<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>mariposa on The Official Wireshark Blog</title>
    <link>https://blog.wireshark.org/tags/mariposa/</link>
    <description>Recent content in mariposa on The Official Wireshark Blog</description>
    <generator>Hugo -- gohugo.io</generator>
    <language>en-us</language>
    <lastBuildDate>Wed, 28 Oct 2009 19:05:19 +0000</lastBuildDate><atom:link href="https://blog.wireshark.org/tags/mariposa/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Using Wireshark to track a botnet</title>
      <link>https://blog.wireshark.org/2009/10/using-wireshark-to-track-a-botnet/</link>
      <pubDate>Wed, 28 Oct 2009 19:05:19 +0000</pubDate>
      
      <guid>https://blog.wireshark.org/2009/10/using-wireshark-to-track-a-botnet/</guid>
      <description>&lt;p&gt;Security researchers have written a Wireshark dissector that will decrypt the command and control protocol used by the Mariposa botnet. More information at &lt;a href=&#34;http://www.paloaltonetworks.com/researchcenter/2009/10/mariposa-tool/&#34;&gt;Palo Alto Networks&lt;/a&gt; and &lt;a href=&#34;http://defintel.blogspot.com/2009/10/mariposa-botnet-analysis.html&#34;&gt;Defence Intelligence&lt;/a&gt;.&lt;/p&gt;
&lt;h2 id=&#34;comments&#34;&gt;Comments &lt;a href=&#34;#comments&#34; class=&#34;anchor&#34;&gt;🔗&lt;/a&gt;&lt;/h2&gt;&lt;h3 id=&#34;comment-by-manonfire-on-2009-11-02-080548-0000&#34;&gt;Comment by ManOnFire on 2009-11-02 08:05:48 +0000 &lt;a href=&#34;#comment-by-manonfire-on-2009-11-02-080548-0000&#34; class=&#34;anchor&#34;&gt;🔗&lt;/a&gt;&lt;/h3&gt;&lt;p&gt;Anyone have a packet capture for mariposa C&amp;amp;C? I would like to test the decryption plugin. Thanks!&lt;/p&gt;
&lt;h3 id=&#34;comment-by-gerald-combs-on-2009-11-04-134755-0000&#34;&gt;Comment by Gerald Combs on 2009-11-04 13:47:55 +0000 &lt;a href=&#34;#comment-by-gerald-combs-on-2009-11-04-134755-0000&#34; class=&#34;anchor&#34;&gt;🔗&lt;/a&gt;&lt;/h3&gt;&lt;p&gt;You might try contacting Palo Alto Networks or Defence Intelligence. I don’t see any capture file downloads on either site.&lt;/p&gt;
</description>
    </item>
    
  </channel>
</rss>
