Malware Traffic Analysis Using PCAP
π Download Full Report (PDF):
Malware Traffic Analysis Report
π‘ Case Overview
A packet capture file (2021-09-14.pcap) containing 3,679 packets was analyzed following reports that an endpoint device may have downloaded malware. The objective of this analysis was to identify suspicious network activity and extract potential Indicators of Compromise (IOCs).
π Tools Used
- Kali Linux
- tcpdump
- wireshark
- WHOIS lookup
- VirusTotal
Step 1 β Opening the Capture File
tcpdump -r 2021-09-14.pcap
To determine the size of the capture: tcpdump -r 2021-09-14.pcap βcount
Result: The capture contained 3,679 packets.
Step 2 β Filtering for Web Traffic
| tcpdump -r 2021-09-14.pcap -A tcp port 80 | egrep βGET | POSTβ |
Step 3 β Suspicious HTTP Request Identified
- Source IP: 10.0.0.168
- Destination IP: 103.232.55.148

Step 4 β OSINT Investigation
The destination IP address was investigated:
- WHOIS lookup indicates infrastructure located in Vietnam

- VirusTotal flagged the IP as suspicious

Step 5 β File Download Observed
The endpoint attempted to download: .audiodg.exe
This is concerning due to the executable format and suspicious naming.
Step 6 - Safely Download and Investigate Malicious File
The suspicious executable was safely extracted using wireshark and subjected to static analysis. File hashing and string inspection were performed without execution to avoid system compromise.

Hash Generation
The fileβs hash was calculated: sha256sum .audiodg.exe && sha1sum .audiodg.exe && md5sum audiodg.exe

Threat Intelligence Verification
The SHA256 hash was searched on VirusTotal, where the file was flagged as malicious by 40 security vendors, identifying it as a Trojan.

This confirms that the observed HTTP traffic resulted in the download of verified malware.
π¨ Indicators of Compromise (IOCs)
| Type | Value |
|---|---|
| Malicious IP | 103.232.55.148 |
| Suspicious File | .audiodg.exe |
| Affected Host | 10.0.0.168 |
| .audiodg.exe Hash | f485d1a65ccf9f857baa49725d337c15e8aa34515b85c8ef59a72afad7b85249 |
π Conclusion
This investigation confirms a successful malware download from a malicious external server. Network evidence, OSINT analysis, and malware hash verification collectively validate the presence of a Trojan infection, supporting escalation for containment and incident response.