Skip to content
KitploitKITPLOIT
StrumentiBlog
Invia
StrumentiBlog
Invia

Strumenti di Hacking, PenTest e Cybersecurity per il tuo Arsenale di Sicurezza!

Kitploit è una directory di strumenti di hacking, cybersecurity e pentesting. Scopri gli ultimi aggiornamenti dei progetti per trovare vulnerabilità, analizzare sistemi, automatizzare i test e rafforzare la tua sicurezza.

··Feed·Contatto·Privacy·© 2026 Kitploit

Directory degli strumenti

Categorie

Vedi tutte le categorie
Loading categories
pingback — Un pacchetto Zeek per rilevare il traffico di rete del tunnel ICMP del malware Pingback per il comando e controllo (C2). | Kitploit
Strumenti/GitHubGitHub/corelight/pingback
Sicurezza di ReteAnalisi MalwareCommand and ControlThreat IntelligenceRilevamento Intrusioni
GitHubcorelight/pingback

pingback

Un pacchetto Zeek per rilevare il traffico di rete del tunnel ICMP del malware Pingback per il comando e controllo (C2).

Vedi Repository
11510 mesi faNon ancora revisionato

Più Popolari

Vedi tutti →

Scopri gli strumenti più utilizzati dalla nostra community.

Esplora tutti gli strumenti

Sfoglia la nostra collezione di strumenti

Vedi tutti gli strumenti →
Condividi

Rilevamento di Pingback C2

Un pacchetto Zeek e regole Suricata per il rilevamento di tunnel ICMP ping creati dallo strumento Pingback C2.
Post del blog di accompagnamento: https://corelight.blog/2021/05/07/pingback-icmp-tunneling-malware/

Installazione

Il modo più semplice per installare questo pacchetto è tramite zkg:

zkg install corelight/pingback

Utilizzo

Usa questo PCAP di esempio e puoi seguire qui sotto:

root@kitploit:~
$ ls
Pingback_ICMP.pcapng

$ zeek -Cr Pingback_ICMP.pcapng pingback

$ cat notice.log 
#separator \x09
#set_separator	,
#empty_field	(empty)
#unset_field	-
#path	notice
#open	2021-05-07-14-43-48
#fields	ts	uid	id.orig_h	id.orig_p	id.resp_h	id.resp_p	fuid	file_mime_type	file_desc	proto	note	msg	sub	src	dst	p	n	peer_descr	actions	suppress_for	remote_location.country_code	remote_location.region	remote_location.city	remote_location.latitude	remote_location.longitude
#types	time	string	addr	port	addr	port	string	string	string	enum	enum	string	string	addr	addr	port	count	string	set[enum]	interval	string	string	string	double	double
1619505583.332605	CH7l4D48kbE3nWo7M7	192.168.38.131	8	192.168.38.172	0	-	-	-	icmp	Pingback::Pingback_Tunnel	An ICMP ping request message may have been Pingback C2 ref:trustwave.com/en-us/resources/blogs/spiderlabs-blog/backdoor-at-the-end-of-the-icmp-tunnel/	seq=53764 , |payload|=788 , icmp_info=[v6=F, itype=8, icode=0, len=788, ttl=64] , first 20 bytes of ICMP payload=shell\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00	192.168.38.131	192.168.38.172	0	-	-	Notice::ACTION_LOG	3600.000000	-	-	-	-	-
1619505583.333021	CH7l4D48kbE3nWo7M7	192.168.38.131	8	192.168.38.172	0	-	-	-	icmp	Pingback::Pingback_Tunnel	An ICMP ping reply message may have been Pingback C2 ref:trustwave.com/en-us/resources/blogs/spiderlabs-blog/backdoor-at-the-end-of-the-icmp-tunnel/	seq=53764 , |payload|=788 , icmp_info=[v6=F, itype=0, icode=0, len=788, ttl=128] , first 20 bytes of ICMP payload=shell\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00	192.168.38.131	192.168.38.172	0	-	-	Notice::ACTION_LOG	3600.000000	-	-	-	-	-
#close	2021-05-07-14-43-48

Riferimenti aggiuntivi

  • https://www.bleepingcomputer.com/news/security/new-windows-pingback-malware-uses-icmp-for-covert-communication/
  • https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/backdoor-at-the-end-of-the-icmp-tunnel/
  • https://github.com/SpiderLabs/pingback
  • https://www.virustotal.com/gui/file/e50943d9f361830502dcfdb00971cbee76877aa73665245427d817047523667f/detection

Licenza

Copyright (c) 2021, Corelight, Inc. Tutti i diritti riservati.

La redistribuzione e l'uso in forma sorgente e binaria, con o senza modifiche, sono consentiti a condizione che siano soddisfatte le seguenti condizioni:

(1) Le redistribuzioni del codice sorgente devono conservare il copyright di cui sopra, il presente elenco di condizioni e la seguente clausola di esclusione di responsabilità.

(2) Le redistribuzioni in forma binaria devono riprodurre il copyright di cui sopra, il presente elenco di condizioni e la seguente clausola di esclusione di responsabilità nella documentazione e/o negli altri materiali forniti con la distribuzione.

(3) Né il nome di Corelight né i nomi di eventuali contributori possono essere utilizzati per approvare o promuovere prodotti derivati da questo software senza una specifica autorizzazione scritta preventiva.

QUESTO SOFTWARE È FORNITO DAI TITOLARI DEL COPYRIGHT E DAI CONTRIBUTORI "COSÌ COM'È" E QUALSIASI GARANZIA ESPRESSA O IMPLICITA, INCLUSI, MA NON LIMITATI A, LE GARANZIE IMPLICITE DI COMMERCIABILITÀ E IDONEITÀ PER UNO SCOPO PARTICOLARE SONO ESCLUSE. IN NESSUN CASO IL COPYRIGHT O I CONTRIBUTORI SARANNO RITENUTI RESPONSABILI PER DANNI DIRETTI, INDIRETTI, INCIDENTALI, SPECIALI, ESEMPLARI O CONSEQUENZIALI (INCLUSI, MA NON LIMITATI A, L'APPROVVIGIONAMENTO DI BENI O SERVIZI SOSTITUTIVI; PERDITA DI USO, DATI O PROFITTI; O INTERRUZIONE DELL'ATTIVITÀ) IN QUALSIASI MODO CAUSATI E SULLA BASE DI QUALSIASI TEORIA DI RESPONSABILITÀ, SIA IN AMBITO CONTRATTUALE, DA RESPONSABILITÀ OGGETTIVA O DA ILLECITO (INCLUSA LA NEGLIGENZA O ALTRO) DERIVANTI IN QUALSIASI MODO DALL'USO DI QUESTO SOFTWARE, ANCHE SE AVVISATI DELLA POSSIBILITÀ DI TALI DANNI.

Scarica lo strumento