MALWARE Analysis with Wireshark // TRICKBOT Infection

แชร์
ฝัง
  • เผยแพร่เมื่อ 10 ก.ค. 2024
  • Download the pcap here and follow along:
    malware-traffic-analysis.net/...
    The password to unzip the file is "infected"
    If you liked this video, I’d really appreciate you giving me a like and subscribing, it helps me a whole lot. Also don't be shy, chat it up in the comments!
    Video for configuring GeoIP in Wireshark:
    • Map IP Address Locatio...
    // Contact Me //
    LinkedIn: / cgreer
    TH-cam: / chrisgreer
    Twitter: / packetpioneer
    == More On-Demand Training from Chris ==
    ▶Getting Started with Wireshark - bit.ly/udemywireshark
    ▶Getting Started with Nmap - bit.ly/udemynmap
    == Live Wireshark Training ==
    ▶TCP/IP Deep Dive Analysis with Wireshark - bit.ly/virtualwireshark
    == Private Wireshark Training ==
    Let's get in touch - packetpioneer.com/product/pri...
    Links above contain affiliate links where I will receive a small amount for any goods purchased. I thank you for clicking because it really helps to support me!!
    0:00 Intro
    0:48 DNS Filters
    2:00 HTTP Requests/Replies
    5:00 Using GeoIP
    5:48 Exporting Usernames and Passwords
    6:48 Exporting System Info
    8:50 Extracting Hidden EXE Files
    11:44 TLS Handshake Signatures
  • วิทยาศาสตร์และเทคโนโลยี

ความคิดเห็น • 234

  • @drakezen
    @drakezen 2 ปีที่แล้ว +54

    Brilliant. You should create a course for people to do some basic verification on their systems for malware, viruses, etc

    • @ChrisGreer
      @ChrisGreer  2 ปีที่แล้ว +60

      Hey it is definitely something I am considering. Let me know if you'd like to see that Packet Heads! 🙂

    • @jaredteaches894
      @jaredteaches894 2 ปีที่แล้ว +1

      @@ChrisGreer I’d love to. I bought Pluralsight just for your courses!

    • @viktor.madarasz
      @viktor.madarasz 2 ปีที่แล้ว

      +1

    • @matimematime2867
      @matimematime2867 2 ปีที่แล้ว

      +2

    • @CyberNancy
      @CyberNancy 2 ปีที่แล้ว +2

      @@ChrisGreer Nice idea - it would be educational to see the impact this has on a Windows system. You could use Volatility for process listing and network connection artifacts. You could also do some registry or file system analysis as well.

  • @skizz_
    @skizz_ 2 ปีที่แล้ว +2

    That was amazing, would love to see deeper dives on malware analysis .
    JA3 was mindblowing. Keep them coming!
    All the best.

  • @Astro-Stock
    @Astro-Stock 2 ปีที่แล้ว +1

    Chris, great content as always! Thank you for these short little "deep dives".

  • @Brutatech
    @Brutatech 9 หลายเดือนก่อน

    Must say that i am pleasantly shocked from your videos and the way you present the analysis- i am working with captures almost 21 years and i still learning something from each of your videos- you are amazing !!!

  • @alaudet
    @alaudet 2 ปีที่แล้ว

    That's a great site for practicing with infected pcaps. Been downloading and analyzing them to cut my teeth a bit. Looking forward to future videos of files I have analyzed to see how I compare to your methodology. Excellent content as usual.

  • @mytechnotalent
    @mytechnotalent 2 ปีที่แล้ว +10

    Nice job Chris. This really shows the detail of how Malware traverses a network. Love the practical breakdown.

    • @ChrisGreer
      @ChrisGreer  2 ปีที่แล้ว +3

      Thanks Kevin! I agree, this was a fun one to work through.

  • @muhammadawais5974
    @muhammadawais5974 2 ปีที่แล้ว +5

    Thanks Chris. I appreciate this effort and would love to see more of 'em in this domain.

  • @robtot1934
    @robtot1934 ปีที่แล้ว

    There are too many words to describe the material you have offered here. Impressive, is one..... your talent to present material, it just makes you the right person for the job... Congratulation

  • @itguy1
    @itguy1 2 ปีที่แล้ว +3

    Recently discovered your channel and I must admit that everything you cover is pure gold - Thank you so much for sharing your knowledge Chris!

