Govware 2025: Full packet capture reveals suspicious connections with empty data to many malicious IPs

Original Entry by : Sundarram Paravastu

Sundarram Paravastu, Principal Software Engineer, Endace


At the recent Govware 2025 event in Singapore, two of Endace’s newest EP94C8 EndaceProbes were installed in the GovWare SOC to provide full packet capture to support the conference SOC directives of Protect, Educate, and Innovate.

Full packet capture provides unique insight into all activity on the network, delivering critical context and evidence for Incident Response and Threat Hunting teams.

The EndaceProbes each hosted three VMs that were running Zeek and delivering critical log data into Splunk.  Custom Zeek script additions provided additional valuable details around clear text passwords in email and HTTP, and the use of insecure protocols.  Attendees at GovWare 2025 impressed the SOC team with a high level of security awareness resulting in a very low prevalence of clear text data and insecure protocols.  Zeek was also used for file-carving and automated submission of object to Splunk Attack Analyzer and a beta of Endace’s new Vault API used in a Cisco XDR automated workflow was field tested.

SOC Findings and Lessons Learned

A firewall incident of blocking connection to a malicious IP by firewall was reported in Cisco XDR.

Looking further into the incident, any markers for compromise was further investigated. Inspecting the packets in EndaceProbe revealed a strange pattern of successive connection creation within a short span of time (2-5ms) to different hosts. The other strange aspect was that the connection was immediately closed after receiving a response from these hosts. Adding to the suspicion was this beaconing was done within a few seconds of connecting to the Wifi network. Most of the ips being connected to on further investigation revealed were flagged and were reported to have been involved in suspicious/malware activities.

Pivoting to the hosted wireshark instance available on all EndaceProbes quickly revealed that a burst of connections were created by the host within a span of 3 milliseconds and closed immediately after receiving response:

Analyzing suspicious traffic bursts in Wireshark

Following the individual connections in Wireshark revealed that no data was being shared, and only ability to connect was being tested.

None of these IP addresses are present in any DNS lookup prior to the connection initiation and this many connections within a very short span (3ms) reveals it is likely a program doing it with a pre-existing list of IP addresses.

This is likely a beaconing to C2 infrastructure, where it is only touching base with servers to see which ones are active and the program is probably in dormant state or in the initial stage of just verifying connectivity.

Having full packet capture gave us visibility beyond the single blocked IP reported by the firewall. It allowed us to examine all other connections that were not flagged. The packet data confirmed that the IP addresses were not obtained via DNS and that the activity was triggered immediately after the host connected to the Wi-Fi network. Additionally, the captures verified that no data was transmitted during the beaconing attempts to the malicious IP addresses. As part of the investigation, we also checked whether other hosts on the network were making connections to these IPs.

Acknowledgements

Once again, our thanks go to the Cisco team lead by @Jessica Oppenheimer for the opportunity to include EndaceProbes in the GovWare SOC architecture.  The SOC team is a collection of Cisco experts across many domains who were a pleasure to work and innovate with and we came away with a great appreciation for power of the Cisco Security tools.  The Endace team was able to prove out integration innovations from previous SOC events and test these in earnest in a real-world environment in preparation for making them generally available to the market.

About GovWare

GovWare Conference and Exhibition is the region’s premier cyber information and connectivity platform, offering multi-channel touchpoints to drive community intel sharing, training, and strategic collaborations.

A trusted nexus for over three decades, GovWare unites policymakers, tech innovators, and end-users across Asia and beyond, driving pertinent dialogues on the latest trends and critical information flow. It empowers growth and innovation through collective insights and partnerships.

Its success lies in the trust and support from the cybersecurity and broader cyber community that it has had the privilege to serve over the years, as well as organisational partners who share the same values and mission to enrich the cyber ecosystem.

