[![Logo](https://www.paloaltonetworks.com/wp-content/uploads/2021/07/PANW_Parent.png)](https://www.paloaltonetworks.com/)  
[![Unit42 Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/unit42-logo-white.svg)](https://unit42.paloaltonetworks.com/)  
Menu

* [Tools](https://unit42.paloaltonetworks.com/tools/)
* [ATOMs](https://unit42.paloaltonetworks.com/atoms/)
* [Security Consulting](https://www.paloaltonetworks.com/unit42)
* [About Us](https://unit42.paloaltonetworks.com/about-unit-42/)
* [**Under Attack?**](https://start.paloaltonetworks.com/contact-unit42.html)  
  English
* [English](https://unit42.paloaltonetworks.com/wireshark-quiz-redline-stealer/)
* [Japanese](https://unit42.paloaltonetworks.com/ja/wireshark-quiz-redline-stealer/)
* [Threat Research Center](https://unit42.paloaltonetworks.com "Threat Research")
* [Learning Hub](https://unit42.paloaltonetworks.com/category/learning-hub/ "Learning Hub")
* [Cybersecurity Tutorials](https://unit42.paloaltonetworks.com/category/cybersecurity-tutorials/ "Cybersecurity Tutorials")  
  [Cybersecurity Tutorials](https://unit42.paloaltonetworks.com/category/cybersecurity-tutorials/)

# Crossing the Line: Unit 42 Wireshark Quiz for RedLine Stealer

![Clock Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-clock.svg) 4 min read  
Related Products  
[![Advanced Threat Prevention icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Advanced Threat Prevention](https://unit42.paloaltonetworks.com/product-category/advanced-threat-prevention/ "Advanced Threat Prevention")[![Advanced WildFire icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Advanced WildFire](https://unit42.paloaltonetworks.com/product-category/advanced-wildfire/ "Advanced WildFire")[![Cloud-Delivered Security Services icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Cloud-Delivered Security Services](https://unit42.paloaltonetworks.com/product-category/cloud-delivered-security-services/ "Cloud-Delivered Security Services")[![Cortex XDR icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/cortex_RGB_logo_Icon_Color.png)Cortex XDR](https://unit42.paloaltonetworks.com/product-category/cortex-xdr/ "Cortex XDR")[![Next-Generation Firewall icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Next-Generation Firewall](https://unit42.paloaltonetworks.com/product-category/next-generation-firewall/ "Next-Generation Firewall")

* ![Profile Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-profile-grey.svg)  
  By:
  
  * [Brad Duncan](https://unit42.paloaltonetworks.com/author/brad-duncan/)

* ![Published Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-calendar-grey.svg)  
  Published:August 18, 2023

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-category.svg)  
  Categories:
  
  * [Cybersecurity Tutorials](https://unit42.paloaltonetworks.com/category/cybersecurity-tutorials/)
  * [Learning Hub](https://unit42.paloaltonetworks.com/category/learning-hub/)

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-tags-grey.svg)  
  Tags:
  
  * [Pcap](https://unit42.paloaltonetworks.com/tag/pcap/)
  * [Redline infostealer](https://unit42.paloaltonetworks.com/tag/redline-infostealer/)
  * [Wireshark](https://unit42.paloaltonetworks.com/tag/wireshark/)
  * [Wireshark Tutorial](https://unit42.paloaltonetworks.com/tag/wireshark-tutorial/)

* [![Download Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-download.svg)](https://unit42.paloaltonetworks.com/wireshark-quiz-redline-stealer/?pdf=download&lg=en&_wpnonce=dc23a6ba65 "Click here to download")

* [![Print Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-print.svg)](https://unit42.paloaltonetworks.com/wireshark-quiz-redline-stealer/?pdf=print&lg=en&_wpnonce=dc23a6ba65 "Click here to print")

Share![Down arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/down-arrow.svg)