    • @ChrisGreer
      @ChrisGreer  2 ปีที่แล้ว +1

      Thank you! Thanks for stopping by the channel.

  • @michalczapnik1988
    @michalczapnik1988 2 ปีที่แล้ว +3

    I just wanted to take a glance at the video as i really appreciate your work and got totally sucked in! Great content and presentation. Simple, clear and effective. Would love to see more.

    • @ChrisGreer
      @ChrisGreer  2 ปีที่แล้ว +1

      Thanks for the feedback Michal! I'll get on it.

  • @SoulJah876
    @SoulJah876 2 ปีที่แล้ว +2

    Very cool video - looking forward to the rest.

  • @bricejackson1576
    @bricejackson1576 6 หลายเดือนก่อน

    Thanks Chris, really enjoyed this video! Very informative and to the point!

  • @pedrobarthacking
    @pedrobarthacking ปีที่แล้ว

    A good user friendly malware analysis! Congrats! 🏴‍☠️

  • @CosmeFulanito008
    @CosmeFulanito008 2 ปีที่แล้ว +1

    Thanks Chris for all the information you bring to us, its incredible how much we can do with wireshark! A lot of things that some people maybe didn't know.
    Please don't stop doing this type of content, i'll be waitint for your next videos.
    Greetings.

  • @shivadhanrityalaya9328
    @shivadhanrityalaya9328 2 ปีที่แล้ว

    Every video of Chris is an eye opener in packet analysis. To the point.. Thank you very much Chris..

    • @ChrisGreer
      @ChrisGreer  2 ปีที่แล้ว

      My pleasure! Thank you for the comment!

  • @vinyldown8490
    @vinyldown8490 ปีที่แล้ว

    what a dope video dude! thank you so much! I learned so many things from this!

  • @melonscratcher
    @melonscratcher ปีที่แล้ว

    Keep making the real world examples, love videos like this.

  • @bbowling619
    @bbowling619 7 หลายเดือนก่อน

    Loving it ! Keep em coming good sir !

  • @Das_lst_Gut_Ja
    @Das_lst_Gut_Ja 7 หลายเดือนก่อน

    You did an amazing job analyzing this infected PCAP file

  • @shruthesh
    @shruthesh 2 ปีที่แล้ว +2

    This was insightful! Please create more videos like this.

  • @nd.b77
    @nd.b77 2 ปีที่แล้ว +3

    Hi Chris. I just want to say that I LIKE THIS KIND OF CONTENT A LOT!👍

    • @ChrisGreer
      @ChrisGreer  2 ปีที่แล้ว +1

      Thank you for the feedback!

  • @maumotec2345
    @maumotec2345 2 ปีที่แล้ว +4

    This is not just a high technical valuable content but enjoyable 👏🏻 someone give a award to this man 🙌🏻 as always, amazing content.

    • @ChrisGreer
      @ChrisGreer  2 ปีที่แล้ว +2

      Much appreciated!

  • @x0rZ15t
    @x0rZ15t 2 ปีที่แล้ว

    Love those malware analysis videos!!!

    • @ChrisGreer
      @ChrisGreer  2 ปีที่แล้ว

      Glad you like them!

  • @Bahlkris100
    @Bahlkris100 2 ปีที่แล้ว +2

    Definitely love this kind of video Chris. Great content.

  • @SinisterSpatula
    @SinisterSpatula 2 ปีที่แล้ว +2

    Discovered you from the david bombal video and man, I'm excited to learn from your videos, this one was great! So cool to see malware attacks from a packet level perspective. If they had taken extra steps to use SSL and a normal user-agent string, aside from the foreign IP it might be a bit harder to spot.

    • @ChrisGreer
      @ChrisGreer  2 ปีที่แล้ว +2

      Thanks for the comment! Welcome to the channel. Suggestions always welcome. 👍

  • @lorieforchia3896
    @lorieforchia3896 ปีที่แล้ว

    Thank you or making this video. I'm getting a degree in Cyber Security and I'm recommending this to everyone!

  • @JFrow83
    @JFrow83 2 ปีที่แล้ว +4

    That was great, could definitely sit through more videos like this.

