1200KM · ANDREY PAUTOV
Home · Article · Ten reports · Screenshot gallery · Publication boundaries

Measured 19 September 2026 · Public derivative · Historical training evidence, not approved threat intelligence.

AdversaryGraph Deterministic PCAP Analysis

Source: 2024-11-26-traffic-analysis-exercise.pcap Capture SHA-256: a38267943a7bf3b0e445d7e51cb0a68b3dee797d67081bc9a033f73d079c0f50 Semantic result SHA-256: 4fa4f2aabaa7bcc51a396dcd62fc65dbd2ee862d01d0ba16095da5915212d518 Analyzer manifest SHA-256: ee952aeb7cdc6958f4ae5178c54c274a1e4f0aec4d42f3bdb95baaff063b3dde

Executive summary

Decoded 26922 packets across 61 IP endpoints and 276 transport flows. Observed 343 DNS events, 74 HTTP requests, 109 TLS ClientHello events, and 11 exported HTTP object(s). Deterministic rules produced 12 finding(s): 2 high, 2 medium, and 8 low. Findings are evidence-bound candidates and require analyst review; encrypted payload contents remain unavailable.

Capture facts

Deterministic findings

MEDIUM — Cleartext HTTP observed on TCP/443

The decoded application protocol is HTTP despite use of the conventional TLS port.

Rule: http-on-tls-port@pcap-rules-v3; confidence: 0.98; evidence: frame 20340 / TCP stream 77, frame 20342 / TCP stream 77, frame 20348 / TCP stream 77, frame 20350 / TCP stream 77, frame 20572 / TCP stream 77.

Metrics: {"destination":"194.180.191.64","host":"194.180.191.64","request_count":58,"source":"10.11.26.183","uri":"http://194.180.191.64/fakeurl.htm"}

HIGH — Periodic HTTP callback pattern

Repeated requests have a stable cadence consistent with automated callback or beacon behavior.

Rule: periodic-http-callbacks@pcap-rules-v3; confidence: 0.88; evidence: frame 20340 / TCP stream 77, frame 20342 / TCP stream 77, frame 20348 / TCP stream 77, frame 20350 / TCP stream 77, frame 20572 / TCP stream 77.

Metrics: {"destination":"194.180.191.64","host":"194.180.191.64","median_absolute_deviation":0.091,"median_interval_seconds":60.154,"method":"POST","port":443,"request_count":58,"source":"10.11.26.183","uri":"http://194.180.191.64/fakeurl.htm"}

HIGH — Remote-access software network signature

An HTTP User-Agent explicitly identifies remote-access software. Validate authorization and endpoint ownership.

Rule: remote-access-user-agent@pcap-rules-v3; confidence: 0.95; evidence: frame 20340 / TCP stream 77, frame 20342 / TCP stream 77, frame 20348 / TCP stream 77, frame 20350 / TCP stream 77, frame 20572 / TCP stream 77.

Metrics: {"destination":"194.180.191.64","request_count":58,"source":"10.11.26.183","user_agent":"NetSupport Manager/1.3"}

MEDIUM — Repeated outbound HTTP POST activity

The same endpoint pair and HTTP target produced repeated POST requests suitable for beaconing or data transfer review.

Rule: repeated-http-posts@pcap-rules-v3; confidence: 0.72; evidence: frame 20340 / TCP stream 77, frame 20342 / TCP stream 77, frame 20348 / TCP stream 77, frame 20350 / TCP stream 77, frame 20572 / TCP stream 77.

Metrics: {"declared_body_bytes":2624,"destination":"194.180.191.64","host":"194.180.191.64","port":443,"request_count":58,"source":"10.11.26.183","uri":"http://194.180.191.64/fakeurl.htm"}

LOW — Repeated unsuccessful DNS resolution

Repeated NXDOMAIN responses may indicate a dead domain, misconfiguration, retrying software, or malicious fallback. They do not establish a domain-generation algorithm.

Rule: repeated-nxdomain@pcap-rules-v3; confidence: 0.5; evidence: frame 23, frame 25, frame 189, frame 190, frame 902.

Metrics: {"domain":"wpad.mshome.net","response_count":24,"source":"10.11.26.183"}

LOW — Repeated unsuccessful DNS resolution

Repeated NXDOMAIN responses may indicate a dead domain, misconfiguration, retrying software, or malicious fallback. They do not establish a domain-generation algorithm.

Rule: repeated-nxdomain@pcap-rules-v3; confidence: 0.5; evidence: frame 19, frame 20, frame 185, frame 186, frame 898.

