Ch9.pcap

MD51a94e9fd79d54c67c86127a09788b51c
Submission Date2018-11-12 08:04:30
Tags(not set)
Alert 1
Showing 1-1 of 1 item.
#
TimestampSrc IpDest IpAlert SignatureP
1
2017-10-29T10:07:28.094332-0700192.168.1.88192.168.1.255ET POLICY Dropbox Client Broadcasting*
DNS 116
Showing 1-20 of 116 items.
#
TimestampSrc IpDest IpDns TypeResource Record NameResource Record TypeResource Data
1
2017-10-29T10:07:32.710881-0700192.168.1.88192.168.1.1queryapis.google.comA(not set)
2
2017-10-29T10:07:32.711051-0700192.168.1.88192.168.1.1queryfonts.googleapis.comA(not set)
3
2017-10-29T10:07:32.758646-0700192.168.1.88192.168.1.1queryogs.google.comA(not set)
4
2017-10-29T10:07:32.766935-0700192.168.1.1192.168.1.88answerfonts.googleapis.comA(not set)
5
2017-10-29T10:07:32.774511-0700192.168.1.1192.168.1.88answerapis.google.comA(not set)
6
2017-10-29T10:07:32.710881-0700192.168.1.88192.168.1.1querygoogleads.g.doubleclick.netA(not set)
7
2017-10-29T10:07:32.710881-0700192.168.1.88192.168.1.1queryclients5.google.comA(not set)
8
2017-10-29T10:07:32.765513-0700192.168.1.1192.168.1.88answergoogleads.g.doubleclick.netA(not set)
9
2017-10-29T10:07:32.774514-0700192.168.1.1192.168.1.88answerclients5.google.comA(not set)
10
2017-10-29T10:07:32.798533-0700192.168.1.88192.168.1.1querygooglehosted.l.googleusercontent.comA(not set)
11
2017-10-29T10:07:32.807781-0700192.168.1.88192.168.1.1queryoutlook.office365.comA(not set)
12
2017-10-29T10:07:32.710148-0700192.168.1.88192.168.1.1querywww.google.comA(not set)
13
2017-10-29T10:07:32.710934-0700192.168.1.88192.168.1.1queryencrypted-tbn0.gstatic.comA(not set)
14
2017-10-29T10:07:32.757969-0700192.168.1.1192.168.1.88answerwww.google.comA(not set)
15
2017-10-29T10:07:32.765744-0700192.168.1.88192.168.1.1queryssl.gstatic.comA(not set)
16
2017-10-29T10:07:32.774515-0700192.168.1.1192.168.1.88answerencrypted-tbn0.gstatic.comA(not set)
17
2017-10-29T10:07:32.888663-0700192.168.1.1192.168.1.88answerssl.gstatic.comA(not set)
18
2017-10-29T10:07:32.817271-0700192.168.1.1192.168.1.88answerogs.google.comA(not set)
19
2017-10-29T10:07:33.057568-0700192.168.1.1192.168.1.88answeroutlook.office365.comA(not set)
20
2017-10-29T10:07:33.078700-0700192.168.1.1192.168.1.88answergooglehosted.l.googleusercontent.comA(not set)
TLS 60
Showing 1-20 of 60 items.
