Tags: pcap wireshark 

Rating: 3.8

Open the file in Wireshark.

All you can see is a bunch of SSH connections to and from localhost, nothing strange going on there. There are a total of 248 TCP connections, which would fit 8 bit per ASCII character.

In the "Conversations" tab in Wireshark you can see all TCP connections. Some connections have around ~16 packets from A->B and some have ~44.


So after exporting those as a CSV and treating the lower number as "0" and the higher one as "1" we get the following string: