SmartApeSG ClickFix to NetSupport RAT: Reading the Whole Infection in One PCAP
A real SmartApeSG ClickFix capture from malware-traffic-analysis.net, walked end to end in the browser: from a 53 MB pile of mixed traffic to the exact PowerShell the victim pasted, the New-Object and Invoke-WebRequest loader, and the hosts that delivered NetSupport RAT.