* ![Link Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-share-link.svg)
* [![Link Email](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-sms.svg)](mailto:?subject=Crossing%20the%20Line:%20Unit%2042%20Wireshark%20Quiz%20for%20RedLine%20Stealer&body=Check%20out%20this%20article%20https%3A%2F%2Funit42.paloaltonetworks.com%2Fwireshark-quiz-redline-stealer%2F "Share in email")
* [![Facebook Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-fb-share.svg)](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Funit42.paloaltonetworks.com%2Fwireshark-quiz-redline-stealer%2F "Share in Facebook")
* [![LinkedIn Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-linkedin-share.svg)](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fwireshark-quiz-redline-stealer%2F&title=Crossing%20the%20Line:%20Unit%2042%20Wireshark%20Quiz%20for%20RedLine%20Stealer "Share in LinkedIn")
* [![Twitter Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-twitter-share.svg)](https://twitter.com/intent/tweet?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fwireshark-quiz-redline-stealer%2F&text=Crossing%20the%20Line:%20Unit%2042%20Wireshark%20Quiz%20for%20RedLine%20Stealer "Share in Twitter")
* [![Reddit Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-reddit-share.svg)](https://www.paloaltonetworks.com//www.reddit.com/submit?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fwireshark-quiz-redline-stealer%2F&ts=markdown "Share in Reddit")
* [![Mastodon Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-mastodon-share.svg)](https://mastodon.social/share?text=Crossing%20the%20Line:%20Unit%2042%20Wireshark%20Quiz%20for%20RedLine%20Stealer%20https%3A%2F%2Funit42.paloaltonetworks.com%2Fwireshark-quiz-redline-stealer%2F "Share in Mastodon")

## Executive Summary

RedLine Stealer is information-stealing malware that harvests login credentials and other sensitive data from a victim's Windows host. This Wireshark quiz uses a packet capture (pcap) that "crosses a line" separating normal traffic from malicious activity. The malicious activity in this pcap is a RedLine Stealer infection from July 2023. Our pcap provides experience analyzing RedLine traffic, and we can determine what specific data was stolen from an infected Windows computer.

Anyone can participate in this quiz. To get the most benefit, participants should be familiar with Wireshark. This quiz also requires a basic understanding of IPv4 traffic. To help people gain this knowledge, we have [a series of Wireshark tutorials](https://unit42.paloaltonetworks.com/wireshark-workshop-videos/) available.

Palo Alto Networks customers receive protection from RedLine Stealer and other malware through [Cortex XDR](https://docs-cortex.paloaltonetworks.com/p/XDR) and our [Next-Generation Firewall (NGFW)](https://docs.paloaltonetworks.com/ngfw) with [Cloud-Delivered Security Services (CDSS)](https://docs.paloaltonetworks.com/cdss) that includes [WildFire](https://docs.paloaltonetworks.com/wildfire) and [Advanced Threat Prevention](https://docs.paloaltonetworks.com/advanced-threat-prevention/administration).

| **Related Unit 42 Topics** | [**pcap**](https://unit42.paloaltonetworks.com/tag/pcap/)**,** [**RedLine**](https://unit42.paloaltonetworks.com/tag/redline/)**,** [**RedLine Stealer**](https://unit42.paloaltonetworks.com/tag/redline-stealer/)**,** [**Wireshark**](https://unit42.paloaltonetworks.com/tag/wireshark/)**,** [**Wireshark Tutorial**](https://unit42.paloaltonetworks.com/tag/wireshark-tutorial/) |
|----------------------------|-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|

## Scenario

Traffic for this quiz occurred in an Active Directory (AD) environment during July 2023. Details of the local area network (LAN) environment for the pcap follow.

### **Local Area Network (LAN) Details**

* LAN segment range: 10.7.10\[.\]0/24 (10.7.10\[.\]1 through 10.7.10\[.\]255)
* Domain: coolweathercoat\[.\]com
* Domain controller IP address: 10.7.10\[.\]9
* Domain controller hostname: WIN-S3WT6LGQFVX
* LAN segment gateway: 10.7.10\[.\]1
* LAN segment broadcast address: 10.7.10\[.\]255

### **Quiz Questions**

* What is the date and time in UTC the infection started?
* What is the IP address of the infected Windows client?
* What is the MAC address of the infected Windows client?
* What is the hostname of the infected Windows client?
* What is the user account name from the infected Windows host?
* What type of information did this RedLine Stealer try to steal?

## Requirements

Participants should use Wireshark to review the pcap. We encourage people to customize their Wireshark column display before reviewing the traffic. While you should personalize Wireshark according to your specific needs, we recommend starting with changes demonstrated in our [Unit 42 series of tutorials and videos](https://unit42.paloaltonetworks.com/wireshark-workshop-videos/).

