[![Logo](https://www.paloaltonetworks.com/wp-content/uploads/2021/07/PANW_Parent.png)](https://www.paloaltonetworks.com/)  
[![Unit42 Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/unit42-logo-white.svg)](https://unit42.paloaltonetworks.com/)  
Menu

* [Tools](https://unit42.paloaltonetworks.com/tools/)
* [ATOMs](https://unit42.paloaltonetworks.com/atoms/)
* [Security Consulting](https://www.paloaltonetworks.com/unit42)
* [About Us](https://unit42.paloaltonetworks.com/about-unit-42/)
* [**Under Attack?**](https://start.paloaltonetworks.com/contact-unit42.html)  
  English
* [English](https://unit42.paloaltonetworks.com/january-wireshark-quiz-answers/)
* [Japanese](https://unit42.paloaltonetworks.com/ja/january-wireshark-quiz-answers/)
* [Threat Research Center](https://unit42.paloaltonetworks.com "Threat Research")
* [Learning Hub](https://unit42.paloaltonetworks.com/category/learning-hub/ "Learning Hub")
* [Cybersecurity Tutorials](https://unit42.paloaltonetworks.com/category/cybersecurity-tutorials/ "Cybersecurity Tutorials")  
  [Cybersecurity Tutorials](https://unit42.paloaltonetworks.com/category/cybersecurity-tutorials/)

# Answers to Unit 42 Wireshark Quiz, January 2023

![Clock Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-clock.svg) 6 min read  
Related Products  
[![Advanced Threat Prevention icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Advanced Threat Prevention](https://unit42.paloaltonetworks.com/product-category/advanced-threat-prevention/ "Advanced Threat Prevention")[![Advanced WildFire icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Advanced WildFire](https://unit42.paloaltonetworks.com/product-category/advanced-wildfire/ "Advanced WildFire")[![Cloud-Delivered Security Services icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Cloud-Delivered Security Services](https://unit42.paloaltonetworks.com/product-category/cloud-delivered-security-services/ "Cloud-Delivered Security Services")[![Cortex XDR icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/cortex_RGB_logo_Icon_Color.png)Cortex XDR](https://unit42.paloaltonetworks.com/product-category/cortex-xdr/ "Cortex XDR")[![Next-Generation Firewall icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Next-Generation Firewall](https://unit42.paloaltonetworks.com/product-category/next-generation-firewall/ "Next-Generation Firewall")

* ![Profile Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-profile-grey.svg)  
  By:
  
  * [Brad Duncan](https://unit42.paloaltonetworks.com/author/brad-duncan/)

* ![Published Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-calendar-grey.svg)  
  Published:January 23, 2023

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-category.svg)  
  Categories:
  
  * [Cybersecurity Tutorials](https://unit42.paloaltonetworks.com/category/cybersecurity-tutorials/)
  * [Learning Hub](https://unit42.paloaltonetworks.com/category/learning-hub/)

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-tags-grey.svg)  
  Tags:
  
  * [AgentTesla](https://unit42.paloaltonetworks.com/tag/agenttesla/)
  * [OriginLogger](https://unit42.paloaltonetworks.com/tag/originlogger/)
  * [Pcap](https://unit42.paloaltonetworks.com/tag/pcap/)
  * [Wireshark](https://unit42.paloaltonetworks.com/tag/wireshark/)
  * [Wireshark Tutorial](https://unit42.paloaltonetworks.com/tag/wireshark-tutorial/)

* [![Download Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-download.svg)](https://unit42.paloaltonetworks.com/january-wireshark-quiz-answers/?pdf=download&lg=en&_wpnonce=c280d701ab "Click here to download")

* [![Print Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-print.svg)](https://unit42.paloaltonetworks.com/january-wireshark-quiz-answers/?pdf=print&lg=en&_wpnonce=c280d701ab "Click here to print")

Share![Down arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/down-arrow.svg)

