<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[My First Wireshark PCAP: Kongtuke Rebuke!]]></title><description><![CDATA[My First Wireshark PCAP: Kongtuke Rebuke!]]></description><link>https://mhk-cyber.hashnode.dev</link><image><url>https://cdn.hashnode.com/uploads/logos/6abccd236851ceb34630d9e1/ad6f8a63-69e1-4847-9f70-aabc4bf36c7b.jpg</url><title>My First Wireshark PCAP: Kongtuke Rebuke!</title><link>https://mhk-cyber.hashnode.dev</link></image><generator>RSS for Node</generator><lastBuildDate>Tue, 06 Oct 2026 11:30:26 GMT</lastBuildDate><atom:link href="https://mhk-cyber.hashnode.dev/rss.xml" rel="self" type="application/rss+xml"/><language><![CDATA[en]]></language><ttl>60</ttl><item><title><![CDATA[My First Wireshark PCAP: Kongtuke Rebuke!
]]></title><description><![CDATA[So I decided to learn Wireshark.
I watched like a 20minute video on YouTube, understood the basics, how to apply filters, conversations, endpoints, some of the protocols, etc.
Nothing too crazy.
Then ]]></description><link>https://mhk-cyber.hashnode.dev/my-first-wireshark-pcap-kongtuke-rebuke</link><guid isPermaLink="true">https://mhk-cyber.hashnode.dev/my-first-wireshark-pcap-kongtuke-rebuke</guid><category><![CDATA[cybersecurity]]></category><category><![CDATA[Wireshark]]></category><category><![CDATA[Security]]></category><category><![CDATA[networking]]></category><category><![CDATA[PCAP Analysis]]></category><category><![CDATA[Kongtuke Rebuke]]></category><category><![CDATA[analysis]]></category><dc:creator><![CDATA[mhk cyber]]></dc:creator><pubDate>Sat, 03 Oct 2026 06:01:21 GMT</pubDate><enclosure url="https://cdn.hashnode.com/uploads/covers/6abccd236851ceb34630d9e1/b33560a3-6fa3-4b51-9f98-83a3b030391a.jpg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>So I decided to learn Wireshark.</p>
<p>I watched like a 20minute video on YouTube, understood the basics, how to apply filters, conversations, endpoints, some of the protocols, etc.</p>
<p>Nothing too crazy.</p>
<p>Then I thought, okay, enough theory. Let's actually analyze some traffic.</p>
<p>So I went straight to solving PCAPs from Malware-Traffic-Analysis.net.</p>
<p>Bad idea.</p>
<p>I struggled.</p>
<p>Then I struggled some more.</p>
<p>And then I struggled even more.</p>
<p>But nevertheless, I solved it.</p>
<p>And the funny part is, this took me basically the whole day. I mean, I was still doing this until around 12 AM.</p>
<p>So here is how I did it.
