0b0e4eab-aece-4353-aba0-730b9fcb3a0e.pcap

MD5bdeafd6f458ee1fa380fc3b50ab82d46
Submission Date2019-10-09 16:11:46
Tags(not set)
Alert 2
Showing 1-2 of 2 items.
#
TimestampSrc IpDest IpAlert SignatureP
1
2019-10-08T10:54:03.816965-0700192.168.100.65192.168.100.2ET POLICY DNS Query to DynDNS Domain *.hopto .org*
2
2019-10-08T10:54:35.231346-0700192.168.100.65192.168.100.2ET POLICY DNS Query to DynDNS Domain *.ddns .net*
DNS 13
Showing 1-13 of 13 items.
#
TimestampSrc IpDest IpDns TypeResource Record NameResource Record TypeResource Data
1
2019-10-08T10:54:03.795311-0700192.168.100.65192.168.100.2querygo.microsoft.comA(not set)
2
2019-10-08T10:54:03.816965-0700192.168.100.65192.168.100.2queryrobertmoore.hopto.orgA(not set)
3
2019-10-08T10:54:03.830725-0700192.168.100.65192.168.100.2queryramseycynthia.gleeze.comA(not set)
4
2019-10-08T10:54:03.977752-0700192.168.100.2192.168.100.65answerramseycynthia.gleeze.comA(not set)
5
2019-10-08T10:54:03.756832-0700192.168.100.65192.168.100.2querywww.bing.comA(not set)
6
2019-10-08T10:54:03.757034-0700192.168.100.2192.168.100.65answerwww.bing.comA(not set)
7
2019-10-08T10:54:03.824676-0700192.168.100.2192.168.100.65answerrobertmoore.hopto.orgA(not set)
8
2019-10-08T10:54:04.793134-0700192.168.100.65192.168.100.2querygo.microsoft.comA(not set)
9
2019-10-08T10:54:04.793230-0700192.168.100.2192.168.100.65answergo.microsoft.comA(not set)
10
2019-10-08T10:54:24.996524-0700192.168.100.65192.168.100.2queryvikkibret.mywire.orgA(not set)
11
2019-10-08T10:54:25.104364-0700192.168.100.2192.168.100.65answervikkibret.mywire.orgA(not set)
12
2019-10-08T10:54:35.231346-0700192.168.100.65192.168.100.2querysnick4059.ddns.netA(not set)
13
2019-10-08T10:54:35.238968-0700192.168.100.2192.168.100.65answersnick4059.ddns.netA(not set)
TLS 0
#
TimestampSource IPDestination IPTLS VersionServer Name Indication
No results found.
TFTP 0
#TimestampSrc IpDest IpTftp PacketTftp FileTftp Mode
No results found.
HTTP 2
Showing 1-2 of 2 items.
#
TimestampSourceHostnamePortMethodURLStatus
1
2019-10-08T10:54:04.230582-0700192.168.100.65www.bing.com80GET/favicon.ico200
2
2019-10-08T10:54:42.169085-0700192.168.100.65go.microsoft.com80GET/fwlink/?prd=11324&pver=4.5&sbp=AppLaunch2&plcid=0x409&o1=SHIM_NOVERSION_FOUND&version=(null)&processName=iexplore.exe&platform=0000&osver=5&isServer=0&shimver=4.0.30319.0(not set)
SMB 0
#
TimestampSrc IpDest IpSMB DialectCommandSessionTree
No results found.
SMTP 0
#
TimestampSourceDestinationEmail FromEmail ToSubject
No results found.
Flow 20
Showing 1-20 of 20 items.
#
TimestampFlow IdEvent TypeSourceSource PortDestinationDestination PortProtocolHost
1
2019-10-08T10:54:42.169085-0700998901165850414flowfe80:0000:0000:0000:a179:b3ff:0199:231462104ff02:0000:0000:0000:0000:0000:0001:00035355UDPpcapanalyzer
2
2019-10-08T10:54:42.169085-07001986009204891271flowfe80:0000:0000:0000:a179:b3ff:0199:231461594ff02:0000:0000:0000:0000:0000:0001:00035355UDPpcapanalyzer
3
2019-10-08T10:54:42.169085-07001717273100962938flow192.168.100.6564082224.0.0.2525355UDPpcapanalyzer
4
2019-10-08T10:54:42.169085-07002182104526292950flow192.168.100.6553802224.0.0.2525355UDPpcapanalyzer
5
2019-10-08T10:54:42.169085-07001901703291838217flow192.168.100.6550314224.0.0.2525355UDPpcapanalyzer
6
2019-10-08T10:54:42.169085-07001341592311581604flowfe80:0000:0000:0000:a179:b3ff:0199:231461896ff02:0000:0000:0000:0000:0000:0001:00035355UDPpcapanalyzer
7
2019-10-08T10:54:42.169085-0700418724098573518flow192.168.100.65137192.168.100.255137UDPpcapanalyzer
8
2019-10-08T10:54:42.169085-0700602243756682087flowfe80:0000:0000:0000:a179:b3ff:0199:2314546ff02:0000:0000:0000:0000:0000:0001:0002547UDPpcapanalyzer
9
2019-10-08T10:54:42.169085-07002173308436060929flow192.168.100.654977965.52.38.1422404TCPpcapanalyzer
10
2019-10-08T10:54:42.169085-07001189657845970092flow192.168.100.6562685192.168.100.253UDPpcapanalyzer
11
2019-10-08T10:54:42.169085-0700770563525813137flow192.168.100.654945113.107.21.20080TCPpcapanalyzer
12
2019-10-08T10:54:42.169085-07001757650089667862flow192.168.100.654945765.52.38.1422404TCPpcapanalyzer
13
2019-10-08T10:54:42.169085-0700221795554405637flow192.168.100.6559337192.168.100.253UDPpcapanalyzer
14
2019-10-08T10:54:42.169085-07002198678806405807flow192.168.100.6555625192.168.100.253UDPpcapanalyzer
15
2019-10-08T10:54:42.169085-0700242797946570674flow192.168.100.6557863192.168.100.253UDPpcapanalyzer
16
2019-10-08T10:54:42.169085-0700666784231033952flow192.168.100.6561207192.168.100.253UDPpcapanalyzer
17
2019-10-08T10:54:42.169085-07001522062543562753flow192.168.100.65494712.19.38.5980TCPpcapanalyzer
18
2019-10-08T10:54:42.169085-0700123646961743685flow192.168.100.6553392192.168.100.253UDPpcapanalyzer
19
2019-10-08T10:54:42.169085-07001539586008825997flow192.168.100.65138192.168.100.255138UDPpcapanalyzer
20
2019-10-08T10:54:42.169085-0700275323733911459flow192.168.100.654993765.52.38.1422404TCPpcapanalyzer
File 1
Showing 1-1 of 1 item.
#
TimestampSourceDestinationFile NameFile MagicFile Size
1
2019-10-08T10:54:04.230582-070013.107.21.200192.168.100.65/favicon.icoPNG image data, 16 x 16, 4-bit colormap, non-interlaced237

Comments(not set)

Update Download PCAP Delete