pak004_932bdb768b3eeeec3fcd3540acd32aa0.pcap

MD5932bdb768b3eeeec3fcd3540acd32aa0
Submission Date2021-10-04 07:56:18
Tags(not set)
Alert 6
Showing 1-6 of 6 items.
#
TimestampSrc IpDest IpAlert SignatureP
1
2012-09-21T07:42:34.494625-0700173.194.41.188172.18.3.11ET INFO Observed Interesting Content-Type Inbound (application/x-sh)*
2
2012-09-21T07:42:36.845858-0700173.194.41.188172.18.3.11ET INFO Observed Interesting Content-Type Inbound (application/x-sh)*
3
2012-09-21T07:42:37.398726-070080.239.254.72172.18.3.11ET INFO Observed Interesting Content-Type Inbound (application/x-sh)*
4
2012-09-21T07:42:39.445690-0700173.194.41.188172.18.3.11ET INFO Observed Interesting Content-Type Inbound (application/x-sh)*
5
2012-09-21T07:42:39.570006-0700173.194.41.188172.18.3.11ET INFO Observed Interesting Content-Type Inbound (application/x-sh)*
6
2012-09-21T07:43:36.151476-070080.239.254.42172.18.3.11ET INFO Observed Interesting Content-Type Inbound (application/x-sh)*
DNS 327
Showing 1-20 of 327 items.
#
TimestampSrc IpDest IpDns TypeResource Record NameResource Record TypeResource Data
1
2012-09-21T07:41:39.704863-0700172.18.3.11172.18.1.100querywww.google.co.ukA(not set)
2
2012-09-21T07:41:40.288015-0700172.18.3.11172.18.1.100queryplay.google.comA(not set)
3
2012-09-21T07:41:40.309850-0700172.18.3.11172.18.1.100querywww.youtube.comA(not set)
4
2012-09-21T07:41:40.337901-0700172.18.1.100172.18.3.11answerplay.google.comA(not set)
5
2012-09-21T07:41:40.339156-0700172.18.3.11172.18.1.100querynews.google.co.ukA(not set)
6
2012-09-21T07:41:40.339186-0700172.18.3.11172.18.1.100querymail.google.comA(not set)
7
2012-09-21T07:41:40.339973-0700172.18.1.100172.18.3.11answerwww.youtube.comA(not set)
8
2012-09-21T07:41:40.339974-0700172.18.1.100172.18.3.11answermail.google.comA(not set)
9
2012-09-21T07:41:40.340579-0700172.18.3.11172.18.1.100querydocs.google.comA(not set)
10
2012-09-21T07:41:40.341765-0700172.18.3.11172.18.1.100querybooks.google.co.ukA(not set)
11
2012-09-21T07:41:40.342098-0700172.18.1.100172.18.3.11answerbooks.google.co.ukA(not set)
12
2012-09-21T07:41:40.342539-0700172.18.3.11172.18.1.100querywww.blogger.comA(not set)
13
2012-09-21T07:41:40.363758-0700172.18.1.100172.18.3.11answernews.google.co.ukA(not set)
14
2012-09-21T07:41:40.363759-0700172.18.1.100172.18.3.11answerwww.blogger.comA(not set)
15
2012-09-21T07:41:40.365252-0700172.18.3.11172.18.1.100querypicasaweb.google.co.ukA(not set)
16
2012-09-21T07:41:40.380116-0700172.18.1.100172.18.3.11answerdocs.google.comA(not set)
17
2012-09-21T07:41:40.409792-0700172.18.1.100172.18.3.11answerpicasaweb.google.co.ukA(not set)
18
2012-09-21T07:41:40.287910-0700172.18.3.11172.18.1.100querymaps.google.co.ukA(not set)
19
2012-09-21T07:41:40.337900-0700172.18.1.100172.18.3.11answermaps.google.co.ukA(not set)
20
2012-09-21T07:41:40.381273-0700172.18.3.11172.18.1.100queryaccounts.google.comA(not set)
TLS 8
Showing 1-8 of 8 items.
