This is a static archive of our old Q&A Site. Please post any new questions and answers at ask.wireshark.org.

Type of attack related to so many TCP Retransmissions

0

I am analysing an attack capture with Wireshark and am having some trouble identifying the type of attack that this one is.

I am guessing it may be a DDoS attack since there are many TCP Retransmissions but I am not quite sure.

Can someone with more experience clarify me?

alt text

asked 03 Apr '16, 10:40

twistedx's gravatar image

twistedx
11225
accept rate: 0%


One Answer:

1

This looks pretty normal to me, except for the duplicate frames in the trace. You'll need to deduplicate the file first, see https://blog.packet-foo.com/2015/03/tcp-analysis-and-the-five-tuple/ for more information.

answered 03 Apr '16, 12:25

Jasper's gravatar image

Jasper ♦♦
23.8k551284
accept rate: 18%

I will take a look at that. But now I was thinking that this can have something to do with a SMB Flow attack. What do you think about that?

(03 Apr '16, 15:25) twistedx