Wireshark - Malware traffic Analysis

Packet analysis is one of the important skills that a security professional should master, Today Will be using the Worlds leading network traffic analyzer, Wireshark for malware traffic analysis,
Wireshark is a popular network protocol analyzer tool that enables you to gain visibility into the live data on a network. It’s a free and open-source tool that runs on multiple platforms.
🌏Web Site
hackexplorer.net/
💾Sample files in video
github.com/HackeXPlorer/Chann...
TimeStamps
0:00 Introduction
0:35 Wiershark quick intro
0:46 What are IOC's?
1:35 Wireshark interface
2:38 Protocol Hierarchy - Understand traffic
3:56 Using filters
4:38 Adding columns to the interface (HTTP destination)
5:28 Find source and destination port
6:58 Finding the infected files downloaded
9:26 Finding hash values of the files
10:06 Using Virustotal
11:43 Find infected website
12:26 Find IP address of the infected site
12:44 Find the MAC address of the infected machine
12:56 Find the Hostname of the infected machine
14:24 Actions on the findings
15:05 More learning - Wireshark 101
15:24 More exercises on www.malware-traffic-analysis.net
Download Wireshark
www.wireshark.org/download.html
Download Malware traffic sample
www.malware-traffic-analysis.n...
Main site: www.malware-traffic-analysis.net/
HashMyFiles
HashMyFiles is a small utility that allows you to calculate the MD5 and SHA1 hashes of one or more files in your system.
Download: www.nirsoft.net/utils/hash_my...
Hishan Shouketh 2019
Facebook
/ hackexplorer
Twitter
/ hack_explorer
Instagram
/ hackexplorer

Пікірлер: 256

  • @phennessey3
    @phennessey32 жыл бұрын

    This was more informative then my worthless college professor and textbook combined. Not only did I pass my lab because of this video, I also learned a lot. Thank you for sharing with us!!!!!!!!!!

  • @nicholegoh6574
    @nicholegoh657413 күн бұрын

    life saver really was so lost with an assignment due tmr and chanced upon this video thanku sm !!

  • @HazelJLMboya
    @HazelJLMboya6 ай бұрын

    I'm just 5mins into this and it's sooo helpful.Totally assisted in better understanding of wireshark. Thank you . NOT ALL HEROES WEAR CAPES!!!

  • @theconcierge9301
    @theconcierge93012 жыл бұрын

    that was the best explaination i´ve ever seen on youtube. bravo! you should bring more content out about wireshark and live examples. great!

  • @happyagain855
    @happyagain8553 жыл бұрын

    This the most informative, hands on video I've watched on this tube about this subject...Just amazing man. Thank you very much.

  • @HackeXPlorer

    @HackeXPlorer

    3 жыл бұрын

    Thank you for the valuable feedback :)

  • @jadielkyle6077

    @jadielkyle6077

    2 жыл бұрын

    I dont mean to be off topic but does someone know a trick to get back into an Instagram account? I was stupid forgot my password. I love any tips you can give me

  • @brooklynzoo81
    @brooklynzoo814 жыл бұрын

    This was presented and broken down very well. Thank you ! Subscribed

  • @HackeXPlorer

    @HackeXPlorer

    4 жыл бұрын

    Thank you for your feedback, appreciate it.

  • @TirthPatel7923

    @TirthPatel7923

    3 жыл бұрын

    Hey bro, I have a project to do on Wireshark, I have to analyze the files, can you please help me out please, like we can meet on zoom

  • @devislight
    @devislight3 жыл бұрын

    Brilliant, clear and great clarity in the delivery. Thank you so much. 👍👏

  • @Foxx999
    @Foxx9993 жыл бұрын

    Excellent presentation, I actually used this for a guide and was able to make a lot more sense of what I was seeing, Thanks a mil!

  • @HackeXPlorer

    @HackeXPlorer

    3 жыл бұрын

    Thank you for the feedback fox, highly appreciate it

  • @FrankTranDesign
    @FrankTranDesign3 жыл бұрын

    Dang, this is super informative. It's 2021, and this video is still ultra useful. Thank you!

