pak004_932bdb768b3eeeec3fcd3540acd32aa0.pcap

MD5932bdb768b3eeeec3fcd3540acd32aa0
Submission Date2021-10-04 07:56:18
Tags(not set)
Alert 6
Showing 1-6 of 6 items.
#
TimestampSrc IpDest IpAlert SignatureP
1
2012-09-21T07:42:34.494625-0700173.194.41.188172.18.3.11ET INFO Observed Interesting Content-Type Inbound (application/x-sh)*
2
2012-09-21T07:42:36.845858-0700173.194.41.188172.18.3.11ET INFO Observed Interesting Content-Type Inbound (application/x-sh)*
3
2012-09-21T07:42:37.398726-070080.239.254.72172.18.3.11ET INFO Observed Interesting Content-Type Inbound (application/x-sh)*
4
2012-09-21T07:42:39.445690-0700173.194.41.188172.18.3.11ET INFO Observed Interesting Content-Type Inbound (application/x-sh)*
5
2012-09-21T07:42:39.570006-0700173.194.41.188172.18.3.11ET INFO Observed Interesting Content-Type Inbound (application/x-sh)*
6
2012-09-21T07:43:36.151476-070080.239.254.42172.18.3.11ET INFO Observed Interesting Content-Type Inbound (application/x-sh)*
DNS 327
Showing 1-20 of 327 items.
#
TimestampSrc IpDest IpDns TypeResource Record NameResource Record TypeResource Data
1
2012-09-21T07:41:39.704863-0700172.18.3.11172.18.1.100querywww.google.co.ukA(not set)
2
2012-09-21T07:41:40.288015-0700172.18.3.11172.18.1.100queryplay.google.comA(not set)
3
2012-09-21T07:41:40.309850-0700172.18.3.11172.18.1.100querywww.youtube.comA(not set)
4
2012-09-21T07:41:40.337901-0700172.18.1.100172.18.3.11answerplay.google.comA(not set)
5
2012-09-21T07:41:40.339156-0700172.18.3.11172.18.1.100querynews.google.co.ukA(not set)
6
2012-09-21T07:41:40.339186-0700172.18.3.11172.18.1.100querymail.google.comA(not set)
7
2012-09-21T07:41:40.339973-0700172.18.1.100172.18.3.11answerwww.youtube.comA(not set)
8
2012-09-21T07:41:40.339974-0700172.18.1.100172.18.3.11answermail.google.comA(not set)
9
2012-09-21T07:41:40.340579-0700172.18.3.11172.18.1.100querydocs.google.comA(not set)
10
2012-09-21T07:41:40.341765-0700172.18.3.11172.18.1.100querybooks.google.co.ukA(not set)
11
2012-09-21T07:41:40.342098-0700172.18.1.100172.18.3.11answerbooks.google.co.ukA(not set)
12
2012-09-21T07:41:40.342539-0700172.18.3.11172.18.1.100querywww.blogger.comA(not set)
13
2012-09-21T07:41:40.363758-0700172.18.1.100172.18.3.11answernews.google.co.ukA(not set)
14
2012-09-21T07:41:40.363759-0700172.18.1.100172.18.3.11answerwww.blogger.comA(not set)
15
2012-09-21T07:41:40.365252-0700172.18.3.11172.18.1.100querypicasaweb.google.co.ukA(not set)
16
2012-09-21T07:41:40.380116-0700172.18.1.100172.18.3.11answerdocs.google.comA(not set)
17
2012-09-21T07:41:40.409792-0700172.18.1.100172.18.3.11answerpicasaweb.google.co.ukA(not set)
18
2012-09-21T07:41:40.287910-0700172.18.3.11172.18.1.100querymaps.google.co.ukA(not set)
19
2012-09-21T07:41:40.337900-0700172.18.1.100172.18.3.11answermaps.google.co.ukA(not set)
20
2012-09-21T07:41:40.381273-0700172.18.3.11172.18.1.100queryaccounts.google.comA(not set)
TLS 8
Showing 1-8 of 8 items.