Participants should use the [latest version of Wireshark](https://www.wireshark.org/download.html) if possible, due to its feature updates and bug fixes over previous versions. We do not recommend outdated Wireshark versions like 1.x and 2.x for these quizzes.

Infection traffic often contains malware or malicious code targeting Microsoft Windows. Because of this, we recommend using Wireshark in a non-Windows environment to review the pcap for this quiz. Operating systems like BSD, Linux or macOS provide an ideal environment for Wireshark when reviewing traffic from Windows-based malware like RedLine Stealer.

## Accessing the Pcap

The pcap for this quiz is located in our [GitHub repository](https://github.com/pan-unit42/Wireshark-quizzes/) as shown in Figure 1. Download the ZIP archive named 2023-07-Unit42-Wireshark-quiz.pcap.zip as shown in Figure 2. Use *infected* as the password to unlock the ZIP archive as shown in Figure 3.
![Image 1 is a screenshot of the GitHub repository for the Unit 42 Wireshark quizzes.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/08/word-image-129632-1.jpeg) Figure 1. Our GitHub repository for Unit 42 Wireshark quizzes. ![Image 2 is a screenshot of how to download the zip file of material for the quiz. After clicking the “View raw” link on the GitHub page, this will prompt a download of the zip archive.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/08/word-image-129632-2.jpeg) Figure 2. After selecting the pcap, download it from the GitHub repository. ![Image 3 is a screenshot of how to extract the zip file contents from the zip. From the downloads window, the user can select “Extract Here” and enter the password into the “Password required” window.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/08/word-image-129632-3.jpeg) Figure 3. Extracting the pcap from the downloaded ZIP archive.

## Conclusion

RedLine Stealer is one of many information stealers within our current threat landscape. This Wireshark quiz can help participants better understand network traffic associated with a RedLine Stealer infection.

The [answers](https://unit42.paloaltonetworks.com/wireshark-quiz-redline-stealer-answers/) to the Unit 42 Wireshark quiz for RedLine Stealer are published in a separate post.

Palo Alto Networks customers receive protection from RedLine Stealer and other malware through [Cortex XDR](https://docs-cortex.paloaltonetworks.com/p/XDR) and our [NGFW](https://docs.paloaltonetworks.com/ngfw) with [CDSS](https://docs.paloaltonetworks.com/cdss) that includes [WildFire](https://docs.paloaltonetworks.com/wildfire) and [Advanced Threat Prevention](https://docs.paloaltonetworks.com/advanced-threat-prevention/administration).

If you think you might have been compromised or have an urgent matter, get in touch with the [Unit 42 Incident Response team](https://start.paloaltonetworks.com/contact-unit42.html) or call:

* North America Toll-Free: 866.486.4842 (866.4.UNIT42)
* EMEA: +31.20.299.3130
* APAC: +65.6983.8730
* Japan: +81.50.1790.0200

Palo Alto Networks has shared these findings, including file samples and indicators of compromise, with our fellow Cyber Threat Alliance (CTA) members. CTA members use this intelligence to rapidly deploy protections to their customers and to systematically disrupt malicious cyber actors. Learn more about the [Cyber Threat Alliance](https://www.cyberthreatalliance.org).