  • @HackeXPlorer

    @HackeXPlorer

    3 жыл бұрын

    The source material i referred to was even older. But still this is the fundamentals 😁. But builds a strong foundation

  • @cyb3rmeerk4t51
    @cyb3rmeerk4t514 жыл бұрын

    Hopefully more episodes of this as well. Thank you for sharing your knowledge

  • @HackeXPlorer

    @HackeXPlorer

    4 жыл бұрын

    You are welcome Mandz 👍

  • @hilkokriel5659
    @hilkokriel56593 жыл бұрын

    WOW!! Crazy level of detail and new-user friendly. Thank you very much for uploading.

  • @HackeXPlorer

    @HackeXPlorer

    3 жыл бұрын

    You're very welcome! Hilko 👍

  • @tomasguagniniiglesias3798
    @tomasguagniniiglesias3798 Жыл бұрын

    Amazing, really clear, you are a great instructor. As I read on a comment below, I learned more from you in 16 min that from textbooks and professor in college

  • @HackeXPlorer

    @HackeXPlorer

    Жыл бұрын

    Thank you for the feedback Tomas

  • @acostamanuel2011
    @acostamanuel20113 жыл бұрын

    Great step by step video. Exactly what i was looking for!!

  • @Cyber_Jagat
    @Cyber_Jagat Жыл бұрын

    I had been looking for this type of worth content and in this video you covered a lot. Thanks for a worthy video.

  • @ruthawele2102
    @ruthawele21023 жыл бұрын

    Omg this is the best malware capture vid for Wireshark, Thank you so much for explaining step-by-step. its really helped me in packet analysis and hunting. Thanks mate!!!

  • @HackeXPlorer

    @HackeXPlorer

    3 жыл бұрын

    You are welcome Ruth, thank-you for the feedback.

  • @sambitsahoo1123
    @sambitsahoo11232 жыл бұрын

    Careful! He's a hero!!! Subscribed !!!

  • @abdoumjid9122
    @abdoumjid91224 жыл бұрын

    First of all, I want to thank you for the logical processes that you've shared here in this video, you have my subscription and like, and please make some playlists about every tool.

  • @HackeXPlorer

    @HackeXPlorer

    4 жыл бұрын

    Thankyou very much abdou 👍

  • @emmanuelmarosi3736
    @emmanuelmarosi37362 жыл бұрын

    this is the best wireshark tutorial

  • @dsha31
    @dsha319 ай бұрын

    Very well done..Will be sharing with my SOC team.

  • @josephnduati1214
    @josephnduati12144 жыл бұрын

    Very well explained and demonstrated. You made a confusing subject easy to understand. Thank you!

  • @HackeXPlorer

    @HackeXPlorer

    4 жыл бұрын

    Thankyou for the feedback Joseph 👍

  • @TirthPatel7923

    @TirthPatel7923

    3 жыл бұрын

    Hey bro, I have a project to do, analyzing the pcap files.. It would be nice of you if you can help me out. PLEASEEE, like we can do a google meet meeting or zoom or something that you like. PLEASE

  • @barkath005
    @barkath005 Жыл бұрын

    Thanks for the easy step by step guidance. Appreciate your efforts. 👍👍👍

  • @georgegonduan8464
    @georgegonduan846411 ай бұрын

    Thanks for the help to understanding wireshark

  • @Kinoti9
    @Kinoti93 жыл бұрын

    Wow that was really really smooth. Thanks. Subbed already

  • @povadventures3740
    @povadventures3740 Жыл бұрын

    I've learned quite a bit knowledge on his analysis. I'm surprise this channel haven't blew up yet. Subscribed for more!! lets go!

  • @HackeXPlorer

    @HackeXPlorer

    Жыл бұрын

    Thanks for the feedback

  • @nashimahmed7035
    @nashimahmed70354 жыл бұрын

    Found something very interesting... really like to see such videos upcoming.. Thanks for sharing !!