#
TimestampSource IPDestination IPTLS VersionServer Name Indication
1
2012-09-21T07:42:39.608580-0700172.18.3.11173.194.41.168TLSv1plusone.google.com
2
2012-09-21T07:42:39.469797-0700172.18.3.11173.194.41.174TLSv1apis.google.com
3
2012-09-21T07:42:39.679741-0700172.18.3.11173.194.41.175TLSv1ssl.gstatic.com
4
2012-09-21T07:42:40.459911-0700172.18.3.112.23.130.110TLSv1s-static.ak.facebook.com
5
2012-09-21T07:42:47.097613-0700172.18.3.11173.194.41.185TLSv1googleads.g.doubleclick.net
6
2012-09-21T07:42:40.801600-0700172.18.3.11173.252.101.16TLSv1www.facebook.com
7
2012-09-21T07:42:59.520623-0700172.18.3.11173.194.67.95TLSv1ajax.googleapis.com
8
2012-09-21T07:43:34.176791-0700172.18.3.11173.194.41.163TLSv1sb-ssl.google.com
TFTP 0
#TimestampSrc IpDest IpTftp PacketTftp FileTftp Mode
No results found.
HTTP 687
Showing 161-180 of 687 items.
#
TimestampSourceHostnamePortMethodURLStatus
161
2012-09-21T07:42:06.659693-0700172.18.3.11www.google.co.uk80GET/s?hl=en&sugexp=les%3B&gs_nf=1&cp=8&gs_id=30&xhr=t&q=The%20key%20&pf=p&output=search&sclient=psy-ab&oq=&gs_l=&pbx=1&bav=on.2,or.r_gc.r_pw.r_qf.&fp=ff301ef4d48490c5&biw=1680&bih=920&tch=1&ech=8&psi=H3tcUJzaJYWf0QW184CYBw.1348238521751.1200
162
2012-09-21T07:42:06.706940-0700172.18.3.11www.google.co.uk80GET/s?hl=en&sugexp=les%3B&gs_nf=1&cp=11&gs_id=4g&xhr=t&q=The%20key%20is%20&pf=p&output=search&sclient=psy-ab&oq=&gs_l=&pbx=1&bav=on.2,or.r_gc.r_pw.r_qf.&fp=ff301ef4d48490c5&biw=1680&bih=920&tch=1&ech=11&psi=H3tcUJzaJYWf0QW184CYBw.1348238521751.1200
163
2012-09-21T07:41:45.538245-0700172.18.3.11news.bbcimg.co.uk80GET/view/3_0_2/cream/hi/shared/img/carousel-prev-next-3.png200
164
2012-09-21T07:41:45.620655-0700172.18.3.11open.live.bbc.co.uk80GET/wurfldemi/network.jsonp?callback=_demi_mobile_network_cb_0200
165
2012-09-21T07:41:45.643105-0700172.18.3.11node1.bbcimg.co.uk80GET/glow/glow/1.7.7/widgets/images/darkpanel/ctr.png200
166
2012-09-21T07:41:54.080921-0700172.18.3.11news.bbcimg.co.uk80GET/view/3_0_2/cream/hi/shared/story.css200
167
2012-09-21T07:42:12.049128-0700172.18.3.11p5-vuomjve4ezg7a-ygiznq2tllkmxoic-759258-i2-v6exp3-v4.metric.gstatic.com80GET/v6exp3/6.gif200
168
2012-09-21T07:41:54.116429-0700172.18.3.11emp.bbci.co.uk80GET/emp/bump?emp=worldwide&enableClear=1301
169