[I wasn't trying to understand every single packet. I was just trying to answer the questions one by one.]</p>
<h2>The PCAP</h2>
<p>The exercise I picked was:</p>
<p>2026-09-11 — Traffic Analysis Exercise: Kongtuke rebuke!</p>
<p>I downloaded the PCAP, opened it in Kali Linux, and loaded it into Wireshark.</p>
<p>There were 73,779 packets.</p>
<p>Yeah.</p>
<p>Looking at that number for the first time was not exactly encouraging.</p>
<p>My first instinct was basically:</p>
<p>"Okay... where the hell do I even start?"</p>
<p>So I started looking around.</p>
<h2>First: looking at the traffic</h2>
<p>I checked the protocols and started seeing things like:</p>
<p>TCP</p>
<p>UDP</p>
<p>DNS</p>
<p>TLS</p>
<p>QUIC</p>
<p>I also opened Statistics → Conversations and Statistics → Endpoints to see which machines were communicating the most.</p>
<p>One IP immediately stood out:</p>
<p>10.9.11.135</p>
<p>I noticed it communicating with:</p>
<p>10.9.11.2</p>
<p>and several external IP addresses.</p>
<p>At this point I didn't know whether 10.9.11.135 was actually the infected machine.</p>
<p>I just had a suspicion.</p>
<p>So I started following the traffic.</p>
<h2>Then I found the Windows environment</h2>
<p>I noticed some interesting ports:</p>
<p>53  → DNS</p>
<p>389 → LDAP</p>
<p>88  → Kerberos</p>
<p>This started making more sense.</p>
<p>It looked like I was dealing with a Windows Active Directory environment.</p>
<p>10.9.11.2 appeared to be the domain controller.</p>
<p>The domain was:</p>
<p>overhands.org</p>
<p>So now I had a basic picture:</p>
<p>Windows client -&gt;
10.9.11.135</p>
<p>Domain Controller -&gt;
10.9.11.2</p>
<p>Domain -&gt;
overhands.org</p>
<p>This was the first point where I stopped randomly clicking packets and started thinking about what each piece of traffic actually meant.</p>
<h2>Finding the suspicious domains</h2>
<p>I started looking at the DNS queries.</p>
<p>Some of the domains I came across were:</p>
<p>quadcinema.com,</p>
<p>aatthews.cfd,</p>
<p>jquary.com,</p>
<p>edge.microsoft.com</p>
<p>There were also some domains that looked like they were trying to resemble legitimate domains.</p>
<p>One that caught my attention was:</p>
<p>aatthews.cfd</p>
<p>I followed its DNS traffic and found these IP addresses:</p>
<p>172.67.205.86
104.21.22.148</p>
<p>The interesting thing was that the infected host was actually communicating with:</p>
<p>172.67.205.86</p>
<p>I followed the UDP stream and ended up looking at QUIC traffic.</p>
<p>And this was one of those moments where I thought:</p>
<p>"Okay, what am I even looking at?"</p>
<p>There was a lot of encrypted/protected data.</p>
<p>Some readable pieces appeared, but most of it looked like complete garbage.</p>
<p>This was probably one of the points where I spent way too much time staring at packets hoping they would magically explain themselves.</p>
<p>They didn't.</p>
<h2>Going back to the actual questions</h2>
<p>Eventually I stopped trying to understand every single packet.</p>
<p>The exercise had specific questions.</p>
<p>So instead of trying to understand all 73,779 packets, I started working backwards from what I actually needed to find.</p>
<p>The first thing I wanted to confirm was the infected machine.</p>
<p>I filtered for:</p>
<p>ip.addr == 10.9.11.135</p>
<p>Now I could focus on traffic involving that machine instead of the entire capture.</p>
<p>That made things much easier.</p>
<h2>Finding the MAC address</h2>
<p>Once I had the IP, finding the MAC address was pretty straightforward.</p>
<p>I opened a packet coming from:</p>
<p>10.9.11.135</p>
<p>Then expanded:</p>
<p>Ethernet II</p>
<p>The source MAC was:</p>
<p>08:d4:0c:7a:29:1e</p>
<p>So I had:</p>
<p>IP:
10.9.11.135</p>
<p>MAC:
08:d4:0c:7a:29:1e</p>
<h2>Finding the hostname</h2>
<p>Next I needed the hostname.</p>
<p>This is where I learned about NBNS.</p>
<p>NBNS stands for NetBIOS Name Service.</p>