  • @matimematime2867
    @matimematime2867 2 ปีที่แล้ว +3

    Brilliant C.G. Please do more of these. Helps to understand the capabilites of wireshark

    • @ChrisGreer
      @ChrisGreer  2 ปีที่แล้ว +2

      More on the way!

  • @xaviervillalobos3958
    @xaviervillalobos3958 5 หลายเดือนก่อน

    This was great! I'm also taking your wireshark master class on Udemy and it's awesome! Great content. Thanks!

  • @siabelle
    @siabelle ปีที่แล้ว

    Hello Chris,
    Love the way you are able to balance on more levels of difficulty and still keep in short, interesting and applicable: you go deep in the packets but seem to avoid long tails where one shoe might fit but than the pathway to the second one zzzzz … btw I learned a lot, enough to be able to identify my ex-boss -as the sneaky-creep-hacker who harassed me more than a year- I would never ever have know whiteout your video’s- thank you Mr C.
    next week -

  • @chekov6668
    @chekov6668 2 ปีที่แล้ว +7

    Thank you Chris for another brilliant session! Very interesting tip with the ja3 hash and I guess that's the voodoo the new next gen firewall use to identify application level traffic?! I am looking forward to your next videos :-)

    • @ChrisGreer
      @ChrisGreer  2 ปีที่แล้ว +1

      Agreed. I'm totally nerding out on JA3 stuff right now. Super cool.

  • @CyberNancy
    @CyberNancy 2 ปีที่แล้ว +2

    If you're interested in learning about SOC work, this is a fast and great intro into some of the often encountered technology and trends.

  • @wie145
    @wie145 2 ปีที่แล้ว +1

    Valuable tips from you. Thanks a lot. Look forward to seeing more videos

  • @thiagocaval8799
    @thiagocaval8799 2 ปีที่แล้ว

    Great work Chris, thanks.

  • @tranxn7971
    @tranxn7971 2 ปีที่แล้ว

    That was very good thanks, this new malware analysis is really interesting.

    • @ChrisGreer
      @ChrisGreer  2 ปีที่แล้ว +1

      Glad you liked it!

  • @Closer80IT
    @Closer80IT 2 ปีที่แล้ว +3

    Very clear and interesting!

    • @ChrisGreer
      @ChrisGreer  2 ปีที่แล้ว +2

      Thanks for the comment Fab!

  • @ravenmccoy0440
    @ravenmccoy0440 11 หลายเดือนก่อน

    Mate, you are the pope of the Wireshark 🙏 it’s the greatest video I’ve ever seen about a Malware network activity. Thanks and we need more and more videos! 🤜💥🤛🙌🦈

    • @ChrisGreer
      @ChrisGreer  11 หลายเดือนก่อน +1

      on it!

  • @RR-vy7jd
    @RR-vy7jd 2 ปีที่แล้ว +1

    Love it. More malware analysis will be great. Great content thx

    • @ChrisGreer
      @ChrisGreer  2 ปีที่แล้ว +1

      More to come! Thank you.

  • @bakri99
    @bakri99 11 หลายเดือนก่อน

    Awesome! Love this kind of videos, we need more like this 👌👌

  • @kevingendron5586
    @kevingendron5586 2 ปีที่แล้ว +2

    More content like this, please! This is amazing and scary. Thanks very much for sharing this.

  • @yhytuncer
    @yhytuncer ปีที่แล้ว

    Awesome
    Video ! You should do more this kind of malware analysis videos with wireshark cause it’s a great skill for defenders

  • @zdrasbuytye
    @zdrasbuytye ปีที่แล้ว

    I love this guy. Thank for your time

  • @fredrikgustafsson7861
    @fredrikgustafsson7861 2 ปีที่แล้ว

    This comment isent just for this video, its for your whole channel. Thank you, mr Greer, for everything! You rock brother. Hope all is well and wish you all the best.

    • @ChrisGreer
      @ChrisGreer  2 ปีที่แล้ว +1

      Thank you for the comment!

  • @benoitburdet7869
    @benoitburdet7869 2 ปีที่แล้ว +1

    Yes I liked it !! Your videos are really intesresting. Thank you

    • @ChrisGreer
      @ChrisGreer  2 ปีที่แล้ว

      Glad you like them!