2012-09-21T07:42:18.443981-0700172.18.3.11www.google.co.uk80GET/s?hl=en&sugexp=les%3B&gs_nf=1&cp=12&gs_id=at&xhr=t&q=The%20key%20is%20%22&pf=p&output=search&sclient=psy-ab&oq=&gs_l=&pbx=1&bav=on.2,or.r_gc.r_pw.r_qf.&fp=ff301ef4d48490c5&biw=1680&bih=920&tch=1&ech=12&psi=H3tcUJzaJYWf0QW184CYBw.1348238521751.1200
170
2012-09-21T07:41:54.184463-0700172.18.3.11emp.bbci.co.uk80GET/emp/releases/bump/revisions/872744/embed.js?emp=worldwide&enableClear=1304
171
2012-09-21T07:41:54.252398-0700172.18.3.11stats.bbc.co.uk80GET/o.gif?~RS~s~RS~News~RS~t~RS~HighWeb_Story~RS~i~RS~19674761~RS~p~RS~99113~RS~a~RS~Domestic~RS~u~RS~/news/technology-19674761~RS~r~RS~http://www.bbc.co.uk/news/technology/~RS~q~RS~~RS~z~RS~04~RS~200
172
2012-09-21T07:41:54.275052-0700172.18.3.11emp.bbci.co.uk80GET/emp/worldwide/embed.js?mediaset=journalism-pc301
173
2012-09-21T07:41:45.731110-0700172.18.3.11news.bbcimg.co.uk80GET/js/app/ticker/2_1_1/ticker.js200
174
2012-09-21T07:41:49.838636-0700172.18.3.11news.bbcimg.co.uk80GET/media/images/63031000/jpg/_63031105_000793140-1.jpg200
175
2012-09-21T07:41:49.847598-0700172.18.3.11news.bbcimg.co.uk80GET/media/images/62978000/jpg/_62978075_62978004.jpg200
176
2012-09-21T07:41:49.879909-0700172.18.3.11newsimg.bbc.co.uk80GET/news/special/2012/newsspec_4095/widget/css/style_w.css200
177
2012-09-21T07:42:20.597822-0700172.18.3.11news.google.co.uk80GET/news/tbn/Zslr3463hrQJ/6.jpg200
178
2012-09-21T07:42:20.599260-0700172.18.3.11www.google.co.uk80GET/s?hl=en&sugexp=les%3B&gs_nf=1&cp=44&gs_id=da&xhr=t&q=The%20key%20is%20%22ad7b9c14083b52bc532fba5948342b98&pf=p&output=search&sclient=psy-ab&oq=&gs_l=&pbx=1&bav=on.2,or.r_gc.r_pw.r_qf.&fp=ff301ef4d48490c5&biw=1680&bih=920&tch=1&ech=13&psi=H3tcUJzaJYWf0QW184CYBw.1348238521751.1200
179
2012-09-21T07:42:20.771452-0700172.18.3.11id.google.co.uk80GET/verify/EAAAAOUmQ06UkEvBLgmOHOaVuYg.gif200
180
2012-09-21T07:42:20.824447-0700172.18.3.11www.google.co.uk80GET/csi?v=3&s=web&action=&ei=MXtcULqJFYi5hAebh4GYCQ&e=17259,18168,28290,28663,37102,39523,39977,4000116,4000354,4000473,4000519,4000545,4000553,4000833,4000841,4000949,4000974,4001007&cr=c&imp=1&pf=1&pfa=n.10,ttfc.59,ttlc.0,cbt.1&pfm=n.10,ttfc.106,ttlc.0,cbt.52&pmd=max.1,avg.0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,1&imn=3&rt=prt.68,pprt.69,ol.69,jsrt.1203,iml.167,kpr.15010,bpl.18917204
SMB 0
#
TimestampSrc IpDest IpSMB DialectCommandSessionTree
No results found.
SMTP 0
#
TimestampSourceDestinationEmail FromEmail ToSubject
No results found.
Flow 405
Showing 41-60 of 405 items.