* ![Link Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-share-link.svg)
* [![Link Email](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-sms.svg)](mailto:?subject=Answers%20to%20Unit%2042%20Wireshark%20Quiz,%20January%202023&body=Check%20out%20this%20article%20https%3A%2F%2Funit42.paloaltonetworks.com%2Fjanuary-wireshark-quiz-answers%2F "Share in email")
* [![Facebook Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-fb-share.svg)](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Funit42.paloaltonetworks.com%2Fjanuary-wireshark-quiz-answers%2F "Share in Facebook")
* [![LinkedIn Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-linkedin-share.svg)](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fjanuary-wireshark-quiz-answers%2F&title=Answers%20to%20Unit%2042%20Wireshark%20Quiz,%20January%202023 "Share in LinkedIn")
* [![Twitter Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-twitter-share.svg)](https://twitter.com/intent/tweet?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fjanuary-wireshark-quiz-answers%2F&text=Answers%20to%20Unit%2042%20Wireshark%20Quiz,%20January%202023 "Share in Twitter")
* [![Reddit Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-reddit-share.svg)](https://www.paloaltonetworks.com//www.reddit.com/submit?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fjanuary-wireshark-quiz-answers%2F&ts=markdown "Share in Reddit")
* [![Mastodon Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-mastodon-share.svg)](https://mastodon.social/share?text=Answers%20to%20Unit%2042%20Wireshark%20Quiz,%20January%202023%20https%3A%2F%2Funit42.paloaltonetworks.com%2Fjanuary-wireshark-quiz-answers%2F "Share in Mastodon")

## Executive Summary

This blog presents the answers for our [January 2023 Unit 42 Wireshark quiz](https://unit42.paloaltonetworks.com/january-wireshark-quiz/). The information is ideal for security professionals who investigate suspicious network activity, but everyone is welcome to review. To get the most benefit, readers should understand basic network traffic concepts and be familiar with [Wireshark](https://www.wireshark.org/).

If you'd like to view the version without answers, [please see the standalone quiz post](https://unit42.paloaltonetworks.com/january-wireshark-quiz/).

| **Related Unit 42 Topics** | [**AgentTesla**](https://unit42.paloaltonetworks.com/category/AgentTesla/)**,** [**OriginLogger**](https://unit42.paloaltonetworks.com/category/OriginLogger/)**,** [**pcap**](https://unit42.paloaltonetworks.com/category/pcap/)**,** [**Wireshark**](https://unit42.paloaltonetworks.com/category/Wireshark/)**,** [**Wireshark Tutorial**](https://unit42.paloaltonetworks.com/category/wireshark-tutorial/) |
|----------------------------|------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|

## Background, Requirements and Quiz Material

This quiz is based on a Palo Alto Networks Unit 42 tweet about [Agent Tesla-style activity from a possible OriginLogger infection](https://twitter.com/Unit42_Intel/status/1611379660029366273) that was found Thursday, Jan. 5, 2023. Figure 1 provides a chain of events from the infection.
![Image 1 is a flow chart showing the Agent Tesla variant infection, starting with malspam. It shows the circuitous route the loader.exe takes depending on the victim’s actions.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/01/word-image-126670-2.jpeg) Figure 1. Flow chart for the Agent Tesla variant infection.

Our investigation for this month's quiz requires [Wireshark](https://www.wireshark.org/). This blog utilizes a recent version of Wireshark, and we recommend Wireshark version 3.x. We also use the [Thunderbird email client](https://www.thunderbird.net/) to review an email extracted from the packet capture (pcap).

Participants should have some basic knowledge of network traffic fundamentals. We also recommend readers customize their Wireshark display to better analyze web traffic. [A list of tutorials and videos is available](https://unit42.paloaltonetworks.com/wireshark-workshop-videos/). As always, we recommend using Wireshark in a non-Windows environment like BSD, Linux or macOS when analyzing malicious Windows-based traffic.

To obtain the pcap, [visit our Github repository](https://github.com/pan-unit42/Wireshark-quizzes/blob/main/2023-01-Unit42-Wireshark-quiz.pcap.zip). Download the ZIP archive and extract the pcap. Use ***infected*** as the password to unlock the ZIP archive.

## Quiz Questions

The Unit 42 Wireshark quiz for January 2023 has the following questions:

* When did the malicious traffic start in UTC?
* What is the victim's IP address?
* What is the victim's MAC address?
* What is the victim's Windows host name?
* What is the victim's Windows user account name?
* How much RAM does the victim's host have?
* What type of CPU is used by the victim's host?
* What is the public IP address of the victim's host?
* What type of account login data was stolen by the malware?

## Quiz Answers

The answers for our January 2023 Unit 42 Wireshark quiz are:

* The malicious traffic started 2023-01-05 at 22:51 UTC
* Victim's IP address: 192.168.1\[.\]27
* Victim's MAC address: bc:ea:fa:22:74:fb
* Victim's Windows host name: DESKTOP-WIN11PC
* Victim's Windows user account name: windows11user
* Amount of victim's RAM on victim's host: 32 GB
* Victim's CPU: Intel(R) Core(TM) i5-13600K
* Victim's public IP address: 173.66.46\[.\]112
* Type of stolen account data: email and web accounts

## Pcap Analysis

Our analysis assumes you have customized Wireshark [according to our tutorials or workshop videos](https://unit42.paloaltonetworks.com/wireshark-workshop-videos/).