  • @HackeXPlorer

    @HackeXPlorer

    4 жыл бұрын

    Appreciate your feedback Nashim

  • @Toczusiek
    @Toczusiek3 жыл бұрын

    You rock man, I needed it to do my university exercise. Thank you so much :)

  • @TirthPatel7923

    @TirthPatel7923

    3 жыл бұрын

    Hey bro, I have a project to do, analyzing the pcap files.. It would be nice of you if you can help me out. PLEASEEE, like we can do a google meet meeting or zoom or something that you like. PLEASE

  • @ashanlahiru8020

    @ashanlahiru8020

    3 жыл бұрын

    Hey bro, I want a help from both of you For my Uni Assignmnt.. Please Can You??

  • @lokeshavm8366
    @lokeshavm836610 ай бұрын

    Great explanation, Please keep posting more videos.

  • @skatetown100
    @skatetown1002 жыл бұрын

    Excellent .. just excellent !!!!! Thanks for this!!

  • @v380riMz
    @v380riMz2 жыл бұрын

    Thanks alot, that export objects is extremely helpful which I didn't know about!

  • @njayapavithra1705
    @njayapavithra17053 жыл бұрын

    Amazing, the author explained it so easy. Thank you

  • @HackeXPlorer

    @HackeXPlorer

    3 жыл бұрын

    Thankyou for thr feedback Jaya.

  • @trendyniro
    @trendyniro Жыл бұрын

    very practical, was able to understand easily. Kudos!

  • @Jackie_Labrador
    @Jackie_Labrador2 жыл бұрын

    Excellent video :) Thanks

  • @tanaysamanta4730
    @tanaysamanta47302 жыл бұрын

    Really man! This video was amazing! Thank you!

  • @little_trash_panda
    @little_trash_panda2 жыл бұрын

    I'm a master student and this video is very helpful for me to do my homework. It is so informative! Thank you.

  • @HackeXPlorer

    @HackeXPlorer

    2 жыл бұрын

    I am glad that this helped you,do let me know what kind of other topics that will be helpful for your studies.

  • @konulaslanova2608
    @konulaslanova26082 жыл бұрын

    Excellent. You made it so clear.

  • @HackeXPlorer

    @HackeXPlorer

    2 жыл бұрын

    Thank you Konul

  • @yadvindersingh4656
    @yadvindersingh46563 жыл бұрын

    The flow was great. Thanks for sharing

  • @HackeXPlorer

    @HackeXPlorer

    3 жыл бұрын

    Glad you enjoyed it!

  • @ashutoshrajput988
    @ashutoshrajput9883 жыл бұрын

    the best video on youtube till now. thanks

  • @HackeXPlorer

    @HackeXPlorer

    3 жыл бұрын

    Glad it helped

  • @johnjohn7549
    @johnjohn75492 жыл бұрын

    Very interesting and presented in a clear manner. Was a little fast a points, but can hopefully learn those bits later.

  • @showvik012
    @showvik0124 жыл бұрын

    Keep them videos coming. Good work!

  • @HackeXPlorer

    @HackeXPlorer

    4 жыл бұрын

    Thankyou Showvik

  • @Leokhawarizmi
    @Leokhawarizmi3 жыл бұрын

    I have learned so much today just in one video, thank you so much please keep going

  • @HackeXPlorer

    @HackeXPlorer

    3 жыл бұрын

    Glad this was helpful, thankyou Leo.

  • @muratafsar9753
    @muratafsar97534 жыл бұрын

    This is amazing work. Thank you sir. Subscribed !

  • @HackeXPlorer

    @HackeXPlorer

    4 жыл бұрын

    Thank you for the feedback ,Murat

  • @pchebbi
    @pchebbi4 жыл бұрын

    Nice explanation with good demo. Thank you!

  • @HackeXPlorer

    @HackeXPlorer

    4 жыл бұрын

    You are welcome Prasanna

  • @dhanukawickramasinghe9290
    @dhanukawickramasinghe92903 жыл бұрын

    thank you man. it was really helpful

  • @rashmiraghukumar5821
    @rashmiraghukumar5821 Жыл бұрын

    Thanks, alot!!! for uploading this informative video, I really learned a lot about Wireshark ethereal

  • @HackeXPlorer

    @HackeXPlorer

    Жыл бұрын

    Thanks for the feedback Rashmi 👍

  • @Martin-ot7xj
    @Martin-ot7xj Жыл бұрын

    Hi there, it was a very very useful & informative tutorial video. please upload more about Wireshark. thnx

  • @user-rj3rv6mv5z
    @user-rj3rv6mv5z9 ай бұрын

    Good explanation and new information.

