← Back to feed
Threat Actors & CampaignsEmerging1 sourceMay 8, 2026 · 11:49via Netresec

Remcos Alerts from FlowCarp in EveBox

Brief

There is a wonderful little web-based alert and event front-end called EveBox, which renders Eve JSON formatted data to a web UI. This blog post demonstrates how EveBox can be used to show alert and flow information that FlowCarp has extracted from a Remcos malware infection.

Remcos RAT

The starting point of my analysis will be a PCAP file with network traffic from a Remcos RAT infection, which Brad Duncan has published on Malware-Traffic-Analysis. net . The password scheme for the zip file containing the PCAP can be found here , in case you'd like to follow along and perform the same analysis steps yourself. All commands and examples in this blog post can be run in both Linux and Windows.

Read more on Netresec