pak004_932bdb768b3eeeec3fcd3540acd32aa0.pcap

MD5932bdb768b3eeeec3fcd3540acd32aa0
Submission Date2021-10-04 07:56:18
Tags(not set)
Alert 6
Showing 1-6 of 6 items.
#
TimestampSrc IpDest IpAlert SignatureP
1
2012-09-21T07:42:34.494625-0700173.194.41.188172.18.3.11ET INFO Observed Interesting Content-Type Inbound (application/x-sh)*
2
2012-09-21T07:42:36.845858-0700173.194.41.188172.18.3.11ET INFO Observed Interesting Content-Type Inbound (application/x-sh)*
3
2012-09-21T07:42:37.398726-070080.239.254.72172.18.3.11ET INFO Observed Interesting Content-Type Inbound (application/x-sh)*
4
2012-09-21T07:42:39.445690-0700173.194.41.188172.18.3.11ET INFO Observed Interesting Content-Type Inbound (application/x-sh)*
5
2012-09-21T07:42:39.570006-0700173.194.41.188172.18.3.11ET INFO Observed Interesting Content-Type Inbound (application/x-sh)*
6
2012-09-21T07:43:36.151476-070080.239.254.42172.18.3.11ET INFO Observed Interesting Content-Type Inbound (application/x-sh)*
DNS 327
Showing 181-200 of 327 items.
#
TimestampSrc IpDest IpDns TypeResource Record NameResource Record TypeResource Data
181
2012-09-21T07:42:35.348677-0700172.18.1.100172.18.3.11answerwww.skynewsarabia.comA(not set)
182
2012-09-21T07:42:35.366987-0700172.18.1.100172.18.3.11answeryourphotos.news.sky.comA(not set)
183
2012-09-21T07:42:35.458077-0700172.18.1.100172.18.3.11answerskyliving.sky.comA(not set)
184
2012-09-21T07:42:36.917543-0700172.18.3.11172.18.1.100querymp.apmebf.comA(not set)
185
2012-09-21T07:42:36.935262-0700172.18.1.100172.18.3.11answermp.apmebf.comA(not set)
186
2012-09-21T07:42:37.398689-0700172.18.3.11172.18.1.100queryatemda.comA(not set)
187
2012-09-21T07:42:37.417114-0700172.18.1.100172.18.3.11answeratemda.comA(not set)
188
2012-09-21T07:42:36.595238-0700172.18.3.11172.18.1.100queryad.doubleclick.netA(not set)
189
2012-09-21T07:42:36.595920-0700172.18.1.100172.18.3.11answerad.doubleclick.netA(not set)
190
2012-09-21T07:42:37.077693-0700172.18.3.11172.18.1.100queryimg.mediaplex.comA(not set)
191
2012-09-21T07:42:37.078030-0700172.18.1.100172.18.3.11answerimg.mediaplex.comA(not set)
192
2012-09-21T07:42:39.925906-0700172.18.3.11172.18.1.100queryp.twitter.comA(not set)
193
2012-09-21T07:42:39.926242-0700172.18.1.100172.18.3.11answerp.twitter.comA(not set)
194
2012-09-21T07:42:39.408475-0700172.18.3.11172.18.1.100queryplatform.twitter.comA(not set)
195
2012-09-21T07:42:39.426110-0700172.18.1.100172.18.3.11answerplatform.twitter.comA(not set)
196
2012-09-21T07:42:39.489539-0700172.18.3.11172.18.1.100queryodb.outbrain.comA(not set)
197
2012-09-21T07:42:39.507495-0700172.18.1.100172.18.3.11answerodb.outbrain.comA(not set)
198
2012-09-21T07:42:37.569751-0700172.18.3.11172.18.1.100querytu.connect.wunderloop.netA(not set)
199
2012-09-21T07:42:37.569838-0700172.18.3.11172.18.1.100querydas.uk.experian.comA(not set)
200
2012-09-21T07:42:37.589416-0700172.18.1.100172.18.3.11answerdas.uk.experian.comA(not set)
TLS 8
Showing 1-8 of 8 items.