Analyzing the pcap requires a basic knowledge of network traffic. You should understand that a router acts as a gateway between public-facing IP addresses and hosts within an internal network.

Participants should recognize internal, non-routable IPv4 addresses. We commonly find one of three classes for non-routable internal IPv4 addresses behind an internet router:

* Class A: 10.0.0\[.\]0/8 (10.0.0\[.\]0 through 10.255.255\[.\]255)
* Class B: 172.16.0\[.\]0/12 (172.16.0\[.\]0 through 172.31.255\[.\]255)
* Class C: 192.168.0\[.\]0/16 (192.168.0\[.\]0 through 192.168.255\[.\]255)

In most pcaps, the victim's IP address is from the internal network. For this month's pcap, our victim is using a Class C non-routable IP address in the 192.168.0\[.\]0/16 range.

How do we find the victim's IP address? Use the basic web filter provided in our Wireshark tutorials, or type the following in your Wireshark filter bar:

http.request or tls.handshake.type eq 1

In the frame details panel for any frame listed in the column display, the source IP address should be 192.168.1\[.\]27. The frame details also provide a MAC address that corresponds to 192.168.1\[.\]27 as shown below in Figure 2.
![Image 2 is a screenshot of the Wireshark program. Highlighted in boxes and with arrows are the victim’s IP address and MAC address in the program.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/01/word-image-126670-3.jpeg) Figure 2. Finding the victim's IP address and MAC address in Wireshark.

In some pcap files, NBNS or SMB traffic provides a victim's Windows host name. Use the following filter in Wireshark:

nbns or smb or smb2

The default host name for a Windows 10 and Windows 11 computer is a 15 character string. The name starts with DESKTOP- and is followed by an alpha-numeric string of seven additional ASCII characters. In Figure 3, we find DESKTOP-WIN11PC in the frame details from one of the frames in the column display.
![Image 4 is a screenshot of the Wireshark program. This shows the SMB traffic from the cpap.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/01/word-image-126670-4.jpeg) Figure 3. Finding the victim's Windows host name in Wireshark.

Please note that threat actors often abuse legitimate products and operating system features for malicious purposes. This does not necessarily imply a flaw or malicious quality to the legitimate software being abused.

The remaining information for this quiz is from stolen data in the unencrypted SMTP traffic. Type smtp in your Wireshark filter. The results reveal several frames as shown below in Figure 4.
![Image 4 is a screenshot of the Wireshark program. This shows the SMTP traffic from the cpap.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/01/word-image-126670-5.jpeg) Figure 4. Finding SMTP traffic from the pcap in Wireshark.

These frames represent a single TCP stream of traffic. Follow the TCP stream to review the associated email as shown in Figures 5 and 6.
![Image 5 is a screenshot of the Wireshark program. Arrows highlight menu windows that show how to follow a single TCP stream.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/01/word-image-126670-6.jpeg) Figure 5. Follow TCP stream for any of the frames in your column display. ![Image 6 is a screenshot of the Wireshark program. It shows the TCP stream of the unencrypted SMTP traffic. Some information has been retracted through blurring.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/01/word-image-126670-7.jpeg) Figure 6. TCP stream of the unencrypted SMTP traffic.

Figure 6 shows the infected Windows host using one email address to relay stolen data to another address. The recipient address collects similar data from other hosts infected by the same malware. The message text has HTML tags, and it is somewhat cumbersome to read.

To more easily view this stolen data, export the email from our pcap, then open the exported file in a Thunderbird email client. Use the following menu chain in Wireshark:

File → Export Objects → IMF

Actions to export the email from the pcap in Wireshark should look similar to Figures 7 and 8.
![Image 7 is a screenshot of the Wireshark program. It shows with arrows how to access the File menu that allows the user to export an IMF file.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/01/word-image-126670-8.jpeg) Figure 7. Exporting an email from unencrypted SMTP traffic in Wireshark. ![Image 8 is a screenshot of the Wireshark program. It shows two windows, showing the process to save an exported email as an .eml file.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/01/word-image-126670-9.jpeg) Figure 8. Saving the exported email as an .eml file.