  • @vicky5573
    @vicky5573 9 หลายเดือนก่อน

    Thank you. Yes, I like this type of training using Wireshark

  • @duscraftphoto
    @duscraftphoto 2 ปีที่แล้ว

    This was great! About to check out the GeoIP video!

    • @ChrisGreer
      @ChrisGreer  2 ปีที่แล้ว +1

      Awesome! Let me know if you like that one. Watch out for my cat to make an appearance on that one too. :-)

    • @duscraftphoto
      @duscraftphoto 2 ปีที่แล้ว

      @@ChrisGreer ha ha! I saw that and it reminded me of a buddy of mine when I worked at Apple who had two cats that were in all of his video calls.
      Great content, on your channel, Chris. I never cared to really mess with Wireshark until I found your channel and now I'm wanting to learn all I can about packet analysis! Thank you for making amazing content and keep it up!

    • @ChrisGreer
      @ChrisGreer  2 ปีที่แล้ว

      @@duscraftphoto Haha - awesome. Hey be sure to check out my new Udemy class when you get a chance - bit.ly/udemywireshark - it's full of this kind of stuff!

  • @IamKhoramdin
    @IamKhoramdin 10 หลายเดือนก่อน

    Amazing, i really enjoy and learned alot

  • @jarbystark
    @jarbystark 2 ปีที่แล้ว

    Great video as always. spent 4 hours looking for malware in my network and cant stop ;))

    • @ChrisGreer
      @ChrisGreer  2 ปีที่แล้ว

      Nice! Keep going!

  • @patrickspaceman305
    @patrickspaceman305 9 หลายเดือนก่อน

    Glorious work, thank you.

  • @alaahaider
    @alaahaider 2 ปีที่แล้ว

    Man… that was excellent video. You are a super star 🌟

    • @ChrisGreer
      @ChrisGreer  2 ปีที่แล้ว +1

      Thanks for watching!

  • @joerockhead7246
    @joerockhead7246 2 ปีที่แล้ว +1

    That was so cool. Would love to see more. Thank you.

    • @ChrisGreer
      @ChrisGreer  2 ปีที่แล้ว +1

      You got it! Thanks Joe.

  • @sugaobilboa
    @sugaobilboa 2 ปีที่แล้ว +3

    I really enjoyed your video! Thank you very much for posting such incredibly interesting stuff! We want more!!! 😀

    • @ChrisGreer
      @ChrisGreer  2 ปีที่แล้ว +2

      Well more you will get! Thanks for the comment.

  • @utkarshmishra1928
    @utkarshmishra1928 ปีที่แล้ว

    Brilliant video Chris!!!!

  • @onrcrn
    @onrcrn 2 ปีที่แล้ว

    Great!! Thank you Chris

  • @jj691
    @jj691 ปีที่แล้ว

    Love these videos, you are truly an amazing teacher!

  • @I_hate_HANDLES
    @I_hate_HANDLES 9 หลายเดือนก่อน

    i begin with your master class and try to understand wireshark more and more before actually using it

  • @vijay85cisco
    @vijay85cisco 2 ปีที่แล้ว +1

    why iam thankful to chris. because his video and sharing his knowledge saved me in my career many times.. when my application team easily pointing anything to my network team.

    • @ChrisGreer
      @ChrisGreer  2 ปีที่แล้ว +1

      Thank you for the comment!

  • @isabelledelmas5332
    @isabelledelmas5332 ปีที่แล้ว

    Excellent content, very informative. Please, create more of those!

  • @mrbrown6421
    @mrbrown6421 ปีที่แล้ว

    I love this stuff!
    45 years ago I would hand disassemble Z80 code to
    figure out what it did, and then modify it as needed.
    I spent many hours digging into binary and hex files
    until I found this thing called a disassembler that
    converted it to 'readable' mnemonics along with
    an assembler that would do the opposite.
    (No internet back then)
    It was a wonderful place for a curious 18 year old and
    I loved it and it launched my career into other
    microprocessors and debugging methods.
    You, sir, are doing the same thing with that
    enthusiasm, but I do not know the 'language'!
    A neighbor flies his drone over my property all the
    time, and I just wanted to capture his GPS data
    to prove to the law both his altitude and position
    over my property. I would be forever thankful
    if someone could point me in that direction
    for this data collection effort.
    I do not know what types of drones he flies,
    but they are all VERY annoying and it is clearly
    an intimidation effort considering his darting
    around while we are outside (9 acres).
    Many thanks.
    Mr. Brown
    North Central Florida.