#
TimestampSource IPDestination IPTLS VersionServer Name Indication
1
2017-10-29T10:07:34.664154-0700192.168.1.8874.125.201.132TLS 1.2apidata.googleusercontent.com
2
2017-10-29T10:07:33.593701-0700192.168.1.8840.97.130.18TLS 1.2outlook.office365.com
3
2017-10-29T10:07:34.664149-0700192.168.1.8874.125.201.132TLS 1.2apidata.googleusercontent.com
4
2017-10-29T10:07:33.769185-0700192.168.1.8874.125.201.132TLS 1.2apidata.googleusercontent.com
5
2017-10-29T10:07:34.664155-0700192.168.1.8874.125.201.132TLS 1.2apidata.googleusercontent.com
6
2017-10-29T10:07:34.664156-0700192.168.1.8874.125.201.132TLS 1.2apidata.googleusercontent.com
7
2017-10-29T10:07:37.209167-0700192.168.1.88172.217.8.174TLS 1.2youtube.com
8
2017-10-29T10:07:37.218772-0700192.168.1.88172.217.8.174TLS 1.2youtube.com
9
2017-10-29T10:07:37.856120-0700192.168.1.88216.58.216.110TLS 1.2www.youtube.com
10
2017-10-29T10:07:39.228497-0700192.168.1.88172.217.4.97TLS 1.2yt3.ggpht.com
11
2017-10-29T10:07:39.315090-0700192.168.1.88172.217.4.97TLS 1.2yt3.ggpht.com
12
2017-10-29T10:07:39.320925-0700192.168.1.88172.217.4.97TLS 1.2yt3.ggpht.com
13
2017-10-29T10:07:39.324843-0700192.168.1.88172.217.4.97TLS 1.2yt3.ggpht.com
14
2017-10-29T10:07:39.369540-0700192.168.1.88172.217.4.97TLS 1.2yt3.ggpht.com
15
2017-10-29T10:07:39.332098-0700192.168.1.88172.217.4.97TLS 1.2yt3.ggpht.com
16
2017-10-29T10:07:41.138636-0700192.168.1.88157.240.2.25TLS 1.2connect.facebook.net
17
2017-10-29T10:07:40.724742-0700192.168.1.88216.58.216.98TLS 1.2pubads.g.doubleclick.net
18
2017-10-29T10:07:41.517042-0700192.168.1.88216.58.192.230TLS 1.2s0.2mdn.net
19
2017-10-29T10:07:41.522223-0700192.168.1.8823.21.109.110TLS 1.2insight.adsrvr.org
20
2017-10-29T10:07:41.544863-0700192.168.1.8813.33.154.31TLS 1.2js.adsrvr.org
TFTP 0
#TimestampSrc IpDest IpTftp PacketTftp FileTftp Mode
No results found.
HTTP 24
Showing 1-20 of 24 items.
#
TimestampSourceHostnamePortMethodURLStatus
1
2017-10-29T10:07:37.094142-0700192.168.1.88youtube.com80GET/301
2
2017-10-29T10:07:40.176209-0700192.168.1.88192.168.1.3180GET/dial/YouTube400
3
2017-10-29T10:07:40.179209-0700192.168.1.88192.168.1.5280GET/dial/YouTube400
4
2017-10-29T10:07:40.180886-0700192.168.1.88192.168.1.1880GET/dial/YouTube400
5
2017-10-29T10:07:40.519846-0700192.168.1.88sau.edu80GET/301
6
2017-10-29T10:07:42.429191-0700192.168.1.88www.googletagmanager.com80GET/gtm.js?id=GTM-MX8CVG404
7
2017-10-29T10:07:42.456445-0700192.168.1.88www.sau.edu80GET/prebuilt/_xbase/images/homepage/icons/visit-icon.svg200
8
2017-10-29T10:07:42.007429-0700192.168.1.88www.sau.edu80GET/200
9
2017-10-29T10:07:42.465001-0700192.168.1.88www.sau.edu80GET/prebuilt/_xbase/images/homepage/icons/cost-calculator-icon.svg200
10
2017-10-29T10:07:43.572091-0700192.168.1.88www.sau.edu80GET/Images/home_page/DBA-advance-Pillutla(0).jpg200
11
2017-10-29T10:07:43.999826-0700192.168.1.88www.sau.edu80GET/prebuilt/_xbase/images/homepage/icons/apply-now-icon.svg200
12
2017-10-29T10:07:42.832740-0700192.168.1.88www.sau.edu80GET/Images/home_page/FriendshipsWbeehive.jpg200
13
2017-10-29T10:07:42.833568-0700192.168.1.88www.sau.edu80GET/prebuilt/_xbase/images/homepage/icons/request-more-info-icon.svg200
14
2017-10-29T10:07:43.974720-0700192.168.1.88www.sau.edu80GET/Images/home_page/small-classes-artQuinn.jpg200
15
2017-10-29T10:07:44.081479-0700192.168.1.88www.sau.edu80GET/Images/News-and-Events/2017-Fall/JIMPLACETHUMB.jpg200
16
2017-10-29T10:07:44.340195-0700192.168.1.88www.sau.edu80GET/images/promos/homepromo/ambrosezine_107.jpg200
17
2017-10-29T10:07:44.412268-0700192.168.1.88www.sau.edu80GET/images/promos/homepromo/Global17LGrgb.jpg200
18
2017-10-29T10:07:43.211936-0700192.168.1.88www.sau.edu80GET/PreBuilt/_xbase/images/shared/m-background.gif200
19
2017-10-29T10:07:43.687796-0700192.168.1.88www.sau.edu80GET/Images/News-and-Events/2017-Fall/WRCThumb_3.jpg200
20
2017-10-29T10:07:43.940312-0700192.168.1.88www.sau.edu80GET/Images/News-and-Events/2017-Fall/Thomas_higgins_thumb.jpg200
SMB 0
#
TimestampSrc IpDest IpSMB DialectCommandSessionTree
No results found.