Once the email has been saved, open the file in Thunderbird to see the content. Figure 9 shows the exported message viewed in Thunderbird.
![Image 9 is a screenshot of the Thunderbird program, an email program. It shows the exported email.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/01/word-image-126670-10.jpeg) Figure 9. Viewing the exported email in Thunderbird.

The email contains information about the infected Windows host, including account credentials saved by the victim's email client (Thunderbird) and web browser (Microsoft Edge). Stolen data includes information such as the operating system, Windows user account name, CPU, amount of RAM and public IP address of the infected host.

Of note, none of these are legitimate login credentials. Before running the malware, we populated the host with fake login data. However, the traffic illustrates the type of data stolen by Agent Tesla variants like OriginLogger.

## Conclusion

This blog provides answers to [our Unit 42 Wireshark quiz for January 2023](https://unit42.paloaltonetworks.com/january-wireshark-quiz/). We reviewed traffic from the pcap to answer characteristics of the infected Windows host, and we discovered what type of data this malware steals.

Many organizations lack access to full packet capture in their IT environment. As a result, many security professionals lack experience in reviewing network traffic. Training material like this Wireshark quiz can help. Pcap analysis is a useful skill that helps us better understand malicious activity.

You can also find the original post, without answers, for this month's Unit 42 Wireshark quiz.

Palo Alto Networks customers receive protections from Agent Tesla variants like OriginLogger through [Cortex XDR](https://www.paloaltonetworks.com/cortex/cortex-xdr) and our [Next-Generation Firewall](https://www.paloaltonetworks.com/network-security/next-generation-firewall) with [cloud-delivered security services](https://www.paloaltonetworks.com/network-security/security-subscriptions) including [WildFire](https://www.paloaltonetworks.com/network-security/wildfire) and [Advanced Threat Prevention](https://www.paloaltonetworks.com/network-security/advanced-threat-prevention).

If you think you may have been compromised or have an urgent matter, contact the [Unit 42 Incident Response team](https://start.paloaltonetworks.com/contact-unit42.html) or call:

* North America Toll-Free: 866.486.4842 (866.4.UNIT42)
* EMEA: +31.20.299.3130
* APAC: +65.6983.8730
* Japan: +81.50.1790.0200

## Additional Resources

[Wireshark Tutorial: Wireshark Workshop Videos Now Available](https://unit42.paloaltonetworks.com/wireshark-workshop-videos/) -- Unit 42, Palo Alto Networks

*Updated Jan. 30, 2023, at 12:26 p.m. PT to correct MB to GB in quiz answers.*
Back to top

### Tags

* [AgentTesla](https://unit42.paloaltonetworks.com/tag/agenttesla/ "AgentTesla")
* [OriginLogger](https://unit42.paloaltonetworks.com/tag/originlogger/ "OriginLogger")
* [Pcap](https://unit42.paloaltonetworks.com/tag/pcap/ "pcap")
* [Wireshark](https://unit42.paloaltonetworks.com/tag/wireshark/ "Wireshark")
* [Wireshark Tutorial](https://unit42.paloaltonetworks.com/tag/wireshark-tutorial/ "Wireshark Tutorial")  
  [Threat Research Center](https://unit42.paloaltonetworks.com "Threat Research") [Next: Unit 42 Wireshark Quiz, January 2023](https://unit42.paloaltonetworks.com/january-wireshark-quiz/ "Unit 42 Wireshark Quiz, January 2023")

### Table of Contents

* 

### Related Articles

* [Uncovering .NET Malware Obfuscated by Encryption and Virtualization](https://unit42.paloaltonetworks.com/malware-obfuscation-techniques/ "article - table of contents")
* [Wireshark Tutorial: Exporting Objects From a Pcap](https://unit42.paloaltonetworks.com/using-wireshark-exporting-objects-from-a-pcap/ "article - table of contents")
* [From DarkGate to AsyncRAT: Malware Detected and Shared As Unit 42 Timely Threat Intelligence](https://unit42.paloaltonetworks.com/unit42-threat-intelligence-roundup/ "article - table of contents")

## Related Cybersecurity Tutorials Resources

![A Black man in business attire using a tablet, with illuminated skyscrapers in the background.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/01_Tutorial_Category_1920x900-786x368.jpg)  
[![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-podcast-player.svg)Learning Hub](https://unit42.paloaltonetworks.com/category/learning-hub/) March 1, 2024 [#### Wireshark Tutorial: Exporting Objects From a Pcap](https://unit42.paloaltonetworks.com/using-wireshark-exporting-objects-from-a-pcap/)

