port4.root.2.pcap

MD5185d59f11156e97d237d5b7321c243a5
Submission Date2019-10-09 07:57:11
Tags
Alert 0
#
TimestampSrc IpDest IpAlert SignatureP
No results found.
DNS 146
Showing 21-40 of 146 items.
#
TimestampSrc IpDest IpDns TypeResource Record NameResource Record TypeResource Data
21
2019-04-18T10:13:00.244769-0700172.24.10.188172.24.1.1queryctldl.windowsupdate.comA(not set)
22
2019-04-18T10:13:00.878334-0700172.24.1.1172.24.10.188answerctldl.windowsupdate.comA(not set)
23
2019-04-18T10:13:04.700469-0700172.24.10.202208.91.112.53querywww.gstatic.comAAAA(not set)
24
2019-04-18T10:13:05.496316-0700208.91.112.53172.24.10.202answerwww.gstatic.comAAAA(not set)
25
2019-04-18T10:13:05.666771-0700172.24.10.188172.24.1.1queryctldl.windowsupdate.comA(not set)
26
2019-04-18T10:13:05.666809-0700172.24.1.1172.24.10.188answerctldl.windowsupdate.comA(not set)
27
2019-04-18T10:13:05.887640-0700172.24.10.202208.91.112.53queryyt3.ggpht.comA(not set)
28
2019-04-18T10:13:06.577884-0700208.91.112.53172.24.10.202answeryt3.ggpht.comA(not set)
29
2019-04-18T10:13:06.579694-0700172.24.10.202208.91.112.53queryphotos-ugc.l.googleusercontent.comA(not set)
30
2019-04-18T10:13:03.909068-0700172.24.10.202208.91.112.53querywww.gstatic.comA(not set)
31
2019-04-18T10:13:03.931752-0700172.24.10.202208.91.112.53queryclients1.google.comA(not set)
32
2019-04-18T10:13:04.256990-0700172.24.10.202208.91.112.53queryi.ytimg.comA(not set)
33
2019-04-18T10:13:04.698704-0700208.91.112.53172.24.10.202answerwww.gstatic.comA(not set)
34
2019-04-18T10:13:04.899676-0700172.24.10.202208.91.112.53queryclients1.google.comA(not set)
35
2019-04-18T10:13:05.080214-0700208.91.112.53172.24.10.202answeri.ytimg.comA(not set)
36
2019-04-18T10:13:05.694266-0700208.91.112.53172.24.10.202answerclients1.google.comA(not set)
37
2019-04-18T10:13:05.904482-0700172.24.10.202208.91.112.53queryytimg-edge-static.l.google.comAAAA(not set)
38
2019-04-18T10:13:06.417066-0700172.24.10.202208.91.112.53queryclients.l.google.comAAAA(not set)
39
2019-04-18T10:13:06.593102-0700208.91.112.53172.24.10.202answerytimg-edge-static.l.google.comAAAA(not set)
40
2019-04-18T10:13:08.053692-0700172.24.10.202208.91.112.53querygstaticadssl.l.google.comAAAA(not set)
TLS 70
Showing 1-20 of 70 items.
#
TimestampSource IPDestination IPTLS VersionServer Name Indication
1
2019-04-18T10:12:58.767206-0700172.24.10.188172.217.10.142TLS 1.3play.google.com
2
2019-04-18T10:12:56.515235-0700172.24.10.18713.107.5.88TLS 1.2evoke-windowsservices-tas.msedge.net
3
2019-04-18T10:12:57.199332-0700172.24.10.202172.24.1.1TLS 1.2(not set)
4
2019-04-18T10:12:57.217448-0700172.24.10.188172.217.12.138TLS 1.3taskassist-pa.clients6.google.com
5
2019-04-18T10:12:58.043105-0700172.24.10.18954.203.74.83TLS 1.2jd.sital.space
6
2019-04-18T10:12:59.168418-0700172.24.10.188172.217.6.197TLS 1.3mail.google.com
7
2019-04-18T10:12:59.313219-0700172.24.10.202172.24.1.1TLS 1.2(not set)
8
2019-04-18T10:12:59.589214-0700172.24.10.188172.217.10.142TLS 1.3play.google.com
9
2019-04-18T10:12:58.013540-0700172.24.10.188172.217.11.33TLS 1.3lh3.googleusercontent.com
10
2019-04-18T10:13:00.219933-0700172.24.10.18852.189.181.71TLS 1.2c.urs.microsoft.com
11
2019-04-18T10:13:00.225018-0700172.24.10.18852.189.181.71TLS 1.2c.urs.microsoft.com
12
2019-04-18T10:13:04.347766-0700172.24.10.202172.24.1.1TLS 1.2(not set)
13
2019-04-18T10:13:05.830606-0700172.24.10.202172.217.10.3TLS 1.3www.gstatic.com
14
2019-04-18T10:13:06.223844-0700172.24.10.202172.217.12.182TLS 1.3i.ytimg.com
15
2019-04-18T10:13:02.219215-0700172.24.10.202172.24.1.1TLS 1.2(not set)
16
2019-04-18T10:13:05.496671-0700172.24.10.202172.217.10.3TLS 1.3www.gstatic.com
17
2019-04-18T10:13:05.883193-0700172.24.10.202172.217.12.182TLS 1.3i.ytimg.com
18
2019-04-18T10:13:06.250672-0700172.24.10.202172.217.10.238TLS 1.3clients1.google.com
19
2019-04-18T10:13:07.282282-0700172.24.10.202172.24.1.1TLS 1.2(not set)
20
2019-04-18T10:13:09.384421-0700172.24.10.202172.24.1.1TLS 1.2(not set)
TFTP 0
#TimestampSrc IpDest IpTftp PacketTftp FileTftp Mode
No results found.
HTTP 6
Showing 1-6 of 6 items.
#
TimestampSourceHostnamePortMethodURLStatus
1