SMTP 0
#
TimestampSourceDestinationEmail FromEmail ToSubject
No results found.
Flow 216
Showing 1-20 of 216 items.
#
TimestampFlow IdEvent TypeSourceSource PortDestinationDestination PortProtocolHost
1
2017-10-29T10:07:56.554589-0700142590948973041flow192.168.1.885876192.168.1.153UDPpcapanalyzer
2
2017-10-29T10:07:56.554589-07001881377935501flow192.168.1.8853331216.58.192.230443UDPpcapanalyzer
3
2017-10-29T10:07:56.554589-07001409533286731573flow192.168.1.8855121172.217.4.97443TCPpcapanalyzer
4
2017-10-29T10:07:56.554589-07001550275070496147flow192.168.1.8855242184.169.131.88443TCPpcapanalyzer
5
2017-10-29T10:07:56.554589-0700424667221225868flow192.168.1.885506675.101.136.4980TCPpcapanalyzer
6
2017-10-29T10:07:56.554589-0700143342568345164flow192.168.1.885505875.101.136.4980TCPpcapanalyzer
7
2017-10-29T10:07:56.554589-07002113886448654038flow192.168.1.885505675.101.136.4980TCPpcapanalyzer
8
2017-10-29T10:07:56.554589-07001270017716044005flow192.168.1.19563647192.168.1.25532412UDPpcapanalyzer
9
2017-10-29T10:07:56.554589-0700284900395363728flow192.168.1.8859474172.217.4.110443UDPpcapanalyzer
10
2017-10-29T10:07:56.554589-0700989229934229386flow192.168.1.8853581172.217.8.162443UDPpcapanalyzer
11
2017-10-29T10:07:56.554589-07001411916993793346flow192.168.1.8842793192.168.1.153UDPpcapanalyzer
12
2017-10-29T10:07:56.554589-0700849065824088460flow192.168.1.885509874.125.201.132443TCPpcapanalyzer
13
2017-10-29T10:07:56.554589-07001131142096791285flow192.168.1.885523135.185.88.112443TCPpcapanalyzer
14
2017-10-29T10:07:56.554589-07002116437659343545flow192.168.1.8821717192.168.1.153UDPpcapanalyzer
15
2017-10-29T10:07:56.554589-0700991106835600660flow192.168.1.8855202198.51.152.184443TCPpcapanalyzer
16
2017-10-29T10:07:56.554589-0700428412432608094flow192.168.1.885505375.101.136.4980TCPpcapanalyzer
17
2017-10-29T10:07:56.554589-0700569313129708709flow192.168.1.8833964192.168.1.153UDPpcapanalyzer
18
2017-10-29T10:07:56.554589-0700569360374662658flow192.168.1.8825528192.168.1.153UDPpcapanalyzer
19
2017-10-29T10:07:56.554589-0700147510834054644flow192.168.1.885517313.33.154.31443TCPpcapanalyzer
20
2017-10-29T10:07:56.554589-07001837612677261502flow192.168.1.885516363.233.192.9580TCPpcapanalyzer
File 20
Showing 1-20 of 20 items.