* [Pcap](https://unit42.paloaltonetworks.com/tag/pcap/ "pcap")

* [Wireshark](https://unit42.paloaltonetworks.com/tag/wireshark/ "Wireshark")

* [Wireshark Tutorial](https://unit42.paloaltonetworks.com/tag/wireshark-tutorial/ "Wireshark Tutorial")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/using-wireshark-exporting-objects-from-a-pcap/ "Wireshark Tutorial: Exporting Objects From a Pcap")  
  ![A man wearing headphones with a microphone is focused on multiple computer screens displaying graphs and data, indicating involvement in a professional tech or analytics environment.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/02_Tutorial_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-podcast-player.svg)Learning Hub](https://unit42.paloaltonetworks.com/category/learning-hub/) October 10, 2023 [#### Wireshark Tutorial: Identifying Hosts and Users](https://unit42.paloaltonetworks.com/using-wireshark-identifying-hosts-and-users/)

* [Pcap](https://unit42.paloaltonetworks.com/tag/pcap/ "pcap")

* [Wireshark](https://unit42.paloaltonetworks.com/tag/wireshark/ "Wireshark")

* [Wireshark Tutorial](https://unit42.paloaltonetworks.com/tag/wireshark-tutorial/ "Wireshark Tutorial")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/using-wireshark-identifying-hosts-and-users/ "Wireshark Tutorial: Identifying Hosts and Users")  
  ![An abstract illustration of a video that has been paused. It includes a red progress bar and a large white Play button.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/03_Tutorial_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-podcast-player.svg)Learning Hub](https://unit42.paloaltonetworks.com/category/learning-hub/) September 8, 2023 [#### Wireshark Tutorial: Display Filter Expressions](https://unit42.paloaltonetworks.com/using-wireshark-display-filter-expressions/)

* [Pcap](https://unit42.paloaltonetworks.com/tag/pcap/ "pcap")

* [Wireshark](https://unit42.paloaltonetworks.com/tag/wireshark/ "Wireshark")

* [Wireshark Tutorial](https://unit42.paloaltonetworks.com/tag/wireshark-tutorial/ "Wireshark Tutorial")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/using-wireshark-display-filter-expressions/ "Wireshark Tutorial: Display Filter Expressions")  
  ![A person focuses intently on a screen, with many lines of code on the monitor reflected in their glasses.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/04_Tutorial_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-podcast-player.svg)Learning Hub](https://unit42.paloaltonetworks.com/category/learning-hub/) September 1, 2023 [#### RedLine Stealer: Answers to Unit 42 Wireshark Quiz](https://unit42.paloaltonetworks.com/wireshark-quiz-redline-stealer-answers/)

* [Pcap](https://unit42.paloaltonetworks.com/tag/pcap/ "pcap")

* [Wireshark Tutorial](https://unit42.paloaltonetworks.com/tag/wireshark-tutorial/ "Wireshark Tutorial")

* [Redline infostealer](https://unit42.paloaltonetworks.com/tag/redline-infostealer/ "Redline infostealer")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/wireshark-quiz-redline-stealer-answers/ "RedLine Stealer: Answers to Unit 42 Wireshark Quiz")  
  ![A man wearing headphones with a microphone is focused on multiple computer screens displaying graphs and data, indicating involvement in a professional tech or analytics environment.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/02_Tutorial_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-podcast-player.svg)Learning Hub](https://unit42.paloaltonetworks.com/category/learning-hub/) August 31, 2023 [#### Wireshark Tutorial: Changing Your Column Display](https://unit42.paloaltonetworks.com/unit42-customizing-wireshark-changing-column-display/)

* [Pcap](https://unit42.paloaltonetworks.com/tag/pcap/ "pcap")

* [Wireshark](https://unit42.paloaltonetworks.com/tag/wireshark/ "Wireshark")

* [Wireshark Tutorial](https://unit42.paloaltonetworks.com/tag/wireshark-tutorial/ "Wireshark Tutorial")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/unit42-customizing-wireshark-changing-column-display/ "Wireshark Tutorial: Changing Your Column Display")  
  ![Person wearing glasses and a hoodie, sitting in a dimly lit room, focused on a computer screen displaying complex data visualizations.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/06_Tutorial_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-podcast-player.svg)Learning Hub](https://unit42.paloaltonetworks.com/category/learning-hub/) August 18, 2023 [#### Crossing the Line: Unit 42 Wireshark Quiz for RedLine Stealer](https://unit42.paloaltonetworks.com/wireshark-quiz-redline-stealer/)