## Additional Resources

* [Wireshark Tutorial: Wireshark Workshop Videos Now Available](https://unit42.paloaltonetworks.com/wireshark-workshop-videos/) -- Unit 42, Palo Alto Networks
* [Unit 42 Wireshark Quiz, January 2023](https://unit42.paloaltonetworks.com/january-wireshark-quiz/) -- Unit 42, Palo Alto Networks
* [Answers to January 2023 Unit 42 Wireshark Quiz](https://unit42.paloaltonetworks.com/january-wireshark-quiz-answers/) -- Unit 42, Palo Alto Networks
* [Unit 42 Wireshark Quiz, February 2023](https://unit42.paloaltonetworks.com/feb-wireshark-quiz/) -- Unit 42, Palo Alto Networks
* [Answers to February 2023 Unit 42 Wireshark Quiz](https://unit42.paloaltonetworks.com/feb-wireshark-quiz-answers/) -- Unit 42, Palo Alto Networks
* [Finding Gozi: Unit 42 Wireshark Quiz, March 2023](https://unit42.paloaltonetworks.com/march-wireshark-gozi/) -- Unit 42, Palo Alto Networks
* [Finding Gozi: Answers to Unit 42 Wireshark Quiz, March 2023](https://unit42.paloaltonetworks.com/march-wireshark-gozi-answers/) -- Unit 42, Palo Alto Networks
* [Cold as Ice: Unit 42 Wireshark Quiz for IcedID](https://unit42.paloaltonetworks.com/wireshark-quiz-icedid/) -- Unit 42, Palo Alto Networks
* [Cold as Ice: Answers to Unit 42 Wireshark Quiz for IcedID](https://unit42.paloaltonetworks.com/wireshark-quiz-icedid-answers/) -- Unit 42, Palo Alto Networks
* [RedLine Stealer: Answers to Unit 42 Wireshark Quiz](https://unit42.paloaltonetworks.com/wireshark-quiz-redline-stealer-answers/) -- Unit 42, Palo Alto Networks
* [New Redline Password Stealer Malware](https://www.proofpoint.com/us/blog/threat-insight/new-redline-stealer-distributed-using-coronavirus-themed-email-campaign) -- Proofpoint Threat Insight, March 2020
* [2023-03-02: Rig EK --\> malware loader --\> Redline Stealer](https://www.malware-traffic-analysis.net/2023/03/02/index.html) -- malware-traffic-analysis.net
* [Malicious AI Tool Ads Used to Deliver Redline Stealer](https://www.trendmicro.com/en_us/research/23/e/malicious-ai-tool-ads-used-to-deliver-redline-stealer.html) -- Trend Micro Research, May 2023
* [Do Not Cross The 'RedLine' Stealer: Detections and Analysis](https://www.splunk.com/en_us/blog/security/do-not-cross-the-redline-stealer-detections-and-analysis.html) -- Splunk Threat Research Team, June 2023
  Back to top

### Tags

* [Pcap](https://unit42.paloaltonetworks.com/tag/pcap/ "pcap")
* [Redline infostealer](https://unit42.paloaltonetworks.com/tag/redline-infostealer/ "Redline infostealer")
* [Wireshark](https://unit42.paloaltonetworks.com/tag/wireshark/ "Wireshark")
* [Wireshark Tutorial](https://unit42.paloaltonetworks.com/tag/wireshark-tutorial/ "Wireshark Tutorial")  
  [Threat Research Center](https://unit42.paloaltonetworks.com "Threat Research") [Next: When a Zero Day and Access Keys Collide in the Cloud: Responding to the SugarCRM Zero-Day Vulnerability](https://unit42.paloaltonetworks.com/sugarcrm-cloud-incident-black-hat/ "When a Zero Day and Access Keys Collide in the Cloud: Responding to the SugarCRM Zero-Day Vulnerability")

### Table of Contents

* 

### Related Articles

* [2025 Unit 42 Global Incident Response Report: Social Engineering Edition](https://unit42.paloaltonetworks.com/2025-unit-42-global-incident-response-report-social-engineering-edition/ "article - table of contents")
* [RustDoor and Koi Stealer for macOS Used by North Korea-Linked Threat Actor to Target the Cryptocurrency Sector](https://unit42.paloaltonetworks.com/macos-malware-targets-crypto-sector/ "article - table of contents")
* [Crypted Hearts: Exposing the HeartCrypt Packer-as-a-Service Operation](https://unit42.paloaltonetworks.com/packer-as-a-service-heartcrypt-malware/ "article - table of contents")

## Related Cybersecurity Tutorials Resources

![A Black man in business attire using a tablet, with illuminated skyscrapers in the background.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/01_Tutorial_Category_1920x900-786x368.jpg)  
[![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-podcast-player.svg)Learning Hub](https://unit42.paloaltonetworks.com/category/learning-hub/) March 1, 2024 [#### Wireshark Tutorial: Exporting Objects From a Pcap](https://unit42.paloaltonetworks.com/using-wireshark-exporting-objects-from-a-pcap/)

* [Pcap](https://unit42.paloaltonetworks.com/tag/pcap/ "pcap")

* [Wireshark](https://unit42.paloaltonetworks.com/tag/wireshark/ "Wireshark")