#
TimestampFlow IdEvent TypeSourceSource PortDestinationDestination PortProtocolHost
41
2012-09-21T07:43:38.102668-07001420543204418984flow172.18.3.116630173.194.41.163443TCPpcapanalyzer
42
2012-09-21T07:43:38.102668-0700154777683566367flow172.18.3.11648080.239.221.4380TCPpcapanalyzer
43
2012-09-21T07:43:38.102668-07001422269777511853flow172.18.3.11651895.172.69.4180TCPpcapanalyzer
44
2012-09-21T07:43:38.102668-07001986164625814363flow172.18.3.116598204.152.194.21880TCPpcapanalyzer
45
2012-09-21T07:43:38.102668-0700156839268714858flow172.18.3.1155101172.18.1.10053UDPpcapanalyzer
46
2012-09-21T07:43:38.102668-07001705132025560923flow172.18.3.11645580.239.254.2480TCPpcapanalyzer
47
2012-09-21T07:43:38.102668-07001284446424283630flow172.18.3.1156936172.18.1.10053UDPpcapanalyzer
48
2012-09-21T07:43:38.102668-0700580763277460763flow172.18.3.11649895.172.69.1880TCPpcapanalyzer
49
2012-09-21T07:43:38.102668-0700158980309083736flow172.18.3.11647280.239.254.13880TCPpcapanalyzer
50
2012-09-21T07:43:38.102668-0700159238004566176flow172.18.3.11645987.249.105.5880TCPpcapanalyzer
51
2012-09-21T07:43:38.102668-07001426167457551627flow172.18.3.116457212.58.244.6180TCPpcapanalyzer
52
2012-09-21T07:43:38.102668-0700864712151734108flow172.18.3.116408173.194.65.9480TCPpcapanalyzer
53
2012-09-21T07:43:38.102668-0700442579150943204flow172.18.3.1164020172.18.1.10053UDPpcapanalyzer
54
2012-09-21T07:43:38.102668-07001005885579686947flow172.18.3.1157204172.18.1.10053UDPpcapanalyzer
55
2012-09-21T07:43:38.102668-07002132288000860563flow172.18.3.11648366.235.156.13180TCPpcapanalyzer
56
2012-09-21T07:43:38.102668-07001569993030858825flow172.18.3.1163147172.18.1.10053UDPpcapanalyzer
57
2012-09-21T07:43:38.102668-0700162873693714987flow172.18.3.116427212.58.244.13080TCPpcapanalyzer
58
2012-09-21T07:43:38.102668-07001851985551105845flow172.18.3.116573173.194.41.17580TCPpcapanalyzer
59
2012-09-21T07:43:38.102668-0700163281718831108flow172.18.3.1164374172.18.1.10053UDPpcapanalyzer
60
2012-09-21T07:43:38.102668-0700304051418595073flow172.18.3.1152481172.18.1.10053UDPpcapanalyzer
File 654
Showing 61-80 of 654 items.
#
TimestampSourceDestinationFile NameFile MagicFile Size
61
2012-09-21T07:41:44.834048-070080.239.217.171172.18.3.11/frameworks/barlesque/2.10.0/desktop/3.5/img/blq-search_grey_alpha.pngPNG image data, 13 x 13, 8-bit/color RGBA, non-interlaced188
62
2012-09-21T07:41:44.979458-070080.239.254.24172.18.3.11/media/images/63025000/jpg/_63025403_post.jpgJPEG image data, JFIF standard 1.01, resolution (DPI), density 96x96, segment length 16, baseline, precision 8, 144x81, frames 35117
63
2012-09-21T07:41:44.868677-070080.239.254.24172.18.3.11/media/images/63007000/jpg/_63007925_63003380.jpgJPEG image data, JFIF standard 1.01, resolution (DPI), density 96x96, segment length 16, baseline, precision 8, 144x81, frames 36163
64
2012-09-21T07:41:45.037413-070080.239.254.24172.18.3.11/media/images/63012000/jpg/_63012843_lynher_dairies_220511_0465.jpgJPEG image data, JFIF standard 1.01, resolution (DPI), density 96x96, segment length 16, baseline, precision 8, 144x81, frames 36038
65
2012-09-21T07:41:45.087322-070080.239.254.24172.18.3.11/js/map/map_0_0_32.jsASCII text, with very long lines, with no line terminators889
66