#
TimestampSource IPDestination IPTLS VersionServer Name Indication
1
2012-09-21T07:42:39.608580-0700172.18.3.11173.194.41.168TLSv1plusone.google.com
2
2012-09-21T07:42:39.469797-0700172.18.3.11173.194.41.174TLSv1apis.google.com
3
2012-09-21T07:42:39.679741-0700172.18.3.11173.194.41.175TLSv1ssl.gstatic.com
4
2012-09-21T07:42:40.459911-0700172.18.3.112.23.130.110TLSv1s-static.ak.facebook.com
5
2012-09-21T07:42:47.097613-0700172.18.3.11173.194.41.185TLSv1googleads.g.doubleclick.net
6
2012-09-21T07:42:40.801600-0700172.18.3.11173.252.101.16TLSv1www.facebook.com
7
2012-09-21T07:42:59.520623-0700172.18.3.11173.194.67.95TLSv1ajax.googleapis.com
8
2012-09-21T07:43:34.176791-0700172.18.3.11173.194.41.163TLSv1sb-ssl.google.com
TFTP 0
#TimestampSrc IpDest IpTftp PacketTftp FileTftp Mode
No results found.
HTTP 687
Showing 81-100 of 687 items.
#
TimestampSourceHostnamePortMethodURLStatus
81
2012-09-21T07:41:45.004622-0700172.18.3.11news.bbcimg.co.uk80GET/media/images/63021000/jpg/_63021371_eatrich144_getty.jpg200
82
2012-09-21T07:41:44.893419-0700172.18.3.11news.bbcimg.co.uk80GET/media/images/62967000/jpg/_62967972_hi016012954.jpg200
83
2012-09-21T07:41:44.897784-0700172.18.3.11news.bbcimg.co.uk80GET/media/images/62987000/jpg/_62987391_hi016011678.jpg200
84
2012-09-21T07:41:45.254892-0700172.18.3.11sa.bbc.co.uk80GET/bbc/bbc/s?name=news.page&cps_asset_id=10263779&page_type=index&section=front-page&app_version=6.2.104-RC6&first_pub=2010-06-10T14:18:30+00:00&last_editorial_update=2012-09-21T14:32:05+00:00&title=&comments_box=false&cps_media_type=&cps_media_state=&app_type=web&ml_name=SSI&ml_version=0.11.1&language=en-GB&bbc_mc=not_set&screen_resolution=1680x1050&blq_s=3.5&blq_r=3.5&blq_v=journalism-domestic&ns__t=1348238505204&ns_c=UTF-8&ns_ti=BBC%20News%20-%20Home&ns_jspageurl=http%3A//www.bbc.co.uk/news/&ns_referrer=302
85
2012-09-21T07:41:44.904783-0700172.18.3.11news.bbcimg.co.uk80GET/media/images/63018000/jpg/_63018262_hi016017809.jpg200
86
2012-09-21T07:41:45.380959-0700172.18.3.11news.bbcimg.co.uk80GET/js/view/0_0_32/news-index.js200
87
2012-09-21T07:41:44.933637-0700172.18.3.11news.bbcimg.co.uk80GET/media/images/63025000/jpg/_63025125_016028534-1.jpg200
88
2012-09-21T07:41:45.414479-0700172.18.3.11sa.bbc.co.uk80GET/bbc/bbc/s?name=news.page&ns_m2=yes&ns_setsiteck=505C7B0F67BF00B2&cps_asset_id=10263779&page_type=index&section=front-page&app_version=6.2.104-RC6&first_pub=2010-06-10T14:18:30+00:00&last_editorial_update=2012-09-21T14:32:05+00:00&title=&comments_box=false&cps_media_type=&cps_media_state=&app_type=web&ml_name=SSI&ml_version=0.11.1&language=en-GB&bbc_mc=not_set&screen_resolution=1680x1050&blq_s=3.5&blq_r=3.5&blq_v=journalism-domestic&ns__t=1348238505204&ns_c=UTF-8&ns_ti=BBC%20News%20-%20Home&ns_jspageurl=http%3A//www.bbc.co.uk/news/&ns_referrer=200
89
2012-09-21T07:41:44.936981-0700172.18.3.11news.bbcimg.co.uk80GET/media/images/63028000/jpg/_63028641_binoche640.jpg200
90
2012-09-21T07:41:45.380433-0700172.18.3.11static.bbci.co.uk80GET/frameworks/demi/0.9.8/sharedmodules/demi-1.js200
91
2012-09-21T07:41:44.950703-0700172.18.3.11news.bbcimg.co.uk80GET/media/images/63012000/jpg/_63012675_63012074.jpg200
92
2012-09-21T07:41:45.418689-0700172.18.3.11static.bbci.co.uk80GET/frameworks/barlesque/2.10.0/desktop/3.5/img/bbccookies/cookie_prompt_sprite.png200
