By Barry “Baz” Shaw, Senior Engineering Manager, Technology Partner Programs, Endace
At GovWare 2025, Suspicious Video traffic was investigated using Full Packet Capture, revealing the traffic was in fact not video at all, but instead a potential threat masquerading as video to evade detection. Without packet capture this traffic would have gone unnoticed.
In this blog we reveal what led us to be suspicious, how we analyzed the traffic, and the clues that lead us to believe it may be threat traffic to a concerning destination.
Endace Always-on Packet Capture
Two of Endace’s newest EP94C8 EndaceProbes were installed in the GovWare SOC to provide full packet capture to support the conference SOC directives of Protect, Educate, and Innovate. Full packet capture provides unique insight into all activities on the network, delivering critical context and evidence for Incident Response and Threat Hunting teams.
The EndaceProbes each hosted three VMs that were running Zeek and delivering critical log data into Splunk. Custom Zeek script additions provided additional valuable details around clear text passwords in email and HTTP, and the use of insecure protocols. Zeek was also used for file-carving and automated submission of objects to Splunk Attack Analyzer and a beta of Endace’s new Vault API used in a Cisco XDR automated workflow was field tested.
SOC Findings and Lessons Learned
During a cursory review of the file mime-types submitted to Splunk Attack Analyzer, a number of video files were observed. To ascertain the contents of these files, an interactive session was launched in Splunk Attack Analyzer and VLC used to open them. Nothing was observed in these media files, and no codec information was available, which lead to the question “Why did Zeek carve these files in the first place?”
A custom search in Splunk to identify more information about files with mime-type video/mpeg or video/mpv showed a curious pattern emerging. A number of these files were approximately 500 bytes in length – far too small to be a legitimate media file. All these small files were associated with various conference WIFI addresses and all being sent to the same remote IP address.
A bespoke investigation into these IP addresses in Cisco XDR indicated that there were connections to known and suspected malicious sites:
Using EndaceVision the relationship between these addresses could also be seen in the Chords chart where 5 infected hosts were communicating with a single external address. The thicker lines indicated larger data transfers:
Pivoting to the hosted Wireshark instance available on all EndaceProbes quickly revealed the data flows from the conference WIFI to the remote address to be in the form of HTTP POSTs:
Following the HTTP streams in Wireshark then revealed an interesting User-Agent:
A search of the web indicated that these Host and User-Agent strings were used by a now-defunct windows application called SIM Instant Messenger. The domain associated with this application was also defunct and indications are that the project was discontinued in 2008.
On the face of it, this could be an old instant messaging client contacting a central server, but the age of the application and the fact the contents were impossibly small MPEG files continued to raise suspicion. Information relevant to the destination IP address also raised doubts that this was legitimate messaging traffic, even within the context of being embedded inside another application.
The question about how these MPEG files were carved was soon answered by Wireshark:
The first eight bytes of each of these POSTs were associated with different MPEG magic numbers, a few of which are shown below:
Notice that the bytes following the magic numbers in the screenshot above are the same, and there was a lot of repetition of content across all the traffic to the external address – could this be compromised endpoints obfuscating their phone home connections to a C2? The short, directional and periodic nature of these connections could also be seen to support this theory.
Unfortunately, no further context was able to be extracted from this small sample of connections, but further monitoring of small POSTs with MPEG contents external sites would be warranted on a corporate network – we will certainly be looking for similar patterns at future events.
It’s important to note that this threat investigation could not have been conducted without continuous full packet capture provided by EndaceProbe. At no point was this traffic flagged or alerted on, therefore a triggered PCAP or metadata only solution would not have captured these packets and their presence on the network and the risk associated with them would have gone unseen by the network operators. When securing the most important networks in the world it’s critical to have full packet capture for visibility to defend against attackers that will go to extreme lengths to obfuscate their activity.
Acknowledgements
Once again, our thanks go to the Cisco team lead by @Jessica Oppenheimer for the opportunity to include EndaceProbes in the GovWare SOC architecture. The SOC team is a collection of Cisco experts across many domains who were a pleasure to work and innovate with and we came away with a great appreciation for power of the Cisco Security tools. The Endace team was able to prove out integration innovations from previous SOC events and test these in earnest in a real-world environment in preparation for making them generally available to the market.
About GovWare
GovWare Conference and Exhibition is the region’s premier cyber information and connectivity platform, offering multi-channel touchpoints to drive community intel sharing, training, and strategic collaborations.
A trusted nexus for over three decades, GovWare unites policymakers, tech innovators, and end-users across Asia and beyond, driving pertinent dialogues on the latest trends and critical information flow. It empowers growth and innovation through collective insights and partnerships.
Its success lies in the trust and support from the cybersecurity and broader cyber community that it has had the privilege to serve over the years, as well as organisational partners who share the same values and mission to enrich the cyber ecosystem.
Read more
For more blogs in our Endace SOC series, see here:
https://blog.endace.com/tag/soc/


















