Do You Use VirusTotal? Give PacketTotal a Spin!

Wingman

Level 4
Thread author
Verified
Well-known
Feb 6, 2017
154
Packettotal ( http://www.packettotal.com ) is a new site that does some nifty analysis of Packet Captures for you if you're not so familiar with Wireshark or other analysis tools

Out of the gate, this site maps out connections, certificates, encryption algorithms and gives up files that are transfered in the session. A great start (I accidentally found another app that runs their own private CA with this), we're looking forward to more great things from this site as they get on! So far everything you can do on Packettotal you can do in Wireshark, but it's as quick and easy as can be on the PT site!

Of course - the standard rules apply - be sure that you're not uploading sensitive informaiton to cloud-based sites of this type! If you're analyzing client data, you might need permission to upload. They also still allow http access to their site (oops) - be sure to browse to them using https explicitly until they fix this.

+1 for the tool, you can perform analysis and timeline of traffic based on pcap along with nice statistics
 

shmu26

Level 85
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Jul 3, 2015
8,153
From the FAQ, it sounds like this is for stuff that you run in VM, because if you upload a packet from your real machine, you are exposing your IP address or other sensitive data.
 

Wingman

Level 4
Thread author
Verified
Well-known
Feb 6, 2017
154
From the FAQ, it sounds like this is for stuff that you run in VM, because if you upload a packet from your real machine, you are exposing your IP address or other sensitive data.

That is correct. Depending on your organisational policy you may/may not be able to upload packet captures. If you want to test how this works you can use any of the pcaps available below

Barracuda Labs Threatglass
 

Wingman

Level 4
Thread author
Verified
Well-known
Feb 6, 2017
154
Yes. VPN will encrypt the traffic, therefore the malware hosts will never actually obtain your real IP address, instead it'll obtain the IP address from the VPN server.

The VPN would hide your real IP but the pcap would also have other sensitive data (depending on your network , that can be anything from DHCP handshake to bonjour advertisements ;) ). Do you mind uploading such information to the service(as an example bonjour advertisements for QNAP can reveal the asset serial number!!! ) ?

I would avoid using VPN to interact with the Malware. If you want to get information about the malware infrastructure only use open source tools (archive.org, whois etc).Malware authors have multiple ways to determine "who is checking what" on their infrastructure (dns requests ,DGA domains that do not match the expected date ,unexpected user agents that shouldn't have triggered the malware infection etc)
 
  • Like
Reactions: shmu26 and Wave
W

Wave

The VPN would hide your real IP but the pcap would also have other sensitive data (depending on your network , that can be anything from DHCP handshake to bonjour advertisements ;) ). Do you mind uploading such information to the service(as an example bonjour advertisements for QNAP can reveal the asset serial number!!! ) ?

I would avoid using VPN to interact with the Malware. If you want to get information about the malware infrastructure only use open source tools (archive.org, whois etc).Malware authors have multiple ways to determine "who is checking what" on their infrastructure (dns requests ,DGA domains that do not match the expected date ,unexpected user agents that shouldn't have triggered the malware infection etc)
You're the expert on networking haha, it's no secret that it's my weakness! Thank you for correcting me bro:)
 
  • Like
Reactions: shmu26 and Wingman

Wingman

Level 4
Thread author
Verified
Well-known
Feb 6, 2017
154
You're the expert on networking haha, it's no secret that it's my weakness! Thank you for correcting me bro:)

I wouldn't say an expect but thanks anyway :)

Network can reveal so much ---especially if you have full packet captures ;)
 
  • Like
Reactions: shmu26 and Wave

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top