Cisco Live Amsterdam 2026: Malicious trojan file sent over POP3 email

Original Entry by : Sundarram Paravastu

Sundarram Paravastu, Principal Software Engineer, Endace


Overview

At each Security Operations Center (SOC) event, we capture and inspect every packet from start of show through to the very last hour, for the purpose of securing the attendees and conference, wiping the data at the end.

We had two of Endace’s newest EP94C8 EndaceProbes™ doing full packet capture providing unique insight into all activity on the network, delivering critical context and evidence for Incident Response and Threat Hunting teams. As part of the setup, we also had Application Dock VMs running on the EndaceProbes, extracting files where possible from unencrypted traffic, and sending rich metadata and Zeek® logs to Splunk® and Splunk Attack Analyzer®.

Stats

Count

Total files extracted

1,743,259

Total files submitted for malware analysis

55,939

Top extensions of files submitted

.xz, .gz, .pptx, .zip, .vnd, .pdf

Files extracted from email (POP3, IMAP etc.)

887

As part of SOC, we extracted more than 1.7M files and many of them were filtered out based on a known benign file list or excluded if they were duplicates of files already submitted. Within the files that were submitted, there were many files that were extracted from HTTP, POP3, IMAP etc.

Incident example: Malicious trojan file sent over email to compromise user system

There were 70+ users using POP3 emails and all their communication was in the clear. It’s worth noting that the SOC already has Splunk automation in place (using logs submitted to Splunk by EndaceProbe-hosted VMs) that notify affected users via email that their communications are using protocols (like POP3, IMAP) that expose their credentials.

In this specific incident example, we went looking for .rar files that were extracted and submitted to Splunk Attack Analyzer. Malicious .rar files have some notoriety so it was natural to look for any potential anomalies. As it turned out, there was indeed an email attachment that had malicious files in it.

The example above had a trojan file inside the archive, that was flagged as malicious.

We now had to trace that file extracted back to the user and their IP addresses for further analysis. Looking into Splunk’s file submission log, we could narrow down the hosts responsible for sending the email:

Digging further using the packet data recorded by our EndaceProbes, we were able to access all that affected user’s POP3 traffic over the two days of the conference and review it.

We analyzed the actual PCAP data related to these POP3 sessions using Wireshark™ – hosted on EndaceProbes – to find the user related to the event.

We then extracted all the files related to those POP3 sessions so they could be submitted to Splunk Attack Analyzer for further analysis.

We did not find further malicious files sent to the user other than the one we had originally found. However, some of the links in the emails were flagged as suspicious.

In this incident, we not only analyzed the files extracted at the time of capture but were also able to retrospectively get all related packets and extract all files related to the host involved in this incident. This enabled us to do very comprehensive, and conclusive, incident analysis.

Acknowledgements

This would not have been possible without the great work done by the Cisco Live EMEA SOC team, led by Jessica Oppenheimer and Ivan Berlinson.

Data collected and analyzed was the result of a team, many thanks go to the following team members:

Network Operations Center Liaisons

Cisco Security and Splunk SOC Team

Endace SOC Team

Read related Cisco Team Blogs from the Cisco Live Europe 2026 SOC: 
https://blogs.cisco.com/security/emea-soc-2026

For more Endace blogs in our SOC series, see here:
https://blog.endace.com/tag/soc/ 

Event SOC Website 
Visit Cisco’s Event SOC website for full details of the SOC setup, and download the whitepaper written by Jessica Oppenheimer:
https://www.cisco.com/site/us/en/products/security/event-soc-report.html


Govware 2025: Full packet capture reveals suspicious connections with empty data to many malicious IPs

Original Entry by : Sundarram Paravastu

Sundarram Paravastu, Principal Software Engineer, Endace


At the recent Govware 2025 event in Singapore, two of Endace’s newest EP94C8 EndaceProbes were installed in the GovWare SOC to provide full packet capture to support the conference SOC directives of Protect, Educate, and Innovate.

Full packet capture provides unique insight into all activity on the network, delivering critical context and evidence for Incident Response and Threat Hunting teams.

The EndaceProbes each hosted three VMs that were running Zeek and delivering critical log data into Splunk.  Custom Zeek script additions provided additional valuable details around clear text passwords in email and HTTP, and the use of insecure protocols.  Attendees at GovWare 2025 impressed the SOC team with a high level of security awareness resulting in a very low prevalence of clear text data and insecure protocols.  Zeek was also used for file-carving and automated submission of object to Splunk Attack Analyzer and a beta of Endace’s new Vault API used in a Cisco XDR automated workflow was field tested.

SOC Findings and Lessons Learned

A firewall incident of blocking connection to a malicious IP by firewall was reported in Cisco XDR.

Looking further into the incident, any markers for compromise was further investigated. Inspecting the packets in EndaceProbe revealed a strange pattern of successive connection creation within a short span of time (2-5ms) to different hosts. The other strange aspect was that the connection was immediately closed after receiving a response from these hosts. Adding to the suspicion was this beaconing was done within a few seconds of connecting to the Wifi network. Most of the ips being connected to on further investigation revealed were flagged and were reported to have been involved in suspicious/malware activities.

Pivoting to the hosted wireshark instance available on all EndaceProbes quickly revealed that a burst of connections were created by the host within a span of 3 milliseconds and closed immediately after receiving response:

Analyzing suspicious traffic bursts in Wireshark

Following the individual connections in Wireshark revealed that no data was being shared, and only ability to connect was being tested.

None of these IP addresses are present in any DNS lookup prior to the connection initiation and this many connections within a very short span (3ms) reveals it is likely a program doing it with a pre-existing list of IP addresses.

This is likely a beaconing to C2 infrastructure, where it is only touching base with servers to see which ones are active and the program is probably in dormant state or in the initial stage of just verifying connectivity.

Having full packet capture gave us visibility beyond the single blocked IP reported by the firewall. It allowed us to examine all other connections that were not flagged. The packet data confirmed that the IP addresses were not obtained via DNS and that the activity was triggered immediately after the host connected to the Wi-Fi network. Additionally, the captures verified that no data was transmitted during the beaconing attempts to the malicious IP addresses. As part of the investigation, we also checked whether other hosts on the network were making connections to these IPs.

Acknowledgements

Once again, our thanks go to the Cisco team lead by @Jessica Oppenheimer for the opportunity to include EndaceProbes in the GovWare SOC architecture.  The SOC team is a collection of Cisco experts across many domains who were a pleasure to work and innovate with and we came away with a great appreciation for power of the Cisco Security tools.  The Endace team was able to prove out integration innovations from previous SOC events and test these in earnest in a real-world environment in preparation for making them generally available to the market.

About GovWare

GovWare Conference and Exhibition is the region’s premier cyber information and connectivity platform, offering multi-channel touchpoints to drive community intel sharing, training, and strategic collaborations.

A trusted nexus for over three decades, GovWare unites policymakers, tech innovators, and end-users across Asia and beyond, driving pertinent dialogues on the latest trends and critical information flow. It empowers growth and innovation through collective insights and partnerships.

Its success lies in the trust and support from the cybersecurity and broader cyber community that it has had the privilege to serve over the years, as well as organisational partners who share the same values and mission to enrich the cyber ecosystem.

Read More

For more blogs in our Endace SOC series, see here:
https://blog.endace.com/tag/soc/