* [Wireshark Tutorial](https://unit42.paloaltonetworks.com/tag/wireshark-tutorial/ "Wireshark Tutorial")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/using-wireshark-exporting-objects-from-a-pcap/ "Wireshark Tutorial: Exporting Objects From a Pcap")  
  ![A man wearing headphones with a microphone is focused on multiple computer screens displaying graphs and data, indicating involvement in a professional tech or analytics environment.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/02_Tutorial_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-podcast-player.svg)Learning Hub](https://unit42.paloaltonetworks.com/category/learning-hub/) October 10, 2023 [#### Wireshark Tutorial: Identifying Hosts and Users](https://unit42.paloaltonetworks.com/using-wireshark-identifying-hosts-and-users/)

* [Pcap](https://unit42.paloaltonetworks.com/tag/pcap/ "pcap")

* [Wireshark](https://unit42.paloaltonetworks.com/tag/wireshark/ "Wireshark")

* [Wireshark Tutorial](https://unit42.paloaltonetworks.com/tag/wireshark-tutorial/ "Wireshark Tutorial")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/using-wireshark-identifying-hosts-and-users/ "Wireshark Tutorial: Identifying Hosts and Users")  
  ![An abstract illustration of a video that has been paused. It includes a red progress bar and a large white Play button.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/03_Tutorial_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-podcast-player.svg)Learning Hub](https://unit42.paloaltonetworks.com/category/learning-hub/) September 8, 2023 [#### Wireshark Tutorial: Display Filter Expressions](https://unit42.paloaltonetworks.com/using-wireshark-display-filter-expressions/)

* [Pcap](https://unit42.paloaltonetworks.com/tag/pcap/ "pcap")

* [Wireshark](https://unit42.paloaltonetworks.com/tag/wireshark/ "Wireshark")

* [Wireshark Tutorial](https://unit42.paloaltonetworks.com/tag/wireshark-tutorial/ "Wireshark Tutorial")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/using-wireshark-display-filter-expressions/ "Wireshark Tutorial: Display Filter Expressions")  
  ![A person focuses intently on a screen, with many lines of code on the monitor reflected in their glasses.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/04_Tutorial_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-podcast-player.svg)Learning Hub](https://unit42.paloaltonetworks.com/category/learning-hub/) September 1, 2023 [#### RedLine Stealer: Answers to Unit 42 Wireshark Quiz](https://unit42.paloaltonetworks.com/wireshark-quiz-redline-stealer-answers/)

* [Pcap](https://unit42.paloaltonetworks.com/tag/pcap/ "pcap")

* [Wireshark Tutorial](https://unit42.paloaltonetworks.com/tag/wireshark-tutorial/ "Wireshark Tutorial")

* [Redline infostealer](https://unit42.paloaltonetworks.com/tag/redline-infostealer/ "Redline infostealer")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/wireshark-quiz-redline-stealer-answers/ "RedLine Stealer: Answers to Unit 42 Wireshark Quiz")  
  ![A man wearing headphones with a microphone is focused on multiple computer screens displaying graphs and data, indicating involvement in a professional tech or analytics environment.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/02_Tutorial_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-podcast-player.svg)Learning Hub](https://unit42.paloaltonetworks.com/category/learning-hub/) August 31, 2023 [#### Wireshark Tutorial: Changing Your Column Display](https://unit42.paloaltonetworks.com/unit42-customizing-wireshark-changing-column-display/)

* [Pcap](https://unit42.paloaltonetworks.com/tag/pcap/ "pcap")

* [Wireshark](https://unit42.paloaltonetworks.com/tag/wireshark/ "Wireshark")

* [Wireshark Tutorial](https://unit42.paloaltonetworks.com/tag/wireshark-tutorial/ "Wireshark Tutorial")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/unit42-customizing-wireshark-changing-column-display/ "Wireshark Tutorial: Changing Your Column Display")  
  ![A man wearing headphones with a microphone is focused on multiple computer screens displaying graphs and data, indicating involvement in a professional tech or analytics environment.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/02_Tutorial_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-podcast-player.svg)Learning Hub](https://unit42.paloaltonetworks.com/category/learning-hub/) May 30, 2023 [#### Cold as Ice: Answers to Unit 42 Wireshark Quiz for IcedID](https://unit42.paloaltonetworks.com/wireshark-quiz-icedid-answers/)