2019-04-18T10:13:01.178504-0700172.24.10.188ocsp.digicert.com80GET/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTBL0V27RVZ7LBduom%2FnYB45SPUEwQU5Z1ZMIJHWMys%2BghUNoZ7OrUETfACEA8sEMlbBsCTf7jUSfg%2BhWk%3D403
2
2019-04-18T10:13:01.405210-0700172.24.10.188crl3.digicert.com80GET/Omniroot2025.crl403
3
2019-04-18T10:13:14.888688-0700172.24.10.188ctldl.windowsupdate.com80GET/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?8a97ea108abed56a403
4
2019-04-18T10:13:15.112128-0700172.24.10.188ctldl.windowsupdate.com80GET/msdownload/update/v3/static/trustedr/en/pinrulesstl.cab?ca6d4fc72938aef6403
5
2019-04-18T10:13:30.002254-0700172.24.10.188ctldl.windowsupdate.com80GET/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?e19f463c081a8e2e403
6
2019-04-18T10:13:30.002254-0700172.24.10.188ctldl.windowsupdate.com80GET/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?6d2dfc8dc96beec7403
SMB 0
#
TimestampSrc IpDest IpSMB DialectCommandSessionTree
No results found.
SMTP 0
#
TimestampSourceDestinationEmail FromEmail ToSubject
No results found.
Flow 222
Showing 181-200 of 222 items.
#
TimestampFlow IdEvent TypeSourceSource PortDestinationDestination PortProtocolHost
181
2019-04-18T10:13:30.002254-07001660544687041574flow172.24.10.1885261113.68.93.109443TCPpcapanalyzer
182
2019-04-18T10:13:30.002254-0700675880483929243flow172.24.10.1875502174.125.192.1255222TCPpcapanalyzer
183
2019-04-18T10:13:30.002254-07002224864734533231flow172.24.10.20257210208.91.112.5353UDPpcapanalyzer
184
2019-04-18T10:13:30.002254-0700958291763817598flow172.24.10.18962603172.217.10.78443TCPpcapanalyzer
185
2019-04-18T10:13:30.002254-0700818731097113380flow172.24.10.18755034209.85.232.109993TCPpcapanalyzer
186
2019-04-18T10:13:30.002254-0700398180783150909flow172.24.10.20264449172.217.3.97443TCPpcapanalyzer
187
2019-04-18T10:13:30.002254-0700398511495735080flow172.24.10.18852595172.217.10.142443TCPpcapanalyzer
188
2019-04-18T10:13:30.002254-0700398859389445998flow172.24.10.20264499172.24.1.1450TCPpcapanalyzer
189
2019-04-18T10:13:30.002254-0700821930846406843flow172.24.10.20253634208.91.112.5353UDPpcapanalyzer
190
2019-04-18T10:13:30.002254-0700822892919886767flow172.24.10.20264457172.24.1.1450TCPpcapanalyzer
191
2019-04-18T10:13:30.002254-07001808733942959358flow172.24.10.18755374172.217.10.142443TCPpcapanalyzer
192
2019-04-18T10:13:30.002254-07001669942073932833flow172.24.10.18863712172.24.1.153UDPpcapanalyzer
193
2019-04-18T10:13:30.002254-0700405387737721612flow172.24.10.18755377172.217.12.195443TCPpcapanalyzer
194
2019-04-18T10:13:30.002254-0700265805595445116flow172.24.10.18852576172.217.12.138443TCPpcapanalyzer
195
2019-04-18T10:13:30.002254-07001251272957134295flow172.24.10.20264444172.217.10.3443TCPpcapanalyzer
196
2019-04-18T10:13:30.002254-0700688559226314755flow172.24.10.18959191172.24.1.153UDPpcapanalyzer
197
2019-04-18T10:13:30.002254-0700970588255489517flow172.24.10.20263652172.217.12.194443TCPpcapanalyzer
198
2019-04-18T10:13:30.002254-07001675048790343805flow172.24.10.20264445172.217.12.182443TCPpcapanalyzer
199
2019-04-18T10:13:30.002254-0700693760433029896flow172.24.10.20255482208.91.112.5353UDPpcapanalyzer
200
2019-04-18T10:13:30.002254-0700413097204593580flow74.125.141.189443172.24.10.18851525TCPpcapanalyzer
File 6
Showing 1-6 of 6 items.
#
TimestampSourceDestinationFile NameFile MagicFile Size
1
2019-04-18T10:13:01.178504-070072.21.91.29172.24.10.188/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTBL0V27RVZ7LBduom/nYB45SPUEwQU5Z1ZMIJHWMys+ghUNoZ7OrUETfACEA8sEMlbBsCTf7jUSfg+hWk=HTML document, ASCII text, with CRLF, LF line terminators3551
2
2019-04-18T10:13:01.405210-070072.21.91.29172.24.10.188/Omniroot2025.crlHTML document, ASCII text3447
3
2019-04-18T10:13:14.888688-07008.253.151.120172.24.10.188/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cabHTML document, ASCII text3515
4
2019-04-18T10:13:15.112128-07008.253.151.120172.24.10.188/msdownload/update/v3/static/trustedr/en/pinrulesstl.cabHTML document, ASCII text3509
5
2019-04-18T10:13:30.002254-070013.107.4.50172.24.10.188/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cabHTML document, ASCII text3515
6
2019-04-18T10:13:30.002254-070013.107.4.50172.24.10.188/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cabHTML document, ASCII text3515

Comments

Update Download PCAP Delete