Wireshark failed to decode the prelogin message with TDS protocol. Below is the package data. The prelogin message was decoded as Data.
Packet comments Frame 4528: 148 bytes on wire (1184 bits), 148 bytes captured (1184 bits) on interface eth:5:0, id 0 (outbound) Ethernet II, Src: xxxx15:fe:72 (00:xx:xx:15:fe:72), Dst: 12:34:56:78:9a:bc (12:34:56:78:9a:bc) Internet Protocol Version 4, Src: 10.xx.0.x8, Dst: xx.1xx.2xx.1 Transmission Control Protocol, Src Port: 1466, Dst Port: 1433, Seq: 1, Ack: 1, Len: 94 Tabular Data Stream Type: TDS7 pre-login message (18) Status: 0x01, End of message .... ...1 = End of message: True .... ..0. = Ignore this event: False .... .0.. = Event notification: False .... 0... = Reset connection: False ...0 .... = Reset connection keeping transaction state: False Length: 94 Channel: 0 Packet Number: 1 Window: 0 Data (86 bytes) Data: 000024000601002a000102002b000103002c0004040030000105003100240600550001ff04081252000001000001397c005363526ed6eae44faa28695c803ba6b8527b3c7cab692b4a96b0d698c7a15d890201000001 [Length: 86]