93
2012-09-21T07:41:45.435571-0700172.18.3.11news.bbcimg.co.uk80GET/view/1_4_35/cream/hi/news/img/subnav-divider.png200
94
2012-09-21T07:41:45.435721-0700172.18.3.11news.bbcimg.co.uk80GET/view/3_0_2/cream/hi/shared/img/transparencies/rgba-0-0-0-07.png200
95
2012-09-21T07:41:45.481766-0700172.18.3.11news.bbcimg.co.uk80GET/view/3_0_2/cream/hi/shared/img/search.png200
96
2012-09-21T07:41:45.478856-0700172.18.3.11news.bbcimg.co.uk80GET/view/1_4_35/cream/hi/news/img/red-masthead.png200
97
2012-09-21T07:41:45.521161-0700172.18.3.11news.bbcimg.co.uk80GET/view/3_0_2/cream/hi/shared/img/programmes-iplayer-brand.png200
98
2012-09-21T07:41:45.524575-0700172.18.3.11news.bbcimg.co.uk80GET/view/1_4_35/cream/hi/news/img/languages-sprite.gif200
99
2012-09-21T07:41:45.566662-0700172.18.3.11static.bbci.co.uk80GET/frameworks/istats/0.11.1/modules/istats-1.js200
100
2012-09-21T07:41:45.508437-0700172.18.3.11emp.bbci.co.uk80GET/emp/worldwide/embed.js?mediaset=journalism-pc301
SMB 0
#
TimestampSrc IpDest IpSMB DialectCommandSessionTree
No results found.
SMTP 0
#
TimestampSourceDestinationEmail FromEmail ToSubject
No results found.
Flow 405
Showing 61-80 of 405 items.
#
TimestampFlow IdEvent TypeSourceSource PortDestinationDestination PortProtocolHost
61
2012-09-21T07:43:38.102668-07001570830550299807flow172.18.3.11658246.229.160.18380TCPpcapanalyzer
62
2012-09-21T07:43:38.102668-07001852803738252911flow172.18.3.1157735172.18.1.10053UDPpcapanalyzer
63
2012-09-21T07:43:38.102668-070025136240057202flow172.18.3.116417212.58.244.6680TCPpcapanalyzer
64
2012-09-21T07:43:38.102668-0700588459860555807flow172.18.3.11658346.229.160.18380TCPpcapanalyzer
65
2012-09-21T07:43:38.102668-07001714374798942141flow172.18.3.116574173.194.41.17580TCPpcapanalyzer
66
2012-09-21T07:43:38.102668-0700307060040794182flow172.18.3.1162928172.18.1.10053UDPpcapanalyzer
67
2012-09-21T07:43:38.102668-07001855627678988811flow172.18.3.1149337172.18.1.10053UDPpcapanalyzer
68
2012-09-21T07:43:38.102668-07001152081974860579flow172.18.3.11652068.67.179.14680TCPpcapanalyzer
69
2012-09-21T07:43:38.102668-07001152105596099636flow172.18.3.1162129172.18.1.10053UDPpcapanalyzer
70
2012-09-21T07:43:38.102668-07001433720160212424flow172.18.3.1164790172.18.1.10053UDPpcapanalyzer
71
2012-09-21T07:43:38.102668-0700870774498157315flow172.18.3.1155212172.18.1.10053UDPpcapanalyzer
72
2012-09-21T07:43:38.102668-07001012319446057641flow172.18.3.11658846.229.160.18380TCPpcapanalyzer
73
2012-09-21T07:43:38.102668-0700168330452953180flow172.18.3.116490173.194.41.18780TCPpcapanalyzer
74
2012-09-21T07:43:38.102668-0700309654205121443flow172.18.3.116567173.194.41.17380TCPpcapanalyzer
75
2012-09-21T07:43:38.102668-07001857906162905495flow172.18.3.1156528172.18.1.10053UDPpcapanalyzer
76
2012-09-21T07:43:38.102668-07001717196588707562flow172.18.3.116453212.58.244.6680TCPpcapanalyzer
77
2012-09-21T07:43:38.102668-07001295518850701542flow172.18.3.1161074172.18.1.10053UDPpcapanalyzer
78
2012-09-21T07:43:38.102668-07002140302413837631flow172.18.3.115353224.0.0.2515353UDPpcapanalyzer
79
2012-09-21T07:43:38.102668-07001858962724829949flow172.18.3.1152048172.18.1.10053UDPpcapanalyzer
80
2012-09-21T07:43:38.102668-07001014831999802999flow172.18.3.116492212.155.198.3080TCPpcapanalyzer
File 654
Showing 141-160 of 654 items.