#
TimestampSource IPDestination IPTLS VersionServer Name Indication
1
2012-09-21T07:42:39.608580-0700172.18.3.11173.194.41.168TLSv1plusone.google.com
2
2012-09-21T07:42:39.469797-0700172.18.3.11173.194.41.174TLSv1apis.google.com
3
2012-09-21T07:42:39.679741-0700172.18.3.11173.194.41.175TLSv1ssl.gstatic.com
4
2012-09-21T07:42:40.459911-0700172.18.3.112.23.130.110TLSv1s-static.ak.facebook.com
5
2012-09-21T07:42:47.097613-0700172.18.3.11173.194.41.185TLSv1googleads.g.doubleclick.net
6
2012-09-21T07:42:40.801600-0700172.18.3.11173.252.101.16TLSv1www.facebook.com
7
2012-09-21T07:42:59.520623-0700172.18.3.11173.194.67.95TLSv1ajax.googleapis.com
8
2012-09-21T07:43:34.176791-0700172.18.3.11173.194.41.163TLSv1sb-ssl.google.com
TFTP 0
#TimestampSrc IpDest IpTftp PacketTftp FileTftp Mode
No results found.
HTTP 687
Showing 121-140 of 687 items.
#
TimestampSourceHostnamePortMethodURLStatus
121
2012-09-21T07:41:45.192088-0700172.18.3.11news.bbcimg.co.uk80GET/media/images/63038000/jpg/_63038944_63038940.jpg200
122
2012-09-21T07:41:45.343096-0700172.18.3.11node1.bbcimg.co.uk80GET/glow/glow/1.7.7/widgets/widgets.css200
123
2012-09-21T07:41:45.755079-0700172.18.3.11news.bbcimg.co.uk80GET/view/3_0_2/cream/hi/shared/img/personalisation-help-icon.gif200
124
2012-09-21T07:41:45.380382-0700172.18.3.11open.live.bbc.co.uk80GET/wurfldemi/useragent.jsonp?callback=define&ua=Mozilla%2F5.0%20(Windows%20NT%206.1%3B%20rv%3A15.0)%20Gecko%2F20100101%20Firefox%2F15.0.1200
125
2012-09-21T07:41:45.755079-0700172.18.3.11emp.bbci.co.uk80GET/emp/releases/worldwide/revisions/749603_749269_749444_6/embed.js?mediaset=journalism-pc200
126
2012-09-21T07:41:45.419584-0700172.18.3.11news.bbcimg.co.uk80GET/view/1_4_35/cream/hi/news/img/news_masthead.gif200
127
2012-09-21T07:41:54.628471-0700172.18.3.11open.bbci.co.uk80GET/buzz/shares?callback=sharetools.counts.receive&url=http%3A%2F%2Fwww.bbc.co.uk%2Fnews%2Ftechnology-19674761&title=BBC%20News%20-%20Microsoft%20releases%20fix%20for%20IE%20bug200
128
2012-09-21T07:41:54.664473-0700172.18.3.11static.bbci.co.uk80GET/modules/sharetools/v1/img/sprite-0.3.2.png200
129
2012-09-21T07:41:45.419729-0700172.18.3.11news.bbcimg.co.uk80GET/view/1_4_35/cream/hi/news/img/nav-divider.png200
130
2012-09-21T07:41:45.437473-0700172.18.3.11static.bbci.co.uk80GET/frameworks/barlesque/2.10.0/desktop/3.5/img/blq-sprite_alpha.png200
131
2012-09-21T07:41:45.458829-0700172.18.3.11news.bbcimg.co.uk80GET/js/net/json/jsonloader/2_13_1/jsonloader.js200
132
2012-09-21T07:42:01.789711-0700172.18.3.11www.google.co.uk80GET/200
133
2012-09-21T07:42:01.999716-0700172.18.3.11www.google.co.uk80GET/csi?v=3&s=webhp&action=&e=17259,18168,28290,28663,37102,39523,39977,4000116,4000354,4000473,4000519,4000545,4000553,4000833,4000841,4000949,4000974,4001007&ei=H3tcUJzaJYWf0QW184CYBw&imc=1&imn=1&imp=0&rt=xjsls.77,prt.81,xjses.129,xjsee.173,xjs.175,ol.177,iml.81,wsrt.95,cst.0,dnst.0,rqst.153,rspt.84204
134
2012-09-21T07:41:49.835585-0700172.18.3.11news.bbcimg.co.uk80GET/media/images/63027000/jpg/_63027505_016036297-1.jpg200
135
2012-09-21T07:41:49.865359-0700172.18.3.11emp.bbci.co.uk80GET/emp/bump?emp=worldwide&enableClear=1301