2012-09-21T07:41:44.873271-070080.239.254.24172.18.3.11/media/images/63001000/jpg/_63001711_63001544.jpgJPEG image data, JFIF standard 1.01, resolution (DPI), density 96x96, segment length 16, baseline, precision 8, 144x81, frames 35968
67
2012-09-21T07:41:44.834057-070080.239.254.34172.18.3.11/iplayer/images/episode/b01mxyyc_150_84.jpgJPEG image data, JFIF standard 1.01, resolution (DPI), density 72x72, segment length 16, baseline, precision 8, 150x84, frames 35292
68
2012-09-21T07:41:44.905789-070080.239.217.171172.18.3.11/frameworks/jquery/0.1.8/sharedmodules/jquery-1.6.2.jsASCII text, with very long lines133644
69
2012-09-21T07:41:44.910416-070080.239.254.24172.18.3.11/media/images/62937000/jpg/_62937264_62934668.jpgJPEG image data, JFIF standard 1.01, resolution (DPI), density 96x96, segment length 16, baseline, precision 8, 144x81, frames 35200
70
2012-09-21T07:41:44.843648-070080.239.254.24172.18.3.11/media/images/63030000/jpg/_63030020_photo(5).jpgJPEG image data, JFIF standard 1.01, resolution (DPI), density 96x96, segment length 16, baseline, precision 8, 144x81, frames 36076
71
2012-09-21T07:41:44.844035-070080.239.217.171172.18.3.11/frameworks/barlesque/2.10.0/desktop/3.5/script/barlesque.jsUTF-8 Unicode text, with very long lines, with no line terminators16858
72
2012-09-21T07:41:44.914523-070080.239.254.24172.18.3.11/media/images/62960000/jpg/_62960904_62960902.jpgJPEG image data, JFIF standard 1.01, resolution (DPI), density 96x96, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=3, xresolution=50, yresolution=58, resolutionunit=2], baseline, precision 8, 144x81, frames 35053
73
2012-09-21T07:41:44.953927-070080.239.254.24172.18.3.11/media/images/63025000/jpg/_63025721_trav.jpgJPEG image data, JFIF standard 1.01, resolution (DPI), density 96x96, segment length 16, baseline, precision 8, 144x81, frames 33974
74
2012-09-21T07:41:44.847059-070080.239.254.24172.18.3.11/media/images/63035000/jpg/_63035362_000145217-1.jpgJPEG image data, JFIF standard 1.01, resolution (DPI), density 96x96, segment length 16, baseline, precision 8, 144x81, frames 34457
75
2012-09-21T07:41:44.957724-070080.239.254.24172.18.3.11/media/images/63014000/jpg/_63014224_jex_1517346_de27-1.jpgJPEG image data, JFIF standard 1.01, resolution (DPI), density 96x96, segment length 16, baseline, precision 8, 144x81, frames 35087
76
2012-09-21T07:41:44.850881-070080.239.254.24172.18.3.11/media/images/63033000/jpg/_63033568_hi016036863.jpgJPEG image data, JFIF standard 1.01, resolution (DPI), density 96x96, segment length 16, baseline, precision 8, 144x81, frames 34747
77
2012-09-21T07:41:44.887840-070080.239.254.34172.18.3.11/glow/glow/1.7.7/core/core.jsASCII text, with very long lines98133
78
2012-09-21T07:41:45.000780-070080.239.254.24172.18.3.11/media/images/63017000/jpg/_63017897_136238087.jpgJPEG image data, JFIF standard 1.01, resolution (DPI), density 96x96, segment length 16, baseline, precision 8, 112x63, frames 34520
79
2012-09-21T07:41:45.128132-070080.239.254.24172.18.3.11/js/view/0_0_32/view.jsHTML document, ASCII text, with very long lines, with no line terminators9927
80
2012-09-21T07:41:45.004622-070080.239.254.24172.18.3.11/media/images/63021000/jpg/_63021371_eatrich144_getty.jpgJPEG image data, JFIF standard 1.01, resolution (DPI), density 96x96, segment length 16, baseline, precision 8, 112x63, frames 34997

Comments(not set)

Update Download PCAP Delete