How to trace the Geolocation of network traffic

时间:2023-12-04 21:18:08

A case about suspicious malware App. A forensic examiner capatured some pcap files and he'd to know where the desitnation is. Let me show you how to solve it with wireshark. First you have to download GeoIP database files. Extract those archive files and put them into some directory.

How to trace the Geolocation of network traffic

Now goto [EDIT]->[Preference]

How to trace the Geolocation of network traffic

Click [Name Resolution] and [Edit] to setup the directory of GeoIP databases.

How to trace the Geolocation of network traffic

Click [New] to create a new entry.

How to trace the Geolocation of network traffic

Browse the directory to find where the GeoIP database files located.

How to trace the Geolocation of network traffic

Don't forget to click [OK] and restart wireshark.

How to trace the Geolocation of network traffic

Open a pcap file and click [Statistics]->[Endpoints]->[IPv4]

How to trace the Geolocation of network traffic

Take a look at [Country] and [City] and you will find where this malware has been.

How to trace the Geolocation of network traffic