* [Pcap](https://unit42.paloaltonetworks.com/tag/pcap/ "pcap")

* [Redline infostealer](https://unit42.paloaltonetworks.com/tag/redline-infostealer/ "Redline infostealer")

* [Wireshark Tutorial](https://unit42.paloaltonetworks.com/tag/wireshark-tutorial/ "Wireshark Tutorial")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/wireshark-quiz-redline-stealer/ "Crossing the Line: Unit 42 Wireshark Quiz for RedLine Stealer")  
  ![A man wearing headphones with a microphone is focused on multiple computer screens displaying graphs and data, indicating involvement in a professional tech or analytics environment.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/02_Tutorial_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-podcast-player.svg)Learning Hub](https://unit42.paloaltonetworks.com/category/learning-hub/) May 30, 2023 [#### Cold as Ice: Answers to Unit 42 Wireshark Quiz for IcedID](https://unit42.paloaltonetworks.com/wireshark-quiz-icedid-answers/)

* [Banking trojans](https://unit42.paloaltonetworks.com/tag/banking-trojans/ "banking trojans")

* [Pcap](https://unit42.paloaltonetworks.com/tag/pcap/ "pcap")

* [Wireshark](https://unit42.paloaltonetworks.com/tag/wireshark/ "Wireshark")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/wireshark-quiz-icedid-answers/ "Cold as Ice: Answers to Unit 42 Wireshark Quiz for IcedID")  
  ![A woman is intently working on a computer in a modern office environment, surrounded by screens displaying dynamic digital data and stock market numbers, highlighting a focus on financial analysis.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/04_Security-Technology_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-podcast-player.svg)Learning Hub](https://unit42.paloaltonetworks.com/category/learning-hub/) May 26, 2023 [#### Cold as Ice: Unit 42 Wireshark Quiz for IcedID](https://unit42.paloaltonetworks.com/wireshark-quiz-icedid/)

* [Banking trojans](https://unit42.paloaltonetworks.com/tag/banking-trojans/ "banking trojans")

* [Pcap](https://unit42.paloaltonetworks.com/tag/pcap/ "pcap")

* [Wireshark](https://unit42.paloaltonetworks.com/tag/wireshark/ "Wireshark")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/wireshark-quiz-icedid/ "Cold as Ice: Unit 42 Wireshark Quiz for IcedID")  
  ![Two people working in a modern office environment with one person concentrating on a computer screen displaying code while another person works in the background.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/10_Security-Technology_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/threat-actor-groups.svg)Threat Actor Groups](https://unit42.paloaltonetworks.com/category/threat-actor-groups/) May 15, 2023 [#### It's All in the Name: How Unit 42 Defines and Tracks Threat Adversaries](https://unit42.paloaltonetworks.com/from-activity-to-formal-naming/)

* [Advanced Persistent Threat](https://unit42.paloaltonetworks.com/tag/advanced-persistent-threat/ "Advanced Persistent Threat")

* [Nomenclature](https://unit42.paloaltonetworks.com/tag/nomenclature/ "nomenclature")

* [Threat actors](https://unit42.paloaltonetworks.com/tag/threat-actors/ "threat actors")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/from-activity-to-formal-naming/ "It’s All in the Name: How Unit 42 Defines and Tracks Threat Adversaries")  
  ![A Black man in business attire using a tablet, with illuminated skyscrapers in the background.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/01_Tutorial_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-podcast-player.svg)Learning Hub](https://unit42.paloaltonetworks.com/category/learning-hub/) March 27, 2023 [#### Finding Gozi: Answers to Unit 42 Wireshark Quiz, March 2023](https://unit42.paloaltonetworks.com/march-wireshark-gozi-answers/)

* [Gozi](https://unit42.paloaltonetworks.com/tag/gozi/ "Gozi")

* [Pcap](https://unit42.paloaltonetworks.com/tag/pcap/ "pcap")

* [Wireshark](https://unit42.paloaltonetworks.com/tag/wireshark/ "Wireshark")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/march-wireshark-gozi-answers/ "Finding Gozi: Answers to Unit 42 Wireshark Quiz, March 2023")

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)  
  ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg) ![Enlarged Image]()  
  ![Newsletter](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/unit42-footer-subscribe-desktop.png)  
  ![UNIT 42 Small Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/palo-alto-logo-small.svg) Get updates from Unit 42

## Peace of mind comes from staying ahead of threats. Subscribe today.

Your Email

Subscribe for email updates to all Unit 42 threat research.  
By submitting this form, you agree to our [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use "Terms of Use") and acknowledge our [Privacy Statement.](https://www.paloaltonetworks.com/legal-notices/privacy "Privacy Statement")

This site is protected by reCAPTCHA and the Google [Privacy Policy](https://policies.google.com/privacy) and [Terms of Service](https://policies.google.com/terms) apply.

