: The MAC address
d0:57:7b:ce:fc:8band hostnameDESKTOP-B8TQK49were identified for the IP address10.11.26.183.
- Method: Filtered Kerberos traffic using the filter
kerberos.CNameString && ip.addr==10.11.26.183. - Result: The Kerberos authentication requests revealed the following user account:
oboomwald.
- ZPHP Malware:
- Domain:
modandcrackedapk.comwas queried and accessed. - IP Address:
193.42.38.139was used to hostmodandcrackedapk.com.
- Domain:
- NetSupport RAT:
- Domain:
geo.netsupportsoftware.comwas queried and accessed for geo-location lookups. - IP Address:
104.26.1.231was used for geo-location lookups. - IP Address:
194.180.191.64was used for C2 communications. Accessed using HTTP POST requests on port 443. - Route:
fakeurl.htmwas used for C2 communications. - User Agent:
NetSupport Manager/1.3was used in HTTP requests.
- Domain:
- Compromised Site:
- Domain:
classicgrand.comwas accessed right before ZPHP related DNS query, indicating a likely entry point.
- Domain: