Malware Traffic Investigation Using Wireshark (PCAP Analysis)
Case Overview
This investigation analyzes a packet capture file (2023-02-03.pcap) to identify suspicious activity, Indicators of Compromise (IOCs), and evidence of malware infection within a local network.
The objective was to examine network traffic, trace malicious downloads, observe post-infection behavior, and determine the overall security impact.
đ Download Full Investigation Report (PDF):
Wireshark Qakbot Malware Analysis Report
Lab Environment & Tools Used
| Category | Tools |
|---|---|
| Traffic Analysis | Wireshark |
| Threat Intelligence | VirusTotal, OSINT |
| Packet Filtering | Wireshark Display Filters |
| File Analysis | Hash extraction, file signature inspection |
| Decoding Tool | CyberChef (Base64 decoding) |
| Protocols Investigated | HTTP, ARP, ICMP, SMTP, SMB |
Initial Traffic Review
After loading the PCAP into Wireshark:
- Total packets captured: ~55,000
- Capture duration: 2 hours 50 minutes
Using Statistics â Conversations, one internal host stood out:
Suspicious Host:
10.0.0.149

This system had an unusually high number of conversations with both internal and external IP addresses.
Protocol Analysis
To understand the types of communication present in the capture, the Protocol Hierarchy feature in Wireshark was used:
Wireshark â Statistics â Protocol Hierarchy
This revealed the following active protocols within the network traffic:
- HTTP â Used for web communication. Its presence is important because HTTP transmits data in plaintext, making it useful for identifying suspicious file downloads and command activity.
- SMTP â Indicates email-related communication. Since SMTP is also plaintext (unless secured), credentials and message content can sometimes be observed.
- SMB â A file-sharing protocol commonly used in Windows environments. Attackers often abuse SMB for lateral movement and transferring malicious files.
- ARP â Used for resolving IP addresses to MAC addresses inside the local network. High ARP activity can indicate network scanning or host discovery attempts.
The presence of these protocols suggests a combination of web-based activity, internal network communication, and potential lateral movement behavior, which aligns with the indicators of compromise discovered later in the investigation.

Malicious File Download via HTTP
Filtering for HTTP traffic revealed 4 packets. Following the HTTP stream showed:
- Source:
10.0.0.149 - User-Agent:
curl - Request Type: HTTP GET
- Requested File:
86607.dat - Host field was an IP address instead of a domain

Inspection of the file content revealed the âMZâ file signature, confirming the .dat file is a Windows executable.

Malware Confirmation
The file was exported and hashed. VirusTotal results:
- Flagged by 50+ vendors
- Identified as Qakbot malware

Post-Infection Behavior â ARP Scanning
Filter used: arp && eth.dst == ff:ff:ff:ff:ff:ff
Host 10.0.0.149 generated numerous ARP broadcast requests indicating network scanning.

ICMP & Port Scanning
Active hosts discovered:
10.0.0.110.0.0.6
Multiple TCP SYN packets suggested port scanning activity.

SMTP Credential Exposure
SMTP AUTH LOGIN traffic revealed Base64 encoded credentials.

Decoded:
- Username: arthit@macnels.co.th
- Password: Art123456

SMB Malware Propagation
SMB traffic showed suspicious DLL file transfers. Hashes matched Qakbot.


Indicators of Compromise (IOCs)
| Type | Value |
|---|---|
| Infected Host | 10.0.0.149 |
| Malware Family | Qakbot |
| Malicious File | 86607.dat |
| Behavior | ARP scanning, Port scanning, SMB propagation |
| Compromised Credentials | arthit@macnels.co.th / Art123456 |
Recommended Mitigations
- Isolate host 10.0.0.149
- Reset exposed credentials
- Block malicious external IP
- Scan network for Qakbot indicators
- Monitor SMB traffic
- Enforce encrypted protocols (HTTPS)
Conclusion
This PCAP analysis revealed a full malware lifecycle: infection, reconnaissance, credential exposure, and lateral movement â consistent with Qakbot malware activity.
This investigation demonstrates the importance of traffic analysis in detecting and responding to network threats.