March 30th, 2015
Bounty: $60 Description:
Do you want to download sharkfin.pcap file?
Looking at the content of the pcap, most of the traffic is HTTP, HTTPS and the rest is noise. However one packet that doesn’t seem right is UDP from 127.0.0.1 to 127.0.0.1. We know that this is not normal traffic but instead it’s crafted.
This doesn’t look like NETBIOS traffic at all, right ? Let’s convert from hex to ascii.