Notes / Threat IntelligenceBabylon RAT C2 Client RequestBabylon RAT C2 Client Request6 February 20221 min readCategories:threat-intelligenceTags:tcp9222trojanbabylonContentsPacket detailsProtocolPortContent MD5Sample date timeASCIIHEXExternal referenceOriginal packetArchive note: This observation was migrated from the former threatdump project. It is retained as historical packet research and is not a live threat feed. Babylon RAT C2 Client RequestPacket detailsProtocolTCPPort9222Content MD5f87d7191-73c3-d4d6-ceef-d62ce5ca99fbSample date time2022-01-31 04:11:11.264ASCIIn/a HEXbdff9eff45ff9effbdff9effa4ff86ffc4ffbeffc7ffdbffeeff785c6439ffedffa4ff9dffcfffd8ffe5ff04ff12ff30ffb1ffbdffe7ffe2ffddffdcffdeffc8ffccffbefff8ff26ff01ff0ffff5ff06fffffff7ff21ffdeff02ff26ff0cff01fff5ff0aff03ffb1ffe4ffdefff0ff2bff12ff02fff8ff03ff02fffaff20ff23ffcbffc1ff9effcdffbaffc3ffc9ff91ffadff External referenceBabylon RAT PCAPCofense Babylon RAT detailsOriginal packetBytes← KUKA.WorkVisual DeviceInfoUnitronics PLC GetID →