  • @ImranShaikh-kt7ey
    @ImranShaikh-kt7ey3 жыл бұрын

    Amazing episode 🔥🔥🔥

  • @BiharCentralSchool
    @BiharCentralSchool3 жыл бұрын

    Absolutely Brilliant EXplanantion

  • @HackeXPlorer

    @HackeXPlorer

    3 жыл бұрын

    Thankyou very much

  • @lawrencestowe7070
    @lawrencestowe70703 жыл бұрын

    Really good video, great advice with columns etc

  • @HackeXPlorer

    @HackeXPlorer

    3 жыл бұрын

    Glad it helped!

  • @riyazshaikh6373
    @riyazshaikh63733 жыл бұрын

    Amazing stuff. presented in a very easy manner to understand.

  • @HackeXPlorer

    @HackeXPlorer

    3 жыл бұрын

    Glad you liked it! Riyaz

  • @chirojitsarkar
    @chirojitsarkar3 жыл бұрын

    Fantastic Explanation. It is really helpful for WIRESHARK Beginners.

  • @HackeXPlorer

    @HackeXPlorer

    3 жыл бұрын

    Glad it was helpful! Thank you Chirojit.

  • @youssefelankoud6497
    @youssefelankoud64974 жыл бұрын

    Thank you so much, this video it's very useful, keep sharing your knowledge

  • @HackeXPlorer

    @HackeXPlorer

    4 жыл бұрын

    You are welcome, and thankyou for the feedback. Appreciate it.

  • @fudbalskafilozofija2818
    @fudbalskafilozofija2818 Жыл бұрын

    TNice tutorials tutorial is so good, tysm

  • @artember1200
    @artember12004 жыл бұрын

    Great work,very informative and professional

  • @HackeXPlorer

    @HackeXPlorer

    4 жыл бұрын

    Thankyou for the feedback Artem.

  • @shafrinainn365
    @shafrinainn3652 жыл бұрын

    Very informative and very good explanation. Thank you.

  • @HackeXPlorer

    @HackeXPlorer

    2 жыл бұрын

    Thankyou Shafrina 👍👍

  • @muruga403
    @muruga4034 жыл бұрын

    Thank you very much for sharing your knowledge, it's very useful Milles merci

  • @HackeXPlorer

    @HackeXPlorer

    4 жыл бұрын

    it's a pleasure Muvi. De rien

  • @captainnemonic
    @captainnemonic3 жыл бұрын

    Great presentation and information. Thanks!

  • @HackeXPlorer

    @HackeXPlorer

    3 жыл бұрын

    Thankyou Larry

  • @vengalachandu4080
    @vengalachandu40802 жыл бұрын

    Excellent # keep doing 👏 👍

  • @mohdfirdaus5237
    @mohdfirdaus52374 жыл бұрын

    Thanks man. Great Explanation.

  • @HackeXPlorer

    @HackeXPlorer

    3 жыл бұрын

    Glad it was helpful! Mohd (y)

  • @lastofdev777
    @lastofdev7773 жыл бұрын

    Thank you man, I really need it for my assigment.

  • @HackeXPlorer

    @HackeXPlorer

    3 жыл бұрын

    Glad this helped you, thanx for the feedback

  • @fritzbiederstadt4869
    @fritzbiederstadt48692 жыл бұрын

    Outstanding video about using Wireshark for security related purposes. I've been doing protocol analysis for a long time with various protocol analyzers, Wireshark is my hands-down favorite. However I've only used it for TCP and application performance analysis and troubleshooting. Although I've had thoughts about getting into the security side of things since, there has been some hesitation. My experience with performance analysis is advanced with computer communication protocols, service layers, etc. Learned a lot - I believe I will download and work through some of this. I'm already using most of the same methodology on the performance analysis side, so it should easy to transfer over my skills. Thanks!