#
TimestampSourceDestinationFile NameFile MagicFile Size
141
2012-09-21T07:42:05.644569-0700173.194.65.94172.18.3.11/sASCII text, with very long lines, with no line terminators1161
142
2012-09-21T07:42:05.651815-0700173.194.41.175172.18.3.11/gb/images/j_e6a6aca6.pngPNG image data, 381 x 45, 8-bit/color RGBA, non-interlaced15130
143
2012-09-21T07:41:45.494531-070080.239.254.24172.18.3.11/view/3_0_2/cream/hi/shared/img/gvl3-icons-0-2.pngPNG image data, 1344 x 48, 8-bit/color RGBA, non-interlaced16784
144
2012-09-21T07:41:49.979235-0700212.58.244.130172.18.3.11/o.gifGIF image data, version 89a, 1 x 143
145
2012-09-21T07:42:05.831689-0700173.194.65.94172.18.3.11/sASCII text, with very long lines, with no line terminators1167
146
2012-09-21T07:41:50.062268-070080.239.254.10172.18.3.11/modules/comments/getcount/ASCII text, with very long lines, with no line terminators501
147
2012-09-21T07:42:05.938968-0700173.194.65.94172.18.3.11/sASCII text, with very long lines, with no line terminators1185
148
2012-09-21T07:41:45.498271-070080.239.254.24172.18.3.11/view/3_0_2/cream/hi/shared/img/livestats-sprite-ko.pngPNG image data, 650 x 96, 8-bit/color RGBA, non-interlaced4729
149
2012-09-21T07:41:50.101114-070080.239.254.42172.18.3.11/emp/worldwide/embed.jsHTML document, ASCII text317
150
2012-09-21T07:42:06.076947-0700173.194.65.94172.18.3.11/sASCII text, with very long lines, with no line terminators1206
151
2012-09-21T07:41:50.192329-0700212.58.244.66172.18.3.11/news/special/shared/js/istats/v2/istats.jsASCII text, with CRLF line terminators539
152
2012-09-21T07:42:06.146127-0700173.194.65.94172.18.3.11/sASCII text, with very long lines, with no line terminators1170
153
2012-09-21T07:41:45.500514-070080.239.254.24172.18.3.11/view/3_0_2/cream/hi/shared/img/market-data-down.pngPNG image data, 9 x 7, 8-bit/color RGBA, non-interlaced180
154
2012-09-21T07:41:45.535215-070080.239.254.24172.18.3.11/view/1_4_35/cream/hi/news/img/services.gifGIF image data, version 89a, 554 x 351128
155
2012-09-21T07:41:54.045062-0700212.58.244.66172.18.3.11/news/technology-19674761HTML document, ASCII text, with CRLF, LF line terminators61765
156
2012-09-21T07:42:06.659693-0700173.194.65.94172.18.3.11/sASCII text, with very long lines, with no line terminators122597
157
2012-09-21T07:41:45.538245-070080.239.254.24172.18.3.11/view/3_0_2/cream/hi/shared/img/carousel-prev-next-3.pngPNG image data, 96 x 181, 8-bit/color RGBA, non-interlaced1594
158
2012-09-21T07:41:45.620655-0700212.58.244.80172.18.3.11/wurfldemi/network.jsonpASCII text, with no line terminators73
159
2012-09-21T07:42:06.706940-0700173.194.65.94172.18.3.11/sASCII text, with very long lines, with no line terminators1286
160
2012-09-21T07:41:54.080921-070080.239.254.24172.18.3.11/view/3_0_2/cream/hi/shared/story.cssASCII text, with very long lines, with no line terminators24536

Comments(not set)

Update Download PCAP Delete