<p>Basically, it is an older Windows networking protocol used for resolving NetBIOS names.</p>
<p>In Wireshark I could filter for:</p>
<p>nbns</p>
<p>or:</p>
<p>udp.port == 137</p>
<p>I looked at the Windows name-resolution traffic involving the infected machine.</p>
<p>Eventually I found:</p>
<p>DESKTOP-6T17ZFM</p>
<p>So now:</p>
<p>IP:
10.9.11.135</p>
<p>MAC:
08:d4:0c:7a:29:1e</p>
<p>Hostname:
DESKTOP-6T17ZFM</p>
<h2>Finding the username</h2>
<p>Then I remembered something I had already seen earlier:</p>
<p>TCP/UDP 88</p>
<p>Port 88 is used by Kerberos, which is heavily used for authentication in Active Directory environments.</p>
<p>So I filtered for Kerberos traffic involving the infected machine.</p>
<p>I was looking for anything that could identify the user account.</p>
<p>I eventually found:</p>
<p>'gmcdowell'</p>
<p>And that gave me the account name.</p>
<p>I also learned something useful here about Wireshark.</p>
<p>You don't necessarily need to manually inspect thousands of packets.</p>
<p>You can search the capture.</p>
<p>For example:</p>
<p>frame contains "gmcdowell"</p>
<p>Wireshark then shows you packets containing that string.</p>
<p>You can look at the packet number in the No. column and inspect that particular frame.</p>
<p>That was a pretty useful "ohhh" moment for me.</p>
<h2>Finding the full name</h2>
<p>Now I had:</p>
<p>'gmcdowell'</p>
<p>But the question wanted the person's full name.</p>
<p>So I searched for the account again and looked at the surrounding Windows/SMB traffic.</p>
<p>Eventually I found:</p>
<p>'Gabriel McDowell'</p>
<p>So the username and full name were:</p>
<p>Username:
gmcdowell</p>
<p>Full name:
Gabriel McDowell</p>
<h2>Final answers</h2>
<p>After all that struggling, I finally had:</p>
<p>Infected IP:
10.9.11.135</p>
<p>MAC address:
08:d4:0c:7a:29:1e</p>
<p>Hostname:
DESKTOP-6T17ZFM</p>
<p>Username:
gmcdowell</p>
<p>Full name:
Gabriel McDowell</p>
<h2>What I actually learned</h2>
<p>Honestly, I think I learned more from getting stuck than I did from the 20minute Wireshark video(though the video was necessary, otherwise i wouldn't have even known where to start).</p>
<p>The video taught me what things like filters, conversations and endpoints were.</p>
<p>The PCAP forced me to actually use them.</p>
<p>I learned that you don't have to understand every packet in a capture.</p>
<p>You need to ask a question and then narrow the traffic down until you can answer it.</p>
<p>For example:</p>
<p>Find the infected machine </p>
<p>↓ </p>
<p>Find its IP </p>
<p>↓ </p>
<p>Find its MAC </p>
<p>↓ </p>
<p>Find its hostname</p>
<p>↓ </p>
<p>Look at Windows authentication</p>
<p>↓ </p>
<p>Find the username </p>
<p>↓ </p>
<p>Find the user's full name</p>
<p>I also learned a few filters that I'll definitely be using again:</p>
<p>ip.addr == 10.9.11.135
nbns
ip.addr == 10.9.11.135 &amp;&amp; kerberos
frame contains "gmcdowell"</p>
<p>And probably the biggest lesson:</p>
<p>Don't just stare at 73,779 packets and hope something makes sense.</p>
<p>Have a question.</p>
<p>Filter.</p>
<p>Investigate.</p>
<p>Follow the evidence.</p>
<p>And if you still don't understand it...</p>
<p>Google it.</p>
<p>Then go back to the PCAP.</p>
<h2>Final thoughts</h2>
<p>This was my first proper attempt at analyzing a PCAP.</p>
<p>Was it clean?</p>
<p>Absolutely not.</p>
<p>Did I know what I was doing the whole time?</p>
<p>Not even close.</p>
<p>Did I get frustrated?</p>
<p>A lot.</p>
<p>Did it take basically the entire day?</p>
<p>Yep.</p>
<p>But I solved it.</p>
<p>And honestly, that's probably the best part of learning cybersecurity for me.</p>
<p>I don't want to just watch someone explain Wireshark.</p>
<p>I want to get thrown into a PCAP, have absolutely no idea what's happening, struggle with it for hours, and eventually have that moment where something finally clicks.</p>
<p>So...</p>
<p>one PCAP down.</p>
<p>Let's see how the next one goes.</p>
]]></content:encoded></item></channel></rss>