Read More

For more blogs in our Endace SOC series, see here:
https://blog.endace.com/tag/soc/


Govware 2025: Full packet capture reveals suspicious traffic masquerading as MPEG in HTTP POSTS

Original Entry by : Barry "Baz" Shaw

By Barry “Baz” Shaw, Senior Engineering Manager, Technology Partner Programs, Endace


Barry

At GovWare 2025, Suspicious Video traffic was investigated using Full Packet Capture, revealing the traffic was in fact not video at all, but instead a potential threat masquerading as video to evade detection. Without packet capture this traffic would have gone unnoticed.

In this blog we reveal what led us to be suspicious, how we analyzed the traffic, and the clues that lead us to believe it may be threat traffic to a concerning destination.

Endace Always-on Packet Capture

Two of Endace’s newest EP94C8 EndaceProbes were installed in the GovWare SOC to provide full packet capture to support the conference SOC directives of Protect, Educate, and Innovate.  Full packet capture provides unique insight into all activities on the network, delivering critical context and evidence for Incident Response and Threat Hunting teams.

The EndaceProbes each hosted three VMs that were running Zeek and delivering critical log data into Splunk.  Custom Zeek script additions provided additional valuable details around clear text passwords in email and HTTP, and the use of insecure protocols.  Zeek was also used for file-carving and automated submission of objects to Splunk Attack Analyzer and a beta of Endace’s new Vault API used in a Cisco XDR automated workflow was field tested.   

SOC Findings and Lessons Learned

During a cursory review of the file mime-types submitted to Splunk Attack Analyzer, a number of video files were observed.  To ascertain the contents of these files, an interactive session was launched in Splunk Attack Analyzer and VLC used to open them.  Nothing was observed in these media files, and no codec information was available, which lead to the question “Why did Zeek carve these files in the first place?”

A custom search in Splunk to identify more information about files with mime-type video/mpeg or video/mpv showed a curious pattern emerging.  A number of these files were approximately 500 bytes in length – far too small to be a legitimate media file.  All these small files were associated with various conference WIFI addresses and all being sent to the same remote IP address.

A bespoke investigation into these IP addresses in Cisco XDR indicated that there were connections to known and suspected malicious sites:

Suspicious hosts in CIsco XDR

Using EndaceVision the relationship between these addresses could also be seen in the Chords chart where 5 infected hosts were communicating with a single external address. The thicker lines indicated larger data transfers:

Using the chord chart to visualize conversations

Pivoting to the hosted Wireshark instance available on all EndaceProbes quickly revealed the data flows from the conference WIFI to the remote address to be in the form of HTTP POSTs:

Following the HTTP streams in Wireshark then revealed an interesting User-Agent:

Following TCP Streams shows a User Agent listed as "IM-SIMUHTTP"

A search of the web indicated that these Host and User-Agent strings were used by a now-defunct windows application called SIM Instant Messenger.  The domain associated with this application was also defunct and indications are that the project was discontinued in 2008. 

On the face of it, this could be an old instant messaging client contacting a central server, but the age of the application and the fact the contents were impossibly small MPEG files continued to raise suspicion.  Information relevant to the destination IP address also raised doubts that this was legitimate messaging traffic, even within the context of being embedded inside another application.

The question about how these MPEG files were carved was soon answered by Wireshark:

Looking at the HTTP posts in Wireshark

The first eight bytes of each of these POSTs were associated with different MPEG magic numbers, a few of which are shown below:

List of Magic Numbers seen in Wireshark analysis of the packets

Notice that the bytes following the magic numbers in the screenshot above are the same, and there was a lot of repetition of content across all the traffic to the external address – could this be compromised endpoints obfuscating their phone home connections to a C2?  The short, directional and periodic nature of these connections could also be seen to support this theory.

Unfortunately, no further context was able to be extracted from this small sample of connections, but further monitoring of small POSTs with MPEG contents external sites would be warranted on a corporate network – we will certainly be looking for similar patterns at future events.

