Grant Dept Network_MS-West Annex_IF-11.pcap

MD55bf608078792182cb40ce2b573ac8c9d
Submission Date2021-04-07 07:52:20
Tags(not set)
Alert 0
#
TimestampSrc IpDest IpAlert SignatureP
No results found.
DNS 72
Showing 1-20 of 72 items.
#
TimestampSrc IpDest IpDns TypeResource Record NameResource Record TypeResource Data
1
2021-04-07T06:42:25.423287-0700192.168.252.151192.168.254.100queryds.agomo.comA(not set)
2
2021-04-07T06:43:17.147396-0700192.168.252.151192.168.254.100queryclients2.google.comA(not set)
3
2021-04-07T06:42:29.490454-0700192.168.252.151192.168.254.100querydc1-st.ksn.kaspersky-labs.comA(not set)
4
2021-04-07T06:42:25.439588-0700192.168.254.100192.168.252.151answerds.agomo.comA(not set)
5
2021-04-07T06:43:15.036972-0700192.168.252.151192.168.254.100queryimap.gmail.comA(not set)
6
2021-04-07T06:43:15.069893-0700192.168.254.100192.168.252.151answerimap.gmail.comA(not set)
7
2021-04-07T06:43:17.195525-0700192.168.254.100192.168.252.151answerclients2.google.comA(not set)
8
2021-04-07T06:43:29.665008-0700192.168.252.151192.168.254.100queryds.agomo.comA(not set)
9
2021-04-07T06:43:29.699051-0700192.168.254.100192.168.252.151answerds.agomo.comA(not set)
10
2021-04-07T06:42:29.498615-0700192.168.254.100192.168.252.151answerdc1-st.ksn.kaspersky-labs.comA(not set)
11
2021-04-07T06:42:53.752280-0700192.168.252.151192.168.254.100querywsus.mahi.localA(not set)
12
2021-04-07T06:42:53.769003-0700192.168.254.100192.168.252.151answerwsus.mahi.localA(not set)
13
2021-04-07T06:43:16.115386-0700192.168.252.151192.168.254.100querysmtp.gmail.comA(not set)
14
2021-04-07T06:43:16.194976-0700192.168.254.100192.168.252.151answersmtp.gmail.comA(not set)
15
2021-04-07T06:43:17.217621-0700192.168.252.151192.168.254.100querycheckappexec.microsoft.comA(not set)
16
2021-04-07T06:43:17.264586-0700192.168.254.100192.168.252.151answercheckappexec.microsoft.comA(not set)
17
2021-04-07T06:44:33.875360-0700192.168.252.151192.168.254.100queryds.agomo.comA(not set)
18
2021-04-07T06:44:33.906681-0700192.168.254.100192.168.252.151answerds.agomo.comA(not set)
19
2021-04-07T06:42:53.752280-0700192.168.252.151192.168.254.100querywsus.mahi.localA(not set)
20
2021-04-07T06:42:53.769003-0700192.168.254.100192.168.252.151answerwsus.mahi.localA(not set)
TLS 44
Showing 1-20 of 44 items.