* [Banking trojans](https://unit42.paloaltonetworks.com/tag/banking-trojans/ "banking trojans")

* [Pcap](https://unit42.paloaltonetworks.com/tag/pcap/ "pcap")

* [Wireshark](https://unit42.paloaltonetworks.com/tag/wireshark/ "Wireshark")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/wireshark-quiz-icedid-answers/ "Cold as Ice: Answers to Unit 42 Wireshark Quiz for IcedID")  
  ![A woman is intently working on a computer in a modern office environment, surrounded by screens displaying dynamic digital data and stock market numbers, highlighting a focus on financial analysis.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/04_Security-Technology_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-podcast-player.svg)Learning Hub](https://unit42.paloaltonetworks.com/category/learning-hub/) May 26, 2023 [#### Cold as Ice: Unit 42 Wireshark Quiz for IcedID](https://unit42.paloaltonetworks.com/wireshark-quiz-icedid/)

* [Banking trojans](https://unit42.paloaltonetworks.com/tag/banking-trojans/ "banking trojans")

* [Pcap](https://unit42.paloaltonetworks.com/tag/pcap/ "pcap")

* [Wireshark](https://unit42.paloaltonetworks.com/tag/wireshark/ "Wireshark")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/wireshark-quiz-icedid/ "Cold as Ice: Unit 42 Wireshark Quiz for IcedID")  
  ![Two people working in a modern office environment with one person concentrating on a computer screen displaying code while another person works in the background.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/10_Security-Technology_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/threat-actor-groups.svg)Threat Actor Groups](https://unit42.paloaltonetworks.com/category/threat-actor-groups/) May 15, 2023 [#### It's All in the Name: How Unit 42 Defines and Tracks Threat Adversaries](https://unit42.paloaltonetworks.com/from-activity-to-formal-naming/)

* [Advanced Persistent Threat](https://unit42.paloaltonetworks.com/tag/advanced-persistent-threat/ "Advanced Persistent Threat")

* [Nomenclature](https://unit42.paloaltonetworks.com/tag/nomenclature/ "nomenclature")

* [Threat actors](https://unit42.paloaltonetworks.com/tag/threat-actors/ "threat actors")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/from-activity-to-formal-naming/ "It’s All in the Name: How Unit 42 Defines and Tracks Threat Adversaries")  
  ![A Black man in business attire using a tablet, with illuminated skyscrapers in the background.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/01_Tutorial_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-podcast-player.svg)Learning Hub](https://unit42.paloaltonetworks.com/category/learning-hub/) March 27, 2023 [#### Finding Gozi: Answers to Unit 42 Wireshark Quiz, March 2023](https://unit42.paloaltonetworks.com/march-wireshark-gozi-answers/)

* [Gozi](https://unit42.paloaltonetworks.com/tag/gozi/ "Gozi")

* [Pcap](https://unit42.paloaltonetworks.com/tag/pcap/ "pcap")

* [Wireshark](https://unit42.paloaltonetworks.com/tag/wireshark/ "Wireshark")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/march-wireshark-gozi-answers/ "Finding Gozi: Answers to Unit 42 Wireshark Quiz, March 2023")

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)  
  ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg) ![Enlarged Image]()  
  ![Newsletter](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/unit42-footer-subscribe-desktop.png)  
  ![UNIT 42 Small Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/palo-alto-logo-small.svg) Get updates from Unit 42

## Peace of mind comes from staying ahead of threats. Subscribe today.

Your Email

Subscribe for email updates to all Unit 42 threat research.  
By submitting this form, you agree to our [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use "Terms of Use") and acknowledge our [Privacy Statement.](https://www.paloaltonetworks.com/legal-notices/privacy "Privacy Statement")

This site is protected by reCAPTCHA and the Google [Privacy Policy](https://policies.google.com/privacy) and [Terms of Service](https://policies.google.com/terms) apply.

