CSW33
CSW33
1. Initial Setup
Look for:
http.request
Look for:
• POST or PUT methods to unknown or external IPs.
• Suspicious User-Agent strings like curl, python, etc.
• Base64-encoded data in payloads.
tcp
Then:
ssl.handshake
Or:
tls
Look for:
Look for payloads in ICMP (shouldn't have much normally), or large amounts of outbound
data in FTP or SMTP.
Step-by-Step in Wireshark
• Launch Wireshark
• Open your .pcap le (File > Open)
Look for:
• Suspicious POST requests (sending data out)
• Weird or obfuscated content (e.g., base64 blobs, binary data)
• Repeated messages or heartbeats (beaconing behaviour)