network traffic analysis

Civilsphere AI VPN: v0.1.0-beta release

The AI VPN is a free software tool that provides users with an automatic network security assessment of their network traffic. Users can request a new OpenVPN or WireGuard VPN profile via email or Telegram, connect to it for a predefined amount of time (hours to days), and receive a full report after their VPN profile expires.

Capturing and Detecting AndroidTester Remote Access Trojan with the Emergency VPN

In this blog post, we show how the Emergency VPN can help identify RAT infections on Android phones. The images and network traffic included in this blog post are part of the original research by Civilsphere researcher Kamila Babayeva on the Android Mischief Dataset.

Civilsphere AI VPN: v0.1-alpha pre-release

The AI VPN is a free software tool that provides users with an automatic network security assessment of their network traffic. Users can request a new VPN profile via email, connect to it for a predefined amount of time (hours to days), and receive a full report after their VPN profile expires.

36c3 Chaos West: Emergency VPN, Analyzing Mobile Network Traffic to Detect Digital Threats

Our team had the opportunity to present a talk at the Chaos West stage on the 36th Chaos Communication Congress (36c3) in Leipzig. The 36c3 is the biggest hacker conference in Europe and it gathers every year more than 16,000 attendees from all over the world. Slides available.

Use of Facebook UDP Priming Revealed in Unencrypted UDP Connection to port 33000

Early this year we observed suspicious UDP connections to port 33000 in a mobile device. This traffic contained a Facebook URL that included a Facebook Graph token, and it was sent unencrypted over the network. In this blog post we show details of this traffic, what information is leaked, and who is affected. We have reported this behavior to Facebook, who confirmed this traffic is part of Facebook’s normal behavior.