  • @HackeXPlorer

    @HackeXPlorer

    2 жыл бұрын

    Thankyou for you feedback Fritz, these keep me motivated to make more videos like this

  • @tugrulserhat
    @tugrulserhat2 жыл бұрын

    very nicely done video. thanks a lot

  • @orca2162
    @orca21623 жыл бұрын

    Great explanation - thank you

  • @HackeXPlorer

    @HackeXPlorer

    3 жыл бұрын

    Many thanks for the feedback Orca.

  • @leestaton1697
    @leestaton16972 жыл бұрын

    good channel I like how you go in depth regarding wireshark Ive got wireshark

  • @HackeXPlorer

    @HackeXPlorer

    2 жыл бұрын

    Thankyou Lee, appreciate the valuable feedback.

  • @awaisshakir1
    @awaisshakir14 жыл бұрын

    Your work is exceptional 👍 please make more videos soon

  • @HackeXPlorer

    @HackeXPlorer

    4 жыл бұрын

    hey Shakir, thanks for the feedback. yah hope to do more soon. stay tuned

  • @sonujalwal4768
    @sonujalwal4768 Жыл бұрын

    very informative video thanks

  • @nilanjenator
    @nilanjenator3 жыл бұрын

    Echoing other comments - nice, well made video. Good focus on teaching, rather than video production. At the same time, very practical information.

  • @HackeXPlorer

    @HackeXPlorer

    3 жыл бұрын

    Thank you for the feedback Nilanjan. Appreciate it a lot.

  • @dilainsholidaytrips5641
    @dilainsholidaytrips56416 күн бұрын

    Good one. Thanks

  • @ravindra.waghmare
    @ravindra.waghmare4 жыл бұрын

    Wonderful...very nicely explained.!!

  • @HackeXPlorer

    @HackeXPlorer

    4 жыл бұрын

    Thanks a lot 😊

  • @bolimov
    @bolimov2 жыл бұрын

    amazing video. simply explained. thanks for the content.

  • @HackeXPlorer

    @HackeXPlorer

    2 жыл бұрын

    Thank you for your feedback, appreciate it

  • @PADARIAD
    @PADARIAD2 жыл бұрын

    No bu****It, right to the point! Love it! you are awesome!

  • @HackeXPlorer

    @HackeXPlorer

    2 жыл бұрын

    Thankyou for the valuable feedback Darpan.

  • @immunesicness3399
    @immunesicness33992 жыл бұрын

    Finaly some info to work with

  • @SandyLaVogue
    @SandyLaVogue Жыл бұрын

    great content!

  • @omomeneehinome
    @omomeneehinome2 жыл бұрын

    awesome. thank you

  • @ShartedDownMyLeg
    @ShartedDownMyLeg2 жыл бұрын

    Great video, worth a sub.

  • @HackeXPlorer

    @HackeXPlorer

    2 жыл бұрын

    Thanks for the sub!

  • @pnn0656
    @pnn06563 жыл бұрын

    Thanks for such a nice video, you have explained very well and thisbis very very helpful for me

  • @HackeXPlorer

    @HackeXPlorer

    3 жыл бұрын

    You are welcome, thanks for the feedback

  • @_admin_user
    @_admin_user2 жыл бұрын

    very informative video

  • @josed4540
    @josed45404 жыл бұрын

    This was very helpful please make more packet analysis videos, maybe other attacks like XSS, beaconing activity and Trojans. Thank you.

  • @HackeXPlorer

    @HackeXPlorer

    4 жыл бұрын

    Thank you Tony, valuable suggestions. I'll add these topics to my future work.

  • @yelinsoe3428
    @yelinsoe34282 жыл бұрын

    Prefect informations!

  • @HackeXPlorer

    @HackeXPlorer

    2 жыл бұрын

    Thank you very much

  • @amirghost281
    @amirghost2813 жыл бұрын

    Thanks bro , you saved me 👍

  • @channel98-jcrx-tv58
    @channel98-jcrx-tv583 жыл бұрын

    Thank you man!

  • @HackeXPlorer

    @HackeXPlorer

    3 жыл бұрын

    Happy to help!