  • @zdzisawdyrma3319
    @zdzisawdyrma3319 2 ปีที่แล้ว +3

    This is very good stuff! It's a shame there wasn't material like this 10+ years ago.

  • @cryptoknight5927
    @cryptoknight5927 2 ปีที่แล้ว +1

    Pretty good infos. Thank you chris, i hope to know more about you actual career and how can i get useful from this great informations

  • @nourmaslouhi3183
    @nourmaslouhi3183 2 ปีที่แล้ว +1

    Genious. Like these type of videos will be very helpful identifying which type of malware by just using pcap file. Please post more videos.

  • @madayag408
    @madayag408 ปีที่แล้ว

    I love your videos. I'm learning a lot. Thank you.

    • @ChrisGreer
      @ChrisGreer  ปีที่แล้ว +1

      Great! I am having a bunch of fun making them.

    • @madayag408
      @madayag408 ปีที่แล้ว

      @@ChrisGreer keep it up! We love more!

  • @danmcd490
    @danmcd490 ปีที่แล้ว

    Love this walkthroughs

  • @anders6671
    @anders6671 2 ปีที่แล้ว

    This is awesome! More of this!

  • @saikiranlingadally1036
    @saikiranlingadally1036 ปีที่แล้ว

    Great Video Love These videos!!!

  • @ruttalaabhinav8105
    @ruttalaabhinav8105 ปีที่แล้ว

    Looking forward for more malware analysis with wireshark

  • @AlexDan123
    @AlexDan123 4 หลายเดือนก่อน

    Just discovered you, thanks for a great guide. i hope you make more security analyst related videos.

  • @skynet.yousha
    @skynet.yousha 2 ปีที่แล้ว +1

    Amazing lectures, this will help me in my Network forensics analysis cases. Really you make my life much easier.

    • @ChrisGreer
      @ChrisGreer  2 ปีที่แล้ว +1

      Glad to hear that!

  • @dezejongeman
    @dezejongeman 2 ปีที่แล้ว

    awesome; more of this please!

  • @zoranzasovski
    @zoranzasovski 2 ปีที่แล้ว

    Great video Chris!!!

  • @albertescaraugustin3981
    @albertescaraugustin3981 ปีที่แล้ว

    Yes I love it , make more of this

  • @Love-yv1fc
    @Love-yv1fc ปีที่แล้ว

    Excellent work sir❤keep it up😊

  • @ltfdagci666
    @ltfdagci666 6 วันที่ผ่านมา

    Thank you for this informative video. ❤

  • @majiddehbi9186
    @majiddehbi9186 2 ปีที่แล้ว +2

    Woow Chris u are so generous with knowledge u share this the way that gentil People act thx a million a god bless u

    • @ChrisGreer
      @ChrisGreer  2 ปีที่แล้ว

      Glad you liked it! Thank you for the comment!

    • @majiddehbi9186
      @majiddehbi9186 2 ปีที่แล้ว +1

      @@ChrisGreer Just to add something in medcin the radiologist is the Guy who see the inside thé organs. And it s the same for u see inside thé packets (data) u heal thé network :)

    • @ChrisGreer
      @ChrisGreer  2 ปีที่แล้ว

      @@majiddehbi9186 Very true! Thanks for the interesting comment.

  • @user-to8pm7ng1d
    @user-to8pm7ng1d 4 หลายเดือนก่อน

    such a wonderful explanation.......

  • @SocksAmpersandSandals
    @SocksAmpersandSandals ปีที่แล้ว

    Excellent-thank you!

    • @ChrisGreer
      @ChrisGreer  ปีที่แล้ว

      Glad you liked it!

  • @DavidMills1222
    @DavidMills1222 2 ปีที่แล้ว

    Amazing as always.