136
2012-09-21T07:41:49.878108-0700172.18.3.11news.bbcimg.co.uk80GET/media/images/62942000/jpg/_62942737_114158299.jpg200
137
2012-09-21T07:42:05.489948-0700172.18.3.11www.google.co.uk80GET/s?hl=en&sugexp=les%3B&gs_nf=1&cp=1&gs_id=5&xhr=t&q=T&pf=p&output=search&sclient=psy-ab&oq=&gs_l=&pbx=1&bav=on.2,or.r_gc.r_pw.r_qf.&fp=ff301ef4d48490c5&biw=1680&bih=920&tch=1&ech=1&psi=H3tcUJzaJYWf0QW184CYBw.1348238521751.1200
138
2012-09-21T07:41:49.919419-0700172.18.3.11news.bbcimg.co.uk80GET/media/images/62998000/jpg/_62998791_3yz8e6jh.jpg200
139
2012-09-21T07:41:49.952254-0700172.18.3.11www.bbc.co.uk80GET/news/technology/200
140
2012-09-21T07:41:49.968528-0700172.18.3.11news.bbcimg.co.uk80GET/media/images/63031000/jpg/_63031637_robot_snake.jpg200
SMB 0
#
TimestampSrc IpDest IpSMB DialectCommandSessionTree
No results found.
SMTP 0
#
TimestampSourceDestinationEmail FromEmail ToSubject
No results found.
Flow 405
Showing 81-100 of 405 items.
#
TimestampFlow IdEvent TypeSourceSource PortDestinationDestination PortProtocolHost
81
2012-09-21T07:43:38.102668-07001015046747382918flow172.18.3.1164572172.18.1.10053UDPpcapanalyzer
82
2012-09-21T07:43:38.102668-070029974525631780flow172.18.3.11657946.229.160.18380TCPpcapanalyzer
83
2012-09-21T07:43:38.102668-0700733704914522847flow172.18.3.1153871172.18.1.10053UDPpcapanalyzer
84
2012-09-21T07:43:38.102668-07001437482551830618flow172.18.3.11654698.124.224.24380TCPpcapanalyzer
85
2012-09-21T07:43:38.102668-07001015742533663495flow172.18.3.1154195172.18.1.10053UDPpcapanalyzer
86
2012-09-21T07:43:38.102668-0700735057830894817flow172.18.3.116568173.194.41.17380TCPpcapanalyzer
87
2012-09-21T07:43:38.102668-07001720662634011504flow172.18.3.116625212.58.244.8080TCPpcapanalyzer
88
2012-09-21T07:43:38.102668-07001861705061211135flow172.18.3.11648864.236.124.22980TCPpcapanalyzer
89
2012-09-21T07:43:38.102668-07002143334657142904flow172.18.3.11653294.127.77.6780TCPpcapanalyzer
90
2012-09-21T07:43:38.102668-0700173239602743460flow172.18.3.116592204.152.194.21880TCPpcapanalyzer
91
2012-09-21T07:43:38.102668-0700454766117294326flow172.18.3.1150757172.18.1.10053UDPpcapanalyzer
92
2012-09-21T07:43:38.102668-07001721762144105648flow172.18.3.116601204.152.194.21880TCPpcapanalyzer
93
2012-09-21T07:43:38.102668-070033023951099558flow172.18.3.1165344.71.33.16780TCPpcapanalyzer
94
2012-09-21T07:43:38.102668-0700877773151343008flow172.18.3.1152566172.18.1.10053UDPpcapanalyzer
95
2012-09-21T07:43:38.102668-0700174324080189534flow172.18.3.116553184.85.159.13980TCPpcapanalyzer
96
2012-09-21T07:43:38.102668-0700315630648409846flow172.18.3.11645480.239.254.2480TCPpcapanalyzer
97
2012-09-21T07:43:38.102668-0700456565708248652flow172.18.3.1157032172.18.1.10053UDPpcapanalyzer
98
2012-09-21T07:43:38.102668-070034804216865735flow172.18.3.116597173.254.205.23180TCPpcapanalyzer
99
2012-09-21T07:43:38.102668-0700316317845307884flow172.18.3.1164122172.18.1.10053UDPpcapanalyzer
100
2012-09-21T07:43:38.102668-07001020733282210210flow172.18.3.11646180.239.254.8380TCPpcapanalyzer
File 654
Showing 1-20 of 654 items.