Metrics: {"domain":"wpad.nemotoads.health","response_count":24,"source":"10.11.26.183"}

LOW — Directory-service protocol activity

Directory protocol operations were decoded. Normal Windows logon uses these protocols; activity alone does not establish discovery, credential theft, or DCSync.

Rule: directory-service-activity@pcap-rules-v3; confidence: 0.95; evidence: frame 304 / TCP stream 11, frame 309 / TCP stream 11, frame 312 / TCP stream 11, frame 315 / TCP stream 11, frame 486 / TCP stream 24.

Metrics: {"destination":"10.11.26.3","event_count":25,"operation_numbers":["0","1","12"],"protocol":"drsuapi","source":"10.11.26.183"}

LOW — Directory-service protocol activity

Directory protocol operations were decoded. Normal Windows logon uses these protocols; activity alone does not establish discovery, credential theft, or DCSync.

Rule: directory-service-activity@pcap-rules-v3; confidence: 0.95; evidence: frame 36 / TCP stream 1, frame 43 / TCP stream 1, frame 46 / TCP stream 1, frame 359 / TCP stream 16, frame 371 / TCP stream 16.

Metrics: {"destination":"10.11.26.3","event_count":64,"operation_numbers":["","0","2","3"],"protocol":"ldap","source":"10.11.26.183"}

LOW — Directory-service protocol activity

Directory protocol operations were decoded. Normal Windows logon uses these protocols; activity alone does not establish discovery, credential theft, or DCSync.

Rule: directory-service-activity@pcap-rules-v3; confidence: 0.95; evidence: frame 330 / TCP stream 10, frame 334 / TCP stream 10, frame 340 / TCP stream 10, frame 344 / TCP stream 10, frame 346 / TCP stream 10.

Metrics: {"destination":"10.11.26.3","event_count":15,"operation_numbers":["1","16","17","3","34","36","39","5","6","64","7"],"protocol":"samr","source":"10.11.26.183"}

LOW — Directory-service protocol activity

Directory protocol operations were decoded. Normal Windows logon uses these protocols; activity alone does not establish discovery, credential theft, or DCSync.

Rule: directory-service-activity@pcap-rules-v3; confidence: 0.95; evidence: frame 305 / TCP stream 11, frame 311 / TCP stream 11, frame 313 / TCP stream 11, frame 316 / TCP stream 11, frame 487 / TCP stream 24.

Metrics: {"destination":"10.11.26.183","event_count":25,"operation_numbers":["0","1","12"],"protocol":"drsuapi","source":"10.11.26.3"}

LOW — Directory-service protocol activity

Directory protocol operations were decoded. Normal Windows logon uses these protocols; activity alone does not establish discovery, credential theft, or DCSync.

Rule: directory-service-activity@pcap-rules-v3; confidence: 0.95; evidence: frame 40 / TCP stream 1, frame 45 / TCP stream 1, frame 363 / TCP stream 16, frame 379 / TCP stream 16, frame 383 / TCP stream 16.

Metrics: {"destination":"10.11.26.183","event_count":49,"operation_numbers":["","1","4,19,19,19,5","4,5","5"],"protocol":"ldap","source":"10.11.26.3"}

LOW — Directory-service protocol activity

Directory protocol operations were decoded. Normal Windows logon uses these protocols; activity alone does not establish discovery, credential theft, or DCSync.

Rule: directory-service-activity@pcap-rules-v3; confidence: 0.95; evidence: frame 333 / TCP stream 10, frame 337 / TCP stream 10, frame 342 / TCP stream 10, frame 345 / TCP stream 10, frame 348 / TCP stream 10.

Metrics: {"destination":"10.11.26.183","event_count":15,"operation_numbers":["1","16","17","3","34","36","39","5","6","64","7"],"protocol":"samr","source":"10.11.26.3"}

ATT&CK candidates

Identities

IOC and artifact candidates

Actor similarity leads

Local enrichment and correlations

No match means unknown in this corpus. Local CTI may postdate the capture. Matches and shared infrastructure require review; no automatic promotion or attribution. Snapshot: 82f0a542eadbd91c1d0554cf45b8bd4f69607e372cf96649bcd6ec9cab5fafb8; recorded 2026-09-19T12:08:41.573203+00:00; mode: local-only. Coverage: {"matched_observables":0,"no_exact_match":243,"observable_limit":5000,"observables_checked":243,"observables_total":243,"prior_case_limit_reached":false,"prior_cases_checked":6,"truncated":false}

Coverage and limitations