Invalid captcha!
Subscribe ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg) ![loader](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-loader.svg)  
{#footer} Products and Services

* [AI-Powered Network Security Platform](https://www.paloaltonetworks.com/network-security)

* [Secure AI by Design](https://www.paloaltonetworks.com/ai-security)

* [Prisma AIRS](https://www.paloaltonetworks.com/ai-security/prisma-airs)

* [AI Access Security](https://www.paloaltonetworks.com/sase/ai-access-security)

* [Cloud Delivered Security Services](https://www.paloaltonetworks.com/network-security/security-subscriptions)

* [Advanced Threat Prevention](https://www.paloaltonetworks.com/network-security/advanced-threat-prevention)

* [Advanced URL Filtering](https://www.paloaltonetworks.com/network-security/advanced-url-filtering)

* [Advanced WildFire](https://www.paloaltonetworks.com/network-security/advanced-wildfire)

* [Advanced DNS Security](https://www.paloaltonetworks.com/network-security/advanced-dns-security)

* [Enterprise Data Loss Prevention](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention)

* [Enterprise IoT Security](https://www.paloaltonetworks.com/network-security/enterprise-device-security)

* [Medical IoT Security](https://www.paloaltonetworks.com/network-security/medical-device-security)

* [Industrial OT Security](https://www.paloaltonetworks.com/network-security/ot-security-solution)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security)

* [Next-Generation Firewalls](https://www.paloaltonetworks.com/network-security/next-generation-firewall)

* [Hardware Firewalls](https://www.paloaltonetworks.com/network-security/hardware-firewall-innovations)

* [Software Firewalls](https://www.paloaltonetworks.com/network-security/software-firewalls)

* [Strata Cloud Manager](https://www.paloaltonetworks.com/network-security/strata-cloud-manager)

* [SD-WAN for NGFW](https://www.paloaltonetworks.com/network-security/sd-wan-subscription)

* [PAN-OS](https://www.paloaltonetworks.com/network-security/pan-os)

* [Panorama](https://www.paloaltonetworks.com/network-security/panorama)

* [Secure Access Service Edge](https://www.paloaltonetworks.com/sase)

* [Prisma SASE](https://www.paloaltonetworks.com/sase)

* [Application Acceleration](https://www.paloaltonetworks.com/sase/app-acceleration)

* [Autonomous Digital Experience Management](https://www.paloaltonetworks.com/sase/adem)

* [Enterprise DLP](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention)

* [Prisma Access](https://www.paloaltonetworks.com/sase/access)

* [Prisma Browser](https://www.paloaltonetworks.com/sase/prisma-browser)

* [Prisma SD-WAN](https://www.paloaltonetworks.com/sase/sd-wan)

* [Remote Browser Isolation](https://www.paloaltonetworks.com/sase/remote-browser-isolation)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security)

* [AI-Driven Security Operations Platform](https://www.paloaltonetworks.com/cortex)

* [Cloud Security](https://www.paloaltonetworks.com/cortex/cloud)

* [Cortex Cloud](https://www.paloaltonetworks.com/cortex/cloud)

* [Application Security](https://www.paloaltonetworks.com/cortex/cloud/application-security)

* [Cloud Posture Security](https://www.paloaltonetworks.com/cortex/cloud/cloud-posture-security)

* [Cloud Runtime Security](https://www.paloaltonetworks.com/cortex/cloud/runtime-security)

* [Prisma Cloud](https://www.paloaltonetworks.com/prisma/cloud)

* [AI-Driven SOC](https://www.paloaltonetworks.com/cortex)

* [Cortex XSIAM](https://www.paloaltonetworks.com/cortex/cortex-xsiam)

* [Cortex XDR](https://www.paloaltonetworks.com/cortex/cortex-xdr)

* [Cortex XSOAR](https://www.paloaltonetworks.com/cortex/cortex-xsoar)

* [Cortex Xpanse](https://www.paloaltonetworks.com/cortex/cortex-xpanse)

* [Unit 42 Managed Detection \& Response](https://www.paloaltonetworks.com/cortex/managed-detection-and-response)