#
TimestampSourceDestinationFile NameFile MagicFile Size
1
2017-10-29T10:07:40.519846-070063.233.192.95192.168.1.88/HTML document, ASCII text142
2
2017-10-29T10:07:42.429191-0700216.58.192.168192.168.1.88/gtm.jsHTML document, UTF-8 Unicode text, with very long lines1581
3
2017-10-29T10:07:42.456445-070063.233.192.95192.168.1.88/prebuilt/_xbase/images/homepage/icons/visit-icon.svgSVG Scalable Vector Graphics image1473
4
2017-10-29T10:07:42.007429-070063.233.192.95192.168.1.88/HTML document, ASCII text, with very long lines, with CRLF line terminators13301
5
2017-10-29T10:07:42.465001-070063.233.192.95192.168.1.88/prebuilt/_xbase/images/homepage/icons/cost-calculator-icon.svgSVG Scalable Vector Graphics image2307
6
2017-10-29T10:07:43.572091-070063.233.192.95192.168.1.88/Images/home_page/DBA-advance-Pillutla(0).jpgJPEG image data, Exif standard: [TIFF image data, little-endian, direntries=0], baseline, precision 8, 682x270, frames 342347
7
2017-10-29T10:07:43.999826-070063.233.192.95192.168.1.88/prebuilt/_xbase/images/homepage/icons/apply-now-icon.svgSVG Scalable Vector Graphics image1049
8
2017-10-29T10:07:42.832740-070063.233.192.95192.168.1.88/Images/home_page/FriendshipsWbeehive.jpgJPEG image data, Exif standard: [TIFF image data, little-endian, direntries=0], baseline, precision 8, 682x270, frames 348313
9
2017-10-29T10:07:43.974720-070063.233.192.95192.168.1.88/Images/home_page/small-classes-artQuinn.jpgJPEG image data, Exif standard: [TIFF image data, little-endian, direntries=0], baseline, precision 8, 682x270, frames 369493
10
2017-10-29T10:07:44.081479-070063.233.192.95192.168.1.88/Images/News-and-Events/2017-Fall/JIMPLACETHUMB.jpgJPEG image data, JFIF standard 1.01, aspect ratio, density 72x72, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=6, orientation=upper-left, xresolution=86, yresolution=94, software=Photos 2.0, datetime=2017:10:27 11:39:51]36305
11
2017-10-29T10:07:44.340195-070063.233.192.95192.168.1.88/images/promos/homepromo/ambrosezine_107.jpgJPEG image data, Exif standard: [TIFF image data, little-endian, direntries=0], baseline, precision 8, 190x107, frames 315228
12
2017-10-29T10:07:42.833568-070063.233.192.95192.168.1.88/prebuilt/_xbase/images/homepage/icons/request-more-info-icon.svgSVG Scalable Vector Graphics image2597
13
2017-10-29T10:07:44.412268-070063.233.192.95192.168.1.88/images/promos/homepromo/Global17LGrgb.jpgJPEG image data, JFIF standard 1.01, aspect ratio, density 72x72, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=8, PhotometricIntepretation=RGB, orientation=upper-left, xresolution=110, yresolution=118, resolutionunit=2, software=Photos 2.0, datetime=2017:05:24 09:48:59]12168
14
2017-10-29T10:07:43.211936-070063.233.192.95192.168.1.88/PreBuilt/_xbase/images/shared/m-background.gifGIF image data, version 89a, 5 x 2471206
15
2017-10-29T10:07:43.687796-070063.233.192.95192.168.1.88/Images/News-and-Events/2017-Fall/WRCThumb_3.jpgJPEG image data, JFIF standard 1.01, aspect ratio, density 72x72, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=9, manufacturer=Canon, model=Canon EOS 7D Mark II, orientation=upper-left, xresolution=150, yresolution=158, resolutionunit=2, software=Photos 2.0, datetime=2017:09:19 15:36:33]39869
16
2017-10-29T10:07:43.940312-070063.233.192.95192.168.1.88/Images/News-and-Events/2017-Fall/Thomas_higgins_thumb.jpgJPEG image data, JFIF standard 1.01, resolution (DPI), density 96x96, segment length 16, baseline, precision 8, 86x86, frames 38229
17
2017-10-29T10:07:44.067334-070063.233.192.95192.168.1.88/Images/home_page/CDU-AHtower16.jpgJPEG image data, Exif standard: [TIFF image data, little-endian, direntries=0], baseline, precision 8, 682x270, frames 380869
18
2017-10-29T10:07:44.115489-070063.233.192.95192.168.1.88/Images/News-and-Events/Publications/Scene/Scene2017-August/NajdaAlexsandra-T.jpgJPEG image data, Exif standard: [TIFF image data, little-endian, direntries=0], baseline, precision 8, 90x90, frames 35115
19
2017-10-29T10:07:44.271527-070063.233.192.95192.168.1.88/images/promos/homepromo/WRC-ConstCam_107.jpgJPEG image data, Exif standard: [TIFF image data, little-endian, direntries=0], baseline, precision 8, 190x107, frames 311132
20
2017-10-29T10:07:44.391092-070063.233.192.95192.168.1.88/images/promos/homepromo/BOF-TCSA190x107.jpgJPEG image data, Exif standard: [TIFF image data, little-endian, direntries=0], baseline, precision 8, 190x107, frames 38229

Comments(not set)

Update Download PCAP Delete