Case Overview

This investigation analyzes a packet capture file (2023-02-03.pcap) to identify suspicious activity, Indicators of Compromise (IOCs), and evidence of malware infection within a local network.

The objective was to examine network traffic, trace malicious downloads, observe post-infection behavior, and determine the overall security impact.

📄 Download Full Investigation Report (PDF):
Wireshark Qakbot Malware Analysis Report


Lab Environment & Tools Used

Category Tools
Traffic Analysis Wireshark
Threat Intelligence VirusTotal, OSINT
Packet Filtering Wireshark Display Filters
File Analysis Hash extraction, file signature inspection
Decoding Tool CyberChef (Base64 decoding)
Protocols Investigated HTTP, ARP, ICMP, SMTP, SMB

Initial Traffic Review

After loading the PCAP into Wireshark:

  • Total packets captured: ~55,000
  • Capture duration: 2 hours 50 minutes

Using Statistics → Conversations, one internal host stood out:

Suspicious Host: 10.0.0.149

Statistics IP Conversation

This system had an unusually high number of conversations with both internal and external IP addresses.

Protocol Analysis

To understand the types of communication present in the capture, the Protocol Hierarchy feature in Wireshark was used:

Wireshark → Statistics → Protocol Hierarchy

This revealed the following active protocols within the network traffic:

  • HTTP – Used for web communication. Its presence is important because HTTP transmits data in plaintext, making it useful for identifying suspicious file downloads and command activity.
  • SMTP – Indicates email-related communication. Since SMTP is also plaintext (unless secured), credentials and message content can sometimes be observed.
  • SMB – A file-sharing protocol commonly used in Windows environments. Attackers often abuse SMB for lateral movement and transferring malicious files.
  • ARP – Used for resolving IP addresses to MAC addresses inside the local network. High ARP activity can indicate network scanning or host discovery attempts.

The presence of these protocols suggests a combination of web-based activity, internal network communication, and potential lateral movement behavior, which aligns with the indicators of compromise discovered later in the investigation.

Protocol Hierarchy


Malicious File Download via HTTP

Filtering for HTTP traffic revealed 4 packets. Following the HTTP stream showed:

  • Source: 10.0.0.149
  • User-Agent: curl
  • Request Type: HTTP GET
  • Requested File: 86607.dat
  • Host field was an IP address instead of a domain

HTTP GET Request

Inspection of the file content revealed the “MZ” file signature, confirming the .dat file is a Windows executable.

MZ Signature


Malware Confirmation

The file was exported and hashed. VirusTotal results:

  • Flagged by 50+ vendors
  • Identified as Qakbot malware

VirusTotal Result


Post-Infection Behavior — ARP Scanning

Filter used: arp && eth.dst == ff:ff:ff:ff:ff:ff

Host 10.0.0.149 generated numerous ARP broadcast requests indicating network scanning.

ARP Traffic


ICMP & Port Scanning

Active hosts discovered:

  • 10.0.0.1
  • 10.0.0.6

Multiple TCP SYN packets suggested port scanning activity.

TCP SYN Packets


SMTP Credential Exposure

SMTP AUTH LOGIN traffic revealed Base64 encoded credentials.

SMTP Base64 Stream

Decoded:

  • Username: arthit@macnels.co.th
  • Password: Art123456

Cyberchef Decode


SMB Malware Propagation

SMB traffic showed suspicious DLL file transfers. Hashes matched Qakbot.

SMB Export

VirusTotal Result


Indicators of Compromise (IOCs)

Type Value
Infected Host 10.0.0.149
Malware Family Qakbot
Malicious File 86607.dat
Behavior ARP scanning, Port scanning, SMB propagation
Compromised Credentials arthit@macnels.co.th / Art123456

  • Isolate host 10.0.0.149
  • Reset exposed credentials
  • Block malicious external IP
  • Scan network for Qakbot indicators
  • Monitor SMB traffic
  • Enforce encrypted protocols (HTTPS)

Conclusion

This PCAP analysis revealed a full malware lifecycle: infection, reconnaissance, credential exposure, and lateral movement — consistent with Qakbot malware activity.

This investigation demonstrates the importance of traffic analysis in detecting and responding to network threats.