#
TimestampSourceDestinationFile NameFile MagicFile Size
1
2012-09-21T07:41:40.178861-0700173.194.65.94172.18.3.11/images/srpr/logo3w.pngPNG image data, 275 x 95, 8-bit colormap, non-interlaced7007
2
2012-09-21T07:41:40.427980-0700173.194.65.103172.18.3.11/textinputassistant/tia.pngPNG image data, 27 x 23, 8-bit/color RGB, non-interlaced387
3
2012-09-21T07:41:40.291561-0700173.194.65.94172.18.3.11/images/swxa.gifGIF image data, version 89a, 120 x 655223
4
2012-09-21T07:41:39.911086-0700173.194.65.94172.18.3.11/HTML document, ASCII text, with very long lines97491
5
2012-09-21T07:41:44.482932-0700212.58.244.66172.18.3.11/favicon.icoMS Windows icon resource - 2 icons, 16x16, 2 colors958
6
2012-09-21T07:41:39.946369-0700173.194.65.94172.18.3.11/images/icons/product/chrome-48.pngPNG image data, 48 x 48, 8-bit colormap, non-interlaced1834
7
2012-09-21T07:41:44.597866-070080.239.217.171172.18.3.11/frameworks/barlesque/2.10.0/desktop/3.5/img/blq-blocks_grey_alpha.pngPNG image data, 84 x 24, 8-bit/color RGBA, non-interlaced1020
8
2012-09-21T07:41:40.204621-0700173.194.65.94172.18.3.11/xjs/_/js/s/s,st,anim,jsa,c,sb,hv,wta,cr,cdos,nos,tbpr,tbui,rsn,ob,mb,lc,du,ada,amcl,klc,kat,aut,bihu,kp,lu,m,shb,tng,hsm,j,p,pcc,csi/rt=j/ver=Npnh78fj8FE.en_US./d=1/sv=1/rs=AItRSTPQPHplxSwT63aSYOfWgPS1dWhc4gASCII text, with very long lines481401
9
2012-09-21T07:41:44.585922-070080.239.254.24172.18.3.11/view/3_0_2/cream/hi/shared/print.cssASCII text, with very long lines, with no line terminators3947
10
2012-09-21T07:41:44.590623-070080.239.254.24172.18.3.11/view/3_0_2/cream/hi/shared/mobile.cssASCII text, with no line terminators36
11
2012-09-21T07:41:44.614033-0700212.58.244.61172.18.3.11/HTML document, ASCII text234
12
2012-09-21T07:41:44.614931-070080.239.254.34172.18.3.11/glow/gloader.0.1.6.jsHTML document, ASCII text, with very long lines15520
13
2012-09-21T07:41:44.643648-070080.239.254.42172.18.3.11/emp/bumpHTML document, ASCII text305
14
2012-09-21T07:41:44.666045-070080.239.254.74172.18.3.11/iplayer/images/episode/b01mxvlw_150_84.jpgJPEG image data, JFIF standard 1.01, resolution (DPI), density 72x72, segment length 16, baseline, precision 8, 150x84, frames 310037
15
2012-09-21T07:41:40.283031-0700173.194.65.94172.18.3.11/extern_chrome/ff301ef4d48490c5.jsASCII text, with very long lines, with no line terminators61792
16
2012-09-21T07:41:44.724056-0700212.58.244.130172.18.3.11/o.gifGIF image data, version 89a, 1 x 143
17
2012-09-21T07:41:44.732058-0700212.58.244.66172.18.3.11/news/HTML document, ASCII text, with CRLF, LF line terminators105102
18
2012-09-21T07:41:44.733613-070080.239.254.24172.18.3.11/view/3_0_2/cream/hi/shared/components/components.cssASCII text, with very long lines, with no line terminators225987
19
2012-09-21T07:41:40.373773-0700173.194.41.175172.18.3.11/gb/js/sem_9d2b852f41bb993a0833b0a332253abb.jsASCII text, with very long lines45888
20
2012-09-21T07:41:40.537968-0700173.194.65.94172.18.3.11/favicon.icoMS Windows icon resource - 2 icons, 16x165430

Comments(not set)

Update Download PCAP Delete