#
TimestampSource IPDestination IPTLS VersionServer Name Indication
1
2021-04-07T06:42:25.546538-0700192.168.252.15152.70.10.94TLS 1.2(not set)
2
2021-04-07T06:42:29.667109-0700192.168.252.15138.113.165.138TLS 1.2dc1-st.ksn.kaspersky-labs.com
3
2021-04-07T06:43:15.122387-0700192.168.252.151142.250.113.108TLS 1.2imap.gmail.com
4
2021-04-07T06:43:17.248291-0700192.168.252.151142.250.113.100TLS 1.2clients2.google.com
5
2021-04-07T06:43:17.327829-0700192.168.252.15170.37.97.229TLS 1.2checkappexec.microsoft.com
6
2021-04-07T06:43:28.363792-0700192.168.252.15123.102.183.116TLS 1.2euc03.evo-ams.com
7
2021-04-07T06:43:29.849022-0700192.168.252.15152.70.10.94TLS 1.2(not set)
8
2021-04-07T06:43:53.096785-0700192.168.252.151192.168.254.17TLS 1.2mail.ahsti.org
9
2021-04-07T06:43:55.335610-0700192.168.252.15138.113.165.138TLS 1.2dc1.ksn.kaspersky-labs.com
10
2021-04-07T06:44:34.014472-0700192.168.252.1513.211.80.175TLS 1.2(not set)
11
2021-04-07T06:43:16.243089-0700192.168.252.151142.250.138.108TLS 1.2smtp.gmail.com
12
2021-04-07T06:42:25.546538-0700192.168.252.15152.70.10.94TLS 1.2(not set)
13
2021-04-07T06:42:29.667109-0700192.168.252.15138.113.165.138TLS 1.2dc1-st.ksn.kaspersky-labs.com
14
2021-04-07T06:43:16.243089-0700192.168.252.151142.250.138.108TLS 1.2smtp.gmail.com
15
2021-04-07T06:43:17.248291-0700192.168.252.151142.250.113.100TLS 1.2clients2.google.com
16
2021-04-07T06:43:28.363792-0700192.168.252.15123.102.183.116TLS 1.2euc03.evo-ams.com
17
2021-04-07T06:43:29.849022-0700192.168.252.15152.70.10.94TLS 1.2(not set)
18
2021-04-07T06:43:53.096785-0700192.168.252.151192.168.254.17TLS 1.2mail.ahsti.org
19
2021-04-07T06:43:55.335610-0700192.168.252.15138.113.165.138TLS 1.2dc1.ksn.kaspersky-labs.com
20
2021-04-07T06:43:15.122387-0700192.168.252.151142.250.113.108TLS 1.2imap.gmail.com
TFTP 0
#TimestampSrc IpDest IpTftp PacketTftp FileTftp Mode
No results found.
HTTP 0
#
TimestampSourceHostnamePortMethodURLStatus
No results found.
SMB 216
Showing 1-20 of 216 items.
#
TimestampSrc IpDest IpSMB DialectCommandSessionTree
1
2021-04-07T06:42:49.525258-0700192.168.252.180192.168.252.1512.??SMB1_COMMAND_NEGOTIATE_PROTOCOL00
2
2021-04-07T06:42:49.528446-0700192.168.252.180192.168.252.1513.11SMB2_COMMAND_NEGOTIATE_PROTOCOL00
3
2021-04-07T06:42:49.532796-0700192.168.252.180192.168.252.1513.11SMB2_COMMAND_SESSION_SETUP7740624941875730
4
2021-04-07T06:42:49.534388-0700192.168.252.180192.168.252.1513.11SMB2_COMMAND_TREE_CONNECT7740624941875731
5
2021-04-07T06:42:49.537276-0700192.168.252.180192.168.252.1513.11SMB2_COMMAND_IOCTL7740624941875731
6
2021-04-07T06:42:49.537276-0700192.168.252.180192.168.252.1513.11SMB2_COMMAND_CREATE7740624941875731
7
2021-04-07T06:42:49.542762-0700192.168.252.180192.168.252.1513.11SMB2_COMMAND_WRITE7740624941875731
8
2021-04-07T06:42:49.544635-0700192.168.252.180192.168.252.1513.11SMB2_COMMAND_IOCTL7740624941875731
9
2021-04-07T06:42:49.546260-0700192.168.252.180192.168.252.1513.11SMB2_COMMAND_IOCTL7740624941875731
10
2021-04-07T06:42:49.552413-0700192.168.252.180192.168.252.1513.11SMB2_COMMAND_CLOSE7740624941875731
11
2021-04-07T06:42:49.552508-0700192.168.252.180192.168.252.1513.11SMB2_COMMAND_CREATE7740624941875731
12
2021-04-07T06:42:49.556386-0700192.168.252.180192.168.252.1513.11SMB2_COMMAND_WRITE7740624941875731
13
2021-04-07T06:42:49.558107-0700192.168.252.180192.168.252.1513.11SMB2_COMMAND_IOCTL7740624941875731
14
2021-04-07T06:42:49.559913-0700192.168.252.180192.168.252.1513.11SMB2_COMMAND_IOCTL7740624941875731
15
2021-04-07T06:42:49.564117-0700192.168.252.180192.168.252.1513.11SMB2_COMMAND_CLOSE7740624941875731
16
2021-04-07T06:42:49.565701-0700192.168.252.180192.168.252.1513.11SMB2_COMMAND_CREATE7740624941875731
17
2021-04-07T06:42:49.569908-0700192.168.252.180192.168.252.1513.11SMB2_COMMAND_WRITE7740624941875731
18
2021-04-07T06:42:49.572591-0700192.168.252.180192.168.252.1513.11SMB2_COMMAND_IOCTL7740624941875731
19
2021-04-07T06:42:49.574649-0700192.168.252.180192.168.252.1513.11SMB2_COMMAND_IOCTL7740624941875731
20
2021-04-07T06:42:49.616409-0700192.168.252.180192.168.252.1513.11SMB2_COMMAND_CLOSE7740624941875731
SMTP 0
#
TimestampSourceDestinationEmail FromEmail ToSubject
No results found.
