A packet capture file stores a capture as a sequence of records, each a timestamp, a length and the frame’s bytes; the libpcap format and its successor pcapng are the common ones, with nanosecond timestamps in their newer variants. A timestamp trailer is a block of bytes that a tapping or switching device appends to the end of a copied frame, carrying the time at which the device saw the frame and where it saw it (device and port), so that the timestamp travels with the frame to wherever it is stored.
firm.wirecap: the device and port that saw the frame and the full UTC time in seconds and nanoseconds, appended after the frame. Vendors’ trailers carry the same information in their own layouts.