NetworkMiner 2.8.1 released today! It now extracts:
πŸ–₯️ #VNC desktop graphics
πŸ€ #njRAT transfers and screenshots
🧊 #IcedID reverse VNC graphics
⌨️ #IcedID reverse VNC keylog
πŸ“‚ #BackConnect file uploads
https://netresec.com/?b=23A41e6
NetworkMiner 2.8.1 Released

I am happy to announce the release of NetworkMiner 2.8.1 today! This new release brings a VNC parser to NetworkMiner, so that screenshots, keystrokes and clipboard data can be extracted from unencrypted VNC traffic. NetworkMiner 2.8.1 additionally includes parsers for command-and-control (C2) protoc[...]

Netresec
A huge thanks to @0xThiebaut for demonstrating that IcedID’s BackConnect VNC traffic can be parsed with his PCAPeek tool.
https://github.com/0xThiebaut/PCAPeek/
GitHub - 0xThiebaut/PCAPeek: A proof-of-concept re-assembler for reverse VNC traffic.

A proof-of-concept re-assembler for reverse VNC traffic. - GitHub - 0xThiebaut/PCAPeek: A proof-of-concept re-assembler for reverse VNC traffic.

GitHub