Invalid captcha!
Subscribe ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg) ![loader](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-loader.svg)  
{#footer} Products and Services

* [AI-Powered Network Security Platform](https://www.paloaltonetworks.com/network-security)

* [Secure AI by Design](https://www.paloaltonetworks.com/ai-security)

* [Prisma AIRS](https://www.paloaltonetworks.com/ai-security/prisma-airs)

* [AI Access Security](https://www.paloaltonetworks.com/sase/ai-access-security)

* [Cloud Delivered Security Services](https://www.paloaltonetworks.com/network-security/security-subscriptions)

* [Advanced Threat Prevention](https://www.paloaltonetworks.com/network-security/advanced-threat-prevention)

* [Advanced URL Filtering](https://www.paloaltonetworks.com/network-security/advanced-url-filtering)

* [Advanced WildFire](https://www.paloaltonetworks.com/network-security/advanced-wildfire)

* [Advanced DNS Security](https://www.paloaltonetworks.com/network-security/advanced-dns-security)

* [Enterprise Data Loss Prevention](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention)

* [Enterprise IoT Security](https://www.paloaltonetworks.com/network-security/enterprise-device-security)

* [Medical IoT Security](https://www.paloaltonetworks.com/network-security/medical-device-security)

* [Industrial OT Security](https://www.paloaltonetworks.com/network-security/ot-security-solution)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security)

* [Next-Generation Firewalls](https://www.paloaltonetworks.com/network-security/next-generation-firewall)

* [Hardware Firewalls](https://www.paloaltonetworks.com/network-security/hardware-firewall-innovations)

* [Software Firewalls](https://www.paloaltonetworks.com/network-security/software-firewalls)

* [Strata Cloud Manager](https://www.paloaltonetworks.com/network-security/strata-cloud-manager)

* [SD-WAN for NGFW](https://www.paloaltonetworks.com/network-security/sd-wan-subscription)

* [PAN-OS](https://www.paloaltonetworks.com/network-security/pan-os)

* [Panorama](https://www.paloaltonetworks.com/network-security/panorama)

* [Secure Access Service Edge](https://www.paloaltonetworks.com/sase)

* [Prisma SASE](https://www.paloaltonetworks.com/sase)

* [Application Acceleration](https://www.paloaltonetworks.com/sase/app-acceleration)

* [Autonomous Digital Experience Management](https://www.paloaltonetworks.com/sase/adem)

* [Enterprise DLP](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention)

* [Prisma Access](https://www.paloaltonetworks.com/sase/access)

* [Prisma Browser](https://www.paloaltonetworks.com/sase/prisma-browser)

* [Prisma SD-WAN](https://www.paloaltonetworks.com/sase/sd-wan)

* [Remote Browser Isolation](https://www.paloaltonetworks.com/sase/remote-browser-isolation)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security)

* [AI-Driven Security Operations Platform](https://www.paloaltonetworks.com/cortex)

* [Cloud Security](https://www.paloaltonetworks.com/cortex/cloud)

* [Cortex Cloud](https://www.paloaltonetworks.com/cortex/cloud)

* [Application Security](https://www.paloaltonetworks.com/cortex/cloud/application-security)

* [Cloud Posture Security](https://www.paloaltonetworks.com/cortex/cloud/cloud-posture-security)

* [Cloud Runtime Security](https://www.paloaltonetworks.com/cortex/cloud/runtime-security)

* [Prisma Cloud](https://www.paloaltonetworks.com/prisma/cloud)

* [AI-Driven SOC](https://www.paloaltonetworks.com/cortex)

* [Cortex XSIAM](https://www.paloaltonetworks.com/cortex/cortex-xsiam)

* [Cortex XDR](https://www.paloaltonetworks.com/cortex/cortex-xdr)

* [Cortex XSOAR](https://www.paloaltonetworks.com/cortex/cortex-xsoar)

* [Cortex Xpanse](https://www.paloaltonetworks.com/cortex/cortex-xpanse)

* [Unit 42 Managed Detection \& Response](https://www.paloaltonetworks.com/content/pan/en_US/cortex/managed-detection-and-response)

* [Managed XSIAM](https://www.paloaltonetworks.com/cortex/managed-xsiam)

* [Next-Generation Identity Security](https://www.paloaltonetworks.com/idira)

* [Privileged Access Management](https://www.paloaltonetworks.com/idira/human/privileged-access-management)

* [Identity and Access Management](https://www.paloaltonetworks.com/idira/human/identity-and-access-management)

