This is our old Q&A Site. Please post any new questions and answers at ask.wireshark.org.

I got a pcap and need to have it deep analysed to find a netbot, how do i do this with wireshark??

asked 12 Jan '14, 07:22

MarkV's gravatar image

MarkV
1111
accept rate: 0%

closed 12 Jan '14, 07:29

Kurt%20Knochner's gravatar image

Kurt Knochner ♦
24.8k1039237

Again the same question??

(12 Jan '14, 07:27) Kurt Knochner ♦

No, not the same i got a several parts analysed but still it's not the solution, so clearly, me as a first timer, am doing something wrong. Al do i'm a first timer with wireshark, therefore the question if someone could help or point me in the direction on how to get all the information out of the pcap stream, and more to see the crypted or hidden info or url's wich i can't find

(12 Jan '14, 07:33) MarkV

@MarkV, this is a Q&A site for Wireshark and its use. While we often have questions about captures and their contents, for your issue, which is quite general and seems to need a lot of interactive discussion, you will be much better off taking the problem to a malware forum.

If you have a specific question about Wireshark use do feel free to post it here.

(12 Jan '14, 12:43) grahamb ♦

The question has been closed for the following reason "You have been told in other questions, that your request is off-toppic!!" by Kurt Knochner 12 Jan '14, 07:29


You tagged your question with "encrypted", so if you can't decrypt the traffic you're out of luck. Unless you have a different approach (like statistical or differential analysis of meta data) that could deal with it without decrypting things. If you can decrypt the stuff you should look for unusual protocols, unusual protocol activity, hosts you don't recognize, strange delta times, and other things that seem odd.

This all requires patience and a lot of experience in reading packet traces, of course.

permanent link

answered 12 Jan '14, 07:29

Jasper's gravatar image

Jasper ♦♦
23.8k551284
accept rate: 18%

Follow this question

By Email:

Once you sign in you will be able to subscribe for any updates here

By RSS:

Answers

Answers and Comments

Markdown Basics

  • *italic* or _italic_
  • **bold** or __bold__
  • link:[text](http://url.com/ "title")
  • image?![alt text](/path/img.jpg "title")
  • numbered list: 1. Foo 2. Bar
  • to add a line break simply add two spaces to where you would like the new line to be.
  • basic HTML tags are also supported

Question tags:

×238
×14
×8

question asked: 12 Jan '14, 07:22

question was seen: 1,478 times

last updated: 12 Jan '14, 12:43

p​o​w​e​r​e​d by O​S​Q​A