* [Managed XSIAM](https://www.paloaltonetworks.com/cortex/managed-xsiam)

* [Next-Generation Identity Security](https://www.paloaltonetworks.com/idira)

* [Privileged Access Management](https://www.paloaltonetworks.com/idira/human/privileged-access-management)

* [Identity and Access Management](https://www.paloaltonetworks.com/idira/human/identity-and-access-management)

* [Endpoint Privilege Manager](https://www.paloaltonetworks.com/idira/human/endpoint-privilege-manager)

* [Identity Governance](https://www.paloaltonetworks.com/idira/human/identity-governance)

* [Workforce Password Management](https://www.paloaltonetworks.com/idira/human/workforce-password-management)

* [Agentic Identities](https://www.paloaltonetworks.com/idira/agentic)

* [Secrets Management](https://www.paloaltonetworks.com/idira/machine/secrets-management)

* [Unified Secrets Governance](https://www.paloaltonetworks.com/idira/machine/unified-secrets-governance)

* [Application Credentials Delivery](https://www.paloaltonetworks.com/idira/machine/application-credentials-delivery)

* [Vendor Privileged Access](https://www.paloaltonetworks.com/idira/human/vendor-privileged-access)

* [Threat Intel and Incident Response Services](https://www.paloaltonetworks.com/unit42)

* [Proactive Assessments](https://www.paloaltonetworks.com/unit42/assess)

* [Incident Response](https://www.paloaltonetworks.com/unit42/respond)

* [Transform Your Security Strategy](https://www.paloaltonetworks.com/unit42/transform)

* [Discover Threat Intelligence](https://www.paloaltonetworks.com/unit42/threat-intelligence-partners)  
  Company

* [About Us](https://www.paloaltonetworks.com/about-us)

* [Careers](https://jobs.paloaltonetworks.com/en/)

* [Contact Us](https://www.paloaltonetworks.com/company/contact-sales)

* [Corporate Responsibility](https://www.paloaltonetworks.com/about-us/corporate-responsibility)

* [Customers](https://www.paloaltonetworks.com/customers)

* [Investor Relations](https://investors.paloaltonetworks.com/)

* [Location](https://www.paloaltonetworks.com/about-us/locations)

* [Newsroom](https://www.paloaltonetworks.com/company/newsroom)  
  Popular Links

* [Blog](https://www.paloaltonetworks.com/blog/)

* [Communities](https://www.paloaltonetworks.com/communities)

* [Content Library](https://www.paloaltonetworks.com/resources)

* [Cyberpedia](https://www.paloaltonetworks.com/cyberpedia)

* [Event Center](https://events.paloaltonetworks.com/)

* [Manage Email Preferences](https://start.paloaltonetworks.com/preference-center)

* [Products A-Z](https://www.paloaltonetworks.com/products/products-a-z)

* [Product Certifications](https://www.paloaltonetworks.com/legal-notices/trust-center/certifications)

* [Report a Vulnerability](https://www.paloaltonetworks.com/security-disclosure)

* [Sitemap](https://www.paloaltonetworks.com/sitemap)

* [Tech Docs](https://docs.paloaltonetworks.com/)

* [Unit 42](https://unit42.paloaltonetworks.com/)

* [Do Not Sell or Share My Personal Information](https://panwedd.exterro.net/portal/dsar.htm?target=panwedd)
  ![Palo Alto Networks Logo](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/pan-logo-dark.svg)

* [Privacy](https://www.paloaltonetworks.com/legal-notices/privacy)

* [Trust Center](https://www.paloaltonetworks.com/legal-notices/trust-center)

* [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use)

* [Documents](https://www.paloaltonetworks.com/legal)

Copyright © 2026 Palo Alto Networks. All Rights Reserved

* [![Youtube](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/youtube-black.svg)](https://www.youtube.com/user/paloaltonetworks)
* [![Podcast](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/icons/podcast.svg)](https://www.paloaltonetworks.com/podcasts/threat-vector)
* [![Facebook](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/facebook-black.svg)](https://www.facebook.com/PaloAltoNetworks/)
* [![LinkedIn](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/linkedin-black.svg)](https://www.linkedin.com/company/palo-alto-networks)
* [![Twitter](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/twitter-x-black.svg)](https://twitter.com/PaloAltoNtwks)
* EN  
  Select your language  
  ![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg) ![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg) ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg)

### Default Heading

Read the article ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg)  
Seekbar

![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg)  
![Volume](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-volume.svg)  
Volume
![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg)