It’s important to note that this threat investigation could not have been conducted without continuous full packet capture provided by EndaceProbe.  At no point was this traffic flagged or alerted on, therefore a triggered PCAP or metadata only solution would not have captured these packets and their presence on the network and the risk associated with them would have gone unseen by the network operators.  When securing the most important networks in the world it’s critical to have full packet capture for visibility to defend against attackers that will go to extreme lengths to obfuscate their activity.

Acknowledgements

Once again, our thanks go to the Cisco team lead by @Jessica Oppenheimer for the opportunity to include EndaceProbes in the GovWare SOC architecture.  The SOC team is a collection of Cisco experts across many domains who were a pleasure to work and innovate with and we came away with a great appreciation for power of the Cisco Security tools.  The Endace team was able to prove out integration innovations from previous SOC events and test these in earnest in a real-world environment in preparation for making them generally available to the market.

About GovWare

GovWare Conference and Exhibition is the region’s premier cyber information and connectivity platform, offering multi-channel touchpoints to drive community intel sharing, training, and strategic collaborations.

A trusted nexus for over three decades, GovWare unites policymakers, tech innovators, and end-users across Asia and beyond, driving pertinent dialogues on the latest trends and critical information flow. It empowers growth and innovation through collective insights and partnerships.

Its success lies in the trust and support from the cybersecurity and broader cyber community that it has had the privilege to serve over the years, as well as organisational partners who share the same values and mission to enrich the cyber ecosystem.

Read more

For more blogs in our Endace SOC series, see here:
https://blog.endace.com/tag/soc/ 


Episode #64 with Steve Fink talking about building next-Gen SOCs with AI, automation, and resilience

Original Entry by : Michael Morris

In the Packet Forensic Files, Episode 64, Michael talks to Steve “Fink”, CTO and CISO at Secure Yeti

By Michael Morris, Director of Global Business Development, Endace


Michael Morris, Director of Global Business Development, Endace

Building Next-Gen SOCs with AI, Automation, and Resilience

In this episode of The Packet Forensic Files, I’m joined by Steve “Fink” Fink, CTO and CISO at Secure Yeti, and the mastermind behind the Security Operations Centers (SOCs) and Networks Operations Centers (NOCs) that power some of the biggest cybersecurity events in the world, including Black Hat, RSA Conference, and Cisco Live.

With more than 26 years in cybersecurity, beginning with pen-testing the FBI, Fink has built and operated some of the most complex SOCs in the world. He shared his insights into what it takes to design resilient, scalable, and future-ready security environments.

It All Starts with the Packets

Fink believes that true visibility begins at the packet level:

“If you don’t have the context of your network, it’s almost impossible to conduct a valid investigation or build an effective response plan.”

By combining full packet capture with contextual data and up-to-date asset inventories, analysts gain the visibility necessary to detect and respond in real-time.

Automation, AI, and Resilience

At Secure Yeti, Fink has automated nearly every SOC function up to Tier 4 using agentic AI, handling over 97% of the workload. This automation enables scalability, consistency, and around-the-clock response, freeing human analysts to focus on higher-level investigations.

Resilience is also a core design principle. Fink ensures redundancy at every level, emphasizing that even if one component fails, “the whole thing shouldn’t descend into chaos.”

Collaboration and Interoperability

At events like Black Hat and RSA, Fink brings together traditionally competing vendors, from firewalls and SIEMs to XDR and packet capture platforms, to collaborate within a single SOC. That cooperation, he says, fuels product innovation and real-world interoperability.

At Endace, we share Fink’s philosophy that packets provide the ultimate source of truth for understanding what’s happening on the network and driving smarter, faster investigations.

Don’t miss this episode as Fink shares how operational excellence and AI-driven security are being redefined.

PFF Ep 64 Steve Fink Video Thumbnail

Other episodes in the Secure Networks video/audio podcast series are available here. Or listen to the podcast here or on your favorite podcast platform.