Flow 202
Showing 1-20 of 202 items.
#
TimestampFlow IdEvent TypeSourceSource PortDestinationDestination PortProtocolHost
1
2021-04-07T06:45:12.688311-07001131095590479212flow192.168.252.15155337192.168.254.2168530TCPpcapanalyzer
2
2021-04-07T06:45:12.688311-0700857342962509959flow192.168.252.151138192.168.252.255138UDPpcapanalyzer
3
2021-04-07T06:45:12.688311-07001149727156812380flow192.168.252.1515528866.110.49.114443TCPpcapanalyzer
4
2021-04-07T06:45:12.688311-0700166415872056304flow192.168.252.15157900239.255.255.2501900UDPpcapanalyzer
5
2021-04-07T06:45:12.688311-0700309219238462234flow192.168.252.15155336192.168.254.2168530TCPpcapanalyzer
6
2021-04-07T06:45:12.688311-0700618491242628640flow192.168.252.1515530438.113.165.138443TCPpcapanalyzer
7
2021-04-07T06:45:12.688311-070061528475360034flow192.168.252.1515531723.102.183.116443TCPpcapanalyzer
8
2021-04-07T06:45:12.688311-07001078254606616993flow192.168.252.1515528538.113.165.142443TCPpcapanalyzer
9
2021-04-07T06:45:12.688311-0700521386331985698flow192.168.252.15158141239.255.255.2503702UDPpcapanalyzer
10
2021-04-07T06:45:12.688311-0700665718703008292flow192.168.252.1515505413.65.248.103443UDPpcapanalyzer
11
2021-04-07T06:45:12.688311-0700668390171736605flow192.168.252.1515533038.113.165.110443TCPpcapanalyzer
12
2021-04-07T06:45:12.688311-0700532475937542334flowfe80:0000:0000:0000:f199:967e:e3c6:df7558142ff02:0000:0000:0000:0000:0000:0000:000c3702UDPpcapanalyzer
13
2021-04-07T06:45:12.688311-07001821099262870646flow54.157.166.45443192.168.252.15155328TCPpcapanalyzer
14
2021-04-07T06:45:12.688311-07001197710533429276flow192.168.252.15155338192.168.254.2168530TCPpcapanalyzer
15
2021-04-07T06:45:12.688311-0700664924133114548flow192.168.252.1515532952.70.10.94443TCPpcapanalyzer
16
2021-04-07T06:45:12.688311-0700705112141496941flow192.168.252.15154876192.168.254.17443TCPpcapanalyzer
17
2021-04-07T06:45:12.688311-0700143214455924566flow192.168.252.1515533538.113.165.138443TCPpcapanalyzer
18
2021-04-07T06:45:12.688311-07001269178795383648flow192.168.252.15165478192.168.254.10053UDPpcapanalyzer
19
2021-04-07T06:45:12.688311-0700853142484164233flow192.168.252.1515482252.242.211.89443TCPpcapanalyzer
20
2021-04-07T06:45:12.688311-0700853657879627634flow192.168.252.15155294130.117.190.228443TCPpcapanalyzer
File 0
#
TimestampSourceDestinationFile NameFile MagicFile Size
No results found.

Comments(not set)

Update Download PCAP Delete