  • @humanrelations3664
    @humanrelations36643 жыл бұрын

    Thanks for the video !!!

  • @HackeXPlorer

    @HackeXPlorer

    3 жыл бұрын

    Thanks appreciate it ☺️

  • @ReligionAndMaterialismDebunked
    @ReligionAndMaterialismDebunked Жыл бұрын

    Thanks, fellow ethical hacker!

  • @meeraramanujam3665
    @meeraramanujam3665 Жыл бұрын

    Thank you🙏🏼

  • @HackeXPlorer

    @HackeXPlorer

    Жыл бұрын

    You’re welcome 😊

  • @saby826
    @saby8263 жыл бұрын

    Very well explained.

  • @HackeXPlorer

    @HackeXPlorer

    3 жыл бұрын

    Thanks Saby

  • @tanzeelhassan2934
    @tanzeelhassan29344 жыл бұрын

    awesome. thanks so much!

  • @HackeXPlorer

    @HackeXPlorer

    4 жыл бұрын

    Hey, Tanzeel you are welcome.

  • @ms7414
    @ms741410 ай бұрын

    Very useful and well done video. I only wish you had expounded more on the other suspicious server little more in depth. Thanks.

  • @shivendrapratapsingh263
    @shivendrapratapsingh263 Жыл бұрын

    amazing tutorial

  • @gamehype3207
    @gamehype3207 Жыл бұрын

    THANK YOU SO MUCH

  • @HackeXPlorer

    @HackeXPlorer

    Жыл бұрын

    You're welcome!

  • @kumarputtappa6507
    @kumarputtappa65073 жыл бұрын

    Hi Sir, I found this useful and shared it with my Front line team to analyze the PCAP logs. Can you please post one more video to analyze the slowness/performance issue when using a different protocol like ( PCoIP, Blast) Some times we face issues saying unable to launch the VDI when using PCoIP and the blast works fine(vice versa). If we can analyze the network logs we can suggest what can be done in his network. . Curious to know how to find the cause and suggest things better.

  • @abhishekrajput9434
    @abhishekrajput94343 жыл бұрын

    Thanxs.

  • @ghitansilviu2389
    @ghitansilviu23892 жыл бұрын

    nice man, tks , i didn.t know how to see the host name. i do now...

  • @adityapaithon6499
    @adityapaithon64994 жыл бұрын

    great job!

  • @HackeXPlorer

    @HackeXPlorer

    4 жыл бұрын

    Thank you Adithya.

  • @ParasScorpio
    @ParasScorpio3 жыл бұрын

    Thanks a lot Sir.

  • @HackeXPlorer

    @HackeXPlorer

    3 жыл бұрын

    Most welcome Paras:)

  • @Brunochavesj
    @Brunochavesj2 жыл бұрын

    Nice

  • @mohamadsalhani
    @mohamadsalhani3 ай бұрын

    Thanks a lot for your efforts. Could you please send again the link of the traffic sample? The one in the description was not opened. I think you used the version 2014 (MTA-2014-files-contains-malware.zip), then the pw should be infected_2014, it also was not worked. Thanks in advance.

  • @ausmanx1161
    @ausmanx11612 жыл бұрын

    Great video Just wondering, when saving those malicious files, while it infect your computer or does it only do that when you run the files

  • @HackeXPlorer

    @HackeXPlorer

    2 жыл бұрын

    only when you run.

  • @kashifumer9283
    @kashifumer9283 Жыл бұрын

    I feel you

  • @gurpreet4449
    @gurpreet44492 жыл бұрын

    I guess this video is helpful only for HTTP traffic. Most of the websites we visit are HTTPS. How can we do malware analysis for the TLS/HTTPS traffic ? Thank you.

  • @nandorbacso4625
    @nandorbacso4625 Жыл бұрын

    Hey, great video, but I got stuck at some point: For me, all the options under File/Export Objects are grey. Should I select something or is there anything I am missing? Thanks!

  • @HackeXPlorer

    @HackeXPlorer

    Жыл бұрын

    If you have a http traffic capture, try typing "http" as a filter, then select a packet . Then check the export object option