* [Endpoint Privilege Manager](https://www.paloaltonetworks.com/idira/human/endpoint-privilege-manager)

* [Identity Governance](https://www.paloaltonetworks.com/idira/human/identity-governance)

* [Workforce Password Management](https://www.paloaltonetworks.com/idira/human/workforce-password-management)

* [Agentic Identities](https://www.paloaltonetworks.com/idira/agentic)

* [Secrets Management](https://www.paloaltonetworks.com/idira/machine/secrets-management)

* [Unified Secrets Governance](https://www.paloaltonetworks.com/idira/machine/unified-secrets-governance)

* [Application Credentials Delivery](https://www.paloaltonetworks.com/idira/machine/application-credentials-delivery)

* [Vendor Privileged Access](https://www.paloaltonetworks.com/idira/human/vendor-privileged-access)

* [Threat Intel and Incident Response Services](https://www.paloaltonetworks.com/unit42)

* [Prepare for Emerging Risks](https://www.paloaltonetworks.com/unit42/frontier-ai-defense)

* [Strengthen Your Defenses](https://www.paloaltonetworks.com/unit42/strengthen-your-defenses)

* [Build Your Security Strategy](https://www.paloaltonetworks.com/unit42/build-your-security-strategy)

* [Understand the Adversary](https://www.paloaltonetworks.com/unit42/threat-intelligence)

* [Respond to a Cyber Attack](https://www.paloaltonetworks.com/unit42/respond)  
  Company

* [About Us](https://www.paloaltonetworks.com/about-us)

* [Careers](https://jobs.paloaltonetworks.com/en/)

* [Contact Us](https://www.paloaltonetworks.com/company/contact-sales)

* [Corporate Responsibility](https://www.paloaltonetworks.com/about-us/corporate-responsibility)

* [Customers](https://www.paloaltonetworks.com/customers)

* [Investor Relations](https://investors.paloaltonetworks.com/)

* [Location](https://www.paloaltonetworks.com/about-us/locations)

* [Newsroom](https://www.paloaltonetworks.com/company/newsroom)  
  Popular Links

* [Blog](https://www.paloaltonetworks.com/blog/)

* [Communities](https://www.paloaltonetworks.com/communities)

* [Content Library](https://www.paloaltonetworks.com/resources)

* [Cyberpedia](https://www.paloaltonetworks.com/cyberpedia)

* [Event Center](https://events.paloaltonetworks.com/)

* [Manage Email Preferences](https://start.paloaltonetworks.com/preference-center)

* [Products A-Z](https://www.paloaltonetworks.com/products/products-a-z)

* [Product Certifications](https://www.paloaltonetworks.com/legal-notices/trust-center/certifications)

* [Report a Vulnerability](https://www.paloaltonetworks.com/security-disclosure)

* [Sitemap](https://www.paloaltonetworks.com/sitemap)

* [Tech Docs](https://docs.paloaltonetworks.com/)

* [Unit 42](https://unit42.paloaltonetworks.com/)

* [Do Not Sell or Share My Personal Information](https://panwedd.exterro.net/portal/dsar.htm?target=panwedd)
  ![Palo Alto Networks Logo](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/pan-logo-dark.svg)

* [Privacy](https://www.paloaltonetworks.com/legal-notices/privacy)

* [Trust Center](https://www.paloaltonetworks.com/legal-notices/trust-center)

* [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use)

* [Documents](https://www.paloaltonetworks.com/legal)

Copyright © 2026 Palo Alto Networks. All Rights Reserved

* [![Youtube](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/youtube-black.svg)](https://www.youtube.com/user/paloaltonetworks)
* [![Podcast](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/icons/podcast.svg)](https://www.paloaltonetworks.com/podcasts/threat-vector)
* [![Facebook](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/facebook-black.svg)](https://www.facebook.com/PaloAltoNetworks/)
* [![LinkedIn](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/linkedin-black.svg)](https://www.linkedin.com/company/palo-alto-networks)
* [![Twitter](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/twitter-x-black.svg)](https://twitter.com/PaloAltoNtwks)
* EN  
  Select your language  
  ![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg) ![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg) ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg)

### Default Heading

Read the article ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg)  
Seekbar

![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg)  
![Volume](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-volume.svg)  
Volume
![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg)