  • @viktor.madarasz
    @viktor.madarasz 2 ปีที่แล้ว

    Need more of this

  • @osmantuncbilek4031
    @osmantuncbilek4031 2 ปีที่แล้ว

    Thank you, this video is very helpful.

    • @ChrisGreer
      @ChrisGreer  2 ปีที่แล้ว +1

      Glad it was helpful!

  • @otienofredrick9972
    @otienofredrick9972 ปีที่แล้ว

    Thank you very much, Mr Chris. Please make a series of such videos for malware analysis using Wireshark.

    • @ChrisGreer
      @ChrisGreer  ปีที่แล้ว +1

      I need to add more on this topic, I know!

    • @otienofredrick9972
      @otienofredrick9972 ปีที่แล้ว

      @@ChrisGreer Thank you sir, I will really appreciate it!
      You just don't know how much you have helped me with your videos...You're impacting the world!
      Thank you once more Mr Chris. God bless.

  • @rlee431
    @rlee431 ปีที่แล้ว

    That was so helpful!!

    • @ChrisGreer
      @ChrisGreer  ปีที่แล้ว

      Glad it was helpful!

  • @roddandavis
    @roddandavis 2 ปีที่แล้ว

    Great work 👏 👍

  • @rager1969
    @rager1969 2 ปีที่แล้ว

    Great video!

  • @vyasG
    @vyasG 2 ปีที่แล้ว +1

    Thank you Chris for this exciting video. Loved the content.
    Will you be adding more videos to the "Masterclass" playlist?

    • @ChrisGreer
      @ChrisGreer  2 ปีที่แล้ว +2

      Hey Vyas! Probably not - now that the Udemy course is out there - bit.ly/udemywireshark

  • @laddn17
    @laddn17 2 ปีที่แล้ว

    This is amazing!

    • @ChrisGreer
      @ChrisGreer  2 ปีที่แล้ว

      glad you like it Nick!

  • @computerunderground2458
    @computerunderground2458 2 ปีที่แล้ว

    Awesome!

  • @gwadangle7288
    @gwadangle7288 ปีที่แล้ว

    thanks heaps Chris.

  • @philosphize
    @philosphize 5 หลายเดือนก่อน

    Awesome video, please make more content on malware analysis

    • @ChrisGreer
      @ChrisGreer  5 หลายเดือนก่อน

      Thanks, will do!

  • @cybersavage1337
    @cybersavage1337 ปีที่แล้ว

    This. Was. Awesome.

    • @ChrisGreer
      @ChrisGreer  ปีที่แล้ว +1

      Thank you! I need to crank out some more of these…

  • @mrj4264
    @mrj4264 ปีที่แล้ว

    Loved the video, just wished you went more into details such as how to remove the malware (such as what ips to blacklist).

  • @tametov
    @tametov 2 ปีที่แล้ว

    Very cool!!!

  • @PalazonPhotograpy
    @PalazonPhotograpy 2 ปีที่แล้ว +2

    Hi, your lessons are really great ! thanks and please keep doing it. I have a question for You...what will your first reaction if when doing a capture of a pc you see no tcp packets ? beacause i got the pb in my network... for one pc i only see NBNS, MDNS, LLMNR but no TCP... i'm a bit confuse...

  • @preadatordetector
    @preadatordetector 2 ปีที่แล้ว

    Man I gotta go see this site. Seems fun.

  • @MrWaf007
    @MrWaf007 ปีที่แล้ว

    nice and informative!

  • @SeroeKrevedko1
    @SeroeKrevedko1 2 ปีที่แล้ว +1

    Great content Mr Greer, thank you. Why attackers use plaintext for transmitting sensitive information?

  • @jrelic
    @jrelic ปีที่แล้ว

    Hey Chris, nice video. I've been practicing Pentesting on my VM's on VMWare. Any videos available for that type of scenario--seeing a hack in real time through Wireshark? Or at least, detecting one after the fact through Wireshark?

  • @abdullahahmed5941
    @abdullahahmed5941 ปีที่แล้ว

    amazing. keeep it going please

  • @ruttalaabhinav8105
    @ruttalaabhinav8105 ปีที่แล้ว

    Great content

  • @DEDEPLDEDE
    @DEDEPLDEDE 10 หลายเดือนก่อน

    Nice video Chris. Where to find the updated database of JA3 hashes ?