Ask Your Question
0

Strange packets captured

asked 2019-06-02 18:34:22 +0000

awfulme gravatar image

updated 2019-06-02 21:19:32 +0000

Hello. I'm receiving strange packets. Does anybody have any idea what is it? image description

edit retag flag offensive close merge delete

Comments

Not from a picture, and especially not from a picture that is no longer available. Could you upload the pcap file somewhere on a public share like dropbox, onedrive, etc and post the link here?

SYN-bit gravatar imageSYN-bit ( 2019-06-02 20:44:00 +0000 )edit
awfulme gravatar imageawfulme ( 2019-06-02 21:18:52 +0000 )edit

1 Answer

Sort by ยป oldest newest most voted
0

answered 2019-06-02 22:15:52 +0000

SYN-bit gravatar image

Thanks for uploading the file and making sure the picture is available. The only things I can deduct are:

  1. IP address 112.11.202.22 Geo-locates to China
  2. Port 8999 might be related to Crypto, backup or quicktime (or something else completely)
  3. The packets are sent out every ~29 sec, which is kind-of odd (usually one would then see around 30 sec interval)
  4. Most UDP payload is the same in every packet, except for byte offset 4-7. These 32 bits seem to count up. As the value increases with ~29000000 between the packets, this looks like a microsecond counter.

Hope this helps a bit...

edit flag offensive delete link more

Comments

1

I don't know what that traffic is, but to take the discovery process a little further:

If you own/control 192.168.31.177, you could check to see if their is a UDP listener for that traffic coming in. If so, the name of the executable might give you a clue. As admin/root, in Linux, you could try

netstat -unlp

or in Windows,

netstat -p udp -nab

Since it is a Dell mac, I am assuming that it is not MacOS.

Look for UDP port 8999 in the results listing; is their an executable? If so, see if you can find where it came from. Maybe the folder it is in... or from Google.

Bob Jones gravatar imageBob Jones ( 2019-06-02 23:19:08 +0000 )edit

Your Answer

Please start posting anonymously - your entry will be published after you log in or create a new account.

Add Answer

Question Tools

Stats

Asked: 2019-06-02 18:34:22 +0000

Seen: 1,624 times

Last updated: Jun 02 '19